{"id":198,"name":"undici","ecosystem":"npm","repository_url":"https://github.com/nodejs/undici","issues_count":15774,"created_at":"2025-06-06T15:01:33.121Z","updated_at":"2025-06-06T15:01:33.121Z","purl":"pkg:npm/undici","metadata":{"id":2500533,"name":"undici","ecosystem":"npm","description":"An HTTP/1.1 client, written from scratch for Node.js","homepage":"https://undici.nodejs.org","licenses":"MIT","normalized_licenses":["MIT"],"repository_url":"https://github.com/nodejs/undici","keywords_array":["fetch","http","https","promise","request","curl","wget","xhr","whatwg"],"namespace":null,"versions_count":244,"first_release_published_at":"2018-07-26T17:26:12.354Z","latest_release_published_at":"2025-05-20T07:19:22.524Z","latest_release_number":"7.10.0","last_synced_at":"2025-05-20T07:20:16.302Z","created_at":"2022-04-10T02:40:57.212Z","updated_at":"2025-06-02T02:00:34.964Z","registry_url":"https://www.npmjs.com/package/undici","install_command":"npm install undici","documentation_url":null,"metadata":{"funding":null,"dist-tags":{"test":"5.24.0-test.6","next":"7.0.0-alpha.10","six":"6.21.2","five":"5.29.0","latest":"7.10.0"}},"repo_metadata":{"id":36969980,"uuid":"133092972","full_name":"nodejs/undici","owner":"nodejs","description":"An HTTP/1.1 client, written from scratch for Node.js","archived":false,"fork":false,"pushed_at":"2024-10-29T09:47:12.000Z","size":10130,"stargazers_count":6197,"open_issues_count":222,"forks_count":542,"subscribers_count":51,"default_branch":"main","last_synced_at":"2024-10-29T11:49:31.355Z","etag":null,"topics":["client","http","nodejs"],"latest_commit_sha":null,"homepage":"https://nodejs.github.io/undici","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/nodejs.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":"GOVERNANCE.md","roadmap":null,"authors":null,"dei":null}},"created_at":"2018-05-11T22:07:48.000Z","updated_at":"2024-10-29T08:47:18.000Z","dependencies_parsed_at":"2023-10-16T03:26:14.914Z","dependency_job_id":"f47ca4c0-4a14-4d56-8564-035b65a32fff","html_url":"https://github.com/nodejs/undici","commit_stats":{"total_commits":2760,"total_committers":273,"mean_commits":10.10989010989011,"dds":"0.47282608695652173","last_synced_commit":"fe44b9b36718ff2c171568fc4a239ecb8eba038d"},"previous_names":["mcollina/undici"],"tags_count":180,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/nodejs","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":222088852,"owners_count":16929035,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"nodejs","name":"Node.js","uuid":"9950313","kind":"organization","description":"","email":null,"website":"https://nodejs.org","location":null,"twitter":"nodejs","company":null,"icon_url":"https://avatars.githubusercontent.com/u/9950313?v=4","repositories_count":207,"last_synced_at":"2024-04-15T13:18:59.622Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/nodejs","funding_links":[],"total_stars":216497,"followers":11140,"following":0,"created_at":"2022-11-02T16:20:00.045Z","updated_at":"2024-04-15T13:20:17.388Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/nodejs","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/nodejs/repositories"},"tags":[{"name":"v6.13.0","sha":"65f768c72762b38e3d35a8a4934c0830c41b0f6c","kind":"commit","published_at":"2024-04-12T08:41:58.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.13.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.13.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.13.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.13.0/manifests"},{"name":"v6.12.0","sha":"7751d9bcd5bbba45b60c90183aeab450b60c0831","kind":"commit","published_at":"2024-04-08T09:46:22.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.12.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.12.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.12.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.12.0/manifests"},{"name":"v6.11.1","sha":"6df3c738d03dc4014a26640316bf699950d62024","kind":"commit","published_at":"2024-04-02T16:44:30.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.11.1","html_url":"https://github.com/nodejs/undici/releases/tag/v6.11.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.11.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.11.1/manifests"},{"name":"v5.28.4","sha":"fb983069071f52e0a7ea0e71078459c765aae172","kind":"commit","published_at":"2024-04-02T16:35:50.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.28.4","html_url":"https://github.com/nodejs/undici/releases/tag/v5.28.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.4/manifests"},{"name":"v6.11.0","sha":"ee5f892f3955eaca37730ed30349153ba203e9cd","kind":"commit","published_at":"2024-04-02T10:40:02.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.11.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.11.0/manifests"},{"name":"v6.10.2","sha":"7485cd9b4cf9a86cb76b1597df527eba15755bfc","kind":"tag","published_at":"2024-03-27T09:34:32.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.10.2","html_url":"https://github.com/nodejs/undici/releases/tag/v6.10.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.10.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.10.2/manifests"},{"name":"v6.10.1","sha":"dd3918fee4f90e02fb93ff1bc04e707144041938","kind":"commit","published_at":"2024-03-21T11:12:02.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.10.1","html_url":"https://github.com/nodejs/undici/releases/tag/v6.10.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.10.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.10.1/manifests"},{"name":"v6.10.0","sha":"e434060efc659e30865d711eafb71a6b01915533","kind":"commit","published_at":"2024-03-21T11:04:51.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.10.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.10.0/manifests"},{"name":"v6.9.0","sha":"3e59a2d7d82ba62b3fd11796f6479579f35a6871","kind":"commit","published_at":"2024-03-14T17:12:36.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.9.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.9.0/manifests"},{"name":"v6.8.0","sha":"f84ec8087e11a26ee3553a0c601f6a73373edae6","kind":"commit","published_at":"2024-03-13T08:44:06.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.8.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.8.0/manifests"},{"name":"v6.7.1","sha":"219da8b7b3fea7e38a7644b8bc35fe6fec97d66e","kind":"commit","published_at":"2024-03-08T08:48:42.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.7.1","html_url":"https://github.com/nodejs/undici/releases/tag/v6.7.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.7.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.7.1/manifests"},{"name":"v6.7.0","sha":"2316bae1b790517b9fbc8d066582410604ab733b","kind":"commit","published_at":"2024-03-03T17:08:17.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.7.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.7.0/manifests"},{"name":"v6.6.2","sha":"e48df9620edf1428bd457f481d47fa2c77f75322","kind":"commit","published_at":"2024-02-06T18:06:36.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.6.2","html_url":"https://github.com/nodejs/undici/releases/tag/v6.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.6.2/manifests"},{"name":"v6.6.1","sha":"d36b19eeaf89b0c02e309bb3bb780c1977b21feb","kind":"commit","published_at":"2024-02-05T11:26:34.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.6.1","html_url":"https://github.com/nodejs/undici/releases/tag/v6.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.6.1/manifests"},{"name":"v5.28.3","sha":"e71cb4c88faae5670a129fde5552266afc2dbc39","kind":"commit","published_at":"2024-02-05T11:25:23.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.28.3","html_url":"https://github.com/nodejs/undici/releases/tag/v5.28.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.3/manifests"},{"name":"v6.6.0","sha":"fa2d2d29a46412f8fb1f1a1ecf07b73e0db66a32","kind":"commit","published_at":"2024-02-01T09:35:25.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.6.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.6.0/manifests"},{"name":"v6.5.0","sha":"519b9e13543a594bcfa4d1954bf639c10cf3e824","kind":"commit","published_at":"2024-01-26T15:10:18.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.5.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.5.0/manifests"},{"name":"v6.4.0","sha":"9b8ee28b1080cebba211b84b6d89682d6fcb2df4","kind":"commit","published_at":"2024-01-19T15:00:17.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.4.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.4.0/manifests"},{"name":"v6.3.0","sha":"887d1cb2df84abdf7c57fb74342d3a51db681652","kind":"commit","published_at":"2024-01-08T14:56:10.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.3.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.3.0/manifests"},{"name":"v6.2.1","sha":"f51f917061aec737edfe635e52db5bccc6fc0ac6","kind":"commit","published_at":"2023-12-22T09:34:17.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.2.1","html_url":"https://github.com/nodejs/undici/releases/tag/v6.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.2.1/manifests"},{"name":"v6.2.0","sha":"0c4c4504852c71dac1a6eb8dfae0f2411b6f2fc6","kind":"commit","published_at":"2023-12-20T15:33:02.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.2.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.2.0/manifests"},{"name":"v6.1.0","sha":"250b89af0ae27b93aaacbb885e852636e2c78ce6","kind":"commit","published_at":"2023-12-20T14:00:32.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.1.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.1.0/manifests"},{"name":"v6.0.1","sha":"0c3c6f8474857497ad1d8ca3d2687a66589079d3","kind":"tag","published_at":"2023-12-06T08:20:55.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.0.1","html_url":"https://github.com/nodejs/undici/releases/tag/v6.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.0.1/manifests"},{"name":"v6.0.0","sha":"e218fc61eda46da8784e0cedcaa88cd7e84dee99","kind":"commit","published_at":"2023-12-05T08:46:41.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.0.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.0.0/manifests"},{"name":"v5.28.2","sha":"9a14e5f32a118fa93e769cc15ae8de9de552f2e4","kind":"commit","published_at":"2023-11-30T15:40:41.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.28.2","html_url":"https://github.com/nodejs/undici/releases/tag/v5.28.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.2/manifests"},{"name":"v5.28.1","sha":"286bb4463b05e01e809737214e8eb1c161b78240","kind":"commit","published_at":"2023-11-27T09:48:11.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.28.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.28.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.1/manifests"},{"name":"v5.28.0","sha":"66029d1b317c0cfe38543553055cc86c658d7635","kind":"commit","published_at":"2023-11-24T08:59:38.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.28.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.28.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.0/manifests"},{"name":"v5.27.2","sha":"1541173d7a728eaf88bcd87263cef2ea0d993e74","kind":"tag","published_at":"2023-11-03T20:35:33.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.27.2","html_url":"https://github.com/nodejs/undici/releases/tag/v5.27.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.27.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.27.2/manifests"},{"name":"v5.27.1","sha":"2aedba485b539335b7ade6977615f9f94173eab2","kind":"tag","published_at":"2023-11-03T16:53:37.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.27.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.27.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.27.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.27.1/manifests"},{"name":"v5.27.0","sha":"41c253d0c23fd1cf63b8033d8ab61c2cf13e8c6e","kind":"tag","published_at":"2023-10-26T11:47:25.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.27.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.27.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.27.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.27.0/manifests"},{"name":"v5.26.5","sha":"9197790ae0d015b40b75fd0c5cdb7420704b5272","kind":"commit","published_at":"2023-10-23T07:25:50.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.26.5","html_url":"https://github.com/nodejs/undici/releases/tag/v5.26.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.5/manifests"},{"name":"v5.26.4","sha":"dea70e27e4d14952eb7b96da021eb44d24d1159e","kind":"commit","published_at":"2023-10-19T08:45:52.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.26.4","html_url":"https://github.com/nodejs/undici/releases/tag/v5.26.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.4/manifests"},{"name":"v5.26.3","sha":"227b9bedf233f741b86dda4ae9d1c7ad69f5d75c","kind":"tag","published_at":"2023-10-11T19:12:15.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.26.3","html_url":"https://github.com/nodejs/undici/releases/tag/v5.26.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.3/manifests"},{"name":"v5.26.2","sha":"12a62187d45f332cf39dd405f7c52b759cf40cdd","kind":"commit","published_at":"2023-10-11T18:57:39.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.26.2","html_url":"https://github.com/nodejs/undici/releases/tag/v5.26.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.2/manifests"},{"name":"v5.26.1","sha":"c8c80b1115d668664d8cf3acec7535b0258c3079","kind":"tag","published_at":"2023-10-11T18:25:52.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.26.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.26.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.1/manifests"},{"name":"v5.26.0","sha":"4006aaf43ac8b30e16d6d3b89fa2e0df4b7eef33","kind":"commit","published_at":"2023-10-11T11:02:16.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.26.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.26.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.0/manifests"},{"name":"v5.23.4","sha":"5e654f351a9a813fed3e9feff4388b5c4fbda787","kind":"commit","published_at":"2023-10-03T17:23:45.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.23.4","html_url":"https://github.com/nodejs/undici/releases/tag/v5.23.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.23.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.23.4/manifests"},{"name":"v5.25.3","sha":"764915396f684168328544bb0778424c58e2d945","kind":"commit","published_at":"2023-10-01T14:52:28.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.25.3","html_url":"https://github.com/nodejs/undici/releases/tag/v5.25.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.25.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.25.3/manifests"},{"name":"v5.25.2","sha":"4013c4b8932e73728809e4106d5c9d9d40648031","kind":"commit","published_at":"2023-09-22T17:37:05.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.25.2","html_url":"https://github.com/nodejs/undici/releases/tag/v5.25.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.25.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.25.2/manifests"},{"name":"v5.25.1","sha":"c86279c9bcf62fe28d124b124b91eb364d478a25","kind":"commit","published_at":"2023-09-20T21:03:45.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.25.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.25.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.25.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.25.1/manifests"},{"name":"v5.25.0","sha":"985b3816708512bafefa1544def183cc6d1536be","kind":"commit","published_at":"2023-09-20T12:55:52.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.25.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.25.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.25.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.25.0/manifests"},{"name":"v5.24.0-test.2","sha":"9c3e7d7ef367ebde507a3111a4bef99d8571cd46","kind":"tag","published_at":"2023-09-19T17:18:16.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.24.0-test.2","html_url":"https://github.com/nodejs/undici/releases/tag/v5.24.0-test.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.24.0-test.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.24.0-test.2/manifests"},{"name":"v5.24.0","sha":"9fa8224c274d52f67cd82d4bb820e72627df1e9f","kind":"commit","published_at":"2023-09-08T14:09:23.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.24.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.24.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.24.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.24.0/manifests"},{"name":"v5.23.0","sha":"59abe3f50d9c41a7e32a068654905f0919c9be71","kind":"tag","published_at":"2023-08-03T08:32:22.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.23.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.23.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.23.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.23.0/manifests"},{"name":"v5.22.1","sha":"9d30456aa6f195b83ea4ba36ed0b51a951e6bd87","kind":"tag","published_at":"2023-05-11T07:49:03.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.22.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.22.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.22.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.22.1/manifests"},{"name":"v5.22.0","sha":"6870d5b4c58e976f99a16c0ec71051d4b7e2e628","kind":"tag","published_at":"2023-04-20T15:07:20.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.22.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.22.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.22.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.22.0/manifests"},{"name":"v5.21.2","sha":"b20405e54a7b69eca58cab70a43d8cdbab511468","kind":"tag","published_at":"2023-04-09T04:52:24.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.21.2","html_url":"https://github.com/nodejs/undici/releases/tag/v5.21.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.21.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.21.2/manifests"},{"name":"v5.21.1","sha":"2d9441733c231da8b70f31c39eb08a234a42e4bf","kind":"tag","published_at":"2023-04-08T16:16:23.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.21.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.21.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.21.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.21.1/manifests"},{"name":"v5.21.0","sha":"98b63b25aab030d4aa08be818adebead9ed77788","kind":"commit","published_at":"2023-03-13T11:22:06.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.21.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.21.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.21.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.21.0/manifests"},{"name":"v5.20.0","sha":"28b9dea3fdcc453e25b3d305d5f004d85330cff1","kind":"commit","published_at":"2023-02-18T08:59:19.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.20.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.20.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.20.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.20.0/manifests"},{"name":"v5.19.1","sha":"984d53bad97c98529424a7f3bef6be1d0e76d039","kind":"commit","published_at":"2023-02-13T11:26:57.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.19.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.19.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.19.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.19.1/manifests"},{"name":"v5.19.0","sha":"f5c89e5c87c7d702996b152c4ad86302b60c4181","kind":"commit","published_at":"2023-02-13T10:23:03.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.19.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.19.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.19.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.19.0/manifests"},{"name":"v5.18.0","sha":"9dceb21156f85de1e0757785dc1da4cbe6eb9853","kind":"tag","published_at":"2023-02-06T07:07:50.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.18.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.18.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.18.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.18.0/manifests"},{"name":"v5.17.1","sha":"ce6a53bcd3ba54b761a0f4bda350b8d0e4283d66","kind":"tag","published_at":"2023-02-04T11:48:04.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.17.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.17.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.17.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.17.1/manifests"},{"name":"v5.17.0","sha":"16b7a68be363c463cba00c85a9006ee938ec1d77","kind":"tag","published_at":"2023-02-04T11:11:39.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.17.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.17.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.17.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.17.0/manifests"},{"name":"v5.16.0","sha":"81b1521c21b5bbfcca06e8aacae4f7c47ac15e7a","kind":"tag","published_at":"2023-01-23T06:23:31.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.16.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.16.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.16.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.16.0/manifests"},{"name":"v5.15.2","sha":"9457c9719029945ef9ff36b71d58557443730942","kind":"tag","published_at":"2023-01-22T09:26:53.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.15.2","html_url":"https://github.com/nodejs/undici/releases/tag/v5.15.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.15.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.15.2/manifests"},{"name":"v5.15.1","sha":"9d5f23177408dc16d3d4cbb8cebf463081c54e16","kind":"tag","published_at":"2023-01-19T11:44:57.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.15.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.15.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.15.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.15.1/manifests"},{"name":"v5.15.0","sha":"8c90b01a0ed0470d0b635b6bce9d17990f811246","kind":"commit","published_at":"2023-01-11T12:15:09.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.15.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.15.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.15.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.15.0/manifests"},{"name":"v5.14.0","sha":"9f6c59299359e7c5166c753e8d691f9dfc05b714","kind":"tag","published_at":"2022-12-08T16:42:33.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.14.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.14.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.14.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.14.0/manifests"},{"name":"v5.13.0","sha":"b3447abca2464739c00dffda96a8513687985481","kind":"commit","published_at":"2022-11-25T11:03:43.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.13.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.13.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.13.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.13.0/manifests"},{"name":"v5.12.0","sha":"1a3707887c7366403a30a45e1d8335945d0f82c1","kind":"tag","published_at":"2022-10-27T09:57:30.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.12.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.12.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.12.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.12.0/manifests"},{"name":"v5.11.0","sha":"0964a83710467b994cc108d096e97f69dd54ac90","kind":"tag","published_at":"2022-10-03T15:42:22.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.11.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.11.0/manifests"},{"name":"v5.10.0","sha":"6a87bfb38b3f4a28be81d2cc44a80083a0e4f798","kind":"commit","published_at":"2022-08-23T21:14:35.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.10.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.10.0/manifests"},{"name":"v5.9.1","sha":"5890e16ddd2703151ce0be0a468e13d685b89f60","kind":"tag","published_at":"2022-08-17T15:11:35.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.9.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.9.1/manifests"},{"name":"v5.8.2","sha":"52d1ce56f7641d0c0d8359fc76537ebe15473e7e","kind":"commit","published_at":"2022-08-09T09:34:10.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.8.2","html_url":"https://github.com/nodejs/undici/releases/tag/v5.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.8.2/manifests"},{"name":"v5.8.1","sha":"e1e1638aedcb64ecdd199708a912a35677cbb530","kind":"tag","published_at":"2022-08-03T14:03:04.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.8.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.8.1/manifests"},{"name":"v5.8.0","sha":"26f60b7b6e612bb831133d7f85914963d1955011","kind":"commit","published_at":"2022-07-18T08:30:33.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.8.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.8.0/manifests"},{"name":"v5.7.0","sha":"c485884cd76287f9412904c9e49923591988a195","kind":"commit","published_at":"2022-07-11T14:27:27.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.7.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.7.0/manifests"},{"name":"v5.6.1","sha":"c1a0490f20760ce700b28ddcddd493758d3f54a1","kind":"tag","published_at":"2022-07-08T12:50:10.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.6.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.6.1/manifests"},{"name":"v5.6.0","sha":"e53242d08f31d08d557c76b0c6fbd36106850603","kind":"commit","published_at":"2022-07-01T07:36:41.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.6.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.6.0/manifests"},{"name":"v5.5.1","sha":"19563f76ad38a8b4b2b1bfc78957c384775686e3","kind":"commit","published_at":"2022-06-13T14:25:22.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.5.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.5.1/manifests"},{"name":"v5.5.0","sha":"2717d70b308e2216a3f8cf04bbbf8566f5254a6e","kind":"commit","published_at":"2022-06-13T10:27:40.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.5.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.5.0/manifests"},{"name":"v5.4.0","sha":"47119827b1a21bacc39426f8b14e3afed07bce8e","kind":"commit","published_at":"2022-05-31T09:01:15.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.4.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.4.0/manifests"},{"name":"v5.3.0","sha":"4684a1543d87e98b441959d731a3a13d20eaa17d","kind":"commit","published_at":"2022-05-24T13:49:38.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.3.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.3.0/manifests"},{"name":"v5.2.0","sha":"15c16313a34ece99d63a92a8556af9110caf4564","kind":"commit","published_at":"2022-05-11T14:42:27.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.2.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.2.0/manifests"},{"name":"v5.1.1","sha":"c458589ceb0010c9d341d0460ca3e5cff460a44f","kind":"tag","published_at":"2022-05-02T07:04:11.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.1.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.1.1/manifests"},{"name":"v5.1.0","sha":"088518a9d2720c47d94c08c77686e89af787cf3a","kind":"commit","published_at":"2022-05-01T15:18:28.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.1.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.1.0/manifests"},{"name":"v5.0.0","sha":"08839e450aa6dd1b0e2c019d6e5869cd5b966be1","kind":"commit","published_at":"2022-03-29T10:58:01.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.0.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.0.0/manifests"},{"name":"v4.16.0","sha":"724775aff71333267a6b363940299cdf478788dc","kind":"commit","published_at":"2022-03-18T15:00:58.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.16.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.16.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.16.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.16.0/manifests"},{"name":"v4.15.1","sha":"cedc7d26f64aaa0571d1af6eaf82c519a1bcc6da","kind":"commit","published_at":"2022-03-07T14:11:35.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.15.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.15.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.15.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.15.1/manifests"},{"name":"v4.15.0","sha":"8b10a4b8769bca6a1c77275ca2a6037377f6e6c9","kind":"commit","published_at":"2022-03-04T15:26:35.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.15.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.15.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.15.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.15.0/manifests"},{"name":"v4.14.1","sha":"db745e43dd19556f82a01f7c019032d282ffa7ef","kind":"tag","published_at":"2022-02-11T16:09:14.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.14.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.14.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.14.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.14.1/manifests"},{"name":"v4.14.0","sha":"ce929b7a6d34b253f7d894271d3c7e94bf89c230","kind":"tag","published_at":"2022-02-11T13:07:41.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.14.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.14.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.14.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.14.0/manifests"},{"name":"v4.13.0","sha":"c85bb047c6ef3613d9213ac7f2ac2eefe17a1a44","kind":"commit","published_at":"2022-01-30T11:12:59.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.13.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.13.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.13.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.13.0/manifests"},{"name":"v4.12.2","sha":"badfe773ff3bcc8f26996f43e40421c26221c145","kind":"tag","published_at":"2022-01-13T14:24:14.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.12.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.12.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.12.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.12.2/manifests"},{"name":"v4.12.1","sha":"44bd5b53c48c7f9f71ded47f297229c4b5d814cc","kind":"tag","published_at":"2021-12-22T10:44:06.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.12.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.12.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.12.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.12.1/manifests"},{"name":"v4.12.0","sha":"6871a115b20478ecb18e3554a779db2904e6a105","kind":"tag","published_at":"2021-12-14T07:46:42.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.12.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.12.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.12.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.12.0/manifests"},{"name":"v4.11.3","sha":"d1bd73088785b3c118a73163c99b65059ce4458a","kind":"tag","published_at":"2021-12-08T19:29:52.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.11.3","html_url":"https://github.com/nodejs/undici/releases/tag/v4.11.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.11.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.11.3/manifests"},{"name":"v4.11.2","sha":"8c744731685149b939e6b3d7c4c21202ba0992f9","kind":"tag","published_at":"2021-12-08T16:04:02.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.11.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.11.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.11.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.11.2/manifests"},{"name":"v4.11.1","sha":"ebea0f7084bb1efdb66c46409d1bfc87054b2870","kind":"tag","published_at":"2021-12-07T13:50:22.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.11.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.11.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.11.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.11.1/manifests"},{"name":"v4.11.0","sha":"d0ea33dd302c6a189f9c12c33e9bfcfdf52d498f","kind":"tag","published_at":"2021-12-03T08:35:15.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.11.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.11.0/manifests"},{"name":"v4.10.4","sha":"ae0420219d399722649e1ec6e4612b070835781a","kind":"tag","published_at":"2021-12-01T20:13:35.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.10.4","html_url":"https://github.com/nodejs/undici/releases/tag/v4.10.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.4/manifests"},{"name":"v4.10.3","sha":"039354bb408f358b749875ed659e60634edd7d7a","kind":"tag","published_at":"2021-11-24T09:38:24.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.10.3","html_url":"https://github.com/nodejs/undici/releases/tag/v4.10.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.3/manifests"},{"name":"v4.10.2","sha":"3f6b564b7d3023d506cad75b16207006b23956a8","kind":"tag","published_at":"2021-11-19T17:46:08.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.10.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.10.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.2/manifests"},{"name":"v4.10.1","sha":"463f529f8b3a031041ad721d1a56255b2dc47065","kind":"tag","published_at":"2021-11-19T09:32:30.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.10.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.10.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.1/manifests"},{"name":"v4.10.0","sha":"e659683899999ea16dfce295bab105790255e18e","kind":"tag","published_at":"2021-11-14T15:45:46.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.10.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.0/manifests"},{"name":"v4.9.5","sha":"eb54d18a783323e124e8a4121218384dae43d26e","kind":"commit","published_at":"2021-11-03T18:54:09.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.9.5","html_url":"https://github.com/nodejs/undici/releases/tag/v4.9.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.5/manifests"},{"name":"v4.9.4","sha":"e3f6d1d0fe2c642fe531fce45817d2fab86bfbcc","kind":"tag","published_at":"2021-11-03T17:53:44.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.9.4","html_url":"https://github.com/nodejs/undici/releases/tag/v4.9.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.4/manifests"},{"name":"v4.9.3","sha":"40dbf0367d46ccce1b3aab55dd93f10b1dd8e66f","kind":"tag","published_at":"2021-11-01T04:58:30.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.9.3","html_url":"https://github.com/nodejs/undici/releases/tag/v4.9.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.3/manifests"},{"name":"v4.9.2","sha":"904e0457d3a07731d8c74ca9e7ece29233e949bf","kind":"tag","published_at":"2021-10-29T10:06:39.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.9.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.9.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.2/manifests"},{"name":"v4.9.1","sha":"729dd6704560ac6f3544751fed22ad34d75aef8c","kind":"tag","published_at":"2021-10-28T07:40:28.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.9.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.1/manifests"},{"name":"v4.9.0","sha":"597976f48c1fa9c4d4a739593ec45ac6f291ad3f","kind":"tag","published_at":"2021-10-28T07:40:13.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.9.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.0/manifests"},{"name":"v4.8.2","sha":"7b03c91cefbb46cd9172db4b2758b34155b4f764","kind":"tag","published_at":"2021-10-27T10:22:50.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.8.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.8.2/manifests"},{"name":"v4.8.1","sha":"1e2321ab494cce6a7125964153a3a83001fd77c3","kind":"commit","published_at":"2021-10-20T08:39:51.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.8.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.8.1/manifests"},{"name":"v4.8.0","sha":"a821ba768ae105dc529e5e4578b0b9b09f729eb4","kind":"commit","published_at":"2021-10-18T09:56:41.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.8.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.8.0/manifests"},{"name":"v4.7.3","sha":"e402e2e5a185049a1a072065b3ca607157a97ba0","kind":"commit","published_at":"2021-10-15T12:29:19.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.7.3","html_url":"https://github.com/nodejs/undici/releases/tag/v4.7.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.7.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.7.3/manifests"},{"name":"v4.7.2","sha":"68a17943f4d6af5f27d36ab10471f5e8860a1ede","kind":"tag","published_at":"2021-10-13T12:16:43.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.7.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.7.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.7.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.7.2/manifests"},{"name":"v4.7.1","sha":"eeeb3853f843177658e3f47dd85e694fedd19e07","kind":"tag","published_at":"2021-10-07T11:44:22.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.7.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.7.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.7.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.7.1/manifests"},{"name":"v4.7.0","sha":"42cf1417e3931591a6064fcbbe5343a43c6b2cb5","kind":"commit","published_at":"2021-09-22T09:24:52.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.7.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.7.0/manifests"},{"name":"v4.6.0","sha":"1e1a6db94e95c1c79e953e8c64c6c8f389bf323a","kind":"tag","published_at":"2021-09-15T10:22:06.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.6.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.6.0/manifests"},{"name":"v4.5.1","sha":"3100a612fc7ae758b1dbd5f8dd92e64e4667336c","kind":"tag","published_at":"2021-08-28T14:38:43.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.5.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.5.1/manifests"},{"name":"v4.5.0","sha":"88403c00140c517c8cfd3590993c02b191fe844f","kind":"tag","published_at":"2021-08-26T08:45:40.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.5.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.5.0/manifests"},{"name":"v4.4.7","sha":"f2b0b672c49fb1855e9d787a4136caba8e11c934","kind":"tag","published_at":"2021-08-24T06:54:59.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.4.7","html_url":"https://github.com/nodejs/undici/releases/tag/v4.4.7","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.7/manifests"},{"name":"v4.4.6","sha":"c4678169ba7f5eedab58ae1c3bda70267f943f79","kind":"tag","published_at":"2021-08-20T14:02:21.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.4.6","html_url":"https://github.com/nodejs/undici/releases/tag/v4.4.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.6/manifests"},{"name":"v4.4.5","sha":"6be77d614bbf8a2fa7a9d17ad2e86438157accb3","kind":"tag","published_at":"2021-08-19T13:16:20.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.4.5","html_url":"https://github.com/nodejs/undici/releases/tag/v4.4.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.5/manifests"},{"name":"v4.4.4","sha":"d0becbce9e4e3790e1a717a1367c4816f0335fe8","kind":"tag","published_at":"2021-08-17T13:40:58.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.4.4","html_url":"https://github.com/nodejs/undici/releases/tag/v4.4.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.4/manifests"},{"name":"v4.4.3","sha":"f00d444fb979949fc05316d112d6e92ef6b2aaa0","kind":"tag","published_at":"2021-08-17T11:53:42.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.4.3","html_url":"https://github.com/nodejs/undici/releases/tag/v4.4.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.3/manifests"},{"name":"v4.4.2","sha":"137da0e45a13b9109ab640937f9084e67e96f080","kind":"tag","published_at":"2021-08-13T17:13:03.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.4.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.4.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.2/manifests"},{"name":"v4.4.1","sha":"913f79c7b816afd6466dbe1927ea909f52ccfac3","kind":"tag","published_at":"2021-08-12T11:54:35.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.4.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.1/manifests"},{"name":"v4.4.0","sha":"bac066d80d96890a608b719c8823a8035aeab440","kind":"tag","published_at":"2021-08-12T11:48:38.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.4.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.0/manifests"},{"name":"v4.3.1","sha":"64fa1b89a3d54d9c7ea0dab2f7fb38ddcea61ee6","kind":"tag","published_at":"2021-07-31T16:24:15.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.3.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.3.1/manifests"},{"name":"v4.3.0","sha":"9f96dc6f8be6179314f4dae8c90b5b25a85b3165","kind":"commit","published_at":"2021-07-31T16:23:16.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.3.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.3.0/manifests"},{"name":"v4.2.2","sha":"02a9d13a902859f537b980fbc0ccd6a2b088d5f1","kind":"tag","published_at":"2021-07-22T18:09:32.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.2.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.2.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.2.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.2.2/manifests"},{"name":"v4.2.1","sha":"aebbb5df86d5584b03102cb9198aad8abae421f1","kind":"tag","published_at":"2021-07-19T13:15:13.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.2.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.2.1/manifests"},{"name":"v4.2.0","sha":"c7be4eabcc9274ed7ed375fa0de520db2cb2c1d5","kind":"tag","published_at":"2021-07-19T13:12:00.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.2.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.2.0/manifests"},{"name":"v4.1.1","sha":"494201af4d95a1d9dbf8727bf4847b858e9f4707","kind":"tag","published_at":"2021-07-12T07:51:45.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.1.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.1.1/manifests"},{"name":"v4.1.0","sha":"e705509ab22ab80aadf0fc1a394afff7dc014fdf","kind":"tag","published_at":"2021-06-29T17:58:29.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.1.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.1.0/manifests"},{"name":"v4.0.0","sha":"06ccb4f78b070e7471b97cac4c6a9e05a0825dbd","kind":"tag","published_at":"2021-06-16T08:26:41.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0/manifests"},{"name":"v4.0.0-rc.8","sha":"1a68acc427d0638e361cad71b6113ccbbea37cab","kind":"tag","published_at":"2021-06-16T07:14:57.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-rc.8","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-rc.8","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.8/manifests"},{"name":"v4.0.0-rc.7","sha":"abfc22b016b7214b03d0d8d6c37064f5cfa6a4b3","kind":"tag","published_at":"2021-06-08T07:49:53.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-rc.7","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-rc.7","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.7/manifests"},{"name":"v4.0.0-rc.6","sha":"8239409499c3a3727eda8c92719d7e4663ff0da1","kind":"tag","published_at":"2021-06-08T07:46:47.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-rc.6","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-rc.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.6/manifests"},{"name":"v4.0.0-rc.5","sha":"622c41b1996ac9101868d55bfc2b99703ed02d92","kind":"tag","published_at":"2021-05-31T11:16:46.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-rc.5","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-rc.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.5/manifests"},{"name":"v4.0.0-rc.4","sha":"7d563c0297e23a1275fa263e47aa0d3ac6fbb23e","kind":"tag","published_at":"2021-05-12T07:21:02.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-rc.4","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-rc.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.4/manifests"},{"name":"v4.0.0-rc.3","sha":"677d6f9a5eb64ec0e3c346ebdf98b8b79d2b4913","kind":"tag","published_at":"2021-05-05T09:03:12.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-rc.3","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-rc.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.3/manifests"},{"name":"v4.0.0-rc.2","sha":"9b05bc127d9beeab05f8a888384208a8c5c598ee","kind":"commit","published_at":"2021-05-03T14:39:18.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-rc.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-rc.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.2/manifests"},{"name":"v4.0.0-rc.1","sha":"31e983bf14f97db21d24f3d1a12b84a765c93bda","kind":"tag","published_at":"2021-04-28T16:29:16.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-rc.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-rc.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.1/manifests"},{"name":"v4.0.0-alpha.5","sha":"7bafbd2442df1dd4140c110b202d55ec1c8e2678","kind":"tag","published_at":"2021-04-27T16:41:12.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-alpha.5","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-alpha.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.5/manifests"},{"name":"v3.3.6","sha":"f744aed29a36f68d295207f5cb509c979029e588","kind":"commit","published_at":"2021-04-24T14:43:06.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.3.6","html_url":"https://github.com/nodejs/undici/releases/tag/v3.3.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.6/manifests"},{"name":"v3.3.5","sha":"decdfc460b8317e34ffe2499e2ee81731eeb47c8","kind":"commit","published_at":"2021-04-21T08:18:24.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.3.5","html_url":"https://github.com/nodejs/undici/releases/tag/v3.3.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.5/manifests"},{"name":"v4.0.0-alpha.4","sha":"5d959626a467800729957a4957d9c918e01e2ed8","kind":"tag","published_at":"2021-04-16T16:22:11.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-alpha.4","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-alpha.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.4/manifests"},{"name":"v4.0.0-alpha.3","sha":"f354d36525f0b610b2f15f3ff15976c5f8ea24d2","kind":"tag","published_at":"2021-04-13T10:20:22.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-alpha.3","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-alpha.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.3/manifests"},{"name":"v4.0.0-alpha.2","sha":"18fefd58e98a829bf1122bb1c049018bedd930a9","kind":"tag","published_at":"2021-04-12T15:18:36.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-alpha.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-alpha.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.2/manifests"},{"name":"v4.0.0-alpha.1","sha":"a1727e0f939995e0adcbbde7cb5b6b024f59c6ea","kind":"tag","published_at":"2021-04-12T13:22:22.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-alpha.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-alpha.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.1/manifests"},{"name":"v4.0.0-alpha.0","sha":"022784138b4baf5e663ff92192e270dadc273f55","kind":"tag","published_at":"2021-04-11T19:35:14.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-alpha.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-alpha.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.0/manifests"},{"name":"v3.3.4","sha":"39eba7190985e0ee41124bb4a60ee8fd12710cb3","kind":"tag","published_at":"2021-04-08T12:09:41.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.3.4","html_url":"https://github.com/nodejs/undici/releases/tag/v3.3.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.4/manifests"},{"name":"v3.3.3","sha":"c99db2d68cb6706210012868db74e02e549a3d37","kind":"tag","published_at":"2021-02-13T16:03:01.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.3.3","html_url":"https://github.com/nodejs/undici/releases/tag/v3.3.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.3/manifests"},{"name":"v3.3.2","sha":"d523180d38fe95448ec9306e1ea9c79c6bbaf6e2","kind":"tag","published_at":"2021-02-13T15:58:35.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.3.2","html_url":"https://github.com/nodejs/undici/releases/tag/v3.3.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.2/manifests"},{"name":"v3.3.1","sha":"6680bd01ecda317d936d5a04b0581c30faaf90d2","kind":"tag","published_at":"2021-02-08T07:56:25.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.3.1","html_url":"https://github.com/nodejs/undici/releases/tag/v3.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.1/manifests"},{"name":"v3.3.0","sha":"6223377672415946ca11a7f559d02faf12284393","kind":"tag","published_at":"2021-02-03T09:33:50.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.3.0","html_url":"https://github.com/nodejs/undici/releases/tag/v3.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.0/manifests"},{"name":"v3.2.0","sha":"de381e13e79a059c4f79952adea35bfda9333f0f","kind":"tag","published_at":"2021-01-13T12:40:13.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.2.0","html_url":"https://github.com/nodejs/undici/releases/tag/v3.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.2.0/manifests"},{"name":"v3.1.0","sha":"b1a4a433b76aef3e9bd12099cf1e88c3df32891e","kind":"commit","published_at":"2021-01-12T09:51:32.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.1.0","html_url":"https://github.com/nodejs/undici/releases/tag/v3.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.1.0/manifests"},{"name":"v3.0.0","sha":"0e289aa8d4b68544f936a92594eb3d5dae750171","kind":"tag","published_at":"2020-12-17T22:39:20.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.0.0","html_url":"https://github.com/nodejs/undici/releases/tag/v3.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.0.0/manifests"},{"name":"v2.2.1","sha":"b253a3af007bc9d53ced69f81534154812804228","kind":"tag","published_at":"2020-12-08T06:22:44.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.2.1","html_url":"https://github.com/nodejs/undici/releases/tag/v2.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.2.1/manifests"},{"name":"v2.2.0","sha":"2e214a29e5625c206454c2bdae81ff7b30cedd7d","kind":"tag","published_at":"2020-11-12T11:58:56.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.2.0","html_url":"https://github.com/nodejs/undici/releases/tag/v2.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.2.0/manifests"},{"name":"v2.1.1","sha":"6b44f36d225b545ad327e0631c179cda8f4fa27f","kind":"tag","published_at":"2020-11-02T19:40:05.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.1.1","html_url":"https://github.com/nodejs/undici/releases/tag/v2.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.1.1/manifests"},{"name":"v2.1.0","sha":"472dbde2394efb964b3b866120fe59e242cfc677","kind":"commit","published_at":"2020-10-23T23:50:00.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.1.0","html_url":"https://github.com/nodejs/undici/releases/tag/v2.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.1.0/manifests"},{"name":"v2.0.7","sha":"e94a35581c14364f7d3e9f355eb21895287365bc","kind":"tag","published_at":"2020-10-09T08:49:40.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.0.7","html_url":"https://github.com/nodejs/undici/releases/tag/v2.0.7","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.7/manifests"},{"name":"v2.0.6","sha":"9e73b20177752b1281f93f30030c7425f2f46945","kind":"tag","published_at":"2020-10-07T19:55:14.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.0.6","html_url":"https://github.com/nodejs/undici/releases/tag/v2.0.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.6/manifests"},{"name":"v2.0.5","sha":"f9f038750629a1f29d2500f6f90a064ceec3ef67","kind":"tag","published_at":"2020-09-24T21:28:26.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.0.5","html_url":"https://github.com/nodejs/undici/releases/tag/v2.0.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.5/manifests"},{"name":"v2.0.4","sha":"f87fa3251808d0f5ce8cd2c6f65444cfbd3425a5","kind":"tag","published_at":"2020-09-23T21:41:57.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.0.4","html_url":"https://github.com/nodejs/undici/releases/tag/v2.0.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.4/manifests"},{"name":"v2.0.3","sha":"4f68bf8678c2381612bbf2f6f41a93d62314274d","kind":"tag","published_at":"2020-09-23T21:37:51.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.0.3","html_url":"https://github.com/nodejs/undici/releases/tag/v2.0.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.3/manifests"},{"name":"v2.0.2","sha":"3ce6832f60951c0b69e1f0624f07e16144bcfcb9","kind":"tag","published_at":"2020-09-18T23:49:47.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.0.2","html_url":"https://github.com/nodejs/undici/releases/tag/v2.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.2/manifests"},{"name":"v2.0.1","sha":"71e482f233de06427e435411ea0e18ebf4dd3e5b","kind":"tag","published_at":"2020-09-12T11:28:06.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.0.1","html_url":"https://github.com/nodejs/undici/releases/tag/v2.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.1/manifests"},{"name":"v2.0.0","sha":"6e91fbf0a1475d2385abcf20b58e1d21f527c0a3","kind":"tag","published_at":"2020-09-05T15:27:07.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.0.0","html_url":"https://github.com/nodejs/undici/releases/tag/v2.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.0/manifests"},{"name":"v1.3.1","sha":"45ec01b23aaa74a653493d8e27d43fc8d9542bc8","kind":"tag","published_at":"2020-08-12T16:27:40.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.3.1","html_url":"https://github.com/nodejs/undici/releases/tag/v1.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.3.1/manifests"},{"name":"v1.3.0","sha":"c707c35a96adf1ec027d6cc8752eb5a5634a4374","kind":"tag","published_at":"2020-08-10T12:23:52.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.3.0","html_url":"https://github.com/nodejs/undici/releases/tag/v1.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.3.0/manifests"},{"name":"v1.2.6","sha":"d8dc40f77400f998817efb4654bc411d0779384c","kind":"commit","published_at":"2020-07-29T18:50:12.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.2.6","html_url":"https://github.com/nodejs/undici/releases/tag/v1.2.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.6/manifests"},{"name":"v1.2.5","sha":"966f3e172a4b8390281782a64de1f69ad94e4b6e","kind":"tag","published_at":"2020-07-29T09:37:41.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.2.5","html_url":"https://github.com/nodejs/undici/releases/tag/v1.2.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.5/manifests"},{"name":"v1.2.4","sha":"ea1c9e92ec4efd1ffdd8cfff069e1f7101b5ba97","kind":"tag","published_at":"2020-07-29T08:50:59.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.2.4","html_url":"https://github.com/nodejs/undici/releases/tag/v1.2.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.4/manifests"},{"name":"v1.2.2","sha":"7e785f8b4d8c157dcc9b250e564ddae23607a2d3","kind":"tag","published_at":"2020-07-16T17:40:52.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.2.2","html_url":"https://github.com/nodejs/undici/releases/tag/v1.2.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.2/manifests"},{"name":"v1.2.1","sha":"d782e63495d8fe5bb4f3b49a1a0650b103c43df9","kind":"tag","published_at":"2020-07-14T13:28:43.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.2.1","html_url":"https://github.com/nodejs/undici/releases/tag/v1.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.1/manifests"},{"name":"v1.2.0","sha":"b7a350589ebb84e1a1e5d95210fa56c94864a52f","kind":"tag","published_at":"2020-07-14T12:30:00.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.2.0","html_url":"https://github.com/nodejs/undici/releases/tag/v1.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.0/manifests"},{"name":"v1.1.0","sha":"75de95ab227e0fc96c36b91e3112c7960d5c292e","kind":"tag","published_at":"2020-07-06T07:08:12.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.1.0","html_url":"https://github.com/nodejs/undici/releases/tag/v1.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.1.0/manifests"},{"name":"elete","sha":"cf8652fd3ba29f8d89b22f630b016a596ae13eca","kind":"tag","published_at":"2020-07-05T16:54:25.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/elete","html_url":"https://github.com/nodejs/undici/releases/tag/elete","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/elete","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/elete/manifests"},{"name":"delete","sha":"cf8652fd3ba29f8d89b22f630b016a596ae13eca","kind":"tag","published_at":"2020-07-05T16:54:25.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/delete","html_url":"https://github.com/nodejs/undici/releases/tag/delete","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/delete","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/delete/manifests"},{"name":"v1.0.3","sha":"df7bade8b8e06ef13936520d5126cbf93889a356","kind":"tag","published_at":"2020-06-15T12:51:08.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.0.3","html_url":"https://github.com/nodejs/undici/releases/tag/v1.0.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.0.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.0.3/manifests"},{"name":"v1.0.2","sha":"625881f4227b32d10a6d206e466f929b001923a0","kind":"tag","published_at":"2020-06-13T17:10:57.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.0.2","html_url":"https://github.com/nodejs/undici/releases/tag/v1.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.0.2/manifests"},{"name":"v1.0.1","sha":"55dc0aed7e90f1b9b97f42ad417fdf46ee1d99db","kind":"tag","published_at":"2020-06-06T20:40:48.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.0.1","html_url":"https://github.com/nodejs/undici/releases/tag/v1.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.0.1/manifests"},{"name":"v1.0.0","sha":"359dea825c73cf21d6ae16bb2075842b9f48bcd3","kind":"tag","published_at":"2020-06-04T16:23:34.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.0.0","html_url":"https://github.com/nodejs/undici/releases/tag/v1.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.0.0/manifests"}]},"repo_metadata_updated_at":"2024-10-29T19:51:19.853Z","dependent_packages_count":1956,"downloads":76040467,"downloads_period":"last-month","dependent_repos_count":98048,"rankings":{"downloads":0.04717544226634877,"dependent_repos_count":0.1008125237520001,"dependent_packages_count":0.0399197880582336,"stargazers_count":1.2981597470542043,"forks_count":1.7358262848531512,"docker_downloads_count":0.04588859038792834,"average":0.5446303960619777},"purl":"pkg:npm/undici","advisories":[{"uuid":"GSA_kwCzR0hTQS0zNzg3LTZwcnYtaDl3M84AA5Vg","url":"https://github.com/advisories/GHSA-3787-6prv-h9w3","title":"Undici proxy-authorization header not cleared on cross-origin redirect in fetch","description":"### Impact\n\nUndici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authorization` headers. \n\n### Patches\n\nThis is patched in v5.28.3 and v6.6.1\n\n### Workarounds\n\nThere are no known workarounds.\n\n### References\n\n- https://fetch.spec.whatwg.org/#authentication-entries\n- https://github.com/nodejs/undici/security/advisories/GHSA-wqq4-5wpv-mx2g","origin":"UNSPECIFIED","severity":"LOW","published_at":"2024-02-16T16:02:52.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-3787-6prv-h9w3","https://github.com/nodejs/undici/commit/b9da3e40f1f096a06b4caedbb27c2568730434ef","https://github.com/nodejs/undici/commit/d3aa574b1259c1d8d329a0f0f495ee82882b1458","https://github.com/nodejs/undici/releases/tag/v5.28.3","https://github.com/nodejs/undici/releases/tag/v6.6.1","https://nvd.nist.gov/vuln/detail/CVE-2024-24758","https://security.netapp.com/advisory/ntap-20240419-0007","http://www.openwall.com/lists/oss-security/2024/03/11/1","https://github.com/advisories/GHSA-3787-6prv-h9w3"],"source_kind":"github","identifiers":["GHSA-3787-6prv-h9w3","CVE-2024-24758"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"6.6.1","vulnerable_version_range":"\u003e= 6.0.0, \u003c= 6.6.0"},{"first_patched_version":"5.28.3","vulnerable_version_range":"\u003c= 5.28.2"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2024-02-16T17:04:40.355Z","updated_at":"2025-06-02T01:09:42.713Z","epss_percentage":0.00042,"epss_percentile":0.12319},{"uuid":"GSA_kwCzR0hTQS01cjlnLXFoNm0tanhmZs4AAxq9","url":"https://github.com/advisories/GHSA-5r9g-qh6m-jxff","title":"CRLF Injection in Nodejs ‘undici’ via host","description":"### Impact\n\nundici library does not protect `host` HTTP header from CRLF injection vulnerabilities.\n\n### Patches\n\nThis issue was patched in Undici v5.19.1.\n\n### Workarounds\n\nSanitize the `headers.host` string before passing to undici.\n\n### References\n\nReported at https://hackerone.com/reports/1820955.\n\n### Credits\n\nThank you to Zhipeng Zhang ([@timon8](https://hackerone.com/timon8)) for reporting this vulnerability. ","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-02-16T20:46:30.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-5r9g-qh6m-jxff","https://nvd.nist.gov/vuln/detail/CVE-2023-23936","https://github.com/nodejs/undici/commit/a2eff05401358f6595138df963837c24348f2034","https://hackerone.com/reports/1820955","https://github.com/nodejs/undici/releases/tag/v5.19.1","https://github.com/advisories/GHSA-5r9g-qh6m-jxff"],"source_kind":"github","identifiers":["GHSA-5r9g-qh6m-jxff","CVE-2023-23936"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"5.19.1","vulnerable_version_range":"\u003e= 2.0.0, \u003c 5.19.1"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2023-02-16T21:03:05.031Z","updated_at":"2025-06-02T01:11:39.851Z","epss_percentage":0.0041,"epss_percentile":0.60516},{"uuid":"GSA_kwCzR0hTQS1yNmNoLW1xZjktcWM5d84AAxq-","url":"https://github.com/advisories/GHSA-r6ch-mqf9-qc9w","title":"Regular Expression Denial of Service in Headers","description":"### Impact\nThe `Headers.set()` and `Headers.append()` methods are vulnerable to Regular Expression Denial of Service (ReDoS) attacks when untrusted values are passed into the functions. This is due to the inefficient regular expression used to normalize the values in the `headerValueNormalize()` utility function.\n\n### Patches\n\nThis vulnerability was patched in v5.19.1.\n\n### Workarounds\nThere is no workaround. Please update to an unaffected version.\n\n### References\n\n* https://hackerone.com/bugs?report_id=1784449\n\n### Credits\n\nCarter Snook reported this vulnerability.\n","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2023-02-16T20:46:10.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-r6ch-mqf9-qc9w","https://nvd.nist.gov/vuln/detail/CVE-2023-24807","https://github.com/nodejs/undici/commit/f2324e549943f0b0937b09fb1c0c16cc7c93abdf","https://github.com/nodejs/undici/releases/tag/v5.19.1","https://hackerone.com/bugs?report_id=1784449","https://github.com/advisories/GHSA-r6ch-mqf9-qc9w"],"source_kind":"github","identifiers":["GHSA-r6ch-mqf9-qc9w","CVE-2023-24807"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"5.19.1","vulnerable_version_range":"\u003c 5.19.1"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2023-02-16T21:03:05.020Z","updated_at":"2023-02-16T20:46:56.000Z","epss_percentage":0.00248,"epss_percentile":0.48017},{"uuid":"GSA_kwCzR0hTQS1xNzY4LXg5bTYtbTlxcM4AAtkI","url":"https://github.com/advisories/GHSA-q768-x9m6-m9qp","title":"undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect","description":"### Impact\n\nAuthorization headers are already cleared on cross-origin redirect in\nhttps://github.com/nodejs/undici/blob/main/lib/handler/redirect.js#L189, based on https://github.com/nodejs/undici/issues/872.\n\nHowever, cookie headers which are sensitive headers and are official headers found in the spec, remain uncleared. There also has been active discussion of implementing a cookie store https://github.com/nodejs/undici/pull/1441, which suggests that there are active users using cookie headers in undici.\nAs such this may lead to accidental leakage of cookie to a 3rd-party site or a malicious attacker who can control the redirection target (ie. an open redirector) to leak the cookie to the 3rd party site.\n\n### Patches\n\nThis was patched in v5.8.0.\n\n### Workarounds\n\nBy default, this vulnerability is not exploitable.\nDo not enable redirections, i.e. `maxRedirections: 0` (the default). \n\n### References\n\nhttps://hackerone.com/reports/1635514\nhttps://curl.se/docs/CVE-2018-1000007.html\nhttps://curl.se/docs/CVE-2022-27776.html\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [undici repository](https://github.com/nodejs/undici/issues)\n* To make a report, follow the [SECURITY](https://github.com/nodejs/node/blob/HEAD/SECURITY.md) document\n","origin":"UNSPECIFIED","severity":"LOW","published_at":"2022-07-21T20:31:05.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-q768-x9m6-m9qp","https://nvd.nist.gov/vuln/detail/CVE-2022-31151","https://github.com/nodejs/undici/issues/872","https://github.com/nodejs/undici/pull/1441","https://github.com/nodejs/undici/commit/0a5bee9465e627be36bac88edf7d9bbc9626126d","https://github.com/nodejs/undici/blob/main/lib/handler/redirect.js#L189","https://github.com/nodejs/undici/releases/tag/v5.8.0","https://hackerone.com/reports/1635514","https://security.netapp.com/advisory/ntap-20220909-0006/","https://github.com/advisories/GHSA-q768-x9m6-m9qp"],"source_kind":"github","identifiers":["GHSA-q768-x9m6-m9qp","CVE-2022-31151"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"5.8.0","vulnerable_version_range":"\u003c 5.8.0"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2022-12-21T16:12:10.113Z","updated_at":"2025-06-02T01:12:09.616Z","epss_percentage":0.00122,"epss_percentile":0.32534},{"uuid":"GSA_kwCzR0hTQS1jNzZoLTJjY3AtNDk3Nc4ABDo4","url":"https://github.com/advisories/GHSA-c76h-2ccp-4975","title":"Use of Insufficiently Random Values in undici","description":"### Impact\n\n[Undici `fetch()` uses Math.random()](https://github.com/nodejs/undici/blob/8b06b8250907d92fead664b3368f1d2aa27c1f35/lib/web/fetch/body.js#L113) to choose the boundary for a multipart/form-data request. It is known that the output of Math.random() can be predicted if several of its generated values are known.\n\nIf there is a mechanism in an app that sends multipart requests to an attacker-controlled website, they can use this to leak the necessary values. Therefore, An attacker can tamper with the requests going to the backend APIs if certain conditions are met.\n\n### Patches\n\nThis is fixed in 5.28.5; 6.21.1; 7.2.3.\n\n### Workarounds\n\nDo not issue multipart requests to attacker controlled servers.\n\n### References\n\n* https://hackerone.com/reports/2913312\n* https://blog.securityevaluators.com/hacking-the-javascript-lottery-80cc437e3b7f\n","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-01-21T21:10:47.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-c76h-2ccp-4975","https://nvd.nist.gov/vuln/detail/CVE-2025-22150","https://github.com/nodejs/undici/commit/711e20772764c29f6622ddc937c63b6eefdf07d0","https://github.com/nodejs/undici/commit/c2d78cd19fe4f4c621424491e26ce299e65e934a","https://github.com/nodejs/undici/commit/c3acc6050b781b827d80c86cbbab34f14458d385","https://hackerone.com/reports/2913312","https://blog.securityevaluators.com/hacking-the-javascript-lottery-80cc437e3b7f","https://github.com/nodejs/undici/blob/8b06b8250907d92fead664b3368f1d2aa27c1f35/lib/web/fetch/body.js#L113","https://github.com/advisories/GHSA-c76h-2ccp-4975"],"source_kind":"github","identifiers":["GHSA-c76h-2ccp-4975","CVE-2025-22150"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"7.2.3","vulnerable_version_range":"\u003e= 7.0.0, \u003c 7.2.3"},{"first_patched_version":"6.21.1","vulnerable_version_range":"\u003e= 6.0.0, \u003c 6.21.1"},{"first_patched_version":"5.28.5","vulnerable_version_range":"\u003e= 4.5.0, \u003c 5.28.5"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2025-01-21T22:08:48.606Z","updated_at":"2025-06-02T01:08:19.587Z","epss_percentage":0.00037,"epss_percentile":0.10101},{"uuid":"GSA_kwCzR0hTQS13cXE0LTV3cHYtbXgyZ84AA2eY","url":"https://github.com/advisories/GHSA-wqq4-5wpv-mx2g","title":"Undici's cookie header not cleared on cross-origin redirect in fetch","description":"### Impact\n\nUndici clears Authorization headers on cross-origin redirects, but does not clear `Cookie` headers. By design, `cookie` headers are [forbidden request headers](https://fetch.spec.whatwg.org/#forbidden-request-header), disallowing them to be set in `RequestInit.headers` in browser environments. Since Undici handles headers more liberally than the specification, there was a disconnect from the assumptions the spec made, and Undici's implementation of fetch.\n\nAs such this may lead to accidental leakage of cookie to a 3rd-party site or a malicious attacker who can control the redirection target (ie. an open redirector) to leak the cookie to the 3rd party site.\n\n### Patches\n\nThis was patched in [e041de359221ebeae04c469e8aff4145764e6d76](https://github.com/nodejs/undici/commit/e041de359221ebeae04c469e8aff4145764e6d76), which is included in version 5.26.2.\n","origin":"UNSPECIFIED","severity":"LOW","published_at":"2023-10-16T14:05:37.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-q768-x9m6-m9qp","https://github.com/nodejs/undici/security/advisories/GHSA-wqq4-5wpv-mx2g","https://nvd.nist.gov/vuln/detail/CVE-2023-45143","https://github.com/nodejs/undici/commit/e041de359221ebeae04c469e8aff4145764e6d76","https://hackerone.com/reports/2166948","https://github.com/nodejs/undici/releases/tag/v5.26.2","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y","https://github.com/advisories/GHSA-wqq4-5wpv-mx2g"],"source_kind":"github","identifiers":["GHSA-wqq4-5wpv-mx2g","CVE-2023-45143"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"5.26.2","vulnerable_version_range":"\u003c 5.26.2"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2023-10-16T15:06:30.108Z","updated_at":"2025-06-02T01:10:30.589Z","epss_percentage":0.00181,"epss_percentile":0.40593},{"uuid":"GSA_kwCzR0hTQS0zZzkyLXc4YzUtNzNwcc4AA9rQ","url":"https://github.com/advisories/GHSA-3g92-w8c5-73pq","title":"Undici vulnerable to data leak when using response.arrayBuffer()","description":"### Impact\n\nDepending on network and process conditions of a `fetch()` request, `response.arrayBuffer()` might include portion of memory from the Node.js process.\n\n### Patches\n\nThis has been patched in v6.19.2.\n\n### Workarounds\n\nThere are no known workaround.\n\n### References\n\nhttps://github.com/nodejs/undici/issues/3337\nhttps://github.com/nodejs/undici/issues/3328\nhttps://github.com/nodejs/undici/pull/3338\nhttps://github.com/nodejs/undici/commit/f979ec3204ca489abf30e7d20e9fee9ea7711d36","origin":"UNSPECIFIED","severity":"LOW","published_at":"2024-07-09T13:32:30.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":2.0,"cvss_vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/nodejs/undici/security/advisories/GHSA-3g92-w8c5-73pq","https://nvd.nist.gov/vuln/detail/CVE-2024-38372","https://github.com/nodejs/undici/issues/3328","https://github.com/nodejs/undici/issues/3337","https://github.com/nodejs/undici/pull/3338","https://github.com/nodejs/undici/commit/f979ec3204ca489abf30e7d20e9fee9ea7711d36","https://github.com/advisories/GHSA-3g92-w8c5-73pq"],"source_kind":"github","identifiers":["GHSA-3g92-w8c5-73pq","CVE-2024-38372"],"repository_url":"https://github.com/nodejs/undici","blast_radius":9.982877478560944,"packages":[{"versions":[{"first_patched_version":"6.19.2","vulnerable_version_range":"\u003e= 6.14.0, \u003c 6.19.2"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2024-07-09T14:05:41.758Z","updated_at":"2025-06-02T01:08:58.261Z","epss_percentage":0.0025,"epss_percentile":0.48568},{"uuid":"GSA_kwCzR0hTQS05ZjI0LWpxaG0tamZjd84AA5Vf","url":"https://github.com/advisories/GHSA-9f24-jqhm-jfcw","title":"fetch(url) leads to a memory leak in undici","description":"### Impact\n\nCalling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. \n\n### Patches\n\nPatched in v6.6.1\n\n### Workarounds\n\nMake sure to always consume the incoming body.\n","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2024-02-16T15:59:38.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-9f24-jqhm-jfcw","https://github.com/nodejs/undici/commit/87a48113f1f68f60aa09abb07276d7c35467c663","https://github.com/nodejs/undici/releases/tag/v6.6.1","https://nvd.nist.gov/vuln/detail/CVE-2024-24750","https://security.netapp.com/advisory/ntap-20240419-0006","https://github.com/advisories/GHSA-9f24-jqhm-jfcw"],"source_kind":"github","identifiers":["GHSA-9f24-jqhm-jfcw","CVE-2024-24750"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"6.6.1","vulnerable_version_range":"\u003e= 6.0.0, \u003c= 6.6.0"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2024-02-16T16:04:42.077Z","updated_at":"2024-12-17T20:04:25.000Z","epss_percentage":0.00465,"epss_percentile":0.63309},{"uuid":"GSA_kwCzR0hTQS1jeHJoLWo0anItcXdnM84ABH4x","url":"https://github.com/advisories/GHSA-cxrh-j4jr-qwg3","title":"undici Denial of Service attack via bad certificate data","description":"### Impact\n\nApplications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak. \n\n### Patches\n\nThis has been patched in https://github.com/nodejs/undici/pull/4088.\n\n### Workarounds\n\nIf a webhook fails, avoid keep calling it repeatedly.\n\n### References\n\nReported as: https://github.com/nodejs/undici/issues/3895","origin":"UNSPECIFIED","severity":"LOW","published_at":"2025-05-15T14:15:06.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-cxrh-j4jr-qwg3","https://github.com/nodejs/undici/issues/3895","https://github.com/nodejs/undici/pull/4088","https://nvd.nist.gov/vuln/detail/CVE-2025-47279","https://github.com/advisories/GHSA-cxrh-j4jr-qwg3"],"source_kind":"github","identifiers":["GHSA-cxrh-j4jr-qwg3","CVE-2025-47279"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"7.5.0","vulnerable_version_range":"\u003e= 7.0.0, \u003c 7.5.0"},{"first_patched_version":"6.21.2","vulnerable_version_range":"\u003e= 6.0.0, \u003c 6.21.2"},{"first_patched_version":"5.29.0","vulnerable_version_range":"\u003c 5.29.0"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2025-05-15T15:09:47.466Z","updated_at":"2025-05-16T02:07:01.000Z","epss_percentage":0.00032,"epss_percentile":0.07905},{"uuid":"GSA_kwCzR0hTQS1tNHY4LXdxdnItcDlmN84AA6o1","url":"https://github.com/advisories/GHSA-m4v8-wqvr-p9f7","title":"Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline","description":"### Impact\n\nUndici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`.\n\n### Patches\n\nThis has been patched in https://github.com/nodejs/undici/commit/6805746680d27a5369d7fb67bc05f95a28247d75.\nFixes has been released in v5.28.4 and v6.11.1.\n\n### Workarounds\n\nuse `fetch()` or disable `maxRedirections`.\n\n### References\n\nLinzi Shang reported this.\n\n* https://hackerone.com/reports/2408074\n* https://github.com/nodejs/undici/security/advisories/GHSA-3787-6prv-h9w3","origin":"UNSPECIFIED","severity":"LOW","published_at":"2024-04-04T14:20:39.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-m4v8-wqvr-p9f7","https://github.com/nodejs/undici/commit/64e3402da4e032e68de46acb52800c9a06aaea3f","https://github.com/nodejs/undici/commit/6805746680d27a5369d7fb67bc05f95a28247d75","https://hackerone.com/reports/2408074","https://nvd.nist.gov/vuln/detail/CVE-2024-30260","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HQVHWAS6WDXXIU7F72XI55VZ2LTZUB33","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NC3V3HFZ5MOJRZDY5ZELL6REIRSPFROJ","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P6Q4RGETHVYVHDIQGTJGU5AV6NJEI67E","https://github.com/advisories/GHSA-m4v8-wqvr-p9f7"],"source_kind":"github","identifiers":["GHSA-m4v8-wqvr-p9f7","CVE-2024-30260"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"6.11.1","vulnerable_version_range":"\u003e= 6.0.0, \u003c 6.11.1"},{"first_patched_version":"5.28.4","vulnerable_version_range":"\u003c 5.28.4"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2024-04-04T15:04:57.956Z","updated_at":"2025-06-02T01:09:31.180Z","epss_percentage":0.00131,"epss_percentile":0.34016},{"uuid":"GSA_kwCzR0hTQS05cXhyLXFqNTQtaDY3Ms4AA6o2","url":"https://github.com/advisories/GHSA-9qxr-qj54-h672","title":"Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect","description":"### Impact\n\nIf an attacker can alter the `integrity` option passed to `fetch()`, they can let `fetch()` accept requests as valid even if they have been tampered.\n\n### Patches\n\nFixed in https://github.com/nodejs/undici/commit/d542b8cd39ec1ba303f038ea26098c3f355974f3.\nFixes has been released in v5.28.4 and v6.11.1.\n\n\n### Workarounds\n\nEnsure that `integrity` cannot be tampered with.\n\n### References\n\nhttps://hackerone.com/reports/2377760\n","origin":"UNSPECIFIED","severity":"LOW","published_at":"2024-04-04T14:20:54.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-9qxr-qj54-h672","https://github.com/nodejs/undici/commit/2b39440bd9ded841c93dd72138f3b1763ae26055","https://github.com/nodejs/undici/commit/d542b8cd39ec1ba303f038ea26098c3f355974f3","https://hackerone.com/reports/2377760","https://nvd.nist.gov/vuln/detail/CVE-2024-30261","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HQVHWAS6WDXXIU7F72XI55VZ2LTZUB33","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P6Q4RGETHVYVHDIQGTJGU5AV6NJEI67E","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NC3V3HFZ5MOJRZDY5ZELL6REIRSPFROJ","https://github.com/advisories/GHSA-9qxr-qj54-h672"],"source_kind":"github","identifiers":["GHSA-9qxr-qj54-h672","CVE-2024-30261"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"6.11.1","vulnerable_version_range":"\u003e= 6.0.0, \u003c 6.11.1"},{"first_patched_version":"5.28.4","vulnerable_version_range":"\u003c 5.28.4"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2024-04-04T15:04:57.928Z","updated_at":"2025-06-02T01:09:31.152Z","epss_percentage":0.00353,"epss_percentile":0.57048},{"uuid":"GSA_kwCzR0hTQS1mNzcyLTY2ZzgtcTVoM84AAuFo","url":"https://github.com/advisories/GHSA-f772-66g8-q5h3","title":"Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type","description":"### Impact\n\n`=\u003c undici@5.8.0` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header.\n\nExample:\n\n```\nimport { request } from 'undici'\n\nconst unsanitizedContentTypeInput =  'application/json\\r\\n\\r\\nGET /foo2 HTTP/1.1'\n\nawait request('http://localhost:3000, {\n    method: 'GET',\n    headers: {\n      'content-type': unsanitizedContentTypeInput\n    },\n})\n```\n\nThe above snippet will perform two requests in a single `request` API call:\n\n1) `http://localhost:3000/`\n2) `http://localhost:3000/foo2`\n\n### Patches\n\nThis issue was patched in Undici v5.8.1\n\n### Workarounds\n\nSanitize input when sending content-type headers using user input.\n\n## For more information\nIf you have any questions or comments about this advisory:\n\n- Open an issue in [undici repository](https://github.com/nodejs/undici/issues)\n- To make a report, follow the [SECURITY](https://github.com/nodejs/node/blob/HEAD/SECURITY.md) document","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-08-18T19:02:56.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-f772-66g8-q5h3","https://nvd.nist.gov/vuln/detail/CVE-2022-35948","https://github.com/nodejs/undici/commit/66165d604fd0aee70a93ed5c44ad4cc2df395f80","https://github.com/nodejs/undici/releases/tag/v5.8.2","https://github.com/advisories/GHSA-f772-66g8-q5h3"],"source_kind":"github","identifiers":["GHSA-f772-66g8-q5h3","CVE-2022-35948"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"5.8.2","vulnerable_version_range":"\u003c= 5.8.1"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2022-12-21T16:12:00.990Z","updated_at":"2025-06-02T01:12:06.888Z","epss_percentage":0.00094,"epss_percentile":0.2778},{"uuid":"GSA_kwCzR0hTQS04cXI0LXhndzYtd21yM84AAuFj","url":"https://github.com/advisories/GHSA-8qr4-xgw6-wmr3","title":"`undici.request` vulnerable to SSRF using absolute URL on `pathname`","description":"### Impact\n\n`undici` is vulnerable to SSRF (Server-side Request Forgery) when an application takes in **user input** into the `path/pathname` option of `undici.request`.\n\nIf a user specifies a URL such as `http://127.0.0.1` or `//127.0.0.1`\n\n```js\nconst undici = require(\"undici\")\nundici.request({origin: \"http://example.com\", pathname: \"//127.0.0.1\"})\n```\n\nInstead of processing the request as `http://example.org//127.0.0.1` (or `http://example.org/http://127.0.0.1` when `http://127.0.0.1 is used`), it actually processes the request as `http://127.0.0.1/` and sends it to `http://127.0.0.1`.\n\nIf a developer passes in user input into `path` parameter of `undici.request`, it can result in an _SSRF_ as they will assume that the hostname cannot change, when in actual fact it can change because the specified path parameter is combined with the base URL.\n\n### Patches\n\nThis issue was fixed in `undici@5.8.1`.\n\n### Workarounds\n\nThe best workaround is to validate user input before passing it to the `undici.request` call.\n\n## For more information\nIf you have any questions or comments about this advisory:\n\n- Open an issue in [undici repository](https://github.com/nodejs/undici/issues)\n- To make a report, follow the [SECURITY](https://github.com/nodejs/node/blob/HEAD/SECURITY.md) document\n","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-08-18T18:59:46.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-8qr4-xgw6-wmr3","https://nvd.nist.gov/vuln/detail/CVE-2022-35949","https://github.com/nodejs/undici/commit/124f7ebf705366b2e1844dff721928d270f87895","https://github.com/nodejs/undici/releases/tag/v5.8.2","https://github.com/advisories/GHSA-8qr4-xgw6-wmr3"],"source_kind":"github","identifiers":["GHSA-8qr4-xgw6-wmr3","CVE-2022-35949"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"5.8.2","vulnerable_version_range":"\u003c= 5.8.1"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2022-12-21T16:12:01.023Z","updated_at":"2025-06-02T01:12:06.960Z","epss_percentage":0.00146,"epss_percentile":0.36286},{"uuid":"GSA_kwCzR0hTQS0zY3ZyLTgyMnItcnFjY84AAtkH","url":"https://github.com/advisories/GHSA-3cvr-822r-rqcc","title":"undici before v5.8.0 vulnerable to CRLF injection in request headers","description":"### Impact\n\nIt is possible to inject CRLF sequences into request headers in Undici.\n\n```js\nconst undici = require('undici')\n\nconst response = undici.request(\"http://127.0.0.1:1000\", {\n  headers: {'a': \"\\r\\nb\"}\n})\n```\n\nThe same applies to `path` and `method`\n\n### Patches\n\nUpdate to v5.8.0\n\n### Workarounds\n\nSanitize all HTTP headers from untrusted sources to eliminate `\\r\\n`.\n\n### References\n\nhttps://hackerone.com/reports/409943\nhttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12116\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Open an issue in [undici repository](https://github.com/nodejs/undici/issues)\n* To make a report, follow the [SECURITY](https://github.com/nodejs/node/blob/HEAD/SECURITY.md) document\n","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-07-21T20:30:10.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-3cvr-822r-rqcc","https://nvd.nist.gov/vuln/detail/CVE-2022-31150","https://github.com/nodejs/undici/commit/a29a151d0140d095742d21a004023d024fe93259","https://hackerone.com/reports/409943","https://github.com/nodejs/undici/releases/tag/v5.8.0","https://security.netapp.com/advisory/ntap-20220915-0002/","https://github.com/advisories/GHSA-3cvr-822r-rqcc"],"source_kind":"github","identifiers":["GHSA-3cvr-822r-rqcc","CVE-2022-31150"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"5.8.0","vulnerable_version_range":"\u003c 5.8.0"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2022-12-21T16:12:10.121Z","updated_at":"2025-06-02T01:12:09.639Z","epss_percentage":0.00147,"epss_percentile":0.36337},{"uuid":"GSA_kwCzR0hTQS1wZ3c3LXd4N3ctMnczM84AArtC","url":"https://github.com/advisories/GHSA-pgw7-wx7w-2w33","title":"ProxyAgent vulnerable to MITM","description":"### Description\n\n`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request \u0026 response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are actually sent via plain-text HTTP between Undici and the proxy server.\n\n### Impact\n\nThis affects all use of HTTPS via HTTP proxy using **`Undici.ProxyAgent`**  with Undici or Node's global `fetch`. In this case, it removes all HTTPS security from all requests sent using Undici's `ProxyAgent`, allowing trivial MitM attacks by anybody on the network path between the client and the target server (local network users, your ISP, the proxy, the target server's ISP, etc).\nThis less seriously affects HTTPS via HTTPS proxies. When you send HTTPS via a proxy to a remote server, the proxy can freely view or modify all HTTPS traffic unexpectedly (but only the proxy). \n\n### Patches\n\nThis issue was patched in Undici v5.5.1.\n\n### Workarounds\n\nAt the time of writing, the only workaround is to not use `ProxyAgent` as a dispatcher for TLS Connections.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-06-17T01:02:29.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-pgw7-wx7w-2w33","https://nvd.nist.gov/vuln/detail/CVE-2022-32210","https://hackerone.com/reports/1583680","https://github.com/advisories/GHSA-pgw7-wx7w-2w33"],"source_kind":"github","identifiers":["GHSA-pgw7-wx7w-2w33","CVE-2022-32210"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"5.5.1","vulnerable_version_range":"\u003e= 4.8.2, \u003c= 5.5.0"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2022-12-21T16:12:19.082Z","updated_at":"2025-06-02T01:12:18.131Z","epss_percentage":0.00131,"epss_percentile":0.34149}],"docker_usage_url":"https://docker.ecosyste.ms/usage/npm/undici","docker_dependents_count":1787,"docker_downloads_count":2620660081,"usage_url":"https://repos.ecosyste.ms/usage/npm/undici","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/npm/undici/dependencies","status":null,"funding_links":[],"critical":true,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/undici/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/undici/version_numbers","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/undici/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/undici/related_packages","maintainers":[{"uuid":"ronag","login":"ronag","name":null,"email":"ronagy@icloud.com","url":null,"packages_count":38,"html_url":"https://www.npmjs.com/~ronag","role":null,"created_at":"2022-11-14T02:52:35.896Z","updated_at":"2022-11-14T02:52:35.896Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/ronag/packages"},{"uuid":"matteo.collina","login":"matteo.collina","name":null,"email":"hello@matteocollina.com","url":null,"packages_count":604,"html_url":"https://www.npmjs.com/~matteo.collina","role":null,"created_at":"2022-11-14T02:52:35.691Z","updated_at":"2022-11-14T02:52:35.691Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/matteo.collina/packages"},{"uuid":"ethan_arrowood","login":"ethan_arrowood","name":null,"email":"ethan@arrowood.dev","url":null,"packages_count":34,"html_url":"https://www.npmjs.com/~ethan_arrowood","role":null,"created_at":"2022-11-14T02:52:35.968Z","updated_at":"2022-11-14T02:52:35.968Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/ethan_arrowood/packages"}],"registry":{"name":"npmjs.org","url":"https://registry.npmjs.org","ecosystem":"npm","default":true,"packages_count":5005320,"maintainers_count":1012640,"namespaces_count":295318,"keywords_count":699769,"github":"npm","metadata":{"funded_packages_count":150180},"icon_url":"https://github.com/npm.png","created_at":"2022-04-04T15:19:23.081Z","updated_at":"2025-06-05T05:52:15.849Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/namespaces"}},"unique_repositories_count":9928,"unique_repositories_count_past_30_days":64,"recent_issues":[{"uuid":"5127396734","node_id":"PR_kwDORIxYSc7936eK","number":12,"state":"open","title":"Bump undici from 7.22.0 to 7.29.0","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-12T05:04:30.000Z","updated_at":"2026-08-12T05:04:50.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"undici","old_version":"7.22.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 7.22.0 to 7.29.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.28.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e7 security advisories\u003c/strong\u003e, all shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 7.28.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^7.28.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v7 line is \u003cstrong\u003enot\u003c/strong\u003e affected by GHSA-38rv-x7px-6hhq (CVE-2026-9675), which is\nan 8.x-only regression.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on GHSA-hm92-r4w5-c3mj:\u003c/strong\u003e this fix shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e, not the\nearlier 7.2x line — the vulnerable single-pool code was still present through\n\u003ccode\u003ev7.27.2\u003c/code\u003e. The per-origin pool fix is\n\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5041\"\u003e#5041\u003c/a\u003e).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8cb10f98\"\u003e\u003ccode\u003e8cb10f98\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g\"\u003eGHSA-vmh5-mc38-953g\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9697\u003c/td\u003e\n\u003ctd\u003eHigh (7.4)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/04201f89\"\u003e\u003ccode\u003e04201f89\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj\"\u003eGHSA-hm92-r4w5-c3mj\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6734\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6\"\u003eGHSA-pr7r-676h-xcf6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9678\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/85a24055\"\u003e\u003ccode\u003e85a24055\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ea8930cf\"\u003e\u003ccode\u003eea8930cf\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f9eba0ad9134e1c0977848476bba9d49734696e4\"\u003e\u003ccode\u003ef9eba0a\u003c/code\u003e\u003c/a\u003e Bumped v7.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5430\"\u003e#5430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.22.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=7.22.0\u0026new-version=7.29.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/jaykode2025/whyismywebsiteslow.com/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/jaykode2025/whyismywebsiteslow.com/pull/12","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/jaykode2025%2Fwhyismywebsiteslow.com/issues/12","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/12/packages"},{"uuid":"5123008776","node_id":"PR_kwDORAPClc79pzrw","number":36,"state":"closed","title":"Bump undici from 6.27.0 to 6.28.0","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-08-11T17:49:22.000Z","author_association":null,"state_reason":null,"created_at":"2026-08-11T17:47:27.000Z","updated_at":"2026-08-11T17:49:32.000Z","time_to_close":115,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"undici","old_version":"6.27.0","new_version":"6.28.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 6.27.0 to 6.28.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.28.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e740a0b7c\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003ecba3a52a\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e4fd5a0c6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003eaf748404\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e and \u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ehttps://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a\"\u003e\u003ccode\u003e01a912e\u003c/code\u003e\u003c/a\u003e Bumped v6.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5591\"\u003e#5591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e\"\u003e\u003ccode\u003e481ecfc\u003c/code\u003e\u003c/a\u003e Use Node 22 and npm 11 to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e\u003ccode\u003e740a0b7\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0\"\u003e\u003ccode\u003e2698e49\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e\u003ccode\u003e4fd5a0c\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003e\u003ccode\u003ecba3a52\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003e\u003ccode\u003eaf74840\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=6.27.0\u0026new-version=6.28.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/paulie-of-punskas/get-lts-versions/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/paulie-of-punskas/get-lts-versions/pull/36","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/paulie-of-punskas%2Fget-lts-versions/issues/36","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/36/packages"},{"uuid":"5113547515","node_id":"PR_kwDOOTUI_M79LRAw","number":1031,"state":"open","title":"Bump the prod group across 1 directory with 5 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-10T19:17:16.000Z","updated_at":"2026-08-10T19:18:39.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"prod","update_count":5,"packages":[{"name":"i18next-fs-backend","old_version":"2.6.6","new_version":"2.6.7","repository_url":"https://github.com/i18next/i18next-fs-backend"},{"name":"i18next-http-middleware","old_version":"3.9.7","new_version":"3.9.8","repository_url":"https://github.com/i18next/i18next-http-middleware"},{"name":"jose","old_version":"6.2.4","new_version":"6.2.8","repository_url":"https://github.com/panva/jose"},{"name":"to-words","old_version":"5.6.1","new_version":"5.7.0","repository_url":"https://github.com/mastermunj/to-words"},{"name":"undici","old_version":"8.9.0","new_version":"8.10.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps the prod group with 5 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [i18next-fs-backend](https://github.com/i18next/i18next-fs-backend) | `2.6.6` | `2.6.7` |\n| [i18next-http-middleware](https://github.com/i18next/i18next-http-middleware) | `3.9.7` | `3.9.8` |\n| [jose](https://github.com/panva/jose) | `6.2.4` | `6.2.8` |\n| [to-words](https://github.com/mastermunj/to-words) | `5.6.1` | `5.7.0` |\n| [undici](https://github.com/nodejs/undici) | `8.9.0` | `8.10.0` |\n\n\nUpdates `i18next-fs-backend` from 2.6.6 to 2.6.7\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/i18next/i18next-fs-backend/blob/master/CHANGELOG.md\"\u003ei18next-fs-backend's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003e2.6.7\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003esecurity (defence-in-depth): \u003ccode\u003ewrite()\u003c/code\u003e iterates own enumerable keys of \u003ccode\u003equeuedWrites\u003c/code\u003e instead of using \u003ccode\u003efor...in\u003c/code\u003e. \u003ccode\u003efor...in\u003c/code\u003e walks the prototype chain, so an \u003ccode\u003eObject.prototype\u003c/code\u003e polluted by any other library in the process was iterated here and turned into \u003ccode\u003ewriteFile()\u003c/code\u003e calls. \u003ccode\u003esetPath\u003c/code\u003e / \u003ccode\u003epushPath\u003c/code\u003e already refuse to create unsafe own keys and \u003ccode\u003einterpolatePath\u003c/code\u003e still validates before anything is written, so this closes an amplification path rather than a traversal.\u003c/li\u003e\n\u003cli\u003edocs: corrected the security section of the README, which still claimed \u003ccode\u003e/\u003c/code\u003e is rejected in both \u003ccode\u003elng\u003c/code\u003e and \u003ccode\u003ens\u003c/code\u003e. That has not been true since 2.6.5, which allows \u003ccode\u003e/\u003c/code\u003e in \u003ccode\u003ens\u003c/code\u003e so nested namespace names such as \u003ccode\u003ea/b\u003c/code\u003e map to subfolder layouts. The per-key split is now described accurately.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/7c51fad9b376d04d6ca70a6a75e1664343b63799\"\u003e\u003ccode\u003e7c51fad\u003c/code\u003e\u003c/a\u003e 2.6.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/d3910ce620bf5b464017b730ec76163089f04fb5\"\u003e\u003ccode\u003ed3910ce\u003c/code\u003e\u003c/a\u003e security: iterate own keys in write(); fix stale README security section\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/8e5a11e2acdc86b24a77840f6aa565002cd86b08\"\u003e\u003ccode\u003e8e5a11e\u003c/code\u003e\u003c/a\u003e Bump i18next-fs-backend from 2.6.4 to 2.6.6 in /example/updatable-cache (\u003ca href=\"https://redirect.github.com/i18next/i18next-fs-backend/issues/84\"\u003e#84\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/ef0e8e5dd70a834a58c8967ec88bfea389a6b841\"\u003e\u003ccode\u003eef0e8e5\u003c/code\u003e\u003c/a\u003e Bump js-yaml from 4.2.0 to 4.3.0 (\u003ca href=\"https://redirect.github.com/i18next/i18next-fs-backend/issues/83\"\u003e#83\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/9e252de02967a5813125dc8c7e91786e69553c96\"\u003e\u003ccode\u003e9e252de\u003c/code\u003e\u003c/a\u003e Bump i18next-http-middleware from 3.9.3 to 3.9.7 in /example/fastify (\u003ca href=\"https://redirect.github.com/i18next/i18next-fs-backend/issues/80\"\u003e#80\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/7e5e5f2e798b7c3f85826ca80285886c257fe689\"\u003e\u003ccode\u003e7e5e5f2\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003e@​babel/core\u003c/code\u003e from 7.29.0 to 7.29.6 (\u003ca href=\"https://redirect.github.com/i18next/i18next-fs-backend/issues/81\"\u003e#81\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/e20a304df62fd597a5ca2fae255c3740f5ef0e9d\"\u003e\u003ccode\u003ee20a304\u003c/code\u003e\u003c/a\u003e Bump i18next-fs-backend from 2.6.4 to 2.6.6 in /example/fastify (\u003ca href=\"https://redirect.github.com/i18next/i18next-fs-backend/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/7534a5c446fd588c988a5a3d041e173eb71b6d07\"\u003e\u003ccode\u003e7534a5c\u003c/code\u003e\u003c/a\u003e Bump js-yaml from 4.1.1 to 4.2.0 (\u003ca href=\"https://redirect.github.com/i18next/i18next-fs-backend/issues/78\"\u003e#78\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/90001dfa95ff96760471375d0820cba9870a1057\"\u003e\u003ccode\u003e90001df\u003c/code\u003e\u003c/a\u003e Bump esbuild from 0.28.0 to 0.28.1 (\u003ca href=\"https://redirect.github.com/i18next/i18next-fs-backend/issues/77\"\u003e#77\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/ae1b436e864cda55bb2c343fe70eb2924359b952\"\u003e\u003ccode\u003eae1b436\u003c/code\u003e\u003c/a\u003e README: mention npx i18next-cli localize as the zero-to-localized path\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/i18next/i18next-fs-backend/compare/v2.6.6...v2.6.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `i18next-http-middleware` from 3.9.7 to 3.9.8\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/i18next/i18next-http-middleware/blob/master/CHANGELOG.md\"\u003ei18next-http-middleware's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/compare/v3.9.7...v3.9.8\"\u003ev3.9.8\u003c/a\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003esecurity: validate \u003ccode\u003elng\u003c/code\u003e/\u003ccode\u003ens\u003c/code\u003e in \u003ccode\u003emissingKeyHandler\u003c/code\u003e before forwarding them to \u003ccode\u003ebackendConnector.saveMissing()\u003c/code\u003e. The route params were used unvalidated, while the sibling \u003ccode\u003egetResourcesHandler\u003c/code\u003e already filtered them since 3.9.3. Because those values become the \u003ccode\u003e{{lng}}\u003c/code\u003e/\u003ccode\u003e{{ns}}\u003c/code\u003e segments of the backend's \u003ccode\u003eaddPath\u003c/code\u003e, and route params arrive percent-decoded, a request such as \u003ccode\u003ePOST /locales/add/..%2f..%2f..%2ftmp%2fpwned/x\u003c/code\u003e could write outside the locales directory on \u003ccode\u003ei18next-fs-backend\u003c/code\u003e; \u003ccode\u003elng=__proto__\u003c/code\u003e additionally reached that backend's \u003ccode\u003equeuedWrites\u003c/code\u003e path walk. Unsafe values now get a \u003ccode\u003e400\u003c/code\u003e and never reach the backend. The same \u003ccode\u003eisSafeLangIdentifier\u003c/code\u003e/\u003ccode\u003eisSafeNsIdentifier\u003c/code\u003e split applies, so legitimate values (including nested namespaces like \u003ccode\u003ea/b\u003c/code\u003e) are unaffected.\u003c/li\u003e\n\u003cli\u003esecurity: apply \u003ccode\u003eutils.isSafeLangIdentifier\u003c/code\u003e to detected languages in \u003ccode\u003eLanguageDetector.detect()\u003c/code\u003e. Detected values come from untrusted request input (querystring, path, cookie, session, header) and were filtered only by \u003ccode\u003eutils.hasXSS\u003c/code\u003e, which targets markup payloads and does not reject \u003ccode\u003e..\u003c/code\u003e, \u003ccode\u003e/\u003c/code\u003e, \u003ccode\u003e\\\u003c/code\u003e, control characters or prototype keys. With the default \u003ccode\u003esupportedLngs: false\u003c/code\u003e, i18next resolves any string, so a crafted \u003ccode\u003e?lng=\u003c/code\u003e could reach the backend's \u003ccode\u003eloadPath\u003c/code\u003e as a traversal segment (arbitrary file read on \u003ccode\u003ei18next-fs-backend\u003c/code\u003e, request forgery on \u003ccode\u003ei18next-http-backend\u003c/code\u003e). The check runs after \u003ccode\u003econvertDetectedLanguage\u003c/code\u003e, so a custom converter cannot reintroduce an unsafe value. All five built-in detectors converge on this one filter.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/commit/e4c0285f9beb6e9084d3c28991c5c607c4ceec16\"\u003e\u003ccode\u003ee4c0285\u003c/code\u003e\u003c/a\u003e 3.9.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/commit/9dd7c94124e633771040d25138cca7c38f6bfd2d\"\u003e\u003ccode\u003e9dd7c94\u003c/code\u003e\u003c/a\u003e security: validate lng/ns in missingKeyHandler and detected languages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/commit/fbce4c49827b9d9eaeafa105a1ee5ff3f29f8de0\"\u003e\u003ccode\u003efbce4c4\u003c/code\u003e\u003c/a\u003e Bump i18next-fs-backend from 2.6.4 to 2.6.6 in /example/fastify-pug (\u003ca href=\"https://redirect.github.com/i18next/i18next-http-middleware/issues/133\"\u003e#133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/commit/fd3a7c87ffc982f95dc464ec66c5f5a573fed322\"\u003e\u003ccode\u003efd3a7c8\u003c/code\u003e\u003c/a\u003e Bump i18next-http-middleware in /example/basic-locize (\u003ca href=\"https://redirect.github.com/i18next/i18next-http-middleware/issues/132\"\u003e#132\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/commit/25815efbab84af6542bd78ad0cc18e2ce1a32522\"\u003e\u003ccode\u003e25815ef\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003e@​babel/core\u003c/code\u003e from 7.29.0 to 7.29.6 (\u003ca href=\"https://redirect.github.com/i18next/i18next-http-middleware/issues/131\"\u003e#131\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/commit/40fdedc6f0f4079032decab5c051bfa9084df0ff\"\u003e\u003ccode\u003e40fdedc\u003c/code\u003e\u003c/a\u003e package.json: use HTTPS URL for repository metadata\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/commit/01f2dc248f2e651c15dd24d2c7d9d1542841ca1d\"\u003e\u003ccode\u003e01f2dc2\u003c/code\u003e\u003c/a\u003e changelog: link 3.9.7 entry to published advisory GHSA-f49m-vf83-692w\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/commit/a3722a803b6eab50141b6a800903e74c7ba65eb1\"\u003e\u003ccode\u003ea3722a8\u003c/code\u003e\u003c/a\u003e Bump i18next-fs-backend from 1.0.7 to 2.6.4 in /example/basic-pug (\u003ca href=\"https://redirect.github.com/i18next/i18next-http-middleware/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/i18next/i18next-http-middleware/compare/v3.9.7...v3.9.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `jose` from 6.2.4 to 6.2.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/panva/jose/releases\"\u003ejose's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.2.8\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eenforce a single recipient when decrypting dir and ECDH-ES (\u003ca href=\"https://github.com/panva/jose/commit/505c3833ecae19807e32ad7be50ff4677d31bcad\"\u003e505c383\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject a non-string \u0026quot;alg\u0026quot; in EmbeddedJWK (\u003ca href=\"https://github.com/panva/jose/commit/714f8704347ccee8b3d0007e028b6e3f546b443c\"\u003e714f870\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eindex the JWS and JWE registries without a wrapper (\u003ca href=\"https://github.com/panva/jose/commit/925f3bbbee4b8d5e335774ffbf6ec086e71c3a05\"\u003e925f3bb\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ename the \u0026quot;alg\u0026quot; source in unsupported algorithm failures (\u003ca href=\"https://github.com/panva/jose/commit/1500459c6ffce48fb486c15cb213d24064a26673\"\u003e1500459\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.2.7\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003erequire own JOSE properties for presence checks (\u003ca href=\"https://github.com/panva/jose/commit/90ab09c461c9bc82fd24af269616be0907a28bc5\"\u003e90ab09c\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ereduce bundle size (\u003ca href=\"https://github.com/panva/jose/commit/767d7f12d025ce54e74f3d38fde3571cc23de5f6\"\u003e767d7f1\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.2.6\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e accept host CryptoKey declarations (\u003ca href=\"https://github.com/panva/jose/commit/b48a15b39696f49c61136b1d4c40d33585f5df97\"\u003eb48a15b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.2.5\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecompare claim values for falsy validation options (\u003ca href=\"https://github.com/panva/jose/commit/eb8695699c75f36c736fb8159a7c7b525be5f6ff\"\u003eeb86956\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eforward key management parameters for a single JWE recipient (\u003ca href=\"https://github.com/panva/jose/commit/2d4f8014e027a1e1ace82bdc864fd0f9b5c66248\"\u003e2d4f801\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ehandle a zero-length JWE additional authenticated data (\u003ca href=\"https://github.com/panva/jose/commit/16ca398103c4ab1527c6c6c51621fd963545bd7e\"\u003e16ca398\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject a generateKeyPair crv option the algorithm does not imply (\u003ca href=\"https://github.com/panva/jose/commit/76364e9f15f2a7d1c2ff0c260e1e2960cf51e620\"\u003e76364e9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject an unencoded payload in the JWS Compact Serialization (\u003ca href=\"https://github.com/panva/jose/commit/01d053f3b02f3627396d4f70686a58f35cf09862\"\u003e01d053f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject characters outside the Base64URL alphabet (\u003ca href=\"https://github.com/panva/jose/commit/0ebb97158a6eed960ec4d5450abd28336b3c20a4\"\u003e0ebb971\u003c/a\u003e), references \u003ca href=\"https://redirect.github.com/panva/jose/issues/879\"\u003e#879\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ereject duplicate \u0026quot;crit\u0026quot; values when producing (\u003ca href=\"https://github.com/panva/jose/commit/31d60e1542141ddecf5b0b87bc894c4bc7e58b1d\"\u003e31d60e1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject invalid UTF-8 in JOSE Headers and JWT Claims Sets (\u003ca href=\"https://github.com/panva/jose/commit/5df3fedcc06d4c52815ec9d0cccc51b508a8291c\"\u003e5df3fed\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject truncated ASN.1 key data (\u003ca href=\"https://github.com/panva/jose/commit/7a16c66b9f1a48bcc2aae572da38ed06396a5181\"\u003e7a16c66\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esurface non-ASCII token segments as JOSE errors (\u003ca href=\"https://github.com/panva/jose/commit/194fe11450d6501d0c2141a50e60886157d3f393\"\u003e194fe11\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e correct JWK and CryptoKey types (\u003ca href=\"https://github.com/panva/jose/commit/62a196dc8e6582dc6edd20eab31c6c44b745f996\"\u003e62a196d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e correct key resolver and JWT header types (\u003ca href=\"https://github.com/panva/jose/commit/e95f8c4086cbb81321497cc7d4b78fa5e88312b6\"\u003ee95f8c4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003evalidate the clockTolerance and currentDate options are finite (\u003ca href=\"https://github.com/panva/jose/commit/ab2f18dad46a98ecae3f3ac5b2aae9c839fb9388\"\u003eab2f18d\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecorrect subpaths and API documentation (\u003ca href=\"https://github.com/panva/jose/commit/2daec382964be1976d5985e0413a56633becdd74\"\u003e2daec38\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edocument consumer-supplied type parameters (\u003ca href=\"https://github.com/panva/jose/commit/9e9f66c86bdf0f4b4ccd1e4b7b84cc85ac9c7883\"\u003e9e9f66c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003estop claiming the JWK \u0026quot;use\u0026quot; parameter is used during import (\u003ca href=\"https://github.com/panva/jose/commit/47a07b2f95c1b2ecf0308c04f35d4b482689568e\"\u003e47a07b2\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate CHANGELOG.md (\u003ca href=\"https://github.com/panva/jose/commit/fc51bf56f9f752aaed7d31c60a45e89f24e30d00\"\u003efc51bf5\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/panva/jose/blob/main/CHANGELOG.md\"\u003ejose's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/panva/jose/compare/v6.2.7...v6.2.8\"\u003e6.2.8\u003c/a\u003e (2026-08-03)\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eenforce a single recipient when decrypting dir and ECDH-ES (\u003ca href=\"https://github.com/panva/jose/commit/505c3833ecae19807e32ad7be50ff4677d31bcad\"\u003e505c383\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject a non-string \u0026quot;alg\u0026quot; in EmbeddedJWK (\u003ca href=\"https://github.com/panva/jose/commit/714f8704347ccee8b3d0007e028b6e3f546b443c\"\u003e714f870\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eindex the JWS and JWE registries without a wrapper (\u003ca href=\"https://github.com/panva/jose/commit/925f3bbbee4b8d5e335774ffbf6ec086e71c3a05\"\u003e925f3bb\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ename the \u0026quot;alg\u0026quot; source in unsupported algorithm failures (\u003ca href=\"https://github.com/panva/jose/commit/1500459c6ffce48fb486c15cb213d24064a26673\"\u003e1500459\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/panva/jose/compare/v6.2.6...v6.2.7\"\u003e6.2.7\u003c/a\u003e (2026-08-01)\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003erequire own JOSE properties for presence checks (\u003ca href=\"https://github.com/panva/jose/commit/90ab09c461c9bc82fd24af269616be0907a28bc5\"\u003e90ab09c\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ereduce bundle size (\u003ca href=\"https://github.com/panva/jose/commit/767d7f12d025ce54e74f3d38fde3571cc23de5f6\"\u003e767d7f1\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/panva/jose/compare/v6.2.5...v6.2.6\"\u003e6.2.6\u003c/a\u003e (2026-07-31)\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e accept host CryptoKey declarations (\u003ca href=\"https://github.com/panva/jose/commit/b48a15b39696f49c61136b1d4c40d33585f5df97\"\u003eb48a15b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/panva/jose/compare/v6.2.4...v6.2.5\"\u003e6.2.5\u003c/a\u003e (2026-07-29)\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecompare claim values for falsy validation options (\u003ca href=\"https://github.com/panva/jose/commit/eb8695699c75f36c736fb8159a7c7b525be5f6ff\"\u003eeb86956\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eforward key management parameters for a single JWE recipient (\u003ca href=\"https://github.com/panva/jose/commit/2d4f8014e027a1e1ace82bdc864fd0f9b5c66248\"\u003e2d4f801\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ehandle a zero-length JWE additional authenticated data (\u003ca href=\"https://github.com/panva/jose/commit/16ca398103c4ab1527c6c6c51621fd963545bd7e\"\u003e16ca398\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject a generateKeyPair crv option the algorithm does not imply (\u003ca href=\"https://github.com/panva/jose/commit/76364e9f15f2a7d1c2ff0c260e1e2960cf51e620\"\u003e76364e9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject an unencoded payload in the JWS Compact Serialization (\u003ca href=\"https://github.com/panva/jose/commit/01d053f3b02f3627396d4f70686a58f35cf09862\"\u003e01d053f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject characters outside the Base64URL alphabet (\u003ca href=\"https://github.com/panva/jose/commit/0ebb97158a6eed960ec4d5450abd28336b3c20a4\"\u003e0ebb971\u003c/a\u003e), references \u003ca href=\"https://redirect.github.com/panva/jose/issues/879\"\u003e#879\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ereject duplicate \u0026quot;crit\u0026quot; values when producing (\u003ca href=\"https://github.com/panva/jose/commit/31d60e1542141ddecf5b0b87bc894c4bc7e58b1d\"\u003e31d60e1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject invalid UTF-8 in JOSE Headers and JWT Claims Sets (\u003ca href=\"https://github.com/panva/jose/commit/5df3fedcc06d4c52815ec9d0cccc51b508a8291c\"\u003e5df3fed\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject truncated ASN.1 key data (\u003ca href=\"https://github.com/panva/jose/commit/7a16c66b9f1a48bcc2aae572da38ed06396a5181\"\u003e7a16c66\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esurface non-ASCII token segments as JOSE errors (\u003ca href=\"https://github.com/panva/jose/commit/194fe11450d6501d0c2141a50e60886157d3f393\"\u003e194fe11\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e correct JWK and CryptoKey types (\u003ca href=\"https://github.com/panva/jose/commit/62a196dc8e6582dc6edd20eab31c6c44b745f996\"\u003e62a196d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e correct key resolver and JWT header types (\u003ca href=\"https://github.com/panva/jose/commit/e95f8c4086cbb81321497cc7d4b78fa5e88312b6\"\u003ee95f8c4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003evalidate the clockTolerance and currentDate options are finite (\u003ca href=\"https://github.com/panva/jose/commit/ab2f18dad46a98ecae3f3ac5b2aae9c839fb9388\"\u003eab2f18d\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecorrect subpaths and API documentation (\u003ca href=\"https://github.com/panva/jose/commit/2daec382964be1976d5985e0413a56633becdd74\"\u003e2daec38\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edocument consumer-supplied type parameters (\u003ca href=\"https://github.com/panva/jose/commit/9e9f66c86bdf0f4b4ccd1e4b7b84cc85ac9c7883\"\u003e9e9f66c\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/8b768eb8d2df7b4e25e1a32441ea770663f6d09f\"\u003e\u003ccode\u003e8b768eb\u003c/code\u003e\u003c/a\u003e chore(release): 6.2.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/1500459c6ffce48fb486c15cb213d24064a26673\"\u003e\u003ccode\u003e1500459\u003c/code\u003e\u003c/a\u003e refactor: name the \u0026quot;alg\u0026quot; source in unsupported algorithm failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/714f8704347ccee8b3d0007e028b6e3f546b443c\"\u003e\u003ccode\u003e714f870\u003c/code\u003e\u003c/a\u003e fix: reject a non-string \u0026quot;alg\u0026quot; in EmbeddedJWK\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/925f3bbbee4b8d5e335774ffbf6ec086e71c3a05\"\u003e\u003ccode\u003e925f3bb\u003c/code\u003e\u003c/a\u003e refactor: index the JWS and JWE registries without a wrapper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/505c3833ecae19807e32ad7be50ff4677d31bcad\"\u003e\u003ccode\u003e505c383\u003c/code\u003e\u003c/a\u003e fix: enforce a single recipient when decrypting dir and ECDH-ES\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/514831da55bcb1121c1dadc1ccca42049e6c60b9\"\u003e\u003ccode\u003e514831d\u003c/code\u003e\u003c/a\u003e chore(deps): bump the actions group with 3 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/45965db443b120d174a5114c7c84a75a906e9012\"\u003e\u003ccode\u003e45965db\u003c/code\u003e\u003c/a\u003e chore: cleanup after release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/60b941f6d57e2bb6f87f690ab7fb4da2c9abf4b0\"\u003e\u003ccode\u003e60b941f\u003c/code\u003e\u003c/a\u003e chore(release): 6.2.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/90ab09c461c9bc82fd24af269616be0907a28bc5\"\u003e\u003ccode\u003e90ab09c\u003c/code\u003e\u003c/a\u003e fix: require own JOSE properties for presence checks\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/767d7f12d025ce54e74f3d38fde3571cc23de5f6\"\u003e\u003ccode\u003e767d7f1\u003c/code\u003e\u003c/a\u003e refactor: reduce bundle size\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/panva/jose/compare/v6.2.4...v6.2.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `to-words` from 5.6.1 to 5.7.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mastermunj/to-words/releases\"\u003eto-words's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.7.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/mastermunj/to-words/compare/v5.6.1...v5.7.0\"\u003e5.7.0\u003c/a\u003e (2026-08-02)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd 3 new locale, update docs (\u003ca href=\"https://github.com/mastermunj/to-words/commit/a37ca0a81999af5a80f05c2d6b88a9f0e4cc55e6\"\u003ea37ca0a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd 3 new locale, update docs (\u003ca href=\"https://github.com/mastermunj/to-words/commit/51916b4e3d1a7c3a2b9c5e3d0eddfddb3ebb0eb4\"\u003e51916b4\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mastermunj/to-words/blob/main/CHANGELOG.md\"\u003eto-words's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/mastermunj/to-words/compare/v5.6.1...v5.7.0\"\u003e5.7.0\u003c/a\u003e (2026-08-02)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd 3 new locale, update docs (\u003ca href=\"https://github.com/mastermunj/to-words/commit/a37ca0a81999af5a80f05c2d6b88a9f0e4cc55e6\"\u003ea37ca0a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd 3 new locale, update docs (\u003ca href=\"https://github.com/mastermunj/to-words/commit/51916b4e3d1a7c3a2b9c5e3d0eddfddb3ebb0eb4\"\u003e51916b4\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/31440636dcaaa25055f5ceacf68b30baaed1bd13\"\u003e\u003ccode\u003e3144063\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mastermunj/to-words/issues/2418\"\u003e#2418\u003c/a\u003e from mastermunj/release-please--branches--main--comp...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/e66172f7098368518b9ab8d1ed8d613255fb426b\"\u003e\u003ccode\u003ee66172f\u003c/code\u003e\u003c/a\u003e chore(release): 5.7.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/a37ca0a81999af5a80f05c2d6b88a9f0e4cc55e6\"\u003e\u003ccode\u003ea37ca0a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mastermunj/to-words/issues/2417\"\u003e#2417\u003c/a\u003e from mastermunj/new-locale-2026-08-02\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/51916b4e3d1a7c3a2b9c5e3d0eddfddb3ebb0eb4\"\u003e\u003ccode\u003e51916b4\u003c/code\u003e\u003c/a\u003e feat: add 3 new locale, update docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/46befa9a39078048b51600e32969458f9c10bf63\"\u003e\u003ccode\u003e46befa9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mastermunj/to-words/issues/2411\"\u003e#2411\u003c/a\u003e from mastermunj/dependabot/github_actions/actions/ch...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/59b709d3b8e73bbfa935e5bb2a86de5428f0d533\"\u003e\u003ccode\u003e59b709d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mastermunj/to-words/issues/2410\"\u003e#2410\u003c/a\u003e from mastermunj/dependabot/github_actions/ossf/score...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/039aa77d9539c7844141241086bc601a32eec93b\"\u003e\u003ccode\u003e039aa77\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mastermunj/to-words/issues/2409\"\u003e#2409\u003c/a\u003e from mastermunj/dependabot/github_actions/codeql-85d...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/d2f3b6d44c80107ee036dbfc8dfd29be109f19dd\"\u003e\u003ccode\u003ed2f3b6d\u003c/code\u003e\u003c/a\u003e chore: update dependencies (\u003ca href=\"https://redirect.github.com/mastermunj/to-words/issues/2412\"\u003e#2412\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/05e4ff2c02e7db1fc5c585bcc21d069521c5f783\"\u003e\u003ccode\u003e05e4ff2\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/checkout from 7.0.0 to 7.0.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/88b72c969eb12bf1cb123297ed25f0b1998d3cfa\"\u003e\u003ccode\u003e88b72c9\u003c/code\u003e\u003c/a\u003e build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mastermunj/to-words/compare/v5.6.1...v5.7.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 8.9.0 to 8.10.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: namespace h2 options by \u003ca href=\"https://github.com/metcoder95\"\u003e\u003ccode\u003e@​metcoder95\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5498\"\u003enodejs/undici#5498\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: update WPT expectations by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5587\"\u003enodejs/undici#5587\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: add cache/dedupe + dns re-dispatch integration tests by \u003ca href=\"https://github.com/GiHoon1123\"\u003e\u003ccode\u003e@​GiHoon1123\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5535\"\u003enodejs/undici#5535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): support process.unref by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5578\"\u003enodejs/undici#5578\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): ensure every request settles by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5603\"\u003enodejs/undici#5603\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(readable): consume a body whose end has already been emitted by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5617\"\u003enodejs/undici#5617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): skip the content-length checkpoint for HEAD and for a 206 without content-range by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5610\"\u003enodejs/undici#5610\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: revert idle socket validation to setTimeout(0) to prevent stall on idle event loop by \u003ca href=\"https://github.com/marceli1404\"\u003e\u003ccode\u003e@​marceli1404\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5606\"\u003enodejs/undici#5606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(env-http-proxy-agent): match bare IPv6 addresses in no_proxy by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5623\"\u003enodejs/undici#5623\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: handle aggregate balanced pool errors by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5377\"\u003enodejs/undici#5377\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(readable): keep body bytes that arrive after setEncoding() by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5620\"\u003enodejs/undici#5620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(socks5): evict unused origin pools by \u003ca href=\"https://github.com/Kkartik14\"\u003e\u003ccode\u003e@​Kkartik14\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5595\"\u003enodejs/undici#5595\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: skip deduplication for upgrade requests by \u003ca href=\"https://github.com/Ram-blip\"\u003e\u003ccode\u003e@​Ram-blip\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5593\"\u003enodejs/undici#5593\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward informational responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5625\"\u003enodejs/undici#5625\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(mock): non-string path matchers under ignoreTrailingSlash, and DataView reply bodies by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5619\"\u003enodejs/undici#5619\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(interceptors): cache() and deduplicate() silently inert on Client/Pool without opts.origin by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5628\"\u003enodejs/undici#5628\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5633\"\u003enodejs/undici#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/init from 4.36.2 to 4.37.3 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5634\"\u003enodejs/undici#5634\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.4.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5636\"\u003enodejs/undici#5636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(mock): emit request body lifecycle hooks by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5367\"\u003enodejs/undici#5367\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): detach upgrade close handler after GOAWAY by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5641\"\u003enodejs/undici#5641\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: retry refused HTTP/2 streams by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5598\"\u003enodejs/undici#5598\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: preserve DNS origin hostname on sockets by \u003ca href=\"https://github.com/cyphercodes\"\u003e\u003ccode\u003e@​cyphercodes\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5577\"\u003enodejs/undici#5577\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marceli1404\"\u003e\u003ccode\u003e@​marceli1404\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5606\"\u003enodejs/undici#5606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kkartik14\"\u003e\u003ccode\u003e@​Kkartik14\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5595\"\u003enodejs/undici#5595\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5641\"\u003enodejs/undici#5641\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cyphercodes\"\u003e\u003ccode\u003e@​cyphercodes\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5577\"\u003enodejs/undici#5577\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v8.9.0...v8.10.0\"\u003ehttps://github.com/nodejs/undici/compare/v8.9.0...v8.10.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/c8d80e6b2dcfab282557b08f51352937bc9e5692\"\u003e\u003ccode\u003ec8d80e6\u003c/code\u003e\u003c/a\u003e Bumped v8.10.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5644\"\u003e#5644\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66923b47dc1ed095581daa6a53b2ad1bf3e899b4\"\u003e\u003ccode\u003e66923b4\u003c/code\u003e\u003c/a\u003e fix: preserve DNS origin hostname on sockets (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5577\"\u003e#5577\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/392649944c3b989681af1eae2e0970661f9ca464\"\u003e\u003ccode\u003e3926499\u003c/code\u003e\u003c/a\u003e fix: retry refused HTTP/2 streams (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5598\"\u003e#5598\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/73d6e9e19df47f85625d2dc082daa919ae6636c1\"\u003e\u003ccode\u003e73d6e9e\u003c/code\u003e\u003c/a\u003e fix(h2): detach upgrade close handler after GOAWAY (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5641\"\u003e#5641\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b111adbb675ebfcfa52790346dcd88e61c700818\"\u003e\u003ccode\u003eb111adb\u003c/code\u003e\u003c/a\u003e fix(mock): emit request body lifecycle hooks (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5367\"\u003e#5367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ae4a3e37a2ddfe798b64771176e31e8e7819c743\"\u003e\u003ccode\u003eae4a3e3\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/setup-node from 6.4.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5636\"\u003e#5636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ec3fbf19aa47eca6decc390b66bf56034bc03d52\"\u003e\u003ccode\u003eec3fbf1\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action/init from 4.36.2 to 4.37.3 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5634\"\u003e#5634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/21517200296205f3aa09a7b976dde571b441405c\"\u003e\u003ccode\u003e2151720\u003c/code\u003e\u003c/a\u003e build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5633\"\u003e#5633\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b96a11620e2f9fe5adafa2ba7b7f363b96b5a9d7\"\u003e\u003ccode\u003eb96a116\u003c/code\u003e\u003c/a\u003e fix(interceptors): allow interceptors without opts.origin (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5628\"\u003e#5628\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/a18ef2d05af48047339be51d8817492abc30f39d\"\u003e\u003ccode\u003ea18ef2d\u003c/code\u003e\u003c/a\u003e fix(mock): non-string path matchers under ignoreTrailingSlash, and DataView r...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v8.9.0...v8.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/DEFRA/epr-frontend/pull/1031","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/DEFRA%2Fepr-frontend/issues/1031","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1031/packages"},{"uuid":"5109232884","node_id":"PR_kwDOKRXhvM789Q_K","number":6793,"state":"open","title":"chore(deps): bump the minor-and-patch group with 53 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-10T10:41:22.000Z","updated_at":"2026-08-10T10:41:37.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"minor-and-patch","update_count":53,"packages":[{"name":"@chakra-ui/react","old_version":"3.36.0","new_version":"3.36.1","repository_url":"https://github.com/chakra-ui/chakra-ui"},{"name":"@clickhouse/client","old_version":"1.23.0","new_version":"1.23.1","repository_url":"https://github.com/ClickHouse/clickhouse-js"},{"name":"@hono/node-server","old_version":"2.0.10","new_version":"2.0.12","repository_url":"https://github.com/honojs/node-server"},{"name":"@modelcontextprotocol/sdk","old_version":"1.29.0","new_version":"1.30.0","repository_url":"https://github.com/modelcontextprotocol/typescript-sdk"},{"name":"@react-email/render","old_version":"2.0.9","new_version":"2.1.0","repository_url":"https://github.com/resend/react-email"},{"name":"@smithy/node-http-handler","old_version":"4.9.12","new_version":"4.9.13","repository_url":"https://github.com/smithy-lang/smithy-typescript"},{"name":"better-auth","old_version":"1.6.23","new_version":"1.6.25","repository_url":"https://github.com/better-auth/better-auth"},{"name":"geoip-country","old_version":"5.0.202607010001","new_version":"5.0.202608010109","repository_url":"https://github.com/sapics/geoip-country"},{"name":"hono","old_version":"4.12.27","new_version":"4.12.33","repository_url":"https://github.com/honojs/hono"},{"name":"js-yaml","old_version":"5.2.1","new_version":"5.2.3","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"libphonenumber-js","old_version":"1.13.7","new_version":"1.13.10"},{"name":"liquidjs","old_version":"10.27.1","new_version":"10.28.0","repository_url":"https://github.com/harttle/liquidjs"},{"name":"marked","old_version":"18.0.5","new_version":"18.0.7","repository_url":"https://github.com/markedjs/marked"},{"name":"msgpackr","old_version":"2.0.4","new_version":"2.0.5","repository_url":"https://github.com/kriszyp/msgpackr"},{"name":"react-router","old_version":"8.1.0","new_version":"8.3.0","repository_url":"https://github.com/remix-run/react-router"},{"name":"sanitize-html","old_version":"2.17.5","new_version":"2.17.6","repository_url":"https://github.com/apostrophecms/apostrophe"},{"name":"undici","old_version":"8.5.0","new_version":"8.9.0","repository_url":"https://github.com/nodejs/undici"},{"name":"@biomejs/biome","old_version":"2.5.1","new_version":"2.5.6","repository_url":"https://github.com/biomejs/biome"},{"name":"@chakra-ui/charts","old_version":"3.36.0","new_version":"3.36.1","repository_url":"https://github.com/chakra-ui/chakra-ui"},{"name":"@hono/zod-validator","old_version":"0.4.3","new_version":"0.9.0","repository_url":"https://github.com/honojs/middleware"},{"name":"@hookform/resolvers","old_version":"5.4.0","new_version":"5.7.1","repository_url":"https://github.com/react-hook-form/resolvers"},{"name":"@microlink/react-json-view","old_version":"1.31.21","new_version":"1.31.25","repository_url":"https://github.com/microlinkhq/react-json-view"},{"name":"@paper-design/shaders-react","old_version":"0.0.76","new_version":"0.0.78"},{"name":"@playwright/test","old_version":"1.61.1","new_version":"1.62.1","repository_url":"https://github.com/microsoft/playwright"},{"name":"@tanstack/react-virtual","old_version":"3.14.5","new_version":"3.14.9","repository_url":"https://github.com/TanStack/virtual"},{"name":"@tiptap/extension-document","old_version":"3.27.1","new_version":"3.29.2","repository_url":"https://github.com/ueberdosis/tiptap"},{"name":"@tiptap/extension-history","old_version":"3.27.1","new_version":"3.29.2","repository_url":"https://github.com/ueberdosis/tiptap"},{"name":"@tiptap/extension-paragraph","old_version":"3.27.1","new_version":"3.29.2","repository_url":"https://github.com/ueberdosis/tiptap"},{"name":"@tiptap/extension-placeholder","old_version":"3.27.1","new_version":"3.29.2","repository_url":"https://github.com/ueberdosis/tiptap"},{"name":"@tiptap/extension-text","old_version":"3.27.1","new_version":"3.29.2","repository_url":"https://github.com/ueberdosis/tiptap"},{"name":"@tiptap/pm","old_version":"3.27.1","new_version":"3.29.2","repository_url":"https://github.com/ueberdosis/tiptap"},{"name":"@tiptap/react","old_version":"3.27.1","new_version":"3.29.2","repository_url":"https://github.com/ueberdosis/tiptap"},{"name":"@vitejs/plugin-react","old_version":"6.0.3","new_version":"6.0.5","repository_url":"https://github.com/vitejs/vite-plugin-react"},{"name":"@xyflow/react","old_version":"12.11.1","new_version":"12.11.2","repository_url":"https://github.com/xyflow/xyflow"},{"name":"immer","old_version":"11.1.8","new_version":"11.1.15","repository_url":"https://github.com/immerjs/immer"},{"name":"lucide-react","old_version":"1.22.0","new_version":"1.28.0","repository_url":"https://github.com/lucide-icons/lucide"},{"name":"monaco-editor","old_version":"0.55.1","new_version":"0.56.0","repository_url":"https://github.com/microsoft/monaco-editor"},{"name":"motion","old_version":"12.42.2","new_version":"12.43.0","repository_url":"https://github.com/motiondivision/motion"},{"name":"node-mocks-http","old_version":"1.17.2","new_version":"1.18.1","repository_url":"https://github.com/eugef/node-mocks-http"},{"name":"playwright","old_version":"1.61.1","new_version":"1.62.1","repository_url":"https://github.com/microsoft/playwright"},{"name":"react-hook-form","old_version":"7.80.0","new_version":"7.84.0","repository_url":"https://github.com/react-hook-form/react-hook-form"},{"name":"recharts","old_version":"3.9.1","new_version":"3.10.1","repository_url":"https://github.com/recharts/recharts"},{"name":"rich-textarea","old_version":"0.27.0","new_version":"0.27.1","repository_url":"https://github.com/inokawa/rich-textarea"},{"name":"sass","old_version":"1.101.0","new_version":"1.102.0","repository_url":"https://github.com/sass/dart-sass"},{"name":"shiki","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/shikijs/shiki"},{"name":"simple-statistics","old_version":"7.9.2","new_version":"7.9.3","repository_url":"https://github.com/simple-statistics/simple-statistics"},{"name":"tsx","old_version":"4.22.4","new_version":"4.23.1","repository_url":"https://github.com/privatenumber/tsx"},{"name":"vite","old_version":"8.1.2","new_version":"8.2.0","repository_url":"https://github.com/vitejs/vite"},{"name":"@rollup/rollup-linux-x64-gnu","old_version":"4.62.2","new_version":"4.62.4","repository_url":"https://github.com/rollup/rollup"},{"name":"tar","old_version":"7.5.21","new_version":"7.5.22","repository_url":"https://github.com/isaacs/node-tar"},{"name":"typescript-eslint","old_version":"8.58.1","new_version":"8.65.0","repository_url":"https://github.com/typescript-eslint/typescript-eslint"},{"name":"yargs","old_version":"18.0.0","new_version":"18.1.0","repository_url":"https://github.com/yargs/yargs"},{"name":"nock","old_version":"14.0.16","new_version":"14.0.17","repository_url":"https://github.com/nock/nock"}],"path":null,"ecosystem":"npm"},"body":"Bumps the minor-and-patch group with 53 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@chakra-ui/react](https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react) | `3.36.0` | `3.36.1` |\n| [@clickhouse/client](https://github.com/ClickHouse/clickhouse-js) | `1.23.0` | `1.23.1` |\n| [@hono/node-server](https://github.com/honojs/node-server) | `2.0.10` | `2.0.12` |\n| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.29.0` | `1.30.0` |\n| [@react-email/render](https://github.com/resend/react-email/tree/HEAD/packages/render) | `2.0.9` | `2.1.0` |\n| [@smithy/node-http-handler](https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/node-http-handler) | `4.9.12` | `4.9.13` |\n| [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) | `1.6.23` | `1.6.25` |\n| [geoip-country](https://github.com/sapics/geoip-country) | `5.0.202607010001` | `5.0.202608010109` |\n| [hono](https://github.com/honojs/hono) | `4.12.27` | `4.12.33` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `5.2.1` | `5.2.3` |\n| [libphonenumber-js](https://gitlab.com/catamphetamine/libphonenumber-js) | `1.13.7` | `1.13.10` |\n| [liquidjs](https://github.com/harttle/liquidjs) | `10.27.1` | `10.28.0` |\n| [marked](https://github.com/markedjs/marked) | `18.0.5` | `18.0.7` |\n| [msgpackr](https://github.com/kriszyp/msgpackr) | `2.0.4` | `2.0.5` |\n| [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router) | `8.1.0` | `8.3.0` |\n| [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) | `2.17.5` | `2.17.6` |\n| [undici](https://github.com/nodejs/undici) | `8.5.0` | `8.9.0` |\n| [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) | `2.5.1` | `2.5.6` |\n| [@chakra-ui/charts](https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/charts) | `3.36.0` | `3.36.1` |\n| [@hono/zod-validator](https://github.com/honojs/middleware/tree/HEAD/packages/zod-validator) | `0.4.3` | `0.9.0` |\n| [@hookform/resolvers](https://github.com/react-hook-form/resolvers) | `5.4.0` | `5.7.1` |\n| [@microlink/react-json-view](https://github.com/microlinkhq/react-json-view) | `1.31.21` | `1.31.25` |\n| @paper-design/shaders-react | `0.0.76` | `0.0.78` |\n| [@playwright/test](https://github.com/microsoft/playwright) | `1.61.1` | `1.62.1` |\n| [@tanstack/react-virtual](https://github.com/TanStack/virtual/tree/HEAD/packages/react-virtual) | `3.14.5` | `3.14.9` |\n| [@tiptap/extension-document](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-document) | `3.27.1` | `3.29.2` |\n| [@tiptap/extension-history](https://github.com/ueberdosis/tiptap/tree/HEAD/packages-deprecated/extension-history) | `3.27.1` | `3.29.2` |\n| [@tiptap/extension-paragraph](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-paragraph) | `3.27.1` | `3.29.2` |\n| [@tiptap/extension-placeholder](https://github.com/ueberdosis/tiptap/tree/HEAD/packages-deprecated/extension-placeholder) | `3.27.1` | `3.29.2` |\n| [@tiptap/extension-text](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-text) | `3.27.1` | `3.29.2` |\n| [@tiptap/pm](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/pm) | `3.27.1` | `3.29.2` |\n| [@tiptap/react](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/react) | `3.27.1` | `3.29.2` |\n| [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) | `6.0.3` | `6.0.5` |\n| [@xyflow/react](https://github.com/xyflow/xyflow/tree/HEAD/packages/react) | `12.11.1` | `12.11.2` |\n| [immer](https://github.com/immerjs/immer) | `11.1.8` | `11.1.15` |\n| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.22.0` | `1.28.0` |\n| [monaco-editor](https://github.com/microsoft/monaco-editor) | `0.55.1` | `0.56.0` |\n| [motion](https://github.com/motiondivision/motion) | `12.42.2` | `12.43.0` |\n| [node-mocks-http](https://github.com/eugef/node-mocks-http) | `1.17.2` | `1.18.1` |\n| [playwright](https://github.com/microsoft/playwright) | `1.61.1` | `1.62.1` |\n| [react-hook-form](https://github.com/react-hook-form/react-hook-form) | `7.80.0` | `7.84.0` |\n| [recharts](https://github.com/recharts/recharts) | `3.9.1` | `3.10.1` |\n| [rich-textarea](https://github.com/inokawa/rich-textarea) | `0.27.0` | `0.27.1` |\n| [sass](https://github.com/sass/dart-sass) | `1.101.0` | `1.102.0` |\n| [shiki](https://github.com/shikijs/shiki/tree/HEAD/packages/shiki) | `4.3.0` | `4.4.1` |\n| [simple-statistics](https://github.com/simple-statistics/simple-statistics) | `7.9.2` | `7.9.3` |\n| [tsx](https://github.com/privatenumber/tsx) | `4.22.4` | `4.23.1` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.1.2` | `8.2.0` |\n| [@rollup/rollup-linux-x64-gnu](https://github.com/rollup/rollup) | `4.62.2` | `4.62.4` |\n| [tar](https://github.com/isaacs/node-tar) | `7.5.21` | `7.5.22` |\n| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.58.1` | `8.65.0` |\n| [yargs](https://github.com/yargs/yargs) | `18.0.0` | `18.1.0` |\n| [nock](https://github.com/nock/nock) | `14.0.16` | `14.0.17` |\n\nUpdates `@chakra-ui/react` from 3.36.0 to 3.36.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/chakra-ui/chakra-ui/releases\"\u003e@​chakra-ui/react's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​chakra-ui/react\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.36.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10868\"\u003e#10868\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/f32a160162ba9523f93080587df086a99ca5bfdc\"\u003e\u003ccode\u003ef32a160\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/WahabKhan7528\"\u003e\u003ccode\u003e@​WahabKhan7528\u003c/code\u003e\u003c/a\u003e! -\n\u003cstrong\u003eOverlayManager\u003c/strong\u003e: add has() method to createOverlay return\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10885\"\u003e#10885\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/e503f8d9f403b7dac71ee586857037d791e7ee8c\"\u003e\u003ccode\u003ee503f8d\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/dfedoryshchev\"\u003e\u003ccode\u003e@​dfedoryshchev\u003c/code\u003e\u003c/a\u003e! - - Bleed: Fix\nincorrect css prop application\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/129c50ff9be80fa4ad5cc0a39b6cff8a20609c42\"\u003e\u003ccode\u003e129c50f\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/segunadebayo\"\u003e\u003ccode\u003e@​segunadebayo\u003c/code\u003e\u003c/a\u003e! - Fix issue where the\nchecked ring of \u003ccode\u003eRadioCard\u003c/code\u003e and \u003ccode\u003eCheckboxCard\u003c/code\u003e (outline variant) gets clipped\nwhen a parent has \u003ccode\u003eoverflow: hidden|auto|scroll\u003c/code\u003e. The ring is now drawn with\nan inset shadow instead of an outer shadow.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10859\"\u003e#10859\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/6f102700bdf5fd4e61971db77e65f1516ce8ab38\"\u003e\u003ccode\u003e6f10270\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/dfedoryshchev\"\u003e\u003ccode\u003e@​dfedoryshchev\u003c/code\u003e\u003c/a\u003e! - - Checkmark: Fix\nincorrect css prop application\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10884\"\u003e#10884\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/e7431f1c9e05cb698492c65c6d72aca2e8c1151c\"\u003e\u003ccode\u003ee7431f1\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/sanjibani\"\u003e\u003ccode\u003e@​sanjibani\u003c/code\u003e\u003c/a\u003e! - - Docs: fix\n\u003ccode\u003eStack.Separator\u003c/code\u003e references in the v3 migration guide. The standalone\n\u003ccode\u003eSeparator\u003c/code\u003e component is now used in both the \u003ccode\u003eStackDivider\u003c/code\u003e and \u003ccode\u003eStack Props\u003c/code\u003e\nexamples.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/0fe305592d90bf943b27b7a40668e4bf1648cb29\"\u003e\u003ccode\u003e0fe3055\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/segunadebayo\"\u003e\u003ccode\u003e@​segunadebayo\u003c/code\u003e\u003c/a\u003e! - Fix error when\nmerging recipes (e.g. composing a recipe-based component through the \u003ccode\u003echakra\u003c/code\u003e\nfactory). Recipe merging now normalizes compiled and raw configs before\ncombining them, and no longer throws or mutates the source configs.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10879\"\u003e#10879\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/e882dc0e714be7d37d7a1fd93fce8ed08fe7905d\"\u003e\u003ccode\u003ee882dc0\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/dfedoryshchev\"\u003e\u003ccode\u003e@​dfedoryshchev\u003c/code\u003e\u003c/a\u003e! - - Float: Fix\nincorrect css prop application\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/2ed9026862cf1d816e981746d723256bcbd59159\"\u003e\u003ccode\u003e2ed9026\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/segunadebayo\"\u003e\u003ccode\u003e@​segunadebayo\u003c/code\u003e\u003c/a\u003e! - Add a default\n\u003ccode\u003eminSize\u003c/code\u003e of \u003ccode\u003e{ width: 240, height: 100 }\u003c/code\u003e to \u003ccode\u003eFloatingPanel.Root\u003c/code\u003e to prevent\nthe panel from being resized to zero. Pass your own \u003ccode\u003eminSize\u003c/code\u003e to override it.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10863\"\u003e#10863\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/b5de5e246bdecfeb9326c301c3cc397cc2cd676d\"\u003e\u003ccode\u003eb5de5e2\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/dfedoryshchev\"\u003e\u003ccode\u003e@​dfedoryshchev\u003c/code\u003e\u003c/a\u003e! - - Image: Fix\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/chakra-ui/chakra-ui/blob/main/packages/react/CHANGELOG.md\"\u003e@​chakra-ui/react's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.36.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10868\"\u003e#10868\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/f32a160162ba9523f93080587df086a99ca5bfdc\"\u003e\u003ccode\u003ef32a160\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/WahabKhan7528\"\u003e\u003ccode\u003e@​WahabKhan7528\u003c/code\u003e\u003c/a\u003e! -\n\u003cstrong\u003eOverlayManager\u003c/strong\u003e: add has() method to createOverlay return\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10885\"\u003e#10885\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/e503f8d9f403b7dac71ee586857037d791e7ee8c\"\u003e\u003ccode\u003ee503f8d\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/dfedoryshchev\"\u003e\u003ccode\u003e@​dfedoryshchev\u003c/code\u003e\u003c/a\u003e! - - Bleed: Fix\nincorrect css prop application\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/129c50ff9be80fa4ad5cc0a39b6cff8a20609c42\"\u003e\u003ccode\u003e129c50f\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/segunadebayo\"\u003e\u003ccode\u003e@​segunadebayo\u003c/code\u003e\u003c/a\u003e! - Fix issue where the\nchecked ring of \u003ccode\u003eRadioCard\u003c/code\u003e and \u003ccode\u003eCheckboxCard\u003c/code\u003e (outline variant) gets clipped\nwhen a parent has \u003ccode\u003eoverflow: hidden|auto|scroll\u003c/code\u003e. The ring is now drawn with\nan inset shadow instead of an outer shadow.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10859\"\u003e#10859\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/6f102700bdf5fd4e61971db77e65f1516ce8ab38\"\u003e\u003ccode\u003e6f10270\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/dfedoryshchev\"\u003e\u003ccode\u003e@​dfedoryshchev\u003c/code\u003e\u003c/a\u003e! - - Checkmark: Fix\nincorrect css prop application\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10884\"\u003e#10884\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/e7431f1c9e05cb698492c65c6d72aca2e8c1151c\"\u003e\u003ccode\u003ee7431f1\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/sanjibani\"\u003e\u003ccode\u003e@​sanjibani\u003c/code\u003e\u003c/a\u003e! - - Docs: fix\n\u003ccode\u003eStack.Separator\u003c/code\u003e references in the v3 migration guide. The standalone\n\u003ccode\u003eSeparator\u003c/code\u003e component is now used in both the \u003ccode\u003eStackDivider\u003c/code\u003e and \u003ccode\u003eStack Props\u003c/code\u003e\nexamples.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/0fe305592d90bf943b27b7a40668e4bf1648cb29\"\u003e\u003ccode\u003e0fe3055\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/segunadebayo\"\u003e\u003ccode\u003e@​segunadebayo\u003c/code\u003e\u003c/a\u003e! - Fix error when\nmerging recipes (e.g. composing a recipe-based component through the \u003ccode\u003echakra\u003c/code\u003e\nfactory). Recipe merging now normalizes compiled and raw configs before\ncombining them, and no longer throws or mutates the source configs.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10879\"\u003e#10879\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/e882dc0e714be7d37d7a1fd93fce8ed08fe7905d\"\u003e\u003ccode\u003ee882dc0\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/dfedoryshchev\"\u003e\u003ccode\u003e@​dfedoryshchev\u003c/code\u003e\u003c/a\u003e! - - Float: Fix\nincorrect css prop application\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/2ed9026862cf1d816e981746d723256bcbd59159\"\u003e\u003ccode\u003e2ed9026\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/segunadebayo\"\u003e\u003ccode\u003e@​segunadebayo\u003c/code\u003e\u003c/a\u003e! - Add a default\n\u003ccode\u003eminSize\u003c/code\u003e of \u003ccode\u003e{ width: 240, height: 100 }\u003c/code\u003e to \u003ccode\u003eFloatingPanel.Root\u003c/code\u003e to prevent\nthe panel from being resized to zero. Pass your own \u003ccode\u003eminSize\u003c/code\u003e to override it.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10863\"\u003e#10863\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/b5de5e246bdecfeb9326c301c3cc397cc2cd676d\"\u003e\u003ccode\u003eb5de5e2\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/f8133940accf0b7de1f7c9ac4aca37e9be5e2027\"\u003e\u003ccode\u003ef813394\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react/issues/10857\"\u003e#10857\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/e503f8d9f403b7dac71ee586857037d791e7ee8c\"\u003e\u003ccode\u003ee503f8d\u003c/code\u003e\u003c/a\u003e fix: correct css prop usage in Bleed component (\u003ca href=\"https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react/issues/10885\"\u003e#10885\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/0fe305592d90bf943b27b7a40668e4bf1648cb29\"\u003e\u003ccode\u003e0fe3055\u003c/code\u003e\u003c/a\u003e perf(react): cache compiled recipes and memoize variant resolution\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/e882dc0e714be7d37d7a1fd93fce8ed08fe7905d\"\u003e\u003ccode\u003ee882dc0\u003c/code\u003e\u003c/a\u003e fix: correct css prop usage in Float component (\u003ca href=\"https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react/issues/10879\"\u003e#10879\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/ff2067e7ad5f08017f7c17bf047a92f9ff2a215a\"\u003e\u003ccode\u003eff2067e\u003c/code\u003e\u003c/a\u003e fix(deps): update non-major dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/c4e79c122a6500f5f68f1c00a826c315a808d511\"\u003e\u003ccode\u003ec4e79c1\u003c/code\u003e\u003c/a\u003e fix: forward the rel attribute on LinkOverlay (\u003ca href=\"https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react/issues/10873\"\u003e#10873\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/f32a160162ba9523f93080587df086a99ca5bfdc\"\u003e\u003ccode\u003ef32a160\u003c/code\u003e\u003c/a\u003e feat(overlay): add has() method to createOverlay return (\u003ca href=\"https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react/issues/10868\"\u003e#10868\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/a1548ba60c3ad95d5b236843528e0aca30c165bc\"\u003e\u003ccode\u003ea1548ba\u003c/code\u003e\u003c/a\u003e fix: correct misspelled \u0026quot;permuations\u0026quot; variable in breakpoints (\u003ca href=\"https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react/issues/10864\"\u003e#10864\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/b5de5e246bdecfeb9326c301c3cc397cc2cd676d\"\u003e\u003ccode\u003eb5de5e2\u003c/code\u003e\u003c/a\u003e fix: correct className usage in Image component (\u003ca href=\"https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react/issues/10863\"\u003e#10863\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/6f102700bdf5fd4e61971db77e65f1516ce8ab38\"\u003e\u003ccode\u003e6f10270\u003c/code\u003e\u003c/a\u003e fix: correct css prop usage in Checkmark component (\u003ca href=\"https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react/issues/10859\"\u003e#10859\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/chakra-ui/chakra-ui/commits/@chakra-ui/react@3.36.1/packages/react\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@clickhouse/client` from 1.23.0 to 1.23.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ClickHouse/clickhouse-js/releases\"\u003e@​clickhouse/client's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eclient-1.23.1\u003c/h2\u003e\n\u003ch2\u003eBug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRe-export \u003ccode\u003eEXCEPTION_TAG_HEADER_NAME\u003c/code\u003e and \u003ccode\u003eextractErrorAtTheEndOfChunk\u003c/code\u003e from \u003ccode\u003e@clickhouse/client\u003c/code\u003e. Both are part of the (now deprecated) \u003ccode\u003e@clickhouse/client-common\u003c/code\u003e public API but were missed when its surface was bundled into and re-exported from the client packages in 1.23.0 (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/845\"\u003e#845\u003c/a\u003e). Reported downstream by Langfuse. (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/935\"\u003e#935\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/935\"\u003e#935\u003c/a\u003e: \u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/pull/935\"\u003eClickHouse/clickhouse-js#935\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/845\"\u003e#845\u003c/a\u003e: \u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/pull/845\"\u003eClickHouse/clickhouse-js#845\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eclient-web-1.23.1\u003c/h2\u003e\n\u003ch2\u003eBug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRe-export \u003ccode\u003eEXCEPTION_TAG_HEADER_NAME\u003c/code\u003e and \u003ccode\u003eextractErrorAtTheEndOfChunk\u003c/code\u003e from \u003ccode\u003e@clickhouse/client-web\u003c/code\u003e. Both are part of the (now deprecated) \u003ccode\u003e@clickhouse/client-common\u003c/code\u003e public API but were missed when its surface was bundled into and re-exported from the client packages in 1.23.0 (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/845\"\u003e#845\u003c/a\u003e). Reported downstream by Langfuse. (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/935\"\u003e#935\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/935\"\u003e#935\u003c/a\u003e: \u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/pull/935\"\u003eClickHouse/clickhouse-js#935\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/845\"\u003e#845\u003c/a\u003e: \u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/pull/845\"\u003eClickHouse/clickhouse-js#845\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ClickHouse/clickhouse-js/blob/main/CHANGELOG.md\"\u003e@​clickhouse/client's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\n\u003cstrong\u003eThis repository-wide changelog is frozen.\u003c/strong\u003e New entries now live in each\npackage's own \u003ccode\u003eCHANGELOG.md\u003c/code\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@clickhouse/client\u003c/code\u003e → \u003ca href=\"https://github.com/ClickHouse/clickhouse-js/blob/main/packages/client-node/CHANGELOG.md\"\u003e\u003ccode\u003ehttps://github.com/ClickHouse/clickhouse-js/blob/main/packages/client-node/CHANGELOG.md\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@clickhouse/client-web\u003c/code\u003e → \u003ca href=\"https://github.com/ClickHouse/clickhouse-js/blob/main/packages/client-web/CHANGELOG.md\"\u003e\u003ccode\u003ehttps://github.com/ClickHouse/clickhouse-js/blob/main/packages/client-web/CHANGELOG.md\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@clickhouse/client-common\u003c/code\u003e (deprecated) → \u003ca href=\"https://github.com/ClickHouse/clickhouse-js/blob/main/packages/client-common/CHANGELOG.md\"\u003e\u003ccode\u003ehttps://github.com/ClickHouse/clickhouse-js/blob/main/packages/client-common/CHANGELOG.md\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@clickhouse/datatype-parser\u003c/code\u003e → \u003ca href=\"https://github.com/ClickHouse/clickhouse-js/blob/main/packages/datatype-parser/CHANGELOG.md\"\u003e\u003ccode\u003ehttps://github.com/ClickHouse/clickhouse-js/blob/main/packages/datatype-parser/CHANGELOG.md\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@clickhouse/rowbinary\u003c/code\u003e → \u003ca href=\"https://github.com/ClickHouse/clickhouse-js/blob/main/skills/clickhouse-js-node-rowbinary-parser/CHANGELOG.md\"\u003e\u003ccode\u003ehttps://github.com/ClickHouse/clickhouse-js/blob/main/skills/clickhouse-js-node-rowbinary-parser/CHANGELOG.md\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe history below (through \u003ccode\u003e@clickhouse/client\u003c/code\u003e 1.23.0) is retained for\nreference and was copied as-is into each client package's changelog as the\nstarting point for the split.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/f67717b944dd4b0451468602cdad9bd3ecad7dd8\"\u003e\u003ccode\u003ef67717b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/941\"\u003e#941\u003c/a\u003e from ClickHouse/main\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/3bccc8139f96a38a80c0cc27d8e22d4820be6181\"\u003e\u003ccode\u003e3bccc81\u003c/code\u003e\u003c/a\u003e chore: bump \u003ccode\u003e@​clickhouse/client-web\u003c/code\u003e version to 1.23.1 (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/940\"\u003e#940\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/cc9383c9576f23fbdb7914f3d01c5c4ef03899d1\"\u003e\u003ccode\u003ecc9383c\u003c/code\u003e\u003c/a\u003e chore: bump \u003ccode\u003e@​clickhouse/client\u003c/code\u003e version to 1.23.1 (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/939\"\u003e#939\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/8415878d0cdd86c3b39bdd635b194108e1a0df07\"\u003e\u003ccode\u003e8415878\u003c/code\u003e\u003c/a\u003e fix(ci): lockfile-age-audit — request full packument so time is present (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/888\"\u003e#888\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/71b2e8a1ac80dacd75b11927926140754e1e64b7\"\u003e\u003ccode\u003e71b2e8a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/936\"\u003e#936\u003c/a\u003e from ClickHouse/main\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/a417d5c051ba5768bc2cc2cbdadff0e14a41e1b6\"\u003e\u003ccode\u003ea417d5c\u003c/code\u003e\u003c/a\u003e fix(client): re-export EXCEPTION_TAG_HEADER_NAME and extractErrorAtTheEndOfCh...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/305030d9714aca93e9b5f7e128408d7e41867bd0\"\u003e\u003ccode\u003e305030d\u003c/code\u003e\u003c/a\u003e Separate per-package READMEs and stop prepack from overwriting them (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/934\"\u003e#934\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/8c51d9a12e67e82ef431e8158d5b77ce26e40e3a\"\u003e\u003ccode\u003e8c51d9a\u003c/code\u003e\u003c/a\u003e ci: run RowBinary skill benchmarks on a live ClickHouse (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/933\"\u003e#933\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/199f99460ab2fda2c87544bd4a7dad8e7509f60f\"\u003e\u003ccode\u003e199f994\u003c/code\u003e\u003c/a\u003e Embed Vitest configs into client packages; run common tests from node/web (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/931\"\u003e#931\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/ed25b25893241eda007bf4412dee16f0d650de1a\"\u003e\u003ccode\u003eed25b25\u003c/code\u003e\u003c/a\u003e Run web Vitest browser tests headless by default (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/930\"\u003e#930\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/ClickHouse/clickhouse-js/compare/client-1.23.0...client-1.23.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@hono/node-server` from 2.0.10 to 2.0.12\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/honojs/node-server/releases\"\u003e@​hono/node-server's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.0.12\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etest: replace supertest by \u003ca href=\"https://github.com/BlankParticle\"\u003e\u003ccode\u003e@​BlankParticle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/379\"\u003ehonojs/node-server#379\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(response): copy headers when init is a foreign Response by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/382\"\u003ehonojs/node-server#382\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v2.0.11...v2.0.12\"\u003ehttps://github.com/honojs/node-server/compare/v2.0.11...v2.0.12\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.0.11\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etest: use a custom helper for path traversal tests by \u003ca href=\"https://github.com/BlankParticle\"\u003e\u003ccode\u003e@​BlankParticle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/377\"\u003ehonojs/node-server#377\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf(request): fast-path QUERY methods by \u003ca href=\"https://github.com/usualoma\"\u003e\u003ccode\u003e@​usualoma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/376\"\u003ehonojs/node-server#376\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf(request): fast-path PATCH method by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/380\"\u003ehonojs/node-server#380\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v2.0.10...v2.0.11\"\u003ehttps://github.com/honojs/node-server/compare/v2.0.10...v2.0.11\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/a813b6cdaa15baac3ead84e9e6ed5b72b2353c96\"\u003e\u003ccode\u003ea813b6c\u003c/code\u003e\u003c/a\u003e 2.0.12\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/caf48bafd4638bac5c338166b8858b72bcf79257\"\u003e\u003ccode\u003ecaf48ba\u003c/code\u003e\u003c/a\u003e fix(response): copy headers when init is a foreign Response (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/382\"\u003e#382\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/3b1dd6875812e0b5aee43ec3fac66c191fd6251f\"\u003e\u003ccode\u003e3b1dd68\u003c/code\u003e\u003c/a\u003e test: replace supertest (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/379\"\u003e#379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/834e54f15cf12b80cf82823c845b2bab41056cf0\"\u003e\u003ccode\u003e834e54f\u003c/code\u003e\u003c/a\u003e 2.0.11\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/ba72bcd8c563fbe1e9678e7ef27794a0aa4a6158\"\u003e\u003ccode\u003eba72bcd\u003c/code\u003e\u003c/a\u003e perf(request): fast-path PATCH method (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/380\"\u003e#380\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/962baa463879da394008f27510d68dc90b640e99\"\u003e\u003ccode\u003e962baa4\u003c/code\u003e\u003c/a\u003e perf(request): fast-path QUERY methods (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/376\"\u003e#376\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/62284d659380cb0354510d0359c160c8d970764d\"\u003e\u003ccode\u003e62284d6\u003c/code\u003e\u003c/a\u003e test: use a custom helper for path traversal tests (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/377\"\u003e#377\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/honojs/node-server/compare/v2.0.10...v2.0.12\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@modelcontextprotocol/sdk` from 1.29.0 to 1.30.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/releases\"\u003e@​modelcontextprotocol/sdk's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.30.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(server): prioritize zod issues and format them by \u003ca href=\"https://github.com/mozmo15\"\u003e\u003ccode\u003e@​mozmo15\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1503\"\u003emodelcontextprotocol/typescript-sdk#1503\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(ci): switch publish to OIDC trusted publishing by \u003ca href=\"https://github.com/felixweinberger\"\u003e\u003ccode\u003e@​felixweinberger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1839\"\u003emodelcontextprotocol/typescript-sdk#1839\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd end-to-end test suite by \u003ca href=\"https://github.com/felixweinberger\"\u003e\u003ccode\u003e@​felixweinberger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2167\"\u003emodelcontextprotocol/typescript-sdk#2167\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ev1 stdio buffer limit by \u003ca href=\"https://github.com/KKonstantinov\"\u003e\u003ccode\u003e@​KKonstantinov\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2239\"\u003emodelcontextprotocol/typescript-sdk#2239\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: support Zod 3.25 method literals by \u003ca href=\"https://github.com/mattzcarey\"\u003e\u003ccode\u003e@​mattzcarey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2368\"\u003emodelcontextprotocol/typescript-sdk#2368\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eValidate Content-Type by parsed media type instead of substring match (v1.x) by \u003ca href=\"https://github.com/felixweinberger\"\u003e\u003ccode\u003e@​felixweinberger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2444\"\u003emodelcontextprotocol/typescript-sdk#2444\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: send SSE keep-alive comment frames from Streamable HTTP server transport (v1.x) by \u003ca href=\"https://github.com/mattzcarey\"\u003e\u003ccode\u003e@​mattzcarey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2538\"\u003emodelcontextprotocol/typescript-sdk#2538\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(deps): widen \u003ccode\u003e@​hono/node-server\u003c/code\u003e past GHSA-frvp-7c67-39w9 by \u003ca href=\"https://github.com/arimu1\"\u003e\u003ccode\u003e@​arimu1\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2549\"\u003emodelcontextprotocol/typescript-sdk#2549\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix SSE keep-alive timer lifecycle in Streamable HTTP server transport (v1.x) by \u003ca href=\"https://github.com/felixweinberger\"\u003e\u003ccode\u003e@​felixweinberger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2547\"\u003emodelcontextprotocol/typescript-sdk#2547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump version to 1.30.0 by \u003ca href=\"https://github.com/felixweinberger\"\u003e\u003ccode\u003e@​felixweinberger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2563\"\u003emodelcontextprotocol/typescript-sdk#2563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mozmo15\"\u003e\u003ccode\u003e@​mozmo15\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1503\"\u003emodelcontextprotocol/typescript-sdk#1503\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/arimu1\"\u003e\u003ccode\u003e@​arimu1\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2549\"\u003emodelcontextprotocol/typescript-sdk#2549\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.29.0...1.30.0\"\u003ehttps://github.com/modelcontextprotocol/typescript-sdk/compare/v1.29.0...1.30.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/2d889f2b329e46680ec9bdd565de4616c497825a\"\u003e\u003ccode\u003e2d889f2\u003c/code\u003e\u003c/a\u003e chore: bump version to 1.30.0 (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/2563\"\u003e#2563\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/e3f3daa12cc2603919939b72136ce9d9e800b868\"\u003e\u003ccode\u003ee3f3daa\u003c/code\u003e\u003c/a\u003e Fix SSE keep-alive timer lifecycle in Streamable HTTP server transport (v1.x)...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/bb5a718cbf90796bacbf62218b359196d210426b\"\u003e\u003ccode\u003ebb5a718\u003c/code\u003e\u003c/a\u003e fix(deps): widen \u003ccode\u003e@​hono/node-server\u003c/code\u003e past GHSA-frvp-7c67-39w9 (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/2549\"\u003e#2549\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/1dad2634ce5799fb386283d14291d1b4935a9a52\"\u003e\u003ccode\u003e1dad263\u003c/code\u003e\u003c/a\u003e fix: send SSE keep-alive comment frames from Streamable HTTP server transport...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/69749aa5081ddfe675d36da8d96c7e27d83742b8\"\u003e\u003ccode\u003e69749aa\u003c/code\u003e\u003c/a\u003e Validate Content-Type by parsed media type instead of substring match (v1.x) ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/369513df7b0e9d8a979c86f68ba1930e0d5f27f0\"\u003e\u003ccode\u003e369513d\u003c/code\u003e\u003c/a\u003e fix: support Zod 3.25 method literals (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/2368\"\u003e#2368\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/e7ee57c2f33b8290a78a3cefa27ab635fe67fbff\"\u003e\u003ccode\u003ee7ee57c\u003c/code\u003e\u003c/a\u003e v1 stdio buffer limit (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/2239\"\u003e#2239\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/c36e1ef5bb3b07b0c23fc6d28d4a6b56ebdd9512\"\u003e\u003ccode\u003ec36e1ef\u003c/code\u003e\u003c/a\u003e Add end-to-end test suite (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/2167\"\u003e#2167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/bf1e022bd219f678b3865093d58595c6c8a67f1a\"\u003e\u003ccode\u003ebf1e022\u003c/code\u003e\u003c/a\u003e chore(ci): switch publish to OIDC trusted publishing (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1839\"\u003e#1839\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/9edbab7a09f31a288a27df3220edbebff45dbb6c\"\u003e\u003ccode\u003e9edbab7\u003c/code\u003e\u003c/a\u003e fix(server): prioritize zod issues and format them (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1503\"\u003e#1503\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.29.0...1.30.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​modelcontextprotocol/sdk\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@react-email/render` from 2.0.9 to 2.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/resend/react-email/releases\"\u003e@​react-email/render's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​react-email/render\u003c/code\u003e\u003ca href=\"https://github.com/2\"\u003e\u003ccode\u003e@​2\u003c/code\u003e\u003c/a\u003e.1.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eba96cfa: introduce new \u003ccode\u003eunstableToPlainText\u003c/code\u003e and \u003ccode\u003eunstableTextConversion\u003c/code\u003e that sidesteps html-to-text\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e58d8c08: feat: add \u003ccode\u003edata-text-format=\u0026quot;dataTable\u0026quot;\u003c/code\u003e to render tables as aligned columns in plain text\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ccode\u003e@​react-email/render\u003c/code\u003e\u003ca href=\"https://github.com/2\"\u003e\u003ccode\u003e@​2\u003c/code\u003e\u003c/a\u003e.0.10\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ec300cfb: Strip React's auto-injected \u003ccode\u003e\u0026lt;link rel=\u0026quot;preload\u0026quot; as=\u0026quot;image\u0026quot;\u0026gt;\u003c/code\u003e resource hints from rendered email HTML. React adds one to the document \u003ccode\u003e\u0026lt;head\u0026gt;\u003c/code\u003e for every \u003ccode\u003e\u0026lt;img\u0026gt;\u003c/code\u003e during SSR, but email clients ignore preload hints, so they were just noise in the output. Other \u003ccode\u003e\u0026lt;link\u0026gt;\u003c/code\u003e tags (stylesheets, fonts, user-authored non-image preloads) are left untouched.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/resend/react-email/blob/canary/packages/render/CHANGELOG.md\"\u003e@​react-email/render's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.1.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eba96cfa: introduce new \u003ccode\u003eunstableToPlainText\u003c/code\u003e and \u003ccode\u003eunstableTextConversion\u003c/code\u003e that sidesteps html-to-text\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e58d8c08: feat: add \u003ccode\u003edata-text-format=\u0026quot;dataTable\u0026quot;\u003c/code\u003e to render tables as aligned columns in plain text\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.0.10\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ec300cfb: Strip React's auto-injected \u003ccode\u003e\u0026lt;link rel=\u0026quot;preload\u0026quot; as=\u0026quot;image\u0026quot;\u0026gt;\u003c/code\u003e resource hints from rendered email HTML. React adds one to the document \u003ccode\u003e\u0026lt;head\u0026gt;\u003c/code\u003e for every \u003ccode\u003e\u0026lt;img\u0026gt;\u003c/code\u003e during SSR, but email clients ignore preload hints, so they were just noise in the output. Other \u003ccode\u003e\u0026lt;link\u0026gt;\u003c/code\u003e tags (stylesheets, fonts, user-authored non-image preloads) are left untouched.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/resend/react-email/commit/a8ccfeca4cf99dff7bbb13e6a067c4b4d0e141a1\"\u003e\u003ccode\u003ea8ccfec\u003c/code\u003e\u003c/a\u003e chore(root): version packages (\u003ca href=\"https://github.com/resend/react-email/tree/HEAD/packages/render/issues/3640\"\u003e#3640\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/resend/react-email/commit/ba96cfa29bd45fafd364d936b8ad3fe510deb84c\"\u003e\u003ccode\u003eba96cfa\u003c/code\u003e\u003c/a\u003e feat(render): new \u003ccode\u003eunstableToPlainText\u003c/code\u003e and \u003ccode\u003eunstableTextConversion\u003c/code\u003e (\u003ca href=\"https://github.com/resend/react-email/tree/HEAD/packages/render/issues/3639\"\u003e#3639\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/resend/react-email/commit/58d8c086ef167e3c4c5ad49c6f799e2a25c80aa9\"\u003e\u003ccode\u003e58d8c08\u003c/code\u003e\u003c/a\u003e feat(render): data-text-format attribute for each html-to-text format (\u003ca href=\"https://github.com/resend/react-email/tree/HEAD/packages/render/issues/2596\"\u003e#2596\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/resend/react-email/commit/ee88bec4679eec7985f9af37f7a6aa9772623c1a\"\u003e\u003ccode\u003eee88bec\u003c/code\u003e\u003c/a\u003e fix(render): resolve implicit TypeScript type errors in pretty util (\u003ca href=\"https://github.com/resend/react-email/tree/HEAD/packages/render/issues/3616\"\u003e#3616\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/resend/react-email/commit/7792c3dbaf39d16a3d1c60841cda5f5c2ea6bfc5\"\u003e\u003ccode\u003e7792c3d\u003c/code\u003e\u003c/a\u003e chore(root): version packages (\u003ca href=\"https://github.com/resend/react-email/tree/HEAD/packages/render/issues/3615\"\u003e#3615\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/resend/react-email/commit/c300cfb2767a87d86e38104bd7a72252acccdd5b\"\u003e\u003ccode\u003ec300cfb\u003c/code\u003e\u003c/a\u003e fix(render): strip auto-injected image preload links from rendered HTML (\u003ca href=\"https://github.com/resend/react-email/tree/HEAD/packages/render/issues/3577\"\u003e#3577\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/resend/react-email/commits/@react-email/render@2.1.0/packages/render\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@smithy/node-http-handler` from 4.9.12 to 4.9.13\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/smithy-lang/smithy-typescript/releases\"\u003e@​smithy/node-http-handler's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​smithy/node-http-handler\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.9.13\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [fcf1366]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​smithy/core\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.31.1\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/smithy-lang/smithy-typescript/blob/main/packages/node-http-handler/CHANGELOG.md\"\u003e@​smithy/node-http-handler's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.9.13\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [fcf1366]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​smithy/core\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.31.1\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smithy-lang/smithy-typescript/commit/bcff71dba309446910f7a23b050350d3be77200d\"\u003e\u003ccode\u003ebcff71d\u003c/code\u003e\u003c/a\u003e Version NPM packages (\u003ca href=\"https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/node-http-handler/issues/2193\"\u003e#2193\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/smithy-lang/smithy-typescript/commits/@smithy/node-http-handler@4.9.13/packages/node-http-handler\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `better-auth` from 1.6.23 to 1.6.25\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/better-auth/better-auth/releases\"\u003ebetter-auth's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.6.25\u003c/h2\u003e\n\u003ch2\u003e\u003ccode\u003ebetter-auth\u003c/code\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Apple OAuth not sending the PKCE code challenge during authorization, causing token exchange failures (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10294\"\u003e#10294\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed Google One Tap creating new users when sign-up was disabled on the Google provider (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10479\"\u003e#10479\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e$fetch\u003c/code\u003e and \u003ccode\u003e$store\u003c/code\u003e not being exposed on the Solid client (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10444\"\u003e#10444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed internal adapter queries being routed to the wrong table when a built-in table's \u003ccode\u003emodelName\u003c/code\u003e was set to another table's schema key (e.g. \u003ccode\u003euser.modelName = \u0026quot;account\u0026quot;\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFor detailed changes, see \u003ca href=\"https://github.com/better-auth/better-auth/blob/07a646ea190167370fbbb60a0fa2c3be3bec5522/packages/better-auth/CHANGELOG.md\"\u003e\u003ccode\u003eCHANGELOG\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eContributors\u003c/h2\u003e\n\u003cp\u003eThanks to everyone who contributed to this release:\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/birkskyum\"\u003e\u003ccode\u003e@​birkskyum\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/jsj\"\u003e\u003ccode\u003e@​jsj\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/krish-vachhani\"\u003e\u003ccode\u003e@​krish-vachhani\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/better-auth/better-auth/compare/v1.6.24...v1.6.25\"\u003e\u003ccode\u003ev1.6.24...v1.6.25\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.6.24\u003c/h2\u003e\n\u003ch2\u003e\u003ccode\u003ebetter-auth\u003c/code\u003e\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded request context (\u003ccode\u003ectx\u003c/code\u003e) as a third argument to \u003ccode\u003everifyIdToken\u003c/code\u003e, enabling custom ID token verifiers to read request headers (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10376\"\u003e#10376\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003ebeforeStoreCookie\u003c/code\u003e option to the last-login-method plugin for GDPR compliance (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/5753\"\u003e#5753\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReplaced flaky MongoDB where-coercion integration test with a direct unit test for more reliable test runs (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10369\"\u003e#10369\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed the \u003ccode\u003eget-session\u003c/code\u003e endpoint to include \u003ccode\u003eno-store\u003c/code\u003e cache control headers, preventing stale session data from being served (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10222\"\u003e#10222\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed SQLite migration diffs to recognize \u003ccode\u003eBIGINT\u003c/code\u003e as a valid number type, preventing spurious pending changes on rate limiter columns (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10316\"\u003e#10316\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed auth requests failing when request cloning throws an error inside verification callbacks (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10336\"\u003e#10336\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003euseSession({ throw: true })\u003c/code\u003e incorrectly excluding \u003ccode\u003enull\u003c/code\u003e from its \u003ccode\u003edata\u003c/code\u003e type (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/9787\"\u003e#9787\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed auth query revalidation and signal listeners not being restored after a client component remounts (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10379\"\u003e#10379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed the \u003ccode\u003eCookieAttributes\u003c/code\u003e index signature type to be more precise (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10442\"\u003e#10442\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed silent misrouting of adapter queries when \u003ccode\u003euser.modelName\u003c/code\u003e was set to a value that collides with another schema key (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10235\"\u003e#10235\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed Kysely migration generation producing duplicate indexes for fields marked both \u003ccode\u003eunique\u003c/code\u003e and \u003ccode\u003eindex\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10357\"\u003e#10357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed magic-link and email-OTP send endpoints to validate the \u003ccode\u003eOrigin\u003c/code\u003e header on cookieless requests, preventing cross-origin abuse (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10368\"\u003e#10368\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed remote MCP auth 401 challenge headers being hidden from browser clients due to missing CORS exposure (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10290\"\u003e#10290\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed OpenAPI schema to include plugin user fields (such as \u003ccode\u003eusername\u003c/code\u003e and \u003ccode\u003edisplayUsername\u003c/code\u003e) in \u003ccode\u003e/sign-up/email\u003c/code\u003e and \u003ccode\u003e/update-user\u003c/code\u003e request bodies (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10453\"\u003e#10453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eorganization.listMembers\u003c/code\u003e failing with \u0026quot;User not found for member\u0026quot; for organizations with more than ~100 members (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10342\"\u003e#10342\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed organization invitations to use database-generated IDs when \u003ccode\u003eadvanced.database.generateId\u003c/code\u003e is configured, matching the behavior of other models (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10040\"\u003e#10040\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003egetDefaultModelName\u003c/code\u003e to prefer exact schema key matches over \u003ccode\u003emodelName\u003c/code\u003e aliases, preventing adapter queries from being misrouted when a built-in table's name collides with another schema key\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFor detailed changes, see \u003ca href=\"https://github.com/better-auth/better-auth/blob/9a661c7b7abceaa81123b2c56757ee24f3ad2ed6/packages/better-auth/CHANGELOG.md\"\u003e\u003ccode\u003eCHANGELOG\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003eauth\u003c/code\u003e\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md\"\u003ebetter-auth's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.6.25\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10479\"\u003e#10479\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/5124c3487903e96223bb3f54347724bb0204bb95\"\u003e\u003ccode\u003e5124c34\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/krish-vachhani\"\u003e\u003ccode\u003e@​krish-vachhani\u003c/code\u003e\u003c/a\u003e! - Prevent Google One Tap from creating new users when sign-up is disabled for the Google provider.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10444\"\u003e#10444\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/743935991f9991e8243d6c3d14773b9cfca462e8\"\u003e\u003ccode\u003e7439359\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/birkskyum\"\u003e\u003ccode\u003e@​birkskyum\u003c/code\u003e\u003c/a\u003e! - Expose the real \u003ccode\u003e$fetch\u003c/code\u003e instance and \u003ccode\u003e$store\u003c/code\u003e atoms from the Solid client instead of resolving them as dynamic API routes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies [\u003ca href=\"https://github.com/better-auth/better-auth/commit/0ffd1fb28d44a8266d62791cd4c97e263444d03b\"\u003e\u003ccode\u003e0ffd1fb\u003c/code\u003e\u003c/a\u003e]:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​better-auth/core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.6.25\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​better-auth/drizzle-adapter\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.6.25\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​better-auth/kysely-adapter\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.6.25\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​better-auth/memory-adapter\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.6.25\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​better-auth/mongo-adapter\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.6.25\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​better-auth/prisma-adapter\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.6.25\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​better-auth/telemetry\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.6.25\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.6.24\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10235\"\u003e#10235\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/03dc5a046f536994950800ea557b8e2e2e0cdfdd\"\u003e\u003ccode\u003e03dc5a0\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ping-maxwell\"\u003e\u003ccode\u003e@​ping-maxwell\u003c/code\u003e\u003c/a\u003e! - Fixes silent foreign-key and adapter-join misrouting when a user remaps a built-in model name to a string that collides with another schema key\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10357\"\u003e#10357\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/750894037639c4158472cc1d4994b0e07bf1f59a\"\u003e\u003ccode\u003e7508940\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/c-nicol\"\u003e\u003ccode\u003e@​c-nicol\u003c/code\u003e\u003c/a\u003e! - Fixes Kysely migration generation for new-table fields that are both unique: true and index: true.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10342\"\u003e#10342\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/bae71988ab79aeb4f19f245ceabac9eca8706a50\"\u003e\u003ccode\u003ebae7198\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ping-maxwell\"\u003e\u003ccode\u003e@​ping-maxwell\u003c/code\u003e\u003c/a\u003e! - Fix \u003ccode\u003eorganization.listMembers\u003c/code\u003e failing with \u0026quot;User not found for member\u0026quot; for orgs with more than ~100 members by applying the same membership limit to the users query.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10336\"\u003e#10336\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/ef4d27360cec8a0bc11a94e135ea4a3dd32b1969\"\u003e\u003ccode\u003eef4d273\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Tushar-Khandelwal-2004\"\u003e\u003ccode\u003e@​Tushar-Khandelwal-2004\u003c/code\u003e\u003c/a\u003e! - Prevent verification callbacks from failing auth requests when cloning the request throws.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10333\"\u003e#10333\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/99dbdd7ea98740d11689394220a718dfb9579276\"\u003e\u003ccode\u003e99dbdd7\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/c-nicol\"\u003e\u003ccode\u003e@​c-nicol\u003c/code\u003e\u003c/a\u003e! - Fixes Drizzle schema generation for fields that are both unique: true and index: true.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10368\"\u003e#10368\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/086ca91f51dd8158aff6cbf54c4f9c7ce220914d\"\u003e\u003ccode\u003e086ca91\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/gaurav0107\"\u003e\u003ccode\u003e@​gaurav0107\u003c/code\u003e\u003c/a\u003e! - Force-validate the request \u003ccode\u003eOrigin\u003c/code\u003e on the magic-link (\u003ccode\u003e/sign-in/magic-link\u003c/code\u003e) and email-otp (\u003ccode\u003e/email-otp/send-verification-otp\u003c/code\u003e) send endpoints, including cookieless requests, to match the built-in \u003ccode\u003e/sign-in/email\u003c/code\u003e and \u003ccode\u003e/sign-up/email\u003c/code\u003e routes. A cookieless cross-origin POST can no longer trigger a magic-link or verification-OTP email to an arbitrary address. Cookieless requests that carry no \u003ccode\u003eOrigin\u003c/code\u003e (server-to-server) are unaffected.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10290\"\u003e#10290\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/8f2dedd89301da9fb52c1a64df6a9683f9be55fd\"\u003e\u003ccode\u003e8f2dedd\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/GautamBytes\"\u003e\u003ccode\u003e@​GautamBytes\u003c/code\u003e\u003c/a\u003e! - Expose the remote MCP auth client's 401 challenge headers to browser clients using CORS.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10453\"\u003e#10453\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/4e685eef420b5576913b9803b58c7e7ee7342203\"\u003e\u003ccode\u003e4e685ee\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ping-maxwell\"\u003e\u003ccode\u003e@​ping-maxwell\u003c/code\u003e\u003c/a\u003e! - OpenAPI now includes \u003ccode\u003euser.additionalFields\u003c/code\u003e and plugin user schema fields (e.g. username plugin \u003ccode\u003eusername\u003c/code\u003e / \u003ccode\u003edisplayUsername\u003c/code\u003e) on \u003ccode\u003e/sign-up/email\u003c/code\u003e and \u003ccode\u003e/update-user\u003c/code\u003e request bodies.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10190\"\u003e#10190\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/3bf0e4981e025ba9af684013a27b0102a04f7c56\"\u003e\u003ccode\u003e3bf0e49\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/gaurav-init\"\u003e\u003ccode\u003e@​gaurav-init\u003c/code\u003e\u003c/a\u003e! - Pass the endpoint context as the second argument to \u003ccode\u003ebeforeDeleteOrganization\u003c/code\u003e and \u003ccode\u003eafterDeleteOrganization\u003c/code\u003e hooks in the organization plugin, matching the signature shown in the docs and the existing \u003ccode\u003edatabaseHooks\u003c/code\u003e pattern. The Stripe plugin's \u003ccode\u003ebeforeDeleteOrganization\u003c/code\u003e wrapper now forwards the context to user-supplied hooks instead of dropping it.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10040\"\u003e#10040\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/f59a0ee7895a024ddd4c5c387344173888e17be4\"\u003e\u003ccode\u003ef59a0ee\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/shiminshen\"\u003e\u003ccode\u003e@​shiminshen\u003c/code\u003e\u003c/a\u003e! - Organization invitations now let the database generate their \u003ccode\u003eid\u003c/code\u003e when ID generation is delegated to the database (e.g. \u003ccode\u003eadvanced.database.generateId: \u0026quot;uuid\u0026quot;\u003c/code\u003e with a UUID-capable adapter such as Postgres), matching every other model. Previously \u003ccode\u003ecreateInvitation\u003c/code\u003e always generated the invitation \u003ccode\u003eid\u003c/code\u003e in application code, so invitation rows received an app-generated value instead of a database-generated one while organizations, members and teams correctly deferred to the database (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/issues/10024\"\u003ebetter-auth/better-auth#10024\u003c/a\u003e). A caller-provided id (e.g. via \u003ccode\u003ebeforeCreateInvitation\u003c/code\u003e) is still honored.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10302\"\u003e#10302\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/0f2cc1b33b77850948dac4d889e5f46bba41e8d5\"\u003e\u003ccode\u003e0f2cc1b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/momomuchu\"\u003e\u003ccode\u003e@​momomuchu\u003c/code\u003e\u003c/a\u003e! - Prefer exact schema-key matches over \u003ccode\u003emodelName\u003c/code\u003e aliases in \u003ccode\u003egetDefaultModelName\u003c/code\u003e, so remapping a built-in table onto another table's schema key (e.g. \u003ccode\u003euser.modelName = \u0026quot;account\u0026quot;\u003c/code\u003e) does not reroute internal adapter queries to the wrong table.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/9787\"\u003e#9787\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/ae781091186f321b4e4ec9e84f64b6e4d5ea1043\"\u003e\u003ccode\u003eae78109\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ping-maxwell\"\u003e\u003ccode\u003e@​ping-maxwell\u003c/code\u003e\u003c/a\u003e! - Fixes an issue where \u003ccode\u003euseSession({ throw: true })\u003c/code\u003e incorrectly excluded \u003ccode\u003enull\u003c/code\u003e from its \u003ccode\u003edata\u003c/code\u003e type.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10222\"\u003e#10222\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/46d2bf02c98902da7b344753372d48cfe0e5ebb3\"\u003e\u003ccode\u003e46d2bf0\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ping-maxwell\"\u003e\u003ccode\u003e@​ping-maxwell\u003c/code\u003e\u003c/a\u003e! - fix: add no-store cache-control headers to get-session route\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10316\"\u003e#10316\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/29a373eaf1778820061a9380c29831c2de2ce704\"\u003e\u003ccode\u003e29a373e\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/vinay-oppuri\"\u003e\u003ccode\u003e@​vinay-oppuri\u003c/code\u003e\u003c/a\u003e! - Recognize SQLite \u003ccode\u003eBIGINT\u003c/code\u003e as a valid number type in migration diffs so database-backed rate limiter columns like \u003ccode\u003elastRequest\u003c/code\u003e no longer report spurious pending changes on every run.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10379\"\u003e#10379\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/f6d18fa8f79b9323e10b50f72e2b1a088844e4bb\"\u003e\u003ccode\u003ef6d18fa\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ping-maxwell\"\u003e\u003ccode\u003e@​ping-maxwell\u003c/code\u003e\u003c/a\u003e! - fix(client): restore auth query revalidation and signal listeners after remount\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/07a646ea190167370fbbb60a0fa2c3be3bec5522\"\u003e\u003ccode\u003e07a646e\u003c/code\u003e\u003c/a\u003e chore: release v1.6.25 (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10491\"\u003e#10491\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/743935991f9991e8243d6c3d14773b9cfca462e8\"\u003e\u003ccode\u003e7439359\u003c/code\u003e\u003c/a\u003e fix(solid): expose $fetch and $store on the solid client (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10444\"\u003e#10444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/dac701c94bcd777e7cb124570d644f8b4a7981a5\"\u003e\u003ccode\u003edac701c\u003c/code\u003e\u003c/a\u003e chore(deps): bump next from 16.2.6 to 16.2.11 (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10493\"\u003e#10493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/5124c3487903e96223bb3f54347724bb0204bb95\"\u003e\u003ccode\u003e5124c34\u003c/code\u003e\u003c/a\u003e fix(one-tap): enforce google provider signup restrictions (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10479\"\u003e#10479\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/9a661c7b7abceaa81123b2c56757ee24f3ad2ed6\"\u003e\u003ccode\u003e9a661c7\u003c/code\u003e\u003c/a\u003e chore: release v1.6.24 (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10323\"\u003e#10323\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/4e685eef420b5576913b9803b58c7e7ee7342203\"\u003e\u003ccode\u003e4e685ee\u003c/code\u003e\u003c/a\u003e fix(open-api): include plugin user fields on sign-up/update bodies (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10453\"\u003e#10453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/d3ce7823324ba64efd423895b1c122d85c6d7663\"\u003e\u003ccode\u003ed3ce782\u003c/code\u003e\u003c/a\u003e fix(cookies): tighten CookieAttributes index signature type (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10441\"\u003e#10441\u003c/a\u003e) (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10442\"\u003e#10442\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/ae781091186f321b4e4ec9e84f64b6e4d5ea1043\"\u003e\u003ccode\u003eae78109\u003c/code\u003e\u003c/a\u003e fix(client): preserve null in useSession().data type with throw:true (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/9787\"\u003e#9787\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/f6d18fa8f79b9323e10b50f72e2b1a088844e4bb\"\u003e\u003ccode\u003ef6d18fa\u003c/code\u003e\u003c/a\u003e fix(client): restore auth query lifecycle after remount (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10379\"\u003e#10379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/086ca91f51dd8158aff6cbf54c4f9c7ce220914d\"\u003e\u003ccode\u003e086ca91\u003c/code\u003e\u003c/a\u003e fix(magic-link, email-otp): force-validate Origin on cookieless send endpoint...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/better-auth/better-auth/commits/v1.6.25/packages/better-auth\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `geoip-country` from 5.0.202607010001 to 5.0.202608010109\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/sapics/geoip-country/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `hono` from 4.12.27 to 4.12.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/honojs/hono/releases\"\u003ehono's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.12.33\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(cookie): relax name validation when parsing Cookie header in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5164\"\u003ehonojs/hono#5164\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump \u003ccode\u003e@hono/node-server\u003c/code\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5167\"\u003ehonojs/hono#5167\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(jsx): handle useSyncExternalStore subscription and snapshot changes in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5166\"\u003ehonojs/hono#5166\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove undici in favor of global fetch in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5168\"\u003ehonojs/hono#5168\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/hono/compare/v4.12.32...v4.12.33\"\u003ehttps://github.com/honojs/hono/compare/v4.12.32...v4.12.33\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.12.32\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eci: enable reports for type \u0026amp; bundle size check in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5148\"\u003ehonojs/hono#5148\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(aws-lambda): add jwt and lambda authorizer types for API Gateway v2 in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5142\"\u003ehonojs/hono#5142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(sse): emit empty id field to reset Last-Event-ID in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5138\"\u003ehonojs/hono#5138\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(cloudflare-workers): add coverage for onClose, onError, send, and close in Cloudflare Workers websocket adapter in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5145\"\u003ehonojs/hono#5145\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: use \u003ccode\u003eObject.create(null)\u003c/code\u003e when parsing query, headers, and params in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5161\"\u003ehonojs/hono#5161\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(secure-headers): keep CSP callbacks scoped to their header in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5147\"\u003ehonojs/hono#5147\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/hono/compare/v4.12.31...v4.12.32\"\u003ehttps://github.com/honojs/hono/compare/v4.12.31...v4.12.32\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.12.31\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etest(context): assert case-insensitive header names in response helpers by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5116\"\u003ehonojs/hono#5116\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(benchmark): add app.fetch() overhead benchmark by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5117\"\u003ehonojs/hono#5117\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor(aws-lambada): remove FIXME in \u003ccode\u003e@ts-expect-error\u003c/code\u003e by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5130\"\u003ehonojs/hono#5130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(utils/body): reuse cached formData in \u003ccode\u003eparseBody()\u003c/code\u003e by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5131\"\u003ehonojs/hono#5131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(request): fix multipart boundary mismatch in \u003ccode\u003ecloneRawRequest\u003c/code\u003e by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5133\"\u003ehonojs/hono#5133\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(sse): emit retry feild when retry is \u003ccode\u003e0\u003c/code\u003e by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5135\"\u003ehonojs/hono#5135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(validator): fix misspelled identifier in transform type test by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5136\"\u003ehonojs/hono#5136\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/hono/compare/v4.12.30...v4.12.31\"\u003ehttps://github.com/honojs/hono/compare/v4.12.30...v4.12.31\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.12.30\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore(benchmark/routers): bump deps in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5107\"\u003ehonojs/hono#5107\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(benchmark): remove not used benchmarks in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5108\"\u003ehonojs/hono#5108\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: update to ts6 in prep for ts7 in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5104\"\u003ehonojs/hono#5104\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): deduplicate Cache-Control directives case-insensitively in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5025\"\u003ehonojs/hono#5025\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(compress): do not compress 206 Partial Content responses in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5020\"\u003ehonojs/hono#5020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(client): replaceUrlParam should not match a param that prefixes another in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5096\"\u003ehonojs/hono#5096\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(method-override): set duplex when forwarding a stream body in query mode in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5110\"\u003ehonojs/hono#5110\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/hono/compare/v4.12.29...v4.12.30\"\u003ehttps://github.com/honojs/hono/compare/v4.12.29...v4.12.30\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.12.29\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(client): merge function headers with per-request headers by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5092\"\u003ehonojs/hono#5092\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: fix no-op tsc in test script by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5093\"\u003ehonojs/hono#5093\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(lambda-edge): resolve the handler with the value passed to the callback by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5094\"\u003ehonojs/hono#5094\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs(language): add JSDoc \u003ca href=\"https://github.com/example\"\u003e\u003ccode\u003e@​example\u003c/code\u003e\u003c/a\u003e to languageDetector by \u003ca href=\"https://github.com/codebybilal18\"\u003e\u003ccode\u003e@​codebybilal18\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5081\"\u003ehonojs/hono#5081\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/hono/commit/51db3131d5e97076327edaa0afdb60ebb77c264f\"\u003e\u003ccode\u003e51db313\u003c/code\u003e\u003c/a\u003e 4.12.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.co...\n\n_Description has been truncated_","html_url":"https://github.com/langwatch/langwatch/pull/6793","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/langwatch%2Flangwatch/issues/6793","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6793/packages"},{"uuid":"5095932581","node_id":"PR_kwDOPqGt_878UmEE","number":842,"state":"closed","title":"chore(deps): bump the npm_and_yarn group across 2 directories with 5 updates","user":"dependabot[bot]","labels":["dependencies","javascript","superseded","security-review"],"assignees":[],"locked":false,"comments_count":4,"pull_request":true,"closed_at":"2026-08-08T04:54:15.000Z","author_association":null,"state_reason":null,"created_at":"2026-08-08T04:53:26.000Z","updated_at":"2026-08-08T04:58:43.000Z","time_to_close":49,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":5,"packages":[{"name":"postcss","old_version":"8.4.35","new_version":"8.5.26","repository_url":"https://github.com/postcss/postcss"},{"name":"vite","old_version":"4.5.14","new_version":"8.2.1","repository_url":"https://github.com/vitejs/vite"},{"name":"ws","old_version":"8.19.0","new_version":"8.21.3","repository_url":"https://github.com/websockets/ws"},{"name":"undici","old_version":"7.16.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 4 updates in the /client directory: [postcss](https://github.com/postcss/postcss), [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite), [picomatch](https://github.com/micromatch/picomatch) and [ws](https://github.com/websockets/ws).\nBumps the npm_and_yarn group with 1 update in the /dynamic/copilot-swe-agent directory: [undici](https://github.com/nodejs/undici).\n\nUpdates `postcss` from 8.4.35 to 8.5.26\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/07b25773f38f77919f2af02ae3e8896b0deb5988\"\u003e\u003ccode\u003e07b2577\u003c/code\u003e\u003c/a\u003e Release 8.5.26 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/47de6b9d7c55674cb326c5de7a734a740916defc\"\u003e\u003ccode\u003e47de6b9\u003c/code\u003e\u003c/a\u003e Update CI\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/1493a83db7830912316512f55ab6064e7b7dd68e\"\u003e\u003ccode\u003e1493a83\u003c/code\u003e\u003c/a\u003e Fix Rule#selectors losing the empty selector (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2129\"\u003e#2129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/180db166e250d20e6761b224ae8d8134c9ba3e40\"\u003e\u003ccode\u003e180db16\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/29e9e00f132c96e46e1de295b816fe88a05354e7\"\u003e\u003ccode\u003e29e9e00\u003c/code\u003e\u003c/a\u003e Resolve symlinks before the previous-source-map containment check (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2125\"\u003e#2125\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3ba8f84703a884329b58abea579c3615684e0b7e\"\u003e\u003ccode\u003e3ba8f84\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/87e72f671fd0d401c52822b5226c656632d92ec0\"\u003e\u003ccode\u003e87e72f6\u003c/code\u003e\u003c/a\u003e Update lock file\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/caaeeb907e4a816c44a23b00b151882bd02325a1\"\u003e\u003ccode\u003ecaaeeb9\u003c/code\u003e\u003c/a\u003e Upgrade nanoid to fix infinite loop on zero size (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2124\"\u003e#2124\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3609b6f4296952d0b5b9ddae42c8d73ee460c041\"\u003e\u003ccode\u003e3609b6f\u003c/code\u003e\u003c/a\u003e Explain how to type plugin options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/fbad419cbd01cd7a9a1a46413447f2cd9b3fce4a\"\u003e\u003ccode\u003efbad419\u003c/code\u003e\u003c/a\u003e docs: show ESM and TypeScript plugin declaration (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2118\"\u003e#2118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.4.35...8.5.26\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `vite` from 4.5.14 to 8.2.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/releases\"\u003evite's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eplugin-legacy@8.2.1\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/plugin-legacy@8.2.1/packages/plugin-legacy/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.2.1\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.2.1/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ecreate-vite@8.2.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/create-vite@8.2.0/packages/create-vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003eplugin-legacy@8.2.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/plugin-legacy@8.2.0/packages/plugin-legacy/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.2.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.2.0/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.2.0-beta.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.2.0-beta.0/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.1.5\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.1.5/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.1.4\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.1.4/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.1.3\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.1.3/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.1.2\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.1.2/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.1.1\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.1.1/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ecreate-vite@8.1.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/create-vite@8.1.0/packages/create-vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003eplugin-legacy@8.1.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/plugin-legacy@8.1.0/packages/plugin-legacy/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.1.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.1.0/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003eplugin-legacy@8.1.0-beta.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/plugin-legacy@8.1.0-beta.0/packages/plugin-legacy/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.1.0-beta.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.1.0-beta.0/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.0.16\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.0.16/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md\"\u003evite's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v8.2.0...v8.2.1\"\u003e8.2.1\u003c/a\u003e (2026-08-06)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e make client chunkImportMap work with \u003ccode\u003esharedPlugins: true\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23184\"\u003e#23184\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/15f03073c915d6ffb9a1fda447ef66b02bf5cde8\"\u003e15f0307\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebundled-dev:\u003c/strong\u003e inject client script tag before chunk scripts (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23161\"\u003e#23161\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/eac0cc84aa2472a85a19ee84561c1ba71e381a55\"\u003eeac0cc8\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecss:\u003c/strong\u003e don't re-run lightningcss visitor during minify (fix \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23146\"\u003e#23146\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23147\"\u003e#23147\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/de041a79b05a0be965c874592fe2c1505bcd48df\"\u003ede041a7\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update all non-major dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23136\"\u003e#23136\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/14454fd8c9a399bc3fdc193e28465b6fcf001e4d\"\u003e14454fd\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update rolldown-related dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23070\"\u003e#23070\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/7ac6f7f590747bbdab9958e2c016e3dd04f10542\"\u003e7ac6f7f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edon't mutate the user config when resolving the lib entry from the top-level \u003ccode\u003einput\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23135\"\u003e#23135\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b4bf59686a7ac238929e91a6e1708c739b843a2f\"\u003eb4bf596\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ehandle shebang ending with uncommon line terminators (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23038\"\u003e#23038\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/17f7b2f193a110d0b47742ad296d182cb4666ce7\"\u003e17f7b2f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eserver:\u003c/strong\u003e use a random port when port is 0 (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23158\"\u003e#23158\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/fddf4ea41de5f7889037a2f957438857ac12a260\"\u003efddf4ea\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance Improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ecss:\u003c/strong\u003e look up pure CSS chunks through a Set (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23114\"\u003e#23114\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/1331b0b438b1e7193effb7d2341660bccb9c3155\"\u003e1331b0b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e fix incomplete \u003ccode\u003e@default\u003c/code\u003e for build.minify (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23177\"\u003e#23177\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/ef02435114c57d0422028f0e6987f3df8db72969\"\u003eef02435\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMiscellaneous Chores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update dependency rolldown-plugin-dts to ^0.28.0 (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23137\"\u003e#23137\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/4adc1e7931d4beceb4e236d9a271d057c858a06f\"\u003e4adc1e7\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update dependency strip-literal to v4 (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23140\"\u003e#23140\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/9db65ce63488ea8f08a3c98dcdc4282b17bd33ff\"\u003e9db65ce\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCode Refactoring\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebundled-dev:\u003c/strong\u003e avoid injecting server values in the bundle (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22967\"\u003e#22967\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/23b8a088dec9dcc3f1c1353f2074f8644b3cc21f\"\u003e23b8a08\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebundled-dev:\u003c/strong\u003e remove rolldown lazy stub module workaround (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23129\"\u003e#23129\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e72036eed2e28936ed824971b18aeaa3900857f6\"\u003ee72036e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eTests\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebundled-dev:\u003c/strong\u003e enable sourcemap playgrounds (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23080\"\u003e#23080\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/c2155fe4d5c8d25fba3a7366d367e3296ae669fa\"\u003ec2155fe\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereduce logs (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23138\"\u003e#23138\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/7673c02e53343ae9356c1f496c1c1da2eb732ac1\"\u003e7673c02\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v8.2.0-beta.0...v8.2.0\"\u003e8.2.0\u003c/a\u003e (2026-07-30)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003einput\u003c/code\u003e to \u003ccode\u003eserver.fs.allow\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23035\"\u003e#23035\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/95a3cdab83e1125b03d2e8dd942fb6b64209e5fa\"\u003e95a3cda\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebundled-dev:\u003c/strong\u003e reload once after rebuild instead of via the fallback page (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23106\"\u003e#23106\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b24381d741941b9ce2b1c07db62cc5f4d7bad981\"\u003eb24381d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebundled-dev:\u003c/strong\u003e support worker file update accepted by HMR (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23068\"\u003e#23068\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/0d04351fdc12258c75b9f1cda5780fdb836ed0ef\"\u003e0d04351\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003econfig:\u003c/strong\u003e include column in config incompatibility location (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23064\"\u003e#23064\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8a245726944ed29225920d49be77c33c6e03afc8\"\u003e8a24572\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edev:\u003c/strong\u003e resolve interface name for explicit host in network URLs (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22965\"\u003e#22965\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/3ac77d9dd742968961af38a5a91ed6b061ceda7d\"\u003e3ac77d9\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebundledDev:\u003c/strong\u003e print build errors to the terminal when an HMR update fails (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23024\"\u003e#23024\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/41c465896e8b11b1eb9c5fbdafbdcc528e189a2c\"\u003e41c4658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update all non-major dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23069\"\u003e#23069\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/4c07b74416f859d7e8bdace13409ef2d080edf76\"\u003e4c07b74\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ehmr:\u003c/strong\u003e preserve environment snapshot during server restart (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22992\"\u003e#22992\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b1186c36d06bb94941c58e8272fc4acb8512c93b\"\u003eb1186c3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eimportAnalysis:\u003c/strong\u003e interop imports injected into optimized dep files by plugins (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23029\"\u003e#23029\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8c2a87d41fb24536e59643351758084cde4d0dd7\"\u003e8c2a87d\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/421615865dad3ed39137d17281814fc78a41246c\"\u003e\u003ccode\u003e4216158\u003c/code\u003e\u003c/a\u003e release: v8.2.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/fddf4ea41de5f7889037a2f957438857ac12a260\"\u003e\u003ccode\u003efddf4ea\u003c/code\u003e\u003c/a\u003e fix(server): use a random port when port is 0 (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23158\"\u003e#23158\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/de041a79b05a0be965c874592fe2c1505bcd48df\"\u003e\u003ccode\u003ede041a7\u003c/code\u003e\u003c/a\u003e fix(css): don't re-run lightningcss visitor during minify (fix \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23146\"\u003e#23146\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23147\"\u003e#23147\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/15f03073c915d6ffb9a1fda447ef66b02bf5cde8\"\u003e\u003ccode\u003e15f0307\u003c/code\u003e\u003c/a\u003e fix(build): make client chunkImportMap work with \u003ccode\u003esharedPlugins: true\u003c/code\u003e (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23184\"\u003e#23184\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/c2155fe4d5c8d25fba3a7366d367e3296ae669fa\"\u003e\u003ccode\u003ec2155fe\u003c/code\u003e\u003c/a\u003e test(bundled-dev): enable sourcemap playgrounds (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23080\"\u003e#23080\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/ef02435114c57d0422028f0e6987f3df8db72969\"\u003e\u003ccode\u003eef02435\u003c/code\u003e\u003c/a\u003e docs(build): fix incomplete \u003ccode\u003e@default\u003c/code\u003e for build.minify (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23177\"\u003e#23177\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/eac0cc84aa2472a85a19ee84561c1ba71e381a55\"\u003e\u003ccode\u003eeac0cc8\u003c/code\u003e\u003c/a\u003e fix(bundled-dev): inject client script tag before chunk scripts (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23161\"\u003e#23161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/23b8a088dec9dcc3f1c1353f2074f8644b3cc21f\"\u003e\u003ccode\u003e23b8a08\u003c/code\u003e\u003c/a\u003e refactor(bundled-dev): avoid injecting server values in the bundle (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22967\"\u003e#22967\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/e72036eed2e28936ed824971b18aeaa3900857f6\"\u003e\u003ccode\u003ee72036e\u003c/code\u003e\u003c/a\u003e refactor(bundled-dev): remove rolldown lazy stub module workaround (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23129\"\u003e#23129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/14454fd8c9a399bc3fdc193e28465b6fcf001e4d\"\u003e\u003ccode\u003e14454fd\u003c/code\u003e\u003c/a\u003e fix(deps): update all non-major dependencies (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23136\"\u003e#23136\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vitejs/vite/commits/v8.2.1/packages/vite\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for vite since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nRemoves `picomatch`\n\nUpdates `ws` from 8.19.0 to 8.21.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/websockets/ws/releases\"\u003ews's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.21.3\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eThe server now correctly rejects permessage-deflate offers if the incoming\n\u003ccode\u003eclient_max_window_bits\u003c/code\u003e parameter value is smaller than its configured\n\u003ccode\u003eclientMaxWindowBits\u003c/code\u003e (e97a20ea).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.21.2\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a test for \u003ca href=\"https://github.com/nodejs/citgm\"\u003eCITGM\u003c/a\u003e (2eb3be0b).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.21.1\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eEmpty fragments are now counted toward the limit (a2f4e7c0).\u003c/li\u003e\n\u003cli\u003eThe default values of the \u003ccode\u003emaxBufferedChunks\u003c/code\u003e and \u003ccode\u003emaxFragments\u003c/code\u003e options have\nbeen reduced (f197ac65).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.21.0\u003c/h2\u003e\n\u003ch1\u003eFeatures\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eIntroduced the \u003ccode\u003emaxBufferedChunks\u003c/code\u003e and \u003ccode\u003emaxFragments\u003c/code\u003e options (2b2abd45).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a remote memory exhaustion DoS vulnerability (2b2abd45).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eA high volume of tiny fragments and data chunks could be sent by a peer, using\nmodest network traffic, to crash a \u003ccode\u003ews\u003c/code\u003e server or client due to OOM.\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003eimport { WebSocket, WebSocketServer } from 'ws';\r\n\u003cp\u003econst wss = new WebSocketServer({ port: 0 }, function () {\nconst data = Buffer.alloc(1);\nconst options = { fin: false };\nconst { port } = wss.address();\nconst ws = new WebSocket(\u003ccode\u003ews://localhost:${port}\u003c/code\u003e);\u003c/p\u003e\n\u003cp\u003ews.on('open', function () {\n(function send() {\nws.send(data, options, function (err) {\nif (err) return;\nsend();\n});\n})();\n});\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt;\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/c791e707eab3c13dd9a261d2479c3cc4a49a6fed\"\u003e\u003ccode\u003ec791e70\u003c/code\u003e\u003c/a\u003e [dist] 8.21.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/e97a20eaa6f2ad7969419eed732a506453251eb9\"\u003e\u003ccode\u003ee97a20e\u003c/code\u003e\u003c/a\u003e [fix] Reject offers with \u003ccode\u003eclient_max_window_bits\u003c/code\u003e below config\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/787ebf22ce3d091fb6f931d20b4c7e914ba7cf85\"\u003e\u003ccode\u003e787ebf2\u003c/code\u003e\u003c/a\u003e [dist] 8.21.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/b4d62ebad40c3b925c84ff305a47975406015422\"\u003e\u003ccode\u003eb4d62eb\u003c/code\u003e\u003c/a\u003e Revert \u0026quot;[ci] Trust Coveralls Homebrew tap\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/e4bb883723a0c18452eea10a74139901ae33c61d\"\u003e\u003ccode\u003ee4bb883\u003c/code\u003e\u003c/a\u003e [security] Use GitHub PVR as main reporting channel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/2eb3be0bff2453e2654b1315c5872e8d5d424a50\"\u003e\u003ccode\u003e2eb3be0\u003c/code\u003e\u003c/a\u003e [test] Skip test on Node.js versions where it does not apply\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/ae1de54330cef77e487548890fabfeb9aae1d83d\"\u003e\u003ccode\u003eae1de54\u003c/code\u003e\u003c/a\u003e [dist] 8.21.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/8e9511b86b3fc6deebbd97dd9af7c9056deea8d1\"\u003e\u003ccode\u003e8e9511b\u003c/code\u003e\u003c/a\u003e [ci] Trust Coveralls Homebrew tap\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/f197ac65140920bdcecdab74bfc69c2d7858e55d\"\u003e\u003ccode\u003ef197ac6\u003c/code\u003e\u003c/a\u003e [fix] Lower default values of \u003ccode\u003emaxBufferedChunks\u003c/code\u003e and \u003ccode\u003emaxFragments\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/8df8265c2f63fd44af3193a98e23cf38888cd991\"\u003e\u003ccode\u003e8df8265\u003c/code\u003e\u003c/a\u003e [ci] Update actions/checkout action to v7\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/websockets/ws/compare/8.19.0...8.21.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.16.0 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.28.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e7 security advisories\u003c/strong\u003e, all shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 7.28.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^7.28.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v7 line is \u003cstrong\u003enot\u003c/strong\u003e affected by GHSA-38rv-x7px-6hhq (CVE-2026-9675), which is\nan 8.x-only regression.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on GHSA-hm92-r4w5-c3mj:\u003c/strong\u003e this fix shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e, not the\nearlier 7.2x line — the vulnerable single-pool code was still present through\n\u003ccode\u003ev7.27.2\u003c/code\u003e. The per-origin pool fix is\n\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5041\"\u003e#5041\u003c/a\u003e).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8cb10f98\"\u003e\u003ccode\u003e8cb10f98\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g\"\u003eGHSA-vmh5-mc38-953g\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9697\u003c/td\u003e\n\u003ctd\u003eHigh (7.4)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/04201f89\"\u003e\u003ccode\u003e04201f89\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj\"\u003eGHSA-hm92-r4w5-c3mj\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6734\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6\"\u003eGHSA-pr7r-676h-xcf6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9678\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/85a24055\"\u003e\u003ccode\u003e85a24055\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ea8930cf\"\u003e\u003ccode\u003eea8930cf\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f9eba0ad9134e1c0977848476bba9d49734696e4\"\u003e\u003ccode\u003ef9eba0a\u003c/code\u003e\u003c/a\u003e Bumped v7.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5430\"\u003e#5430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.16.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/mrdannyclark82/Milla-Rayne/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/mrdannyclark82/Milla-Rayne/pull/842","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/mrdannyclark82%2FMilla-Rayne/issues/842","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/842/packages"},{"uuid":"5095685495","node_id":"PR_kwDOS3GQx878T12k","number":127,"state":"closed","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 3 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-08-08T03:35:08.000Z","author_association":null,"state_reason":null,"created_at":"2026-08-08T03:34:42.000Z","updated_at":"2026-08-08T03:35:10.000Z","time_to_close":26,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":3,"packages":[{"name":"brace-expansion","old_version":"1.1.15","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"postcss","old_version":"8.5.15","new_version":"8.5.26","repository_url":"https://github.com/postcss/postcss"},{"name":"undici","old_version":"7.28.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 3 updates in the /client directory: [brace-expansion](https://github.com/juliangruber/brace-expansion), [postcss](https://github.com/postcss/postcss) and [undici](https://github.com/nodejs/undici).\n\nUpdates `brace-expansion` from 1.1.15 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.15...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.15 to 8.5.26\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/07b25773f38f77919f2af02ae3e8896b0deb5988\"\u003e\u003ccode\u003e07b2577\u003c/code\u003e\u003c/a\u003e Release 8.5.26 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/47de6b9d7c55674cb326c5de7a734a740916defc\"\u003e\u003ccode\u003e47de6b9\u003c/code\u003e\u003c/a\u003e Update CI\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/1493a83db7830912316512f55ab6064e7b7dd68e\"\u003e\u003ccode\u003e1493a83\u003c/code\u003e\u003c/a\u003e Fix Rule#selectors losing the empty selector (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2129\"\u003e#2129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/180db166e250d20e6761b224ae8d8134c9ba3e40\"\u003e\u003ccode\u003e180db16\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/29e9e00f132c96e46e1de295b816fe88a05354e7\"\u003e\u003ccode\u003e29e9e00\u003c/code\u003e\u003c/a\u003e Resolve symlinks before the previous-source-map containment check (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2125\"\u003e#2125\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3ba8f84703a884329b58abea579c3615684e0b7e\"\u003e\u003ccode\u003e3ba8f84\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/87e72f671fd0d401c52822b5226c656632d92ec0\"\u003e\u003ccode\u003e87e72f6\u003c/code\u003e\u003c/a\u003e Update lock file\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/caaeeb907e4a816c44a23b00b151882bd02325a1\"\u003e\u003ccode\u003ecaaeeb9\u003c/code\u003e\u003c/a\u003e Upgrade nanoid to fix infinite loop on zero size (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2124\"\u003e#2124\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3609b6f4296952d0b5b9ddae42c8d73ee460c041\"\u003e\u003ccode\u003e3609b6f\u003c/code\u003e\u003c/a\u003e Explain how to type plugin options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/fbad419cbd01cd7a9a1a46413447f2cd9b3fce4a\"\u003e\u003ccode\u003efbad419\u003c/code\u003e\u003c/a\u003e docs: show ESM and TypeScript plugin declaration (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2118\"\u003e#2118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.15...8.5.26\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.28.0 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/arthurgregorio/investlog/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/arthurgregorio/investlog/pull/127","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/arthurgregorio%2Finvestlog/issues/127","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/127/packages"},{"uuid":"5094497191","node_id":"PR_kwDOJmRLdM78QGJp","number":287,"state":"open","title":"chore(deps): bump undici and @aurodesignsystem/auro-cli","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T22:39:02.000Z","updated_at":"2026-08-07T22:39:11.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"undici","repository_url":"https://github.com/nodejs/undici","old_version":"6.27.0","new_version":"6.28.0"},{"name":"@aurodesignsystem/auro-cli","repository_url":"https://github.com/AlaskaAirlines/auro-cli","old_version":"3.5.1","new_version":"3.7.1"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) to 6.28.0 and updates ancestor dependency [@aurodesignsystem/auro-cli](https://github.com/AlaskaAirlines/auro-cli). These dependencies need to be updated together.\n\nUpdates `undici` from 6.27.0 to 6.28.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.28.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e740a0b7c\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003ecba3a52a\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e4fd5a0c6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003eaf748404\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e and \u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ehttps://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a\"\u003e\u003ccode\u003e01a912e\u003c/code\u003e\u003c/a\u003e Bumped v6.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5591\"\u003e#5591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e\"\u003e\u003ccode\u003e481ecfc\u003c/code\u003e\u003c/a\u003e Use Node 22 and npm 11 to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e\u003ccode\u003e740a0b7\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0\"\u003e\u003ccode\u003e2698e49\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e\u003ccode\u003e4fd5a0c\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003e\u003ccode\u003ecba3a52\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003e\u003ccode\u003eaf74840\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@aurodesignsystem/auro-cli` from 3.5.1 to 3.7.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/releases\"\u003e@​aurodesignsystem/auro-cli's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.7.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/compare/v3.7.0...v3.7.1\"\u003e3.7.1\u003c/a\u003e (2026-05-11)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e error on unresolved imports in demo bundles (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/9e5bca652bd4589ed39c5ab1d3964e220b3d40b3\"\u003e9e5bca6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e isolate demo bundles and bump \u003ccode\u003e@​actions/github\u003c/code\u003e (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/6b57f98627e8c6b5deec1af0ebd3fe7b488728fc\"\u003e6b57f98\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e resolve hoisted workspace packages in demo bundles (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/3b29a21da0a5cc6f630c9f6a2d8ae41f31946214\"\u003e3b29a21\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.7.1-rc-291.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/compare/v3.7.0...v3.7.1-rc-291.1\"\u003e3.7.1-rc-291.1\u003c/a\u003e (2026-05-11)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e error on unresolved imports in demo bundles (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/9e5bca652bd4589ed39c5ab1d3964e220b3d40b3\"\u003e9e5bca6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e isolate demo bundles and bump \u003ccode\u003e@​actions/github\u003c/code\u003e (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/6b57f98627e8c6b5deec1af0ebd3fe7b488728fc\"\u003e6b57f98\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e resolve hoisted workspace packages in demo bundles (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/3b29a21da0a5cc6f630c9f6a2d8ae41f31946214\"\u003e3b29a21\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.7.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/compare/v3.6.0...v3.7.0\"\u003e3.7.0\u003c/a\u003e (2026-05-06)\u003c/h1\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003erefine whitespace stripping in post-processing to preserve markdown structure (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/36242f3ad2b78df299204932c04ec8d648cdaa7a\"\u003e36242f3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eresolve SCSS imports using package.json exports map (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/97517203737c5d382c32632b84b57892fa023519\"\u003e9751720\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd --readme-template flag and centralize shared utilities (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/e71cd8f8ef7846cfde31285bd4c49f72b6047fbb\"\u003ee71cd8f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd demo SCSS compilation, README copy, and watch mode to docs command (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/3f7a5f6be82fb60ee33cbeb1fe1e4f4757edd8c1\"\u003e3f7a5f6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd post-processing for markdown doc files (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/a5d63bc5241c28d1c95d8bb78dd7aef8b2eafec7\"\u003ea5d63bc\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eenhance defaultDocsProcessorConfig with monorepoName and extraVars support (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/e252574f8adaa7b92dd2a418ecc04b66cd16db20\"\u003ee252574\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.7.0-rc-287.1\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/compare/v3.6.0...v3.7.0-rc-287.1\"\u003e3.7.0-rc-287.1\u003c/a\u003e (2026-05-06)\u003c/h1\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003erefine whitespace stripping in post-processing to preserve markdown structure (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/36242f3ad2b78df299204932c04ec8d648cdaa7a\"\u003e36242f3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eresolve SCSS imports using package.json exports map (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/97517203737c5d382c32632b84b57892fa023519\"\u003e9751720\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd --readme-template flag and centralize shared utilities (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/e71cd8f8ef7846cfde31285bd4c49f72b6047fbb\"\u003ee71cd8f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/40a82d77c7a98d1d92ea423ab739d94d4e33e2dd\"\u003e\u003ccode\u003e40a82d7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/AlaskaAirlines/auro-cli/issues/292\"\u003e#292\u003c/a\u003e from AlaskaAirlines/rc/291\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/9e5bca652bd4589ed39c5ab1d3964e220b3d40b3\"\u003e\u003ccode\u003e9e5bca6\u003c/code\u003e\u003c/a\u003e fix(build): error on unresolved imports in demo bundles\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/3b29a21da0a5cc6f630c9f6a2d8ae41f31946214\"\u003e\u003ccode\u003e3b29a21\u003c/code\u003e\u003c/a\u003e fix(build): resolve hoisted workspace packages in demo bundles\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/6b57f98627e8c6b5deec1af0ebd3fe7b488728fc\"\u003e\u003ccode\u003e6b57f98\u003c/code\u003e\u003c/a\u003e fix(build): isolate demo bundles and bump \u003ccode\u003e@​actions/github\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/c3c60a78df454aa3b64052a0de69a15449502e12\"\u003e\u003ccode\u003ec3c60a7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/AlaskaAirlines/auro-cli/issues/288\"\u003e#288\u003c/a\u003e from AlaskaAirlines/rc/287\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/53fd747faf8de08b3943e258d6ee9a3ba9c0e390\"\u003e\u003ccode\u003e53fd747\u003c/code\u003e\u003c/a\u003e ci: update Node.js version to 22.22.1 in workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/e252574f8adaa7b92dd2a418ecc04b66cd16db20\"\u003e\u003ccode\u003ee252574\u003c/code\u003e\u003c/a\u003e feat: enhance defaultDocsProcessorConfig with monorepoName and extraVars support\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/36242f3ad2b78df299204932c04ec8d648cdaa7a\"\u003e\u003ccode\u003e36242f3\u003c/code\u003e\u003c/a\u003e fix: refine whitespace stripping in post-processing to preserve markdown stru...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/a5d63bc5241c28d1c95d8bb78dd7aef8b2eafec7\"\u003e\u003ccode\u003ea5d63bc\u003c/code\u003e\u003c/a\u003e feat: add post-processing for markdown doc files\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/97517203737c5d382c32632b84b57892fa023519\"\u003e\u003ccode\u003e9751720\u003c/code\u003e\u003c/a\u003e fix: resolve SCSS imports using package.json exports map\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/compare/v3.5.1...v3.7.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/AlaskaAirlines/auro-library/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/AlaskaAirlines/auro-library/pull/287","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/AlaskaAirlines%2Fauro-library/issues/287","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/287/packages"},{"uuid":"5093830529","node_id":"PR_kwDOTpN49s78N9jy","number":3,"state":"open","title":"build(deps): bump undici from 8.9.0 to 8.10.0","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T20:44:14.000Z","updated_at":"2026-08-07T20:44:41.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"undici","old_version":"8.9.0","new_version":"8.10.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 8.9.0 to 8.10.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: namespace h2 options by \u003ca href=\"https://github.com/metcoder95\"\u003e\u003ccode\u003e@​metcoder95\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5498\"\u003enodejs/undici#5498\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: update WPT expectations by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5587\"\u003enodejs/undici#5587\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: add cache/dedupe + dns re-dispatch integration tests by \u003ca href=\"https://github.com/GiHoon1123\"\u003e\u003ccode\u003e@​GiHoon1123\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5535\"\u003enodejs/undici#5535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): support process.unref by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5578\"\u003enodejs/undici#5578\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): ensure every request settles by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5603\"\u003enodejs/undici#5603\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(readable): consume a body whose end has already been emitted by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5617\"\u003enodejs/undici#5617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): skip the content-length checkpoint for HEAD and for a 206 without content-range by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5610\"\u003enodejs/undici#5610\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: revert idle socket validation to setTimeout(0) to prevent stall on idle event loop by \u003ca href=\"https://github.com/marceli1404\"\u003e\u003ccode\u003e@​marceli1404\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5606\"\u003enodejs/undici#5606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(env-http-proxy-agent): match bare IPv6 addresses in no_proxy by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5623\"\u003enodejs/undici#5623\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: handle aggregate balanced pool errors by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5377\"\u003enodejs/undici#5377\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(readable): keep body bytes that arrive after setEncoding() by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5620\"\u003enodejs/undici#5620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(socks5): evict unused origin pools by \u003ca href=\"https://github.com/Kkartik14\"\u003e\u003ccode\u003e@​Kkartik14\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5595\"\u003enodejs/undici#5595\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: skip deduplication for upgrade requests by \u003ca href=\"https://github.com/Ram-blip\"\u003e\u003ccode\u003e@​Ram-blip\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5593\"\u003enodejs/undici#5593\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward informational responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5625\"\u003enodejs/undici#5625\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(mock): non-string path matchers under ignoreTrailingSlash, and DataView reply bodies by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5619\"\u003enodejs/undici#5619\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(interceptors): cache() and deduplicate() silently inert on Client/Pool without opts.origin by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5628\"\u003enodejs/undici#5628\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5633\"\u003enodejs/undici#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/init from 4.36.2 to 4.37.3 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5634\"\u003enodejs/undici#5634\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.4.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5636\"\u003enodejs/undici#5636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(mock): emit request body lifecycle hooks by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5367\"\u003enodejs/undici#5367\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): detach upgrade close handler after GOAWAY by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5641\"\u003enodejs/undici#5641\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: retry refused HTTP/2 streams by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5598\"\u003enodejs/undici#5598\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: preserve DNS origin hostname on sockets by \u003ca href=\"https://github.com/cyphercodes\"\u003e\u003ccode\u003e@​cyphercodes\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5577\"\u003enodejs/undici#5577\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marceli1404\"\u003e\u003ccode\u003e@​marceli1404\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5606\"\u003enodejs/undici#5606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kkartik14\"\u003e\u003ccode\u003e@​Kkartik14\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5595\"\u003enodejs/undici#5595\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5641\"\u003enodejs/undici#5641\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cyphercodes\"\u003e\u003ccode\u003e@​cyphercodes\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5577\"\u003enodejs/undici#5577\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v8.9.0...v8.10.0\"\u003ehttps://github.com/nodejs/undici/compare/v8.9.0...v8.10.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/c8d80e6b2dcfab282557b08f51352937bc9e5692\"\u003e\u003ccode\u003ec8d80e6\u003c/code\u003e\u003c/a\u003e Bumped v8.10.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5644\"\u003e#5644\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66923b47dc1ed095581daa6a53b2ad1bf3e899b4\"\u003e\u003ccode\u003e66923b4\u003c/code\u003e\u003c/a\u003e fix: preserve DNS origin hostname on sockets (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5577\"\u003e#5577\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/392649944c3b989681af1eae2e0970661f9ca464\"\u003e\u003ccode\u003e3926499\u003c/code\u003e\u003c/a\u003e fix: retry refused HTTP/2 streams (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5598\"\u003e#5598\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/73d6e9e19df47f85625d2dc082daa919ae6636c1\"\u003e\u003ccode\u003e73d6e9e\u003c/code\u003e\u003c/a\u003e fix(h2): detach upgrade close handler after GOAWAY (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5641\"\u003e#5641\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b111adbb675ebfcfa52790346dcd88e61c700818\"\u003e\u003ccode\u003eb111adb\u003c/code\u003e\u003c/a\u003e fix(mock): emit request body lifecycle hooks (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5367\"\u003e#5367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ae4a3e37a2ddfe798b64771176e31e8e7819c743\"\u003e\u003ccode\u003eae4a3e3\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/setup-node from 6.4.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5636\"\u003e#5636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ec3fbf19aa47eca6decc390b66bf56034bc03d52\"\u003e\u003ccode\u003eec3fbf1\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action/init from 4.36.2 to 4.37.3 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5634\"\u003e#5634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/21517200296205f3aa09a7b976dde571b441405c\"\u003e\u003ccode\u003e2151720\u003c/code\u003e\u003c/a\u003e build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5633\"\u003e#5633\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b96a11620e2f9fe5adafa2ba7b7f363b96b5a9d7\"\u003e\u003ccode\u003eb96a116\u003c/code\u003e\u003c/a\u003e fix(interceptors): allow interceptors without opts.origin (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5628\"\u003e#5628\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/a18ef2d05af48047339be51d8817492abc30f39d\"\u003e\u003ccode\u003ea18ef2d\u003c/code\u003e\u003c/a\u003e fix(mock): non-string path matchers under ignoreTrailingSlash, and DataView r...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v8.9.0...v8.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=8.9.0\u0026new-version=8.10.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Priyanshu91930/teraapi/pull/3","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Priyanshu91930%2Fteraapi/issues/3","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/3/packages"},{"uuid":"5093740783","node_id":"PR_kwDOQv0FkM78NrFC","number":119,"state":"open","title":"chore(deps): bump undici from 6.23.0 to 6.28.0 in /mobile","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T20:29:21.000Z","updated_at":"2026-08-07T20:29:28.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"undici","old_version":"6.23.0","new_version":"6.28.0","repository_url":"https://github.com/nodejs/undici"}],"path":"/mobile","ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 6.23.0 to 6.28.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.28.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e740a0b7c\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003ecba3a52a\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e4fd5a0c6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003eaf748404\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e and \u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ehttps://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.27.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e4 security advisories\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 6.27.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^6.27.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on patched version:\u003c/strong\u003e the v6 fixes shipped in \u003cstrong\u003ev6.27.0\u003c/strong\u003e, not \u003ccode\u003e6.26.0\u003c/code\u003e\n— \u003ccode\u003ev6.26.0\u003c/code\u003e contains only the chunked-EOF fix (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5308\"\u003e#5308\u003c/a\u003e) and the version bump, none\nof the security fixes below.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v6 line is \u003cstrong\u003enot\u003c/strong\u003e affected by the SOCKS5 advisories (GHSA-vmh5-mc38-953g,\nGHSA-hm92-r4w5-c3mj), the shared-cache disclosure (GHSA-pr7r-676h-xcf6), or the\n8.x-only WebSocket regression (GHSA-38rv-x7px-6hhq).\u003c/p\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7\"\u003e\u003ccode\u003eb7f252e7\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447\"\u003e\u003ccode\u003e25efa447\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447\"\u003e\u003ccode\u003e25efa447\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f4c31d60\"\u003e\u003ccode\u003ef4c31d60\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003ch2\u003eHigh severity\u003c/h2\u003e\n\u003ch3\u003eWebSocket DoS via fragment count bypass — CVE-2026-12151\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/strong\u003e · CWE-400, CWE-770\n\u003cstrong\u003eFix:\u003c/strong\u003e \u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7\"\u003e\u003ccode\u003eb7f252e7\u003c/code\u003e\u003c/a\u003e \u003cem\u003eBackport WebSocket maxPayloadSize fixes\u003c/em\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5423\"\u003e#5423\u003c/a\u003e, backported to v6 in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5428\"\u003e#5428\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eA malicious WebSocket server can stream a large number of small or empty\ncontinuation frames. Undici enforced a limit on cumulative payload size but did\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a\"\u003e\u003ccode\u003e01a912e\u003c/code\u003e\u003c/a\u003e Bumped v6.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5591\"\u003e#5591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e\"\u003e\u003ccode\u003e481ecfc\u003c/code\u003e\u003c/a\u003e Use Node 22 and npm 11 to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e\u003ccode\u003e740a0b7\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0\"\u003e\u003ccode\u003e2698e49\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e\u003ccode\u003e4fd5a0c\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003e\u003ccode\u003ecba3a52\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003e\u003ccode\u003eaf74840\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/551138cbc1742c92242a68216167761075e8a82c\"\u003e\u003ccode\u003e551138c\u003c/code\u003e\u003c/a\u003e Bumped v6.27.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5431\"\u003e#5431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7c0841418fb9d95cd297bdd9fad9d2a53\"\u003e\u003ccode\u003eb7f252e\u003c/code\u003e\u003c/a\u003e Backport WebSocket maxPayloadSize fixes to v7.x (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5423\"\u003e#5423\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5428\"\u003e#5428\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447997f74d5881edd144525c3fd7db945a4\"\u003e\u003ccode\u003e25efa44\u003c/code\u003e\u003c/a\u003e fix(cookies): preserve values and parse SameSite strictly\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.23.0...v6.28.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=6.23.0\u0026new-version=6.28.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/nexora-africa-ltd/vitora/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/nexora-africa-ltd/vitora/pull/119","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/nexora-africa-ltd%2Fvitora/issues/119","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/119/packages"},{"uuid":"5092978113","node_id":"PR_kwDOQUVehM78LOua","number":3,"state":"open","title":"build(deps): bump the npm_and_yarn group across 2 directories with 8 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T18:34:27.000Z","updated_at":"2026-08-07T18:36:17.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":8,"packages":[{"name":"axios","old_version":"1.12.2","new_version":"1.18.0","repository_url":"https://github.com/axios/axios"},{"name":"undici","old_version":"7.15.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"},{"name":"dompurify","old_version":"3.2.6","new_version":"3.4.13","repository_url":"https://github.com/cure53/DOMPurify"},{"name":"shell-quote","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/ljharb/shell-quote"},{"name":"next","old_version":"15.2.5","new_version":"15.5.21","repository_url":"https://github.com/vercel/next.js"},{"name":"postcss","old_version":"8.5.4","new_version":"8.5.23","repository_url":"https://github.com/postcss/postcss"},{"name":"electron","old_version":"34.4.1","new_version":"39.8.10","repository_url":"https://github.com/electron/electron"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 7 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [axios](https://github.com/axios/axios) | `1.12.2` | `1.18.0` |\n| [undici](https://github.com/nodejs/undici) | `7.15.0` | `7.29.0` |\n| [dompurify](https://github.com/cure53/DOMPurify) | `3.2.6` | `3.4.13` |\n| [shell-quote](https://github.com/ljharb/shell-quote) | `1.8.2` | `1.9.0` |\n| [next](https://github.com/vercel/next.js) | `15.2.5` | `15.5.21` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.4` | `8.5.23` |\n| [electron](https://github.com/electron/electron) | `34.4.1` | `39.8.10` |\n\nBumps the npm_and_yarn group with 3 updates in the /jetbrains/host directory: [undici](https://github.com/nodejs/undici), [postcss](https://github.com/postcss/postcss) and [electron](https://github.com/electron/electron).\n\nUpdates `axios` from 1.12.2 to 1.18.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/releases\"\u003eaxios's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.18.0 — June 13, 2026\u003c/h2\u003e\n\u003cp\u003eThis release hardens redirect and URL handling, improves the validateStatus configuration semantics, and includes updates to documentation, dependencies, and release metadata.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRedirect Header Safety:\u003c/strong\u003e Added Node HTTP adapter support for stripping caller-specified sensitive headers on cross-origin redirects, helping prevent custom auth headers such as API keys from leaking to another origin. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eURL And Request Hardening:\u003c/strong\u003e Rejects malformed \u003ccode\u003ehttp:\u003c/code\u003e and \u003ccode\u003ehttps:\u003c/code\u003e URLs that omit \u003ccode\u003e//\u003c/code\u003e with \u003ccode\u003eERR_INVALID_URL\u003c/code\u003e, while tightening prototype-pollution-safe config reads, stream size limits, FormData depth handling, data URL sizing, and local \u003ccode\u003eNO_PROXY\u003c/code\u003e matching. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eStatus Validation:\u003c/strong\u003e Added \u003ccode\u003etransitional.validateStatusUndefinedResolves\u003c/code\u003e so applications can opt in to treating \u003ccode\u003evalidateStatus: undefined\u003c/code\u003e like the option was omitted, while \u003ccode\u003evalidateStatus: null\u003c/code\u003e remains the explicit way to accept every status. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation:\u003c/strong\u003e Published the v1.17.0 release notes, fixed a changelog typo, clarified the package update PR policy, and marked the \u003ccode\u003eproxy\u003c/code\u003e request config as Node.js-only in the advanced docs. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDependencies:\u003c/strong\u003e Bumped \u003ccode\u003e@babel/core\u003c/code\u003e, \u003ccode\u003e@babel/preset-env\u003c/code\u003e, \u003ccode\u003e@commitlint/cli\u003c/code\u003e, \u003ccode\u003e@commitlint/config-conventional\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-babel\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-commonjs\u003c/code\u003e, \u003ccode\u003e@vitest/browser\u003c/code\u003e, \u003ccode\u003e@vitest/browser-playwright\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003elint-staged\u003c/code\u003e, \u003ccode\u003erollup\u003c/code\u003e, \u003ccode\u003evitest\u003c/code\u003e, and \u003ccode\u003eactions/checkout\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10996\"\u003e#10996\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10997\"\u003e#10997\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRelease Metadata:\u003c/strong\u003e Prepared the 1.18.0 release by updating package metadata and the runtime \u003ccode\u003eVERSION\u003c/code\u003e value. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/drori12\"\u003e\u003ccode\u003e@​drori12\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/eyupcanakman\"\u003e\u003ccode\u003e@​eyupcanakman\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/Adi-Beker\"\u003e\u003ccode\u003e@​Adi-Beker\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/axios/axios/compare/v1.17.0...v1.18.0\"\u003eFull Changelog\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.17.0 — June 1, 2026\u003c/h2\u003e\n\u003cp\u003eThis release adds Node HTTP zstd decompression, hardens config and release workflows, and fixes authentication, header, proxy, and type-handling regressions.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eConfig Hardening:\u003c/strong\u003e Guarded \u003ccode\u003esocketPath\u003c/code\u003e, \u003ccode\u003eparams\u003c/code\u003e, and \u003ccode\u003eparamsSerializer\u003c/code\u003e reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10901\"\u003e#10901\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10922\"\u003e#10922\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRelease Publishing:\u003c/strong\u003e Switched the publish workflow to npm staged publishing for safer, auditable package releases with provenance. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10926\"\u003e#10926\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚀 New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP Compression:\u003c/strong\u003e Added Node HTTP adapter support for zstd response decompression, with \u003ccode\u003etransitional.advertiseZstdAcceptEncoding\u003c/code\u003e controlling whether \u003ccode\u003ezstd\u003c/code\u003e is advertised in \u003ccode\u003eAccept-Encoding\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/6792\"\u003e#6792\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10920\"\u003e#10920\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eAuthentication Handling:\u003c/strong\u003e Restored Basic auth on same-origin Node redirects while continuing to strip credentials cross-origin, and aligned the fetch adapter with HTTP adapter behavior for URL-embedded Basic auth. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10929\"\u003e#10929\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10896\"\u003e#10896\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eProxy TLS:\u003c/strong\u003e Preserved user \u003ccode\u003ehttpsAgent\u003c/code\u003e TLS options when tunneling HTTPS requests through HTTP CONNECT proxies. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10957\"\u003e#10957\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReact Native FormData:\u003c/strong\u003e Cleared default \u003ccode\u003eContent-Type\u003c/code\u003e for React Native \u003ccode\u003eFormData\u003c/code\u003e so multipart boundaries can be generated correctly. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10898\"\u003e#10898\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/blob/v1.x/CHANGELOG.md\"\u003eaxios's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.18.0 — June 13, 2026\u003c/h2\u003e\n\u003cp\u003eThis release hardens redirect and URL handling, improves the validateStatus configuration semantics, and includes updates to documentation, dependencies, and release metadata.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRedirect Header Safety:\u003c/strong\u003e Added Node HTTP adapter support for stripping caller-specified sensitive headers on cross-origin redirects, helping prevent custom auth headers such as API keys from leaking to another origin. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eURL And Request Hardening:\u003c/strong\u003e Rejects malformed \u003ccode\u003ehttp:\u003c/code\u003e and \u003ccode\u003ehttps:\u003c/code\u003e URLs that omit \u003ccode\u003e//\u003c/code\u003e with \u003ccode\u003eERR_INVALID_URL\u003c/code\u003e, while tightening prototype-pollution-safe config reads, stream size limits, FormData depth handling, data URL sizing, and local \u003ccode\u003eNO_PROXY\u003c/code\u003e matching. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eStatus Validation:\u003c/strong\u003e Added \u003ccode\u003etransitional.validateStatusUndefinedResolves\u003c/code\u003e so applications can opt in to treating \u003ccode\u003evalidateStatus: undefined\u003c/code\u003e like the option was omitted, while \u003ccode\u003evalidateStatus: null\u003c/code\u003e remains the explicit way to accept every status. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation:\u003c/strong\u003e Published the v1.17.0 release notes, fixed a changelog typo, clarified the package update PR policy, and marked the \u003ccode\u003eproxy\u003c/code\u003e request config as Node.js-only in the advanced docs. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDependencies:\u003c/strong\u003e Bumped \u003ccode\u003e@babel/core\u003c/code\u003e, \u003ccode\u003e@babel/preset-env\u003c/code\u003e, \u003ccode\u003e@commitlint/cli\u003c/code\u003e, \u003ccode\u003e@commitlint/config-conventional\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-babel\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-commonjs\u003c/code\u003e, \u003ccode\u003e@vitest/browser\u003c/code\u003e, \u003ccode\u003e@vitest/browser-playwright\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003elint-staged\u003c/code\u003e, \u003ccode\u003erollup\u003c/code\u003e, \u003ccode\u003evitest\u003c/code\u003e, and \u003ccode\u003eactions/checkout\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10996\"\u003e#10996\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10997\"\u003e#10997\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRelease Metadata:\u003c/strong\u003e Prepared the 1.18.0 release by updating package metadata and the runtime \u003ccode\u003eVERSION\u003c/code\u003e value. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/drori12\"\u003e\u003ccode\u003e@​drori12\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/eyupcanakman\"\u003e\u003ccode\u003e@​eyupcanakman\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/Adi-Beker\"\u003e\u003ccode\u003e@​Adi-Beker\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/axios/axios/compare/v1.17.0...v1.18.0\"\u003eFull Changelog\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.17.0 — June 1, 2026\u003c/h2\u003e\n\u003cp\u003eThis release adds Node HTTP zstd decompression, hardens config and release workflows, and fixes authentication, header, proxy, and type-handling regressions.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eConfig Hardening:\u003c/strong\u003e Guarded \u003ccode\u003esocketPath\u003c/code\u003e, \u003ccode\u003eparams\u003c/code\u003e, and \u003ccode\u003eparamsSerializer\u003c/code\u003e reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10901\"\u003e#10901\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10922\"\u003e#10922\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRelease Publishing:\u003c/strong\u003e Switched the publish workflow to npm staged publishing for safer, auditable package releases with provenance. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10926\"\u003e#10926\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚀 New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP Compression:\u003c/strong\u003e Added Node HTTP adapter support for zstd response decompression, with \u003ccode\u003etransitional.advertiseZstdAcceptEncoding\u003c/code\u003e controlling whether \u003ccode\u003ezstd\u003c/code\u003e is advertised in \u003ccode\u003eAccept-Encoding\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/6792\"\u003e#6792\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10920\"\u003e#10920\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eAuthentication Handling:\u003c/strong\u003e Restored Basic auth on same-origin Node redirects while continuing to strip credentials cross-origin, and aligned the fetch adapter with HTTP adapter behavior for URL-embedded Basic auth. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10929\"\u003e#10929\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10896\"\u003e#10896\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eProxy TLS:\u003c/strong\u003e Preserved user \u003ccode\u003ehttpsAgent\u003c/code\u003e TLS options when tunneling HTTPS requests through HTTP CONNECT proxies. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10957\"\u003e#10957\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReact Native FormData:\u003c/strong\u003e Cleared default \u003ccode\u003eContent-Type\u003c/code\u003e for React Native \u003ccode\u003eFormData\u003c/code\u003e so multipart boundaries can be generated correctly. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10898\"\u003e#10898\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/2d06f96e8602c2db13b65a26340ee4a1bbc0b61f\"\u003e\u003ccode\u003e2d06f96\u003c/code\u003e\u003c/a\u003e chore(release): prepare release 1.18.0 (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/32fc489632377d214db55bfa4e2c48486a7d7ce2\"\u003e\u003ccode\u003e32fc489\u003c/code\u003e\u003c/a\u003e fix: malformed http urls (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/b40ce498abfa10d90b873b4fd08f520afa5d2545\"\u003e\u003ccode\u003eb40ce49\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump the development_dependencies group with 10 updates (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10\"\u003e#10\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/fe964f960ecb52c3e1155b0daf7be77541956b01\"\u003e\u003ccode\u003efe964f9\u003c/code\u003e\u003c/a\u003e docs: mark proxy config as Node.js only (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/5f229d2d1f018d1db3dab6bbe034dbf3f9041b99\"\u003e\u003ccode\u003e5f229d2\u003c/code\u003e\u003c/a\u003e chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/fae9d4e7db6a858c407c75e607a071c533c5c4f6\"\u003e\u003ccode\u003efae9d4e\u003c/code\u003e\u003c/a\u003e docs: clarify package update PR policy (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/28ab2ced820e55192806c53472ab3eb0cbb68dc2\"\u003e\u003ccode\u003e28ab2ce\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump the development_dependencies group with 2 updates (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/a8e4f13aeecc45a3b8fab3ecfd9ddb5d70fb772b\"\u003e\u003ccode\u003ea8e4f13\u003c/code\u003e\u003c/a\u003e fix(core): keep default validateStatus when request passes undefined (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/614f4552a17de757d4171ad7c3bd38c9c1025fd8\"\u003e\u003ccode\u003e614f455\u003c/code\u003e\u003c/a\u003e docs: publish v1.17.0 release notes (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/6bb12c191f5380fad321322fb90216ae0dc36985\"\u003e\u003ccode\u003e6bb12c1\u003c/code\u003e\u003c/a\u003e fix: custom auth headers not stripped on cross-origin redirects (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/axios/axios/compare/v1.12.2...v1.18.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for axios since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version modifies \u003ccode\u003eprepare\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.15.0 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.28.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e7 security advisories\u003c/strong\u003e, all shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 7.28.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^7.28.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v7 line is \u003cstrong\u003enot\u003c/strong\u003e affected by GHSA-38rv-x7px-6hhq (CVE-2026-9675), which is\nan 8.x-only regression.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on GHSA-hm92-r4w5-c3mj:\u003c/strong\u003e this fix shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e, not the\nearlier 7.2x line — the vulnerable single-pool code was still present through\n\u003ccode\u003ev7.27.2\u003c/code\u003e. The per-origin pool fix is\n\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5041\"\u003e#5041\u003c/a\u003e).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8cb10f98\"\u003e\u003ccode\u003e8cb10f98\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g\"\u003eGHSA-vmh5-mc38-953g\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9697\u003c/td\u003e\n\u003ctd\u003eHigh (7.4)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/04201f89\"\u003e\u003ccode\u003e04201f89\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj\"\u003eGHSA-hm92-r4w5-c3mj\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6734\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6\"\u003eGHSA-pr7r-676h-xcf6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9678\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/85a24055\"\u003e\u003ccode\u003e85a24055\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ea8930cf\"\u003e\u003ccode\u003eea8930cf\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f9eba0ad9134e1c0977848476bba9d49734696e4\"\u003e\u003ccode\u003ef9eba0a\u003c/code\u003e\u003c/a\u003e Bumped v7.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5430\"\u003e#5430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.15.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for undici since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `dompurify` from 3.2.6 to 3.4.13\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cure53/DOMPurify/releases\"\u003edompurify's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eDOMPurify 3.4.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue with hook removal during \u003ccode\u003eIN_PLACE\u003c/code\u003e sanitization, thanks \u003ca href=\"https://github.com/koyokr\"\u003e\u003ccode\u003e@​koyokr\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue with hooks potentially bypassing the clone guard, thanks \u003ca href=\"https://github.com/AkshayjainG\"\u003e\u003ccode\u003e@​AkshayjainG\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue with DOM clobbering via \u003ccode\u003eownerDocument\u003c/code\u003e during \u003ccode\u003eIN_PLACE\u003c/code\u003e, thanks \u003ca href=\"https://github.com/AkshayjainG\"\u003e\u003ccode\u003e@​AkshayjainG\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where a hook would not get called for custom elements, thanks \u003ca href=\"https://github.com/Rikuxx0\"\u003e\u003ccode\u003e@​Rikuxx0\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHardened the handling of hooks removing elements, \u003ca href=\"https://github.com/mkrause-bee360\"\u003e\u003ccode\u003e@​mkrause-bee360\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded support for a few new SVG attributes, thanks \u003ca href=\"https://github.com/cbn-falias\"\u003e\u003ccode\u003e@​cbn-falias\u003c/code\u003e\u003c/a\u003e \u0026amp; \u003ca href=\"https://github.com/Develop-KIM\"\u003e\u003ccode\u003e@​Develop-KIM\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHardened the handling of declarative partial updates\u003c/li\u003e\n\u003cli\u003eUpdated the documentation is several spots, README, wiki, etc.\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue with a leaky config for hooks via \u003ccode\u003esetConfig\u003c/code\u003e, thanks \u003ca href=\"https://github.com/trace37labs\"\u003e\u003ccode\u003e@​trace37labs\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBumped vulnerable development dependencies to arrive at plain 0 with \u003ccode\u003enpm audit\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eUpdated the \u003ccode\u003eosv-scanner\u003c/code\u003e suppression list as no vulnerable dependencies are left for now\u003c/li\u003e\n\u003cli\u003eUpdated up the linting tool-chain and removed now-redundant lint directives\u003c/li\u003e\n\u003cli\u003eUpdated the documentation is several spots, README, wiki, etc.\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.10\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRefactored codebase for clarity: extracted the public type declarations into \u003ccode\u003etypes.ts\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eDecomposed the three largest sanitizer functions into focused helpers\u003c/li\u003e\n\u003cli\u003eRemoved duplicated defaults and dead branches, consolidated \u003ccode\u003eSAFE_FOR_TEMPLATES\u003c/code\u003e scrubbing into single shared path\u003c/li\u003e\n\u003cli\u003eImproved per-node performance by hoisting the mXSS probe regexes and testing \u003ccode\u003etextContent\u003c/code\u003e before \u003ccode\u003einnerHTML\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdded a deterministic micro-benchmark harness (\u003ccode\u003enpm run bench\u003c/code\u003e) with a \u003ccode\u003e--compare\u003c/code\u003e mode\u003c/li\u003e\n\u003cli\u003eReduced CI cost by running the full three-engine browser suite once per PR\u003c/li\u003e\n\u003cli\u003eRefreshed the \u003ccode\u003edemos/\u003c/code\u003e folder so every demo runs again, and added a SVG-via-\u003ccode\u003e\u0026lt;img\u0026gt;\u003c/code\u003e demo\u003c/li\u003e\n\u003cli\u003eDocumented the bench and \u003ccode\u003etest:happydom\u003c/code\u003e scripts in the README\u003c/li\u003e\n\u003cli\u003eCompleted the Attack Classes \u0026amp; Bypass History wiki page\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFurther improved the handling of Trusted Types config options, thanks \u003ca href=\"https://github.com/offset\"\u003e\u003ccode\u003e@​offset\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFurther improved the handling of \u003ccode\u003eIN_PLACE\u003c/code\u003e sanitization, thanks \u003ca href=\"https://github.com/mozfreddyb\"\u003e\u003ccode\u003e@​mozfreddyb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded more test coverage for \u003ccode\u003eIN_PLACE\u003c/code\u003e and Trusted Types related usage\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003cli\u003eUpdated README and wiki with more accurate documentation \u0026amp; attack samples\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCleaned up the repository root, renamed some and removed unneeded files\u003c/li\u003e\n\u003cli\u003eFixed an issue with handling of Trusted Types policies, thanks \u003ca href=\"https://github.com/fulstadev\"\u003e\u003ccode\u003e@​fulstadev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed the node iterator for better template scrubbing, thanks \u003ca href=\"https://github.com/IamLeandrooooo\"\u003e\u003ccode\u003e@​IamLeandrooooo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIncluded formerly missing LICENSE-MPL in published npm package, thanks \u003ca href=\"https://github.com/asamuzaK\"\u003e\u003ccode\u003e@​asamuzaK\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHardened the handling of Shadow Roots when using \u003ccode\u003eIN_PLACE\u003c/code\u003e, thanks \u003ca href=\"https://github.com/GameZoneHacker\"\u003e\u003ccode\u003e@​GameZoneHacker\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/3067f774676975de12306effd6db6ad7a9a8c17f\"\u003e\u003ccode\u003e3067f77\u003c/code\u003e\u003c/a\u003e release: 3.4.13 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1562\"\u003e#1562\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/a9ca1e537422319a557a9a2aa61f003b23b4a197\"\u003e\u003ccode\u003ea9ca1e5\u003c/code\u003e\u003c/a\u003e release: 3.4.12 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1537\"\u003e#1537\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/0cae5187403132f96a6d357649e4b15633fc210a\"\u003e\u003ccode\u003e0cae518\u003c/code\u003e\u003c/a\u003e release: 3.4.11 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1494\"\u003e#1494\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/6ee5716f8336989753611beeca364957c0eb0c3e\"\u003e\u003ccode\u003e6ee5716\u003c/code\u003e\u003c/a\u003e release: 3.4.10 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1478\"\u003e#1478\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/52102472d46035857c52df19e44285f8a1e102fc\"\u003e\u003ccode\u003e5210247\u003c/code\u003e\u003c/a\u003e release: 3.4.9 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1459\"\u003e#1459\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/bcdd8285412dc9c4c149652aed2d712e790d6ccf\"\u003e\u003ccode\u003ebcdd828\u003c/code\u003e\u003c/a\u003e release: 3.4.8 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1439\"\u003e#1439\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/ca30f070c360df162a3e3848e80e6fd3c9e74bff\"\u003e\u003ccode\u003eca30f07\u003c/code\u003e\u003c/a\u003e release: 3.4.7 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1414\"\u003e#1414\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/bb7739e5bccec7e1ab3dae3f3e42d02db3acaaae\"\u003e\u003ccode\u003ebb7739e\u003c/code\u003e\u003c/a\u003e release: 3.4.6 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1394\"\u003e#1394\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/011b0c78f2a0f57ee54f5fcccb697a46ca6e63ea\"\u003e\u003ccode\u003e011b0c7\u003c/code\u003e\u003c/a\u003e release: 3.4.5 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1382\"\u003e#1382\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/5817ad969c15e67dfcd6cb37248d6e9c1553e7c3\"\u003e\u003ccode\u003e5817ad9\u003c/code\u003e\u003c/a\u003e release: 3.4.4 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1374\"\u003e#1374\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/cure53/DOMPurify/compare/3.2.6...3.4.13\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version adds \u003ccode\u003eprepare\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `shell-quote` from 1.8.2 to 1.9.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md\"\u003eshell-quote's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.4...v1.9.0\"\u003ev1.9.0\u003c/a\u003e - 2026-06-24\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[New] add types \u003ca href=\"https://github.com/ljharb/shell-quote/commit/dca6e21a02df4cc1a83ed1b5baa4d82df134170a\"\u003e\u003ccode\u003edca6e21\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9aa9e8f60991f8c4053a29e476795d891ff851ad\"\u003e\u003ccode\u003e9aa9e8f\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: finalize tokens in linear time (GHSA-395f-4hp3-45gv) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7ff5488599d01c323514f02f5efb74088dd134ec\"\u003e\u003ccode\u003e7ff5488\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] update workflows \u003ca href=\"https://github.com/ljharb/shell-quote/commit/75e849741ffaf2d3aa53ae0e18ef6bf9929ef478\"\u003e\u003ccode\u003e75e8497\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 4/6/7: pin eslint to 9 before install, since npm 2/3 cannot stage eslint 10\u003ccode\u003e@types/esrecurse\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3fb739de44b81c69431947d54fbfc18998dd6d72\"\u003e\u003ccode\u003e3fb739d\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] retry \u003ccode\u003enpm install\u003c/code\u003e on Windows to survive npm 2/3 staging-rename flake \u003ca href=\"https://github.com/ljharb/shell-quote/commit/abe0163293c82963fa8a16cfaa87181846d5aced\"\u003e\u003ccode\u003eabe0163\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 5/7: install deps with a modern node \u003ca href=\"https://github.com/ljharb/shell-quote/commit/b4bafa2e7e58d53d9839b1c24976f61e54b43326\"\u003e\u003ccode\u003eb4bafa2\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: escape leading \u003ccode\u003e~\u003c/code\u003e to prevent shell tilde-expansion \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7a76c1a12d8461c2234a1c655b943cee84cbff91\"\u003e\u003ccode\u003e7a76c1a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7184b4458b65c17b931e126d8cb5f586c6717dc8\"\u003e\u003ccode\u003e7184b44\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] apparently \u003ccode\u003ejackspeak\u003c/code\u003e is no longer in the graph \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9ba368a4057b9f498b0fef23b5b15543ef81b98c\"\u003e\u003ccode\u003e9ba368a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.3...v1.8.4\"\u003ev1.8.4\u003c/a\u003e - 2026-05-22\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: validate object-token shapes \u003ca href=\"https://github.com/ljharb/shell-quote/commit/4378a6e613db5948168684864e49b42b83134d2d\"\u003e\u003ccode\u003e4378a6e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003enpmignore\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/22ebec04349065a45ad8afc8cc8d53c4624634a6\"\u003e\u003ccode\u003e22ebec0\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] increase coverage \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9f3caa31900cc6ee64858b31134144c648ce206d\"\u003e\u003ccode\u003e9f3caa3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] replace runkit CI badge with shields.io check-runs badge \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3344a047dd1e95f71c4ca27522cbfd05c56277e0\"\u003e\u003ccode\u003e3344a04\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/699c5113d135f4d4591574bebf173334ffa453d4\"\u003e\u003ccode\u003e699c511\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.2...v1.8.3\"\u003ev1.8.3\u003c/a\u003e - 2025-06-01\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] remove unnecessary backslash escaping in single quotes \u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/15\"\u003e\u003ccode\u003e[#15](https://github.com/ljharb/shell-quote/issues/15)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/db09fc7a9e3546807c19e2de2682ec31112a6520\"\u003e\u003ccode\u003edb09fc7\u003c/code\u003e\u003c/a\u003e v1.9.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/7ff5488599d01c323514f02f5efb74088dd134ec\"\u003e\u003ccode\u003e7ff5488\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003eparse\u003c/code\u003e: finalize tokens in linear time (GHSA-395f-4hp3-45gv)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/b4bafa2e7e58d53d9839b1c24976f61e54b43326\"\u003e\u003ccode\u003eb4bafa2\u003c/code\u003e\u003c/a\u003e [actions] Windows + node 5/7: install deps with a modern node\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/3fb739de44b81c69431947d54fbfc18998dd6d72\"\u003e\u003ccode\u003e3fb739d\u003c/code\u003e\u003c/a\u003e [actions] Windows + node 4/6/7: pin eslint to 9 before install, since npm 2/3...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/abe0163293c82963fa8a16cfaa87181846d5aced\"\u003e\u003ccode\u003eabe0163\u003c/code\u003e\u003c/a\u003e [actions] retry \u003ccode\u003enpm install\u003c/code\u003e on Windows to survive npm 2/3 staging-rename flake\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/7a76c1a12d8461c2234a1c655b943cee84cbff91\"\u003e\u003ccode\u003e7a76c1a\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003equote\u003c/code\u003e: escape leading \u003ccode\u003e~\u003c/code\u003e to prevent shell tilde-expansion\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/75e849741ffaf2d3aa53ae0e18ef6bf9929ef478\"\u003e\u003ccode\u003e75e8497\u003c/code\u003e\u003c/a\u003e [actions] update workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/dca6e21a02df4cc1a83ed1b5baa4d82df134170a\"\u003e\u003ccode\u003edca6e21\u003c/code\u003e\u003c/a\u003e [New] add types\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/9aa9e8f60991f8c4053a29e476795d891ff851ad\"\u003e\u003ccode\u003e9aa9e8f\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/9ba368a4057b9f498b0fef23b5b15543ef81b98c\"\u003e\u003ccode\u003e9ba368a\u003c/code\u003e\u003c/a\u003e [Dev Deps] apparently \u003ccode\u003ejackspeak\u003c/code\u003e is no longer in the graph\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.2...v1.9.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `next` from 15.2.5 to 15.5.21\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev15.5.21\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eHigh:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-m99w-x7hq-7vfj\"\u003eDenial of Service in App Router using Server Actions\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-6gpp-xcg3-4w24\"\u003eMiddleware / Proxy bypass in App Router applications using Turbopack and single locale\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p9j2-gv94-2wf4\"\u003eServer-Side Request Forgery in rewrites via attacker-controlled destination hostname\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-89xv-2m56-2m9x\"\u003eServer-Side Request Forgery in Server Actions on custom servers\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eModerate:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-68g3-v927-f742\"\u003eCache confusion of response bodies for requests with bodies\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-4633-3j49-mh5q\"\u003eCache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-q8wf-6r8g-63ch\"\u003eDenial of Service in the Image Optimization API using SVGs\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-955p-x3mx-jcvp\"\u003eUnauthenticated disclosure of internal Server Function endpoints\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-4c39-4ccg-62r3\"\u003eUnbounded Server Action payload in Edge runtime\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev15.5.20\u003c/h2\u003e\n\u003cp\u003eContains no changes except publishing \u003ccode\u003e@next/swc-wasm-web\u003c/code\u003e which was accidentally not published since 15.5.15.\u003c/p\u003e\n\u003ch2\u003e15.5.19\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[15.5.x] Don't drop \u003ccode\u003eFormData\u003c/code\u003e entries (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/94244\"\u003e#94244\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[15.5.x] Fix CI (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/94281\"\u003e#94281\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/e26f6ffaa710fc62ca0c8640db0e43b6663edf32\"\u003e\u003ccode\u003ee26f6ff\u003c/code\u003e\u003c/a\u003e v15.5.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/7f5deeb6c594b7515edecb879b0547beba1b8a82\"\u003e\u003ccode\u003e7f5deeb\u003c/code\u003e\u003c/a\u003e [15.x] Improve performance of checking valid MPA form submissions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/57c31f724d746e86a9e8b92aa8be538a922446a4\"\u003e\u003ccode\u003e57c31f7\u003c/code\u003e\u003c/a\u003e [15.x] Enforce \u003ccode\u003eserverActions.bodySizeLimit\u003c/code\u003e for Server Actions in Edge runtime\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/e3e5666ccead3a15162793d697af5e48b7cc0498\"\u003e\u003ccode\u003ee3e5666\u003c/code\u003e\u003c/a\u003e [15.x] Set correct origin for internal redirects in custom server\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/35f501357e9b0fe7c950b0d6aa8fcf5343f707e9\"\u003e\u003ccode\u003e35f5013\u003c/code\u003e\u003c/a\u003e [15.x] Ensure exotic rewrite param values are properly encoded\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/062f66700b52a5d6bba2c0605d55577ab7ad262c\"\u003e\u003ccode\u003e062f667\u003c/code\u003e\u003c/a\u003e [15.x] fix(fetch-cache): key fetch(Request, init) by the effective request\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/577c9dc0a08ac806e35f591fec528d5fb7407ad4\"\u003e\u003ccode\u003e577c9dc\u003c/code\u003e\u003c/a\u003e [15.x] fix(incremental-cache): byte-exact fetch cache key for binary bodies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/530d4fa31e010a05f28ea6e26a5f51f80f61e0c6\"\u003e\u003ccode\u003e530d4fa\u003c/code\u003e\u003c/a\u003e [15.x] fix(next/image): improve performance of detectContentType()\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/8fabaf3225be100d62dfb0f44d85ab43c2a14a20\"\u003e\u003ccode\u003e8fabaf3\u003c/code\u003e\u003c/a\u003e [15.x] Performance improvements when decoding React Server function payloads\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/ff12a6124e1504f17b62de948b8a553fdecaef7b\"\u003e\u003ccode\u003eff12a61\u003c/code\u003e\u003c/a\u003e [15.x] Validate server reference IDs during manifest lookup\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v15.2.5...v15.5.21\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for next since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.4 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003epostcss-scss\u003c/code\u003e commend regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed reading any file via user-generated CSS.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eopts.unsafeMap\u003c/code\u003e to disable checks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed nested brackets parsing performance (by \u003ca href=\"https://github.com/offset\"\u003e\u003ccode\u003e@​offset\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.10\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed XSS via unescaped \u003ccode\u003e\u0026lt;/style\u0026gt;\u003c/code\u003e in non-bundler cases (by \u003ca href=\"https://github.com/TharVid\"\u003e\u003ccode\u003e@​TharVid\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.4...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `electron` from 34.4.1 to 39.8.10\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/electron/electron/releases\"\u003eelectron's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eelectron v39.8.10\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.10\u003c/h1\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!WARNING]\nElectron 39.x.y has reached end-of-support as per the project's \u003ca href=\"https://www.electronjs.org/docs/latest/tutorial/electron-timelines#version-support-policy\"\u003esupport policy\u003c/a\u003e. Developers and applications are encouraged to upgrade to a newer version of Electron.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eFixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnsured cross-origin \u003ccode\u003efetch()\u003c/code\u003e and XHR are blocked for custom protocols registered with \u003ccode\u003esupportFetchAPI: true\u003c/code\u003e unless \u003ccode\u003ecorsEnabled: true\u003c/code\u003e is also set; cross-origin \u003ccode\u003emode: 'no-cors'\u003c/code\u003e requests now receive an opaque response. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51272\"\u003e#51272\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/51271\"\u003e40\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/51270\"\u003e41\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/51269\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue where the Squirrel.Mac installer could resolve the target bundle path to different locations at different stages of an install. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50766\"\u003e#50766\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/50765\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eOther Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackported a fix for route_id validation in the GPU command buffer. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51327\"\u003e#51327\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBackported security fixes for 493319454, 494158331, 493234757, 492736100, 493413432, 492668885, 496281816. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51257\"\u003e#51257\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBackported several fixes in Skia, ANGLE, and WebRTC from upstream. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51266\"\u003e#51266\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eelectron v39.8.9\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.9\u003c/h1\u003e\n\u003ch2\u003eOther Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003egn gen\u003c/code\u003e failing to resolve \u003ccode\u003eelectron_version\u003c/code\u003e when building from a \u003ccode\u003egit worktree\u003c/code\u003e checkout. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51163\"\u003e#51163\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/51164\"\u003e40\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/51165\"\u003e41\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/51166\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: backported fixes for CVE-2026-6296, CVE-2026-6297, CVE-2026-6298, CVE-2026-6299, CVE-2026-6300, CVE-2026-6301, CVE-2026-6302, CVE-2026-6303, CVE-2026-6304, CVE-2026-6305, CVE-2026-6306, CVE-2026-6307, CVE-2026-6308, CVE-2026-6309, CVE-2026-6311, CVE-2026-6312, CVE-2026-6313, CVE-2026-6314, CVE-2026-6316, CVE-2026-6318, CVE-2026-6358, CVE-2026-6359, CVE-2026-6360, CVE-2026-6361, CVE-2026-6362, CVE-2026-6363, CVE-2026-6364. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51141\"\u003e#51141\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eelectron v39.8.8\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.8\u003c/h1\u003e\n\u003ch2\u003eFixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where DevTools would re-attach to the window when opened after previously being detached. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50818\"\u003e#50818\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/50817\"\u003e40\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/50816\"\u003e41\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/50815\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eOther Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackported fix for \u003ca href=\"https://issues.chromium.org/issues/474266014\"\u003echromium:74266014\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50175\"\u003e#50175\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBackported upstream v8 fixes for several maglev, inspector, and arm64 code-generation edge cases. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50993\"\u003e#50993\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eelectron v39.8.7\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.7\u003c/h1\u003e\n\u003ch2\u003eOther Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackported fix for 489711638. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50624\"\u003e#50624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBackported fix for 493952652. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50620\"\u003e#50620\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eelectron v39.8.6\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.6\u003c/h1\u003e\n\u003ch2\u003eFixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a crash when calling \u003ccode\u003econtentTracing.getTraceBufferUsage()\u003c/code\u003e while a trace session is active. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50595\"\u003e#50595\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/50593\"\u003e40\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/50594\"\u003e41\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/50592\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/d7c42ebd5cd501a0e6d9f009e232369832f92d69\"\u003e\u003ccode\u003ed7c42eb\u003c/code\u003e\u003c/a\u003e chore: backport removal of private macOS APIs (\u003ca href=\"https://redirect.github.com/electron/electron/issues/51502\"\u003e#51502\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/c76d48c5d94d4fe621befa1656b998220d016eeb\"\u003e\u003ccode\u003ec76d48c\u003c/code\u003e\u003c/a\u003e build: replace spec dep fork with transitive resolution (\u003ca href=\"https://redirect.github.com/electron/electron/issues/51490\"\u003e#51490\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/3ff23c52ab364a0afc6ab5bd7851291d3159de57\"\u003e\u003ccode\u003e3ff23c5\u003c/code\u003e\u003c/a\u003e fix: respect iframe sandbox flags on the OpenURL navigation path (\u003ca href=\"https://redirect.github.com/electron/electron/issues/51437\"\u003e#51437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/01faabfc250801a980fc94d64608046c67fc1cd9\"\u003e\u003ccode\u003e01faabf\u003c/code\u003e\u003c/a\u003e fix: resolve target bundle path once at start of install (\u003ca href=\"https://redirect.github.com/electron/electron/issues/50766\"\u003e#50766\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/8287d59922c85ea23cf3a540cd1b49b74074853d\"\u003e\u003ccode\u003e8287d59\u003c/code\u003e\u003c/a\u003e build(deps): bump dorny/paths-filter from 3.0.2 to 4.0.1 (\u003ca href=\"https://redirect.github.com/electron/electron/issues/51409\"\u003e#51409\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/a8a79eaf61fb2a211acc2e9f568137db8b47b682\"\u003e\u003ccode\u003ea8a79ea\u003c/code\u003e\u003c/a\u003e ci: backport secondary siso patch (\u003ca href=\"https://redirect.github.com/electron/electron/issues/51390\"\u003e#51390\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/593607e9c072312c4df6b61a83b172e441fdc72f\"\u003e\u003ccode\u003e593607e\u003c/code\u003e\u003c/a\u003e chore: cherry-pick 1 change from chromium (\u003ca href=\"https://redirect.github.com/electron/electron/issues/51327\"\u003e#51327\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/aa7791ff97c9cfcb0cd5e2001f4de704bbdf59cf\"\u003e\u003ccode\u003eaa7791f\u003c/code\u003e\u003c/a\u003e build: restrict npm tarball contents to an explicit allowlist (\u003ca href=\"https://redirect.github.com/electron/electron/issues/51307\"\u003e#51307\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/5392e9a9addc157d5d18e87947deed555488b3b5\"\u003e\u003ccode\u003e5392e9a\u003c/code\u003e\u003c/a\u003e fix: ensure corsEnabled: false protocol handlers do not work across protocols...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/2c24640e7b0b9c74fe9f44bce0fde138340ff4fb\"\u003e\u003ccode\u003e2c24640\u003c/code\u003e\u003c/a\u003e fix: validate OSR frame geometry against shared-memory mapping size (39-x-y) ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/electron/electron/compare/v34.4.1...v39.8.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sharp` from 0.33.5 to 0.34.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lovell/sharp/releases\"\u003esharp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.34.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.17.3 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdd experimental support for prebuilt Linux RISC-V 64-bit binaries.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport building from source with npm v12+, deprecate \u003ccode\u003e--build-from-source\u003c/code\u003e flag.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4458\"\u003e#4458\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdd support for BigTIFF output.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4459\"\u003e#4459\u003c/a\u003e\n\u003ca href=\"https://github.com/throwbi\"\u003e\u003ccode\u003e@​throwbi\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove error messaging when only warnings issued.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4465\"\u003e#4465\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSimplify ICC processing when retaining input profiles.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4468\"\u003e#4468\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.34.5-rc.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.17.3 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdd experimental support for prebuilt Linux RISC-V 64-bit binaries.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport building from source with npm v12+, deprecate \u003ccode\u003e--build-from-source\u003c/code\u003e flag.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4458\"\u003e#4458\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdd support for BigTIFF output.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4459\"\u003e#4459\u003c/a\u003e\n\u003ca href=\"https://github.com/throwbi\"\u003e\u003ccode\u003e@​throwbi\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove error messaging when only warnings issued.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4465\"\u003e#4465\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSimplify ICC processing when retaining input profiles.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4468\"\u003e#4468\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.34.5-rc.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.17.3 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdd experimental support for prebuilt Linux RISC-V 64-bit binaries.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport building from source with npm v12+, deprecate \u003ccode\u003e--build-from-source\u003c/code\u003e flag.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4458\"\u003e#4458\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdd support for BigTIFF output.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4459\"\u003e#4459\u003c/a\u003e\n\u003ca href=\"https://github.com/throwbi\"\u003e\u003ccode\u003e@​throwbi\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove error messaging when only warnings issued.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4465\"\u003e#4465\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e0624568686516209c434de2d3c0ef6688f0811d\"\u003e\u003ccode\u003ee062456\u003c/code\u003e\u003c/a\u003e Release v0.34.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/6450c704a686d4205a2c21ddb1d10d5fc28c6c23\"\u003e\u003ccode\u003e6450c70\u003c/code\u003e\u003c/a\u003e Prerelease v0.34.5-rc.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/f7c95d1bf0f24049ee6ee77b21b1c1bb8d181aa2\"\u003e\u003ccode\u003ef7c95d1\u003c/code\u003e\u003c/a\u003e TypeScript: consolidate a few enum-like properties\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ef86a75560adb40605d3dfc85dc3656a0b88c413\"\u003e\u003ccode\u003eef86a75\u003c/code\u003e\u003c/a\u003e Prerelease v0.34.5-rc.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/6c1e840098ea4a25d833518b30703d9b0af83d32\"\u003e\u003ccode\u003e6c1e840\u003c/code\u003e\u003c/a\u003e Use structured binding for tuples where possible\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e1628d8ef5033dedde9ed1ddd4dd681e1fc30e1e\"\u003e\u003ccode\u003ee1628d8\u003c/code\u003e\u003c/a\u003e Simplify ICC processing when retaining input profiles \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4468\"\u003e#4468\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/4f9f8179a6350448a32851e5daf5508d61c727ba\"\u003e\u003ccode\u003e4f9f817\u003c/code\u003e\u003c/a\u003e Linter: apply all recommended biome settings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/09d5aa8cfa09522ddc67342295cb75ab1d044b09\"\u003e\u003ccode\u003e09d5aa8\u003c/code\u003e\u003c/a\u003e Docs: update internal and libvips doc links\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/040b73ca746f4b8e71950708de4a464c7ba6a188\"\u003e\u003ccode\u003e040b73c\u003c/code\u003e\u003c/a\u003e Upgrade to libvips v8.17.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/1f2f33d9a7eb8ffba91b8576e49a39df5fdebb76\"\u003e\u003ccode\u003e1f2f33d\u003c/code\u003e\u003c/a\u003e Ensure licensing headers are retained by code bundlers\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lovell/sharp/compare/v0.33.5...v0.34.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for sharp since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version modifies \u003ccode\u003einstall\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.16.0 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca...\n\n_Description has been truncated_\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nUpgrade dependencies across the monorepo to pick up security fixes and platform updates, including `next`, `axios`, `undici`, `postcss`, `dompurify`, `shell-quote`, and `electron`. This hardens networking, sanitization, and build tooling with minimal code changes expected.\n\n- **Dependencies**\n  - Web: `next` 15.5.21 and `postcss` 8.5.23 with fixes for SSRF, DoS, cache confusion, and safer source map handling.\n  - Networking: `axios` 1.18.0 and `undici` 7.29.0 tighten redirect/header handling, URL validation, cache parsing, and cookie validation.\n  - Sanitization/Parsing: `dompurify` 3.4.13 hardens hooks and in-place sanitization; `shell-quote` 1.9.0 adds types and fixes parsing/quoting.\n  - Desktop host: `electron` 39.8.10 brings backported security fixes and stricter custom protocol CORS behavior.\n\n- **Migration**\n  - Electron custom protocols: set `corsEnabled: true` if used with `supportFetchAPI: true`; otherwise cross-origin `fetch`/XHR will be blocked. Re-test packaging and DevTools flows.\n  - Axios: malformed `http:`/`https:` URLs without `//` now reject; verify any custom `validateStatus` usage.\n  - PostCSS: if running PostCSS directly, ensure `opts.from` is set when loading source maps.\n\n\u003csup\u003eWritten for commit 6ad731aff0a83f4e3688fb115c080c595e002023. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/ThePlenkov/kilocode/pull/3?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/ThePlenkov/kilocode/pull/3","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ThePlenkov%2Fkilocode/issues/3","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/3/packages"},{"uuid":"5092852177","node_id":"PR_kwDOQ77-1M78K06R","number":2705,"state":"open","title":"chore(deps): bump undici from 6.27.0 to 6.28.0 in the npm-security group across 1 directory","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T18:15:57.000Z","updated_at":"2026-08-07T18:15:58.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"undici","old_version":"6.27.0","new_version":"6.28.0","repository_url":"https://github.com/nodejs/undici"}],"path":"the npm-security group across 1 directory","ecosystem":"npm"},"body":"Bumps the npm-security group with 1 update in the / directory: [undici](https://github.com/nodejs/undici).\n\nUpdates `undici` from 6.27.0 to 6.28.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.28.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e740a0b7c\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003ecba3a52a\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e4fd5a0c6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003eaf748404\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e and \u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ehttps://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a\"\u003e\u003ccode\u003e01a912e\u003c/code\u003e\u003c/a\u003e Bumped v6.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5591\"\u003e#5591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e\"\u003e\u003ccode\u003e481ecfc\u003c/code\u003e\u003c/a\u003e Use Node 22 and npm 11 to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e\u003ccode\u003e740a0b7\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0\"\u003e\u003ccode\u003e2698e49\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e\u003ccode\u003e4fd5a0c\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003e\u003ccode\u003ecba3a52\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003e\u003ccode\u003eaf74840\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=6.27.0\u0026new-version=6.28.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/affaan-m/ECC/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/affaan-m/ECC/pull/2705","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/affaan-m%2FECC/issues/2705","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2705/packages"},{"uuid":"5092225805","node_id":"PR_kwDOQUVehM78I03U","number":2,"state":"open","title":"build(deps): bump the npm_and_yarn group across 3 directories with 9 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T16:47:55.000Z","updated_at":"2026-08-07T16:49:05.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":9,"packages":[{"name":"axios","old_version":"1.12.2","new_version":"1.18.0","repository_url":"https://github.com/axios/axios"},{"name":"undici","old_version":"7.15.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"},{"name":"dompurify","old_version":"3.2.6","new_version":"3.4.13","repository_url":"https://github.com/cure53/DOMPurify"},{"name":"shell-quote","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/ljharb/shell-quote"},{"name":"vite","old_version":"6.3.5","new_version":"6.4.3","repository_url":"https://github.com/vitejs/vite"},{"name":"next","old_version":"15.2.5","new_version":"15.5.21","repository_url":"https://github.com/vercel/next.js"},{"name":"postcss","old_version":"8.5.4","new_version":"8.5.23","repository_url":"https://github.com/postcss/postcss"},{"name":"electron","old_version":"34.4.1","new_version":"39.8.10","repository_url":"https://github.com/electron/electron"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 8 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [axios](https://github.com/axios/axios) | `1.12.2` | `1.18.0` |\n| [undici](https://github.com/nodejs/undici) | `7.15.0` | `7.29.0` |\n| [dompurify](https://github.com/cure53/DOMPurify) | `3.2.6` | `3.4.13` |\n| [shell-quote](https://github.com/ljharb/shell-quote) | `1.8.2` | `1.9.0` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `6.3.5` | `6.4.3` |\n| [next](https://github.com/vercel/next.js) | `15.2.5` | `15.5.21` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.4` | `8.5.23` |\n| [electron](https://github.com/electron/electron) | `34.4.1` | `39.8.10` |\n\nBumps the npm_and_yarn group with 3 updates in the /jetbrains/host directory: [undici](https://github.com/nodejs/undici), [postcss](https://github.com/postcss/postcss) and [electron](https://github.com/electron/electron).\nBumps the npm_and_yarn group with 4 updates in the /webview-ui directory: [axios](https://github.com/axios/axios), [dompurify](https://github.com/cure53/DOMPurify), [shell-quote](https://github.com/ljharb/shell-quote) and [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite).\n\nUpdates `axios` from 1.12.2 to 1.18.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/releases\"\u003eaxios's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.18.0 — June 13, 2026\u003c/h2\u003e\n\u003cp\u003eThis release hardens redirect and URL handling, improves the validateStatus configuration semantics, and includes updates to documentation, dependencies, and release metadata.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRedirect Header Safety:\u003c/strong\u003e Added Node HTTP adapter support for stripping caller-specified sensitive headers on cross-origin redirects, helping prevent custom auth headers such as API keys from leaking to another origin. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eURL And Request Hardening:\u003c/strong\u003e Rejects malformed \u003ccode\u003ehttp:\u003c/code\u003e and \u003ccode\u003ehttps:\u003c/code\u003e URLs that omit \u003ccode\u003e//\u003c/code\u003e with \u003ccode\u003eERR_INVALID_URL\u003c/code\u003e, while tightening prototype-pollution-safe config reads, stream size limits, FormData depth handling, data URL sizing, and local \u003ccode\u003eNO_PROXY\u003c/code\u003e matching. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eStatus Validation:\u003c/strong\u003e Added \u003ccode\u003etransitional.validateStatusUndefinedResolves\u003c/code\u003e so applications can opt in to treating \u003ccode\u003evalidateStatus: undefined\u003c/code\u003e like the option was omitted, while \u003ccode\u003evalidateStatus: null\u003c/code\u003e remains the explicit way to accept every status. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation:\u003c/strong\u003e Published the v1.17.0 release notes, fixed a changelog typo, clarified the package update PR policy, and marked the \u003ccode\u003eproxy\u003c/code\u003e request config as Node.js-only in the advanced docs. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDependencies:\u003c/strong\u003e Bumped \u003ccode\u003e@babel/core\u003c/code\u003e, \u003ccode\u003e@babel/preset-env\u003c/code\u003e, \u003ccode\u003e@commitlint/cli\u003c/code\u003e, \u003ccode\u003e@commitlint/config-conventional\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-babel\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-commonjs\u003c/code\u003e, \u003ccode\u003e@vitest/browser\u003c/code\u003e, \u003ccode\u003e@vitest/browser-playwright\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003elint-staged\u003c/code\u003e, \u003ccode\u003erollup\u003c/code\u003e, \u003ccode\u003evitest\u003c/code\u003e, and \u003ccode\u003eactions/checkout\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10996\"\u003e#10996\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10997\"\u003e#10997\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRelease Metadata:\u003c/strong\u003e Prepared the 1.18.0 release by updating package metadata and the runtime \u003ccode\u003eVERSION\u003c/code\u003e value. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/drori12\"\u003e\u003ccode\u003e@​drori12\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/eyupcanakman\"\u003e\u003ccode\u003e@​eyupcanakman\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/Adi-Beker\"\u003e\u003ccode\u003e@​Adi-Beker\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/axios/axios/compare/v1.17.0...v1.18.0\"\u003eFull Changelog\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.17.0 — June 1, 2026\u003c/h2\u003e\n\u003cp\u003eThis release adds Node HTTP zstd decompression, hardens config and release workflows, and fixes authentication, header, proxy, and type-handling regressions.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eConfig Hardening:\u003c/strong\u003e Guarded \u003ccode\u003esocketPath\u003c/code\u003e, \u003ccode\u003eparams\u003c/code\u003e, and \u003ccode\u003eparamsSerializer\u003c/code\u003e reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10901\"\u003e#10901\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10922\"\u003e#10922\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRelease Publishing:\u003c/strong\u003e Switched the publish workflow to npm staged publishing for safer, auditable package releases with provenance. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10926\"\u003e#10926\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚀 New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP Compression:\u003c/strong\u003e Added Node HTTP adapter support for zstd response decompression, with \u003ccode\u003etransitional.advertiseZstdAcceptEncoding\u003c/code\u003e controlling whether \u003ccode\u003ezstd\u003c/code\u003e is advertised in \u003ccode\u003eAccept-Encoding\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/6792\"\u003e#6792\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10920\"\u003e#10920\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eAuthentication Handling:\u003c/strong\u003e Restored Basic auth on same-origin Node redirects while continuing to strip credentials cross-origin, and aligned the fetch adapter with HTTP adapter behavior for URL-embedded Basic auth. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10929\"\u003e#10929\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10896\"\u003e#10896\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eProxy TLS:\u003c/strong\u003e Preserved user \u003ccode\u003ehttpsAgent\u003c/code\u003e TLS options when tunneling HTTPS requests through HTTP CONNECT proxies. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10957\"\u003e#10957\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReact Native FormData:\u003c/strong\u003e Cleared default \u003ccode\u003eContent-Type\u003c/code\u003e for React Native \u003ccode\u003eFormData\u003c/code\u003e so multipart boundaries can be generated correctly. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10898\"\u003e#10898\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/blob/v1.x/CHANGELOG.md\"\u003eaxios's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.18.0 — June 13, 2026\u003c/h2\u003e\n\u003cp\u003eThis release hardens redirect and URL handling, improves the validateStatus configuration semantics, and includes updates to documentation, dependencies, and release metadata.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRedirect Header Safety:\u003c/strong\u003e Added Node HTTP adapter support for stripping caller-specified sensitive headers on cross-origin redirects, helping prevent custom auth headers such as API keys from leaking to another origin. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eURL And Request Hardening:\u003c/strong\u003e Rejects malformed \u003ccode\u003ehttp:\u003c/code\u003e and \u003ccode\u003ehttps:\u003c/code\u003e URLs that omit \u003ccode\u003e//\u003c/code\u003e with \u003ccode\u003eERR_INVALID_URL\u003c/code\u003e, while tightening prototype-pollution-safe config reads, stream size limits, FormData depth handling, data URL sizing, and local \u003ccode\u003eNO_PROXY\u003c/code\u003e matching. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eStatus Validation:\u003c/strong\u003e Added \u003ccode\u003etransitional.validateStatusUndefinedResolves\u003c/code\u003e so applications can opt in to treating \u003ccode\u003evalidateStatus: undefined\u003c/code\u003e like the option was omitted, while \u003ccode\u003evalidateStatus: null\u003c/code\u003e remains the explicit way to accept every status. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation:\u003c/strong\u003e Published the v1.17.0 release notes, fixed a changelog typo, clarified the package update PR policy, and marked the \u003ccode\u003eproxy\u003c/code\u003e request config as Node.js-only in the advanced docs. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDependencies:\u003c/strong\u003e Bumped \u003ccode\u003e@babel/core\u003c/code\u003e, \u003ccode\u003e@babel/preset-env\u003c/code\u003e, \u003ccode\u003e@commitlint/cli\u003c/code\u003e, \u003ccode\u003e@commitlint/config-conventional\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-babel\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-commonjs\u003c/code\u003e, \u003ccode\u003e@vitest/browser\u003c/code\u003e, \u003ccode\u003e@vitest/browser-playwright\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003elint-staged\u003c/code\u003e, \u003ccode\u003erollup\u003c/code\u003e, \u003ccode\u003evitest\u003c/code\u003e, and \u003ccode\u003eactions/checkout\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10996\"\u003e#10996\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10997\"\u003e#10997\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRelease Metadata:\u003c/strong\u003e Prepared the 1.18.0 release by updating package metadata and the runtime \u003ccode\u003eVERSION\u003c/code\u003e value. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/drori12\"\u003e\u003ccode\u003e@​drori12\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/eyupcanakman\"\u003e\u003ccode\u003e@​eyupcanakman\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/Adi-Beker\"\u003e\u003ccode\u003e@​Adi-Beker\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/axios/axios/compare/v1.17.0...v1.18.0\"\u003eFull Changelog\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.17.0 — June 1, 2026\u003c/h2\u003e\n\u003cp\u003eThis release adds Node HTTP zstd decompression, hardens config and release workflows, and fixes authentication, header, proxy, and type-handling regressions.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eConfig Hardening:\u003c/strong\u003e Guarded \u003ccode\u003esocketPath\u003c/code\u003e, \u003ccode\u003eparams\u003c/code\u003e, and \u003ccode\u003eparamsSerializer\u003c/code\u003e reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10901\"\u003e#10901\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10922\"\u003e#10922\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRelease Publishing:\u003c/strong\u003e Switched the publish workflow to npm staged publishing for safer, auditable package releases with provenance. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10926\"\u003e#10926\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚀 New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP Compression:\u003c/strong\u003e Added Node HTTP adapter support for zstd response decompression, with \u003ccode\u003etransitional.advertiseZstdAcceptEncoding\u003c/code\u003e controlling whether \u003ccode\u003ezstd\u003c/code\u003e is advertised in \u003ccode\u003eAccept-Encoding\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/6792\"\u003e#6792\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10920\"\u003e#10920\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eAuthentication Handling:\u003c/strong\u003e Restored Basic auth on same-origin Node redirects while continuing to strip credentials cross-origin, and aligned the fetch adapter with HTTP adapter behavior for URL-embedded Basic auth. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10929\"\u003e#10929\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10896\"\u003e#10896\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eProxy TLS:\u003c/strong\u003e Preserved user \u003ccode\u003ehttpsAgent\u003c/code\u003e TLS options when tunneling HTTPS requests through HTTP CONNECT proxies. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10957\"\u003e#10957\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReact Native FormData:\u003c/strong\u003e Cleared default \u003ccode\u003eContent-Type\u003c/code\u003e for React Native \u003ccode\u003eFormData\u003c/code\u003e so multipart boundaries can be generated correctly. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10898\"\u003e#10898\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/2d06f96e8602c2db13b65a26340ee4a1bbc0b61f\"\u003e\u003ccode\u003e2d06f96\u003c/code\u003e\u003c/a\u003e chore(release): prepare release 1.18.0 (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/32fc489632377d214db55bfa4e2c48486a7d7ce2\"\u003e\u003ccode\u003e32fc489\u003c/code\u003e\u003c/a\u003e fix: malformed http urls (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/b40ce498abfa10d90b873b4fd08f520afa5d2545\"\u003e\u003ccode\u003eb40ce49\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump the development_dependencies group with 10 updates (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10\"\u003e#10\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/fe964f960ecb52c3e1155b0daf7be77541956b01\"\u003e\u003ccode\u003efe964f9\u003c/code\u003e\u003c/a\u003e docs: mark proxy config as Node.js only (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/5f229d2d1f018d1db3dab6bbe034dbf3f9041b99\"\u003e\u003ccode\u003e5f229d2\u003c/code\u003e\u003c/a\u003e chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/fae9d4e7db6a858c407c75e607a071c533c5c4f6\"\u003e\u003ccode\u003efae9d4e\u003c/code\u003e\u003c/a\u003e docs: clarify package update PR policy (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/28ab2ced820e55192806c53472ab3eb0cbb68dc2\"\u003e\u003ccode\u003e28ab2ce\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump the development_dependencies group with 2 updates (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/a8e4f13aeecc45a3b8fab3ecfd9ddb5d70fb772b\"\u003e\u003ccode\u003ea8e4f13\u003c/code\u003e\u003c/a\u003e fix(core): keep default validateStatus when request passes undefined (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/614f4552a17de757d4171ad7c3bd38c9c1025fd8\"\u003e\u003ccode\u003e614f455\u003c/code\u003e\u003c/a\u003e docs: publish v1.17.0 release notes (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/6bb12c191f5380fad321322fb90216ae0dc36985\"\u003e\u003ccode\u003e6bb12c1\u003c/code\u003e\u003c/a\u003e fix: custom auth headers not stripped on cross-origin redirects (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/axios/axios/compare/v1.12.2...v1.18.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for axios since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version modifies \u003ccode\u003eprepare\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.15.0 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.28.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e7 security advisories\u003c/strong\u003e, all shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 7.28.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^7.28.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v7 line is \u003cstrong\u003enot\u003c/strong\u003e affected by GHSA-38rv-x7px-6hhq (CVE-2026-9675), which is\nan 8.x-only regression.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on GHSA-hm92-r4w5-c3mj:\u003c/strong\u003e this fix shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e, not the\nearlier 7.2x line — the vulnerable single-pool code was still present through\n\u003ccode\u003ev7.27.2\u003c/code\u003e. The per-origin pool fix is\n\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5041\"\u003e#5041\u003c/a\u003e).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8cb10f98\"\u003e\u003ccode\u003e8cb10f98\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g\"\u003eGHSA-vmh5-mc38-953g\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9697\u003c/td\u003e\n\u003ctd\u003eHigh (7.4)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/04201f89\"\u003e\u003ccode\u003e04201f89\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj\"\u003eGHSA-hm92-r4w5-c3mj\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6734\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6\"\u003eGHSA-pr7r-676h-xcf6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9678\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/85a24055\"\u003e\u003ccode\u003e85a24055\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ea8930cf\"\u003e\u003ccode\u003eea8930cf\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f9eba0ad9134e1c0977848476bba9d49734696e4\"\u003e\u003ccode\u003ef9eba0a\u003c/code\u003e\u003c/a\u003e Bumped v7.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5430\"\u003e#5430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.15.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for undici since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `dompurify` from 3.2.6 to 3.4.13\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cure53/DOMPurify/releases\"\u003edompurify's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eDOMPurify 3.4.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue with hook removal during \u003ccode\u003eIN_PLACE\u003c/code\u003e sanitization, thanks \u003ca href=\"https://github.com/koyokr\"\u003e\u003ccode\u003e@​koyokr\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue with hooks potentially bypassing the clone guard, thanks \u003ca href=\"https://github.com/AkshayjainG\"\u003e\u003ccode\u003e@​AkshayjainG\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue with DOM clobbering via \u003ccode\u003eownerDocument\u003c/code\u003e during \u003ccode\u003eIN_PLACE\u003c/code\u003e, thanks \u003ca href=\"https://github.com/AkshayjainG\"\u003e\u003ccode\u003e@​AkshayjainG\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where a hook would not get called for custom elements, thanks \u003ca href=\"https://github.com/Rikuxx0\"\u003e\u003ccode\u003e@​Rikuxx0\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHardened the handling of hooks removing elements, \u003ca href=\"https://github.com/mkrause-bee360\"\u003e\u003ccode\u003e@​mkrause-bee360\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded support for a few new SVG attributes, thanks \u003ca href=\"https://github.com/cbn-falias\"\u003e\u003ccode\u003e@​cbn-falias\u003c/code\u003e\u003c/a\u003e \u0026amp; \u003ca href=\"https://github.com/Develop-KIM\"\u003e\u003ccode\u003e@​Develop-KIM\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHardened the handling of declarative partial updates\u003c/li\u003e\n\u003cli\u003eUpdated the documentation is several spots, README, wiki, etc.\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue with a leaky config for hooks via \u003ccode\u003esetConfig\u003c/code\u003e, thanks \u003ca href=\"https://github.com/trace37labs\"\u003e\u003ccode\u003e@​trace37labs\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBumped vulnerable development dependencies to arrive at plain 0 with \u003ccode\u003enpm audit\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eUpdated the \u003ccode\u003eosv-scanner\u003c/code\u003e suppression list as no vulnerable dependencies are left for now\u003c/li\u003e\n\u003cli\u003eUpdated up the linting tool-chain and removed now-redundant lint directives\u003c/li\u003e\n\u003cli\u003eUpdated the documentation is several spots, README, wiki, etc.\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.10\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRefactored codebase for clarity: extracted the public type declarations into \u003ccode\u003etypes.ts\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eDecomposed the three largest sanitizer functions into focused helpers\u003c/li\u003e\n\u003cli\u003eRemoved duplicated defaults and dead branches, consolidated \u003ccode\u003eSAFE_FOR_TEMPLATES\u003c/code\u003e scrubbing into single shared path\u003c/li\u003e\n\u003cli\u003eImproved per-node performance by hoisting the mXSS probe regexes and testing \u003ccode\u003etextContent\u003c/code\u003e before \u003ccode\u003einnerHTML\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdded a deterministic micro-benchmark harness (\u003ccode\u003enpm run bench\u003c/code\u003e) with a \u003ccode\u003e--compare\u003c/code\u003e mode\u003c/li\u003e\n\u003cli\u003eReduced CI cost by running the full three-engine browser suite once per PR\u003c/li\u003e\n\u003cli\u003eRefreshed the \u003ccode\u003edemos/\u003c/code\u003e folder so every demo runs again, and added a SVG-via-\u003ccode\u003e\u0026lt;img\u0026gt;\u003c/code\u003e demo\u003c/li\u003e\n\u003cli\u003eDocumented the bench and \u003ccode\u003etest:happydom\u003c/code\u003e scripts in the README\u003c/li\u003e\n\u003cli\u003eCompleted the Attack Classes \u0026amp; Bypass History wiki page\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFurther improved the handling of Trusted Types config options, thanks \u003ca href=\"https://github.com/offset\"\u003e\u003ccode\u003e@​offset\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFurther improved the handling of \u003ccode\u003eIN_PLACE\u003c/code\u003e sanitization, thanks \u003ca href=\"https://github.com/mozfreddyb\"\u003e\u003ccode\u003e@​mozfreddyb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded more test coverage for \u003ccode\u003eIN_PLACE\u003c/code\u003e and Trusted Types related usage\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003cli\u003eUpdated README and wiki with more accurate documentation \u0026amp; attack samples\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCleaned up the repository root, renamed some and removed unneeded files\u003c/li\u003e\n\u003cli\u003eFixed an issue with handling of Trusted Types policies, thanks \u003ca href=\"https://github.com/fulstadev\"\u003e\u003ccode\u003e@​fulstadev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed the node iterator for better template scrubbing, thanks \u003ca href=\"https://github.com/IamLeandrooooo\"\u003e\u003ccode\u003e@​IamLeandrooooo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIncluded formerly missing LICENSE-MPL in published npm package, thanks \u003ca href=\"https://github.com/asamuzaK\"\u003e\u003ccode\u003e@​asamuzaK\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHardened the handling of Shadow Roots when using \u003ccode\u003eIN_PLACE\u003c/code\u003e, thanks \u003ca href=\"https://github.com/GameZoneHacker\"\u003e\u003ccode\u003e@​GameZoneHacker\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/3067f774676975de12306effd6db6ad7a9a8c17f\"\u003e\u003ccode\u003e3067f77\u003c/code\u003e\u003c/a\u003e release: 3.4.13 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1562\"\u003e#1562\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/a9ca1e537422319a557a9a2aa61f003b23b4a197\"\u003e\u003ccode\u003ea9ca1e5\u003c/code\u003e\u003c/a\u003e release: 3.4.12 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1537\"\u003e#1537\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/0cae5187403132f96a6d357649e4b15633fc210a\"\u003e\u003ccode\u003e0cae518\u003c/code\u003e\u003c/a\u003e release: 3.4.11 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1494\"\u003e#1494\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/6ee5716f8336989753611beeca364957c0eb0c3e\"\u003e\u003ccode\u003e6ee5716\u003c/code\u003e\u003c/a\u003e release: 3.4.10 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1478\"\u003e#1478\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/52102472d46035857c52df19e44285f8a1e102fc\"\u003e\u003ccode\u003e5210247\u003c/code\u003e\u003c/a\u003e release: 3.4.9 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1459\"\u003e#1459\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/bcdd8285412dc9c4c149652aed2d712e790d6ccf\"\u003e\u003ccode\u003ebcdd828\u003c/code\u003e\u003c/a\u003e release: 3.4.8 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1439\"\u003e#1439\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/ca30f070c360df162a3e3848e80e6fd3c9e74bff\"\u003e\u003ccode\u003eca30f07\u003c/code\u003e\u003c/a\u003e release: 3.4.7 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1414\"\u003e#1414\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/bb7739e5bccec7e1ab3dae3f3e42d02db3acaaae\"\u003e\u003ccode\u003ebb7739e\u003c/code\u003e\u003c/a\u003e release: 3.4.6 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1394\"\u003e#1394\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/011b0c78f2a0f57ee54f5fcccb697a46ca6e63ea\"\u003e\u003ccode\u003e011b0c7\u003c/code\u003e\u003c/a\u003e release: 3.4.5 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1382\"\u003e#1382\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/5817ad969c15e67dfcd6cb37248d6e9c1553e7c3\"\u003e\u003ccode\u003e5817ad9\u003c/code\u003e\u003c/a\u003e release: 3.4.4 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1374\"\u003e#1374\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/cure53/DOMPurify/compare/3.2.6...3.4.13\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version adds \u003ccode\u003eprepare\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `shell-quote` from 1.8.2 to 1.9.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md\"\u003eshell-quote's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.4...v1.9.0\"\u003ev1.9.0\u003c/a\u003e - 2026-06-24\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[New] add types \u003ca href=\"https://github.com/ljharb/shell-quote/commit/dca6e21a02df4cc1a83ed1b5baa4d82df134170a\"\u003e\u003ccode\u003edca6e21\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9aa9e8f60991f8c4053a29e476795d891ff851ad\"\u003e\u003ccode\u003e9aa9e8f\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: finalize tokens in linear time (GHSA-395f-4hp3-45gv) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7ff5488599d01c323514f02f5efb74088dd134ec\"\u003e\u003ccode\u003e7ff5488\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] update workflows \u003ca href=\"https://github.com/ljharb/shell-quote/commit/75e849741ffaf2d3aa53ae0e18ef6bf9929ef478\"\u003e\u003ccode\u003e75e8497\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 4/6/7: pin eslint to 9 before install, since npm 2/3 cannot stage eslint 10\u003ccode\u003e@types/esrecurse\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3fb739de44b81c69431947d54fbfc18998dd6d72\"\u003e\u003ccode\u003e3fb739d\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] retry \u003ccode\u003enpm install\u003c/code\u003e on Windows to survive npm 2/3 staging-rename flake \u003ca href=\"https://github.com/ljharb/shell-quote/commit/abe0163293c82963fa8a16cfaa87181846d5aced\"\u003e\u003ccode\u003eabe0163\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 5/7: install deps with a modern node \u003ca href=\"https://github.com/ljharb/shell-quote/commit/b4bafa2e7e58d53d9839b1c24976f61e54b43326\"\u003e\u003ccode\u003eb4bafa2\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: escape leading \u003ccode\u003e~\u003c/code\u003e to prevent shell tilde-expansion \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7a76c1a12d8461c2234a1c655b943cee84cbff91\"\u003e\u003ccode\u003e7a76c1a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7184b4458b65c17b931e126d8cb5f586c6717dc8\"\u003e\u003ccode\u003e7184b44\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] apparently \u003ccode\u003ejackspeak\u003c/code\u003e is no longer in the graph \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9ba368a4057b9f498b0fef23b5b15543ef81b98c\"\u003e\u003ccode\u003e9ba368a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.3...v1.8.4\"\u003ev1.8.4\u003c/a\u003e - 2026-05-22\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: validate object-token shapes \u003ca href=\"https://github.com/ljharb/shell-quote/commit/4378a6e613db5948168684864e49b42b83134d2d\"\u003e\u003ccode\u003e4378a6e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003enpmignore\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/22ebec04349065a45ad8afc8cc8d53c4624634a6\"\u003e\u003ccode\u003e22ebec0\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] increase coverage \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9f3caa31900cc6ee64858b31134144c648ce206d\"\u003e\u003ccode\u003e9f3caa3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] replace runkit CI badge with shields.io check-runs badge \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3344a047dd1e95f71c4ca27522cbfd05c56277e0\"\u003e\u003ccode\u003e3344a04\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/699c5113d135f4d4591574bebf173334ffa453d4\"\u003e\u003ccode\u003e699c511\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.2...v1.8.3\"\u003ev1.8.3\u003c/a\u003e - 2025-06-01\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] remove unnecessary backslash escaping in single quotes \u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/15\"\u003e\u003ccode\u003e[#15](https://github.com/ljharb/shell-quote/issues/15)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/db09fc7a9e3546807c19e2de2682ec31112a6520\"\u003e\u003ccode\u003edb09fc7\u003c/code\u003e\u003c/a\u003e v1.9.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/7ff5488599d01c323514f02f5efb74088dd134ec\"\u003e\u003ccode\u003e7ff5488\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003eparse\u003c/code\u003e: finalize tokens in linear time (GHSA-395f-4hp3-45gv)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/b4bafa2e7e58d53d9839b1c24976f61e54b43326\"\u003e\u003ccode\u003eb4bafa2\u003c/code\u003e\u003c/a\u003e [actions] Windows + node 5/7: install deps with a modern node\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/3fb739de44b81c69431947d54fbfc18998dd6d72\"\u003e\u003ccode\u003e3fb739d\u003c/code\u003e\u003c/a\u003e [actions] Windows + node 4/6/7: pin eslint to 9 before install, since npm 2/3...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/abe0163293c82963fa8a16cfaa87181846d5aced\"\u003e\u003ccode\u003eabe0163\u003c/code\u003e\u003c/a\u003e [actions] retry \u003ccode\u003enpm install\u003c/code\u003e on Windows to survive npm 2/3 staging-rename flake\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/7a76c1a12d8461c2234a1c655b943cee84cbff91\"\u003e\u003ccode\u003e7a76c1a\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003equote\u003c/code\u003e: escape leading \u003ccode\u003e~\u003c/code\u003e to prevent shell tilde-expansion\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/75e849741ffaf2d3aa53ae0e18ef6bf9929ef478\"\u003e\u003ccode\u003e75e8497\u003c/code\u003e\u003c/a\u003e [actions] update workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/dca6e21a02df4cc1a83ed1b5baa4d82df134170a\"\u003e\u003ccode\u003edca6e21\u003c/code\u003e\u003c/a\u003e [New] add types\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/9aa9e8f60991f8c4053a29e476795d891ff851ad\"\u003e\u003ccode\u003e9aa9e8f\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/9ba368a4057b9f498b0fef23b5b15543ef81b98c\"\u003e\u003ccode\u003e9ba368a\u003c/code\u003e\u003c/a\u003e [Dev Deps] apparently \u003ccode\u003ejackspeak\u003c/code\u003e is no longer in the graph\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.2...v1.9.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `vite` from 6.3.5 to 6.4.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/releases\"\u003evite's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.4.3\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v6.4.3/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev6.4.2\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v6.4.2/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev6.4.1\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v6.4.1/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev6.4.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v6.4.0/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev6.3.7\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v6.3.7/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/blob/v6.4.3/packages/vite/CHANGELOG.md\"\u003evite's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e6.4.3 (2026-06-01)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22576\"\u003e#22576\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/96b0c10162e9c55485d922db2cfc6b8227cbc176\"\u003e96b0c10\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22572\"\u003e#22572\u003c/a\u003e \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22576\"\u003e#22576\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(deps): backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22575\"\u003e#22575\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8fed5cf540c0d475266787f52072f258478cd42f\"\u003e8fed5cf\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22571\"\u003e#22571\u003c/a\u003e \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22575\"\u003e#22575\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e6.4.2 (2026-04-06)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: apply server.fs check to env transport (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22159\"\u003e#22159\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22163\"\u003e#22163\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/fe28e47e9463e4c9619f94bfa06d2f8f1411b44b\"\u003efe28e47\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22159\"\u003e#22159\u003c/a\u003e \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22163\"\u003e#22163\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid path traversal with optimize deps sourcemap handler (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22161\"\u003e#22161\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/ca4da5d1fb45c9cfdce606aa30825095791b164b\"\u003eca4da5d\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22161\"\u003e#22161\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e6.4.1 (2025-10-20)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(dev): trim trailing slash before \u003ccode\u003eserver.fs.deny\u003c/code\u003e check (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20968\"\u003e#20968\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20969\"\u003e#20969\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/1114b5d7ea03e26572708715343bec69db4536e8\"\u003e1114b5d\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/20968\"\u003e#20968\u003c/a\u003e \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/20969\"\u003e#20969\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e6.4.0 (2025-10-15)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: allow passing down resolved config to vite's createServer (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20932\"\u003e#20932\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/ca6455ee9eb6111a9caa9810506a1b9ac96a520a\"\u003eca6455e\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/20932\"\u003e#20932\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e6.3.7 (2025-10-14)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(esbuild): inject esbuild helpers correctly for esbuild 0.25.9+ (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20940\"\u003e#20940\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/c59a222aa584c087cfe710173de1b9ecb597a3ff\"\u003ec59a222\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/20940\"\u003e#20940\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e6.3.6 (2025-09-08)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: apply \u003ccode\u003efs.strict\u003c/code\u003e check to HTML files (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20736\"\u003e#20736\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/0ab19ea9fcb66f544328f442cf6e70f7c0528d5f\"\u003e0ab19ea\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/20736\"\u003e#20736\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: upgrade sirv to 3.0.2 (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20735\"\u003e#20735\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e11d24008b97d4ca731ecc1a3b95260a6d12e7e0\"\u003ee11d240\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/20735\"\u003e#20735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: detect ts support via \u003ccode\u003eprocess.features\u003c/code\u003e (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20544\"\u003e#20544\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/7d9922972b62329d37a71d4da5a4a382d0bf8a79\"\u003e7d99229\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/20544\"\u003e#20544\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/6c2c881f15495738ff03bc1d67cc052c07e0cac4\"\u003e\u003ccode\u003e6c2c881\u003c/code\u003e\u003c/a\u003e release: v6.4.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/96b0c10162e9c55485d922db2cfc6b8227cbc176\"\u003e\u003ccode\u003e96b0c10\u003c/code\u003e\u003c/a\u003e fix: backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22576\"\u003e#22576\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/8fed5cf540c0d475266787f52072f258478cd42f\"\u003e\u003ccode\u003e8fed5cf\u003c/code\u003e\u003c/a\u003e fix(deps): backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/2\"\u003e#2\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/6b3fad02abd550bd7b79934ff92c58dbd7f33045\"\u003e\u003ccode\u003e6b3fad0\u003c/code\u003e\u003c/a\u003e release: v6.4.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/ca4da5d1fb45c9cfdce606aa30825095791b164b\"\u003e\u003ccode\u003eca4da5d\u003c/code\u003e\u003c/a\u003e fix: avoid path traversal with optimize deps sourcemap handler (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22161\"\u003e#22161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/fe28e47e9463e4c9619f94bfa06d2f8f1411b44b\"\u003e\u003ccode\u003efe28e47\u003c/code\u003e\u003c/a\u003e fix: apply server.fs check to env transport (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22159\"\u003e#22159\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22163\"\u003e#22163\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/5487f4f641f70c47ea05fd101a4319897df048b3\"\u003e\u003ccode\u003e5487f4f\u003c/code\u003e\u003c/a\u003e release: v6.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/1114b5d7ea03e26572708715343bec69db4536e8\"\u003e\u003ccode\u003e1114b5d\u003c/code\u003e\u003c/a\u003e fix(dev): trim trailing slash before \u003ccode\u003eserver.fs.deny\u003c/code\u003e check (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20968\"\u003e#20968\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20969\"\u003e#20969\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/f12697c0f64b9a37196b9ab218a0911829d5b103\"\u003e\u003ccode\u003ef12697c\u003c/code\u003e\u003c/a\u003e release: v6.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/ca6455ee9eb6111a9caa9810506a1b9ac96a520a\"\u003e\u003ccode\u003eca6455e\u003c/code\u003e\u003c/a\u003e feat: allow passing down resolved config to vite's createServer (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20932\"\u003e#20932\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vitejs/vite/commits/v6.4.3/packages/vite\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for vite since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `next` from 15.2.5 to 15.5.21\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev15.5.21\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eHigh:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-m99w-x7hq-7vfj\"\u003eDenial of Service in App Router using Server Actions\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-6gpp-xcg3-4w24\"\u003eMiddleware / Proxy bypass in App Router applications using Turbopack and single locale\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p9j2-gv94-2wf4\"\u003eServer-Side Request Forgery in rewrites via attacker-controlled destination hostname\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-89xv-2m56-2m9x\"\u003eServer-Side Request Forgery in Server Actions on custom servers\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eModerate:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-68g3-v927-f742\"\u003eCache confusion of response bodies for requests with bodies\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-4633-3j49-mh5q\"\u003eCache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-q8wf-6r8g-63ch\"\u003eDenial of Service in the Image Optimization API using SVGs\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-955p-x3mx-jcvp\"\u003eUnauthenticated disclosure of internal Server Function endpoints\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-4c39-4ccg-62r3\"\u003eUnbounded Server Action payload in Edge runtime\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev15.5.20\u003c/h2\u003e\n\u003cp\u003eContains no changes except publishing \u003ccode\u003e@next/swc-wasm-web\u003c/code\u003e which was accidentally not published since 15.5.15.\u003c/p\u003e\n\u003ch2\u003e15.5.19\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[15.5.x] Don't drop \u003ccode\u003eFormData\u003c/code\u003e entries (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/94244\"\u003e#94244\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[15.5.x] Fix CI (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/94281\"\u003e#94281\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/e26f6ffaa710fc62ca0c8640db0e43b6663edf32\"\u003e\u003ccode\u003ee26f6ff\u003c/code\u003e\u003c/a\u003e v15.5.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/7f5deeb6c594b7515edecb879b0547beba1b8a82\"\u003e\u003ccode\u003e7f5deeb\u003c/code\u003e\u003c/a\u003e [15.x] Improve performance of checking valid MPA form submissions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/57c31f724d746e86a9e8b92aa8be538a922446a4\"\u003e\u003ccode\u003e57c31f7\u003c/code\u003e\u003c/a\u003e [15.x] Enforce \u003ccode\u003eserverActions.bodySizeLimit\u003c/code\u003e for Server Actions in Edge runtime\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/e3e5666ccead3a15162793d697af5e48b7cc0498\"\u003e\u003ccode\u003ee3e5666\u003c/code\u003e\u003c/a\u003e [15.x] Set correct origin for internal redirects in custom server\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/35f501357e9b0fe7c950b0d6aa8fcf5343f707e9\"\u003e\u003ccode\u003e35f5013\u003c/code\u003e\u003c/a\u003e [15.x] Ensure exotic rewrite param values are properly encoded\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/062f66700b52a5d6bba2c0605d55577ab7ad262c\"\u003e\u003ccode\u003e062f667\u003c/code\u003e\u003c/a\u003e [15.x] fix(fetch-cache): key fetch(Request, init) by the effective request\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/577c9dc0a08ac806e35f591fec528d5fb7407ad4\"\u003e\u003ccode\u003e577c9dc\u003c/code\u003e\u003c/a\u003e [15.x] fix(incremental-cache): byte-exact fetch cache key for binary bodies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/530d4fa31e010a05f28ea6e26a5f51f80f61e0c6\"\u003e\u003ccode\u003e530d4fa\u003c/code\u003e\u003c/a\u003e [15.x] fix(next/image): improve performance of detectContentType()\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/8fabaf3225be100d62dfb0f44d85ab43c2a14a20\"\u003e\u003ccode\u003e8fabaf3\u003c/code\u003e\u003c/a\u003e [15.x] Performance improvements when decoding React Server function payloads\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/ff12a6124e1504f17b62de948b8a553fdecaef7b\"\u003e\u003ccode\u003eff12a61\u003c/code\u003e\u003c/a\u003e [15.x] Validate server reference IDs during manifest lookup\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v15.2.5...v15.5.21\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for next since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.4 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003epostcss-scss\u003c/code\u003e commend regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed reading any file via user-generated CSS.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eopts.unsafeMap\u003c/code\u003e to disable checks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed nested brackets parsing performance (by \u003ca href=\"https://github.com/offset\"\u003e\u003ccode\u003e@​offset\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.10\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed XSS via unescaped \u003ccode\u003e\u0026lt;/style\u0026gt;\u003c/code\u003e in non-bundler cases (by \u003ca href=\"https://github.com/TharVid\"\u003e\u003ccode\u003e@​TharVid\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.4...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `electron` from 34.4.1 to 39.8.10\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/electron/electron/releases\"\u003eelectron's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eelectron v39.8.10\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.10\u003c/h1\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!WARNING]\nElectron 39.x.y has reached end-of-support as per the project's \u003ca href=\"https://www.electronjs.org/docs/latest/tutorial/electron-timelines#version-support-policy\"\u003esupport policy\u003c/a\u003e. Developers and applications are encouraged to upgrade to a newer version of Electron.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eFixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnsured cross-origin \u003ccode\u003efetch()\u003c/code\u003e and XHR are blocked for custom protocols registered with \u003ccode\u003esupportFetchAPI: true\u003c/code\u003e unless \u003ccode\u003ecorsEnabled: true\u003c/code\u003e is also set; cross-origin \u003ccode\u003emode: 'no-cors'\u003c/code\u003e requests now receive an opaque response. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51272\"\u003e#51272\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/51271\"\u003e40\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/51270\"\u003e41\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/51269\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue where the Squirrel.Mac installer could resolve the target bundle path to different locations at different stages of an install. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50766\"\u003e#50766\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/50765\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eOther Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackported a fix for route_id validation in the GPU command buffer. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51327\"\u003e#51327\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBackported security fixes for 493319454, 494158331, 493234757, 492736100, 493413432, 492668885, 496281816. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51257\"\u003e#51257\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBackported several fixes in Skia, ANGLE, and WebRTC from upstream. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51266\"\u003e#51266\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eelectron v39.8.9\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.9\u003c/h1\u003e\n\u003ch2\u003eOther Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003egn gen\u003c/code\u003e failing to resolve \u003ccode\u003eelectron_version\u003c/code\u003e when building from a \u003ccode\u003egit worktree\u003c/code\u003e checkout. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51163\"\u003e#51163\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/51164\"\u003e40\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/51165\"\u003e41\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/51166\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: backported fixes for CVE-2026-6296, CVE-2026-6297, CVE-2026-6298, CVE-2026-6299, CVE-2026-6300, CVE-2026-6301, CVE-2026-6302, CVE-2026-6303, CVE-2026-6304, CVE-2026-6305, CVE-2026-6306, CVE-2026-6307, CVE-2026-6308, CVE-2026-6309, CVE-2026-6311, CVE-2026-6312, CVE-2026-6313, CVE-2026-6314, CVE-2026-6316, CVE-2026-6318, CVE-2026-6358, CVE-2026-6359, CVE-2026-6360, CVE-2026-6361, CVE-2026-6362, CVE-2026-6363, CVE-2026-6364. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51141\"\u003e#51141\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eelectron v39.8.8\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.8\u003c/h1\u003e\n\u003ch2\u003eFixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where DevTools would re-attach to the window when opened after previously being detached. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50818\"\u003e#50818\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/50817\"\u003e40\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/50816\"\u003e41\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/50815\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eOther Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackported fix for \u003ca href=\"https://issues.chromium.org/issues/474266014\"\u003echromium:74266014\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50175\"\u003e#50175\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBackported upstream v8 fixes for several maglev, inspector, and arm64 code-generation edge cases. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50993\"\u003e#50993\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eelectron v39.8.7\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.7\u003c/h1\u003e\n\u003ch2\u003eOther Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackported fix for 489711638. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50624\"\u003e#50624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBackported fix for 493952...\n\n_Description has been truncated_\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nUpdate core dependencies across root, webview-ui, and JetBrains host to pull in security fixes and dev-server hardening. Key upgrades include `next`, `electron`, `axios`, `undici`, `postcss`, `vite`, `dompurify`, and `shell-quote`.\n\n- **Dependencies**\n  - `next`: 15.2.5 → 15.5.21 (security fixes) in `apps/web-evals`, `apps/web-roo-code`\n  - `electron`: 34.4.1 → 39.8.10 (security backports) in `jetbrains/host`\n  - `axios`: 1.12.2 → 1.18.0 (redirect/header \u0026 URL hardening)\n  - `undici`: 7.15.0 → 7.29.0 (security fixes)\n  - `postcss`: 8.5.4 → 8.5.23 (stricter source map handling)\n  - `vite`: 6.3.5/6.3.6 → 6.4.3 (dev-server path hardening) in `apps/storybook`, `webview-ui`\n  - `dompurify`: 3.2.6 → 3.4.13 (sanitization hardening)\n  - `shell-quote`: 1.8.2 → 1.9.0 (parser fixes, types)\n\n\u003csup\u003eWritten for commit a6f2ddcb3e710e07dca1df9243840121433935ea. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/ThePlenkov/kilocode/pull/2?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/ThePlenkov/kilocode/pull/2","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ThePlenkov%2Fkilocode/issues/2","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2/packages"},{"uuid":"5092145578","node_id":"PR_kwDOCQda3s78Ikm1","number":2799,"state":"closed","title":"chore(deps): bump undici from 7.28.0 to 7.29.0","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-08-07T16:37:51.000Z","author_association":null,"state_reason":null,"created_at":"2026-08-07T16:36:11.000Z","updated_at":"2026-08-07T16:37:53.000Z","time_to_close":100,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"undici","old_version":"7.28.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 7.28.0 to 7.29.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=7.28.0\u0026new-version=7.29.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/IsmaelMartinez/teams-for-linux/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/IsmaelMartinez/teams-for-linux/pull/2799","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/IsmaelMartinez%2Fteams-for-linux/issues/2799","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2799/packages"},{"uuid":"5092072919","node_id":"PR_kwDOSeiN3s78IVUh","number":65,"state":"closed","title":"chore(deps): Bump the npm_and_yarn group across 15 directories with 9 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-08-07T16:34:31.000Z","author_association":null,"state_reason":null,"created_at":"2026-08-07T16:27:19.000Z","updated_at":"2026-08-07T16:34:32.000Z","time_to_close":432,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): Bump","group_name":"npm_and_yarn","update_count":9,"packages":[{"name":"postcss","old_version":"8.5.6","new_version":"8.5.23","repository_url":"https://github.com/postcss/postcss"},{"name":"undici","old_version":"6.24.1","new_version":"6.28.0","repository_url":"https://github.com/nodejs/undici"},{"name":"@angular/common","old_version":"17.3.8","new_version":"20.3.27","repository_url":"https://github.com/angular/angular"},{"name":"@angular/compiler","old_version":"17.3.8","new_version":"20.3.27","repository_url":"https://github.com/angular/angular"},{"name":"@angular/core","old_version":"17.3.8","new_version":"20.3.25","repository_url":"https://github.com/angular/angular"},{"name":"@angular/common","old_version":"17.3.8","new_version":"20.3.27","repository_url":"https://github.com/angular/angular"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 2 updates in the / directory: [postcss](https://github.com/postcss/postcss) and [undici](https://github.com/nodejs/undici).\nBumps the npm_and_yarn group with 3 updates in the /examples/with-angular directory: [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common), [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) and [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core).\nBumps the npm_and_yarn group with 3 updates in the /examples/with-angular/apps/docs directory: [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common), [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) and [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core).\nBumps the npm_and_yarn group with 3 updates in the /examples/with-angular/apps/web directory: [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common), [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) and [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core).\nBumps the npm_and_yarn group with 3 updates in the /examples/with-angular/packages/ui directory: [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common), [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) and [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core).\nBumps the npm_and_yarn group with 1 update in the /examples/with-npm directory: [postcss](https://github.com/postcss/postcss).\nBumps the npm_and_yarn group with 1 update in the /examples/with-prisma directory: [fast-uri](https://github.com/fastify/fast-uri).\nBumps the npm_and_yarn group with 1 update in the /examples/with-tailwind directory: [postcss](https://github.com/postcss/postcss).\nBumps the npm_and_yarn group with 2 updates in the /examples/with-vue-nuxt directory: [@nuxt/devtools](https://github.com/nuxt/devtools/tree/HEAD/packages/devtools) and [nuxt](https://github.com/nuxt/nuxt/tree/HEAD/packages/nuxt).\nBumps the npm_and_yarn group with 1 update in the /examples/with-vue-nuxt/apps/docs directory: [nuxt](https://github.com/nuxt/nuxt/tree/HEAD/packages/nuxt).\nBumps the npm_and_yarn group with 1 update in the /lockfile-tests/fixtures/berry directory: [fast-uri](https://github.com/fastify/fast-uri).\nBumps the npm_and_yarn group with 2 updates in the /lockfile-tests/fixtures/npm-lock-workspace-variation directory: [postcss](https://github.com/postcss/postcss) and [fast-uri](https://github.com/fastify/fast-uri).\nBumps the npm_and_yarn group with 1 update in the /lockfile-tests/fixtures/pnpm-override-peer-variant directory: [hono](https://github.com/honojs/hono).\nBumps the npm_and_yarn group with 1 update in the /lockfile-tests/fixtures/robust-berry-resolutions directory: [fast-uri](https://github.com/fastify/fast-uri).\nBumps the npm_and_yarn group with 1 update in the /turborepo-tests/integration/fixtures/framework_inference directory: [postcss](https://github.com/postcss/postcss).\n\nUpdates `postcss` from 8.5.6 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003epostcss-scss\u003c/code\u003e commend regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed reading any file via user-generated CSS.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eopts.unsafeMap\u003c/code\u003e to disable checks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed nested brackets parsing performance (by \u003ca href=\"https://github.com/offset\"\u003e\u003ccode\u003e@​offset\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.10\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed XSS via unescaped \u003ccode\u003e\u0026lt;/style\u0026gt;\u003c/code\u003e in non-bundler cases (by \u003ca href=\"https://github.com/TharVid\"\u003e\u003ccode\u003e@​TharVid\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.6...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 6.24.1 to 6.28.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.28.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e740a0b7c\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003ecba3a52a\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e4fd5a0c6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003eaf748404\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e and \u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ehttps://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.27.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e4 security advisories\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 6.27.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^6.27.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on patched version:\u003c/strong\u003e the v6 fixes shipped in \u003cstrong\u003ev6.27.0\u003c/strong\u003e, not \u003ccode\u003e6.26.0\u003c/code\u003e\n— \u003ccode\u003ev6.26.0\u003c/code\u003e contains only the chunked-EOF fix (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5308\"\u003e#5308\u003c/a\u003e) and the version bump, none\nof the security fixes below.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v6 line is \u003cstrong\u003enot\u003c/strong\u003e affected by the SOCKS5 advisories (GHSA-vmh5-mc38-953g,\nGHSA-hm92-r4w5-c3mj), the shared-cache disclosure (GHSA-pr7r-676h-xcf6), or the\n8.x-only WebSocket regression (GHSA-38rv-x7px-6hhq).\u003c/p\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7\"\u003e\u003ccode\u003eb7f252e7\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447\"\u003e\u003ccode\u003e25efa447\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447\"\u003e\u003ccode\u003e25efa447\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f4c31d60\"\u003e\u003ccode\u003ef4c31d60\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003ch2\u003eHigh severity\u003c/h2\u003e\n\u003ch3\u003eWebSocket DoS via fragment count bypass — CVE-2026-12151\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/strong\u003e · CWE-400, CWE-770\n\u003cstrong\u003eFix:\u003c/strong\u003e \u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7\"\u003e\u003ccode\u003eb7f252e7\u003c/code\u003e\u003c/a\u003e \u003cem\u003eBackport WebSocket maxPayloadSize fixes\u003c/em\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5423\"\u003e#5423\u003c/a\u003e, backported to v6 in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5428\"\u003e#5428\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eA malicious WebSocket server can stream a large number of small or empty\ncontinuation frames. Undici enforced a limit on cumulative payload size but did\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a\"\u003e\u003ccode\u003e01a912e\u003c/code\u003e\u003c/a\u003e Bumped v6.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5591\"\u003e#5591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e\"\u003e\u003ccode\u003e481ecfc\u003c/code\u003e\u003c/a\u003e Use Node 22 and npm 11 to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e\u003ccode\u003e740a0b7\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0\"\u003e\u003ccode\u003e2698e49\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e\u003ccode\u003e4fd5a0c\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003e\u003ccode\u003ecba3a52\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003e\u003ccode\u003eaf74840\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/551138cbc1742c92242a68216167761075e8a82c\"\u003e\u003ccode\u003e551138c\u003c/code\u003e\u003c/a\u003e Bumped v6.27.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5431\"\u003e#5431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7c0841418fb9d95cd297bdd9fad9d2a53\"\u003e\u003ccode\u003eb7f252e\u003c/code\u003e\u003c/a\u003e Backport WebSocket maxPayloadSize fixes to v7.x (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5423\"\u003e#5423\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5428\"\u003e#5428\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447997f74d5881edd144525c3fd7db945a4\"\u003e\u003ccode\u003e25efa44\u003c/code\u003e\u003c/a\u003e fix(cookies): preserve values and parse SameSite strictly\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.24.1...v6.28.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@angular/common` from 17.3.8 to 20.3.27\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/releases\"\u003e@​angular/common's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e20.3.27\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e\u003cimg src=\"https://img.shields.io/badge/5dbcd0ee16-fix-green\" alt=\"fix - 5dbcd0ee16\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003e\u003cimg src=\"https://img.shields.io/badge/db0d4a1a39-fix-green\" alt=\"fix - db0d4a1a39\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003cimg src=\"https://img.shields.io/badge/a64e2883e9-fix-green\" alt=\"fix - a64e2883e9\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e\u003cimg src=\"https://img.shields.io/badge/6f80cca0b8-fix-green\" alt=\"fix - 6f80cca0b8\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.26\u003c/h2\u003e\n\u003ch3\u003ecompiler-cli\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/406aaa31e6ac4d3c155f5ab76e315ccd8d0387fe\"\u003e\u003cimg src=\"https://img.shields.io/badge/406aaa31e6-fix-green\" alt=\"fix - 406aaa31e6\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate babel dependencies to latest v7\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/26831d0cbd7e692210ca0799a203a7a5a0e741cd\"\u003e\u003cimg src=\"https://img.shields.io/badge/26831d0cbd-fix-green\" alt=\"fix - 26831d0cbd\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eavoid caching missing locale data\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8eb7aea08b27c0f1bcdeec3171880a6fcf28aa9a\"\u003e\u003cimg src=\"https://img.shields.io/badge/8eb7aea08b-fix-green\" alt=\"fix - 8eb7aea08b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003ereject dynamic script host elements\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003cimg src=\"https://img.shields.io/badge/b963f61028-fix-green\" alt=\"fix - b963f61028\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eprevent caching of responses with Set-Cookie headers\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1fdf2341684a0f528d1d31005bd48d882c0a47d1\"\u003e\u003cimg src=\"https://img.shields.io/badge/1fdf234168-fix-green\" alt=\"fix - 1fdf234168\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/baa093ba68c1d5ca7c35c562568c6021eb409b4c\"\u003e\u003cimg src=\"https://img.shields.io/badge/baa093ba68-fix-green\" alt=\"fix - baa093ba68\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer policy in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.25\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003cimg src=\"https://img.shields.io/badge/9f443bc24c-fix-green\" alt=\"fix - 9f443bc24c\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003cimg src=\"https://img.shields.io/badge/566ad05f20-fix-green\" alt=\"fix - 566ad05f20\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003cimg src=\"https://img.shields.io/badge/1a62130a6b-fix-green\" alt=\"fix - 1a62130a6b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003cimg src=\"https://img.shields.io/badge/a68ec702a0-fix-green\" alt=\"fix - a68ec702a0\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003cimg src=\"https://img.shields.io/badge/768a349e6e-fix-green\" alt=\"fix - 768a349e6e\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/blob/main/CHANGELOG.md\"\u003e@​angular/common's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e20.3.27 (2026-07-29)\u003c/h1\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e5dbcd0ee16\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003edb0d4a1a39\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003ea64e2883e9\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e6f80cca0b8\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.8 (2026-07-22)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/c0368f227846024bb26d3628c59541e870bb36e4\"\u003ec0368f2278\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve crossorigin on image preloads\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8616ba9db6240f3fbf8b905342d07326e096302b\"\u003e8616ba9db6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure SVG animation attributeName is checked case-insensitively\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eforms\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d302c7ab833c0bd3bba951135e76e0c48273b3d7\"\u003ed302c7ab83\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure \u003ccode\u003epending\u003c/code\u003e status propagates to the root form in signal forms\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9d40f8aefef9dcd893db5d01bc58d3e65e1cb4c2\"\u003e9d40f8aefe\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eprevent transfer cache key collisions\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003emigrations\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/388daea2fc188aad3ab69fb81bd3f893ac3cd846\"\u003e388daea2fc\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003ecorrectly migrate ngClass with mixed space-separated keys\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/bb39cda6483de2edab2f8221459b0ed5b73ef221\"\u003ebb39cda648\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve NgClass import on partial migration\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.7 (2026-07-15)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/91e33aa1de47d250d8cde21047597e8df771f07d\"\u003e91e33aa1de\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eavoid prototype lookups in date format caches\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003ccode\u003ea64e288\u003c/code\u003e\u003c/a\u003e fix(http): distinguish repeated transfer cache params\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003ccode\u003eb963f61\u003c/code\u003e\u003c/a\u003e fix(http): prevent caching of responses with Set-Cookie headers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/06be29826741212ca00e21efb6abff653e4541b5\"\u003e\u003ccode\u003e06be298\u003c/code\u003e\u003c/a\u003e fix(http): preserve empty referrer option in HttpRequest\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003ccode\u003e9f443bc\u003c/code\u003e\u003c/a\u003e fix(common): Limits date format string length\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/fa940e1f4de75c33ccca50357d941be53a5a0950\"\u003e\u003ccode\u003efa940e1\u003c/code\u003e\u003c/a\u003e fix(http): Rejects non-HTTP(S) URLs in JSONP requests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003ccode\u003e1a62130\u003c/code\u003e\u003c/a\u003e fix(common): use cryptographically secure SHA-256 for transfer cache key gene...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003ccode\u003e566ad05\u003c/code\u003e\u003c/a\u003e fix(common): skip transfer cache for uncacheable HTTP traffic\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/e2ef1ce72ae084e01a76950c731052f4fa97fcdd\"\u003e\u003ccode\u003ee2ef1ce\u003c/code\u003e\u003c/a\u003e fix(http): skip transfer cache for fetch credentialed requests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/3d135ce59bbf7426825bc493bc681f266846ac79\"\u003e\u003ccode\u003e3d135ce\u003c/code\u003e\u003c/a\u003e fix(common): add upper bounds for digitsInfo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/39a4b4cc8e8d101a566a70658707bc9f53dd5883\"\u003e\u003ccode\u003e39a4b4c\u003c/code\u003e\u003c/a\u003e fix(common): sanitize placeholder\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/angular/angular/commits/v20.3.27/packages/common\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@angular/compiler` from 17.3.8 to 20.3.27\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/releases\"\u003e@​angular/compiler's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e20.3.27\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e\u003cimg src=\"https://img.shields.io/badge/5dbcd0ee16-fix-green\" alt=\"fix - 5dbcd0ee16\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003e\u003cimg src=\"https://img.shields.io/badge/db0d4a1a39-fix-green\" alt=\"fix - db0d4a1a39\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003cimg src=\"https://img.shields.io/badge/a64e2883e9-fix-green\" alt=\"fix - a64e2883e9\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e\u003cimg src=\"https://img.shields.io/badge/6f80cca0b8-fix-green\" alt=\"fix - 6f80cca0b8\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.26\u003c/h2\u003e\n\u003ch3\u003ecompiler-cli\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/406aaa31e6ac4d3c155f5ab76e315ccd8d0387fe\"\u003e\u003cimg src=\"https://img.shields.io/badge/406aaa31e6-fix-green\" alt=\"fix - 406aaa31e6\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate babel dependencies to latest v7\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/26831d0cbd7e692210ca0799a203a7a5a0e741cd\"\u003e\u003cimg src=\"https://img.shields.io/badge/26831d0cbd-fix-green\" alt=\"fix - 26831d0cbd\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eavoid caching missing locale data\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8eb7aea08b27c0f1bcdeec3171880a6fcf28aa9a\"\u003e\u003cimg src=\"https://img.shields.io/badge/8eb7aea08b-fix-green\" alt=\"fix - 8eb7aea08b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003ereject dynamic script host elements\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003cimg src=\"https://img.shields.io/badge/b963f61028-fix-green\" alt=\"fix - b963f61028\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eprevent caching of responses with Set-Cookie headers\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1fdf2341684a0f528d1d31005bd48d882c0a47d1\"\u003e\u003cimg src=\"https://img.shields.io/badge/1fdf234168-fix-green\" alt=\"fix - 1fdf234168\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/baa093ba68c1d5ca7c35c562568c6021eb409b4c\"\u003e\u003cimg src=\"https://img.shields.io/badge/baa093ba68-fix-green\" alt=\"fix - baa093ba68\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer policy in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.25\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003cimg src=\"https://img.shields.io/badge/9f443bc24c-fix-green\" alt=\"fix - 9f443bc24c\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003cimg src=\"https://img.shields.io/badge/566ad05f20-fix-green\" alt=\"fix - 566ad05f20\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003cimg src=\"https://img.shields.io/badge/1a62130a6b-fix-green\" alt=\"fix - 1a62130a6b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003cimg src=\"https://img.shields.io/badge/a68ec702a0-fix-green\" alt=\"fix - a68ec702a0\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003cimg src=\"https://img.shields.io/badge/768a349e6e-fix-green\" alt=\"fix - 768a349e6e\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/blob/main/CHANGELOG.md\"\u003e@​angular/compiler's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e20.3.27 (2026-07-29)\u003c/h1\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e5dbcd0ee16\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003edb0d4a1a39\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003ea64e2883e9\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e6f80cca0b8\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.8 (2026-07-22)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/c0368f227846024bb26d3628c59541e870bb36e4\"\u003ec0368f2278\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve crossorigin on image preloads\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8616ba9db6240f3fbf8b905342d07326e096302b\"\u003e8616ba9db6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure SVG animation attributeName is checked case-insensitively\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eforms\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d302c7ab833c0bd3bba951135e76e0c48273b3d7\"\u003ed302c7ab83\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure \u003ccode\u003epending\u003c/code\u003e status propagates to the root form in signal forms\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9d40f8aefef9dcd893db5d01bc58d3e65e1cb4c2\"\u003e9d40f8aefe\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eprevent transfer cache key collisions\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003emigrations\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/388daea2fc188aad3ab69fb81bd3f893ac3cd846\"\u003e388daea2fc\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003ecorrectly migrate ngClass with mixed space-separated keys\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/bb39cda6483de2edab2f8221459b0ed5b73ef221\"\u003ebb39cda648\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve NgClass import on partial migration\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.7 (2026-07-15)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/91e33aa1de47d250d8cde21047597e8df771f07d\"\u003e91e33aa1de\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eavoid prototype lookups in date format caches\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003e\u003ccode\u003edb0d4a1\u003c/code\u003e\u003c/a\u003e fix(compiler): restrict possible event handler check to property names longer...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e\u003ccode\u003e5dbcd0e\u003c/code\u003e\u003c/a\u003e fix(compiler): disallow i18n event attributes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003ccode\u003ea68ec70\u003c/code\u003e\u003c/a\u003e fix(compiler): sanitize two-way properties\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/d40acc6431997b304ec54c951e55d2e52ed6f6dc\"\u003e\u003ccode\u003ed40acc6\u003c/code\u003e\u003c/a\u003e fix(compiler): prevent namespaced SVG \u0026lt;style\u0026gt; elements from being stripped\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/7ae6381a4845ad4b13a7a5574c5433b077c93c5c\"\u003e\u003ccode\u003e7ae6381\u003c/code\u003e\u003c/a\u003e test(compiler-cli): align ngtsc sanitization expectations with modern DOM sch...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/36200bd81a3420d8222dfe10767437c383a20fe8\"\u003e\u003ccode\u003e36200bd\u003c/code\u003e\u003c/a\u003e test(core): update spec files to match 20.3.x limits and actual contexts (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/compiler/issues/68\"\u003e#68\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/823b37f0468f7c8b38637ce93e26fc8db791b282\"\u003e\u003ccode\u003e823b37f\u003c/code\u003e\u003c/a\u003e test(compiler): remove obsolete schema_extractor import (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/compiler/issues/68926\"\u003e#68926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/e345a58069ede97250af449f5b7e9b94f828d30c\"\u003e\u003ccode\u003ee345a58\u003c/code\u003e\u003c/a\u003e fix(core): normalize tag names in runtime i18n attribute security context loo...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/8f35b182b1479ed80d652f185c2c3ee5a82ea34c\"\u003e\u003ccode\u003e8f35b18\u003c/code\u003e\u003c/a\u003e fix(compiler): normalize tag names with custom namespaces in DomElementSchema...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/64a89e917a0794a3d74713bdb4c9c63d703b317b\"\u003e\u003ccode\u003e64a89e9\u003c/code\u003e\u003c/a\u003e fix(compiler): sanitize dynamic href and xlink:href bindings on SVG a element...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/angular/angular/commits/v20.3.27/packages/compiler\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@angular/core` from 17.3.8 to 20.3.25\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/releases\"\u003e@​angular/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e20.3.25\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003cimg src=\"https://img.shields.io/badge/9f443bc24c-fix-green\" alt=\"fix - 9f443bc24c\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003cimg src=\"https://img.shields.io/badge/566ad05f20-fix-green\" alt=\"fix - 566ad05f20\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003cimg src=\"https://img.shields.io/badge/1a62130a6b-fix-green\" alt=\"fix - 1a62130a6b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003cimg src=\"https://img.shields.io/badge/a68ec702a0-fix-green\" alt=\"fix - a68ec702a0\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003cimg src=\"https://img.shields.io/badge/768a349e6e-fix-green\" alt=\"fix - 768a349e6e\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/ca48b4728d5f6770be63a08f64a6432207ad54c0\"\u003e\u003cimg src=\"https://img.shields.io/badge/ca48b4728d-fix-green\" alt=\"fix - ca48b4728d\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003evalidate lowercase SVG animation attribute names (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/69270\"\u003e#69270\u003c/a\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/06be29826741212ca00e21efb6abff653e4541b5\"\u003e\u003cimg src=\"https://img.shields.io/badge/06be298267-fix-green\" alt=\"fix - 06be298267\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve empty referrer option in HttpRequest\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/fa940e1f4de75c33ccca50357d941be53a5a0950\"\u003e\u003cimg src=\"https://img.shields.io/badge/fa940e1f4d-fix-green\" alt=\"fix - fa940e1f4d\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eRejects non-HTTP(S) URLs in JSONP requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/e2ef1ce72ae084e01a76950c731052f4fa97fcdd\"\u003e\u003cimg src=\"https://img.shields.io/badge/e2ef1ce72a-fix-green\" alt=\"fix - e2ef1ce72a\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for fetch credentialed requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/49368c185907edb48467074c56e305abbfa3544a\"\u003e\u003cimg src=\"https://img.shields.io/badge/49368c1859-fix-green\" alt=\"fix - 49368c1859\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden platform location origin validation during SSR\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d55c94ad811a15c9c255164a0d66892c645f602e\"\u003e\u003cimg src=\"https://img.shields.io/badge/d55c94ad81-refactor-yellow\" alt=\"refactor - d55c94ad81\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edeprecate ServerXhr (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/69256\"\u003e#69256\u003c/a\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d65a5f457b1afd6bdd4d952d3f213c6aa1aabcbc\"\u003e\u003cimg src=\"https://img.shields.io/badge/d65a5f457b-fix-green\" alt=\"fix - d65a5f457b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eStrips sensitive headers on cross-origin redirects\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003eDeprecations\u003c/h2\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eXHR support in \u003ccode\u003e@angular/platform-server\u003c/code\u003e is deprecated. Use standard \u003ccode\u003efetch\u003c/code\u003e APIs instead.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e20.3.24\u003c/h2\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6ca433e56bcf74fdb6ad01d3afdf59628fba69b6\"\u003e\u003cimg src=\"https://img.shields.io/badge/6ca433e56b-fix-green\" alt=\"fix - 6ca433e56b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003ethrow on suspicious URLs and restrict protocol-relative URLs\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8680b5152fe58ebde81e331b74ba806fc86514cc\"\u003e\u003cimg src=\"https://img.shields.io/badge/8680b5152f-fix-green\" alt=\"fix - 8680b5152f\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.23\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d40acc6431997b304ec54c951e55d2e52ed6f6dc\"\u003e\u003cimg src=\"https://img.shields.io/badge/d40acc6431-fix-green\" alt=\"fix - d40acc6431\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eprevent namespaced SVG \u003c!-- raw HTML omitted --\u003e elements from being stripped\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.22\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/blob/main/CHANGELOG.md\"\u003e@​angular/core's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e20.3.25 (2026-06-10)\u003c/h1\u003e\n\u003ch2\u003eDeprecations\u003c/h2\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eXHR support in \u003ccode\u003e@angular/platform-server\u003c/code\u003e is deprecated. Use standard \u003ccode\u003efetch\u003c/code\u003e APIs instead.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e9f443bc24c\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e566ad05f20\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e1a62130a6b\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003ea68ec702a0\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e768a349e6e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/ca48b4728d5f6770be63a08f64a6432207ad54c0\"\u003eca48b4728d\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003evalidate lowercase SVG animation attribute names (\u003ca href=\"https://redirect.github.com/angular/angular/pull/69270\"\u003e#69270\u003c/a\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/06be29826741212ca00e21efb6abff653e4541b5\"\u003e06be298267\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve empty referrer option in HttpRequest\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/fa940e1f4de75c33ccca50357d941be53a5a0950\"\u003efa940e1f4d\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eRejects non-HTTP(S) URLs in JSONP requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/e2ef1ce72ae084e01a76950c731052f4fa97fcdd\"\u003ee2ef1ce72a\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for fetch credentialed requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/49368c185907edb48467074c56e305abbfa3544a\"\u003e49368c1859\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eharden platform location origin validation during SSR\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d55c94ad811a15c9c255164a0d66892c645f602e\"\u003ed55c94ad81\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003erefactor\u003c/td\u003e\n\u003ctd\u003edeprecate ServerXhr (\u003ca href=\"https://redirect.github.com/angular/angular/pull/69256\"\u003e#69256\u003c/a\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d65a5f457b1afd6bdd4d952d3f213c6aa1aabcbc\"\u003ed65a5f457b\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eStrips sensitive headers on cross-origin redirects\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.0 (2026-06-03)\u003c/h1\u003e\n\u003cp\u003e\u003ca href=\"https://goo.gle/angular-v22-blog\"\u003eBlog post \u0026quot;Announcing Angular v22\u0026quot;\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eBreaking Changes\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThis change will trigger the \u003ccode\u003enullishCoalescingNotNullable\u003c/code\u003e and \u003ccode\u003eoptionalChainNotNullable\u003c/code\u003e diagnostics on exisiting projects.\nYou might want to disable those 2 diagnotiscs in your \u003ccode\u003etsconfig\u003c/code\u003e temporarily.\u003c/li\u003e\n\u003cli\u003edata prefixed attribute no-longer bind inputs nor outputs.\u003c/li\u003e\n\u003cli\u003eThe compiler will throw when there a when inputs, outputs or model are binding to the same input/outputs.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ein\u003c/code\u003e variables will throw in template expressions.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ecompiler-cli\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/ca48b4728d5f6770be63a08f64a6432207ad54c0\"\u003e\u003ccode\u003eca48b47\u003c/code\u003e\u003c/a\u003e fix(core): validate lowercase SVG animation attribute names (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/69270\"\u003e#69270\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003ccode\u003e1a62130\u003c/code\u003e\u003c/a\u003e fix(common): use cryptographically secure SHA-256 for transfer cache key gene...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/49368c185907edb48467074c56e305abbfa3544a\"\u003e\u003ccode\u003e49368c1\u003c/code\u003e\u003c/a\u003e fix(platform-server): harden platform location origin validation during SSR\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003ccode\u003e566ad05\u003c/code\u003e\u003c/a\u003e fix(common): skip transfer cache for uncacheable HTTP traffic\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003ccode\u003e768a349\u003c/code\u003e\u003c/a\u003e fix(core): harden TransferState restoration against DOM clobbering\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/7ae6381a4845ad4b13a7a5574c5433b077c93c5c\"\u003e\u003ccode\u003e7ae6381\u003c/code\u003e\u003c/a\u003e test(compiler-cli): align ngtsc sanitization expectations with modern DOM sch...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/65954092483a88fc69cccd3b4c56d96450ac2fe8\"\u003e\u003ccode\u003e6595409\u003c/code\u003e\u003c/a\u003e test(core): update golden symbols and host bindings sanitization spec (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/68926\"\u003e#68926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/d86e4e7b2ad0e667aeb0f8ed053e2cb2bd154b81\"\u003e\u003ccode\u003ed86e4e7\u003c/code\u003e\u003c/a\u003e fix(core): reject script element as a dynamic component host (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/68926\"\u003e#68926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/b8f1f7276514e258e8c815ec5c7d9b8826ecd372\"\u003e\u003ccode\u003eb8f1f72\u003c/code\u003e\u003c/a\u003e test(core): remove obsolete blockquote cite host binding tests (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/68926\"\u003e#68926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/36200bd81a3420d8222dfe10767437c383a20fe8\"\u003e\u003ccode\u003e36200bd\u003c/code\u003e\u003c/a\u003e test(core): update spec files to match 20.3.x limits and actual contexts (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/68\"\u003e#68\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/angular/angular/commits/v20.3.25/packages/core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@angular/common` from 17.3.8 to 20.3.27\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/releases\"\u003e@​angular/common's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e20.3.27\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e\u003cimg src=\"https://img.shields.io/badge/5dbcd0ee16-fix-green\" alt=\"fix - 5dbcd0ee16\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003e\u003cimg src=\"https://img.shields.io/badge/db0d4a1a39-fix-green\" alt=\"fix - db0d4a1a39\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003cimg src=\"https://img.shields.io/badge/a64e2883e9-fix-green\" alt=\"fix - a64e2883e9\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e\u003cimg src=\"https://img.shields.io/badge/6f80cca0b8-fix-green\" alt=\"fix - 6f80cca0b8\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.26\u003c/h2\u003e\n\u003ch3\u003ecompiler-cli\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/406aaa31e6ac4d3c155f5ab76e315ccd8d0387fe\"\u003e\u003cimg src=\"https://img.shields.io/badge/406aaa31e6-fix-green\" alt=\"fix - 406aaa31e6\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate babel dependencies to latest v7\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/26831d0cbd7e692210ca0799a203a7a5a0e741cd\"\u003e\u003cimg src=\"https://img.shields.io/badge/26831d0cbd-fix-green\" alt=\"fix - 26831d0cbd\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eavoid caching missing locale data\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8eb7aea08b27c0f1bcdeec3171880a6fcf28aa9a\"\u003e\u003cimg src=\"https://img.shields.io/badge/8eb7aea08b-fix-green\" alt=\"fix - 8eb7aea08b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003ereject dynamic script host elements\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003cimg src=\"https://img.shields.io/badge/b963f61028-fix-green\" alt=\"fix - b963f61028\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eprevent caching of responses with Set-Cookie headers\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1fdf2341684a0f528d1d31005bd48d882c0a47d1\"\u003e\u003cimg src=\"https://img.shields.io/badge/1fdf234168-fix-green\" alt=\"fix - 1fdf234168\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/baa093ba68c1d5ca7c35c562568c6021eb409b4c\"\u003e\u003cimg src=\"https://img.shields.io/badge/baa093ba68-fix-green\" alt=\"fix - baa093ba68\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer policy in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.25\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003cimg src=\"https://img.shields.io/badge/9f443bc24c-fix-green\" alt=\"fix - 9f443bc24c\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003cimg src=\"https://img.shields.io/badge/566ad05f20-fix-green\" alt=\"fix - 566ad05f20\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003cimg src=\"https://img.shields.io/badge/1a62130a6b-fix-green\" alt=\"fix - 1a62130a6b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003cimg src=\"https://img.shields.io/badge/a68ec702a0-fix-green\" alt=\"fix - a68ec702a0\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003cimg src=\"https://img.shields.io/badge/768a349e6e-fix-green\" alt=\"fix - 768a349e6e\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/blob/main/CHANGELOG.md\"\u003e@​angular/common's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e20.3.27 (2026-07-29)\u003c/h1\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e5dbcd0ee16\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003edb0d4a1a39\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003ea64e2883e9\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e6f80cca0b8\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.8 (2026-07-22)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/c0368f227846024bb26d3628c59541e870bb36e4\"\u003ec0368f2278\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve crossorigin on image preloads\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8616ba9db6240f3fbf8b905342d07326e096302b\"\u003e8616ba9db6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure SVG animation attributeName is checked case-insensitively\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eforms\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d302c7ab833c0bd3bba951135e76e0c48273b3d7\"\u003ed302c7ab83\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure \u003ccode\u003epending\u003c/code\u003e status propagates to the root form in signal forms\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9d40f8aefef9dcd893db5d01bc58d3e65e1cb4c2\"\u003e9d40f8aefe\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eprevent transfer cache key collisions\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003emigrations\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/388daea2fc188aad3ab69fb81bd3f893ac3cd846\"\u003e388daea2fc\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003ecorrectly migrate ngClass with mixed space-separated keys\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/bb39cda6483de2edab2f8221459b0ed5b73ef221\"\u003ebb39cda648\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve NgClass import on partial migration\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.7 (2026-07-15)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/91e33aa1de47d250d8cde21047597e8df771f07d\"\u003e91e33aa1de\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eavoid prototype lookups in date format caches\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003ccode\u003ea64e288\u003c/code\u003e\u003c/a\u003e fix(http): distinguish repeated transfer cache params\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003ccode\u003eb963f61\u003c/code\u003e\u003c/a\u003e fix(http): prevent caching of responses with Set-Cookie headers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/06be29826741212ca00e21efb6abff653e4541b5\"\u003e\u003ccode\u003e06be298\u003c/code\u003e\u003c/a\u003e fix(http): preserve empty referrer option in HttpRequest\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003ccode\u003e9f443bc\u003c/code\u003e\u003c/a\u003e fix(common): Limits date format string length\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/fa940e1f4de75c33ccca50357d941be53a5a0950\"\u003e\u003ccode\u003efa940e1\u003c/code\u003e\u003c/a\u003e fix(http): Rejects non-HTTP(S) URLs in JSONP requests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003ccode\u003e1a62130\u003c/code\u003e\u003c/a\u003e fix(common): use cryptographically secure SHA-256 for transfer cache key gene...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003ccode\u003e566ad05\u003c/code\u003e\u003c/a\u003e fix(common): skip transfer cache for uncacheable HTTP traffic\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/e2ef1ce72ae08...\n\n_Description has been truncated_\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nUpdate dependencies across the repo to pick up security fixes and keep example apps current. Key upgrades include Angular 20, `postcss` 8.5.23, and `undici` 6.28.0; no app logic changes.\n\n- **Dependencies**\n  - `postcss` → 8.5.23 (security and bug fixes)\n  - `undici` → 6.28.0 (security fixes)\n  - Angular examples: `@angular/common` → 20.3.27, `@angular/compiler` → 20.3.27, `@angular/core` → 20.3.25\n  - `nuxt` → 3.21.10 and `@nuxt/devtools` → 3.4.1\n  - `next` → 16.3.0 in example apps\n  - `fast-uri` → 3.1.5, `hono` → 4.12.34\n  - Refreshed npm/pnpm/yarn lockfiles across fixtures and examples\n\n\u003csup\u003eWritten for commit 6dd1a9a82be8d49a1447c270bd914cc3207b2281. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/michaelhughes2501/turborepo/pull/65?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/michaelhughes2501/turborepo/pull/65","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/michaelhughes2501%2Fturborepo/issues/65","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/65/packages"},{"uuid":"5091879766","node_id":"PR_kwDOCS99lM78HtAU","number":509,"state":"open","title":"Bump undici from 7.28.0 to 8.10.0","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T16:03:04.000Z","updated_at":"2026-08-07T16:04:37.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"undici","old_version":"7.28.0","new_version":"8.10.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 7.28.0 to 8.10.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: namespace h2 options by \u003ca href=\"https://github.com/metcoder95\"\u003e\u003ccode\u003e@​metcoder95\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5498\"\u003enodejs/undici#5498\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: update WPT expectations by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5587\"\u003enodejs/undici#5587\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: add cache/dedupe + dns re-dispatch integration tests by \u003ca href=\"https://github.com/GiHoon1123\"\u003e\u003ccode\u003e@​GiHoon1123\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5535\"\u003enodejs/undici#5535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): support process.unref by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5578\"\u003enodejs/undici#5578\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): ensure every request settles by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5603\"\u003enodejs/undici#5603\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(readable): consume a body whose end has already been emitted by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5617\"\u003enodejs/undici#5617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): skip the content-length checkpoint for HEAD and for a 206 without content-range by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5610\"\u003enodejs/undici#5610\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: revert idle socket validation to setTimeout(0) to prevent stall on idle event loop by \u003ca href=\"https://github.com/marceli1404\"\u003e\u003ccode\u003e@​marceli1404\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5606\"\u003enodejs/undici#5606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(env-http-proxy-agent): match bare IPv6 addresses in no_proxy by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5623\"\u003enodejs/undici#5623\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: handle aggregate balanced pool errors by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5377\"\u003enodejs/undici#5377\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(readable): keep body bytes that arrive after setEncoding() by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5620\"\u003enodejs/undici#5620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(socks5): evict unused origin pools by \u003ca href=\"https://github.com/Kkartik14\"\u003e\u003ccode\u003e@​Kkartik14\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5595\"\u003enodejs/undici#5595\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: skip deduplication for upgrade requests by \u003ca href=\"https://github.com/Ram-blip\"\u003e\u003ccode\u003e@​Ram-blip\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5593\"\u003enodejs/undici#5593\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward informational responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5625\"\u003enodejs/undici#5625\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(mock): non-string path matchers under ignoreTrailingSlash, and DataView reply bodies by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5619\"\u003enodejs/undici#5619\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(interceptors): cache() and deduplicate() silently inert on Client/Pool without opts.origin by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5628\"\u003enodejs/undici#5628\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5633\"\u003enodejs/undici#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/init from 4.36.2 to 4.37.3 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5634\"\u003enodejs/undici#5634\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.4.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5636\"\u003enodejs/undici#5636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(mock): emit request body lifecycle hooks by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5367\"\u003enodejs/undici#5367\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): detach upgrade close handler after GOAWAY by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5641\"\u003enodejs/undici#5641\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: retry refused HTTP/2 streams by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5598\"\u003enodejs/undici#5598\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: preserve DNS origin hostname on sockets by \u003ca href=\"https://github.com/cyphercodes\"\u003e\u003ccode\u003e@​cyphercodes\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5577\"\u003enodejs/undici#5577\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marceli1404\"\u003e\u003ccode\u003e@​marceli1404\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5606\"\u003enodejs/undici#5606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kkartik14\"\u003e\u003ccode\u003e@​Kkartik14\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5595\"\u003enodejs/undici#5595\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5641\"\u003enodejs/undici#5641\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cyphercodes\"\u003e\u003ccode\u003e@​cyphercodes\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5577\"\u003enodejs/undici#5577\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v8.9.0...v8.10.0\"\u003ehttps://github.com/nodejs/undici/compare/v8.9.0...v8.10.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev8.9.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4fe5bc5fefe5ac81a200fc8e1cf84b8bf8464451\"\u003e4fe5bc5f\u003c/a\u003e with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/9f09b49accd391cca818409447f2fb8bc93229b3\"\u003e9f09b49a\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7d3cf924c262c486bc77f951348f4e5c847b7b42\"\u003e7d3cf924\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/c601fff1c56eca84438c3ed4ecb39404252be622\"\u003ec601fff1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e11a68ed4ff345c79402476f7a00d473443e318d\"\u003ee11a68ed\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/2b3f749336d356bbbc50192f87f6cf7bc714721a\"\u003e2b3f7493\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/10d93fc332f2c8c161982dec3833201de29891b5\"\u003e10d93fc3\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eAdditional hardening\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/c8d80e6b2dcfab282557b08f51352937bc9e5692\"\u003e\u003ccode\u003ec8d80e6\u003c/code\u003e\u003c/a\u003e Bumped v8.10.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5644\"\u003e#5644\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66923b47dc1ed095581daa6a53b2ad1bf3e899b4\"\u003e\u003ccode\u003e66923b4\u003c/code\u003e\u003c/a\u003e fix: preserve DNS origin hostname on sockets (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5577\"\u003e#5577\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/392649944c3b989681af1eae2e0970661f9ca464\"\u003e\u003ccode\u003e3926499\u003c/code\u003e\u003c/a\u003e fix: retry refused HTTP/2 streams (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5598\"\u003e#5598\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/73d6e9e19df47f85625d2dc082daa919ae6636c1\"\u003e\u003ccode\u003e73d6e9e\u003c/code\u003e\u003c/a\u003e fix(h2): detach upgrade close handler after GOAWAY (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5641\"\u003e#5641\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b111adbb675ebfcfa52790346dcd88e61c700818\"\u003e\u003ccode\u003eb111adb\u003c/code\u003e\u003c/a\u003e fix(mock): emit request body lifecycle hooks (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5367\"\u003e#5367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ae4a3e37a2ddfe798b64771176e31e8e7819c743\"\u003e\u003ccode\u003eae4a3e3\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/setup-node from 6.4.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5636\"\u003e#5636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ec3fbf19aa47eca6decc390b66bf56034bc03d52\"\u003e\u003ccode\u003eec3fbf1\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action/init from 4.36.2 to 4.37.3 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5634\"\u003e#5634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/21517200296205f3aa09a7b976dde571b441405c\"\u003e\u003ccode\u003e2151720\u003c/code\u003e\u003c/a\u003e build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5633\"\u003e#5633\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b96a11620e2f9fe5adafa2ba7b7f363b96b5a9d7\"\u003e\u003ccode\u003eb96a116\u003c/code\u003e\u003c/a\u003e fix(interceptors): allow interceptors without opts.origin (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5628\"\u003e#5628\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/a18ef2d05af48047339be51d8817492abc30f39d\"\u003e\u003ccode\u003ea18ef2d\u003c/code\u003e\u003c/a\u003e fix(mock): non-string path matchers under ignoreTrailingSlash, and DataView r...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v8.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=7.28.0\u0026new-version=8.10.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/hugo19941994/jwks-fetch/pull/509","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/hugo19941994%2Fjwks-fetch/issues/509","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/509/packages"},{"uuid":"5091617869","node_id":"PR_kwDOScp_gM78G3EK","number":56,"state":"open","title":"chore(deps): Bump the npm_and_yarn group across 15 directories with 10 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":4,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T15:29:43.000Z","updated_at":"2026-08-07T15:31:41.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): Bump","group_name":"npm_and_yarn","update_count":10,"packages":[{"name":"postcss","old_version":"8.5.16","new_version":"8.5.23","repository_url":"https://github.com/postcss/postcss"},{"name":"undici","old_version":"6.27.0","new_version":"6.28.0"},{"name":"fast-uri","old_version":"3.1.3","new_version":"3.1.5","repository_url":"https://github.com/fastify/fast-uri"},{"name":"ip-address","old_version":"10.2.0","new_version":"10.4.0"},{"name":"@angular/common","old_version":"17.3.8","new_version":"20.3.27","repository_url":"https://github.com/angular/angular"},{"name":"@angular/compiler","old_version":"17.3.8","new_version":"20.3.27","repository_url":"https://github.com/angular/angular"},{"name":"@angular/core","old_version":"17.3.8","new_version":"20.3.25","repository_url":"https://github.com/angular/angular"},{"name":"@angular/common","old_version":"17.3.8","new_version":"20.3.27","repository_url":"https://github.com/angular/angular"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 1 update in the / directory: [postcss](https://github.com/postcss/postcss).\nBumps the npm_and_yarn group with 3 updates in the /examples/with-angular directory: [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common), [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) and [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core).\nBumps the npm_and_yarn group with 3 updates in the /examples/with-angular/apps/docs directory: [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common), [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) and [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core).\nBumps the npm_and_yarn group with 3 updates in the /examples/with-angular/apps/web directory: [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common), [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) and [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core).\nBumps the npm_and_yarn group with 3 updates in the /examples/with-angular/packages/ui directory: [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common), [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) and [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core).\nBumps the npm_and_yarn group with 1 update in the /examples/with-npm directory: [postcss](https://github.com/postcss/postcss).\nBumps the npm_and_yarn group with 1 update in the /examples/with-prisma directory: [fast-uri](https://github.com/fastify/fast-uri).\nBumps the npm_and_yarn group with 1 update in the /examples/with-tailwind directory: [postcss](https://github.com/postcss/postcss).\nBumps the npm_and_yarn group with 2 updates in the /examples/with-vue-nuxt directory: [@nuxt/devtools](https://github.com/nuxt/devtools/tree/HEAD/packages/devtools) and [nuxt](https://github.com/nuxt/nuxt/tree/HEAD/packages/nuxt).\nBumps the npm_and_yarn group with 1 update in the /examples/with-vue-nuxt/apps/docs directory: [nuxt](https://github.com/nuxt/nuxt/tree/HEAD/packages/nuxt).\nBumps the npm_and_yarn group with 1 update in the /lockfile-tests/fixtures/berry directory: [fast-uri](https://github.com/fastify/fast-uri).\nBumps the npm_and_yarn group with 2 updates in the /lockfile-tests/fixtures/npm-lock-workspace-variation directory: [postcss](https://github.com/postcss/postcss) and [fast-uri](https://github.com/fastify/fast-uri).\nBumps the npm_and_yarn group with 1 update in the /lockfile-tests/fixtures/pnpm-override-peer-variant directory: [hono](https://github.com/honojs/hono).\nBumps the npm_and_yarn group with 1 update in the /lockfile-tests/fixtures/robust-berry-resolutions directory: [fast-uri](https://github.com/fastify/fast-uri).\nBumps the npm_and_yarn group with 1 update in the /turborepo-tests/integration/fixtures/framework_inference directory: [postcss](https://github.com/postcss/postcss).\n\nUpdates `postcss` from 8.5.16 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.16...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 6.27.0 to 6.28.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.28.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e740a0b7c\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003ecba3a52a\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e4fd5a0c6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003eaf748404\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e and \u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ehttps://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a\"\u003e\u003ccode\u003e01a912e\u003c/code\u003e\u003c/a\u003e Bumped v6.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5591\"\u003e#5591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e\"\u003e\u003ccode\u003e481ecfc\u003c/code\u003e\u003c/a\u003e Use Node 22 and npm 11 to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e\u003ccode\u003e740a0b7\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0\"\u003e\u003ccode\u003e2698e49\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e\u003ccode\u003e4fd5a0c\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003e\u003ccode\u003ecba3a52\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003e\u003ccode\u003eaf74840\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.3 to 3.1.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v39h-62p7-jpjc\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v39h-62p7-jpjc\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHandle malformed fragment decoding as a parse error by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/171\"\u003efastify/fast-uri#171\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.1...v3.1.2\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.1...v3.1.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.1\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-q3j6-qgpj-74h6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-q3j6-qgpj-74h6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump tsd from 0.32.0 to 0.33.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/148\"\u003efastify/fast-uri#148\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 4 to 5 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/149\"\u003efastify/fast-uri#149\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(.npmrc): ignore scripts by \u003ca href=\"https://github.com/Fdawgs\"\u003e\u003ccode\u003e@​Fdawgs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/150\"\u003efastify/fast-uri#150\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): remove \u003ccode\u003e@​fastify/pre-commit\u003c/code\u003e by \u003ca href=\"https://github.com/Fdawgs\"\u003e\u003ccode\u003e@​Fdawgs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/151\"\u003efastify/fast-uri#151\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 4 to 5 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/152\"\u003efastify/fast-uri#152\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(ci): add concurrency config by \u003ca href=\"https://github.com/Fdawgs\"\u003e\u003ccode\u003e@​Fdawgs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/153\"\u003efastify/fast-uri#153\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 5 to 6 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/154\"\u003efastify/fast-uri#154\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 5 to 6 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/156\"\u003efastify/fast-uri#156\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(license): standardise license notice by \u003ca href=\"https://github.com/Fdawgs\"\u003e\u003ccode\u003e@​Fdawgs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/159\"\u003efastify/fast-uri#159\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003estyle: remove trailing whitespace by \u003ca href=\"https://github.com/Fdawgs\"\u003e\u003ccode\u003e@​Fdawgs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/161\"\u003efastify/fast-uri#161\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: remove unused github files by \u003ca href=\"https://github.com/Tony133\"\u003e\u003ccode\u003e@​Tony133\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/162\"\u003efastify/fast-uri#162\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: update readme by \u003ca href=\"https://github.com/Tony133\"\u003e\u003ccode\u003e@​Tony133\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/164\"\u003efastify/fast-uri#164\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/5e179cbb4636d5f773ed21126e5bd3068e87e94e\"\u003e\u003ccode\u003e5e179cb\u003c/code\u003e\u003c/a\u003e Bumped v3.1.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/2cad02d6ed428a720499bb7a3c3d6c3d41f10f5a\"\u003e\u003ccode\u003e2cad02d\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6aeece669e4166b2446a89f17c07a3b15dfb7ed4\"\u003e\u003ccode\u003e6aeece6\u003c/code\u003e\u003c/a\u003e Bumped v3.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/2d50fbabc80e4d0884fe0f6a98fe118ce6faa353\"\u003e\u003ccode\u003e2d50fba\u003c/code\u003e\u003c/a\u003e fix: reject literal backslash in URI authority\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/0549fe35b0d482233f3be2816439f3ec803603fa\"\u003e\u003ccode\u003e0549fe3\u003c/code\u003e\u003c/a\u003e Bumped v3.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/2a6d357a18a68e6d812824379fd3388a1ae50d05\"\u003e\u003ccode\u003e2a6d357\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/919dd8ea7689fcc220d0d9b71307f5095e723ef9\"\u003e\u003ccode\u003e919dd8e\u003c/code\u003e\u003c/a\u003e Bumped v3.1.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c65ba573714af6b8e19e481d9444c27bc4355d07\"\u003e\u003ccode\u003ec65ba57\u003c/code\u003e\u003c/a\u003e fixup: linting\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6c86c17c3d76fb93aa3700ec6c0fa00faeb97293\"\u003e\u003ccode\u003e6c86c17\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/a95158ad308df4d92bbde4eba699ce5165e9f796\"\u003e\u003ccode\u003ea95158a\u003c/code\u003e\u003c/a\u003e Handle malformed fragment decoding without throwing (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/171\"\u003e#171\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.0...v3.1.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ip-address` from 10.2.0 to 10.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/beaugunderson/ip-address/releases\"\u003eip-address's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev10.4.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd GitHub Actions CI by \u003ca href=\"https://github.com/beaugunderson\"\u003e\u003ccode\u003e@​beaugunderson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/pull/213\"\u003ebeaugunderson/ip-address#213\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eKeep the package loadable on node 12, and enforce it by \u003ca href=\"https://github.com/beaugunderson\"\u003e\u003ccode\u003e@​beaugunderson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/pull/216\"\u003ebeaugunderson/ip-address#216\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eValidate the byte arrays Address6 is given by \u003ca href=\"https://github.com/beaugunderson\"\u003e\u003ccode\u003e@​beaugunderson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/pull/217\"\u003ebeaugunderson/ip-address#217\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.3.1...v10.4.0\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.3.1...v10.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.3.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.3.0...v10.3.1\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.3.0...v10.3.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.3.0\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.2.2...v10.3.0\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.2.2...v10.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.2.2\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.2.1...v10.2.2\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.2.1...v10.2.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.2.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.2.1\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.2.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/fbb8db28f1559842b7191cab7d8ea6408ed82f7b\"\u003e\u003ccode\u003efbb8db2\u003c/code\u003e\u003c/a\u003e 10.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/45a2b11ec254a2e5620de66e248adcb33d16e669\"\u003e\u003ccode\u003e45a2b11\u003c/code\u003e\u003c/a\u003e Validate the byte arrays Address6 is given (\u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/issues/217\"\u003e#217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/bac8810b3935cab123316a4bc5ebaa22db140299\"\u003e\u003ccode\u003ebac8810\u003c/code\u003e\u003c/a\u003e Keep the package loadable on node 12, and enforce it (\u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/9b3d8488d15e6bfe5f5503867b088ce056723e08\"\u003e\u003ccode\u003e9b3d848\u003c/code\u003e\u003c/a\u003e Add a security policy and a README section on security posture\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/e84a7b381d02cb97ed114023e44133efae151254\"\u003e\u003ccode\u003ee84a7b3\u003c/code\u003e\u003c/a\u003e Order the README API reference Address4, Address6, AddressError\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/015160b85ee60b39548219817a5de3c4e828a6d6\"\u003e\u003ccode\u003e015160b\u003c/code\u003e\u003c/a\u003e Collapse each class in the README API reference\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/34061a897d526b7a063c3605402cd30a8363a035\"\u003e\u003ccode\u003e34061a8\u003c/code\u003e\u003c/a\u003e Pin checkout and setup-node to commits in the release job\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/c5fae5d9bdfe8ded7f4ca01a3d3ea8d97f8f1277\"\u003e\u003ccode\u003ec5fae5d\u003c/code\u003e\u003c/a\u003e Pin action-gh-release to a commit and move it to 3.0.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/e0ef0484193218b0d28cfbb53795bc44ddb3cc21\"\u003e\u003ccode\u003ee0ef048\u003c/code\u003e\u003c/a\u003e Replace CircleCI with GitHub Actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/5e3ceb779aee6ad3f33264e66225e8e7584ab612\"\u003e\u003ccode\u003e5e3ceb7\u003c/code\u003e\u003c/a\u003e Add GitHub Actions CI across Node 20, 22, 24 and 25 (\u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/issues/213\"\u003e#213\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.4.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for ip-address since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version adds \u003ccode\u003eprepare\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@angular/common` from 17.3.8 to 20.3.27\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/releases\"\u003e@​angular/common's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e20.3.27\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e\u003cimg src=\"https://img.shields.io/badge/5dbcd0ee16-fix-green\" alt=\"fix - 5dbcd0ee16\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003e\u003cimg src=\"https://img.shields.io/badge/db0d4a1a39-fix-green\" alt=\"fix - db0d4a1a39\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003cimg src=\"https://img.shields.io/badge/a64e2883e9-fix-green\" alt=\"fix - a64e2883e9\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e\u003cimg src=\"https://img.shields.io/badge/6f80cca0b8-fix-green\" alt=\"fix - 6f80cca0b8\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.26\u003c/h2\u003e\n\u003ch3\u003ecompiler-cli\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/406aaa31e6ac4d3c155f5ab76e315ccd8d0387fe\"\u003e\u003cimg src=\"https://img.shields.io/badge/406aaa31e6-fix-green\" alt=\"fix - 406aaa31e6\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate babel dependencies to latest v7\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/26831d0cbd7e692210ca0799a203a7a5a0e741cd\"\u003e\u003cimg src=\"https://img.shields.io/badge/26831d0cbd-fix-green\" alt=\"fix - 26831d0cbd\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eavoid caching missing locale data\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8eb7aea08b27c0f1bcdeec3171880a6fcf28aa9a\"\u003e\u003cimg src=\"https://img.shields.io/badge/8eb7aea08b-fix-green\" alt=\"fix - 8eb7aea08b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003ereject dynamic script host elements\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003cimg src=\"https://img.shields.io/badge/b963f61028-fix-green\" alt=\"fix - b963f61028\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eprevent caching of responses with Set-Cookie headers\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1fdf2341684a0f528d1d31005bd48d882c0a47d1\"\u003e\u003cimg src=\"https://img.shields.io/badge/1fdf234168-fix-green\" alt=\"fix - 1fdf234168\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/baa093ba68c1d5ca7c35c562568c6021eb409b4c\"\u003e\u003cimg src=\"https://img.shields.io/badge/baa093ba68-fix-green\" alt=\"fix - baa093ba68\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer policy in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.25\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003cimg src=\"https://img.shields.io/badge/9f443bc24c-fix-green\" alt=\"fix - 9f443bc24c\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003cimg src=\"https://img.shields.io/badge/566ad05f20-fix-green\" alt=\"fix - 566ad05f20\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003cimg src=\"https://img.shields.io/badge/1a62130a6b-fix-green\" alt=\"fix - 1a62130a6b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003cimg src=\"https://img.shields.io/badge/a68ec702a0-fix-green\" alt=\"fix - a68ec702a0\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003cimg src=\"https://img.shields.io/badge/768a349e6e-fix-green\" alt=\"fix - 768a349e6e\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/blob/main/CHANGELOG.md\"\u003e@​angular/common's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e20.3.27 (2026-07-29)\u003c/h1\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e5dbcd0ee16\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003edb0d4a1a39\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003ea64e2883e9\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e6f80cca0b8\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.8 (2026-07-22)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/c0368f227846024bb26d3628c59541e870bb36e4\"\u003ec0368f2278\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve crossorigin on image preloads\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8616ba9db6240f3fbf8b905342d07326e096302b\"\u003e8616ba9db6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure SVG animation attributeName is checked case-insensitively\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eforms\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d302c7ab833c0bd3bba951135e76e0c48273b3d7\"\u003ed302c7ab83\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure \u003ccode\u003epending\u003c/code\u003e status propagates to the root form in signal forms\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9d40f8aefef9dcd893db5d01bc58d3e65e1cb4c2\"\u003e9d40f8aefe\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eprevent transfer cache key collisions\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003emigrations\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/388daea2fc188aad3ab69fb81bd3f893ac3cd846\"\u003e388daea2fc\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003ecorrectly migrate ngClass with mixed space-separated keys\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/bb39cda6483de2edab2f8221459b0ed5b73ef221\"\u003ebb39cda648\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve NgClass import on partial migration\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.7 (2026-07-15)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/91e33aa1de47d250d8cde21047597e8df771f07d\"\u003e91e33aa1de\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eavoid prototype lookups in date format caches\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003ccode\u003ea64e288\u003c/code\u003e\u003c/a\u003e fix(http): distinguish repeated transfer cache params\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003ccode\u003eb963f61\u003c/code\u003e\u003c/a\u003e fix(http): prevent caching of responses with Set-Cookie headers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/06be29826741212ca00e21efb6abff653e4541b5\"\u003e\u003ccode\u003e06be298\u003c/code\u003e\u003c/a\u003e fix(http): preserve empty referrer option in HttpRequest\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003ccode\u003e9f443bc\u003c/code\u003e\u003c/a\u003e fix(common): Limits date format string length\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/fa940e1f4de75c33ccca50357d941be53a5a0950\"\u003e\u003ccode\u003efa940e1\u003c/code\u003e\u003c/a\u003e fix(http): Rejects non-HTTP(S) URLs in JSONP requests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003ccode\u003e1a62130\u003c/code\u003e\u003c/a\u003e fix(common): use cryptographically secure SHA-256 for transfer cache key gene...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003ccode\u003e566ad05\u003c/code\u003e\u003c/a\u003e fix(common): skip transfer cache for uncacheable HTTP traffic\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/e2ef1ce72ae084e01a76950c731052f4fa97fcdd\"\u003e\u003ccode\u003ee2ef1ce\u003c/code\u003e\u003c/a\u003e fix(http): skip transfer cache for fetch credentialed requests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/3d135ce59bbf7426825bc493bc681f266846ac79\"\u003e\u003ccode\u003e3d135ce\u003c/code\u003e\u003c/a\u003e fix(common): add upper bounds for digitsInfo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/39a4b4cc8e8d101a566a70658707bc9f53dd5883\"\u003e\u003ccode\u003e39a4b4c\u003c/code\u003e\u003c/a\u003e fix(common): sanitize placeholder\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/angular/angular/commits/v20.3.27/packages/common\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@angular/compiler` from 17.3.8 to 20.3.27\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/releases\"\u003e@​angular/compiler's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e20.3.27\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e\u003cimg src=\"https://img.shields.io/badge/5dbcd0ee16-fix-green\" alt=\"fix - 5dbcd0ee16\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003e\u003cimg src=\"https://img.shields.io/badge/db0d4a1a39-fix-green\" alt=\"fix - db0d4a1a39\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003cimg src=\"https://img.shields.io/badge/a64e2883e9-fix-green\" alt=\"fix - a64e2883e9\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e\u003cimg src=\"https://img.shields.io/badge/6f80cca0b8-fix-green\" alt=\"fix - 6f80cca0b8\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.26\u003c/h2\u003e\n\u003ch3\u003ecompiler-cli\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/406aaa31e6ac4d3c155f5ab76e315ccd8d0387fe\"\u003e\u003cimg src=\"https://img.shields.io/badge/406aaa31e6-fix-green\" alt=\"fix - 406aaa31e6\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate babel dependencies to latest v7\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/26831d0cbd7e692210ca0799a203a7a5a0e741cd\"\u003e\u003cimg src=\"https://img.shields.io/badge/26831d0cbd-fix-green\" alt=\"fix - 26831d0cbd\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eavoid caching missing locale data\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8eb7aea08b27c0f1bcdeec3171880a6fcf28aa9a\"\u003e\u003cimg src=\"https://img.shields.io/badge/8eb7aea08b-fix-green\" alt=\"fix - 8eb7aea08b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003ereject dynamic script host elements\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003cimg src=\"https://img.shields.io/badge/b963f61028-fix-green\" alt=\"fix - b963f61028\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eprevent caching of responses with Set-Cookie headers\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1fdf2341684a0f528d1d31005bd48d882c0a47d1\"\u003e\u003cimg src=\"https://img.shields.io/badge/1fdf234168-fix-green\" alt=\"fix - 1fdf234168\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/baa093ba68c1d5ca7c35c562568c6021eb409b4c\"\u003e\u003cimg src=\"https://img.shields.io/badge/baa093ba68-fix-green\" alt=\"fix - baa093ba68\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer policy in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.25\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003cimg src=\"https://img.shields.io/badge/9f443bc24c-fix-green\" alt=\"fix - 9f443bc24c\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003cimg src=\"https://img.shields.io/badge/566ad05f20-fix-green\" alt=\"fix - 566ad05f20\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003cimg src=\"https://img.shields.io/badge/1a62130a6b-fix-green\" alt=\"fix - 1a62130a6b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003cimg src=\"https://img.shields.io/badge/a68ec702a0-fix-green\" alt=\"fix - a68ec702a0\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003cimg src=\"https://img.shields.io/badge/768a349e6e-fix-green\" alt=\"fix - 768a349e6e\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/blob/main/CHANGELOG.md\"\u003e@​angular/compiler's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e20.3.27 (2026-07-29)\u003c/h1\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e5dbcd0ee16\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003edb0d4a1a39\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003ea64e2883e9\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e6f80cca0b8\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.8 (2026-07-22)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/c0368f227846024bb26d3628c59541e870bb36e4\"\u003ec0368f2278\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve crossorigin on image preloads\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8616ba9db6240f3fbf8b905342d07326e096302b\"\u003e8616ba9db6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure SVG animation attributeName is checked case-insensitively\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eforms\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d302c7ab833c0bd3bba951135e76e0c48273b3d7\"\u003ed302c7ab83\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure \u003ccode\u003epending\u003c/code\u003e status propagates to the root form in signal forms\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9d40f8aefef9dcd893db5d01bc58d3e65e1cb4c2\"\u003e9d40f8aefe\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eprevent transfer cache key collisions\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003emigrations\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/388daea2fc188aad3ab69fb81bd3f893ac3cd846\"\u003e388daea2fc\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003ecorrectly migrate ngClass with mixed space-separated keys\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/bb39cda6483de2edab2f8221459b0ed5b73ef221\"\u003ebb39cda648\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve NgClass import on partial migration\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.7 (2026-07-15)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/91e33aa1de47d250d8cde21047597e8df771f07d\"\u003e91e33aa1de\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eavoid prototype lookups in date format caches\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003e\u003ccode\u003edb0d4a1\u003c/code\u003e\u003c/a\u003e fix(compiler): restrict possible event handler check to property names longer...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e\u003ccode\u003e5dbcd0e\u003c/code\u003e\u003c/a\u003e fix(compiler): disallow i18n event attributes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003ccode\u003ea68ec70\u003c/code\u003e\u003c/a\u003e fix(compiler): sanitize two-way properties\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/d40acc6431997b304ec54c951e55d2e52ed6f6dc\"\u003e\u003ccode\u003ed40acc6\u003c/code\u003e\u003c/a\u003e fix(compiler): prevent namespaced SVG \u0026lt;style\u0026gt; elements from being stripped\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/7ae6381a4845ad4b13a7a5574c5433b077c93c5c\"\u003e\u003ccode\u003e7ae6381\u003c/code\u003e\u003c/a\u003e test(compiler-cli): align ngtsc sanitization expectations with modern DOM sch...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/36200bd81a3420d8222dfe10767437c383a20fe8\"\u003e\u003ccode\u003e36200bd\u003c/code\u003e\u003c/a\u003e test(core): update spec files to match 20.3.x limits and actual contexts (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/compiler/issues/68\"\u003e#68\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/823b37f0468f7c8b38637ce93e26fc8db791b282\"\u003e\u003ccode\u003e823b37f\u003c/code\u003e\u003c/a\u003e test(compiler): remove obsolete schema_extractor import (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/compiler/issues/68926\"\u003e#68926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/e345a58069ede97250af449f5b7e9b94f828d30c\"\u003e\u003ccode\u003ee345a58\u003c/code\u003e\u003c/a\u003e fix(core): normalize tag names in runtime i18n attribute security context loo...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/8f35b182b1479ed80d652f185c2c3ee5a82ea34c\"\u003e\u003ccode\u003e8f35b18\u003c/code\u003e\u003c/a\u003e fix(compiler): normalize tag names with custom namespaces in DomElementSchema...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/64a89e917a0794a3d74713bdb4c9c63d703b317b\"\u003e\u003ccode\u003e64a89e9\u003c/code\u003e\u003c/a\u003e fix(compiler): sanitize dynamic href and xlink:href bindings on SVG a element...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/angular/angular/commits/v20.3.27/packages/compiler\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@angular/core` from 17.3.8 to 20.3.25\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/releases\"\u003e@​angular/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e20.3.25\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003cimg src=\"https://img.shields.io/badge/9f443bc24c-fix-green\" alt=\"fix - 9f443bc24c\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003cimg src=\"https://img.shields.io/badge/566ad05f20-fix-green\" alt=\"fix - 566ad05f20\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003cimg src=\"https://img.shields.io/badge/1a62130a6b-fix-green\" alt=\"fix - 1a62130a6b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003cimg src=\"https://img.shields.io/badge/a68ec702a0-fix-green\" alt=\"fix - a68ec702a0\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003cimg src=\"https://img.shields.io/badge/768a349e6e-fix-green\" alt=\"fix - 768a349e6e\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/ca48b4728d5f6770be63a08f64a6432207ad54c0\"\u003e\u003cimg src=\"https://img.shields.io/badge/ca48b4728d-fix-green\" alt=\"fix - ca48b4728d\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003evalidate lowercase SVG animation attribute names (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/69270\"\u003e#69270\u003c/a\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/06be29826741212ca00e21efb6abff653e4541b5\"\u003e\u003cimg src=\"https://img.shields.io/badge/06be298267-fix-green\" alt=\"fix - 06be298267\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve empty referrer option in HttpRequest\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/fa940e1f4de75c33ccca50357d941be53a5a0950\"\u003e\u003cimg src=\"https://img.shields.io/badge/fa940e1f4d-fix-green\" alt=\"fix - fa940e1f4d\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eRejects non-HTTP(S) URLs in JSONP requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/e2ef1ce72ae084e01a76950c731052f4fa97fcdd\"\u003e\u003cimg src=\"https://img.shields.io/badge/e2ef1ce72a-fix-green\" alt=\"fix - e2ef1ce72a\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for fetch credentialed requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/49368c185907edb48467074c56e305abbfa3544a\"\u003e\u003cimg src=\"https://img.shields.io/badge/49368c1859-fix-green\" alt=\"fix - 49368c1859\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden platform location origin validation during SSR\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d55c94ad811a15c9c255164a0d66892c645f602e\"\u003e\u003cimg src=\"https://img.shields.io/badge/d55c94ad81-refactor-yellow\" alt=\"refactor - d55c94ad81\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edeprecate ServerXhr (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/69256\"\u003e#69256\u003c/a\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d65a5f457b1afd6bdd4d952d3f213c6aa1aabcbc\"\u003e\u003cimg src=\"https://img.shields.io/badge/d65a5f457b-fix-green\" alt=\"fix - d65a5f457b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eStrips sensitive headers on cross-origin redirects\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003eDeprecations\u003c/h2\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eXHR support in \u003ccode\u003e@angular/platform-server\u003c/code\u003e is deprecated. Use standard \u003ccode\u003efetch\u003c/code\u003e APIs instead.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e20.3.24\u003c/h2\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6ca433e56bcf74fdb6ad01d3afdf59628fba69b6\"\u003e\u003cimg src=\"https://img.shields.io/badge/6ca433e56b-fix-green\" alt=\"fix - 6ca433e56b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003ethrow on suspicious URLs and restrict protocol-relative URLs\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8680b5152fe58ebde81e331b74ba806fc86514cc\"\u003e\u003cimg src=\"https://img.shields.io/badge/8680b5152f-fix-green\" alt=\"fix - 8680b5152f\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.23\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d40acc6431997b304ec54c951e55d2e52ed6f6dc\"\u003e\u003cimg src=\"https://img.shields.io/badge/d40acc6431-fix-green\" alt=\"fix - d40acc6431\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eprevent namespaced SVG \u003c!-- raw HTML omitted --\u003e elements from being stripped\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.22\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/blob/main/CHANGELOG.md\"\u003e@​angular/core's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e20.3.25 (2026-06-10)\u003c/h1\u003e\n\u003ch2\u003eDeprecations\u003c/h2\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eXHR support in \u003ccode\u003e@angular/platform-server\u003c/code\u003e is deprecated. Use standard \u003ccode\u003efetch\u003c/code\u003e APIs instead.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e9f443bc24c\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e566ad05f20\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e1a62130a6b\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003ea68ec702a0\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e768a349e6e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/ca48b4728d5f6770be63a08f64a6432207ad54c0\"\u003eca48b4728d\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003evalidate lowercase SVG animation attribute names (\u003ca href=\"https://redirect.github.com/angular/angular/pull/69270\"\u003e#69270\u003c/a\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/06be29826741212ca00e21efb6abff653e4541b5\"\u003e06be298267\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve empty referrer option in HttpRequest\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/fa940e1f4de75c33ccca50357d941be53a5a0950\"\u003efa940e1f4d\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eRejects non-HTTP(S) URLs in JSONP requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/e2ef1ce72ae084e01a76950c731052f4fa97fcdd\"\u003ee2ef1ce72a\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for fetch credentialed requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/49368c185907edb48467074c56e305abbfa3544a\"\u003e49368c1859\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eharden platform location origin validation during SSR\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d55c94ad811a15c9c255164a0d66892c645f602e\"\u003ed55c94ad81\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003erefactor\u003c/td\u003e\n\u003ctd\u003edeprecate ServerXhr (\u003ca href=\"https://redirect.github.com/angular/angular/pull/69256\"\u003e#69256\u003c/a\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d65a5f457b1afd6bdd4d952d3f213c6aa1aabcbc\"\u003ed65a5f457b\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eStrips sensitive headers on cross-origin redirects\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.0 (2026-06-03)\u003c/h1\u003e\n\u003cp\u003e\u003ca href=\"https://goo.gle/angular-v22-blog\"\u003eBlog post \u0026quot;Announcing Angular v22\u0026quot;\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eBreaking Changes\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThis change will trigger the \u003ccode\u003enullishCoalescingNotNullable\u003c/code\u003e and \u003ccode\u003eoptionalChainNotNullable\u003c/code\u003e diagnostics on exisiting projects.\nYou might want to disable those 2 diagnotiscs in your \u003ccode\u003etsconfig\u003c/code\u003e temporarily.\u003c/li\u003e\n\u003cli\u003edata prefixed attribute no-longer bind inputs nor outputs.\u003c/li\u003e\n\u003cli\u003eThe compiler will throw when there a when inputs, outputs or model are binding to the same input/outputs.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ein\u003c/code\u003e variables will throw in template expressions.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ecompiler-cli\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/ca48b4728d5f6770be63a08f64a6432207ad54c0\"\u003e\u003ccode\u003eca48b47\u003c/code\u003e\u003c/a\u003e fix(core): validate lowercase SVG animation attribute names (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/69270\"\u003e#69270\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003ccode\u003e1a62130\u003c/code\u003e\u003c/a\u003e fix(common): use cryptographically secure SHA-256 for transfer cache key gene...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/49368c185907edb48467074c56e305abbfa3544a\"\u003e\u003ccode\u003e49368c1\u003c/code\u003e\u003c/a\u003e fix(platform-server): harden platform location origin validation during SSR\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003ccode\u003e566ad05\u003c/code\u003e\u003c/a\u003e fix(common): skip transfer cache for uncacheable HTTP traffic\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003ccode\u003e768a349\u003c/code\u003e\u003c/a\u003e fix(core): harden TransferState restoration against DOM clobbering\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/7ae6381a4845ad4b13a7a5574c5433b077c93c5c\"\u003e\u003ccode\u003e7ae6381\u003c/code\u003e\u003c/a\u003e test(compiler-cli): align ngtsc sanitization expectations with modern DOM sch...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/65954092483a88fc69cccd3b4c56d96450ac2fe8\"\u003e\u003ccode\u003e6595409\u003c/code\u003e\u003c/a\u003e test(core): update golden symbols and host bindings sanitization spec (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/68926\"\u003e#68926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/d86e4e7b2ad0e667aeb0f8ed053e2cb2bd154b81\"\u003e\u003ccode\u003ed86e4e7\u003c/code\u003e\u003c/a\u003e fix(core): reject script element as a dynamic component host (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/68926\"\u003e#68926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/b8f1f7276514e258e8c815ec5c7d9b8826ecd372\"\u003e\u003ccode\u003eb8f1f72\u003c/code\u003e\u003c/a\u003e test(core): remove obsolete blockquote cite host binding tests (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/68926\"\u003e#68926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/36200bd81a3420d8222dfe10767437c383a20fe8\"\u003e\u003ccode\u003e36200bd\u003c/code\u003e\u003c/a\u003e test(core): update spec files to match 20.3.x limits and actual contexts (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/68\"\u003e#68\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/angular/angular/commits/v20.3.25/packages/core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@angular/common` from 17.3.8 to 20.3.27\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/releases\"\u003e@​angular/common's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e20.3.27\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e\u003cimg src=\"https://img.shields.io/badge/5dbcd0ee16-fix-green\" alt=\"fix - 5dbcd0ee16\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003e\u003cimg src=\"https://img.shields.io/badge/db0d4a1a39-fix-green\" alt=\"fix - db0d4a1a39\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003cimg src=\"https://img.shields.io/badge/a64e2883e9-fix-green\" alt=\"fix - a64e2883e9\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e\u003cimg src=\"https://img.shields.io/badge/6f80cca0b8-fix-green\" alt=\"fix - 6f80cca0b8\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.26\u003c/h2\u003e\n\u003ch3\u003ecompiler-cli\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/406aaa31e6ac4d3c155f5ab76e315ccd8d0387fe\"\u003e\u003cimg src=\"https://img.shields.io/badge/406aaa31e6-fix-green\" alt=\"fix - 406aaa31e6\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate babel dependencies to latest v7\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/26831d0cbd7e692210ca0799a203a7a5a0e741cd\"\u003e\u003cimg src=\"https://img.shields.io/badge/26831d0cbd-fix-green\" alt=\"fix - 26831d0cbd\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eavoid caching missing locale data\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8eb7aea08b27c0f1bcdeec3171880a6fcf28aa9a\"\u003e\u003cimg src=\"https://img.shields.io/badge/8eb7aea08b-fix-green\" alt=\"fix - 8eb7aea08b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003ereject dynamic script host elements\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003cimg src=\"https://img.shields.io/badge/b963f61028-fix-green\" alt=\"fix - b963f61028\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eprevent caching of responses with Set-Cookie headers\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1fdf2341684a0f528d1d31005bd48d882c0a47d1\"\u003e\u003cimg src=\"https://img.shields.io/badge/1fdf234168-fix-green\" alt=\"fix - 1fdf234168\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/baa093ba68c1d5ca7c35c562568c6021eb409b4c\"\u003e\u003cimg src=\"https://img.shields.io/badge/baa093ba68-fix-green\" alt=\"fix - baa093ba68\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer policy in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.25\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003cimg src=\"https://img.shields.io/badge/9f443bc24c-fix-green\" alt=\"fix - 9f443bc24c\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003cimg src=\"https://img.shields.io/badge/566ad05f20-fix-green\" alt=\"fix - 566ad05f20\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003cimg src=\"https://img.shields.io/badge/1a62130a6b-fix-green\" alt=\"fix - 1a62130a6b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003cimg src=\"https://img.shields.io/badge/a68ec702a0-fix-green\" alt=\"fix - a68ec702a0\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003cimg src=\"https://img.shields.io/badge/768a349e6e-fix-green\" alt=\"fix - 768a349e6e\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/blob/main/CHANGELOG.md\"\u003e@​angular/common's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e20.3.27 (2026-07-29)\u003c/h1\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e5dbcd0ee16\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edisallow...\n\n_Description has been truncated_\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nUpdates dependencies across examples and lockfiles to pick up security fixes and keep framework templates current. Highlights: `postcss` 8.5.23, Angular examples to v20.3.x, `nuxt` 3.21.10, `next` 16.3.0, plus security patches in `fast-uri` and `undici`.\n\n- **Dependencies**\n  - `postcss` → 8.5.23 (security hardening around source maps)\n  - Angular examples: `@angular/common`/`compiler` → 20.3.27, `@angular/core` → 20.3.25\n  - Nuxt example: `nuxt` → 3.21.10\n  - Next examples: `next` → 16.3.0\n  - Fixtures/tests: `fast-uri` → 3.1.5 (security), `undici` → 6.28.0 (security), `ip-address` → 10.4.0, `hono` → 4.12.34\n\n- **Migration**\n  - Angular examples target v20; align local CLI/Node if you run them (e.g., `ng` v20, Node 18+).\n  - If your PostCSS setup reads previous source maps, ensure `from` is set or adjust `unsafeMap` as needed.\n\n\u003csup\u003eWritten for commit e2bb3a2019a5cebaff76e871e24f4e18a2527921. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/Dev-moe-kyawaung/turborepo/pull/56?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/Dev-moe-kyawaung/turborepo/pull/56","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Dev-moe-kyawaung%2Fturborepo/issues/56","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/56/packages"},{"uuid":"5091128241","node_id":"PR_kwDOPUe_o878FSDH","number":36,"state":"open","title":"Bump the npm_and_yarn group across 19 directories with 17 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T14:31:45.000Z","updated_at":"2026-08-07T14:33:30.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"npm_and_yarn","update_count":17,"packages":[{"name":"uuid","old_version":"8.3.2","new_version":"removed","repository_url":"https://github.com/uuidjs/uuid"},{"name":"@tootallnate/once","old_version":"3.0.0","new_version":"3.0.1","repository_url":"https://github.com/TooTallNate/once"},{"name":"brace-expansion","old_version":"1.1.12","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"ws","old_version":"7.5.10","new_version":"7.5.13","repository_url":"https://github.com/websockets/ws"},{"name":"ip-address","old_version":"9.0.5","new_version":"10.4.0","repository_url":"https://github.com/beaugunderson/ip-address"},{"name":"js-yaml","old_version":"4.1.0","new_version":"4.3.1","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"linkify-it","old_version":"5.0.0","new_version":"5.0.2","repository_url":"https://github.com/markdown-it/linkify-it"},{"name":"markdown-it","old_version":"14.1.0","new_version":"14.3.0","repository_url":"https://github.com/markdown-it/markdown-it"},{"name":"morgan","old_version":"1.10.0","new_version":"1.11.0","repository_url":"https://github.com/expressjs/morgan"},{"name":"shell-quote","old_version":"1.7.3","new_version":"1.10.0","repository_url":"https://github.com/ljharb/shell-quote"},{"name":"undici","old_version":"7.9.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 11 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [uuid](https://github.com/uuidjs/uuid) | `8.3.2` | `removed` |\n| [@tootallnate/once](https://github.com/TooTallNate/once) | `3.0.0` | `3.0.1` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.12` | `1.1.18` |\n| [ws](https://github.com/websockets/ws) | `7.5.10` | `7.5.13` |\n| [ip-address](https://github.com/beaugunderson/ip-address) | `9.0.5` | `10.4.0` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.0` | `4.3.1` |\n| [linkify-it](https://github.com/markdown-it/linkify-it) | `5.0.0` | `5.0.2` |\n| [markdown-it](https://github.com/markdown-it/markdown-it) | `14.1.0` | `14.3.0` |\n| [morgan](https://github.com/expressjs/morgan) | `1.10.0` | `1.11.0` |\n| [shell-quote](https://github.com/ljharb/shell-quote) | `1.7.3` | `1.10.0` |\n| [undici](https://github.com/nodejs/undici) | `7.9.0` | `7.29.0` |\n\nBumps the npm_and_yarn group with 4 updates in the /build directory: [uuid](https://github.com/uuidjs/uuid), [brace-expansion](https://github.com/juliangruber/brace-expansion), [linkify-it](https://github.com/markdown-it/linkify-it) and [tmp](https://github.com/raszi/node-tmp).\nBumps the npm_and_yarn group with 3 updates in the /build/npm/gyp directory: [brace-expansion](https://github.com/juliangruber/brace-expansion), [tar](https://github.com/isaacs/node-tar) and [ip-address](https://github.com/beaugunderson/ip-address).\nBumps the npm_and_yarn group with 1 update in the /extensions/css-language-features directory: [brace-expansion](https://github.com/juliangruber/brace-expansion).\nBumps the npm_and_yarn group with 2 updates in the /extensions/extension-editing directory: [linkify-it](https://github.com/markdown-it/linkify-it) and [markdown-it](https://github.com/markdown-it/markdown-it).\nBumps the npm_and_yarn group with 2 updates in the /extensions/github-authentication directory: [form-data](https://github.com/form-data/form-data) and [@nevware21/ts-utils](https://github.com/nevware21/ts-utils).\nBumps the npm_and_yarn group with 2 updates in the /extensions/html-language-features directory: [brace-expansion](https://github.com/juliangruber/brace-expansion) and [@nevware21/ts-utils](https://github.com/nevware21/ts-utils).\nBumps the npm_and_yarn group with 2 updates in the /extensions/json-language-features directory: [brace-expansion](https://github.com/juliangruber/brace-expansion) and [@nevware21/ts-utils](https://github.com/nevware21/ts-utils).\nBumps the npm_and_yarn group with 5 updates in the /extensions/markdown-language-features directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.11` | `1.1.18` |\n| [linkify-it](https://github.com/markdown-it/linkify-it) | `3.0.3` | `6.1.0` |\n| [markdown-it](https://github.com/markdown-it/markdown-it) | `12.3.2` | `15.0.0` |\n| [@nevware21/ts-utils](https://github.com/nevware21/ts-utils) | `0.11.6` | `0.16.0` |\n| [dompurify](https://github.com/cure53/DOMPurify) | `3.2.4` | `3.4.12` |\n\nBumps the npm_and_yarn group with 1 update in the /extensions/merge-conflict directory: [@nevware21/ts-utils](https://github.com/nevware21/ts-utils).\nBumps the npm_and_yarn group with 3 updates in the /extensions/microsoft-authentication directory: [uuid](https://github.com/uuidjs/uuid), [form-data](https://github.com/form-data/form-data) and [@nevware21/ts-utils](https://github.com/nevware21/ts-utils).\nBumps the npm_and_yarn group with 3 updates in the /extensions/notebook-renderers directory: [@tootallnate/once](https://github.com/TooTallNate/once), [form-data](https://github.com/form-data/form-data) and [ws](https://github.com/websockets/ws).\nBumps the npm_and_yarn group with 2 updates in the /extensions/npm directory: [brace-expansion](https://github.com/juliangruber/brace-expansion) and [js-yaml](https://github.com/nodeca/js-yaml).\nBumps the npm_and_yarn group with 1 update in the /extensions/simple-browser directory: [@nevware21/ts-utils](https://github.com/nevware21/ts-utils).\nBumps the npm_and_yarn group with 1 update in the /extensions/typescript-language-features directory: [@nevware21/ts-utils](https://github.com/nevware21/ts-utils).\nBumps the npm_and_yarn group with 4 updates in the /remote directory: [uuid](https://github.com/uuidjs/uuid), [@tootallnate/once](https://github.com/TooTallNate/once), [ip-address](https://github.com/beaugunderson/ip-address) and [undici](https://github.com/nodejs/undici).\nBumps the npm_and_yarn group with 3 updates in the /test/automation directory: [brace-expansion](https://github.com/juliangruber/brace-expansion), [shell-quote](https://github.com/ljharb/shell-quote) and [tmp](https://github.com/raszi/node-tmp).\nBumps the npm_and_yarn group with 2 updates in the /test/integration/browser directory: [brace-expansion](https://github.com/juliangruber/brace-expansion) and [tmp](https://github.com/raszi/node-tmp).\nBumps the npm_and_yarn group with 3 updates in the /test/smoke directory: [brace-expansion](https://github.com/juliangruber/brace-expansion), [form-data](https://github.com/form-data/form-data) and [shell-quote](https://github.com/ljharb/shell-quote).\n\nRemoves `uuid`\n\nUpdates `@tootallnate/once` from 3.0.0 to 3.0.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/TooTallNate/once/releases\"\u003e@​tootallnate/once's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.0.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e28dbc5d: Fix promise hang when \u003ccode\u003eAbortSignal\u003c/code\u003e is aborted\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/TooTallNate/once/blob/master/CHANGELOG.md\"\u003e@​tootallnate/once's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.0.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e28dbc5d: Fix promise hang when \u003ccode\u003eAbortSignal\u003c/code\u003e is aborted\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/b31c7623e18b128325a05da02aa0832ee289b893\"\u003e\u003ccode\u003eb31c762\u003c/code\u003e\u003c/a\u003e Fix publish?\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/d2f7407721c023426c1af0712dbd71a3ca91d899\"\u003e\u003ccode\u003ed2f7407\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://redirect.github.com/TooTallNate/once/issues/9\"\u003e#9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/081645cb260aa86a55e5bffad2f1b52155cee8ea\"\u003e\u003ccode\u003e081645c\u003c/code\u003e\u003c/a\u003e Fix release script\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/f01fa45d958113c60f54bf7f83e460741d811a47\"\u003e\u003ccode\u003ef01fa45\u003c/code\u003e\u003c/a\u003e Fix Release job\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/28dbc5d7f9342ddfb6014ca5f3dc4206048db9cb\"\u003e\u003ccode\u003e28dbc5d\u003c/code\u003e\u003c/a\u003e Add Changesets\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/e66503b7f028a9fe7d22e2547d17cea71be05937\"\u003e\u003ccode\u003ee66503b\u003c/code\u003e\u003c/a\u003e Use pnpm in CI\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/6ec8b43f617a6feeb78ab98a4eb999123b664d2b\"\u003e\u003ccode\u003e6ec8b43\u003c/code\u003e\u003c/a\u003e Fix CI\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/b9f43cc5259bee2952d91ad3cdbd201a82df448a\"\u003e\u003ccode\u003eb9f43cc\u003c/code\u003e\u003c/a\u003e Fix promise hang when \u003ccode\u003eAbortSignal\u003c/code\u003e is aborted\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/a8c9dc3b7a241f992ebcde5b6b76ad5f97ce99af\"\u003e\u003ccode\u003ea8c9dc3\u003c/code\u003e\u003c/a\u003e Add pnpm-lock.yaml file\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/TooTallNate/once/compare/3.0.0...v3.0.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​tootallnate/once\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.12 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3\"\u003e\u003ccode\u003e10c05fc\u003c/code\u003e\u003c/a\u003e 1.1.14\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ws` from 7.5.10 to 7.5.13\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/websockets/ws/releases\"\u003ews's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e7.5.13\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug introduced in version 7.5.12 that prevented the fragment counter\nfrom resetting (18bcb11a).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.5.12\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eBackported a2f4e7c0 and f197ac65 to the v7.x release line (fb8a1935, deec2114).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.5.11\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eBackported 2b2abd45 to the 7.x release line (e14c4586).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/16808010390d5fb4b612a3a92e8803b1971e00c1\"\u003e\u003ccode\u003e1680801\u003c/code\u003e\u003c/a\u003e [dist] 7.5.13\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/18bcb11afa5ecebb7b1e33fc359acd5b7c7fcc9b\"\u003e\u003ccode\u003e18bcb11\u003c/code\u003e\u003c/a\u003e [fix] Reset the fragment counter when the message is complete\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/98fce81f1af6e2198fdd81c2f9241b897cea3885\"\u003e\u003ccode\u003e98fce81\u003c/code\u003e\u003c/a\u003e [dist] 7.5.12\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/deec2114f0d0fbd66e52e9229a755e05027f6724\"\u003e\u003ccode\u003edeec211\u003c/code\u003e\u003c/a\u003e [fix] Lower default values of \u003ccode\u003emaxBufferedChunks\u003c/code\u003e and \u003ccode\u003emaxFragments\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/fb8a1935f1ed7697cf283de69146f09d7e6bea63\"\u003e\u003ccode\u003efb8a193\u003c/code\u003e\u003c/a\u003e [fix] Count empty fragments toward the limit (\u003ca href=\"https://redirect.github.com/websockets/ws/issues/2329\"\u003e#2329\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/fd36cd864fcdf62a08273a99e19a7d975401fee8\"\u003e\u003ccode\u003efd36cd8\u003c/code\u003e\u003c/a\u003e [dist] 7.5.11\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/e14c45861deca0cef60dec0f9109b694abebdf52\"\u003e\u003ccode\u003ee14c458\u003c/code\u003e\u003c/a\u003e [security] Limit retained message parts\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/websockets/ws/compare/7.5.10...7.5.13\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ip-address` from 9.0.5 to 10.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/beaugunderson/ip-address/releases\"\u003eip-address's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev10.4.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd GitHub Actions CI by \u003ca href=\"https://github.com/beaugunderson\"\u003e\u003ccode\u003e@​beaugunderson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/pull/213\"\u003ebeaugunderson/ip-address#213\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eKeep the package loadable on node 12, and enforce it by \u003ca href=\"https://github.com/beaugunderson\"\u003e\u003ccode\u003e@​beaugunderson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/pull/216\"\u003ebeaugunderson/ip-address#216\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eValidate the byte arrays Address6 is given by \u003ca href=\"https://github.com/beaugunderson\"\u003e\u003ccode\u003e@​beaugunderson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/pull/217\"\u003ebeaugunderson/ip-address#217\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.3.1...v10.4.0\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.3.1...v10.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.3.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.3.0...v10.3.1\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.3.0...v10.3.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.3.0\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.2.2...v10.3.0\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.2.2...v10.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.2.2\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.2.1...v10.2.2\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.2.1...v10.2.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.2.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.2.1\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.2.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/fbb8db28f1559842b7191cab7d8ea6408ed82f7b\"\u003e\u003ccode\u003efbb8db2\u003c/code\u003e\u003c/a\u003e 10.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/45a2b11ec254a2e5620de66e248adcb33d16e669\"\u003e\u003ccode\u003e45a2b11\u003c/code\u003e\u003c/a\u003e Validate the byte arrays Address6 is given (\u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/issues/217\"\u003e#217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/bac8810b3935cab123316a4bc5ebaa22db140299\"\u003e\u003ccode\u003ebac8810\u003c/code\u003e\u003c/a\u003e Keep the package loadable on node 12, and enforce it (\u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/9b3d8488d15e6bfe5f5503867b088ce056723e08\"\u003e\u003ccode\u003e9b3d848\u003c/code\u003e\u003c/a\u003e Add a security policy and a README section on security posture\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/e84a7b381d02cb97ed114023e44133efae151254\"\u003e\u003ccode\u003ee84a7b3\u003c/code\u003e\u003c/a\u003e Order the README API reference Address4, Address6, AddressError\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/015160b85ee60b39548219817a5de3c4e828a6d6\"\u003e\u003ccode\u003e015160b\u003c/code\u003e\u003c/a\u003e Collapse each class in the README API reference\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/34061a897d526b7a063c3605402cd30a8363a035\"\u003e\u003ccode\u003e34061a8\u003c/code\u003e\u003c/a\u003e Pin checkout and setup-node to commits in the release job\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/c5fae5d9bdfe8ded7f4ca01a3d3ea8d97f8f1277\"\u003e\u003ccode\u003ec5fae5d\u003c/code\u003e\u003c/a\u003e Pin action-gh-release to a commit and move it to 3.0.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/e0ef0484193218b0d28cfbb53795bc44ddb3cc21\"\u003e\u003ccode\u003ee0ef048\u003c/code\u003e\u003c/a\u003e Replace CircleCI with GitHub Actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/5e3ceb779aee6ad3f33264e66225e8e7584ab612\"\u003e\u003ccode\u003e5e3ceb7\u003c/code\u003e\u003c/a\u003e Add GitHub Actions CI across Node 20, 22, 24 and 25 (\u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/issues/213\"\u003e#213\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v9.0.5...v10.4.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for ip-address since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version adds \u003ccode\u003eprepare\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `js-yaml` from 4.1.0 to 4.3.1\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.3.1 - 2026-07-31\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Remove quadratic complexity from \u003ccode\u003e!!omap\u003c/code\u003e duplicate key detection.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.3.0 - 2026-06-27\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Added \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (10000) loader option to limit the total number of\nkeys processed by YAML merge (\u003ccode\u003e\u0026lt;\u0026lt;\u003c/code\u003e) across one \u003ccode\u003eload()\u003c/code\u003e / \u003ccode\u003eloadAll()\u003c/code\u003e call.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRestore umd builds back to es5.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRemoved\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e replaced with \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e for limiting YAML merge\nprocessing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[4.2.0] - 2026-06-01\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003edocs/safety.md\u003c/code\u003e with notes about processing untrusted YAML.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxDepth\u003c/code\u003e (100) loader option. Not a problem, but gives a better\nexception instead of RangeError on stack overflow.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e (20) loader option. Not a problem after \u003ccode\u003emerge\u003c/code\u003e fix,\nbut an additional restriction for safety.\u003c/li\u003e\n\u003cli\u003eAdded sourcemaps to \u003ccode\u003edist/\u003c/code\u003e builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStop resolving numbers with underscores as numeric scalars, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/627\"\u003e#627\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eSwitched dev toolchains to Vite / neostandard.\u003c/li\u003e\n\u003cli\u003eUpdated demo.\u003c/li\u003e\n\u003cli\u003eReorganized tests.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edist/\u003c/code\u003e files are no longer kept in the repository.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix parsing of properties on the first implicit block mapping key, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/62\"\u003e#62\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix trailing whitespace handling when folding flow scalar lines, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/307\"\u003e#307\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eReject top-level block scalars without content indentation, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/280\"\u003e#280\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eEnsure numbers survive round-trip, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/737\"\u003e#737\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix test coverage for issue \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/221\"\u003e#221\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix flow scalar trailing whitespace folding, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/307\"\u003e#307\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix digits in YAML named tag handles.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix potential DoS via quadratic complexity in merge - deduplicate repeated\nelements (makes sense for malformed files \u0026gt; 10K).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[3.14.2] - 2025-11-15\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/86e91b815b8794c3c73a179c1770871e37ec2df8\"\u003e\u003ccode\u003e86e91b8\u003c/code\u003e\u003c/a\u003e 4.3.1 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/c3cc4b0bb9ddb9af2dd9b61e0d56f5ce7983cd4a\"\u003e\u003ccode\u003ec3cc4b0\u003c/code\u003e\u003c/a\u003e Backport quadratic complexity fix for !!omap\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/33d05b5d29a8c21360f620f7e1c1706e24522eda\"\u003e\u003ccode\u003e33d05b5\u003c/code\u003e\u003c/a\u003e 4.3.0 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/663bfab6db2b4a146a9366fd685f069345be4ddb\"\u003e\u003ccode\u003e663bfab\u003c/code\u003e\u003c/a\u003e Drop demo publish, to not override new v5 one.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/1cb8c7b94bf75e15116869c1c0482dcb22785986\"\u003e\u003ccode\u003e1cb8c7b\u003c/code\u003e\u003c/a\u003e Add v4-legacy tag for publish\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/02f27afad532763263cd2b6be35c24ee8e1f6157\"\u003e\u003ccode\u003e02f27af\u003c/code\u003e\u003c/a\u003e Restore umd builds back to es5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/8be84edaf15e7c394fa3b813179d1bcc280e87fb\"\u003e\u003ccode\u003e8be84ed\u003c/code\u003e\u003c/a\u003e Fix es5 compatibility\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4\"\u003e\u003ccode\u003e59423c6\u003c/code\u003e\u003c/a\u003e Replace \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e option with \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (more robust). Ba...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/6842ef6a02df01ca7282ea01dc3c70787710c05d\"\u003e\u003ccode\u003e6842ef6\u003c/code\u003e\u003c/a\u003e doc polish\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/590dbabadd172b099c07654fab2eabec8c7a07b9\"\u003e\u003ccode\u003e590dbab\u003c/code\u003e\u003c/a\u003e 4.2.0 released\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/4.1.0...4.3.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `linkify-it` from 5.0.0 to 5.0.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md\"\u003elinkify-it's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.0.2 / 2026-07-02\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed DoS in \u003ccode\u003emailto:\u003c/code\u003e links (restrict user name to 64 chars).\u003c/li\u003e\n\u003cli\u003eRestricted user/pass part length in links.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e5.0.1 / 2026-05-23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed DoS in fuzzy links/emails search.\u003c/li\u003e\n\u003cli\u003eReworked search logic - check each pattern separate, use \u003ccode\u003eg\u003c/code\u003e regexes instead\nof slice.\u003c/li\u003e\n\u003cli\u003eRemoved internal cache - useless overcomplication.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/50a0c914f834b201cab25ff4faefd1f832b37332\"\u003e\u003ccode\u003e50a0c91\u003c/code\u003e\u003c/a\u003e 5.0.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/de3b88554b5e465d5fa19914e2a1801ebb3069ef\"\u003e\u003ccode\u003ede3b885\u003c/code\u003e\u003c/a\u003e Update package hooks\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/13effaaa4600d1fcff9f63c38fecdd601bfd83e7\"\u003e\u003ccode\u003e13effaa\u003c/code\u003e\u003c/a\u003e Add package lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/39d748dbfc77534e9be04d87cd9f57a13b9b4216\"\u003e\u003ccode\u003e39d748d\u003c/code\u003e\u003c/a\u003e Bump c8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/00ce8771ac0c3e6784dcacaa1625ca0fc1b62a12\"\u003e\u003ccode\u003e00ce877\u003c/code\u003e\u003c/a\u003e Drop tlds deps\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/ecde82341a1b2e349b03eb01f3e1d2cc105bcd7f\"\u003e\u003ccode\u003eecde823\u003c/code\u003e\u003c/a\u003e Update benchmark to mitata\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/23c62cdd14ef36e89c175c6726e2229e5b76e75f\"\u003e\u003ccode\u003e23c62cd\u003c/code\u003e\u003c/a\u003e Refactor demo / doc build and publish\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/fd63f3b4ab433ca3561304409b572eed465706cd\"\u003e\u003ccode\u003efd63f3b\u003c/code\u003e\u003c/a\u003e CI config update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/f4ea5afaa6a8e1109c44898158d4910b3fb128fb\"\u003e\u003ccode\u003ef4ea5af\u003c/code\u003e\u003c/a\u003e demo: update bootstrap \u0026amp; layout\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/1454fb645f00c33a05edbded18640d5078ba7710\"\u003e\u003ccode\u003e1454fb6\u003c/code\u003e\u003c/a\u003e lint: dim warnings\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/markdown-it/linkify-it/compare/5.0.0...5.0.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `markdown-it` from 14.1.0 to 14.3.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md\"\u003emarkdown-it's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[14.3.0] - 2026-07-02\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReworked build pipeline \u0026amp; tools.\u003c/li\u003e\n\u003cli\u003eAdded source maps.\u003c/li\u003e\n\u003cli\u003eBumped \u003ccode\u003elinkify-it\u003c/code\u003e to 5.0.2.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve backslash-space hard line breaks, matching CommonMark 6.7, \u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1185\"\u003e#1185\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[14.2.0] - 2026-05-24\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eisPunctCharCode\u003c/code\u003e to utilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDon't end HTML comment blocks on a blank line, \u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1155\"\u003e#1155\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eProperly recognize astral chars (surrogates) in delimiter scans for\nemphasis-like markers, \u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1072\"\u003e#1072\u003c/a\u003e. Big thanks to \u003ca href=\"https://github.com/tats-u\"\u003e\u003ccode\u003e@​tats-u\u003c/code\u003e\u003c/a\u003e for his global efforts\nwith improving CJK support.\u003c/li\u003e\n\u003cli\u003ePreserve unicode whitespaces when trimm headings/paragraphs, \u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1074\"\u003e#1074\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eMore strict entities decode to avoid false positives \u003ccode\u003e;\u003c/code\u003e, \u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1096\"\u003e#1096\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eRestore block parser state on fail in \u003ccode\u003elheading\u003c/code\u003e rule, \u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1131\"\u003e#1131\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed poor smartquotes perfomance on \u0026gt; 70k quotes in single block\u003c/li\u003e\n\u003cli\u003eBumped linkify-it to 5.0.1 with fixed potential perfomance issues.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[14.1.1] - 2026-01-11\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed regression from v13 in linkify inline rule. Specific patterns could\ncause high CPU use. Thanks to \u003ca href=\"https://github.com/ltduc147\"\u003e\u003ccode\u003e@​ltduc147\u003c/code\u003e\u003c/a\u003e for report.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/ff0ee084fc6b0d10fac049fa562bc2925b5cc723\"\u003e\u003ccode\u003eff0ee08\u003c/code\u003e\u003c/a\u003e 14.3.0 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/52e2749ab25aaf841bf74b50560929aa93b8e14d\"\u003e\u003ccode\u003e52e2749\u003c/code\u003e\u003c/a\u003e Bump linkify-it / vite deps\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/56c2404e6d3e78632ce7b37a95f289fc04330c76\"\u003e\u003ccode\u003e56c2404\u003c/code\u003e\u003c/a\u003e fix: keep backslash-space hard line break (CommonMark 6.7) (\u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1185\"\u003e#1185\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/0fbb18b23145158a39255f7476c781dbce320a16\"\u003e\u003ccode\u003e0fbb18b\u003c/code\u003e\u003c/a\u003e Bump vite from 8.0.14 to 8.0.16 (\u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1181\"\u003e#1181\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/83450e2bc3836ad9f68f652e5685031e9dce4897\"\u003e\u003ccode\u003e83450e2\u003c/code\u003e\u003c/a\u003e Rework benchmark deps and bump versions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/57a68632ce317593fe316b7131105b131691b90b\"\u003e\u003ccode\u003e57a6863\u003c/code\u003e\u003c/a\u003e benchmark =\u0026gt; tinybench\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/7608db19a5b14f84b47b34cced43c574b1abfd0c\"\u003e\u003ccode\u003e7608db1\u003c/code\u003e\u003c/a\u003e Update CI config\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/9d8eb42a72e0e576125733acc7ae6154e8f6cb5a\"\u003e\u003ccode\u003e9d8eb42\u003c/code\u003e\u003c/a\u003e Added package-lock and updated versions to latest possible\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/0aee70db5e8284c84201d39d64c2b14228fd280a\"\u003e\u003ccode\u003e0aee70d\u003c/code\u003e\u003c/a\u003e lint: enable \u003ccode\u003e@​stylistic/no-multi-spaces\u003c/code\u003e rule\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/88789854dc44db99b7736fd4349487dfda0d4067\"\u003e\u003ccode\u003e8878985\u003c/code\u003e\u003c/a\u003e lint =\u0026gt; neostandard\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/markdown-it/markdown-it/compare/14.1.0...14.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `morgan` from 1.10.0 to 1.11.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/morgan/releases\"\u003emorgan's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.11.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: add :pid token by \u003ca href=\"https://github.com/ganesh3367\"\u003e\u003ccode\u003e@​ganesh3367\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/329\"\u003eexpressjs/morgan#329\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSecurity Fix:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEscape control characters in \u003ccode\u003e:remote-user\u003c/code\u003e token to prevent log injection\n\u003cul\u003e\n\u003cli\u003eFixes \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2026-5078\"\u003eCVE-2026-5078\u003c/a\u003e \u003ca href=\"https://github.com/expressjs/morgan/security/advisories/GHSA-4vj7-5mj6-jm8m\"\u003eGHSA-4vj7-5mj6-jm8m\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/inigomarquinez\"\u003e\u003ccode\u003e@​inigomarquinez\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/291\"\u003eexpressjs/morgan#291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jonchurch\"\u003e\u003ccode\u003e@​jonchurch\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/299\"\u003eexpressjs/morgan#299\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bjohansebas\"\u003e\u003ccode\u003e@​bjohansebas\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/301\"\u003eexpressjs/morgan#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/300\"\u003eexpressjs/morgan#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ctcpip\"\u003e\u003ccode\u003e@​ctcpip\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/319\"\u003eexpressjs/morgan#319\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ganesh3367\"\u003e\u003ccode\u003e@​ganesh3367\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/329\"\u003eexpressjs/morgan#329\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/morgan/compare/1.10.0...1.11.0\"\u003ehttps://github.com/expressjs/morgan/compare/1.10.0...1.11.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.10.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003erenaming simple to sample in readme by \u003ca href=\"https://github.com/ryhinchey\"\u003e\u003ccode\u003e@​ryhinchey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/237\"\u003eexpressjs/morgan#237\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eadding installation instructions to readme by \u003ca href=\"https://github.com/ryhinchey\"\u003e\u003ccode\u003e@​ryhinchey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/233\"\u003eexpressjs/morgan#233\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: add support for OSSF scorecard reporting by \u003ca href=\"https://github.com/inigomarquinez\"\u003e\u003ccode\u003e@​inigomarquinez\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/291\"\u003eexpressjs/morgan#291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: replace travis with github actions by \u003ca href=\"https://github.com/inigomarquinez\"\u003e\u003ccode\u003e@​inigomarquinez\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/290\"\u003eexpressjs/morgan#290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: add example output for log formats by \u003ca href=\"https://github.com/jonchurch\"\u003e\u003ccode\u003e@​jonchurch\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/299\"\u003eexpressjs/morgan#299\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: use ubuntu-latest by \u003ca href=\"https://github.com/bjohansebas\"\u003e\u003ccode\u003e@​bjohansebas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/301\"\u003eexpressjs/morgan#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: apply OSSF Scorecard security best practices by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/300\"\u003eexpressjs/morgan#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eremove --bail by \u003ca href=\"https://github.com/jonchurch\"\u003e\u003ccode\u003e@​jonchurch\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/314\"\u003eexpressjs/morgan#314\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e⬆️ bump on-headers by \u003ca href=\"https://github.com/ctcpip\"\u003e\u003ccode\u003e@​ctcpip\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/319\"\u003eexpressjs/morgan#319\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/inigomarquinez\"\u003e\u003ccode\u003e@​inigomarquinez\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/291\"\u003eexpressjs/morgan#291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jonchurch\"\u003e\u003ccode\u003e@​jonchurch\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/299\"\u003eexpressjs/morgan#299\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bjohansebas\"\u003e\u003ccode\u003e@​bjohansebas\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/301\"\u003eexpressjs/morgan#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/300\"\u003eexpressjs/morgan#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ctcpip\"\u003e\u003ccode\u003e@​ctcpip\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/319\"\u003eexpressjs/morgan#319\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/morgan/compare/1.10.0...1.10.1\"\u003ehttps://github.com/expressjs/morgan/compare/1.10.0...1.10.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/morgan/blob/master/HISTORY.md\"\u003emorgan's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e1.11.0 / 2026-06-02\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003e:pid\u003c/code\u003e token\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSecurity Fix:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEscape control characters in \u003ccode\u003e:remote-user\u003c/code\u003e token to prevent log injection\n\u003cul\u003e\n\u003cli\u003eFixes \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2026-5078\"\u003eCVE-2026-5078\u003c/a\u003e \u003ca href=\"https://github.com/expressjs/morgan/security/advisories/GHSA-4vj7-5mj6-jm8m\"\u003eGHSA-4vj7-5mj6-jm8m\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.10.1 / 2025-07-17\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003edeps: on-headers@~1.1.0\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2025-7339\"\u003eCVE-2025-7339\u003c/a\u003e (\u003ca href=\"https://github.com/expressjs/on-headers/security/advisories/GHSA-76c9-3jph-rj3q\"\u003eGHSA-76c9-3jph-rj3q\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/e0e6f17574db56396f8e60ebb03bb7aaaeb9cc6f\"\u003e\u003ccode\u003ee0e6f17\u003c/code\u003e\u003c/a\u003e Release 1.11.0 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/350\"\u003e#350\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/b3f5d9bdb388690dfae9c06ab966328f49b7982b\"\u003e\u003ccode\u003eb3f5d9b\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/203c75852adadcc5e3a9ba23b0ef07a8e81c5af7\"\u003e\u003ccode\u003e203c758\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action from 4.32.4 to 4.35.2 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/346\"\u003e#346\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/002bc81f47a7641d86b7e16ee0f343e5eed81a6a\"\u003e\u003ccode\u003e002bc81\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/347\"\u003e#347\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/561b0d70bf4486245b311a02259d32ae45756331\"\u003e\u003ccode\u003e561b0d7\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/upload-artifact from 5.0.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/338\"\u003e#338\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/2db705ecf05eed5a2990da4be8731a1d7051692c\"\u003e\u003ccode\u003e2db705e\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action from 3.29.7 to 4.32.4 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/337\"\u003e#337\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/a373c5f25df88c7f31b4abb36306d7e025edcc8c\"\u003e\u003ccode\u003ea373c5f\u003c/code\u003e\u003c/a\u003e build(deps): bump ossf/scorecard-action from 2.3.1 to 2.4.3 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/327\"\u003e#327\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/c8e72fa73c7e54a00f0e28db1bc6edbeb83dbbc0\"\u003e\u003ccode\u003ec8e72fa\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/checkout from 4.1.1 to 6.0.1 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/324\"\u003e#324\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/023300e37da5e2a3394a50171d07a0bb6860eab5\"\u003e\u003ccode\u003e023300e\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/upload-artifact from 4.3.1 to 4.6.2 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/307\"\u003e#307\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/9d8d6c099765b1d4722aadfb68dbf0a227ff8e64\"\u003e\u003ccode\u003e9d8d6c0\u003c/code\u003e\u003c/a\u003e build(deps): bump coverallsapp/github-action from 1.2.5 to 2.3.6 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/expressjs/morgan/compare/1.10.0...1.11.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~ulisesgascon\"\u003eulisesgascon\u003c/a\u003e, a new releaser for morgan since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `shell-quote` from 1.7.3 to 1.10.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md\"\u003eshell-quote's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.9.0...v1.10.0\"\u003ev1.10.0\u003c/a\u003e - 2026-07-10\u003c/h2\u003e\n\u003ch3\u003eMerged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[New] \u003ccode\u003eparse\u003c/code\u003e: add opt-in \u003ccode\u003esplitUnquoted\u003c/code\u003e option for shell field-splitting of unquoted expansions \u003ca href=\"https://redirect.github.com/ljharb/shell-quote/pull/1\"\u003e\u003ccode\u003e[#1](https://github.com/ljharb/shell-quote/issues/1)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: match nested \u003ccode\u003e${...}\u003c/code\u003e braces so nested parameter expansion is consumed as one substitution \u003ca href=\"https://github.com/ljharb/shell-quote/commit/c0842c8a7a034066da2496a75e91cbe500ff736c\"\u003e\u003ccode\u003ec0842c8\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003eparse\u003c/code\u003e: pin single-quote literalness and unmatched-quote handling \u003ca href=\"https://github.com/ljharb/shell-quote/commit/a0d03e35c8ede24016502c4433b8f5d6b3100a62\"\u003e\u003ccode\u003ea0d03e3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] remove the space in js code fences so evalmd evaluates them \u003ca href=\"https://github.com/ljharb/shell-quote/commit/2116fa36aeea77fe8d561b0db46b1f9b26b8cf1b\"\u003e\u003ccode\u003e2116fa3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: pin conservative escaping of \u003ccode\u003e=\u003c/code\u003e, \u003ccode\u003e@\u003c/code\u003e, \u003ccode\u003e^\u003c/code\u003e, \u003ccode\u003e,\u003c/code\u003e, \u003ccode\u003e:\u003c/code\u003e, \u003ccode\u003e!\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/1c36f3ff77d26d200620c1027e5c271050120b8e\"\u003e\u003ccode\u003e1c36f3f\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] document that \u003ccode\u003equote\u003c/code\u003e outputs POSIX quoting, not \u003ccode\u003ecmd.exe\u003c/code\u003e/PowerShell \u003ca href=\"https://github.com/ljharb/shell-quote/commit/100e96e0ffadcca97d63dda15651c70b9f83507c\"\u003e\u003ccode\u003e100e96e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] document \u003ccode\u003eparse\u003c/code\u003e's supported parameter-expansion subset \u003ca href=\"https://github.com/ljharb/shell-quote/commit/e1c75cd6e4a3c60003792c7f2802587d328622cb\"\u003e\u003ccode\u003ee1c75cd\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: a backslash inside single quotes must not escape the closing quote \u003ca href=\"https://github.com/ljharb/shell-quote/commit/5d460a332b54b83153297fe7d1964330b28fa491\"\u003e\u003ccode\u003e5d460a3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] fix stale example outputs \u003ca href=\"https://github.com/ljharb/shell-quote/commit/2de86f5d44f44d3ac9df36413d8a05f3534cdec6\"\u003e\u003ccode\u003e2de86f5\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: pin that a backslash with whitespace is not doubled in single quotes (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/14\"\u003e#14\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/190e236bcf1d81caa8e40e8ea3bb11998575be71\"\u003e\u003ccode\u003e190e236\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] \u003ccode\u003equote\u003c/code\u003e: use output verbatim; do not re-quote it (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/1b364683b1e9e8d078fd3017cde82cf10c9c04a5\"\u003e\u003ccode\u003e1b36468\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Refactor] \u003ccode\u003eparse\u003c/code\u003e: fix swapped \u003ccode\u003eSINGLE_QUOTE\u003c/code\u003e/\u003ccode\u003eDOUBLE_QUOTE\u003c/code\u003e variable names \u003ca href=\"https://github.com/ljharb/shell-quote/commit/801af5c935b27d6dcda63b3975d5e92a7b6f887f\"\u003e\u003ccode\u003e801af5c\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[types] fix an error TS v6 ignores but v7 fails on \u003ca href=\"https://github.com/ljharb/shell-quote/commit/59bbf8b81bf3236842deb72805744d489f650eba\"\u003e\u003ccode\u003e59bbf8b\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@arethetypeswrong/cli\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/a04d47516e1cd5b1b4d3f720ddf97561ed0082fc\"\u003e\u003ccode\u003ea04d475\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@arethetypeswrong/ci\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/d390f9a92b97a04b1f799298634e90dc581021e6\"\u003e\u003ccode\u003ed390f9a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: the tilde test escapes every \u003ccode\u003e~\u003c/code\u003e, not just a leading one (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/9\"\u003e#9\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/617d119795c7b44d6e49a4d41f80195c4aa5735c\"\u003e\u003ccode\u003e617d119\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.4...v1.9.0\"\u003ev1.9.0\u003c/a\u003e - 2026-06-24\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[New] add types \u003ca href=\"https://github.com/ljharb/shell-quote/commit/dca6e21a02df4cc1a83ed1b5baa4d82df134170a\"\u003e\u003ccode\u003edca6e21\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9aa9e8f60991f8c4053a29e476795d891ff851ad\"\u003e\u003ccode\u003e9aa9e8f\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: finalize tokens in linear time (GHSA-395f-4hp3-45gv) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7ff5488599d01c323514f02f5efb74088dd134ec\"\u003e\u003ccode\u003e7ff5488\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] update workflows \u003ca href=\"https://github.com/ljharb/shell-quote/commit/75e849741ffaf2d3aa53ae0e18ef6bf9929ef478\"\u003e\u003ccode\u003e75e8497\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 4/6/7: pin eslint to 9 before install, since npm 2/3 cannot stage eslint 10\u003ccode\u003e@types/esrecurse\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3fb739de44b81c69431947d54fbfc18998dd6d72\"\u003e\u003ccode\u003e3fb739d\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] retry \u003ccode\u003enpm install\u003c/code\u003e on Windows to survive npm 2/3 staging-rename flake \u003ca href=\"https://github.com/ljharb/shell-quote/commit/abe0163293c82963fa8a16cfaa87181846d5aced\"\u003e\u003ccode\u003eabe0163\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 5/7: install deps with a modern node \u003ca href=\"https://github.com/ljharb/shell-quote/commit/b4bafa2e7e58d53d9839b1c24976f61e54b43326\"\u003e\u003ccode\u003eb4bafa2\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: escape leading \u003ccode\u003e~\u003c/code\u003e to prevent shell tilde-expansion \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7a76c1a12d8461c2234a1c655b943cee84cbff91\"\u003e\u003ccode\u003e7a76c1a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7184b4458b65c17b931e126d8cb5f586c6717dc8\"\u003e\u003ccode\u003e7184b44\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] apparently \u003ccode\u003ejackspeak\u003c/code\u003e is no longer in the graph \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9ba368a4057b9f498b0fef23b5b15543ef81b98c\"\u003e\u003ccode\u003e9ba368a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.3...v1.8.4\"\u003ev1.8.4\u003c/a\u003e - 2026-05-22\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: validate object-token shapes \u003ca href=\"https://github.com/ljharb/shell-quote/commit/4378a6e613db5948168684864e49b42b83134d2d\"\u003e\u003ccode\u003e4378a6e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003enpmignore\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/22ebec04349065a45ad8afc8cc8d53c4624634a6\"\u003e\u003ccode\u003e22ebec0\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] increase coverage \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9f3caa31900cc6ee64858b31134144c648ce206d\"\u003e\u003ccode\u003e9f3caa3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] replace runkit CI badge with shields.io check-runs badge \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3344a047dd1e95f71c4ca27522cbfd05c56277e0\"\u003e\u003ccode\u003e3344a04\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/699c5113d135f4d4591574bebf173334ffa453d4\"\u003e\u003ccode\u003e699c511\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.2...v1.8.3\"\u003ev1.8.3\u003c/a\u003e - 2025-06-01\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/64988d9a0e73a2ae710488952e3614958ef289d4\"\u003e\u003ccode\u003e64988d9\u003c/code\u003e\u003c/a\u003e v1.10.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/617d119795c7b44d6e49a4d41f80195c4aa5735c\"\u003e\u003ccode\u003e617d119\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: the tilde test escapes every \u003ccode\u003e~\u003c/code\u003e, not just a leading one (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/9\"\u003e#9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/59bbf8b81bf3236842deb72805744d489f650eba\"\u003e\u003ccode\u003e59bbf8b\u003c/code\u003e\u003c/a\u003e [types] fix an error TS v6 ignores but v7 fails on\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/190e236bcf1d81caa8e40e8ea3bb11998575be71\"\u003e\u003ccode\u003e190e236\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: pin that a backslash with whitespace is not doubled in singl...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/a04d47516e1cd5b1b4d3f720ddf97561ed0082fc\"\u003e\u003ccode\u003ea04d475\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003e@arethetypeswrong/cli\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/b9545b39f4de17aa169410823c98acf58387e474\"\u003e\u003ccode\u003eb9545b3\u003c/code\u003e\u003c/a\u003e [New] \u003ccode\u003eparse\u003c/code\u003e: add opt-in \u003ccode\u003esplitUnquoted\u003c/code\u003e option for shell field-splitting of...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/1b364683b1e9e8d078fd3017cde82cf10c9c04a5\"\u003e\u003ccode\u003e1b36468\u003c/code\u003e\u003c/a\u003e [readme] \u003ccode\u003equote\u003c/code\u003e: use output verbatim; do not re-quote it (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/1c36f3ff77d26d200620c1027e5c271050120b8e\"\u003e\u003ccode\u003e1c36f3f\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: pin conservative escaping of \u003ccode\u003e=\u003c/code\u003e, \u003ccode\u003e@\u003c/code\u003e, \u003ccode\u003e^\u003c/code\u003e, \u003ccode\u003e,\u003c/code\u003e, \u003ccode\u003e:\u003c/code\u003e, \u003ccode\u003e!\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/e1c75cd6e4a3c60003792c7f2802587d328622cb\"\u003e\u003ccode\u003ee1c75cd\u003c/code\u003e\u003c/a\u003e [readme] document \u003ccode\u003eparse\u003c/code\u003e's supported parameter-expansion subset\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/c0842c8a7a034066da2496a75e91cbe500ff736c\"\u003e\u003ccode\u003ec0842c8\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003eparse\u003c/code\u003e: match nested \u003ccode\u003e${...}\u003c/code\u003e braces so nested parameter expansion is ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.7.3...v1.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~ljharb\"\u003eljharb\u003c/a\u003e, a new releaser for shell-quote since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version adds \u003ccode\u003eprepublish\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.9.0 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.28.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e7 security advisories\u003c/strong\u003e, all shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 7.28.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^7.28.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v7 line is \u003cstrong\u003enot\u003c/strong\u003e affected by GHSA-38rv-x7px-6hhq (CVE-2026-9675), which is\nan 8.x-only regression.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on GHSA-hm92-r4w5-c3mj:\u003c/strong\u003e this fix shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e, not the\nearlier 7.2x line — the vulnerable single-pool code was still present through\n\u003ccode\u003ev7.27.2\u003c/code\u003e. The per-origin pool fix is\n\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5041\"\u003e#5041\u003c/a\u003e).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8cb10f98\"\u003e\u003ccode\u003e8cb10f98\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g\"\u003eGHSA-vmh5-mc38-953g\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9697\u003c/td\u003e\n\u003ctd\u003eHigh (7.4)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/04201f89\"\u003e\u003ccode\u003e04201f89\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj\"\u003eGHSA-hm92-r4w5-c3mj\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6734\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6\"\u003eGHSA-pr7r-676h-xcf6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9678\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/85a24055\"\u003e\u003ccode\u003e85a24055\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ea8930cf\"\u003e\u003ccode\u003eea8930cf\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f9eba0ad9134e1c0977848476bba9d49734696e4\"\u003e\u003ccode\u003ef9eba0a\u003c/code\u003e\u003c/a\u003e Bumped v7.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5430\"\u003e#5430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.9.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for undici since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nRemoves `uuid`\n\nUpdates `brace-expansion` from 1.1.12 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3\"\u003e\u003ccode\u003e10c05fc\u003c/code\u003e\u003c/a\u003e 1.1.14\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 2.0.2 to 2.1.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3\"\u003e\u003ccode\u003e10c05fc\u003c/code\u003e\u003c/a\u003e 1.1.14\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `linkify-it` from 3.0.3 to 5.0.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md\"\u003elinkify-it's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.0.2 / 2026-07-02\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed DoS in \u003ccode\u003emailto:\u003c/code\u003e links (restrict user name to 64 chars).\u003c/li\u003e\n\u003cli\u003eRestricted user/pass part length in links.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e5.0.1 / 2026-05-23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed DoS in fuzzy links/emails search.\u003c/li\u003e\n\u003cli\u003eReworked search logic - check each pattern separate, use \u003ccode\u003eg\u003c/code\u003e regexes instead\nof slice.\u003c/li\u003e\n\u003cli\u003eRemoved internal cache - useless overcomplication.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/50a0c914f834b201cab25ff4faefd1f832b37332\"\u003e\u003ccode\u003e50a0c91\u003c/code\u003e\u003c/a\u003e 5.0.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/de3b88554b5e465d5fa19914e2a1801ebb3069ef\"\u003e\u003ccode\u003ede3b885\u003c/code\u003e\u003c/a\u003e Update package hooks\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/13effaaa4600d1fcff9f63c38fecdd601bfd83e7\"\u003e\u003ccode\u003e13effaa\u003c/code\u003e\u003c/a\u003e Add package lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/39d748dbfc77534e9be04d87cd9f57a13b9b4216\"\u003e\u003ccode\u003e39d748d\u003c/code\u003e\u003c/a\u003e Bump c8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/00ce8771ac0c3e6784dcacaa1625ca0fc1b62a12\"\u003e\u003ccode\u003e00ce877\u003c/code\u003e\u003c/a\u003e Drop tlds deps\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/ecde82341a1b2e349b03eb01f3e1d2cc105bcd7f\"\u003e\u003ccode\u003eecde823\u003c/code\u003e\u003c/a\u003e Update benchmark to mitata\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/23c62cdd14ef36e89c175c6726e2229e5b76e75f\"\u003e\u003ccode\u003e23c62cd\u003c/code\u003e\u003c/a\u003e Refactor demo / doc build and publish\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/fd63f3b4ab433ca3561304409b572eed465706cd\"\u003e\u003ccode\u003efd63f3b\u003c/code\u003e\u003c/a\u003e CI config update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/f4ea5afaa6a8e1109c44898158d4910b3fb128fb\"\u003e\u003ccode\u003ef4ea5af\u003c/code\u003e\u003c/a\u003e demo: update bootstrap \u0026amp; layout\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/1454fb645f00c33a05edbded18640d5078ba7710\"\u003e\u003ccode\u003e1454fb6\u003c/code\u003e\u003c/a\u003e lint: dim warnings\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/markdown-it/linkify-it/compare/5.0.0...5.0.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `markdown-it` from 12.3.2 to 14.3.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md\"\u003emarkdown-it's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[14.3.0] - 2026-07-02\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReworked build pipeline \u0026amp; tools.\u003c/li\u003e\n\u003cli\u003eAdded source maps.\u003c/li\u003e\n\u003cli\u003eBumped \u003ccode\u003elinkify-it\u003c/code\u003e to 5.0.2.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve backslash-space hard line breaks, matching CommonMark 6.7, \u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1185\"\u003e#1185\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[14.2.0] - 2026-05-24\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eisPunctCharCode\u003c/code\u003e to utilities.\u003c/li...\n\n_Description has been truncated_","html_url":"https://github.com/goodgollyholly/vscode/pull/36","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/goodgollyholly%2Fvscode/issues/36","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/36/packages"},{"uuid":"5089852722","node_id":"PR_kwDORgSK_878BLc4","number":41,"state":"closed","title":"chore(deps): bump undici from 7.28.0 to 7.29.0","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-08-07T16:42:41.000Z","author_association":null,"state_reason":null,"created_at":"2026-08-07T11:46:48.000Z","updated_at":"2026-08-07T16:42:50.000Z","time_to_close":17753,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"undici","old_version":"7.28.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 7.28.0 to 7.29.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=7.28.0\u0026new-version=7.29.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/NetAuraTech/adonisjs-foundry/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/NetAuraTech/adonisjs-foundry/pull/41","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/NetAuraTech%2Fadonisjs-foundry/issues/41","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/41/packages"},{"uuid":"5087482746","node_id":"PR_kwDOSPVWK8775iEI","number":368,"state":"closed","title":"deps-dev: Bump the dev-minor-patch group across 1 directory with 18 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-08-14T06:21:54.000Z","author_association":null,"state_reason":null,"created_at":"2026-08-07T06:21:35.000Z","updated_at":"2026-08-14T06:21:56.000Z","time_to_close":604819,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"deps-dev: Bump","group_name":"dev-minor-patch","update_count":18,"packages":[{"name":"@eslint/eslintrc","old_version":"3.3.5","new_version":"3.3.6","repository_url":"https://github.com/eslint/eslintrc"},{"name":"@playwright/test","old_version":"1.61.1","new_version":"1.62.1","repository_url":"https://github.com/microsoft/playwright"},{"name":"@tailwindcss/postcss","old_version":"4.3.2","new_version":"4.3.3","repository_url":"https://github.com/tailwindlabs/tailwindcss"},{"name":"@testing-library/user-event","old_version":"14.6.1","new_version":"14.6.3","repository_url":"https://github.com/testing-library/user-event"},{"name":"@types/node","old_version":"25.9.4","new_version":"25.9.5","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"@types/pg","old_version":"8.20.0","new_version":"8.20.3","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"@vitest/coverage-v8","old_version":"4.1.9","new_version":"4.1.10","repository_url":"https://github.com/vitest-dev/vitest"},{"name":"eslint-config-next","old_version":"16.2.10","new_version":"16.3.0","repository_url":"https://github.com/vercel/next.js"},{"name":"msw","old_version":"2.14.6","new_version":"2.15.0","repository_url":"https://github.com/mswjs/msw"},{"name":"postcss","old_version":"8.5.15","new_version":"8.5.25","repository_url":"https://github.com/postcss/postcss"},{"name":"prettier","old_version":"3.9.4","new_version":"3.9.6","repository_url":"https://github.com/prettier/prettier"},{"name":"prettier-plugin-tailwindcss","old_version":"0.8.0","new_version":"0.8.1","repository_url":"https://github.com/tailwindlabs/prettier-plugin-tailwindcss"},{"name":"tailwindcss","old_version":"4.3.2","new_version":"4.3.3","repository_url":"https://github.com/tailwindlabs/tailwindcss"},{"name":"tsx","old_version":"4.23.0","new_version":"4.23.5","repository_url":"https://github.com/privatenumber/tsx"},{"name":"typescript-eslint","old_version":"8.62.1","new_version":"8.66.0","repository_url":"https://github.com/typescript-eslint/typescript-eslint"},{"name":"undici","old_version":"8.7.0","new_version":"8.10.0","repository_url":"https://github.com/nodejs/undici"},{"name":"vite","old_version":"8.1.3","new_version":"8.2.0","repository_url":"https://github.com/vitejs/vite"},{"name":"vitest","old_version":"4.1.9","new_version":"4.1.10","repository_url":"https://github.com/vitest-dev/vitest"}],"path":null,"ecosystem":"npm"},"body":"Bumps the dev-minor-patch group with 18 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@eslint/eslintrc](https://github.com/eslint/eslintrc) | `3.3.5` | `3.3.6` |\n| [@playwright/test](https://github.com/microsoft/playwright) | `1.61.1` | `1.62.1` |\n| [@tailwindcss/postcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss) | `4.3.2` | `4.3.3` |\n| [@testing-library/user-event](https://github.com/testing-library/user-event) | `14.6.1` | `14.6.3` |\n| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `25.9.4` | `25.9.5` |\n| [@types/pg](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/pg) | `8.20.0` | `8.20.3` |\n| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `4.1.9` | `4.1.10` |\n| [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.2.10` | `16.3.0` |\n| [msw](https://github.com/mswjs/msw) | `2.14.6` | `2.15.0` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.15` | `8.5.25` |\n| [prettier](https://github.com/prettier/prettier) | `3.9.4` | `3.9.6` |\n| [prettier-plugin-tailwindcss](https://github.com/tailwindlabs/prettier-plugin-tailwindcss) | `0.8.0` | `0.8.1` |\n| [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) | `4.3.2` | `4.3.3` |\n| [tsx](https://github.com/privatenumber/tsx) | `4.23.0` | `4.23.5` |\n| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.62.1` | `8.66.0` |\n| [undici](https://github.com/nodejs/undici) | `8.7.0` | `8.10.0` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.1.3` | `8.2.0` |\n| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.9` | `4.1.10` |\n\n\nUpdates `@eslint/eslintrc` from 3.3.5 to 3.3.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eslint/eslintrc/releases\"\u003e@​eslint/eslintrc's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eeslintrc: v3.3.6\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.5...eslintrc-v3.3.6\"\u003e3.3.6\u003c/a\u003e (2026-07-10)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdate \u003ccode\u003ejs-yaml\u003c/code\u003e to 4.3.0 to address security vulnerability (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/235\"\u003e#235\u003c/a\u003e) (\u003ca href=\"https://github.com/eslint/eslintrc/commit/0c5de746dd98ac6904ee05ca594c50c5695e88bc\"\u003e0c5de74\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eslint/eslintrc/blob/main/CHANGELOG.md\"\u003e@​eslint/eslintrc's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.5...eslintrc-v3.3.6\"\u003e3.3.6\u003c/a\u003e (2026-07-10)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdate \u003ccode\u003ejs-yaml\u003c/code\u003e to 4.3.0 to address security vulnerability (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/235\"\u003e#235\u003c/a\u003e) (\u003ca href=\"https://github.com/eslint/eslintrc/commit/0c5de746dd98ac6904ee05ca594c50c5695e88bc\"\u003e0c5de74\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/b433a223f965b957ef3e3b8a21b77d6ac5b5d8d1\"\u003e\u003ccode\u003eb433a22\u003c/code\u003e\u003c/a\u003e chore: release 3.3.6 🚀 (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/236\"\u003e#236\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/0c5de746dd98ac6904ee05ca594c50c5695e88bc\"\u003e\u003ccode\u003e0c5de74\u003c/code\u003e\u003c/a\u003e fix: update \u003ccode\u003ejs-yaml\u003c/code\u003e to 4.3.0 to address security vulnerability (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/235\"\u003e#235\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/94837a4ae3ceb0d592d880b38280c4059b50ef78\"\u003e\u003ccode\u003e94837a4\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/dbae1a1449c05b38e50cf862e5851f415db42404\"\u003e\u003ccode\u003edbae1a1\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/19fe72a30f48d39bda5fa63f3dafc5106e4f3687\"\u003e\u003ccode\u003e19fe72a\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/92ebd174471b294fd52b4f8c8b786c0087a017eb\"\u003e\u003ccode\u003e92ebd17\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/3ba4c8c2cbe1e85eed14679e0b6a28ae7fde98b7\"\u003e\u003ccode\u003e3ba4c8c\u003c/code\u003e\u003c/a\u003e ci: add Node.js 26 to CI (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/231\"\u003e#231\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/f8d268a51a004668bb72d20d1706f4d4a4928c87\"\u003e\u003ccode\u003ef8d268a\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/6e20867b312094e53afa559dcad21ceeff6cac58\"\u003e\u003ccode\u003e6e20867\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/6d722b64e8331bbd663eeb4ec55a9c03679904b7\"\u003e\u003ccode\u003e6d722b6\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.5...eslintrc-v3.3.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@playwright/test` from 1.61.1 to 1.62.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/microsoft/playwright/releases\"\u003e@​playwright/test's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.62.1\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/41989\"\u003e#41989\u003c/a\u003e [Regression]: tsconfig \u0026quot;extends\u0026quot; bare specifier isn't resolved via node_modules walk-up like tsc (fatal since 1.62)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/41998\"\u003e#41998\u003c/a\u003e [Regression]: directory-form tsconfig project references (\u0026quot;path\u0026quot;: \u0026quot;../pkg\u0026quot;) fail to resolve (fatal since 1.62)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/41985\"\u003e#41985\u003c/a\u003e Accessibility snapshot drops button name when text is nested inside spans with aria-hidden SVG\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42000\"\u003e#42000\u003c/a\u003e [Regression]: page.evaluate() arg of a branded primitive type (string \u0026amp; { brand }) no longer type-checks since 1.62\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42013\"\u003e#42013\u003c/a\u003e [BUG]Image-type actionable elements are not presented in the snapshot.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.62.0\u003c/h2\u003e\n\u003ch2\u003e🧱 New component testing model\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://playwright.dev/docs/test-components\"\u003eComponent testing\u003c/a\u003e moves to a \u003cstrong\u003estories and galleries\u003c/strong\u003e model.\nA \u003cstrong\u003estory\u003c/strong\u003e wraps your component in one specific scenario — hard-coded props, mock data, providers — and a \u003cstrong\u003egallery\u003c/strong\u003e page that you serve renders stories on demand.\nThe new \u003ca href=\"https://playwright.dev/docs/api/class-fixtures#fixtures-mount\"\u003efixtures.mount()\u003c/a\u003e fixture navigates to the gallery, mounts a story by id, and returns a \u003ca href=\"https://playwright.dev/docs/api/class-locator\"\u003eLocator\u003c/a\u003e scoped to the story's root element:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003etest('click should expand', async ({ mount }) =\u0026gt; {\r\n  const component = await mount('components/Expandable/Stateful');\r\n  await component.getByRole('button').click();\r\n  await expect(component.getByTestId('expanded')).toHaveValue('true');\r\n});\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003ePass a story type as a template argument to type-check its props, and use \u003ccode\u003eupdate(props)\u003c/code\u003e / \u003ccode\u003eunmount()\u003c/code\u003e on the returned locator to re-render or tear down within a test.\u003c/p\u003e\n\u003ch2\u003e🛑 Cancel operations with AbortSignal\u003c/h2\u003e\n\u003cp\u003eMost operations and web-first assertions now accept a \u003ccode\u003esignal\u003c/code\u003e option that takes an \u003ca href=\"https://developer.mozilla.org/en-US/docs/Web/API/AbortSignal\"\u003e\u003ccode\u003eAbortSignal\u003c/code\u003e\u003c/a\u003e, letting you cancel long-running actions, navigations, waits, and assertions:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003econst controller = new AbortController();\r\nsetTimeout(() =\u0026gt; controller.abort(), 1000);\r\n\u003cp\u003eawait page.getByRole('button', { name: 'Submit' }).click({ signal: controller.signal });\nawait expect(page.getByText('Done')).toBeVisible({ signal: controller.signal });\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eProviding a signal does not disable the default timeout; pass \u003ccode\u003etimeout: 0\u003c/code\u003e to disable it.\u003c/p\u003e\n\u003ch2\u003e🖼️ WebP screenshots\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://playwright.dev/docs/api/class-pageassertions#page-assertions-to-have-screenshot-1\"\u003eexpect(page).toHaveScreenshot()\u003c/a\u003e and \u003ca href=\"https://playwright.dev/docs/api/class-locatorassertions#locator-assertions-to-have-screenshot-1\"\u003eexpect(locator).toHaveScreenshot()\u003c/a\u003e can now store snapshots in the WebP format — just give the snapshot a \u003ccode\u003e.webp\u003c/code\u003e name:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Visual comparisons store the golden snapshot as lossless WebP.\r\nawait expect(page).toHaveScreenshot('homepage.webp');\r\n\u003cp\u003e// Standalone screenshots can trade quality for size with lossy WebP.\nawait page.screenshot({ path: 'homepage.webp', quality: 50 });\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt;\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/26a9e470a7b3c7822084b09fb7f13902c5f37b51\"\u003e\u003ccode\u003e26a9e47\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42043\"\u003e#42043\u003c/a\u003e): docs: release notes for v1.62 Python, Java, and .NET (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/4\"\u003e#4\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/0a81d5d09b10eeefe228fe745c3f80c7368a239b\"\u003e\u003ccode\u003e0a81d5d\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42040\"\u003e#42040\u003c/a\u003e): docs(release-notes): mention the isolated headless clipb...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/83768264e64a821bcef9e634b8e5c33897f2b032\"\u003e\u003ccode\u003e8376826\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42034\"\u003e#42034\u003c/a\u003e): fix(aria): keep icon-only clickable elements in ai snaps...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/66c5cc92a60ce20ab3abe779339e1f90d2e2e888\"\u003e\u003ccode\u003e66c5cc9\u003c/code\u003e\u003c/a\u003e chore: mark v1.62.1 (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42020\"\u003e#42020\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/9672bc3f2a7098cb6a9791ca97222187363a3037\"\u003e\u003ccode\u003e9672bc3\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42009\"\u003e#42009\u003c/a\u003e): fix(types): support branded primitives in evaluate argum...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/4325804427a214aa0c8c39bb1352f4ac4f712fd1\"\u003e\u003ccode\u003e4325804\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/41988\"\u003e#41988\u003c/a\u003e): fix(aria): preserve names from collapsed text contributors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/9632f8ecbc2accba140ea342f1070ccfdd5f5d41\"\u003e\u003ccode\u003e9632f8e\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42005\"\u003e#42005\u003c/a\u003e): fix(tsconfig): do not throw when \u0026quot;extends\u0026quot;/\u0026quot;references\u0026quot; ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/e3950d9c140d007bd52853b45813c6274b24e36f\"\u003e\u003ccode\u003ee3950d9\u003c/code\u003e\u003c/a\u003e chore: mark v1.62.0 (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/41981\"\u003e#41981\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/f07e0f720fbe6691cc3d3d66ff9f3e58139e804c\"\u003e\u003ccode\u003ef07e0f7\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/41940\"\u003e#41940\u003c/a\u003e): docs: release notes for v1.62 (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/41967\"\u003e#41967\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/05a306c78f11767535fd986eebab5d4c4dad4614\"\u003e\u003ccode\u003e05a306c\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/41964\"\u003e#41964\u003c/a\u003e): Revert \u0026quot;feat(routeFromHar): add interceptAPIRequests opt...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/microsoft/playwright/compare/v1.61.1...v1.62.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@tailwindcss/postcss` from 4.3.2 to 4.3.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/tailwindcss/releases\"\u003e@​tailwindcss/postcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.3.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003e--watch --poll[=ms]\u003c/code\u003e in \u003ccode\u003e@tailwindcss/cli\u003c/code\u003e when filesystem events are unreliable or unavailable (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20297\"\u003e#20297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCanonicalization: match arbitrary hex colors against theme colors case-insensitively (e.g. \u003ccode\u003ebg-[#fff]\u003c/code\u003e and \u003ccode\u003ebg-[#FFF]\u003c/code\u003e → \u003ccode\u003ebg-white\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20298\"\u003e#20298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent Preflight from overriding Firefox's native \u003ccode\u003eiframe:focus-visible\u003c/code\u003e outline styles (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20292\"\u003e#20292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003etheme('colors.foo')\u003c/code\u003e in JS plugins resolves correctly when both \u003ccode\u003e--color-foo\u003c/code\u003e and \u003ccode\u003e--color-foo-bar\u003c/code\u003e exist (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20299\"\u003e#20299\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure fractional opacity modifiers work with named shadow sizes like \u003ccode\u003eshadow-sm/12.5\u003c/code\u003e, \u003ccode\u003etext-shadow-sm/12.5\u003c/code\u003e, \u003ccode\u003edrop-shadow-sm/12.5\u003c/code\u003e, and \u003ccode\u003einset-shadow-sm/12.5\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20302\"\u003e#20302\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eParse selectors like \u003ccode\u003e[data-foo]div\u003c/code\u003e as two selectors instead of one (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20303\"\u003e#20303\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e@tailwindcss/postcss\u003c/code\u003e rebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20310\"\u003e#20310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure CSS nesting is handled even when Lightning CSS isn't run, such as in \u003ccode\u003e@tailwindcss/browser\u003c/code\u003e and Tailwind Play (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20124\"\u003e#20124\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent achromatic theme colors from shifting hue when mixed in polar color spaces like \u003ccode\u003eoklch\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20314\"\u003e#20314\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e--spacing(0)\u003c/code\u003e is optimized to \u003ccode\u003e0px\u003c/code\u003e instead of \u003ccode\u003e0\u003c/code\u003e so it remains a \u003ccode\u003e\u0026lt;length\u0026gt;\u003c/code\u003e when used in \u003ccode\u003ecalc(…)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20319\"\u003e#20319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eLoad \u003ccode\u003e@parcel/watcher\u003c/code\u003e only when needed in \u003ccode\u003e@tailwindcss/cli --watch\u003c/code\u003e mode, so one-off builds and \u003ccode\u003e--watch --poll\u003c/code\u003e work when \u003ccode\u003e@parcel/watcher\u003c/code\u003e can't be loaded (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20325\"\u003e#20325\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUse explicit platform fonts instead of \u003ccode\u003esystem-ui\u003c/code\u003e and \u003ccode\u003eui-sans-serif\u003c/code\u003e so CJK text respects the page's \u003ccode\u003elang\u003c/code\u003e attribute on Windows (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20318\"\u003e#20318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent \u003ccode\u003e@tailwindcss/upgrade\u003c/code\u003e from rewriting ignored files when run from a subdirectory (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20329\"\u003e#20329\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure earlier \u003ccode\u003e@source\u003c/code\u003e rules pointing to nested files are scanned when later \u003ccode\u003e@source\u003c/code\u003e rules point to files in parent folders (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20335\"\u003e#20335\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent \u003ccode\u003e@tailwindcss/vite\u003c/code\u003e from triggering full page reloads when scanned files are processed by Vite but haven't been loaded as modules yet (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20336\"\u003e#20336\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md\"\u003e@​tailwindcss/postcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[4.3.3] - 2026-07-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003e--watch --poll[=ms]\u003c/code\u003e in \u003ccode\u003e@tailwindcss/cli\u003c/code\u003e when filesystem events are unreliable or unavailable (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20297\"\u003e#20297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCanonicalization: match arbitrary hex colors against theme colors case-insensitively (e.g. \u003ccode\u003ebg-[#fff]\u003c/code\u003e and \u003ccode\u003ebg-[#FFF]\u003c/code\u003e → \u003ccode\u003ebg-white\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20298\"\u003e#20298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent Preflight from overriding Firefox's native \u003ccode\u003eiframe:focus-visible\u003c/code\u003e outline styles (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20292\"\u003e#20292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003etheme('colors.foo')\u003c/code\u003e in JS plugins resolves correctly when both \u003ccode\u003e--color-foo\u003c/code\u003e and \u003ccode\u003e--color-foo-bar\u003c/code\u003e exist (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20299\"\u003e#20299\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure fractional opacity modifiers work with named shadow sizes like \u003ccode\u003eshadow-sm/12.5\u003c/code\u003e, \u003ccode\u003etext-shadow-sm/12.5\u003c/code\u003e, \u003ccode\u003edrop-shadow-sm/12.5\u003c/code\u003e, and \u003ccode\u003einset-shadow-sm/12.5\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20302\"\u003e#20302\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eParse selectors like \u003ccode\u003e[data-foo]div\u003c/code\u003e as two selectors instead of one (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20303\"\u003e#20303\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e@tailwindcss/postcss\u003c/code\u003e rebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20310\"\u003e#20310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure CSS nesting is handled even when Lightning CSS isn't run, such as in \u003ccode\u003e@tailwindcss/browser\u003c/code\u003e and Tailwind Play (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20124\"\u003e#20124\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent achromatic theme colors from shifting hue when mixed in polar color spaces like \u003ccode\u003eoklch\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20314\"\u003e#20314\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e--spacing(0)\u003c/code\u003e is optimized to \u003ccode\u003e0px\u003c/code\u003e instead of \u003ccode\u003e0\u003c/code\u003e so it remains a \u003ccode\u003e\u0026lt;length\u0026gt;\u003c/code\u003e when used in \u003ccode\u003ecalc(…)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20319\"\u003e#20319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eLoad \u003ccode\u003e@parcel/watcher\u003c/code\u003e only when needed in \u003ccode\u003e@tailwindcss/cli --watch\u003c/code\u003e mode, so one-off builds and \u003ccode\u003e--watch --poll\u003c/code\u003e work when \u003ccode\u003e@parcel/watcher\u003c/code\u003e can't be loaded (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20325\"\u003e#20325\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUse explicit platform fonts instead of \u003ccode\u003esystem-ui\u003c/code\u003e and \u003ccode\u003eui-sans-serif\u003c/code\u003e so CJK text respects the page's \u003ccode\u003elang\u003c/code\u003e attribute on Windows (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20318\"\u003e#20318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent \u003ccode\u003e@tailwindcss/upgrade\u003c/code\u003e from rewriting ignored files when run from a subdirectory (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20329\"\u003e#20329\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure earlier \u003ccode\u003e@source\u003c/code\u003e rules pointing to nested files are scanned when later \u003ccode\u003e@source\u003c/code\u003e rules point to files in parent folders (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20335\"\u003e#20335\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent \u003ccode\u003e@tailwindcss/vite\u003c/code\u003e from triggering full page reloads when scanned files are processed by Vite but haven't been loaded as modules yet (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20336\"\u003e#20336\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss/commit/c2b24dd15fed1c59dd521bd86082f520c9f5ad0d\"\u003e\u003ccode\u003ec2b24dd\u003c/code\u003e\u003c/a\u003e 4.3.3 (\u003ca href=\"https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss/issues/20334\"\u003e#20334\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss/commit/e48c5e80473c25fe5a27fe267fbaf4f6512424a3\"\u003e\u003ccode\u003ee48c5e8\u003c/code\u003e\u003c/a\u003e Fix weird character rendering on Windows with Japanese locale (\u003ca href=\"https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss/issues/20318\"\u003e#20318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss/commit/9b0e8af25861ad5b8f5af420ad3ee0b188665027\"\u003e\u003ccode\u003e9b0e8af\u003c/code\u003e\u003c/a\u003e Ensure \u003ccode\u003e@tailwindcss/postcss\u003c/code\u003e rebuilds when the input CSS changes but its mti...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss/commit/b53fa096c92d830fc64b7cf69581496242583446\"\u003e\u003ccode\u003eb53fa09\u003c/code\u003e\u003c/a\u003e fix: exclude iframes from focus-visible auto outline in Preflight (\u003ca href=\"https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss/issues/20292\"\u003e#20292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/tailwindlabs/tailwindcss/commits/v4.3.3/packages/@tailwindcss-postcss\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@testing-library/user-event` from 14.6.1 to 14.6.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/testing-library/user-event/releases\"\u003e@​testing-library/user-event's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev14.6.3\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/testing-library/user-event/compare/v14.6.2...v14.6.3\"\u003e14.6.3\u003c/a\u003e (2026-08-03)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003erelease:\u003c/strong\u003e manually release a patch version (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1321\"\u003e#1321\u003c/a\u003e) (\u003ca href=\"https://github.com/testing-library/user-event/commit/1d18b1fae589eeed8e08838672a4c2de0dcc2b36\"\u003e1d18b1f\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1317\"\u003e#1317\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev14.6.2\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/testing-library/user-event/compare/v14.6.1...v14.6.2\"\u003e14.6.2\u003c/a\u003e (2026-08-03)\u003c/h2\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/1d18b1fae589eeed8e08838672a4c2de0dcc2b36\"\u003e\u003ccode\u003e1d18b1f\u003c/code\u003e\u003c/a\u003e fix(release): manually release a patch version (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1321\"\u003e#1321\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/232f3e6f4f92459c02161d156a70bddd13a59eaa\"\u003e\u003ccode\u003e232f3e6\u003c/code\u003e\u003c/a\u003e docs: add migration note and clean up README badges (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1320\"\u003e#1320\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/83e2b2261b40f5f08296eaf5af3d42018e6681ed\"\u003e\u003ccode\u003e83e2b22\u003c/code\u003e\u003c/a\u003e ci: remove deprecated CodeSandbox CI (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1318\"\u003e#1318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/e8da81953bd9b48512a1e4ce9b73cc36aeaeee37\"\u003e\u003ccode\u003ee8da819\u003c/code\u003e\u003c/a\u003e ci: publish to npm via OIDC trusted publishing (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1317\"\u003e#1317\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/13fa4bc1f0dedeb866a8730fa357229832437418\"\u003e\u003ccode\u003e13fa4bc\u003c/code\u003e\u003c/a\u003e ci: stop lint errors from blocking release (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1316\"\u003e#1316\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/c3cec1832f180b6d1dcb7c5d2b0771339dd5e848\"\u003e\u003ccode\u003ec3cec18\u003c/code\u003e\u003c/a\u003e chore(ci): make releases work with full git history (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1315\"\u003e#1315\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/ebab6c6e81e7022af7afa5aacd07d01626895eb8\"\u003e\u003ccode\u003eebab6c6\u003c/code\u003e\u003c/a\u003e add Liadshiran as a contributor for doc (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1300\"\u003e#1300\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/ec470bfd55ab7a741ce2a5b71e98c0f5686ac915\"\u003e\u003ccode\u003eec470bf\u003c/code\u003e\u003c/a\u003e docs: fix wrong default enum value (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1298\"\u003e#1298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/ba79c2f9a58d5927725fee506210d279fde218b5\"\u003e\u003ccode\u003eba79c2f\u003c/code\u003e\u003c/a\u003e chore: upgrade node version in csb (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1299\"\u003e#1299\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/63ac399e06bd8f2397a6c581915acd29235f2d38\"\u003e\u003ccode\u003e63ac399\u003c/code\u003e\u003c/a\u003e fix: allow reassignment of  \u003ccode\u003eHTMLElement.prototype.focus\u003c/code\u003e and \u003ccode\u003e.blur\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/testing-library/user-event/compare/v14.6.1...v14.6.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​testing-library/user-event\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@types/node` from 25.9.4 to 25.9.5\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@types/pg` from 8.20.0 to 8.20.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/pg\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@vitest/coverage-v8` from 4.1.9 to 4.1.10\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitest-dev/vitest/releases\"\u003e@​vitest/coverage-v8's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.1.10\u003c/h2\u003e\n\u003ch3\u003e   🐞 Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebrowser\u003c/strong\u003e: Check fs access in builtin commands [backport to v4]  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eHiroshi Ogawa\u003c/strong\u003e and \u003cstrong\u003eOpenCode (claude-opus-4-8)\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10680\"\u003evitest-dev/vitest#10680\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/5c18dd267\"\u003e\u003c!-- raw HTML omitted --\u003e(5c18d)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003evm\u003c/strong\u003e: Fix external module resolve error with deps optimizer query for encoded URI [backport to v4]  -  by \u003ca href=\"https://github.com/SveLil\"\u003e\u003ccode\u003e@​SveLil\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10661\"\u003evitest-dev/vitest#10661\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/bae52b511\"\u003e\u003c!-- raw HTML omitted --\u003e(bae52)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch5\u003e    \u003ca href=\"https://github.com/vitest-dev/vitest/compare/v4.1.9...v4.1.10\"\u003eView changes on GitHub\u003c/a\u003e\u003c/h5\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/db616d227b6e0cb07a94f5d1bba262ee95db7e46\"\u003e\u003ccode\u003edb616d2\u003c/code\u003e\u003c/a\u003e chore: release v4.1.10 (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/10718\"\u003e#10718\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/coverage-v8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eslint-config-next` from 16.2.10 to 16.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003eeslint-config-next's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.0\u003c/h2\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate vendored lodash to 4.17.23 to fix CVE-2025-13465: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91558\"\u003e#91558\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix invalid HTML response for route-level RSC requests in deployment adapter: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91541\"\u003e#91541\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eNormalize encoded dynamic placeholders in app routes: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91603\"\u003e#91603\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix(pages-router): restore Content-Length and ETag for /_next/data/ JSON responses: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/90304\"\u003e#90304\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate tokio from 1.43.0 to 1.47.3: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/90945\"\u003e#90945\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[turbopack] Simplify snapshotting logic: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91178\"\u003e#91178\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: enable server HMR for app route handlers: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91466\"\u003e#91466\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eturbo-tasks-backend: batch find_and_schedule_dirty using for_each_task_meta: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91497\"\u003e#91497\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[turbopack] Use bail! instead of panic! for duplicate module ident error: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91636\"\u003e#91636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSkip loadBindings() Lightning CSS check during next start: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91538\"\u003e#91538\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eturbo-tasks-backend: batch schedule dirty tasks in aggregation_update: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91461\"\u003e#91461\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: Add importModule() support to webpack loaders: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/89630\"\u003e#89630\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eturbo-persistence: fix mmap page alignment and improve error context in MetaFile::open_internal: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91640\"\u003e#91640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eturbopack-css: demote recoverable CSS parse warnings to Warning severity: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91524\"\u003e#91524\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(node-streams): add config flag, define-env, and env precedence test: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/90427\"\u003e#90427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRename /_next/webpack-hmr to /_next/hmr: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91415\"\u003e#91415\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd per-slot error attribution for instant validation using slot markers and config depth preference: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91610\"\u003e#91610\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHandle encoded params further: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91627\"\u003e#91627\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[turbopack] Respect \u003ccode\u003e{eval:true}\u003c/code\u003e in worker_threads constructors: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91666\"\u003e#91666\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing route in otel spans without base-server: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91665\"\u003e#91665\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[turbopack] Optimize compaction cpu usage: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91468\"\u003e#91468\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix layout segment optimization: move app-page imports to server-utility transition: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91701\"\u003e#91701\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix server actions in standalone mode with \u003ccode\u003ecacheComponents\u003c/code\u003e: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91711\"\u003e#91711\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eturbo-persistence: remove Unmergeable mmap advice: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91713\"\u003e#91713\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eturbopack: move \u0026quot;compact database\u0026quot; tracing span to backend layer: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91693\"\u003e#91693\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: lazy require metadata and handle TLA: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91705\"\u003e#91705\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix adapter outputs for dynamic metadata routes: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91680\"\u003e#91680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: fix webpack loader runner layer: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91727\"\u003e#91727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[turbopack] Remove incorrect debug_assert in try_read_task_cell: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91699\"\u003e#91699\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd module count field to module graph tracing spans: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91697\"\u003e#91697\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eturbopack-cli: add --persistent-caching flag for filesystem-backed cache: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91657\"\u003e#91657\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: pull in updated vercel/nft tests: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91651\"\u003e#91651\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[turbopack] Improve regressed build speed on cross-compiled MUSL: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91477\"\u003e#91477\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Segment Bundling] [Scaffolding] Ensure inlining hint correctness: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91320\"\u003e#91320\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Segment Bundling] [Scaffolding] Track which segments can be omitted from prefetch: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91438\"\u003e#91438\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid deprecated TS node10 moduleResolution defaults: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91847\"\u003e#91847\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[turbopack] Rebuild the docker build scripts: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91799\"\u003e#91799\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix TS6 baseUrl deprecation for extended tsconfig: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91855\"\u003e#91855\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003enext internal post-build\u003c/code\u003e CLI command for Turbopack database compaction: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91336\"\u003e#91336\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: Define \u003ccode\u003eEffect\u003c/code\u003e as a trait instead of a closure: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/89080\"\u003e#89080\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: Implement TraceRawVcs and NonLocalValue correctly for Effects: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/89133\"\u003e#89133\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eturbo-tasks-backend: improve print_cache_item_size instrumentation: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91742\"\u003e#91742\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: switch from base40 to base38 hash encoding (remove ~ and . from charset): \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91832\"\u003e#91832\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse charCodeAt for normalizePathTrailingSlash: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91380\"\u003e#91380\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: Only patch lockfile when bindings fails to load: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91379\"\u003e#91379\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[create-next-app] Skip interactive prompts when CLI flags are provided: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91840\"\u003e#91840\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[devtools] Make instant navs panel draggable: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91914\"\u003e#91914\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Segment Bundling] Bundle static prefetches based on size: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91439\"\u003e#91439\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d73f5622e226358dcef8cf7a8a373333ff265ae7\"\u003e\u003ccode\u003ed73f562\u003c/code\u003e\u003c/a\u003e v16.3.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/4fd843fb488f770c5b2023ddc58ff4be4ee81f14\"\u003e\u003ccode\u003e4fd843f\u003c/code\u003e\u003c/a\u003e v16.3.0-canary.107\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/9480f7f9ffdc271014d959e7b10d681882eaabb5\"\u003e\u003ccode\u003e9480f7f\u003c/code\u003e\u003c/a\u003e v16.3.0-canary.106\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/a8dcd2562f0bde39380d48507ec3fffd86c21e53\"\u003e\u003ccode\u003ea8dcd25\u003c/code\u003e\u003c/a\u003e v16.3.0-canary.105\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/38f0cdee4659b1b8f987bc46e3f1aacd12ee5c90\"\u003e\u003ccode\u003e38f0cde\u003c/code\u003e\u003c/a\u003e v16.3.0-canary.104\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/f3edea1b06730ce507aeb1b10c8e4f652ca5540d\"\u003e\u003ccode\u003ef3edea1\u003c/code\u003e\u003c/a\u003e v16.3.0-canary.103\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/0d5ff0d321424b1f1c55b4466406ddee213d11c7\"\u003e\u003ccode\u003e0d5ff0d\u003c/code\u003e\u003c/a\u003e v16.3.0-canary.102\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/cf1e001f40b311f5a4f19775ec9ea4f1d8bdece9\"\u003e\u003ccode\u003ecf1e001\u003c/code\u003e\u003c/a\u003e v16.3.0-canary.101\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/267d6b1a17fb4b4b03860c4677e6eeefa65ba2b8\"\u003e\u003ccode\u003e267d6b1\u003c/code\u003e\u003c/a\u003e v16.3.0-canary.100\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/ad618bf13fbc4be57d6b6136a20547af50708eb2\"\u003e\u003ccode\u003ead618bf\u003c/code\u003e\u003c/a\u003e Restore canary version 16.3.0-canary.99 after v16.3.0-preview.10 preview release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/commits/v16.3.0/packages/eslint-config-next\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `msw` from 2.14.6 to 2.15.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mswjs/msw/releases\"\u003emsw's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.15.0 (2026-07-08)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003esse:\u003c/strong\u003e invoke \u003ccode\u003efinalize\u003c/code\u003e on response stream end (\u003ca href=\"https://redirect.github.com/mswjs/msw/issues/2741\"\u003e#2741\u003c/a\u003e) (7fae0cc0954b20c739ae8e95a24eefc8a78710e8) \u003ca href=\"https://github.com/kettanaito\"\u003e\u003ccode\u003e@​kettanaito\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.14.7 (2026-07-07)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003esse:\u003c/strong\u003e proper logging for concurrent requests (\u003ca href=\"https://redirect.github.com/mswjs/msw/issues/2762\"\u003e#2762\u003c/a\u003e) (5c0ae1c334a0cbe52638bd2949540372be3d46ba) \u003ca href=\"https://github.com/kettanaito\"\u003e\u003ccode\u003e@​kettanaito\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/49d9d47f613b072f8d20e1a025feaee7c5382b2b\"\u003e\u003ccode\u003e49d9d47\u003c/code\u003e\u003c/a\u003e chore(release): v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/ed885831bf90136044d305e1ae1035fb13491cec\"\u003e\u003ccode\u003eed88583\u003c/code\u003e\u003c/a\u003e test(finalize): use \u003ccode\u003eexpect.poll\u003c/code\u003e vs \u003ccode\u003ewaitFor\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/7fae0cc0954b20c739ae8e95a24eefc8a78710e8\"\u003e\u003ccode\u003e7fae0cc\u003c/code\u003e\u003c/a\u003e feat(sse): invoke \u003ccode\u003efinalize\u003c/code\u003e on response stream end (\u003ca href=\"https://redirect.github.com/mswjs/msw/issues/2741\"\u003e#2741\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/db818ee6c943bcfad18f6ecff2bb0dc210c457ca\"\u003e\u003ccode\u003edb818ee\u003c/code\u003e\u003c/a\u003e chore(release): v2.14.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/418854a04a1424eef25a7722e1016feea433a5a9\"\u003e\u003ccode\u003e418854a\u003c/code\u003e\u003c/a\u003e chore: upgrade \u003ccode\u003e@ossjs/release\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/5c0ae1c334a0cbe52638bd2949540372be3d46ba\"\u003e\u003ccode\u003e5c0ae1c\u003c/code\u003e\u003c/a\u003e fix(sse): proper logging for concurrent requests (\u003ca href=\"https://redirect.github.com/mswjs/msw/issues/2762\"\u003e#2762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/3016bda37757420b1c5adca9a3956f0dc8654456\"\u003e\u003ccode\u003e3016bda\u003c/code\u003e\u003c/a\u003e test: fix flaky \u003ccode\u003ews.clients.browser.test.ts\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/0df6d6a06fd99bb7066ee12457966c69f329fd38\"\u003e\u003ccode\u003e0df6d6a\u003c/code\u003e\u003c/a\u003e test: fix flaky \u003ccode\u003ein-flight-request.test.ts\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/ff6836b19cf250cfe0be721bfdf098a14c23506a\"\u003e\u003ccode\u003eff6836b\u003c/code\u003e\u003c/a\u003e chore: pin github actions to commit sha, update pnpm (\u003ca href=\"https://redirect.github.com/mswjs/msw/issues/2761\"\u003e#2761\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/8a19d5485adad2b8a816e04a937f4c76169cd5b9\"\u003e\u003ccode\u003e8a19d54\u003c/code\u003e\u003c/a\u003e chore: improve github actions security (\u003ca href=\"https://redirect.github.com/mswjs/msw/issues/2747\"\u003e#2747\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mswjs/msw/compare/v2.14.6...v2.15.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.15 to 8.5.25\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/08c989c43cc87edb1ed71408c2f5164c54fc21df\"\u003e\u003ccode\u003e08c989c\u003c/code\u003e\u003c/a\u003e Release 8.5.25 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/24f681471645cd960ee760ab7f9e348fbabfd42c\"\u003e\u003ccode\u003e24f6814\u003c/code\u003e\u003c/a\u003e Fix 8.5.17 visitor regression\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f2fa53f11daab3a16c7eb8bcaf5a945142341df3\"\u003e\u003ccode\u003ef2fa53f\u003c/code\u003e\u003c/a\u003e Add supply chain security requirement to PostCSS plugin guide\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/10edf0b0606f97b1510e040c27bfd078c48d6ea7\"\u003e\u003ccode\u003e10edf0b\u003c/code\u003e\u003c/a\u003e fix: return empty array for empty string in list.split (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2121\"\u003e#2121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/0ebe8ad591621ab4e48311da47a76974617571f9\"\u003e\u003ccode\u003e0ebe8ad\u003c/code\u003e\u003c/a\u003e Release 8.5.24 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/73218c64245be53e25d58150e0cc7e984f1d162d\"\u003e\u003ccode\u003e73218c6\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9a114f62b0deb37be859102f93b414b49385805a\"\u003e\u003ccode\u003e9a114f6\u003c/code\u003e\u003c/a\u003e Preserve the BOM when stringifying (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2119\"\u003e#2119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/90692619125cb9424f5eafd8c64bc76b2da23db1\"\u003e\u003ccode\u003e9069261\u003c/code\u003e\u003c/a\u003e Fix types check\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.15...8.5.25\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `prettier` from 3.9.4 to 3.9.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/prettier/prettier/releases\"\u003eprettier's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.9.6\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve quotes for methods named \u003ccode\u003enew\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19621\"\u003eprettier/prettier#19621\u003c/a\u003e by \u003ca href=\"https://github.com/kovsu\"\u003e\u003ccode\u003e@​kovsu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSupport \u003ccode\u003eimport defer\u003c/code\u003e in \u003ccode\u003etypescript\u003c/code\u003e parser (\u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19624\"\u003eprettier/prettier#19624\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19675\"\u003eprettier/prettier#19675\u003c/a\u003e by \u003ca href=\"https://github.com/fisker\"\u003e\u003ccode\u003e@​fisker\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdded a new official plugin \u003ca href=\"https://github.com/prettier/prettier/tree/3.9.6/packages/plugin-yuku\"\u003e\u003ccode\u003e@prettier/plugin-yuku\u003c/code\u003e 🚀\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19628\"\u003eprettier/prettier#19628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19629\"\u003eprettier/prettier#19629\u003c/a\u003e by \u003ca href=\"https://github.com/fisker\"\u003e\u003ccode\u003e@​fisker\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e🔗 \u003ca href=\"https://github.com/prettier/prettier/blob/3.9.6/CHANGELOG.md#396\"\u003eChangelog\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.9.5\u003c/h2\u003e\n\u003cp\u003e🔗 \u003ca href=\"https://github.com/prettier/prettier/blob/3.9.5/CHANGELOG.md#395\"\u003eChangelog\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/prettier/prettier/blob/main/CHANGELOG.md\"\u003eprettier's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e3.9.6\u003c/h1\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/prettier/prettier/compare/3.9.5...3.9.6\"\u003ediff\u003c/a\u003e\u003c/p\u003e\n\u003ch4\u003eTypeScript: Preserve quotes for methods named \u003ccode\u003enew\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19621\"\u003e#19621\u003c/a\u003e by \u003ca href=\"https://github.com/kovsu\"\u003e\u003ccode\u003e@​kovsu\u003c/code\u003e\u003c/a\u003e)\u003c/h4\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cpre lang=\"tsx\"\u003e\u003ccode\u003e// Input\ninterface Container {\n  \u0026quot;new\u0026quot;(id: string): number;\n}\n\u003cp\u003e// Prettier 3.9.5\u003cbr /\u003e\ninterface Container {\u003cbr /\u003e\nnew(id: string): number;\u003cbr /\u003e\n}\u003c/p\u003e\n\u003cp\u003e// Prettier 3.9.6\u003cbr /\u003e\ninterface Container {\u003cbr /\u003e\n\u0026quot;new\u0026quot;(id: string): number;\u003cbr /\u003e\n}\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003ch4\u003eTypeScript: Support \u003ccode\u003eimport defer\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19624\"\u003e#19624\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19675\"\u003e#19675\u003c/a\u003e by \u003ca href=\"https://github.com/fisker\"\u003e\u003ccode\u003e@​fisker\u003c/code\u003e\u003c/a\u003e)\u003c/h4\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cpre lang=\"tsx\"\u003e\u003ccode\u003e// Input\nimport defer * as foo from \u0026quot;foo\u0026quot;;\n\u003cp\u003e// Prettier 3.9.5\u003cbr /\u003e\nimport * as foo from \u0026quot;foo\u0026quot;;\u003c/p\u003e\n\u003cp\u003e// Prettier 3.9.6\u003cbr /\u003e\nimport defer * as foo from \u0026quot;foo\u0026quot;;\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003ch4\u003eJavaScript: Added a new official plugin \u003ccode\u003e@prettier/plugin-yuku\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19628\"\u003e#19628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19629\"\u003e#19629\u003c/a\u003e by \u003ca href=\"https://github.com/fisker\"\u003e\u003ccode\u003e@​fisker\u003c/code\u003e\u003c/a\u003e)\u003c/h4\u003e\n\u003cp\u003e\u003ccode\u003e@prettier/plugin-yuku\u003c/code\u003e is powered by \u003ca href=\"https://yuku.fyi/\"\u003eYuku\u003c/a\u003e (A high-performance JavaScript/TypeScript compiler toolchain written in Zig).\u003c/p\u003e\n\u003cp\u003eThis plugin includes two new parsers: \u003ccode\u003eyuku\u003c/code\u003e (JavaScript syntax) and \u003ccode\u003eyuku-ts\u003c/code\u003e (TypeScript syntax).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eTo use this plugin:\u003c/strong\u003e\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003e\n\u003cp\u003eInstall the plugin:\u003c/p\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003eyarn add --dev prettier @prettier/plugin-yuku\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/8f0c95057cc91d5836409466cd9d9af3bb901e84\"\u003e\u003ccode\u003e8f0c950\u003c/code\u003e\u003c/a\u003e Release 3.9.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/e9107647d0497d8ff1cacbb0f970d4543df77c1c\"\u003e\u003ccode\u003ee910764\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/ec3f1c7bd74495992bc6954323a1a7fc8368808e\"\u003e\u003ccode\u003eec3f1c7\u003c/code\u003e\u003c/a\u003e Update typescript-eslint to v8.65.0 (\u003ca href=\"https://redirect.github.com/prettier/prettier/issues/19675\"\u003e#19675\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/73d2efc2c6cba6f579585c88ef171132d90834ec\"\u003e\u003ccode\u003e73d2efc\u003c/code\u003e\u003c/a\u003e Update Yuku parser to v0.7.0 (\u003ca href=\"https://redirect.github.com/prettier/prettier/issues/19664\"\u003e#19664\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/dd5e24eabeab1f75ad573c79781e5fd408bcfad3\"\u003e\u003ccode\u003edd5e24e\u003c/code\u003e\u003c/a\u003e Preserve quotes for \u003ccode\u003eTSMethodSignature\u003c/code\u003e nodes named \u003ccode\u003enew\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/prettier/prettier/issues/19621\"\u003e#19621\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/c03ab4e71c23154d6b11537eee3c938f0d0f67d3\"\u003e\u003ccode\u003ec03ab4e\u003c/code\u003e\u003c/a\u003e Update dependency eslint-plugin-unicorn to v72 (\u003ca href=\"https://redirect.github.com/prettier/prettier/issues/19633\"\u003e#19633\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/b74dd53076c7208291a6b2e585c310844b41d35f\"\u003e\u003ccode\u003eb74dd53\u003c/code\u003e\u003c/a\u003e Update Yuku parser to v0.6.5 (\u003ca href=\"https://redirect.github.com/prettier/prettier/issues/19654\"\u003e#19654\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/f1b594ea1db1520c383d0e281d623551f671f824\"\u003e\u003ccode\u003ef1b594e\u003c/code\u003e\u003c/a\u003e Update dependency eslint-plugin-simple-import-sort to v14 (\u003ca href=\"https://redirect.github.com/prettier/prettier/issues/19655\"\u003e#19655\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/0d9dfb61530986373000dd107ea58ceebb79e233\"\u003e\u003ccode\u003e0d9dfb6\u003c/code\u003e\u003c/a\u003e Update Yuku parser to v0.6.4 (\u003ca href=\"https://redirect.github.com/prettier/prettier/issues/19650\"\u003e#19650\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/3bbb8159eb55575d4042653aa99f5f92a1416c19\"\u003e\u003ccode\u003e3bbb815\u003c/code\u003e\u003c/a\u003e Remove \u003ccode\u003etypescript-only\u003c/code\u003e directory (\u003ca href=\"https://redirect.github.com/prettier/prettier/issues/19636\"\u003e#19636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/prettier/prettier/compare/3.9.4...3.9.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `prettier-plugin-tailwindcss` from 0.8.0 to 0.8.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/prettier-plugin-tailwindcss/releases\"\u003eprettier-plugin-tailwindcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.8.1\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDon't remove escape sequences when sorting classes in JavaScript string literals, which could produce invalid code in Vue attribute expressions (\u003ca href=\"https://redirect.github.com/tailwindlabs/prettier-plugin-tailwindcss/pull/461\"\u003e#461\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRestore class sorting in Svelte markup and dynamic \u003ccode\u003eclass={...}\u003c/code\u003e expressions when using \u003ccode\u003eprettier-plugin-svelte\u003c/code\u003e v4 (\u003ca href=\"https://redirect.github.com/tailwindlabs/prettier-plugin-tailwindcss/pull/462\"\u003e#462\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/prettier-plugin-tailwindcss/blob/main/CHANGELOG.md\"\u003eprettier-plugin-tailwindcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[0.8.1] - 2026-07-15\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDon't remove escape sequences when sorting classes in JavaScript string literals, which could produce invalid code in Vue attribute expressions (\u003ca href=\"https://redirect.github.com/tailwindlabs/prettier-plugin-tailwindcss/pull/461\"\u003e#461\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRestore class sorting in Svelte markup and dynamic \u003ccode\u003eclass={...}\u003c/code\u003e expressions when using \u003ccode\u003eprettier-plugin-svelte\u003c/code\u003e v4 (\u003ca href=\"https://redirect.github.com/tailwindlabs/prettier-plugin-tailwindcss/pull/462\"\u003e#462\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/prettier-plugin-tailwindcss/commit/fad3e0740088240af58046d9a8b05b47dd85f7b6\"\u003e\u003ccode\u003efad3e07\u003c/code\u003e\u003c/a\u003e 0.8.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/prettier-plugin-tailwindcss/commit/fc3a063f4bccbccb9c20ea757098fceefbfd8c80\"\u003e\u003ccode\u003efc3a063\u003c/code\u003e\u003c/a\u003e sync changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/prettier-plugin-tailwindcss/commit/2b6f3c23bbd6755eebae31c141b006553c3fc841\"\u003e\u003ccode\u003e2b6f3c2\u003c/code\u003e\u003c/a\u003e fix: Preserve escape sequences when sorting JS string literals (\u003ca href=\"https://redirect.github.com/tailwindlabs/prettier-plugin-tailwindcss/issues/461\"\u003e#461\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/prettier-plugin-tailwindcss/commit/410eb88e836cafe3871345e004ef2ad3eaac2e37\"\u003e\u003ccode\u003e410eb88\u003c/code\u003e\u003c/a\u003e Fix Svelte class sorting with prettier-plugin-svelte v4 (\u003ca href=\"https://redirect.github.com/tailwindlabs/prettier-plugin-tailwindcss/issues/462\"\u003e#462\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/tailwindlabs/prettier-plugin-tailwindcss/compare/v0.8.0...v0.8.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tailwindcss` from 4.3.2 to 4.3.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/tailwindcss/releases\"\u003etailwindcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.3.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003e--watch --poll[=ms]\u003c/code\u003e in \u003ccode\u003e@tailwindcss/cli\u003c/code\u003e when filesystem events are unreliable or unavailable (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20297\"\u003e#20297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCanonicalization: match arbitrary hex colors against theme colors case-insensitively (e.g. \u003ccode\u003ebg-[#fff]\u003c/code\u003e and \u003ccode\u003ebg-[#FFF]\u003c/code\u003e → \u003ccode\u003ebg-white\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20298\"\u003e#20298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent Preflight from overriding Firefox's native \u003ccode\u003eiframe:focus-visible\u003c/code\u003e outline styles (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20292\"\u003e#20292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003etheme('colors.foo')\u003c/code\u003e in JS plugins resolves correctly when both \u003ccode\u003e--color-foo\u003c/code\u003e and \u003ccode\u003e--color-foo-bar\u003c/code\u003e exist (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20299\"\u003e#20299\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure fractional opacity modifiers work with named shadow sizes like \u003ccode\u003eshadow-sm/12.5\u003c/code\u003e, \u003ccode\u003etext-shadow-sm/12.5\u003c/code\u003e, \u003ccode\u003edrop-shadow-sm/12.5\u003c/code\u003e, and \u003ccode\u003einset-shadow-sm/12.5\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20302\"\u003e#20302\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eParse selectors like \u003ccode\u003e[data-foo]div\u003c/code\u003e as two selectors instead of one (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20303\"\u003e#20303\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e@tailwindcss/postcss\u003c/code\u003e rebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20310\"\u003e#20310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure CSS nesting is handled even when Lightning CSS isn't run, such as in \u003ccode\u003e@tailwindcss/browser\u003c/code\u003e and Tailwind Play (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20124\"\u003e#20124\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent achromatic theme colors from shifting hue when mixed in polar color spaces like \u003ccode\u003eoklch\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20314\"\u003e#20314\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e--spacing(0)\u003c/code\u003e is optimized to \u003ccode\u003e0px\u003c/code\u003e instead of \u003ccode\u003e0\u003c/code\u003e so it remains a \u003ccode\u003e\u0026lt;length\u0026gt;\u003c/code\u003e when used in \u003ccode\u003ecalc(…)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20319\"\u003e#20319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eLoad \u003ccode\u003e@parcel/watcher\u003c/code\u003e only when needed in \u003ccode\u003e@tailwindcss/cli --watch\u003c/code\u003e mode, so one-off builds and \u003ccode\u003e--watch --poll\u003c/code\u003e work when \u003ccode\u003e@parcel/watcher\u003c/code\u003e can't be loaded (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20325\"\u003e#20325\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUse explicit platform fonts instead of \u003ccode\u003esystem-ui\u003c/code\u003e and \u003ccode\u003eui-sans-serif\u003c/code\u003e so CJK text respects the page's \u003ccode\u003elang\u003c/code\u003e attribute on Windows (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20318\"\u003e#20318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent \u003ccode\u003e@tailwindcss/upgrade\u003c/code\u003e from rewriting ignored files when run from a subdirectory (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20329\"\u003e#20329\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure earlier \u003ccode\u003e@source\u003c/code\u003e rules pointing to nested files are scanned when later \u003ccode\u003e@source\u003c/code\u003e rules point to files in parent folders (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20335\"\u003e#20335\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent \u003ccode\u003e@tailwindcss/vite\u003c/code\u003e from triggering full page reloads when scanned files are processed by Vite but haven't been loaded as modules yet (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20336\"\u003e#20336\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md\"\u003etailwindcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[4.3.3] - 2026-07-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003e--watch --poll[=ms]\u003c/code\u003e in \u003ccode\u003e@tailwindcss/cli\u003c/code\u003e when filesystem events are unreliable or unavailable (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20297\"\u003e#20297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCanonicalization: match arbitrary hex colors against theme colors case-insensitively (e.g. \u003ccode\u003ebg-[#fff]\u003c/code\u003e and \u003ccode\u003ebg-[#FFF]\u003c/code\u003e → \u003ccode\u003ebg-white\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20298\"\u003e#20298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent Preflight from overriding Firefox's native \u003ccode\u003eiframe:focus-visible\u003c/code\u003e outline styles (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20292\"\u003e#20292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003etheme('colors.foo')\u003c/code\u003e in JS plugins resolves correctly when both \u003ccode\u003e--color-foo\u003c/code\u003e and \u003ccode\u003e--color-foo-bar\u003c/code\u003e exist (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20299\"\u003e#20299\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure fractional opacity modifiers work with named shadow sizes like \u003ccode\u003eshadow-sm/12.5\u003c/code\u003e, \u003ccode\u003etext-shadow-sm/12.5\u003c/code\u003e, \u003ccode\u003edrop-shadow-sm/12.5\u003c/code\u003e, and \u003ccode\u003einset-shadow-sm/12.5\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20302\"\u003e#20302\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eParse selectors like \u003ccode\u003e[data-foo]div\u003c/code\u003e as two selectors instead of one (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20303\"\u003e#20303\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e@tailwindcss/postcss\u003c/code\u003e rebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20310\"\u003e#20310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure CSS nesting is handled even when Lightning CSS isn't run, such as in \u003ccode\u003e@tailwindcss/browser\u003c/code\u003e and Tailwind Play (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20124\"\u003e#20124\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent achromatic theme colors from shifting hue when mixed in polar color spaces like \u003ccode\u003eoklch\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20314\"\u003e#20314\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e--spacing(0)\u003c/code\u003e is optimized to \u003ccode\u003e0px\u003c/code\u003e instead of \u003ccode\u003e0\u003c/code\u003e so it remains a \u003ccode\u003e\u0026lt;length\u0026gt;\u003c/code\u003e when used in \u003ccode\u003ecalc(…)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20319\"\u003e#20319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eLoad \u003ccode\u003e@parcel/watcher\u003c/code\u003e only when needed in \u003ccode\u003e@tailwindcss/cli --watch\u003c/code\u003e mode, so one-off builds and \u003ccode\u003e--watch --poll\u003c/code\u003e work when \u003ccode\u003e@parcel/watcher\u003c/code\u003e can't be loaded (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20325\"\u003e#20325\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUse explicit platform fonts instead of \u003ccode\u003esystem-ui\u003c/code\u003e and \u003ccode\u003eui-sans-serif\u003c/code\u003e so CJK text respects the page's \u003ccode\u003elang\u003c/code\u003e attribute on Windows (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20318\"\u003e#20318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent \u003ccode\u003e@tailwindcss/upgrade\u003c/code\u003e from rewriting ignored files when run from a subdirectory (\u003ca href=\"http...\n\n_Description has been truncated_","html_url":"https://github.com/devresponse/devresponsekit/pull/368","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/devresponse%2Fdevresponsekit/issues/368","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/368/packages"},{"uuid":"5075313856","node_id":"PR_kwDORVvv5c77Sn8E","number":116,"state":"closed","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 5 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-08-07T18:40:20.000Z","author_association":null,"state_reason":null,"created_at":"2026-08-05T21:20:07.000Z","updated_at":"2026-08-07T18:40:28.000Z","time_to_close":163213,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":5,"packages":[{"name":"dompurify","old_version":"3.4.11","new_version":"3.4.13","repository_url":"https://github.com/cure53/DOMPurify"},{"name":"postcss","old_version":"8.5.15","new_version":"8.5.25","repository_url":"https://github.com/postcss/postcss"},{"name":"brace-expansion","old_version":"5.0.6","new_version":"5.0.9","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"fast-uri","old_version":"3.1.2","new_version":"3.1.5","repository_url":"https://github.com/fastify/fast-uri"},{"name":"undici","old_version":"7.28.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 5 updates in the /resume-designer directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [dompurify](https://github.com/cure53/DOMPurify) | `3.4.11` | `3.4.13` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.15` | `8.5.25` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `5.0.6` | `5.0.9` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.2` | `3.1.5` |\n| [undici](https://github.com/nodejs/undici) | `7.28.0` | `7.29.0` |\n\n\nUpdates `dompurify` from 3.4.11 to 3.4.13\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cure53/DOMPurify/releases\"\u003edompurify's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eDOMPurify 3.4.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue with hook removal during \u003ccode\u003eIN_PLACE\u003c/code\u003e sanitization, thanks \u003ca href=\"https://github.com/koyokr\"\u003e\u003ccode\u003e@​koyokr\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue with hooks potentially bypassing the clone guard, thanks \u003ca href=\"https://github.com/AkshayjainG\"\u003e\u003ccode\u003e@​AkshayjainG\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue with DOM clobbering via \u003ccode\u003eownerDocument\u003c/code\u003e during \u003ccode\u003eIN_PLACE\u003c/code\u003e, thanks \u003ca href=\"https://github.com/AkshayjainG\"\u003e\u003ccode\u003e@​AkshayjainG\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where a hook would not get called for custom elements, thanks \u003ca href=\"https://github.com/Rikuxx0\"\u003e\u003ccode\u003e@​Rikuxx0\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHardened the handling of hooks removing elements, \u003ca href=\"https://github.com/mkrause-bee360\"\u003e\u003ccode\u003e@​mkrause-bee360\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded support for a few new SVG attributes, thanks \u003ca href=\"https://github.com/cbn-falias\"\u003e\u003ccode\u003e@​cbn-falias\u003c/code\u003e\u003c/a\u003e \u0026amp; \u003ca href=\"https://github.com/Develop-KIM\"\u003e\u003ccode\u003e@​Develop-KIM\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHardened the handling of declarative partial updates\u003c/li\u003e\n\u003cli\u003eUpdated the documentation is several spots, README, wiki, etc.\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/3067f774676975de12306effd6db6ad7a9a8c17f\"\u003e\u003ccode\u003e3067f77\u003c/code\u003e\u003c/a\u003e release: 3.4.13 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1562\"\u003e#1562\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/a9ca1e537422319a557a9a2aa61f003b23b4a197\"\u003e\u003ccode\u003ea9ca1e5\u003c/code\u003e\u003c/a\u003e release: 3.4.12 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1537\"\u003e#1537\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cure53/DOMPurify/compare/3.4.11...3.4.13\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.15 to 8.5.25\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/08c989c43cc87edb1ed71408c2f5164c54fc21df\"\u003e\u003ccode\u003e08c989c\u003c/code\u003e\u003c/a\u003e Release 8.5.25 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/24f681471645cd960ee760ab7f9e348fbabfd42c\"\u003e\u003ccode\u003e24f6814\u003c/code\u003e\u003c/a\u003e Fix 8.5.17 visitor regression\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f2fa53f11daab3a16c7eb8bcaf5a945142341df3\"\u003e\u003ccode\u003ef2fa53f\u003c/code\u003e\u003c/a\u003e Add supply chain security requirement to PostCSS plugin guide\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/10edf0b0606f97b1510e040c27bfd078c48d6ea7\"\u003e\u003ccode\u003e10edf0b\u003c/code\u003e\u003c/a\u003e fix: return empty array for empty string in list.split (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2121\"\u003e#2121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/0ebe8ad591621ab4e48311da47a76974617571f9\"\u003e\u003ccode\u003e0ebe8ad\u003c/code\u003e\u003c/a\u003e Release 8.5.24 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/73218c64245be53e25d58150e0cc7e984f1d162d\"\u003e\u003ccode\u003e73218c6\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9a114f62b0deb37be859102f93b414b49385805a\"\u003e\u003ccode\u003e9a114f6\u003c/code\u003e\u003c/a\u003e Preserve the BOM when stringifying (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2119\"\u003e#2119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/90692619125cb9424f5eafd8c64bc76b2da23db1\"\u003e\u003ccode\u003e9069261\u003c/code\u003e\u003c/a\u003e Fix types check\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.15...8.5.25\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 5.0.6 to 5.0.9\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/fbcf8ec75b88c79374b4aac06559b1a5288a1223\"\u003e\u003ccode\u003efbcf8ec\u003c/code\u003e\u003c/a\u003e 5.0.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/f6f3939e531052d536c9066b100ad19d4175d3cc\"\u003e\u003ccode\u003ef6f3939\u003c/code\u003e\u003c/a\u003e test: cover dropping empties when only some prefixes are empty\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/688a99eeaab02627c2b89ba8ba4821fecfa659cf\"\u003e\u003ccode\u003e688a99e\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c66e5f9bce61a1c2b232cdfcc5178cd26322a979\"\u003e\u003ccode\u003ec66e5f9\u003c/code\u003e\u003c/a\u003e docs: make the maxLength example produce a non-empty result (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/137\"\u003e#137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/473d3e95e9614c783a6033f9c8577c0ba9cb6881\"\u003e\u003ccode\u003e473d3e9\u003c/code\u003e\u003c/a\u003e Bump linkify-it from 5.0.1 to 5.0.2 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/128\"\u003e#128\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/96a63c0011c0288846ad41773c73e3fbd0906b59\"\u003e\u003ccode\u003e96a63c0\u003c/code\u003e\u003c/a\u003e 5.0.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/a1bd33999ea75262c4749fff3bbb0d1372bd07b5\"\u003e\u003ccode\u003ea1bd339\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/592a36fd18455c37f81e0848a642d84c63147fa7\"\u003e\u003ccode\u003e592a36f\u003c/code\u003e\u003c/a\u003e Bump tar from 7.5.16 to 7.5.20 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/127\"\u003e#127\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/bd146909cd6c7bedde61a5d6428ba252860a0159\"\u003e\u003ccode\u003ebd14690\u003c/code\u003e\u003c/a\u003e Bump brace-expansion from 2.0.2 to 2.1.2 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/126\"\u003e#126\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/e729ba647887042f16b531fdb3d8ac3d7762ccad\"\u003e\u003ccode\u003ee729ba6\u003c/code\u003e\u003c/a\u003e Bump ws from 8.19.0 to 8.21.1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/124\"\u003e#124\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v5.0.6...v5.0.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.2 to 3.1.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/5e179cbb4636d5f773ed21126e5bd3068e87e94e\"\u003e\u003ccode\u003e5e179cb\u003c/code\u003e\u003c/a\u003e Bumped v3.1.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/2cad02d6ed428a720499bb7a3c3d6c3d41f10f5a\"\u003e\u003ccode\u003e2cad02d\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6aeece669e4166b2446a89f17c07a3b15dfb7ed4\"\u003e\u003ccode\u003e6aeece6\u003c/code\u003e\u003c/a\u003e Bumped v3.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/2d50fbabc80e4d0884fe0f6a98fe118ce6faa353\"\u003e\u003ccode\u003e2d50fba\u003c/code\u003e\u003c/a\u003e fix: reject literal backslash in URI authority\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/0549fe35b0d482233f3be2816439f3ec803603fa\"\u003e\u003ccode\u003e0549fe3\u003c/code\u003e\u003c/a\u003e Bumped v3.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/2a6d357a18a68e6d812824379fd3388a1ae50d05\"\u003e\u003ccode\u003e2a6d357\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.28.0 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/ashproto/Resume-Designer/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/ashproto/Resume-Designer/pull/116","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ashproto%2FResume-Designer/issues/116","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/116/packages"}],"issue_packages":[{"old_version":"7.22.0","new_version":"7.29.0","update_type":"minor","path":null,"pr_created_at":"2026-08-12T05:04:30.000Z","version_change":"7.22.0 → 7.29.0","issue":{"uuid":"5127396734","node_id":"PR_kwDORIxYSc7936eK","number":12,"state":"open","title":"Bump undici from 7.22.0 to 7.29.0","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-12T05:04:30.000Z","updated_at":"2026-08-12T05:04:50.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"undici","old_version":"7.22.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 7.22.0 to 7.29.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.28.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e7 security advisories\u003c/strong\u003e, all shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 7.28.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^7.28.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v7 line is \u003cstrong\u003enot\u003c/strong\u003e affected by GHSA-38rv-x7px-6hhq (CVE-2026-9675), which is\nan 8.x-only regression.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on GHSA-hm92-r4w5-c3mj:\u003c/strong\u003e this fix shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e, not the\nearlier 7.2x line — the vulnerable single-pool code was still present through\n\u003ccode\u003ev7.27.2\u003c/code\u003e. The per-origin pool fix is\n\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5041\"\u003e#5041\u003c/a\u003e).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8cb10f98\"\u003e\u003ccode\u003e8cb10f98\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g\"\u003eGHSA-vmh5-mc38-953g\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9697\u003c/td\u003e\n\u003ctd\u003eHigh (7.4)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/04201f89\"\u003e\u003ccode\u003e04201f89\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj\"\u003eGHSA-hm92-r4w5-c3mj\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6734\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6\"\u003eGHSA-pr7r-676h-xcf6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9678\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/85a24055\"\u003e\u003ccode\u003e85a24055\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ea8930cf\"\u003e\u003ccode\u003eea8930cf\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f9eba0ad9134e1c0977848476bba9d49734696e4\"\u003e\u003ccode\u003ef9eba0a\u003c/code\u003e\u003c/a\u003e Bumped v7.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5430\"\u003e#5430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.22.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=7.22.0\u0026new-version=7.29.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/jaykode2025/whyismywebsiteslow.com/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/jaykode2025/whyismywebsiteslow.com/pull/12","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/jaykode2025%2Fwhyismywebsiteslow.com/issues/12","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/12/packages"}},{"old_version":"6.27.0","new_version":"6.28.0","update_type":"minor","path":null,"pr_created_at":"2026-08-11T17:47:27.000Z","version_change":"6.27.0 → 6.28.0","issue":{"uuid":"5123008776","node_id":"PR_kwDORAPClc79pzrw","number":36,"state":"closed","title":"Bump undici from 6.27.0 to 6.28.0","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-08-11T17:49:22.000Z","author_association":null,"state_reason":null,"created_at":"2026-08-11T17:47:27.000Z","updated_at":"2026-08-11T17:49:32.000Z","time_to_close":115,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"undici","old_version":"6.27.0","new_version":"6.28.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 6.27.0 to 6.28.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.28.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e740a0b7c\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003ecba3a52a\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e4fd5a0c6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003eaf748404\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e and \u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ehttps://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a\"\u003e\u003ccode\u003e01a912e\u003c/code\u003e\u003c/a\u003e Bumped v6.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5591\"\u003e#5591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e\"\u003e\u003ccode\u003e481ecfc\u003c/code\u003e\u003c/a\u003e Use Node 22 and npm 11 to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e\u003ccode\u003e740a0b7\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0\"\u003e\u003ccode\u003e2698e49\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e\u003ccode\u003e4fd5a0c\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003e\u003ccode\u003ecba3a52\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003e\u003ccode\u003eaf74840\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=6.27.0\u0026new-version=6.28.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/paulie-of-punskas/get-lts-versions/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/paulie-of-punskas/get-lts-versions/pull/36","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/paulie-of-punskas%2Fget-lts-versions/issues/36","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/36/packages"}},{"old_version":"8.9.0","new_version":"8.10.0","update_type":"minor","path":null,"pr_created_at":"2026-08-10T19:17:16.000Z","version_change":"8.9.0 → 8.10.0","issue":{"uuid":"5113547515","node_id":"PR_kwDOOTUI_M79LRAw","number":1031,"state":"open","title":"Bump the prod group across 1 directory with 5 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-10T19:17:16.000Z","updated_at":"2026-08-10T19:18:39.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"prod","update_count":5,"packages":[{"name":"i18next-fs-backend","old_version":"2.6.6","new_version":"2.6.7","repository_url":"https://github.com/i18next/i18next-fs-backend"},{"name":"i18next-http-middleware","old_version":"3.9.7","new_version":"3.9.8","repository_url":"https://github.com/i18next/i18next-http-middleware"},{"name":"jose","old_version":"6.2.4","new_version":"6.2.8","repository_url":"https://github.com/panva/jose"},{"name":"to-words","old_version":"5.6.1","new_version":"5.7.0","repository_url":"https://github.com/mastermunj/to-words"},{"name":"undici","old_version":"8.9.0","new_version":"8.10.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps the prod group with 5 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [i18next-fs-backend](https://github.com/i18next/i18next-fs-backend) | `2.6.6` | `2.6.7` |\n| [i18next-http-middleware](https://github.com/i18next/i18next-http-middleware) | `3.9.7` | `3.9.8` |\n| [jose](https://github.com/panva/jose) | `6.2.4` | `6.2.8` |\n| [to-words](https://github.com/mastermunj/to-words) | `5.6.1` | `5.7.0` |\n| [undici](https://github.com/nodejs/undici) | `8.9.0` | `8.10.0` |\n\n\nUpdates `i18next-fs-backend` from 2.6.6 to 2.6.7\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/i18next/i18next-fs-backend/blob/master/CHANGELOG.md\"\u003ei18next-fs-backend's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003e2.6.7\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003esecurity (defence-in-depth): \u003ccode\u003ewrite()\u003c/code\u003e iterates own enumerable keys of \u003ccode\u003equeuedWrites\u003c/code\u003e instead of using \u003ccode\u003efor...in\u003c/code\u003e. \u003ccode\u003efor...in\u003c/code\u003e walks the prototype chain, so an \u003ccode\u003eObject.prototype\u003c/code\u003e polluted by any other library in the process was iterated here and turned into \u003ccode\u003ewriteFile()\u003c/code\u003e calls. \u003ccode\u003esetPath\u003c/code\u003e / \u003ccode\u003epushPath\u003c/code\u003e already refuse to create unsafe own keys and \u003ccode\u003einterpolatePath\u003c/code\u003e still validates before anything is written, so this closes an amplification path rather than a traversal.\u003c/li\u003e\n\u003cli\u003edocs: corrected the security section of the README, which still claimed \u003ccode\u003e/\u003c/code\u003e is rejected in both \u003ccode\u003elng\u003c/code\u003e and \u003ccode\u003ens\u003c/code\u003e. That has not been true since 2.6.5, which allows \u003ccode\u003e/\u003c/code\u003e in \u003ccode\u003ens\u003c/code\u003e so nested namespace names such as \u003ccode\u003ea/b\u003c/code\u003e map to subfolder layouts. The per-key split is now described accurately.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/7c51fad9b376d04d6ca70a6a75e1664343b63799\"\u003e\u003ccode\u003e7c51fad\u003c/code\u003e\u003c/a\u003e 2.6.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/d3910ce620bf5b464017b730ec76163089f04fb5\"\u003e\u003ccode\u003ed3910ce\u003c/code\u003e\u003c/a\u003e security: iterate own keys in write(); fix stale README security section\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/8e5a11e2acdc86b24a77840f6aa565002cd86b08\"\u003e\u003ccode\u003e8e5a11e\u003c/code\u003e\u003c/a\u003e Bump i18next-fs-backend from 2.6.4 to 2.6.6 in /example/updatable-cache (\u003ca href=\"https://redirect.github.com/i18next/i18next-fs-backend/issues/84\"\u003e#84\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/ef0e8e5dd70a834a58c8967ec88bfea389a6b841\"\u003e\u003ccode\u003eef0e8e5\u003c/code\u003e\u003c/a\u003e Bump js-yaml from 4.2.0 to 4.3.0 (\u003ca href=\"https://redirect.github.com/i18next/i18next-fs-backend/issues/83\"\u003e#83\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/9e252de02967a5813125dc8c7e91786e69553c96\"\u003e\u003ccode\u003e9e252de\u003c/code\u003e\u003c/a\u003e Bump i18next-http-middleware from 3.9.3 to 3.9.7 in /example/fastify (\u003ca href=\"https://redirect.github.com/i18next/i18next-fs-backend/issues/80\"\u003e#80\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/7e5e5f2e798b7c3f85826ca80285886c257fe689\"\u003e\u003ccode\u003e7e5e5f2\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003e@​babel/core\u003c/code\u003e from 7.29.0 to 7.29.6 (\u003ca href=\"https://redirect.github.com/i18next/i18next-fs-backend/issues/81\"\u003e#81\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/e20a304df62fd597a5ca2fae255c3740f5ef0e9d\"\u003e\u003ccode\u003ee20a304\u003c/code\u003e\u003c/a\u003e Bump i18next-fs-backend from 2.6.4 to 2.6.6 in /example/fastify (\u003ca href=\"https://redirect.github.com/i18next/i18next-fs-backend/issues/79\"\u003e#79\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/7534a5c446fd588c988a5a3d041e173eb71b6d07\"\u003e\u003ccode\u003e7534a5c\u003c/code\u003e\u003c/a\u003e Bump js-yaml from 4.1.1 to 4.2.0 (\u003ca href=\"https://redirect.github.com/i18next/i18next-fs-backend/issues/78\"\u003e#78\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/90001dfa95ff96760471375d0820cba9870a1057\"\u003e\u003ccode\u003e90001df\u003c/code\u003e\u003c/a\u003e Bump esbuild from 0.28.0 to 0.28.1 (\u003ca href=\"https://redirect.github.com/i18next/i18next-fs-backend/issues/77\"\u003e#77\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-fs-backend/commit/ae1b436e864cda55bb2c343fe70eb2924359b952\"\u003e\u003ccode\u003eae1b436\u003c/code\u003e\u003c/a\u003e README: mention npx i18next-cli localize as the zero-to-localized path\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/i18next/i18next-fs-backend/compare/v2.6.6...v2.6.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `i18next-http-middleware` from 3.9.7 to 3.9.8\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/i18next/i18next-http-middleware/blob/master/CHANGELOG.md\"\u003ei18next-http-middleware's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/compare/v3.9.7...v3.9.8\"\u003ev3.9.8\u003c/a\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003esecurity: validate \u003ccode\u003elng\u003c/code\u003e/\u003ccode\u003ens\u003c/code\u003e in \u003ccode\u003emissingKeyHandler\u003c/code\u003e before forwarding them to \u003ccode\u003ebackendConnector.saveMissing()\u003c/code\u003e. The route params were used unvalidated, while the sibling \u003ccode\u003egetResourcesHandler\u003c/code\u003e already filtered them since 3.9.3. Because those values become the \u003ccode\u003e{{lng}}\u003c/code\u003e/\u003ccode\u003e{{ns}}\u003c/code\u003e segments of the backend's \u003ccode\u003eaddPath\u003c/code\u003e, and route params arrive percent-decoded, a request such as \u003ccode\u003ePOST /locales/add/..%2f..%2f..%2ftmp%2fpwned/x\u003c/code\u003e could write outside the locales directory on \u003ccode\u003ei18next-fs-backend\u003c/code\u003e; \u003ccode\u003elng=__proto__\u003c/code\u003e additionally reached that backend's \u003ccode\u003equeuedWrites\u003c/code\u003e path walk. Unsafe values now get a \u003ccode\u003e400\u003c/code\u003e and never reach the backend. The same \u003ccode\u003eisSafeLangIdentifier\u003c/code\u003e/\u003ccode\u003eisSafeNsIdentifier\u003c/code\u003e split applies, so legitimate values (including nested namespaces like \u003ccode\u003ea/b\u003c/code\u003e) are unaffected.\u003c/li\u003e\n\u003cli\u003esecurity: apply \u003ccode\u003eutils.isSafeLangIdentifier\u003c/code\u003e to detected languages in \u003ccode\u003eLanguageDetector.detect()\u003c/code\u003e. Detected values come from untrusted request input (querystring, path, cookie, session, header) and were filtered only by \u003ccode\u003eutils.hasXSS\u003c/code\u003e, which targets markup payloads and does not reject \u003ccode\u003e..\u003c/code\u003e, \u003ccode\u003e/\u003c/code\u003e, \u003ccode\u003e\\\u003c/code\u003e, control characters or prototype keys. With the default \u003ccode\u003esupportedLngs: false\u003c/code\u003e, i18next resolves any string, so a crafted \u003ccode\u003e?lng=\u003c/code\u003e could reach the backend's \u003ccode\u003eloadPath\u003c/code\u003e as a traversal segment (arbitrary file read on \u003ccode\u003ei18next-fs-backend\u003c/code\u003e, request forgery on \u003ccode\u003ei18next-http-backend\u003c/code\u003e). The check runs after \u003ccode\u003econvertDetectedLanguage\u003c/code\u003e, so a custom converter cannot reintroduce an unsafe value. All five built-in detectors converge on this one filter.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/commit/e4c0285f9beb6e9084d3c28991c5c607c4ceec16\"\u003e\u003ccode\u003ee4c0285\u003c/code\u003e\u003c/a\u003e 3.9.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/commit/9dd7c94124e633771040d25138cca7c38f6bfd2d\"\u003e\u003ccode\u003e9dd7c94\u003c/code\u003e\u003c/a\u003e security: validate lng/ns in missingKeyHandler and detected languages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/commit/fbce4c49827b9d9eaeafa105a1ee5ff3f29f8de0\"\u003e\u003ccode\u003efbce4c4\u003c/code\u003e\u003c/a\u003e Bump i18next-fs-backend from 2.6.4 to 2.6.6 in /example/fastify-pug (\u003ca href=\"https://redirect.github.com/i18next/i18next-http-middleware/issues/133\"\u003e#133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/commit/fd3a7c87ffc982f95dc464ec66c5f5a573fed322\"\u003e\u003ccode\u003efd3a7c8\u003c/code\u003e\u003c/a\u003e Bump i18next-http-middleware in /example/basic-locize (\u003ca href=\"https://redirect.github.com/i18next/i18next-http-middleware/issues/132\"\u003e#132\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/commit/25815efbab84af6542bd78ad0cc18e2ce1a32522\"\u003e\u003ccode\u003e25815ef\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003e@​babel/core\u003c/code\u003e from 7.29.0 to 7.29.6 (\u003ca href=\"https://redirect.github.com/i18next/i18next-http-middleware/issues/131\"\u003e#131\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/commit/40fdedc6f0f4079032decab5c051bfa9084df0ff\"\u003e\u003ccode\u003e40fdedc\u003c/code\u003e\u003c/a\u003e package.json: use HTTPS URL for repository metadata\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/commit/01f2dc248f2e651c15dd24d2c7d9d1542841ca1d\"\u003e\u003ccode\u003e01f2dc2\u003c/code\u003e\u003c/a\u003e changelog: link 3.9.7 entry to published advisory GHSA-f49m-vf83-692w\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next-http-middleware/commit/a3722a803b6eab50141b6a800903e74c7ba65eb1\"\u003e\u003ccode\u003ea3722a8\u003c/code\u003e\u003c/a\u003e Bump i18next-fs-backend from 1.0.7 to 2.6.4 in /example/basic-pug (\u003ca href=\"https://redirect.github.com/i18next/i18next-http-middleware/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/i18next/i18next-http-middleware/compare/v3.9.7...v3.9.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `jose` from 6.2.4 to 6.2.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/panva/jose/releases\"\u003ejose's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.2.8\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eenforce a single recipient when decrypting dir and ECDH-ES (\u003ca href=\"https://github.com/panva/jose/commit/505c3833ecae19807e32ad7be50ff4677d31bcad\"\u003e505c383\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject a non-string \u0026quot;alg\u0026quot; in EmbeddedJWK (\u003ca href=\"https://github.com/panva/jose/commit/714f8704347ccee8b3d0007e028b6e3f546b443c\"\u003e714f870\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eindex the JWS and JWE registries without a wrapper (\u003ca href=\"https://github.com/panva/jose/commit/925f3bbbee4b8d5e335774ffbf6ec086e71c3a05\"\u003e925f3bb\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ename the \u0026quot;alg\u0026quot; source in unsupported algorithm failures (\u003ca href=\"https://github.com/panva/jose/commit/1500459c6ffce48fb486c15cb213d24064a26673\"\u003e1500459\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.2.7\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003erequire own JOSE properties for presence checks (\u003ca href=\"https://github.com/panva/jose/commit/90ab09c461c9bc82fd24af269616be0907a28bc5\"\u003e90ab09c\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ereduce bundle size (\u003ca href=\"https://github.com/panva/jose/commit/767d7f12d025ce54e74f3d38fde3571cc23de5f6\"\u003e767d7f1\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.2.6\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e accept host CryptoKey declarations (\u003ca href=\"https://github.com/panva/jose/commit/b48a15b39696f49c61136b1d4c40d33585f5df97\"\u003eb48a15b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.2.5\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecompare claim values for falsy validation options (\u003ca href=\"https://github.com/panva/jose/commit/eb8695699c75f36c736fb8159a7c7b525be5f6ff\"\u003eeb86956\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eforward key management parameters for a single JWE recipient (\u003ca href=\"https://github.com/panva/jose/commit/2d4f8014e027a1e1ace82bdc864fd0f9b5c66248\"\u003e2d4f801\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ehandle a zero-length JWE additional authenticated data (\u003ca href=\"https://github.com/panva/jose/commit/16ca398103c4ab1527c6c6c51621fd963545bd7e\"\u003e16ca398\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject a generateKeyPair crv option the algorithm does not imply (\u003ca href=\"https://github.com/panva/jose/commit/76364e9f15f2a7d1c2ff0c260e1e2960cf51e620\"\u003e76364e9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject an unencoded payload in the JWS Compact Serialization (\u003ca href=\"https://github.com/panva/jose/commit/01d053f3b02f3627396d4f70686a58f35cf09862\"\u003e01d053f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject characters outside the Base64URL alphabet (\u003ca href=\"https://github.com/panva/jose/commit/0ebb97158a6eed960ec4d5450abd28336b3c20a4\"\u003e0ebb971\u003c/a\u003e), references \u003ca href=\"https://redirect.github.com/panva/jose/issues/879\"\u003e#879\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ereject duplicate \u0026quot;crit\u0026quot; values when producing (\u003ca href=\"https://github.com/panva/jose/commit/31d60e1542141ddecf5b0b87bc894c4bc7e58b1d\"\u003e31d60e1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject invalid UTF-8 in JOSE Headers and JWT Claims Sets (\u003ca href=\"https://github.com/panva/jose/commit/5df3fedcc06d4c52815ec9d0cccc51b508a8291c\"\u003e5df3fed\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject truncated ASN.1 key data (\u003ca href=\"https://github.com/panva/jose/commit/7a16c66b9f1a48bcc2aae572da38ed06396a5181\"\u003e7a16c66\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esurface non-ASCII token segments as JOSE errors (\u003ca href=\"https://github.com/panva/jose/commit/194fe11450d6501d0c2141a50e60886157d3f393\"\u003e194fe11\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e correct JWK and CryptoKey types (\u003ca href=\"https://github.com/panva/jose/commit/62a196dc8e6582dc6edd20eab31c6c44b745f996\"\u003e62a196d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e correct key resolver and JWT header types (\u003ca href=\"https://github.com/panva/jose/commit/e95f8c4086cbb81321497cc7d4b78fa5e88312b6\"\u003ee95f8c4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003evalidate the clockTolerance and currentDate options are finite (\u003ca href=\"https://github.com/panva/jose/commit/ab2f18dad46a98ecae3f3ac5b2aae9c839fb9388\"\u003eab2f18d\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecorrect subpaths and API documentation (\u003ca href=\"https://github.com/panva/jose/commit/2daec382964be1976d5985e0413a56633becdd74\"\u003e2daec38\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edocument consumer-supplied type parameters (\u003ca href=\"https://github.com/panva/jose/commit/9e9f66c86bdf0f4b4ccd1e4b7b84cc85ac9c7883\"\u003e9e9f66c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003estop claiming the JWK \u0026quot;use\u0026quot; parameter is used during import (\u003ca href=\"https://github.com/panva/jose/commit/47a07b2f95c1b2ecf0308c04f35d4b482689568e\"\u003e47a07b2\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate CHANGELOG.md (\u003ca href=\"https://github.com/panva/jose/commit/fc51bf56f9f752aaed7d31c60a45e89f24e30d00\"\u003efc51bf5\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/panva/jose/blob/main/CHANGELOG.md\"\u003ejose's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/panva/jose/compare/v6.2.7...v6.2.8\"\u003e6.2.8\u003c/a\u003e (2026-08-03)\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eenforce a single recipient when decrypting dir and ECDH-ES (\u003ca href=\"https://github.com/panva/jose/commit/505c3833ecae19807e32ad7be50ff4677d31bcad\"\u003e505c383\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject a non-string \u0026quot;alg\u0026quot; in EmbeddedJWK (\u003ca href=\"https://github.com/panva/jose/commit/714f8704347ccee8b3d0007e028b6e3f546b443c\"\u003e714f870\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eindex the JWS and JWE registries without a wrapper (\u003ca href=\"https://github.com/panva/jose/commit/925f3bbbee4b8d5e335774ffbf6ec086e71c3a05\"\u003e925f3bb\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ename the \u0026quot;alg\u0026quot; source in unsupported algorithm failures (\u003ca href=\"https://github.com/panva/jose/commit/1500459c6ffce48fb486c15cb213d24064a26673\"\u003e1500459\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/panva/jose/compare/v6.2.6...v6.2.7\"\u003e6.2.7\u003c/a\u003e (2026-08-01)\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003erequire own JOSE properties for presence checks (\u003ca href=\"https://github.com/panva/jose/commit/90ab09c461c9bc82fd24af269616be0907a28bc5\"\u003e90ab09c\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ereduce bundle size (\u003ca href=\"https://github.com/panva/jose/commit/767d7f12d025ce54e74f3d38fde3571cc23de5f6\"\u003e767d7f1\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/panva/jose/compare/v6.2.5...v6.2.6\"\u003e6.2.6\u003c/a\u003e (2026-07-31)\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e accept host CryptoKey declarations (\u003ca href=\"https://github.com/panva/jose/commit/b48a15b39696f49c61136b1d4c40d33585f5df97\"\u003eb48a15b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/panva/jose/compare/v6.2.4...v6.2.5\"\u003e6.2.5\u003c/a\u003e (2026-07-29)\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecompare claim values for falsy validation options (\u003ca href=\"https://github.com/panva/jose/commit/eb8695699c75f36c736fb8159a7c7b525be5f6ff\"\u003eeb86956\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eforward key management parameters for a single JWE recipient (\u003ca href=\"https://github.com/panva/jose/commit/2d4f8014e027a1e1ace82bdc864fd0f9b5c66248\"\u003e2d4f801\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ehandle a zero-length JWE additional authenticated data (\u003ca href=\"https://github.com/panva/jose/commit/16ca398103c4ab1527c6c6c51621fd963545bd7e\"\u003e16ca398\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject a generateKeyPair crv option the algorithm does not imply (\u003ca href=\"https://github.com/panva/jose/commit/76364e9f15f2a7d1c2ff0c260e1e2960cf51e620\"\u003e76364e9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject an unencoded payload in the JWS Compact Serialization (\u003ca href=\"https://github.com/panva/jose/commit/01d053f3b02f3627396d4f70686a58f35cf09862\"\u003e01d053f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject characters outside the Base64URL alphabet (\u003ca href=\"https://github.com/panva/jose/commit/0ebb97158a6eed960ec4d5450abd28336b3c20a4\"\u003e0ebb971\u003c/a\u003e), references \u003ca href=\"https://redirect.github.com/panva/jose/issues/879\"\u003e#879\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ereject duplicate \u0026quot;crit\u0026quot; values when producing (\u003ca href=\"https://github.com/panva/jose/commit/31d60e1542141ddecf5b0b87bc894c4bc7e58b1d\"\u003e31d60e1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject invalid UTF-8 in JOSE Headers and JWT Claims Sets (\u003ca href=\"https://github.com/panva/jose/commit/5df3fedcc06d4c52815ec9d0cccc51b508a8291c\"\u003e5df3fed\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereject truncated ASN.1 key data (\u003ca href=\"https://github.com/panva/jose/commit/7a16c66b9f1a48bcc2aae572da38ed06396a5181\"\u003e7a16c66\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esurface non-ASCII token segments as JOSE errors (\u003ca href=\"https://github.com/panva/jose/commit/194fe11450d6501d0c2141a50e60886157d3f393\"\u003e194fe11\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e correct JWK and CryptoKey types (\u003ca href=\"https://github.com/panva/jose/commit/62a196dc8e6582dc6edd20eab31c6c44b745f996\"\u003e62a196d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e correct key resolver and JWT header types (\u003ca href=\"https://github.com/panva/jose/commit/e95f8c4086cbb81321497cc7d4b78fa5e88312b6\"\u003ee95f8c4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003evalidate the clockTolerance and currentDate options are finite (\u003ca href=\"https://github.com/panva/jose/commit/ab2f18dad46a98ecae3f3ac5b2aae9c839fb9388\"\u003eab2f18d\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecorrect subpaths and API documentation (\u003ca href=\"https://github.com/panva/jose/commit/2daec382964be1976d5985e0413a56633becdd74\"\u003e2daec38\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edocument consumer-supplied type parameters (\u003ca href=\"https://github.com/panva/jose/commit/9e9f66c86bdf0f4b4ccd1e4b7b84cc85ac9c7883\"\u003e9e9f66c\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/8b768eb8d2df7b4e25e1a32441ea770663f6d09f\"\u003e\u003ccode\u003e8b768eb\u003c/code\u003e\u003c/a\u003e chore(release): 6.2.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/1500459c6ffce48fb486c15cb213d24064a26673\"\u003e\u003ccode\u003e1500459\u003c/code\u003e\u003c/a\u003e refactor: name the \u0026quot;alg\u0026quot; source in unsupported algorithm failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/714f8704347ccee8b3d0007e028b6e3f546b443c\"\u003e\u003ccode\u003e714f870\u003c/code\u003e\u003c/a\u003e fix: reject a non-string \u0026quot;alg\u0026quot; in EmbeddedJWK\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/925f3bbbee4b8d5e335774ffbf6ec086e71c3a05\"\u003e\u003ccode\u003e925f3bb\u003c/code\u003e\u003c/a\u003e refactor: index the JWS and JWE registries without a wrapper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/505c3833ecae19807e32ad7be50ff4677d31bcad\"\u003e\u003ccode\u003e505c383\u003c/code\u003e\u003c/a\u003e fix: enforce a single recipient when decrypting dir and ECDH-ES\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/514831da55bcb1121c1dadc1ccca42049e6c60b9\"\u003e\u003ccode\u003e514831d\u003c/code\u003e\u003c/a\u003e chore(deps): bump the actions group with 3 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/45965db443b120d174a5114c7c84a75a906e9012\"\u003e\u003ccode\u003e45965db\u003c/code\u003e\u003c/a\u003e chore: cleanup after release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/60b941f6d57e2bb6f87f690ab7fb4da2c9abf4b0\"\u003e\u003ccode\u003e60b941f\u003c/code\u003e\u003c/a\u003e chore(release): 6.2.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/90ab09c461c9bc82fd24af269616be0907a28bc5\"\u003e\u003ccode\u003e90ab09c\u003c/code\u003e\u003c/a\u003e fix: require own JOSE properties for presence checks\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/767d7f12d025ce54e74f3d38fde3571cc23de5f6\"\u003e\u003ccode\u003e767d7f1\u003c/code\u003e\u003c/a\u003e refactor: reduce bundle size\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/panva/jose/compare/v6.2.4...v6.2.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `to-words` from 5.6.1 to 5.7.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mastermunj/to-words/releases\"\u003eto-words's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.7.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/mastermunj/to-words/compare/v5.6.1...v5.7.0\"\u003e5.7.0\u003c/a\u003e (2026-08-02)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd 3 new locale, update docs (\u003ca href=\"https://github.com/mastermunj/to-words/commit/a37ca0a81999af5a80f05c2d6b88a9f0e4cc55e6\"\u003ea37ca0a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd 3 new locale, update docs (\u003ca href=\"https://github.com/mastermunj/to-words/commit/51916b4e3d1a7c3a2b9c5e3d0eddfddb3ebb0eb4\"\u003e51916b4\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mastermunj/to-words/blob/main/CHANGELOG.md\"\u003eto-words's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/mastermunj/to-words/compare/v5.6.1...v5.7.0\"\u003e5.7.0\u003c/a\u003e (2026-08-02)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd 3 new locale, update docs (\u003ca href=\"https://github.com/mastermunj/to-words/commit/a37ca0a81999af5a80f05c2d6b88a9f0e4cc55e6\"\u003ea37ca0a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd 3 new locale, update docs (\u003ca href=\"https://github.com/mastermunj/to-words/commit/51916b4e3d1a7c3a2b9c5e3d0eddfddb3ebb0eb4\"\u003e51916b4\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/31440636dcaaa25055f5ceacf68b30baaed1bd13\"\u003e\u003ccode\u003e3144063\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mastermunj/to-words/issues/2418\"\u003e#2418\u003c/a\u003e from mastermunj/release-please--branches--main--comp...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/e66172f7098368518b9ab8d1ed8d613255fb426b\"\u003e\u003ccode\u003ee66172f\u003c/code\u003e\u003c/a\u003e chore(release): 5.7.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/a37ca0a81999af5a80f05c2d6b88a9f0e4cc55e6\"\u003e\u003ccode\u003ea37ca0a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mastermunj/to-words/issues/2417\"\u003e#2417\u003c/a\u003e from mastermunj/new-locale-2026-08-02\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/51916b4e3d1a7c3a2b9c5e3d0eddfddb3ebb0eb4\"\u003e\u003ccode\u003e51916b4\u003c/code\u003e\u003c/a\u003e feat: add 3 new locale, update docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/46befa9a39078048b51600e32969458f9c10bf63\"\u003e\u003ccode\u003e46befa9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mastermunj/to-words/issues/2411\"\u003e#2411\u003c/a\u003e from mastermunj/dependabot/github_actions/actions/ch...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/59b709d3b8e73bbfa935e5bb2a86de5428f0d533\"\u003e\u003ccode\u003e59b709d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mastermunj/to-words/issues/2410\"\u003e#2410\u003c/a\u003e from mastermunj/dependabot/github_actions/ossf/score...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/039aa77d9539c7844141241086bc601a32eec93b\"\u003e\u003ccode\u003e039aa77\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mastermunj/to-words/issues/2409\"\u003e#2409\u003c/a\u003e from mastermunj/dependabot/github_actions/codeql-85d...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/d2f3b6d44c80107ee036dbfc8dfd29be109f19dd\"\u003e\u003ccode\u003ed2f3b6d\u003c/code\u003e\u003c/a\u003e chore: update dependencies (\u003ca href=\"https://redirect.github.com/mastermunj/to-words/issues/2412\"\u003e#2412\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/05e4ff2c02e7db1fc5c585bcc21d069521c5f783\"\u003e\u003ccode\u003e05e4ff2\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/checkout from 7.0.0 to 7.0.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mastermunj/to-words/commit/88b72c969eb12bf1cb123297ed25f0b1998d3cfa\"\u003e\u003ccode\u003e88b72c9\u003c/code\u003e\u003c/a\u003e build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mastermunj/to-words/compare/v5.6.1...v5.7.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 8.9.0 to 8.10.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: namespace h2 options by \u003ca href=\"https://github.com/metcoder95\"\u003e\u003ccode\u003e@​metcoder95\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5498\"\u003enodejs/undici#5498\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: update WPT expectations by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5587\"\u003enodejs/undici#5587\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: add cache/dedupe + dns re-dispatch integration tests by \u003ca href=\"https://github.com/GiHoon1123\"\u003e\u003ccode\u003e@​GiHoon1123\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5535\"\u003enodejs/undici#5535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): support process.unref by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5578\"\u003enodejs/undici#5578\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): ensure every request settles by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5603\"\u003enodejs/undici#5603\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(readable): consume a body whose end has already been emitted by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5617\"\u003enodejs/undici#5617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): skip the content-length checkpoint for HEAD and for a 206 without content-range by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5610\"\u003enodejs/undici#5610\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: revert idle socket validation to setTimeout(0) to prevent stall on idle event loop by \u003ca href=\"https://github.com/marceli1404\"\u003e\u003ccode\u003e@​marceli1404\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5606\"\u003enodejs/undici#5606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(env-http-proxy-agent): match bare IPv6 addresses in no_proxy by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5623\"\u003enodejs/undici#5623\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: handle aggregate balanced pool errors by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5377\"\u003enodejs/undici#5377\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(readable): keep body bytes that arrive after setEncoding() by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5620\"\u003enodejs/undici#5620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(socks5): evict unused origin pools by \u003ca href=\"https://github.com/Kkartik14\"\u003e\u003ccode\u003e@​Kkartik14\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5595\"\u003enodejs/undici#5595\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: skip deduplication for upgrade requests by \u003ca href=\"https://github.com/Ram-blip\"\u003e\u003ccode\u003e@​Ram-blip\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5593\"\u003enodejs/undici#5593\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward informational responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5625\"\u003enodejs/undici#5625\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(mock): non-string path matchers under ignoreTrailingSlash, and DataView reply bodies by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5619\"\u003enodejs/undici#5619\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(interceptors): cache() and deduplicate() silently inert on Client/Pool without opts.origin by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5628\"\u003enodejs/undici#5628\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5633\"\u003enodejs/undici#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/init from 4.36.2 to 4.37.3 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5634\"\u003enodejs/undici#5634\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.4.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5636\"\u003enodejs/undici#5636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(mock): emit request body lifecycle hooks by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5367\"\u003enodejs/undici#5367\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): detach upgrade close handler after GOAWAY by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5641\"\u003enodejs/undici#5641\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: retry refused HTTP/2 streams by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5598\"\u003enodejs/undici#5598\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: preserve DNS origin hostname on sockets by \u003ca href=\"https://github.com/cyphercodes\"\u003e\u003ccode\u003e@​cyphercodes\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5577\"\u003enodejs/undici#5577\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marceli1404\"\u003e\u003ccode\u003e@​marceli1404\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5606\"\u003enodejs/undici#5606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kkartik14\"\u003e\u003ccode\u003e@​Kkartik14\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5595\"\u003enodejs/undici#5595\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5641\"\u003enodejs/undici#5641\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cyphercodes\"\u003e\u003ccode\u003e@​cyphercodes\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5577\"\u003enodejs/undici#5577\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v8.9.0...v8.10.0\"\u003ehttps://github.com/nodejs/undici/compare/v8.9.0...v8.10.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/c8d80e6b2dcfab282557b08f51352937bc9e5692\"\u003e\u003ccode\u003ec8d80e6\u003c/code\u003e\u003c/a\u003e Bumped v8.10.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5644\"\u003e#5644\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66923b47dc1ed095581daa6a53b2ad1bf3e899b4\"\u003e\u003ccode\u003e66923b4\u003c/code\u003e\u003c/a\u003e fix: preserve DNS origin hostname on sockets (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5577\"\u003e#5577\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/392649944c3b989681af1eae2e0970661f9ca464\"\u003e\u003ccode\u003e3926499\u003c/code\u003e\u003c/a\u003e fix: retry refused HTTP/2 streams (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5598\"\u003e#5598\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/73d6e9e19df47f85625d2dc082daa919ae6636c1\"\u003e\u003ccode\u003e73d6e9e\u003c/code\u003e\u003c/a\u003e fix(h2): detach upgrade close handler after GOAWAY (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5641\"\u003e#5641\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b111adbb675ebfcfa52790346dcd88e61c700818\"\u003e\u003ccode\u003eb111adb\u003c/code\u003e\u003c/a\u003e fix(mock): emit request body lifecycle hooks (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5367\"\u003e#5367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ae4a3e37a2ddfe798b64771176e31e8e7819c743\"\u003e\u003ccode\u003eae4a3e3\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/setup-node from 6.4.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5636\"\u003e#5636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ec3fbf19aa47eca6decc390b66bf56034bc03d52\"\u003e\u003ccode\u003eec3fbf1\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action/init from 4.36.2 to 4.37.3 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5634\"\u003e#5634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/21517200296205f3aa09a7b976dde571b441405c\"\u003e\u003ccode\u003e2151720\u003c/code\u003e\u003c/a\u003e build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5633\"\u003e#5633\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b96a11620e2f9fe5adafa2ba7b7f363b96b5a9d7\"\u003e\u003ccode\u003eb96a116\u003c/code\u003e\u003c/a\u003e fix(interceptors): allow interceptors without opts.origin (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5628\"\u003e#5628\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/a18ef2d05af48047339be51d8817492abc30f39d\"\u003e\u003ccode\u003ea18ef2d\u003c/code\u003e\u003c/a\u003e fix(mock): non-string path matchers under ignoreTrailingSlash, and DataView r...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v8.9.0...v8.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/DEFRA/epr-frontend/pull/1031","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/DEFRA%2Fepr-frontend/issues/1031","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1031/packages"}},{"old_version":"8.5.0","new_version":"8.9.0","update_type":"minor","path":null,"pr_created_at":"2026-08-10T10:41:22.000Z","version_change":"8.5.0 → 8.9.0","issue":{"uuid":"5109232884","node_id":"PR_kwDOKRXhvM789Q_K","number":6793,"state":"open","title":"chore(deps): bump the minor-and-patch group with 53 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-10T10:41:22.000Z","updated_at":"2026-08-10T10:41:37.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"minor-and-patch","update_count":53,"packages":[{"name":"@chakra-ui/react","old_version":"3.36.0","new_version":"3.36.1","repository_url":"https://github.com/chakra-ui/chakra-ui"},{"name":"@clickhouse/client","old_version":"1.23.0","new_version":"1.23.1","repository_url":"https://github.com/ClickHouse/clickhouse-js"},{"name":"@hono/node-server","old_version":"2.0.10","new_version":"2.0.12","repository_url":"https://github.com/honojs/node-server"},{"name":"@modelcontextprotocol/sdk","old_version":"1.29.0","new_version":"1.30.0","repository_url":"https://github.com/modelcontextprotocol/typescript-sdk"},{"name":"@react-email/render","old_version":"2.0.9","new_version":"2.1.0","repository_url":"https://github.com/resend/react-email"},{"name":"@smithy/node-http-handler","old_version":"4.9.12","new_version":"4.9.13","repository_url":"https://github.com/smithy-lang/smithy-typescript"},{"name":"better-auth","old_version":"1.6.23","new_version":"1.6.25","repository_url":"https://github.com/better-auth/better-auth"},{"name":"geoip-country","old_version":"5.0.202607010001","new_version":"5.0.202608010109","repository_url":"https://github.com/sapics/geoip-country"},{"name":"hono","old_version":"4.12.27","new_version":"4.12.33","repository_url":"https://github.com/honojs/hono"},{"name":"js-yaml","old_version":"5.2.1","new_version":"5.2.3","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"libphonenumber-js","old_version":"1.13.7","new_version":"1.13.10"},{"name":"liquidjs","old_version":"10.27.1","new_version":"10.28.0","repository_url":"https://github.com/harttle/liquidjs"},{"name":"marked","old_version":"18.0.5","new_version":"18.0.7","repository_url":"https://github.com/markedjs/marked"},{"name":"msgpackr","old_version":"2.0.4","new_version":"2.0.5","repository_url":"https://github.com/kriszyp/msgpackr"},{"name":"react-router","old_version":"8.1.0","new_version":"8.3.0","repository_url":"https://github.com/remix-run/react-router"},{"name":"sanitize-html","old_version":"2.17.5","new_version":"2.17.6","repository_url":"https://github.com/apostrophecms/apostrophe"},{"name":"undici","old_version":"8.5.0","new_version":"8.9.0","repository_url":"https://github.com/nodejs/undici"},{"name":"@biomejs/biome","old_version":"2.5.1","new_version":"2.5.6","repository_url":"https://github.com/biomejs/biome"},{"name":"@chakra-ui/charts","old_version":"3.36.0","new_version":"3.36.1","repository_url":"https://github.com/chakra-ui/chakra-ui"},{"name":"@hono/zod-validator","old_version":"0.4.3","new_version":"0.9.0","repository_url":"https://github.com/honojs/middleware"},{"name":"@hookform/resolvers","old_version":"5.4.0","new_version":"5.7.1","repository_url":"https://github.com/react-hook-form/resolvers"},{"name":"@microlink/react-json-view","old_version":"1.31.21","new_version":"1.31.25","repository_url":"https://github.com/microlinkhq/react-json-view"},{"name":"@paper-design/shaders-react","old_version":"0.0.76","new_version":"0.0.78"},{"name":"@playwright/test","old_version":"1.61.1","new_version":"1.62.1","repository_url":"https://github.com/microsoft/playwright"},{"name":"@tanstack/react-virtual","old_version":"3.14.5","new_version":"3.14.9","repository_url":"https://github.com/TanStack/virtual"},{"name":"@tiptap/extension-document","old_version":"3.27.1","new_version":"3.29.2","repository_url":"https://github.com/ueberdosis/tiptap"},{"name":"@tiptap/extension-history","old_version":"3.27.1","new_version":"3.29.2","repository_url":"https://github.com/ueberdosis/tiptap"},{"name":"@tiptap/extension-paragraph","old_version":"3.27.1","new_version":"3.29.2","repository_url":"https://github.com/ueberdosis/tiptap"},{"name":"@tiptap/extension-placeholder","old_version":"3.27.1","new_version":"3.29.2","repository_url":"https://github.com/ueberdosis/tiptap"},{"name":"@tiptap/extension-text","old_version":"3.27.1","new_version":"3.29.2","repository_url":"https://github.com/ueberdosis/tiptap"},{"name":"@tiptap/pm","old_version":"3.27.1","new_version":"3.29.2","repository_url":"https://github.com/ueberdosis/tiptap"},{"name":"@tiptap/react","old_version":"3.27.1","new_version":"3.29.2","repository_url":"https://github.com/ueberdosis/tiptap"},{"name":"@vitejs/plugin-react","old_version":"6.0.3","new_version":"6.0.5","repository_url":"https://github.com/vitejs/vite-plugin-react"},{"name":"@xyflow/react","old_version":"12.11.1","new_version":"12.11.2","repository_url":"https://github.com/xyflow/xyflow"},{"name":"immer","old_version":"11.1.8","new_version":"11.1.15","repository_url":"https://github.com/immerjs/immer"},{"name":"lucide-react","old_version":"1.22.0","new_version":"1.28.0","repository_url":"https://github.com/lucide-icons/lucide"},{"name":"monaco-editor","old_version":"0.55.1","new_version":"0.56.0","repository_url":"https://github.com/microsoft/monaco-editor"},{"name":"motion","old_version":"12.42.2","new_version":"12.43.0","repository_url":"https://github.com/motiondivision/motion"},{"name":"node-mocks-http","old_version":"1.17.2","new_version":"1.18.1","repository_url":"https://github.com/eugef/node-mocks-http"},{"name":"playwright","old_version":"1.61.1","new_version":"1.62.1","repository_url":"https://github.com/microsoft/playwright"},{"name":"react-hook-form","old_version":"7.80.0","new_version":"7.84.0","repository_url":"https://github.com/react-hook-form/react-hook-form"},{"name":"recharts","old_version":"3.9.1","new_version":"3.10.1","repository_url":"https://github.com/recharts/recharts"},{"name":"rich-textarea","old_version":"0.27.0","new_version":"0.27.1","repository_url":"https://github.com/inokawa/rich-textarea"},{"name":"sass","old_version":"1.101.0","new_version":"1.102.0","repository_url":"https://github.com/sass/dart-sass"},{"name":"shiki","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/shikijs/shiki"},{"name":"simple-statistics","old_version":"7.9.2","new_version":"7.9.3","repository_url":"https://github.com/simple-statistics/simple-statistics"},{"name":"tsx","old_version":"4.22.4","new_version":"4.23.1","repository_url":"https://github.com/privatenumber/tsx"},{"name":"vite","old_version":"8.1.2","new_version":"8.2.0","repository_url":"https://github.com/vitejs/vite"},{"name":"@rollup/rollup-linux-x64-gnu","old_version":"4.62.2","new_version":"4.62.4","repository_url":"https://github.com/rollup/rollup"},{"name":"tar","old_version":"7.5.21","new_version":"7.5.22","repository_url":"https://github.com/isaacs/node-tar"},{"name":"typescript-eslint","old_version":"8.58.1","new_version":"8.65.0","repository_url":"https://github.com/typescript-eslint/typescript-eslint"},{"name":"yargs","old_version":"18.0.0","new_version":"18.1.0","repository_url":"https://github.com/yargs/yargs"},{"name":"nock","old_version":"14.0.16","new_version":"14.0.17","repository_url":"https://github.com/nock/nock"}],"path":null,"ecosystem":"npm"},"body":"Bumps the minor-and-patch group with 53 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@chakra-ui/react](https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react) | `3.36.0` | `3.36.1` |\n| [@clickhouse/client](https://github.com/ClickHouse/clickhouse-js) | `1.23.0` | `1.23.1` |\n| [@hono/node-server](https://github.com/honojs/node-server) | `2.0.10` | `2.0.12` |\n| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.29.0` | `1.30.0` |\n| [@react-email/render](https://github.com/resend/react-email/tree/HEAD/packages/render) | `2.0.9` | `2.1.0` |\n| [@smithy/node-http-handler](https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/node-http-handler) | `4.9.12` | `4.9.13` |\n| [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) | `1.6.23` | `1.6.25` |\n| [geoip-country](https://github.com/sapics/geoip-country) | `5.0.202607010001` | `5.0.202608010109` |\n| [hono](https://github.com/honojs/hono) | `4.12.27` | `4.12.33` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `5.2.1` | `5.2.3` |\n| [libphonenumber-js](https://gitlab.com/catamphetamine/libphonenumber-js) | `1.13.7` | `1.13.10` |\n| [liquidjs](https://github.com/harttle/liquidjs) | `10.27.1` | `10.28.0` |\n| [marked](https://github.com/markedjs/marked) | `18.0.5` | `18.0.7` |\n| [msgpackr](https://github.com/kriszyp/msgpackr) | `2.0.4` | `2.0.5` |\n| [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router) | `8.1.0` | `8.3.0` |\n| [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) | `2.17.5` | `2.17.6` |\n| [undici](https://github.com/nodejs/undici) | `8.5.0` | `8.9.0` |\n| [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) | `2.5.1` | `2.5.6` |\n| [@chakra-ui/charts](https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/charts) | `3.36.0` | `3.36.1` |\n| [@hono/zod-validator](https://github.com/honojs/middleware/tree/HEAD/packages/zod-validator) | `0.4.3` | `0.9.0` |\n| [@hookform/resolvers](https://github.com/react-hook-form/resolvers) | `5.4.0` | `5.7.1` |\n| [@microlink/react-json-view](https://github.com/microlinkhq/react-json-view) | `1.31.21` | `1.31.25` |\n| @paper-design/shaders-react | `0.0.76` | `0.0.78` |\n| [@playwright/test](https://github.com/microsoft/playwright) | `1.61.1` | `1.62.1` |\n| [@tanstack/react-virtual](https://github.com/TanStack/virtual/tree/HEAD/packages/react-virtual) | `3.14.5` | `3.14.9` |\n| [@tiptap/extension-document](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-document) | `3.27.1` | `3.29.2` |\n| [@tiptap/extension-history](https://github.com/ueberdosis/tiptap/tree/HEAD/packages-deprecated/extension-history) | `3.27.1` | `3.29.2` |\n| [@tiptap/extension-paragraph](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-paragraph) | `3.27.1` | `3.29.2` |\n| [@tiptap/extension-placeholder](https://github.com/ueberdosis/tiptap/tree/HEAD/packages-deprecated/extension-placeholder) | `3.27.1` | `3.29.2` |\n| [@tiptap/extension-text](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-text) | `3.27.1` | `3.29.2` |\n| [@tiptap/pm](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/pm) | `3.27.1` | `3.29.2` |\n| [@tiptap/react](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/react) | `3.27.1` | `3.29.2` |\n| [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) | `6.0.3` | `6.0.5` |\n| [@xyflow/react](https://github.com/xyflow/xyflow/tree/HEAD/packages/react) | `12.11.1` | `12.11.2` |\n| [immer](https://github.com/immerjs/immer) | `11.1.8` | `11.1.15` |\n| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.22.0` | `1.28.0` |\n| [monaco-editor](https://github.com/microsoft/monaco-editor) | `0.55.1` | `0.56.0` |\n| [motion](https://github.com/motiondivision/motion) | `12.42.2` | `12.43.0` |\n| [node-mocks-http](https://github.com/eugef/node-mocks-http) | `1.17.2` | `1.18.1` |\n| [playwright](https://github.com/microsoft/playwright) | `1.61.1` | `1.62.1` |\n| [react-hook-form](https://github.com/react-hook-form/react-hook-form) | `7.80.0` | `7.84.0` |\n| [recharts](https://github.com/recharts/recharts) | `3.9.1` | `3.10.1` |\n| [rich-textarea](https://github.com/inokawa/rich-textarea) | `0.27.0` | `0.27.1` |\n| [sass](https://github.com/sass/dart-sass) | `1.101.0` | `1.102.0` |\n| [shiki](https://github.com/shikijs/shiki/tree/HEAD/packages/shiki) | `4.3.0` | `4.4.1` |\n| [simple-statistics](https://github.com/simple-statistics/simple-statistics) | `7.9.2` | `7.9.3` |\n| [tsx](https://github.com/privatenumber/tsx) | `4.22.4` | `4.23.1` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.1.2` | `8.2.0` |\n| [@rollup/rollup-linux-x64-gnu](https://github.com/rollup/rollup) | `4.62.2` | `4.62.4` |\n| [tar](https://github.com/isaacs/node-tar) | `7.5.21` | `7.5.22` |\n| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.58.1` | `8.65.0` |\n| [yargs](https://github.com/yargs/yargs) | `18.0.0` | `18.1.0` |\n| [nock](https://github.com/nock/nock) | `14.0.16` | `14.0.17` |\n\nUpdates `@chakra-ui/react` from 3.36.0 to 3.36.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/chakra-ui/chakra-ui/releases\"\u003e@​chakra-ui/react's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​chakra-ui/react\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.36.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10868\"\u003e#10868\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/f32a160162ba9523f93080587df086a99ca5bfdc\"\u003e\u003ccode\u003ef32a160\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/WahabKhan7528\"\u003e\u003ccode\u003e@​WahabKhan7528\u003c/code\u003e\u003c/a\u003e! -\n\u003cstrong\u003eOverlayManager\u003c/strong\u003e: add has() method to createOverlay return\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10885\"\u003e#10885\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/e503f8d9f403b7dac71ee586857037d791e7ee8c\"\u003e\u003ccode\u003ee503f8d\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/dfedoryshchev\"\u003e\u003ccode\u003e@​dfedoryshchev\u003c/code\u003e\u003c/a\u003e! - - Bleed: Fix\nincorrect css prop application\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/129c50ff9be80fa4ad5cc0a39b6cff8a20609c42\"\u003e\u003ccode\u003e129c50f\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/segunadebayo\"\u003e\u003ccode\u003e@​segunadebayo\u003c/code\u003e\u003c/a\u003e! - Fix issue where the\nchecked ring of \u003ccode\u003eRadioCard\u003c/code\u003e and \u003ccode\u003eCheckboxCard\u003c/code\u003e (outline variant) gets clipped\nwhen a parent has \u003ccode\u003eoverflow: hidden|auto|scroll\u003c/code\u003e. The ring is now drawn with\nan inset shadow instead of an outer shadow.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10859\"\u003e#10859\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/6f102700bdf5fd4e61971db77e65f1516ce8ab38\"\u003e\u003ccode\u003e6f10270\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/dfedoryshchev\"\u003e\u003ccode\u003e@​dfedoryshchev\u003c/code\u003e\u003c/a\u003e! - - Checkmark: Fix\nincorrect css prop application\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10884\"\u003e#10884\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/e7431f1c9e05cb698492c65c6d72aca2e8c1151c\"\u003e\u003ccode\u003ee7431f1\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/sanjibani\"\u003e\u003ccode\u003e@​sanjibani\u003c/code\u003e\u003c/a\u003e! - - Docs: fix\n\u003ccode\u003eStack.Separator\u003c/code\u003e references in the v3 migration guide. The standalone\n\u003ccode\u003eSeparator\u003c/code\u003e component is now used in both the \u003ccode\u003eStackDivider\u003c/code\u003e and \u003ccode\u003eStack Props\u003c/code\u003e\nexamples.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/0fe305592d90bf943b27b7a40668e4bf1648cb29\"\u003e\u003ccode\u003e0fe3055\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/segunadebayo\"\u003e\u003ccode\u003e@​segunadebayo\u003c/code\u003e\u003c/a\u003e! - Fix error when\nmerging recipes (e.g. composing a recipe-based component through the \u003ccode\u003echakra\u003c/code\u003e\nfactory). Recipe merging now normalizes compiled and raw configs before\ncombining them, and no longer throws or mutates the source configs.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10879\"\u003e#10879\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/e882dc0e714be7d37d7a1fd93fce8ed08fe7905d\"\u003e\u003ccode\u003ee882dc0\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/dfedoryshchev\"\u003e\u003ccode\u003e@​dfedoryshchev\u003c/code\u003e\u003c/a\u003e! - - Float: Fix\nincorrect css prop application\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/2ed9026862cf1d816e981746d723256bcbd59159\"\u003e\u003ccode\u003e2ed9026\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/segunadebayo\"\u003e\u003ccode\u003e@​segunadebayo\u003c/code\u003e\u003c/a\u003e! - Add a default\n\u003ccode\u003eminSize\u003c/code\u003e of \u003ccode\u003e{ width: 240, height: 100 }\u003c/code\u003e to \u003ccode\u003eFloatingPanel.Root\u003c/code\u003e to prevent\nthe panel from being resized to zero. Pass your own \u003ccode\u003eminSize\u003c/code\u003e to override it.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10863\"\u003e#10863\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/b5de5e246bdecfeb9326c301c3cc397cc2cd676d\"\u003e\u003ccode\u003eb5de5e2\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/dfedoryshchev\"\u003e\u003ccode\u003e@​dfedoryshchev\u003c/code\u003e\u003c/a\u003e! - - Image: Fix\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/chakra-ui/chakra-ui/blob/main/packages/react/CHANGELOG.md\"\u003e@​chakra-ui/react's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.36.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10868\"\u003e#10868\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/f32a160162ba9523f93080587df086a99ca5bfdc\"\u003e\u003ccode\u003ef32a160\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/WahabKhan7528\"\u003e\u003ccode\u003e@​WahabKhan7528\u003c/code\u003e\u003c/a\u003e! -\n\u003cstrong\u003eOverlayManager\u003c/strong\u003e: add has() method to createOverlay return\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10885\"\u003e#10885\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/e503f8d9f403b7dac71ee586857037d791e7ee8c\"\u003e\u003ccode\u003ee503f8d\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/dfedoryshchev\"\u003e\u003ccode\u003e@​dfedoryshchev\u003c/code\u003e\u003c/a\u003e! - - Bleed: Fix\nincorrect css prop application\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/129c50ff9be80fa4ad5cc0a39b6cff8a20609c42\"\u003e\u003ccode\u003e129c50f\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/segunadebayo\"\u003e\u003ccode\u003e@​segunadebayo\u003c/code\u003e\u003c/a\u003e! - Fix issue where the\nchecked ring of \u003ccode\u003eRadioCard\u003c/code\u003e and \u003ccode\u003eCheckboxCard\u003c/code\u003e (outline variant) gets clipped\nwhen a parent has \u003ccode\u003eoverflow: hidden|auto|scroll\u003c/code\u003e. The ring is now drawn with\nan inset shadow instead of an outer shadow.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10859\"\u003e#10859\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/6f102700bdf5fd4e61971db77e65f1516ce8ab38\"\u003e\u003ccode\u003e6f10270\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/dfedoryshchev\"\u003e\u003ccode\u003e@​dfedoryshchev\u003c/code\u003e\u003c/a\u003e! - - Checkmark: Fix\nincorrect css prop application\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10884\"\u003e#10884\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/e7431f1c9e05cb698492c65c6d72aca2e8c1151c\"\u003e\u003ccode\u003ee7431f1\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/sanjibani\"\u003e\u003ccode\u003e@​sanjibani\u003c/code\u003e\u003c/a\u003e! - - Docs: fix\n\u003ccode\u003eStack.Separator\u003c/code\u003e references in the v3 migration guide. The standalone\n\u003ccode\u003eSeparator\u003c/code\u003e component is now used in both the \u003ccode\u003eStackDivider\u003c/code\u003e and \u003ccode\u003eStack Props\u003c/code\u003e\nexamples.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/0fe305592d90bf943b27b7a40668e4bf1648cb29\"\u003e\u003ccode\u003e0fe3055\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/segunadebayo\"\u003e\u003ccode\u003e@​segunadebayo\u003c/code\u003e\u003c/a\u003e! - Fix error when\nmerging recipes (e.g. composing a recipe-based component through the \u003ccode\u003echakra\u003c/code\u003e\nfactory). Recipe merging now normalizes compiled and raw configs before\ncombining them, and no longer throws or mutates the source configs.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10879\"\u003e#10879\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/e882dc0e714be7d37d7a1fd93fce8ed08fe7905d\"\u003e\u003ccode\u003ee882dc0\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/dfedoryshchev\"\u003e\u003ccode\u003e@​dfedoryshchev\u003c/code\u003e\u003c/a\u003e! - - Float: Fix\nincorrect css prop application\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/2ed9026862cf1d816e981746d723256bcbd59159\"\u003e\u003ccode\u003e2ed9026\u003c/code\u003e\u003c/a\u003e\nThanks \u003ca href=\"https://github.com/segunadebayo\"\u003e\u003ccode\u003e@​segunadebayo\u003c/code\u003e\u003c/a\u003e! - Add a default\n\u003ccode\u003eminSize\u003c/code\u003e of \u003ccode\u003e{ width: 240, height: 100 }\u003c/code\u003e to \u003ccode\u003eFloatingPanel.Root\u003c/code\u003e to prevent\nthe panel from being resized to zero. Pass your own \u003ccode\u003eminSize\u003c/code\u003e to override it.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/chakra-ui/chakra-ui/pull/10863\"\u003e#10863\u003c/a\u003e\n\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/b5de5e246bdecfeb9326c301c3cc397cc2cd676d\"\u003e\u003ccode\u003eb5de5e2\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/f8133940accf0b7de1f7c9ac4aca37e9be5e2027\"\u003e\u003ccode\u003ef813394\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react/issues/10857\"\u003e#10857\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/e503f8d9f403b7dac71ee586857037d791e7ee8c\"\u003e\u003ccode\u003ee503f8d\u003c/code\u003e\u003c/a\u003e fix: correct css prop usage in Bleed component (\u003ca href=\"https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react/issues/10885\"\u003e#10885\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/0fe305592d90bf943b27b7a40668e4bf1648cb29\"\u003e\u003ccode\u003e0fe3055\u003c/code\u003e\u003c/a\u003e perf(react): cache compiled recipes and memoize variant resolution\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/e882dc0e714be7d37d7a1fd93fce8ed08fe7905d\"\u003e\u003ccode\u003ee882dc0\u003c/code\u003e\u003c/a\u003e fix: correct css prop usage in Float component (\u003ca href=\"https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react/issues/10879\"\u003e#10879\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/ff2067e7ad5f08017f7c17bf047a92f9ff2a215a\"\u003e\u003ccode\u003eff2067e\u003c/code\u003e\u003c/a\u003e fix(deps): update non-major dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/c4e79c122a6500f5f68f1c00a826c315a808d511\"\u003e\u003ccode\u003ec4e79c1\u003c/code\u003e\u003c/a\u003e fix: forward the rel attribute on LinkOverlay (\u003ca href=\"https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react/issues/10873\"\u003e#10873\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/f32a160162ba9523f93080587df086a99ca5bfdc\"\u003e\u003ccode\u003ef32a160\u003c/code\u003e\u003c/a\u003e feat(overlay): add has() method to createOverlay return (\u003ca href=\"https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react/issues/10868\"\u003e#10868\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/a1548ba60c3ad95d5b236843528e0aca30c165bc\"\u003e\u003ccode\u003ea1548ba\u003c/code\u003e\u003c/a\u003e fix: correct misspelled \u0026quot;permuations\u0026quot; variable in breakpoints (\u003ca href=\"https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react/issues/10864\"\u003e#10864\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/b5de5e246bdecfeb9326c301c3cc397cc2cd676d\"\u003e\u003ccode\u003eb5de5e2\u003c/code\u003e\u003c/a\u003e fix: correct className usage in Image component (\u003ca href=\"https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react/issues/10863\"\u003e#10863\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chakra-ui/chakra-ui/commit/6f102700bdf5fd4e61971db77e65f1516ce8ab38\"\u003e\u003ccode\u003e6f10270\u003c/code\u003e\u003c/a\u003e fix: correct css prop usage in Checkmark component (\u003ca href=\"https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react/issues/10859\"\u003e#10859\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/chakra-ui/chakra-ui/commits/@chakra-ui/react@3.36.1/packages/react\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@clickhouse/client` from 1.23.0 to 1.23.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ClickHouse/clickhouse-js/releases\"\u003e@​clickhouse/client's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eclient-1.23.1\u003c/h2\u003e\n\u003ch2\u003eBug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRe-export \u003ccode\u003eEXCEPTION_TAG_HEADER_NAME\u003c/code\u003e and \u003ccode\u003eextractErrorAtTheEndOfChunk\u003c/code\u003e from \u003ccode\u003e@clickhouse/client\u003c/code\u003e. Both are part of the (now deprecated) \u003ccode\u003e@clickhouse/client-common\u003c/code\u003e public API but were missed when its surface was bundled into and re-exported from the client packages in 1.23.0 (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/845\"\u003e#845\u003c/a\u003e). Reported downstream by Langfuse. (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/935\"\u003e#935\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/935\"\u003e#935\u003c/a\u003e: \u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/pull/935\"\u003eClickHouse/clickhouse-js#935\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/845\"\u003e#845\u003c/a\u003e: \u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/pull/845\"\u003eClickHouse/clickhouse-js#845\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eclient-web-1.23.1\u003c/h2\u003e\n\u003ch2\u003eBug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRe-export \u003ccode\u003eEXCEPTION_TAG_HEADER_NAME\u003c/code\u003e and \u003ccode\u003eextractErrorAtTheEndOfChunk\u003c/code\u003e from \u003ccode\u003e@clickhouse/client-web\u003c/code\u003e. Both are part of the (now deprecated) \u003ccode\u003e@clickhouse/client-common\u003c/code\u003e public API but were missed when its surface was bundled into and re-exported from the client packages in 1.23.0 (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/845\"\u003e#845\u003c/a\u003e). Reported downstream by Langfuse. (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/935\"\u003e#935\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/935\"\u003e#935\u003c/a\u003e: \u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/pull/935\"\u003eClickHouse/clickhouse-js#935\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/845\"\u003e#845\u003c/a\u003e: \u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/pull/845\"\u003eClickHouse/clickhouse-js#845\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ClickHouse/clickhouse-js/blob/main/CHANGELOG.md\"\u003e@​clickhouse/client's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\n\u003cstrong\u003eThis repository-wide changelog is frozen.\u003c/strong\u003e New entries now live in each\npackage's own \u003ccode\u003eCHANGELOG.md\u003c/code\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@clickhouse/client\u003c/code\u003e → \u003ca href=\"https://github.com/ClickHouse/clickhouse-js/blob/main/packages/client-node/CHANGELOG.md\"\u003e\u003ccode\u003ehttps://github.com/ClickHouse/clickhouse-js/blob/main/packages/client-node/CHANGELOG.md\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@clickhouse/client-web\u003c/code\u003e → \u003ca href=\"https://github.com/ClickHouse/clickhouse-js/blob/main/packages/client-web/CHANGELOG.md\"\u003e\u003ccode\u003ehttps://github.com/ClickHouse/clickhouse-js/blob/main/packages/client-web/CHANGELOG.md\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@clickhouse/client-common\u003c/code\u003e (deprecated) → \u003ca href=\"https://github.com/ClickHouse/clickhouse-js/blob/main/packages/client-common/CHANGELOG.md\"\u003e\u003ccode\u003ehttps://github.com/ClickHouse/clickhouse-js/blob/main/packages/client-common/CHANGELOG.md\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@clickhouse/datatype-parser\u003c/code\u003e → \u003ca href=\"https://github.com/ClickHouse/clickhouse-js/blob/main/packages/datatype-parser/CHANGELOG.md\"\u003e\u003ccode\u003ehttps://github.com/ClickHouse/clickhouse-js/blob/main/packages/datatype-parser/CHANGELOG.md\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@clickhouse/rowbinary\u003c/code\u003e → \u003ca href=\"https://github.com/ClickHouse/clickhouse-js/blob/main/skills/clickhouse-js-node-rowbinary-parser/CHANGELOG.md\"\u003e\u003ccode\u003ehttps://github.com/ClickHouse/clickhouse-js/blob/main/skills/clickhouse-js-node-rowbinary-parser/CHANGELOG.md\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe history below (through \u003ccode\u003e@clickhouse/client\u003c/code\u003e 1.23.0) is retained for\nreference and was copied as-is into each client package's changelog as the\nstarting point for the split.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/f67717b944dd4b0451468602cdad9bd3ecad7dd8\"\u003e\u003ccode\u003ef67717b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/941\"\u003e#941\u003c/a\u003e from ClickHouse/main\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/3bccc8139f96a38a80c0cc27d8e22d4820be6181\"\u003e\u003ccode\u003e3bccc81\u003c/code\u003e\u003c/a\u003e chore: bump \u003ccode\u003e@​clickhouse/client-web\u003c/code\u003e version to 1.23.1 (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/940\"\u003e#940\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/cc9383c9576f23fbdb7914f3d01c5c4ef03899d1\"\u003e\u003ccode\u003ecc9383c\u003c/code\u003e\u003c/a\u003e chore: bump \u003ccode\u003e@​clickhouse/client\u003c/code\u003e version to 1.23.1 (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/939\"\u003e#939\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/8415878d0cdd86c3b39bdd635b194108e1a0df07\"\u003e\u003ccode\u003e8415878\u003c/code\u003e\u003c/a\u003e fix(ci): lockfile-age-audit — request full packument so time is present (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/888\"\u003e#888\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/71b2e8a1ac80dacd75b11927926140754e1e64b7\"\u003e\u003ccode\u003e71b2e8a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/936\"\u003e#936\u003c/a\u003e from ClickHouse/main\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/a417d5c051ba5768bc2cc2cbdadff0e14a41e1b6\"\u003e\u003ccode\u003ea417d5c\u003c/code\u003e\u003c/a\u003e fix(client): re-export EXCEPTION_TAG_HEADER_NAME and extractErrorAtTheEndOfCh...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/305030d9714aca93e9b5f7e128408d7e41867bd0\"\u003e\u003ccode\u003e305030d\u003c/code\u003e\u003c/a\u003e Separate per-package READMEs and stop prepack from overwriting them (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/934\"\u003e#934\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/8c51d9a12e67e82ef431e8158d5b77ce26e40e3a\"\u003e\u003ccode\u003e8c51d9a\u003c/code\u003e\u003c/a\u003e ci: run RowBinary skill benchmarks on a live ClickHouse (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/933\"\u003e#933\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/199f99460ab2fda2c87544bd4a7dad8e7509f60f\"\u003e\u003ccode\u003e199f994\u003c/code\u003e\u003c/a\u003e Embed Vitest configs into client packages; run common tests from node/web (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/931\"\u003e#931\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ClickHouse/clickhouse-js/commit/ed25b25893241eda007bf4412dee16f0d650de1a\"\u003e\u003ccode\u003eed25b25\u003c/code\u003e\u003c/a\u003e Run web Vitest browser tests headless by default (\u003ca href=\"https://redirect.github.com/ClickHouse/clickhouse-js/issues/930\"\u003e#930\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/ClickHouse/clickhouse-js/compare/client-1.23.0...client-1.23.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@hono/node-server` from 2.0.10 to 2.0.12\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/honojs/node-server/releases\"\u003e@​hono/node-server's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.0.12\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etest: replace supertest by \u003ca href=\"https://github.com/BlankParticle\"\u003e\u003ccode\u003e@​BlankParticle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/379\"\u003ehonojs/node-server#379\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(response): copy headers when init is a foreign Response by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/382\"\u003ehonojs/node-server#382\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v2.0.11...v2.0.12\"\u003ehttps://github.com/honojs/node-server/compare/v2.0.11...v2.0.12\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.0.11\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etest: use a custom helper for path traversal tests by \u003ca href=\"https://github.com/BlankParticle\"\u003e\u003ccode\u003e@​BlankParticle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/377\"\u003ehonojs/node-server#377\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf(request): fast-path QUERY methods by \u003ca href=\"https://github.com/usualoma\"\u003e\u003ccode\u003e@​usualoma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/376\"\u003ehonojs/node-server#376\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf(request): fast-path PATCH method by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/380\"\u003ehonojs/node-server#380\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v2.0.10...v2.0.11\"\u003ehttps://github.com/honojs/node-server/compare/v2.0.10...v2.0.11\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/a813b6cdaa15baac3ead84e9e6ed5b72b2353c96\"\u003e\u003ccode\u003ea813b6c\u003c/code\u003e\u003c/a\u003e 2.0.12\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/caf48bafd4638bac5c338166b8858b72bcf79257\"\u003e\u003ccode\u003ecaf48ba\u003c/code\u003e\u003c/a\u003e fix(response): copy headers when init is a foreign Response (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/382\"\u003e#382\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/3b1dd6875812e0b5aee43ec3fac66c191fd6251f\"\u003e\u003ccode\u003e3b1dd68\u003c/code\u003e\u003c/a\u003e test: replace supertest (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/379\"\u003e#379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/834e54f15cf12b80cf82823c845b2bab41056cf0\"\u003e\u003ccode\u003e834e54f\u003c/code\u003e\u003c/a\u003e 2.0.11\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/ba72bcd8c563fbe1e9678e7ef27794a0aa4a6158\"\u003e\u003ccode\u003eba72bcd\u003c/code\u003e\u003c/a\u003e perf(request): fast-path PATCH method (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/380\"\u003e#380\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/962baa463879da394008f27510d68dc90b640e99\"\u003e\u003ccode\u003e962baa4\u003c/code\u003e\u003c/a\u003e perf(request): fast-path QUERY methods (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/376\"\u003e#376\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/62284d659380cb0354510d0359c160c8d970764d\"\u003e\u003ccode\u003e62284d6\u003c/code\u003e\u003c/a\u003e test: use a custom helper for path traversal tests (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/377\"\u003e#377\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/honojs/node-server/compare/v2.0.10...v2.0.12\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@modelcontextprotocol/sdk` from 1.29.0 to 1.30.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/releases\"\u003e@​modelcontextprotocol/sdk's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.30.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(server): prioritize zod issues and format them by \u003ca href=\"https://github.com/mozmo15\"\u003e\u003ccode\u003e@​mozmo15\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1503\"\u003emodelcontextprotocol/typescript-sdk#1503\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(ci): switch publish to OIDC trusted publishing by \u003ca href=\"https://github.com/felixweinberger\"\u003e\u003ccode\u003e@​felixweinberger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1839\"\u003emodelcontextprotocol/typescript-sdk#1839\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd end-to-end test suite by \u003ca href=\"https://github.com/felixweinberger\"\u003e\u003ccode\u003e@​felixweinberger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2167\"\u003emodelcontextprotocol/typescript-sdk#2167\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ev1 stdio buffer limit by \u003ca href=\"https://github.com/KKonstantinov\"\u003e\u003ccode\u003e@​KKonstantinov\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2239\"\u003emodelcontextprotocol/typescript-sdk#2239\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: support Zod 3.25 method literals by \u003ca href=\"https://github.com/mattzcarey\"\u003e\u003ccode\u003e@​mattzcarey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2368\"\u003emodelcontextprotocol/typescript-sdk#2368\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eValidate Content-Type by parsed media type instead of substring match (v1.x) by \u003ca href=\"https://github.com/felixweinberger\"\u003e\u003ccode\u003e@​felixweinberger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2444\"\u003emodelcontextprotocol/typescript-sdk#2444\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: send SSE keep-alive comment frames from Streamable HTTP server transport (v1.x) by \u003ca href=\"https://github.com/mattzcarey\"\u003e\u003ccode\u003e@​mattzcarey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2538\"\u003emodelcontextprotocol/typescript-sdk#2538\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(deps): widen \u003ccode\u003e@​hono/node-server\u003c/code\u003e past GHSA-frvp-7c67-39w9 by \u003ca href=\"https://github.com/arimu1\"\u003e\u003ccode\u003e@​arimu1\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2549\"\u003emodelcontextprotocol/typescript-sdk#2549\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix SSE keep-alive timer lifecycle in Streamable HTTP server transport (v1.x) by \u003ca href=\"https://github.com/felixweinberger\"\u003e\u003ccode\u003e@​felixweinberger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2547\"\u003emodelcontextprotocol/typescript-sdk#2547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump version to 1.30.0 by \u003ca href=\"https://github.com/felixweinberger\"\u003e\u003ccode\u003e@​felixweinberger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2563\"\u003emodelcontextprotocol/typescript-sdk#2563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mozmo15\"\u003e\u003ccode\u003e@​mozmo15\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1503\"\u003emodelcontextprotocol/typescript-sdk#1503\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/arimu1\"\u003e\u003ccode\u003e@​arimu1\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2549\"\u003emodelcontextprotocol/typescript-sdk#2549\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.29.0...1.30.0\"\u003ehttps://github.com/modelcontextprotocol/typescript-sdk/compare/v1.29.0...1.30.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/2d889f2b329e46680ec9bdd565de4616c497825a\"\u003e\u003ccode\u003e2d889f2\u003c/code\u003e\u003c/a\u003e chore: bump version to 1.30.0 (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/2563\"\u003e#2563\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/e3f3daa12cc2603919939b72136ce9d9e800b868\"\u003e\u003ccode\u003ee3f3daa\u003c/code\u003e\u003c/a\u003e Fix SSE keep-alive timer lifecycle in Streamable HTTP server transport (v1.x)...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/bb5a718cbf90796bacbf62218b359196d210426b\"\u003e\u003ccode\u003ebb5a718\u003c/code\u003e\u003c/a\u003e fix(deps): widen \u003ccode\u003e@​hono/node-server\u003c/code\u003e past GHSA-frvp-7c67-39w9 (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/2549\"\u003e#2549\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/1dad2634ce5799fb386283d14291d1b4935a9a52\"\u003e\u003ccode\u003e1dad263\u003c/code\u003e\u003c/a\u003e fix: send SSE keep-alive comment frames from Streamable HTTP server transport...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/69749aa5081ddfe675d36da8d96c7e27d83742b8\"\u003e\u003ccode\u003e69749aa\u003c/code\u003e\u003c/a\u003e Validate Content-Type by parsed media type instead of substring match (v1.x) ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/369513df7b0e9d8a979c86f68ba1930e0d5f27f0\"\u003e\u003ccode\u003e369513d\u003c/code\u003e\u003c/a\u003e fix: support Zod 3.25 method literals (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/2368\"\u003e#2368\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/e7ee57c2f33b8290a78a3cefa27ab635fe67fbff\"\u003e\u003ccode\u003ee7ee57c\u003c/code\u003e\u003c/a\u003e v1 stdio buffer limit (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/2239\"\u003e#2239\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/c36e1ef5bb3b07b0c23fc6d28d4a6b56ebdd9512\"\u003e\u003ccode\u003ec36e1ef\u003c/code\u003e\u003c/a\u003e Add end-to-end test suite (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/2167\"\u003e#2167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/bf1e022bd219f678b3865093d58595c6c8a67f1a\"\u003e\u003ccode\u003ebf1e022\u003c/code\u003e\u003c/a\u003e chore(ci): switch publish to OIDC trusted publishing (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1839\"\u003e#1839\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/9edbab7a09f31a288a27df3220edbebff45dbb6c\"\u003e\u003ccode\u003e9edbab7\u003c/code\u003e\u003c/a\u003e fix(server): prioritize zod issues and format them (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1503\"\u003e#1503\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.29.0...1.30.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​modelcontextprotocol/sdk\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@react-email/render` from 2.0.9 to 2.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/resend/react-email/releases\"\u003e@​react-email/render's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​react-email/render\u003c/code\u003e\u003ca href=\"https://github.com/2\"\u003e\u003ccode\u003e@​2\u003c/code\u003e\u003c/a\u003e.1.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eba96cfa: introduce new \u003ccode\u003eunstableToPlainText\u003c/code\u003e and \u003ccode\u003eunstableTextConversion\u003c/code\u003e that sidesteps html-to-text\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e58d8c08: feat: add \u003ccode\u003edata-text-format=\u0026quot;dataTable\u0026quot;\u003c/code\u003e to render tables as aligned columns in plain text\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ccode\u003e@​react-email/render\u003c/code\u003e\u003ca href=\"https://github.com/2\"\u003e\u003ccode\u003e@​2\u003c/code\u003e\u003c/a\u003e.0.10\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ec300cfb: Strip React's auto-injected \u003ccode\u003e\u0026lt;link rel=\u0026quot;preload\u0026quot; as=\u0026quot;image\u0026quot;\u0026gt;\u003c/code\u003e resource hints from rendered email HTML. React adds one to the document \u003ccode\u003e\u0026lt;head\u0026gt;\u003c/code\u003e for every \u003ccode\u003e\u0026lt;img\u0026gt;\u003c/code\u003e during SSR, but email clients ignore preload hints, so they were just noise in the output. Other \u003ccode\u003e\u0026lt;link\u0026gt;\u003c/code\u003e tags (stylesheets, fonts, user-authored non-image preloads) are left untouched.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/resend/react-email/blob/canary/packages/render/CHANGELOG.md\"\u003e@​react-email/render's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.1.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eba96cfa: introduce new \u003ccode\u003eunstableToPlainText\u003c/code\u003e and \u003ccode\u003eunstableTextConversion\u003c/code\u003e that sidesteps html-to-text\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e58d8c08: feat: add \u003ccode\u003edata-text-format=\u0026quot;dataTable\u0026quot;\u003c/code\u003e to render tables as aligned columns in plain text\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.0.10\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ec300cfb: Strip React's auto-injected \u003ccode\u003e\u0026lt;link rel=\u0026quot;preload\u0026quot; as=\u0026quot;image\u0026quot;\u0026gt;\u003c/code\u003e resource hints from rendered email HTML. React adds one to the document \u003ccode\u003e\u0026lt;head\u0026gt;\u003c/code\u003e for every \u003ccode\u003e\u0026lt;img\u0026gt;\u003c/code\u003e during SSR, but email clients ignore preload hints, so they were just noise in the output. Other \u003ccode\u003e\u0026lt;link\u0026gt;\u003c/code\u003e tags (stylesheets, fonts, user-authored non-image preloads) are left untouched.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/resend/react-email/commit/a8ccfeca4cf99dff7bbb13e6a067c4b4d0e141a1\"\u003e\u003ccode\u003ea8ccfec\u003c/code\u003e\u003c/a\u003e chore(root): version packages (\u003ca href=\"https://github.com/resend/react-email/tree/HEAD/packages/render/issues/3640\"\u003e#3640\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/resend/react-email/commit/ba96cfa29bd45fafd364d936b8ad3fe510deb84c\"\u003e\u003ccode\u003eba96cfa\u003c/code\u003e\u003c/a\u003e feat(render): new \u003ccode\u003eunstableToPlainText\u003c/code\u003e and \u003ccode\u003eunstableTextConversion\u003c/code\u003e (\u003ca href=\"https://github.com/resend/react-email/tree/HEAD/packages/render/issues/3639\"\u003e#3639\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/resend/react-email/commit/58d8c086ef167e3c4c5ad49c6f799e2a25c80aa9\"\u003e\u003ccode\u003e58d8c08\u003c/code\u003e\u003c/a\u003e feat(render): data-text-format attribute for each html-to-text format (\u003ca href=\"https://github.com/resend/react-email/tree/HEAD/packages/render/issues/2596\"\u003e#2596\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/resend/react-email/commit/ee88bec4679eec7985f9af37f7a6aa9772623c1a\"\u003e\u003ccode\u003eee88bec\u003c/code\u003e\u003c/a\u003e fix(render): resolve implicit TypeScript type errors in pretty util (\u003ca href=\"https://github.com/resend/react-email/tree/HEAD/packages/render/issues/3616\"\u003e#3616\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/resend/react-email/commit/7792c3dbaf39d16a3d1c60841cda5f5c2ea6bfc5\"\u003e\u003ccode\u003e7792c3d\u003c/code\u003e\u003c/a\u003e chore(root): version packages (\u003ca href=\"https://github.com/resend/react-email/tree/HEAD/packages/render/issues/3615\"\u003e#3615\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/resend/react-email/commit/c300cfb2767a87d86e38104bd7a72252acccdd5b\"\u003e\u003ccode\u003ec300cfb\u003c/code\u003e\u003c/a\u003e fix(render): strip auto-injected image preload links from rendered HTML (\u003ca href=\"https://github.com/resend/react-email/tree/HEAD/packages/render/issues/3577\"\u003e#3577\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/resend/react-email/commits/@react-email/render@2.1.0/packages/render\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@smithy/node-http-handler` from 4.9.12 to 4.9.13\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/smithy-lang/smithy-typescript/releases\"\u003e@​smithy/node-http-handler's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​smithy/node-http-handler\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.9.13\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [fcf1366]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​smithy/core\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.31.1\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/smithy-lang/smithy-typescript/blob/main/packages/node-http-handler/CHANGELOG.md\"\u003e@​smithy/node-http-handler's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.9.13\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [fcf1366]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​smithy/core\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.31.1\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smithy-lang/smithy-typescript/commit/bcff71dba309446910f7a23b050350d3be77200d\"\u003e\u003ccode\u003ebcff71d\u003c/code\u003e\u003c/a\u003e Version NPM packages (\u003ca href=\"https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/node-http-handler/issues/2193\"\u003e#2193\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/smithy-lang/smithy-typescript/commits/@smithy/node-http-handler@4.9.13/packages/node-http-handler\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `better-auth` from 1.6.23 to 1.6.25\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/better-auth/better-auth/releases\"\u003ebetter-auth's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.6.25\u003c/h2\u003e\n\u003ch2\u003e\u003ccode\u003ebetter-auth\u003c/code\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Apple OAuth not sending the PKCE code challenge during authorization, causing token exchange failures (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10294\"\u003e#10294\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed Google One Tap creating new users when sign-up was disabled on the Google provider (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10479\"\u003e#10479\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e$fetch\u003c/code\u003e and \u003ccode\u003e$store\u003c/code\u003e not being exposed on the Solid client (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10444\"\u003e#10444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed internal adapter queries being routed to the wrong table when a built-in table's \u003ccode\u003emodelName\u003c/code\u003e was set to another table's schema key (e.g. \u003ccode\u003euser.modelName = \u0026quot;account\u0026quot;\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFor detailed changes, see \u003ca href=\"https://github.com/better-auth/better-auth/blob/07a646ea190167370fbbb60a0fa2c3be3bec5522/packages/better-auth/CHANGELOG.md\"\u003e\u003ccode\u003eCHANGELOG\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eContributors\u003c/h2\u003e\n\u003cp\u003eThanks to everyone who contributed to this release:\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/birkskyum\"\u003e\u003ccode\u003e@​birkskyum\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/jsj\"\u003e\u003ccode\u003e@​jsj\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/krish-vachhani\"\u003e\u003ccode\u003e@​krish-vachhani\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/better-auth/better-auth/compare/v1.6.24...v1.6.25\"\u003e\u003ccode\u003ev1.6.24...v1.6.25\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.6.24\u003c/h2\u003e\n\u003ch2\u003e\u003ccode\u003ebetter-auth\u003c/code\u003e\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded request context (\u003ccode\u003ectx\u003c/code\u003e) as a third argument to \u003ccode\u003everifyIdToken\u003c/code\u003e, enabling custom ID token verifiers to read request headers (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10376\"\u003e#10376\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003ebeforeStoreCookie\u003c/code\u003e option to the last-login-method plugin for GDPR compliance (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/5753\"\u003e#5753\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReplaced flaky MongoDB where-coercion integration test with a direct unit test for more reliable test runs (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10369\"\u003e#10369\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed the \u003ccode\u003eget-session\u003c/code\u003e endpoint to include \u003ccode\u003eno-store\u003c/code\u003e cache control headers, preventing stale session data from being served (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10222\"\u003e#10222\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed SQLite migration diffs to recognize \u003ccode\u003eBIGINT\u003c/code\u003e as a valid number type, preventing spurious pending changes on rate limiter columns (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10316\"\u003e#10316\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed auth requests failing when request cloning throws an error inside verification callbacks (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10336\"\u003e#10336\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003euseSession({ throw: true })\u003c/code\u003e incorrectly excluding \u003ccode\u003enull\u003c/code\u003e from its \u003ccode\u003edata\u003c/code\u003e type (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/9787\"\u003e#9787\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed auth query revalidation and signal listeners not being restored after a client component remounts (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10379\"\u003e#10379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed the \u003ccode\u003eCookieAttributes\u003c/code\u003e index signature type to be more precise (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10442\"\u003e#10442\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed silent misrouting of adapter queries when \u003ccode\u003euser.modelName\u003c/code\u003e was set to a value that collides with another schema key (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10235\"\u003e#10235\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed Kysely migration generation producing duplicate indexes for fields marked both \u003ccode\u003eunique\u003c/code\u003e and \u003ccode\u003eindex\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10357\"\u003e#10357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed magic-link and email-OTP send endpoints to validate the \u003ccode\u003eOrigin\u003c/code\u003e header on cookieless requests, preventing cross-origin abuse (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10368\"\u003e#10368\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed remote MCP auth 401 challenge headers being hidden from browser clients due to missing CORS exposure (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10290\"\u003e#10290\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed OpenAPI schema to include plugin user fields (such as \u003ccode\u003eusername\u003c/code\u003e and \u003ccode\u003edisplayUsername\u003c/code\u003e) in \u003ccode\u003e/sign-up/email\u003c/code\u003e and \u003ccode\u003e/update-user\u003c/code\u003e request bodies (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10453\"\u003e#10453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eorganization.listMembers\u003c/code\u003e failing with \u0026quot;User not found for member\u0026quot; for organizations with more than ~100 members (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10342\"\u003e#10342\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed organization invitations to use database-generated IDs when \u003ccode\u003eadvanced.database.generateId\u003c/code\u003e is configured, matching the behavior of other models (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10040\"\u003e#10040\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003egetDefaultModelName\u003c/code\u003e to prefer exact schema key matches over \u003ccode\u003emodelName\u003c/code\u003e aliases, preventing adapter queries from being misrouted when a built-in table's name collides with another schema key\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFor detailed changes, see \u003ca href=\"https://github.com/better-auth/better-auth/blob/9a661c7b7abceaa81123b2c56757ee24f3ad2ed6/packages/better-auth/CHANGELOG.md\"\u003e\u003ccode\u003eCHANGELOG\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003eauth\u003c/code\u003e\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md\"\u003ebetter-auth's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.6.25\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10479\"\u003e#10479\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/5124c3487903e96223bb3f54347724bb0204bb95\"\u003e\u003ccode\u003e5124c34\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/krish-vachhani\"\u003e\u003ccode\u003e@​krish-vachhani\u003c/code\u003e\u003c/a\u003e! - Prevent Google One Tap from creating new users when sign-up is disabled for the Google provider.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10444\"\u003e#10444\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/743935991f9991e8243d6c3d14773b9cfca462e8\"\u003e\u003ccode\u003e7439359\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/birkskyum\"\u003e\u003ccode\u003e@​birkskyum\u003c/code\u003e\u003c/a\u003e! - Expose the real \u003ccode\u003e$fetch\u003c/code\u003e instance and \u003ccode\u003e$store\u003c/code\u003e atoms from the Solid client instead of resolving them as dynamic API routes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies [\u003ca href=\"https://github.com/better-auth/better-auth/commit/0ffd1fb28d44a8266d62791cd4c97e263444d03b\"\u003e\u003ccode\u003e0ffd1fb\u003c/code\u003e\u003c/a\u003e]:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​better-auth/core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.6.25\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​better-auth/drizzle-adapter\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.6.25\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​better-auth/kysely-adapter\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.6.25\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​better-auth/memory-adapter\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.6.25\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​better-auth/mongo-adapter\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.6.25\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​better-auth/prisma-adapter\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.6.25\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​better-auth/telemetry\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.6.25\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.6.24\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10235\"\u003e#10235\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/03dc5a046f536994950800ea557b8e2e2e0cdfdd\"\u003e\u003ccode\u003e03dc5a0\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ping-maxwell\"\u003e\u003ccode\u003e@​ping-maxwell\u003c/code\u003e\u003c/a\u003e! - Fixes silent foreign-key and adapter-join misrouting when a user remaps a built-in model name to a string that collides with another schema key\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10357\"\u003e#10357\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/750894037639c4158472cc1d4994b0e07bf1f59a\"\u003e\u003ccode\u003e7508940\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/c-nicol\"\u003e\u003ccode\u003e@​c-nicol\u003c/code\u003e\u003c/a\u003e! - Fixes Kysely migration generation for new-table fields that are both unique: true and index: true.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10342\"\u003e#10342\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/bae71988ab79aeb4f19f245ceabac9eca8706a50\"\u003e\u003ccode\u003ebae7198\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ping-maxwell\"\u003e\u003ccode\u003e@​ping-maxwell\u003c/code\u003e\u003c/a\u003e! - Fix \u003ccode\u003eorganization.listMembers\u003c/code\u003e failing with \u0026quot;User not found for member\u0026quot; for orgs with more than ~100 members by applying the same membership limit to the users query.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10336\"\u003e#10336\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/ef4d27360cec8a0bc11a94e135ea4a3dd32b1969\"\u003e\u003ccode\u003eef4d273\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Tushar-Khandelwal-2004\"\u003e\u003ccode\u003e@​Tushar-Khandelwal-2004\u003c/code\u003e\u003c/a\u003e! - Prevent verification callbacks from failing auth requests when cloning the request throws.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10333\"\u003e#10333\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/99dbdd7ea98740d11689394220a718dfb9579276\"\u003e\u003ccode\u003e99dbdd7\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/c-nicol\"\u003e\u003ccode\u003e@​c-nicol\u003c/code\u003e\u003c/a\u003e! - Fixes Drizzle schema generation for fields that are both unique: true and index: true.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10368\"\u003e#10368\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/086ca91f51dd8158aff6cbf54c4f9c7ce220914d\"\u003e\u003ccode\u003e086ca91\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/gaurav0107\"\u003e\u003ccode\u003e@​gaurav0107\u003c/code\u003e\u003c/a\u003e! - Force-validate the request \u003ccode\u003eOrigin\u003c/code\u003e on the magic-link (\u003ccode\u003e/sign-in/magic-link\u003c/code\u003e) and email-otp (\u003ccode\u003e/email-otp/send-verification-otp\u003c/code\u003e) send endpoints, including cookieless requests, to match the built-in \u003ccode\u003e/sign-in/email\u003c/code\u003e and \u003ccode\u003e/sign-up/email\u003c/code\u003e routes. A cookieless cross-origin POST can no longer trigger a magic-link or verification-OTP email to an arbitrary address. Cookieless requests that carry no \u003ccode\u003eOrigin\u003c/code\u003e (server-to-server) are unaffected.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10290\"\u003e#10290\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/8f2dedd89301da9fb52c1a64df6a9683f9be55fd\"\u003e\u003ccode\u003e8f2dedd\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/GautamBytes\"\u003e\u003ccode\u003e@​GautamBytes\u003c/code\u003e\u003c/a\u003e! - Expose the remote MCP auth client's 401 challenge headers to browser clients using CORS.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10453\"\u003e#10453\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/4e685eef420b5576913b9803b58c7e7ee7342203\"\u003e\u003ccode\u003e4e685ee\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ping-maxwell\"\u003e\u003ccode\u003e@​ping-maxwell\u003c/code\u003e\u003c/a\u003e! - OpenAPI now includes \u003ccode\u003euser.additionalFields\u003c/code\u003e and plugin user schema fields (e.g. username plugin \u003ccode\u003eusername\u003c/code\u003e / \u003ccode\u003edisplayUsername\u003c/code\u003e) on \u003ccode\u003e/sign-up/email\u003c/code\u003e and \u003ccode\u003e/update-user\u003c/code\u003e request bodies.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10190\"\u003e#10190\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/3bf0e4981e025ba9af684013a27b0102a04f7c56\"\u003e\u003ccode\u003e3bf0e49\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/gaurav-init\"\u003e\u003ccode\u003e@​gaurav-init\u003c/code\u003e\u003c/a\u003e! - Pass the endpoint context as the second argument to \u003ccode\u003ebeforeDeleteOrganization\u003c/code\u003e and \u003ccode\u003eafterDeleteOrganization\u003c/code\u003e hooks in the organization plugin, matching the signature shown in the docs and the existing \u003ccode\u003edatabaseHooks\u003c/code\u003e pattern. The Stripe plugin's \u003ccode\u003ebeforeDeleteOrganization\u003c/code\u003e wrapper now forwards the context to user-supplied hooks instead of dropping it.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10040\"\u003e#10040\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/f59a0ee7895a024ddd4c5c387344173888e17be4\"\u003e\u003ccode\u003ef59a0ee\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/shiminshen\"\u003e\u003ccode\u003e@​shiminshen\u003c/code\u003e\u003c/a\u003e! - Organization invitations now let the database generate their \u003ccode\u003eid\u003c/code\u003e when ID generation is delegated to the database (e.g. \u003ccode\u003eadvanced.database.generateId: \u0026quot;uuid\u0026quot;\u003c/code\u003e with a UUID-capable adapter such as Postgres), matching every other model. Previously \u003ccode\u003ecreateInvitation\u003c/code\u003e always generated the invitation \u003ccode\u003eid\u003c/code\u003e in application code, so invitation rows received an app-generated value instead of a database-generated one while organizations, members and teams correctly deferred to the database (\u003ca href=\"https://redirect.github.com/better-auth/better-auth/issues/10024\"\u003ebetter-auth/better-auth#10024\u003c/a\u003e). A caller-provided id (e.g. via \u003ccode\u003ebeforeCreateInvitation\u003c/code\u003e) is still honored.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10302\"\u003e#10302\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/0f2cc1b33b77850948dac4d889e5f46bba41e8d5\"\u003e\u003ccode\u003e0f2cc1b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/momomuchu\"\u003e\u003ccode\u003e@​momomuchu\u003c/code\u003e\u003c/a\u003e! - Prefer exact schema-key matches over \u003ccode\u003emodelName\u003c/code\u003e aliases in \u003ccode\u003egetDefaultModelName\u003c/code\u003e, so remapping a built-in table onto another table's schema key (e.g. \u003ccode\u003euser.modelName = \u0026quot;account\u0026quot;\u003c/code\u003e) does not reroute internal adapter queries to the wrong table.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/9787\"\u003e#9787\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/ae781091186f321b4e4ec9e84f64b6e4d5ea1043\"\u003e\u003ccode\u003eae78109\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ping-maxwell\"\u003e\u003ccode\u003e@​ping-maxwell\u003c/code\u003e\u003c/a\u003e! - Fixes an issue where \u003ccode\u003euseSession({ throw: true })\u003c/code\u003e incorrectly excluded \u003ccode\u003enull\u003c/code\u003e from its \u003ccode\u003edata\u003c/code\u003e type.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10222\"\u003e#10222\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/46d2bf02c98902da7b344753372d48cfe0e5ebb3\"\u003e\u003ccode\u003e46d2bf0\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ping-maxwell\"\u003e\u003ccode\u003e@​ping-maxwell\u003c/code\u003e\u003c/a\u003e! - fix: add no-store cache-control headers to get-session route\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10316\"\u003e#10316\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/29a373eaf1778820061a9380c29831c2de2ce704\"\u003e\u003ccode\u003e29a373e\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/vinay-oppuri\"\u003e\u003ccode\u003e@​vinay-oppuri\u003c/code\u003e\u003c/a\u003e! - Recognize SQLite \u003ccode\u003eBIGINT\u003c/code\u003e as a valid number type in migration diffs so database-backed rate limiter columns like \u003ccode\u003elastRequest\u003c/code\u003e no longer report spurious pending changes on every run.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/better-auth/better-auth/pull/10379\"\u003e#10379\u003c/a\u003e \u003ca href=\"https://github.com/better-auth/better-auth/commit/f6d18fa8f79b9323e10b50f72e2b1a088844e4bb\"\u003e\u003ccode\u003ef6d18fa\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ping-maxwell\"\u003e\u003ccode\u003e@​ping-maxwell\u003c/code\u003e\u003c/a\u003e! - fix(client): restore auth query revalidation and signal listeners after remount\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/07a646ea190167370fbbb60a0fa2c3be3bec5522\"\u003e\u003ccode\u003e07a646e\u003c/code\u003e\u003c/a\u003e chore: release v1.6.25 (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10491\"\u003e#10491\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/743935991f9991e8243d6c3d14773b9cfca462e8\"\u003e\u003ccode\u003e7439359\u003c/code\u003e\u003c/a\u003e fix(solid): expose $fetch and $store on the solid client (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10444\"\u003e#10444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/dac701c94bcd777e7cb124570d644f8b4a7981a5\"\u003e\u003ccode\u003edac701c\u003c/code\u003e\u003c/a\u003e chore(deps): bump next from 16.2.6 to 16.2.11 (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10493\"\u003e#10493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/5124c3487903e96223bb3f54347724bb0204bb95\"\u003e\u003ccode\u003e5124c34\u003c/code\u003e\u003c/a\u003e fix(one-tap): enforce google provider signup restrictions (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10479\"\u003e#10479\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/9a661c7b7abceaa81123b2c56757ee24f3ad2ed6\"\u003e\u003ccode\u003e9a661c7\u003c/code\u003e\u003c/a\u003e chore: release v1.6.24 (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10323\"\u003e#10323\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/4e685eef420b5576913b9803b58c7e7ee7342203\"\u003e\u003ccode\u003e4e685ee\u003c/code\u003e\u003c/a\u003e fix(open-api): include plugin user fields on sign-up/update bodies (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10453\"\u003e#10453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/d3ce7823324ba64efd423895b1c122d85c6d7663\"\u003e\u003ccode\u003ed3ce782\u003c/code\u003e\u003c/a\u003e fix(cookies): tighten CookieAttributes index signature type (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10441\"\u003e#10441\u003c/a\u003e) (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10442\"\u003e#10442\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/ae781091186f321b4e4ec9e84f64b6e4d5ea1043\"\u003e\u003ccode\u003eae78109\u003c/code\u003e\u003c/a\u003e fix(client): preserve null in useSession().data type with throw:true (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/9787\"\u003e#9787\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/f6d18fa8f79b9323e10b50f72e2b1a088844e4bb\"\u003e\u003ccode\u003ef6d18fa\u003c/code\u003e\u003c/a\u003e fix(client): restore auth query lifecycle after remount (\u003ca href=\"https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10379\"\u003e#10379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/better-auth/better-auth/commit/086ca91f51dd8158aff6cbf54c4f9c7ce220914d\"\u003e\u003ccode\u003e086ca91\u003c/code\u003e\u003c/a\u003e fix(magic-link, email-otp): force-validate Origin on cookieless send endpoint...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/better-auth/better-auth/commits/v1.6.25/packages/better-auth\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `geoip-country` from 5.0.202607010001 to 5.0.202608010109\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/sapics/geoip-country/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `hono` from 4.12.27 to 4.12.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/honojs/hono/releases\"\u003ehono's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.12.33\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(cookie): relax name validation when parsing Cookie header in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5164\"\u003ehonojs/hono#5164\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump \u003ccode\u003e@hono/node-server\u003c/code\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5167\"\u003ehonojs/hono#5167\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(jsx): handle useSyncExternalStore subscription and snapshot changes in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5166\"\u003ehonojs/hono#5166\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove undici in favor of global fetch in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5168\"\u003ehonojs/hono#5168\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/hono/compare/v4.12.32...v4.12.33\"\u003ehttps://github.com/honojs/hono/compare/v4.12.32...v4.12.33\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.12.32\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eci: enable reports for type \u0026amp; bundle size check in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5148\"\u003ehonojs/hono#5148\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(aws-lambda): add jwt and lambda authorizer types for API Gateway v2 in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5142\"\u003ehonojs/hono#5142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(sse): emit empty id field to reset Last-Event-ID in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5138\"\u003ehonojs/hono#5138\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(cloudflare-workers): add coverage for onClose, onError, send, and close in Cloudflare Workers websocket adapter in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5145\"\u003ehonojs/hono#5145\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: use \u003ccode\u003eObject.create(null)\u003c/code\u003e when parsing query, headers, and params in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5161\"\u003ehonojs/hono#5161\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(secure-headers): keep CSP callbacks scoped to their header in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5147\"\u003ehonojs/hono#5147\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/hono/compare/v4.12.31...v4.12.32\"\u003ehttps://github.com/honojs/hono/compare/v4.12.31...v4.12.32\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.12.31\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etest(context): assert case-insensitive header names in response helpers by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5116\"\u003ehonojs/hono#5116\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(benchmark): add app.fetch() overhead benchmark by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5117\"\u003ehonojs/hono#5117\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor(aws-lambada): remove FIXME in \u003ccode\u003e@ts-expect-error\u003c/code\u003e by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5130\"\u003ehonojs/hono#5130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(utils/body): reuse cached formData in \u003ccode\u003eparseBody()\u003c/code\u003e by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5131\"\u003ehonojs/hono#5131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(request): fix multipart boundary mismatch in \u003ccode\u003ecloneRawRequest\u003c/code\u003e by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5133\"\u003ehonojs/hono#5133\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(sse): emit retry feild when retry is \u003ccode\u003e0\u003c/code\u003e by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5135\"\u003ehonojs/hono#5135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(validator): fix misspelled identifier in transform type test by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5136\"\u003ehonojs/hono#5136\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/hono/compare/v4.12.30...v4.12.31\"\u003ehttps://github.com/honojs/hono/compare/v4.12.30...v4.12.31\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.12.30\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore(benchmark/routers): bump deps in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5107\"\u003ehonojs/hono#5107\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(benchmark): remove not used benchmarks in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5108\"\u003ehonojs/hono#5108\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: update to ts6 in prep for ts7 in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5104\"\u003ehonojs/hono#5104\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): deduplicate Cache-Control directives case-insensitively in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5025\"\u003ehonojs/hono#5025\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(compress): do not compress 206 Partial Content responses in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5020\"\u003ehonojs/hono#5020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(client): replaceUrlParam should not match a param that prefixes another in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5096\"\u003ehonojs/hono#5096\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(method-override): set duplex when forwarding a stream body in query mode in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5110\"\u003ehonojs/hono#5110\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/hono/compare/v4.12.29...v4.12.30\"\u003ehttps://github.com/honojs/hono/compare/v4.12.29...v4.12.30\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.12.29\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(client): merge function headers with per-request headers by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5092\"\u003ehonojs/hono#5092\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: fix no-op tsc in test script by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5093\"\u003ehonojs/hono#5093\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(lambda-edge): resolve the handler with the value passed to the callback by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5094\"\u003ehonojs/hono#5094\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs(language): add JSDoc \u003ca href=\"https://github.com/example\"\u003e\u003ccode\u003e@​example\u003c/code\u003e\u003c/a\u003e to languageDetector by \u003ca href=\"https://github.com/codebybilal18\"\u003e\u003ccode\u003e@​codebybilal18\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5081\"\u003ehonojs/hono#5081\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/hono/commit/51db3131d5e97076327edaa0afdb60ebb77c264f\"\u003e\u003ccode\u003e51db313\u003c/code\u003e\u003c/a\u003e 4.12.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.co...\n\n_Description has been truncated_","html_url":"https://github.com/langwatch/langwatch/pull/6793","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/langwatch%2Flangwatch/issues/6793","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6793/packages"}},{"old_version":"7.16.0","new_version":"7.29.0","update_type":"minor","path":null,"pr_created_at":"2026-08-08T04:53:26.000Z","version_change":"7.16.0 → 7.29.0","issue":{"uuid":"5095932581","node_id":"PR_kwDOPqGt_878UmEE","number":842,"state":"closed","title":"chore(deps): bump the npm_and_yarn group across 2 directories with 5 updates","user":"dependabot[bot]","labels":["dependencies","javascript","superseded","security-review"],"assignees":[],"locked":false,"comments_count":4,"pull_request":true,"closed_at":"2026-08-08T04:54:15.000Z","author_association":null,"state_reason":null,"created_at":"2026-08-08T04:53:26.000Z","updated_at":"2026-08-08T04:58:43.000Z","time_to_close":49,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":5,"packages":[{"name":"postcss","old_version":"8.4.35","new_version":"8.5.26","repository_url":"https://github.com/postcss/postcss"},{"name":"vite","old_version":"4.5.14","new_version":"8.2.1","repository_url":"https://github.com/vitejs/vite"},{"name":"ws","old_version":"8.19.0","new_version":"8.21.3","repository_url":"https://github.com/websockets/ws"},{"name":"undici","old_version":"7.16.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 4 updates in the /client directory: [postcss](https://github.com/postcss/postcss), [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite), [picomatch](https://github.com/micromatch/picomatch) and [ws](https://github.com/websockets/ws).\nBumps the npm_and_yarn group with 1 update in the /dynamic/copilot-swe-agent directory: [undici](https://github.com/nodejs/undici).\n\nUpdates `postcss` from 8.4.35 to 8.5.26\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/07b25773f38f77919f2af02ae3e8896b0deb5988\"\u003e\u003ccode\u003e07b2577\u003c/code\u003e\u003c/a\u003e Release 8.5.26 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/47de6b9d7c55674cb326c5de7a734a740916defc\"\u003e\u003ccode\u003e47de6b9\u003c/code\u003e\u003c/a\u003e Update CI\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/1493a83db7830912316512f55ab6064e7b7dd68e\"\u003e\u003ccode\u003e1493a83\u003c/code\u003e\u003c/a\u003e Fix Rule#selectors losing the empty selector (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2129\"\u003e#2129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/180db166e250d20e6761b224ae8d8134c9ba3e40\"\u003e\u003ccode\u003e180db16\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/29e9e00f132c96e46e1de295b816fe88a05354e7\"\u003e\u003ccode\u003e29e9e00\u003c/code\u003e\u003c/a\u003e Resolve symlinks before the previous-source-map containment check (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2125\"\u003e#2125\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3ba8f84703a884329b58abea579c3615684e0b7e\"\u003e\u003ccode\u003e3ba8f84\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/87e72f671fd0d401c52822b5226c656632d92ec0\"\u003e\u003ccode\u003e87e72f6\u003c/code\u003e\u003c/a\u003e Update lock file\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/caaeeb907e4a816c44a23b00b151882bd02325a1\"\u003e\u003ccode\u003ecaaeeb9\u003c/code\u003e\u003c/a\u003e Upgrade nanoid to fix infinite loop on zero size (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2124\"\u003e#2124\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3609b6f4296952d0b5b9ddae42c8d73ee460c041\"\u003e\u003ccode\u003e3609b6f\u003c/code\u003e\u003c/a\u003e Explain how to type plugin options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/fbad419cbd01cd7a9a1a46413447f2cd9b3fce4a\"\u003e\u003ccode\u003efbad419\u003c/code\u003e\u003c/a\u003e docs: show ESM and TypeScript plugin declaration (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2118\"\u003e#2118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.4.35...8.5.26\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `vite` from 4.5.14 to 8.2.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/releases\"\u003evite's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eplugin-legacy@8.2.1\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/plugin-legacy@8.2.1/packages/plugin-legacy/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.2.1\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.2.1/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ecreate-vite@8.2.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/create-vite@8.2.0/packages/create-vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003eplugin-legacy@8.2.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/plugin-legacy@8.2.0/packages/plugin-legacy/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.2.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.2.0/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.2.0-beta.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.2.0-beta.0/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.1.5\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.1.5/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.1.4\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.1.4/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.1.3\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.1.3/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.1.2\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.1.2/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.1.1\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.1.1/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ecreate-vite@8.1.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/create-vite@8.1.0/packages/create-vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003eplugin-legacy@8.1.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/plugin-legacy@8.1.0/packages/plugin-legacy/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.1.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.1.0/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003eplugin-legacy@8.1.0-beta.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/plugin-legacy@8.1.0-beta.0/packages/plugin-legacy/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.1.0-beta.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.1.0-beta.0/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.0.16\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v8.0.16/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md\"\u003evite's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v8.2.0...v8.2.1\"\u003e8.2.1\u003c/a\u003e (2026-08-06)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e make client chunkImportMap work with \u003ccode\u003esharedPlugins: true\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23184\"\u003e#23184\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/15f03073c915d6ffb9a1fda447ef66b02bf5cde8\"\u003e15f0307\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebundled-dev:\u003c/strong\u003e inject client script tag before chunk scripts (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23161\"\u003e#23161\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/eac0cc84aa2472a85a19ee84561c1ba71e381a55\"\u003eeac0cc8\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecss:\u003c/strong\u003e don't re-run lightningcss visitor during minify (fix \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23146\"\u003e#23146\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23147\"\u003e#23147\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/de041a79b05a0be965c874592fe2c1505bcd48df\"\u003ede041a7\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update all non-major dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23136\"\u003e#23136\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/14454fd8c9a399bc3fdc193e28465b6fcf001e4d\"\u003e14454fd\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update rolldown-related dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23070\"\u003e#23070\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/7ac6f7f590747bbdab9958e2c016e3dd04f10542\"\u003e7ac6f7f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edon't mutate the user config when resolving the lib entry from the top-level \u003ccode\u003einput\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23135\"\u003e#23135\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b4bf59686a7ac238929e91a6e1708c739b843a2f\"\u003eb4bf596\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ehandle shebang ending with uncommon line terminators (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23038\"\u003e#23038\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/17f7b2f193a110d0b47742ad296d182cb4666ce7\"\u003e17f7b2f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eserver:\u003c/strong\u003e use a random port when port is 0 (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23158\"\u003e#23158\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/fddf4ea41de5f7889037a2f957438857ac12a260\"\u003efddf4ea\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance Improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ecss:\u003c/strong\u003e look up pure CSS chunks through a Set (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23114\"\u003e#23114\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/1331b0b438b1e7193effb7d2341660bccb9c3155\"\u003e1331b0b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e fix incomplete \u003ccode\u003e@default\u003c/code\u003e for build.minify (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23177\"\u003e#23177\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/ef02435114c57d0422028f0e6987f3df8db72969\"\u003eef02435\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMiscellaneous Chores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update dependency rolldown-plugin-dts to ^0.28.0 (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23137\"\u003e#23137\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/4adc1e7931d4beceb4e236d9a271d057c858a06f\"\u003e4adc1e7\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update dependency strip-literal to v4 (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23140\"\u003e#23140\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/9db65ce63488ea8f08a3c98dcdc4282b17bd33ff\"\u003e9db65ce\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCode Refactoring\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebundled-dev:\u003c/strong\u003e avoid injecting server values in the bundle (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22967\"\u003e#22967\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/23b8a088dec9dcc3f1c1353f2074f8644b3cc21f\"\u003e23b8a08\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebundled-dev:\u003c/strong\u003e remove rolldown lazy stub module workaround (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23129\"\u003e#23129\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e72036eed2e28936ed824971b18aeaa3900857f6\"\u003ee72036e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eTests\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebundled-dev:\u003c/strong\u003e enable sourcemap playgrounds (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23080\"\u003e#23080\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/c2155fe4d5c8d25fba3a7366d367e3296ae669fa\"\u003ec2155fe\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ereduce logs (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23138\"\u003e#23138\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/7673c02e53343ae9356c1f496c1c1da2eb732ac1\"\u003e7673c02\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v8.2.0-beta.0...v8.2.0\"\u003e8.2.0\u003c/a\u003e (2026-07-30)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003einput\u003c/code\u003e to \u003ccode\u003eserver.fs.allow\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23035\"\u003e#23035\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/95a3cdab83e1125b03d2e8dd942fb6b64209e5fa\"\u003e95a3cda\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebundled-dev:\u003c/strong\u003e reload once after rebuild instead of via the fallback page (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23106\"\u003e#23106\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b24381d741941b9ce2b1c07db62cc5f4d7bad981\"\u003eb24381d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebundled-dev:\u003c/strong\u003e support worker file update accepted by HMR (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23068\"\u003e#23068\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/0d04351fdc12258c75b9f1cda5780fdb836ed0ef\"\u003e0d04351\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003econfig:\u003c/strong\u003e include column in config incompatibility location (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23064\"\u003e#23064\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8a245726944ed29225920d49be77c33c6e03afc8\"\u003e8a24572\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edev:\u003c/strong\u003e resolve interface name for explicit host in network URLs (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22965\"\u003e#22965\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/3ac77d9dd742968961af38a5a91ed6b061ceda7d\"\u003e3ac77d9\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebundledDev:\u003c/strong\u003e print build errors to the terminal when an HMR update fails (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23024\"\u003e#23024\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/41c465896e8b11b1eb9c5fbdafbdcc528e189a2c\"\u003e41c4658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update all non-major dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23069\"\u003e#23069\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/4c07b74416f859d7e8bdace13409ef2d080edf76\"\u003e4c07b74\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ehmr:\u003c/strong\u003e preserve environment snapshot during server restart (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22992\"\u003e#22992\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b1186c36d06bb94941c58e8272fc4acb8512c93b\"\u003eb1186c3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eimportAnalysis:\u003c/strong\u003e interop imports injected into optimized dep files by plugins (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23029\"\u003e#23029\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8c2a87d41fb24536e59643351758084cde4d0dd7\"\u003e8c2a87d\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/421615865dad3ed39137d17281814fc78a41246c\"\u003e\u003ccode\u003e4216158\u003c/code\u003e\u003c/a\u003e release: v8.2.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/fddf4ea41de5f7889037a2f957438857ac12a260\"\u003e\u003ccode\u003efddf4ea\u003c/code\u003e\u003c/a\u003e fix(server): use a random port when port is 0 (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23158\"\u003e#23158\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/de041a79b05a0be965c874592fe2c1505bcd48df\"\u003e\u003ccode\u003ede041a7\u003c/code\u003e\u003c/a\u003e fix(css): don't re-run lightningcss visitor during minify (fix \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23146\"\u003e#23146\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23147\"\u003e#23147\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/15f03073c915d6ffb9a1fda447ef66b02bf5cde8\"\u003e\u003ccode\u003e15f0307\u003c/code\u003e\u003c/a\u003e fix(build): make client chunkImportMap work with \u003ccode\u003esharedPlugins: true\u003c/code\u003e (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23184\"\u003e#23184\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/c2155fe4d5c8d25fba3a7366d367e3296ae669fa\"\u003e\u003ccode\u003ec2155fe\u003c/code\u003e\u003c/a\u003e test(bundled-dev): enable sourcemap playgrounds (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23080\"\u003e#23080\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/ef02435114c57d0422028f0e6987f3df8db72969\"\u003e\u003ccode\u003eef02435\u003c/code\u003e\u003c/a\u003e docs(build): fix incomplete \u003ccode\u003e@default\u003c/code\u003e for build.minify (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23177\"\u003e#23177\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/eac0cc84aa2472a85a19ee84561c1ba71e381a55\"\u003e\u003ccode\u003eeac0cc8\u003c/code\u003e\u003c/a\u003e fix(bundled-dev): inject client script tag before chunk scripts (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23161\"\u003e#23161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/23b8a088dec9dcc3f1c1353f2074f8644b3cc21f\"\u003e\u003ccode\u003e23b8a08\u003c/code\u003e\u003c/a\u003e refactor(bundled-dev): avoid injecting server values in the bundle (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22967\"\u003e#22967\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/e72036eed2e28936ed824971b18aeaa3900857f6\"\u003e\u003ccode\u003ee72036e\u003c/code\u003e\u003c/a\u003e refactor(bundled-dev): remove rolldown lazy stub module workaround (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23129\"\u003e#23129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/14454fd8c9a399bc3fdc193e28465b6fcf001e4d\"\u003e\u003ccode\u003e14454fd\u003c/code\u003e\u003c/a\u003e fix(deps): update all non-major dependencies (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23136\"\u003e#23136\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vitejs/vite/commits/v8.2.1/packages/vite\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for vite since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nRemoves `picomatch`\n\nUpdates `ws` from 8.19.0 to 8.21.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/websockets/ws/releases\"\u003ews's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.21.3\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eThe server now correctly rejects permessage-deflate offers if the incoming\n\u003ccode\u003eclient_max_window_bits\u003c/code\u003e parameter value is smaller than its configured\n\u003ccode\u003eclientMaxWindowBits\u003c/code\u003e (e97a20ea).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.21.2\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a test for \u003ca href=\"https://github.com/nodejs/citgm\"\u003eCITGM\u003c/a\u003e (2eb3be0b).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.21.1\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eEmpty fragments are now counted toward the limit (a2f4e7c0).\u003c/li\u003e\n\u003cli\u003eThe default values of the \u003ccode\u003emaxBufferedChunks\u003c/code\u003e and \u003ccode\u003emaxFragments\u003c/code\u003e options have\nbeen reduced (f197ac65).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.21.0\u003c/h2\u003e\n\u003ch1\u003eFeatures\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eIntroduced the \u003ccode\u003emaxBufferedChunks\u003c/code\u003e and \u003ccode\u003emaxFragments\u003c/code\u003e options (2b2abd45).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a remote memory exhaustion DoS vulnerability (2b2abd45).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eA high volume of tiny fragments and data chunks could be sent by a peer, using\nmodest network traffic, to crash a \u003ccode\u003ews\u003c/code\u003e server or client due to OOM.\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003eimport { WebSocket, WebSocketServer } from 'ws';\r\n\u003cp\u003econst wss = new WebSocketServer({ port: 0 }, function () {\nconst data = Buffer.alloc(1);\nconst options = { fin: false };\nconst { port } = wss.address();\nconst ws = new WebSocket(\u003ccode\u003ews://localhost:${port}\u003c/code\u003e);\u003c/p\u003e\n\u003cp\u003ews.on('open', function () {\n(function send() {\nws.send(data, options, function (err) {\nif (err) return;\nsend();\n});\n})();\n});\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt;\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/c791e707eab3c13dd9a261d2479c3cc4a49a6fed\"\u003e\u003ccode\u003ec791e70\u003c/code\u003e\u003c/a\u003e [dist] 8.21.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/e97a20eaa6f2ad7969419eed732a506453251eb9\"\u003e\u003ccode\u003ee97a20e\u003c/code\u003e\u003c/a\u003e [fix] Reject offers with \u003ccode\u003eclient_max_window_bits\u003c/code\u003e below config\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/787ebf22ce3d091fb6f931d20b4c7e914ba7cf85\"\u003e\u003ccode\u003e787ebf2\u003c/code\u003e\u003c/a\u003e [dist] 8.21.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/b4d62ebad40c3b925c84ff305a47975406015422\"\u003e\u003ccode\u003eb4d62eb\u003c/code\u003e\u003c/a\u003e Revert \u0026quot;[ci] Trust Coveralls Homebrew tap\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/e4bb883723a0c18452eea10a74139901ae33c61d\"\u003e\u003ccode\u003ee4bb883\u003c/code\u003e\u003c/a\u003e [security] Use GitHub PVR as main reporting channel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/2eb3be0bff2453e2654b1315c5872e8d5d424a50\"\u003e\u003ccode\u003e2eb3be0\u003c/code\u003e\u003c/a\u003e [test] Skip test on Node.js versions where it does not apply\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/ae1de54330cef77e487548890fabfeb9aae1d83d\"\u003e\u003ccode\u003eae1de54\u003c/code\u003e\u003c/a\u003e [dist] 8.21.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/8e9511b86b3fc6deebbd97dd9af7c9056deea8d1\"\u003e\u003ccode\u003e8e9511b\u003c/code\u003e\u003c/a\u003e [ci] Trust Coveralls Homebrew tap\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/f197ac65140920bdcecdab74bfc69c2d7858e55d\"\u003e\u003ccode\u003ef197ac6\u003c/code\u003e\u003c/a\u003e [fix] Lower default values of \u003ccode\u003emaxBufferedChunks\u003c/code\u003e and \u003ccode\u003emaxFragments\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/8df8265c2f63fd44af3193a98e23cf38888cd991\"\u003e\u003ccode\u003e8df8265\u003c/code\u003e\u003c/a\u003e [ci] Update actions/checkout action to v7\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/websockets/ws/compare/8.19.0...8.21.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.16.0 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.28.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e7 security advisories\u003c/strong\u003e, all shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 7.28.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^7.28.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v7 line is \u003cstrong\u003enot\u003c/strong\u003e affected by GHSA-38rv-x7px-6hhq (CVE-2026-9675), which is\nan 8.x-only regression.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on GHSA-hm92-r4w5-c3mj:\u003c/strong\u003e this fix shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e, not the\nearlier 7.2x line — the vulnerable single-pool code was still present through\n\u003ccode\u003ev7.27.2\u003c/code\u003e. The per-origin pool fix is\n\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5041\"\u003e#5041\u003c/a\u003e).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8cb10f98\"\u003e\u003ccode\u003e8cb10f98\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g\"\u003eGHSA-vmh5-mc38-953g\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9697\u003c/td\u003e\n\u003ctd\u003eHigh (7.4)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/04201f89\"\u003e\u003ccode\u003e04201f89\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj\"\u003eGHSA-hm92-r4w5-c3mj\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6734\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6\"\u003eGHSA-pr7r-676h-xcf6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9678\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/85a24055\"\u003e\u003ccode\u003e85a24055\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ea8930cf\"\u003e\u003ccode\u003eea8930cf\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f9eba0ad9134e1c0977848476bba9d49734696e4\"\u003e\u003ccode\u003ef9eba0a\u003c/code\u003e\u003c/a\u003e Bumped v7.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5430\"\u003e#5430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.16.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/mrdannyclark82/Milla-Rayne/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/mrdannyclark82/Milla-Rayne/pull/842","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/mrdannyclark82%2FMilla-Rayne/issues/842","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/842/packages"}},{"old_version":"7.28.0","new_version":"7.29.0","update_type":"minor","path":null,"pr_created_at":"2026-08-08T03:34:42.000Z","version_change":"7.28.0 → 7.29.0","issue":{"uuid":"5095685495","node_id":"PR_kwDOS3GQx878T12k","number":127,"state":"closed","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 3 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-08-08T03:35:08.000Z","author_association":null,"state_reason":null,"created_at":"2026-08-08T03:34:42.000Z","updated_at":"2026-08-08T03:35:10.000Z","time_to_close":26,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":3,"packages":[{"name":"brace-expansion","old_version":"1.1.15","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"postcss","old_version":"8.5.15","new_version":"8.5.26","repository_url":"https://github.com/postcss/postcss"},{"name":"undici","old_version":"7.28.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 3 updates in the /client directory: [brace-expansion](https://github.com/juliangruber/brace-expansion), [postcss](https://github.com/postcss/postcss) and [undici](https://github.com/nodejs/undici).\n\nUpdates `brace-expansion` from 1.1.15 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.15...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.15 to 8.5.26\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/07b25773f38f77919f2af02ae3e8896b0deb5988\"\u003e\u003ccode\u003e07b2577\u003c/code\u003e\u003c/a\u003e Release 8.5.26 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/47de6b9d7c55674cb326c5de7a734a740916defc\"\u003e\u003ccode\u003e47de6b9\u003c/code\u003e\u003c/a\u003e Update CI\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/1493a83db7830912316512f55ab6064e7b7dd68e\"\u003e\u003ccode\u003e1493a83\u003c/code\u003e\u003c/a\u003e Fix Rule#selectors losing the empty selector (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2129\"\u003e#2129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/180db166e250d20e6761b224ae8d8134c9ba3e40\"\u003e\u003ccode\u003e180db16\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/29e9e00f132c96e46e1de295b816fe88a05354e7\"\u003e\u003ccode\u003e29e9e00\u003c/code\u003e\u003c/a\u003e Resolve symlinks before the previous-source-map containment check (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2125\"\u003e#2125\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3ba8f84703a884329b58abea579c3615684e0b7e\"\u003e\u003ccode\u003e3ba8f84\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/87e72f671fd0d401c52822b5226c656632d92ec0\"\u003e\u003ccode\u003e87e72f6\u003c/code\u003e\u003c/a\u003e Update lock file\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/caaeeb907e4a816c44a23b00b151882bd02325a1\"\u003e\u003ccode\u003ecaaeeb9\u003c/code\u003e\u003c/a\u003e Upgrade nanoid to fix infinite loop on zero size (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2124\"\u003e#2124\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3609b6f4296952d0b5b9ddae42c8d73ee460c041\"\u003e\u003ccode\u003e3609b6f\u003c/code\u003e\u003c/a\u003e Explain how to type plugin options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/fbad419cbd01cd7a9a1a46413447f2cd9b3fce4a\"\u003e\u003ccode\u003efbad419\u003c/code\u003e\u003c/a\u003e docs: show ESM and TypeScript plugin declaration (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2118\"\u003e#2118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.15...8.5.26\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.28.0 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/arthurgregorio/investlog/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/arthurgregorio/investlog/pull/127","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/arthurgregorio%2Finvestlog/issues/127","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/127/packages"}},{"old_version":"6.27.0","new_version":"6.28.0","update_type":"minor","path":null,"pr_created_at":"2026-08-07T22:39:02.000Z","version_change":"6.27.0 → 6.28.0","issue":{"uuid":"5094497191","node_id":"PR_kwDOJmRLdM78QGJp","number":287,"state":"open","title":"chore(deps): bump undici and @aurodesignsystem/auro-cli","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T22:39:02.000Z","updated_at":"2026-08-07T22:39:11.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"undici","repository_url":"https://github.com/nodejs/undici","old_version":"6.27.0","new_version":"6.28.0"},{"name":"@aurodesignsystem/auro-cli","repository_url":"https://github.com/AlaskaAirlines/auro-cli","old_version":"3.5.1","new_version":"3.7.1"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) to 6.28.0 and updates ancestor dependency [@aurodesignsystem/auro-cli](https://github.com/AlaskaAirlines/auro-cli). These dependencies need to be updated together.\n\nUpdates `undici` from 6.27.0 to 6.28.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.28.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e740a0b7c\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003ecba3a52a\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e4fd5a0c6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003eaf748404\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e and \u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ehttps://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a\"\u003e\u003ccode\u003e01a912e\u003c/code\u003e\u003c/a\u003e Bumped v6.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5591\"\u003e#5591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e\"\u003e\u003ccode\u003e481ecfc\u003c/code\u003e\u003c/a\u003e Use Node 22 and npm 11 to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e\u003ccode\u003e740a0b7\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0\"\u003e\u003ccode\u003e2698e49\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e\u003ccode\u003e4fd5a0c\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003e\u003ccode\u003ecba3a52\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003e\u003ccode\u003eaf74840\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@aurodesignsystem/auro-cli` from 3.5.1 to 3.7.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/releases\"\u003e@​aurodesignsystem/auro-cli's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.7.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/compare/v3.7.0...v3.7.1\"\u003e3.7.1\u003c/a\u003e (2026-05-11)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e error on unresolved imports in demo bundles (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/9e5bca652bd4589ed39c5ab1d3964e220b3d40b3\"\u003e9e5bca6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e isolate demo bundles and bump \u003ccode\u003e@​actions/github\u003c/code\u003e (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/6b57f98627e8c6b5deec1af0ebd3fe7b488728fc\"\u003e6b57f98\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e resolve hoisted workspace packages in demo bundles (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/3b29a21da0a5cc6f630c9f6a2d8ae41f31946214\"\u003e3b29a21\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.7.1-rc-291.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/compare/v3.7.0...v3.7.1-rc-291.1\"\u003e3.7.1-rc-291.1\u003c/a\u003e (2026-05-11)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e error on unresolved imports in demo bundles (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/9e5bca652bd4589ed39c5ab1d3964e220b3d40b3\"\u003e9e5bca6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e isolate demo bundles and bump \u003ccode\u003e@​actions/github\u003c/code\u003e (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/6b57f98627e8c6b5deec1af0ebd3fe7b488728fc\"\u003e6b57f98\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e resolve hoisted workspace packages in demo bundles (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/3b29a21da0a5cc6f630c9f6a2d8ae41f31946214\"\u003e3b29a21\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.7.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/compare/v3.6.0...v3.7.0\"\u003e3.7.0\u003c/a\u003e (2026-05-06)\u003c/h1\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003erefine whitespace stripping in post-processing to preserve markdown structure (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/36242f3ad2b78df299204932c04ec8d648cdaa7a\"\u003e36242f3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eresolve SCSS imports using package.json exports map (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/97517203737c5d382c32632b84b57892fa023519\"\u003e9751720\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd --readme-template flag and centralize shared utilities (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/e71cd8f8ef7846cfde31285bd4c49f72b6047fbb\"\u003ee71cd8f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd demo SCSS compilation, README copy, and watch mode to docs command (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/3f7a5f6be82fb60ee33cbeb1fe1e4f4757edd8c1\"\u003e3f7a5f6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd post-processing for markdown doc files (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/a5d63bc5241c28d1c95d8bb78dd7aef8b2eafec7\"\u003ea5d63bc\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eenhance defaultDocsProcessorConfig with monorepoName and extraVars support (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/e252574f8adaa7b92dd2a418ecc04b66cd16db20\"\u003ee252574\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.7.0-rc-287.1\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/compare/v3.6.0...v3.7.0-rc-287.1\"\u003e3.7.0-rc-287.1\u003c/a\u003e (2026-05-06)\u003c/h1\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003erefine whitespace stripping in post-processing to preserve markdown structure (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/36242f3ad2b78df299204932c04ec8d648cdaa7a\"\u003e36242f3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eresolve SCSS imports using package.json exports map (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/97517203737c5d382c32632b84b57892fa023519\"\u003e9751720\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd --readme-template flag and centralize shared utilities (\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/e71cd8f8ef7846cfde31285bd4c49f72b6047fbb\"\u003ee71cd8f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/40a82d77c7a98d1d92ea423ab739d94d4e33e2dd\"\u003e\u003ccode\u003e40a82d7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/AlaskaAirlines/auro-cli/issues/292\"\u003e#292\u003c/a\u003e from AlaskaAirlines/rc/291\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/9e5bca652bd4589ed39c5ab1d3964e220b3d40b3\"\u003e\u003ccode\u003e9e5bca6\u003c/code\u003e\u003c/a\u003e fix(build): error on unresolved imports in demo bundles\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/3b29a21da0a5cc6f630c9f6a2d8ae41f31946214\"\u003e\u003ccode\u003e3b29a21\u003c/code\u003e\u003c/a\u003e fix(build): resolve hoisted workspace packages in demo bundles\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/6b57f98627e8c6b5deec1af0ebd3fe7b488728fc\"\u003e\u003ccode\u003e6b57f98\u003c/code\u003e\u003c/a\u003e fix(build): isolate demo bundles and bump \u003ccode\u003e@​actions/github\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/c3c60a78df454aa3b64052a0de69a15449502e12\"\u003e\u003ccode\u003ec3c60a7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/AlaskaAirlines/auro-cli/issues/288\"\u003e#288\u003c/a\u003e from AlaskaAirlines/rc/287\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/53fd747faf8de08b3943e258d6ee9a3ba9c0e390\"\u003e\u003ccode\u003e53fd747\u003c/code\u003e\u003c/a\u003e ci: update Node.js version to 22.22.1 in workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/e252574f8adaa7b92dd2a418ecc04b66cd16db20\"\u003e\u003ccode\u003ee252574\u003c/code\u003e\u003c/a\u003e feat: enhance defaultDocsProcessorConfig with monorepoName and extraVars support\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/36242f3ad2b78df299204932c04ec8d648cdaa7a\"\u003e\u003ccode\u003e36242f3\u003c/code\u003e\u003c/a\u003e fix: refine whitespace stripping in post-processing to preserve markdown stru...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/a5d63bc5241c28d1c95d8bb78dd7aef8b2eafec7\"\u003e\u003ccode\u003ea5d63bc\u003c/code\u003e\u003c/a\u003e feat: add post-processing for markdown doc files\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/commit/97517203737c5d382c32632b84b57892fa023519\"\u003e\u003ccode\u003e9751720\u003c/code\u003e\u003c/a\u003e fix: resolve SCSS imports using package.json exports map\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/AlaskaAirlines/auro-cli/compare/v3.5.1...v3.7.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/AlaskaAirlines/auro-library/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/AlaskaAirlines/auro-library/pull/287","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/AlaskaAirlines%2Fauro-library/issues/287","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/287/packages"}},{"old_version":"8.9.0","new_version":"8.10.0","update_type":"minor","path":null,"pr_created_at":"2026-08-07T20:44:14.000Z","version_change":"8.9.0 → 8.10.0","issue":{"uuid":"5093830529","node_id":"PR_kwDOTpN49s78N9jy","number":3,"state":"open","title":"build(deps): bump undici from 8.9.0 to 8.10.0","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T20:44:14.000Z","updated_at":"2026-08-07T20:44:41.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"undici","old_version":"8.9.0","new_version":"8.10.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 8.9.0 to 8.10.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: namespace h2 options by \u003ca href=\"https://github.com/metcoder95\"\u003e\u003ccode\u003e@​metcoder95\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5498\"\u003enodejs/undici#5498\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: update WPT expectations by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5587\"\u003enodejs/undici#5587\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: add cache/dedupe + dns re-dispatch integration tests by \u003ca href=\"https://github.com/GiHoon1123\"\u003e\u003ccode\u003e@​GiHoon1123\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5535\"\u003enodejs/undici#5535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): support process.unref by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5578\"\u003enodejs/undici#5578\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): ensure every request settles by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5603\"\u003enodejs/undici#5603\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(readable): consume a body whose end has already been emitted by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5617\"\u003enodejs/undici#5617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): skip the content-length checkpoint for HEAD and for a 206 without content-range by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5610\"\u003enodejs/undici#5610\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: revert idle socket validation to setTimeout(0) to prevent stall on idle event loop by \u003ca href=\"https://github.com/marceli1404\"\u003e\u003ccode\u003e@​marceli1404\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5606\"\u003enodejs/undici#5606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(env-http-proxy-agent): match bare IPv6 addresses in no_proxy by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5623\"\u003enodejs/undici#5623\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: handle aggregate balanced pool errors by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5377\"\u003enodejs/undici#5377\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(readable): keep body bytes that arrive after setEncoding() by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5620\"\u003enodejs/undici#5620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(socks5): evict unused origin pools by \u003ca href=\"https://github.com/Kkartik14\"\u003e\u003ccode\u003e@​Kkartik14\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5595\"\u003enodejs/undici#5595\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: skip deduplication for upgrade requests by \u003ca href=\"https://github.com/Ram-blip\"\u003e\u003ccode\u003e@​Ram-blip\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5593\"\u003enodejs/undici#5593\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward informational responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5625\"\u003enodejs/undici#5625\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(mock): non-string path matchers under ignoreTrailingSlash, and DataView reply bodies by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5619\"\u003enodejs/undici#5619\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(interceptors): cache() and deduplicate() silently inert on Client/Pool without opts.origin by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5628\"\u003enodejs/undici#5628\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5633\"\u003enodejs/undici#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/init from 4.36.2 to 4.37.3 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5634\"\u003enodejs/undici#5634\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.4.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5636\"\u003enodejs/undici#5636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(mock): emit request body lifecycle hooks by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5367\"\u003enodejs/undici#5367\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): detach upgrade close handler after GOAWAY by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5641\"\u003enodejs/undici#5641\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: retry refused HTTP/2 streams by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5598\"\u003enodejs/undici#5598\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: preserve DNS origin hostname on sockets by \u003ca href=\"https://github.com/cyphercodes\"\u003e\u003ccode\u003e@​cyphercodes\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5577\"\u003enodejs/undici#5577\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marceli1404\"\u003e\u003ccode\u003e@​marceli1404\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5606\"\u003enodejs/undici#5606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kkartik14\"\u003e\u003ccode\u003e@​Kkartik14\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5595\"\u003enodejs/undici#5595\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5641\"\u003enodejs/undici#5641\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cyphercodes\"\u003e\u003ccode\u003e@​cyphercodes\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5577\"\u003enodejs/undici#5577\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v8.9.0...v8.10.0\"\u003ehttps://github.com/nodejs/undici/compare/v8.9.0...v8.10.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/c8d80e6b2dcfab282557b08f51352937bc9e5692\"\u003e\u003ccode\u003ec8d80e6\u003c/code\u003e\u003c/a\u003e Bumped v8.10.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5644\"\u003e#5644\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66923b47dc1ed095581daa6a53b2ad1bf3e899b4\"\u003e\u003ccode\u003e66923b4\u003c/code\u003e\u003c/a\u003e fix: preserve DNS origin hostname on sockets (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5577\"\u003e#5577\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/392649944c3b989681af1eae2e0970661f9ca464\"\u003e\u003ccode\u003e3926499\u003c/code\u003e\u003c/a\u003e fix: retry refused HTTP/2 streams (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5598\"\u003e#5598\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/73d6e9e19df47f85625d2dc082daa919ae6636c1\"\u003e\u003ccode\u003e73d6e9e\u003c/code\u003e\u003c/a\u003e fix(h2): detach upgrade close handler after GOAWAY (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5641\"\u003e#5641\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b111adbb675ebfcfa52790346dcd88e61c700818\"\u003e\u003ccode\u003eb111adb\u003c/code\u003e\u003c/a\u003e fix(mock): emit request body lifecycle hooks (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5367\"\u003e#5367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ae4a3e37a2ddfe798b64771176e31e8e7819c743\"\u003e\u003ccode\u003eae4a3e3\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/setup-node from 6.4.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5636\"\u003e#5636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ec3fbf19aa47eca6decc390b66bf56034bc03d52\"\u003e\u003ccode\u003eec3fbf1\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action/init from 4.36.2 to 4.37.3 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5634\"\u003e#5634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/21517200296205f3aa09a7b976dde571b441405c\"\u003e\u003ccode\u003e2151720\u003c/code\u003e\u003c/a\u003e build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5633\"\u003e#5633\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b96a11620e2f9fe5adafa2ba7b7f363b96b5a9d7\"\u003e\u003ccode\u003eb96a116\u003c/code\u003e\u003c/a\u003e fix(interceptors): allow interceptors without opts.origin (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5628\"\u003e#5628\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/a18ef2d05af48047339be51d8817492abc30f39d\"\u003e\u003ccode\u003ea18ef2d\u003c/code\u003e\u003c/a\u003e fix(mock): non-string path matchers under ignoreTrailingSlash, and DataView r...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v8.9.0...v8.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=8.9.0\u0026new-version=8.10.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Priyanshu91930/teraapi/pull/3","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Priyanshu91930%2Fteraapi/issues/3","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/3/packages"}},{"old_version":"6.23.0","new_version":"6.28.0","update_type":"minor","path":"/mobile","pr_created_at":"2026-08-07T20:29:21.000Z","version_change":"6.23.0 → 6.28.0","issue":{"uuid":"5093740783","node_id":"PR_kwDOQv0FkM78NrFC","number":119,"state":"open","title":"chore(deps): bump undici from 6.23.0 to 6.28.0 in /mobile","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T20:29:21.000Z","updated_at":"2026-08-07T20:29:28.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"undici","old_version":"6.23.0","new_version":"6.28.0","repository_url":"https://github.com/nodejs/undici"}],"path":"/mobile","ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 6.23.0 to 6.28.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.28.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e740a0b7c\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003ecba3a52a\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e4fd5a0c6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003eaf748404\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e and \u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ehttps://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.27.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e4 security advisories\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 6.27.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^6.27.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on patched version:\u003c/strong\u003e the v6 fixes shipped in \u003cstrong\u003ev6.27.0\u003c/strong\u003e, not \u003ccode\u003e6.26.0\u003c/code\u003e\n— \u003ccode\u003ev6.26.0\u003c/code\u003e contains only the chunked-EOF fix (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5308\"\u003e#5308\u003c/a\u003e) and the version bump, none\nof the security fixes below.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v6 line is \u003cstrong\u003enot\u003c/strong\u003e affected by the SOCKS5 advisories (GHSA-vmh5-mc38-953g,\nGHSA-hm92-r4w5-c3mj), the shared-cache disclosure (GHSA-pr7r-676h-xcf6), or the\n8.x-only WebSocket regression (GHSA-38rv-x7px-6hhq).\u003c/p\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7\"\u003e\u003ccode\u003eb7f252e7\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447\"\u003e\u003ccode\u003e25efa447\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447\"\u003e\u003ccode\u003e25efa447\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f4c31d60\"\u003e\u003ccode\u003ef4c31d60\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003ch2\u003eHigh severity\u003c/h2\u003e\n\u003ch3\u003eWebSocket DoS via fragment count bypass — CVE-2026-12151\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/strong\u003e · CWE-400, CWE-770\n\u003cstrong\u003eFix:\u003c/strong\u003e \u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7\"\u003e\u003ccode\u003eb7f252e7\u003c/code\u003e\u003c/a\u003e \u003cem\u003eBackport WebSocket maxPayloadSize fixes\u003c/em\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5423\"\u003e#5423\u003c/a\u003e, backported to v6 in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5428\"\u003e#5428\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eA malicious WebSocket server can stream a large number of small or empty\ncontinuation frames. Undici enforced a limit on cumulative payload size but did\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a\"\u003e\u003ccode\u003e01a912e\u003c/code\u003e\u003c/a\u003e Bumped v6.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5591\"\u003e#5591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e\"\u003e\u003ccode\u003e481ecfc\u003c/code\u003e\u003c/a\u003e Use Node 22 and npm 11 to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e\u003ccode\u003e740a0b7\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0\"\u003e\u003ccode\u003e2698e49\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e\u003ccode\u003e4fd5a0c\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003e\u003ccode\u003ecba3a52\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003e\u003ccode\u003eaf74840\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/551138cbc1742c92242a68216167761075e8a82c\"\u003e\u003ccode\u003e551138c\u003c/code\u003e\u003c/a\u003e Bumped v6.27.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5431\"\u003e#5431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7c0841418fb9d95cd297bdd9fad9d2a53\"\u003e\u003ccode\u003eb7f252e\u003c/code\u003e\u003c/a\u003e Backport WebSocket maxPayloadSize fixes to v7.x (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5423\"\u003e#5423\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5428\"\u003e#5428\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447997f74d5881edd144525c3fd7db945a4\"\u003e\u003ccode\u003e25efa44\u003c/code\u003e\u003c/a\u003e fix(cookies): preserve values and parse SameSite strictly\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.23.0...v6.28.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=6.23.0\u0026new-version=6.28.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/nexora-africa-ltd/vitora/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/nexora-africa-ltd/vitora/pull/119","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/nexora-africa-ltd%2Fvitora/issues/119","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/119/packages"}},{"old_version":"7.15.0","new_version":"7.29.0","update_type":"minor","path":null,"pr_created_at":"2026-08-07T18:34:27.000Z","version_change":"7.15.0 → 7.29.0","issue":{"uuid":"5092978113","node_id":"PR_kwDOQUVehM78LOua","number":3,"state":"open","title":"build(deps): bump the npm_and_yarn group across 2 directories with 8 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T18:34:27.000Z","updated_at":"2026-08-07T18:36:17.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":8,"packages":[{"name":"axios","old_version":"1.12.2","new_version":"1.18.0","repository_url":"https://github.com/axios/axios"},{"name":"undici","old_version":"7.15.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"},{"name":"dompurify","old_version":"3.2.6","new_version":"3.4.13","repository_url":"https://github.com/cure53/DOMPurify"},{"name":"shell-quote","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/ljharb/shell-quote"},{"name":"next","old_version":"15.2.5","new_version":"15.5.21","repository_url":"https://github.com/vercel/next.js"},{"name":"postcss","old_version":"8.5.4","new_version":"8.5.23","repository_url":"https://github.com/postcss/postcss"},{"name":"electron","old_version":"34.4.1","new_version":"39.8.10","repository_url":"https://github.com/electron/electron"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 7 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [axios](https://github.com/axios/axios) | `1.12.2` | `1.18.0` |\n| [undici](https://github.com/nodejs/undici) | `7.15.0` | `7.29.0` |\n| [dompurify](https://github.com/cure53/DOMPurify) | `3.2.6` | `3.4.13` |\n| [shell-quote](https://github.com/ljharb/shell-quote) | `1.8.2` | `1.9.0` |\n| [next](https://github.com/vercel/next.js) | `15.2.5` | `15.5.21` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.4` | `8.5.23` |\n| [electron](https://github.com/electron/electron) | `34.4.1` | `39.8.10` |\n\nBumps the npm_and_yarn group with 3 updates in the /jetbrains/host directory: [undici](https://github.com/nodejs/undici), [postcss](https://github.com/postcss/postcss) and [electron](https://github.com/electron/electron).\n\nUpdates `axios` from 1.12.2 to 1.18.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/releases\"\u003eaxios's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.18.0 — June 13, 2026\u003c/h2\u003e\n\u003cp\u003eThis release hardens redirect and URL handling, improves the validateStatus configuration semantics, and includes updates to documentation, dependencies, and release metadata.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRedirect Header Safety:\u003c/strong\u003e Added Node HTTP adapter support for stripping caller-specified sensitive headers on cross-origin redirects, helping prevent custom auth headers such as API keys from leaking to another origin. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eURL And Request Hardening:\u003c/strong\u003e Rejects malformed \u003ccode\u003ehttp:\u003c/code\u003e and \u003ccode\u003ehttps:\u003c/code\u003e URLs that omit \u003ccode\u003e//\u003c/code\u003e with \u003ccode\u003eERR_INVALID_URL\u003c/code\u003e, while tightening prototype-pollution-safe config reads, stream size limits, FormData depth handling, data URL sizing, and local \u003ccode\u003eNO_PROXY\u003c/code\u003e matching. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eStatus Validation:\u003c/strong\u003e Added \u003ccode\u003etransitional.validateStatusUndefinedResolves\u003c/code\u003e so applications can opt in to treating \u003ccode\u003evalidateStatus: undefined\u003c/code\u003e like the option was omitted, while \u003ccode\u003evalidateStatus: null\u003c/code\u003e remains the explicit way to accept every status. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation:\u003c/strong\u003e Published the v1.17.0 release notes, fixed a changelog typo, clarified the package update PR policy, and marked the \u003ccode\u003eproxy\u003c/code\u003e request config as Node.js-only in the advanced docs. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDependencies:\u003c/strong\u003e Bumped \u003ccode\u003e@babel/core\u003c/code\u003e, \u003ccode\u003e@babel/preset-env\u003c/code\u003e, \u003ccode\u003e@commitlint/cli\u003c/code\u003e, \u003ccode\u003e@commitlint/config-conventional\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-babel\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-commonjs\u003c/code\u003e, \u003ccode\u003e@vitest/browser\u003c/code\u003e, \u003ccode\u003e@vitest/browser-playwright\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003elint-staged\u003c/code\u003e, \u003ccode\u003erollup\u003c/code\u003e, \u003ccode\u003evitest\u003c/code\u003e, and \u003ccode\u003eactions/checkout\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10996\"\u003e#10996\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10997\"\u003e#10997\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRelease Metadata:\u003c/strong\u003e Prepared the 1.18.0 release by updating package metadata and the runtime \u003ccode\u003eVERSION\u003c/code\u003e value. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/drori12\"\u003e\u003ccode\u003e@​drori12\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/eyupcanakman\"\u003e\u003ccode\u003e@​eyupcanakman\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/Adi-Beker\"\u003e\u003ccode\u003e@​Adi-Beker\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/axios/axios/compare/v1.17.0...v1.18.0\"\u003eFull Changelog\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.17.0 — June 1, 2026\u003c/h2\u003e\n\u003cp\u003eThis release adds Node HTTP zstd decompression, hardens config and release workflows, and fixes authentication, header, proxy, and type-handling regressions.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eConfig Hardening:\u003c/strong\u003e Guarded \u003ccode\u003esocketPath\u003c/code\u003e, \u003ccode\u003eparams\u003c/code\u003e, and \u003ccode\u003eparamsSerializer\u003c/code\u003e reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10901\"\u003e#10901\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10922\"\u003e#10922\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRelease Publishing:\u003c/strong\u003e Switched the publish workflow to npm staged publishing for safer, auditable package releases with provenance. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10926\"\u003e#10926\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚀 New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP Compression:\u003c/strong\u003e Added Node HTTP adapter support for zstd response decompression, with \u003ccode\u003etransitional.advertiseZstdAcceptEncoding\u003c/code\u003e controlling whether \u003ccode\u003ezstd\u003c/code\u003e is advertised in \u003ccode\u003eAccept-Encoding\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/6792\"\u003e#6792\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10920\"\u003e#10920\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eAuthentication Handling:\u003c/strong\u003e Restored Basic auth on same-origin Node redirects while continuing to strip credentials cross-origin, and aligned the fetch adapter with HTTP adapter behavior for URL-embedded Basic auth. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10929\"\u003e#10929\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10896\"\u003e#10896\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eProxy TLS:\u003c/strong\u003e Preserved user \u003ccode\u003ehttpsAgent\u003c/code\u003e TLS options when tunneling HTTPS requests through HTTP CONNECT proxies. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10957\"\u003e#10957\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReact Native FormData:\u003c/strong\u003e Cleared default \u003ccode\u003eContent-Type\u003c/code\u003e for React Native \u003ccode\u003eFormData\u003c/code\u003e so multipart boundaries can be generated correctly. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10898\"\u003e#10898\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/blob/v1.x/CHANGELOG.md\"\u003eaxios's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.18.0 — June 13, 2026\u003c/h2\u003e\n\u003cp\u003eThis release hardens redirect and URL handling, improves the validateStatus configuration semantics, and includes updates to documentation, dependencies, and release metadata.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRedirect Header Safety:\u003c/strong\u003e Added Node HTTP adapter support for stripping caller-specified sensitive headers on cross-origin redirects, helping prevent custom auth headers such as API keys from leaking to another origin. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eURL And Request Hardening:\u003c/strong\u003e Rejects malformed \u003ccode\u003ehttp:\u003c/code\u003e and \u003ccode\u003ehttps:\u003c/code\u003e URLs that omit \u003ccode\u003e//\u003c/code\u003e with \u003ccode\u003eERR_INVALID_URL\u003c/code\u003e, while tightening prototype-pollution-safe config reads, stream size limits, FormData depth handling, data URL sizing, and local \u003ccode\u003eNO_PROXY\u003c/code\u003e matching. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eStatus Validation:\u003c/strong\u003e Added \u003ccode\u003etransitional.validateStatusUndefinedResolves\u003c/code\u003e so applications can opt in to treating \u003ccode\u003evalidateStatus: undefined\u003c/code\u003e like the option was omitted, while \u003ccode\u003evalidateStatus: null\u003c/code\u003e remains the explicit way to accept every status. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation:\u003c/strong\u003e Published the v1.17.0 release notes, fixed a changelog typo, clarified the package update PR policy, and marked the \u003ccode\u003eproxy\u003c/code\u003e request config as Node.js-only in the advanced docs. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDependencies:\u003c/strong\u003e Bumped \u003ccode\u003e@babel/core\u003c/code\u003e, \u003ccode\u003e@babel/preset-env\u003c/code\u003e, \u003ccode\u003e@commitlint/cli\u003c/code\u003e, \u003ccode\u003e@commitlint/config-conventional\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-babel\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-commonjs\u003c/code\u003e, \u003ccode\u003e@vitest/browser\u003c/code\u003e, \u003ccode\u003e@vitest/browser-playwright\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003elint-staged\u003c/code\u003e, \u003ccode\u003erollup\u003c/code\u003e, \u003ccode\u003evitest\u003c/code\u003e, and \u003ccode\u003eactions/checkout\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10996\"\u003e#10996\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10997\"\u003e#10997\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRelease Metadata:\u003c/strong\u003e Prepared the 1.18.0 release by updating package metadata and the runtime \u003ccode\u003eVERSION\u003c/code\u003e value. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/drori12\"\u003e\u003ccode\u003e@​drori12\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/eyupcanakman\"\u003e\u003ccode\u003e@​eyupcanakman\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/Adi-Beker\"\u003e\u003ccode\u003e@​Adi-Beker\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/axios/axios/compare/v1.17.0...v1.18.0\"\u003eFull Changelog\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.17.0 — June 1, 2026\u003c/h2\u003e\n\u003cp\u003eThis release adds Node HTTP zstd decompression, hardens config and release workflows, and fixes authentication, header, proxy, and type-handling regressions.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eConfig Hardening:\u003c/strong\u003e Guarded \u003ccode\u003esocketPath\u003c/code\u003e, \u003ccode\u003eparams\u003c/code\u003e, and \u003ccode\u003eparamsSerializer\u003c/code\u003e reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10901\"\u003e#10901\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10922\"\u003e#10922\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRelease Publishing:\u003c/strong\u003e Switched the publish workflow to npm staged publishing for safer, auditable package releases with provenance. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10926\"\u003e#10926\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚀 New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP Compression:\u003c/strong\u003e Added Node HTTP adapter support for zstd response decompression, with \u003ccode\u003etransitional.advertiseZstdAcceptEncoding\u003c/code\u003e controlling whether \u003ccode\u003ezstd\u003c/code\u003e is advertised in \u003ccode\u003eAccept-Encoding\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/6792\"\u003e#6792\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10920\"\u003e#10920\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eAuthentication Handling:\u003c/strong\u003e Restored Basic auth on same-origin Node redirects while continuing to strip credentials cross-origin, and aligned the fetch adapter with HTTP adapter behavior for URL-embedded Basic auth. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10929\"\u003e#10929\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10896\"\u003e#10896\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eProxy TLS:\u003c/strong\u003e Preserved user \u003ccode\u003ehttpsAgent\u003c/code\u003e TLS options when tunneling HTTPS requests through HTTP CONNECT proxies. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10957\"\u003e#10957\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReact Native FormData:\u003c/strong\u003e Cleared default \u003ccode\u003eContent-Type\u003c/code\u003e for React Native \u003ccode\u003eFormData\u003c/code\u003e so multipart boundaries can be generated correctly. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10898\"\u003e#10898\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/2d06f96e8602c2db13b65a26340ee4a1bbc0b61f\"\u003e\u003ccode\u003e2d06f96\u003c/code\u003e\u003c/a\u003e chore(release): prepare release 1.18.0 (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/32fc489632377d214db55bfa4e2c48486a7d7ce2\"\u003e\u003ccode\u003e32fc489\u003c/code\u003e\u003c/a\u003e fix: malformed http urls (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/b40ce498abfa10d90b873b4fd08f520afa5d2545\"\u003e\u003ccode\u003eb40ce49\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump the development_dependencies group with 10 updates (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10\"\u003e#10\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/fe964f960ecb52c3e1155b0daf7be77541956b01\"\u003e\u003ccode\u003efe964f9\u003c/code\u003e\u003c/a\u003e docs: mark proxy config as Node.js only (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/5f229d2d1f018d1db3dab6bbe034dbf3f9041b99\"\u003e\u003ccode\u003e5f229d2\u003c/code\u003e\u003c/a\u003e chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/fae9d4e7db6a858c407c75e607a071c533c5c4f6\"\u003e\u003ccode\u003efae9d4e\u003c/code\u003e\u003c/a\u003e docs: clarify package update PR policy (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/28ab2ced820e55192806c53472ab3eb0cbb68dc2\"\u003e\u003ccode\u003e28ab2ce\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump the development_dependencies group with 2 updates (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/a8e4f13aeecc45a3b8fab3ecfd9ddb5d70fb772b\"\u003e\u003ccode\u003ea8e4f13\u003c/code\u003e\u003c/a\u003e fix(core): keep default validateStatus when request passes undefined (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/614f4552a17de757d4171ad7c3bd38c9c1025fd8\"\u003e\u003ccode\u003e614f455\u003c/code\u003e\u003c/a\u003e docs: publish v1.17.0 release notes (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/6bb12c191f5380fad321322fb90216ae0dc36985\"\u003e\u003ccode\u003e6bb12c1\u003c/code\u003e\u003c/a\u003e fix: custom auth headers not stripped on cross-origin redirects (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/axios/axios/compare/v1.12.2...v1.18.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for axios since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version modifies \u003ccode\u003eprepare\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.15.0 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.28.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e7 security advisories\u003c/strong\u003e, all shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 7.28.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^7.28.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v7 line is \u003cstrong\u003enot\u003c/strong\u003e affected by GHSA-38rv-x7px-6hhq (CVE-2026-9675), which is\nan 8.x-only regression.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on GHSA-hm92-r4w5-c3mj:\u003c/strong\u003e this fix shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e, not the\nearlier 7.2x line — the vulnerable single-pool code was still present through\n\u003ccode\u003ev7.27.2\u003c/code\u003e. The per-origin pool fix is\n\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5041\"\u003e#5041\u003c/a\u003e).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8cb10f98\"\u003e\u003ccode\u003e8cb10f98\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g\"\u003eGHSA-vmh5-mc38-953g\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9697\u003c/td\u003e\n\u003ctd\u003eHigh (7.4)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/04201f89\"\u003e\u003ccode\u003e04201f89\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj\"\u003eGHSA-hm92-r4w5-c3mj\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6734\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6\"\u003eGHSA-pr7r-676h-xcf6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9678\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/85a24055\"\u003e\u003ccode\u003e85a24055\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ea8930cf\"\u003e\u003ccode\u003eea8930cf\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f9eba0ad9134e1c0977848476bba9d49734696e4\"\u003e\u003ccode\u003ef9eba0a\u003c/code\u003e\u003c/a\u003e Bumped v7.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5430\"\u003e#5430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.15.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for undici since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `dompurify` from 3.2.6 to 3.4.13\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cure53/DOMPurify/releases\"\u003edompurify's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eDOMPurify 3.4.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue with hook removal during \u003ccode\u003eIN_PLACE\u003c/code\u003e sanitization, thanks \u003ca href=\"https://github.com/koyokr\"\u003e\u003ccode\u003e@​koyokr\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue with hooks potentially bypassing the clone guard, thanks \u003ca href=\"https://github.com/AkshayjainG\"\u003e\u003ccode\u003e@​AkshayjainG\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue with DOM clobbering via \u003ccode\u003eownerDocument\u003c/code\u003e during \u003ccode\u003eIN_PLACE\u003c/code\u003e, thanks \u003ca href=\"https://github.com/AkshayjainG\"\u003e\u003ccode\u003e@​AkshayjainG\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where a hook would not get called for custom elements, thanks \u003ca href=\"https://github.com/Rikuxx0\"\u003e\u003ccode\u003e@​Rikuxx0\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHardened the handling of hooks removing elements, \u003ca href=\"https://github.com/mkrause-bee360\"\u003e\u003ccode\u003e@​mkrause-bee360\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded support for a few new SVG attributes, thanks \u003ca href=\"https://github.com/cbn-falias\"\u003e\u003ccode\u003e@​cbn-falias\u003c/code\u003e\u003c/a\u003e \u0026amp; \u003ca href=\"https://github.com/Develop-KIM\"\u003e\u003ccode\u003e@​Develop-KIM\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHardened the handling of declarative partial updates\u003c/li\u003e\n\u003cli\u003eUpdated the documentation is several spots, README, wiki, etc.\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue with a leaky config for hooks via \u003ccode\u003esetConfig\u003c/code\u003e, thanks \u003ca href=\"https://github.com/trace37labs\"\u003e\u003ccode\u003e@​trace37labs\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBumped vulnerable development dependencies to arrive at plain 0 with \u003ccode\u003enpm audit\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eUpdated the \u003ccode\u003eosv-scanner\u003c/code\u003e suppression list as no vulnerable dependencies are left for now\u003c/li\u003e\n\u003cli\u003eUpdated up the linting tool-chain and removed now-redundant lint directives\u003c/li\u003e\n\u003cli\u003eUpdated the documentation is several spots, README, wiki, etc.\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.10\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRefactored codebase for clarity: extracted the public type declarations into \u003ccode\u003etypes.ts\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eDecomposed the three largest sanitizer functions into focused helpers\u003c/li\u003e\n\u003cli\u003eRemoved duplicated defaults and dead branches, consolidated \u003ccode\u003eSAFE_FOR_TEMPLATES\u003c/code\u003e scrubbing into single shared path\u003c/li\u003e\n\u003cli\u003eImproved per-node performance by hoisting the mXSS probe regexes and testing \u003ccode\u003etextContent\u003c/code\u003e before \u003ccode\u003einnerHTML\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdded a deterministic micro-benchmark harness (\u003ccode\u003enpm run bench\u003c/code\u003e) with a \u003ccode\u003e--compare\u003c/code\u003e mode\u003c/li\u003e\n\u003cli\u003eReduced CI cost by running the full three-engine browser suite once per PR\u003c/li\u003e\n\u003cli\u003eRefreshed the \u003ccode\u003edemos/\u003c/code\u003e folder so every demo runs again, and added a SVG-via-\u003ccode\u003e\u0026lt;img\u0026gt;\u003c/code\u003e demo\u003c/li\u003e\n\u003cli\u003eDocumented the bench and \u003ccode\u003etest:happydom\u003c/code\u003e scripts in the README\u003c/li\u003e\n\u003cli\u003eCompleted the Attack Classes \u0026amp; Bypass History wiki page\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFurther improved the handling of Trusted Types config options, thanks \u003ca href=\"https://github.com/offset\"\u003e\u003ccode\u003e@​offset\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFurther improved the handling of \u003ccode\u003eIN_PLACE\u003c/code\u003e sanitization, thanks \u003ca href=\"https://github.com/mozfreddyb\"\u003e\u003ccode\u003e@​mozfreddyb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded more test coverage for \u003ccode\u003eIN_PLACE\u003c/code\u003e and Trusted Types related usage\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003cli\u003eUpdated README and wiki with more accurate documentation \u0026amp; attack samples\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCleaned up the repository root, renamed some and removed unneeded files\u003c/li\u003e\n\u003cli\u003eFixed an issue with handling of Trusted Types policies, thanks \u003ca href=\"https://github.com/fulstadev\"\u003e\u003ccode\u003e@​fulstadev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed the node iterator for better template scrubbing, thanks \u003ca href=\"https://github.com/IamLeandrooooo\"\u003e\u003ccode\u003e@​IamLeandrooooo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIncluded formerly missing LICENSE-MPL in published npm package, thanks \u003ca href=\"https://github.com/asamuzaK\"\u003e\u003ccode\u003e@​asamuzaK\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHardened the handling of Shadow Roots when using \u003ccode\u003eIN_PLACE\u003c/code\u003e, thanks \u003ca href=\"https://github.com/GameZoneHacker\"\u003e\u003ccode\u003e@​GameZoneHacker\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/3067f774676975de12306effd6db6ad7a9a8c17f\"\u003e\u003ccode\u003e3067f77\u003c/code\u003e\u003c/a\u003e release: 3.4.13 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1562\"\u003e#1562\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/a9ca1e537422319a557a9a2aa61f003b23b4a197\"\u003e\u003ccode\u003ea9ca1e5\u003c/code\u003e\u003c/a\u003e release: 3.4.12 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1537\"\u003e#1537\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/0cae5187403132f96a6d357649e4b15633fc210a\"\u003e\u003ccode\u003e0cae518\u003c/code\u003e\u003c/a\u003e release: 3.4.11 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1494\"\u003e#1494\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/6ee5716f8336989753611beeca364957c0eb0c3e\"\u003e\u003ccode\u003e6ee5716\u003c/code\u003e\u003c/a\u003e release: 3.4.10 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1478\"\u003e#1478\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/52102472d46035857c52df19e44285f8a1e102fc\"\u003e\u003ccode\u003e5210247\u003c/code\u003e\u003c/a\u003e release: 3.4.9 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1459\"\u003e#1459\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/bcdd8285412dc9c4c149652aed2d712e790d6ccf\"\u003e\u003ccode\u003ebcdd828\u003c/code\u003e\u003c/a\u003e release: 3.4.8 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1439\"\u003e#1439\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/ca30f070c360df162a3e3848e80e6fd3c9e74bff\"\u003e\u003ccode\u003eca30f07\u003c/code\u003e\u003c/a\u003e release: 3.4.7 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1414\"\u003e#1414\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/bb7739e5bccec7e1ab3dae3f3e42d02db3acaaae\"\u003e\u003ccode\u003ebb7739e\u003c/code\u003e\u003c/a\u003e release: 3.4.6 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1394\"\u003e#1394\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/011b0c78f2a0f57ee54f5fcccb697a46ca6e63ea\"\u003e\u003ccode\u003e011b0c7\u003c/code\u003e\u003c/a\u003e release: 3.4.5 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1382\"\u003e#1382\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/5817ad969c15e67dfcd6cb37248d6e9c1553e7c3\"\u003e\u003ccode\u003e5817ad9\u003c/code\u003e\u003c/a\u003e release: 3.4.4 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1374\"\u003e#1374\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/cure53/DOMPurify/compare/3.2.6...3.4.13\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version adds \u003ccode\u003eprepare\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `shell-quote` from 1.8.2 to 1.9.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md\"\u003eshell-quote's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.4...v1.9.0\"\u003ev1.9.0\u003c/a\u003e - 2026-06-24\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[New] add types \u003ca href=\"https://github.com/ljharb/shell-quote/commit/dca6e21a02df4cc1a83ed1b5baa4d82df134170a\"\u003e\u003ccode\u003edca6e21\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9aa9e8f60991f8c4053a29e476795d891ff851ad\"\u003e\u003ccode\u003e9aa9e8f\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: finalize tokens in linear time (GHSA-395f-4hp3-45gv) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7ff5488599d01c323514f02f5efb74088dd134ec\"\u003e\u003ccode\u003e7ff5488\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] update workflows \u003ca href=\"https://github.com/ljharb/shell-quote/commit/75e849741ffaf2d3aa53ae0e18ef6bf9929ef478\"\u003e\u003ccode\u003e75e8497\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 4/6/7: pin eslint to 9 before install, since npm 2/3 cannot stage eslint 10\u003ccode\u003e@types/esrecurse\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3fb739de44b81c69431947d54fbfc18998dd6d72\"\u003e\u003ccode\u003e3fb739d\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] retry \u003ccode\u003enpm install\u003c/code\u003e on Windows to survive npm 2/3 staging-rename flake \u003ca href=\"https://github.com/ljharb/shell-quote/commit/abe0163293c82963fa8a16cfaa87181846d5aced\"\u003e\u003ccode\u003eabe0163\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 5/7: install deps with a modern node \u003ca href=\"https://github.com/ljharb/shell-quote/commit/b4bafa2e7e58d53d9839b1c24976f61e54b43326\"\u003e\u003ccode\u003eb4bafa2\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: escape leading \u003ccode\u003e~\u003c/code\u003e to prevent shell tilde-expansion \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7a76c1a12d8461c2234a1c655b943cee84cbff91\"\u003e\u003ccode\u003e7a76c1a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7184b4458b65c17b931e126d8cb5f586c6717dc8\"\u003e\u003ccode\u003e7184b44\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] apparently \u003ccode\u003ejackspeak\u003c/code\u003e is no longer in the graph \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9ba368a4057b9f498b0fef23b5b15543ef81b98c\"\u003e\u003ccode\u003e9ba368a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.3...v1.8.4\"\u003ev1.8.4\u003c/a\u003e - 2026-05-22\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: validate object-token shapes \u003ca href=\"https://github.com/ljharb/shell-quote/commit/4378a6e613db5948168684864e49b42b83134d2d\"\u003e\u003ccode\u003e4378a6e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003enpmignore\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/22ebec04349065a45ad8afc8cc8d53c4624634a6\"\u003e\u003ccode\u003e22ebec0\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] increase coverage \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9f3caa31900cc6ee64858b31134144c648ce206d\"\u003e\u003ccode\u003e9f3caa3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] replace runkit CI badge with shields.io check-runs badge \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3344a047dd1e95f71c4ca27522cbfd05c56277e0\"\u003e\u003ccode\u003e3344a04\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/699c5113d135f4d4591574bebf173334ffa453d4\"\u003e\u003ccode\u003e699c511\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.2...v1.8.3\"\u003ev1.8.3\u003c/a\u003e - 2025-06-01\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] remove unnecessary backslash escaping in single quotes \u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/15\"\u003e\u003ccode\u003e[#15](https://github.com/ljharb/shell-quote/issues/15)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/db09fc7a9e3546807c19e2de2682ec31112a6520\"\u003e\u003ccode\u003edb09fc7\u003c/code\u003e\u003c/a\u003e v1.9.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/7ff5488599d01c323514f02f5efb74088dd134ec\"\u003e\u003ccode\u003e7ff5488\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003eparse\u003c/code\u003e: finalize tokens in linear time (GHSA-395f-4hp3-45gv)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/b4bafa2e7e58d53d9839b1c24976f61e54b43326\"\u003e\u003ccode\u003eb4bafa2\u003c/code\u003e\u003c/a\u003e [actions] Windows + node 5/7: install deps with a modern node\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/3fb739de44b81c69431947d54fbfc18998dd6d72\"\u003e\u003ccode\u003e3fb739d\u003c/code\u003e\u003c/a\u003e [actions] Windows + node 4/6/7: pin eslint to 9 before install, since npm 2/3...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/abe0163293c82963fa8a16cfaa87181846d5aced\"\u003e\u003ccode\u003eabe0163\u003c/code\u003e\u003c/a\u003e [actions] retry \u003ccode\u003enpm install\u003c/code\u003e on Windows to survive npm 2/3 staging-rename flake\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/7a76c1a12d8461c2234a1c655b943cee84cbff91\"\u003e\u003ccode\u003e7a76c1a\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003equote\u003c/code\u003e: escape leading \u003ccode\u003e~\u003c/code\u003e to prevent shell tilde-expansion\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/75e849741ffaf2d3aa53ae0e18ef6bf9929ef478\"\u003e\u003ccode\u003e75e8497\u003c/code\u003e\u003c/a\u003e [actions] update workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/dca6e21a02df4cc1a83ed1b5baa4d82df134170a\"\u003e\u003ccode\u003edca6e21\u003c/code\u003e\u003c/a\u003e [New] add types\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/9aa9e8f60991f8c4053a29e476795d891ff851ad\"\u003e\u003ccode\u003e9aa9e8f\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/9ba368a4057b9f498b0fef23b5b15543ef81b98c\"\u003e\u003ccode\u003e9ba368a\u003c/code\u003e\u003c/a\u003e [Dev Deps] apparently \u003ccode\u003ejackspeak\u003c/code\u003e is no longer in the graph\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.2...v1.9.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `next` from 15.2.5 to 15.5.21\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev15.5.21\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eHigh:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-m99w-x7hq-7vfj\"\u003eDenial of Service in App Router using Server Actions\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-6gpp-xcg3-4w24\"\u003eMiddleware / Proxy bypass in App Router applications using Turbopack and single locale\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p9j2-gv94-2wf4\"\u003eServer-Side Request Forgery in rewrites via attacker-controlled destination hostname\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-89xv-2m56-2m9x\"\u003eServer-Side Request Forgery in Server Actions on custom servers\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eModerate:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-68g3-v927-f742\"\u003eCache confusion of response bodies for requests with bodies\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-4633-3j49-mh5q\"\u003eCache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-q8wf-6r8g-63ch\"\u003eDenial of Service in the Image Optimization API using SVGs\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-955p-x3mx-jcvp\"\u003eUnauthenticated disclosure of internal Server Function endpoints\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-4c39-4ccg-62r3\"\u003eUnbounded Server Action payload in Edge runtime\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev15.5.20\u003c/h2\u003e\n\u003cp\u003eContains no changes except publishing \u003ccode\u003e@next/swc-wasm-web\u003c/code\u003e which was accidentally not published since 15.5.15.\u003c/p\u003e\n\u003ch2\u003e15.5.19\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[15.5.x] Don't drop \u003ccode\u003eFormData\u003c/code\u003e entries (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/94244\"\u003e#94244\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[15.5.x] Fix CI (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/94281\"\u003e#94281\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/e26f6ffaa710fc62ca0c8640db0e43b6663edf32\"\u003e\u003ccode\u003ee26f6ff\u003c/code\u003e\u003c/a\u003e v15.5.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/7f5deeb6c594b7515edecb879b0547beba1b8a82\"\u003e\u003ccode\u003e7f5deeb\u003c/code\u003e\u003c/a\u003e [15.x] Improve performance of checking valid MPA form submissions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/57c31f724d746e86a9e8b92aa8be538a922446a4\"\u003e\u003ccode\u003e57c31f7\u003c/code\u003e\u003c/a\u003e [15.x] Enforce \u003ccode\u003eserverActions.bodySizeLimit\u003c/code\u003e for Server Actions in Edge runtime\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/e3e5666ccead3a15162793d697af5e48b7cc0498\"\u003e\u003ccode\u003ee3e5666\u003c/code\u003e\u003c/a\u003e [15.x] Set correct origin for internal redirects in custom server\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/35f501357e9b0fe7c950b0d6aa8fcf5343f707e9\"\u003e\u003ccode\u003e35f5013\u003c/code\u003e\u003c/a\u003e [15.x] Ensure exotic rewrite param values are properly encoded\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/062f66700b52a5d6bba2c0605d55577ab7ad262c\"\u003e\u003ccode\u003e062f667\u003c/code\u003e\u003c/a\u003e [15.x] fix(fetch-cache): key fetch(Request, init) by the effective request\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/577c9dc0a08ac806e35f591fec528d5fb7407ad4\"\u003e\u003ccode\u003e577c9dc\u003c/code\u003e\u003c/a\u003e [15.x] fix(incremental-cache): byte-exact fetch cache key for binary bodies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/530d4fa31e010a05f28ea6e26a5f51f80f61e0c6\"\u003e\u003ccode\u003e530d4fa\u003c/code\u003e\u003c/a\u003e [15.x] fix(next/image): improve performance of detectContentType()\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/8fabaf3225be100d62dfb0f44d85ab43c2a14a20\"\u003e\u003ccode\u003e8fabaf3\u003c/code\u003e\u003c/a\u003e [15.x] Performance improvements when decoding React Server function payloads\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/ff12a6124e1504f17b62de948b8a553fdecaef7b\"\u003e\u003ccode\u003eff12a61\u003c/code\u003e\u003c/a\u003e [15.x] Validate server reference IDs during manifest lookup\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v15.2.5...v15.5.21\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for next since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.4 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003epostcss-scss\u003c/code\u003e commend regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed reading any file via user-generated CSS.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eopts.unsafeMap\u003c/code\u003e to disable checks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed nested brackets parsing performance (by \u003ca href=\"https://github.com/offset\"\u003e\u003ccode\u003e@​offset\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.10\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed XSS via unescaped \u003ccode\u003e\u0026lt;/style\u0026gt;\u003c/code\u003e in non-bundler cases (by \u003ca href=\"https://github.com/TharVid\"\u003e\u003ccode\u003e@​TharVid\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.4...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `electron` from 34.4.1 to 39.8.10\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/electron/electron/releases\"\u003eelectron's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eelectron v39.8.10\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.10\u003c/h1\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!WARNING]\nElectron 39.x.y has reached end-of-support as per the project's \u003ca href=\"https://www.electronjs.org/docs/latest/tutorial/electron-timelines#version-support-policy\"\u003esupport policy\u003c/a\u003e. Developers and applications are encouraged to upgrade to a newer version of Electron.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eFixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnsured cross-origin \u003ccode\u003efetch()\u003c/code\u003e and XHR are blocked for custom protocols registered with \u003ccode\u003esupportFetchAPI: true\u003c/code\u003e unless \u003ccode\u003ecorsEnabled: true\u003c/code\u003e is also set; cross-origin \u003ccode\u003emode: 'no-cors'\u003c/code\u003e requests now receive an opaque response. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51272\"\u003e#51272\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/51271\"\u003e40\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/51270\"\u003e41\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/51269\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue where the Squirrel.Mac installer could resolve the target bundle path to different locations at different stages of an install. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50766\"\u003e#50766\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/50765\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eOther Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackported a fix for route_id validation in the GPU command buffer. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51327\"\u003e#51327\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBackported security fixes for 493319454, 494158331, 493234757, 492736100, 493413432, 492668885, 496281816. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51257\"\u003e#51257\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBackported several fixes in Skia, ANGLE, and WebRTC from upstream. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51266\"\u003e#51266\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eelectron v39.8.9\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.9\u003c/h1\u003e\n\u003ch2\u003eOther Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003egn gen\u003c/code\u003e failing to resolve \u003ccode\u003eelectron_version\u003c/code\u003e when building from a \u003ccode\u003egit worktree\u003c/code\u003e checkout. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51163\"\u003e#51163\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/51164\"\u003e40\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/51165\"\u003e41\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/51166\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: backported fixes for CVE-2026-6296, CVE-2026-6297, CVE-2026-6298, CVE-2026-6299, CVE-2026-6300, CVE-2026-6301, CVE-2026-6302, CVE-2026-6303, CVE-2026-6304, CVE-2026-6305, CVE-2026-6306, CVE-2026-6307, CVE-2026-6308, CVE-2026-6309, CVE-2026-6311, CVE-2026-6312, CVE-2026-6313, CVE-2026-6314, CVE-2026-6316, CVE-2026-6318, CVE-2026-6358, CVE-2026-6359, CVE-2026-6360, CVE-2026-6361, CVE-2026-6362, CVE-2026-6363, CVE-2026-6364. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51141\"\u003e#51141\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eelectron v39.8.8\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.8\u003c/h1\u003e\n\u003ch2\u003eFixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where DevTools would re-attach to the window when opened after previously being detached. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50818\"\u003e#50818\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/50817\"\u003e40\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/50816\"\u003e41\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/50815\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eOther Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackported fix for \u003ca href=\"https://issues.chromium.org/issues/474266014\"\u003echromium:74266014\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50175\"\u003e#50175\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBackported upstream v8 fixes for several maglev, inspector, and arm64 code-generation edge cases. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50993\"\u003e#50993\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eelectron v39.8.7\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.7\u003c/h1\u003e\n\u003ch2\u003eOther Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackported fix for 489711638. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50624\"\u003e#50624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBackported fix for 493952652. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50620\"\u003e#50620\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eelectron v39.8.6\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.6\u003c/h1\u003e\n\u003ch2\u003eFixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a crash when calling \u003ccode\u003econtentTracing.getTraceBufferUsage()\u003c/code\u003e while a trace session is active. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50595\"\u003e#50595\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/50593\"\u003e40\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/50594\"\u003e41\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/50592\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/d7c42ebd5cd501a0e6d9f009e232369832f92d69\"\u003e\u003ccode\u003ed7c42eb\u003c/code\u003e\u003c/a\u003e chore: backport removal of private macOS APIs (\u003ca href=\"https://redirect.github.com/electron/electron/issues/51502\"\u003e#51502\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/c76d48c5d94d4fe621befa1656b998220d016eeb\"\u003e\u003ccode\u003ec76d48c\u003c/code\u003e\u003c/a\u003e build: replace spec dep fork with transitive resolution (\u003ca href=\"https://redirect.github.com/electron/electron/issues/51490\"\u003e#51490\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/3ff23c52ab364a0afc6ab5bd7851291d3159de57\"\u003e\u003ccode\u003e3ff23c5\u003c/code\u003e\u003c/a\u003e fix: respect iframe sandbox flags on the OpenURL navigation path (\u003ca href=\"https://redirect.github.com/electron/electron/issues/51437\"\u003e#51437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/01faabfc250801a980fc94d64608046c67fc1cd9\"\u003e\u003ccode\u003e01faabf\u003c/code\u003e\u003c/a\u003e fix: resolve target bundle path once at start of install (\u003ca href=\"https://redirect.github.com/electron/electron/issues/50766\"\u003e#50766\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/8287d59922c85ea23cf3a540cd1b49b74074853d\"\u003e\u003ccode\u003e8287d59\u003c/code\u003e\u003c/a\u003e build(deps): bump dorny/paths-filter from 3.0.2 to 4.0.1 (\u003ca href=\"https://redirect.github.com/electron/electron/issues/51409\"\u003e#51409\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/a8a79eaf61fb2a211acc2e9f568137db8b47b682\"\u003e\u003ccode\u003ea8a79ea\u003c/code\u003e\u003c/a\u003e ci: backport secondary siso patch (\u003ca href=\"https://redirect.github.com/electron/electron/issues/51390\"\u003e#51390\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/593607e9c072312c4df6b61a83b172e441fdc72f\"\u003e\u003ccode\u003e593607e\u003c/code\u003e\u003c/a\u003e chore: cherry-pick 1 change from chromium (\u003ca href=\"https://redirect.github.com/electron/electron/issues/51327\"\u003e#51327\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/aa7791ff97c9cfcb0cd5e2001f4de704bbdf59cf\"\u003e\u003ccode\u003eaa7791f\u003c/code\u003e\u003c/a\u003e build: restrict npm tarball contents to an explicit allowlist (\u003ca href=\"https://redirect.github.com/electron/electron/issues/51307\"\u003e#51307\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/5392e9a9addc157d5d18e87947deed555488b3b5\"\u003e\u003ccode\u003e5392e9a\u003c/code\u003e\u003c/a\u003e fix: ensure corsEnabled: false protocol handlers do not work across protocols...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/electron/electron/commit/2c24640e7b0b9c74fe9f44bce0fde138340ff4fb\"\u003e\u003ccode\u003e2c24640\u003c/code\u003e\u003c/a\u003e fix: validate OSR frame geometry against shared-memory mapping size (39-x-y) ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/electron/electron/compare/v34.4.1...v39.8.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sharp` from 0.33.5 to 0.34.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lovell/sharp/releases\"\u003esharp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.34.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.17.3 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdd experimental support for prebuilt Linux RISC-V 64-bit binaries.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport building from source with npm v12+, deprecate \u003ccode\u003e--build-from-source\u003c/code\u003e flag.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4458\"\u003e#4458\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdd support for BigTIFF output.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4459\"\u003e#4459\u003c/a\u003e\n\u003ca href=\"https://github.com/throwbi\"\u003e\u003ccode\u003e@​throwbi\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove error messaging when only warnings issued.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4465\"\u003e#4465\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSimplify ICC processing when retaining input profiles.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4468\"\u003e#4468\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.34.5-rc.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.17.3 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdd experimental support for prebuilt Linux RISC-V 64-bit binaries.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport building from source with npm v12+, deprecate \u003ccode\u003e--build-from-source\u003c/code\u003e flag.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4458\"\u003e#4458\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdd support for BigTIFF output.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4459\"\u003e#4459\u003c/a\u003e\n\u003ca href=\"https://github.com/throwbi\"\u003e\u003ccode\u003e@​throwbi\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove error messaging when only warnings issued.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4465\"\u003e#4465\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSimplify ICC processing when retaining input profiles.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4468\"\u003e#4468\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.34.5-rc.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.17.3 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdd experimental support for prebuilt Linux RISC-V 64-bit binaries.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport building from source with npm v12+, deprecate \u003ccode\u003e--build-from-source\u003c/code\u003e flag.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4458\"\u003e#4458\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdd support for BigTIFF output.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4459\"\u003e#4459\u003c/a\u003e\n\u003ca href=\"https://github.com/throwbi\"\u003e\u003ccode\u003e@​throwbi\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove error messaging when only warnings issued.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4465\"\u003e#4465\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e0624568686516209c434de2d3c0ef6688f0811d\"\u003e\u003ccode\u003ee062456\u003c/code\u003e\u003c/a\u003e Release v0.34.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/6450c704a686d4205a2c21ddb1d10d5fc28c6c23\"\u003e\u003ccode\u003e6450c70\u003c/code\u003e\u003c/a\u003e Prerelease v0.34.5-rc.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/f7c95d1bf0f24049ee6ee77b21b1c1bb8d181aa2\"\u003e\u003ccode\u003ef7c95d1\u003c/code\u003e\u003c/a\u003e TypeScript: consolidate a few enum-like properties\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ef86a75560adb40605d3dfc85dc3656a0b88c413\"\u003e\u003ccode\u003eef86a75\u003c/code\u003e\u003c/a\u003e Prerelease v0.34.5-rc.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/6c1e840098ea4a25d833518b30703d9b0af83d32\"\u003e\u003ccode\u003e6c1e840\u003c/code\u003e\u003c/a\u003e Use structured binding for tuples where possible\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e1628d8ef5033dedde9ed1ddd4dd681e1fc30e1e\"\u003e\u003ccode\u003ee1628d8\u003c/code\u003e\u003c/a\u003e Simplify ICC processing when retaining input profiles \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4468\"\u003e#4468\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/4f9f8179a6350448a32851e5daf5508d61c727ba\"\u003e\u003ccode\u003e4f9f817\u003c/code\u003e\u003c/a\u003e Linter: apply all recommended biome settings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/09d5aa8cfa09522ddc67342295cb75ab1d044b09\"\u003e\u003ccode\u003e09d5aa8\u003c/code\u003e\u003c/a\u003e Docs: update internal and libvips doc links\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/040b73ca746f4b8e71950708de4a464c7ba6a188\"\u003e\u003ccode\u003e040b73c\u003c/code\u003e\u003c/a\u003e Upgrade to libvips v8.17.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/1f2f33d9a7eb8ffba91b8576e49a39df5fdebb76\"\u003e\u003ccode\u003e1f2f33d\u003c/code\u003e\u003c/a\u003e Ensure licensing headers are retained by code bundlers\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lovell/sharp/compare/v0.33.5...v0.34.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for sharp since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version modifies \u003ccode\u003einstall\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.16.0 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca...\n\n_Description has been truncated_\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nUpgrade dependencies across the monorepo to pick up security fixes and platform updates, including `next`, `axios`, `undici`, `postcss`, `dompurify`, `shell-quote`, and `electron`. This hardens networking, sanitization, and build tooling with minimal code changes expected.\n\n- **Dependencies**\n  - Web: `next` 15.5.21 and `postcss` 8.5.23 with fixes for SSRF, DoS, cache confusion, and safer source map handling.\n  - Networking: `axios` 1.18.0 and `undici` 7.29.0 tighten redirect/header handling, URL validation, cache parsing, and cookie validation.\n  - Sanitization/Parsing: `dompurify` 3.4.13 hardens hooks and in-place sanitization; `shell-quote` 1.9.0 adds types and fixes parsing/quoting.\n  - Desktop host: `electron` 39.8.10 brings backported security fixes and stricter custom protocol CORS behavior.\n\n- **Migration**\n  - Electron custom protocols: set `corsEnabled: true` if used with `supportFetchAPI: true`; otherwise cross-origin `fetch`/XHR will be blocked. Re-test packaging and DevTools flows.\n  - Axios: malformed `http:`/`https:` URLs without `//` now reject; verify any custom `validateStatus` usage.\n  - PostCSS: if running PostCSS directly, ensure `opts.from` is set when loading source maps.\n\n\u003csup\u003eWritten for commit 6ad731aff0a83f4e3688fb115c080c595e002023. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/ThePlenkov/kilocode/pull/3?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/ThePlenkov/kilocode/pull/3","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ThePlenkov%2Fkilocode/issues/3","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/3/packages"}},{"old_version":"6.27.0","new_version":"6.28.0","update_type":"minor","path":"the npm-security group across 1 directory","pr_created_at":"2026-08-07T18:15:57.000Z","version_change":"6.27.0 → 6.28.0","issue":{"uuid":"5092852177","node_id":"PR_kwDOQ77-1M78K06R","number":2705,"state":"open","title":"chore(deps): bump undici from 6.27.0 to 6.28.0 in the npm-security group across 1 directory","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T18:15:57.000Z","updated_at":"2026-08-07T18:15:58.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"undici","old_version":"6.27.0","new_version":"6.28.0","repository_url":"https://github.com/nodejs/undici"}],"path":"the npm-security group across 1 directory","ecosystem":"npm"},"body":"Bumps the npm-security group with 1 update in the / directory: [undici](https://github.com/nodejs/undici).\n\nUpdates `undici` from 6.27.0 to 6.28.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.28.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e740a0b7c\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003ecba3a52a\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e4fd5a0c6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003eaf748404\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e and \u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ehttps://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a\"\u003e\u003ccode\u003e01a912e\u003c/code\u003e\u003c/a\u003e Bumped v6.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5591\"\u003e#5591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e\"\u003e\u003ccode\u003e481ecfc\u003c/code\u003e\u003c/a\u003e Use Node 22 and npm 11 to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e\u003ccode\u003e740a0b7\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0\"\u003e\u003ccode\u003e2698e49\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e\u003ccode\u003e4fd5a0c\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003e\u003ccode\u003ecba3a52\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003e\u003ccode\u003eaf74840\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=6.27.0\u0026new-version=6.28.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/affaan-m/ECC/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/affaan-m/ECC/pull/2705","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/affaan-m%2FECC/issues/2705","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2705/packages"}},{"old_version":"7.15.0","new_version":"7.29.0","update_type":"minor","path":null,"pr_created_at":"2026-08-07T16:47:55.000Z","version_change":"7.15.0 → 7.29.0","issue":{"uuid":"5092225805","node_id":"PR_kwDOQUVehM78I03U","number":2,"state":"open","title":"build(deps): bump the npm_and_yarn group across 3 directories with 9 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T16:47:55.000Z","updated_at":"2026-08-07T16:49:05.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":9,"packages":[{"name":"axios","old_version":"1.12.2","new_version":"1.18.0","repository_url":"https://github.com/axios/axios"},{"name":"undici","old_version":"7.15.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"},{"name":"dompurify","old_version":"3.2.6","new_version":"3.4.13","repository_url":"https://github.com/cure53/DOMPurify"},{"name":"shell-quote","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/ljharb/shell-quote"},{"name":"vite","old_version":"6.3.5","new_version":"6.4.3","repository_url":"https://github.com/vitejs/vite"},{"name":"next","old_version":"15.2.5","new_version":"15.5.21","repository_url":"https://github.com/vercel/next.js"},{"name":"postcss","old_version":"8.5.4","new_version":"8.5.23","repository_url":"https://github.com/postcss/postcss"},{"name":"electron","old_version":"34.4.1","new_version":"39.8.10","repository_url":"https://github.com/electron/electron"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 8 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [axios](https://github.com/axios/axios) | `1.12.2` | `1.18.0` |\n| [undici](https://github.com/nodejs/undici) | `7.15.0` | `7.29.0` |\n| [dompurify](https://github.com/cure53/DOMPurify) | `3.2.6` | `3.4.13` |\n| [shell-quote](https://github.com/ljharb/shell-quote) | `1.8.2` | `1.9.0` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `6.3.5` | `6.4.3` |\n| [next](https://github.com/vercel/next.js) | `15.2.5` | `15.5.21` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.4` | `8.5.23` |\n| [electron](https://github.com/electron/electron) | `34.4.1` | `39.8.10` |\n\nBumps the npm_and_yarn group with 3 updates in the /jetbrains/host directory: [undici](https://github.com/nodejs/undici), [postcss](https://github.com/postcss/postcss) and [electron](https://github.com/electron/electron).\nBumps the npm_and_yarn group with 4 updates in the /webview-ui directory: [axios](https://github.com/axios/axios), [dompurify](https://github.com/cure53/DOMPurify), [shell-quote](https://github.com/ljharb/shell-quote) and [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite).\n\nUpdates `axios` from 1.12.2 to 1.18.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/releases\"\u003eaxios's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.18.0 — June 13, 2026\u003c/h2\u003e\n\u003cp\u003eThis release hardens redirect and URL handling, improves the validateStatus configuration semantics, and includes updates to documentation, dependencies, and release metadata.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRedirect Header Safety:\u003c/strong\u003e Added Node HTTP adapter support for stripping caller-specified sensitive headers on cross-origin redirects, helping prevent custom auth headers such as API keys from leaking to another origin. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eURL And Request Hardening:\u003c/strong\u003e Rejects malformed \u003ccode\u003ehttp:\u003c/code\u003e and \u003ccode\u003ehttps:\u003c/code\u003e URLs that omit \u003ccode\u003e//\u003c/code\u003e with \u003ccode\u003eERR_INVALID_URL\u003c/code\u003e, while tightening prototype-pollution-safe config reads, stream size limits, FormData depth handling, data URL sizing, and local \u003ccode\u003eNO_PROXY\u003c/code\u003e matching. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eStatus Validation:\u003c/strong\u003e Added \u003ccode\u003etransitional.validateStatusUndefinedResolves\u003c/code\u003e so applications can opt in to treating \u003ccode\u003evalidateStatus: undefined\u003c/code\u003e like the option was omitted, while \u003ccode\u003evalidateStatus: null\u003c/code\u003e remains the explicit way to accept every status. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation:\u003c/strong\u003e Published the v1.17.0 release notes, fixed a changelog typo, clarified the package update PR policy, and marked the \u003ccode\u003eproxy\u003c/code\u003e request config as Node.js-only in the advanced docs. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDependencies:\u003c/strong\u003e Bumped \u003ccode\u003e@babel/core\u003c/code\u003e, \u003ccode\u003e@babel/preset-env\u003c/code\u003e, \u003ccode\u003e@commitlint/cli\u003c/code\u003e, \u003ccode\u003e@commitlint/config-conventional\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-babel\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-commonjs\u003c/code\u003e, \u003ccode\u003e@vitest/browser\u003c/code\u003e, \u003ccode\u003e@vitest/browser-playwright\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003elint-staged\u003c/code\u003e, \u003ccode\u003erollup\u003c/code\u003e, \u003ccode\u003evitest\u003c/code\u003e, and \u003ccode\u003eactions/checkout\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10996\"\u003e#10996\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10997\"\u003e#10997\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRelease Metadata:\u003c/strong\u003e Prepared the 1.18.0 release by updating package metadata and the runtime \u003ccode\u003eVERSION\u003c/code\u003e value. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/drori12\"\u003e\u003ccode\u003e@​drori12\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/eyupcanakman\"\u003e\u003ccode\u003e@​eyupcanakman\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/Adi-Beker\"\u003e\u003ccode\u003e@​Adi-Beker\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/axios/axios/compare/v1.17.0...v1.18.0\"\u003eFull Changelog\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.17.0 — June 1, 2026\u003c/h2\u003e\n\u003cp\u003eThis release adds Node HTTP zstd decompression, hardens config and release workflows, and fixes authentication, header, proxy, and type-handling regressions.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eConfig Hardening:\u003c/strong\u003e Guarded \u003ccode\u003esocketPath\u003c/code\u003e, \u003ccode\u003eparams\u003c/code\u003e, and \u003ccode\u003eparamsSerializer\u003c/code\u003e reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10901\"\u003e#10901\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10922\"\u003e#10922\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRelease Publishing:\u003c/strong\u003e Switched the publish workflow to npm staged publishing for safer, auditable package releases with provenance. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10926\"\u003e#10926\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚀 New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP Compression:\u003c/strong\u003e Added Node HTTP adapter support for zstd response decompression, with \u003ccode\u003etransitional.advertiseZstdAcceptEncoding\u003c/code\u003e controlling whether \u003ccode\u003ezstd\u003c/code\u003e is advertised in \u003ccode\u003eAccept-Encoding\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/6792\"\u003e#6792\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10920\"\u003e#10920\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eAuthentication Handling:\u003c/strong\u003e Restored Basic auth on same-origin Node redirects while continuing to strip credentials cross-origin, and aligned the fetch adapter with HTTP adapter behavior for URL-embedded Basic auth. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10929\"\u003e#10929\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10896\"\u003e#10896\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eProxy TLS:\u003c/strong\u003e Preserved user \u003ccode\u003ehttpsAgent\u003c/code\u003e TLS options when tunneling HTTPS requests through HTTP CONNECT proxies. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10957\"\u003e#10957\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReact Native FormData:\u003c/strong\u003e Cleared default \u003ccode\u003eContent-Type\u003c/code\u003e for React Native \u003ccode\u003eFormData\u003c/code\u003e so multipart boundaries can be generated correctly. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10898\"\u003e#10898\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/blob/v1.x/CHANGELOG.md\"\u003eaxios's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.18.0 — June 13, 2026\u003c/h2\u003e\n\u003cp\u003eThis release hardens redirect and URL handling, improves the validateStatus configuration semantics, and includes updates to documentation, dependencies, and release metadata.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRedirect Header Safety:\u003c/strong\u003e Added Node HTTP adapter support for stripping caller-specified sensitive headers on cross-origin redirects, helping prevent custom auth headers such as API keys from leaking to another origin. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eURL And Request Hardening:\u003c/strong\u003e Rejects malformed \u003ccode\u003ehttp:\u003c/code\u003e and \u003ccode\u003ehttps:\u003c/code\u003e URLs that omit \u003ccode\u003e//\u003c/code\u003e with \u003ccode\u003eERR_INVALID_URL\u003c/code\u003e, while tightening prototype-pollution-safe config reads, stream size limits, FormData depth handling, data URL sizing, and local \u003ccode\u003eNO_PROXY\u003c/code\u003e matching. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eStatus Validation:\u003c/strong\u003e Added \u003ccode\u003etransitional.validateStatusUndefinedResolves\u003c/code\u003e so applications can opt in to treating \u003ccode\u003evalidateStatus: undefined\u003c/code\u003e like the option was omitted, while \u003ccode\u003evalidateStatus: null\u003c/code\u003e remains the explicit way to accept every status. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation:\u003c/strong\u003e Published the v1.17.0 release notes, fixed a changelog typo, clarified the package update PR policy, and marked the \u003ccode\u003eproxy\u003c/code\u003e request config as Node.js-only in the advanced docs. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDependencies:\u003c/strong\u003e Bumped \u003ccode\u003e@babel/core\u003c/code\u003e, \u003ccode\u003e@babel/preset-env\u003c/code\u003e, \u003ccode\u003e@commitlint/cli\u003c/code\u003e, \u003ccode\u003e@commitlint/config-conventional\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-babel\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-commonjs\u003c/code\u003e, \u003ccode\u003e@vitest/browser\u003c/code\u003e, \u003ccode\u003e@vitest/browser-playwright\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003elint-staged\u003c/code\u003e, \u003ccode\u003erollup\u003c/code\u003e, \u003ccode\u003evitest\u003c/code\u003e, and \u003ccode\u003eactions/checkout\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10996\"\u003e#10996\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10997\"\u003e#10997\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRelease Metadata:\u003c/strong\u003e Prepared the 1.18.0 release by updating package metadata and the runtime \u003ccode\u003eVERSION\u003c/code\u003e value. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/drori12\"\u003e\u003ccode\u003e@​drori12\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/eyupcanakman\"\u003e\u003ccode\u003e@​eyupcanakman\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/Adi-Beker\"\u003e\u003ccode\u003e@​Adi-Beker\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/axios/axios/compare/v1.17.0...v1.18.0\"\u003eFull Changelog\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.17.0 — June 1, 2026\u003c/h2\u003e\n\u003cp\u003eThis release adds Node HTTP zstd decompression, hardens config and release workflows, and fixes authentication, header, proxy, and type-handling regressions.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eConfig Hardening:\u003c/strong\u003e Guarded \u003ccode\u003esocketPath\u003c/code\u003e, \u003ccode\u003eparams\u003c/code\u003e, and \u003ccode\u003eparamsSerializer\u003c/code\u003e reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10901\"\u003e#10901\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10922\"\u003e#10922\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRelease Publishing:\u003c/strong\u003e Switched the publish workflow to npm staged publishing for safer, auditable package releases with provenance. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10926\"\u003e#10926\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚀 New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP Compression:\u003c/strong\u003e Added Node HTTP adapter support for zstd response decompression, with \u003ccode\u003etransitional.advertiseZstdAcceptEncoding\u003c/code\u003e controlling whether \u003ccode\u003ezstd\u003c/code\u003e is advertised in \u003ccode\u003eAccept-Encoding\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/6792\"\u003e#6792\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10920\"\u003e#10920\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eAuthentication Handling:\u003c/strong\u003e Restored Basic auth on same-origin Node redirects while continuing to strip credentials cross-origin, and aligned the fetch adapter with HTTP adapter behavior for URL-embedded Basic auth. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10929\"\u003e#10929\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10896\"\u003e#10896\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eProxy TLS:\u003c/strong\u003e Preserved user \u003ccode\u003ehttpsAgent\u003c/code\u003e TLS options when tunneling HTTPS requests through HTTP CONNECT proxies. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10957\"\u003e#10957\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReact Native FormData:\u003c/strong\u003e Cleared default \u003ccode\u003eContent-Type\u003c/code\u003e for React Native \u003ccode\u003eFormData\u003c/code\u003e so multipart boundaries can be generated correctly. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10898\"\u003e#10898\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/2d06f96e8602c2db13b65a26340ee4a1bbc0b61f\"\u003e\u003ccode\u003e2d06f96\u003c/code\u003e\u003c/a\u003e chore(release): prepare release 1.18.0 (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/32fc489632377d214db55bfa4e2c48486a7d7ce2\"\u003e\u003ccode\u003e32fc489\u003c/code\u003e\u003c/a\u003e fix: malformed http urls (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/b40ce498abfa10d90b873b4fd08f520afa5d2545\"\u003e\u003ccode\u003eb40ce49\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump the development_dependencies group with 10 updates (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10\"\u003e#10\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/fe964f960ecb52c3e1155b0daf7be77541956b01\"\u003e\u003ccode\u003efe964f9\u003c/code\u003e\u003c/a\u003e docs: mark proxy config as Node.js only (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/5f229d2d1f018d1db3dab6bbe034dbf3f9041b99\"\u003e\u003ccode\u003e5f229d2\u003c/code\u003e\u003c/a\u003e chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/fae9d4e7db6a858c407c75e607a071c533c5c4f6\"\u003e\u003ccode\u003efae9d4e\u003c/code\u003e\u003c/a\u003e docs: clarify package update PR policy (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/28ab2ced820e55192806c53472ab3eb0cbb68dc2\"\u003e\u003ccode\u003e28ab2ce\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump the development_dependencies group with 2 updates (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/a8e4f13aeecc45a3b8fab3ecfd9ddb5d70fb772b\"\u003e\u003ccode\u003ea8e4f13\u003c/code\u003e\u003c/a\u003e fix(core): keep default validateStatus when request passes undefined (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/614f4552a17de757d4171ad7c3bd38c9c1025fd8\"\u003e\u003ccode\u003e614f455\u003c/code\u003e\u003c/a\u003e docs: publish v1.17.0 release notes (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/6bb12c191f5380fad321322fb90216ae0dc36985\"\u003e\u003ccode\u003e6bb12c1\u003c/code\u003e\u003c/a\u003e fix: custom auth headers not stripped on cross-origin redirects (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/axios/axios/compare/v1.12.2...v1.18.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for axios since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version modifies \u003ccode\u003eprepare\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.15.0 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.28.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e7 security advisories\u003c/strong\u003e, all shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 7.28.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^7.28.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v7 line is \u003cstrong\u003enot\u003c/strong\u003e affected by GHSA-38rv-x7px-6hhq (CVE-2026-9675), which is\nan 8.x-only regression.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on GHSA-hm92-r4w5-c3mj:\u003c/strong\u003e this fix shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e, not the\nearlier 7.2x line — the vulnerable single-pool code was still present through\n\u003ccode\u003ev7.27.2\u003c/code\u003e. The per-origin pool fix is\n\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5041\"\u003e#5041\u003c/a\u003e).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8cb10f98\"\u003e\u003ccode\u003e8cb10f98\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g\"\u003eGHSA-vmh5-mc38-953g\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9697\u003c/td\u003e\n\u003ctd\u003eHigh (7.4)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/04201f89\"\u003e\u003ccode\u003e04201f89\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj\"\u003eGHSA-hm92-r4w5-c3mj\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6734\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6\"\u003eGHSA-pr7r-676h-xcf6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9678\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/85a24055\"\u003e\u003ccode\u003e85a24055\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ea8930cf\"\u003e\u003ccode\u003eea8930cf\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f9eba0ad9134e1c0977848476bba9d49734696e4\"\u003e\u003ccode\u003ef9eba0a\u003c/code\u003e\u003c/a\u003e Bumped v7.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5430\"\u003e#5430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.15.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for undici since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `dompurify` from 3.2.6 to 3.4.13\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cure53/DOMPurify/releases\"\u003edompurify's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eDOMPurify 3.4.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue with hook removal during \u003ccode\u003eIN_PLACE\u003c/code\u003e sanitization, thanks \u003ca href=\"https://github.com/koyokr\"\u003e\u003ccode\u003e@​koyokr\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue with hooks potentially bypassing the clone guard, thanks \u003ca href=\"https://github.com/AkshayjainG\"\u003e\u003ccode\u003e@​AkshayjainG\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue with DOM clobbering via \u003ccode\u003eownerDocument\u003c/code\u003e during \u003ccode\u003eIN_PLACE\u003c/code\u003e, thanks \u003ca href=\"https://github.com/AkshayjainG\"\u003e\u003ccode\u003e@​AkshayjainG\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where a hook would not get called for custom elements, thanks \u003ca href=\"https://github.com/Rikuxx0\"\u003e\u003ccode\u003e@​Rikuxx0\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHardened the handling of hooks removing elements, \u003ca href=\"https://github.com/mkrause-bee360\"\u003e\u003ccode\u003e@​mkrause-bee360\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded support for a few new SVG attributes, thanks \u003ca href=\"https://github.com/cbn-falias\"\u003e\u003ccode\u003e@​cbn-falias\u003c/code\u003e\u003c/a\u003e \u0026amp; \u003ca href=\"https://github.com/Develop-KIM\"\u003e\u003ccode\u003e@​Develop-KIM\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHardened the handling of declarative partial updates\u003c/li\u003e\n\u003cli\u003eUpdated the documentation is several spots, README, wiki, etc.\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue with a leaky config for hooks via \u003ccode\u003esetConfig\u003c/code\u003e, thanks \u003ca href=\"https://github.com/trace37labs\"\u003e\u003ccode\u003e@​trace37labs\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBumped vulnerable development dependencies to arrive at plain 0 with \u003ccode\u003enpm audit\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eUpdated the \u003ccode\u003eosv-scanner\u003c/code\u003e suppression list as no vulnerable dependencies are left for now\u003c/li\u003e\n\u003cli\u003eUpdated up the linting tool-chain and removed now-redundant lint directives\u003c/li\u003e\n\u003cli\u003eUpdated the documentation is several spots, README, wiki, etc.\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.10\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRefactored codebase for clarity: extracted the public type declarations into \u003ccode\u003etypes.ts\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eDecomposed the three largest sanitizer functions into focused helpers\u003c/li\u003e\n\u003cli\u003eRemoved duplicated defaults and dead branches, consolidated \u003ccode\u003eSAFE_FOR_TEMPLATES\u003c/code\u003e scrubbing into single shared path\u003c/li\u003e\n\u003cli\u003eImproved per-node performance by hoisting the mXSS probe regexes and testing \u003ccode\u003etextContent\u003c/code\u003e before \u003ccode\u003einnerHTML\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdded a deterministic micro-benchmark harness (\u003ccode\u003enpm run bench\u003c/code\u003e) with a \u003ccode\u003e--compare\u003c/code\u003e mode\u003c/li\u003e\n\u003cli\u003eReduced CI cost by running the full three-engine browser suite once per PR\u003c/li\u003e\n\u003cli\u003eRefreshed the \u003ccode\u003edemos/\u003c/code\u003e folder so every demo runs again, and added a SVG-via-\u003ccode\u003e\u0026lt;img\u0026gt;\u003c/code\u003e demo\u003c/li\u003e\n\u003cli\u003eDocumented the bench and \u003ccode\u003etest:happydom\u003c/code\u003e scripts in the README\u003c/li\u003e\n\u003cli\u003eCompleted the Attack Classes \u0026amp; Bypass History wiki page\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFurther improved the handling of Trusted Types config options, thanks \u003ca href=\"https://github.com/offset\"\u003e\u003ccode\u003e@​offset\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFurther improved the handling of \u003ccode\u003eIN_PLACE\u003c/code\u003e sanitization, thanks \u003ca href=\"https://github.com/mozfreddyb\"\u003e\u003ccode\u003e@​mozfreddyb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded more test coverage for \u003ccode\u003eIN_PLACE\u003c/code\u003e and Trusted Types related usage\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003cli\u003eUpdated README and wiki with more accurate documentation \u0026amp; attack samples\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCleaned up the repository root, renamed some and removed unneeded files\u003c/li\u003e\n\u003cli\u003eFixed an issue with handling of Trusted Types policies, thanks \u003ca href=\"https://github.com/fulstadev\"\u003e\u003ccode\u003e@​fulstadev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed the node iterator for better template scrubbing, thanks \u003ca href=\"https://github.com/IamLeandrooooo\"\u003e\u003ccode\u003e@​IamLeandrooooo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIncluded formerly missing LICENSE-MPL in published npm package, thanks \u003ca href=\"https://github.com/asamuzaK\"\u003e\u003ccode\u003e@​asamuzaK\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHardened the handling of Shadow Roots when using \u003ccode\u003eIN_PLACE\u003c/code\u003e, thanks \u003ca href=\"https://github.com/GameZoneHacker\"\u003e\u003ccode\u003e@​GameZoneHacker\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/3067f774676975de12306effd6db6ad7a9a8c17f\"\u003e\u003ccode\u003e3067f77\u003c/code\u003e\u003c/a\u003e release: 3.4.13 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1562\"\u003e#1562\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/a9ca1e537422319a557a9a2aa61f003b23b4a197\"\u003e\u003ccode\u003ea9ca1e5\u003c/code\u003e\u003c/a\u003e release: 3.4.12 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1537\"\u003e#1537\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/0cae5187403132f96a6d357649e4b15633fc210a\"\u003e\u003ccode\u003e0cae518\u003c/code\u003e\u003c/a\u003e release: 3.4.11 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1494\"\u003e#1494\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/6ee5716f8336989753611beeca364957c0eb0c3e\"\u003e\u003ccode\u003e6ee5716\u003c/code\u003e\u003c/a\u003e release: 3.4.10 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1478\"\u003e#1478\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/52102472d46035857c52df19e44285f8a1e102fc\"\u003e\u003ccode\u003e5210247\u003c/code\u003e\u003c/a\u003e release: 3.4.9 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1459\"\u003e#1459\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/bcdd8285412dc9c4c149652aed2d712e790d6ccf\"\u003e\u003ccode\u003ebcdd828\u003c/code\u003e\u003c/a\u003e release: 3.4.8 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1439\"\u003e#1439\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/ca30f070c360df162a3e3848e80e6fd3c9e74bff\"\u003e\u003ccode\u003eca30f07\u003c/code\u003e\u003c/a\u003e release: 3.4.7 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1414\"\u003e#1414\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/bb7739e5bccec7e1ab3dae3f3e42d02db3acaaae\"\u003e\u003ccode\u003ebb7739e\u003c/code\u003e\u003c/a\u003e release: 3.4.6 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1394\"\u003e#1394\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/011b0c78f2a0f57ee54f5fcccb697a46ca6e63ea\"\u003e\u003ccode\u003e011b0c7\u003c/code\u003e\u003c/a\u003e release: 3.4.5 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1382\"\u003e#1382\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/5817ad969c15e67dfcd6cb37248d6e9c1553e7c3\"\u003e\u003ccode\u003e5817ad9\u003c/code\u003e\u003c/a\u003e release: 3.4.4 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1374\"\u003e#1374\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/cure53/DOMPurify/compare/3.2.6...3.4.13\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version adds \u003ccode\u003eprepare\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `shell-quote` from 1.8.2 to 1.9.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md\"\u003eshell-quote's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.4...v1.9.0\"\u003ev1.9.0\u003c/a\u003e - 2026-06-24\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[New] add types \u003ca href=\"https://github.com/ljharb/shell-quote/commit/dca6e21a02df4cc1a83ed1b5baa4d82df134170a\"\u003e\u003ccode\u003edca6e21\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9aa9e8f60991f8c4053a29e476795d891ff851ad\"\u003e\u003ccode\u003e9aa9e8f\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: finalize tokens in linear time (GHSA-395f-4hp3-45gv) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7ff5488599d01c323514f02f5efb74088dd134ec\"\u003e\u003ccode\u003e7ff5488\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] update workflows \u003ca href=\"https://github.com/ljharb/shell-quote/commit/75e849741ffaf2d3aa53ae0e18ef6bf9929ef478\"\u003e\u003ccode\u003e75e8497\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 4/6/7: pin eslint to 9 before install, since npm 2/3 cannot stage eslint 10\u003ccode\u003e@types/esrecurse\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3fb739de44b81c69431947d54fbfc18998dd6d72\"\u003e\u003ccode\u003e3fb739d\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] retry \u003ccode\u003enpm install\u003c/code\u003e on Windows to survive npm 2/3 staging-rename flake \u003ca href=\"https://github.com/ljharb/shell-quote/commit/abe0163293c82963fa8a16cfaa87181846d5aced\"\u003e\u003ccode\u003eabe0163\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 5/7: install deps with a modern node \u003ca href=\"https://github.com/ljharb/shell-quote/commit/b4bafa2e7e58d53d9839b1c24976f61e54b43326\"\u003e\u003ccode\u003eb4bafa2\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: escape leading \u003ccode\u003e~\u003c/code\u003e to prevent shell tilde-expansion \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7a76c1a12d8461c2234a1c655b943cee84cbff91\"\u003e\u003ccode\u003e7a76c1a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7184b4458b65c17b931e126d8cb5f586c6717dc8\"\u003e\u003ccode\u003e7184b44\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] apparently \u003ccode\u003ejackspeak\u003c/code\u003e is no longer in the graph \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9ba368a4057b9f498b0fef23b5b15543ef81b98c\"\u003e\u003ccode\u003e9ba368a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.3...v1.8.4\"\u003ev1.8.4\u003c/a\u003e - 2026-05-22\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: validate object-token shapes \u003ca href=\"https://github.com/ljharb/shell-quote/commit/4378a6e613db5948168684864e49b42b83134d2d\"\u003e\u003ccode\u003e4378a6e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003enpmignore\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/22ebec04349065a45ad8afc8cc8d53c4624634a6\"\u003e\u003ccode\u003e22ebec0\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] increase coverage \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9f3caa31900cc6ee64858b31134144c648ce206d\"\u003e\u003ccode\u003e9f3caa3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] replace runkit CI badge with shields.io check-runs badge \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3344a047dd1e95f71c4ca27522cbfd05c56277e0\"\u003e\u003ccode\u003e3344a04\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/699c5113d135f4d4591574bebf173334ffa453d4\"\u003e\u003ccode\u003e699c511\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.2...v1.8.3\"\u003ev1.8.3\u003c/a\u003e - 2025-06-01\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] remove unnecessary backslash escaping in single quotes \u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/15\"\u003e\u003ccode\u003e[#15](https://github.com/ljharb/shell-quote/issues/15)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/db09fc7a9e3546807c19e2de2682ec31112a6520\"\u003e\u003ccode\u003edb09fc7\u003c/code\u003e\u003c/a\u003e v1.9.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/7ff5488599d01c323514f02f5efb74088dd134ec\"\u003e\u003ccode\u003e7ff5488\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003eparse\u003c/code\u003e: finalize tokens in linear time (GHSA-395f-4hp3-45gv)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/b4bafa2e7e58d53d9839b1c24976f61e54b43326\"\u003e\u003ccode\u003eb4bafa2\u003c/code\u003e\u003c/a\u003e [actions] Windows + node 5/7: install deps with a modern node\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/3fb739de44b81c69431947d54fbfc18998dd6d72\"\u003e\u003ccode\u003e3fb739d\u003c/code\u003e\u003c/a\u003e [actions] Windows + node 4/6/7: pin eslint to 9 before install, since npm 2/3...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/abe0163293c82963fa8a16cfaa87181846d5aced\"\u003e\u003ccode\u003eabe0163\u003c/code\u003e\u003c/a\u003e [actions] retry \u003ccode\u003enpm install\u003c/code\u003e on Windows to survive npm 2/3 staging-rename flake\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/7a76c1a12d8461c2234a1c655b943cee84cbff91\"\u003e\u003ccode\u003e7a76c1a\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003equote\u003c/code\u003e: escape leading \u003ccode\u003e~\u003c/code\u003e to prevent shell tilde-expansion\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/75e849741ffaf2d3aa53ae0e18ef6bf9929ef478\"\u003e\u003ccode\u003e75e8497\u003c/code\u003e\u003c/a\u003e [actions] update workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/dca6e21a02df4cc1a83ed1b5baa4d82df134170a\"\u003e\u003ccode\u003edca6e21\u003c/code\u003e\u003c/a\u003e [New] add types\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/9aa9e8f60991f8c4053a29e476795d891ff851ad\"\u003e\u003ccode\u003e9aa9e8f\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/9ba368a4057b9f498b0fef23b5b15543ef81b98c\"\u003e\u003ccode\u003e9ba368a\u003c/code\u003e\u003c/a\u003e [Dev Deps] apparently \u003ccode\u003ejackspeak\u003c/code\u003e is no longer in the graph\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.2...v1.9.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `vite` from 6.3.5 to 6.4.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/releases\"\u003evite's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.4.3\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v6.4.3/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev6.4.2\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v6.4.2/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev6.4.1\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v6.4.1/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev6.4.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v6.4.0/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev6.3.7\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v6.3.7/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/blob/v6.4.3/packages/vite/CHANGELOG.md\"\u003evite's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e6.4.3 (2026-06-01)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22576\"\u003e#22576\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/96b0c10162e9c55485d922db2cfc6b8227cbc176\"\u003e96b0c10\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22572\"\u003e#22572\u003c/a\u003e \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22576\"\u003e#22576\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(deps): backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22575\"\u003e#22575\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8fed5cf540c0d475266787f52072f258478cd42f\"\u003e8fed5cf\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22571\"\u003e#22571\u003c/a\u003e \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22575\"\u003e#22575\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e6.4.2 (2026-04-06)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: apply server.fs check to env transport (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22159\"\u003e#22159\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22163\"\u003e#22163\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/fe28e47e9463e4c9619f94bfa06d2f8f1411b44b\"\u003efe28e47\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22159\"\u003e#22159\u003c/a\u003e \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22163\"\u003e#22163\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid path traversal with optimize deps sourcemap handler (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22161\"\u003e#22161\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/ca4da5d1fb45c9cfdce606aa30825095791b164b\"\u003eca4da5d\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22161\"\u003e#22161\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e6.4.1 (2025-10-20)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(dev): trim trailing slash before \u003ccode\u003eserver.fs.deny\u003c/code\u003e check (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20968\"\u003e#20968\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20969\"\u003e#20969\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/1114b5d7ea03e26572708715343bec69db4536e8\"\u003e1114b5d\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/20968\"\u003e#20968\u003c/a\u003e \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/20969\"\u003e#20969\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e6.4.0 (2025-10-15)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: allow passing down resolved config to vite's createServer (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20932\"\u003e#20932\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/ca6455ee9eb6111a9caa9810506a1b9ac96a520a\"\u003eca6455e\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/20932\"\u003e#20932\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e6.3.7 (2025-10-14)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(esbuild): inject esbuild helpers correctly for esbuild 0.25.9+ (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20940\"\u003e#20940\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/c59a222aa584c087cfe710173de1b9ecb597a3ff\"\u003ec59a222\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/20940\"\u003e#20940\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e6.3.6 (2025-09-08)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: apply \u003ccode\u003efs.strict\u003c/code\u003e check to HTML files (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20736\"\u003e#20736\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/0ab19ea9fcb66f544328f442cf6e70f7c0528d5f\"\u003e0ab19ea\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/20736\"\u003e#20736\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: upgrade sirv to 3.0.2 (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20735\"\u003e#20735\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e11d24008b97d4ca731ecc1a3b95260a6d12e7e0\"\u003ee11d240\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/20735\"\u003e#20735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: detect ts support via \u003ccode\u003eprocess.features\u003c/code\u003e (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20544\"\u003e#20544\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/7d9922972b62329d37a71d4da5a4a382d0bf8a79\"\u003e7d99229\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/20544\"\u003e#20544\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/6c2c881f15495738ff03bc1d67cc052c07e0cac4\"\u003e\u003ccode\u003e6c2c881\u003c/code\u003e\u003c/a\u003e release: v6.4.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/96b0c10162e9c55485d922db2cfc6b8227cbc176\"\u003e\u003ccode\u003e96b0c10\u003c/code\u003e\u003c/a\u003e fix: backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22576\"\u003e#22576\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/8fed5cf540c0d475266787f52072f258478cd42f\"\u003e\u003ccode\u003e8fed5cf\u003c/code\u003e\u003c/a\u003e fix(deps): backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/2\"\u003e#2\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/6b3fad02abd550bd7b79934ff92c58dbd7f33045\"\u003e\u003ccode\u003e6b3fad0\u003c/code\u003e\u003c/a\u003e release: v6.4.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/ca4da5d1fb45c9cfdce606aa30825095791b164b\"\u003e\u003ccode\u003eca4da5d\u003c/code\u003e\u003c/a\u003e fix: avoid path traversal with optimize deps sourcemap handler (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22161\"\u003e#22161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/fe28e47e9463e4c9619f94bfa06d2f8f1411b44b\"\u003e\u003ccode\u003efe28e47\u003c/code\u003e\u003c/a\u003e fix: apply server.fs check to env transport (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22159\"\u003e#22159\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22163\"\u003e#22163\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/5487f4f641f70c47ea05fd101a4319897df048b3\"\u003e\u003ccode\u003e5487f4f\u003c/code\u003e\u003c/a\u003e release: v6.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/1114b5d7ea03e26572708715343bec69db4536e8\"\u003e\u003ccode\u003e1114b5d\u003c/code\u003e\u003c/a\u003e fix(dev): trim trailing slash before \u003ccode\u003eserver.fs.deny\u003c/code\u003e check (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20968\"\u003e#20968\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20969\"\u003e#20969\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/f12697c0f64b9a37196b9ab218a0911829d5b103\"\u003e\u003ccode\u003ef12697c\u003c/code\u003e\u003c/a\u003e release: v6.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/ca6455ee9eb6111a9caa9810506a1b9ac96a520a\"\u003e\u003ccode\u003eca6455e\u003c/code\u003e\u003c/a\u003e feat: allow passing down resolved config to vite's createServer (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/20932\"\u003e#20932\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vitejs/vite/commits/v6.4.3/packages/vite\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for vite since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `next` from 15.2.5 to 15.5.21\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev15.5.21\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eHigh:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-m99w-x7hq-7vfj\"\u003eDenial of Service in App Router using Server Actions\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-6gpp-xcg3-4w24\"\u003eMiddleware / Proxy bypass in App Router applications using Turbopack and single locale\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p9j2-gv94-2wf4\"\u003eServer-Side Request Forgery in rewrites via attacker-controlled destination hostname\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-89xv-2m56-2m9x\"\u003eServer-Side Request Forgery in Server Actions on custom servers\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eModerate:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-68g3-v927-f742\"\u003eCache confusion of response bodies for requests with bodies\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-4633-3j49-mh5q\"\u003eCache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-q8wf-6r8g-63ch\"\u003eDenial of Service in the Image Optimization API using SVGs\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-955p-x3mx-jcvp\"\u003eUnauthenticated disclosure of internal Server Function endpoints\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-4c39-4ccg-62r3\"\u003eUnbounded Server Action payload in Edge runtime\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev15.5.20\u003c/h2\u003e\n\u003cp\u003eContains no changes except publishing \u003ccode\u003e@next/swc-wasm-web\u003c/code\u003e which was accidentally not published since 15.5.15.\u003c/p\u003e\n\u003ch2\u003e15.5.19\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[15.5.x] Don't drop \u003ccode\u003eFormData\u003c/code\u003e entries (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/94244\"\u003e#94244\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[15.5.x] Fix CI (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/94281\"\u003e#94281\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/e26f6ffaa710fc62ca0c8640db0e43b6663edf32\"\u003e\u003ccode\u003ee26f6ff\u003c/code\u003e\u003c/a\u003e v15.5.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/7f5deeb6c594b7515edecb879b0547beba1b8a82\"\u003e\u003ccode\u003e7f5deeb\u003c/code\u003e\u003c/a\u003e [15.x] Improve performance of checking valid MPA form submissions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/57c31f724d746e86a9e8b92aa8be538a922446a4\"\u003e\u003ccode\u003e57c31f7\u003c/code\u003e\u003c/a\u003e [15.x] Enforce \u003ccode\u003eserverActions.bodySizeLimit\u003c/code\u003e for Server Actions in Edge runtime\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/e3e5666ccead3a15162793d697af5e48b7cc0498\"\u003e\u003ccode\u003ee3e5666\u003c/code\u003e\u003c/a\u003e [15.x] Set correct origin for internal redirects in custom server\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/35f501357e9b0fe7c950b0d6aa8fcf5343f707e9\"\u003e\u003ccode\u003e35f5013\u003c/code\u003e\u003c/a\u003e [15.x] Ensure exotic rewrite param values are properly encoded\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/062f66700b52a5d6bba2c0605d55577ab7ad262c\"\u003e\u003ccode\u003e062f667\u003c/code\u003e\u003c/a\u003e [15.x] fix(fetch-cache): key fetch(Request, init) by the effective request\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/577c9dc0a08ac806e35f591fec528d5fb7407ad4\"\u003e\u003ccode\u003e577c9dc\u003c/code\u003e\u003c/a\u003e [15.x] fix(incremental-cache): byte-exact fetch cache key for binary bodies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/530d4fa31e010a05f28ea6e26a5f51f80f61e0c6\"\u003e\u003ccode\u003e530d4fa\u003c/code\u003e\u003c/a\u003e [15.x] fix(next/image): improve performance of detectContentType()\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/8fabaf3225be100d62dfb0f44d85ab43c2a14a20\"\u003e\u003ccode\u003e8fabaf3\u003c/code\u003e\u003c/a\u003e [15.x] Performance improvements when decoding React Server function payloads\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/ff12a6124e1504f17b62de948b8a553fdecaef7b\"\u003e\u003ccode\u003eff12a61\u003c/code\u003e\u003c/a\u003e [15.x] Validate server reference IDs during manifest lookup\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v15.2.5...v15.5.21\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for next since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.4 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003epostcss-scss\u003c/code\u003e commend regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed reading any file via user-generated CSS.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eopts.unsafeMap\u003c/code\u003e to disable checks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed nested brackets parsing performance (by \u003ca href=\"https://github.com/offset\"\u003e\u003ccode\u003e@​offset\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.10\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed XSS via unescaped \u003ccode\u003e\u0026lt;/style\u0026gt;\u003c/code\u003e in non-bundler cases (by \u003ca href=\"https://github.com/TharVid\"\u003e\u003ccode\u003e@​TharVid\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.4...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `electron` from 34.4.1 to 39.8.10\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/electron/electron/releases\"\u003eelectron's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eelectron v39.8.10\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.10\u003c/h1\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!WARNING]\nElectron 39.x.y has reached end-of-support as per the project's \u003ca href=\"https://www.electronjs.org/docs/latest/tutorial/electron-timelines#version-support-policy\"\u003esupport policy\u003c/a\u003e. Developers and applications are encouraged to upgrade to a newer version of Electron.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eFixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnsured cross-origin \u003ccode\u003efetch()\u003c/code\u003e and XHR are blocked for custom protocols registered with \u003ccode\u003esupportFetchAPI: true\u003c/code\u003e unless \u003ccode\u003ecorsEnabled: true\u003c/code\u003e is also set; cross-origin \u003ccode\u003emode: 'no-cors'\u003c/code\u003e requests now receive an opaque response. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51272\"\u003e#51272\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/51271\"\u003e40\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/51270\"\u003e41\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/51269\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue where the Squirrel.Mac installer could resolve the target bundle path to different locations at different stages of an install. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50766\"\u003e#50766\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/50765\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eOther Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackported a fix for route_id validation in the GPU command buffer. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51327\"\u003e#51327\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBackported security fixes for 493319454, 494158331, 493234757, 492736100, 493413432, 492668885, 496281816. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51257\"\u003e#51257\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBackported several fixes in Skia, ANGLE, and WebRTC from upstream. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51266\"\u003e#51266\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eelectron v39.8.9\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.9\u003c/h1\u003e\n\u003ch2\u003eOther Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003egn gen\u003c/code\u003e failing to resolve \u003ccode\u003eelectron_version\u003c/code\u003e when building from a \u003ccode\u003egit worktree\u003c/code\u003e checkout. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51163\"\u003e#51163\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/51164\"\u003e40\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/51165\"\u003e41\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/51166\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: backported fixes for CVE-2026-6296, CVE-2026-6297, CVE-2026-6298, CVE-2026-6299, CVE-2026-6300, CVE-2026-6301, CVE-2026-6302, CVE-2026-6303, CVE-2026-6304, CVE-2026-6305, CVE-2026-6306, CVE-2026-6307, CVE-2026-6308, CVE-2026-6309, CVE-2026-6311, CVE-2026-6312, CVE-2026-6313, CVE-2026-6314, CVE-2026-6316, CVE-2026-6318, CVE-2026-6358, CVE-2026-6359, CVE-2026-6360, CVE-2026-6361, CVE-2026-6362, CVE-2026-6363, CVE-2026-6364. \u003ca href=\"https://redirect.github.com/electron/electron/pull/51141\"\u003e#51141\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eelectron v39.8.8\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.8\u003c/h1\u003e\n\u003ch2\u003eFixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where DevTools would re-attach to the window when opened after previously being detached. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50818\"\u003e#50818\u003c/a\u003e \u003c!-- raw HTML omitted --\u003e(Also in \u003ca href=\"https://redirect.github.com/electron/electron/pull/50817\"\u003e40\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/50816\"\u003e41\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/electron/electron/pull/50815\"\u003e42\u003c/a\u003e)\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eOther Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackported fix for \u003ca href=\"https://issues.chromium.org/issues/474266014\"\u003echromium:74266014\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50175\"\u003e#50175\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBackported upstream v8 fixes for several maglev, inspector, and arm64 code-generation edge cases. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50993\"\u003e#50993\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eelectron v39.8.7\u003c/h2\u003e\n\u003ch1\u003eRelease Notes for v39.8.7\u003c/h1\u003e\n\u003ch2\u003eOther Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackported fix for 489711638. \u003ca href=\"https://redirect.github.com/electron/electron/pull/50624\"\u003e#50624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBackported fix for 493952...\n\n_Description has been truncated_\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nUpdate core dependencies across root, webview-ui, and JetBrains host to pull in security fixes and dev-server hardening. Key upgrades include `next`, `electron`, `axios`, `undici`, `postcss`, `vite`, `dompurify`, and `shell-quote`.\n\n- **Dependencies**\n  - `next`: 15.2.5 → 15.5.21 (security fixes) in `apps/web-evals`, `apps/web-roo-code`\n  - `electron`: 34.4.1 → 39.8.10 (security backports) in `jetbrains/host`\n  - `axios`: 1.12.2 → 1.18.0 (redirect/header \u0026 URL hardening)\n  - `undici`: 7.15.0 → 7.29.0 (security fixes)\n  - `postcss`: 8.5.4 → 8.5.23 (stricter source map handling)\n  - `vite`: 6.3.5/6.3.6 → 6.4.3 (dev-server path hardening) in `apps/storybook`, `webview-ui`\n  - `dompurify`: 3.2.6 → 3.4.13 (sanitization hardening)\n  - `shell-quote`: 1.8.2 → 1.9.0 (parser fixes, types)\n\n\u003csup\u003eWritten for commit a6f2ddcb3e710e07dca1df9243840121433935ea. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/ThePlenkov/kilocode/pull/2?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/ThePlenkov/kilocode/pull/2","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ThePlenkov%2Fkilocode/issues/2","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2/packages"}},{"old_version":"7.28.0","new_version":"7.29.0","update_type":"minor","path":null,"pr_created_at":"2026-08-07T16:36:11.000Z","version_change":"7.28.0 → 7.29.0","issue":{"uuid":"5092145578","node_id":"PR_kwDOCQda3s78Ikm1","number":2799,"state":"closed","title":"chore(deps): bump undici from 7.28.0 to 7.29.0","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-08-07T16:37:51.000Z","author_association":null,"state_reason":null,"created_at":"2026-08-07T16:36:11.000Z","updated_at":"2026-08-07T16:37:53.000Z","time_to_close":100,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"undici","old_version":"7.28.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 7.28.0 to 7.29.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=7.28.0\u0026new-version=7.29.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/IsmaelMartinez/teams-for-linux/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/IsmaelMartinez/teams-for-linux/pull/2799","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/IsmaelMartinez%2Fteams-for-linux/issues/2799","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2799/packages"}},{"old_version":"6.24.1","new_version":"6.28.0","update_type":"minor","path":null,"pr_created_at":"2026-08-07T16:27:19.000Z","version_change":"6.24.1 → 6.28.0","issue":{"uuid":"5092072919","node_id":"PR_kwDOSeiN3s78IVUh","number":65,"state":"closed","title":"chore(deps): Bump the npm_and_yarn group across 15 directories with 9 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-08-07T16:34:31.000Z","author_association":null,"state_reason":null,"created_at":"2026-08-07T16:27:19.000Z","updated_at":"2026-08-07T16:34:32.000Z","time_to_close":432,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): Bump","group_name":"npm_and_yarn","update_count":9,"packages":[{"name":"postcss","old_version":"8.5.6","new_version":"8.5.23","repository_url":"https://github.com/postcss/postcss"},{"name":"undici","old_version":"6.24.1","new_version":"6.28.0","repository_url":"https://github.com/nodejs/undici"},{"name":"@angular/common","old_version":"17.3.8","new_version":"20.3.27","repository_url":"https://github.com/angular/angular"},{"name":"@angular/compiler","old_version":"17.3.8","new_version":"20.3.27","repository_url":"https://github.com/angular/angular"},{"name":"@angular/core","old_version":"17.3.8","new_version":"20.3.25","repository_url":"https://github.com/angular/angular"},{"name":"@angular/common","old_version":"17.3.8","new_version":"20.3.27","repository_url":"https://github.com/angular/angular"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 2 updates in the / directory: [postcss](https://github.com/postcss/postcss) and [undici](https://github.com/nodejs/undici).\nBumps the npm_and_yarn group with 3 updates in the /examples/with-angular directory: [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common), [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) and [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core).\nBumps the npm_and_yarn group with 3 updates in the /examples/with-angular/apps/docs directory: [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common), [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) and [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core).\nBumps the npm_and_yarn group with 3 updates in the /examples/with-angular/apps/web directory: [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common), [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) and [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core).\nBumps the npm_and_yarn group with 3 updates in the /examples/with-angular/packages/ui directory: [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common), [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) and [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core).\nBumps the npm_and_yarn group with 1 update in the /examples/with-npm directory: [postcss](https://github.com/postcss/postcss).\nBumps the npm_and_yarn group with 1 update in the /examples/with-prisma directory: [fast-uri](https://github.com/fastify/fast-uri).\nBumps the npm_and_yarn group with 1 update in the /examples/with-tailwind directory: [postcss](https://github.com/postcss/postcss).\nBumps the npm_and_yarn group with 2 updates in the /examples/with-vue-nuxt directory: [@nuxt/devtools](https://github.com/nuxt/devtools/tree/HEAD/packages/devtools) and [nuxt](https://github.com/nuxt/nuxt/tree/HEAD/packages/nuxt).\nBumps the npm_and_yarn group with 1 update in the /examples/with-vue-nuxt/apps/docs directory: [nuxt](https://github.com/nuxt/nuxt/tree/HEAD/packages/nuxt).\nBumps the npm_and_yarn group with 1 update in the /lockfile-tests/fixtures/berry directory: [fast-uri](https://github.com/fastify/fast-uri).\nBumps the npm_and_yarn group with 2 updates in the /lockfile-tests/fixtures/npm-lock-workspace-variation directory: [postcss](https://github.com/postcss/postcss) and [fast-uri](https://github.com/fastify/fast-uri).\nBumps the npm_and_yarn group with 1 update in the /lockfile-tests/fixtures/pnpm-override-peer-variant directory: [hono](https://github.com/honojs/hono).\nBumps the npm_and_yarn group with 1 update in the /lockfile-tests/fixtures/robust-berry-resolutions directory: [fast-uri](https://github.com/fastify/fast-uri).\nBumps the npm_and_yarn group with 1 update in the /turborepo-tests/integration/fixtures/framework_inference directory: [postcss](https://github.com/postcss/postcss).\n\nUpdates `postcss` from 8.5.6 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003epostcss-scss\u003c/code\u003e commend regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed reading any file via user-generated CSS.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eopts.unsafeMap\u003c/code\u003e to disable checks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed nested brackets parsing performance (by \u003ca href=\"https://github.com/offset\"\u003e\u003ccode\u003e@​offset\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.10\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed XSS via unescaped \u003ccode\u003e\u0026lt;/style\u0026gt;\u003c/code\u003e in non-bundler cases (by \u003ca href=\"https://github.com/TharVid\"\u003e\u003ccode\u003e@​TharVid\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.6...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 6.24.1 to 6.28.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.28.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e740a0b7c\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003ecba3a52a\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e4fd5a0c6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003eaf748404\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e and \u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ehttps://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.27.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e4 security advisories\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 6.27.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^6.27.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on patched version:\u003c/strong\u003e the v6 fixes shipped in \u003cstrong\u003ev6.27.0\u003c/strong\u003e, not \u003ccode\u003e6.26.0\u003c/code\u003e\n— \u003ccode\u003ev6.26.0\u003c/code\u003e contains only the chunked-EOF fix (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5308\"\u003e#5308\u003c/a\u003e) and the version bump, none\nof the security fixes below.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v6 line is \u003cstrong\u003enot\u003c/strong\u003e affected by the SOCKS5 advisories (GHSA-vmh5-mc38-953g,\nGHSA-hm92-r4w5-c3mj), the shared-cache disclosure (GHSA-pr7r-676h-xcf6), or the\n8.x-only WebSocket regression (GHSA-38rv-x7px-6hhq).\u003c/p\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7\"\u003e\u003ccode\u003eb7f252e7\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447\"\u003e\u003ccode\u003e25efa447\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447\"\u003e\u003ccode\u003e25efa447\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f4c31d60\"\u003e\u003ccode\u003ef4c31d60\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003ch2\u003eHigh severity\u003c/h2\u003e\n\u003ch3\u003eWebSocket DoS via fragment count bypass — CVE-2026-12151\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/strong\u003e · CWE-400, CWE-770\n\u003cstrong\u003eFix:\u003c/strong\u003e \u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7\"\u003e\u003ccode\u003eb7f252e7\u003c/code\u003e\u003c/a\u003e \u003cem\u003eBackport WebSocket maxPayloadSize fixes\u003c/em\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5423\"\u003e#5423\u003c/a\u003e, backported to v6 in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5428\"\u003e#5428\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eA malicious WebSocket server can stream a large number of small or empty\ncontinuation frames. Undici enforced a limit on cumulative payload size but did\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a\"\u003e\u003ccode\u003e01a912e\u003c/code\u003e\u003c/a\u003e Bumped v6.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5591\"\u003e#5591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e\"\u003e\u003ccode\u003e481ecfc\u003c/code\u003e\u003c/a\u003e Use Node 22 and npm 11 to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e\u003ccode\u003e740a0b7\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0\"\u003e\u003ccode\u003e2698e49\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e\u003ccode\u003e4fd5a0c\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003e\u003ccode\u003ecba3a52\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003e\u003ccode\u003eaf74840\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/551138cbc1742c92242a68216167761075e8a82c\"\u003e\u003ccode\u003e551138c\u003c/code\u003e\u003c/a\u003e Bumped v6.27.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5431\"\u003e#5431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7c0841418fb9d95cd297bdd9fad9d2a53\"\u003e\u003ccode\u003eb7f252e\u003c/code\u003e\u003c/a\u003e Backport WebSocket maxPayloadSize fixes to v7.x (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5423\"\u003e#5423\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5428\"\u003e#5428\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447997f74d5881edd144525c3fd7db945a4\"\u003e\u003ccode\u003e25efa44\u003c/code\u003e\u003c/a\u003e fix(cookies): preserve values and parse SameSite strictly\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.24.1...v6.28.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@angular/common` from 17.3.8 to 20.3.27\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/releases\"\u003e@​angular/common's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e20.3.27\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e\u003cimg src=\"https://img.shields.io/badge/5dbcd0ee16-fix-green\" alt=\"fix - 5dbcd0ee16\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003e\u003cimg src=\"https://img.shields.io/badge/db0d4a1a39-fix-green\" alt=\"fix - db0d4a1a39\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003cimg src=\"https://img.shields.io/badge/a64e2883e9-fix-green\" alt=\"fix - a64e2883e9\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e\u003cimg src=\"https://img.shields.io/badge/6f80cca0b8-fix-green\" alt=\"fix - 6f80cca0b8\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.26\u003c/h2\u003e\n\u003ch3\u003ecompiler-cli\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/406aaa31e6ac4d3c155f5ab76e315ccd8d0387fe\"\u003e\u003cimg src=\"https://img.shields.io/badge/406aaa31e6-fix-green\" alt=\"fix - 406aaa31e6\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate babel dependencies to latest v7\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/26831d0cbd7e692210ca0799a203a7a5a0e741cd\"\u003e\u003cimg src=\"https://img.shields.io/badge/26831d0cbd-fix-green\" alt=\"fix - 26831d0cbd\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eavoid caching missing locale data\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8eb7aea08b27c0f1bcdeec3171880a6fcf28aa9a\"\u003e\u003cimg src=\"https://img.shields.io/badge/8eb7aea08b-fix-green\" alt=\"fix - 8eb7aea08b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003ereject dynamic script host elements\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003cimg src=\"https://img.shields.io/badge/b963f61028-fix-green\" alt=\"fix - b963f61028\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eprevent caching of responses with Set-Cookie headers\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1fdf2341684a0f528d1d31005bd48d882c0a47d1\"\u003e\u003cimg src=\"https://img.shields.io/badge/1fdf234168-fix-green\" alt=\"fix - 1fdf234168\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/baa093ba68c1d5ca7c35c562568c6021eb409b4c\"\u003e\u003cimg src=\"https://img.shields.io/badge/baa093ba68-fix-green\" alt=\"fix - baa093ba68\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer policy in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.25\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003cimg src=\"https://img.shields.io/badge/9f443bc24c-fix-green\" alt=\"fix - 9f443bc24c\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003cimg src=\"https://img.shields.io/badge/566ad05f20-fix-green\" alt=\"fix - 566ad05f20\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003cimg src=\"https://img.shields.io/badge/1a62130a6b-fix-green\" alt=\"fix - 1a62130a6b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003cimg src=\"https://img.shields.io/badge/a68ec702a0-fix-green\" alt=\"fix - a68ec702a0\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003cimg src=\"https://img.shields.io/badge/768a349e6e-fix-green\" alt=\"fix - 768a349e6e\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/blob/main/CHANGELOG.md\"\u003e@​angular/common's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e20.3.27 (2026-07-29)\u003c/h1\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e5dbcd0ee16\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003edb0d4a1a39\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003ea64e2883e9\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e6f80cca0b8\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.8 (2026-07-22)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/c0368f227846024bb26d3628c59541e870bb36e4\"\u003ec0368f2278\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve crossorigin on image preloads\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8616ba9db6240f3fbf8b905342d07326e096302b\"\u003e8616ba9db6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure SVG animation attributeName is checked case-insensitively\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eforms\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d302c7ab833c0bd3bba951135e76e0c48273b3d7\"\u003ed302c7ab83\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure \u003ccode\u003epending\u003c/code\u003e status propagates to the root form in signal forms\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9d40f8aefef9dcd893db5d01bc58d3e65e1cb4c2\"\u003e9d40f8aefe\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eprevent transfer cache key collisions\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003emigrations\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/388daea2fc188aad3ab69fb81bd3f893ac3cd846\"\u003e388daea2fc\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003ecorrectly migrate ngClass with mixed space-separated keys\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/bb39cda6483de2edab2f8221459b0ed5b73ef221\"\u003ebb39cda648\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve NgClass import on partial migration\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.7 (2026-07-15)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/91e33aa1de47d250d8cde21047597e8df771f07d\"\u003e91e33aa1de\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eavoid prototype lookups in date format caches\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003ccode\u003ea64e288\u003c/code\u003e\u003c/a\u003e fix(http): distinguish repeated transfer cache params\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003ccode\u003eb963f61\u003c/code\u003e\u003c/a\u003e fix(http): prevent caching of responses with Set-Cookie headers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/06be29826741212ca00e21efb6abff653e4541b5\"\u003e\u003ccode\u003e06be298\u003c/code\u003e\u003c/a\u003e fix(http): preserve empty referrer option in HttpRequest\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003ccode\u003e9f443bc\u003c/code\u003e\u003c/a\u003e fix(common): Limits date format string length\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/fa940e1f4de75c33ccca50357d941be53a5a0950\"\u003e\u003ccode\u003efa940e1\u003c/code\u003e\u003c/a\u003e fix(http): Rejects non-HTTP(S) URLs in JSONP requests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003ccode\u003e1a62130\u003c/code\u003e\u003c/a\u003e fix(common): use cryptographically secure SHA-256 for transfer cache key gene...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003ccode\u003e566ad05\u003c/code\u003e\u003c/a\u003e fix(common): skip transfer cache for uncacheable HTTP traffic\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/e2ef1ce72ae084e01a76950c731052f4fa97fcdd\"\u003e\u003ccode\u003ee2ef1ce\u003c/code\u003e\u003c/a\u003e fix(http): skip transfer cache for fetch credentialed requests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/3d135ce59bbf7426825bc493bc681f266846ac79\"\u003e\u003ccode\u003e3d135ce\u003c/code\u003e\u003c/a\u003e fix(common): add upper bounds for digitsInfo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/39a4b4cc8e8d101a566a70658707bc9f53dd5883\"\u003e\u003ccode\u003e39a4b4c\u003c/code\u003e\u003c/a\u003e fix(common): sanitize placeholder\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/angular/angular/commits/v20.3.27/packages/common\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@angular/compiler` from 17.3.8 to 20.3.27\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/releases\"\u003e@​angular/compiler's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e20.3.27\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e\u003cimg src=\"https://img.shields.io/badge/5dbcd0ee16-fix-green\" alt=\"fix - 5dbcd0ee16\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003e\u003cimg src=\"https://img.shields.io/badge/db0d4a1a39-fix-green\" alt=\"fix - db0d4a1a39\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003cimg src=\"https://img.shields.io/badge/a64e2883e9-fix-green\" alt=\"fix - a64e2883e9\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e\u003cimg src=\"https://img.shields.io/badge/6f80cca0b8-fix-green\" alt=\"fix - 6f80cca0b8\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.26\u003c/h2\u003e\n\u003ch3\u003ecompiler-cli\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/406aaa31e6ac4d3c155f5ab76e315ccd8d0387fe\"\u003e\u003cimg src=\"https://img.shields.io/badge/406aaa31e6-fix-green\" alt=\"fix - 406aaa31e6\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate babel dependencies to latest v7\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/26831d0cbd7e692210ca0799a203a7a5a0e741cd\"\u003e\u003cimg src=\"https://img.shields.io/badge/26831d0cbd-fix-green\" alt=\"fix - 26831d0cbd\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eavoid caching missing locale data\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8eb7aea08b27c0f1bcdeec3171880a6fcf28aa9a\"\u003e\u003cimg src=\"https://img.shields.io/badge/8eb7aea08b-fix-green\" alt=\"fix - 8eb7aea08b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003ereject dynamic script host elements\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003cimg src=\"https://img.shields.io/badge/b963f61028-fix-green\" alt=\"fix - b963f61028\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eprevent caching of responses with Set-Cookie headers\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1fdf2341684a0f528d1d31005bd48d882c0a47d1\"\u003e\u003cimg src=\"https://img.shields.io/badge/1fdf234168-fix-green\" alt=\"fix - 1fdf234168\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/baa093ba68c1d5ca7c35c562568c6021eb409b4c\"\u003e\u003cimg src=\"https://img.shields.io/badge/baa093ba68-fix-green\" alt=\"fix - baa093ba68\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer policy in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.25\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003cimg src=\"https://img.shields.io/badge/9f443bc24c-fix-green\" alt=\"fix - 9f443bc24c\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003cimg src=\"https://img.shields.io/badge/566ad05f20-fix-green\" alt=\"fix - 566ad05f20\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003cimg src=\"https://img.shields.io/badge/1a62130a6b-fix-green\" alt=\"fix - 1a62130a6b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003cimg src=\"https://img.shields.io/badge/a68ec702a0-fix-green\" alt=\"fix - a68ec702a0\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003cimg src=\"https://img.shields.io/badge/768a349e6e-fix-green\" alt=\"fix - 768a349e6e\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/blob/main/CHANGELOG.md\"\u003e@​angular/compiler's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e20.3.27 (2026-07-29)\u003c/h1\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e5dbcd0ee16\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003edb0d4a1a39\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003ea64e2883e9\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e6f80cca0b8\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.8 (2026-07-22)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/c0368f227846024bb26d3628c59541e870bb36e4\"\u003ec0368f2278\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve crossorigin on image preloads\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8616ba9db6240f3fbf8b905342d07326e096302b\"\u003e8616ba9db6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure SVG animation attributeName is checked case-insensitively\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eforms\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d302c7ab833c0bd3bba951135e76e0c48273b3d7\"\u003ed302c7ab83\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure \u003ccode\u003epending\u003c/code\u003e status propagates to the root form in signal forms\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9d40f8aefef9dcd893db5d01bc58d3e65e1cb4c2\"\u003e9d40f8aefe\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eprevent transfer cache key collisions\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003emigrations\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/388daea2fc188aad3ab69fb81bd3f893ac3cd846\"\u003e388daea2fc\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003ecorrectly migrate ngClass with mixed space-separated keys\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/bb39cda6483de2edab2f8221459b0ed5b73ef221\"\u003ebb39cda648\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve NgClass import on partial migration\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.7 (2026-07-15)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/91e33aa1de47d250d8cde21047597e8df771f07d\"\u003e91e33aa1de\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eavoid prototype lookups in date format caches\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003e\u003ccode\u003edb0d4a1\u003c/code\u003e\u003c/a\u003e fix(compiler): restrict possible event handler check to property names longer...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e\u003ccode\u003e5dbcd0e\u003c/code\u003e\u003c/a\u003e fix(compiler): disallow i18n event attributes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003ccode\u003ea68ec70\u003c/code\u003e\u003c/a\u003e fix(compiler): sanitize two-way properties\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/d40acc6431997b304ec54c951e55d2e52ed6f6dc\"\u003e\u003ccode\u003ed40acc6\u003c/code\u003e\u003c/a\u003e fix(compiler): prevent namespaced SVG \u0026lt;style\u0026gt; elements from being stripped\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/7ae6381a4845ad4b13a7a5574c5433b077c93c5c\"\u003e\u003ccode\u003e7ae6381\u003c/code\u003e\u003c/a\u003e test(compiler-cli): align ngtsc sanitization expectations with modern DOM sch...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/36200bd81a3420d8222dfe10767437c383a20fe8\"\u003e\u003ccode\u003e36200bd\u003c/code\u003e\u003c/a\u003e test(core): update spec files to match 20.3.x limits and actual contexts (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/compiler/issues/68\"\u003e#68\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/823b37f0468f7c8b38637ce93e26fc8db791b282\"\u003e\u003ccode\u003e823b37f\u003c/code\u003e\u003c/a\u003e test(compiler): remove obsolete schema_extractor import (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/compiler/issues/68926\"\u003e#68926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/e345a58069ede97250af449f5b7e9b94f828d30c\"\u003e\u003ccode\u003ee345a58\u003c/code\u003e\u003c/a\u003e fix(core): normalize tag names in runtime i18n attribute security context loo...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/8f35b182b1479ed80d652f185c2c3ee5a82ea34c\"\u003e\u003ccode\u003e8f35b18\u003c/code\u003e\u003c/a\u003e fix(compiler): normalize tag names with custom namespaces in DomElementSchema...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/64a89e917a0794a3d74713bdb4c9c63d703b317b\"\u003e\u003ccode\u003e64a89e9\u003c/code\u003e\u003c/a\u003e fix(compiler): sanitize dynamic href and xlink:href bindings on SVG a element...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/angular/angular/commits/v20.3.27/packages/compiler\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@angular/core` from 17.3.8 to 20.3.25\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/releases\"\u003e@​angular/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e20.3.25\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003cimg src=\"https://img.shields.io/badge/9f443bc24c-fix-green\" alt=\"fix - 9f443bc24c\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003cimg src=\"https://img.shields.io/badge/566ad05f20-fix-green\" alt=\"fix - 566ad05f20\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003cimg src=\"https://img.shields.io/badge/1a62130a6b-fix-green\" alt=\"fix - 1a62130a6b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003cimg src=\"https://img.shields.io/badge/a68ec702a0-fix-green\" alt=\"fix - a68ec702a0\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003cimg src=\"https://img.shields.io/badge/768a349e6e-fix-green\" alt=\"fix - 768a349e6e\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/ca48b4728d5f6770be63a08f64a6432207ad54c0\"\u003e\u003cimg src=\"https://img.shields.io/badge/ca48b4728d-fix-green\" alt=\"fix - ca48b4728d\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003evalidate lowercase SVG animation attribute names (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/69270\"\u003e#69270\u003c/a\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/06be29826741212ca00e21efb6abff653e4541b5\"\u003e\u003cimg src=\"https://img.shields.io/badge/06be298267-fix-green\" alt=\"fix - 06be298267\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve empty referrer option in HttpRequest\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/fa940e1f4de75c33ccca50357d941be53a5a0950\"\u003e\u003cimg src=\"https://img.shields.io/badge/fa940e1f4d-fix-green\" alt=\"fix - fa940e1f4d\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eRejects non-HTTP(S) URLs in JSONP requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/e2ef1ce72ae084e01a76950c731052f4fa97fcdd\"\u003e\u003cimg src=\"https://img.shields.io/badge/e2ef1ce72a-fix-green\" alt=\"fix - e2ef1ce72a\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for fetch credentialed requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/49368c185907edb48467074c56e305abbfa3544a\"\u003e\u003cimg src=\"https://img.shields.io/badge/49368c1859-fix-green\" alt=\"fix - 49368c1859\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden platform location origin validation during SSR\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d55c94ad811a15c9c255164a0d66892c645f602e\"\u003e\u003cimg src=\"https://img.shields.io/badge/d55c94ad81-refactor-yellow\" alt=\"refactor - d55c94ad81\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edeprecate ServerXhr (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/69256\"\u003e#69256\u003c/a\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d65a5f457b1afd6bdd4d952d3f213c6aa1aabcbc\"\u003e\u003cimg src=\"https://img.shields.io/badge/d65a5f457b-fix-green\" alt=\"fix - d65a5f457b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eStrips sensitive headers on cross-origin redirects\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003eDeprecations\u003c/h2\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eXHR support in \u003ccode\u003e@angular/platform-server\u003c/code\u003e is deprecated. Use standard \u003ccode\u003efetch\u003c/code\u003e APIs instead.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e20.3.24\u003c/h2\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6ca433e56bcf74fdb6ad01d3afdf59628fba69b6\"\u003e\u003cimg src=\"https://img.shields.io/badge/6ca433e56b-fix-green\" alt=\"fix - 6ca433e56b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003ethrow on suspicious URLs and restrict protocol-relative URLs\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8680b5152fe58ebde81e331b74ba806fc86514cc\"\u003e\u003cimg src=\"https://img.shields.io/badge/8680b5152f-fix-green\" alt=\"fix - 8680b5152f\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.23\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d40acc6431997b304ec54c951e55d2e52ed6f6dc\"\u003e\u003cimg src=\"https://img.shields.io/badge/d40acc6431-fix-green\" alt=\"fix - d40acc6431\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eprevent namespaced SVG \u003c!-- raw HTML omitted --\u003e elements from being stripped\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.22\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/blob/main/CHANGELOG.md\"\u003e@​angular/core's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e20.3.25 (2026-06-10)\u003c/h1\u003e\n\u003ch2\u003eDeprecations\u003c/h2\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eXHR support in \u003ccode\u003e@angular/platform-server\u003c/code\u003e is deprecated. Use standard \u003ccode\u003efetch\u003c/code\u003e APIs instead.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e9f443bc24c\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e566ad05f20\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e1a62130a6b\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003ea68ec702a0\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e768a349e6e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/ca48b4728d5f6770be63a08f64a6432207ad54c0\"\u003eca48b4728d\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003evalidate lowercase SVG animation attribute names (\u003ca href=\"https://redirect.github.com/angular/angular/pull/69270\"\u003e#69270\u003c/a\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/06be29826741212ca00e21efb6abff653e4541b5\"\u003e06be298267\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve empty referrer option in HttpRequest\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/fa940e1f4de75c33ccca50357d941be53a5a0950\"\u003efa940e1f4d\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eRejects non-HTTP(S) URLs in JSONP requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/e2ef1ce72ae084e01a76950c731052f4fa97fcdd\"\u003ee2ef1ce72a\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for fetch credentialed requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/49368c185907edb48467074c56e305abbfa3544a\"\u003e49368c1859\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eharden platform location origin validation during SSR\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d55c94ad811a15c9c255164a0d66892c645f602e\"\u003ed55c94ad81\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003erefactor\u003c/td\u003e\n\u003ctd\u003edeprecate ServerXhr (\u003ca href=\"https://redirect.github.com/angular/angular/pull/69256\"\u003e#69256\u003c/a\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d65a5f457b1afd6bdd4d952d3f213c6aa1aabcbc\"\u003ed65a5f457b\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eStrips sensitive headers on cross-origin redirects\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.0 (2026-06-03)\u003c/h1\u003e\n\u003cp\u003e\u003ca href=\"https://goo.gle/angular-v22-blog\"\u003eBlog post \u0026quot;Announcing Angular v22\u0026quot;\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eBreaking Changes\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThis change will trigger the \u003ccode\u003enullishCoalescingNotNullable\u003c/code\u003e and \u003ccode\u003eoptionalChainNotNullable\u003c/code\u003e diagnostics on exisiting projects.\nYou might want to disable those 2 diagnotiscs in your \u003ccode\u003etsconfig\u003c/code\u003e temporarily.\u003c/li\u003e\n\u003cli\u003edata prefixed attribute no-longer bind inputs nor outputs.\u003c/li\u003e\n\u003cli\u003eThe compiler will throw when there a when inputs, outputs or model are binding to the same input/outputs.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ein\u003c/code\u003e variables will throw in template expressions.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ecompiler-cli\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/ca48b4728d5f6770be63a08f64a6432207ad54c0\"\u003e\u003ccode\u003eca48b47\u003c/code\u003e\u003c/a\u003e fix(core): validate lowercase SVG animation attribute names (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/69270\"\u003e#69270\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003ccode\u003e1a62130\u003c/code\u003e\u003c/a\u003e fix(common): use cryptographically secure SHA-256 for transfer cache key gene...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/49368c185907edb48467074c56e305abbfa3544a\"\u003e\u003ccode\u003e49368c1\u003c/code\u003e\u003c/a\u003e fix(platform-server): harden platform location origin validation during SSR\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003ccode\u003e566ad05\u003c/code\u003e\u003c/a\u003e fix(common): skip transfer cache for uncacheable HTTP traffic\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003ccode\u003e768a349\u003c/code\u003e\u003c/a\u003e fix(core): harden TransferState restoration against DOM clobbering\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/7ae6381a4845ad4b13a7a5574c5433b077c93c5c\"\u003e\u003ccode\u003e7ae6381\u003c/code\u003e\u003c/a\u003e test(compiler-cli): align ngtsc sanitization expectations with modern DOM sch...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/65954092483a88fc69cccd3b4c56d96450ac2fe8\"\u003e\u003ccode\u003e6595409\u003c/code\u003e\u003c/a\u003e test(core): update golden symbols and host bindings sanitization spec (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/68926\"\u003e#68926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/d86e4e7b2ad0e667aeb0f8ed053e2cb2bd154b81\"\u003e\u003ccode\u003ed86e4e7\u003c/code\u003e\u003c/a\u003e fix(core): reject script element as a dynamic component host (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/68926\"\u003e#68926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/b8f1f7276514e258e8c815ec5c7d9b8826ecd372\"\u003e\u003ccode\u003eb8f1f72\u003c/code\u003e\u003c/a\u003e test(core): remove obsolete blockquote cite host binding tests (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/68926\"\u003e#68926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/36200bd81a3420d8222dfe10767437c383a20fe8\"\u003e\u003ccode\u003e36200bd\u003c/code\u003e\u003c/a\u003e test(core): update spec files to match 20.3.x limits and actual contexts (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/68\"\u003e#68\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/angular/angular/commits/v20.3.25/packages/core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@angular/common` from 17.3.8 to 20.3.27\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/releases\"\u003e@​angular/common's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e20.3.27\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e\u003cimg src=\"https://img.shields.io/badge/5dbcd0ee16-fix-green\" alt=\"fix - 5dbcd0ee16\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003e\u003cimg src=\"https://img.shields.io/badge/db0d4a1a39-fix-green\" alt=\"fix - db0d4a1a39\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003cimg src=\"https://img.shields.io/badge/a64e2883e9-fix-green\" alt=\"fix - a64e2883e9\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e\u003cimg src=\"https://img.shields.io/badge/6f80cca0b8-fix-green\" alt=\"fix - 6f80cca0b8\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.26\u003c/h2\u003e\n\u003ch3\u003ecompiler-cli\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/406aaa31e6ac4d3c155f5ab76e315ccd8d0387fe\"\u003e\u003cimg src=\"https://img.shields.io/badge/406aaa31e6-fix-green\" alt=\"fix - 406aaa31e6\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate babel dependencies to latest v7\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/26831d0cbd7e692210ca0799a203a7a5a0e741cd\"\u003e\u003cimg src=\"https://img.shields.io/badge/26831d0cbd-fix-green\" alt=\"fix - 26831d0cbd\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eavoid caching missing locale data\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8eb7aea08b27c0f1bcdeec3171880a6fcf28aa9a\"\u003e\u003cimg src=\"https://img.shields.io/badge/8eb7aea08b-fix-green\" alt=\"fix - 8eb7aea08b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003ereject dynamic script host elements\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003cimg src=\"https://img.shields.io/badge/b963f61028-fix-green\" alt=\"fix - b963f61028\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eprevent caching of responses with Set-Cookie headers\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1fdf2341684a0f528d1d31005bd48d882c0a47d1\"\u003e\u003cimg src=\"https://img.shields.io/badge/1fdf234168-fix-green\" alt=\"fix - 1fdf234168\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/baa093ba68c1d5ca7c35c562568c6021eb409b4c\"\u003e\u003cimg src=\"https://img.shields.io/badge/baa093ba68-fix-green\" alt=\"fix - baa093ba68\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer policy in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.25\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003cimg src=\"https://img.shields.io/badge/9f443bc24c-fix-green\" alt=\"fix - 9f443bc24c\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003cimg src=\"https://img.shields.io/badge/566ad05f20-fix-green\" alt=\"fix - 566ad05f20\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003cimg src=\"https://img.shields.io/badge/1a62130a6b-fix-green\" alt=\"fix - 1a62130a6b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003cimg src=\"https://img.shields.io/badge/a68ec702a0-fix-green\" alt=\"fix - a68ec702a0\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003cimg src=\"https://img.shields.io/badge/768a349e6e-fix-green\" alt=\"fix - 768a349e6e\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/blob/main/CHANGELOG.md\"\u003e@​angular/common's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e20.3.27 (2026-07-29)\u003c/h1\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e5dbcd0ee16\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003edb0d4a1a39\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003ea64e2883e9\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e6f80cca0b8\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.8 (2026-07-22)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/c0368f227846024bb26d3628c59541e870bb36e4\"\u003ec0368f2278\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve crossorigin on image preloads\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8616ba9db6240f3fbf8b905342d07326e096302b\"\u003e8616ba9db6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure SVG animation attributeName is checked case-insensitively\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eforms\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d302c7ab833c0bd3bba951135e76e0c48273b3d7\"\u003ed302c7ab83\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure \u003ccode\u003epending\u003c/code\u003e status propagates to the root form in signal forms\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9d40f8aefef9dcd893db5d01bc58d3e65e1cb4c2\"\u003e9d40f8aefe\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eprevent transfer cache key collisions\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003emigrations\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/388daea2fc188aad3ab69fb81bd3f893ac3cd846\"\u003e388daea2fc\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003ecorrectly migrate ngClass with mixed space-separated keys\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/bb39cda6483de2edab2f8221459b0ed5b73ef221\"\u003ebb39cda648\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve NgClass import on partial migration\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.7 (2026-07-15)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/91e33aa1de47d250d8cde21047597e8df771f07d\"\u003e91e33aa1de\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eavoid prototype lookups in date format caches\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003ccode\u003ea64e288\u003c/code\u003e\u003c/a\u003e fix(http): distinguish repeated transfer cache params\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003ccode\u003eb963f61\u003c/code\u003e\u003c/a\u003e fix(http): prevent caching of responses with Set-Cookie headers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/06be29826741212ca00e21efb6abff653e4541b5\"\u003e\u003ccode\u003e06be298\u003c/code\u003e\u003c/a\u003e fix(http): preserve empty referrer option in HttpRequest\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003ccode\u003e9f443bc\u003c/code\u003e\u003c/a\u003e fix(common): Limits date format string length\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/fa940e1f4de75c33ccca50357d941be53a5a0950\"\u003e\u003ccode\u003efa940e1\u003c/code\u003e\u003c/a\u003e fix(http): Rejects non-HTTP(S) URLs in JSONP requests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003ccode\u003e1a62130\u003c/code\u003e\u003c/a\u003e fix(common): use cryptographically secure SHA-256 for transfer cache key gene...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003ccode\u003e566ad05\u003c/code\u003e\u003c/a\u003e fix(common): skip transfer cache for uncacheable HTTP traffic\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/e2ef1ce72ae08...\n\n_Description has been truncated_\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nUpdate dependencies across the repo to pick up security fixes and keep example apps current. Key upgrades include Angular 20, `postcss` 8.5.23, and `undici` 6.28.0; no app logic changes.\n\n- **Dependencies**\n  - `postcss` → 8.5.23 (security and bug fixes)\n  - `undici` → 6.28.0 (security fixes)\n  - Angular examples: `@angular/common` → 20.3.27, `@angular/compiler` → 20.3.27, `@angular/core` → 20.3.25\n  - `nuxt` → 3.21.10 and `@nuxt/devtools` → 3.4.1\n  - `next` → 16.3.0 in example apps\n  - `fast-uri` → 3.1.5, `hono` → 4.12.34\n  - Refreshed npm/pnpm/yarn lockfiles across fixtures and examples\n\n\u003csup\u003eWritten for commit 6dd1a9a82be8d49a1447c270bd914cc3207b2281. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/michaelhughes2501/turborepo/pull/65?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/michaelhughes2501/turborepo/pull/65","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/michaelhughes2501%2Fturborepo/issues/65","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/65/packages"}},{"old_version":"7.28.0","new_version":"8.10.0","update_type":"major","path":null,"pr_created_at":"2026-08-07T16:03:04.000Z","version_change":"7.28.0 → 8.10.0","issue":{"uuid":"5091879766","node_id":"PR_kwDOCS99lM78HtAU","number":509,"state":"open","title":"Bump undici from 7.28.0 to 8.10.0","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T16:03:04.000Z","updated_at":"2026-08-07T16:04:37.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"undici","old_version":"7.28.0","new_version":"8.10.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 7.28.0 to 8.10.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: namespace h2 options by \u003ca href=\"https://github.com/metcoder95\"\u003e\u003ccode\u003e@​metcoder95\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5498\"\u003enodejs/undici#5498\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: update WPT expectations by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5587\"\u003enodejs/undici#5587\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: add cache/dedupe + dns re-dispatch integration tests by \u003ca href=\"https://github.com/GiHoon1123\"\u003e\u003ccode\u003e@​GiHoon1123\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5535\"\u003enodejs/undici#5535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): support process.unref by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5578\"\u003enodejs/undici#5578\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): ensure every request settles by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5603\"\u003enodejs/undici#5603\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(readable): consume a body whose end has already been emitted by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5617\"\u003enodejs/undici#5617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): skip the content-length checkpoint for HEAD and for a 206 without content-range by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5610\"\u003enodejs/undici#5610\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: revert idle socket validation to setTimeout(0) to prevent stall on idle event loop by \u003ca href=\"https://github.com/marceli1404\"\u003e\u003ccode\u003e@​marceli1404\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5606\"\u003enodejs/undici#5606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(env-http-proxy-agent): match bare IPv6 addresses in no_proxy by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5623\"\u003enodejs/undici#5623\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: handle aggregate balanced pool errors by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5377\"\u003enodejs/undici#5377\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(readable): keep body bytes that arrive after setEncoding() by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5620\"\u003enodejs/undici#5620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(socks5): evict unused origin pools by \u003ca href=\"https://github.com/Kkartik14\"\u003e\u003ccode\u003e@​Kkartik14\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5595\"\u003enodejs/undici#5595\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: skip deduplication for upgrade requests by \u003ca href=\"https://github.com/Ram-blip\"\u003e\u003ccode\u003e@​Ram-blip\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5593\"\u003enodejs/undici#5593\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward informational responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5625\"\u003enodejs/undici#5625\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(mock): non-string path matchers under ignoreTrailingSlash, and DataView reply bodies by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5619\"\u003enodejs/undici#5619\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(interceptors): cache() and deduplicate() silently inert on Client/Pool without opts.origin by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5628\"\u003enodejs/undici#5628\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5633\"\u003enodejs/undici#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/init from 4.36.2 to 4.37.3 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5634\"\u003enodejs/undici#5634\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.4.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5636\"\u003enodejs/undici#5636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(mock): emit request body lifecycle hooks by \u003ca href=\"https://github.com/marko1olo\"\u003e\u003ccode\u003e@​marko1olo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5367\"\u003enodejs/undici#5367\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): detach upgrade close handler after GOAWAY by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5641\"\u003enodejs/undici#5641\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: retry refused HTTP/2 streams by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5598\"\u003enodejs/undici#5598\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: preserve DNS origin hostname on sockets by \u003ca href=\"https://github.com/cyphercodes\"\u003e\u003ccode\u003e@​cyphercodes\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5577\"\u003enodejs/undici#5577\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marceli1404\"\u003e\u003ccode\u003e@​marceli1404\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5606\"\u003enodejs/undici#5606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kkartik14\"\u003e\u003ccode\u003e@​Kkartik14\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5595\"\u003enodejs/undici#5595\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5641\"\u003enodejs/undici#5641\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cyphercodes\"\u003e\u003ccode\u003e@​cyphercodes\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5577\"\u003enodejs/undici#5577\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v8.9.0...v8.10.0\"\u003ehttps://github.com/nodejs/undici/compare/v8.9.0...v8.10.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev8.9.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4fe5bc5fefe5ac81a200fc8e1cf84b8bf8464451\"\u003e4fe5bc5f\u003c/a\u003e with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/9f09b49accd391cca818409447f2fb8bc93229b3\"\u003e9f09b49a\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7d3cf924c262c486bc77f951348f4e5c847b7b42\"\u003e7d3cf924\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/c601fff1c56eca84438c3ed4ecb39404252be622\"\u003ec601fff1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e11a68ed4ff345c79402476f7a00d473443e318d\"\u003ee11a68ed\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/2b3f749336d356bbbc50192f87f6cf7bc714721a\"\u003e2b3f7493\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/10d93fc332f2c8c161982dec3833201de29891b5\"\u003e10d93fc3\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eAdditional hardening\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/c8d80e6b2dcfab282557b08f51352937bc9e5692\"\u003e\u003ccode\u003ec8d80e6\u003c/code\u003e\u003c/a\u003e Bumped v8.10.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5644\"\u003e#5644\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66923b47dc1ed095581daa6a53b2ad1bf3e899b4\"\u003e\u003ccode\u003e66923b4\u003c/code\u003e\u003c/a\u003e fix: preserve DNS origin hostname on sockets (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5577\"\u003e#5577\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/392649944c3b989681af1eae2e0970661f9ca464\"\u003e\u003ccode\u003e3926499\u003c/code\u003e\u003c/a\u003e fix: retry refused HTTP/2 streams (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5598\"\u003e#5598\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/73d6e9e19df47f85625d2dc082daa919ae6636c1\"\u003e\u003ccode\u003e73d6e9e\u003c/code\u003e\u003c/a\u003e fix(h2): detach upgrade close handler after GOAWAY (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5641\"\u003e#5641\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b111adbb675ebfcfa52790346dcd88e61c700818\"\u003e\u003ccode\u003eb111adb\u003c/code\u003e\u003c/a\u003e fix(mock): emit request body lifecycle hooks (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5367\"\u003e#5367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ae4a3e37a2ddfe798b64771176e31e8e7819c743\"\u003e\u003ccode\u003eae4a3e3\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/setup-node from 6.4.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5636\"\u003e#5636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ec3fbf19aa47eca6decc390b66bf56034bc03d52\"\u003e\u003ccode\u003eec3fbf1\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action/init from 4.36.2 to 4.37.3 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5634\"\u003e#5634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/21517200296205f3aa09a7b976dde571b441405c\"\u003e\u003ccode\u003e2151720\u003c/code\u003e\u003c/a\u003e build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5633\"\u003e#5633\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b96a11620e2f9fe5adafa2ba7b7f363b96b5a9d7\"\u003e\u003ccode\u003eb96a116\u003c/code\u003e\u003c/a\u003e fix(interceptors): allow interceptors without opts.origin (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5628\"\u003e#5628\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/a18ef2d05af48047339be51d8817492abc30f39d\"\u003e\u003ccode\u003ea18ef2d\u003c/code\u003e\u003c/a\u003e fix(mock): non-string path matchers under ignoreTrailingSlash, and DataView r...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v8.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=7.28.0\u0026new-version=8.10.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/hugo19941994/jwks-fetch/pull/509","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/hugo19941994%2Fjwks-fetch/issues/509","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/509/packages"}},{"old_version":"6.27.0","new_version":"6.28.0","update_type":"minor","path":null,"pr_created_at":"2026-08-07T15:29:43.000Z","version_change":"6.27.0 → 6.28.0","issue":{"uuid":"5091617869","node_id":"PR_kwDOScp_gM78G3EK","number":56,"state":"open","title":"chore(deps): Bump the npm_and_yarn group across 15 directories with 10 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":4,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T15:29:43.000Z","updated_at":"2026-08-07T15:31:41.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): Bump","group_name":"npm_and_yarn","update_count":10,"packages":[{"name":"postcss","old_version":"8.5.16","new_version":"8.5.23","repository_url":"https://github.com/postcss/postcss"},{"name":"undici","old_version":"6.27.0","new_version":"6.28.0"},{"name":"fast-uri","old_version":"3.1.3","new_version":"3.1.5","repository_url":"https://github.com/fastify/fast-uri"},{"name":"ip-address","old_version":"10.2.0","new_version":"10.4.0"},{"name":"@angular/common","old_version":"17.3.8","new_version":"20.3.27","repository_url":"https://github.com/angular/angular"},{"name":"@angular/compiler","old_version":"17.3.8","new_version":"20.3.27","repository_url":"https://github.com/angular/angular"},{"name":"@angular/core","old_version":"17.3.8","new_version":"20.3.25","repository_url":"https://github.com/angular/angular"},{"name":"@angular/common","old_version":"17.3.8","new_version":"20.3.27","repository_url":"https://github.com/angular/angular"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 1 update in the / directory: [postcss](https://github.com/postcss/postcss).\nBumps the npm_and_yarn group with 3 updates in the /examples/with-angular directory: [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common), [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) and [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core).\nBumps the npm_and_yarn group with 3 updates in the /examples/with-angular/apps/docs directory: [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common), [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) and [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core).\nBumps the npm_and_yarn group with 3 updates in the /examples/with-angular/apps/web directory: [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common), [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) and [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core).\nBumps the npm_and_yarn group with 3 updates in the /examples/with-angular/packages/ui directory: [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common), [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) and [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core).\nBumps the npm_and_yarn group with 1 update in the /examples/with-npm directory: [postcss](https://github.com/postcss/postcss).\nBumps the npm_and_yarn group with 1 update in the /examples/with-prisma directory: [fast-uri](https://github.com/fastify/fast-uri).\nBumps the npm_and_yarn group with 1 update in the /examples/with-tailwind directory: [postcss](https://github.com/postcss/postcss).\nBumps the npm_and_yarn group with 2 updates in the /examples/with-vue-nuxt directory: [@nuxt/devtools](https://github.com/nuxt/devtools/tree/HEAD/packages/devtools) and [nuxt](https://github.com/nuxt/nuxt/tree/HEAD/packages/nuxt).\nBumps the npm_and_yarn group with 1 update in the /examples/with-vue-nuxt/apps/docs directory: [nuxt](https://github.com/nuxt/nuxt/tree/HEAD/packages/nuxt).\nBumps the npm_and_yarn group with 1 update in the /lockfile-tests/fixtures/berry directory: [fast-uri](https://github.com/fastify/fast-uri).\nBumps the npm_and_yarn group with 2 updates in the /lockfile-tests/fixtures/npm-lock-workspace-variation directory: [postcss](https://github.com/postcss/postcss) and [fast-uri](https://github.com/fastify/fast-uri).\nBumps the npm_and_yarn group with 1 update in the /lockfile-tests/fixtures/pnpm-override-peer-variant directory: [hono](https://github.com/honojs/hono).\nBumps the npm_and_yarn group with 1 update in the /lockfile-tests/fixtures/robust-berry-resolutions directory: [fast-uri](https://github.com/fastify/fast-uri).\nBumps the npm_and_yarn group with 1 update in the /turborepo-tests/integration/fixtures/framework_inference directory: [postcss](https://github.com/postcss/postcss).\n\nUpdates `postcss` from 8.5.16 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.16...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 6.27.0 to 6.28.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.28.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e740a0b7c\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003ecba3a52a\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e4fd5a0c6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003eaf748404\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e and \u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ehttps://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a\"\u003e\u003ccode\u003e01a912e\u003c/code\u003e\u003c/a\u003e Bumped v6.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5591\"\u003e#5591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e\"\u003e\u003ccode\u003e481ecfc\u003c/code\u003e\u003c/a\u003e Use Node 22 and npm 11 to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e\u003ccode\u003e740a0b7\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0\"\u003e\u003ccode\u003e2698e49\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e\u003ccode\u003e4fd5a0c\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003e\u003ccode\u003ecba3a52\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003e\u003ccode\u003eaf74840\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.3 to 3.1.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v39h-62p7-jpjc\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v39h-62p7-jpjc\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHandle malformed fragment decoding as a parse error by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/171\"\u003efastify/fast-uri#171\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.1...v3.1.2\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.1...v3.1.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.1\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-q3j6-qgpj-74h6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-q3j6-qgpj-74h6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump tsd from 0.32.0 to 0.33.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/148\"\u003efastify/fast-uri#148\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 4 to 5 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/149\"\u003efastify/fast-uri#149\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(.npmrc): ignore scripts by \u003ca href=\"https://github.com/Fdawgs\"\u003e\u003ccode\u003e@​Fdawgs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/150\"\u003efastify/fast-uri#150\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): remove \u003ccode\u003e@​fastify/pre-commit\u003c/code\u003e by \u003ca href=\"https://github.com/Fdawgs\"\u003e\u003ccode\u003e@​Fdawgs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/151\"\u003efastify/fast-uri#151\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 4 to 5 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/152\"\u003efastify/fast-uri#152\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(ci): add concurrency config by \u003ca href=\"https://github.com/Fdawgs\"\u003e\u003ccode\u003e@​Fdawgs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/153\"\u003efastify/fast-uri#153\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 5 to 6 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/154\"\u003efastify/fast-uri#154\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 5 to 6 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/156\"\u003efastify/fast-uri#156\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(license): standardise license notice by \u003ca href=\"https://github.com/Fdawgs\"\u003e\u003ccode\u003e@​Fdawgs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/159\"\u003efastify/fast-uri#159\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003estyle: remove trailing whitespace by \u003ca href=\"https://github.com/Fdawgs\"\u003e\u003ccode\u003e@​Fdawgs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/161\"\u003efastify/fast-uri#161\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: remove unused github files by \u003ca href=\"https://github.com/Tony133\"\u003e\u003ccode\u003e@​Tony133\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/162\"\u003efastify/fast-uri#162\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: update readme by \u003ca href=\"https://github.com/Tony133\"\u003e\u003ccode\u003e@​Tony133\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fastify/fast-uri/pull/164\"\u003efastify/fast-uri#164\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/5e179cbb4636d5f773ed21126e5bd3068e87e94e\"\u003e\u003ccode\u003e5e179cb\u003c/code\u003e\u003c/a\u003e Bumped v3.1.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/2cad02d6ed428a720499bb7a3c3d6c3d41f10f5a\"\u003e\u003ccode\u003e2cad02d\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6aeece669e4166b2446a89f17c07a3b15dfb7ed4\"\u003e\u003ccode\u003e6aeece6\u003c/code\u003e\u003c/a\u003e Bumped v3.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/2d50fbabc80e4d0884fe0f6a98fe118ce6faa353\"\u003e\u003ccode\u003e2d50fba\u003c/code\u003e\u003c/a\u003e fix: reject literal backslash in URI authority\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/0549fe35b0d482233f3be2816439f3ec803603fa\"\u003e\u003ccode\u003e0549fe3\u003c/code\u003e\u003c/a\u003e Bumped v3.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/2a6d357a18a68e6d812824379fd3388a1ae50d05\"\u003e\u003ccode\u003e2a6d357\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/919dd8ea7689fcc220d0d9b71307f5095e723ef9\"\u003e\u003ccode\u003e919dd8e\u003c/code\u003e\u003c/a\u003e Bumped v3.1.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c65ba573714af6b8e19e481d9444c27bc4355d07\"\u003e\u003ccode\u003ec65ba57\u003c/code\u003e\u003c/a\u003e fixup: linting\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6c86c17c3d76fb93aa3700ec6c0fa00faeb97293\"\u003e\u003ccode\u003e6c86c17\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/a95158ad308df4d92bbde4eba699ce5165e9f796\"\u003e\u003ccode\u003ea95158a\u003c/code\u003e\u003c/a\u003e Handle malformed fragment decoding without throwing (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/171\"\u003e#171\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.0...v3.1.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ip-address` from 10.2.0 to 10.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/beaugunderson/ip-address/releases\"\u003eip-address's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev10.4.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd GitHub Actions CI by \u003ca href=\"https://github.com/beaugunderson\"\u003e\u003ccode\u003e@​beaugunderson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/pull/213\"\u003ebeaugunderson/ip-address#213\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eKeep the package loadable on node 12, and enforce it by \u003ca href=\"https://github.com/beaugunderson\"\u003e\u003ccode\u003e@​beaugunderson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/pull/216\"\u003ebeaugunderson/ip-address#216\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eValidate the byte arrays Address6 is given by \u003ca href=\"https://github.com/beaugunderson\"\u003e\u003ccode\u003e@​beaugunderson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/pull/217\"\u003ebeaugunderson/ip-address#217\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.3.1...v10.4.0\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.3.1...v10.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.3.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.3.0...v10.3.1\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.3.0...v10.3.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.3.0\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.2.2...v10.3.0\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.2.2...v10.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.2.2\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.2.1...v10.2.2\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.2.1...v10.2.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.2.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.2.1\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.2.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/fbb8db28f1559842b7191cab7d8ea6408ed82f7b\"\u003e\u003ccode\u003efbb8db2\u003c/code\u003e\u003c/a\u003e 10.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/45a2b11ec254a2e5620de66e248adcb33d16e669\"\u003e\u003ccode\u003e45a2b11\u003c/code\u003e\u003c/a\u003e Validate the byte arrays Address6 is given (\u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/issues/217\"\u003e#217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/bac8810b3935cab123316a4bc5ebaa22db140299\"\u003e\u003ccode\u003ebac8810\u003c/code\u003e\u003c/a\u003e Keep the package loadable on node 12, and enforce it (\u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/9b3d8488d15e6bfe5f5503867b088ce056723e08\"\u003e\u003ccode\u003e9b3d848\u003c/code\u003e\u003c/a\u003e Add a security policy and a README section on security posture\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/e84a7b381d02cb97ed114023e44133efae151254\"\u003e\u003ccode\u003ee84a7b3\u003c/code\u003e\u003c/a\u003e Order the README API reference Address4, Address6, AddressError\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/015160b85ee60b39548219817a5de3c4e828a6d6\"\u003e\u003ccode\u003e015160b\u003c/code\u003e\u003c/a\u003e Collapse each class in the README API reference\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/34061a897d526b7a063c3605402cd30a8363a035\"\u003e\u003ccode\u003e34061a8\u003c/code\u003e\u003c/a\u003e Pin checkout and setup-node to commits in the release job\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/c5fae5d9bdfe8ded7f4ca01a3d3ea8d97f8f1277\"\u003e\u003ccode\u003ec5fae5d\u003c/code\u003e\u003c/a\u003e Pin action-gh-release to a commit and move it to 3.0.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/e0ef0484193218b0d28cfbb53795bc44ddb3cc21\"\u003e\u003ccode\u003ee0ef048\u003c/code\u003e\u003c/a\u003e Replace CircleCI with GitHub Actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/5e3ceb779aee6ad3f33264e66225e8e7584ab612\"\u003e\u003ccode\u003e5e3ceb7\u003c/code\u003e\u003c/a\u003e Add GitHub Actions CI across Node 20, 22, 24 and 25 (\u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/issues/213\"\u003e#213\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.4.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for ip-address since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version adds \u003ccode\u003eprepare\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@angular/common` from 17.3.8 to 20.3.27\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/releases\"\u003e@​angular/common's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e20.3.27\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e\u003cimg src=\"https://img.shields.io/badge/5dbcd0ee16-fix-green\" alt=\"fix - 5dbcd0ee16\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003e\u003cimg src=\"https://img.shields.io/badge/db0d4a1a39-fix-green\" alt=\"fix - db0d4a1a39\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003cimg src=\"https://img.shields.io/badge/a64e2883e9-fix-green\" alt=\"fix - a64e2883e9\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e\u003cimg src=\"https://img.shields.io/badge/6f80cca0b8-fix-green\" alt=\"fix - 6f80cca0b8\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.26\u003c/h2\u003e\n\u003ch3\u003ecompiler-cli\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/406aaa31e6ac4d3c155f5ab76e315ccd8d0387fe\"\u003e\u003cimg src=\"https://img.shields.io/badge/406aaa31e6-fix-green\" alt=\"fix - 406aaa31e6\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate babel dependencies to latest v7\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/26831d0cbd7e692210ca0799a203a7a5a0e741cd\"\u003e\u003cimg src=\"https://img.shields.io/badge/26831d0cbd-fix-green\" alt=\"fix - 26831d0cbd\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eavoid caching missing locale data\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8eb7aea08b27c0f1bcdeec3171880a6fcf28aa9a\"\u003e\u003cimg src=\"https://img.shields.io/badge/8eb7aea08b-fix-green\" alt=\"fix - 8eb7aea08b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003ereject dynamic script host elements\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003cimg src=\"https://img.shields.io/badge/b963f61028-fix-green\" alt=\"fix - b963f61028\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eprevent caching of responses with Set-Cookie headers\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1fdf2341684a0f528d1d31005bd48d882c0a47d1\"\u003e\u003cimg src=\"https://img.shields.io/badge/1fdf234168-fix-green\" alt=\"fix - 1fdf234168\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/baa093ba68c1d5ca7c35c562568c6021eb409b4c\"\u003e\u003cimg src=\"https://img.shields.io/badge/baa093ba68-fix-green\" alt=\"fix - baa093ba68\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer policy in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.25\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003cimg src=\"https://img.shields.io/badge/9f443bc24c-fix-green\" alt=\"fix - 9f443bc24c\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003cimg src=\"https://img.shields.io/badge/566ad05f20-fix-green\" alt=\"fix - 566ad05f20\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003cimg src=\"https://img.shields.io/badge/1a62130a6b-fix-green\" alt=\"fix - 1a62130a6b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003cimg src=\"https://img.shields.io/badge/a68ec702a0-fix-green\" alt=\"fix - a68ec702a0\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003cimg src=\"https://img.shields.io/badge/768a349e6e-fix-green\" alt=\"fix - 768a349e6e\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/blob/main/CHANGELOG.md\"\u003e@​angular/common's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e20.3.27 (2026-07-29)\u003c/h1\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e5dbcd0ee16\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003edb0d4a1a39\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003ea64e2883e9\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e6f80cca0b8\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.8 (2026-07-22)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/c0368f227846024bb26d3628c59541e870bb36e4\"\u003ec0368f2278\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve crossorigin on image preloads\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8616ba9db6240f3fbf8b905342d07326e096302b\"\u003e8616ba9db6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure SVG animation attributeName is checked case-insensitively\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eforms\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d302c7ab833c0bd3bba951135e76e0c48273b3d7\"\u003ed302c7ab83\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure \u003ccode\u003epending\u003c/code\u003e status propagates to the root form in signal forms\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9d40f8aefef9dcd893db5d01bc58d3e65e1cb4c2\"\u003e9d40f8aefe\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eprevent transfer cache key collisions\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003emigrations\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/388daea2fc188aad3ab69fb81bd3f893ac3cd846\"\u003e388daea2fc\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003ecorrectly migrate ngClass with mixed space-separated keys\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/bb39cda6483de2edab2f8221459b0ed5b73ef221\"\u003ebb39cda648\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve NgClass import on partial migration\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.7 (2026-07-15)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/91e33aa1de47d250d8cde21047597e8df771f07d\"\u003e91e33aa1de\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eavoid prototype lookups in date format caches\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003ccode\u003ea64e288\u003c/code\u003e\u003c/a\u003e fix(http): distinguish repeated transfer cache params\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003ccode\u003eb963f61\u003c/code\u003e\u003c/a\u003e fix(http): prevent caching of responses with Set-Cookie headers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/06be29826741212ca00e21efb6abff653e4541b5\"\u003e\u003ccode\u003e06be298\u003c/code\u003e\u003c/a\u003e fix(http): preserve empty referrer option in HttpRequest\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003ccode\u003e9f443bc\u003c/code\u003e\u003c/a\u003e fix(common): Limits date format string length\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/fa940e1f4de75c33ccca50357d941be53a5a0950\"\u003e\u003ccode\u003efa940e1\u003c/code\u003e\u003c/a\u003e fix(http): Rejects non-HTTP(S) URLs in JSONP requests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003ccode\u003e1a62130\u003c/code\u003e\u003c/a\u003e fix(common): use cryptographically secure SHA-256 for transfer cache key gene...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003ccode\u003e566ad05\u003c/code\u003e\u003c/a\u003e fix(common): skip transfer cache for uncacheable HTTP traffic\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/e2ef1ce72ae084e01a76950c731052f4fa97fcdd\"\u003e\u003ccode\u003ee2ef1ce\u003c/code\u003e\u003c/a\u003e fix(http): skip transfer cache for fetch credentialed requests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/3d135ce59bbf7426825bc493bc681f266846ac79\"\u003e\u003ccode\u003e3d135ce\u003c/code\u003e\u003c/a\u003e fix(common): add upper bounds for digitsInfo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/39a4b4cc8e8d101a566a70658707bc9f53dd5883\"\u003e\u003ccode\u003e39a4b4c\u003c/code\u003e\u003c/a\u003e fix(common): sanitize placeholder\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/angular/angular/commits/v20.3.27/packages/common\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@angular/compiler` from 17.3.8 to 20.3.27\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/releases\"\u003e@​angular/compiler's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e20.3.27\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e\u003cimg src=\"https://img.shields.io/badge/5dbcd0ee16-fix-green\" alt=\"fix - 5dbcd0ee16\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003e\u003cimg src=\"https://img.shields.io/badge/db0d4a1a39-fix-green\" alt=\"fix - db0d4a1a39\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003cimg src=\"https://img.shields.io/badge/a64e2883e9-fix-green\" alt=\"fix - a64e2883e9\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e\u003cimg src=\"https://img.shields.io/badge/6f80cca0b8-fix-green\" alt=\"fix - 6f80cca0b8\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.26\u003c/h2\u003e\n\u003ch3\u003ecompiler-cli\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/406aaa31e6ac4d3c155f5ab76e315ccd8d0387fe\"\u003e\u003cimg src=\"https://img.shields.io/badge/406aaa31e6-fix-green\" alt=\"fix - 406aaa31e6\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate babel dependencies to latest v7\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/26831d0cbd7e692210ca0799a203a7a5a0e741cd\"\u003e\u003cimg src=\"https://img.shields.io/badge/26831d0cbd-fix-green\" alt=\"fix - 26831d0cbd\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eavoid caching missing locale data\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8eb7aea08b27c0f1bcdeec3171880a6fcf28aa9a\"\u003e\u003cimg src=\"https://img.shields.io/badge/8eb7aea08b-fix-green\" alt=\"fix - 8eb7aea08b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003ereject dynamic script host elements\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003cimg src=\"https://img.shields.io/badge/b963f61028-fix-green\" alt=\"fix - b963f61028\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eprevent caching of responses with Set-Cookie headers\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1fdf2341684a0f528d1d31005bd48d882c0a47d1\"\u003e\u003cimg src=\"https://img.shields.io/badge/1fdf234168-fix-green\" alt=\"fix - 1fdf234168\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/baa093ba68c1d5ca7c35c562568c6021eb409b4c\"\u003e\u003cimg src=\"https://img.shields.io/badge/baa093ba68-fix-green\" alt=\"fix - baa093ba68\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer policy in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.25\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003cimg src=\"https://img.shields.io/badge/9f443bc24c-fix-green\" alt=\"fix - 9f443bc24c\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003cimg src=\"https://img.shields.io/badge/566ad05f20-fix-green\" alt=\"fix - 566ad05f20\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003cimg src=\"https://img.shields.io/badge/1a62130a6b-fix-green\" alt=\"fix - 1a62130a6b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003cimg src=\"https://img.shields.io/badge/a68ec702a0-fix-green\" alt=\"fix - a68ec702a0\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003cimg src=\"https://img.shields.io/badge/768a349e6e-fix-green\" alt=\"fix - 768a349e6e\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/blob/main/CHANGELOG.md\"\u003e@​angular/compiler's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e20.3.27 (2026-07-29)\u003c/h1\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e5dbcd0ee16\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003edb0d4a1a39\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003ea64e2883e9\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e6f80cca0b8\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.8 (2026-07-22)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/c0368f227846024bb26d3628c59541e870bb36e4\"\u003ec0368f2278\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve crossorigin on image preloads\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8616ba9db6240f3fbf8b905342d07326e096302b\"\u003e8616ba9db6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure SVG animation attributeName is checked case-insensitively\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eforms\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d302c7ab833c0bd3bba951135e76e0c48273b3d7\"\u003ed302c7ab83\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eensure \u003ccode\u003epending\u003c/code\u003e status propagates to the root form in signal forms\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9d40f8aefef9dcd893db5d01bc58d3e65e1cb4c2\"\u003e9d40f8aefe\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eprevent transfer cache key collisions\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003emigrations\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/388daea2fc188aad3ab69fb81bd3f893ac3cd846\"\u003e388daea2fc\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003ecorrectly migrate ngClass with mixed space-separated keys\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/bb39cda6483de2edab2f8221459b0ed5b73ef221\"\u003ebb39cda648\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve NgClass import on partial migration\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.7 (2026-07-15)\u003c/h1\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/91e33aa1de47d250d8cde21047597e8df771f07d\"\u003e91e33aa1de\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eavoid prototype lookups in date format caches\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003e\u003ccode\u003edb0d4a1\u003c/code\u003e\u003c/a\u003e fix(compiler): restrict possible event handler check to property names longer...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e\u003ccode\u003e5dbcd0e\u003c/code\u003e\u003c/a\u003e fix(compiler): disallow i18n event attributes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003ccode\u003ea68ec70\u003c/code\u003e\u003c/a\u003e fix(compiler): sanitize two-way properties\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/d40acc6431997b304ec54c951e55d2e52ed6f6dc\"\u003e\u003ccode\u003ed40acc6\u003c/code\u003e\u003c/a\u003e fix(compiler): prevent namespaced SVG \u0026lt;style\u0026gt; elements from being stripped\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/7ae6381a4845ad4b13a7a5574c5433b077c93c5c\"\u003e\u003ccode\u003e7ae6381\u003c/code\u003e\u003c/a\u003e test(compiler-cli): align ngtsc sanitization expectations with modern DOM sch...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/36200bd81a3420d8222dfe10767437c383a20fe8\"\u003e\u003ccode\u003e36200bd\u003c/code\u003e\u003c/a\u003e test(core): update spec files to match 20.3.x limits and actual contexts (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/compiler/issues/68\"\u003e#68\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/823b37f0468f7c8b38637ce93e26fc8db791b282\"\u003e\u003ccode\u003e823b37f\u003c/code\u003e\u003c/a\u003e test(compiler): remove obsolete schema_extractor import (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/compiler/issues/68926\"\u003e#68926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/e345a58069ede97250af449f5b7e9b94f828d30c\"\u003e\u003ccode\u003ee345a58\u003c/code\u003e\u003c/a\u003e fix(core): normalize tag names in runtime i18n attribute security context loo...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/8f35b182b1479ed80d652f185c2c3ee5a82ea34c\"\u003e\u003ccode\u003e8f35b18\u003c/code\u003e\u003c/a\u003e fix(compiler): normalize tag names with custom namespaces in DomElementSchema...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/64a89e917a0794a3d74713bdb4c9c63d703b317b\"\u003e\u003ccode\u003e64a89e9\u003c/code\u003e\u003c/a\u003e fix(compiler): sanitize dynamic href and xlink:href bindings on SVG a element...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/angular/angular/commits/v20.3.27/packages/compiler\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@angular/core` from 17.3.8 to 20.3.25\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/releases\"\u003e@​angular/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e20.3.25\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003cimg src=\"https://img.shields.io/badge/9f443bc24c-fix-green\" alt=\"fix - 9f443bc24c\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003cimg src=\"https://img.shields.io/badge/566ad05f20-fix-green\" alt=\"fix - 566ad05f20\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003cimg src=\"https://img.shields.io/badge/1a62130a6b-fix-green\" alt=\"fix - 1a62130a6b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003cimg src=\"https://img.shields.io/badge/a68ec702a0-fix-green\" alt=\"fix - a68ec702a0\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003cimg src=\"https://img.shields.io/badge/768a349e6e-fix-green\" alt=\"fix - 768a349e6e\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/ca48b4728d5f6770be63a08f64a6432207ad54c0\"\u003e\u003cimg src=\"https://img.shields.io/badge/ca48b4728d-fix-green\" alt=\"fix - ca48b4728d\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003evalidate lowercase SVG animation attribute names (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/69270\"\u003e#69270\u003c/a\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/06be29826741212ca00e21efb6abff653e4541b5\"\u003e\u003cimg src=\"https://img.shields.io/badge/06be298267-fix-green\" alt=\"fix - 06be298267\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve empty referrer option in HttpRequest\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/fa940e1f4de75c33ccca50357d941be53a5a0950\"\u003e\u003cimg src=\"https://img.shields.io/badge/fa940e1f4d-fix-green\" alt=\"fix - fa940e1f4d\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eRejects non-HTTP(S) URLs in JSONP requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/e2ef1ce72ae084e01a76950c731052f4fa97fcdd\"\u003e\u003cimg src=\"https://img.shields.io/badge/e2ef1ce72a-fix-green\" alt=\"fix - e2ef1ce72a\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for fetch credentialed requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/49368c185907edb48467074c56e305abbfa3544a\"\u003e\u003cimg src=\"https://img.shields.io/badge/49368c1859-fix-green\" alt=\"fix - 49368c1859\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden platform location origin validation during SSR\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d55c94ad811a15c9c255164a0d66892c645f602e\"\u003e\u003cimg src=\"https://img.shields.io/badge/d55c94ad81-refactor-yellow\" alt=\"refactor - d55c94ad81\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edeprecate ServerXhr (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/69256\"\u003e#69256\u003c/a\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d65a5f457b1afd6bdd4d952d3f213c6aa1aabcbc\"\u003e\u003cimg src=\"https://img.shields.io/badge/d65a5f457b-fix-green\" alt=\"fix - d65a5f457b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eStrips sensitive headers on cross-origin redirects\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003eDeprecations\u003c/h2\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eXHR support in \u003ccode\u003e@angular/platform-server\u003c/code\u003e is deprecated. Use standard \u003ccode\u003efetch\u003c/code\u003e APIs instead.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e20.3.24\u003c/h2\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6ca433e56bcf74fdb6ad01d3afdf59628fba69b6\"\u003e\u003cimg src=\"https://img.shields.io/badge/6ca433e56b-fix-green\" alt=\"fix - 6ca433e56b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003ethrow on suspicious URLs and restrict protocol-relative URLs\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8680b5152fe58ebde81e331b74ba806fc86514cc\"\u003e\u003cimg src=\"https://img.shields.io/badge/8680b5152f-fix-green\" alt=\"fix - 8680b5152f\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.23\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d40acc6431997b304ec54c951e55d2e52ed6f6dc\"\u003e\u003cimg src=\"https://img.shields.io/badge/d40acc6431-fix-green\" alt=\"fix - d40acc6431\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eprevent namespaced SVG \u003c!-- raw HTML omitted --\u003e elements from being stripped\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.22\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/blob/main/CHANGELOG.md\"\u003e@​angular/core's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e20.3.25 (2026-06-10)\u003c/h1\u003e\n\u003ch2\u003eDeprecations\u003c/h2\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eXHR support in \u003ccode\u003e@angular/platform-server\u003c/code\u003e is deprecated. Use standard \u003ccode\u003efetch\u003c/code\u003e APIs instead.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e9f443bc24c\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e566ad05f20\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e1a62130a6b\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003ea68ec702a0\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e768a349e6e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/ca48b4728d5f6770be63a08f64a6432207ad54c0\"\u003eca48b4728d\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003evalidate lowercase SVG animation attribute names (\u003ca href=\"https://redirect.github.com/angular/angular/pull/69270\"\u003e#69270\u003c/a\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/06be29826741212ca00e21efb6abff653e4541b5\"\u003e06be298267\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003epreserve empty referrer option in HttpRequest\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/fa940e1f4de75c33ccca50357d941be53a5a0950\"\u003efa940e1f4d\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eRejects non-HTTP(S) URLs in JSONP requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/e2ef1ce72ae084e01a76950c731052f4fa97fcdd\"\u003ee2ef1ce72a\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for fetch credentialed requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/49368c185907edb48467074c56e305abbfa3544a\"\u003e49368c1859\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eharden platform location origin validation during SSR\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d55c94ad811a15c9c255164a0d66892c645f602e\"\u003ed55c94ad81\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003erefactor\u003c/td\u003e\n\u003ctd\u003edeprecate ServerXhr (\u003ca href=\"https://redirect.github.com/angular/angular/pull/69256\"\u003e#69256\u003c/a\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/d65a5f457b1afd6bdd4d952d3f213c6aa1aabcbc\"\u003ed65a5f457b\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003eStrips sensitive headers on cross-origin redirects\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch1\u003e22.0.0 (2026-06-03)\u003c/h1\u003e\n\u003cp\u003e\u003ca href=\"https://goo.gle/angular-v22-blog\"\u003eBlog post \u0026quot;Announcing Angular v22\u0026quot;\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eBreaking Changes\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThis change will trigger the \u003ccode\u003enullishCoalescingNotNullable\u003c/code\u003e and \u003ccode\u003eoptionalChainNotNullable\u003c/code\u003e diagnostics on exisiting projects.\nYou might want to disable those 2 diagnotiscs in your \u003ccode\u003etsconfig\u003c/code\u003e temporarily.\u003c/li\u003e\n\u003cli\u003edata prefixed attribute no-longer bind inputs nor outputs.\u003c/li\u003e\n\u003cli\u003eThe compiler will throw when there a when inputs, outputs or model are binding to the same input/outputs.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ein\u003c/code\u003e variables will throw in template expressions.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ecompiler-cli\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/ca48b4728d5f6770be63a08f64a6432207ad54c0\"\u003e\u003ccode\u003eca48b47\u003c/code\u003e\u003c/a\u003e fix(core): validate lowercase SVG animation attribute names (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/69270\"\u003e#69270\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003ccode\u003e1a62130\u003c/code\u003e\u003c/a\u003e fix(common): use cryptographically secure SHA-256 for transfer cache key gene...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/49368c185907edb48467074c56e305abbfa3544a\"\u003e\u003ccode\u003e49368c1\u003c/code\u003e\u003c/a\u003e fix(platform-server): harden platform location origin validation during SSR\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003ccode\u003e566ad05\u003c/code\u003e\u003c/a\u003e fix(common): skip transfer cache for uncacheable HTTP traffic\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003ccode\u003e768a349\u003c/code\u003e\u003c/a\u003e fix(core): harden TransferState restoration against DOM clobbering\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/7ae6381a4845ad4b13a7a5574c5433b077c93c5c\"\u003e\u003ccode\u003e7ae6381\u003c/code\u003e\u003c/a\u003e test(compiler-cli): align ngtsc sanitization expectations with modern DOM sch...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/65954092483a88fc69cccd3b4c56d96450ac2fe8\"\u003e\u003ccode\u003e6595409\u003c/code\u003e\u003c/a\u003e test(core): update golden symbols and host bindings sanitization spec (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/68926\"\u003e#68926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/d86e4e7b2ad0e667aeb0f8ed053e2cb2bd154b81\"\u003e\u003ccode\u003ed86e4e7\u003c/code\u003e\u003c/a\u003e fix(core): reject script element as a dynamic component host (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/68926\"\u003e#68926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/b8f1f7276514e258e8c815ec5c7d9b8826ecd372\"\u003e\u003ccode\u003eb8f1f72\u003c/code\u003e\u003c/a\u003e test(core): remove obsolete blockquote cite host binding tests (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/68926\"\u003e#68926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/angular/angular/commit/36200bd81a3420d8222dfe10767437c383a20fe8\"\u003e\u003ccode\u003e36200bd\u003c/code\u003e\u003c/a\u003e test(core): update spec files to match 20.3.x limits and actual contexts (\u003ca href=\"https://github.com/angular/angular/tree/HEAD/packages/core/issues/68\"\u003e#68\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/angular/angular/commits/v20.3.25/packages/core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@angular/common` from 17.3.8 to 20.3.27\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/releases\"\u003e@​angular/common's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e20.3.27\u003c/h2\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e\u003cimg src=\"https://img.shields.io/badge/5dbcd0ee16-fix-green\" alt=\"fix - 5dbcd0ee16\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edisallow i18n event attributes\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/db0d4a1a39db2dc0773f3bc9d7a0e1cfc59fa251\"\u003e\u003cimg src=\"https://img.shields.io/badge/db0d4a1a39-fix-green\" alt=\"fix - db0d4a1a39\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003erestrict possible event handler check to property names longer than 2 characters\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b\"\u003e\u003cimg src=\"https://img.shields.io/badge/a64e2883e9-fix-green\" alt=\"fix - a64e2883e9\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003edistinguish repeated transfer cache params\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eplatform-server\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/6f80cca0b8af23b37f24fb8ee0229b6901d01df2\"\u003e\u003cimg src=\"https://img.shields.io/badge/6f80cca0b8-fix-green\" alt=\"fix - 6f80cca0b8\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate domino to latest version\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.26\u003c/h2\u003e\n\u003ch3\u003ecompiler-cli\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/406aaa31e6ac4d3c155f5ab76e315ccd8d0387fe\"\u003e\u003cimg src=\"https://img.shields.io/badge/406aaa31e6-fix-green\" alt=\"fix - 406aaa31e6\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eupdate babel dependencies to latest v7\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/26831d0cbd7e692210ca0799a203a7a5a0e741cd\"\u003e\u003cimg src=\"https://img.shields.io/badge/26831d0cbd-fix-green\" alt=\"fix - 26831d0cbd\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eavoid caching missing locale data\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/8eb7aea08b27c0f1bcdeec3171880a6fcf28aa9a\"\u003e\u003cimg src=\"https://img.shields.io/badge/8eb7aea08b-fix-green\" alt=\"fix - 8eb7aea08b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003ereject dynamic script host elements\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ehttp\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/b963f61028c747843db48c6fb82965123365fd4a\"\u003e\u003cimg src=\"https://img.shields.io/badge/b963f61028-fix-green\" alt=\"fix - b963f61028\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eprevent caching of responses with Set-Cookie headers\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003eservice-worker\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1fdf2341684a0f528d1d31005bd48d882c0a47d1\"\u003e\u003cimg src=\"https://img.shields.io/badge/1fdf234168-fix-green\" alt=\"fix - 1fdf234168\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/baa093ba68c1d5ca7c35c562568c6021eb409b4c\"\u003e\u003cimg src=\"https://img.shields.io/badge/baa093ba68-fix-green\" alt=\"fix - baa093ba68\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003epreserve referrer policy in asset requests\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e20.3.25\u003c/h2\u003e\n\u003ch3\u003ecommon\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/9f443bc24c79dca998c9434d1e235dc19dc29bba\"\u003e\u003cimg src=\"https://img.shields.io/badge/9f443bc24c-fix-green\" alt=\"fix - 9f443bc24c\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eLimits date format string length\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/566ad05f20732c38855353c3e73771ef9a34dadc\"\u003e\u003cimg src=\"https://img.shields.io/badge/566ad05f20-fix-green\" alt=\"fix - 566ad05f20\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eskip transfer cache for uncacheable HTTP traffic\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/1a62130a6bb313e4441f005e480768a360c71be5\"\u003e\u003cimg src=\"https://img.shields.io/badge/1a62130a6b-fix-green\" alt=\"fix - 1a62130a6b\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003euse cryptographically secure SHA-256 for transfer cache key generation\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/a68ec702a056a2706a152fce29081241fd276f12\"\u003e\u003cimg src=\"https://img.shields.io/badge/a68ec702a0-fix-green\" alt=\"fix - a68ec702a0\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003esanitize two-way properties\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3\u003ecore\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/768a349e6e54ff16deba4c1bfe12be9d0f55f443\"\u003e\u003cimg src=\"https://img.shields.io/badge/768a349e6e-fix-green\" alt=\"fix - 768a349e6e\" /\u003e\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eharden TransferState restoration against DOM clobbering\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/angular/angular/blob/main/CHANGELOG.md\"\u003e@​angular/common's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e20.3.27 (2026-07-29)\u003c/h1\u003e\n\u003ch3\u003ecompiler\u003c/h3\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCommit\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/angular/angular/commit/5dbcd0ee16011369bec00e10e22cbcae6ebabd7a\"\u003e5dbcd0ee16\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003efix\u003c/td\u003e\n\u003ctd\u003edisallow...\n\n_Description has been truncated_\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nUpdates dependencies across examples and lockfiles to pick up security fixes and keep framework templates current. Highlights: `postcss` 8.5.23, Angular examples to v20.3.x, `nuxt` 3.21.10, `next` 16.3.0, plus security patches in `fast-uri` and `undici`.\n\n- **Dependencies**\n  - `postcss` → 8.5.23 (security hardening around source maps)\n  - Angular examples: `@angular/common`/`compiler` → 20.3.27, `@angular/core` → 20.3.25\n  - Nuxt example: `nuxt` → 3.21.10\n  - Next examples: `next` → 16.3.0\n  - Fixtures/tests: `fast-uri` → 3.1.5 (security), `undici` → 6.28.0 (security), `ip-address` → 10.4.0, `hono` → 4.12.34\n\n- **Migration**\n  - Angular examples target v20; align local CLI/Node if you run them (e.g., `ng` v20, Node 18+).\n  - If your PostCSS setup reads previous source maps, ensure `from` is set or adjust `unsafeMap` as needed.\n\n\u003csup\u003eWritten for commit e2bb3a2019a5cebaff76e871e24f4e18a2527921. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/Dev-moe-kyawaung/turborepo/pull/56?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/Dev-moe-kyawaung/turborepo/pull/56","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Dev-moe-kyawaung%2Fturborepo/issues/56","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/56/packages"}},{"old_version":"7.9.0","new_version":"7.29.0","update_type":"minor","path":null,"pr_created_at":"2026-08-07T14:31:45.000Z","version_change":"7.9.0 → 7.29.0","issue":{"uuid":"5091128241","node_id":"PR_kwDOPUe_o878FSDH","number":36,"state":"open","title":"Bump the npm_and_yarn group across 19 directories with 17 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-08-07T14:31:45.000Z","updated_at":"2026-08-07T14:33:30.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"npm_and_yarn","update_count":17,"packages":[{"name":"uuid","old_version":"8.3.2","new_version":"removed","repository_url":"https://github.com/uuidjs/uuid"},{"name":"@tootallnate/once","old_version":"3.0.0","new_version":"3.0.1","repository_url":"https://github.com/TooTallNate/once"},{"name":"brace-expansion","old_version":"1.1.12","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"ws","old_version":"7.5.10","new_version":"7.5.13","repository_url":"https://github.com/websockets/ws"},{"name":"ip-address","old_version":"9.0.5","new_version":"10.4.0","repository_url":"https://github.com/beaugunderson/ip-address"},{"name":"js-yaml","old_version":"4.1.0","new_version":"4.3.1","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"linkify-it","old_version":"5.0.0","new_version":"5.0.2","repository_url":"https://github.com/markdown-it/linkify-it"},{"name":"markdown-it","old_version":"14.1.0","new_version":"14.3.0","repository_url":"https://github.com/markdown-it/markdown-it"},{"name":"morgan","old_version":"1.10.0","new_version":"1.11.0","repository_url":"https://github.com/expressjs/morgan"},{"name":"shell-quote","old_version":"1.7.3","new_version":"1.10.0","repository_url":"https://github.com/ljharb/shell-quote"},{"name":"undici","old_version":"7.9.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 11 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [uuid](https://github.com/uuidjs/uuid) | `8.3.2` | `removed` |\n| [@tootallnate/once](https://github.com/TooTallNate/once) | `3.0.0` | `3.0.1` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.12` | `1.1.18` |\n| [ws](https://github.com/websockets/ws) | `7.5.10` | `7.5.13` |\n| [ip-address](https://github.com/beaugunderson/ip-address) | `9.0.5` | `10.4.0` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.0` | `4.3.1` |\n| [linkify-it](https://github.com/markdown-it/linkify-it) | `5.0.0` | `5.0.2` |\n| [markdown-it](https://github.com/markdown-it/markdown-it) | `14.1.0` | `14.3.0` |\n| [morgan](https://github.com/expressjs/morgan) | `1.10.0` | `1.11.0` |\n| [shell-quote](https://github.com/ljharb/shell-quote) | `1.7.3` | `1.10.0` |\n| [undici](https://github.com/nodejs/undici) | `7.9.0` | `7.29.0` |\n\nBumps the npm_and_yarn group with 4 updates in the /build directory: [uuid](https://github.com/uuidjs/uuid), [brace-expansion](https://github.com/juliangruber/brace-expansion), [linkify-it](https://github.com/markdown-it/linkify-it) and [tmp](https://github.com/raszi/node-tmp).\nBumps the npm_and_yarn group with 3 updates in the /build/npm/gyp directory: [brace-expansion](https://github.com/juliangruber/brace-expansion), [tar](https://github.com/isaacs/node-tar) and [ip-address](https://github.com/beaugunderson/ip-address).\nBumps the npm_and_yarn group with 1 update in the /extensions/css-language-features directory: [brace-expansion](https://github.com/juliangruber/brace-expansion).\nBumps the npm_and_yarn group with 2 updates in the /extensions/extension-editing directory: [linkify-it](https://github.com/markdown-it/linkify-it) and [markdown-it](https://github.com/markdown-it/markdown-it).\nBumps the npm_and_yarn group with 2 updates in the /extensions/github-authentication directory: [form-data](https://github.com/form-data/form-data) and [@nevware21/ts-utils](https://github.com/nevware21/ts-utils).\nBumps the npm_and_yarn group with 2 updates in the /extensions/html-language-features directory: [brace-expansion](https://github.com/juliangruber/brace-expansion) and [@nevware21/ts-utils](https://github.com/nevware21/ts-utils).\nBumps the npm_and_yarn group with 2 updates in the /extensions/json-language-features directory: [brace-expansion](https://github.com/juliangruber/brace-expansion) and [@nevware21/ts-utils](https://github.com/nevware21/ts-utils).\nBumps the npm_and_yarn group with 5 updates in the /extensions/markdown-language-features directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.11` | `1.1.18` |\n| [linkify-it](https://github.com/markdown-it/linkify-it) | `3.0.3` | `6.1.0` |\n| [markdown-it](https://github.com/markdown-it/markdown-it) | `12.3.2` | `15.0.0` |\n| [@nevware21/ts-utils](https://github.com/nevware21/ts-utils) | `0.11.6` | `0.16.0` |\n| [dompurify](https://github.com/cure53/DOMPurify) | `3.2.4` | `3.4.12` |\n\nBumps the npm_and_yarn group with 1 update in the /extensions/merge-conflict directory: [@nevware21/ts-utils](https://github.com/nevware21/ts-utils).\nBumps the npm_and_yarn group with 3 updates in the /extensions/microsoft-authentication directory: [uuid](https://github.com/uuidjs/uuid), [form-data](https://github.com/form-data/form-data) and [@nevware21/ts-utils](https://github.com/nevware21/ts-utils).\nBumps the npm_and_yarn group with 3 updates in the /extensions/notebook-renderers directory: [@tootallnate/once](https://github.com/TooTallNate/once), [form-data](https://github.com/form-data/form-data) and [ws](https://github.com/websockets/ws).\nBumps the npm_and_yarn group with 2 updates in the /extensions/npm directory: [brace-expansion](https://github.com/juliangruber/brace-expansion) and [js-yaml](https://github.com/nodeca/js-yaml).\nBumps the npm_and_yarn group with 1 update in the /extensions/simple-browser directory: [@nevware21/ts-utils](https://github.com/nevware21/ts-utils).\nBumps the npm_and_yarn group with 1 update in the /extensions/typescript-language-features directory: [@nevware21/ts-utils](https://github.com/nevware21/ts-utils).\nBumps the npm_and_yarn group with 4 updates in the /remote directory: [uuid](https://github.com/uuidjs/uuid), [@tootallnate/once](https://github.com/TooTallNate/once), [ip-address](https://github.com/beaugunderson/ip-address) and [undici](https://github.com/nodejs/undici).\nBumps the npm_and_yarn group with 3 updates in the /test/automation directory: [brace-expansion](https://github.com/juliangruber/brace-expansion), [shell-quote](https://github.com/ljharb/shell-quote) and [tmp](https://github.com/raszi/node-tmp).\nBumps the npm_and_yarn group with 2 updates in the /test/integration/browser directory: [brace-expansion](https://github.com/juliangruber/brace-expansion) and [tmp](https://github.com/raszi/node-tmp).\nBumps the npm_and_yarn group with 3 updates in the /test/smoke directory: [brace-expansion](https://github.com/juliangruber/brace-expansion), [form-data](https://github.com/form-data/form-data) and [shell-quote](https://github.com/ljharb/shell-quote).\n\nRemoves `uuid`\n\nUpdates `@tootallnate/once` from 3.0.0 to 3.0.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/TooTallNate/once/releases\"\u003e@​tootallnate/once's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.0.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e28dbc5d: Fix promise hang when \u003ccode\u003eAbortSignal\u003c/code\u003e is aborted\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/TooTallNate/once/blob/master/CHANGELOG.md\"\u003e@​tootallnate/once's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.0.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e28dbc5d: Fix promise hang when \u003ccode\u003eAbortSignal\u003c/code\u003e is aborted\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/b31c7623e18b128325a05da02aa0832ee289b893\"\u003e\u003ccode\u003eb31c762\u003c/code\u003e\u003c/a\u003e Fix publish?\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/d2f7407721c023426c1af0712dbd71a3ca91d899\"\u003e\u003ccode\u003ed2f7407\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://redirect.github.com/TooTallNate/once/issues/9\"\u003e#9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/081645cb260aa86a55e5bffad2f1b52155cee8ea\"\u003e\u003ccode\u003e081645c\u003c/code\u003e\u003c/a\u003e Fix release script\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/f01fa45d958113c60f54bf7f83e460741d811a47\"\u003e\u003ccode\u003ef01fa45\u003c/code\u003e\u003c/a\u003e Fix Release job\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/28dbc5d7f9342ddfb6014ca5f3dc4206048db9cb\"\u003e\u003ccode\u003e28dbc5d\u003c/code\u003e\u003c/a\u003e Add Changesets\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/e66503b7f028a9fe7d22e2547d17cea71be05937\"\u003e\u003ccode\u003ee66503b\u003c/code\u003e\u003c/a\u003e Use pnpm in CI\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/6ec8b43f617a6feeb78ab98a4eb999123b664d2b\"\u003e\u003ccode\u003e6ec8b43\u003c/code\u003e\u003c/a\u003e Fix CI\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/b9f43cc5259bee2952d91ad3cdbd201a82df448a\"\u003e\u003ccode\u003eb9f43cc\u003c/code\u003e\u003c/a\u003e Fix promise hang when \u003ccode\u003eAbortSignal\u003c/code\u003e is aborted\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TooTallNate/once/commit/a8c9dc3b7a241f992ebcde5b6b76ad5f97ce99af\"\u003e\u003ccode\u003ea8c9dc3\u003c/code\u003e\u003c/a\u003e Add pnpm-lock.yaml file\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/TooTallNate/once/compare/3.0.0...v3.0.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​tootallnate/once\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.12 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3\"\u003e\u003ccode\u003e10c05fc\u003c/code\u003e\u003c/a\u003e 1.1.14\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ws` from 7.5.10 to 7.5.13\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/websockets/ws/releases\"\u003ews's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e7.5.13\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug introduced in version 7.5.12 that prevented the fragment counter\nfrom resetting (18bcb11a).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.5.12\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eBackported a2f4e7c0 and f197ac65 to the v7.x release line (fb8a1935, deec2114).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.5.11\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eBackported 2b2abd45 to the 7.x release line (e14c4586).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/16808010390d5fb4b612a3a92e8803b1971e00c1\"\u003e\u003ccode\u003e1680801\u003c/code\u003e\u003c/a\u003e [dist] 7.5.13\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/18bcb11afa5ecebb7b1e33fc359acd5b7c7fcc9b\"\u003e\u003ccode\u003e18bcb11\u003c/code\u003e\u003c/a\u003e [fix] Reset the fragment counter when the message is complete\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/98fce81f1af6e2198fdd81c2f9241b897cea3885\"\u003e\u003ccode\u003e98fce81\u003c/code\u003e\u003c/a\u003e [dist] 7.5.12\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/deec2114f0d0fbd66e52e9229a755e05027f6724\"\u003e\u003ccode\u003edeec211\u003c/code\u003e\u003c/a\u003e [fix] Lower default values of \u003ccode\u003emaxBufferedChunks\u003c/code\u003e and \u003ccode\u003emaxFragments\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/fb8a1935f1ed7697cf283de69146f09d7e6bea63\"\u003e\u003ccode\u003efb8a193\u003c/code\u003e\u003c/a\u003e [fix] Count empty fragments toward the limit (\u003ca href=\"https://redirect.github.com/websockets/ws/issues/2329\"\u003e#2329\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/fd36cd864fcdf62a08273a99e19a7d975401fee8\"\u003e\u003ccode\u003efd36cd8\u003c/code\u003e\u003c/a\u003e [dist] 7.5.11\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/e14c45861deca0cef60dec0f9109b694abebdf52\"\u003e\u003ccode\u003ee14c458\u003c/code\u003e\u003c/a\u003e [security] Limit retained message parts\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/websockets/ws/compare/7.5.10...7.5.13\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ip-address` from 9.0.5 to 10.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/beaugunderson/ip-address/releases\"\u003eip-address's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev10.4.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd GitHub Actions CI by \u003ca href=\"https://github.com/beaugunderson\"\u003e\u003ccode\u003e@​beaugunderson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/pull/213\"\u003ebeaugunderson/ip-address#213\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eKeep the package loadable on node 12, and enforce it by \u003ca href=\"https://github.com/beaugunderson\"\u003e\u003ccode\u003e@​beaugunderson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/pull/216\"\u003ebeaugunderson/ip-address#216\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eValidate the byte arrays Address6 is given by \u003ca href=\"https://github.com/beaugunderson\"\u003e\u003ccode\u003e@​beaugunderson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/pull/217\"\u003ebeaugunderson/ip-address#217\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.3.1...v10.4.0\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.3.1...v10.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.3.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.3.0...v10.3.1\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.3.0...v10.3.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.3.0\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.2.2...v10.3.0\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.2.2...v10.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.2.2\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.2.1...v10.2.2\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.2.1...v10.2.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev10.2.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.2.1\"\u003ehttps://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.2.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/fbb8db28f1559842b7191cab7d8ea6408ed82f7b\"\u003e\u003ccode\u003efbb8db2\u003c/code\u003e\u003c/a\u003e 10.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/45a2b11ec254a2e5620de66e248adcb33d16e669\"\u003e\u003ccode\u003e45a2b11\u003c/code\u003e\u003c/a\u003e Validate the byte arrays Address6 is given (\u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/issues/217\"\u003e#217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/bac8810b3935cab123316a4bc5ebaa22db140299\"\u003e\u003ccode\u003ebac8810\u003c/code\u003e\u003c/a\u003e Keep the package loadable on node 12, and enforce it (\u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/9b3d8488d15e6bfe5f5503867b088ce056723e08\"\u003e\u003ccode\u003e9b3d848\u003c/code\u003e\u003c/a\u003e Add a security policy and a README section on security posture\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/e84a7b381d02cb97ed114023e44133efae151254\"\u003e\u003ccode\u003ee84a7b3\u003c/code\u003e\u003c/a\u003e Order the README API reference Address4, Address6, AddressError\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/015160b85ee60b39548219817a5de3c4e828a6d6\"\u003e\u003ccode\u003e015160b\u003c/code\u003e\u003c/a\u003e Collapse each class in the README API reference\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/34061a897d526b7a063c3605402cd30a8363a035\"\u003e\u003ccode\u003e34061a8\u003c/code\u003e\u003c/a\u003e Pin checkout and setup-node to commits in the release job\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/c5fae5d9bdfe8ded7f4ca01a3d3ea8d97f8f1277\"\u003e\u003ccode\u003ec5fae5d\u003c/code\u003e\u003c/a\u003e Pin action-gh-release to a commit and move it to 3.0.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/e0ef0484193218b0d28cfbb53795bc44ddb3cc21\"\u003e\u003ccode\u003ee0ef048\u003c/code\u003e\u003c/a\u003e Replace CircleCI with GitHub Actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beaugunderson/ip-address/commit/5e3ceb779aee6ad3f33264e66225e8e7584ab612\"\u003e\u003ccode\u003e5e3ceb7\u003c/code\u003e\u003c/a\u003e Add GitHub Actions CI across Node 20, 22, 24 and 25 (\u003ca href=\"https://redirect.github.com/beaugunderson/ip-address/issues/213\"\u003e#213\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/beaugunderson/ip-address/compare/v9.0.5...v10.4.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for ip-address since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version adds \u003ccode\u003eprepare\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `js-yaml` from 4.1.0 to 4.3.1\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.3.1 - 2026-07-31\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Remove quadratic complexity from \u003ccode\u003e!!omap\u003c/code\u003e duplicate key detection.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.3.0 - 2026-06-27\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Added \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (10000) loader option to limit the total number of\nkeys processed by YAML merge (\u003ccode\u003e\u0026lt;\u0026lt;\u003c/code\u003e) across one \u003ccode\u003eload()\u003c/code\u003e / \u003ccode\u003eloadAll()\u003c/code\u003e call.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRestore umd builds back to es5.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRemoved\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e replaced with \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e for limiting YAML merge\nprocessing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[4.2.0] - 2026-06-01\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003edocs/safety.md\u003c/code\u003e with notes about processing untrusted YAML.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxDepth\u003c/code\u003e (100) loader option. Not a problem, but gives a better\nexception instead of RangeError on stack overflow.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e (20) loader option. Not a problem after \u003ccode\u003emerge\u003c/code\u003e fix,\nbut an additional restriction for safety.\u003c/li\u003e\n\u003cli\u003eAdded sourcemaps to \u003ccode\u003edist/\u003c/code\u003e builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStop resolving numbers with underscores as numeric scalars, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/627\"\u003e#627\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eSwitched dev toolchains to Vite / neostandard.\u003c/li\u003e\n\u003cli\u003eUpdated demo.\u003c/li\u003e\n\u003cli\u003eReorganized tests.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edist/\u003c/code\u003e files are no longer kept in the repository.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix parsing of properties on the first implicit block mapping key, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/62\"\u003e#62\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix trailing whitespace handling when folding flow scalar lines, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/307\"\u003e#307\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eReject top-level block scalars without content indentation, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/280\"\u003e#280\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eEnsure numbers survive round-trip, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/737\"\u003e#737\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix test coverage for issue \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/221\"\u003e#221\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix flow scalar trailing whitespace folding, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/307\"\u003e#307\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix digits in YAML named tag handles.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix potential DoS via quadratic complexity in merge - deduplicate repeated\nelements (makes sense for malformed files \u0026gt; 10K).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[3.14.2] - 2025-11-15\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/86e91b815b8794c3c73a179c1770871e37ec2df8\"\u003e\u003ccode\u003e86e91b8\u003c/code\u003e\u003c/a\u003e 4.3.1 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/c3cc4b0bb9ddb9af2dd9b61e0d56f5ce7983cd4a\"\u003e\u003ccode\u003ec3cc4b0\u003c/code\u003e\u003c/a\u003e Backport quadratic complexity fix for !!omap\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/33d05b5d29a8c21360f620f7e1c1706e24522eda\"\u003e\u003ccode\u003e33d05b5\u003c/code\u003e\u003c/a\u003e 4.3.0 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/663bfab6db2b4a146a9366fd685f069345be4ddb\"\u003e\u003ccode\u003e663bfab\u003c/code\u003e\u003c/a\u003e Drop demo publish, to not override new v5 one.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/1cb8c7b94bf75e15116869c1c0482dcb22785986\"\u003e\u003ccode\u003e1cb8c7b\u003c/code\u003e\u003c/a\u003e Add v4-legacy tag for publish\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/02f27afad532763263cd2b6be35c24ee8e1f6157\"\u003e\u003ccode\u003e02f27af\u003c/code\u003e\u003c/a\u003e Restore umd builds back to es5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/8be84edaf15e7c394fa3b813179d1bcc280e87fb\"\u003e\u003ccode\u003e8be84ed\u003c/code\u003e\u003c/a\u003e Fix es5 compatibility\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4\"\u003e\u003ccode\u003e59423c6\u003c/code\u003e\u003c/a\u003e Replace \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e option with \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (more robust). Ba...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/6842ef6a02df01ca7282ea01dc3c70787710c05d\"\u003e\u003ccode\u003e6842ef6\u003c/code\u003e\u003c/a\u003e doc polish\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/590dbabadd172b099c07654fab2eabec8c7a07b9\"\u003e\u003ccode\u003e590dbab\u003c/code\u003e\u003c/a\u003e 4.2.0 released\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/4.1.0...4.3.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `linkify-it` from 5.0.0 to 5.0.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md\"\u003elinkify-it's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.0.2 / 2026-07-02\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed DoS in \u003ccode\u003emailto:\u003c/code\u003e links (restrict user name to 64 chars).\u003c/li\u003e\n\u003cli\u003eRestricted user/pass part length in links.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e5.0.1 / 2026-05-23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed DoS in fuzzy links/emails search.\u003c/li\u003e\n\u003cli\u003eReworked search logic - check each pattern separate, use \u003ccode\u003eg\u003c/code\u003e regexes instead\nof slice.\u003c/li\u003e\n\u003cli\u003eRemoved internal cache - useless overcomplication.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/50a0c914f834b201cab25ff4faefd1f832b37332\"\u003e\u003ccode\u003e50a0c91\u003c/code\u003e\u003c/a\u003e 5.0.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/de3b88554b5e465d5fa19914e2a1801ebb3069ef\"\u003e\u003ccode\u003ede3b885\u003c/code\u003e\u003c/a\u003e Update package hooks\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/13effaaa4600d1fcff9f63c38fecdd601bfd83e7\"\u003e\u003ccode\u003e13effaa\u003c/code\u003e\u003c/a\u003e Add package lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/39d748dbfc77534e9be04d87cd9f57a13b9b4216\"\u003e\u003ccode\u003e39d748d\u003c/code\u003e\u003c/a\u003e Bump c8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/00ce8771ac0c3e6784dcacaa1625ca0fc1b62a12\"\u003e\u003ccode\u003e00ce877\u003c/code\u003e\u003c/a\u003e Drop tlds deps\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/ecde82341a1b2e349b03eb01f3e1d2cc105bcd7f\"\u003e\u003ccode\u003eecde823\u003c/code\u003e\u003c/a\u003e Update benchmark to mitata\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/23c62cdd14ef36e89c175c6726e2229e5b76e75f\"\u003e\u003ccode\u003e23c62cd\u003c/code\u003e\u003c/a\u003e Refactor demo / doc build and publish\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/fd63f3b4ab433ca3561304409b572eed465706cd\"\u003e\u003ccode\u003efd63f3b\u003c/code\u003e\u003c/a\u003e CI config update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/f4ea5afaa6a8e1109c44898158d4910b3fb128fb\"\u003e\u003ccode\u003ef4ea5af\u003c/code\u003e\u003c/a\u003e demo: update bootstrap \u0026amp; layout\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/1454fb645f00c33a05edbded18640d5078ba7710\"\u003e\u003ccode\u003e1454fb6\u003c/code\u003e\u003c/a\u003e lint: dim warnings\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/markdown-it/linkify-it/compare/5.0.0...5.0.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `markdown-it` from 14.1.0 to 14.3.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md\"\u003emarkdown-it's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[14.3.0] - 2026-07-02\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReworked build pipeline \u0026amp; tools.\u003c/li\u003e\n\u003cli\u003eAdded source maps.\u003c/li\u003e\n\u003cli\u003eBumped \u003ccode\u003elinkify-it\u003c/code\u003e to 5.0.2.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve backslash-space hard line breaks, matching CommonMark 6.7, \u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1185\"\u003e#1185\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[14.2.0] - 2026-05-24\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eisPunctCharCode\u003c/code\u003e to utilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDon't end HTML comment blocks on a blank line, \u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1155\"\u003e#1155\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eProperly recognize astral chars (surrogates) in delimiter scans for\nemphasis-like markers, \u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1072\"\u003e#1072\u003c/a\u003e. Big thanks to \u003ca href=\"https://github.com/tats-u\"\u003e\u003ccode\u003e@​tats-u\u003c/code\u003e\u003c/a\u003e for his global efforts\nwith improving CJK support.\u003c/li\u003e\n\u003cli\u003ePreserve unicode whitespaces when trimm headings/paragraphs, \u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1074\"\u003e#1074\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eMore strict entities decode to avoid false positives \u003ccode\u003e;\u003c/code\u003e, \u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1096\"\u003e#1096\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eRestore block parser state on fail in \u003ccode\u003elheading\u003c/code\u003e rule, \u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1131\"\u003e#1131\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed poor smartquotes perfomance on \u0026gt; 70k quotes in single block\u003c/li\u003e\n\u003cli\u003eBumped linkify-it to 5.0.1 with fixed potential perfomance issues.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[14.1.1] - 2026-01-11\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed regression from v13 in linkify inline rule. Specific patterns could\ncause high CPU use. Thanks to \u003ca href=\"https://github.com/ltduc147\"\u003e\u003ccode\u003e@​ltduc147\u003c/code\u003e\u003c/a\u003e for report.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/ff0ee084fc6b0d10fac049fa562bc2925b5cc723\"\u003e\u003ccode\u003eff0ee08\u003c/code\u003e\u003c/a\u003e 14.3.0 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/52e2749ab25aaf841bf74b50560929aa93b8e14d\"\u003e\u003ccode\u003e52e2749\u003c/code\u003e\u003c/a\u003e Bump linkify-it / vite deps\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/56c2404e6d3e78632ce7b37a95f289fc04330c76\"\u003e\u003ccode\u003e56c2404\u003c/code\u003e\u003c/a\u003e fix: keep backslash-space hard line break (CommonMark 6.7) (\u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1185\"\u003e#1185\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/0fbb18b23145158a39255f7476c781dbce320a16\"\u003e\u003ccode\u003e0fbb18b\u003c/code\u003e\u003c/a\u003e Bump vite from 8.0.14 to 8.0.16 (\u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1181\"\u003e#1181\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/83450e2bc3836ad9f68f652e5685031e9dce4897\"\u003e\u003ccode\u003e83450e2\u003c/code\u003e\u003c/a\u003e Rework benchmark deps and bump versions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/57a68632ce317593fe316b7131105b131691b90b\"\u003e\u003ccode\u003e57a6863\u003c/code\u003e\u003c/a\u003e benchmark =\u0026gt; tinybench\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/7608db19a5b14f84b47b34cced43c574b1abfd0c\"\u003e\u003ccode\u003e7608db1\u003c/code\u003e\u003c/a\u003e Update CI config\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/9d8eb42a72e0e576125733acc7ae6154e8f6cb5a\"\u003e\u003ccode\u003e9d8eb42\u003c/code\u003e\u003c/a\u003e Added package-lock and updated versions to latest possible\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/0aee70db5e8284c84201d39d64c2b14228fd280a\"\u003e\u003ccode\u003e0aee70d\u003c/code\u003e\u003c/a\u003e lint: enable \u003ccode\u003e@​stylistic/no-multi-spaces\u003c/code\u003e rule\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/markdown-it/commit/88789854dc44db99b7736fd4349487dfda0d4067\"\u003e\u003ccode\u003e8878985\u003c/code\u003e\u003c/a\u003e lint =\u0026gt; neostandard\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/markdown-it/markdown-it/compare/14.1.0...14.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `morgan` from 1.10.0 to 1.11.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/morgan/releases\"\u003emorgan's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.11.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: add :pid token by \u003ca href=\"https://github.com/ganesh3367\"\u003e\u003ccode\u003e@​ganesh3367\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/329\"\u003eexpressjs/morgan#329\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSecurity Fix:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEscape control characters in \u003ccode\u003e:remote-user\u003c/code\u003e token to prevent log injection\n\u003cul\u003e\n\u003cli\u003eFixes \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2026-5078\"\u003eCVE-2026-5078\u003c/a\u003e \u003ca href=\"https://github.com/expressjs/morgan/security/advisories/GHSA-4vj7-5mj6-jm8m\"\u003eGHSA-4vj7-5mj6-jm8m\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/inigomarquinez\"\u003e\u003ccode\u003e@​inigomarquinez\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/291\"\u003eexpressjs/morgan#291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jonchurch\"\u003e\u003ccode\u003e@​jonchurch\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/299\"\u003eexpressjs/morgan#299\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bjohansebas\"\u003e\u003ccode\u003e@​bjohansebas\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/301\"\u003eexpressjs/morgan#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/300\"\u003eexpressjs/morgan#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ctcpip\"\u003e\u003ccode\u003e@​ctcpip\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/319\"\u003eexpressjs/morgan#319\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ganesh3367\"\u003e\u003ccode\u003e@​ganesh3367\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/329\"\u003eexpressjs/morgan#329\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/morgan/compare/1.10.0...1.11.0\"\u003ehttps://github.com/expressjs/morgan/compare/1.10.0...1.11.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.10.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003erenaming simple to sample in readme by \u003ca href=\"https://github.com/ryhinchey\"\u003e\u003ccode\u003e@​ryhinchey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/237\"\u003eexpressjs/morgan#237\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eadding installation instructions to readme by \u003ca href=\"https://github.com/ryhinchey\"\u003e\u003ccode\u003e@​ryhinchey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/233\"\u003eexpressjs/morgan#233\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: add support for OSSF scorecard reporting by \u003ca href=\"https://github.com/inigomarquinez\"\u003e\u003ccode\u003e@​inigomarquinez\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/291\"\u003eexpressjs/morgan#291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: replace travis with github actions by \u003ca href=\"https://github.com/inigomarquinez\"\u003e\u003ccode\u003e@​inigomarquinez\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/290\"\u003eexpressjs/morgan#290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: add example output for log formats by \u003ca href=\"https://github.com/jonchurch\"\u003e\u003ccode\u003e@​jonchurch\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/299\"\u003eexpressjs/morgan#299\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: use ubuntu-latest by \u003ca href=\"https://github.com/bjohansebas\"\u003e\u003ccode\u003e@​bjohansebas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/301\"\u003eexpressjs/morgan#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: apply OSSF Scorecard security best practices by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/300\"\u003eexpressjs/morgan#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eremove --bail by \u003ca href=\"https://github.com/jonchurch\"\u003e\u003ccode\u003e@​jonchurch\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/314\"\u003eexpressjs/morgan#314\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e⬆️ bump on-headers by \u003ca href=\"https://github.com/ctcpip\"\u003e\u003ccode\u003e@​ctcpip\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/319\"\u003eexpressjs/morgan#319\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/inigomarquinez\"\u003e\u003ccode\u003e@​inigomarquinez\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/291\"\u003eexpressjs/morgan#291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jonchurch\"\u003e\u003ccode\u003e@​jonchurch\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/299\"\u003eexpressjs/morgan#299\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bjohansebas\"\u003e\u003ccode\u003e@​bjohansebas\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/301\"\u003eexpressjs/morgan#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/300\"\u003eexpressjs/morgan#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ctcpip\"\u003e\u003ccode\u003e@​ctcpip\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/morgan/pull/319\"\u003eexpressjs/morgan#319\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/morgan/compare/1.10.0...1.10.1\"\u003ehttps://github.com/expressjs/morgan/compare/1.10.0...1.10.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/morgan/blob/master/HISTORY.md\"\u003emorgan's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e1.11.0 / 2026-06-02\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003e:pid\u003c/code\u003e token\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSecurity Fix:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEscape control characters in \u003ccode\u003e:remote-user\u003c/code\u003e token to prevent log injection\n\u003cul\u003e\n\u003cli\u003eFixes \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2026-5078\"\u003eCVE-2026-5078\u003c/a\u003e \u003ca href=\"https://github.com/expressjs/morgan/security/advisories/GHSA-4vj7-5mj6-jm8m\"\u003eGHSA-4vj7-5mj6-jm8m\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.10.1 / 2025-07-17\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003edeps: on-headers@~1.1.0\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2025-7339\"\u003eCVE-2025-7339\u003c/a\u003e (\u003ca href=\"https://github.com/expressjs/on-headers/security/advisories/GHSA-76c9-3jph-rj3q\"\u003eGHSA-76c9-3jph-rj3q\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/e0e6f17574db56396f8e60ebb03bb7aaaeb9cc6f\"\u003e\u003ccode\u003ee0e6f17\u003c/code\u003e\u003c/a\u003e Release 1.11.0 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/350\"\u003e#350\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/b3f5d9bdb388690dfae9c06ab966328f49b7982b\"\u003e\u003ccode\u003eb3f5d9b\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/203c75852adadcc5e3a9ba23b0ef07a8e81c5af7\"\u003e\u003ccode\u003e203c758\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action from 4.32.4 to 4.35.2 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/346\"\u003e#346\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/002bc81f47a7641d86b7e16ee0f343e5eed81a6a\"\u003e\u003ccode\u003e002bc81\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/347\"\u003e#347\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/561b0d70bf4486245b311a02259d32ae45756331\"\u003e\u003ccode\u003e561b0d7\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/upload-artifact from 5.0.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/338\"\u003e#338\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/2db705ecf05eed5a2990da4be8731a1d7051692c\"\u003e\u003ccode\u003e2db705e\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action from 3.29.7 to 4.32.4 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/337\"\u003e#337\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/a373c5f25df88c7f31b4abb36306d7e025edcc8c\"\u003e\u003ccode\u003ea373c5f\u003c/code\u003e\u003c/a\u003e build(deps): bump ossf/scorecard-action from 2.3.1 to 2.4.3 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/327\"\u003e#327\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/c8e72fa73c7e54a00f0e28db1bc6edbeb83dbbc0\"\u003e\u003ccode\u003ec8e72fa\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/checkout from 4.1.1 to 6.0.1 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/324\"\u003e#324\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/023300e37da5e2a3394a50171d07a0bb6860eab5\"\u003e\u003ccode\u003e023300e\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/upload-artifact from 4.3.1 to 4.6.2 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/307\"\u003e#307\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/morgan/commit/9d8d6c099765b1d4722aadfb68dbf0a227ff8e64\"\u003e\u003ccode\u003e9d8d6c0\u003c/code\u003e\u003c/a\u003e build(deps): bump coverallsapp/github-action from 1.2.5 to 2.3.6 (\u003ca href=\"https://redirect.github.com/expressjs/morgan/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/expressjs/morgan/compare/1.10.0...1.11.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~ulisesgascon\"\u003eulisesgascon\u003c/a\u003e, a new releaser for morgan since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `shell-quote` from 1.7.3 to 1.10.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md\"\u003eshell-quote's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.9.0...v1.10.0\"\u003ev1.10.0\u003c/a\u003e - 2026-07-10\u003c/h2\u003e\n\u003ch3\u003eMerged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[New] \u003ccode\u003eparse\u003c/code\u003e: add opt-in \u003ccode\u003esplitUnquoted\u003c/code\u003e option for shell field-splitting of unquoted expansions \u003ca href=\"https://redirect.github.com/ljharb/shell-quote/pull/1\"\u003e\u003ccode\u003e[#1](https://github.com/ljharb/shell-quote/issues/1)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: match nested \u003ccode\u003e${...}\u003c/code\u003e braces so nested parameter expansion is consumed as one substitution \u003ca href=\"https://github.com/ljharb/shell-quote/commit/c0842c8a7a034066da2496a75e91cbe500ff736c\"\u003e\u003ccode\u003ec0842c8\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003eparse\u003c/code\u003e: pin single-quote literalness and unmatched-quote handling \u003ca href=\"https://github.com/ljharb/shell-quote/commit/a0d03e35c8ede24016502c4433b8f5d6b3100a62\"\u003e\u003ccode\u003ea0d03e3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] remove the space in js code fences so evalmd evaluates them \u003ca href=\"https://github.com/ljharb/shell-quote/commit/2116fa36aeea77fe8d561b0db46b1f9b26b8cf1b\"\u003e\u003ccode\u003e2116fa3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: pin conservative escaping of \u003ccode\u003e=\u003c/code\u003e, \u003ccode\u003e@\u003c/code\u003e, \u003ccode\u003e^\u003c/code\u003e, \u003ccode\u003e,\u003c/code\u003e, \u003ccode\u003e:\u003c/code\u003e, \u003ccode\u003e!\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/1c36f3ff77d26d200620c1027e5c271050120b8e\"\u003e\u003ccode\u003e1c36f3f\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] document that \u003ccode\u003equote\u003c/code\u003e outputs POSIX quoting, not \u003ccode\u003ecmd.exe\u003c/code\u003e/PowerShell \u003ca href=\"https://github.com/ljharb/shell-quote/commit/100e96e0ffadcca97d63dda15651c70b9f83507c\"\u003e\u003ccode\u003e100e96e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] document \u003ccode\u003eparse\u003c/code\u003e's supported parameter-expansion subset \u003ca href=\"https://github.com/ljharb/shell-quote/commit/e1c75cd6e4a3c60003792c7f2802587d328622cb\"\u003e\u003ccode\u003ee1c75cd\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: a backslash inside single quotes must not escape the closing quote \u003ca href=\"https://github.com/ljharb/shell-quote/commit/5d460a332b54b83153297fe7d1964330b28fa491\"\u003e\u003ccode\u003e5d460a3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] fix stale example outputs \u003ca href=\"https://github.com/ljharb/shell-quote/commit/2de86f5d44f44d3ac9df36413d8a05f3534cdec6\"\u003e\u003ccode\u003e2de86f5\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: pin that a backslash with whitespace is not doubled in single quotes (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/14\"\u003e#14\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/190e236bcf1d81caa8e40e8ea3bb11998575be71\"\u003e\u003ccode\u003e190e236\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] \u003ccode\u003equote\u003c/code\u003e: use output verbatim; do not re-quote it (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/1b364683b1e9e8d078fd3017cde82cf10c9c04a5\"\u003e\u003ccode\u003e1b36468\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Refactor] \u003ccode\u003eparse\u003c/code\u003e: fix swapped \u003ccode\u003eSINGLE_QUOTE\u003c/code\u003e/\u003ccode\u003eDOUBLE_QUOTE\u003c/code\u003e variable names \u003ca href=\"https://github.com/ljharb/shell-quote/commit/801af5c935b27d6dcda63b3975d5e92a7b6f887f\"\u003e\u003ccode\u003e801af5c\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[types] fix an error TS v6 ignores but v7 fails on \u003ca href=\"https://github.com/ljharb/shell-quote/commit/59bbf8b81bf3236842deb72805744d489f650eba\"\u003e\u003ccode\u003e59bbf8b\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@arethetypeswrong/cli\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/a04d47516e1cd5b1b4d3f720ddf97561ed0082fc\"\u003e\u003ccode\u003ea04d475\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@arethetypeswrong/ci\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/d390f9a92b97a04b1f799298634e90dc581021e6\"\u003e\u003ccode\u003ed390f9a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: the tilde test escapes every \u003ccode\u003e~\u003c/code\u003e, not just a leading one (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/9\"\u003e#9\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/617d119795c7b44d6e49a4d41f80195c4aa5735c\"\u003e\u003ccode\u003e617d119\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.4...v1.9.0\"\u003ev1.9.0\u003c/a\u003e - 2026-06-24\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[New] add types \u003ca href=\"https://github.com/ljharb/shell-quote/commit/dca6e21a02df4cc1a83ed1b5baa4d82df134170a\"\u003e\u003ccode\u003edca6e21\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9aa9e8f60991f8c4053a29e476795d891ff851ad\"\u003e\u003ccode\u003e9aa9e8f\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: finalize tokens in linear time (GHSA-395f-4hp3-45gv) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7ff5488599d01c323514f02f5efb74088dd134ec\"\u003e\u003ccode\u003e7ff5488\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] update workflows \u003ca href=\"https://github.com/ljharb/shell-quote/commit/75e849741ffaf2d3aa53ae0e18ef6bf9929ef478\"\u003e\u003ccode\u003e75e8497\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 4/6/7: pin eslint to 9 before install, since npm 2/3 cannot stage eslint 10\u003ccode\u003e@types/esrecurse\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3fb739de44b81c69431947d54fbfc18998dd6d72\"\u003e\u003ccode\u003e3fb739d\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] retry \u003ccode\u003enpm install\u003c/code\u003e on Windows to survive npm 2/3 staging-rename flake \u003ca href=\"https://github.com/ljharb/shell-quote/commit/abe0163293c82963fa8a16cfaa87181846d5aced\"\u003e\u003ccode\u003eabe0163\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 5/7: install deps with a modern node \u003ca href=\"https://github.com/ljharb/shell-quote/commit/b4bafa2e7e58d53d9839b1c24976f61e54b43326\"\u003e\u003ccode\u003eb4bafa2\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: escape leading \u003ccode\u003e~\u003c/code\u003e to prevent shell tilde-expansion \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7a76c1a12d8461c2234a1c655b943cee84cbff91\"\u003e\u003ccode\u003e7a76c1a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7184b4458b65c17b931e126d8cb5f586c6717dc8\"\u003e\u003ccode\u003e7184b44\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] apparently \u003ccode\u003ejackspeak\u003c/code\u003e is no longer in the graph \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9ba368a4057b9f498b0fef23b5b15543ef81b98c\"\u003e\u003ccode\u003e9ba368a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.3...v1.8.4\"\u003ev1.8.4\u003c/a\u003e - 2026-05-22\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: validate object-token shapes \u003ca href=\"https://github.com/ljharb/shell-quote/commit/4378a6e613db5948168684864e49b42b83134d2d\"\u003e\u003ccode\u003e4378a6e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003enpmignore\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/22ebec04349065a45ad8afc8cc8d53c4624634a6\"\u003e\u003ccode\u003e22ebec0\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] increase coverage \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9f3caa31900cc6ee64858b31134144c648ce206d\"\u003e\u003ccode\u003e9f3caa3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] replace runkit CI badge with shields.io check-runs badge \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3344a047dd1e95f71c4ca27522cbfd05c56277e0\"\u003e\u003ccode\u003e3344a04\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/699c5113d135f4d4591574bebf173334ffa453d4\"\u003e\u003ccode\u003e699c511\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.2...v1.8.3\"\u003ev1.8.3\u003c/a\u003e - 2025-06-01\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/64988d9a0e73a2ae710488952e3614958ef289d4\"\u003e\u003ccode\u003e64988d9\u003c/code\u003e\u003c/a\u003e v1.10.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/617d119795c7b44d6e49a4d41f80195c4aa5735c\"\u003e\u003ccode\u003e617d119\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: the tilde test escapes every \u003ccode\u003e~\u003c/code\u003e, not just a leading one (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/9\"\u003e#9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/59bbf8b81bf3236842deb72805744d489f650eba\"\u003e\u003ccode\u003e59bbf8b\u003c/code\u003e\u003c/a\u003e [types] fix an error TS v6 ignores but v7 fails on\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/190e236bcf1d81caa8e40e8ea3bb11998575be71\"\u003e\u003ccode\u003e190e236\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: pin that a backslash with whitespace is not doubled in singl...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/a04d47516e1cd5b1b4d3f720ddf97561ed0082fc\"\u003e\u003ccode\u003ea04d475\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003e@arethetypeswrong/cli\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/b9545b39f4de17aa169410823c98acf58387e474\"\u003e\u003ccode\u003eb9545b3\u003c/code\u003e\u003c/a\u003e [New] \u003ccode\u003eparse\u003c/code\u003e: add opt-in \u003ccode\u003esplitUnquoted\u003c/code\u003e option for shell field-splitting of...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/1b364683b1e9e8d078fd3017cde82cf10c9c04a5\"\u003e\u003ccode\u003e1b36468\u003c/code\u003e\u003c/a\u003e [readme] \u003ccode\u003equote\u003c/code\u003e: use output verbatim; do not re-quote it (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/1c36f3ff77d26d200620c1027e5c271050120b8e\"\u003e\u003ccode\u003e1c36f3f\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: pin conservative escaping of \u003ccode\u003e=\u003c/code\u003e, \u003ccode\u003e@\u003c/code\u003e, \u003ccode\u003e^\u003c/code\u003e, \u003ccode\u003e,\u003c/code\u003e, \u003ccode\u003e:\u003c/code\u003e, \u003ccode\u003e!\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/e1c75cd6e4a3c60003792c7f2802587d328622cb\"\u003e\u003ccode\u003ee1c75cd\u003c/code\u003e\u003c/a\u003e [readme] document \u003ccode\u003eparse\u003c/code\u003e's supported parameter-expansion subset\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/c0842c8a7a034066da2496a75e91cbe500ff736c\"\u003e\u003ccode\u003ec0842c8\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003eparse\u003c/code\u003e: match nested \u003ccode\u003e${...}\u003c/code\u003e braces so nested parameter expansion is ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.7.3...v1.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~ljharb\"\u003eljharb\u003c/a\u003e, a new releaser for shell-quote since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version adds \u003ccode\u003eprepublish\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.9.0 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.28.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e7 security advisories\u003c/strong\u003e, all shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 7.28.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^7.28.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v7 line is \u003cstrong\u003enot\u003c/strong\u003e affected by GHSA-38rv-x7px-6hhq (CVE-2026-9675), which is\nan 8.x-only regression.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on GHSA-hm92-r4w5-c3mj:\u003c/strong\u003e this fix shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e, not the\nearlier 7.2x line — the vulnerable single-pool code was still present through\n\u003ccode\u003ev7.27.2\u003c/code\u003e. The per-origin pool fix is\n\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5041\"\u003e#5041\u003c/a\u003e).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8cb10f98\"\u003e\u003ccode\u003e8cb10f98\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g\"\u003eGHSA-vmh5-mc38-953g\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9697\u003c/td\u003e\n\u003ctd\u003eHigh (7.4)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/04201f89\"\u003e\u003ccode\u003e04201f89\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj\"\u003eGHSA-hm92-r4w5-c3mj\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6734\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6\"\u003eGHSA-pr7r-676h-xcf6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9678\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/85a24055\"\u003e\u003ccode\u003e85a24055\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ea8930cf\"\u003e\u003ccode\u003eea8930cf\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f9eba0ad9134e1c0977848476bba9d49734696e4\"\u003e\u003ccode\u003ef9eba0a\u003c/code\u003e\u003c/a\u003e Bumped v7.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5430\"\u003e#5430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.9.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for undici since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nRemoves `uuid`\n\nUpdates `brace-expansion` from 1.1.12 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3\"\u003e\u003ccode\u003e10c05fc\u003c/code\u003e\u003c/a\u003e 1.1.14\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 2.0.2 to 2.1.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3\"\u003e\u003ccode\u003e10c05fc\u003c/code\u003e\u003c/a\u003e 1.1.14\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `linkify-it` from 3.0.3 to 5.0.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md\"\u003elinkify-it's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.0.2 / 2026-07-02\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed DoS in \u003ccode\u003emailto:\u003c/code\u003e links (restrict user name to 64 chars).\u003c/li\u003e\n\u003cli\u003eRestricted user/pass part length in links.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e5.0.1 / 2026-05-23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed DoS in fuzzy links/emails search.\u003c/li\u003e\n\u003cli\u003eReworked search logic - check each pattern separate, use \u003ccode\u003eg\u003c/code\u003e regexes instead\nof slice.\u003c/li\u003e\n\u003cli\u003eRemoved internal cache - useless overcomplication.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/50a0c914f834b201cab25ff4faefd1f832b37332\"\u003e\u003ccode\u003e50a0c91\u003c/code\u003e\u003c/a\u003e 5.0.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/de3b88554b5e465d5fa19914e2a1801ebb3069ef\"\u003e\u003ccode\u003ede3b885\u003c/code\u003e\u003c/a\u003e Update package hooks\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/13effaaa4600d1fcff9f63c38fecdd601bfd83e7\"\u003e\u003ccode\u003e13effaa\u003c/code\u003e\u003c/a\u003e Add package lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/39d748dbfc77534e9be04d87cd9f57a13b9b4216\"\u003e\u003ccode\u003e39d748d\u003c/code\u003e\u003c/a\u003e Bump c8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/00ce8771ac0c3e6784dcacaa1625ca0fc1b62a12\"\u003e\u003ccode\u003e00ce877\u003c/code\u003e\u003c/a\u003e Drop tlds deps\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/ecde82341a1b2e349b03eb01f3e1d2cc105bcd7f\"\u003e\u003ccode\u003eecde823\u003c/code\u003e\u003c/a\u003e Update benchmark to mitata\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/23c62cdd14ef36e89c175c6726e2229e5b76e75f\"\u003e\u003ccode\u003e23c62cd\u003c/code\u003e\u003c/a\u003e Refactor demo / doc build and publish\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/fd63f3b4ab433ca3561304409b572eed465706cd\"\u003e\u003ccode\u003efd63f3b\u003c/code\u003e\u003c/a\u003e CI config update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/f4ea5afaa6a8e1109c44898158d4910b3fb128fb\"\u003e\u003ccode\u003ef4ea5af\u003c/code\u003e\u003c/a\u003e demo: update bootstrap \u0026amp; layout\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/markdown-it/linkify-it/commit/1454fb645f00c33a05edbded18640d5078ba7710\"\u003e\u003ccode\u003e1454fb6\u003c/code\u003e\u003c/a\u003e lint: dim warnings\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/markdown-it/linkify-it/compare/5.0.0...5.0.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `markdown-it` from 12.3.2 to 14.3.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md\"\u003emarkdown-it's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[14.3.0] - 2026-07-02\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReworked build pipeline \u0026amp; tools.\u003c/li\u003e\n\u003cli\u003eAdded source maps.\u003c/li\u003e\n\u003cli\u003eBumped \u003ccode\u003elinkify-it\u003c/code\u003e to 5.0.2.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve backslash-space hard line breaks, matching CommonMark 6.7, \u003ca href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1185\"\u003e#1185\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[14.2.0] - 2026-05-24\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eisPunctCharCode\u003c/code\u003e to utilities.\u003c/li...\n\n_Description has been truncated_","html_url":"https://github.com/goodgollyholly/vscode/pull/36","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/goodgollyholly%2Fvscode/issues/36","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/36/packages"}},{"old_version":"7.28.0","new_version":"7.29.0","update_type":"minor","path":null,"pr_created_at":"2026-08-07T11:46:48.000Z","version_change":"7.28.0 → 7.29.0","issue":{"uuid":"5089852722","node_id":"PR_kwDORgSK_878BLc4","number":41,"state":"closed","title":"chore(deps): bump undici from 7.28.0 to 7.29.0","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-08-07T16:42:41.000Z","author_association":null,"state_reason":null,"created_at":"2026-08-07T11:46:48.000Z","updated_at":"2026-08-07T16:42:50.000Z","time_to_close":17753,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"undici","old_version":"7.28.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 7.28.0 to 7.29.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=7.28.0\u0026new-version=7.29.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/NetAuraTech/adonisjs-foundry/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/NetAuraTech/adonisjs-foundry/pull/41","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/NetAuraTech%2Fadonisjs-foundry/issues/41","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/41/packages"}},{"old_version":"8.7.0","new_version":"8.10.0","update_type":"minor","path":null,"pr_created_at":"2026-08-07T06:21:35.000Z","version_change":"8.7.0 → 8.10.0","issue":{"uuid":"5087482746","node_id":"PR_kwDOSPVWK8775iEI","number":368,"state":"closed","title":"deps-dev: Bump the dev-minor-patch group across 1 directory with 18 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-08-14T06:21:54.000Z","author_association":null,"state_reason":null,"created_at":"2026-08-07T06:21:35.000Z","updated_at":"2026-08-14T06:21:56.000Z","time_to_close":604819,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"deps-dev: Bump","group_name":"dev-minor-patch","update_count":18,"packages":[{"name":"@eslint/eslintrc","old_version":"3.3.5","new_version":"3.3.6","repository_url":"https://github.com/eslint/eslintrc"},{"name":"@playwright/test","old_version":"1.61.1","new_version":"1.62.1","repository_url":"https://github.com/microsoft/playwright"},{"name":"@tailwindcss/postcss","old_version":"4.3.2","new_version":"4.3.3","repository_url":"https://github.com/tailwindlabs/tailwindcss"},{"name":"@testing-library/user-event","old_version":"14.6.1","new_version":"14.6.3","repository_url":"https://github.com/testing-library/user-event"},{"name":"@types/node","old_version":"25.9.4","new_version":"25.9.5","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"@types/pg","old_version":"8.20.0","new_version":"8.20.3","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"@vitest/coverage-v8","old_version":"4.1.9","new_version":"4.1.10","repository_url":"https://github.com/vitest-dev/vitest"},{"name":"eslint-config-next","old_version":"16.2.10","new_version":"16.3.0","repository_url":"https://github.com/vercel/next.js"},{"name":"msw","old_version":"2.14.6","new_version":"2.15.0","repository_url":"https://github.com/mswjs/msw"},{"name":"postcss","old_version":"8.5.15","new_version":"8.5.25","repository_url":"https://github.com/postcss/postcss"},{"name":"prettier","old_version":"3.9.4","new_version":"3.9.6","repository_url":"https://github.com/prettier/prettier"},{"name":"prettier-plugin-tailwindcss","old_version":"0.8.0","new_version":"0.8.1","repository_url":"https://github.com/tailwindlabs/prettier-plugin-tailwindcss"},{"name":"tailwindcss","old_version":"4.3.2","new_version":"4.3.3","repository_url":"https://github.com/tailwindlabs/tailwindcss"},{"name":"tsx","old_version":"4.23.0","new_version":"4.23.5","repository_url":"https://github.com/privatenumber/tsx"},{"name":"typescript-eslint","old_version":"8.62.1","new_version":"8.66.0","repository_url":"https://github.com/typescript-eslint/typescript-eslint"},{"name":"undici","old_version":"8.7.0","new_version":"8.10.0","repository_url":"https://github.com/nodejs/undici"},{"name":"vite","old_version":"8.1.3","new_version":"8.2.0","repository_url":"https://github.com/vitejs/vite"},{"name":"vitest","old_version":"4.1.9","new_version":"4.1.10","repository_url":"https://github.com/vitest-dev/vitest"}],"path":null,"ecosystem":"npm"},"body":"Bumps the dev-minor-patch group with 18 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@eslint/eslintrc](https://github.com/eslint/eslintrc) | `3.3.5` | `3.3.6` |\n| [@playwright/test](https://github.com/microsoft/playwright) | `1.61.1` | `1.62.1` |\n| [@tailwindcss/postcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss) | `4.3.2` | `4.3.3` |\n| [@testing-library/user-event](https://github.com/testing-library/user-event) | `14.6.1` | `14.6.3` |\n| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `25.9.4` | `25.9.5` |\n| [@types/pg](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/pg) | `8.20.0` | `8.20.3` |\n| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `4.1.9` | `4.1.10` |\n| [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.2.10` | `16.3.0` |\n| [msw](https://github.com/mswjs/msw) | `2.14.6` | `2.15.0` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.15` | `8.5.25` |\n| [prettier](https://github.com/prettier/prettier) | `3.9.4` | `3.9.6` |\n| [prettier-plugin-tailwindcss](https://github.com/tailwindlabs/prettier-plugin-tailwindcss) | `0.8.0` | `0.8.1` |\n| [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) | `4.3.2` | `4.3.3` |\n| [tsx](https://github.com/privatenumber/tsx) | `4.23.0` | `4.23.5` |\n| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.62.1` | `8.66.0` |\n| [undici](https://github.com/nodejs/undici) | `8.7.0` | `8.10.0` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.1.3` | `8.2.0` |\n| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.9` | `4.1.10` |\n\n\nUpdates `@eslint/eslintrc` from 3.3.5 to 3.3.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eslint/eslintrc/releases\"\u003e@​eslint/eslintrc's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eeslintrc: v3.3.6\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.5...eslintrc-v3.3.6\"\u003e3.3.6\u003c/a\u003e (2026-07-10)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdate \u003ccode\u003ejs-yaml\u003c/code\u003e to 4.3.0 to address security vulnerability (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/235\"\u003e#235\u003c/a\u003e) (\u003ca href=\"https://github.com/eslint/eslintrc/commit/0c5de746dd98ac6904ee05ca594c50c5695e88bc\"\u003e0c5de74\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eslint/eslintrc/blob/main/CHANGELOG.md\"\u003e@​eslint/eslintrc's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.5...eslintrc-v3.3.6\"\u003e3.3.6\u003c/a\u003e (2026-07-10)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdate \u003ccode\u003ejs-yaml\u003c/code\u003e to 4.3.0 to address security vulnerability (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/235\"\u003e#235\u003c/a\u003e) (\u003ca href=\"https://github.com/eslint/eslintrc/commit/0c5de746dd98ac6904ee05ca594c50c5695e88bc\"\u003e0c5de74\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/b433a223f965b957ef3e3b8a21b77d6ac5b5d8d1\"\u003e\u003ccode\u003eb433a22\u003c/code\u003e\u003c/a\u003e chore: release 3.3.6 🚀 (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/236\"\u003e#236\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/0c5de746dd98ac6904ee05ca594c50c5695e88bc\"\u003e\u003ccode\u003e0c5de74\u003c/code\u003e\u003c/a\u003e fix: update \u003ccode\u003ejs-yaml\u003c/code\u003e to 4.3.0 to address security vulnerability (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/235\"\u003e#235\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/94837a4ae3ceb0d592d880b38280c4059b50ef78\"\u003e\u003ccode\u003e94837a4\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/dbae1a1449c05b38e50cf862e5851f415db42404\"\u003e\u003ccode\u003edbae1a1\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/19fe72a30f48d39bda5fa63f3dafc5106e4f3687\"\u003e\u003ccode\u003e19fe72a\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/92ebd174471b294fd52b4f8c8b786c0087a017eb\"\u003e\u003ccode\u003e92ebd17\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/3ba4c8c2cbe1e85eed14679e0b6a28ae7fde98b7\"\u003e\u003ccode\u003e3ba4c8c\u003c/code\u003e\u003c/a\u003e ci: add Node.js 26 to CI (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/231\"\u003e#231\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/f8d268a51a004668bb72d20d1706f4d4a4928c87\"\u003e\u003ccode\u003ef8d268a\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/6e20867b312094e53afa559dcad21ceeff6cac58\"\u003e\u003ccode\u003e6e20867\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/6d722b64e8331bbd663eeb4ec55a9c03679904b7\"\u003e\u003ccode\u003e6d722b6\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.5...eslintrc-v3.3.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@playwright/test` from 1.61.1 to 1.62.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/microsoft/playwright/releases\"\u003e@​playwright/test's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.62.1\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/41989\"\u003e#41989\u003c/a\u003e [Regression]: tsconfig \u0026quot;extends\u0026quot; bare specifier isn't resolved via node_modules walk-up like tsc (fatal since 1.62)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/41998\"\u003e#41998\u003c/a\u003e [Regression]: directory-form tsconfig project references (\u0026quot;path\u0026quot;: \u0026quot;../pkg\u0026quot;) fail to resolve (fatal since 1.62)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/41985\"\u003e#41985\u003c/a\u003e Accessibility snapshot drops button name when text is nested inside spans with aria-hidden SVG\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42000\"\u003e#42000\u003c/a\u003e [Regression]: page.evaluate() arg of a branded primitive type (string \u0026amp; { brand }) no longer type-checks since 1.62\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42013\"\u003e#42013\u003c/a\u003e [BUG]Image-type actionable elements are not presented in the snapshot.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.62.0\u003c/h2\u003e\n\u003ch2\u003e🧱 New component testing model\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://playwright.dev/docs/test-components\"\u003eComponent testing\u003c/a\u003e moves to a \u003cstrong\u003estories and galleries\u003c/strong\u003e model.\nA \u003cstrong\u003estory\u003c/strong\u003e wraps your component in one specific scenario — hard-coded props, mock data, providers — and a \u003cstrong\u003egallery\u003c/strong\u003e page that you serve renders stories on demand.\nThe new \u003ca href=\"https://playwright.dev/docs/api/class-fixtures#fixtures-mount\"\u003efixtures.mount()\u003c/a\u003e fixture navigates to the gallery, mounts a story by id, and returns a \u003ca href=\"https://playwright.dev/docs/api/class-locator\"\u003eLocator\u003c/a\u003e scoped to the story's root element:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003etest('click should expand', async ({ mount }) =\u0026gt; {\r\n  const component = await mount('components/Expandable/Stateful');\r\n  await component.getByRole('button').click();\r\n  await expect(component.getByTestId('expanded')).toHaveValue('true');\r\n});\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003ePass a story type as a template argument to type-check its props, and use \u003ccode\u003eupdate(props)\u003c/code\u003e / \u003ccode\u003eunmount()\u003c/code\u003e on the returned locator to re-render or tear down within a test.\u003c/p\u003e\n\u003ch2\u003e🛑 Cancel operations with AbortSignal\u003c/h2\u003e\n\u003cp\u003eMost operations and web-first assertions now accept a \u003ccode\u003esignal\u003c/code\u003e option that takes an \u003ca href=\"https://developer.mozilla.org/en-US/docs/Web/API/AbortSignal\"\u003e\u003ccode\u003eAbortSignal\u003c/code\u003e\u003c/a\u003e, letting you cancel long-running actions, navigations, waits, and assertions:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003econst controller = new AbortController();\r\nsetTimeout(() =\u0026gt; controller.abort(), 1000);\r\n\u003cp\u003eawait page.getByRole('button', { name: 'Submit' }).click({ signal: controller.signal });\nawait expect(page.getByText('Done')).toBeVisible({ signal: controller.signal });\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eProviding a signal does not disable the default timeout; pass \u003ccode\u003etimeout: 0\u003c/code\u003e to disable it.\u003c/p\u003e\n\u003ch2\u003e🖼️ WebP screenshots\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://playwright.dev/docs/api/class-pageassertions#page-assertions-to-have-screenshot-1\"\u003eexpect(page).toHaveScreenshot()\u003c/a\u003e and \u003ca href=\"https://playwright.dev/docs/api/class-locatorassertions#locator-assertions-to-have-screenshot-1\"\u003eexpect(locator).toHaveScreenshot()\u003c/a\u003e can now store snapshots in the WebP format — just give the snapshot a \u003ccode\u003e.webp\u003c/code\u003e name:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Visual comparisons store the golden snapshot as lossless WebP.\r\nawait expect(page).toHaveScreenshot('homepage.webp');\r\n\u003cp\u003e// Standalone screenshots can trade quality for size with lossy WebP.\nawait page.screenshot({ path: 'homepage.webp', quality: 50 });\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt;\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/26a9e470a7b3c7822084b09fb7f13902c5f37b51\"\u003e\u003ccode\u003e26a9e47\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42043\"\u003e#42043\u003c/a\u003e): docs: release notes for v1.62 Python, Java, and .NET (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/4\"\u003e#4\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/0a81d5d09b10eeefe228fe745c3f80c7368a239b\"\u003e\u003ccode\u003e0a81d5d\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42040\"\u003e#42040\u003c/a\u003e): docs(release-notes): mention the isolated headless clipb...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/83768264e64a821bcef9e634b8e5c33897f2b032\"\u003e\u003ccode\u003e8376826\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42034\"\u003e#42034\u003c/a\u003e): fix(aria): keep icon-only clickable elements in ai snaps...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/66c5cc92a60ce20ab3abe779339e1f90d2e2e888\"\u003e\u003ccode\u003e66c5cc9\u003c/code\u003e\u003c/a\u003e chore: mark v1.62.1 (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42020\"\u003e#42020\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/9672bc3f2a7098cb6a9791ca97222187363a3037\"\u003e\u003ccode\u003e9672bc3\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42009\"\u003e#42009\u003c/a\u003e): fix(types): support branded primitives in evaluate argum...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/4325804427a214aa0c8c39bb1352f4ac4f712fd1\"\u003e\u003ccode\u003e4325804\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/41988\"\u003e#41988\u003c/a\u003e): fix(aria): preserve names from collapsed text contributors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/9632f8ecbc2accba140ea342f1070ccfdd5f5d41\"\u003e\u003ccode\u003e9632f8e\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42005\"\u003e#42005\u003c/a\u003e): fix(tsconfig): do not throw when \u0026quot;extends\u0026quot;/\u0026quot;references\u0026quot; ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/e3950d9c140d007bd52853b45813c6274b24e36f\"\u003e\u003ccode\u003ee3950d9\u003c/code\u003e\u003c/a\u003e chore: mark v1.62.0 (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/41981\"\u003e#41981\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/f07e0f720fbe6691cc3d3d66ff9f3e58139e804c\"\u003e\u003ccode\u003ef07e0f7\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/41940\"\u003e#41940\u003c/a\u003e): docs: release notes for v1.62 (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/41967\"\u003e#41967\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/05a306c78f11767535fd986eebab5d4c4dad4614\"\u003e\u003ccode\u003e05a306c\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/41964\"\u003e#41964\u003c/a\u003e): Revert \u0026quot;feat(routeFromHar): add interceptAPIRequests opt...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/microsoft/playwright/compare/v1.61.1...v1.62.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@tailwindcss/postcss` from 4.3.2 to 4.3.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/tailwindcss/releases\"\u003e@​tailwindcss/postcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.3.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003e--watch --poll[=ms]\u003c/code\u003e in \u003ccode\u003e@tailwindcss/cli\u003c/code\u003e when filesystem events are unreliable or unavailable (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20297\"\u003e#20297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCanonicalization: match arbitrary hex colors against theme colors case-insensitively (e.g. \u003ccode\u003ebg-[#fff]\u003c/code\u003e and \u003ccode\u003ebg-[#FFF]\u003c/code\u003e → \u003ccode\u003ebg-white\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20298\"\u003e#20298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent Preflight from overriding Firefox's native \u003ccode\u003eiframe:focus-visible\u003c/code\u003e outline styles (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20292\"\u003e#20292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003etheme('colors.foo')\u003c/code\u003e in JS plugins resolves correctly when both \u003ccode\u003e--color-foo\u003c/code\u003e and \u003ccode\u003e--color-foo-bar\u003c/code\u003e exist (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20299\"\u003e#20299\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure fractional opacity modifiers work with named shadow sizes like \u003ccode\u003eshadow-sm/12.5\u003c/code\u003e, \u003ccode\u003etext-shadow-sm/12.5\u003c/code\u003e, \u003ccode\u003edrop-shadow-sm/12.5\u003c/code\u003e, and \u003ccode\u003einset-shadow-sm/12.5\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20302\"\u003e#20302\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eParse selectors like \u003ccode\u003e[data-foo]div\u003c/code\u003e as two selectors instead of one (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20303\"\u003e#20303\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e@tailwindcss/postcss\u003c/code\u003e rebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20310\"\u003e#20310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure CSS nesting is handled even when Lightning CSS isn't run, such as in \u003ccode\u003e@tailwindcss/browser\u003c/code\u003e and Tailwind Play (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20124\"\u003e#20124\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent achromatic theme colors from shifting hue when mixed in polar color spaces like \u003ccode\u003eoklch\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20314\"\u003e#20314\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e--spacing(0)\u003c/code\u003e is optimized to \u003ccode\u003e0px\u003c/code\u003e instead of \u003ccode\u003e0\u003c/code\u003e so it remains a \u003ccode\u003e\u0026lt;length\u0026gt;\u003c/code\u003e when used in \u003ccode\u003ecalc(…)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20319\"\u003e#20319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eLoad \u003ccode\u003e@parcel/watcher\u003c/code\u003e only when needed in \u003ccode\u003e@tailwindcss/cli --watch\u003c/code\u003e mode, so one-off builds and \u003ccode\u003e--watch --poll\u003c/code\u003e work when \u003ccode\u003e@parcel/watcher\u003c/code\u003e can't be loaded (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20325\"\u003e#20325\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUse explicit platform fonts instead of \u003ccode\u003esystem-ui\u003c/code\u003e and \u003ccode\u003eui-sans-serif\u003c/code\u003e so CJK text respects the page's \u003ccode\u003elang\u003c/code\u003e attribute on Windows (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20318\"\u003e#20318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent \u003ccode\u003e@tailwindcss/upgrade\u003c/code\u003e from rewriting ignored files when run from a subdirectory (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20329\"\u003e#20329\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure earlier \u003ccode\u003e@source\u003c/code\u003e rules pointing to nested files are scanned when later \u003ccode\u003e@source\u003c/code\u003e rules point to files in parent folders (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20335\"\u003e#20335\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent \u003ccode\u003e@tailwindcss/vite\u003c/code\u003e from triggering full page reloads when scanned files are processed by Vite but haven't been loaded as modules yet (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20336\"\u003e#20336\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md\"\u003e@​tailwindcss/postcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[4.3.3] - 2026-07-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003e--watch --poll[=ms]\u003c/code\u003e in \u003ccode\u003e@tailwindcss/cli\u003c/code\u003e when filesystem events are unreliable or unavailable (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20297\"\u003e#20297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCanonicalization: match arbitrary hex colors against theme colors case-insensitively (e.g. \u003ccode\u003ebg-[#fff]\u003c/code\u003e and \u003ccode\u003ebg-[#FFF]\u003c/code\u003e → \u003ccode\u003ebg-white\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20298\"\u003e#20298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent Preflight from overriding Firefox's native \u003ccode\u003eiframe:focus-visible\u003c/code\u003e outline styles (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20292\"\u003e#20292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003etheme('colors.foo')\u003c/code\u003e in JS plugins resolves correctly when both \u003ccode\u003e--color-foo\u003c/code\u003e and \u003ccode\u003e--color-foo-bar\u003c/code\u003e exist (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20299\"\u003e#20299\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure fractional opacity modifiers work with named shadow sizes like \u003ccode\u003eshadow-sm/12.5\u003c/code\u003e, \u003ccode\u003etext-shadow-sm/12.5\u003c/code\u003e, \u003ccode\u003edrop-shadow-sm/12.5\u003c/code\u003e, and \u003ccode\u003einset-shadow-sm/12.5\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20302\"\u003e#20302\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eParse selectors like \u003ccode\u003e[data-foo]div\u003c/code\u003e as two selectors instead of one (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20303\"\u003e#20303\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e@tailwindcss/postcss\u003c/code\u003e rebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20310\"\u003e#20310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure CSS nesting is handled even when Lightning CSS isn't run, such as in \u003ccode\u003e@tailwindcss/browser\u003c/code\u003e and Tailwind Play (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20124\"\u003e#20124\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent achromatic theme colors from shifting hue when mixed in polar color spaces like \u003ccode\u003eoklch\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20314\"\u003e#20314\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e--spacing(0)\u003c/code\u003e is optimized to \u003ccode\u003e0px\u003c/code\u003e instead of \u003ccode\u003e0\u003c/code\u003e so it remains a \u003ccode\u003e\u0026lt;length\u0026gt;\u003c/code\u003e when used in \u003ccode\u003ecalc(…)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20319\"\u003e#20319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eLoad \u003ccode\u003e@parcel/watcher\u003c/code\u003e only when needed in \u003ccode\u003e@tailwindcss/cli --watch\u003c/code\u003e mode, so one-off builds and \u003ccode\u003e--watch --poll\u003c/code\u003e work when \u003ccode\u003e@parcel/watcher\u003c/code\u003e can't be loaded (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20325\"\u003e#20325\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUse explicit platform fonts instead of \u003ccode\u003esystem-ui\u003c/code\u003e and \u003ccode\u003eui-sans-serif\u003c/code\u003e so CJK text respects the page's \u003ccode\u003elang\u003c/code\u003e attribute on Windows (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20318\"\u003e#20318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent \u003ccode\u003e@tailwindcss/upgrade\u003c/code\u003e from rewriting ignored files when run from a subdirectory (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20329\"\u003e#20329\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure earlier \u003ccode\u003e@source\u003c/code\u003e rules pointing to nested files are scanned when later \u003ccode\u003e@source\u003c/code\u003e rules point to files in parent folders (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20335\"\u003e#20335\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent \u003ccode\u003e@tailwindcss/vite\u003c/code\u003e from triggering full page reloads when scanned files are processed by Vite but haven't been loaded as modules yet (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20336\"\u003e#20336\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss/commit/c2b24dd15fed1c59dd521bd86082f520c9f5ad0d\"\u003e\u003ccode\u003ec2b24dd\u003c/code\u003e\u003c/a\u003e 4.3.3 (\u003ca href=\"https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss/issues/20334\"\u003e#20334\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss/commit/e48c5e80473c25fe5a27fe267fbaf4f6512424a3\"\u003e\u003ccode\u003ee48c5e8\u003c/code\u003e\u003c/a\u003e Fix weird character rendering on Windows with Japanese locale (\u003ca href=\"https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss/issues/20318\"\u003e#20318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss/commit/9b0e8af25861ad5b8f5af420ad3ee0b188665027\"\u003e\u003ccode\u003e9b0e8af\u003c/code\u003e\u003c/a\u003e Ensure \u003ccode\u003e@tailwindcss/postcss\u003c/code\u003e rebuilds when the input CSS changes but its mti...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss/commit/b53fa096c92d830fc64b7cf69581496242583446\"\u003e\u003ccode\u003eb53fa09\u003c/code\u003e\u003c/a\u003e fix: exclude iframes from focus-visible auto outline in Preflight (\u003ca href=\"https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss/issues/20292\"\u003e#20292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/tailwindlabs/tailwindcss/commits/v4.3.3/packages/@tailwindcss-postcss\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@testing-library/user-event` from 14.6.1 to 14.6.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/testing-library/user-event/releases\"\u003e@​testing-library/user-event's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev14.6.3\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/testing-library/user-event/compare/v14.6.2...v14.6.3\"\u003e14.6.3\u003c/a\u003e (2026-08-03)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003erelease:\u003c/strong\u003e manually release a patch version (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1321\"\u003e#1321\u003c/a\u003e) (\u003ca href=\"https://github.com/testing-library/user-event/commit/1d18b1fae589eeed8e08838672a4c2de0dcc2b36\"\u003e1d18b1f\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1317\"\u003e#1317\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev14.6.2\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/testing-library/user-event/compare/v14.6.1...v14.6.2\"\u003e14.6.2\u003c/a\u003e (2026-08-03)\u003c/h2\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/1d18b1fae589eeed8e08838672a4c2de0dcc2b36\"\u003e\u003ccode\u003e1d18b1f\u003c/code\u003e\u003c/a\u003e fix(release): manually release a patch version (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1321\"\u003e#1321\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/232f3e6f4f92459c02161d156a70bddd13a59eaa\"\u003e\u003ccode\u003e232f3e6\u003c/code\u003e\u003c/a\u003e docs: add migration note and clean up README badges (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1320\"\u003e#1320\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/83e2b2261b40f5f08296eaf5af3d42018e6681ed\"\u003e\u003ccode\u003e83e2b22\u003c/code\u003e\u003c/a\u003e ci: remove deprecated CodeSandbox CI (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1318\"\u003e#1318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/e8da81953bd9b48512a1e4ce9b73cc36aeaeee37\"\u003e\u003ccode\u003ee8da819\u003c/code\u003e\u003c/a\u003e ci: publish to npm via OIDC trusted publishing (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1317\"\u003e#1317\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/13fa4bc1f0dedeb866a8730fa357229832437418\"\u003e\u003ccode\u003e13fa4bc\u003c/code\u003e\u003c/a\u003e ci: stop lint errors from blocking release (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1316\"\u003e#1316\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/c3cec1832f180b6d1dcb7c5d2b0771339dd5e848\"\u003e\u003ccode\u003ec3cec18\u003c/code\u003e\u003c/a\u003e chore(ci): make releases work with full git history (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1315\"\u003e#1315\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/ebab6c6e81e7022af7afa5aacd07d01626895eb8\"\u003e\u003ccode\u003eebab6c6\u003c/code\u003e\u003c/a\u003e add Liadshiran as a contributor for doc (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1300\"\u003e#1300\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/ec470bfd55ab7a741ce2a5b71e98c0f5686ac915\"\u003e\u003ccode\u003eec470bf\u003c/code\u003e\u003c/a\u003e docs: fix wrong default enum value (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1298\"\u003e#1298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/ba79c2f9a58d5927725fee506210d279fde218b5\"\u003e\u003ccode\u003eba79c2f\u003c/code\u003e\u003c/a\u003e chore: upgrade node version in csb (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1299\"\u003e#1299\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/user-event/commit/63ac399e06bd8f2397a6c581915acd29235f2d38\"\u003e\u003ccode\u003e63ac399\u003c/code\u003e\u003c/a\u003e fix: allow reassignment of  \u003ccode\u003eHTMLElement.prototype.focus\u003c/code\u003e and \u003ccode\u003e.blur\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/testing-library/user-event/issues/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/testing-library/user-event/compare/v14.6.1...v14.6.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​testing-library/user-event\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@types/node` from 25.9.4 to 25.9.5\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@types/pg` from 8.20.0 to 8.20.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/pg\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@vitest/coverage-v8` from 4.1.9 to 4.1.10\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitest-dev/vitest/releases\"\u003e@​vitest/coverage-v8's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.1.10\u003c/h2\u003e\n\u003ch3\u003e   🐞 Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebrowser\u003c/strong\u003e: Check fs access in builtin commands [backport to v4]  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eHiroshi Ogawa\u003c/strong\u003e and \u003cstrong\u003eOpenCode (claude-opus-4-8)\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10680\"\u003evitest-dev/vitest#10680\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/5c18dd267\"\u003e\u003c!-- raw HTML omitted --\u003e(5c18d)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003evm\u003c/strong\u003e: Fix external module resolve error with deps optimizer query for encoded URI [backport to v4]  -  by \u003ca href=\"https://github.com/SveLil\"\u003e\u003ccode\u003e@​SveLil\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10661\"\u003evitest-dev/vitest#10661\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/bae52b511\"\u003e\u003c!-- raw HTML omitted --\u003e(bae52)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch5\u003e    \u003ca href=\"https://github.com/vitest-dev/vitest/compare/v4.1.9...v4.1.10\"\u003eView changes on GitHub\u003c/a\u003e\u003c/h5\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/db616d227b6e0cb07a94f5d1bba262ee95db7e46\"\u003e\u003ccode\u003edb616d2\u003c/code\u003e\u003c/a\u003e chore: release v4.1.10 (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/10718\"\u003e#10718\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/coverage-v8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eslint-config-next` from 16.2.10 to 16.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003eeslint-config-next's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.0\u003c/h2\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate vendored lodash to 4.17.23 to fix CVE-2025-13465: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91558\"\u003e#91558\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix invalid HTML response for route-level RSC requests in deployment adapter: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91541\"\u003e#91541\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eNormalize encoded dynamic placeholders in app routes: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91603\"\u003e#91603\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix(pages-router): restore Content-Length and ETag for /_next/data/ JSON responses: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/90304\"\u003e#90304\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate tokio from 1.43.0 to 1.47.3: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/90945\"\u003e#90945\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[turbopack] Simplify snapshotting logic: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91178\"\u003e#91178\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: enable server HMR for app route handlers: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91466\"\u003e#91466\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eturbo-tasks-backend: batch find_and_schedule_dirty using for_each_task_meta: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91497\"\u003e#91497\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[turbopack] Use bail! instead of panic! for duplicate module ident error: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91636\"\u003e#91636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSkip loadBindings() Lightning CSS check during next start: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91538\"\u003e#91538\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eturbo-tasks-backend: batch schedule dirty tasks in aggregation_update: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91461\"\u003e#91461\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: Add importModule() support to webpack loaders: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/89630\"\u003e#89630\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eturbo-persistence: fix mmap page alignment and improve error context in MetaFile::open_internal: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91640\"\u003e#91640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eturbopack-css: demote recoverable CSS parse warnings to Warning severity: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91524\"\u003e#91524\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(node-streams): add config flag, define-env, and env precedence test: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/90427\"\u003e#90427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRename /_next/webpack-hmr to /_next/hmr: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91415\"\u003e#91415\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd per-slot error attribution for instant validation using slot markers and config depth preference: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91610\"\u003e#91610\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHandle encoded params further: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91627\"\u003e#91627\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[turbopack] Respect \u003ccode\u003e{eval:true}\u003c/code\u003e in worker_threads constructors: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91666\"\u003e#91666\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing route in otel spans without base-server: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91665\"\u003e#91665\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[turbopack] Optimize compaction cpu usage: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91468\"\u003e#91468\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix layout segment optimization: move app-page imports to server-utility transition: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91701\"\u003e#91701\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix server actions in standalone mode with \u003ccode\u003ecacheComponents\u003c/code\u003e: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91711\"\u003e#91711\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eturbo-persistence: remove Unmergeable mmap advice: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91713\"\u003e#91713\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eturbopack: move \u0026quot;compact database\u0026quot; tracing span to backend layer: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91693\"\u003e#91693\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: lazy require metadata and handle TLA: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91705\"\u003e#91705\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix adapter outputs for dynamic metadata routes: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91680\"\u003e#91680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: fix webpack loader runner layer: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91727\"\u003e#91727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[turbopack] Remove incorrect debug_assert in try_read_task_cell: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91699\"\u003e#91699\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd module count field to module graph tracing spans: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91697\"\u003e#91697\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eturbopack-cli: add --persistent-caching flag for filesystem-backed cache: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91657\"\u003e#91657\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: pull in updated vercel/nft tests: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91651\"\u003e#91651\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[turbopack] Improve regressed build speed on cross-compiled MUSL: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91477\"\u003e#91477\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Segment Bundling] [Scaffolding] Ensure inlining hint correctness: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91320\"\u003e#91320\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Segment Bundling] [Scaffolding] Track which segments can be omitted from prefetch: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91438\"\u003e#91438\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid deprecated TS node10 moduleResolution defaults: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91847\"\u003e#91847\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[turbopack] Rebuild the docker build scripts: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91799\"\u003e#91799\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix TS6 baseUrl deprecation for extended tsconfig: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91855\"\u003e#91855\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003enext internal post-build\u003c/code\u003e CLI command for Turbopack database compaction: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91336\"\u003e#91336\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: Define \u003ccode\u003eEffect\u003c/code\u003e as a trait instead of a closure: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/89080\"\u003e#89080\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: Implement TraceRawVcs and NonLocalValue correctly for Effects: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/89133\"\u003e#89133\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eturbo-tasks-backend: improve print_cache_item_size instrumentation: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91742\"\u003e#91742\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: switch from base40 to base38 hash encoding (remove ~ and . from charset): \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91832\"\u003e#91832\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse charCodeAt for normalizePathTrailingSlash: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91380\"\u003e#91380\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTurbopack: Only patch lockfile when bindings fails to load: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91379\"\u003e#91379\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[create-next-app] Skip interactive prompts when CLI flags are provided: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91840\"\u003e#91840\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[devtools] Make instant navs panel draggable: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91914\"\u003e#91914\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Segment Bundling] Bundle static prefetches based on size: \u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next/issues/91439\"\u003e#91439\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d73f5622e226358dcef8cf7a8a373333ff265ae7\"\u003e\u003ccode\u003ed73f562\u003c/code\u003e\u003c/a\u003e v16.3.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/4fd843fb488f770c5b2023ddc58ff4be4ee81f14\"\u003e\u003ccode\u003e4fd843f\u003c/code\u003e\u003c/a\u003e v16.3.0-canary.107\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/9480f7f9ffdc271014d959e7b10d681882eaabb5\"\u003e\u003ccode\u003e9480f7f\u003c/code\u003e\u003c/a\u003e v16.3.0-canary.106\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/a8dcd2562f0bde39380d48507ec3fffd86c21e53\"\u003e\u003ccode\u003ea8dcd25\u003c/code\u003e\u003c/a\u003e v16.3.0-canary.105\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/38f0cdee4659b1b8f987bc46e3f1aacd12ee5c90\"\u003e\u003ccode\u003e38f0cde\u003c/code\u003e\u003c/a\u003e v16.3.0-canary.104\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/f3edea1b06730ce507aeb1b10c8e4f652ca5540d\"\u003e\u003ccode\u003ef3edea1\u003c/code\u003e\u003c/a\u003e v16.3.0-canary.103\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/0d5ff0d321424b1f1c55b4466406ddee213d11c7\"\u003e\u003ccode\u003e0d5ff0d\u003c/code\u003e\u003c/a\u003e v16.3.0-canary.102\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/cf1e001f40b311f5a4f19775ec9ea4f1d8bdece9\"\u003e\u003ccode\u003ecf1e001\u003c/code\u003e\u003c/a\u003e v16.3.0-canary.101\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/267d6b1a17fb4b4b03860c4677e6eeefa65ba2b8\"\u003e\u003ccode\u003e267d6b1\u003c/code\u003e\u003c/a\u003e v16.3.0-canary.100\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/ad618bf13fbc4be57d6b6136a20547af50708eb2\"\u003e\u003ccode\u003ead618bf\u003c/code\u003e\u003c/a\u003e Restore canary version 16.3.0-canary.99 after v16.3.0-preview.10 preview release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/commits/v16.3.0/packages/eslint-config-next\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `msw` from 2.14.6 to 2.15.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mswjs/msw/releases\"\u003emsw's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.15.0 (2026-07-08)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003esse:\u003c/strong\u003e invoke \u003ccode\u003efinalize\u003c/code\u003e on response stream end (\u003ca href=\"https://redirect.github.com/mswjs/msw/issues/2741\"\u003e#2741\u003c/a\u003e) (7fae0cc0954b20c739ae8e95a24eefc8a78710e8) \u003ca href=\"https://github.com/kettanaito\"\u003e\u003ccode\u003e@​kettanaito\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.14.7 (2026-07-07)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003esse:\u003c/strong\u003e proper logging for concurrent requests (\u003ca href=\"https://redirect.github.com/mswjs/msw/issues/2762\"\u003e#2762\u003c/a\u003e) (5c0ae1c334a0cbe52638bd2949540372be3d46ba) \u003ca href=\"https://github.com/kettanaito\"\u003e\u003ccode\u003e@​kettanaito\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/49d9d47f613b072f8d20e1a025feaee7c5382b2b\"\u003e\u003ccode\u003e49d9d47\u003c/code\u003e\u003c/a\u003e chore(release): v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/ed885831bf90136044d305e1ae1035fb13491cec\"\u003e\u003ccode\u003eed88583\u003c/code\u003e\u003c/a\u003e test(finalize): use \u003ccode\u003eexpect.poll\u003c/code\u003e vs \u003ccode\u003ewaitFor\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/7fae0cc0954b20c739ae8e95a24eefc8a78710e8\"\u003e\u003ccode\u003e7fae0cc\u003c/code\u003e\u003c/a\u003e feat(sse): invoke \u003ccode\u003efinalize\u003c/code\u003e on response stream end (\u003ca href=\"https://redirect.github.com/mswjs/msw/issues/2741\"\u003e#2741\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/db818ee6c943bcfad18f6ecff2bb0dc210c457ca\"\u003e\u003ccode\u003edb818ee\u003c/code\u003e\u003c/a\u003e chore(release): v2.14.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/418854a04a1424eef25a7722e1016feea433a5a9\"\u003e\u003ccode\u003e418854a\u003c/code\u003e\u003c/a\u003e chore: upgrade \u003ccode\u003e@ossjs/release\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/5c0ae1c334a0cbe52638bd2949540372be3d46ba\"\u003e\u003ccode\u003e5c0ae1c\u003c/code\u003e\u003c/a\u003e fix(sse): proper logging for concurrent requests (\u003ca href=\"https://redirect.github.com/mswjs/msw/issues/2762\"\u003e#2762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/3016bda37757420b1c5adca9a3956f0dc8654456\"\u003e\u003ccode\u003e3016bda\u003c/code\u003e\u003c/a\u003e test: fix flaky \u003ccode\u003ews.clients.browser.test.ts\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/0df6d6a06fd99bb7066ee12457966c69f329fd38\"\u003e\u003ccode\u003e0df6d6a\u003c/code\u003e\u003c/a\u003e test: fix flaky \u003ccode\u003ein-flight-request.test.ts\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/ff6836b19cf250cfe0be721bfdf098a14c23506a\"\u003e\u003ccode\u003eff6836b\u003c/code\u003e\u003c/a\u003e chore: pin github actions to commit sha, update pnpm (\u003ca href=\"https://redirect.github.com/mswjs/msw/issues/2761\"\u003e#2761\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswjs/msw/commit/8a19d5485adad2b8a816e04a937f4c76169cd5b9\"\u003e\u003ccode\u003e8a19d54\u003c/code\u003e\u003c/a\u003e chore: improve github actions security (\u003ca href=\"https://redirect.github.com/mswjs/msw/issues/2747\"\u003e#2747\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mswjs/msw/compare/v2.14.6...v2.15.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.15 to 8.5.25\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/08c989c43cc87edb1ed71408c2f5164c54fc21df\"\u003e\u003ccode\u003e08c989c\u003c/code\u003e\u003c/a\u003e Release 8.5.25 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/24f681471645cd960ee760ab7f9e348fbabfd42c\"\u003e\u003ccode\u003e24f6814\u003c/code\u003e\u003c/a\u003e Fix 8.5.17 visitor regression\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f2fa53f11daab3a16c7eb8bcaf5a945142341df3\"\u003e\u003ccode\u003ef2fa53f\u003c/code\u003e\u003c/a\u003e Add supply chain security requirement to PostCSS plugin guide\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/10edf0b0606f97b1510e040c27bfd078c48d6ea7\"\u003e\u003ccode\u003e10edf0b\u003c/code\u003e\u003c/a\u003e fix: return empty array for empty string in list.split (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2121\"\u003e#2121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/0ebe8ad591621ab4e48311da47a76974617571f9\"\u003e\u003ccode\u003e0ebe8ad\u003c/code\u003e\u003c/a\u003e Release 8.5.24 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/73218c64245be53e25d58150e0cc7e984f1d162d\"\u003e\u003ccode\u003e73218c6\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9a114f62b0deb37be859102f93b414b49385805a\"\u003e\u003ccode\u003e9a114f6\u003c/code\u003e\u003c/a\u003e Preserve the BOM when stringifying (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2119\"\u003e#2119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/90692619125cb9424f5eafd8c64bc76b2da23db1\"\u003e\u003ccode\u003e9069261\u003c/code\u003e\u003c/a\u003e Fix types check\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.15...8.5.25\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `prettier` from 3.9.4 to 3.9.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/prettier/prettier/releases\"\u003eprettier's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.9.6\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve quotes for methods named \u003ccode\u003enew\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19621\"\u003eprettier/prettier#19621\u003c/a\u003e by \u003ca href=\"https://github.com/kovsu\"\u003e\u003ccode\u003e@​kovsu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSupport \u003ccode\u003eimport defer\u003c/code\u003e in \u003ccode\u003etypescript\u003c/code\u003e parser (\u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19624\"\u003eprettier/prettier#19624\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19675\"\u003eprettier/prettier#19675\u003c/a\u003e by \u003ca href=\"https://github.com/fisker\"\u003e\u003ccode\u003e@​fisker\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdded a new official plugin \u003ca href=\"https://github.com/prettier/prettier/tree/3.9.6/packages/plugin-yuku\"\u003e\u003ccode\u003e@prettier/plugin-yuku\u003c/code\u003e 🚀\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19628\"\u003eprettier/prettier#19628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19629\"\u003eprettier/prettier#19629\u003c/a\u003e by \u003ca href=\"https://github.com/fisker\"\u003e\u003ccode\u003e@​fisker\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e🔗 \u003ca href=\"https://github.com/prettier/prettier/blob/3.9.6/CHANGELOG.md#396\"\u003eChangelog\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.9.5\u003c/h2\u003e\n\u003cp\u003e🔗 \u003ca href=\"https://github.com/prettier/prettier/blob/3.9.5/CHANGELOG.md#395\"\u003eChangelog\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/prettier/prettier/blob/main/CHANGELOG.md\"\u003eprettier's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e3.9.6\u003c/h1\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/prettier/prettier/compare/3.9.5...3.9.6\"\u003ediff\u003c/a\u003e\u003c/p\u003e\n\u003ch4\u003eTypeScript: Preserve quotes for methods named \u003ccode\u003enew\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19621\"\u003e#19621\u003c/a\u003e by \u003ca href=\"https://github.com/kovsu\"\u003e\u003ccode\u003e@​kovsu\u003c/code\u003e\u003c/a\u003e)\u003c/h4\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cpre lang=\"tsx\"\u003e\u003ccode\u003e// Input\ninterface Container {\n  \u0026quot;new\u0026quot;(id: string): number;\n}\n\u003cp\u003e// Prettier 3.9.5\u003cbr /\u003e\ninterface Container {\u003cbr /\u003e\nnew(id: string): number;\u003cbr /\u003e\n}\u003c/p\u003e\n\u003cp\u003e// Prettier 3.9.6\u003cbr /\u003e\ninterface Container {\u003cbr /\u003e\n\u0026quot;new\u0026quot;(id: string): number;\u003cbr /\u003e\n}\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003ch4\u003eTypeScript: Support \u003ccode\u003eimport defer\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19624\"\u003e#19624\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19675\"\u003e#19675\u003c/a\u003e by \u003ca href=\"https://github.com/fisker\"\u003e\u003ccode\u003e@​fisker\u003c/code\u003e\u003c/a\u003e)\u003c/h4\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cpre lang=\"tsx\"\u003e\u003ccode\u003e// Input\nimport defer * as foo from \u0026quot;foo\u0026quot;;\n\u003cp\u003e// Prettier 3.9.5\u003cbr /\u003e\nimport * as foo from \u0026quot;foo\u0026quot;;\u003c/p\u003e\n\u003cp\u003e// Prettier 3.9.6\u003cbr /\u003e\nimport defer * as foo from \u0026quot;foo\u0026quot;;\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003ch4\u003eJavaScript: Added a new official plugin \u003ccode\u003e@prettier/plugin-yuku\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19628\"\u003e#19628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/prettier/prettier/pull/19629\"\u003e#19629\u003c/a\u003e by \u003ca href=\"https://github.com/fisker\"\u003e\u003ccode\u003e@​fisker\u003c/code\u003e\u003c/a\u003e)\u003c/h4\u003e\n\u003cp\u003e\u003ccode\u003e@prettier/plugin-yuku\u003c/code\u003e is powered by \u003ca href=\"https://yuku.fyi/\"\u003eYuku\u003c/a\u003e (A high-performance JavaScript/TypeScript compiler toolchain written in Zig).\u003c/p\u003e\n\u003cp\u003eThis plugin includes two new parsers: \u003ccode\u003eyuku\u003c/code\u003e (JavaScript syntax) and \u003ccode\u003eyuku-ts\u003c/code\u003e (TypeScript syntax).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eTo use this plugin:\u003c/strong\u003e\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003e\n\u003cp\u003eInstall the plugin:\u003c/p\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003eyarn add --dev prettier @prettier/plugin-yuku\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/8f0c95057cc91d5836409466cd9d9af3bb901e84\"\u003e\u003ccode\u003e8f0c950\u003c/code\u003e\u003c/a\u003e Release 3.9.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/e9107647d0497d8ff1cacbb0f970d4543df77c1c\"\u003e\u003ccode\u003ee910764\u003c/code\u003e\u003c/a\u003e Update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/ec3f1c7bd74495992bc6954323a1a7fc8368808e\"\u003e\u003ccode\u003eec3f1c7\u003c/code\u003e\u003c/a\u003e Update typescript-eslint to v8.65.0 (\u003ca href=\"https://redirect.github.com/prettier/prettier/issues/19675\"\u003e#19675\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/73d2efc2c6cba6f579585c88ef171132d90834ec\"\u003e\u003ccode\u003e73d2efc\u003c/code\u003e\u003c/a\u003e Update Yuku parser to v0.7.0 (\u003ca href=\"https://redirect.github.com/prettier/prettier/issues/19664\"\u003e#19664\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/dd5e24eabeab1f75ad573c79781e5fd408bcfad3\"\u003e\u003ccode\u003edd5e24e\u003c/code\u003e\u003c/a\u003e Preserve quotes for \u003ccode\u003eTSMethodSignature\u003c/code\u003e nodes named \u003ccode\u003enew\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/prettier/prettier/issues/19621\"\u003e#19621\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/c03ab4e71c23154d6b11537eee3c938f0d0f67d3\"\u003e\u003ccode\u003ec03ab4e\u003c/code\u003e\u003c/a\u003e Update dependency eslint-plugin-unicorn to v72 (\u003ca href=\"https://redirect.github.com/prettier/prettier/issues/19633\"\u003e#19633\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/b74dd53076c7208291a6b2e585c310844b41d35f\"\u003e\u003ccode\u003eb74dd53\u003c/code\u003e\u003c/a\u003e Update Yuku parser to v0.6.5 (\u003ca href=\"https://redirect.github.com/prettier/prettier/issues/19654\"\u003e#19654\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/f1b594ea1db1520c383d0e281d623551f671f824\"\u003e\u003ccode\u003ef1b594e\u003c/code\u003e\u003c/a\u003e Update dependency eslint-plugin-simple-import-sort to v14 (\u003ca href=\"https://redirect.github.com/prettier/prettier/issues/19655\"\u003e#19655\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/0d9dfb61530986373000dd107ea58ceebb79e233\"\u003e\u003ccode\u003e0d9dfb6\u003c/code\u003e\u003c/a\u003e Update Yuku parser to v0.6.4 (\u003ca href=\"https://redirect.github.com/prettier/prettier/issues/19650\"\u003e#19650\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/prettier/prettier/commit/3bbb8159eb55575d4042653aa99f5f92a1416c19\"\u003e\u003ccode\u003e3bbb815\u003c/code\u003e\u003c/a\u003e Remove \u003ccode\u003etypescript-only\u003c/code\u003e directory (\u003ca href=\"https://redirect.github.com/prettier/prettier/issues/19636\"\u003e#19636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/prettier/prettier/compare/3.9.4...3.9.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `prettier-plugin-tailwindcss` from 0.8.0 to 0.8.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/prettier-plugin-tailwindcss/releases\"\u003eprettier-plugin-tailwindcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.8.1\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDon't remove escape sequences when sorting classes in JavaScript string literals, which could produce invalid code in Vue attribute expressions (\u003ca href=\"https://redirect.github.com/tailwindlabs/prettier-plugin-tailwindcss/pull/461\"\u003e#461\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRestore class sorting in Svelte markup and dynamic \u003ccode\u003eclass={...}\u003c/code\u003e expressions when using \u003ccode\u003eprettier-plugin-svelte\u003c/code\u003e v4 (\u003ca href=\"https://redirect.github.com/tailwindlabs/prettier-plugin-tailwindcss/pull/462\"\u003e#462\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/prettier-plugin-tailwindcss/blob/main/CHANGELOG.md\"\u003eprettier-plugin-tailwindcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[0.8.1] - 2026-07-15\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDon't remove escape sequences when sorting classes in JavaScript string literals, which could produce invalid code in Vue attribute expressions (\u003ca href=\"https://redirect.github.com/tailwindlabs/prettier-plugin-tailwindcss/pull/461\"\u003e#461\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRestore class sorting in Svelte markup and dynamic \u003ccode\u003eclass={...}\u003c/code\u003e expressions when using \u003ccode\u003eprettier-plugin-svelte\u003c/code\u003e v4 (\u003ca href=\"https://redirect.github.com/tailwindlabs/prettier-plugin-tailwindcss/pull/462\"\u003e#462\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/prettier-plugin-tailwindcss/commit/fad3e0740088240af58046d9a8b05b47dd85f7b6\"\u003e\u003ccode\u003efad3e07\u003c/code\u003e\u003c/a\u003e 0.8.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/prettier-plugin-tailwindcss/commit/fc3a063f4bccbccb9c20ea757098fceefbfd8c80\"\u003e\u003ccode\u003efc3a063\u003c/code\u003e\u003c/a\u003e sync changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/prettier-plugin-tailwindcss/commit/2b6f3c23bbd6755eebae31c141b006553c3fc841\"\u003e\u003ccode\u003e2b6f3c2\u003c/code\u003e\u003c/a\u003e fix: Preserve escape sequences when sorting JS string literals (\u003ca href=\"https://redirect.github.com/tailwindlabs/prettier-plugin-tailwindcss/issues/461\"\u003e#461\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/prettier-plugin-tailwindcss/commit/410eb88e836cafe3871345e004ef2ad3eaac2e37\"\u003e\u003ccode\u003e410eb88\u003c/code\u003e\u003c/a\u003e Fix Svelte class sorting with prettier-plugin-svelte v4 (\u003ca href=\"https://redirect.github.com/tailwindlabs/prettier-plugin-tailwindcss/issues/462\"\u003e#462\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/tailwindlabs/prettier-plugin-tailwindcss/compare/v0.8.0...v0.8.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tailwindcss` from 4.3.2 to 4.3.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/tailwindcss/releases\"\u003etailwindcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.3.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003e--watch --poll[=ms]\u003c/code\u003e in \u003ccode\u003e@tailwindcss/cli\u003c/code\u003e when filesystem events are unreliable or unavailable (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20297\"\u003e#20297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCanonicalization: match arbitrary hex colors against theme colors case-insensitively (e.g. \u003ccode\u003ebg-[#fff]\u003c/code\u003e and \u003ccode\u003ebg-[#FFF]\u003c/code\u003e → \u003ccode\u003ebg-white\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20298\"\u003e#20298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent Preflight from overriding Firefox's native \u003ccode\u003eiframe:focus-visible\u003c/code\u003e outline styles (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20292\"\u003e#20292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003etheme('colors.foo')\u003c/code\u003e in JS plugins resolves correctly when both \u003ccode\u003e--color-foo\u003c/code\u003e and \u003ccode\u003e--color-foo-bar\u003c/code\u003e exist (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20299\"\u003e#20299\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure fractional opacity modifiers work with named shadow sizes like \u003ccode\u003eshadow-sm/12.5\u003c/code\u003e, \u003ccode\u003etext-shadow-sm/12.5\u003c/code\u003e, \u003ccode\u003edrop-shadow-sm/12.5\u003c/code\u003e, and \u003ccode\u003einset-shadow-sm/12.5\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20302\"\u003e#20302\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eParse selectors like \u003ccode\u003e[data-foo]div\u003c/code\u003e as two selectors instead of one (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20303\"\u003e#20303\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e@tailwindcss/postcss\u003c/code\u003e rebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20310\"\u003e#20310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure CSS nesting is handled even when Lightning CSS isn't run, such as in \u003ccode\u003e@tailwindcss/browser\u003c/code\u003e and Tailwind Play (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20124\"\u003e#20124\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent achromatic theme colors from shifting hue when mixed in polar color spaces like \u003ccode\u003eoklch\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20314\"\u003e#20314\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e--spacing(0)\u003c/code\u003e is optimized to \u003ccode\u003e0px\u003c/code\u003e instead of \u003ccode\u003e0\u003c/code\u003e so it remains a \u003ccode\u003e\u0026lt;length\u0026gt;\u003c/code\u003e when used in \u003ccode\u003ecalc(…)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20319\"\u003e#20319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eLoad \u003ccode\u003e@parcel/watcher\u003c/code\u003e only when needed in \u003ccode\u003e@tailwindcss/cli --watch\u003c/code\u003e mode, so one-off builds and \u003ccode\u003e--watch --poll\u003c/code\u003e work when \u003ccode\u003e@parcel/watcher\u003c/code\u003e can't be loaded (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20325\"\u003e#20325\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUse explicit platform fonts instead of \u003ccode\u003esystem-ui\u003c/code\u003e and \u003ccode\u003eui-sans-serif\u003c/code\u003e so CJK text respects the page's \u003ccode\u003elang\u003c/code\u003e attribute on Windows (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20318\"\u003e#20318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent \u003ccode\u003e@tailwindcss/upgrade\u003c/code\u003e from rewriting ignored files when run from a subdirectory (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20329\"\u003e#20329\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure earlier \u003ccode\u003e@source\u003c/code\u003e rules pointing to nested files are scanned when later \u003ccode\u003e@source\u003c/code\u003e rules point to files in parent folders (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20335\"\u003e#20335\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent \u003ccode\u003e@tailwindcss/vite\u003c/code\u003e from triggering full page reloads when scanned files are processed by Vite but haven't been loaded as modules yet (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20336\"\u003e#20336\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md\"\u003etailwindcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[4.3.3] - 2026-07-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003e--watch --poll[=ms]\u003c/code\u003e in \u003ccode\u003e@tailwindcss/cli\u003c/code\u003e when filesystem events are unreliable or unavailable (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20297\"\u003e#20297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCanonicalization: match arbitrary hex colors against theme colors case-insensitively (e.g. \u003ccode\u003ebg-[#fff]\u003c/code\u003e and \u003ccode\u003ebg-[#FFF]\u003c/code\u003e → \u003ccode\u003ebg-white\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20298\"\u003e#20298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent Preflight from overriding Firefox's native \u003ccode\u003eiframe:focus-visible\u003c/code\u003e outline styles (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20292\"\u003e#20292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003etheme('colors.foo')\u003c/code\u003e in JS plugins resolves correctly when both \u003ccode\u003e--color-foo\u003c/code\u003e and \u003ccode\u003e--color-foo-bar\u003c/code\u003e exist (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20299\"\u003e#20299\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure fractional opacity modifiers work with named shadow sizes like \u003ccode\u003eshadow-sm/12.5\u003c/code\u003e, \u003ccode\u003etext-shadow-sm/12.5\u003c/code\u003e, \u003ccode\u003edrop-shadow-sm/12.5\u003c/code\u003e, and \u003ccode\u003einset-shadow-sm/12.5\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20302\"\u003e#20302\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eParse selectors like \u003ccode\u003e[data-foo]div\u003c/code\u003e as two selectors instead of one (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20303\"\u003e#20303\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e@tailwindcss/postcss\u003c/code\u003e rebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20310\"\u003e#20310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure CSS nesting is handled even when Lightning CSS isn't run, such as in \u003ccode\u003e@tailwindcss/browser\u003c/code\u003e and Tailwind Play (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20124\"\u003e#20124\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent achromatic theme colors from shifting hue when mixed in polar color spaces like \u003ccode\u003eoklch\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20314\"\u003e#20314\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e--spacing(0)\u003c/code\u003e is optimized to \u003ccode\u003e0px\u003c/code\u003e instead of \u003ccode\u003e0\u003c/code\u003e so it remains a \u003ccode\u003e\u0026lt;length\u0026gt;\u003c/code\u003e when used in \u003ccode\u003ecalc(…)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20319\"\u003e#20319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eLoad \u003ccode\u003e@parcel/watcher\u003c/code\u003e only when needed in \u003ccode\u003e@tailwindcss/cli --watch\u003c/code\u003e mode, so one-off builds and \u003ccode\u003e--watch --poll\u003c/code\u003e work when \u003ccode\u003e@parcel/watcher\u003c/code\u003e can't be loaded (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20325\"\u003e#20325\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUse explicit platform fonts instead of \u003ccode\u003esystem-ui\u003c/code\u003e and \u003ccode\u003eui-sans-serif\u003c/code\u003e so CJK text respects the page's \u003ccode\u003elang\u003c/code\u003e attribute on Windows (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss/pull/20318\"\u003e#20318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent \u003ccode\u003e@tailwindcss/upgrade\u003c/code\u003e from rewriting ignored files when run from a subdirectory (\u003ca href=\"http...\n\n_Description has been truncated_","html_url":"https://github.com/devresponse/devresponsekit/pull/368","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/devresponse%2Fdevresponsekit/issues/368","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/368/packages"}},{"old_version":"7.28.0","new_version":"7.29.0","update_type":"minor","path":null,"pr_created_at":"2026-08-05T21:20:07.000Z","version_change":"7.28.0 → 7.29.0","issue":{"uuid":"5075313856","node_id":"PR_kwDORVvv5c77Sn8E","number":116,"state":"closed","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 5 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-08-07T18:40:20.000Z","author_association":null,"state_reason":null,"created_at":"2026-08-05T21:20:07.000Z","updated_at":"2026-08-07T18:40:28.000Z","time_to_close":163213,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":5,"packages":[{"name":"dompurify","old_version":"3.4.11","new_version":"3.4.13","repository_url":"https://github.com/cure53/DOMPurify"},{"name":"postcss","old_version":"8.5.15","new_version":"8.5.25","repository_url":"https://github.com/postcss/postcss"},{"name":"brace-expansion","old_version":"5.0.6","new_version":"5.0.9","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"fast-uri","old_version":"3.1.2","new_version":"3.1.5","repository_url":"https://github.com/fastify/fast-uri"},{"name":"undici","old_version":"7.28.0","new_version":"7.29.0","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 5 updates in the /resume-designer directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [dompurify](https://github.com/cure53/DOMPurify) | `3.4.11` | `3.4.13` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.15` | `8.5.25` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `5.0.6` | `5.0.9` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.2` | `3.1.5` |\n| [undici](https://github.com/nodejs/undici) | `7.28.0` | `7.29.0` |\n\n\nUpdates `dompurify` from 3.4.11 to 3.4.13\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cure53/DOMPurify/releases\"\u003edompurify's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eDOMPurify 3.4.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue with hook removal during \u003ccode\u003eIN_PLACE\u003c/code\u003e sanitization, thanks \u003ca href=\"https://github.com/koyokr\"\u003e\u003ccode\u003e@​koyokr\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue with hooks potentially bypassing the clone guard, thanks \u003ca href=\"https://github.com/AkshayjainG\"\u003e\u003ccode\u003e@​AkshayjainG\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed an issue with DOM clobbering via \u003ccode\u003eownerDocument\u003c/code\u003e during \u003ccode\u003eIN_PLACE\u003c/code\u003e, thanks \u003ca href=\"https://github.com/AkshayjainG\"\u003e\u003ccode\u003e@​AkshayjainG\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDOMPurify 3.4.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where a hook would not get called for custom elements, thanks \u003ca href=\"https://github.com/Rikuxx0\"\u003e\u003ccode\u003e@​Rikuxx0\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHardened the handling of hooks removing elements, \u003ca href=\"https://github.com/mkrause-bee360\"\u003e\u003ccode\u003e@​mkrause-bee360\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded support for a few new SVG attributes, thanks \u003ca href=\"https://github.com/cbn-falias\"\u003e\u003ccode\u003e@​cbn-falias\u003c/code\u003e\u003c/a\u003e \u0026amp; \u003ca href=\"https://github.com/Develop-KIM\"\u003e\u003ccode\u003e@​Develop-KIM\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHardened the handling of declarative partial updates\u003c/li\u003e\n\u003cli\u003eUpdated the documentation is several spots, README, wiki, etc.\u003c/li\u003e\n\u003cli\u003eBumped several dependencies where possible\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/3067f774676975de12306effd6db6ad7a9a8c17f\"\u003e\u003ccode\u003e3067f77\u003c/code\u003e\u003c/a\u003e release: 3.4.13 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1562\"\u003e#1562\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cure53/DOMPurify/commit/a9ca1e537422319a557a9a2aa61f003b23b4a197\"\u003e\u003ccode\u003ea9ca1e5\u003c/code\u003e\u003c/a\u003e release: 3.4.12 (\u003ca href=\"https://redirect.github.com/cure53/DOMPurify/issues/1537\"\u003e#1537\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cure53/DOMPurify/compare/3.4.11...3.4.13\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.15 to 8.5.25\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/08c989c43cc87edb1ed71408c2f5164c54fc21df\"\u003e\u003ccode\u003e08c989c\u003c/code\u003e\u003c/a\u003e Release 8.5.25 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/24f681471645cd960ee760ab7f9e348fbabfd42c\"\u003e\u003ccode\u003e24f6814\u003c/code\u003e\u003c/a\u003e Fix 8.5.17 visitor regression\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f2fa53f11daab3a16c7eb8bcaf5a945142341df3\"\u003e\u003ccode\u003ef2fa53f\u003c/code\u003e\u003c/a\u003e Add supply chain security requirement to PostCSS plugin guide\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/10edf0b0606f97b1510e040c27bfd078c48d6ea7\"\u003e\u003ccode\u003e10edf0b\u003c/code\u003e\u003c/a\u003e fix: return empty array for empty string in list.split (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2121\"\u003e#2121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/0ebe8ad591621ab4e48311da47a76974617571f9\"\u003e\u003ccode\u003e0ebe8ad\u003c/code\u003e\u003c/a\u003e Release 8.5.24 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/73218c64245be53e25d58150e0cc7e984f1d162d\"\u003e\u003ccode\u003e73218c6\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9a114f62b0deb37be859102f93b414b49385805a\"\u003e\u003ccode\u003e9a114f6\u003c/code\u003e\u003c/a\u003e Preserve the BOM when stringifying (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2119\"\u003e#2119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/90692619125cb9424f5eafd8c64bc76b2da23db1\"\u003e\u003ccode\u003e9069261\u003c/code\u003e\u003c/a\u003e Fix types check\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.15...8.5.25\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 5.0.6 to 5.0.9\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/fbcf8ec75b88c79374b4aac06559b1a5288a1223\"\u003e\u003ccode\u003efbcf8ec\u003c/code\u003e\u003c/a\u003e 5.0.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/f6f3939e531052d536c9066b100ad19d4175d3cc\"\u003e\u003ccode\u003ef6f3939\u003c/code\u003e\u003c/a\u003e test: cover dropping empties when only some prefixes are empty\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/688a99eeaab02627c2b89ba8ba4821fecfa659cf\"\u003e\u003ccode\u003e688a99e\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c66e5f9bce61a1c2b232cdfcc5178cd26322a979\"\u003e\u003ccode\u003ec66e5f9\u003c/code\u003e\u003c/a\u003e docs: make the maxLength example produce a non-empty result (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/137\"\u003e#137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/473d3e95e9614c783a6033f9c8577c0ba9cb6881\"\u003e\u003ccode\u003e473d3e9\u003c/code\u003e\u003c/a\u003e Bump linkify-it from 5.0.1 to 5.0.2 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/128\"\u003e#128\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/96a63c0011c0288846ad41773c73e3fbd0906b59\"\u003e\u003ccode\u003e96a63c0\u003c/code\u003e\u003c/a\u003e 5.0.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/a1bd33999ea75262c4749fff3bbb0d1372bd07b5\"\u003e\u003ccode\u003ea1bd339\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/592a36fd18455c37f81e0848a642d84c63147fa7\"\u003e\u003ccode\u003e592a36f\u003c/code\u003e\u003c/a\u003e Bump tar from 7.5.16 to 7.5.20 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/127\"\u003e#127\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/bd146909cd6c7bedde61a5d6428ba252860a0159\"\u003e\u003ccode\u003ebd14690\u003c/code\u003e\u003c/a\u003e Bump brace-expansion from 2.0.2 to 2.1.2 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/126\"\u003e#126\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/e729ba647887042f16b531fdb3d8ac3d7762ccad\"\u003e\u003ccode\u003ee729ba6\u003c/code\u003e\u003c/a\u003e Bump ws from 8.19.0 to 8.21.1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/124\"\u003e#124\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v5.0.6...v5.0.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.2 to 3.1.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/5e179cbb4636d5f773ed21126e5bd3068e87e94e\"\u003e\u003ccode\u003e5e179cb\u003c/code\u003e\u003c/a\u003e Bumped v3.1.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/2cad02d6ed428a720499bb7a3c3d6c3d41f10f5a\"\u003e\u003ccode\u003e2cad02d\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6aeece669e4166b2446a89f17c07a3b15dfb7ed4\"\u003e\u003ccode\u003e6aeece6\u003c/code\u003e\u003c/a\u003e Bumped v3.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/2d50fbabc80e4d0884fe0f6a98fe118ce6faa353\"\u003e\u003ccode\u003e2d50fba\u003c/code\u003e\u003c/a\u003e fix: reject literal backslash in URI authority\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/0549fe35b0d482233f3be2816439f3ec803603fa\"\u003e\u003ccode\u003e0549fe3\u003c/code\u003e\u003c/a\u003e Bumped v3.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/2a6d357a18a68e6d812824379fd3388a1ae50d05\"\u003e\u003ccode\u003e2a6d357\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.28.0 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/ashproto/Resume-Designer/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/ashproto/Resume-Designer/pull/116","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ashproto%2FResume-Designer/issues/116","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/116/packages"}}]}