engine
engine copied to clipboard
chore(deps): bump the npm_and_yarn group across 2 directories with 10 updates
Bumps the npm_and_yarn group with 8 updates in the / directory:
| Package | From | To |
|---|---|---|
| fastify | 4.29.0 |
4.29.1 |
| undici | 6.20.1 |
6.21.2 |
| vitest | 2.1.8 |
2.1.9 |
| js-yaml | 4.1.0 |
4.1.1 |
| pbkdf2 | 3.1.2 |
3.1.5 |
| sha.js | 2.4.11 |
2.4.12 |
| tmp | 0.2.3 |
0.2.5 |
| vite | 5.4.11 |
5.4.21 |
Bumps the npm_and_yarn group with 2 updates in the /sdk directory: brace-expansion and @babel/helpers.
Updates fastify from 4.29.0 to 4.29.1
Release notes
Sourced from fastify's releases.
v4.29.1
⚠️ Security Release ⚠️
Fix for "Invalid content-type parsing could lead to validation bypass" and CVE-2025-32442.
Full Changelog: https://github.com/fastify/fastify/compare/v4.29.0...v4.29.1
Commits
Updates undici from 6.20.1 to 6.21.2
Release notes
Sourced from undici's releases.
v6.21.2
What's Changed
- fix(types): add missing DNS interceptor by
@slagiewkain nodejs/undici#4024- [v6.x] fix wpts on windows by
@mcollinain nodejs/undici#4093- Removed clients with unrecoverable errors from the Pool nodejs/undici#4088
New Contributors
@slagiewkamade their first contribution in nodejs/undici#4024Full Changelog: https://github.com/nodejs/undici/compare/v6.21.1...v6.21.2
v6.21.1
⚠️ Security Release ⚠️
Fixes CVE CVE-2025-22150 https://github.com/nodejs/undici/security/advisories/GHSA-c76h-2ccp-4975 (embargoed until 22-01-2025).
What's Changed
- fix(#3736): back-port 183f8e9 to v6.x by
@ggoodmanin nodejs/undici#3855- fix(#3817): send servername for SNI on TLS (#3821) [backport] by
@metcoder95in nodejs/undici#3864- fix: sending formdata bodies with http2 (#3863) [backport] by
@metcoder95in nodejs/undici#3866- [Backport v6.x] fix: Fixed the issue that there is no running request when http2 goaway by
@github-actionsin nodejs/undici#3877- types: [backport] Update return type of RetryCallback (#3851) by
@metcoder95in nodejs/undici#3876Full Changelog: https://github.com/nodejs/undici/compare/v6.21.0...v6.21.1
v6.21.0
What's Changed
- [Backport v6.x] web: mark as uncloneable when possible (#3709) by
@jazellyin nodejs/undici#3744- [Backport v6.x] fetch: fix content-encoding order by
@github-actionsin nodejs/undici#3764- [Backport v6.x] fix: handle undefined deref() of WeakRef(socket) by
@github-actionsin nodejs/undici#3822- [Backport v6.x] fix: range end is zero-indexed by
@github-actionsin nodejs/undici#3827Full Changelog: https://github.com/nodejs/undici/compare/v6.20.1...v6.21.0
Commits
b63d939Bumped v6.21.2de1e4b8[v6.x] fix wpts on windows (#4093)4e07ddatest: fix windows wpt (#4050)1333871Removed clients with unrecoverable errors from the Pool (#4088)a0e76c7fix(types): add missing DNS interceptor (#4024)e260e7bBumped v6.21.1c3acc60Merge commit from fork2414bc9Update return type of RetryCallback (#3851) (#3876)be8cd0a[Backport v6.x] fix: Fixed the issue that there is no running request when ht...ee6176cfix: sending formdata bodies with http2 (#3863) [backport] (#3866)- Additional commits viewable in compare view
Updates vitest from 2.1.8 to 2.1.9
Release notes
Sourced from vitest's releases.
v2.1.9
This release includes security patches for:
- Browser mode serves arbitrary files | CVE-2025-24963
- Remote Code Execution when accessing a malicious website while Vitest API server is listening | CVE-2025-24964
🐞 Bug Fixes
- backport vitest-dev/vitest#7317 to v2 - by
@hi-ogawain vitest-dev/vitest#7318- (backport #7340 to v2) restrict served files from
/__screenshot-error- by@hi-ogawain vitest-dev/vitest#7343View changes on GitHub
Commits
c9e59a0chore: release v2.1.9e0fe1d8fix: backport #7317 to v2 (#7318)- See full diff in compare view
Updates js-yaml from 4.1.0 to 4.1.1
Changelog
Sourced from js-yaml's changelog.
[4.1.1] - 2025-11-12
Security
- Fix prototype pollution issue in yaml merge (<<) operator.
Commits
Updates pbkdf2 from 3.1.2 to 3.1.5
Changelog
Sourced from pbkdf2's changelog.
v3.1.5 - 2025-09-23
Commits
- [Fix] only allow finite iterations
67bd94d- [Fix] restore node 0.10 support
8f59d96- [Fix] check parameters before the "no Promise" bailout
d2dc5f0v3.1.4 - 2025-09-22
Commits
- [Deps] update
create-hash,ripemd160,sha.js,to-buffer8dbf49b- [meta] update repo URLs
d15bc35- [Dev Deps] update
@ljharb/eslint-configaaf870bv3.1.3 - 2025-06-20
Commits
- Only apps should have lockfiles
8b06730- [lint] fix whitespace
9a76e2f- [lint] fix parens/curlies/semis/etc
6fd84bf- [meta] add
auto-changelog796c38d- [Tests] fix tests in node 17
3661fb0- Revert "[Tests] fix tests in node < 3"
7431b57- [Tests] fix tests in node < 3
eb9f97a- [Fix] ensure unknown algorithms throw + known ones match node
26d4fd3- [Tests] add GHA, always run nyc
513906a- [lint] fix a few more rules
ab04da8- [lint] switch to eslint
89694cf- [Tests] add coverage
d0d534b- [Refactor] use
to-buffere3102a8- [readme] improve badges
fca0c9d- [Tests] remove unused travis file
a2c7d93- [meta] switch from
filestonpmignore7f31fbc- [Tests] use .nycrc
8d628e8- [Refactor] minor tweaks
fc61005- [Deps] update
create-hmac,safe-buffer,sha.jsae2a7d0- [Fix] pin
create-hash,ripemd160due to breaking changese079968- [Tests] fix tests in node 3
45fbcf3- [meta] skip publishing benchmarks
19ea57b- [Dev Deps] add missing peer dep
645e252
Commits
3687905v3.1.567bd94d[Fix] only allow finite iterations8f59d96[Fix] restore node 0.10 supportd2dc5f0[Fix] check parameters before the "no Promise" bailoutb2ad615v3.1.48dbf49b[Deps] updatecreate-hash,ripemd160,sha.js,to-bufferaaf870b[Dev Deps] update@ljharb/eslint-configd15bc35[meta] update repo URLs3e40827v3.1.3e3102a8[Refactor] useto-buffer- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by ljharb, a new releaser for pbkdf2 since your current version.
Updates sha.js from 2.4.11 to 2.4.12
Changelog
Sourced from sha.js's changelog.
v2.4.12 - 2025-07-01
Commits
- [eslint] switch to eslint
7acadfb- [meta] add
auto-changelogb46e711- [eslint] fix package.json indentation
df9d521- [Tests] migrate from travis to GHA
c43c64a- [Fix] support multi-byte wide typed arrays
f2a258e- [meta] reorder package.json
d8d77c0- [meta] add
npmignore35aec35- [Tests] avoid console logs
73e33ae- [Tests] fix tests run in batch
2629130- [Tests] drop node requirement to 0.10
00c7f23- [Dev Deps] update
buffer,hash-test-vectors,standard,tape,typedarray92b5de5- [Tests] drop node requirement to v3
9b5eca8- [meta] set engines to
>= 4807084c- Only apps should have lockfiles
c72789c- [Deps] update
inherits,safe-buffer5428cfc- [Dev Deps] update
@ljharb/eslint-config2dbe0aa- update README to reflect LICENSE
8938256- [Dev Deps] add missing peer dep
d528896- [Dev Deps] remove unused
bufferdep94ca724
Commits
eb4ea2fv2.4.12d8d77c0[meta] reorder package.jsondf9d521[eslint] fix package.json indentation35aec35[meta] addnpmignored528896[Dev Deps] add missing peer depb46e711[meta] addauto-changelog94ca724[Dev Deps] remove unusedbufferdep2dbe0aa[Dev Deps] update@ljharb/eslint-config73e33ae[Tests] avoid console logsf2a258e[Fix] support multi-byte wide typed arrays- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by ljharb, a new releaser for sha.js since your current version.
Updates tmp from 0.2.3 to 0.2.5
Commits
3d2fe38Bump up the versione162828Merge pull request #309 from fflorent/fix-tmp-dir-with-dirb847d2fFix use of tmp.dir() withdiroption08fa3abUpdate version1cf4ec5Merge commit from fork188b25eFix GHSA-52f5-9888-hmc673b9fe4Add test case for GHSA-52f5-9888-hmc6b8e2f29Remove broken tests2892a02Remove outdated URLf592318Reformat package.json- Additional commits viewable in compare view
Updates vite from 5.4.11 to 5.4.21
Release notes
Sourced from vite's releases.
v5.4.21
Please refer to CHANGELOG.md for details.
v5.4.20
Please refer to CHANGELOG.md for details.
v5.4.19
Please refer to CHANGELOG.md for details.
v5.4.18
Please refer to CHANGELOG.md for details.
v5.4.17
Please refer to CHANGELOG.md for details.
v5.4.16
Please refer to CHANGELOG.md for details.
v5.4.15
Please refer to CHANGELOG.md for details.
Changelog
Sourced from vite's changelog.
5.4.21 (2025-10-20)
- fix(dev): trim trailing slash before
server.fs.denycheck (#20968) (#20970) (cad1d31), closes #20968 #20970- chore: update CHANGELOG (ca88ed7)
5.4.20 (2025-09-08)
- fix: apply
fs.strictcheck to HTML files (#20736) (482000f), closes #20736- fix: port [email protected] changes to [email protected] (#20737) (4f1c35b), closes #20737
5.4.19 (2025-04-30)
5.4.18 (2025-04-10)
- fix: backport #19830, reject requests with
#in request-target (#19831) (823675b), closes #19830 #198315.4.17 (2025-04-03)
5.4.16 (2025-03-31)
5.4.15 (2025-03-24)
5.4.14 (2025-01-21)
... (truncated)
Commits
adce3c2release: v5.4.21cad1d31fix(dev): trim trailing slash beforeserver.fs.denycheck (#20968) (#20970)ca88ed7chore: update CHANGELOG997700frelease: v5.4.20482000ffix: applyfs.strictcheck to HTML files (#20736)80a333arelease: v5.4.19766947efix: backport #19965, check static serve file inside sirv (#19966)731b77drelease: v5.4.18823675bfix: backport #19830, reject requests with#in request-target (#19831)0a2518arelease: v5.4.17- Additional commits viewable in compare view
Updates brace-expansion from 1.1.11 to 1.1.12
Release notes
Sourced from brace-expansion's releases.
v1.1.12
- pkg: publish on tag 1.x c460dbd
- fmt ccb8ac6
- Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65) c3c73c8
https://github.com/juliangruber/brace-expansion/compare/v1.1.11...v1.1.12
Commits
Updates @babel/helpers from 7.23.2 to 7.28.4
Release notes
Sourced from @babel/helpers's releases.
v7.28.4 (2025-09-05)
Thanks
@gwillenand@mrginglymusfor your first PRs!:house: Internal
babel-core,babel-helper-check-duplicate-nodes,babel-traverse,babel-typesbabel-plugin-transform-regenerator
- #17455 chore: Clean up
transform-regenerator(@liuxingbaoyu)babel-core
- #17474 Switch to
@jridgewell/remapping(@mrginglymus)Committers: 5
- Babel Bot (
@babel-bot)- Bill Collins (
@mrginglymus)- Glenn Willen (
@gwillen)- Huáng Jùnliàng (
@JLHwung)@liuxingbaoyuv7.28.3 (2025-08-14)
:eyeglasses: Spec Compliance
babel-helper-create-class-features-plugin,babel-plugin-proposal-decorators,babel-plugin-transform-class-static-block,babel-preset-env
- #17443 [static blocks] Do not inject new static fields after static code (
@nicolo-ribaudo):bug: Bug Fix
babel-parser:nail_care: Polish
babel-plugin-transform-regenerator,babel-plugin-transform-runtime
- #17363 Do not save last yield in call in temp var (
@nicolo-ribaudo):memo: Documentation
:house: Internal
:microscope: Output optimization
babel-plugin-proposal-destructuring-private,babel-plugin-proposal-do-expressionsCommitters: 5
- Babel Bot (
@babel-bot)- Huáng Jùnliàng (
@JLHwung)- Jam Balaya (
@JamBalaya56562)- Nicolò Ribaudo (
@nicolo-ribaudo)- easrng (
@easrng)
... (truncated)
Changelog
Sourced from @babel/helpers's changelog.
v7.28.4 (2025-09-05)
:house: Internal
babel-core,babel-helper-check-duplicate-nodes,babel-traverse,babel-typesbabel-plugin-transform-regenerator
- #17455 chore: Clean up
transform-regenerator(@liuxingbaoyu)babel-core
- #17474 Switch to
@jridgewell/remapping(@mrginglymus)v7.28.3 (2025-08-14)
:eyeglasses: Spec Compliance
babel-helper-create-class-features-plugin,babel-plugin-proposal-decorators,babel-plugin-transform-class-static-block,babel-preset-env
- #17443 [static blocks] Do not inject new static fields after static code (
@nicolo-ribaudo):bug: Bug Fix
babel-parser:nail_care: Polish
babel-plugin-transform-regenerator,babel-plugin-transform-runtime
- #17363 Do not save last yield in call in temp var (
@nicolo-ribaudo):memo: Documentation
:house: Internal
:microscope: Output optimization
babel-plugin-proposal-destructuring-private,babel-plugin-proposal-do-expressionsv7.28.2 (2025-07-24)
:bug: Bug Fix
babel-types
- #17445 [babel 7] Make
operatorparam int.tsTypeOperatoroptional (@nicolo-ribaudo)babel-helpers,babel-plugin-transform-async-generator-functions,babel-plugin-transform-regenerator,babel-preset-env,babel-runtime-corejs3
- #17441 fix:
regeneratorDefinecompatibility with es5 strict mode (@liuxingbaoyu)v7.28.1 (2025-07-12)
:bug: Bug Fix
babel-plugin-transform-async-generator-functions,babel-plugin-transform-regenerator
- #17426 fix:
regeneratorcorrectly handlesthrowoutside oftry(@liuxingbaoyu):memo: Documentation
... (truncated)
Commits
35055e3v7.28.418d88b8Improve@babel/coretypings (#17471)ef155f5v7.28.3741cbd2chore: fix various typos across codebase (#17476)cac0ff4v7.28.2f743094fix:regeneratorDefinecompatibility with es5 strict mode (#17441)baa4cb8v7.27.6fdbf1b3fix:finallycauses unexpected return value (#17366)7d06930v7.27.45b9468dReduceregeneratorsize more (#17287)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the Security Alerts page.
PR-Codex overview
This PR focuses on updating various dependencies in the package.json and yarn.lock files to their latest versions, ensuring compatibility and potentially improving performance and security.
Detailed summary
- Updated
fastifyfrom^4.28.1to^4.29.1 - Updated
undicifrom^6.20.1to^6.21.2 - Updated
vitestfrom^2.0.3to^2.1.9 - Updated several Babel packages to newer versions
- Updated
brace-expansionfrom1.1.11to1.1.12 - Updated
js-yamlfrom4.1.0to4.1.1 - Updated
pbkdf2from3.1.2to3.1.5 - Updated
vite-nodefrom2.1.8to2.1.9 - Updated
vitefrom5.4.11to5.4.21 - Updated multiple
@vitestpackages from2.1.8to2.1.9 - Updated various other dependencies to their latest versions
✨ Ask PR-Codex anything about this PR by commenting with
/codex {your question}
[!IMPORTANT]
Review skipped
Bot user detected.
To trigger a single review, invoke the
@coderabbitai reviewcommand.You can disable this status message by setting the
reviews.review_statustofalsein the CodeRabbit configuration file.
Comment @coderabbitai help to get the list of available commands and usage tips.
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
| Diff | Package | Supply Chain Security |
Vulnerability | Quality | Maintenance | License |
|---|---|---|---|---|---|---|
| vitest@2.1.8 ⏵ 2.1.9 | ||||||
| undici@6.20.1 ⏵ 6.21.2 | ||||||
| fastify@4.29.0 ⏵ 4.29.1 |
This PR is stale because it has been open for 7 days with no activity. Remove stale label or comment or this PR will be closed in 3 days.
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.
To ignore these dependencies, configure ignore rules in dependabot.yml