fix(deps): update all non-major dependencies - #131
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
4 times, most recently
from
March 27, 2025 05:06
f321c69 to
69b93f0
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
April 5, 2025 20:08
a51f201 to
e329007
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
3 times, most recently
from
April 15, 2025 09:04
1fd8fbf to
2378090
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
5 times, most recently
from
April 28, 2025 09:45
ec4832b to
fc6d70b
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
May 1, 2025 01:02
fc6d70b to
3ff7c63
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
8 times, most recently
from
May 8, 2025 05:11
9f9f5d2 to
9b2c36a
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
4 times, most recently
from
May 14, 2025 21:27
c3aa263 to
a4d7e6c
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
May 19, 2025 01:23
5ff2c07 to
2c978d3
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
June 22, 2025 07:39
4ce6e0e to
245a457
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
3 times, most recently
from
June 28, 2025 11:53
8b465d9 to
ec7781a
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
3 times, most recently
from
July 8, 2025 21:54
46ea143 to
2b5909d
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
4 times, most recently
from
July 15, 2025 15:55
c32bfdc to
245d112
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
July 19, 2025 04:26
49b1d72 to
4a19b43
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
3 times, most recently
from
August 3, 2025 15:14
b977912 to
24b3e7c
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
August 15, 2025 11:25
acb94fc to
4a65639
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
August 25, 2025 11:35
2e5ef83 to
3e26107
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
September 4, 2025 10:32
d2bce67 to
848c168
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 10, 2025 22:52
848c168 to
f9a4ade
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
4 times, most recently
from
September 18, 2025 03:27
8eccf3b to
50a5d84
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.5.2→0.8.122.13.9→22.20.410.0.3→10.0.57.0.3→7.0.430.4.2→30.5.222.14.0→22.23.211.0.0→11.0.425.0.5→25.0.96.0.0→6.0.229.4.11→29.4.12Release Notes
expo/expo (@expo/plist)
v0.8.1Compare Source
This version does not introduce any user-facing changes.
v0.8.0Compare Source
This version does not introduce any user-facing changes.
v0.7.0Compare Source
🐛 Bug fixes
v0.6.1Compare Source
This version does not introduce any user-facing changes.
v0.6.0Compare Source
This version does not introduce any user-facing changes.
v0.5.4Compare Source
v0.5.3Compare Source
This version does not introduce any user-facing changes.
open-cli-tools/concurrently (concurrently)
v10.0.5Compare Source
What's Changed
New Contributors
Full Changelog: open-cli-tools/concurrently@v10.0.4...v10.0.5
v10.0.4Compare Source
What's Changed
New Contributors
Full Changelog: open-cli-tools/concurrently@v10.0.3...v10.0.4
3846masa/http-cookie-agent (http-cookie-agent)
v7.0.4Compare Source
Bug Fixes
jestjs/jest (jest)
v30.5.2Compare Source
Features
[@jest/transform]Strip TypeScript types with Node when no transformer claims a.ts,.mtsor.ctsfile (#16421)Fixes
[jest-core, jest-haste-map, jest-transform]Keeprequire('../package.json')external when bundling, sojest --versionand the transform and haste-map cache keys report the released version instead of the previous one (#16422)[jest-each]Escape a table row's keys before building the$variableinterpolationRegExp, so a column name such ascount(*)no longer fails the whole table withInvalid regular expression, and a.or|in a column name is matched literally (#16345)[@jest/source-map]Resolve absolute Windows paths in a source map'ssourcesandsourceRootagain, instead of appending them to the transformed file's directory (#16439)v30.5.1Compare Source
Fixes
[jest-config]Don't warn about global-only options in the config that supplies the global config - the root config a project resolves to, or the first entry of--projectswhen no root config is passed (#16411)[jest-config, jest-types]Stop acceptingreporters,coverageReporters,workerIdleMemoryLimit,cwdandrunnerOptionsin a project config - they were silently ignored, and now warn like the other global-only options (#16411)[jest-config, jest-validate]Warn aboutmaxWorkersandcoverageThresholdin a project config instead of dropping them without a word (#16411)[jest-resolve]MatchmoduleNameMapperpatterns against the specifier as written again (reverting #16390) (#16417)[jest-runtime]Resolve packageimportsspecifiers like#depunder ESM again (#16413)Chore & Maintenance
[jest-util]Name thetestEnvironmentOptions.globalsCleanupoption and link the docs from theJEST-01deprecation warning, and document the option's modes (#16404)v30.5.0Compare Source
Features
[@jest/expect-utils, jest-mock]AddmockFn.whenCalledWith(...args)for configuring return values per argument list, with first-class asymmetric-matcher support (#16053)[@jest/expect-utils]ExportAsymmetricMatcherandFunctionParameterstypes (previously private toexpect) (#16053)[jest-circus, jest-core, jest-jasmine2, jest-test-result, jest-types]--collectTestsnow expandstest.each/describe.eachcases and reports per-status counts (skipped/todo via the newwouldRunflag for selected tests) plus a summary line that match a real run, including under--testNamePatternand.only/fdescribefocus on both the circus and jasmine2 runners (#16259)[jest-circus, jest-environment, jest-runtime, jest-types]Add describe-level retries viajest.retryTimes(..., {entireDescribe: true})(#16322)[jest-circus, jest-message-util, jest-reporters, jest-types]AddretryMessagestoAssertionResultand exportformatErrorStack, so the retry log renders nestedcauseandAggregateErrorsections with code frames instead of serialized[cause]:/[errors]:markers (#16316)[jest-circus, jest-types]AddunhandledErrorsDetailedtoCircus.RunResult, so an unhandled rejection reports itscausechain andAggregateErrorentries with code frames instead of a pre-serialized stack (#16316)[jest-haste-map]ReplaceNodeWatcherandFSEventsWatcherwith@parcel/watcherfor the non-watchman watch path (#16188)[jest-resolve]Bumpunrs-resolverto 1.12.1, removejest-pnp-resolverand unnecessary checks (#15721)[jest-resolve]Honor Node's--preserve-symlinks/NODE_PRESERVE_SYMLINKSin the default resolver by passingsymlinks: falsetounrs-resolver(#16260)[jest-runtime]Apply automocking and manual__mocks__files to synchronously evaluable ESM graphs on Node 24.9+ - static imports, dynamicimport()andrequire()of an ESM file now generate an automock from the real module's namespace instead of failing with "Attempting to import a mock without a factory". Graphs that need async evaluation (top-level await) or an async-only resolver or transformer still throw (#16391)[jest-runtime]Routeprocess.getBuiltinModulethrough the sandbox, so it returns the sandboxprocessand the hookednode:moduleinstead of the host's (#16391)[jest-runtime]Throw an actionable error frommodule.register()andmodule.registerHooks()inside a test - the hooks attached to the loader running Jest itself, never saw the sandboxed requires they were meant for, and stayed registered for every later test file in the worker (#16391)[jest-runtime]Surface resolution and import-attribute errors in an ESM graph before executing any of its CJS dependencies on Node 24.9+, matching Node's run-nothing-on-a-broken-graph behavior; the legacy loader on older versions keeps its linking-time execution order (#16391)[jest-runtime]ThrowERR_SOURCE_PHASE_NOT_DEFINEDwith an actionable message forimport sourceandimport.source(), instead of failing at instantiation with V8's bare "Source phase import object is not defined" (#16391)[jest-runtime]Emit the JSON-without-import-attribute deprecation warning once per test file instead of once per worker, so it is no longer silently swallowed for every file after the first (#16391)[jest-runtime]Setimport.meta.maintotruein the test file andfalsein every module it loads, matching Node 24+ (#16367)[jest-runtime]Resolve themodule-syncexport condition, so a package that exposes its ESM entry point forrequire()loads the same file Node would (#16336)[jest-snapshot]Add external snapshot paths to custom reporter failure details (#16374)Fixes
[jest-console, jest-reporters]CustomConsolenow buffers console output soTestResult.consoleis populated for reporters whenverboseis enabled, whileGitHubActionsReporteravoids replaying buffered output in verbose mode (#16155)[expect, jest-message-util, jest-pattern, jest-regex-util, jest-util]Revertnode:protocol imports to restore webpack/browser-bundle compatibility (#16167)[expect]WidentoMatchObjectandobjectContainingparameter type fromRecord<string, unknown>toobjectso class instances are accepted (#16196)[jest-circus]Call a generator test body with the shared test context, sothismatches what a regular test function receives (#16347)[jest-circus]Capture the error listeners of the parent process instead of the in-sandboxprocess, so listeners registered before the test file survive teardown and sandbox listeners no longer leak onto the parent (#16347)[jest-circus]ClearcurrentlyRunningTestafter skipped and todo tests (#16342)[jest-circus]Prevent latedone()callbacks from affecting later test or hook invocations (#16343)[jest-circus, jest-jasmine2]Honor--expandwhen formattingnode:assertfailures, instead of always collapsing the diff (#16347)[jest-circus, jest-jasmine2, jest-message-util]Serialize the inner errors of anAggregateErrorintofailureMessages,retryReasonsandunhandledErrors, so--jsonoutput and reporter annotations include them (#16316)[jest-circus, jest-snapshot]Keep snapshot state and counts correct when a test retries (#16344)[@jest/create-cache-key-function]Include the caller support flags in the generated key, so a transformer that emits ESM or CJS based on them no longer shares one cache entry between the two (#16331)[@jest/create-cache-key-function]Include the stringified project config in the generated key, so editing a transformer's own settings invalidates what it cached (#16331)[@jest/transform]Include the caller support flags in a transform's cache key, so a file transformed both as ESM and as CJS no longer serves one shape's output for the other (#16331)[jest-config]Add missingfindRelatedTests,outputFile, andreplnameentries toValidConfigso they no longer trigger spurious "Unknown option" warnings (#16224)[jest-config]Use--configfor the global config when multiple--projectsare specified (#16273)[jest-core]Serializebigintvalues in--jsonand--outputFileoutput as their literal form (4n), instead of failing the run withTypeError: Do not know how to serialize a BigInt(#16338)[jest-core]Do not report aCustomGCasync resource (used by N-API addons such as napi-rs for per-isolate GC bookkeeping) as an open handle, since it isnapi_unref'd by the addon and can never keep the event loop alive (#16379)[jest-each]Keep a$&,$`,$'or$$inside a%pparam value out of the replacement, so the title shows the value instead of the text around it (#16338)[jest-each]Interpolate abigintinto a%jtitle as its literal form ("4n") at any depth, instead of throwingTypeError: Do not know how to serialize a BigIntwhile collecting the tests (#16338)[jest-environment, jest-runtime]BindsandboxInjectedGlobalsto the right values wheninjectGlobalsisfalse, instead of shifting every one of them by a position (#16377)[jest-environment-node, jest-util]Only warn about a conflictingglobalsCleanupmode when one was explicitly configured, and follow the mode that is actually in effect (#16323)[jest-environment-node, jest-util]Stop resolving lazy globals when setting up an environment, so Node 26's builtin module globals are no longer loaded (and no longer emit their deprecation warnings) for every test file (#16324)[jest-haste-map]Keep watch mode alive when an outside process briefly makes a file unreadable on Windows, instead of tearing the watcher down onEPERM(#16295)[jest-haste-map]Keep indexing when an outside process holds a file open on Windows, instead of failing the whole crawl onEPERM(#16358)[jest-haste-map]Keep a duplicated manual mock resolving when the file it pointed at is deleted in watch mode (#16360)[jest-haste-map]Shut the worker farm down when a duplicate manual mock aborts the build underthrowOnModuleCollision(#16354)[jest-haste-map]Attach the watchman client'serrorlistener before the first command, so a watchman failure falls back to the node crawler instead of crashing on an unhandlederrorevent, and always end the client (#16355)[jest-haste-map]Stop delivering watch events afterWatchmanWatcheris closed, and route its warnings through the configured console (#16355)[jest-haste-map]Restore the nestedduplicatesindex correctly inModuleMap.fromJSON, so a haste collision reported inside a test worker raisesDuplicateHasteCandidatesErrorinstead of aTypeError(#16353)[jest-haste-map]Match watched files on a full extension, somoduleFileExtensions: ['js']no longer acceptsfoo.mjs(#16352)[jest-haste-map]Delimit the fields that make up the haste map cache key, so two different option sets cannot hash to the same cache file (#16352)[jest-message-util]Print the inner errors of anAggregateErrorthrown inside a test (#16316)[jest-message-util]Indent nestedcauseandAggregateErrorsections of a test failure by one level per depth, so the nesting is legible instead of rendering flat (#16316)[jest-message-util]Color stack traces line by line so blank lines stay blank (#16316)[jest-message-util]Detect Jest's own frames without assuming the checkout directory's name, and cover@jest/*packages, so stack traces and code frames point at user code (#16326)[jest-mock]mockResolvedValue/mockRejectedValuenow see all overload return types, so a Promise-returning overload survives even when a later overload returns a non-Promise (e.g.pg.Client['end']) (#16237)[@jest-environment/jsdom-abstract]Make@types/jsdoma peer dependency (#16166)[jest-mock]Remove the leftover own accessor descriptor when restoring aspyOnof an inherited getter or setter, so the instance keeps reflecting the prototype (#16226)[jest-resolve]IncludeextensionsToTreatAsEsmin theshouldLoadAsEsmcache key, so projects with different extension lists don't read each other's answers (#16369)[jest-resolve]MakegetModuleIDAsyncbuild and cachedata:URI module IDs the same way asgetModuleID(#16370)[jest-resolve]Keep thenode:prefix when resolving a core module asynchronously, so a builtin that only exists prefixed (node:sea,node:sqlite,node:test,node:test/reporters) resolves instead of failing as a missing bare package (#16388)[jest-resolve]Look up manual mocks fornode:protocol specifiers under the unprefixed name they are stored as (#16388)[jest-resolve]ApplymoduleNameMapperconsistently to both spellings of core module specifiers (fsvsnode:fs) (#16390)[jest-resolve]Keep virtual and ordinary mock module IDs isolated across test files (#16296)[jest-resolve]Guard missingrequire.resolve.paths(#16052)[jest-resolve, jest-config, jest-runner]Support a user resolver written as an ES module (#16332)[jest-resolve, jest-runtime]Throw the CJS parse error for ESM syntax in a"type": "commonjs"package or a.cjsfile instead of loading it as ESM, matching Node (#16368)[@jest/source-map]Keep source map sources that name a scheme, such aswebpack:///, instead of resolving them into a path that does not exist (#16327)[@jest/source-map]Look up--testLocationInResultspositions at the right column, and keep a mapping to the first column instead of discarding it (#16327)[@jest/source-map]Warn when a source map cannot be parsed, instead of silently leaving its frames untranslated (#16327)[jest-runner, @jest/source-map]Keep a source-mapped stack for an error thrown after the test environment was torn down (#16327)[jest-runtime, @jest/source-map]Keep source maps past teardown and past the next test file'sinstall, so a stack from a file no earlier stack mentioned still points at the original source (#16330)[jest-runtime]Report that no coverage was collected whengetAllV8CoverageInfoCopyis called afterteardown, instead of returning an empty result (#16385)[jest-runtime]Cache a CJS module's parsed exports before walking its re-exports, so two modules that re-export each other no longer overflow the stack when imported from ESM (#16363)[jest-runtime]Keep a re-exported ES module's parse failure from marking the re-exporting CommonJS file as ESM, somodule.exports = require('./dep.mjs')loads instead of failing withmodule is not defined(#16363)[jest-runtime]Scope module mocks instantiated insidejest.isolateModules/isolateModulesAsyncto that block, so a mock first imported there no longer outlives it - matching how CommonJS mocks already behave (#16365)[jest-runtime]Suspend module isolation while generating an automock, so loading the real module to read its shape no longer populates the isolated registry (#16365)[jest-runtime]Check a cached ES module's status beforerequire()returns it, so a module whose evaluation threw rethrows that error and one left linked by a failed sibling is evaluated instead of returning uninitialized bindings (#16364)[jest-runtime]Report the originalERR_REQUIRE_ASYNC_MODULEwhen arequire()of a top-level-await graph is retried, instead of a spurious "concurrentimport()" error (#16364)[jest-runtime]Throw the evaluation error when another caller'simport()of the same module failed while we awaited it, instead of resolving with the errored module (#16364)[jest-runtime]Mark the result ofrequire()ing an ES module that has a default export with__esModule: truethrough a live-binding facade, and serve the same object fromrequire.cache, matching Node (#16367)[jest-runtime]Provide a CommonJS module's exports under the'module.exports'named export when imported from ESM, matching Node 23+ (#16367)[jest-runtime]Give the test file itself a non-nullrequire.main(#16367)[jest-runtime]Populatemodule.childrenwith the modules a file loads, matching Node (#16368)[jest-runtime]Provideimport.meta.resolveandimport.meta.jestindata:URI modules, accept any-case mediatype parameters, and use Node's error codes for invaliddata:URIs (#16368)[jest-runtime]Key ES modules by full URL, so query and fragment suffixes create the same module instances as Node and show up inimport.meta.url(#16375)[jest-runtime]Share modules between overlapping graphs when a CommonJS modulerequire()s an ES module mid-load, instead of evaluating shared dependencies twice (#16375)[jest-runtime]ThrowERR_REQUIRE_CYCLE_MODULElike Node when a CommonJS modulerequire()s an ES module that is still being loaded, instead of evaluating the module a second time (#16366)[jest-runtime]Key builtin modules in the ESM registry by one canonical specifier (#16341)[jest-runtime]import.meta.resolve()for a builtin uses itsnode:specifier (#16341)[jest-runtime]Fall back to native ESM when a.jsfile contains ESM syntax but has no"type":"module"marker (#16152)[jest-runtime]Allowrequire()of ESM-marked files on Node < 24.9 via transform fallback (#16244)[jest-runtime, @jest/transform]Surface actionableERR_REQUIRE_ESMerror for files with untransformed ESM syntax instead of the generic "unexpected token" message (#16244)[jest-runtime]Support older test environments whosemoduleMockerdoes not implementclearMocksOnScope(#16169)[jest-runtime]Applyjest.unstable_mockModulewhen the mocked file itself isrequire()d, not only when it is imported as a dependency (#16389)[jest-runtime]Applyjest.unstable_mockModuleto statically importeddata:URIs on Node 24.9+, matching dynamicimport()(#16389)[jest-runtime]Run an asyncjest.unstable_mockModulefactory once per module instead of twice, and fail the import instead of crashing the worker when the factory rejects (#16389)[jest-runtime]Hide arequire(esm)module that failed to evaluate fromrequire.cache, as Node does, instead of exposing a namespace with uninitialized bindings (#16389)[jest-runtime]Strip the byte-order mark when importing a JSON module, matchingrequire()and Node (#16389)[jest-runtime]ThrowERR_REQUIRE_ASYNC_MODULEwhenrequire(esm)runs under an async-only custom resolver, instead of silently resolving with the default resolver (#16389)[jest-runtime]Parse imported JSON modules with the test realm'sJSON, so their objects passinstanceof Objectinside the test likerequire()d JSON does (#16389)[jest-runtime]Accept everyfile:URL string in the sandboxedmodule.createRequire, including one with alocalhostauthority, as Node does (#16389)[jest-runtime]Point at{virtual: true}whenjest.mockorjest.unstable_mockModuleis given a module that cannot be resolved (#16389)[jest-reporters]Fix coverage report table formatting in CI/GitHub Actions environments whereprocess.stdout.columnsis undefined by falling back to theCOLUMNSenv var or80columns in CI, preserving existing behaviour in other non-TTY environments (#16227)[jest-runtime]Support CJS-in-ESM exports via"module.exports"named exports (#16277)[jest-snapshot]Keep a skipped or failed test's hinted snapshots, instead of reporting them obsolete (#16348)[jest-util]StopglobsToMatcherreusing a cached matcher compiled with different picomatch options, and keep itsdot: truedefault whendotis passed asundefined(#16381)[pretty-format]Move thereact-isaliases into the@jestscope, so they cannot be shadowed by unrelated packages published under the alias names (#16333)Chore & Maintenance
[docs]Document the intentional divergences from Node's module system in the ECMAScript Modules page (#16368)[docs]Note deprecation ofreact-test-rendererin React Native tutorial andpretty-formatREADME (#16294)[docs]Use@testing-library/react-nativein the React Native tutorial instead of the deprecatedreact-test-renderer(#16318)[babel-jest, @jest/transform]Updatebabel-plugin-istanbulto v8 (#16049)[jest-config, @jest/reporters, jest-runtime]Updateglobto v13 (#16397)[jest-haste-map]Refactor massive class into multiple files (#16180)[jest-haste-map]Dropwalkerdependency; replace hand-rolled directory recursion in the JS crawler and watcher startup withfdir(#16187)[jest-haste-map]Reuse cached metadata for files whose haste name is a known duplicate, instead of re-reading and re-parsing them on every startup (#16351)[jest-haste-map]Cache the watchman socket path and replace thewatchman --versionprobe withget-sockname, so warm runs spawn no watchman processes (#16386)[jest-resolve]Store the per-directory package-type lookup in the cache it reads, so it actually memoizes (#16369)[jest-resolve, jest-runtime]Cut repeated work on the resolution hot path: hoist the platform-extension list to construction, memoizeisCoreModuleand the options cache-key serialization, skip mapper preparation when nomoduleNameMapperis configured, run each mapper regex once, and stop re-parsingNODE_OPTIONSon every default-resolver call (#16371)[jest-resolve]Cut warm resolution cost to about a third: reuse oneunrs-resolverfactory per options shape instead of cloning per resolution, compose the factory cache key from per-array cached strings instead of serializing options, and stop constructing anErrorfor misses thatfindNodeModuleswallows; add a__benchmarks__suite for the default resolver (#16373)[jest-runner, @jest/source-map]Replacesource-map-supportwith an implementation in@jest/source-map(#16327)[jest-snapshot]Load babel, semver and synckit lazily, so requiring the package (which every test process does through@jest/expect) no longer loads ~200 modules that only writing inline snapshots needs (#16387)[jest-runtime]Reduce per-require overhead: skip module ID resolution when no mock can apply, answer core modules before probing for a manual mock, share onerequire.cacheproxy across modules, and cache empty files (#16376)[@jest/source-map]DeprecategetCallsitein favour ofSourceMapSupport#getCallsite(#16327)[jest-runtime]Avoid magicalnullvalue in ESM loader (#16160)nodejs/node (node)
v22.23.2: 2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolitoCompare Source
This is a security release.
Notable Changes
Commits
4b12ac38a1] - deps: update llhttp to 9.4.3 (Paolo Insogna) nodejs-private/node-private#9353fd0aa51d0] - deps: update undici to 6.28.0 (Node.js GitHub Bot) #6471422efc051a3] - (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) nodejs-private/node-private#929c8525ac3a6] - (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) nodejs-private/node-private#932daa6d25e3d] - (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) nodejs-private/node-private#921f14d78b9e0] - (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) #6375251123159fe] - (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) nodejs-private/node-private#934acaf4266b2] - (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) nodejs-private/node-private#930440329f624] - (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) nodejs-private/node-private#911ed18b9cc07] - (CVE-2026-58039) permission: check final report output path (RafaelGSS) nodejs-private/node-private#9260566c3cccd] - (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) nodejs-private/node-private#9270d072480c3] - (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) nodejs-private/node-private#931v22.23.1: 2026-06-23, Version 22.23.1 'Jod' (LTS), @RafaelGSSCompare Source
This release includes a fix for an unexpected behavior introduced
by the recent security release (22.23.0).
Commits
41d2ee13be] - build: switch coverage-windows towindows-2022(Richard Lau) #63940eaa292549e] - http: avoid stream listeners on idle agent sockets (Matteo Collina) #64004v22.23.0: 2026-06-18, Version 22.23.0 'Jod' (LTS), @aduh95Compare Source
This is a security release.
Notable Changes
Commits
38b4c5ed51] - (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) nodejs-private/node-private#878ad8a10c1bb] - deps: update llhttp to 9.4.2 (Antoine du Hamel) nodejs-private/node-private#890ca825a87cc] - deps: update undici to 6.27.0 (aduh95) #63711a1a5bb9683] - (CVE-2026-48937) deps: fix integration issues with the latest nghttp2 (Tim Perry) #628910f48583512] - (SEMVER-MAJOR) deps: update nghttp2 to 1.69.0 (Node.js GitHub Bot) #6289138c869fc05] - deps: update nghttp2 to 1.68.0 (nodejs-github-bot) #61136290667c84f] - deps: update nghttp2 to 1.67.1 (nodejs-github-bot) #59790c9f3da76aa] - deps: update nghttp2 to 1.66.0 (Node.js GitHub Bot) #5878660890be563] - deps: update nghttp2 to 1.65.0 (Node.js GitHub Bot) #572695024c7d5d8] - deps: update archs files for openssl-3.5.7 (Node.js GitHub Bot) #638207f4eb5af2e] - deps: upgrade openssl sources to openssl-3.5.7 (Node.js GitHub Bot) #63820ebb4ec78a8] - deps: fix aix implicit declaration in OpenSSL (Abdirahim Musse) #626565763d40826] - deps: update llhttp to 9.4.1 (Node.js GitHub Bot) #63045c551a51d0c] - (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) nodejs-private/node-private#8680a22d40180] - (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) nodejs-private/node-private#846c79968e108] - (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) nodejs-private/node-private#8550c37bff2ff] - http2: fix DEP0194 message (KaKa) #58669ea5dc6b529] - (SEMVER-MAJOR) http2: remove support for priority signaling (Matteo Collina) #582939b6af26132] - (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) nodejs-private/node-private#86728dcd38864] - (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) nodejs-private/node-private#8732f62693801] - (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) nodejs-private/node-private#8701662a3ea09] - test: add session reuse host verification regressions (Matteo Collina) nodejs-private/node-private#854718d5d0e2c] - test: skiptest-fs-utimes-y2K38on armv7 (Richard Lau) #63836041185b61f] - test: skip test-cluster-dgram-reuse on AIX 7.3 (Stewart X Addison) #62238fd890ba01d] - (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) nodejs-private/node-private#85439d1d09684] - (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) nodejs-private/node-private#8572197a47144] - (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) nodejs-private/node-private#869v22.22.3: 2026-05-13, Version 22.22.3 'Jod' (LTS), @marco-ippolitoCompare Source
Commits
4f780905c5] - crypto: fix potential null pointer dereference when BIO_meth_new() fails (Nora Dossche) #617884a09efb947] - crypto: update root certificates to NSS 3.121 (Node.js GitHub Bot) #62485e4c0d99839] - deps: update timezone to 2026a (Node.js GitHub Bot) #621640226c8dd7a] - deps: update simdjson to 4.5.0 (Node.js GitHub Bot) #62382e742ab748c] - deps: update sqlite to 3.51.3 (Node.js GitHub Bot) #6225673cac0571a] - deps: update amaro to 1.1.8 (Node.js GitHub Bot) #62151ae5c162b93] - deps: update amaro to 1.1.7 (Node.js GitHub Bot) #61730b819cb9977] - deps: update amaro to 1.1.6 (Node.js GitHub Bot) #61603bbcce09dc7] - deps: update sqlite to 3.52.0 (Node.js GitHub Bot) #6215022ff2d81ce] - deps: update simdjson to 4.3.1 (Node.js GitHub Bot) #61930f49b51d75c] - deps: update acorn-walk to 8.3.5 (Node.js GitHub Bot) #619281a5cec0d49] - deps: update acorn to 8.16.0 (Node.js GitHub Bot) #61925d339497688] - deps: update nbytes to 0.1.3 (Node.js GitHub Bot) #618793ff8ffd459] - deps: remove stale OpenSSL arch configs (René) #61834b8ddbc1e9a] - **depConfiguration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.