Skip to content

Commit e4401fb

Browse files
🧺 chore(deps): update all non-major dependencies (#25)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | Type | Update | Pending | |---|---|---|---|---|---|---| | [@commitlint/types](https://commitlint.js.org/) ([source](https://redirect.github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/types)) | [`^20.4.3` → `^20.5.0`](https://renovatebot.com/diffs/npm/@commitlint%2ftypes/20.4.3/20.5.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@commitlint%2ftypes/20.5.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@commitlint%2ftypes/20.4.3/20.5.0?slim=true) | devDependencies | minor | | | [actions/cache](https://redirect.github.com/actions/cache) | `v5.0.3` → `v5.0.4` | ![age](https://developer.mend.io/api/mc/badges/age/github-tags/actions%2fcache/v5.0.4?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/github-tags/actions%2fcache/v5.0.3/v5.0.4?slim=true) | action | patch | `v5.0.5` | | [actions/create-github-app-token](https://redirect.github.com/actions/create-github-app-token) | `v2.2.1` → `v2.2.2` | ![age](https://developer.mend.io/api/mc/badges/age/github-tags/actions%2fcreate-github-app-token/v2.2.2?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/github-tags/actions%2fcreate-github-app-token/v2.2.1/v2.2.2?slim=true) | action | patch | | | [actions/dependency-review-action](https://redirect.github.com/actions/dependency-review-action) | `v4.8.3` → `v4.9.0` | ![age](https://developer.mend.io/api/mc/badges/age/github-tags/actions%2fdependency-review-action/v4.9.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/github-tags/actions%2fdependency-review-action/v4.8.3/v4.9.0?slim=true) | action | minor | | | [github/codeql-action](https://redirect.github.com/github/codeql-action) | `v4.32.5` → `v4.35.1` | ![age](https://developer.mend.io/api/mc/badges/age/github-tags/github%2fcodeql-action/v4.35.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/github-tags/github%2fcodeql-action/v4.32.5/v4.35.1?slim=true) | action | minor | `v4.35.2` | | [jdx/mise-action](https://redirect.github.com/jdx/mise-action) | `v3.6.2` → `v3.6.3` | ![age](https://developer.mend.io/api/mc/badges/age/github-tags/jdx%2fmise-action/v3.6.3?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/github-tags/jdx%2fmise-action/v3.6.2/v3.6.3?slim=true) | action | patch | | | [step-security/harden-runner](https://redirect.github.com/step-security/harden-runner) | `v2.15.0` → `v2.17.0` | ![age](https://developer.mend.io/api/mc/badges/age/github-tags/step-security%2fharden-runner/v2.17.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/github-tags/step-security%2fharden-runner/v2.15.0/v2.17.0?slim=true) | action | minor | `v2.18.0` | | [undici](https://undici.nodejs.org) ([source](https://redirect.github.com/nodejs/undici)) | [`^7.22.0` → `^7.24.8`](https://renovatebot.com/diffs/npm/undici/7.22.0/7.24.8) | ![age](https://developer.mend.io/api/mc/badges/age/npm/undici/7.24.8?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/undici/7.22.0/7.24.8?slim=true) | overrides | minor | `7.25.0` | --- ### Release Notes <details> <summary>conventional-changelog/commitlint (@&#8203;commitlint/types)</summary> ### [`v20.5.0`](https://redirect.github.com/conventional-changelog/commitlint/blob/HEAD/@&#8203;commitlint/types/CHANGELOG.md#2050-2026-03-15) [Compare Source](https://redirect.github.com/conventional-changelog/commitlint/compare/v20.4.4...v20.5.0) ##### Features - **cz-commitlint:** add exclamation mark support for breaking changes ([#&#8203;4655](https://redirect.github.com/conventional-changelog/commitlint/issues/4655)) ([3b124a7](https://redirect.github.com/conventional-changelog/commitlint/commit/3b124a78000dc2ad353884b72db5ba0c78a642a3)) #### [20.4.4](https://redirect.github.com/conventional-changelog/commitlint/compare/v20.4.3...v20.4.4) (2026-03-12) ##### Bug Fixes - **types:** allow context parameter in QualifiedRuleConfig functions ([#&#8203;4636](https://redirect.github.com/conventional-changelog/commitlint/issues/4636)) ([17537ae](https://redirect.github.com/conventional-changelog/commitlint/commit/17537ae05f3402f3b196d5a8cb92ae7207af8ba5)), closes [#&#8203;4357](https://redirect.github.com/conventional-changelog/commitlint/issues/4357) #### [20.4.3](https://redirect.github.com/conventional-changelog/commitlint/compare/v20.4.2...v20.4.3) (2026-03-03) ##### Bug Fixes - footer parser does not escape special chars for regex [#&#8203;4560](https://redirect.github.com/conventional-changelog/commitlint/issues/4560) ([#&#8203;4634](https://redirect.github.com/conventional-changelog/commitlint/issues/4634)) ([8ff7c7f](https://redirect.github.com/conventional-changelog/commitlint/commit/8ff7c7fcbc2db2b45910ecb5c01e9f1763060770)) - **types:** incorrect types for rule options ([#&#8203;4633](https://redirect.github.com/conventional-changelog/commitlint/issues/4633)) ([77b85f2](https://redirect.github.com/conventional-changelog/commitlint/commit/77b85f24d3858161d076078d333c96909e6136f8)) ### [`v20.4.4`](https://redirect.github.com/conventional-changelog/commitlint/blob/HEAD/@&#8203;commitlint/types/CHANGELOG.md#2044-2026-03-12) [Compare Source](https://redirect.github.com/conventional-changelog/commitlint/compare/v20.4.3...v20.4.4) ##### Bug Fixes - **types:** allow context parameter in QualifiedRuleConfig functions ([#&#8203;4636](https://redirect.github.com/conventional-changelog/commitlint/issues/4636)) ([17537ae](https://redirect.github.com/conventional-changelog/commitlint/commit/17537ae05f3402f3b196d5a8cb92ae7207af8ba5)), closes [#&#8203;4357](https://redirect.github.com/conventional-changelog/commitlint/issues/4357) </details> <details> <summary>actions/cache (actions/cache)</summary> ### [`v5.0.4`](https://redirect.github.com/actions/cache/compare/v5.0.3...v5.0.4) [Compare Source](https://redirect.github.com/actions/cache/compare/v5.0.3...v5.0.4) </details> <details> <summary>actions/create-github-app-token (actions/create-github-app-token)</summary> ### [`v2.2.2`](https://redirect.github.com/actions/create-github-app-token/releases/tag/v2.2.2) [Compare Source](https://redirect.github.com/actions/create-github-app-token/compare/v2.2.1...v2.2.2) ##### Bug Fixes - **deps:** bump [@&#8203;actions/core](https://redirect.github.com/actions/core) from 1.11.1 to 3.0.0 ([#&#8203;337](https://redirect.github.com/actions/create-github-app-token/issues/337)) ([b044133](https://redirect.github.com/actions/create-github-app-token/commit/b04413352d4644ac2131b9a90c074f5e93ca18a1)) - **deps:** bump minimatch from 9.0.5 to 9.0.9 ([#&#8203;335](https://redirect.github.com/actions/create-github-app-token/issues/335)) ([5cbc656](https://redirect.github.com/actions/create-github-app-token/commit/5cbc65624c9ddc4589492bda7c8b146223e8c3e4)) - **deps:** bump the production-dependencies group with 4 updates ([#&#8203;336](https://redirect.github.com/actions/create-github-app-token/issues/336)) ([6bda5bc](https://redirect.github.com/actions/create-github-app-token/commit/6bda5bc1410576b9a0879ce6076d53345485bba9)) - **deps:** bump undici from 7.16.0 to 7.18.2 ([#&#8203;323](https://redirect.github.com/actions/create-github-app-token/issues/323)) ([b4f638f](https://redirect.github.com/actions/create-github-app-token/commit/b4f638f48ee0dcdbb0bc646c48e4cb2a2de847fe)) </details> <details> <summary>actions/dependency-review-action (actions/dependency-review-action)</summary> ### [`v4.9.0`](https://redirect.github.com/actions/dependency-review-action/releases/tag/v4.9.0): Dependency Review Action 4.9.0 [Compare Source](https://redirect.github.com/actions/dependency-review-action/compare/v4.8.3...v4.9.0) This feature release contains a couple of notable changes: - There is a new configuration option `show_patched_versions` which will add a column to the output, showing the fix version of each vulnerable dependency. Thanks [@&#8203;felickz](https://redirect.github.com/felickz)! - Runs which do not display OpenSSF scorecards no longer fetch scorecard information; previously it was fetched regardless of whether or not it was displayed, causing unneccessary slowness. Great catch [@&#8203;jantiebot](https://redirect.github.com/jantiebot)! - There are a couple of fixes to purl parsing which should improve match accuracy for `allow-package-dependency` lists, including case (in)sensitivity and url-encoded namespaces Thanks [@&#8203;juxtin](https://redirect.github.com/juxtin)! #### What's Changed - Compare normalized purls to account for encoding quirks by [@&#8203;juxtin](https://redirect.github.com/juxtin) in [#&#8203;1056](https://redirect.github.com/actions/dependency-review-action/pull/1056) - Make purl comparisons case insensitive by [@&#8203;juxtin](https://redirect.github.com/juxtin) in [#&#8203;1057](https://redirect.github.com/actions/dependency-review-action/pull/1057) - Feat: Add `Patched Version` to `Vulnerabilities` summary by [@&#8203;felickz](https://redirect.github.com/felickz) in [#&#8203;1045](https://redirect.github.com/actions/dependency-review-action/pull/1045) - fix: only get scorecard levels if user wants to see the OpenSSF scorecard by [@&#8203;jantiebot](https://redirect.github.com/jantiebot) in [#&#8203;1060](https://redirect.github.com/actions/dependency-review-action/pull/1060) - Bump actions/stale from 10.1.0 to 10.2.0 by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;1058](https://redirect.github.com/actions/dependency-review-action/pull/1058) - Bump actions/checkout from 4 to 6 by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;1021](https://redirect.github.com/actions/dependency-review-action/pull/1021) - Updates for release 4.9.0 by [@&#8203;ahpook](https://redirect.github.com/ahpook) in [#&#8203;1064](https://redirect.github.com/actions/dependency-review-action/pull/1064) #### New Contributors - [@&#8203;jantiebot](https://redirect.github.com/jantiebot) made their first contribution in [#&#8203;1060](https://redirect.github.com/actions/dependency-review-action/pull/1060) **Full Changelog**: <actions/dependency-review-action@v4.8.3...v4.9.0> </details> <details> <summary>github/codeql-action (github/codeql-action)</summary> ### [`v4.35.1`](https://redirect.github.com/github/codeql-action/releases/tag/v4.35.1) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v4.35.0...v4.35.1) - Fix incorrect minimum required Git version for [improved incremental analysis](https://redirect.github.com/github/roadmap/issues/1158): it should have been 2.36.0, not 2.11.0. [#&#8203;3781](https://redirect.github.com/github/codeql-action/pull/3781) ### [`v4.35.0`](https://redirect.github.com/github/codeql-action/releases/tag/v4.35.0) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v4.34.1...v4.35.0) - Reduced the minimum Git version required for [improved incremental analysis](https://redirect.github.com/github/roadmap/issues/1158) from 2.38.0 to 2.11.0. [#&#8203;3767](https://redirect.github.com/github/codeql-action/pull/3767) - Update default CodeQL bundle version to [2.25.1](https://redirect.github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.1). [#&#8203;3773](https://redirect.github.com/github/codeql-action/pull/3773) ### [`v4.34.1`](https://redirect.github.com/github/codeql-action/releases/tag/v4.34.1) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v4.34.0...v4.34.1) - Downgrade default CodeQL bundle version to [2.24.3](https://redirect.github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3) due to issues with a small percentage of Actions and JavaScript analyses. [#&#8203;3762](https://redirect.github.com/github/codeql-action/pull/3762) ### [`v4.34.0`](https://redirect.github.com/github/codeql-action/releases/tag/v4.34.0) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v4.33.0...v4.34.0) - Added an experimental change which disables TRAP caching when [improved incremental analysis](https://redirect.github.com/github/roadmap/issues/1158) is enabled, since improved incremental analysis supersedes TRAP caching. This will improve performance and reduce Actions cache usage. We expect to roll this change out to everyone in March. [#&#8203;3569](https://redirect.github.com/github/codeql-action/pull/3569) - We are rolling out improved incremental analysis to C/C++ analyses that use build mode `none`. We expect this rollout to be complete by the end of April 2026. [#&#8203;3584](https://redirect.github.com/github/codeql-action/pull/3584) - Update default CodeQL bundle version to [2.25.0](https://redirect.github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.0). [#&#8203;3585](https://redirect.github.com/github/codeql-action/pull/3585) ### [`v4.33.0`](https://redirect.github.com/github/codeql-action/releases/tag/v4.33.0) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v4.32.6...v4.33.0) - Upcoming change: Starting April 2026, the CodeQL Action will skip collecting file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. Pull request analyses will log a warning about this upcoming change. [#&#8203;3562](https://redirect.github.com/github/codeql-action/pull/3562) To opt out of this change: - **Repositories owned by an organization:** Create a custom repository property with the name `github-codeql-file-coverage-on-prs` and the type "True/false", then set this property to `true` in the repository's settings. For more information, see [Managing custom properties for repositories in your organization](https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization). Alternatively, if you are using an advanced setup workflow, you can set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true` in your workflow. - **User-owned repositories using default setup:** Switch to an advanced setup workflow and set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true` in your workflow. - **User-owned repositories using advanced setup:** Set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true` in your workflow. - Fixed [a bug](https://redirect.github.com/github/codeql-action/issues/3555) which caused the CodeQL Action to fail loading repository properties if a "Multi select" repository property was configured for the repository. [#&#8203;3557](https://redirect.github.com/github/codeql-action/pull/3557) - The CodeQL Action now loads [custom repository properties](https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization) on GitHub Enterprise Server, enabling the customization of features such as `github-codeql-disable-overlay` that was previously only available on GitHub.com. [#&#8203;3559](https://redirect.github.com/github/codeql-action/pull/3559) - Once [private package registries](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries) can be configured with OIDC-based authentication for organizations, the CodeQL Action will now be able to accept such configurations. [#&#8203;3563](https://redirect.github.com/github/codeql-action/pull/3563) - Fixed the retry mechanism for database uploads. Previously this would fail with the error "Response body object should not be disturbed or locked". [#&#8203;3564](https://redirect.github.com/github/codeql-action/pull/3564) - A warning is now emitted if the CodeQL Action detects a repository property whose name suggests that it relates to the CodeQL Action, but which is not one of the properties recognised by the current version of the CodeQL Action. [#&#8203;3570](https://redirect.github.com/github/codeql-action/pull/3570) ### [`v4.32.6`](https://redirect.github.com/github/codeql-action/releases/tag/v4.32.6) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v4.32.5...v4.32.6) - Update default CodeQL bundle version to [2.24.3](https://redirect.github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3). [#&#8203;3548](https://redirect.github.com/github/codeql-action/pull/3548) </details> <details> <summary>jdx/mise-action (jdx/mise-action)</summary> ### [`v3.6.3`](https://redirect.github.com/jdx/mise-action/releases/tag/v3.6.3) [Compare Source](https://redirect.github.com/jdx/mise-action/compare/v3.6.2...v3.6.3) ##### What's Changed - fix: pass cwd to all exec calls in exportMiseEnv() by [@&#8203;andrewthauer](https://redirect.github.com/andrewthauer) in [#&#8203;390](https://redirect.github.com/jdx/mise-action/pull/390) - chore: release v3.6.3 by [@&#8203;mise-en-dev](https://redirect.github.com/mise-en-dev) in [#&#8203;391](https://redirect.github.com/jdx/mise-action/pull/391) ##### New Contributors - [@&#8203;andrewthauer](https://redirect.github.com/andrewthauer) made their first contribution in [#&#8203;390](https://redirect.github.com/jdx/mise-action/pull/390) **Full Changelog**: <jdx/mise-action@v3.6.2...v3.6.3> </details> <details> <summary>step-security/harden-runner (step-security/harden-runner)</summary> ### [`v2.17.0`](https://redirect.github.com/step-security/harden-runner/releases/tag/v2.17.0) [Compare Source](https://redirect.github.com/step-security/harden-runner/compare/v2.16.1...v2.17.0) ##### What's Changed ##### Policy Store Support Added `use-policy-store` and `api-key` inputs to fetch security policies directly from the [StepSecurity Policy Store](https://docs.stepsecurity.io/harden-runner/policy-store). Policies can be defined and attached at the workflow, repo, org, or cluster (ARC) level, with the most granular policy taking precedence. This is the preferred method over the existing `policy` input which requires `id-token: write` permission. If no policy is found in the store, the action defaults to audit mode. **Full Changelog**: <step-security/harden-runner@v2.16.1...v2.17.0> ### [`v2.16.1`](https://redirect.github.com/step-security/harden-runner/releases/tag/v2.16.1) [Compare Source](https://redirect.github.com/step-security/harden-runner/compare/v2.16.0...v2.16.1) ##### What's Changed Enterprise tier: Added support for direct IP addresses in the allow list Community tier: Migrated Harden Runner telemetry to a new endpoint **Full Changelog**: <step-security/harden-runner@v2.16.0...v2.16.1> ### [`v2.16.0`](https://redirect.github.com/step-security/harden-runner/releases/tag/v2.16.0) [Compare Source](https://redirect.github.com/step-security/harden-runner/compare/v2.15.1...v2.16.0) #### What's Changed - Updated action.yml to use node24 - Security fix: Fixed a medium severity vulnerability where the egress block policy could be bypassed via DNS over HTTPS (DoH) by proxying DNS queries through a permitted resolver, allowing data exfiltration even with a restrictive allowed-endpoints list. This issue only affects the Community Tier; the Enterprise Tier is not affected. See [GHSA-46g3-37rh-v698](https://redirect.github.com/step-security/harden-runner/security/advisories/GHSA-46g3-37rh-v698) for details. - Security fix: Fixed a medium severity vulnerability where the egress block policy could be bypassed via DNS queries over TCP to external resolvers, allowing outbound network communication that evades configured network restrictions. This issue only affects the Community Tier; the Enterprise Tier is not affected. See [GHSA-g699-3x6g-wm3g](https://redirect.github.com/step-security/harden-runner/security/advisories/GHSA-g699-3x6g-wm3g) for details. **Full Changelog**: <step-security/harden-runner@v2.15.1...v2.16.0> ### [`v2.15.1`](https://redirect.github.com/step-security/harden-runner/releases/tag/v2.15.1) [Compare Source](https://redirect.github.com/step-security/harden-runner/compare/v2.15.0...v2.15.1) ##### What's Changed - Fixes [#&#8203;642](https://redirect.github.com/step-security/harden-runner/issues/642) bug due to which post step was failing on Windows ARM runners - Updates npm packages **Full Changelog**: <step-security/harden-runner@v2.15.0...v2.15.1> </details> <details> <summary>nodejs/undici (undici)</summary> ### [`v7.24.8`](https://redirect.github.com/nodejs/undici/releases/tag/v7.24.8) [Compare Source](https://redirect.github.com/nodejs/undici/compare/v7.24.7...v7.24.8) #### What's Changed - fix: backport 401 stream-backed body fix to v7.x by [@&#8203;mcollina](https://redirect.github.com/mcollina) in [#&#8203;5006](https://redirect.github.com/nodejs/undici/pull/5006) **Full Changelog**: <nodejs/undici@v7.24.7...v7.24.8> ### [`v7.24.7`](https://redirect.github.com/nodejs/undici/releases/tag/v7.24.7) [Compare Source](https://redirect.github.com/nodejs/undici/compare/v7.24.6...v7.24.7) #### What's Changed - docs: update broken links in file "Dispatcher.md" by [@&#8203;samuel871211](https://redirect.github.com/samuel871211) in [#&#8203;4924](https://redirect.github.com/nodejs/undici/pull/4924) - doc: remove unused parameter `redirectionLimitReached` by [@&#8203;samuel871211](https://redirect.github.com/samuel871211) in [#&#8203;4933](https://redirect.github.com/nodejs/undici/pull/4933) - test: skip flaky macOS Node 20 cookie fetch cases by [@&#8203;mcollina](https://redirect.github.com/mcollina) in [#&#8203;4932](https://redirect.github.com/nodejs/undici/pull/4932) - fix(types): align Response with DOM fetch types by [@&#8203;theamodhshetty](https://redirect.github.com/theamodhshetty) in [#&#8203;4867](https://redirect.github.com/nodejs/undici/pull/4867) - fix(types): Fix clone method type declaration to be an instance method rather than instance property by [@&#8203;mistval](https://redirect.github.com/mistval) in [#&#8203;4925](https://redirect.github.com/nodejs/undici/pull/4925) - test: skip IPv6 tests when IPv6 is not available by [@&#8203;mcollina](https://redirect.github.com/mcollina) in [#&#8203;4939](https://redirect.github.com/nodejs/undici/pull/4939) - fix: correctly handle multi-value rawHeaders in fetch by [@&#8203;mcollina](https://redirect.github.com/mcollina) in [#&#8203;4938](https://redirect.github.com/nodejs/undici/pull/4938) - ignore AGENTS.md by [@&#8203;mcollina](https://redirect.github.com/mcollina) in [#&#8203;4942](https://redirect.github.com/nodejs/undici/pull/4942) #### New Contributors - [@&#8203;samuel871211](https://redirect.github.com/samuel871211) made their first contribution in [#&#8203;4924](https://redirect.github.com/nodejs/undici/pull/4924) - [@&#8203;mistval](https://redirect.github.com/mistval) made their first contribution in [#&#8203;4925](https://redirect.github.com/nodejs/undici/pull/4925) **Full Changelog**: <nodejs/undici@v7.24.6...v7.24.7> ### [`v7.24.6`](https://redirect.github.com/nodejs/undici/releases/tag/v7.24.6) [Compare Source](https://redirect.github.com/nodejs/undici/compare/v7.24.5...v7.24.6) ##### What's Changed - fix(test): client wasm compatible with clang 22 by [@&#8203;rozzilla](https://redirect.github.com/rozzilla) in [#&#8203;4909](https://redirect.github.com/nodejs/undici/pull/4909) - fix(mock): improve error message when intercepts are exhausted by [@&#8203;travisbreaks](https://redirect.github.com/travisbreaks) in [#&#8203;4912](https://redirect.github.com/nodejs/undici/pull/4912) - fix(websocket): support open diagnostics over h2 by [@&#8203;mcollina](https://redirect.github.com/mcollina) in [#&#8203;4921](https://redirect.github.com/nodejs/undici/pull/4921) - fix: assume http/https scheme for scheme-less proxy env vars by [@&#8203;travisbreaks](https://redirect.github.com/travisbreaks) in [#&#8203;4914](https://redirect.github.com/nodejs/undici/pull/4914) - fix(cache): check Authorization on request headers per RFC 9111 §3.5 by [@&#8203;metalix2](https://redirect.github.com/metalix2) in [#&#8203;4911](https://redirect.github.com/nodejs/undici/pull/4911) - fix: wrap kConnector call in try/catch to prevent client hang by [@&#8203;veeceey](https://redirect.github.com/veeceey) in [#&#8203;4834](https://redirect.github.com/nodejs/undici/pull/4834) - docs: clarify fetch and FormData pairing by [@&#8203;mcollina](https://redirect.github.com/mcollina) in [#&#8203;4922](https://redirect.github.com/nodejs/undici/pull/4922) - fix: support Connection header with connection-specific header names per RFC 7230 by [@&#8203;mcollina](https://redirect.github.com/mcollina) in [#&#8203;4775](https://redirect.github.com/nodejs/undici/pull/4775) - fix: avoid prototype collisions in parseHeaders by [@&#8203;mcollina](https://redirect.github.com/mcollina) in [#&#8203;4923](https://redirect.github.com/nodejs/undici/pull/4923) - build(deps-dev): bump typescript from 5.9.3 to 6.0.2 by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;4926](https://redirect.github.com/nodejs/undici/pull/4926) - test: auto-init WPT submodule by [@&#8203;mcollina](https://redirect.github.com/mcollina) in [#&#8203;4930](https://redirect.github.com/nodejs/undici/pull/4930) ##### New Contributors - [@&#8203;rozzilla](https://redirect.github.com/rozzilla) made their first contribution in [#&#8203;4909](https://redirect.github.com/nodejs/undici/pull/4909) - [@&#8203;veeceey](https://redirect.github.com/veeceey) made their first contribution in [#&#8203;4834](https://redirect.github.com/nodejs/undici/pull/4834) **Full Changelog**: <nodejs/undici@v7.24.5...v7.24.6> ### [`v7.24.5`](https://redirect.github.com/nodejs/undici/releases/tag/v7.24.5) [Compare Source](https://redirect.github.com/nodejs/undici/compare/v7.24.4...v7.24.5) #### What's Changed - Formdata tests by [@&#8203;KhafraDev](https://redirect.github.com/KhafraDev) in [#&#8203;4902](https://redirect.github.com/nodejs/undici/pull/4902) - test: add unexpected disconnect guards to more client test files by [@&#8203;samayer12](https://redirect.github.com/samayer12) in [#&#8203;4844](https://redirect.github.com/nodejs/undici/pull/4844) - fix(cache): only apply 1-year deleteAt for immutable responses by [@&#8203;metalix2](https://redirect.github.com/metalix2) in [#&#8203;4913](https://redirect.github.com/nodejs/undici/pull/4913) #### New Contributors - [@&#8203;metalix2](https://redirect.github.com/metalix2) made their first contribution in [#&#8203;4913](https://redirect.github.com/nodejs/undici/pull/4913) **Full Changelog**: <nodejs/undici@v7.24.4...v7.24.5> ### [`v7.24.4`](https://redirect.github.com/nodejs/undici/releases/tag/v7.24.4) [Compare Source](https://redirect.github.com/nodejs/undici/compare/v7.24.3...v7.24.4) #### What's Changed - fix(fetch): handle URL credentials in dispatch path extraction by [@&#8203;mcollina](https://redirect.github.com/mcollina) in [#&#8203;4892](https://redirect.github.com/nodejs/undici/pull/4892) **Full Changelog**: <nodejs/undici@v7.24.3...v7.24.4> ### [`v7.24.3`](https://redirect.github.com/nodejs/undici/releases/tag/v7.24.3) [Compare Source](https://redirect.github.com/nodejs/undici/compare/v7.24.2...v7.24.3) #### What's Changed - fix(h2): TypeError: Cannot read properties of null (reading 'push') i… by [@&#8203;hxinhan](https://redirect.github.com/hxinhan) in [#&#8203;4881](https://redirect.github.com/nodejs/undici/pull/4881) **Full Changelog**: <nodejs/undici@v7.24.2...v7.24.3> ### [`v7.24.2`](https://redirect.github.com/nodejs/undici/releases/tag/v7.24.2) [Compare Source](https://redirect.github.com/nodejs/undici/compare/v7.24.1...v7.24.2) #### What's Changed - fix fetch path logic by [@&#8203;KhafraDev](https://redirect.github.com/KhafraDev) in [#&#8203;4890](https://redirect.github.com/nodejs/undici/pull/4890) - remove maxDecompressedMessageSize by [@&#8203;KhafraDev](https://redirect.github.com/KhafraDev) in [#&#8203;4891](https://redirect.github.com/nodejs/undici/pull/4891) **Full Changelog**: <nodejs/undici@v7.24.1...v7.24.2> ### [`v7.24.1`](https://redirect.github.com/nodejs/undici/compare/v7.24.0...23e3cd362ba6beb3988e6a9a63000336dd219591) [Compare Source](https://redirect.github.com/nodejs/undici/compare/v7.24.0...v7.24.1) ### [`v7.24.0`](https://redirect.github.com/nodejs/undici/releases/tag/v7.24.0) [Compare Source](https://redirect.github.com/nodejs/undici/compare/v7.23.0...v7.24.0) #### What's Changed **Full Changelog**: <nodejs/undici@v7.23.0...v7.24.0> ### [`v7.23.0`](https://redirect.github.com/nodejs/undici/compare/v7.22.0...fbda3c166860772dd80b2577175617d9dddcdb81) [Compare Source](https://redirect.github.com/nodejs/undici/compare/v7.22.0...v7.23.0) </details> --- ### Configuration 📅 **Schedule**: (in timezone America/Chicago) - Branch creation - "after 9am and before 5pm every weekday" - Automerge - "after 9am and before 5pm every weekday" 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/UniquePixels/unicorn). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My41OS4wIiwidXBkYXRlZEluVmVyIjoiNDMuMTIwLjIiLCJ0YXJnZXRCcmFuY2giOiJkZXZlbG9wIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
1 parent bcb1f4b commit e4401fb

7 files changed

Lines changed: 20 additions & 20 deletions

File tree

‎.github/actions/setup-env/action.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,9 +5,9 @@ runs:
55
using: composite
66
steps:
77
- name: Setup mise
8-
uses: jdx/mise-action@e79ddf65a11cec7b0e882bedced08d6e976efb2d # v3.6.2
8+
uses: jdx/mise-action@5228313ee0372e111a38da051671ca30fc5a96db # v3.6.3
99
- name: Setup cache
10-
uses: actions/cache@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5.0.3
10+
uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
1111
with:
1212
path: |
1313
~/.bun/install/cache

‎.github/workflows/ci-bun.yml‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ jobs:
3232
command: bun qa:test
3333
steps:
3434
- name: Harden runner
35-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
35+
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
3636
with:
3737
disable-sudo: true
3838
egress-policy: block
@@ -60,7 +60,7 @@ jobs:
6060
pull-requests: write
6161
steps:
6262
- name: Harden runner
63-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
63+
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
6464
with:
6565
disable-sudo: true
6666
egress-policy: block
@@ -72,4 +72,4 @@ jobs:
7272
- name: Checkout repository
7373
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
7474
- name: Dependency review
75-
uses: actions/dependency-review-action@05fe4576374b728f0c523d6a13d64c25081e0803 # v4.8.3
75+
uses: actions/dependency-review-action@2031cfc080254a8a887f58cffee85186f0e49e48 # v4.9.0

‎.github/workflows/ci-codeql.yml‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ jobs:
3535

3636
steps:
3737
- name: Harden runner
38-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
38+
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
3939
with:
4040
disable-sudo: true
4141
egress-policy: block
@@ -50,12 +50,12 @@ jobs:
5050

5151
# Initializes the CodeQL tools for scanning.
5252
- name: Initialize CodeQL
53-
uses: github/codeql-action/init@c793b717bc78562f491db7b0e93a3a178b099162 # v4.32.5
53+
uses: github/codeql-action/init@c10b8064de6f491fea524254123dbe5e09572f13 # v4.35.1
5454
with:
5555
languages: ${{ matrix.language }}
5656
queries: ${{ matrix.queries }}
5757

5858
- name: Perform CodeQL Analysis
59-
uses: github/codeql-action/analyze@c793b717bc78562f491db7b0e93a3a178b099162 # v4.32.5
59+
uses: github/codeql-action/analyze@c10b8064de6f491fea524254123dbe5e09572f13 # v4.35.1
6060
with:
6161
category: "/language:${{matrix.language}}"

‎.github/workflows/ci-release.yml‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ jobs:
2323
pull-requests: write
2424
steps:
2525
- name: Harden runner
26-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
26+
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
2727
with:
2828
disable-sudo: true
2929
egress-policy: block
@@ -35,7 +35,7 @@ jobs:
3535
3636
- name: Generate release bot token
3737
id: app-token
38-
uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1
38+
uses: actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349 # v2.2.2
3939
with:
4040
app-id: ${{ vars.RELEASE_BOT_APP_ID }}
4141
private-key: ${{ secrets.RELEASE_BOT_PRIVATE_KEY }}
@@ -158,7 +158,7 @@ jobs:
158158
contents: write
159159
steps:
160160
- name: Harden runner
161-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
161+
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
162162
with:
163163
disable-sudo: true
164164
egress-policy: block
@@ -231,7 +231,7 @@ jobs:
231231
- name: Generate release bot token
232232
if: steps.release.outputs.created == 'true'
233233
id: app-token
234-
uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1
234+
uses: actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349 # v2.2.2
235235
with:
236236
app-id: ${{ vars.RELEASE_BOT_APP_ID }}
237237
private-key: ${{ secrets.RELEASE_BOT_PRIVATE_KEY }}

‎.github/workflows/ci-scorecard.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ jobs:
2323
id-token: write
2424
steps:
2525
- name: Harden runner
26-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
26+
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
2727
with:
2828
disable-sudo: true
2929
egress-policy: block
@@ -47,7 +47,7 @@ jobs:
4747
results_format: sarif
4848
publish_results: true
4949
- name: Upload results to code-scanning
50-
uses: github/codeql-action/upload-sarif@c793b717bc78562f491db7b0e93a3a178b099162 # v4.32.5
50+
uses: github/codeql-action/upload-sarif@c10b8064de6f491fea524254123dbe5e09572f13 # v4.35.1
5151
with:
5252
sarif_file: results.sarif
5353
category: scorecard

‎bun.lock‎

Lines changed: 4 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎package.json‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@
2020
},
2121
"devDependencies": {
2222
"@biomejs/biome": "2.4.6",
23-
"@commitlint/types": "^20.4.3",
23+
"@commitlint/types": "^20.5.0",
2424
"@types/bun": "1.3.12",
2525
"pino-pretty": "^13.1.3",
2626
"typescript": "^5.9.3"
@@ -32,7 +32,7 @@
3232
"bun": ">=1.3.0"
3333
},
3434
"overrides": {
35-
"undici": "^7.22.0"
35+
"undici": "^7.24.8"
3636
},
3737
"dependencies": {
3838
"@sentry/bun": "^10.42.0",

0 commit comments

Comments
 (0)