Repository navigation
fix(deps): update all non-major dependencies - #160
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
April 7, 2025 05:00
04b35a2 to
761ca7c
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
April 13, 2025 08:26
b93510b to
836f178
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
8 times, most recently
from
April 25, 2025 21:06
a2e88b4 to
a587ad0
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
4 times, most recently
from
May 4, 2025 01:03
a6efa8b to
56580ba
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
9 times, most recently
from
May 8, 2025 18:33
cf5a855 to
586d13e
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
5 times, most recently
from
May 17, 2025 08:35
4d9f008 to
ecd6eb8
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
May 30, 2025 20:39
eeace5b to
1a91200
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
3 times, most recently
from
June 12, 2025 04:29
ffc89af to
a9f4809
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
June 22, 2025 06:57
dc7a4a5 to
bbb759b
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
8 times, most recently
from
July 1, 2025 20:58
0657686 to
3fa8007
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
5 times, most recently
from
July 15, 2025 16:05
f58db62 to
a928c2b
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
July 19, 2025 04:32
25e6a2d to
bb135e0
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
July 24, 2025 10:06
bb135e0 to
eb02b2a
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
5 times, most recently
from
August 3, 2025 15:07
c697b1e to
7fc967a
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 8, 2025 18:06
7fc967a to
26882ad
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
12.27.0→12.34.02.2.0→2.5.011.0.1→11.0.612.0.1→12.0.222.14.0→22.20.56.9.18→6.15.14.3.1→4.3.29.1.2→9.2.422.14.0→22.23.36.14.0→6.16.06.0.1→6.1.324.2.3→24.2.929.3.1→29.4.140.28.1→0.28.204.0.0→4.1.45.8.2→5.9.3Release Notes
Azure/azure-sdk-for-js (@azure/storage-blob)
v12.34.0Compare Source
v12.33.0Compare Source
v12.32.0Compare Source
v12.31.0Compare Source
v12.30.0Compare Source
v12.29.1Compare Source
v12.29.0Compare Source
v12.28.0Compare Source
pliancy/semantic-release-config-npm (@pliancy/semantic-release-config-npm)
v2.5.0Compare Source
v2.4.0Compare Source
v2.3.0Compare Source
semantic-release/github (@semantic-release/github)
v11.0.6Compare Source
Bug Fixes
v11.0.5Compare Source
Bug Fixes
v11.0.4Compare Source
Bug Fixes
v11.0.3Compare Source
Bug Fixes
v11.0.2Compare Source
Bug Fixes
semantic-release/npm (@semantic-release/npm)
v12.0.2Compare Source
Bug Fixes
commitizen/cz-cli (commitizen)
v4.3.2Compare Source
4.3.2 (2026-06-12)
open-cli-tools/concurrently (concurrently)
v9.2.4Compare Source
Full Changelog: open-cli-tools/concurrently@v9.2.3...v9.2.4
v9.2.3Compare Source
shell-quote- #591, #596v9.2.1Compare Source
What's Changed
Full Changelog: open-cli-tools/concurrently@v9.2.0...v9.2.1
v9.2.0Compare Source
What's Changed
--kill-timeoutby @gustavohenke in #540New Contributors
Full Changelog: open-cli-tools/concurrently@v9.1.2...v9.2.0
nodejs/node (node)
v22.23.3: 2026-09-23, Version 22.23.3 'Jod' (LTS), @aduh95 prepared by @juanarbolCompare Source
Notable Changes
fe2a6b2be8] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746871167ddfd] - deps: update corepack to 0.36.0 (Node.js GitHub Bot) #65653b816fc8958] - deps: upgrade npm to 10.9.9 (npm team) #64884e306521444] - deps: update icu to 78.3 (Node.js GitHub Bot) #62324a9cb31129f] - deps: update OpenSSL 3.5.8 (Node.js GitHub Bot) #655422a3548e51c] - deps: update Undici to 6.28.1 (mcollina) #657903909ff2c4a] - node-api: supportSharedArrayBufferinnapi_create_typedarray(Yilong Li) #6271066de6349ad] - node-api: addnapi_create_external_sharedarraybuffer(Ben Noordhuis) #62623Commits
44cf27b8fa] - build: update binary-upload to use correct tarball name (Stewart X Addison) #65282fe2a6b2be8] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #6474671feba6b69] - crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527871167ddfd] - deps: update corepack to 0.36.0 (Node.js GitHub Bot) #656532a3548e51c] - deps: update undici to 6.28.1 (mcollina) #6579059d853a4df] - deps: update archs files for openssl-3.5.8 (Node.js GitHub Bot) #65542a9cb31129f] - deps: upgrade openssl sources to openssl-3.5.8 (Node.js GitHub Bot) #655423376e27de2] - deps: V8: cherry-picka6eaf75(Camillo Bruni) #65402b816fc8958] - deps: upgrade npm to 10.9.9 (npm team) #648844e4bd1b104] - deps: update timezone to 2026c (Node.js GitHub Bot) #645887d82841b4e] - deps: update c-ares to 1.34.8 (Node.js GitHub Bot) #6433001855a19d3] - deps: c-ares: cherry-pick8ba37af(René) #6411023fb398c3d] - deps: update corepack to 0.35.0 (Node.js GitHub Bot) #633755286330365] - deps: update corepack to 0.34.7 (Node.js GitHub Bot) #628106d6c3c98b1] - deps: update timezone to 2026b (Node.js GitHub Bot) #62962e306521444] - deps: update icu to 78.3 (Node.js GitHub Bot) #62324d9cb8468a3] - doc: clarifyfilteroption ofsqlite.database.applyChangeset(Antoine du Hamel) #63515c9c5662d91] - doc: add sxa GPG key (ed25519) (Stewart X Addison) #6419337f21068c4] - fs: restore fs patchability in ESM loader (Joyee Cheung) #628357c2df5dd96] - http2: avoid uaf while receiving and sending rst_stream (esgor) #641663909ff2c4a] - node-api: support SharedArrayBuffer in napi_create_typedarray (Yilong Li) #6271066de6349ad] - node-api: add napi_create_external_sharedarraybuffer (Ben Noordhuis) #62623ce9139107f] - src: escape Windows environment variables in task runner (Antoine du Hamel) #65217839480a471] - test: fix link-local dgram scope assertion (Filip Skokan) #6562940eac4a32f] - test: account for varied OpenSSL CCM final behaviours (Filip Skokan) #6554275098a9e8c] - tools: update gr2m/create-or-update-pull-request-action to v1.10.1 (Mike McCready) #6306508b6ac0416] - tools: revert OpenSSL update workflow to ubuntu-latest (Richard Lau) #6262702cafc479f] - tools: fix commit linter for semver-major release proposals (Antoine du Hamel) #629936f6cd3768d] - tools: sync mk-ca-bundle.pl with curl (Archkon) #64753bc5753d438] - tools: removeenvinfofrom our workflows (Antoine du Hamel) #64259d68ee9f8a5] - tools: validate version number in release proposal commit message lint (Antoine du Hamel) #6407038ee2e895f] - tools: avoid test/fixtures/wpt/README.md conflicts (Filip Skokan) #63938fdc65e489f] - tools: use different branch for tool updates on staging branches (Antoine du Hamel) #63110e5a6fde002] - tools: update gyp-next to 0.22.1 (Node.js GitHub Bot) #629615fbbad6e82] - url: handle unparsable serialized URLs in setters (Matteo Collina) #64651ed019e4854] - util: preserve function names without source map names (Hiroki Osame) #65108v22.23.2: 2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolitoCompare Source
This is a security release.
Notable Changes
Commits
4b12ac38a1] - deps: update llhttp to 9.4.3 (Paolo Insogna) nodejs-private/node-private#9353fd0aa51d0] - deps: update undici to 6.28.0 (Node.js GitHub Bot) #6471422efc051a3] - (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) nodejs-private/node-private#929c8525ac3a6] - (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) nodejs-private/node-private#932daa6d25e3d] - (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) nodejs-private/node-private#921f14d78b9e0] - (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) #6375251123159fe] - (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) nodejs-private/node-private#934acaf4266b2] - (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) nodejs-private/node-private#930440329f624] - (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) nodejs-private/node-private#911ed18b9cc07] - (CVE-2026-58039) permission: check final report output path (RafaelGSS) nodejs-private/node-private#9260566c3cccd] - (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) nodejs-private/node-private#9270d072480c3] - (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) nodejs-private/node-private#931v22.23.1: 2026-06-23, Version 22.23.1 'Jod' (LTS), @RafaelGSSCompare Source
This release includes a fix for an unexpected behavior introduced
by the recent security release (22.23.0).
Commits
41d2ee13be] - build: switch coverage-windows towindows-2022(Richard Lau) #63940eaa292549e] - http: avoid stream listeners on idle agent sockets (Matteo Collina) #64004v22.23.0: 2026-06-18, Version 22.23.0 'Jod' (LTS), @aduh95Compare Source
This is a security release.
Notable Changes
Commits
38b4c5ed51] - (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) nodejs-private/node-private#878ad8a10c1bb] - deps: update llhttp to 9.4.2 (Antoine du Hamel) nodejs-private/node-private#890ca825a87cc] - deps: update undici to 6.27.0 (aduh95) #63711a1a5bb9683] - (CVE-2026-48937) deps: fix integration issues with the latest nghttp2 (Tim Perry) #628910f48583512] - (SEMVER-MAJOR) deps: update nghttp2 to 1.69.0 (Node.js GitHub Bot) #6289138c869fc05] - deps: update nghttp2 to 1.68.0 (nodejs-github-bot) #61136290667c84f] - deps: update nghttp2 to 1.67.1 (nodejs-github-bot) #59790c9f3da76aa] - deps: update nghttp2 to 1.66.0 (Node.js GitHub Bot) #5878660890be563] - deps: update nghttp2 to 1.65.0 (Node.js GitHub Bot) #572695024c7d5d8] - deps: update archs files for openssl-3.5.7 (Node.js GitHub Bot) #638207f4eb5af2e] - deps: upgrade openssl sources to openssl-3.5.7 (Node.js GitHub Bot) #63820ebb4ec78a8] - deps: fix aix implicit declaration in OpenSSL (Abdirahim Musse) #626565763d40826] - deps: update llhttp to 9.4.1 (Node.js GitHub Bot) #63045c551a51d0c] - (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) nodejs-private/node-private#8680a22d40180] - (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) nodejs-private/node-private#846c79968e108] - (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) nodejs-private/node-private#8550c37bff2ff] - http2: fix DEP0194 message (KaKa) #58669ea5dc6b529] - (SEMVER-MAJOR) http2: remove support for priority signaling (Matteo Collina) #582939b6af26132] - (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) nodejs-private/node-private#86728dcd38864] - (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) nodejs-private/node-private#8732f62693801] - (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) nodejs-private/node-private#8701662a3ea09] - test: add session reuse host verification regressions (Matteo Collina) nodejs-private/node-private#854718d5d0e2c] - test: skiptest-fs-utimes-y2K38on armv7 (Richard Lau) #63836041185b61f] - test: skip test-cluster-dgram-reuse on AIX 7.3 (Stewart X Addison) #62238fd890ba01d] - (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) nodejs-private/node-private#85439d1d09684] - (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) nodejs-private/node-private#8572197a47144] - (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) nodejs-private/node-private#869v22.22.3: 2026-05-13, Version 22.22.3 'Jod' (LTS), @marco-ippolitoCompare Source
Commits
4f780905c5] - crypto: fix potential null pointer dereference when BIO_meth_new() fails (Nora Dossche) #617884a09efb947] - crypto: update root certificates to NSS 3.121 (Node.js GitHub Bot) #62485e4c0d99839] - deps: update timezone to 2026a (Node.js GitHub Bot) #621640226c8dd7a] - deps: update simdjson to 4.5.0 (Node.js GitHub Bot) #62382e742ab748c] - deps: update sqlite to 3.51.3 (Node.js GitHub Bot) #6225673cac0571a] - deps: update amaro to 1.1.8 (Node.js GitHub Bot) #62151ae5c162b93] - deps: update amaro to 1.1.7 (Node.js GitHub Bot) #61730b819cb9977] - deps: update amaro to 1.1.6 (Node.js GitHub Bot) #61603bbcce09dc7] - deps: update sqlite to 3.52.0 (Node.js GitHub Bot) #6215022ff2d81ce] - deps: update simdjson to 4.3.1 (Node.js GitHub Bot) #61930f49b51d75c] - deps: update acorn-walk to 8.3.5 (Node.js GitHub Bot) #619281a5cec0d49] - deps: update acorn to 8.16.0 (Node.js GitHub Bot) #61925d339497688] - deps: update nbytes to 0.1.3 (Node.js GitHub Bot) #618793ff8ffd459] - deps: remove stale OpenSSL arch configs (René) #61834b8ddbc1e9a] - deps: update llhttp to 9.3.1 (Node.js GitHub Bot) #61827ffda97afd4] - deps: update googletest to2461743(Node.js GitHub Bot) #6248479aa32cf4f] - deps: update googletest to73a63ea(Node.js GitHub Bot) #61927b6957e13b6] - deps: update archs files for openssl-3.5.6 (Node.js GitHub Bot) #626293a27669063] - deps: upgrade openssl sources to openssl-3.5.6 (Node.js GitHub Bot) #62629d568a1bb53] - deps: upgrade npm to 10.9.8 (npm team) #62463ec11f3c1d5] - deps: V8: backport85b3900(Thibaud Michaud) #6278308609712ed] - deps: V8: backport1b27e46(Thibaud Michaud) #62783dcc60d5ab2] - deps: V8: backport9997fc0(Thibaud Michaud) #627831d1f4451fb] - deps: V8: cherry-pickb96e40d(Clemens Backes) #627832268567237] - deps: V8: cherry-pick7cb6188(Thibaud Michaud) #6278392804cdbea] - deps: V8: cherry-picke7ccf0a(Thibaud Michaud) #62783eae2c27a40] - deps: V8: cherry-pick8e214ec(Thibaud Michaud) #62783a1799a49bb] - deps: V8: backport63b8849(Thibaud Michaud) #62783a2df2d8731] - deps: V8: backport3239427(Thibaud Michaud) #62783e3d65c7dca] - deps: V8: backport89dc6ea(Thibaud Michaud) #627835e7db133de] - deps: V8: backport910cb91(Jakob Kummerow) #62783d0c24a28af] - deps: V8: cherry-pickb8f91e5(Thibaud Michaud) #62783d358687824] - deps: V8: cherry-pickcf03d55(Thibaud Michaud) #6278367c8b2c349] - deps: V8: cherry-pick692f3d5(Sébastien Doeraene) #6278371e5a59ffd] - deps: V8: cherry-pickc734674(Manos Koukoutos) #62783f0dbe81c7b] - deps: V8: cherry-pickb2f3aea(Thibaud Michaud) #62783d333f480c3] - deps: V8: cherry-pick5f1342c(Matthias Liedtke) #62783db722725bb] - deps: use npm undici@six tag inupdate-undici.sh(Matteo Collina) #630129b57979d9c] - doc: add Rafael to last security release steward (Rafael Gonzaga) #62423d8075585bf] - doc: add path to vulnerabilities.json mention (Rafael Gonzaga) #623556ec9a70204] - doc: clarify fs.ReadStream and fs.WriteStream are not constructable (Kit Dallege) #622081fc86fcb6e] - doc: add note (and caveat) formock.moduleabout customization hooks (Jacob Smith) #62075491be80bd9] - doc: add efekrskl as triager (Efe) #6187618558293a3] - doc: fix module.stripTypeScriptTypes indentation (René) #619928e20976522] - doc: explicitly mention Slack handle (Rafael Gonzaga) #6198670b8e6b4fb] - doc: rename invalidfunctionparameter (René) #619424045c76f6c] - doc: clarify status of feature request issues (Antoine du Hamel) #61505c54652f2aa] - doc: remove incorrect mention ofmoduleintypescript.md(Rob Palmer) #618399fad6cedf5] - doc: clarify async caveats forevents.once()(René) [#61572](https://redirect.github.com/nodejs/node/Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.