Update Non-major updates #66

Merged
renovate-bot merged 1 commit from renovate/non-major-updates into dev 2026-08-13 16:02:12 +02:00
Collaborator

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
globals 17.8.0 → 17.9.0 age confidence devDependencies minor 17.11.0 (+1)
node (source) 24.18.1 → 24.19.0 age confidence minor
node 24.18.1 → 24.19.0 age confidence uses-with minor
npm:pnpm (source) 11.19.0 → 11.20.0 age confidence minor 11.21.0
pnpm (source) 11.19.0 → 11.20.0 age confidence uses-with minor 11.21.0
typescript-eslint (source) 8.65.0 → 8.66.0 age confidence devDependencies minor 8.67.0
vite (source) 8.2.0 → 8.2.1 age confidence devDependencies patch

Release Notes

sindresorhus/globals (globals)

v17.9.0

Compare Source


nodejs/node (node)

v24.19.0: 2026-08-03, Version 24.19.0 'Krypton' (LTS), @​aduh95

Compare Source

Notable Changes
  • [d08872b530] - (SEMVER-MINOR) buffer: implement blob.textStream() (Matthew Aitken) #​64036
  • [35222948be] - (SEMVER-MINOR) deps: update OpenSSL build config to support compression (Tim Perry) #​62217
  • [d6ab039f24] - (SEMVER-MINOR) doc: update blockList stability status to release candidate (alphaleadership) #​63050
  • [1da05fb79d] - doc: mark stream.compose stable (Matteo Collina) #​62562
  • [3c1636dabf] - (SEMVER-MINOR) esm: add --experimental-import-text flag (Efe) #​62300
  • [e323e877be] - (SEMVER-MINOR) fs: support caller-supplied readFile() buffers (Matteo Collina) #​63634
  • [c1248c9544] - (SEMVER-MINOR) http: add httpValidation option to configure header value validation (RajeshKumar11) #​61597
  • [a534b65815] - (SEMVER-MINOR) net: support TCP_KEEPINTVL and TCP_KEEPCNT in setKeepAlive (Guy Bedford) #​63825
  • [a23cdec683] - (SEMVER-MINOR) perf_hooks: sample delay per event loop iteration (Pablo Erhard) #​62935
  • [7428b57a37] - (SEMVER-MINOR) src: allow empty --experimental-config-file (Marco Ippolito) #​61610
  • [e57597173c] - (SEMVER-MINOR) stream: expose ReadableStreamTee (Matteo Collina) #​64195
  • [5396235993] - (SEMVER-MINOR) tls: report negotiated TLS groups (Filip Skokan) #​64119
  • [5e901b5cd9] - (SEMVER-MINOR) tls: add certificateCompression option (Tim Perry) #​62217
Commits
actions/node-versions (node)

v24.19.0: 24.19.0

Compare Source

Node.js 24.19.0

pnpm/pnpm (npm:pnpm)

v11.20.0: pnpm 11.20

Compare Source

Minor Changes
  • Security fix. Affects projects using namedRegistries on pnpm 11.1.0–11.19.x. It is semi-breaking for those projects — see "If you use named registries" below.

    The lockfile recorded no marker for which registry a package came from. Packages were keyed by name@version alone, and entry lookup went through refToRelative(ref, name), so a dependency you declared against one registry could be satisfied by an entry that was actually resolved from another. When two registries served the same name and version, both collapsed onto a single packages: entry and whichever resolved first decided the tarball every consumer got.

    That is a package-substitution risk: a package you expect from your private registry could be installed from a different registry that publishes the same name and version, and the lockfile recorded nothing that would let you tell.

    Packages resolved from a named registry are now recorded under registry-qualified keys (<name>@&#8203;<registryName>:<version>, e.g. foo@work:1.0.0), so each registry gets its own entry and the lockfile pins which one a dependency came from.

    The lockfile format version is unchanged. Registry-qualified keys appear only for packages resolved from a named registry, so a project that does not use namedRegistries sees no difference, and older pnpm versions keep reading the file.

If you use named registries

Your next non-frozen install re-keys those entries, which shows up as a lockfile diff. Commit it — that diff is the fix being applied. Review it: an entry that moves to a registry you did not expect is worth investigating.

Everyone working on the project should be on this version or newer before you do. An older pnpm reads the re-keyed lockfile fine — frozen installs are unaffected — but it does not produce registry-qualified keys itself, so any install that updates the lockfile writes those entries back to the old shape, and the next install on a current pnpm re-qualifies them. The result is a lockfile that flips back and forth, and while it is in the old shape the project is exposed again. Because the lockfile format version is deliberately unchanged, pnpm cannot detect this and warn you about it.

There is no setting to keep the old behavior: the old shape is the vulnerability.

Tarball URLs that follow the standard registry layout are no longer written to the lockfile for named-registry packages; they are recomputed from the namedRegistries setting on demand.

To use named registries, map your aliases in pnpm-workspace.yaml:

namedRegistries:
  work: https://npm.enterprise.example.com/
New built-in npmjs: alias

npmjs: now resolves to https://registry.npmjs.org/ with no configuration, alongside the existing gh: alias for GitHub Packages. It pins a dependency to the public registry even when registry points elsewhere, such as an internal proxy:

{ "dependencies": { "left-pad": "npmjs:^1.3.0" } }

npm: cannot do this — it is the alias protocol (npm:<name>@&#8203;<range>) and resolves through whatever registry points at.

If you mirror or proxy npmjs, point the alias at your mirror:

namedRegistries:
  npmjs: https://npm.internal.example.com/

Built-in registry URLs are also the prefixes a lockfile's recorded tarball URL is matched against when pnpm verifies a package. Without the override, an entry whose tarball URL is on registry.npmjs.org is verified against the public registry rather than your mirror. This only affects lockfiles that record such URLs — a canonical URL for your configured registry is omitted from the lockfile and unaffected — and only when a tarball-URL, minimumReleaseAge, or trustPolicy check runs. Overriding the alias is the same escape hatch GHES users already have for gh.

Every alias the lockfile references must stay in namedRegistries: reading an entry whose alias is gone fails with ERR_PNPM_MISSING_NAMED_REGISTRY rather than silently falling back to the default registry, since that would fetch a different package. Renaming an alias re-resolves the packages that used it.

Named registry aliases that shadow a reserved dependency specifier prefix (file, link, workspace, runtime, npm, jsr, ...) are now rejected with ERR_PNPM_RESERVED_NAMED_REGISTRY_NAME instead of being silently shadowed by the corresponding resolver.

pnpm licenses and pnpm sbom now keep the two artifacts apart as well: license records carry the registry alias, and SBOM components carry the purl repository_url qualifier.

Patch Changes
  • An empty http-proxy, https-proxy, proxy, or no-proxy value — from the .npmrc, pnpm-workspace.yaml, the CLI, or the HTTP_PROXY / HTTPS_PROXY / PROXY / NO_PROXY environment variables — no longer fails the install with ERR_PNPM_INVALID_PROXY. Empty settings read as unset, so a shell exporting HTTP_PROXY= disables the proxy, and an empty proxy= in the .npmrc no longer suppresses HTTPS_PROXY #​13533.

    proxy=false in the .npmrc or proxy: false in pnpm-workspace.yaml now turns proxying off instead of being read as a proxy host named false. false and null on https-proxy / http-proxy / no-proxy read as unset, and on the command line they are ordinary host names, since a flag carries its value verbatim.

  • The env lockfile no longer pins @pnpm/exe alongside pnpm when the wanted pnpm version is 12 or newer. From v12 the unscoped pnpm package is itself the native executable, so @pnpm/exe is not published for it and resolving it would fail. The engine identity check now verifies the native binary through whichever package ships it.

  • lexCompare and nerfDart are now published as @pnpm/text.ordinal-comparator and @pnpm/config.registry-auth-key. Use these instead of @pnpm/util.lex-comparator and @pnpm/config.nerf-dart.

  • Fixed the order in which pnpm matches a lockfile's recorded tarball URL against known registry URLs. Two registry URLs of equal length were previously ordered arbitrarily, so which one a tarball URL matched could differ between runs.

  • Dependency resolution is faster: package metadata is now filtered once per packument instead of once per dependency edge when minimumReleaseAge is active, and parsed semver versions and ranges are reused instead of re-parsed on every comparison.

  • Security: pnpm rebuild now refuses a lockfile whose packages key carries a path traversal in the package name (e.g. ../../../escaped@1.0.0), instead of running that package's lifecycle scripts and linking its bins in a directory outside the virtual store. Such a name is rejected with ERR_PNPM_INVALID_DEPENDENCY_NAME.

Platinum Sponsors
Bit
OpenAI
Gold Sponsors
Sanity Discord Vite
SerpApi CodeRabbit Stackblitz
Workleap Nx
typescript-eslint/typescript-eslint (typescript-eslint)

v8.66.0

Compare Source

This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

vitejs/vite (vite)

v8.2.1

Compare Source

Bug Fixes
Performance Improvements
Documentation
Miscellaneous Chores
Code Refactoring
Tests

Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • "after 11pm every weekday,before 5am every weekday,every weekend"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | Type | Update | Pending | |---|---|---|---|---|---|---| | [globals](https://github.com/sindresorhus/globals) | [`17.8.0` → `17.9.0`](https://renovatebot.com/diffs/npm/globals/17.8.0/17.9.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/globals/17.9.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/globals/17.8.0/17.9.0?slim=true) | devDependencies | minor | `17.11.0` (+1) | | [node](https://nodejs.org) ([source](https://github.com/nodejs/node)) | `24.18.1` → `24.19.0` | ![age](https://developer.mend.io/api/mc/badges/age/node-version/node/v24.19.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/node-version/node/v24.18.1/v24.19.0?slim=true) | | minor | | | [node](https://github.com/actions/node-versions) | `24.18.1` → `24.19.0` | ![age](https://developer.mend.io/api/mc/badges/age/github-releases/actions%2fnode-versions/24.19.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/github-releases/actions%2fnode-versions/24.18.1/24.19.0?slim=true) | uses-with | minor | | | [npm:pnpm](https://pnpm.io) ([source](https://github.com/pnpm/pnpm/tree/HEAD/pnpm11/pnpm)) | `11.19.0` → `11.20.0` | ![age](https://developer.mend.io/api/mc/badges/age/npm/pnpm/11.20.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/pnpm/11.19.0/11.20.0?slim=true) | | minor | `11.21.0` | | [pnpm](https://pnpm.io) ([source](https://github.com/pnpm/pnpm/tree/HEAD/pnpm11/pnpm)) | `11.19.0` → `11.20.0` | ![age](https://developer.mend.io/api/mc/badges/age/npm/pnpm/11.20.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/pnpm/11.19.0/11.20.0?slim=true) | uses-with | minor | `11.21.0` | | [typescript-eslint](https://typescript-eslint.io/packages/typescript-eslint) ([source](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint)) | [`8.65.0` → `8.66.0`](https://renovatebot.com/diffs/npm/typescript-eslint/8.65.0/8.66.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/typescript-eslint/8.66.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/typescript-eslint/8.65.0/8.66.0?slim=true) | devDependencies | minor | `8.67.0` | | [vite](https://vite.dev) ([source](https://github.com/vitejs/vite/tree/HEAD/packages/vite)) | [`8.2.0` → `8.2.1`](https://renovatebot.com/diffs/npm/vite/8.2.0/8.2.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/vite/8.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/vite/8.2.0/8.2.1?slim=true) | devDependencies | patch | | --- ### Release Notes <details> <summary>sindresorhus/globals (globals)</summary> ### [`v17.9.0`](https://github.com/sindresorhus/globals/releases/tag/v17.9.0) [Compare Source](https://github.com/sindresorhus/globals/compare/v17.8.0...v17.9.0) - Update globals (2026-08-01) ([#&#8203;348](https://github.com/sindresorhus/globals/issues/348)) [`5a958ed`](https://github.com/sindresorhus/globals/commit/5a958ed) *** </details> <details> <summary>nodejs/node (node)</summary> ### [`v24.19.0`](https://github.com/nodejs/node/releases/tag/v24.19.0): 2026-08-03, Version 24.19.0 'Krypton' (LTS), @&#8203;aduh95 [Compare Source](https://github.com/nodejs/node/compare/v24.18.1...v24.19.0) ##### Notable Changes - \[[`d08872b530`](https://github.com/nodejs/node/commit/d08872b530)] - **(SEMVER-MINOR)** **buffer**: implement `blob.textStream()` (Matthew Aitken) [#&#8203;64036](https://github.com/nodejs/node/pull/64036) - \[[`35222948be`](https://github.com/nodejs/node/commit/35222948be)] - **(SEMVER-MINOR)** **deps**: update OpenSSL build config to support compression (Tim Perry) [#&#8203;62217](https://github.com/nodejs/node/pull/62217) - \[[`d6ab039f24`](https://github.com/nodejs/node/commit/d6ab039f24)] - **(SEMVER-MINOR)** **doc**: update `blockList` stability status to release candidate (alphaleadership) [#&#8203;63050](https://github.com/nodejs/node/pull/63050) - \[[`1da05fb79d`](https://github.com/nodejs/node/commit/1da05fb79d)] - **doc**: mark `stream.compose` stable (Matteo Collina) [#&#8203;62562](https://github.com/nodejs/node/pull/62562) - \[[`3c1636dabf`](https://github.com/nodejs/node/commit/3c1636dabf)] - **(SEMVER-MINOR)** **esm**: add `--experimental-import-text` flag (Efe) [#&#8203;62300](https://github.com/nodejs/node/pull/62300) - \[[`e323e877be`](https://github.com/nodejs/node/commit/e323e877be)] - **(SEMVER-MINOR)** **fs**: support caller-supplied `readFile()` buffers (Matteo Collina) [#&#8203;63634](https://github.com/nodejs/node/pull/63634) - \[[`c1248c9544`](https://github.com/nodejs/node/commit/c1248c9544)] - **(SEMVER-MINOR)** **http**: add `httpValidation` option to configure header value validation (RajeshKumar11) [#&#8203;61597](https://github.com/nodejs/node/pull/61597) - \[[`a534b65815`](https://github.com/nodejs/node/commit/a534b65815)] - **(SEMVER-MINOR)** **net**: support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive` (Guy Bedford) [#&#8203;63825](https://github.com/nodejs/node/pull/63825) - \[[`a23cdec683`](https://github.com/nodejs/node/commit/a23cdec683)] - **(SEMVER-MINOR)** **perf\_hooks**: sample delay per event loop iteration (Pablo Erhard) [#&#8203;62935](https://github.com/nodejs/node/pull/62935) - \[[`7428b57a37`](https://github.com/nodejs/node/commit/7428b57a37)] - **(SEMVER-MINOR)** **src**: allow empty `--experimental-config-file` (Marco Ippolito) [#&#8203;61610](https://github.com/nodejs/node/pull/61610) - \[[`e57597173c`](https://github.com/nodejs/node/commit/e57597173c)] - **(SEMVER-MINOR)** **stream**: expose `ReadableStreamTee` (Matteo Collina) [#&#8203;64195](https://github.com/nodejs/node/pull/64195) - \[[`5396235993`](https://github.com/nodejs/node/commit/5396235993)] - **(SEMVER-MINOR)** **tls**: report negotiated TLS groups (Filip Skokan) [#&#8203;64119](https://github.com/nodejs/node/pull/64119) - \[[`5e901b5cd9`](https://github.com/nodejs/node/commit/5e901b5cd9)] - **(SEMVER-MINOR)** **tls**: add `certificateCompression` option (Tim Perry) [#&#8203;62217](https://github.com/nodejs/node/pull/62217) ##### Commits - \[[`676467fa9f`](https://github.com/nodejs/node/commit/676467fa9f)] - **benchmark**: trim down the argon2 sets (Filip Skokan) [#&#8203;64218](https://github.com/nodejs/node/pull/64218) - \[[`a77a2000b7`](https://github.com/nodejs/node/commit/a77a2000b7)] - **benchmark**: add child\_process async path baselines (Yagiz Nizipli) [#&#8203;63929](https://github.com/nodejs/node/pull/63929) - \[[`dd4482e915`](https://github.com/nodejs/node/commit/dd4482e915)] - **buffer**: remove unreachable overflow check in atob (haramjeong) [#&#8203;60161](https://github.com/nodejs/node/pull/60161) - \[[`081c41eb86`](https://github.com/nodejs/node/commit/081c41eb86)] - **buffer**: add fast api for isUtf8 and isAscii (Gürgün Dayıoğlu) [#&#8203;64169](https://github.com/nodejs/node/pull/64169) - \[[`d08872b530`](https://github.com/nodejs/node/commit/d08872b530)] - **(SEMVER-MINOR)** **buffer**: implement blob.textStream() (Matthew Aitken) [#&#8203;64036](https://github.com/nodejs/node/pull/64036) - \[[`6e2f7e6013`](https://github.com/nodejs/node/commit/6e2f7e6013)] - **build**: remove redundant intermediate node\_aix\_shared (Chengzhong Wu) [#&#8203;63747](https://github.com/nodejs/node/pull/63747) - \[[`87e0675f51`](https://github.com/nodejs/node/commit/87e0675f51)] - **build**: build codecache and snapshot with libnode (Chengzhong Wu) [#&#8203;63626](https://github.com/nodejs/node/pull/63626) - \[[`32174a7bae`](https://github.com/nodejs/node/commit/32174a7bae)] - **build**: support setting an emulator from configure script (Ivan Trubach) [#&#8203;53899](https://github.com/nodejs/node/pull/53899) - \[[`69cfb2f240`](https://github.com/nodejs/node/commit/69cfb2f240)] - **build**: remove duplicated node\_use\_sqlite and node\_use\_ffi conditions (Chengzhong Wu) [#&#8203;63629](https://github.com/nodejs/node/pull/63629) - \[[`37ac6e8cb5`](https://github.com/nodejs/node/commit/37ac6e8cb5)] - **build**: add manually-dispatched stress-test workflow (Joyee Cheung) [#&#8203;64118](https://github.com/nodejs/node/pull/64118) - \[[`2424207191`](https://github.com/nodejs/node/commit/2424207191)] - **build**: suppress compiler warnings for histogram (Richard Lau) [#&#8203;63980](https://github.com/nodejs/node/pull/63980) - \[[`63502b7404`](https://github.com/nodejs/node/commit/63502b7404)] - **build,win**: fix VS2022 arm64 PGO build (Stefan Stojanovic) [#&#8203;63413](https://github.com/nodejs/node/pull/63413) - \[[`fe4e4055d0`](https://github.com/nodejs/node/commit/fe4e4055d0)] - **child\_process**: fix permission model propagation via NODE\_OPTIONS (Matteo Collina) [#&#8203;63972](https://github.com/nodejs/node/pull/63972) - \[[`aa2f3c066e`](https://github.com/nodejs/node/commit/aa2f3c066e)] - **child\_process**: pass spawn options to the binding positionally (Yagiz Nizipli) [#&#8203;63930](https://github.com/nodejs/node/pull/63930) - \[[`fcf32cf77a`](https://github.com/nodejs/node/commit/fcf32cf77a)] - **child\_process**: serialize advanced IPC messages natively (Yagiz Nizipli) [#&#8203;63933](https://github.com/nodejs/node/pull/63933) - \[[`7907134734`](https://github.com/nodejs/node/commit/7907134734)] - **crypto**: reject small-order EdDSA points during verify (Filip Skokan) [#&#8203;64026](https://github.com/nodejs/node/pull/64026) - \[[`b505cd5465`](https://github.com/nodejs/node/commit/b505cd5465)] - **crypto**: support non-byte WebCrypto lengths and cSHAKE (Filip Skokan) [#&#8203;63988](https://github.com/nodejs/node/pull/63988) - \[[`0f54a872e2`](https://github.com/nodejs/node/commit/0f54a872e2)] - **crypto**: share WebCrypto method and usage helpers (Filip Skokan) [#&#8203;63975](https://github.com/nodejs/node/pull/63975) - \[[`824ec11c05`](https://github.com/nodejs/node/commit/824ec11c05)] - **crypto**: refactor keyObject.toCryptoKey() and SubtleCrypto.getPublicKey() (Filip Skokan) [#&#8203;63622](https://github.com/nodejs/node/pull/63622) - \[[`73aba92689`](https://github.com/nodejs/node/commit/73aba92689)] - **crypto**: coerce -0 to +0 before native calls (Filip Skokan) [#&#8203;63556](https://github.com/nodejs/node/pull/63556) - \[[`c83b79874e`](https://github.com/nodejs/node/commit/c83b79874e)] - **crypto**: reject invalid raw key imports (Filip Skokan) [#&#8203;63134](https://github.com/nodejs/node/pull/63134) - \[[`934fda64b9`](https://github.com/nodejs/node/commit/934fda64b9)] - **crypto**: improve accuracy of SubtleCrypto.supports (Filip Skokan) [#&#8203;63104](https://github.com/nodejs/node/pull/63104) - \[[`e392e1f791`](https://github.com/nodejs/node/commit/e392e1f791)] - **crypto**: fix large DH generator validation (Tobias Nießen) [#&#8203;64092](https://github.com/nodejs/node/pull/64092) - \[[`e75a363e70`](https://github.com/nodejs/node/commit/e75a363e70)] - **crypto**: use EVP\_MAC for HMAC on OpenSSL >=3 (Filip Skokan) [#&#8203;63942](https://github.com/nodejs/node/pull/63942) - \[[`adbaf7af9b`](https://github.com/nodejs/node/commit/adbaf7af9b)] - **crypto**: make webcrypto aliasKeyFormat directional (Filip Skokan) [#&#8203;63910](https://github.com/nodejs/node/pull/63910) - \[[`bb1aea8897`](https://github.com/nodejs/node/commit/bb1aea8897)] - **crypto**: fix unhandled error in Hash.\_transform (Haram Jeong) [#&#8203;63261](https://github.com/nodejs/node/pull/63261) - \[[`12c87732c1`](https://github.com/nodejs/node/commit/12c87732c1)] - **crypto**: handle cipher context allocation failures (Tian Teng) [#&#8203;63542](https://github.com/nodejs/node/pull/63542) - \[[`858496b453`](https://github.com/nodejs/node/commit/858496b453)] - **crypto**: deduplicate X509 subject matching logic (Tobias Nießen) [#&#8203;63644](https://github.com/nodejs/node/pull/63644) - \[[`9a29cb0964`](https://github.com/nodejs/node/commit/9a29cb0964)] - **crypto**: fix warnings in test\_node\_crypto.cc (Maya Lekova) [#&#8203;63490](https://github.com/nodejs/node/pull/63490) - \[[`8bb536066d`](https://github.com/nodejs/node/commit/8bb536066d)] - **crypto**: optimize normalizeAlgorithm dispatch hot path (Filip Skokan) [#&#8203;62756](https://github.com/nodejs/node/pull/62756) - \[[`329e5496ff`](https://github.com/nodejs/node/commit/329e5496ff)] - **crypto,tls**: do not ignore BN\_get\_word error (Tobias Nießen) [#&#8203;63895](https://github.com/nodejs/node/pull/63895) - \[[`97b7a3f9c7`](https://github.com/nodejs/node/commit/97b7a3f9c7)] - **debugger**: add --max-hit option to probe mode (Joyee Cheung) [#&#8203;63704](https://github.com/nodejs/node/pull/63704) - \[[`9098585c5e`](https://github.com/nodejs/node/commit/9098585c5e)] - **debugger**: add more logs to probe mode (Joyee Cheung) [#&#8203;63663](https://github.com/nodejs/node/pull/63663) - \[[`59cca26cd5`](https://github.com/nodejs/node/commit/59cca26cd5)] - **debugger**: surface inspector failures in probe mode (Joyee Cheung) [#&#8203;63437](https://github.com/nodejs/node/pull/63437) - \[[`2922290eae`](https://github.com/nodejs/node/commit/2922290eae)] - **debugger**: disambiguate probe location binding (Joyee Cheung) [#&#8203;63286](https://github.com/nodejs/node/pull/63286) - \[[`6fb2c2c7e2`](https://github.com/nodejs/node/commit/6fb2c2c7e2)] - **debugger**: lazily wait for initial break output (Trivikram Kamat) [#&#8203;63969](https://github.com/nodejs/node/pull/63969) - \[[`688e792551`](https://github.com/nodejs/node/commit/688e792551)] - **debugger**: defer probe pause handling until startup (Trivikram Kamat) [#&#8203;63608](https://github.com/nodejs/node/pull/63608) - \[[`1ac93cc05a`](https://github.com/nodejs/node/commit/1ac93cc05a)] - **debugger**: await initialization after run and restart (Trivikram Kamat) [#&#8203;63607](https://github.com/nodejs/node/pull/63607) - \[[`92a909cf72`](https://github.com/nodejs/node/commit/92a909cf72)] - **debugger,test**: deflake resume failure test and add debug logs (Joyee Cheung) [#&#8203;63524](https://github.com/nodejs/node/pull/63524) - \[[`8b37af8b11`](https://github.com/nodejs/node/commit/8b37af8b11)] - **deps**: V8: backport [`bef0d9c`](https://github.com/nodejs/node/commit/bef0d9c1bc90) (Joyee Cheung) [#&#8203;62132](https://github.com/nodejs/node/pull/62132) - \[[`8832126422`](https://github.com/nodejs/node/commit/8832126422)] - **deps**: V8: cherry-pick [`64b36b4`](https://github.com/nodejs/node/commit/64b36b441179) (Dan Carney) [#&#8203;61712](https://github.com/nodejs/node/pull/61712) - \[[`75990c2cd6`](https://github.com/nodejs/node/commit/75990c2cd6)] - **deps**: update googletest to [`8b53336`](https://github.com/nodejs/node/commit/8b53336594cc52213c6c2c7a0b29194fa896d039) (Node.js GitHub Bot) [#&#8203;64181](https://github.com/nodejs/node/pull/64181) - \[[`8500c7ba86`](https://github.com/nodejs/node/commit/8500c7ba86)] - **deps**: update sqlite to 3.53.3 (Node.js GitHub Bot) [#&#8203;64180](https://github.com/nodejs/node/pull/64180) - \[[`dc78091b45`](https://github.com/nodejs/node/commit/dc78091b45)] - **deps**: c-ares: cherry-pick [`8ba37af`](https://github.com/nodejs/node/commit/8ba37af8e3fb) (René) [#&#8203;64110](https://github.com/nodejs/node/pull/64110) - \[[`873cc72125`](https://github.com/nodejs/node/commit/873cc72125)] - **deps**: update googletest to [`0b1e895`](https://github.com/nodejs/node/commit/0b1e895ba4226c2fda5ee0178c9b5b1195a741aa) (Node.js GitHub Bot) [#&#8203;64039](https://github.com/nodejs/node/pull/64039) - \[[`1d3d166538`](https://github.com/nodejs/node/commit/1d3d166538)] - **deps**: update acorn to 8.17.0 (Node.js GitHub Bot) [#&#8203;63901](https://github.com/nodejs/node/pull/63901) - \[[`35222948be`](https://github.com/nodejs/node/commit/35222948be)] - **(SEMVER-MINOR)** **deps**: update OpenSSL build config to support compression (Tim Perry) [#&#8203;62217](https://github.com/nodejs/node/pull/62217) - \[[`e40cee5f79`](https://github.com/nodejs/node/commit/e40cee5f79)] - **deps**: upgrade npm to 11.17.0 (npm team) [#&#8203;63857](https://github.com/nodejs/node/pull/63857) - \[[`85c6d46606`](https://github.com/nodejs/node/commit/85c6d46606)] - **deps**: add ngtcp2\_fmt.c to build configuration (ngtcp2.gyp) (沈鸿飞) [#&#8203;63821](https://github.com/nodejs/node/pull/63821) - \[[`d2ea8b7a8c`](https://github.com/nodejs/node/commit/d2ea8b7a8c)] - **deps**: update googletest to [`7140cd4`](https://github.com/nodejs/node/commit/7140cd416cecd7462a8aae488024abeee55598e4) (Node.js GitHub Bot) [#&#8203;63775](https://github.com/nodejs/node/pull/63775) - \[[`25b4d57bb6`](https://github.com/nodejs/node/commit/25b4d57bb6)] - **deps**: update sqlite to 3.53.2 (Node.js GitHub Bot) [#&#8203;63774](https://github.com/nodejs/node/pull/63774) - \[[`a96368e4c7`](https://github.com/nodejs/node/commit/a96368e4c7)] - **deps**: update zlib to 1.3.2.1-motley-3246f1b (Node.js GitHub Bot) [#&#8203;63773](https://github.com/nodejs/node/pull/63773) - \[[`b59f1f5f37`](https://github.com/nodejs/node/commit/b59f1f5f37)] - **deps**: update amaro to 1.1.10 (Node.js GitHub Bot) [#&#8203;63670](https://github.com/nodejs/node/pull/63670) - \[[`0b3b56ee95`](https://github.com/nodejs/node/commit/0b3b56ee95)] - **deps**: update googletest to [`8736d2c`](https://github.com/nodejs/node/commit/8736d2cd5c1dcba41170ed2fddca14021d4916c3) (Node.js GitHub Bot) [#&#8203;63669](https://github.com/nodejs/node/pull/63669) - \[[`aa67b5b9c4`](https://github.com/nodejs/node/commit/aa67b5b9c4)] - **dgram**: add synchronous Socket connectSync() (Guy Bedford) [#&#8203;63932](https://github.com/nodejs/node/pull/63932) - \[[`ef38374875`](https://github.com/nodejs/node/commit/ef38374875)] - **dgram**: add synchronous Socket.prototype.bindSync() (Guy Bedford) [#&#8203;63838](https://github.com/nodejs/node/pull/63838) - \[[`6edc3a9967`](https://github.com/nodejs/node/commit/6edc3a9967)] - **dgram**: skip dns.lookup() for literal IP addresses (Ruben Bridgewater) [#&#8203;64133](https://github.com/nodejs/node/pull/64133) - \[[`d4cfe2d8ac`](https://github.com/nodejs/node/commit/d4cfe2d8ac)] - **dns**: coerce -0 to +0 in lookup and resolver inputs (Filip Skokan) [#&#8203;63556](https://github.com/nodejs/node/pull/63556) - \[[`91c9ce5a45`](https://github.com/nodejs/node/commit/91c9ce5a45)] - **doc**: improve `fs.StatFs` properties descriptions (aymanxdev) [#&#8203;62578](https://github.com/nodejs/node/pull/62578) - \[[`54e21675fa`](https://github.com/nodejs/node/commit/54e21675fa)] - **doc**: fix inconsistencies in CJS code snippets (Antoine du Hamel) [#&#8203;63199](https://github.com/nodejs/node/pull/63199) - \[[`64c23daa76`](https://github.com/nodejs/node/commit/64c23daa76)] - **doc**: remove typo comma from man page (Vas Sudanagunta) [#&#8203;63080](https://github.com/nodejs/node/pull/63080) - \[[`bc943cd34a`](https://github.com/nodejs/node/commit/bc943cd34a)] - **doc**: update Http2SecureServer.on("timeout") default value (YuSheng Chen) [#&#8203;64187](https://github.com/nodejs/node/pull/64187) - \[[`a46bc452a6`](https://github.com/nodejs/node/commit/a46bc452a6)] - **doc**: add note on visibility of CI failures to new contributor guide (Stewart X Addison) [#&#8203;64256](https://github.com/nodejs/node/pull/64256) - \[[`c0fb52506c`](https://github.com/nodejs/node/commit/c0fb52506c)] - **doc**: clarify HTTP/1.1 response ordering (Matteo Collina) [#&#8203;64213](https://github.com/nodejs/node/pull/64213) - \[[`d3073a7ba6`](https://github.com/nodejs/node/commit/d3073a7ba6)] - **doc**: recommend node-stress-single-test for flaky tests (Trivikram Kamat) [#&#8203;64223](https://github.com/nodejs/node/pull/64223) - \[[`bb9951ead0`](https://github.com/nodejs/node/commit/bb9951ead0)] - **doc**: fix typo in examples (Vas Sudanagunta) [#&#8203;64184](https://github.com/nodejs/node/pull/64184) - \[[`fe674e96fc`](https://github.com/nodejs/node/commit/fe674e96fc)] - **doc**: clarify defense-in-depth issues (Matteo Collina) [#&#8203;64215](https://github.com/nodejs/node/pull/64215) - \[[`faad042184`](https://github.com/nodejs/node/commit/faad042184)] - **doc**: add guide and answers to FAQs for first-time contributors (Joyee Cheung) [#&#8203;63685](https://github.com/nodejs/node/pull/63685) - \[[`79d685adf3`](https://github.com/nodejs/node/commit/79d685adf3)] - **doc**: update `Http2Server.close` & `Http2SecureServer.close` (YuSheng Chen) [#&#8203;63298](https://github.com/nodejs/node/pull/63298) - \[[`744e40e05e`](https://github.com/nodejs/node/commit/744e40e05e)] - **doc**: update list of people in `SECURITY.md` (Richard Lau) [#&#8203;64152](https://github.com/nodejs/node/pull/64152) - \[[`185f57c4a4`](https://github.com/nodejs/node/commit/185f57c4a4)] - **doc**: add missing option to man page (Richard Lau) [#&#8203;64156](https://github.com/nodejs/node/pull/64156) - \[[`8933303568`](https://github.com/nodejs/node/commit/8933303568)] - **doc**: fix callback example import in fs docs (Kamal Rawal) [#&#8203;63912](https://github.com/nodejs/node/pull/63912) - \[[`3a0549dacb`](https://github.com/nodejs/node/commit/3a0549dacb)] - **doc**: fix keepAliveTimeout default in http.createServer options (Jahanzaib iqbal) [#&#8203;63974](https://github.com/nodejs/node/pull/63974) - \[[`5a35e48d08`](https://github.com/nodejs/node/commit/5a35e48d08)] - **doc**: add sxa GPG key ([`ed25519`](https://github.com/nodejs/node/commit/ed25519)) (Stewart X Addison) [#&#8203;64193](https://github.com/nodejs/node/pull/64193) - \[[`66e7f815f1`](https://github.com/nodejs/node/commit/66e7f815f1)] - **doc**: add aduh95 to last security release steward (Antoine du Hamel) [#&#8203;63981](https://github.com/nodejs/node/pull/63981) - \[[`a7e35040dd`](https://github.com/nodejs/node/commit/a7e35040dd)] - **doc**: fix typo in util.md (Daijiro Wachi) [#&#8203;63961](https://github.com/nodejs/node/pull/63961) - \[[`d74b3a7e90`](https://github.com/nodejs/node/commit/d74b3a7e90)] - **doc**: clarify callback exceptions (Matteo Collina) [#&#8203;63939](https://github.com/nodejs/node/pull/63939) - \[[`b7a8f8fabd`](https://github.com/nodejs/node/commit/b7a8f8fabd)] - **doc**: fix incorrect test runner mock examples (Kimaswa Emmanuel Yusufu) [#&#8203;63656](https://github.com/nodejs/node/pull/63656) - \[[`f11aa690cd`](https://github.com/nodejs/node/commit/f11aa690cd)] - **doc**: fix typo in cli.md (Daijiro Wachi) [#&#8203;63883](https://github.com/nodejs/node/pull/63883) - \[[`df85f50269`](https://github.com/nodejs/node/commit/df85f50269)] - **doc**: fix typo in vm.md (Daijiro Wachi) [#&#8203;63881](https://github.com/nodejs/node/pull/63881) - \[[`a00a567175`](https://github.com/nodejs/node/commit/a00a567175)] - **doc**: fix typo in packages.md (Daijiro Wachi) [#&#8203;63882](https://github.com/nodejs/node/pull/63882) - \[[`206c1b8437`](https://github.com/nodejs/node/commit/206c1b8437)] - **doc**: fix a/an article typos in module, util, and dns (Daijiro Wachi) [#&#8203;63766](https://github.com/nodejs/node/pull/63766) - \[[`e3e5ef1cff`](https://github.com/nodejs/node/commit/e3e5ef1cff)] - **doc**: update npm supported versions link (hojeong park) [#&#8203;63672](https://github.com/nodejs/node/pull/63672) - \[[`e3c4852413`](https://github.com/nodejs/node/commit/e3c4852413)] - **doc**: fix AES-OCB IV length in SubtleCrypto.supports example (Anshika Jain) [#&#8203;63717](https://github.com/nodejs/node/pull/63717) - \[[`0b3fbc82d7`](https://github.com/nodejs/node/commit/0b3fbc82d7)] - **doc**: add webstreams to args for `pipeline` from `stream/promises` (David Sanders) [#&#8203;63628](https://github.com/nodejs/node/pull/63628) - \[[`62078a8328`](https://github.com/nodejs/node/commit/62078a8328)] - **doc**: fix "used to sent" → "used to send" in http2 (Daijiro Wachi) [#&#8203;63700](https://github.com/nodejs/node/pull/63700) - \[[`fd74eefb23`](https://github.com/nodejs/node/commit/fd74eefb23)] - **doc**: clarify tty raw mode applies to input processing only (Muhammad Zeeshan) [#&#8203;63438](https://github.com/nodejs/node/pull/63438) - \[[`42cd7e47de`](https://github.com/nodejs/node/commit/42cd7e47de)] - **doc**: add worker\_threads history entries (Bob Put) [#&#8203;63545](https://github.com/nodejs/node/pull/63545) - \[[`d6ab039f24`](https://github.com/nodejs/node/commit/d6ab039f24)] - **(SEMVER-MINOR)** **doc**: update `blockList` stability status to release candidate (alphaleadership) [#&#8203;63050](https://github.com/nodejs/node/pull/63050) - \[[`56bdd87378`](https://github.com/nodejs/node/commit/56bdd87378)] - **doc**: move hyperlinks outside of text blocks (Aviv Keller) [#&#8203;63493](https://github.com/nodejs/node/pull/63493) - \[[`1da05fb79d`](https://github.com/nodejs/node/commit/1da05fb79d)] - **doc**: mark stream.compose stable (Matteo Collina) [#&#8203;62562](https://github.com/nodejs/node/pull/62562) - \[[`7bb6dab70c`](https://github.com/nodejs/node/commit/7bb6dab70c)] - **doc,crypto**: mark argon2 and encap/decap as stable (Filip Skokan) [#&#8203;63924](https://github.com/nodejs/node/pull/63924) - \[[`1a4edb3c22`](https://github.com/nodejs/node/commit/1a4edb3c22)] - **doc,lib**: align WebCrypto names with spec (Filip Skokan) [#&#8203;63518](https://github.com/nodejs/node/pull/63518) - \[[`3c1636dabf`](https://github.com/nodejs/node/commit/3c1636dabf)] - **(SEMVER-MINOR)** **esm**: add `--experimental-import-text` flag (Efe) [#&#8203;62300](https://github.com/nodejs/node/pull/62300) - \[[`e0f211ca79`](https://github.com/nodejs/node/commit/e0f211ca79)] - **events**: improve `addAbortListener` perf by caching options object (Raz Luvaton) [#&#8203;52367](https://github.com/nodejs/node/pull/52367) - \[[`a124429b36`](https://github.com/nodejs/node/commit/a124429b36)] - **fs**: do not treat EPERM as ENOTEMPTY on Windows (Kirill Saied) [#&#8203;63709](https://github.com/nodejs/node/pull/63709) - \[[`e323e877be`](https://github.com/nodejs/node/commit/e323e877be)] - **(SEMVER-MINOR)** **fs**: support caller-supplied readFile() buffers (Matteo Collina) [#&#8203;63634](https://github.com/nodejs/node/pull/63634) - \[[`a41b4824d7`](https://github.com/nodejs/node/commit/a41b4824d7)] - **fs**: prevent spurious recursive watch events on prefix siblings (Marco) [#&#8203;63095](https://github.com/nodejs/node/pull/63095) - \[[`c63e00e3a5`](https://github.com/nodejs/node/commit/c63e00e3a5)] - **fs**: ignore deleted dirs in recursive watch scan (Trivikram Kamat) [#&#8203;63686](https://github.com/nodejs/node/pull/63686) - \[[`d3d7cd05e3`](https://github.com/nodejs/node/commit/d3d7cd05e3)] - **fs**: coerce -0 to +0 in mode flags and watch intervals (Filip Skokan) [#&#8203;63556](https://github.com/nodejs/node/pull/63556) - \[[`6f6387ecb3`](https://github.com/nodejs/node/commit/6f6387ecb3)] - **gyp**: update deps gypfiles (Nad Alaba) [#&#8203;63117](https://github.com/nodejs/node/pull/63117) - \[[`592544af44`](https://github.com/nodejs/node/commit/592544af44)] - **http**: document and validate options.path when it's in absolute-form (Joyee Cheung) [#&#8203;64108](https://github.com/nodejs/node/pull/64108) - \[[`c1248c9544`](https://github.com/nodejs/node/commit/c1248c9544)] - **(SEMVER-MINOR)** **http**: add httpValidation option to configure header value validation (RajeshKumar11) [#&#8203;61597](https://github.com/nodejs/node/pull/61597) - \[[`85a223bf15`](https://github.com/nodejs/node/commit/85a223bf15)] - **http**: fix drain event with cork/uncork (David Evans) [#&#8203;64038](https://github.com/nodejs/node/pull/64038) - \[[`8b060a9628`](https://github.com/nodejs/node/commit/8b060a9628)] - **inspector**: fix crash when writing to closed inspector socket (ympark2011) [#&#8203;64209](https://github.com/nodejs/node/pull/64209) - \[[`e68a3d33ac`](https://github.com/nodejs/node/commit/e68a3d33ac)] - **inspector**: fix inspector.close() documented behavior (Chengzhong Wu) [#&#8203;63837](https://github.com/nodejs/node/pull/63837) - \[[`d3682930b7`](https://github.com/nodejs/node/commit/d3682930b7)] - **lib**: fix missing lazyDOMException import (Filip Skokan) [#&#8203;64033](https://github.com/nodejs/node/pull/64033) - \[[`af9ea9cfcf`](https://github.com/nodejs/node/commit/af9ea9cfcf)] - **lib**: reject string "0" in validatePort when allowZero is false (Daijiro Wachi) [#&#8203;64174](https://github.com/nodejs/node/pull/64174) - \[[`cd1ea26110`](https://github.com/nodejs/node/commit/cd1ea26110)] - **lib**: use `__proto__: null` when calling `ObjectDefineProperty` (Antoine du Hamel) [#&#8203;64239](https://github.com/nodejs/node/pull/64239) - \[[`5b264398ce`](https://github.com/nodejs/node/commit/5b264398ce)] - **lib**: lazily initialize kEvents and kHandlers maps (Guilherme Araújo) [#&#8203;63702](https://github.com/nodejs/node/pull/63702) - \[[`823efe8c71`](https://github.com/nodejs/node/commit/823efe8c71)] - **lib**: improve control abstraction coverage in frozen intrinsics (Renegade334) [#&#8203;63698](https://github.com/nodejs/node/pull/63698) - \[[`7f4af5568f`](https://github.com/nodejs/node/commit/7f4af5568f)] - **lib**: add Iterator global to primordials (Renegade334) [#&#8203;63698](https://github.com/nodejs/node/pull/63698) - \[[`c8f3f5e5a5`](https://github.com/nodejs/node/commit/c8f3f5e5a5)] - **lib**: make `Navigator#language` getter throw on invalid `this` (Mohamed Sayed) [#&#8203;63601](https://github.com/nodejs/node/pull/63601) - \[[`1ebbbd59cf`](https://github.com/nodejs/node/commit/1ebbbd59cf)] - **lib**: optimize webidl conversion options (Filip Skokan) [#&#8203;62756](https://github.com/nodejs/node/pull/62756) - \[[`88590d1bb7`](https://github.com/nodejs/node/commit/88590d1bb7)] - **meta**: bump actions/checkout from 6.0.2 to 6.0.3 (dependabot\[bot]) [#&#8203;63726](https://github.com/nodejs/node/pull/63726) - \[[`0ea9cb9630`](https://github.com/nodejs/node/commit/0ea9cb9630)] - **meta**: bump actions/upload-artifact from 7.0.0 to 7.0.1 (dependabot\[bot]) [#&#8203;62850](https://github.com/nodejs/node/pull/62850) - \[[`f7275a0864`](https://github.com/nodejs/node/commit/f7275a0864)] - **meta**: fix linter warning in `stale.yml` (Antoine du Hamel) [#&#8203;64281](https://github.com/nodejs/node/pull/64281) - \[[`3a77d21d8c`](https://github.com/nodejs/node/commit/3a77d21d8c)] - **meta**: bump actions/cache from 5.0.5 to 6.1.0 (dependabot\[bot]) [#&#8203;64248](https://github.com/nodejs/node/pull/64248) - \[[`84e2836c95`](https://github.com/nodejs/node/commit/84e2836c95)] - **meta**: bump github/codeql-action/autobuild from 4.36.1 to 4.36.2 (dependabot\[bot]) [#&#8203;64247](https://github.com/nodejs/node/pull/64247) - \[[`09f800eec6`](https://github.com/nodejs/node/commit/09f800eec6)] - **meta**: bump github/codeql-action/analyze from 4.36.1 to 4.36.2 (dependabot\[bot]) [#&#8203;64246](https://github.com/nodejs/node/pull/64246) - \[[`6df1f97e64`](https://github.com/nodejs/node/commit/6df1f97e64)] - **meta**: bump codecov/codecov-action from 6.0.1 to 7.0.0 (dependabot\[bot]) [#&#8203;64244](https://github.com/nodejs/node/pull/64244) - \[[`737eb89651`](https://github.com/nodejs/node/commit/737eb89651)] - **meta**: bump rtCamp/action-slack-notify from 2.3.3 to 2.4.0 (dependabot\[bot]) [#&#8203;64243](https://github.com/nodejs/node/pull/64243) - \[[`dac3cd8b8f`](https://github.com/nodejs/node/commit/dac3cd8b8f)] - **meta**: bump github/codeql-action/init from 4.36.1 to 4.36.2 (dependabot\[bot]) [#&#8203;64242](https://github.com/nodejs/node/pull/64242) - \[[`108a6bc481`](https://github.com/nodejs/node/commit/108a6bc481)] - **meta**: bump github/codeql-action/upload-sarif from 4.36.1 to 4.36.2 (dependabot\[bot]) [#&#8203;64240](https://github.com/nodejs/node/pull/64240) - \[[`34d09a725d`](https://github.com/nodejs/node/commit/34d09a725d)] - **meta**: clarify V8 flags are outside threat model (Matteo Collina) [#&#8203;64224](https://github.com/nodejs/node/pull/64224) - \[[`944d9bc25f`](https://github.com/nodejs/node/commit/944d9bc25f)] - **meta**: move one or more collaborators to emeritus (Node.js GitHub Bot) [#&#8203;64057](https://github.com/nodejs/node/pull/64057) - \[[`cc22555402`](https://github.com/nodejs/node/commit/cc22555402)] - **meta**: update status of past strategic initiatives (Joyee Cheung) [#&#8203;63480](https://github.com/nodejs/node/pull/63480) - \[[`da7a21931e`](https://github.com/nodejs/node/commit/da7a21931e)] - **meta**: speed up stale bot (Aviv Keller) [#&#8203;64075](https://github.com/nodejs/node/pull/64075) - \[[`7bfcf7ca56`](https://github.com/nodejs/node/commit/7bfcf7ca56)] - **meta**: bump github/codeql-action from 4.35.3 to 4.36.1 (dependabot\[bot]) [#&#8203;63724](https://github.com/nodejs/node/pull/63724) - \[[`db6c983cdd`](https://github.com/nodejs/node/commit/db6c983cdd)] - **meta**: bump actions/cache from 5.0.4 to 5.0.5 (dependabot\[bot]) [#&#8203;62847](https://github.com/nodejs/node/pull/62847) - \[[`9e4f1339d1`](https://github.com/nodejs/node/commit/9e4f1339d1)] - **meta**: bump codecov/codecov-action from 6.0.0 to 6.0.1 (dependabot\[bot]) [#&#8203;63725](https://github.com/nodejs/node/pull/63725) - \[[`92c98d3ade`](https://github.com/nodejs/node/commit/92c98d3ade)] - **meta**: bump actions/stale from 10.2.0 to 10.3.0 (dependabot\[bot]) [#&#8203;63728](https://github.com/nodejs/node/pull/63728) - \[[`bbd3ffde89`](https://github.com/nodejs/node/commit/bbd3ffde89)] - **meta**: bump step-security/harden-runner from 2.19.0 to 2.19.4 (dependabot\[bot]) [#&#8203;63727](https://github.com/nodejs/node/pull/63727) - \[[`a6dd675c82`](https://github.com/nodejs/node/commit/a6dd675c82)] - **module**: enable import support for addons by default (Chengzhong Wu) [#&#8203;64221](https://github.com/nodejs/node/pull/64221) - \[[`fb2ccb15a1`](https://github.com/nodejs/node/commit/fb2ccb15a1)] - **module**: use file: URL as sourceURL for type-stripped CommonJS (Joyee Cheung) [#&#8203;63705](https://github.com/nodejs/node/pull/63705) - \[[`b9e17dc424`](https://github.com/nodejs/node/commit/b9e17dc424)] - **net**: early TCP binding via synchronous net.BoundSocket (Guy Bedford) [#&#8203;63951](https://github.com/nodejs/node/pull/63951) - \[[`a534b65815`](https://github.com/nodejs/node/commit/a534b65815)] - **(SEMVER-MINOR)** **net**: support TCP\_KEEPINTVL and TCP\_KEEPCNT in setKeepAlive (Guy Bedford) [#&#8203;63825](https://github.com/nodejs/node/pull/63825) - \[[`c55dd030e6`](https://github.com/nodejs/node/commit/c55dd030e6)] - **net**: coerce -0 to +0 in BlockList prefixes (Filip Skokan) [#&#8203;63556](https://github.com/nodejs/node/pull/63556) - \[[`a23cdec683`](https://github.com/nodejs/node/commit/a23cdec683)] - **(SEMVER-MINOR)** **perf\_hooks**: sample delay per event loop iteration (Pablo Erhard) [#&#8203;62935](https://github.com/nodejs/node/pull/62935) - \[[`f08b83bc1d`](https://github.com/nodejs/node/commit/f08b83bc1d)] - **perf\_hooks**: add NODE\_PERFORMANCE\_GC\_MINOR\_MARK\_SWEEP constant (Attila Szegedi) [#&#8203;63877](https://github.com/nodejs/node/pull/63877) - \[[`8d58e1b415`](https://github.com/nodejs/node/commit/8d58e1b415)] - **process**: fix finalization cleanup ref tracking (Trivikram Kamat) [#&#8203;64087](https://github.com/nodejs/node/pull/64087) - \[[`c757e3ef59`](https://github.com/nodejs/node/commit/c757e3ef59)] - **sqlite**: do not leave database open after failed open (Yagiz Nizipli) [#&#8203;63854](https://github.com/nodejs/node/pull/63854) - \[[`87064a096b`](https://github.com/nodejs/node/commit/87064a096b)] - **sqlite**: fix stack-use-after-scope with function callback (ndossche) [#&#8203;63640](https://github.com/nodejs/node/pull/63640) - \[[`7428b57a37`](https://github.com/nodejs/node/commit/7428b57a37)] - **(SEMVER-MINOR)** **src**: allow empty --experimental-config-file (Marco Ippolito) [#&#8203;61610](https://github.com/nodejs/node/pull/61610) - \[[`d7946c9c07`](https://github.com/nodejs/node/commit/d7946c9c07)] - **src**: add test flag to config file (Marco Ippolito) [#&#8203;60798](https://github.com/nodejs/node/pull/60798) - \[[`a642657d71`](https://github.com/nodejs/node/commit/a642657d71)] - **src**: rename config file testRunner to test (Marco Ippolito) [#&#8203;60798](https://github.com/nodejs/node/pull/60798) - \[[`818b43d09e`](https://github.com/nodejs/node/commit/818b43d09e)] - **src**: do not enable wasm trap handler if there's not enough vmem (Joyee Cheung) [#&#8203;62132](https://github.com/nodejs/node/pull/62132) - \[[`af5e1a9729`](https://github.com/nodejs/node/commit/af5e1a9729)] - **src**: fix escaping of single quotes in task runner (Antoine du Hamel) [#&#8203;64089](https://github.com/nodejs/node/pull/64089) - \[[`8a5d3bc168`](https://github.com/nodejs/node/commit/8a5d3bc168)] - **src**: abstract tracing agent for both legacy and perfetto (Chengzhong Wu) [#&#8203;64053](https://github.com/nodejs/node/pull/64053) - \[[`ce6f29e45b`](https://github.com/nodejs/node/commit/ce6f29e45b)] - **src**: avoid redundant call to `std::get_if<>()` (Tobias Nießen) [#&#8203;64094](https://github.com/nodejs/node/pull/64094) - \[[`96478050f2`](https://github.com/nodejs/node/commit/96478050f2)] - **src**: omit unconvertible names in cjs\_lexer::Parse (Yagiz Nizipli) [#&#8203;63943](https://github.com/nodejs/node/pull/63943) - \[[`0147ed746e`](https://github.com/nodejs/node/commit/0147ed746e)] - **src**: guard OpenSSL compression header include (Filip Skokan) [#&#8203;64009](https://github.com/nodejs/node/pull/64009) - \[[`8d2858a9c4`](https://github.com/nodejs/node/commit/8d2858a9c4)] - **src**: handle empty MaybeLocal in cjs\_lexer::Parse (Yagiz Nizipli) [#&#8203;63885](https://github.com/nodejs/node/pull/63885) - \[[`e5289d180f`](https://github.com/nodejs/node/commit/e5289d180f)] - **src**: do not track weak `BaseObject`s as childrens of `Realm`s (Anna Henningsen) [#&#8203;63842](https://github.com/nodejs/node/pull/63842) - \[[`e8352ff754`](https://github.com/nodejs/node/commit/e8352ff754)] - **src**: allow tracking children in `MemoryTracker` with weak edges (Anna Henningsen) [#&#8203;63842](https://github.com/nodejs/node/pull/63842) - \[[`a408f279c5`](https://github.com/nodejs/node/commit/a408f279c5)] - **src**: use C++14 deprecated attribute for `NODE_DEPRECATED` (Anna Henningsen) [#&#8203;63755](https://github.com/nodejs/node/pull/63755) - \[[`4b5eb7b72d`](https://github.com/nodejs/node/commit/4b5eb7b72d)] - **src**: add cleanup hooks to `node::ObjectWrap` (Anna Henningsen) [#&#8203;63642](https://github.com/nodejs/node/pull/63642) - \[[`44976c6071`](https://github.com/nodejs/node/commit/44976c6071)] - **src**: fix edge case when deflateInit2() fails with Z\_VERSION\_ERROR (Nora Dossche) [#&#8203;63476](https://github.com/nodejs/node/pull/63476) - \[[`5b3bb284f3`](https://github.com/nodejs/node/commit/5b3bb284f3)] - **src**: add Latin1 fast path in StringBytes::Encode utf8 (Mert Can Altin) [#&#8203;63385](https://github.com/nodejs/node/pull/63385) - \[[`7cdad636c4`](https://github.com/nodejs/node/commit/7cdad636c4)] - **src**: fix crash when reading length on Storage.prototype (Mohamed Sayed) [#&#8203;63529](https://github.com/nodejs/node/pull/63529) - \[[`c438250c68`](https://github.com/nodejs/node/commit/c438250c68)] - **stream**: cut per-chunk overhead in WHATWG streams (Matteo Collina) [#&#8203;64252](https://github.com/nodejs/node/pull/64252) - \[[`291c127947`](https://github.com/nodejs/node/commit/291c127947)] - **stream**: reduce allocations on WHATWG streams hot paths (Matteo Collina) [#&#8203;63876](https://github.com/nodejs/node/pull/63876) - \[[`3d91aeb434`](https://github.com/nodejs/node/commit/3d91aeb434)] - **stream**: optimize pipeTo promise handling (Matteo Collina) [#&#8203;63572](https://github.com/nodejs/node/pull/63572) - \[[`fcbff00a44`](https://github.com/nodejs/node/commit/fcbff00a44)] - **stream**: preserve half-open duplexes in async iteration (Efe) [#&#8203;64275](https://github.com/nodejs/node/pull/64275) - \[[`e57597173c`](https://github.com/nodejs/node/commit/e57597173c)] - **(SEMVER-MINOR)** **stream**: expose ReadableStreamTee (Matteo Collina) [#&#8203;64195](https://github.com/nodejs/node/pull/64195) - \[[`a48edf40e8`](https://github.com/nodejs/node/commit/a48edf40e8)] - **stream**: proxy first own method in Readable.wrap() (Daijiro Wachi) [#&#8203;64048](https://github.com/nodejs/node/pull/64048) - \[[`f58c5bafcf`](https://github.com/nodejs/node/commit/f58c5bafcf)] - **stream**: fix Writable.toWeb() desiredSize for non-object-mode (Matteo Collina) [#&#8203;62986](https://github.com/nodejs/node/pull/62986) - \[[`7261276f45`](https://github.com/nodejs/node/commit/7261276f45)] - **stream**: fix Utf8Stream stall after full write of multi-byte data (Daijiro Wachi) [#&#8203;63964](https://github.com/nodejs/node/pull/63964) - \[[`1558986b78`](https://github.com/nodejs/node/commit/1558986b78)] - **stream**: only pass the expected number of parameters to callbacks (Antoine du Hamel) [#&#8203;63909](https://github.com/nodejs/node/pull/63909) - \[[`edef89ba6a`](https://github.com/nodejs/node/commit/edef89ba6a)] - **stream**: fix dropped first chunk in Utf8Stream buffer mode (Daijiro Wachi) [#&#8203;63833](https://github.com/nodejs/node/pull/63833) - \[[`915e3e2f42`](https://github.com/nodejs/node/commit/915e3e2f42)] - **stream**: check done before backpressure in stream reader (Daijiro Wachi) [#&#8203;63699](https://github.com/nodejs/node/pull/63699) - \[[`2d29628b5b`](https://github.com/nodejs/node/commit/2d29628b5b)] - **test**: update WPT for WebCryptoAPI to [`03a1476`](https://github.com/nodejs/node/commit/03a1476844) (Node.js GitHub Bot) [#&#8203;63900](https://github.com/nodejs/node/pull/63900) - \[[`89e23b70c4`](https://github.com/nodejs/node/commit/89e23b70c4)] - **test**: deflake test-debugger-probe-timeout (Joyee Cheung) [#&#8203;63547](https://github.com/nodejs/node/pull/63547) - \[[`54ca514414`](https://github.com/nodejs/node/commit/54ca514414)] - **test**: make blob desiredSize assertion robust (Trivikram Kamat) [#&#8203;64106](https://github.com/nodejs/node/pull/64106) - \[[`01cbe530eb`](https://github.com/nodejs/node/commit/01cbe530eb)] - **test**: update WPT for urlpattern to [`11a459a`](https://github.com/nodejs/node/commit/11a459a2b1) (Node.js GitHub Bot) [#&#8203;64037](https://github.com/nodejs/node/pull/64037) - \[[`6fcd3cf516`](https://github.com/nodejs/node/commit/6fcd3cf516)] - **test**: improve lcov reporter snapshot diagnostics (Trivikram Kamat) [#&#8203;64049](https://github.com/nodejs/node/pull/64049) - \[[`f50a55d7e5`](https://github.com/nodejs/node/commit/f50a55d7e5)] - **test**: keep finalization close fixture ref alive (Trivikram Kamat) [#&#8203;64085](https://github.com/nodejs/node/pull/64085) - \[[`3085714530`](https://github.com/nodejs/node/commit/3085714530)] - **test**: fix typo from overriden to overridden (parkhojeong) [#&#8203;63403](https://github.com/nodejs/node/pull/63403) - \[[`9f5347e8df`](https://github.com/nodejs/node/commit/9f5347e8df)] - **test**: mark hr-time WPT flaky on macos15-x64 (Trivikram Kamat) [#&#8203;64054](https://github.com/nodejs/node/pull/64054) - \[[`44b4fe4246`](https://github.com/nodejs/node/commit/44b4fe4246)] - **test**: use one-off agent in http consumed timeout test (Trivikram Kamat) [#&#8203;64052](https://github.com/nodejs/node/pull/64052) - \[[`2f567edaca`](https://github.com/nodejs/node/commit/2f567edaca)] - **test**: fix flaky test-runner coverage threshold test (Trivikram Kamat) [#&#8203;64051](https://github.com/nodejs/node/pull/64051) - \[[`a56fbb2d36`](https://github.com/nodejs/node/commit/a56fbb2d36)] - **test**: tolerate duplicate watch change events (Trivikram Kamat) [#&#8203;63937](https://github.com/nodejs/node/pull/63937) - \[[`b636f4769c`](https://github.com/nodejs/node/commit/b636f4769c)] - **test**: mark test-debugger-run-after-quit-restart as flaky on macOS (Matteo Collina) [#&#8203;64006](https://github.com/nodejs/node/pull/64006) - \[[`ba23eb9717`](https://github.com/nodejs/node/commit/ba23eb9717)] - **test**: update WPT for url to [`d4598eb`](https://github.com/nodejs/node/commit/d4598eba09) (Node.js GitHub Bot) [#&#8203;63899](https://github.com/nodejs/node/pull/63899) - \[[`bc420f20d8`](https://github.com/nodejs/node/commit/bc420f20d8)] - **test**: update WPT for urlpattern to [`23aac92`](https://github.com/nodejs/node/commit/23aac92784) (Node.js GitHub Bot) [#&#8203;63898](https://github.com/nodejs/node/pull/63898) - \[[`d2c9c07af8`](https://github.com/nodejs/node/commit/d2c9c07af8)] - **test**: add tests for 3 methods in utils (Daijiro Wachi) [#&#8203;63765](https://github.com/nodejs/node/pull/63765) - \[[`4e00c8ec2e`](https://github.com/nodejs/node/commit/4e00c8ec2e)] - **test**: mark SEA tests flaky on linux arm debug (Trivikram Kamat) [#&#8203;63743](https://github.com/nodejs/node/pull/63743) - \[[`a17cf06d12`](https://github.com/nodejs/node/commit/a17cf06d12)] - **test**: validate ERR\_INVALID\_THIS for scheduler methods (Daijiro Wachi) [#&#8203;63764](https://github.com/nodejs/node/pull/63764) - \[[`d59d7fdd16`](https://github.com/nodejs/node/commit/d59d7fdd16)] - **test**: add coverage outside SEA (Daijiro Wachi) [#&#8203;63744](https://github.com/nodejs/node/pull/63744) - \[[`71a32d31bf`](https://github.com/nodejs/node/commit/71a32d31bf)] - **test**: update WPT for urlpattern to [`2f28df5`](https://github.com/nodejs/node/commit/2f28df545c) (Node.js GitHub Bot) [#&#8203;63771](https://github.com/nodejs/node/pull/63771) - \[[`28c77ab174`](https://github.com/nodejs/node/commit/28c77ab174)] - **test**: make Brotli 16GB test wait for backpressure (Trivikram Kamat) [#&#8203;63389](https://github.com/nodejs/node/pull/63389) - \[[`9a81921d4a`](https://github.com/nodejs/node/commit/9a81921d4a)] - **test**: add regression test for using `ObjectWrap` in worker (Mohamed Akram) [#&#8203;63642](https://github.com/nodejs/node/pull/63642) - \[[`88ab61f2f8`](https://github.com/nodejs/node/commit/88ab61f2f8)] - **test**: accept SIGILL aborts in async-hooks tests (Trivikram Kamat) [#&#8203;63687](https://github.com/nodejs/node/pull/63687) - \[[`b4f5c86463`](https://github.com/nodejs/node/commit/b4f5c86463)] - **test**: add more test cases for pathToFileURL (Rafael Gonzaga) [#&#8203;63293](https://github.com/nodejs/node/pull/63293) - \[[`812a66f0ac`](https://github.com/nodejs/node/commit/812a66f0ac)] - **test**: update test426-fixtures to [`2965987`](https://github.com/nodejs/node/commit/2965987bf4c96afa400c9356c8e620cb340aaee) (Node.js GitHub Bot) [#&#8203;63668](https://github.com/nodejs/node/pull/63668) - \[[`2bf0de838d`](https://github.com/nodejs/node/commit/2bf0de838d)] - **test**: cover webcrypto prototype pollution systematically (Filip Skokan) [#&#8203;63520](https://github.com/nodejs/node/pull/63520) - \[[`bec6856ae8`](https://github.com/nodejs/node/commit/bec6856ae8)] - **test,debugger**: add test for type stripping in debugger probe mode (Joyee Cheung) [#&#8203;63748](https://github.com/nodejs/node/pull/63748) - \[[`a2b9095e03`](https://github.com/nodejs/node/commit/a2b9095e03)] - **test\_runner**: avoid recompiling coverage globs for every file (sangwook) [#&#8203;63675](https://github.com/nodejs/node/pull/63675) - \[[`02fbff446f`](https://github.com/nodejs/node/commit/02fbff446f)] - **test\_runner**: cache `shouldSkipFileCoverage` result per URL (sangwook) [#&#8203;63675](https://github.com/nodejs/node/pull/63675) - \[[`094869354a`](https://github.com/nodejs/node/commit/094869354a)] - **test\_runner**: ignore erased TS lines in coverage (Matteo Collina) [#&#8203;63510](https://github.com/nodejs/node/pull/63510) - \[[`68edc2b009`](https://github.com/nodejs/node/commit/68edc2b009)] - **test\_runner**: fix suite diagnostic chanel end (Moshe Atlow) [#&#8203;63533](https://github.com/nodejs/node/pull/63533) - \[[`659d5bf068`](https://github.com/nodejs/node/commit/659d5bf068)] - **test\_runner**: add parentId to test events with testId (Moshe Atlow) [#&#8203;63435](https://github.com/nodejs/node/pull/63435) - \[[`eaebeb8b88`](https://github.com/nodejs/node/commit/eaebeb8b88)] - **test\_runner**: fix hooks test context (Moshe Atlow) [#&#8203;63285](https://github.com/nodejs/node/pull/63285) - \[[`d03d96889b`](https://github.com/nodejs/node/commit/d03d96889b)] - **test\_runner**: add tags option and tag-name filter (Chemi Atlow) [#&#8203;63221](https://github.com/nodejs/node/pull/63221) - \[[`e8c3db1364`](https://github.com/nodejs/node/commit/e8c3db1364)] - **test\_runner**: add `getTestContext()` (Moshe Atlow) [#&#8203;62501](https://github.com/nodejs/node/pull/62501) - \[[`345c591d10`](https://github.com/nodejs/node/commit/345c591d10)] - **test\_runner**: filter execArgv fallback for child tests (Trivikram Kamat) [#&#8203;64056](https://github.com/nodejs/node/pull/64056) - \[[`2f47fb23bf`](https://github.com/nodejs/node/commit/2f47fb23bf)] - **test\_runner**: improve coverage failure diagnostics (Trivikram Kamat) [#&#8203;64050](https://github.com/nodejs/node/pull/64050) - \[[`260cf1ac89`](https://github.com/nodejs/node/commit/260cf1ac89)] - **test\_runner**: add timestamp to JUnit reporter testsuites (sangwook) [#&#8203;64029](https://github.com/nodejs/node/pull/64029) - \[[`24140eafdf`](https://github.com/nodejs/node/commit/24140eafdf)] - **test\_runner**: remove unused shuffleArrayWithSeed (Daijiro Wachi) [#&#8203;63847](https://github.com/nodejs/node/pull/63847) - \[[`b7fdb4891a`](https://github.com/nodejs/node/commit/b7fdb4891a)] - **test\_runner**: fix watch cwd with isolation none (Trivikram Kamat) [#&#8203;63690](https://github.com/nodejs/node/pull/63690) - \[[`e48b307e09`](https://github.com/nodejs/node/commit/e48b307e09)] - **timers**: reuse Timeout objects in setStreamTimeout (Matteo Collina) [#&#8203;64254](https://github.com/nodejs/node/pull/64254) - \[[`5396235993`](https://github.com/nodejs/node/commit/5396235993)] - **(SEMVER-MINOR)** **tls**: report negotiated TLS groups (Filip Skokan) [#&#8203;64119](https://github.com/nodejs/node/pull/64119) - \[[`a653e9bb57`](https://github.com/nodejs/node/commit/a653e9bb57)] - **tls**: handle large RSA exponents in X.509 cert (Tobias Nießen) [#&#8203;64093](https://github.com/nodejs/node/pull/64093) - \[[`5e901b5cd9`](https://github.com/nodejs/node/commit/5e901b5cd9)] - **(SEMVER-MINOR)** **tls**: add certificateCompression option (Tim Perry) [#&#8203;62217](https://github.com/nodejs/node/pull/62217) - \[[`3abcfa723c`](https://github.com/nodejs/node/commit/3abcfa723c)] - **tls**: route event listener exceptions through error handlers (Antoine du Hamel) [#&#8203;63822](https://github.com/nodejs/node/pull/63822) - \[[`eaba4cd59d`](https://github.com/nodejs/node/commit/eaba4cd59d)] - **tools**: bump the eslint group in /tools/eslint with 8 updates (dependabot\[bot]) [#&#8203;64249](https://github.com/nodejs/node/pull/64249) - \[[`7d7ea1dbca`](https://github.com/nodejs/node/commit/7d7ea1dbca)] - **tools**: update c-ares updater script (Antoine du Hamel) [#&#8203;64194](https://github.com/nodejs/node/pull/64194) - \[[`976827cd71`](https://github.com/nodejs/node/commit/976827cd71)] - **tools**: validate version number in release proposal commit message lint (Antoine du Hamel) [#&#8203;64070](https://github.com/nodejs/node/pull/64070) - \[[`cc0c586b52`](https://github.com/nodejs/node/commit/cc0c586b52)] - **tools**: update sccache to v0.16.0 (Michaël Zasso) [#&#8203;63078](https://github.com/nodejs/node/pull/63078) - \[[`f0a35fa56a`](https://github.com/nodejs/node/commit/f0a35fa56a)] - **tools**: bump js-yaml from 4.1.1 to 4.2.0 in /tools/lint-md (dependabot\[bot]) [#&#8203;63948](https://github.com/nodejs/node/pull/63948) - \[[`dafbd23240`](https://github.com/nodejs/node/commit/dafbd23240)] - **tools**: bump js-yaml from 4.1.1 to 4.2.0 in /tools/eslint (dependabot\[bot]) [#&#8203;63947](https://github.com/nodejs/node/pull/63947) - \[[`0ae1552650`](https://github.com/nodejs/node/commit/0ae1552650)] - **tools**: update the llhttp updater script (Antoine du Hamel) [#&#8203;63819](https://github.com/nodejs/node/pull/63819) - \[[`3623586d1f`](https://github.com/nodejs/node/commit/3623586d1f)] - **tools**: align Bash snippets in GHA with `lint-sh` conventions (Antoine du Hamel) [#&#8203;63829](https://github.com/nodejs/node/pull/63829) - \[[`64b130ce1d`](https://github.com/nodejs/node/commit/64b130ce1d)] - **tools**: bump the eslint group in /tools/eslint with 7 updates (dependabot\[bot]) [#&#8203;63730](https://github.com/nodejs/node/pull/63730) - \[[`4900cac251`](https://github.com/nodejs/node/commit/4900cac251)] - **tools**: fix zlib updater script (Antoine du Hamel) [#&#8203;63707](https://github.com/nodejs/node/pull/63707) - \[[`8edf3abafc`](https://github.com/nodejs/node/commit/8edf3abafc)] - **typings**: add typing for crypto (Filip Skokan) [#&#8203;64122](https://github.com/nodejs/node/pull/64122) - \[[`d5be94e820`](https://github.com/nodejs/node/commit/d5be94e820)] - **url**: fix URLSearchParams(null) to prudce null= per spec (Marco) [#&#8203;63782](https://github.com/nodejs/node/pull/63782) - \[[`ee66a3851c`](https://github.com/nodejs/node/commit/ee66a3851c)] - **util**: fix OOM in inspect color stack formatting (Ijtihed Kilani) [#&#8203;64022](https://github.com/nodejs/node/pull/64022) - \[[`e26f183699`](https://github.com/nodejs/node/commit/e26f183699)] - **util**: fix scientific notation formatting (Daijiro Wachi) [#&#8203;63823](https://github.com/nodejs/node/pull/63823) - \[[`7993e3e476`](https://github.com/nodejs/node/commit/7993e3e476)] - **util**: fix -0 formatting when numericSeparator is enabled (Daijiro Wachi) [#&#8203;63815](https://github.com/nodejs/node/pull/63815) - \[[`38758a7789`](https://github.com/nodejs/node/commit/38758a7789)] - **util**: remove style caches from styleText slow path (Guilherme Araújo) [#&#8203;63706](https://github.com/nodejs/node/pull/63706) - \[[`46a0ca256a`](https://github.com/nodejs/node/commit/46a0ca256a)] - **watch**: print name of changed file that triggers restart (Marco) [#&#8203;63781](https://github.com/nodejs/node/pull/63781) - \[[`e1582818ad`](https://github.com/nodejs/node/commit/e1582818ad)] - **watch**: cancel pending restart on shutdown (Trivikram Kamat) [#&#8203;63383](https://github.com/nodejs/node/pull/63383) - \[[`9a208668b0`](https://github.com/nodejs/node/commit/9a208668b0)] - **zlib**: validate flush king for all streams (Ic3b3rg) [#&#8203;63746](https://github.com/nodejs/node/pull/63746) - \[[`928981d803`](https://github.com/nodejs/node/commit/928981d803)] - **zlib**: validate flush kind for brotli streams (Ic3b3rg) [#&#8203;63746](https://github.com/nodejs/node/pull/63746) - \[[`fd0fb00164`](https://github.com/nodejs/node/commit/fd0fb00164)] - **zlib**: expose rejectGarbageAfterEnd option (Filip Skokan) [#&#8203;64023](https://github.com/nodejs/node/pull/64023) - \[[`e334d30b4c`](https://github.com/nodejs/node/commit/e334d30b4c)] - **zlib**: reject trailing gzip members in web streams (Filip Skokan) [#&#8203;64023](https://github.com/nodejs/node/pull/64023) - \[[`7433c3df2e`](https://github.com/nodejs/node/commit/7433c3df2e)] - **zlib**: coerce -0 to +0 for crc32 seeds (Filip Skokan) [#&#8203;63556](https://github.com/nodejs/node/pull/63556) </details> <details> <summary>actions/node-versions (node)</summary> ### [`v24.19.0`](https://github.com/actions/node-versions/releases/tag/24.19.0-30872449280): 24.19.0 [Compare Source](https://github.com/actions/node-versions/compare/24.18.1-30508414346...24.19.0-30872449280) Node.js 24.19.0 </details> <details> <summary>pnpm/pnpm (npm:pnpm)</summary> ### [`v11.20.0`](https://github.com/pnpm/pnpm/releases/tag/v11.20.0): pnpm 11.20 [Compare Source](https://github.com/pnpm/pnpm/compare/v11.19.0...v11.20.0) ##### Minor Changes - **Security fix.** Affects projects using `namedRegistries` on pnpm 11.1.0–11.19.x. It is **semi-breaking** for those projects — see "If you use named registries" below. The lockfile recorded no marker for which registry a package came from. Packages were keyed by `name@version` alone, and entry lookup went through `refToRelative(ref, name)`, so a dependency you declared against one registry could be satisfied by an entry that was actually resolved from another. When two registries served the same name and version, both collapsed onto a single `packages:` entry and whichever resolved first decided the tarball every consumer got. That is a package-substitution risk: a package you expect from your private registry could be installed from a different registry that publishes the same name and version, and the lockfile recorded nothing that would let you tell. Packages resolved from a named registry are now recorded under registry-qualified keys (`<name>@&#8203;<registryName>:<version>`, e.g. `foo@work:1.0.0`), so each registry gets its own entry and the lockfile pins which one a dependency came from. The lockfile format version is unchanged. Registry-qualified keys appear only for packages resolved from a named registry, so a project that does not use `namedRegistries` sees no difference, and older pnpm versions keep reading the file. ##### If you use named registries Your next non-frozen install re-keys those entries, which shows up as a lockfile diff. Commit it — that diff is the fix being applied. Review it: an entry that moves to a registry you did not expect is worth investigating. Everyone working on the project should be on this version or newer before you do. An older pnpm reads the re-keyed lockfile fine — frozen installs are unaffected — but it does not produce registry-qualified keys itself, so any install that updates the lockfile writes those entries back to the old shape, and the next install on a current pnpm re-qualifies them. The result is a lockfile that flips back and forth, and while it is in the old shape the project is exposed again. Because the lockfile format version is deliberately unchanged, pnpm cannot detect this and warn you about it. There is no setting to keep the old behavior: the old shape is the vulnerability. Tarball URLs that follow the standard registry layout are no longer written to the lockfile for named-registry packages; they are recomputed from the `namedRegistries` setting on demand. To use named registries, map your aliases in `pnpm-workspace.yaml`: ```yaml namedRegistries: work: https://npm.enterprise.example.com/ ``` ##### New built-in `npmjs:` alias `npmjs:` now resolves to `https://registry.npmjs.org/` with no configuration, alongside the existing `gh:` alias for GitHub Packages. It pins a dependency to the public registry even when `registry` points elsewhere, such as an internal proxy: ```json { "dependencies": { "left-pad": "npmjs:^1.3.0" } } ``` `npm:` cannot do this — it is the alias protocol (`npm:<name>@&#8203;<range>`) and resolves through whatever `registry` points at. **If you mirror or proxy npmjs, point the alias at your mirror:** ```yaml namedRegistries: npmjs: https://npm.internal.example.com/ ``` Built-in registry URLs are also the prefixes a lockfile's recorded tarball URL is matched against when pnpm verifies a package. Without the override, an entry whose tarball URL is on `registry.npmjs.org` is verified against the public registry rather than your mirror. This only affects lockfiles that record such URLs — a canonical URL for your configured registry is omitted from the lockfile and unaffected — and only when a tarball-URL, `minimumReleaseAge`, or `trustPolicy` check runs. Overriding the alias is the same escape hatch GHES users already have for `gh`. Every alias the lockfile references must stay in `namedRegistries`: reading an entry whose alias is gone fails with `ERR_PNPM_MISSING_NAMED_REGISTRY` rather than silently falling back to the default registry, since that would fetch a different package. Renaming an alias re-resolves the packages that used it. Named registry aliases that shadow a reserved dependency specifier prefix (`file`, `link`, `workspace`, `runtime`, `npm`, `jsr`, ...) are now rejected with `ERR_PNPM_RESERVED_NAMED_REGISTRY_NAME` instead of being silently shadowed by the corresponding resolver. `pnpm licenses` and `pnpm sbom` now keep the two artifacts apart as well: license records carry the registry alias, and SBOM components carry the purl `repository_url` qualifier. ##### Patch Changes - An empty `http-proxy`, `https-proxy`, `proxy`, or `no-proxy` value — from the `.npmrc`, `pnpm-workspace.yaml`, the CLI, or the `HTTP_PROXY` / `HTTPS_PROXY` / `PROXY` / `NO_PROXY` environment variables — no longer fails the install with `ERR_PNPM_INVALID_PROXY`. Empty settings read as unset, so a shell exporting `HTTP_PROXY=` disables the proxy, and an empty `proxy=` in the `.npmrc` no longer suppresses `HTTPS_PROXY` [#&#8203;13533](https://github.com/pnpm/pnpm/issues/13533). `proxy=false` in the `.npmrc` or `proxy: false` in `pnpm-workspace.yaml` now turns proxying off instead of being read as a proxy host named `false`. `false` and `null` on `https-proxy` / `http-proxy` / `no-proxy` read as unset, and on the command line they are ordinary host names, since a flag carries its value verbatim. - The env lockfile no longer pins `@pnpm/exe` alongside `pnpm` when the wanted pnpm version is 12 or newer. From v12 the unscoped `pnpm` package is itself the native executable, so `@pnpm/exe` is not published for it and resolving it would fail. The engine identity check now verifies the native binary through whichever package ships it. - `lexCompare` and `nerfDart` are now published as `@pnpm/text.ordinal-comparator` and `@pnpm/config.registry-auth-key`. Use these instead of `@pnpm/util.lex-comparator` and `@pnpm/config.nerf-dart`. - Fixed the order in which pnpm matches a lockfile's recorded tarball URL against known registry URLs. Two registry URLs of equal length were previously ordered arbitrarily, so which one a tarball URL matched could differ between runs. - Dependency resolution is faster: package metadata is now filtered once per packument instead of once per dependency edge when `minimumReleaseAge` is active, and parsed semver versions and ranges are reused instead of re-parsed on every comparison. - Security: `pnpm rebuild` now refuses a lockfile whose `packages` key carries a path traversal in the package name (e.g. `../../../escaped@1.0.0`), instead of running that package's lifecycle scripts and linking its bins in a directory outside the virtual store. Such a name is rejected with `ERR_PNPM_INVALID_DEPENDENCY_NAME`. <!-- sponsors --> ##### Platinum Sponsors <table> <tbody> <tr> <td align="center" valign="middle"> <a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a> </td> </tr> <tr> <td align="center" valign="middle"> <a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/openai_dark.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/openai_light.svg" /> <img src="https://pnpm.io/img/users/openai_dark.svg" width="160" alt="OpenAI" /> </picture> </a> </td> </tr> </tbody> </table> ##### Gold Sponsors <table> <tbody> <tr> <td align="center" valign="middle"> <a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/sanity.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/sanity_light.svg" /> <img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/discord.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/discord_light.svg" /> <img src="https://pnpm.io/img/users/discord.svg" width="220" alt="Discord" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a> </td> </tr> <tr> <td align="center" valign="middle"> <a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/serpapi_dark.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/serpapi_light.svg" /> <img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160" alt="SerpApi" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/coderabbit.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/coderabbit_light.svg" /> <img src="https://pnpm.io/img/users/coderabbit.svg" width="220" alt="CodeRabbit" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/stackblitz.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/stackblitz_light.svg" /> <img src="https://pnpm.io/img/users/stackblitz.svg" width="190" alt="Stackblitz" /> </picture> </a> </td> </tr> <tr> <td align="center" valign="middle"> <a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/workleap.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/workleap_light.svg" /> <img src="https://pnpm.io/img/users/workleap.svg" width="190" alt="Workleap" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://nx.dev/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/nx.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/nx_light.svg" /> <img src="https://pnpm.io/img/users/nx.svg" width="50" alt="Nx" /> </picture> </a> </td> </tr> </tbody> </table> <!-- sponsors end --> </details> <details> <summary>typescript-eslint/typescript-eslint (typescript-eslint)</summary> ### [`v8.66.0`](https://github.com/typescript-eslint/typescript-eslint/blob/HEAD/packages/typescript-eslint/CHANGELOG.md#8660-2026-08-03) [Compare Source](https://github.com/typescript-eslint/typescript-eslint/compare/v8.65.0...v8.66.0) This was a version bump only for typescript-eslint to align it with other projects, there were no code changes. See [GitHub Releases](https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.66.0) for more information. You can read about our [versioning strategy](https://typescript-eslint.io/users/versioning) and [releases](https://typescript-eslint.io/users/releases) on our website. </details> <details> <summary>vitejs/vite (vite)</summary> ### [`v8.2.1`](https://github.com/vitejs/vite/blob/HEAD/packages/vite/CHANGELOG.md#small-821-2026-08-06-small) [Compare Source](https://github.com/vitejs/vite/compare/v8.2.0...v8.2.1) ##### Bug Fixes - **build:** make client chunkImportMap work with `sharedPlugins: true` ([#&#8203;23184](https://github.com/vitejs/vite/issues/23184)) ([15f0307](https://github.com/vitejs/vite/commit/15f03073c915d6ffb9a1fda447ef66b02bf5cde8)) - **bundled-dev:** inject client script tag before chunk scripts ([#&#8203;23161](https://github.com/vitejs/vite/issues/23161)) ([eac0cc8](https://github.com/vitejs/vite/commit/eac0cc84aa2472a85a19ee84561c1ba71e381a55)) - **css:** don't re-run lightningcss visitor during minify (fix [#&#8203;23146](https://github.com/vitejs/vite/issues/23146)) ([#&#8203;23147](https://github.com/vitejs/vite/issues/23147)) ([de041a7](https://github.com/vitejs/vite/commit/de041a79b05a0be965c874592fe2c1505bcd48df)) - **deps:** update all non-major dependencies ([#&#8203;23136](https://github.com/vitejs/vite/issues/23136)) ([14454fd](https://github.com/vitejs/vite/commit/14454fd8c9a399bc3fdc193e28465b6fcf001e4d)) - **deps:** update rolldown-related dependencies ([#&#8203;23070](https://github.com/vitejs/vite/issues/23070)) ([7ac6f7f](https://github.com/vitejs/vite/commit/7ac6f7f590747bbdab9958e2c016e3dd04f10542)) - don't mutate the user config when resolving the lib entry from the top-level `input` ([#&#8203;23135](https://github.com/vitejs/vite/issues/23135)) ([b4bf596](https://github.com/vitejs/vite/commit/b4bf59686a7ac238929e91a6e1708c739b843a2f)) - handle shebang ending with uncommon line terminators ([#&#8203;23038](https://github.com/vitejs/vite/issues/23038)) ([17f7b2f](https://github.com/vitejs/vite/commit/17f7b2f193a110d0b47742ad296d182cb4666ce7)) - **server:** use a random port when port is 0 ([#&#8203;23158](https://github.com/vitejs/vite/issues/23158)) ([fddf4ea](https://github.com/vitejs/vite/commit/fddf4ea41de5f7889037a2f957438857ac12a260)) ##### Performance Improvements - **css:** look up pure CSS chunks through a Set ([#&#8203;23114](https://github.com/vitejs/vite/issues/23114)) ([1331b0b](https://github.com/vitejs/vite/commit/1331b0b438b1e7193effb7d2341660bccb9c3155)) ##### Documentation - **build:** fix incomplete `@default` for build.minify ([#&#8203;23177](https://github.com/vitejs/vite/issues/23177)) ([ef02435](https://github.com/vitejs/vite/commit/ef02435114c57d0422028f0e6987f3df8db72969)) ##### Miscellaneous Chores - **deps:** update dependency rolldown-plugin-dts to ^0.28.0 ([#&#8203;23137](https://github.com/vitejs/vite/issues/23137)) ([4adc1e7](https://github.com/vitejs/vite/commit/4adc1e7931d4beceb4e236d9a271d057c858a06f)) - **deps:** update dependency strip-literal to v4 ([#&#8203;23140](https://github.com/vitejs/vite/issues/23140)) ([9db65ce](https://github.com/vitejs/vite/commit/9db65ce63488ea8f08a3c98dcdc4282b17bd33ff)) ##### Code Refactoring - **bundled-dev:** avoid injecting server values in the bundle ([#&#8203;22967](https://github.com/vitejs/vite/issues/22967)) ([23b8a08](https://github.com/vitejs/vite/commit/23b8a088dec9dcc3f1c1353f2074f8644b3cc21f)) - **bundled-dev:** remove rolldown lazy stub module workaround ([#&#8203;23129](https://github.com/vitejs/vite/issues/23129)) ([e72036e](https://github.com/vitejs/vite/commit/e72036eed2e28936ed824971b18aeaa3900857f6)) ##### Tests - **bundled-dev:** enable sourcemap playgrounds ([#&#8203;23080](https://github.com/vitejs/vite/issues/23080)) ([c2155fe](https://github.com/vitejs/vite/commit/c2155fe4d5c8d25fba3a7366d367e3296ae669fa)) - reduce logs ([#&#8203;23138](https://github.com/vitejs/vite/issues/23138)) ([7673c02](https://github.com/vitejs/vite/commit/7673c02e53343ae9356c1f496c1c1da2eb732ac1)) </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Berlin) - Branch creation - "after 11pm every weekday,before 5am every weekday,every weekend" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](undefined) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMzQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjIzNC4wIiwidGFyZ2V0QnJhbmNoIjoiZGV2IiwibGFiZWxzIjpbXX0=-->
Update Non-major updates
Some checks failed
renovate/stability-days Updates have met minimum release age requirement
CI / test (pull_request) Failing after 4s
CI / build (pull_request) Has been skipped
CI / deploy-dev (pull_request) Has been skipped
CI / deploy-prod (pull_request) Has been skipped
c5915b20dc
renovate-bot scheduled this pull request to auto merge when all checks succeed 2026-08-12 07:01:17 +02:00
renovate-bot force-pushed renovate/non-major-updates from c5915b20dc
Some checks failed
renovate/stability-days Updates have met minimum release age requirement
CI / test (pull_request) Failing after 4s
CI / build (pull_request) Has been skipped
CI / deploy-dev (pull_request) Has been skipped
CI / deploy-prod (pull_request) Has been skipped
to bf2c8e4455
Some checks failed
CI / test (pull_request) Failing after 4s
CI / build (pull_request) Has been skipped
CI / deploy-dev (pull_request) Has been skipped
CI / deploy-prod (pull_request) Has been skipped
renovate/stability-days Updates have met minimum release age requirement
2026-08-13 16:02:07 +02:00
Compare
renovate-bot deleted branch renovate/non-major-updates 2026-08-13 16:02:12 +02:00
Sign in to join this conversation.
No reviewers
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
IC3P3/hcss-website!66
No description provided.