Update Non-major updates #76

Merged
renovate-bot merged 1 commit from renovate/non-major-updates into dev 2026-09-21 17:42:18 +02:00
Collaborator

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
@playwright/test (source) 1.62.1 → 1.63.0 age confidence devDependencies minor
@types/node (source) 24.13.3 → 24.13.4 age confidence devDependencies patch 24.13.6 (+1)
eslint (source) 10.9.1 → 10.10.0 age confidence devDependencies minor 10.11.0
node (source) 24.20.0 → 24.21.0 age confidence minor
node 24.20.0 → 24.21.0 age confidence uses-with minor
npm:pnpm (source) 11.25.0 → 11.27.0 age confidence minor 11.27.1
playwright (source) 1.62.1 → 1.63.0 age confidence devDependencies minor
pnpm (source) 11.25.0 → 11.27.0 age confidence uses-with minor 11.27.1
typescript-eslint (source) 8.69.0 → 8.70.0 age confidence devDependencies minor
vite (source) 8.2.2 → 8.3.0 age confidence devDependencies minor

Release Notes

microsoft/playwright (@​playwright/test)

v1.63.0

Compare Source

🔒 Test locks

Tests that access a shared resource — an external service, a global account setting — can now declare a named lock.
Tests that share a lock name never run concurrently, across files, workers and projects, while
everything else keeps running in parallel:

test('update user settings', { lock: 'user-settings' }, async ({ page }) => {
  // never runs at the same time as other tests holding 'user-settings'
});

A test can hold multiple locks, and test.describe() accepts a lock for the whole group.
Learn more about test locks.

🪟 Locate across frames

page.frameLocator() and frame.frameLocator() called without a selector search in any frame of the
subtree, so you no longer need to locate the iframe first:

// Finds the button in any frame on the page.
await page.frameLocator().getByRole('button').click();

The rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it
matches elements in several frames.

👁️ Visible-only locators

New locator.visible() returns a locator that matches only visible elements. It is the recommended
replacement for the :visible CSS pseudo-class:

await page.locator('button').visible().click();
🧾 Step params and subtitles

Steps now carry structured data for reporters. Playwright API steps report the target locator and call arguments,
and test.step() accepts subtitle and params options for your own steps:

await test.step('Login', async () => {
  // ...
}, { subtitle: 'as admin', params: { user: 'admin' } });

Reporters receive them via testStep.subtitle and testStep.params. For Playwright API
steps, the subtitle is the locator or the navigation url — for example, Click with subtitle getByRole('button').
Both are rendered next to the step title in the trace viewer and the HTML report.

🖼️ Aria and screen snapshots in traces

The snapshots option of tracing.start() and the testOptions.trace fixture option now accept an
object selecting what to capture on every action:

// playwright.config.ts
export default defineConfig({
  use: {
    trace: {
      mode: 'on',
      snapshots: { dom: true, aria: true, screen: true }
    },
  },
});

With aria and screen snapshots recorded, the new Display Aria mode in the trace viewer shows the action screenshot
side by side with the aria snapshot, and hovering an aria node highlights it on the screenshot.

New APIs
Browser and Context
Locators
const response = await request.get<User>('/api/users/42');
const user = await response.json(); // typed as User
Test runner
  • New standalone testOptions.reducedMotion, testOptions.forcedColors and testOptions.contrast options.
  • New --add-reporter command line option appends a reporter on top of the ones configured in playwright.config, instead of replacing them like --reporter does.
  • New omitTags option for the list, line, dot, github and junit reporters suppresses the tags that are automatically appended to test titles.
Command line
  • npx playwright install --no-remove keeps the browsers of other Playwright installations instead of removing them.
  • npx playwright codegen --http-credentials records against pages behind HTTP authentication.
Miscellaneous
  • New built-in perfetto reporter writes a Trace Event Format file for the Perfetto UI or chrome://tracing, rendering the test run as a timeline with a lane per worker.
  • The HTML report renders a duration waterfall next to test steps.
Announcements
  • ⚠️ The experimental @playwright/experimental-ct-react, @playwright/experimental-ct-react17 and @playwright/experimental-ct-vue packages will no longer be updated. Follow the migration guide to move to the stories model introduced in 1.62. Story ids passed to fixtures.mount() can now be typed through the generated Stories registry.
  • ⚠️ Ubuntu 20.04 is not supported anymore.
  • 🐧 On Linux arm64, Playwright now downloads the Chrome for Testing build of Chromium, the same build used on all other platforms.
Browser Versions
  • Chromium 153.0.8010.12
  • Mozilla Firefox 155.0
  • WebKit 26.6

This version was also tested against the following stable channels:

  • Google Chrome 153
  • Microsoft Edge 153
eslint/eslint (eslint)

v10.10.0

Compare Source

Features

  • 264b434 feat: add d and v flags to no-unexpected-multiline (#​21305) (Gihyeon Jeong / 정기현)
  • c6cc6c5 feat: check Object.prototype property names in new-cap (#​21269) (crimsonjay0)
  • 5661fa6 feat: no-extra-bind false negatives with class fields and static blocks (#​21260) (synthex-byte)

Bug Fixes

  • bb47dc6 fix: update dependency file-entry-cache to v11 (#​20801) (Milos Djermanovic)
  • 427ac0a fix: use format strings in debug calls (#​21247) (Francesco Trotta)
  • 9d81532 fix: support __proto__ in /* exported */ comments (#​21261) (sethamus)
  • 87e0a08 fix: prefer-object-has-own autofix breaks when Object is shadowed (#​21282) (김채영)
  • 8e2cb14 fix: new-cap false positive for UTC calls with properties: false (#​21275) (Pixel)
  • 9f4a364 fix: Ignore static imports in no-unreachable (#​21276) (Taha Kotil)

Documentation

  • 2417cad docs: Update README (GitHub Actions Bot)
  • 9cecb8a docs: document \c control letter escapes in no-control-regex (#​21286) (한국)
  • 8724829 docs: update compat table links (#​21263) (fnx)
  • 5634542 docs: Clarify eqeqeq suggestion behavior (#​21256) (Müslüm Yılmaz)

Chores

nodejs/node (node)

v24.21.0: 2026-09-08, Version 24.21.0 'Krypton' (LTS), @​aduh95

Compare Source

Notable Changes
  • [71106e1f17] - crypto: update root certificates to NSS 3.126 (Node.js GitHub Bot) #​65495
  • [afca0a912d] - (SEMVER-MINOR) crypto: support loading private keys through STORE loaders (Filip Skokan) #​63949
  • [6274fccbd9] - deps: update OpenSSL to 3.5.8 (Node.js GitHub Bot) #​65542
  • [53cba013c7] - deps: update Undici to 7.29.1 (Node.js GitHub Bot) #​65789
  • [0529772798] - (SEMVER-MINOR) lib,src: improve histogram implementation (James M Snell) #​65024
  • [41c7062b81] - (SEMVER-MINOR) net: improve performance of net.BlockList (James M Snell) #​64974
  • [5197b5a3c5] - (SEMVER-MINOR) perf_hooks: add statistical hypothesis testing to histogram (James M Snell) #​65416
  • [35c635b032] - (SEMVER-MINOR) util: add non-throwing MIMEType.parse (James M Snell) #​64965
Commits
actions/node-versions (node)

v24.21.0: 24.21.0

Compare Source

Node.js 24.21.0

pnpm/pnpm (npm:pnpm)

v11.27.0: pnpm 11.27

Compare Source

Minor Changes
  • nodeDownloadMirrors can now be set in the global config file (config.yaml) and through the PNPM_CONFIG_NODE_DOWNLOAD_MIRRORS environment variable, so a Node.js download mirror can be configured once for a machine instead of in every workspace #​12124, #​13611.

    PNPM_CONFIG_NODE_DOWNLOAD_MIRRORS='{"release":"https://npmmirror.com/mirrors/node/"}'
    
  • Added a new setting trustPolicyExcludePrune (default: false). When enabled, pnpm add, pnpm update, and pnpm remove prune the entries of trustPolicyExclude in pnpm-workspace.yaml that the freshly written lockfile no longer resolves: versions that are gone are dropped (an entry is removed once none of its versions remain), and entries for packages that are no longer in the lockfile are removed too. Name patterns (@scope/*) are always kept. The cleanup is skipped when the install's lockfile does not cover the whole workspace (sharedWorkspaceLockfile: false), since entries another project still needs would look stale.

Patch Changes
  • pnpm now reads the packageManager, devEngines.packageManager and runtime pins from the workspace root's package.json when lockfileDir is set. A project that moved its lockfile lost the pins it declared there #​14633.

  • Fixed pnpm add -g, pnpm update -g, and pnpm remove -g mutating global bins or install directories after only partially reading an installed package group. If any declared package manifest is missing, malformed, or unreadable, pnpm now fails before activation or removal and leaves the existing global installation intact pnpm/pnpm#13796.

  • fetch-timeout now limits how long a request may make no progress. The timer restarts on every chunk that arrives. A large download over a slow connection is no longer aborted while data is still coming in. A connection that stops delivering data still fails after fetch-timeout #​14604.

  • pnpm peers check no longer reports a peer dependency declared as workspace:^, workspace:~, or a bare workspace: as unmet. pnpm reported these as unmet whatever version the linked workspace project supplied #​14770.

  • A readPackage hook that edits its argument in place no longer changes what a later install in the same command resolves. A deprecated notice read from the lockfile no longer carries over to another install either #​13988.

  • pnpm install now auto-installs missing transitive peers when workspace projects share a dependency at different depths. This also removes incomplete duplicate peer contexts from the lockfile. Fixes pnpm/pnpm#14840.

  • GitHub Actions updates now stop if an action reference changes while its versions are being resolved. Unrelated workflow edits are preserved.

    GitHub Actions homepage links no longer expose server credentials. GitHub server URLs now require HTTPS, with HTTP allowed only for loopback hosts.

  • pnpm licenses list now reports the runtime downloaded through devEngines.runtime with onFail: "download". The command previously failed with ERR_PNPM_UNSUPPORTED_PACKAGE_TYPE #​14172.

  • pnpm no longer creates a project pnpm-lock.yaml when devEngines.packageManager.onFail is download and lockfile writing is turned off with lockfile: false or --no-lockfile. pnpm still switches to the pinned version #​14728.

  • A registry or @scope:registry set in an .npmrc now wins over the registry a pnpm login credential stored in the global config.yaml points at. Previously, after logging in to one registry, installs in a project whose .npmrc named a private registry went to the logged-in registry instead. They now go to the registry the .npmrc names #​14614.

  • A patch that gives a dependency a preinstall, install, or postinstall script, or a binding.gyp, now runs that build. pnpm asks for build approval first, so the package is listed under "Ignored build scripts" until it is allowed to build. pnpm 12 ran nothing, and pnpm 11 ran it without asking #​14648.

  • Registries that share a host but differ by URL path — one JFrog Artifactory, Nexus, AWS CodeArtifact or GitLab Packages instance serving several repositories — now get a metadata cache directory each. Previously they shared one, so resolving a package from one of them could answer with another's versions, integrity hashes and tarball URLs and fail with ERR_PNPM_TARBALL_URL_MISMATCH #​13558.

    The URL scheme is part of the cache directory name too, so an http registry can no longer hand its metadata — which can be rewritten in transit — to a resolution configured for https at the same host.

    The first install after upgrading refetches registry metadata once. The package store is untouched.

    pnpm cache view now labels each entry with the full registry URL. It printed registry.npmjs.org before and prints https://registry.npmjs.org/ now.

    pnpm cache list-registries and pnpm cache list print the new directory names. Scripts that parse either command need updating.

  • Updated the embedded Node.js release keys to the current canonical nodejs/release-keys list.

  • pnpm sbom now omits package author fields when the manifest author name is empty or contains only whitespace pnpm/pnpm#14685. In a filtered or split workspace run, only a project with no author field inherits the workspace root's author.

  • pnpm sbom --sbom-format spdx now writes creationInfo.created with whole seconds, such as 2026-09-08T10:38:21Z. The timestamp carried fractional seconds, which strict SPDX consumers rejected #​14684.

  • Windows filesystem operations now retry permission errors for up to one second. Permanent permission errors previously delayed failure by a minute. Sharing and lock violations retain their one-minute retry budget pnpm/pnpm#14682.

  • pnpm now writes node_modules/.package-map.json only when nodeExperimentalPackageMap is enabled. Nothing reads the file without that setting. An install that stops writing the map removes the one a previous install left.

  • pnpm now unpacks a downloaded runtime archive into a randomly named directory inside the store. It previously used a predictable path, where another user of a shared store could plant a symlink and redirect the write outside the store (GHSA-vwc7-r8mq-g2x9).

Platinum Sponsors
Bit OpenAI Notion
CodeRabbit
Gold Sponsors
Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v11.26.0: pnpm 11.26

Compare Source

Minor Changes
  • Catalogs can now resolve workspace dependencies through the workspace: protocol.

  • pnpm remove and pnpm update now accept --trust-lockfile, --no-trust-lockfile, --trust-policy, --trust-policy-exclude, and --trust-policy-ignore-after. pnpm remove checks the whole lockfile against the active policies unless --trust-lockfile is set.

  • Added pnpm change check for CI validation of package versions against the versioning.epics bands and versioning.fixed groups in pnpm-workspace.yaml.

Patch Changes
  • Fetch and tarball errors and retry logs now hide URL credentials, query strings, and fragments that could expose secrets.

  • Fixed a race during config dependency updates that could redirect a lockfile write through a symlink #​14322.

  • pnpm add --allow-build=!<pkg> now correctly denies builds, including in global installs. pnpm approve-builds <pkg> and pnpm approve-builds !<pkg> now save decisions even when the package is not awaiting approval, with a warning #​14067.

  • Fixed pnpm audit --fix failing without a value or when followed by another flag. pnpm audit --fix=override now respects saveExact and savePrefix when writing overrides #​13261, #​11523.

  • pnpm audit now excludes ignored advisories from vulnerability totals and severity counts, and reports them separately #​14535.

  • pnpm deploy no longer requires injectWorkspacePackages. If a workspace dependency's peer has multiple possible versions, deployment reports ERR_PNPM_DEPLOY_AMBIGUOUS_PEER with the conflicting versions. Pin the peer with overrides to deploy without injection #​9386.

  • Fixed concurrent installs sharing a store occasionally failing with an ENOENT error while importing a package file #​14353.

  • Fixed installation failures when a linked local dependency provides a peer dependency also provided by an ancestor, including with pnpm deploy --legacy.

  • pnpm install --node-linker=hoisted no longer downloads skipped optional dependencies when node_modules already exists #​14139.

  • Fixed pnpm install rejecting a symlinked lockfile when config dependencies are unchanged. Updates to config dependencies also preserve lockfiles with a byte order mark. Writes through symlinked lockfiles remain blocked #​14372.

  • pnpm install now relinks workspace packages when publishConfig.linkDirectory changes. Frozen installs require the lockfile to be regenerated #​14488.

  • Auto-installed optional peers now satisfy their declared range even when the workspace root uses a version outside that range #​13867.

  • Fixed global virtual store paths for dependency cycles to consistently account for the runtime engine when dependencies have allowed builds #​14341.

  • Standalone installations now preserve the bundled node-gyp files needed to build native dependencies.

  • Downloaded runtimes are now available to dependency lifecycle scripts during installation.

  • Node.js downloads from nodeDownloadMirrors now use URL-scoped npm credentials, including bearer tokens, basic auth, and tokenHelper #​14334.

  • Fixed globalDir and globalBinDir handling in global configuration and environment variables, including ~/ expansion. This fixes pnpm add -g failing after pnpm config set -g global-bin-dir #​14336.

  • The JavaScript pnpm can again switch to the project's pinned pnpm version on hosts without a matching native binary. If the requested version requires an unavailable native binary, the error now identifies the unsupported host #​13622.

  • Global pnpm config commands now skip project package manager version switching, allowing authentication to be configured before downloading the pinned version #​14463.

  • pnpm self-update, pnpm with, and automatic version switching no longer wait through registry retries when a configured registry has no signatures and registry.npmjs.org is unavailable #​14483.

  • Fixed argument forwarding on Windows with shellEmulator enabled. Trailing backslashes, line breaks, and literal shell expressions are preserved #​14548.

  • Relative scriptShell paths now resolve from the workspace root. Bare command names such as bash still use PATH #​14422.

  • pnpm import now preserves the project-local lockfile when lockfileDir points elsewhere and restores the destination lockfile on failure. Branch lockfile imports leave the shared lockfile unchanged #​14563.

  • catalogMode and --save-catalog no longer move local paths, tarballs, or workspace:<path> specifiers into catalogs #​14437.

  • --side-effects-cache, --no-side-effects-cache, and PNPM_CONFIG_SIDE_EFFECTS_CACHE now toggle only the local cache, preserving any remote cache configured in sideEffectsCache.

  • pnpm unpublish now handles registry two-factor authentication challenges through web authentication or a one-time password prompt #​14464.

  • pnpm outdated and pnpm update now follow GitHub Actions references using self-repository syntax, such as uses: $/.github/actions/setup.

  • pnpm remove now accepts --unsafe-perm.

Platinum Sponsors
Bit OpenAI Notion
CodeRabbit
Gold Sponsors
Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude
typescript-eslint/typescript-eslint (typescript-eslint)

v8.70.0

Compare Source

🩹 Fixes
  • eslint-plugin: [no-deprecated] report deprecated imported values used in object shorthand properties (#​12780)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

vitejs/vite (vite)

v8.3.0

Compare Source

Features
Bug Fixes
Performance Improvements
Miscellaneous Chores
Code Refactoring
Tests
Beta Changelogs
8.3.0-beta.1 (2026-09-07)

See 8.3.0-beta.1 changelog

8.3.0-beta.0 (2026-09-02)

See 8.3.0-beta.0 changelog


Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • "after 11pm every weekday,before 5am every weekday,every weekend"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | Type | Update | Pending | |---|---|---|---|---|---|---| | [@playwright/test](https://playwright.dev) ([source](https://github.com/microsoft/playwright)) | [`1.62.1` → `1.63.0`](https://renovatebot.com/diffs/npm/@playwright%2ftest/1.62.1/1.63.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@playwright%2ftest/1.63.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@playwright%2ftest/1.62.1/1.63.0?slim=true) | devDependencies | minor | | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/node) ([source](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)) | [`24.13.3` → `24.13.4`](https://renovatebot.com/diffs/npm/@types%2fnode/24.13.3/24.13.4) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@types%2fnode/24.13.4?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@types%2fnode/24.13.3/24.13.4?slim=true) | devDependencies | patch | `24.13.6` (+1) | | [eslint](https://eslint.org) ([source](https://github.com/eslint/eslint)) | [`10.9.1` → `10.10.0`](https://renovatebot.com/diffs/npm/eslint/10.9.1/10.10.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/eslint/10.10.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/eslint/10.9.1/10.10.0?slim=true) | devDependencies | minor | `10.11.0` | | [node](https://nodejs.org) ([source](https://github.com/nodejs/node)) | `24.20.0` → `24.21.0` | ![age](https://developer.mend.io/api/mc/badges/age/node-version/node/v24.21.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/node-version/node/v24.20.0/v24.21.0?slim=true) | | minor | | | [node](https://github.com/actions/node-versions) | `24.20.0` → `24.21.0` | ![age](https://developer.mend.io/api/mc/badges/age/github-releases/actions%2fnode-versions/24.21.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/github-releases/actions%2fnode-versions/24.20.0/24.21.0?slim=true) | uses-with | minor | | | [npm:pnpm](https://github.com/pnpm/pnpm/tree/main/pnpm) ([source](https://github.com/pnpm/pnpm/tree/HEAD/pnpm/npm/pnpm)) | `11.25.0` → `11.27.0` | ![age](https://developer.mend.io/api/mc/badges/age/npm/pnpm/11.27.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/pnpm/11.25.0/11.27.0?slim=true) | | minor | `11.27.1` | | [playwright](https://playwright.dev) ([source](https://github.com/microsoft/playwright)) | [`1.62.1` → `1.63.0`](https://renovatebot.com/diffs/npm/playwright/1.62.1/1.63.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/playwright/1.63.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/playwright/1.62.1/1.63.0?slim=true) | devDependencies | minor | | | [pnpm](https://github.com/pnpm/pnpm/tree/main/pnpm) ([source](https://github.com/pnpm/pnpm/tree/HEAD/pnpm/npm/pnpm)) | `11.25.0` → `11.27.0` | ![age](https://developer.mend.io/api/mc/badges/age/npm/pnpm/11.27.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/pnpm/11.25.0/11.27.0?slim=true) | uses-with | minor | `11.27.1` | | [typescript-eslint](https://typescript-eslint.io/packages/typescript-eslint) ([source](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint)) | [`8.69.0` → `8.70.0`](https://renovatebot.com/diffs/npm/typescript-eslint/8.69.0/8.70.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/typescript-eslint/8.70.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/typescript-eslint/8.69.0/8.70.0?slim=true) | devDependencies | minor | | | [vite](https://vite.dev) ([source](https://github.com/vitejs/vite/tree/HEAD/packages/vite)) | [`8.2.2` → `8.3.0`](https://renovatebot.com/diffs/npm/vite/8.2.2/8.3.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/vite/8.3.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/vite/8.2.2/8.3.0?slim=true) | devDependencies | minor | | --- ### Release Notes <details> <summary>microsoft/playwright (@&#8203;playwright/test)</summary> ### [`v1.63.0`](https://github.com/microsoft/playwright/releases/tag/v1.63.0) [Compare Source](https://github.com/microsoft/playwright/compare/v1.62.1...v1.63.0) ##### 🔒 Test locks Tests that access a shared resource — an external service, a global account setting — can now declare a named `lock`. Tests that share a lock name never run concurrently, across files, workers and [projects](https://playwright.dev/docs/test-projects), while everything else keeps running in parallel: ```js test('update user settings', { lock: 'user-settings' }, async ({ page }) => { // never runs at the same time as other tests holding 'user-settings' }); ``` A test can hold multiple locks, and [test.describe()](https://playwright.dev/docs/api/class-test#test-describe) accepts a `lock` for the whole group. Learn more about [test locks](https://playwright.dev/docs/test-parallel#test-locks). ##### 🪟 Locate across frames [page.frameLocator()](https://playwright.dev/docs/api/class-page#page-frame-locator) and [frame.frameLocator()](https://playwright.dev/docs/api/class-frame#frame-frame-locator) called without a selector search in any frame of the subtree, so you no longer need to locate the iframe first: ```js // Finds the button in any frame on the page. await page.frameLocator().getByRole('button').click(); ``` The rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it matches elements in several frames. ##### 👁️ Visible-only locators New [locator.visible()](https://playwright.dev/docs/api/class-locator#locator-visible) returns a locator that matches only visible elements. It is the recommended replacement for the `:visible` CSS pseudo-class: ```js await page.locator('button').visible().click(); ``` ##### 🧾 Step params and subtitles Steps now carry structured data for reporters. Playwright API steps report the target locator and call arguments, and [test.step()](https://playwright.dev/docs/api/class-test#test-step) accepts `subtitle` and `params` options for your own steps: ```js await test.step('Login', async () => { // ... }, { subtitle: 'as admin', params: { user: 'admin' } }); ``` Reporters receive them via [testStep.subtitle](https://playwright.dev/docs/api/class-teststep#test-step-subtitle) and [testStep.params](https://playwright.dev/docs/api/class-teststep#test-step-params). For Playwright API steps, the subtitle is the locator or the navigation url — for example, `Click` with subtitle `getByRole('button')`. Both are rendered next to the step title in the trace viewer and the HTML report. ##### 🖼️ Aria and screen snapshots in traces The `snapshots` option of [tracing.start()](https://playwright.dev/docs/api/class-tracing#tracing-start) and the [testOptions.trace](https://playwright.dev/docs/api/class-testoptions#test-options-trace) fixture option now accept an object selecting what to capture on every action: ```js // playwright.config.ts export default defineConfig({ use: { trace: { mode: 'on', snapshots: { dom: true, aria: true, screen: true } }, }, }); ``` With aria and screen snapshots recorded, the new **Display Aria** mode in the trace viewer shows the action screenshot side by side with the aria snapshot, and hovering an aria node highlights it on the screenshot. ##### New APIs ##### Browser and Context - [`httpCredentials`](https://playwright.dev/docs/api/class-browser#browser-new-context-option-http-credentials) now also accepts an array of credentials. The first entry matching the request origin is used, and entries without an origin match any request. - New option [`opfs`](https://playwright.dev/docs/api/class-browsercontext#browser-context-storage-state-option-opfs) includes the [origin private file system](https://developer.mozilla.org/en-US/docs/Web/API/File_System_API/Origin_private_file_system) in the storage state, so it can be persisted and restored into later contexts. - New events [page.on('dialogclosed')](https://playwright.dev/docs/api/class-page#page-event-dialog-closed) and [browserContext.on('dialogclosed')](https://playwright.dev/docs/api/class-browsercontext#browser-context-event-dialog-closed) are emitted when a JavaScript dialog is accepted, dismissed or closed by the user. ##### Locators - New [locator.ariaSnapshotJSON()](https://playwright.dev/docs/api/class-locator#locator-aria-snapshot-json) and [page.ariaSnapshotJSON()](https://playwright.dev/docs/api/class-page#page-aria-snapshot-json) return the aria snapshot as a JSON value instead of YAML markup, with `mode`, `depth` and `boxes` options. - [apiRequestContext.get()](https://playwright.dev/docs/api/class-apirequestcontext#api-request-context-get) and other request methods accept a type argument that types the response `json()`: ```js const response = await request.get<User>('/api/users/42'); const user = await response.json(); // typed as User ``` ##### Test runner - New standalone [testOptions.reducedMotion](https://playwright.dev/docs/api/class-testoptions#test-options-reduced-motion), [testOptions.forcedColors](https://playwright.dev/docs/api/class-testoptions#test-options-forced-colors) and [testOptions.contrast](https://playwright.dev/docs/api/class-testoptions#test-options-contrast) options. - New `--add-reporter` command line option appends a reporter on top of the ones configured in `playwright.config`, instead of replacing them like `--reporter` does. - New `omitTags` option for the `list`, `line`, `dot`, `github` and `junit` reporters suppresses the tags that are automatically appended to test titles. ##### Command line - `npx playwright install --no-remove` keeps the browsers of other Playwright installations instead of removing them. - `npx playwright codegen --http-credentials` records against pages behind HTTP authentication. ##### Miscellaneous - New built-in [`perfetto`](https://playwright.dev/docs/test-reporters#perfetto-reporter) reporter writes a Trace Event Format file for the [Perfetto UI](https://ui.perfetto.dev) or `chrome://tracing`, rendering the test run as a timeline with a lane per worker. - The HTML report renders a duration waterfall next to test steps. ##### Announcements - ⚠️ The experimental `@playwright/experimental-ct-react`, `@playwright/experimental-ct-react17` and `@playwright/experimental-ct-vue` packages will no longer be updated. Follow the [migration guide](https://playwright.dev/docs/test-components#migration-from-the-experimental-packages) to move to the stories model introduced in 1.62. Story ids passed to [fixtures.mount()](https://playwright.dev/docs/api/class-fixtures#fixtures-mount) can now be typed through the generated `Stories` registry. - ⚠️ Ubuntu 20.04 is not supported anymore. - 🐧 On Linux arm64, Playwright now downloads the [Chrome for Testing](https://developer.chrome.com/blog/chrome-for-testing) build of Chromium, the same build used on all other platforms. ##### Browser Versions - Chromium 153.0.8010.12 - Mozilla Firefox 155.0 - WebKit 26.6 This version was also tested against the following stable channels: - Google Chrome 153 - Microsoft Edge 153 </details> <details> <summary>eslint/eslint (eslint)</summary> ### [`v10.10.0`](https://github.com/eslint/eslint/releases/tag/v10.10.0) [Compare Source](https://github.com/eslint/eslint/compare/v10.9.1...v10.10.0) #### Features - [`264b434`](https://github.com/eslint/eslint/commit/264b4346d1963701df0c398b4aeb2f6e8b2af93e) feat: add `d` and `v` flags to `no-unexpected-multiline` ([#&#8203;21305](https://github.com/eslint/eslint/issues/21305)) (Gihyeon Jeong / 정기현) - [`c6cc6c5`](https://github.com/eslint/eslint/commit/c6cc6c592f30901345d94ef75e0d42c1894fae6c) feat: check `Object.prototype` property names in `new-cap` ([#&#8203;21269](https://github.com/eslint/eslint/issues/21269)) (crimsonjay0) - [`5661fa6`](https://github.com/eslint/eslint/commit/5661fa65fde9fd4c14f0b730e3cee6a42fc657c1) feat: no-extra-bind false negatives with class fields and static blocks ([#&#8203;21260](https://github.com/eslint/eslint/issues/21260)) (synthex-byte) #### Bug Fixes - [`bb47dc6`](https://github.com/eslint/eslint/commit/bb47dc6da2399a8f76c0c0c3273e6bc314c480e5) fix: update dependency file-entry-cache to v11 ([#&#8203;20801](https://github.com/eslint/eslint/issues/20801)) (Milos Djermanovic) - [`427ac0a`](https://github.com/eslint/eslint/commit/427ac0a014066c36aa57fa8fa9af20fd9fb591e1) fix: use format strings in debug calls ([#&#8203;21247](https://github.com/eslint/eslint/issues/21247)) (Francesco Trotta) - [`9d81532`](https://github.com/eslint/eslint/commit/9d8153223dbf47b9aecdc1474202aaee4845f146) fix: support `__proto__` in `/* exported */` comments ([#&#8203;21261](https://github.com/eslint/eslint/issues/21261)) (sethamus) - [`87e0a08`](https://github.com/eslint/eslint/commit/87e0a082438264ad90b87fd74165ab4fd90f63ef) fix: prefer-object-has-own autofix breaks when Object is shadowed ([#&#8203;21282](https://github.com/eslint/eslint/issues/21282)) (김채영) - [`8e2cb14`](https://github.com/eslint/eslint/commit/8e2cb142217f2efee1d10dcc02bfb75145ae775d) fix: `new-cap` false positive for `UTC` calls with `properties: false` ([#&#8203;21275](https://github.com/eslint/eslint/issues/21275)) (Pixel) - [`9f4a364`](https://github.com/eslint/eslint/commit/9f4a364ab0ade048dfce1f37792b1d461d866e55) fix: Ignore static imports in no-unreachable ([#&#8203;21276](https://github.com/eslint/eslint/issues/21276)) (Taha Kotil) #### Documentation - [`2417cad`](https://github.com/eslint/eslint/commit/2417cad57d7d1bc4cf3ecf0f0575cfb10ff2011c) docs: Update README (GitHub Actions Bot) - [`9cecb8a`](https://github.com/eslint/eslint/commit/9cecb8a0a2348070abf72321965d41919c7cc626) docs: document `\c` control letter escapes in no-control-regex ([#&#8203;21286](https://github.com/eslint/eslint/issues/21286)) (한국) - [`8724829`](https://github.com/eslint/eslint/commit/8724829f69f8ed80c876e3a5a017da199ce78739) docs: update compat table links ([#&#8203;21263](https://github.com/eslint/eslint/issues/21263)) (fnx) - [`5634542`](https://github.com/eslint/eslint/commit/5634542be580750ffb1a5766470f9e9c72719696) docs: Clarify eqeqeq suggestion behavior ([#&#8203;21256](https://github.com/eslint/eslint/issues/21256)) (Müslüm Yılmaz) #### Chores - [`b3d876b`](https://github.com/eslint/eslint/commit/b3d876b46083d67899eb1d9613118c1c583632a2) chore: disable npm audit in ecosystem tests ([#&#8203;21306](https://github.com/eslint/eslint/issues/21306)) (Francesco Trotta) - [`1696682`](https://github.com/eslint/eslint/commit/1696682791661c13167eb905da2f38d1b8f4a3bf) ci: restore EMFILE test on Node.js 26 ([#&#8203;21297](https://github.com/eslint/eslint/issues/21297)) (Marry (Subin Yang)) - [`2c7f5d6`](https://github.com/eslint/eslint/commit/2c7f5d6f47a92e8c0847af103e40fdb2f4dc61ef) chore: update github/codeql-action action to v4.37.9 ([#&#8203;21296](https://github.com/eslint/eslint/issues/21296)) (renovate\[bot]) - [`3c753f1`](https://github.com/eslint/eslint/commit/3c753f18b461bfbf36d41a79a7863c093ef48489) chore: update eslint ([#&#8203;21289](https://github.com/eslint/eslint/issues/21289)) (renovate\[bot]) - [`1c73469`](https://github.com/eslint/eslint/commit/1c734690bf6f4f9c542bec428d5a1a5c6cc4a19b) chore: update ecosystem plugins ([#&#8203;21280](https://github.com/eslint/eslint/issues/21280)) (ESLint Bot) - [`08a02be`](https://github.com/eslint/eslint/commit/08a02be429e21fc93d86c8dd16cec6dc945ea2c1) test: add error locations to `no-extra-boolean-cast` ([#&#8203;21266](https://github.com/eslint/eslint/issues/21266)) (lumir) - [`77bb1db`](https://github.com/eslint/eslint/commit/77bb1db8e730b7da2347c647d60f215706aa349a) chore: update github/codeql-action action to v4.37.8 ([#&#8203;21270](https://github.com/eslint/eslint/issues/21270)) (renovate\[bot]) - [`007e81a`](https://github.com/eslint/eslint/commit/007e81ac0ad66bd0be4887d88a276df292ae0bed) ci: skip EMFILE test on Node.js 26 ([#&#8203;21265](https://github.com/eslint/eslint/issues/21265)) (lumir) - [`0430280`](https://github.com/eslint/eslint/commit/0430280e7cca9dc0fdbf0bc50464e98e84285c49) chore: improve ecosystem tests compatibility on Windows ([#&#8203;21178](https://github.com/eslint/eslint/issues/21178)) (crimsonjay0) </details> <details> <summary>nodejs/node (node)</summary> ### [`v24.21.0`](https://github.com/nodejs/node/releases/tag/v24.21.0): 2026-09-08, Version 24.21.0 'Krypton' (LTS), @&#8203;aduh95 [Compare Source](https://github.com/nodejs/node/compare/v24.20.0...v24.21.0) ##### Notable Changes - \[[`71106e1f17`](https://github.com/nodejs/node/commit/71106e1f17)] - **crypto**: update root certificates to NSS 3.126 (Node.js GitHub Bot) [#&#8203;65495](https://github.com/nodejs/node/pull/65495) - \[[`afca0a912d`](https://github.com/nodejs/node/commit/afca0a912d)] - **(SEMVER-MINOR)** **crypto**: support loading private keys through STORE loaders (Filip Skokan) [#&#8203;63949](https://github.com/nodejs/node/pull/63949) - \[[`6274fccbd9`](https://github.com/nodejs/node/commit/6274fccbd9)] - **deps**: update OpenSSL to 3.5.8 (Node.js GitHub Bot) [#&#8203;65542](https://github.com/nodejs/node/pull/65542) - \[[`53cba013c7`](https://github.com/nodejs/node/commit/53cba013c7)] - **deps**: update Undici to 7.29.1 (Node.js GitHub Bot) [#&#8203;65789](https://github.com/nodejs/node/pull/65789) - \[[`0529772798`](https://github.com/nodejs/node/commit/0529772798)] - **(SEMVER-MINOR)** **lib,src**: improve histogram implementation (James M Snell) [#&#8203;65024](https://github.com/nodejs/node/pull/65024) - \[[`41c7062b81`](https://github.com/nodejs/node/commit/41c7062b81)] - **(SEMVER-MINOR)** **net**: improve performance of `net.BlockList` (James M Snell) [#&#8203;64974](https://github.com/nodejs/node/pull/64974) - \[[`5197b5a3c5`](https://github.com/nodejs/node/commit/5197b5a3c5)] - **(SEMVER-MINOR)** **perf\_hooks**: add statistical hypothesis testing to histogram (James M Snell) [#&#8203;65416](https://github.com/nodejs/node/pull/65416) - \[[`35c635b032`](https://github.com/nodejs/node/commit/35c635b032)] - **(SEMVER-MINOR)** **util**: add non-throwing `MIMEType.parse` (James M Snell) [#&#8203;64965](https://github.com/nodejs/node/pull/64965) ##### Commits - \[[`84d706cb9b`](https://github.com/nodejs/node/commit/84d706cb9b)] - **assert**: improve documentation wording (Kamal Rawal) [#&#8203;64953](https://github.com/nodejs/node/pull/64953) - \[[`90d127db33`](https://github.com/nodejs/node/commit/90d127db33)] - **(SEMVER-MINOR)** **benchmark**: add --analyze mode to compare.js (James M Snell) [#&#8203;65416](https://github.com/nodejs/node/pull/65416) - \[[`ad1d7884c3`](https://github.com/nodejs/node/commit/ad1d7884c3)] - **benchmark**: add test-only and mock timers cases (Luan Muniz) [#&#8203;64097](https://github.com/nodejs/node/pull/64097) - \[[`1d8f045914`](https://github.com/nodejs/node/commit/1d8f045914)] - **benchmark**: apply `highWaterMark` in webstreams `pipe-to` (Matteo Collina) [#&#8203;65138](https://github.com/nodejs/node/pull/65138) - \[[`ed7ba3c993`](https://github.com/nodejs/node/commit/ed7ba3c993)] - **benchmark**: complete the sqlite is-transaction fix (Edy Silva) [#&#8203;65218](https://github.com/nodejs/node/pull/65218) - \[[`c8837e1aa3`](https://github.com/nodejs/node/commit/c8837e1aa3)] - **benchmark**: add test runner hooks and options (Luan Muniz) [#&#8203;63754](https://github.com/nodejs/node/pull/63754) - \[[`2ba8661e23`](https://github.com/nodejs/node/commit/2ba8661e23)] - **buffer**: prevent string write offset overflow (Matteo Collina) [#&#8203;65043](https://github.com/nodejs/node/pull/65043) - \[[`cc9ee6c2ae`](https://github.com/nodejs/node/commit/cc9ee6c2ae)] - **buffer**: treat detached ArrayBuffers as empty (Archkon) [#&#8203;64504](https://github.com/nodejs/node/pull/64504) - \[[`5a5d73e4c5`](https://github.com/nodejs/node/commit/5a5d73e4c5)] - **build**: pass target architecture to small-icu genccode (ulofiai) [#&#8203;65095](https://github.com/nodejs/node/pull/65095) - \[[`273e72d1a5`](https://github.com/nodejs/node/commit/273e72d1a5)] - **build**: deprecate always enabled `--enable-static` (Chengzhong Wu) [#&#8203;65103](https://github.com/nodejs/node/pull/65103) - \[[`89a67246e3`](https://github.com/nodejs/node/commit/89a67246e3)] - **build**: check FIPS option value in node.gyp (Filip Skokan) [#&#8203;64982](https://github.com/nodejs/node/pull/64982) - \[[`2d21f41cd5`](https://github.com/nodejs/node/commit/2d21f41cd5)] - **build**: handle malformed OpenSSL macros (Filip Skokan) [#&#8203;64982](https://github.com/nodejs/node/pull/64982) - \[[`f62bc0f862`](https://github.com/nodejs/node/commit/f62bc0f862)] - **build,win**: add PGO workload scripts (Stefan Stojanovic) [#&#8203;63696](https://github.com/nodejs/node/pull/63696) - \[[`33d0c7dc12`](https://github.com/nodejs/node/commit/33d0c7dc12)] - **child\_process**: keep SIGWINCH from killing on Win (Kirill Saied) [#&#8203;64510](https://github.com/nodejs/node/pull/64510) - \[[`71106e1f17`](https://github.com/nodejs/node/commit/71106e1f17)] - **crypto**: update root certificates to NSS 3.126 (Node.js GitHub Bot) [#&#8203;65495](https://github.com/nodejs/node/pull/65495) - \[[`419af8b86d`](https://github.com/nodejs/node/commit/419af8b86d)] - **crypto**: fix missing error checks on ASN1\_STRING\_to\_UTF8() (Nora Dossche) [#&#8203;65200](https://github.com/nodejs/node/pull/65200) - \[[`8029383f3f`](https://github.com/nodejs/node/commit/8029383f3f)] - **crypto**: use available BoringSSL APIs (Filip Skokan) [#&#8203;65423](https://github.com/nodejs/node/pull/65423) - \[[`a9bd780e19`](https://github.com/nodejs/node/commit/a9bd780e19)] - **crypto**: remove obsolete BoringSSL shims (Filip Skokan) [#&#8203;65423](https://github.com/nodejs/node/pull/65423) - \[[`7defefad3f`](https://github.com/nodejs/node/commit/7defefad3f)] - **crypto**: read WebCrypto inputs through primordials (Filip Skokan) [#&#8203;65115](https://github.com/nodejs/node/pull/65115) - \[[`6ed1e38627`](https://github.com/nodejs/node/commit/6ed1e38627)] - **crypto**: fix disabling FIPS mode (Filip Skokan) [#&#8203;64982](https://github.com/nodejs/node/pull/64982) - \[[`afca0a912d`](https://github.com/nodejs/node/commit/afca0a912d)] - **(SEMVER-MINOR)** **crypto**: support loading private keys through STORE loaders (Filip Skokan) [#&#8203;63949](https://github.com/nodejs/node/pull/63949) - \[[`9b9dd6e9cf`](https://github.com/nodejs/node/commit/9b9dd6e9cf)] - **debugger**: wait for target startup (Filip Skokan) [#&#8203;65194](https://github.com/nodejs/node/pull/65194) - \[[`07faaeeffd`](https://github.com/nodejs/node/commit/07faaeeffd)] - **deps**: update corepack to 0.36.0 (Node.js GitHub Bot) [#&#8203;65653](https://github.com/nodejs/node/pull/65653) - \[[`53cba013c7`](https://github.com/nodejs/node/commit/53cba013c7)] - **deps**: update undici to 7.29.1 (Node.js GitHub Bot) [#&#8203;65789](https://github.com/nodejs/node/pull/65789) - \[[`0268ca547c`](https://github.com/nodejs/node/commit/0268ca547c)] - **deps**: update archs files for openssl-3.5.8 (Node.js GitHub Bot) [#&#8203;65542](https://github.com/nodejs/node/pull/65542) - \[[`6274fccbd9`](https://github.com/nodejs/node/commit/6274fccbd9)] - **deps**: upgrade openssl sources to openssl-3.5.8 (Node.js GitHub Bot) [#&#8203;65542](https://github.com/nodejs/node/pull/65542) - \[[`6bdcd121fa`](https://github.com/nodejs/node/commit/6bdcd121fa)] - **deps**: update zlib to 1.3.2.1-motley-8002e91 (Node.js GitHub Bot) [#&#8203;65316](https://github.com/nodejs/node/pull/65316) - \[[`c2aa446b6d`](https://github.com/nodejs/node/commit/c2aa446b6d)] - **deps**: update simdjson to 4.6.7 (Node.js GitHub Bot) [#&#8203;65318](https://github.com/nodejs/node/pull/65318) - \[[`3e58e48ea8`](https://github.com/nodejs/node/commit/3e58e48ea8)] - **deps**: update googletest to [`49495ea`](https://github.com/nodejs/node/commit/49495eacfdbda3f4b6ba219923fedbb2e3f99376) (Node.js GitHub Bot) [#&#8203;65317](https://github.com/nodejs/node/pull/65317) - \[[`670b3665c0`](https://github.com/nodejs/node/commit/670b3665c0)] - **deps**: cherry-pick [libuv/libuv@`e640dc9`](https://github.com/libuv/libuv/commit/e640dc9) (ulofiai) [#&#8203;65118](https://github.com/nodejs/node/pull/65118) - \[[`ca1c67b021`](https://github.com/nodejs/node/commit/ca1c67b021)] - **deps**: float ICU-23262 patch for icu78 (René) [#&#8203;64678](https://github.com/nodejs/node/pull/64678) - \[[`4ad043b0aa`](https://github.com/nodejs/node/commit/4ad043b0aa)] - **deps**: enable AVX-512 OpenSSL asm with clang (Daniel Lemire) [#&#8203;65136](https://github.com/nodejs/node/pull/65136) - \[[`96b4af109b`](https://github.com/nodejs/node/commit/96b4af109b)] - **deps**: update googletest to [`d89aac5`](https://github.com/nodejs/node/commit/d89aac5f0dd4021198d903d39de16f896726de21) (Node.js GitHub Bot) [#&#8203;65153](https://github.com/nodejs/node/pull/65153) - \[[`774f663c56`](https://github.com/nodejs/node/commit/774f663c56)] - **dgram**: don't swallow bind errors when callback is provided (armanmikoyan) [#&#8203;62602](https://github.com/nodejs/node/pull/62602) - \[[`94b118d62e`](https://github.com/nodejs/node/commit/94b118d62e)] - **diagnostics\_channel**: validate before channel activation (Trivikram Kamat) [#&#8203;65313](https://github.com/nodejs/node/pull/65313) - \[[`09788665bd`](https://github.com/nodejs/node/commit/09788665bd)] - **dns**: validate address type in lookupService (Lazizbek Ergashev) [#&#8203;64878](https://github.com/nodejs/node/pull/64878) - \[[`15f95fc0e2`](https://github.com/nodejs/node/commit/15f95fc0e2)] - **dns**: validate port range in `setServers()` (René) [#&#8203;65021](https://github.com/nodejs/node/pull/65021) - \[[`37b9e9a154`](https://github.com/nodejs/node/commit/37b9e9a154)] - **dns**: fix crash on setServers with port 0 (Lazizbek Ergashev) [#&#8203;65009](https://github.com/nodejs/node/pull/65009) - \[[`cd6205fa0d`](https://github.com/nodejs/node/commit/cd6205fa0d)] - **doc**: update AHAFS reference link (Taeuk Ha) [#&#8203;65481](https://github.com/nodejs/node/pull/65481) - \[[`0e6f9ae42e`](https://github.com/nodejs/node/commit/0e6f9ae42e)] - **doc**: fix property names in os.networkInterfaces() example (Jihwan) [#&#8203;65469](https://github.com/nodejs/node/pull/65469) - \[[`034a827b41`](https://github.com/nodejs/node/commit/034a827b41)] - **doc**: fix broken links in cli.md (Donghoon Kang) [#&#8203;65412](https://github.com/nodejs/node/pull/65412) - \[[`eb364621d4`](https://github.com/nodejs/node/commit/eb364621d4)] - **doc**: remove outdated WASI version fallback (이혜미) [#&#8203;65303](https://github.com/nodejs/node/pull/65303) - \[[`b13f425bf8`](https://github.com/nodejs/node/commit/b13f425bf8)] - **doc**: fix broken GYP link in n-api.md (Donghoon Kang) [#&#8203;65413](https://github.com/nodejs/node/pull/65413) - \[[`45c4011067`](https://github.com/nodejs/node/commit/45c4011067)] - **doc**: document that an empty OPENSSL\_CONF skips config loading (Orgad Shaneh) [#&#8203;64949](https://github.com/nodejs/node/pull/64949) - \[[`fde6776c5f`](https://github.com/nodejs/node/commit/fde6776c5f)] - **doc**: fix broken TLS security level example (soreavis) [#&#8203;65391](https://github.com/nodejs/node/pull/65391) - \[[`290c1fec04`](https://github.com/nodejs/node/commit/290c1fec04)] - **doc**: clarify socket destroyed behavior (Dayun) [#&#8203;65395](https://github.com/nodejs/node/pull/65395) - \[[`a7e8269947`](https://github.com/nodejs/node/commit/a7e8269947)] - **doc**: update outdated nodejs.org guide links (Donghoon Kang) [#&#8203;65394](https://github.com/nodejs/node/pull/65394) - \[[`7809f11249`](https://github.com/nodejs/node/commit/7809f11249)] - **doc**: clarify that ipv4 mapped to ipv6 are classified as ipv6 (Vedant Kulkarni) [#&#8203;62117](https://github.com/nodejs/node/pull/62117) - \[[`64cd3a6e95`](https://github.com/nodejs/node/commit/64cd3a6e95)] - **doc**: clarify how fs.Dirent file types are determined (soreavis) [#&#8203;64532](https://github.com/nodejs/node/pull/64532) - \[[`9b92fdce14`](https://github.com/nodejs/node/commit/9b92fdce14)] - **doc**: update security release prepare command (Rafael Gonzaga) [#&#8203;64699](https://github.com/nodejs/node/pull/64699) - \[[`6f9b9df3c1`](https://github.com/nodejs/node/commit/6f9b9df3c1)] - **doc**: clarify copyFile symlink behavior (T) [#&#8203;62941](https://github.com/nodejs/node/pull/62941) - \[[`2480acb550`](https://github.com/nodejs/node/commit/2480acb550)] - **doc**: document setRawMode write access on Windows (Erik Demaine) [#&#8203;63856](https://github.com/nodejs/node/pull/63856) - \[[`a1e9c3a5db`](https://github.com/nodejs/node/commit/a1e9c3a5db)] - **doc**: add missing return types in fs.md (Chaseton Collins) [#&#8203;65307](https://github.com/nodejs/node/pull/65307) - \[[`4533572040`](https://github.com/nodejs/node/commit/4533572040)] - **doc**: add missing return types in buffer.md (Yuya Inoue) [#&#8203;65308](https://github.com/nodejs/node/pull/65308) - \[[`39ecedbbd2`](https://github.com/nodejs/node/commit/39ecedbbd2)] - **doc**: fix lint clean command (greenhead) [#&#8203;65274](https://github.com/nodejs/node/pull/65274) - \[[`0b1fb8fcd8`](https://github.com/nodejs/node/commit/0b1fb8fcd8)] - **doc**: fix typo in onboarding.md (서울민트초코) [#&#8203;65295](https://github.com/nodejs/node/pull/65295) - \[[`3165b5d38a`](https://github.com/nodejs/node/commit/3165b5d38a)] - **doc**: add missing `added:` tags to `fs.lchmod` (Lazizbek Ergashev) [#&#8203;65283](https://github.com/nodejs/node/pull/65283) - \[[`113b808e59`](https://github.com/nodejs/node/commit/113b808e59)] - **doc**: fix SQLite changeset constant descriptions (greenhead) [#&#8203;65265](https://github.com/nodejs/node/pull/65265) - \[[`c3eb51d5a1`](https://github.com/nodejs/node/commit/c3eb51d5a1)] - **doc**: document open pull request limit (Matteo Collina) [#&#8203;65250](https://github.com/nodejs/node/pull/65250) - \[[`d7accdcd52`](https://github.com/nodejs/node/commit/d7accdcd52)] - **doc**: document http2 header constants (Harjoth Khara) [#&#8203;64548](https://github.com/nodejs/node/pull/64548) - \[[`f47111416f`](https://github.com/nodejs/node/commit/f47111416f)] - **doc**: create ai-guidelines and include to CONTRIBUTING (Rafael Gonzaga) [#&#8203;62105](https://github.com/nodejs/node/pull/62105) - \[[`c3b120e737`](https://github.com/nodejs/node/commit/c3b120e737)] - **doc**: update synopsis (Augustin Mauroy) [#&#8203;65171](https://github.com/nodejs/node/pull/65171) - \[[`39f4c831fd`](https://github.com/nodejs/node/commit/39f4c831fd)] - **doc**: fix broken internal links (greenhead) [#&#8203;64901](https://github.com/nodejs/node/pull/64901) - \[[`be25cdd69e`](https://github.com/nodejs/node/commit/be25cdd69e)] - **doc**: report proper return type on urlPattern.test (Brian Muenzenmeyer) [#&#8203;64831](https://github.com/nodejs/node/pull/64831) - \[[`1bf7737810`](https://github.com/nodejs/node/commit/1bf7737810)] - **doc**: fix permission documentation examples (greenhead) [#&#8203;64897](https://github.com/nodejs/node/pull/64897) - \[[`b7932e68a1`](https://github.com/nodejs/node/commit/b7932e68a1)] - **doc**: document sqlite parameter binding (Guilherme Araújo) [#&#8203;65089](https://github.com/nodejs/node/pull/65089) - \[[`5234a5169c`](https://github.com/nodejs/node/commit/5234a5169c)] - **doc**: finalize statements in sqlite examples (Guilherme Araújo) [#&#8203;65088](https://github.com/nodejs/node/pull/65088) - \[[`39ea929da7`](https://github.com/nodejs/node/commit/39ea929da7)] - **doc**: document quic stopSending() and resetStream() (Issac) [#&#8203;64888](https://github.com/nodejs/node/pull/64888) - \[[`2ba198db73`](https://github.com/nodejs/node/commit/2ba198db73)] - **doc**: clarify sqlite bare parameter default (Sumit Kumar Das) [#&#8203;62009](https://github.com/nodejs/node/pull/62009) - \[[`314f9b200f`](https://github.com/nodejs/node/commit/314f9b200f)] - **doc**: remove usage of `util.inherits` (Augustin Mauroy) [#&#8203;60817](https://github.com/nodejs/node/pull/60817) - \[[`d82a61662c`](https://github.com/nodejs/node/commit/d82a61662c)] - **doc**: fix grammar in worker\_threads.md (이혜미) [#&#8203;64913](https://github.com/nodejs/node/pull/64913) - \[[`44c0c8ff5b`](https://github.com/nodejs/node/commit/44c0c8ff5b)] - **doc**: clarify OpenSSL FIPS configuration (Filip Skokan) [#&#8203;64982](https://github.com/nodejs/node/pull/64982) - \[[`9b2ca70e0d`](https://github.com/nodejs/node/commit/9b2ca70e0d)] - **doc**: remove `--expose-gc` flag from CLI documentation (Dario Piotrowicz) [#&#8203;58909](https://github.com/nodejs/node/pull/58909) - \[[`a0a12397b9`](https://github.com/nodejs/node/commit/a0a12397b9)] - **doc**: document ArrayBuffer support in pbkd2Sync (kyungrae2002) [#&#8203;64976](https://github.com/nodejs/node/pull/64976) - \[[`b48699e077`](https://github.com/nodejs/node/commit/b48699e077)] - **doc**: correct default highWaterMark values (Yilong Li) [#&#8203;64617](https://github.com/nodejs/node/pull/64617) - \[[`0312ee133c`](https://github.com/nodejs/node/commit/0312ee133c)] - **esm**: avoid super-linear data URL MIME regex (Sumit Kumar Das) [#&#8203;61951](https://github.com/nodejs/node/pull/61951) - \[[`cd84d55c81`](https://github.com/nodejs/node/commit/cd84d55c81)] - **esm**: only register text format when enabled (Efe Karasakal) [#&#8203;64992](https://github.com/nodejs/node/pull/64992) - \[[`c0a8ef611e`](https://github.com/nodejs/node/commit/c0a8ef611e)] - **esm**: fix wasm import name in error message (이혜미) [#&#8203;64950](https://github.com/nodejs/node/pull/64950) - \[[`e6c34f90c2`](https://github.com/nodejs/node/commit/e6c34f90c2)] - **events**: inline iterationCondition hybrid dispatch closure (Szymon Łągiewka) [#&#8203;64473](https://github.com/nodejs/node/pull/64473) - \[[`6ee4b40c91`](https://github.com/nodejs/node/commit/6ee4b40c91)] - **events**: inline createEvent hybrid dispatch closure (Szymon Łągiewka) [#&#8203;64473](https://github.com/nodejs/node/pull/64473) - \[[`367549eed5`](https://github.com/nodejs/node/commit/367549eed5)] - **fs**: use sized reads for large files in readFileUtf8 (Shelley Vohr) [#&#8203;65328](https://github.com/nodejs/node/pull/65328) - \[[`8a5b1ae4c2`](https://github.com/nodejs/node/commit/8a5b1ae4c2)] - **fs**: fix realpath of namespaced drive paths (Jason Zhang) [#&#8203;65378](https://github.com/nodejs/node/pull/65378) - \[[`c9233b950d`](https://github.com/nodejs/node/commit/c9233b950d)] - **fs**: fix glob early return skipping sibling entries (Srinu desetti) [#&#8203;64895](https://github.com/nodejs/node/pull/64895) - \[[`bc54dd8905`](https://github.com/nodejs/node/commit/bc54dd8905)] - **fs**: pass symlink type in cp when filter is provided (Jerry Zhao) [#&#8203;62654](https://github.com/nodejs/node/pull/62654) - \[[`fcb4333aca`](https://github.com/nodejs/node/commit/fcb4333aca)] - **fs**: allocate FSReqPromise stat arrays lazily (Samuel Attard) [#&#8203;63886](https://github.com/nodejs/node/pull/63886) - \[[`c35876154e`](https://github.com/nodejs/node/commit/c35876154e)] - **fs**: fix out-of-bounds write in mkdtemp for long prefixes (Hierax\_Umbra) [#&#8203;64770](https://github.com/nodejs/node/pull/64770) - \[[`b269616936`](https://github.com/nodejs/node/commit/b269616936)] - **fs**: treat `std::errc::permission_denied` as `EPERM` error (Kirill Saied) [#&#8203;64698](https://github.com/nodejs/node/pull/64698) - \[[`212fe77e76`](https://github.com/nodejs/node/commit/212fe77e76)] - **fs**: add windowsHandle option to file streams (Kirill Saied) [#&#8203;63851](https://github.com/nodejs/node/pull/63851) - \[[`75df6cb435`](https://github.com/nodejs/node/commit/75df6cb435)] - **http**: improve performance with known-length calls to end() (Tim Perry) [#&#8203;65466](https://github.com/nodejs/node/pull/65466) - \[[`48d9cd4a28`](https://github.com/nodejs/node/commit/48d9cd4a28)] - **http**: cache maxHeaderPairs per header section (GetThatCookie) [#&#8203;64988](https://github.com/nodejs/node/pull/64988) - \[[`04785c8f43`](https://github.com/nodejs/node/commit/04785c8f43)] - **http**: fix keylog listener setup on existing agent sockets (Shani Singh) [#&#8203;65066](https://github.com/nodejs/node/pull/65066) - \[[`4b90031534`](https://github.com/nodejs/node/commit/4b90031534)] - **http**: emit drain on socket takeover and avoid stale HWM reuse (Naman Trivedi) [#&#8203;64991](https://github.com/nodejs/node/pull/64991) - \[[`83a27559cd`](https://github.com/nodejs/node/commit/83a27559cd)] - **http2**: adapt receive deferral for Node.js 24 (Matteo Collina) [#&#8203;65093](https://github.com/nodejs/node/pull/65093) - \[[`f43bed0ecc`](https://github.com/nodejs/node/commit/f43bed0ecc)] - **http2**: avoid uaf while receiving and sending rst\_stream (esgor) [#&#8203;64166](https://github.com/nodejs/node/pull/64166) - \[[`b42d664321`](https://github.com/nodejs/node/commit/b42d664321)] - **inspector**: avoid calling into JS from V8 interrupts (Joyee Cheung) [#&#8203;65028](https://github.com/nodejs/node/pull/65028) - \[[`6bf852197d`](https://github.com/nodejs/node/commit/6bf852197d)] - **lib**: use bracket notation instead of startsWith/endsWith for single char (Taejin Kim) [#&#8203;61500](https://github.com/nodejs/node/pull/61500) - \[[`151ca7e104`](https://github.com/nodejs/node/commit/151ca7e104)] - **lib**: harden webidl dictionary member reads (Filip Skokan) [#&#8203;65115](https://github.com/nodejs/node/pull/65115) - \[[`7e8c2c9f44`](https://github.com/nodejs/node/commit/7e8c2c9f44)] - **lib**: use validateArray for array arguments (greenhead) [#&#8203;64959](https://github.com/nodejs/node/pull/64959) - \[[`424fe2bc5a`](https://github.com/nodejs/node/commit/424fe2bc5a)] - **lib**: add and test \[EnforceRange] in webcrypto dictionaries (Filip Skokan) [#&#8203;65091](https://github.com/nodejs/node/pull/65091) - \[[`0529772798`](https://github.com/nodejs/node/commit/0529772798)] - **(SEMVER-MINOR)** **lib,src**: improve histogram implementation (James M Snell) [#&#8203;65024](https://github.com/nodejs/node/pull/65024) - \[[`186e1b76e8`](https://github.com/nodejs/node/commit/186e1b76e8)] - **meta**: move targos to emeritus (Michaël Zasso) [#&#8203;65393](https://github.com/nodejs/node/pull/65393) - \[[`b41b07c72a`](https://github.com/nodejs/node/commit/b41b07c72a)] - **meta**: add unified http api initiative (James M Snell) [#&#8203;65139](https://github.com/nodejs/node/pull/65139) - \[[`f85b6ecd67`](https://github.com/nodejs/node/commit/f85b6ecd67)] - **meta**: move one or more collaborators to emeritus (Node.js GitHub Bot) [#&#8203;65182](https://github.com/nodejs/node/pull/65182) - \[[`8f3d01bdce`](https://github.com/nodejs/node/commit/8f3d01bdce)] - **meta**: add Aviv Keller to `.mailmap` (Aviv Keller) [#&#8203;65048](https://github.com/nodejs/node/pull/65048) - \[[`cfad1d5b28`](https://github.com/nodejs/node/commit/cfad1d5b28)] - **meta**: update sccache to 0.17.0 (René) [#&#8203;64985](https://github.com/nodejs/node/pull/64985) - \[[`349c53c441`](https://github.com/nodejs/node/commit/349c53c441)] - **module**: report unreadable package.json (Paul Bouchon) [#&#8203;65223](https://github.com/nodejs/node/pull/65223) - \[[`bd21e6706e`](https://github.com/nodejs/node/commit/bd21e6706e)] - **module**: cache nearest parent package.json per directory (Shelley Vohr) [#&#8203;65326](https://github.com/nodejs/node/pull/65326) - \[[`961bd04370`](https://github.com/nodejs/node/commit/961bd04370)] - **module**: fix --check on ambiguous ESM files (Paul Bouchon) [#&#8203;65203](https://github.com/nodejs/node/pull/65203) - \[[`f45ef73420`](https://github.com/nodejs/node/commit/f45ef73420)] - **net**: handle undefined parent in \_unrefTimer and \_destroy (Shivay-98) [#&#8203;64644](https://github.com/nodejs/node/pull/64644) - \[[`41c7062b81`](https://github.com/nodejs/node/commit/41c7062b81)] - **(SEMVER-MINOR)** **net**: improve performance of net.BlockList (James M Snell) [#&#8203;64974](https://github.com/nodejs/node/pull/64974) - \[[`5197b5a3c5`](https://github.com/nodejs/node/commit/5197b5a3c5)] - **(SEMVER-MINOR)** **perf\_hooks**: add statistical hypothesis testing to histogram (James M Snell) [#&#8203;65416](https://github.com/nodejs/node/pull/65416) - \[[`1722ddac28`](https://github.com/nodejs/node/commit/1722ddac28)] - **permission**: enforce addon permission in GetLinkedBinding (Rafael Gonzaga) [#&#8203;65432](https://github.com/nodejs/node/pull/65432) - \[[`dff2b675db`](https://github.com/nodejs/node/commit/dff2b675db)] - **process**: validate resource stats array offsets (Archkon) [#&#8203;65098](https://github.com/nodejs/node/pull/65098) - \[[`f277983e7b`](https://github.com/nodejs/node/commit/f277983e7b)] - **quic**: changes for nghttp3\_conn\_close\_stream2 (Marten Richter) [#&#8203;64574](https://github.com/nodejs/node/pull/64574) - \[[`a4c770c78e`](https://github.com/nodejs/node/commit/a4c770c78e)] - **quic**: mark drain promise handled (James M Snell) [#&#8203;65319](https://github.com/nodejs/node/pull/65319) - \[[`2460b171c5`](https://github.com/nodejs/node/commit/2460b171c5)] - **quic**: reset rejected HTTP/3 request streams with H3\_REQUEST\_REJECTED (trivenay) [#&#8203;65442](https://github.com/nodejs/node/pull/65442) - \[[`18a7ccf302`](https://github.com/nodejs/node/commit/18a7ccf302)] - **quic**: write desired size needs update on maxstream (Marten Richter) [#&#8203;64768](https://github.com/nodejs/node/pull/64768) - \[[`9017f4a780`](https://github.com/nodejs/node/commit/9017f4a780)] - **quic**: do not destroy incoming streams that have a consumer (trivenay) [#&#8203;65335](https://github.com/nodejs/node/pull/65335) - \[[`ddc41c1ef4`](https://github.com/nodejs/node/commit/ddc41c1ef4)] - **quic**: fix wake up blob (Marten Richter) [#&#8203;64044](https://github.com/nodejs/node/pull/64044) - \[[`88bee43d7c`](https://github.com/nodejs/node/commit/88bee43d7c)] - **quic**: convert incoming :status header to number (Hallison Pereira Melo) [#&#8203;63589](https://github.com/nodejs/node/pull/63589) - \[[`cd776fe97c`](https://github.com/nodejs/node/commit/cd776fe97c)] - **quic**: fix infinite loop if STOP\_SENDING received on a buffering stream (Tim Perry) [#&#8203;64715](https://github.com/nodejs/node/pull/64715) - \[[`4f6eda3c23`](https://github.com/nodejs/node/commit/4f6eda3c23)] - **repl**: keep entries added while history file is loading (Mhayk Whandson) [#&#8203;64513](https://github.com/nodejs/node/pull/64513) - \[[`cd1e6ce29b`](https://github.com/nodejs/node/commit/cd1e6ce29b)] - **repl**: add benchmarks (Aviv Keller) [#&#8203;64590](https://github.com/nodejs/node/pull/64590) - \[[`2ba740669d`](https://github.com/nodejs/node/commit/2ba740669d)] - **sea**: avoid dangling CLI option pointers (Archkon) [#&#8203;64755](https://github.com/nodejs/node/pull/64755) - \[[`ec5e2d6856`](https://github.com/nodejs/node/commit/ec5e2d6856)] - **sea**: handle NUL bytes in asset keys (Archkon) [#&#8203;64773](https://github.com/nodejs/node/pull/64773) - \[[`703b854293`](https://github.com/nodejs/node/commit/703b854293)] - **sea**: reject trailing content in config JSON (Archkon) [#&#8203;64774](https://github.com/nodejs/node/pull/64774) - \[[`a61a5fdd1c`](https://github.com/nodejs/node/commit/a61a5fdd1c)] - **sqlite**: prevent reentrant session.close() (Trivikram Kamat) [#&#8203;65349](https://github.com/nodejs/node/pull/65349) - \[[`6ae81be0a3`](https://github.com/nodejs/node/commit/6ae81be0a3)] - **sqlite**: reject statement-less SQL in prepare() (Trevor Burnham) [#&#8203;65157](https://github.com/nodejs/node/pull/65157) - \[[`043dfe4996`](https://github.com/nodejs/node/commit/043dfe4996)] - **sqlite**: reject statement-less SQL in SQLTagStore (Trevor Burnham) [#&#8203;65157](https://github.com/nodejs/node/pull/65157) - \[[`b8faee02e1`](https://github.com/nodejs/node/commit/b8faee02e1)] - **sqlite**: check null returns from sqlite value functions (Nora Dossche) [#&#8203;63288](https://github.com/nodejs/node/pull/63288) - \[[`d6d2a71bee`](https://github.com/nodejs/node/commit/d6d2a71bee)] - **sqlite**: validate maxSize argument in createTagStore() (Anshika Jain) [#&#8203;63792](https://github.com/nodejs/node/pull/63792) - \[[`61a046309f`](https://github.com/nodejs/node/commit/61a046309f)] - **sqlite**: reject non-positive backup rates (Trivikram Kamat) [#&#8203;64893](https://github.com/nodejs/node/pull/64893) - \[[`514e3f30fb`](https://github.com/nodejs/node/commit/514e3f30fb)] - **sqlite**: clear SQLTagStore bindings (Matteo Collina) [#&#8203;65041](https://github.com/nodejs/node/pull/65041) - \[[`c1542255b8`](https://github.com/nodejs/node/commit/c1542255b8)] - **sqlite**: bind Boolean (mike-git374) [#&#8203;62001](https://github.com/nodejs/node/pull/62001) - \[[`cdb732beb5`](https://github.com/nodejs/node/commit/cdb732beb5)] - **sqlite**: fix undefined behaviour in `Session::Changeset()` (Nora Dossche) [#&#8203;63637](https://github.com/nodejs/node/pull/63637) - \[[`fbe8861111`](https://github.com/nodejs/node/commit/fbe8861111)] - **sqlite**: bind ArrayBuffer (mike-git374) [#&#8203;62061](https://github.com/nodejs/node/pull/62061) - \[[`e3c6bd6bc8`](https://github.com/nodejs/node/commit/e3c6bd6bc8)] - **src**: add missing vector include (Filip Skokan) [#&#8203;65622](https://github.com/nodejs/node/pull/65622) - \[[`793cf69df8`](https://github.com/nodejs/node/commit/793cf69df8)] - **src**: fix heap value deduplication in embedder graph (Ilyas Shabi) [#&#8203;64801](https://github.com/nodejs/node/pull/64801) - \[[`ea5935b04c`](https://github.com/nodejs/node/commit/ea5935b04c)] - **src**: fix out-of-bounds write when transcoding odd-length ucs2 (nashit hayat) [#&#8203;64512](https://github.com/nodejs/node/pull/64512) - \[[`22e5023f4d`](https://github.com/nodejs/node/commit/22e5023f4d)] - **src**: escape Windows environment variables in task runner (Antoine du Hamel) [#&#8203;65217](https://github.com/nodejs/node/pull/65217) - \[[`a0f3c62bd9`](https://github.com/nodejs/node/commit/a0f3c62bd9)] - **src**: simplify c++ diagnostics channel API (James M Snell) [#&#8203;65158](https://github.com/nodejs/node/pull/65158) - \[[`8e831a3d2e`](https://github.com/nodejs/node/commit/8e831a3d2e)] - **src**: make minor cleanup to permission checks (James M Snell) [#&#8203;65158](https://github.com/nodejs/node/pull/65158) - \[[`968b2ca3a3`](https://github.com/nodejs/node/commit/968b2ca3a3)] - **src**: use DictionaryTemplate for permission diag channel message (James M Snell) [#&#8203;65158](https://github.com/nodejs/node/pull/65158) - \[[`18e16e7f8d`](https://github.com/nodejs/node/commit/18e16e7f8d)] - **src**: cache permission strings (James M Snell) [#&#8203;65158](https://github.com/nodejs/node/pull/65158) - \[[`c8625a4b6f`](https://github.com/nodejs/node/commit/c8625a4b6f)] - **src**: add SetAbortHandler (Max H Fisher) [#&#8203;64684](https://github.com/nodejs/node/pull/64684) - \[[`c990140d60`](https://github.com/nodejs/node/commit/c990140d60)] - **src**: match cmd.exe case-insensitively in task runner (Archkon) [#&#8203;64907](https://github.com/nodejs/node/pull/64907) - \[[`d7463b9dbc`](https://github.com/nodejs/node/commit/d7463b9dbc)] - **src**: reuse cached env strings in remaining files (Seongeun Lee) [#&#8203;65039](https://github.com/nodejs/node/pull/65039) - \[[`b055a43b93`](https://github.com/nodejs/node/commit/b055a43b93)] - **src**: expose Windows-only fs open flags (Kirill Saied) [#&#8203;64775](https://github.com/nodejs/node/pull/64775) - \[[`7f21e37496`](https://github.com/nodejs/node/commit/7f21e37496)] - **src**: report why --enable-fips failed (Filip Skokan) [#&#8203;64979](https://github.com/nodejs/node/pull/64979) - \[[`8c11beae27`](https://github.com/nodejs/node/commit/8c11beae27)] - **src**: update repeated use strings to env (James M Snell) [#&#8203;64760](https://github.com/nodejs/node/pull/64760) - \[[`9e2c477e26`](https://github.com/nodejs/node/commit/9e2c477e26)] - **stream**: normalize fused stateless transform results (Trivikram Kamat) [#&#8203;65367](https://github.com/nodejs/node/pull/65367) - \[[`107e96dd41`](https://github.com/nodejs/node/commit/107e96dd41)] - **stream**: encode whole chunks in TextEncoderStream (Matteo Collina) [#&#8203;65414](https://github.com/nodejs/node/pull/65414) - \[[`164068279b`](https://github.com/nodejs/node/commit/164068279b)] - **stream**: prevent share from eagerly draining source (Trivikram Kamat) [#&#8203;65338](https://github.com/nodejs/node/pull/65338) - \[[`93d822bdc1`](https://github.com/nodejs/node/commit/93d822bdc1)] - **stream**: drain pending writes before broadcast end (Trivikram Kamat) [#&#8203;65334](https://github.com/nodejs/node/pull/65334) - \[[`6b8b9c362f`](https://github.com/nodejs/node/commit/6b8b9c362f)] - **stream**: reuse unexposed managed read buffers (GetThatCookie) [#&#8203;64990](https://github.com/nodejs/node/pull/64990) - \[[`4ec4fab367`](https://github.com/nodejs/node/commit/4ec4fab367)] - **stream**: avoid duplicated endReadableNT scheduling (Matteo Collina) [#&#8203;65310](https://github.com/nodejs/node/pull/65310) - \[[`86d1196ebf`](https://github.com/nodejs/node/commit/86d1196ebf)] - **stream**: decouple transform backpressure changes (Matteo Collina) [#&#8203;65143](https://github.com/nodejs/node/pull/65143) - \[[`b8a7a75b19`](https://github.com/nodejs/node/commit/b8a7a75b19)] - **stream**: reject pull on signal abort during flush (Trivikram Kamat) [#&#8203;65346](https://github.com/nodejs/node/pull/65346) - \[[`386ed6a06d`](https://github.com/nodejs/node/commit/386ed6a06d)] - **stream**: avoid leaking consumers on signal failure (Trivikram Kamat) [#&#8203;65299](https://github.com/nodejs/node/pull/65299) - \[[`74d53bd73b`](https://github.com/nodejs/node/commit/74d53bd73b)] - **stream**: use validateObject for zlib/iter params (greenhead) [#&#8203;65015](https://github.com/nodejs/node/pull/65015) - \[[`3a174ce16b`](https://github.com/nodejs/node/commit/3a174ce16b)] - **stream**: use validateNumber for BYOB reader options.min (greenhead) [#&#8203;65014](https://github.com/nodejs/node/pull/65014) - \[[`859ea01cb2`](https://github.com/nodejs/node/commit/859ea01cb2)] - **stream**: consolidate non-op algorithm callbacks (Matteo Collina) [#&#8203;65138](https://github.com/nodejs/node/pull/65138) - \[[`c577669825`](https://github.com/nodejs/node/commit/c577669825)] - **stream**: cut promise churn in webstreams hot paths (Matteo Collina) [#&#8203;65138](https://github.com/nodejs/node/pull/65138) - \[[`d631e910db`](https://github.com/nodejs/node/commit/d631e910db)] - **stream**: preserve falsy cancellation reasons (Trivikram Kamat) [#&#8203;64705](https://github.com/nodejs/node/pull/64705) - \[[`f9c21eabbd`](https://github.com/nodejs/node/commit/f9c21eabbd)] - **stream**: use validateBuffer for BYOB reader view (greenhead) [#&#8203;65046](https://github.com/nodejs/node/pull/65046) - \[[`b89c8f5d1e`](https://github.com/nodejs/node/commit/b89c8f5d1e)] - **stream**: fix recursive WritableStream abort (Jeong SeokChan) [#&#8203;64825](https://github.com/nodejs/node/pull/64825) - \[[`39e0457e86`](https://github.com/nodejs/node/commit/39e0457e86)] - **test**: fix link-local dgram scope assertion (Filip Skokan) [#&#8203;65629](https://github.com/nodejs/node/pull/65629) - \[[`1433cf9d5b`](https://github.com/nodejs/node/commit/1433cf9d5b)] - **test**: account for varied OpenSSL CCM final behaviours (Filip Skokan) [#&#8203;65542](https://github.com/nodejs/node/pull/65542) - \[[`7d135d24b7`](https://github.com/nodejs/node/commit/7d135d24b7)] - **test**: convert forEach to for of test-messageevent-brandcheck file (Nachiketa Pathak) [#&#8203;65279](https://github.com/nodejs/node/pull/65279) - \[[`421ee11715`](https://github.com/nodejs/node/commit/421ee11715)] - **test**: use spawnSyncAndAssert in windowsHide test (Junsoo Ha) [#&#8203;65351](https://github.com/nodejs/node/pull/65351) - \[[`929d5705bc`](https://github.com/nodejs/node/commit/929d5705bc)] - **test**: remove test-debugger-run-after-quit-restart as flaky on macOS (Yuya Inoue) [#&#8203;65424](https://github.com/nodejs/node/pull/65424) - \[[`f38f154c14`](https://github.com/nodejs/node/commit/f38f154c14)] - **test**: simplify test-timers-interval-promisified.js (Donghoon Kang) [#&#8203;65322](https://github.com/nodejs/node/pull/65322) - \[[`a98e27f2a9`](https://github.com/nodejs/node/commit/a98e27f2a9)] - **test**: add Headers coverage and benchmark (Yagiz Nizipli) [#&#8203;65365](https://github.com/nodejs/node/pull/65365) - \[[`38fdbb62aa`](https://github.com/nodejs/node/commit/38fdbb62aa)] - **test**: deflake test-net-listen-ipv6only (sangwook) [#&#8203;64173](https://github.com/nodejs/node/pull/64173) - \[[`06c7684b01`](https://github.com/nodejs/node/commit/06c7684b01)] - **test**: use common/child\_process spawnSync helpers (Junsoo Ha) [#&#8203;65377](https://github.com/nodejs/node/pull/65377) - \[[`6438c70004`](https://github.com/nodejs/node/commit/6438c70004)] - **test**: fix Linux debug skip in SEA test guard (구현우) [#&#8203;63751](https://github.com/nodejs/node/pull/63751) - \[[`fe0e4f1b65`](https://github.com/nodejs/node/commit/fe0e4f1b65)] - **test**: avoid timer race in event loop delay test (Trivikram Kamat) [#&#8203;64728](https://github.com/nodejs/node/pull/64728) - \[[`6ff69baea8`](https://github.com/nodejs/node/commit/6ff69baea8)] - **test**: enforce exit code in `test-http-server-stale-close` (Antoine du Hamel) [#&#8203;65198](https://github.com/nodejs/node/pull/65198) - \[[`ba87603016`](https://github.com/nodejs/node/commit/ba87603016)] - **test**: convert test-async-local-storage-bind to async loop (freida-code) [#&#8203;65270](https://github.com/nodejs/node/pull/65270) - \[[`8d6b89f454`](https://github.com/nodejs/node/commit/8d6b89f454)] - **test**: replace `forEach()` with `for...of` in parallel tests (Phillip Markert) [#&#8203;65272](https://github.com/nodejs/node/pull/65272) - \[[`a60572a7bb`](https://github.com/nodejs/node/commit/a60572a7bb)] - **test**: convert forEach to for in test-constant.js file (NIxxy25) [#&#8203;65271](https://github.com/nodejs/node/pull/65271) - \[[`f82060c6ce`](https://github.com/nodejs/node/commit/f82060c6ce)] - **test**: use for-of instead of forEach (Felix P.) [#&#8203;65268](https://github.com/nodejs/node/pull/65268) - \[[`5ded71f9cc`](https://github.com/nodejs/node/commit/5ded71f9cc)] - **test**: cover `realpathSync` resolving symlinks after a FIFO stat (Hendrik Liebau) [#&#8203;65113](https://github.com/nodejs/node/pull/65113) - \[[`ac9835225e`](https://github.com/nodejs/node/commit/ac9835225e)] - **test**: account for \[EnforceRange] in test-webcrypto-prototype-pollution (Filip Skokan) [#&#8203;65173](https://github.com/nodejs/node/pull/65173) - \[[`550d24277e`](https://github.com/nodejs/node/commit/550d24277e)] - **test**: update WPT for WebCryptoAPI to [`4c2fd05`](https://github.com/nodejs/node/commit/4c2fd05ed5) (Node.js GitHub Bot) [#&#8203;65150](https://github.com/nodejs/node/pull/65150) - \[[`2aa26559f0`](https://github.com/nodejs/node/commit/2aa26559f0)] - **test**: update WPT for urlpattern to [`4832db4`](https://github.com/nodejs/node/commit/4832db4761) (Node.js GitHub Bot) [#&#8203;65151](https://github.com/nodejs/node/pull/65151) - \[[`d45c010108`](https://github.com/nodejs/node/commit/d45c010108)] - **test**: fix hidden error in test-http-server-stale-close.js (Meghan Denny) [#&#8203;59357](https://github.com/nodejs/node/pull/59357) - \[[`881f8d092d`](https://github.com/nodejs/node/commit/881f8d092d)] - **test**: avoid deadlock issue in pipeline http2 tests to fix flakiness (Tim Perry) [#&#8203;65079](https://github.com/nodejs/node/pull/65079) - \[[`e4b1e3ee75`](https://github.com/nodejs/node/commit/e4b1e3ee75)] - **test**: allow half-open CONNECT tunnel sockets (Trivikram Kamat) [#&#8203;64973](https://github.com/nodejs/node/pull/64973) - \[[`00f4240d48`](https://github.com/nodejs/node/commit/00f4240d48)] - **test**: update passphrases to comply with the next OpenSSL FIPS mode (Filip Skokan) [#&#8203;65077](https://github.com/nodejs/node/pull/65077) - \[[`cf7680efb7`](https://github.com/nodejs/node/commit/cf7680efb7)] - **test**: use libuv clock for immediate queue test (Trivikram Kamat) [#&#8203;64889](https://github.com/nodejs/node/pull/64889) - \[[`b0c12772ff`](https://github.com/nodejs/node/commit/b0c12772ff)] - **test**: increase timeout in probe-failure-hang-during-evaluate (Joyee Cheung) [#&#8203;64719](https://github.com/nodejs/node/pull/64719) - \[[`7e279104b4`](https://github.com/nodejs/node/commit/7e279104b4)] - **test**: update WPT for WebCryptoAPI to [`82c3d90`](https://github.com/nodejs/node/commit/82c3d9069c) (Node.js GitHub Bot) [#&#8203;64977](https://github.com/nodejs/node/pull/64977) - \[[`ac11f88d16`](https://github.com/nodejs/node/commit/ac11f88d16)] - **test,doc**: cover and document multi-byte offset/size in randomFill (kyungrae2002) [#&#8203;64834](https://github.com/nodejs/node/pull/64834) - \[[`67da38cada`](https://github.com/nodejs/node/commit/67da38cada)] - **test\_runner**: match dotfiles in default coverage exclude (semimikoh) [#&#8203;63401](https://github.com/nodejs/node/pull/63401) - \[[`b06c61a08f`](https://github.com/nodejs/node/commit/b06c61a08f)] - **test\_runner**: print coverage and diagnostic info with dot reporter (mag123c) [#&#8203;61423](https://github.com/nodejs/node/pull/61423) - \[[`7cb9c9c126`](https://github.com/nodejs/node/commit/7cb9c9c126)] - **test\_runner**: use run options with isolation="none" (Sylvester Keil) [#&#8203;62269](https://github.com/nodejs/node/pull/62269) - \[[`339acf4201`](https://github.com/nodejs/node/commit/339acf4201)] - **test\_runner**: mock dual-package with conditional exports (Maruthan G) [#&#8203;62943](https://github.com/nodejs/node/pull/62943) - \[[`e7a68bca08`](https://github.com/nodejs/node/commit/e7a68bca08)] - **test\_runner**: add classname hierarchy for JUnit reporter (mag123c) [#&#8203;60220](https://github.com/nodejs/node/pull/60220) - \[[`6a248acefe`](https://github.com/nodejs/node/commit/6a248acefe)] - **test\_runner**: fix junit report on empty diagnostic (Lazizbek Ergashev) [#&#8203;65357](https://github.com/nodejs/node/pull/65357) - \[[`d01dda79b6`](https://github.com/nodejs/node/commit/d01dda79b6)] - **test\_runner**: do not tag-filter test file wrappers (Chemi Atlow) [#&#8203;65170](https://github.com/nodejs/node/pull/65170) - \[[`32ead10ddd`](https://github.com/nodejs/node/commit/32ead10ddd)] - **test\_runner**: fix env option validation (Jihwan) [#&#8203;64865](https://github.com/nodejs/node/pull/64865) - \[[`b0ef155440`](https://github.com/nodejs/node/commit/b0ef155440)] - **tls**: throw on invalid ALPNProtocols instead of aborting (Sankalp Thakur) [#&#8203;65076](https://github.com/nodejs/node/pull/65076) - \[[`dcf65c50ce`](https://github.com/nodejs/node/commit/dcf65c50ce)] - **tls**: fix authorized state on no-cert TLS1.3 client cert resumption (Tim Perry) [#&#8203;64677](https://github.com/nodejs/node/pull/64677) - \[[`b0f54bda78`](https://github.com/nodejs/node/commit/b0f54bda78)] - **tools**: improve commit queue failure comment (Filip Skokan) [#&#8203;65433](https://github.com/nodejs/node/pull/65433) - \[[`bc1f2718d5`](https://github.com/nodejs/node/commit/bc1f2718d5)] - **tools**: fix max body length handler in `create-release-proposal.sh` (Antoine du Hamel) [#&#8203;65455](https://github.com/nodejs/node/pull/65455) - \[[`bbe76516a9`](https://github.com/nodejs/node/commit/bbe76516a9)] - **tools**: bump brace-expansion in `/tools/clang-format` (dependabot\[bot]) [#&#8203;64984](https://github.com/nodejs/node/pull/64984) - \[[`67697debdf`](https://github.com/nodejs/node/commit/67697debdf)] - **tools**: make env variables consistent in cron jobs (Antoine du Hamel) [#&#8203;65168](https://github.com/nodejs/node/pull/65168) - \[[`ac8a68ec92`](https://github.com/nodejs/node/commit/ac8a68ec92)] - **tools**: only include fast-tracked and old enough PRs in CQ (Antoine du Hamel) [#&#8203;65197](https://github.com/nodejs/node/pull/65197) - \[[`6d9999fa2e`](https://github.com/nodejs/node/commit/6d9999fa2e)] - **tools**: remove skip logic in `commit-queue.sh` (Antoine du Hamel) [#&#8203;65162](https://github.com/nodejs/node/pull/65162) - \[[`60bfa1694e`](https://github.com/nodejs/node/commit/60bfa1694e)] - **tools**: bump js-yaml from 4.2.0 to 4.3.1 in /tools/lint-md (dependabot\[bot]) [#&#8203;65129](https://github.com/nodejs/node/pull/65129) - \[[`782748527e`](https://github.com/nodejs/node/commit/782748527e)] - **tools**: bump js-yaml from 4.2.0 to 4.3.1 in /tools/eslint (dependabot\[bot]) [#&#8203;65130](https://github.com/nodejs/node/pull/65130) - \[[`dac257340f`](https://github.com/nodejs/node/commit/dac257340f)] - **tools**: fix GITHUB\_TOKEN permissions for CQ workflow (Antoine du Hamel) [#&#8203;65192](https://github.com/nodejs/node/pull/65192) - \[[`e624785846`](https://github.com/nodejs/node/commit/e624785846)] - **tools**: use the read-only token when filtering PRs in CQ (Antoine du Hamel) [#&#8203;65169](https://github.com/nodejs/node/pull/65169) - \[[`7d9dcfaaa7`](https://github.com/nodejs/node/commit/7d9dcfaaa7)] - **tools**: delay removal of `commit-queue` label (Antoine du Hamel) [#&#8203;65101](https://github.com/nodejs/node/pull/65101) - \[[`0d7c7936e7`](https://github.com/nodejs/node/commit/0d7c7936e7)] - **tools**: move ncu config to global for commit queue (Filip Skokan) [#&#8203;65132](https://github.com/nodejs/node/pull/65132) - \[[`5e1db5a38a`](https://github.com/nodejs/node/commit/5e1db5a38a)] - **tools**: prefilter commit queue metadata (Filip Skokan) [#&#8203;64343](https://github.com/nodejs/node/pull/64343) - \[[`f41509b91d`](https://github.com/nodejs/node/commit/f41509b91d)] - **tools**: lazy-abort failed PR merges in CQ (Antoine du Hamel) [#&#8203;65004](https://github.com/nodejs/node/pull/65004) - \[[`ceb0e99acd`](https://github.com/nodejs/node/commit/ceb0e99acd)] - **tools**: sync mk-ca-bundle.pl with curl (Archkon) [#&#8203;64753](https://github.com/nodejs/node/pull/64753) - \[[`600663b23f`](https://github.com/nodejs/node/commit/600663b23f)] - **tty**: add raw-vt and io raw modes (Samuel Williams) [#&#8203;64140](https://github.com/nodejs/node/pull/64140) - \[[`a40bfc742e`](https://github.com/nodejs/node/commit/a40bfc742e)] - **typings**: add signal\_wrap internal binding types (Seongeun Lee) [#&#8203;65229](https://github.com/nodejs/node/pull/65229) - \[[`b103a4a3b9`](https://github.com/nodejs/node/commit/b103a4a3b9)] - **typings**: add diagnostics\_channel typings (Seongeun Lee) [#&#8203;65227](https://github.com/nodejs/node/pull/65227) - \[[`e64de34b89`](https://github.com/nodejs/node/commit/e64de34b89)] - **typings**: add watchdog internal binding types (Seongeun Lee) [#&#8203;65228](https://github.com/nodejs/node/pull/65228) - \[[`c57c83b4d1`](https://github.com/nodejs/node/commit/c57c83b4d1)] - **typings**: add internal\_only\_v8 binding typeis (Donghoon Kang) [#&#8203;65071](https://github.com/nodejs/node/pull/65071) - \[[`f15e8c9dcd`](https://github.com/nodejs/node/commit/f15e8c9dcd)] - **typings**: add credentials internal binding types (Donghoon Kang) [#&#8203;65036](https://github.com/nodejs/node/pull/65036) - \[[`a500256b0b`](https://github.com/nodejs/node/commit/a500256b0b)] - **url**: skip unused href reuse comparison (Yagiz Nizipli) [#&#8203;65361](https://github.com/nodejs/node/pull/65361) - \[[`58390f8bec`](https://github.com/nodejs/node/commit/58390f8bec)] - **url**: speed up WHATWG URL parsing (Yagiz Nizipli) [#&#8203;65361](https://github.com/nodejs/node/pull/65361) - \[[`7d5428c812`](https://github.com/nodejs/node/commit/7d5428c812)] - **url**: speed up URLSearchParams (Yagiz Nizipli) [#&#8203;65363](https://github.com/nodejs/node/pull/65363) - \[[`8e2461d819`](https://github.com/nodejs/node/commit/8e2461d819)] - **url**: bounds-check short Windows file URL paths (Archkon) [#&#8203;64788](https://github.com/nodejs/node/pull/64788) - \[[`9ffc0da90c`](https://github.com/nodejs/node/commit/9ffc0da90c)] - **url**: handle unparsable serialized URLs in setters (Matteo Collina) [#&#8203;64651](https://github.com/nodejs/node/pull/64651) - \[[`fa9d4e075d`](https://github.com/nodejs/node/commit/fa9d4e075d)] - **util**: allow single-line format when break length is infinite (Hamid Reza Ghavami) [#&#8203;64238](https://github.com/nodejs/node/pull/64238) - \[[`b68a7c3862`](https://github.com/nodejs/node/commit/b68a7c3862)] - **util**: fix OSC 8 hyperlink stripping in stripVTControlCharacters (Dushyant Singh Hada) [#&#8203;64319](https://github.com/nodejs/node/pull/64319) - \[[`10cbb6dc00`](https://github.com/nodejs/node/commit/10cbb6dc00)] - **util**: fix formatting of functions returned from getters (Richard Gibson) [#&#8203;64839](https://github.com/nodejs/node/pull/64839) - \[[`64c20b449e`](https://github.com/nodejs/node/commit/64c20b449e)] - **util**: use more primordials in `comparisons.js` (Ayoub Mabrouk) [#&#8203;61198](https://github.com/nodejs/node/pull/61198) - \[[`cea9786de8`](https://github.com/nodejs/node/commit/cea9786de8)] - **util**: preserve function names without source map names (Hiroki Osame) [#&#8203;65108](https://github.com/nodejs/node/pull/65108) - \[[`35c635b032`](https://github.com/nodejs/node/commit/35c635b032)] - **(SEMVER-MINOR)** **util**: add non-throwing MIMEType.parse (James M Snell) [#&#8203;64965](https://github.com/nodejs/node/pull/64965) - \[[`5858c2ba9a`](https://github.com/nodejs/node/commit/5858c2ba9a)] - **zlib**: validate pledgedSrcSize for sync zstd (Archkon) [#&#8203;64601](https://github.com/nodejs/node/pull/64601) </details> <details> <summary>actions/node-versions (node)</summary> ### [`v24.21.0`](https://github.com/actions/node-versions/releases/tag/24.21.0-34304089047): 24.21.0 [Compare Source](https://github.com/actions/node-versions/compare/24.20.0-33034074684...24.21.0-34304089047) Node.js 24.21.0 </details> <details> <summary>pnpm/pnpm (npm:pnpm)</summary> ### [`v11.27.0`](https://github.com/pnpm/pnpm/releases/tag/v11.27.0): pnpm 11.27 [Compare Source](https://github.com/pnpm/pnpm/compare/v11.26.0...v11.27.0) ##### Minor Changes - `nodeDownloadMirrors` can now be set in the global config file (`config.yaml`) and through the `PNPM_CONFIG_NODE_DOWNLOAD_MIRRORS` environment variable, so a Node.js download mirror can be configured once for a machine instead of in every workspace [#&#8203;12124](https://github.com/pnpm/pnpm/issues/12124), [#&#8203;13611](https://github.com/pnpm/pnpm/issues/13611). ```sh PNPM_CONFIG_NODE_DOWNLOAD_MIRRORS='{"release":"https://npmmirror.com/mirrors/node/"}' ``` - Added a new setting `trustPolicyExcludePrune` (default: `false`). When enabled, `pnpm add`, `pnpm update`, and `pnpm remove` prune the entries of `trustPolicyExclude` in `pnpm-workspace.yaml` that the freshly written lockfile no longer resolves: versions that are gone are dropped (an entry is removed once none of its versions remain), and entries for packages that are no longer in the lockfile are removed too. Name patterns (`@scope/*`) are always kept. The cleanup is skipped when the install's lockfile does not cover the whole workspace (`sharedWorkspaceLockfile: false`), since entries another project still needs would look stale. ##### Patch Changes - pnpm now reads the `packageManager`, `devEngines.packageManager` and runtime pins from the workspace root's `package.json` when `lockfileDir` is set. A project that moved its lockfile lost the pins it declared there [#&#8203;14633](https://github.com/pnpm/pnpm/issues/14633). - Fixed `pnpm add -g`, `pnpm update -g`, and `pnpm remove -g` mutating global bins or install directories after only partially reading an installed package group. If any declared package manifest is missing, malformed, or unreadable, pnpm now fails before activation or removal and leaves the existing global installation intact [pnpm/pnpm#13796](https://github.com/pnpm/pnpm/issues/13796). - `fetch-timeout` now limits how long a request may make no progress. The timer restarts on every chunk that arrives. A large download over a slow connection is no longer aborted while data is still coming in. A connection that stops delivering data still fails after `fetch-timeout` [#&#8203;14604](https://github.com/pnpm/pnpm/issues/14604). - `pnpm peers check` no longer reports a peer dependency declared as `workspace:^`, `workspace:~`, or a bare `workspace:` as unmet. pnpm reported these as unmet whatever version the linked workspace project supplied [#&#8203;14770](https://github.com/pnpm/pnpm/issues/14770). - A `readPackage` hook that edits its argument in place no longer changes what a later install in the same command resolves. A `deprecated` notice read from the lockfile no longer carries over to another install either [#&#8203;13988](https://github.com/pnpm/pnpm/issues/13988). - `pnpm install` now auto-installs missing transitive peers when workspace projects share a dependency at different depths. This also removes incomplete duplicate peer contexts from the lockfile. Fixes [pnpm/pnpm#14840](https://github.com/pnpm/pnpm/issues/14840). - GitHub Actions updates now stop if an action reference changes while its versions are being resolved. Unrelated workflow edits are preserved. GitHub Actions homepage links no longer expose server credentials. GitHub server URLs now require HTTPS, with HTTP allowed only for loopback hosts. - `pnpm licenses list` now reports the runtime downloaded through `devEngines.runtime` with `onFail: "download"`. The command previously failed with `ERR_PNPM_UNSUPPORTED_PACKAGE_TYPE` [#&#8203;14172](https://github.com/pnpm/pnpm/issues/14172). - pnpm no longer creates a project `pnpm-lock.yaml` when `devEngines.packageManager.onFail` is `download` and lockfile writing is turned off with `lockfile: false` or `--no-lockfile`. pnpm still switches to the pinned version [#&#8203;14728](https://github.com/pnpm/pnpm/issues/14728). - A `registry` or `@scope:registry` set in an `.npmrc` now wins over the registry a `pnpm login` credential stored in the global `config.yaml` points at. Previously, after logging in to one registry, installs in a project whose `.npmrc` named a private registry went to the logged-in registry instead. They now go to the registry the `.npmrc` names [#&#8203;14614](https://github.com/pnpm/pnpm/issues/14614). - A patch that gives a dependency a `preinstall`, `install`, or `postinstall` script, or a `binding.gyp`, now runs that build. pnpm asks for build approval first, so the package is listed under "Ignored build scripts" until it is allowed to build. pnpm 12 ran nothing, and pnpm 11 ran it without asking [#&#8203;14648](https://github.com/pnpm/pnpm/issues/14648). - Registries that share a host but differ by URL path — one JFrog Artifactory, Nexus, AWS CodeArtifact or GitLab Packages instance serving several repositories — now get a metadata cache directory each. Previously they shared one, so resolving a package from one of them could answer with another's versions, integrity hashes and tarball URLs and fail with `ERR_PNPM_TARBALL_URL_MISMATCH` [#&#8203;13558](https://github.com/pnpm/pnpm/issues/13558). The URL scheme is part of the cache directory name too, so an `http` registry can no longer hand its metadata — which can be rewritten in transit — to a resolution configured for `https` at the same host. The first install after upgrading refetches registry metadata once. The package store is untouched. `pnpm cache view` now labels each entry with the full registry URL. It printed `registry.npmjs.org` before and prints `https://registry.npmjs.org/` now. `pnpm cache list-registries` and `pnpm cache list` print the new directory names. Scripts that parse either command need updating. - Updated the embedded Node.js release keys to the current canonical `nodejs/release-keys` list. - `pnpm sbom` now omits package author fields when the manifest author name is empty or contains only whitespace [pnpm/pnpm#14685](https://github.com/pnpm/pnpm/issues/14685). In a filtered or split workspace run, only a project with no `author` field inherits the workspace root's author. - `pnpm sbom --sbom-format spdx` now writes `creationInfo.created` with whole seconds, such as `2026-09-08T10:38:21Z`. The timestamp carried fractional seconds, which strict SPDX consumers rejected [#&#8203;14684](https://github.com/pnpm/pnpm/issues/14684). - Windows filesystem operations now retry permission errors for up to one second. Permanent permission errors previously delayed failure by a minute. Sharing and lock violations retain their one-minute retry budget [pnpm/pnpm#14682](https://github.com/pnpm/pnpm/issues/14682). - pnpm now writes `node_modules/.package-map.json` only when `nodeExperimentalPackageMap` is enabled. Nothing reads the file without that setting. An install that stops writing the map removes the one a previous install left. - pnpm now unpacks a downloaded runtime archive into a randomly named directory inside the store. It previously used a predictable path, where another user of a shared store could plant a symlink and redirect the write outside the store ([GHSA-vwc7-r8mq-g2x9](https://github.com/advisories/GHSA-vwc7-r8mq-g2x9)). <!-- sponsors --> ##### Platinum Sponsors <table> <tbody> <tr> <td align="center" valign="middle"> <a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a> </td> <td align="center" valign="middle"> <a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/openai_dark.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/openai_light.svg" /> <img src="https://pnpm.io/img/users/openai_dark.svg" width="160" alt="OpenAI" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://notion.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/notion.svg" width="80" alt="Notion"></a> </td> </tr> <tr> <td align="center" valign="middle"> <a href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/coderabbit.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/coderabbit_light.svg" /> <img src="https://pnpm.io/img/users/coderabbit.svg" width="220" alt="CodeRabbit" /> </picture> </a> </td> </tr> </tbody> </table> ##### Gold Sponsors <table> <tbody> <tr> <td align="center" valign="middle"> <a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/sanity.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/sanity_light.svg" /> <img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/discord.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/discord_light.svg" /> <img src="https://pnpm.io/img/users/discord.svg" width="220" alt="Discord" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a> </td> </tr> <tr> <td align="center" valign="middle"> <a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/serpapi_dark.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/serpapi_light.svg" /> <img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160" alt="SerpApi" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/stackblitz.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/stackblitz_light.svg" /> <img src="https://pnpm.io/img/users/stackblitz.svg" width="190" alt="Stackblitz" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/workleap.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/workleap_light.svg" /> <img src="https://pnpm.io/img/users/workleap.svg" width="190" alt="Workleap" /> </picture> </a> </td> </tr> <tr> <td align="center" valign="middle"> <a href="https://nx.dev/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/nx.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/nx_light.svg" /> <img src="https://pnpm.io/img/users/nx.svg" width="50" alt="Nx" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://latitude.so/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/latitude.svg" width="160" alt="Latitude"></a> </td> </tr> </tbody> </table> <!-- sponsors end --> ### [`v11.26.0`](https://github.com/pnpm/pnpm/releases/tag/v11.26.0): pnpm 11.26 [Compare Source](https://github.com/pnpm/pnpm/compare/v11.25.0...v11.26.0) ##### Minor Changes - Catalogs can now resolve workspace dependencies through the `workspace:` protocol. - `pnpm remove` and `pnpm update` now accept `--trust-lockfile`, `--no-trust-lockfile`, `--trust-policy`, `--trust-policy-exclude`, and `--trust-policy-ignore-after`. `pnpm remove` checks the whole lockfile against the active policies unless `--trust-lockfile` is set. - Added `pnpm change check` for CI validation of package versions against the `versioning.epics` bands and `versioning.fixed` groups in `pnpm-workspace.yaml`. ##### Patch Changes - Fetch and tarball errors and retry logs now hide URL credentials, query strings, and fragments that could expose secrets. - Fixed a race during config dependency updates that could redirect a lockfile write through a symlink [#&#8203;14322](https://github.com/pnpm/pnpm/issues/14322). - `pnpm add --allow-build=!<pkg>` now correctly denies builds, including in global installs. `pnpm approve-builds <pkg>` and `pnpm approve-builds !<pkg>` now save decisions even when the package is not awaiting approval, with a warning [#&#8203;14067](https://github.com/pnpm/pnpm/issues/14067). - Fixed `pnpm audit --fix` failing without a value or when followed by another flag. `pnpm audit --fix=override` now respects `saveExact` and `savePrefix` when writing overrides [#&#8203;13261](https://github.com/pnpm/pnpm/issues/13261), [#&#8203;11523](https://github.com/pnpm/pnpm/issues/11523). - `pnpm audit` now excludes ignored advisories from vulnerability totals and severity counts, and reports them separately [#&#8203;14535](https://github.com/pnpm/pnpm/issues/14535). - `pnpm deploy` no longer requires `injectWorkspacePackages`. If a workspace dependency's peer has multiple possible versions, deployment reports `ERR_PNPM_DEPLOY_AMBIGUOUS_PEER` with the conflicting versions. Pin the peer with `overrides` to deploy without injection [#&#8203;9386](https://github.com/pnpm/pnpm/issues/9386). - Fixed concurrent installs sharing a store occasionally failing with an `ENOENT` error while importing a package file [#&#8203;14353](https://github.com/pnpm/pnpm/issues/14353). - Fixed installation failures when a linked local dependency provides a peer dependency also provided by an ancestor, including with `pnpm deploy --legacy`. - `pnpm install --node-linker=hoisted` no longer downloads skipped optional dependencies when `node_modules` already exists [#&#8203;14139](https://github.com/pnpm/pnpm/issues/14139). - Fixed `pnpm install` rejecting a symlinked lockfile when config dependencies are unchanged. Updates to config dependencies also preserve lockfiles with a byte order mark. Writes through symlinked lockfiles remain blocked [#&#8203;14372](https://github.com/pnpm/pnpm/issues/14372). - `pnpm install` now relinks workspace packages when `publishConfig.linkDirectory` changes. Frozen installs require the lockfile to be regenerated [#&#8203;14488](https://github.com/pnpm/pnpm/issues/14488). - Auto-installed optional peers now satisfy their declared range even when the workspace root uses a version outside that range [#&#8203;13867](https://github.com/pnpm/pnpm/issues/13867). - Fixed global virtual store paths for dependency cycles to consistently account for the runtime engine when dependencies have allowed builds [#&#8203;14341](https://github.com/pnpm/pnpm/issues/14341). - Standalone installations now preserve the bundled `node-gyp` files needed to build native dependencies. - Downloaded runtimes are now available to dependency lifecycle scripts during installation. - Node.js downloads from `nodeDownloadMirrors` now use URL-scoped npm credentials, including bearer tokens, basic auth, and `tokenHelper` [#&#8203;14334](https://github.com/pnpm/pnpm/issues/14334). - Fixed `globalDir` and `globalBinDir` handling in global configuration and environment variables, including `~/` expansion. This fixes `pnpm add -g` failing after `pnpm config set -g global-bin-dir` [#&#8203;14336](https://github.com/pnpm/pnpm/issues/14336). - The JavaScript pnpm can again switch to the project's pinned pnpm version on hosts without a matching native binary. If the requested version requires an unavailable native binary, the error now identifies the unsupported host [#&#8203;13622](https://github.com/pnpm/pnpm/issues/13622). - Global `pnpm config` commands now skip project package manager version switching, allowing authentication to be configured before downloading the pinned version [#&#8203;14463](https://github.com/pnpm/pnpm/issues/14463). - `pnpm self-update`, `pnpm with`, and automatic version switching no longer wait through registry retries when a configured registry has no signatures and `registry.npmjs.org` is unavailable [#&#8203;14483](https://github.com/pnpm/pnpm/issues/14483). - Fixed argument forwarding on Windows with `shellEmulator` enabled. Trailing backslashes, line breaks, and literal shell expressions are preserved [#&#8203;14548](https://github.com/pnpm/pnpm/issues/14548). - Relative `scriptShell` paths now resolve from the workspace root. Bare command names such as `bash` still use `PATH` [#&#8203;14422](https://github.com/pnpm/pnpm/issues/14422). - `pnpm import` now preserves the project-local lockfile when `lockfileDir` points elsewhere and restores the destination lockfile on failure. Branch lockfile imports leave the shared lockfile unchanged [#&#8203;14563](https://github.com/pnpm/pnpm/issues/14563). - `catalogMode` and `--save-catalog` no longer move local paths, tarballs, or `workspace:<path>` specifiers into catalogs [#&#8203;14437](https://github.com/pnpm/pnpm/issues/14437). - `--side-effects-cache`, `--no-side-effects-cache`, and `PNPM_CONFIG_SIDE_EFFECTS_CACHE` now toggle only the local cache, preserving any remote cache configured in `sideEffectsCache`. - `pnpm unpublish` now handles registry two-factor authentication challenges through web authentication or a one-time password prompt [#&#8203;14464](https://github.com/pnpm/pnpm/issues/14464). - `pnpm outdated` and `pnpm update` now follow GitHub Actions references using self-repository syntax, such as `uses: $/.github/actions/setup`. - `pnpm remove` now accepts `--unsafe-perm`. <!-- sponsors --> ##### Platinum Sponsors <table> <tbody> <tr> <td align="center" valign="middle"> <a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a> </td> <td align="center" valign="middle"> <a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/openai_dark.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/openai_light.svg" /> <img src="https://pnpm.io/img/users/openai_dark.svg" width="160" alt="OpenAI" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://notion.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/notion.svg" width="80" alt="Notion"></a> </td> </tr> <tr> <td align="center" valign="middle"> <a href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/coderabbit.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/coderabbit_light.svg" /> <img src="https://pnpm.io/img/users/coderabbit.svg" width="220" alt="CodeRabbit" /> </picture> </a> </td> </tr> </tbody> </table> ##### Gold Sponsors <table> <tbody> <tr> <td align="center" valign="middle"> <a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/sanity.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/sanity_light.svg" /> <img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/discord.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/discord_light.svg" /> <img src="https://pnpm.io/img/users/discord.svg" width="220" alt="Discord" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a> </td> </tr> <tr> <td align="center" valign="middle"> <a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/serpapi_dark.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/serpapi_light.svg" /> <img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160" alt="SerpApi" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/stackblitz.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/stackblitz_light.svg" /> <img src="https://pnpm.io/img/users/stackblitz.svg" width="190" alt="Stackblitz" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/workleap.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/workleap_light.svg" /> <img src="https://pnpm.io/img/users/workleap.svg" width="190" alt="Workleap" /> </picture> </a> </td> </tr> <tr> <td align="center" valign="middle"> <a href="https://nx.dev/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/nx.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/nx_light.svg" /> <img src="https://pnpm.io/img/users/nx.svg" width="50" alt="Nx" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://latitude.so/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/latitude.svg" width="160" alt="Latitude"></a> </td> </tr> </tbody> </table> <!-- sponsors end --> </details> <details> <summary>typescript-eslint/typescript-eslint (typescript-eslint)</summary> ### [`v8.70.0`](https://github.com/typescript-eslint/typescript-eslint/blob/HEAD/packages/typescript-eslint/CHANGELOG.md#8700-2026-09-07) [Compare Source](https://github.com/typescript-eslint/typescript-eslint/compare/v8.69.0...v8.70.0) ##### 🩹 Fixes - **eslint-plugin:** \[no-deprecated] report deprecated imported values used in object shorthand properties ([#&#8203;12780](https://github.com/typescript-eslint/typescript-eslint/pull/12780)) ##### ❤️ Thank You - Ulrich Stark [@&#8203;ulrichstark](https://github.com/ulrichstark) See [GitHub Releases](https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.0) for more information. You can read about our [versioning strategy](https://typescript-eslint.io/users/versioning) and [releases](https://typescript-eslint.io/users/releases) on our website. </details> <details> <summary>vitejs/vite (vite)</summary> ### [`v8.3.0`](https://github.com/vitejs/vite/blob/HEAD/packages/vite/CHANGELOG.md#830-2026-09-10) [Compare Source](https://github.com/vitejs/vite/compare/v8.2.2...v8.3.0) ##### Features - **build:** avoid settling seen preload dependencies for performance ([#&#8203;23446](https://github.com/vitejs/vite/issues/23446)) ([e6f6b3e](https://github.com/vitejs/vite/commit/e6f6b3e3119256daa837b2dc399058c8aa45b470)) - **devtools:** enable dev server integration ([#&#8203;23333](https://github.com/vitejs/vite/issues/23333)) ([68aeb8a](https://github.com/vitejs/vite/commit/68aeb8a3b5a5a2ccd505288999bae1a5e6942ee1)) - accept Rolldown watch options in `server.watch` ([#&#8203;23133](https://github.com/vitejs/vite/issues/23133)) ([1b5cfe3](https://github.com/vitejs/vite/commit/1b5cfe3d3777d4ceb7f35fcee9d3c4279316a084)) - add closeServer and closePreviewServer hooks ([#&#8203;23110](https://github.com/vitejs/vite/issues/23110)) ([e17d2d5](https://github.com/vitejs/vite/commit/e17d2d565b0288f169c7995adb2b192f917548e7)) - add top-level `tsconfig` option ([#&#8203;23310](https://github.com/vitejs/vite/issues/23310)) ([93164c3](https://github.com/vitejs/vite/commit/93164c3530a7b4fc7bbedfb986d6afa9546cdef3)) - add warning for unsupported hooks in plugin returned from `applyToEnvironment` hook ([#&#8203;23191](https://github.com/vitejs/vite/issues/23191)) ([fdef04f](https://github.com/vitejs/vite/commit/fdef04f112aadfea40ad3c448d96a49a04c168bd)) - **cli:** support naming the CPU profile via --profile \[name] ([#&#8203;23042](https://github.com/vitejs/vite/issues/23042)) ([a500dee](https://github.com/vitejs/vite/commit/a500deeb6f52d93ca501a0fc612a5392b939f2f5)) - **config:** warn on named imports from JSON modules ([#&#8203;23378](https://github.com/vitejs/vite/issues/23378)) ([472385e](https://github.com/vitejs/vite/commit/472385e6ec4b21e3167c7abf9769883d1c9675f8)) - **css:** minify style tag ([#&#8203;23183](https://github.com/vitejs/vite/issues/23183)) ([8156684](https://github.com/vitejs/vite/commit/8156684572bdcf73e9d8568ed67971f0467fab60)) - searched params attached to workers are now preserved ([#&#8203;22280](https://github.com/vitejs/vite/issues/22280)) ([517b97f](https://github.com/vitejs/vite/commit/517b97f57ab9473e7417da856eb641d76870a56e)) - support subpath imports in dynamic import statements ([#&#8203;23185](https://github.com/vitejs/vite/issues/23185)) ([b78e2f1](https://github.com/vitejs/vite/commit/b78e2f1bc1cba404c4bd9faf518d26ec85e89fc7)) - use `import.meta.ROLLDOWN_FILE_URL_*` for assets in JS ([#&#8203;22888](https://github.com/vitejs/vite/issues/22888)) ([4366ac4](https://github.com/vitejs/vite/commit/4366ac468343252df6d5706361a6348afa66f9cc)) - use `import.meta.ROLLDOWN_FILE_URL_*` for other plugins ([#&#8203;22894](https://github.com/vitejs/vite/issues/22894)) ([e38f29e](https://github.com/vitejs/vite/commit/e38f29ee48bea5ea3178faec5b78708e86f38afb)) - **worker:** remove worker chunk if it's detected that it's not referenced ([#&#8203;22473](https://github.com/vitejs/vite/issues/22473)) ([924997a](https://github.com/vitejs/vite/commit/924997a4bdda9115faee9bdb622fcec4fc8357f0)) ##### Bug Fixes - handle CRLF line endings in code frame positions ([#&#8203;23219](https://github.com/vitejs/vite/issues/23219)) ([9913672](https://github.com/vitejs/vite/commit/9913672bee9c34a2df7fff4c2538783cd4f43b4e)) - only treat whole `node_modules` path segments as dependencies (fix [#&#8203;17467](https://github.com/vitejs/vite/issues/17467)) ([#&#8203;23437](https://github.com/vitejs/vite/issues/23437)) ([ef0dc17](https://github.com/vitejs/vite/commit/ef0dc17ada53d1169ae5a89cb8f6482831466755)) - **build:** keep hash placeholders as-is in `resolveFileUrl` hook ([#&#8203;23422](https://github.com/vitejs/vite/issues/23422)) ([e8d6a4d](https://github.com/vitejs/vite/commit/e8d6a4d3399c739772080d70c7f3c4d548a637c9)) - **bundled-dev:** mark payload delivered on client report ([#&#8203;23373](https://github.com/vitejs/vite/issues/23373)) ([a6d43bc](https://github.com/vitejs/vite/commit/a6d43bc9e3464faa4d49f090e75e1ab334ffb7b0)) - **deps:** update all non-major dependencies ([#&#8203;23445](https://github.com/vitejs/vite/issues/23445)) ([fc7c104](https://github.com/vitejs/vite/commit/fc7c104e74d35a97fa313d5dd6f1b5e7d5b26159)) - **html:** don't inline preload link targets (fix [#&#8203;13355](https://github.com/vitejs/vite/issues/13355)) ([#&#8203;23387](https://github.com/vitejs/vite/issues/23387)) ([12e709c](https://github.com/vitejs/vite/commit/12e709ca4df1059747db1cb7c5d1cd71aba79a24)) - resolve the actual package root in findNearestMainPackageData for nested package.json ([#&#8203;23356](https://github.com/vitejs/vite/issues/23356)) ([8492422](https://github.com/vitejs/vite/commit/8492422b8f110625a90c702f42f30784e8cf19dc)) - shortcuts extend error ([#&#8203;23447](https://github.com/vitejs/vite/issues/23447)) ([4ec58d1](https://github.com/vitejs/vite/commit/4ec58d159df4a1b4799356a1fda62db88ed14752)) - **config:** close bundles when generation fails ([#&#8203;23256](https://github.com/vitejs/vite/issues/23256)) ([6bacc95](https://github.com/vitejs/vite/commit/6bacc956df5a76cc5653b9de4493453b953439fd)) - **css:** keep newline-separated srcset candidates intact ([#&#8203;23265](https://github.com/vitejs/vite/issues/23265)) ([4f9d2f4](https://github.com/vitejs/vite/commit/4f9d2f4dadc83191200de7d2154c957a711e8c3d)) - **deps:** update all non-major dependencies ([#&#8203;23337](https://github.com/vitejs/vite/issues/23337)) ([d550815](https://github.com/vitejs/vite/commit/d55081581ddd4d55667fef38e85d02ab7f879f15)) - **deps:** update all non-major dependencies ([#&#8203;23404](https://github.com/vitejs/vite/issues/23404)) ([238ad81](https://github.com/vitejs/vite/commit/238ad811c7fb9e4730cbd317d0657867ed3447b3)) - **deps:** update rolldown-related dependencies ([#&#8203;23338](https://github.com/vitejs/vite/issues/23338)) ([76e8082](https://github.com/vitejs/vite/commit/76e8082c56a2872dc8017c5672bc36cba8dcf75d)) - **deps:** update rolldown-related dependencies ([#&#8203;23405](https://github.com/vitejs/vite/issues/23405)) ([b882566](https://github.com/vitejs/vite/commit/b88256607e3a051b7bcb0b338b3c4665926b55a8)) - **dev:** run closeBundle after buildEnd failure ([#&#8203;23165](https://github.com/vitejs/vite/issues/23165)) ([8cb872e](https://github.com/vitejs/vite/commit/8cb872e7fb65b03f6068923c6aa7fcf3e71baf21)) - **hmr:** handle `import.meta.hot.invalidate` in virtual module ([#&#8203;23171](https://github.com/vitejs/vite/issues/23171)) ([6162968](https://github.com/vitejs/vite/commit/616296895bd135386d35069a479a5f188c7de298)) - **utils:** handle dot in srcset density descriptor ([#&#8203;23346](https://github.com/vitejs/vite/issues/23346)) ([b50e1b4](https://github.com/vitejs/vite/commit/b50e1b4a3d66128a4076e19769b2e29657985516)) - **utils:** match timestamp query parameter with proper delimiters ([#&#8203;23364](https://github.com/vitejs/vite/issues/23364)) ([41f3c6f](https://github.com/vitejs/vite/commit/41f3c6fff88ade015669cac5c42db946e0b6f5c9)) ##### Performance Improvements - **proxy:** pre-compile context matchers at server creation ([#&#8203;23263](https://github.com/vitejs/vite/issues/23263)) ([8abf700](https://github.com/vitejs/vite/commit/8abf700eeb2411d8402d08f8e2696effafdbe774)) ##### Miscellaneous Chores - introducing `@e18e/eslint-plugin` ([#&#8203;23357](https://github.com/vitejs/vite/issues/23357)) ([f794133](https://github.com/vitejs/vite/commit/f79413353995a2344879014410a9128b1b9f8e9a)) - remove unnecessary comment ([#&#8203;23448](https://github.com/vitejs/vite/issues/23448)) ([b919a1a](https://github.com/vitejs/vite/commit/b919a1a8b5a7c694667f993d677973f42d349458)) - delete unused `PluginContainerOptions` ([#&#8203;23382](https://github.com/vitejs/vite/issues/23382)) ([ee64401](https://github.com/vitejs/vite/commit/ee644014aab61e546742b862a7d7b0d6c7d67a7b)) - use oxfmt `sortImports` ([#&#8203;23319](https://github.com/vitejs/vite/issues/23319)) ([97ad042](https://github.com/vitejs/vite/commit/97ad042170f4c71b518239723b733dd98e8e3e76)) ##### Code Refactoring - delete unused `esbuildPlugin` ([#&#8203;23381](https://github.com/vitejs/vite/issues/23381)) ([f40efef](https://github.com/vitejs/vite/commit/f40efefbb3630cdb7235286bc2b51673d9fbfc27)) - exclude postfix from `__VITE_ASSET__` ([#&#8203;22886](https://github.com/vitejs/vite/issues/22886)) ([a6c08e1](https://github.com/vitejs/vite/commit/a6c08e10a624bd89b78683ff1b0e8cfa1d89aa45)) - remove HmrUrl concept ([#&#8203;23172](https://github.com/vitejs/vite/issues/23172)) ([67a6807](https://github.com/vitejs/vite/commit/67a680767317f8e2cb28b6b0500192f993a567cf)) - use `urlId` of `import.meta.ROLLDOWN_FILE_URL` in wasm plugin ([#&#8203;22962](https://github.com/vitejs/vite/issues/22962)) ([92bd2a7](https://github.com/vitejs/vite/commit/92bd2a7f325ed102349cdc6c1ad4b5cd25e1d72f)) ##### Tests - add `renderBuiltUrl` change changes hash ([#&#8203;23118](https://github.com/vitejs/vite/issues/23118)) ([0291408](https://github.com/vitejs/vite/commit/0291408b8443129ce6f6d1d440be8facabe9683b)) ##### Beta Changelogs ##### [8.3.0-beta.1](https://github.com/vitejs/vite/compare/v8.3.0-beta.0...v8.3.0-beta.1) (2026-09-07) See [8.3.0-beta.1 changelog](https://github.com/vitejs/vite/blob/v8.3.0-beta.1/packages/vite/CHANGELOG.md) ##### [8.3.0-beta.0](https://github.com/vitejs/vite/compare/v8.2.2...v8.3.0-beta.0) (2026-09-02) See [8.3.0-beta.0 changelog](https://github.com/vitejs/vite/blob/v8.3.0-beta.0/packages/vite/CHANGELOG.md) </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Berlin) - Branch creation - "after 11pm every weekday,before 5am every weekday,every weekend" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](undefined) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMzQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjIzNC4wIiwidGFyZ2V0QnJhbmNoIjoiZGV2IiwibGFiZWxzIjpbXX0=-->
Update Non-major updates
Some checks failed
renovate/stability-days Updates have met minimum release age requirement
CI / test (pull_request) Failing after 5s
CI / build (pull_request) Has been skipped
CI / deploy-dev (pull_request) Has been skipped
CI / deploy-prod (pull_request) Has been skipped
61386e42c7
renovate-bot scheduled this pull request to auto merge when all checks succeed 2026-09-13 03:02:04 +02:00
renovate-bot force-pushed renovate/non-major-updates from 61386e42c7
Some checks failed
renovate/stability-days Updates have met minimum release age requirement
CI / test (pull_request) Failing after 5s
CI / build (pull_request) Has been skipped
CI / deploy-dev (pull_request) Has been skipped
CI / deploy-prod (pull_request) Has been skipped
to 19076ded70
Some checks failed
CI / test (pull_request) Failing after 4s
CI / build (pull_request) Has been skipped
CI / deploy-dev (pull_request) Has been skipped
CI / deploy-prod (pull_request) Has been skipped
renovate/stability-days Updates have met minimum release age requirement
2026-09-21 17:42:14 +02:00
Compare
renovate-bot deleted branch renovate/non-major-updates 2026-09-21 17:42:19 +02:00
Sign in to join this conversation.
No reviewers
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
IC3P3/hcss-website!76
No description provided.