-
Notifications
You must be signed in to change notification settings - Fork 33
chore(deps): update all minor dependencies (minor) #277
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate
wants to merge
1
commit into
main
Choose a base branch
from
renovate/all-minor-dependencies
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
The latest updates on your projects. Learn more about Vercel for GitHub.
💡 Enable Vercel Agent with $100 free credit for automated AI reviews |
6f5d07d
to
05cc14e
Compare
05cc14e
to
5804272
Compare
5804272
to
74e2a2f
Compare
74e2a2f
to
47f3759
Compare
47f3759
to
5bbac29
Compare
5bbac29
to
70215a5
Compare
70215a5
to
6fdc53a
Compare
6fdc53a
to
9017d83
Compare
9017d83
to
901c4cd
Compare
901c4cd
to
741aa88
Compare
741aa88
to
b6691b7
Compare
b6691b7
to
7fc1d88
Compare
7fc1d88
to
b1af6a2
Compare
2f86f81
to
097d852
Compare
097d852
to
1d5c0d1
Compare
1d5c0d1
to
3da15f3
Compare
3da15f3
to
7cdadbe
Compare
7cdadbe
to
3fbfd1d
Compare
3fbfd1d
to
2481cb9
Compare
2481cb9
to
56a857c
Compare
56a857c
to
b67149a
Compare
b67149a
to
91f9f4d
Compare
91f9f4d
to
d4960b5
Compare
d4960b5
to
5fa93de
Compare
5fa93de
to
02bd7ae
Compare
02bd7ae
to
f1f62d6
Compare
f1f62d6
to
071b6e3
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^22.8.2
->^22.18.12
20.18.0
->20.19.5
9.12.3
->9.15.9
^8.4.47
->^8.5.6
^5.6.3
->^5.9.3
^3.23.8
->^3.25.76
Release Notes
nodejs/node (node)
v20.19.5
: 2025-09-03, Version 20.19.5 'Iron' (LTS), @marco-ippolitoCompare Source
Notable Changes
f5b293ad48
] - doc: add JonasBa to collaborators (Jonas Badalic) #583554e6ae787c6
] - doc: add puskin to collaborators (Giovanni Bucci) #58308d06db658fc
] - doc: add Filip Skokan to TSC (Rafael Gonzaga) #584993c6206cac9
] - doc: add @geeksilva97 to collaborators (Edy Silva) #57241Commits
ea20403467
] - build: fix uvwasi pkgname (Antoine du Hamel) #58270c647aa4b30
] - build: fix pointer compression builds (Joyee Cheung) #58171d2c5e609ae
] - build: disable v8_enable_pointer_compression_shared_cage on non-64bit (Shelley Vohr) #5886784d5c4d244
] - build: search for libnode.so in multiple places (Jan Staněk) #58213068c439552
] - crypto: fix SHAKE128/256 breaking change introduced with OpenSSL 3.4 (Filip Skokan) #58942edff105c34
] - debugger: fix behavior of plain object exec in debugger repl (Dario Piotrowicz) #574980473e35b7f
] - deps: update zlib to 1.3.1-470d3a2 (Node.js GitHub Bot) #586281218dbbea5
] - deps: update zlib to 1.3.0.1-motley-780819f (Node.js GitHub Bot) #577680e3cd9ec00
] - deps: update zlib to 1.3.0.1-motley-788cb3c (Node.js GitHub Bot) #56655a194dd9bd4
] - deps: update archs files for openssl-3.0.16 (Node.js GitHub Bot) #57335cc9b79ca70
] - deps: upgrade openssl sources to quictls/openssl-3.0.16 (Node.js GitHub Bot) #5733582c46d5358
] - deps: update cjs-module-lexer to 2.1.0 (Node.js GitHub Bot) #5718043e3f9b26b
] - deps: update cjs-module-lexer to 2.0.0 (Michael Dawson) #5685591282ff16b
] - deps: update corepack to 0.33.0 (Node.js GitHub Bot) #58566b76bca6f38
] - deps: update acorn to 8.15.0 (Node.js GitHub Bot) #58711ae11481011
] - deps: update acorn to 8.14.1 (Node.js GitHub Bot) #57382142d701201
] - deps: update minimatch to 10.0.3 (Node.js GitHub Bot) #58712fee082d684
] - deps: update llhttp to 9.3.0 (Fedor Indutny) #58144c06f6f3f05
] - dns: remove redundant code using common variable (Deokjin Kim) #57386cded8e7e77
] - dns: fix parse memory leaky (theanarkh) #58973182ae67233
] - dns: fix dns query cache implementation (Ethan Arrowood) #58404621b66a297
] - doc: add review guidelines for collaborator nominations (Antoine du Hamel) #57449b1009b5b72
] - doc: explicit mention arbitrary code execution as a vuln (Rafael Gonzaga) #57426f5b293ad48
] - doc: add JonasBa to collaborators (Jonas Badalic) #583554e6ae787c6
] - doc: add puskin to collaborators (Giovanni Bucci) #58308530473f479
] - doc: add ovflowd back to core collaborators (Claudio W.) #5891138e8bbc131
] - doc: add info on how project manages social media (Michael Dawson) #57318d06bb4dcc2
] - doc: ping nodejs/tsc for each security pull request (Rafael Gonzaga) #57309d06db658fc
] - doc: add Filip Skokan to TSC (Rafael Gonzaga) #584998c3bc156ed
] - doc: clarifypath.isAbsolute
is not path traversal mitigation (Eric Fortis) #57073e688410bda
] - doc: fix rendering of DEP0174 description (David Sanders) #56835e6a0c6a0fa
] - doc: add missing assert return types (Colin Ihrig) #57219026b3cab6a
] - doc: add 1ilsang to triage team (1ilsang) #571833c6206cac9
] - doc: add @geeksilva97 to collaborators (Edy Silva) #57241ef3a4675c7
] - doc: fix web.libera.chat link in pull-requests.md (Samuel Bronson) #570761db42b76f7
] - doc: remove buffered flag from performance hooks examples (Pavel Romanov) #52607b73a1356ce
] - doc: addmodule namespace object
links (Dario Piotrowicz) #5709309368db20f
] - doc: disambiguate pseudo-code statement (Dario Piotrowicz) #570922c3dc569a1
] - doc: fix wrong articles used to address modules (Dario Piotrowicz) #57090cd8259cb4e
] - doc:modules.md
: fixdistance
definition (Alexander “weej” Jones) #570467b0ea9ab2d
] - doc: fix wrong verb form (Dario Piotrowicz) #5709114fcfc242b
] - doc: add a note aboutrequire('../common')
in testing documentation (Aditi) #56953bc7d18b6ea
] - doc: recommend writing tests in new files and including comments (Joyee Cheung) #57028acd4d7f269
] - doc: improve documentation on argument validation (Aditi) #569544cd6b3ca73
] - doc: buffer: fix typo onBuffer.copyBytesFrom(
offset
option (tpoisseau) #5701501220607f2
] - doc: update cleanup to trust on vuln db automation (Rafael Gonzaga) #5700477a0505a32
] - doc: update post sec release process (Rafael Gonzaga) #5690777dbcfce5f
] - doc: add section about using npx with permission model (Rafael Gonzaga) #5653973e51407b7
] - doc: remove RedYetiDev from triagers team (Aviv Keller) #559479a36cbb792
] - doc: fix relative path mention in --allow-fs (Rafael Gonzaga) #5579104d9c5baeb
] - doc: add scroll margin to links (Roman Reiss) #58982959a67f6ff
] - doc: make Stability labels not sticky in Stability index (Livia Medeiros) #582918757a5532f
] - doc: update release key for aduh95 (Antoine du Hamel) #588776fa0626327
] - doc,src,test: fix typos (Noritaka Kobayashi) #584779991788e4a
] - http: coerce content-length to number (Marco Ippolito) #57458ff5cf8a428
] - http2: fix check forframe->hd.type
(hanguanqiang) #576442f333b6c51
] - lib: optimizeprepareStackTrace
on builtin frames (Chengzhong Wu) #56299cdf985071f
] - lib: suppress source map lookup exceptions (Chengzhong Wu) #56299faa08b14ed
] - lib: fixup incorrect argument order in assertEncoding (James M Snell) #57177a683cd1232
] - meta: add IlyasShabi to collaborators (Ilyas Shabi) #58916b145bb28aa
] - meta: bump codecov/codecov-action from 5.4.2 to 5.4.3 (dependabot[bot]) #585512c59789001
] - meta: bump ossf/scorecard-action from 2.4.1 to 2.4.2 (dependabot[bot]) #585504095337e96
] - meta: bump rtCamp/action-slack-notify from 2.3.2 to 2.3.3 (dependabot[bot]) #58108631fed8e39
] - meta: move one or more collaborators to emeritus (Node.js GitHub Bot) #584567d2f7180b6
] - meta: bump codecov/codecov-action from 5.4.0 to 5.4.2 (dependabot[bot]) #581101558551ea5
] - meta: bump actions/download-artifact from 4.2.1 to 4.3.0 (dependabot[bot]) #58106e1f12fe737
] - meta: ignore mailmap changes in linux ci (Jonas Badalic) #583561b78eb1313
] - meta: bump actions/setup-node from 4.3.0 to 4.4.0 (dependabot[bot]) #581112b8449c39a
] - meta: bump actions/setup-python from 5.5.0 to 5.6.0 (dependabot[bot]) #58107833b70bbc5
] - meta: allow penetration testing on live system with prior authorization (Matteo Collina) #57966c6a88561f5
] - meta: bump actions/setup-python from 5.4.0 to 5.5.0 (dependabot[bot]) #577189046ef4fb3
] - meta: bump peter-evans/create-pull-request from 7.0.7 to 7.0.8 (dependabot[bot]) #5771746388a4e2a
] - meta: bump actions/cache from 4.2.2 to 4.2.3 (dependabot[bot]) #57715d3970685bd
] - meta: bump actions/setup-node from 4.2.0 to 4.3.0 (dependabot[bot]) #5771447004ef37f
] - meta: bump actions/upload-artifact from 4.6.1 to 4.6.2 (dependabot[bot]) #577134abe83ec03
] - meta: add some clarification to the nomination process (James M Snell) #5750345e9b88363
] - meta: remove collaborator self-nomination (Rich Trott) #57537d10949b7d8
] - meta: edit collaborator nomination process (Antoine du Hamel) #57483704562fb7a
] - meta: move ovflowd to emeritus (Claudio W.) #574433f981b8537
] - meta: bump codecov/codecov-action from 5.3.1 to 5.4.0 (dependabot[bot]) #572577e1ff7b332
] - meta: bump ossf/scorecard-action from 2.4.0 to 2.4.1 (dependabot[bot]) #572538d4ec412b9
] - meta: move RaisinTen back to collaborators, triagers and SEA champion (Darshan Sen) #57292cc2abb5d17
] - meta: bump peter-evans/create-pull-request from 7.0.6 to 7.0.7 (dependabot[bot]) #572594fad2b8758
] - meta: bump actions/cache from 4.2.0 to 4.2.2 (dependabot[bot]) #572565f5bb8b986
] - meta: bump actions/upload-artifact from 4.6.0 to 4.6.1 (dependabot[bot]) #57255e949359a56
] - meta: bumpactions/setup-python
from 5.3.0 to 5.4.0 (dependabot[bot]) #56867d3c5ad7510
] - meta: bumppeter-evans/create-pull-request
from 7.0.5 to 7.0.6 (dependabot[bot]) #5686656decfe2d1
] - meta: bumpcodecov/codecov-action
from 5.0.7 to 5.3.1 (dependabot[bot]) #5686452e518444d
] - meta: bumpactions/cache
from 4.1.2 to 4.2.0 (dependabot[bot]) #568629cac93d9c3
] - meta: bumpactions/stale
from 9.0.0 to 9.1.0 (dependabot[bot]) #56860ecf4252f7c
] - meta: update last name for jkrems (Jan Martin) #57006e8beaaaedf
] - meta: bumpactions/upload-artifact
from 4.4.3 to 4.6.0 (dependabot[bot]) #568615462c257f8
] - meta: bumpactions/setup-node
from 4.1.0 to 4.2.0 (dependabot[bot]) #5686889c37891a0
] - meta: move one or more collaborators to emeritus (Node.js GitHub Bot) #568892a0175c291
] - meta: add @nodejs/url as codeowner (Chengzhong Wu) #56783c12aae1e78
] - meta: bump github/codeql-action from 3.28.18 to 3.29.2 (dependabot[bot]) #589224ef09990f1
] - meta: bump github/codeql-action from 3.28.16 to 3.28.18 (dependabot[bot]) #58552889654eb2c
] - meta: bump github/codeql-action from 3.28.11 to 3.28.16 (dependabot[bot]) #58112091e5c1bb9
] - meta: bump github/codeql-action from 3.28.10 to 3.28.13 (dependabot[bot]) #5771601415153de
] - meta: bump github/codeql-action from 3.28.8 to 3.28.10 (dependabot[bot]) #5725472ea8aac34
] - meta: bumpgithub/codeql-action
from 3.27.5 to 3.28.8 (dependabot[bot]) #5685999a271e588
] - meta: bump step-security/harden-runner from 2.12.0 to 2.12.2 (dependabot[bot]) #58923b4c4c02490
] - meta: bump step-security/harden-runner from 2.11.0 to 2.12.0 (dependabot[bot]) #581095361bb9157
] - meta: bump step-security/harden-runner from 2.10.4 to 2.11.0 (dependabot[bot]) #5725828e33acf30
] - meta: bumpstep-security/harden-runner
from 2.10.2 to 2.10.4 (dependabot[bot]) #56863fad773cede
] - module: throw error when re-runing errored module jobs (Joyee Cheung) #589572531185423
] - module: allow cycles in require() in the CJS handling in ESM loader (Joyee Cheung) #58598ed43b69689
] - module: clarify cjs global-like error on ModuleJobSync (Carlos Espa) #564916e02db1b12
] - module: handle instantiated async module jobs in require(esm) (Joyee Cheung) #58067badba50d30
] - module: fix incorrect formatting in require(esm) cycle error message (haykam821) #57453939ecf8906
] - module: handle cached linked async jobs in require(esm) (Joyee Cheung) #57187ba7f8a0353
] - module: improve error message from asynchronicity in require(esm) (Joyee Cheung) #57126c1e7fa2586
] - module: handle .mjs in .js handler in CommonJS (Joyee Cheung) #5559041f3dfd21b
] - module: fix require.resolve() crash on non-string paths (Aditi) #56942043dcdd628
] - os: fix GetInterfaceAddresses memory lieaky (theanarkh) #589409b74e9bfd9
] - permission: ignore internalModuleStat on module loading (Rafael Gonzaga) #55797611a147b45
] - readline: fix unresolved promise on abortion (Daniel Venable) #54030f891ae3421
] - repl: avoid deprecatedrequire.extensions
in tab completion (baki gul) #586537ba44290bf
] - repl: fix tab completion not working with computer string properties (Dario Piotrowicz) #58709eb842048b2
] - src: do not format single string argument for THROW_ERR_* (Joyee Cheung) #571264f004937ec
] - src: fixup errorhandling more in various places (James M Snell) #578525daa7fe2e2
] - src: fix module buffer allocation (X-BW) #57738586b1be11b
] - src: fix build when using shared simdutf (Antoine du Hamel) #58407563e61f012
] - src: fix possible dereference of null pointer (Eusgor) #58459cbec07ea0b
] - src: fix FIPS init error handling (Tobias Nießen) #5837980fb80e71b
] - src: fix -Wunreachable-code in src/node_api.cc (Shelley Vohr) #589015e97719860
] - test: skip test-http-imports on macos (Marco Ippolito) #5974569c43bdfcc
] - test: fix internet/test-dns (Michaël Zasso) #596606fd58e0338
] - tools: update coverage GitHub Actions to fixed version (Rich Trott) #59512eb7bbce73e
] - tools: disable failing coverage jobs (Antoine du Hamel) #5877065b1669936
] - util: fix formatting of objects with built-in Symbol.toPrimitive (Shima Ryuhei) #578328a29f13bec
] - util: fix parseEnv incorrectly splitting multiple ‘=‘ in value (HEESEUNG) #57421077d5020c4
] - v8: fix missing callback in heap utils destroy (Ruben Bridgewater) #5884634ae9f8b18
] - vm: import call should return a promise in the current context (Chengzhong Wu) #583090dd3a8d6d1
] - win,build: fix MSVS v17.14 compilation issue (StefanStojanovic) #589021b83a2bd2d
] - zlib: remove mentions of unexposed Z_TREES constant (Jimmy Leung) #583719dc9604502
] - zlib: fix pointer alignment (jhofstee) #57727v20.19.4
: 2025-07-15, Version 20.19.4 'Iron' (LTS), @RafaelGSSCompare Source
This is a security release.
Notable Changes
Commits
db7b93fcef
] - (CVE-2025-27210) lib: handle all windows reserved driver name (RafaelGSS) nodejs-private/node-private#721v20.19.3
: 2025-06-23, Version 20.19.3 'Iron' (LTS), @marco-ippolitoCompare Source
Notable Changes
c535a3c483
] - crypto: graduate WebCryptoAPIEd25519
and X25519 algorithms as stable (Filip Skokan) #56142af1dc63815
] - crypto: update root certificates to NSS 3.108 (Node.js GitHub Bot) #5738101d63a4ddf
] - deps: update timezone to 2025b (Node.js GitHub Bot) #57857b6daa344eb
] - doc: add dario-piotrowicz to collaborators (Dario Piotrowicz) #58102Commits
fc1fa7a357
] - build: use FILE_OFFSET_BITS=64 esp. on 32-bit arch (RafaelGSS) #5809079e0812181
] - build: use glob for dependencies of out/Makefile (Richard Lau) #55789f56e62851a
] - crypto: allow length=0 for HKDF and PBKDF2 in SubtleCrypto.deriveBits (Filip Skokan) #55866c535a3c483
] - crypto: graduate WebCryptoAPIEd25519
and X25519 algorithms as stable (Filip Skokan) #5614239925de8b1
] - crypto: allow non-multiple of 8 in SubtleCrypto.deriveBits (Filip Skokan) #55296af1dc63815
] - crypto: update root certificates to NSS 3.108 (Node.js GitHub Bot) #57381d09008add3
] - deps: V8: cherry-pick1a3ecc2
(Michaël Zasso) #58342fd56652425
] - deps: V8: cherry-pick182d9c0
(Andrey Kosyakov) #58342447481e829
] - deps: V8: cherry-pick third_party/zlib@646b7f5
(Hans Wennborg) #58342eb447168df
] - deps: update simdutf to 6.4.2 (Node.js GitHub Bot) #5785501d63a4ddf
] - deps: update timezone to 2025b (Node.js GitHub Bot) #5785710fb49f2a9
] - deps: update icu to 77.1 (Node.js GitHub Bot) #57455f1dc7d0205
] - deps: update corepack to 0.32.0 (Node.js GitHub Bot) #572657a2e64bb8a
] - deps: update simdutf to 6.4.0 (Node.js GitHub Bot) #56764e80669be0d
] - doc: mention reports should align with Node.js CoC (Rafael Gonzaga) #576077b2c0bc92e
] - doc: add gurgunday as triager (Gürgün Dayıoğlu) #57594791e4879de
] - doc: document REPL custom eval arguments (Dario Piotrowicz) #576902917f09876
] - doc: improved fetch docs (Alessandro Miliucci) #57296d940b15843
] - doc: clarifyunhandledRejection
events behaviors in process doc (Dario Piotrowicz) #5765471c664fab7
] - doc: update position type to integer | null in fs (Yukihiro Hasegawa) #577450c0fbfa9c6
] - doc: add missing v0.x changelog entries (Antoine du Hamel) #57779e99462c9fc
] - doc: correct deprecation type ofassert.CallTracker
(René) #57997c7e92696ef
] - doc: add returns for https.get (Eng Zer Jun) #58025ccc42b69ce
] - doc: fix env variable name inutil.styleText
(Antoine du Hamel) #58072b6daa344eb
] - doc: add dario-piotrowicz to collaborators (Dario Piotrowicz) #58102e5d6a3df16
] - doc: fixAsyncLocalStorage
example response changes after node v18 (Naor Tedgi (Abu Emma)) #57969f006411998
] - doc: fix typo of filezlib.md
(yusheng chen) #580935193735df4
] - doc: add missing options.signal to readlinePromises.createInterface() (Jimmy Leung) #55456fd44af730f
] - doc: fix misaligned options in vm.compileFunction() (Jimmy Leung) #581450fdcc0ddcd
] - doc: add ambassaor message (Brian Muenzenmeyer) #576005ca9616bd3
] - doc: increase z-index of header element (Dario Piotrowicz) #5785181342d10f0
] - doc: fix deprecation type forDEP0148
(Livia Medeiros) #57785776becfe01
] - doc: remove mention of--require
not supporting ES modules (Huáng Jùnliàng) #576203140a8f133
] - doc: add missingdeprecated
badges infs.md
(Yukihiro Hasegawa) #57384441ce24ae3
] - doc: deprecate passing invalid types infs.existsSync
(Carlos Espa) #558920556f54544
] - http: correctly translate HTTP method (Paolo Insogna) #52701c2c6d2b035
] - http: be more generational GC friendly (ywave620) #56767cdf3fa241c
] - http2: skip writeHead if stream is closed (Shima Ryuhei) #57686bbd5aec785
] - http2: fix graceful session close (Kushagra Pandey) #57808b427ae4f34
] - meta: removebuild-windows.yml
(Aviv Keller) #5466249e624f554
] - os: fix netmask format check condition in getCIDR function (Wiyeong Seo) #57324d582954434
] - src: remove unused variable in crypto_x509.cc (Michaël Zasso) #57754234a505e96
] - src: allow embedder customization of OOMErrorHandler (Shelley Vohr) #57325c0252cd380
] - src: fix -Wunreachable-code-return in node_sea (Shelley Vohr) #57664fcd1622fc1
] - src: fix kill signal 0 on Windows (Stefan Stojanovic) #57695850192b06b
] - test: skip broken sea on rhel8 (Marco Ippolito) #587613cf7cfb695
] - test: update WPT for WebCryptoAPI toedd42c0
(Node.js GitHub Bot) #57365f57765bdcf
] - test: mark test-without-async-context-frame flaky on windows (James M Snell) #56753275ea8e7ef
] - test: force GC in test-file-write-stream4 (Luigi Pinca) #57930da6a13c338
] - test: deflake test-http2-options-max-headers-block-length (Luigi Pinca) #5795956fce6691e
] - test: prevent extraneous HOSTNAME substitution in test-runner-output (René) #58076c9c0be5596
] - test: update expected error message for macOS (Antoine du Hamel) #577423cbf5f93d2
] - test: fix missing edge case in test-blob-slice-with-large-size (Joyee Cheung) #58414bffd4ec379
] - test: skip in test-buffer-tostring-rangeerror on allocation failure (Joyee Cheung) #584158237346fb7
] - test,crypto: update WebCryptoAPI WPT (Filip Skokan) #54593b90c4ab937
] - tools: remove unusedosx-pkg-postinstall.sh
(Antoine du Hamel) #57667414013dcfb
] - tools: edit create-release-proposal workflow to handle pr body length (Elves Vieira) #578417c449ed6b3
] - tools: fix tarball testing directory (Marco Ippolito) #57994d164dc2d38
] - tools: update sccache version to v0.10.0 (Marco Ippolito) #57994debd3c2cc0
] - tools: disable failing test envs intest-linux
CI (Antoine du Hamel) #58351152112505a
] - typings: fixImportModuleDynamicallyCallback
return type (Chengzhong Wu) #57160363bf744ab
] - worker: flush stdout and stderr on exit (Matteo Collina) #56428v20.19.2
: 2025-05-14, Version 20.19.2 'Iron' (LTS), @RafaelGSSCompare Source
This is a security release.
Notable Changes
Commits
eb25047b1b
] - deps: update llhttp to 9.2.0 (Node.js GitHub Bot) #5171912dcd8db08
] - deps: update llhttp to 9.1.3 (Node.js GitHub Bot) #50080190e45a291
] - (SEMVER-MAJOR) (CVE-2025-23167) deps: update llhttp to 9.1.2 (Paolo Insogna) #48981fc68c44e6a
] - fs: added test for missing call to uv_fs_req_cleanup (Justin Nietzel) #578119e13bf0a81
] - (CVE-2025-23165) fs: add missing call to uv_fs_req_cleanup (Justin Nietzel) #57811bd0aa5d44c
] - (CVE-2024-27982) http: do not allow OBS fold in headers by default (Paolo Insogna) nodejs-private/node-private#5566c57465920
] - (CVE-2025-23166) src: fix error handling on async crypto operations (RafaelGSS) nodejs-private/node-private#710v20.19.1
: 2025-04-22, Version 20.19.1 'Iron' (LTS), @UlisesGascon prepared by @RafaelGSSCompare Source
Notable Changes
d5e73ce0f8
] - deps: update undici to 6.21.2 (Matteo Collina) #57442e4a6323ab2
] - deps: update c-ares to v1.34.5 (Node.js GitHub Bot) #57792Commits
d5e73ce0f8
] - deps: update undici to 6.21.2 (Matteo Collina) #57442e4a6323ab2
] - deps: update c-ares to v1.34.5 (Node.js GitHub Bot) #57792b2b9eb36af
] - dns: restore dns query cache ttl (Ethan Arrowood) #5764007a99a5c0b
] - doc: correct status of require(esm) warning in v20 changelog (Joyee Cheung) #57529d45517ccbf
] - meta: bump Mozilla-Actions/sccache-action from 0.0.8 to 0.0.9 (dependabot[bot]) #57720fa93bb2633
] - test: update parallel/test-tls-dhe for OpenSSL 3.5 (Richard Lau) #5747729c032403c
] - tools: update sccache to support GH cache changes (Michaël Zasso) #57573v20.19.0
: 2025-03-13, Version 20.19.0 'Iron' (LTS), @marco-ippolitoCompare Source
Notable Changes
require(esm) is now enabled by default
Support for loading native ES modules using require() had been available on v20.x under the command line flag --experimental-require-module, and available by default on v22.x and v23.x. In this release, it is now no longer behind a flag on v20.x.
This feature has been tested on v23.x and v22.x, and we are looking for user feedback from v20.x to make more final tweaks before fully stabilizing it.
It now no longer emits a warning unless
--trace-require-module
is explicitly used.If there happens to be any regressions caused by this feature, users can report it to the Node.js issue tracker. Meanwhile this feature can also be disabled using
--no-experimental-require-module
as a workaround.With this feature enabled, Node.js will no longer throw
ERR_REQUIRE_ESM
ifrequire()
is used to load a ES module. It can, however, throwERR_REQUIRE_ASYNC_MODULE
if the ES module being loaded or its dependencies contain top-levelawait
. When the ES module is loaded successfully byrequire()
, the returned object will either be a ES module namespace object similar to what's returned byimport()
, or what gets exported as"module.exports"
in the ES module.Users can check
process.features.require_module
to see whetherrequire(esm)
is enabled in the current Node.js instance. For packages, the"module-sync"
exports condition can be used as a way to detectrequire(esm)
support in the current Node.js instance and allow bothrequire()
andimport
to load the same native ES module. See the documentation for more details about this feature.Contributed by Joyee Cheung in #55085
Module syntax detection is now enabled by default
Module syntax detection (the
--experimental-detect-module
flag) is nowenabled by default. Use
--no-experimental-detect-module
to disable it ifneeded.
Syntax detection attempts to run ambiguous files as CommonJS, and if the module
fails to parse as CommonJS due to ES module syntax, Node.js tries again and runs
the file as an ES module.
Ambiguous files are those with a
.js
or no extension, where the nearest parentpackage.json
has no"type"
field (either"type": "module"
or"type": "commonjs"
).Syntax detection should have no performance impact on CommonJS modules, but it
incurs a sli
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.