Repository navigation
Update all - #1215
Open
renovate[bot] wants to merge 1 commit into
Open
Update all#1215renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/all
branch
3 times, most recently
from
July 4, 2025 16:38
5529f5a to
c35765f
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
6 times, most recently
from
July 15, 2025 14:31
986117b to
f95066d
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
2 times, most recently
from
July 19, 2025 06:23
169dcd4 to
9392ade
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
7 times, most recently
from
August 1, 2025 00:24
5516dd5 to
6242a8d
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
3 times, most recently
from
August 11, 2025 17:28
8f92f27 to
a8d64f3
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
6 times, most recently
from
August 22, 2025 03:12
8d96b49 to
50724cb
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
3 times, most recently
from
August 27, 2025 18:12
02a9ac2 to
375a626
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
4 times, most recently
from
September 29, 2025 22:23
c00c0fd to
50e28de
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
2 times, most recently
from
October 3, 2025 08:46
1ee983b to
d0e6d39
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
2 times, most recently
from
October 13, 2025 05:01
20cbd2b to
d10c03a
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
3 times, most recently
from
October 24, 2025 04:45
1b58a5e to
bb7256e
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
2 times, most recently
from
October 30, 2025 00:47
412acf2 to
aa5bedd
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
3 times, most recently
from
March 5, 2026 19:01
6719a08 to
311a05c
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
3 times, most recently
from
March 16, 2026 14:59
545b097 to
9826409
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
5 times, most recently
from
March 30, 2026 18:08
ad35af7 to
11821b0
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
3 times, most recently
from
April 10, 2026 04:43
3166937 to
5786a6c
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
2 times, most recently
from
April 11, 2026 21:55
8449787 to
304ecfa
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
6.0.4→6.1.06.0.2→6.0.318.19.112→18.19.1308.15.0→8.19.08.3.4→8.3.56.4.0→6.4.19.1.3→9.2.16.10.0→6.11.00.30.17→0.30.212.8.1→2.10.222.16.0→22.23.310.2.0→10.3.010.19.6→10.29.83.2.5→3.9.103.6.0→3.9.105.0.5→5.0.100.3.4→0.4.021.0.0→21.1.23.0.1→3.0.25.8.3→5.9.3Release Notes
rollup/plugins (@rollup/plugin-babel)
v6.1.02025-10-13
Features
rollup/plugins (@rollup/plugin-replace)
v6.0.32025-10-29
Bugfixes
acornjs/acorn (acorn)
v8.19.0Compare Source
v8.18.0Compare Source
v8.17.0Compare Source
v8.16.0Compare Source
avajs/ava (ava)
v6.4.1Compare Source
What's Changed
New Contributors
Full Changelog: avajs/ava@v6.4.0...v6.4.1
babel/babel-loader (babel-loader)
v9.2.1Compare Source
What's Changed
Full Changelog: babel/babel-loader@v9.2.0...v9.2.1
v9.2.0Compare Source
What's Changed
cacheIdentifieris computed from the merged options by @JLHwung in #1000Full Changelog: babel/babel-loader@v9.1.3...v9.2.0
webpack/css-loader (css-loader)
v6.11.0Compare Source
Features
Bug Fixes
@scopeat-rule without params (#1581) (e022e3b)Rich-Harris/magic-string (magic-string)
v0.30.21Compare Source
v0.30.19Compare Source
Bug Fixes
Features
replace(All)support replacement for functions when the first parameter is a string (#304) (fd1d887)v0.30.18Compare Source
Bug Fixes
webpack/mini-css-extract-plugin (mini-css-extract-plugin)
v2.10.2Compare Source
v2.10.1Compare Source
v2.10.0Compare Source
Features
output.cssFilenameandoutput.cssChunkFilename(#1151) (54f775d)Bug Fixes
2.9.4 (2025-08-11)
Bug Fixes
2.9.3 (2025-08-04)
Bug Fixes
2.9.2 (2024-11-01)
Bug Fixes
2.9.1 (2024-08-19)
Bug Fixes
export default {}when CSS modules enabled and a file is empty for thedefaultExportoption (8f77e19)v2.9.4Compare Source
Features
output.cssFilenameandoutput.cssChunkFilename(#1151) (54f775d)Bug Fixes
2.9.4 (2025-08-11)
Bug Fixes
2.9.3 (2025-08-04)
Bug Fixes
2.9.2 (2024-11-01)
Bug Fixes
2.9.1 (2024-08-19)
Bug Fixes
export default {}when CSS modules enabled and a file is empty for thedefaultExportoption (8f77e19)v2.9.3Compare Source
Features
output.cssFilenameandoutput.cssChunkFilename(#1151) (54f775d)Bug Fixes
2.9.4 (2025-08-11)
Bug Fixes
2.9.3 (2025-08-04)
Bug Fixes
2.9.2 (2024-11-01)
Bug Fixes
2.9.1 (2024-08-19)
Bug Fixes
export default {}when CSS modules enabled and a file is empty for thedefaultExportoption (8f77e19)v2.9.2Compare Source
Features
output.cssFilenameandoutput.cssChunkFilename(#1151) (54f775d)Bug Fixes
2.9.4 (2025-08-11)
Bug Fixes
2.9.3 (2025-08-04)
Bug Fixes
2.9.2 (2024-11-01)
Bug Fixes
2.9.1 (2024-08-19)
Bug Fixes
export default {}when CSS modules enabled and a file is empty for thedefaultExportoption (8f77e19)v2.9.1Compare Source
Features
output.cssFilenameandoutput.cssChunkFilename(#1151) (54f775d)Bug Fixes
2.9.4 (2025-08-11)
Bug Fixes
2.9.3 (2025-08-04)
Bug Fixes
2.9.2 (2024-11-01)
Bug Fixes
2.9.1 (2024-08-19)
Bug Fixes
export default {}when CSS modules enabled and a file is empty for thedefaultExportoption (8f77e19)v2.9.0Compare Source
Features
output.cssFilenameandoutput.cssChunkFilename(#1151) (54f775d)Bug Fixes
2.9.4 (2025-08-11)
Bug Fixes
2.9.3 (2025-08-04)
Bug Fixes
2.9.2 (2024-11-01)
Bug Fixes
2.9.1 (2024-08-19)
Bug Fixes
export default {}when CSS modules enabled and a file is empty for thedefaultExportoption (8f77e19)nodejs/node (node)
v22.23.3: 2026-09-23, Version 22.23.3 'Jod' (LTS), @aduh95 prepared by @juanarbolCompare Source
Notable Changes
fe2a6b2be8] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746871167ddfd] - deps: update corepack to 0.36.0 (Node.js GitHub Bot) #65653b816fc8958] - deps: upgrade npm to 10.9.9 (npm team) #64884e306521444] - deps: update icu to 78.3 (Node.js GitHub Bot) #62324a9cb31129f] - deps: update OpenSSL 3.5.8 (Node.js GitHub Bot) #655422a3548e51c] - deps: update Undici to 6.28.1 (mcollina) #657903909ff2c4a] - node-api: supportSharedArrayBufferinnapi_create_typedarray(Yilong Li) #6271066de6349ad] - node-api: addnapi_create_external_sharedarraybuffer(Ben Noordhuis) #62623Commits
44cf27b8fa] - build: update binary-upload to use correct tarball name (Stewart X Addison) #65282fe2a6b2be8] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #6474671feba6b69] - crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527871167ddfd] - deps: update corepack to 0.36.0 (Node.js GitHub Bot) #656532a3548e51c] - deps: update undici to 6.28.1 (mcollina) #6579059d853a4df] - deps: update archs files for openssl-3.5.8 (Node.js GitHub Bot) #65542a9cb31129f] - deps: upgrade openssl sources to openssl-3.5.8 (Node.js GitHub Bot) #655423376e27de2] - deps: V8: cherry-picka6eaf75(Camillo Bruni) #65402b816fc8958] - deps: upgrade npm to 10.9.9 (npm team) #648844e4bd1b104] - deps: update timezone to 2026c (Node.js GitHub Bot) #645887d82841b4e] - deps: update c-ares to 1.34.8 (Node.js GitHub Bot) #6433001855a19d3] - deps: c-ares: cherry-pick8ba37af(René) #6411023fb398c3d] - deps: update corepack to 0.35.0 (Node.js GitHub Bot) #633755286330365] - deps: update corepack to 0.34.7 (Node.js GitHub Bot) #628106d6c3c98b1] - deps: update timezone to 2026b (Node.js GitHub Bot) #62962e306521444] - deps: update icu to 78.3 (Node.js GitHub Bot) #62324d9cb8468a3] - doc: clarifyfilteroption ofsqlite.database.applyChangeset(Antoine du Hamel) #63515c9c5662d91] - doc: add sxa GPG key (ed25519) (Stewart X Addison) #6419337f21068c4] - fs: restore fs patchability in ESM loader (Joyee Cheung) #628357c2df5dd96] - http2: avoid uaf while receiving and sending rst_stream (esgor) #641663909ff2c4a] - node-api: support SharedArrayBuffer in napi_create_typedarray (Yilong Li) #6271066de6349ad] - node-api: add napi_create_external_sharedarraybuffer (Ben Noordhuis) #62623ce9139107f] - src: escape Windows environment variables in task runner (Antoine du Hamel) #65217839480a471] - test: fix link-local dgram scope assertion (Filip Skokan) #6562940eac4a32f] - test: account for varied OpenSSL CCM final behaviours (Filip Skokan) #6554275098a9e8c] - tools: update gr2m/create-or-update-pull-request-action to v1.10.1 (Mike McCready) #6306508b6ac0416] - tools: revert OpenSSL update workflow to ubuntu-latest (Richard Lau) #6262702cafc479f] - tools: fix commit linter for semver-major release proposals (Antoine du Hamel) #629936f6cd3768d] - tools: sync mk-ca-bundle.pl with curl (Archkon) #64753bc5753d438] - tools: removeenvinfofrom our workflows (Antoine du Hamel) #64259d68ee9f8a5] - tools: validate version number in release proposal commit message lint (Antoine du Hamel) #6407038ee2e895f] - tools: avoid test/fixtures/wpt/README.md conflicts (Filip Skokan) #63938fdc65e489f] - tools: use different branch for tool updates on staging branches (Antoine du Hamel) #63110e5a6fde002] - tools: update gyp-next to 0.22.1 (Node.js GitHub Bot) #629615fbbad6e82] - url: handle unparsable serialized URLs in setters (Matteo Collina) #64651ed019e4854] - util: preserve function names without source map names (Hiroki Osame) #65108v22.23.2: 2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolitoCompare Source
This is a security release.
Notable Changes
Commits
4b12ac38a1] - deps: update llhttp to 9.4.3 (Paolo Insogna) nodejs-private/node-private#9353fd0aa51d0] - deps: update undici to 6.28.0 (Node.js GitHub Bot) #6471422efc051a3] - (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) nodejs-private/node-private#929c8525ac3a6] - (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) nodejs-private/node-private#932daa6d25e3d] - (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) nodejs-private/node-private#921f14d78b9e0] - (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) #6375251123159fe] - (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) nodejs-private/node-private#934acaf4266b2] - (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) nodejs-private/node-private#930440329f624] - (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) nodejs-private/node-private#911ed18b9cc07] - (CVE-2026-58039) permission: check final report output path (RafaelGSS) nodejs-private/node-private#9260566c3cccd] - (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) nodejs-private/node-private#9270d072480c3] - (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) nodejs-private/node-private#931v22.23.1: 2026-06-23, Version 22.23.1 'Jod' (LTS), @RafaelGSSCompare Source
This release includes a fix for an unexpected behavior introduced
by the recent security release (22.23.0).
Commits
41d2ee13be] - build: switch coverage-windows towindows-2022(Richard Lau) #63940eaa292549e] - http: avoid stream listeners on idle agent sockets (Matteo Collina) #64004v22.23.0: 2026-06-18, Version 22.23.0 'Jod' (LTS), @aduh95Compare Source
This is a security release.
Notable Changes
Commits
38b4c5ed51] - (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) nodejs-private/node-private#878ad8a10c1bb] - deps: update llhttp to 9.4.2 (Antoine du Hamel) nodejs-private/node-private#890ca825a87cc] - deps: update undici to 6.27.0 (aduh95) #63711a1a5bb9683] - (CVE-2026-48937) deps: fix integration issues with the latest nghttp2 (Tim Perry) #628910f48583512] - (SEMVER-MAJOR) deps: update nghttp2 to 1.69.0 (Node.js GitHub Bot) #6289138c869fc05] - deps: update nghttp2 to 1.68.0 (nodejs-github-bot) #61136290667c84f] - deps: update nghttp2 to 1.67.1 (nodejs-github-bot) #59790c9f3da76aa] - deps: update nghttp2 to 1.66.0 (Node.js GitHub Bot) #5878660890be563] - deps: update nghttp2 to 1.65.0 (Node.js GitHub Bot) #572695024c7d5d8] - deps: update archs files for openssl-3.5.7 (Node.js GitHub Bot) #638207f4eb5af2e] - deps: upgrade openssl sources to openssl-3.5.7 (Node.js GitHub Bot) #63820ebb4ec78a8] - deps: fix aix implicit declaration in OpenSSL (Abdirahim Musse) #626565763d40826] - deps: update llhttp to 9.4.1 (Node.js GitHub Bot) #63045c551a51d0c] - (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) nodejs-private/node-private#8680a22d40180] - (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) nodejs-private/node-private#846c79968e108] - (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) nodejs-private/node-private#8550c37bff2ff] - http2: fix DEP0194 message (KaKa) #58669ea5dc6b529] - (SEMVER-MAJOR) http2: remove support for priority signaling (Matteo Collina) #582939b6af26132] - (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) nodejs-private/node-private#86728dcd38864] - (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) nodejs-private/node-private#8732f62693801] - (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) nodejs-private/node-private#8701662a3ea09] - test: add session reuse host verification regressions (Matteo Collina) nodejs-private/node-private#854718d5d0e2c] - test: skiptest-fs-utimes-y2K38on armv7 (Richard Lau) #63836041185b61f] - test: skip test-cluster-dgram-reuse on AIX 7.3 (Stewart X Addison) #62238fd890ba01d] - (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) nodejs-private/node-private#85439d1d09684] - (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) nodejs-private/node-private#8572197a47144] - (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) nodejs-private/node-private#869v22.22.3: 2026-05-13, Version 22.22.3 'Jod' (LTS), @marco-ippolitoCompare Source
Commits
4f780905c5] - crypto: fix potential null pointer dereference when BIO_meth_new() fails (Nora Dossche) #617884a09efb947] - crypto: update root certificates to NSS 3.121 (Node.js GitHub Bot) #62485e4c0d99839] - deps: update timezone to 2026a (Node.js GitHub Bot) #621640226c8dd7a] - deps: update simdjson to 4.5.0 (Node.js GitHub Bot) #62382e742ab748c] - deps: update sqlite to 3.51.3 (Node.js GitHub Bot) #6225673cac0571a] - deps: update amaro to 1.1.8 (Node.js GitHub Bot) #62151ae5c162b93] - deps: update amaro to 1.1.7 (Node.js GitHub Bot) #61730b819cb9977] - deps: update amaro to 1.1.6 (Node.js GitHub Bot) #61603bbcce09dc7] - deps: update sqlite to 3.52.0 (Node.js GitHub Bot) #6215022ff2d81ce] - deps: update simdjson to 4.3.1 (Node.js GitHub Bot) #61930f49b51d75c] - deps: update acorn-walk to 8.3.5 (Node.js GitHub Bot) #619281a5cec0d49] - deps: update acorn to 8.16.0 (Node.js GitHub Bot) #61925d339497688] - deps: update nbytes to 0.1.3 (Node.js GitHub Bot) #618793ff8ffd459] - deps: remove stale OpenSSL arch configs (René) #61834b8ddbc1e9a] - deps: update llhttp to 9.3.1 (Node.js GitHub Bot) #61827ffda97afd4] - deps: update googletest to2461743(Node.js GitHub Bot) #6248479aa32cf4f] - deps: update googletest to73a63ea(Node.js GitHub Bot) #61927b6957e13b6] - deps: update archs files for openssl-3.5.6 (Node.js GitHub Bot) #626293a27669063] - deps: upgrade openssl sources to openssl-3.5.6 (Node.js GitHub Bot) #62629d568a1bb53] - deps: upgrade npm to 10.9.8 (npm team) #62463ec11f3c1d5] - deps: V8: backport85b3900(Thibaud Michaud) #6278308609712ed] - deps: V8: backport1b27e46(Thibaud Michaud) #62783dcc60d5ab2] - deps: V8: backport9997fc0(Thibaud Michaud) #627831d1f4451fb] - deps: V8: cherry-pickb96e40d(Clemens Backes) #627832268567237](https://redirect.github.com/nodejsConfiguration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.