Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: deeplay-io/nice-grpc
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: nice-grpc@2.1.14
Choose a base ref
...
head repository: deeplay-io/nice-grpc
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: nice-grpc@2.1.15
Choose a head ref
  • 19 commits
  • 94 files changed
  • 3 contributors

Commits on Mar 8, 2026

  1. chore(deps): update dependencies from Dependabot PRs (#847)

    Update abort-controller-x ^0.4→^0.5, grpc-tools ^1.12→^1.13,
    @tsconfig/recommended ^1.0.1→^1.0.13, lint-staged ^15→^16, rimraf ^5→^6,
    ts-jest ^29.0→^29.4, mocha ^11.1→^11.7, glob ^10→^11, testcontainers
    ^10→^11, @types/ws ^8.2→^8.5, ws ^8.4→^8.18, @wdio/cli ^9.2→^9.21.
    
    ---------
    
    Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
    aikoven and claude authored Mar 8, 2026
    Configuration menu
    Copy the full SHA
    6bf4b8f View commit details
    Browse the repository at this point in the history

Commits on Mar 9, 2026

  1. chore: migrate from jest to vitest (#848)

    Replace jest with vitest across all 11 packages (excluding nice-grpc-web
    which uses mocha). Remove jest, ts-jest, @types/jest, jest-mock-random,
    and jest-os-detection dependencies.
    
    ---------
    
    Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
    aikoven and claude authored Mar 9, 2026
    Configuration menu
    Copy the full SHA
    328d90e View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    4a4eb1f View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    7f70564 View commit details
    Browse the repository at this point in the history

Commits on Apr 12, 2026

  1. chore(deps): bump basic-ftp from 5.0.5 to 5.2.2 (#867)

    Bumps [basic-ftp](https://github.com/patrickjuchli/basic-ftp) from 5.0.5
    to 5.2.2.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/patrickjuchli/basic-ftp/releases">basic-ftp's
    releases</a>.</em></p>
    <blockquote>
    <h2>5.2.2</h2>
    <ul>
    <li>Fixed: Improve control character rejection, fixes <a
    href="https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-6v7q-wjvx-w8wg">https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-6v7q-wjvx-w8wg</a>.</li>
    </ul>
    <h2>5.2.1</h2>
    <ul>
    <li>Fixed: Reject control character injection attempts using paths. See
    <a
    href="https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-chqc-8p9q-pq6q">https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-chqc-8p9q-pq6q</a>.</li>
    </ul>
    <h2>5.2.0</h2>
    <ul>
    <li>Changed: Skip files with invalid name in downloadToDir.</li>
    </ul>
    <h2>5.1.0</h2>
    <ul>
    <li>Added: Add the option to prevent the use of separate transfer host
    IPs when using PASV. (<a
    href="https://redirect.github.com/patrickjuchli/basic-ftp/issues/259">#259</a>)</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/patrickjuchli/basic-ftp/blob/master/CHANGELOG.md">basic-ftp's
    changelog</a>.</em></p>
    <blockquote>
    <h2>5.2.2</h2>
    <ul>
    <li>Fixed: Improve control character rejection, fixes <a
    href="https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-6v7q-wjvx-w8wg">https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-6v7q-wjvx-w8wg</a>.</li>
    </ul>
    <h2>5.2.1</h2>
    <ul>
    <li>Fixed: Reject control character injection attempts using paths. See
    <a
    href="https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-chqc-8p9q-pq6q">https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-chqc-8p9q-pq6q</a>.</li>
    </ul>
    <h2>5.2.0</h2>
    <ul>
    <li>Changed: Skip files with invalid name in downloadToDir. Fixes
    security vulnerability CVE-2026-27699, see <a
    href="https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-5rq4-664w-9x2c">https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-5rq4-664w-9x2c</a>.</li>
    </ul>
    <h2>5.1.0</h2>
    <ul>
    <li>Added: Add the option to prevent the use of separate transfer host
    IPs when using PASV. (<a
    href="https://redirect.github.com/patrickjuchli/basic-ftp/issues/259">#259</a>)</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/patrickjuchli/basic-ftp/commit/e9d09d6815b300b73e1297cdcf91786a979ef212"><code>e9d09d6</code></a>
    Bump version</li>
    <li><a
    href="https://github.com/patrickjuchli/basic-ftp/commit/20327d35126e57e5fdbaae79a4b65222fbadc53c"><code>20327d3</code></a>
    Move prevention of control character injection to more central
    place</li>
    <li><a
    href="https://github.com/patrickjuchli/basic-ftp/commit/ba40f9d60e1ff7b63de5d5bb272ae317e5382689"><code>ba40f9d</code></a>
    Update dev dependencies</li>
    <li><a
    href="https://github.com/patrickjuchli/basic-ftp/commit/6b0008b7cf5ca0b81d31604d15a9ff0bcbf1a5db"><code>6b0008b</code></a>
    Bump version</li>
    <li><a
    href="https://github.com/patrickjuchli/basic-ftp/commit/2ecc8e2c500c5234115f06fd1dbde1aa03d70f4b"><code>2ecc8e2</code></a>
    Reject control character injection attempts using paths</li>
    <li><a
    href="https://github.com/patrickjuchli/basic-ftp/commit/515d21fee0b05be5ab934af5acb79d1d977e8026"><code>515d21f</code></a>
    Update security policy and reporting instructions</li>
    <li><a
    href="https://github.com/patrickjuchli/basic-ftp/commit/9744254b56061159751aee1b86ddd0f2ecef32ce"><code>9744254</code></a>
    Link to security advisory</li>
    <li><a
    href="https://github.com/patrickjuchli/basic-ftp/commit/5d41e45073ed1a8a3b5e5a1bbfcd131e61295bf8"><code>5d41e45</code></a>
    Bump version</li>
    <li><a
    href="https://github.com/patrickjuchli/basic-ftp/commit/49c2e73ed1cae4962ae38b33ab93a3548c2f5622"><code>49c2e73</code></a>
    Update dependencies</li>
    <li><a
    href="https://github.com/patrickjuchli/basic-ftp/commit/2a2a0e6514357b9eda07c2f8afbd3f04727a7cd9"><code>2a2a0e6</code></a>
    Skip invalid filenames</li>
    <li>Additional commits viewable in <a
    href="https://github.com/patrickjuchli/basic-ftp/compare/v5.0.5...v5.2.2">compare
    view</a></li>
    </ul>
    </details>
    <details>
    <summary>Maintainer changes</summary>
    <p>This version was pushed to npm by <a
    href="https://www.npmjs.com/~patrickjuchli">patrickjuchli</a>, a new
    releaser for basic-ftp since your current version.</p>
    </details>
    <details>
    <summary>Install script changes</summary>
    <p>This version adds <code>prepare</code> script that runs during
    installation. Review the package contents before updating.</p>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=basic-ftp&package-manager=npm_and_yarn&previous-version=5.0.5&new-version=5.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the
    [Security Alerts
    page](https://github.com/deeplay-io/nice-grpc/network/alerts).
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Apr 12, 2026
    Configuration menu
    Copy the full SHA
    54fbae0 View commit details
    Browse the repository at this point in the history
  2. chore(deps): bump lodash from 4.17.23 to 4.18.1 (#866)

    Bumps [lodash](https://github.com/lodash/lodash) from 4.17.23 to 4.18.1.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/lodash/lodash/releases">lodash's
    releases</a>.</em></p>
    <blockquote>
    <h2>4.18.1</h2>
    <h2>Bugs</h2>
    <p>Fixes a <code>ReferenceError</code> issue in <code>lodash</code>
    <code>lodash-es</code> <code>lodash-amd</code> and
    <code>lodash.template</code> when using the <code>template</code> and
    <code>fromPairs</code> functions from the modular builds. See <a
    href="https://redirect.github.com/lodash/lodash/issues/6167#issuecomment-4165269769">lodash/lodash#6167</a></p>
    <p>These defects were related to how lodash distributions are built from
    the main branch using <a
    href="https://github.com/lodash-archive/lodash-cli">https://github.com/lodash-archive/lodash-cli</a>.
    When internal dependencies change inside lodash functions, equivalent
    updates need to be made to a mapping in the lodash-cli. (hey, it was
    ahead of its time once upon a time!). We know this, but we missed it in
    the last release. It's the kind of thing that passes in CI, but fails bc
    the build is not the same thing you tested.</p>
    <p>There is no diff on main for this, but you can see the diffs for each
    of the npm packages on their respective branches:</p>
    <ul>
    <li><code>lodash</code>: <a
    href="https://github.com/lodash/lodash/compare/4.18.0-npm...4.18.1-npm">https://github.com/lodash/lodash/compare/4.18.0-npm...4.18.1-npm</a></li>
    <li><code>lodash-es</code>: <a
    href="https://github.com/lodash/lodash/compare/4.18.0-es...4.18.1-es">https://github.com/lodash/lodash/compare/4.18.0-es...4.18.1-es</a></li>
    <li><code>lodash-amd</code>: <a
    href="https://github.com/lodash/lodash/compare/4.18.0-amd...4.18.1-amd">https://github.com/lodash/lodash/compare/4.18.0-amd...4.18.1-amd</a></li>
    <li><code>lodash.template</code><a
    href="https://github.com/lodash/lodash/compare/4.18.0-npm-packages...4.18.1-npm-packages">https://github.com/lodash/lodash/compare/4.18.0-npm-packages...4.18.1-npm-packages</a></li>
    </ul>
    <h2>4.18.0</h2>
    <h2>v4.18.0</h2>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/lodash/lodash/compare/4.17.23...4.18.0">https://github.com/lodash/lodash/compare/4.17.23...4.18.0</a></p>
    <h3>Security</h3>
    <p><strong><code>_.unset</code> / <code>_.omit</code></strong>: Fixed
    prototype pollution via <code>constructor</code>/<code>prototype</code>
    path traversal (<a
    href="https://github.com/lodash/lodash/security/advisories/GHSA-f23m-r3pf-42rh">GHSA-f23m-r3pf-42rh</a>,
    <a
    href="https://github.com/lodash/lodash/commit/fe8d32eda854377349a4f922ab7655c8e5df9a0b">fe8d32e</a>).
    Previously, array-wrapped path segments and primitive roots could bypass
    the existing guards, allowing deletion of properties from built-in
    prototypes. Now <code>constructor</code> and <code>prototype</code> are
    blocked unconditionally as non-terminal path keys, matching
    <code>baseSet</code>. Calls that previously returned <code>true</code>
    and deleted the property now return <code>false</code> and leave the
    target untouched.</p>
    <p><strong><code>_.template</code></strong>: Fixed code injection via
    <code>imports</code> keys (<a
    href="https://github.com/lodash/lodash/security/advisories/GHSA-r5fr-rjxr-66jc">GHSA-r5fr-rjxr-66jc</a>,
    CVE-2026-4800, <a
    href="https://github.com/lodash/lodash/commit/879aaa93132d78c2f8d20c60279da9f8b21576d6">879aaa9</a>).
    Fixes an incomplete patch for CVE-2021-23337. The <code>variable</code>
    option was validated against <code>reForbiddenIdentifierChars</code> but
    <code>importsKeys</code> was left unguarded, allowing code injection via
    the same <code>Function()</code> constructor sink. <code>imports</code>
    keys containing forbidden identifier characters now throw
    <code>&quot;Invalid imports option passed into
    _.template&quot;</code>.</p>
    <h3>Docs</h3>
    <ul>
    <li>Add security notice for <code>_.template</code> in threat model and
    API docs (<a
    href="https://redirect.github.com/lodash/lodash/pull/6099">#6099</a>)</li>
    <li>Document <code>lower &gt; upper</code> behavior in
    <code>_.random</code> (<a
    href="https://redirect.github.com/lodash/lodash/pull/6115">#6115</a>)</li>
    <li>Fix quotes in <code>_.compact</code> jsdoc (<a
    href="https://redirect.github.com/lodash/lodash/pull/6090">#6090</a>)</li>
    </ul>
    <h3><code>lodash.*</code> modular packages</h3>
    <p><a
    href="https://redirect.github.com/lodash/lodash/pull/6157">Diff</a></p>
    <p>We have also regenerated and published a select number of the
    <code>lodash.*</code> modular packages.</p>
    <p>These modular packages had fallen out of sync significantly from the
    minor/patch updates to lodash. Specifically, we have brought the
    following packages up to parity w/ the latest lodash release because
    they have had CVEs on them in the past:</p>
    <ul>
    <li><a
    href="https://www.npmjs.com/package/lodash.orderby">lodash.orderby</a></li>
    <li><a
    href="https://www.npmjs.com/package/lodash.tonumber">lodash.tonumber</a></li>
    <li><a
    href="https://www.npmjs.com/package/lodash.trim">lodash.trim</a></li>
    <li><a
    href="https://www.npmjs.com/package/lodash.trimend">lodash.trimend</a></li>
    <li><a
    href="https://www.npmjs.com/package/lodash.sortedindexby">lodash.sortedindexby</a></li>
    <li><a
    href="https://www.npmjs.com/package/lodash.zipobjectdeep">lodash.zipobjectdeep</a></li>
    <li><a
    href="https://www.npmjs.com/package/lodash.unset">lodash.unset</a></li>
    <li><a
    href="https://www.npmjs.com/package/lodash.omit">lodash.omit</a></li>
    <li><a
    href="https://www.npmjs.com/package/lodash.template">lodash.template</a></li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/lodash/lodash/commit/cb0b9b9212521c08e3eafe7c8cb0af1b42b6649e"><code>cb0b9b9</code></a>
    release(patch): bump main to 4.18.1 (<a
    href="https://redirect.github.com/lodash/lodash/issues/6177">#6177</a>)</li>
    <li><a
    href="https://github.com/lodash/lodash/commit/75535f57883b7225adb96de1cfc1cd4169cfcb51"><code>75535f5</code></a>
    chore: prune stale advisory refs (<a
    href="https://redirect.github.com/lodash/lodash/issues/6170">#6170</a>)</li>
    <li><a
    href="https://github.com/lodash/lodash/commit/62e91bc6a39c98d85b9ada8c44d40593deaf82a4"><code>62e91bc</code></a>
    docs: remove n_ Node.js &lt; 6 REPL note from README (<a
    href="https://redirect.github.com/lodash/lodash/issues/6165">#6165</a>)</li>
    <li><a
    href="https://github.com/lodash/lodash/commit/59be2de61f8aa9461c7856533b51d31b7d8babc4"><code>59be2de</code></a>
    release(minor): bump to 4.18.0 (<a
    href="https://redirect.github.com/lodash/lodash/issues/6161">#6161</a>)</li>
    <li><a
    href="https://github.com/lodash/lodash/commit/af634573030f979194871da7c68f79420992f53d"><code>af63457</code></a>
    fix: broken tests for _.template 879aaa9</li>
    <li><a
    href="https://github.com/lodash/lodash/commit/1073a7693e1727e0cf3641e5f71f75ddcf8de7c0"><code>1073a76</code></a>
    fix: linting issues</li>
    <li><a
    href="https://github.com/lodash/lodash/commit/879aaa93132d78c2f8d20c60279da9f8b21576d6"><code>879aaa9</code></a>
    fix: validate imports keys in _.template</li>
    <li><a
    href="https://github.com/lodash/lodash/commit/fe8d32eda854377349a4f922ab7655c8e5df9a0b"><code>fe8d32e</code></a>
    fix: block prototype pollution in baseUnset via constructor/prototype
    traversal</li>
    <li><a
    href="https://github.com/lodash/lodash/commit/18ba0a32f42fd02117f096b032f89c984173462d"><code>18ba0a3</code></a>
    refactor(fromPairs): use baseAssignValue for consistent assignment (<a
    href="https://redirect.github.com/lodash/lodash/issues/6153">#6153</a>)</li>
    <li><a
    href="https://github.com/lodash/lodash/commit/b8190803d48d60b8c80ad45d39125f32fa618cb2"><code>b819080</code></a>
    ci: add dist sync validation workflow (<a
    href="https://redirect.github.com/lodash/lodash/issues/6137">#6137</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/lodash/lodash/compare/4.17.23...4.18.1">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=lodash&package-manager=npm_and_yarn&previous-version=4.17.23&new-version=4.18.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the
    [Security Alerts
    page](https://github.com/deeplay-io/nice-grpc/network/alerts).
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Apr 12, 2026
    Configuration menu
    Copy the full SHA
    4fe9bd9 View commit details
    Browse the repository at this point in the history
  3. chore(deps): bump fast-xml-parser from 4.5.4 to 4.5.6 (#865)

    Bumps
    [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser)
    from 4.5.4 to 4.5.6.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/NaturalIntelligence/fast-xml-parser/releases">fast-xml-parser's
    releases</a>.</em></p>
    <blockquote>
    <h2>Summary update on all the previous releases from v4.2.4</h2>
    <ul>
    <li>Multiple minor fixes provided in the validator and parser</li>
    <li>v6 is added for experimental use.</li>
    <li>ignoreAttributes support function, and array of string or regex</li>
    <li>Add support for parsing HTML numeric entities</li>
    <li>v5 of the application is ESM module now. However, JS is also
    supported</li>
    </ul>
    <p><strong>Note</strong>: Release section in not updated frequently.
    Please check <a
    href="https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md">CHANGELOG</a>
    or <a
    href="https://github.com/NaturalIntelligence/fast-xml-parser/tags">Tags</a>
    for latest release information.</p>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/NaturalIntelligence/fast-xml-parser/commit/42fbb0bc95e753e03fe52cb0805a8774bba4bf28"><code>42fbb0b</code></a>
    update release info</li>
    <li><a
    href="https://github.com/NaturalIntelligence/fast-xml-parser/commit/805671cb6c19108b171b876cf3e8865f18cdb8fd"><code>805671c</code></a>
    increase expansion limit as many system need it</li>
    <li><a
    href="https://github.com/NaturalIntelligence/fast-xml-parser/commit/9a2cf097c2961d4ad878f618e39fb0a9f5a0e9e5"><code>9a2cf09</code></a>
    update version</li>
    <li><a
    href="https://github.com/NaturalIntelligence/fast-xml-parser/commit/88d0936a23dabe51bfbf42255e2ce912dfee2221"><code>88d0936</code></a>
    apply all fixes from v5</li>
    <li><a
    href="https://github.com/NaturalIntelligence/fast-xml-parser/commit/d4eb6b4713a8d11e6730943392419040898ecbc0"><code>d4eb6b4</code></a>
    update release version</li>
    <li><a
    href="https://github.com/NaturalIntelligence/fast-xml-parser/commit/b1b9f633ff30cb4708337355c2789f08bc0558d2"><code>b1b9f63</code></a>
    update release info</li>
    <li><a
    href="https://github.com/NaturalIntelligence/fast-xml-parser/commit/faccca126e1db96b90084adda6fbe2ea2ed434e7"><code>faccca1</code></a>
    sync with v5.3.9</li>
    <li>See full diff in <a
    href="https://github.com/NaturalIntelligence/fast-xml-parser/compare/v4.5.4...v4.5.6">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fast-xml-parser&package-manager=npm_and_yarn&previous-version=4.5.4&new-version=4.5.6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the
    [Security Alerts
    page](https://github.com/deeplay-io/nice-grpc/network/alerts).
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Apr 12, 2026
    Configuration menu
    Copy the full SHA
    56d3995 View commit details
    Browse the repository at this point in the history
  4. chore(deps-dev): bump glob from 11.1.0 to 13.0.6 (#864)

    Bumps [glob](https://github.com/isaacs/node-glob) from 11.1.0 to 13.0.6.
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/isaacs/node-glob/blob/main/changelog.md">glob's
    changelog</a>.</em></p>
    <blockquote>
    <h1>changeglob</h1>
    <h2>13</h2>
    <ul>
    <li>Move the CLI program out to a separate package,
    <code>glob-bin</code>.
    Install that if you'd like to continue using glob from the
    command line.</li>
    </ul>
    <h2>12</h2>
    <ul>
    <li>Remove the unsafe <code>--shell</code> option. The
    <code>--shell</code> option is now
    ONLY supported on known shells where the behavior can be
    implemented safely.</li>
    </ul>
    <h2>11.1</h2>
    <p><a
    href="https://github.com/isaacs/node-glob/security/advisories/GHSA-5j98-mcp5-4vw2">GHSA-5j98-mcp5-4vw2</a></p>
    <ul>
    <li>Add the <code>--shell</code> option for the command line, with a
    warning
    that this is unsafe. (It will be removed in v12.)</li>
    <li>Add the <code>--cmd-arg</code>/<code>-g</code> as a way to
    <em>safely</em> add positional
    arguments to the command provided to the CLI tool.</li>
    <li>Detect commands with space or quote characters on known shells,
    and pass positional arguments to them safely, avoiding
    <code>shell:true</code> execution.</li>
    </ul>
    <h2>11.0</h2>
    <ul>
    <li>Drop support for node before v20</li>
    </ul>
    <h2>10.4</h2>
    <ul>
    <li>Add <code>includeChildMatches: false</code> option</li>
    <li>Export the <code>Ignore</code> class</li>
    </ul>
    <h2>10.3</h2>
    <ul>
    <li>Add <code>--default -p</code> flag to provide a default pattern</li>
    <li>exclude symbolic links to directories when <code>follow</code> and
    <code>nodir</code>
    are both set</li>
    </ul>
    <h2>10.2</h2>
    <ul>
    <li>Add glob cli</li>
    </ul>
    <h2>10.1</h2>
    <ul>
    <li>Return <code>'.'</code> instead of the empty string <code>''</code>
    when the current
    working directory is returned as a match.</li>
    <li>Add <code>posix: true</code> option to return <code>/</code>
    delimited paths, even on</li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/isaacs/node-glob/commit/e80cb38ae60d6cbff9e75f39032a994858994d35"><code>e80cb38</code></a>
    13.0.6</li>
    <li><a
    href="https://github.com/isaacs/node-glob/commit/9cdbbfff75c64fb158c8842d4d0eb3e908676a41"><code>9cdbbff</code></a>
    revert tsgo, not ready for test coverage correctness yet</li>
    <li><a
    href="https://github.com/isaacs/node-glob/commit/89c99ba8e276438b8e31ce878b63186e2cd375b4"><code>89c99ba</code></a>
    use tsgo compiler</li>
    <li><a
    href="https://github.com/isaacs/node-glob/commit/b7275d54f294174607f544acf07cc7ec526b7878"><code>b7275d5</code></a>
    update deps, expand engines to include node 18</li>
    <li><a
    href="https://github.com/isaacs/node-glob/commit/942e360a669e0c378c0abd261e7d329ca2cee661"><code>942e360</code></a>
    update workflows, pull taprc out of package.json</li>
    <li><a
    href="https://github.com/isaacs/node-glob/commit/4a0d53c7531f3f0df97f9e4d26c78489e7f6d7ef"><code>4a0d53c</code></a>
    update tap for mockImport bugfix</li>
    <li><a
    href="https://github.com/isaacs/node-glob/commit/ef94ad2696c12129628208cf4e38575e7240c1c4"><code>ef94ad2</code></a>
    update tap</li>
    <li><a
    href="https://github.com/isaacs/node-glob/commit/180c2d43cb135f134c0c5446408dc107c79a5a9b"><code>180c2d4</code></a>
    update docs</li>
    <li><a
    href="https://github.com/isaacs/node-glob/commit/37993c86faddcb780458b2d7ae3c2ead7a84bf31"><code>37993c8</code></a>
    remove stray console.error in test</li>
    <li><a
    href="https://github.com/isaacs/node-glob/commit/03ae4c244cac6331817158b0bc12effd30deeb43"><code>03ae4c2</code></a>
    13.0.5</li>
    <li>Additional commits viewable in <a
    href="https://github.com/isaacs/node-glob/compare/v11.1.0...v13.0.6">compare
    view</a></li>
    </ul>
    </details>
    <details>
    <summary>Maintainer changes</summary>
    <p>This version was pushed to npm by <a
    href="https://www.npmjs.com/~isaacs">isaacs</a>, a new releaser for glob
    since your current version.</p>
    </details>
    <details>
    <summary>Install script changes</summary>
    <p>This version adds <code>prepare</code> script that runs during
    installation. Review the package contents before updating.</p>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=glob&package-manager=npm_and_yarn&previous-version=11.1.0&new-version=13.0.6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Apr 12, 2026
    Configuration menu
    Copy the full SHA
    8b36d77 View commit details
    Browse the repository at this point in the history
  5. chore(deps-dev): bump expect from 29.7.0 to 30.3.0 (#863)

    Bumps [expect](https://github.com/jestjs/jest/tree/HEAD/packages/expect)
    from 29.7.0 to 30.3.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/jestjs/jest/releases">expect's
    releases</a>.</em></p>
    <blockquote>
    <h2>v30.3.0</h2>
    <h3>Features</h3>
    <ul>
    <li><code>[jest-config]</code> Add <code>defineConfig</code> and
    <code>mergeConfig</code> helpers for type-safe Jest config (<a
    href="https://redirect.github.com/jestjs/jest/pull/15844">#15844</a>)</li>
    <li><code>[jest-fake-timers]</code> Add <code>setTimerTickMode</code> to
    configure how timers advance</li>
    <li><code>[*]</code> Reduce token usage when run through LLMs (<a
    href="https://github.com/jestjs/jest/commit/3f17932061c0203999451e5852664093de876709"><code>3f17932</code></a>)</li>
    </ul>
    <h3>Fixes</h3>
    <ul>
    <li><code>[jest-config]</code> Keep CLI coverage output when using
    <code>--json</code> with <code>--outputFile</code> (<a
    href="https://redirect.github.com/jestjs/jest/pull/15918">#15918</a>)</li>
    <li><code>[jest-mock]</code> Use <code>Symbol</code> from test
    environment (<a
    href="https://redirect.github.com/jestjs/jest/pull/15858">#15858</a>)</li>
    <li><code>[jest-reporters]</code> Fix issue where console output not
    displayed for GHA reporter even with <code>silent: false</code> option
    (<a
    href="https://redirect.github.com/jestjs/jest/pull/15864">#15864</a>)</li>
    <li><code>[jest-runtime]</code> Fix issue where user cannot utilize
    dynamic import despite specifying <code>--experimental-vm-modules</code>
    Node option (<a
    href="https://redirect.github.com/jestjs/jest/pull/15842">#15842</a>)</li>
    <li><code>[jest-test-sequencer]</code> Fix issue where failed tests due
    to compilation errors not getting re-executed even with
    <code>--onlyFailures</code> CLI option (<a
    href="https://redirect.github.com/jestjs/jest/pull/15851">#15851</a>)</li>
    <li><code>[jest-util]</code> Make sure
    <code>process.features.require_module</code> is <code>false</code> (<a
    href="https://redirect.github.com/jestjs/jest/pull/15867">#15867</a>)</li>
    </ul>
    <h3>Chore &amp; Maintenance</h3>
    <ul>
    <li><code>[*]</code> Replace remaining micromatch uses with
    picomatch</li>
    <li><code>[deps]</code> Update to sinon/fake-timers v15</li>
    <li><code>[docs]</code> Update V30 migration guide to notify users on
    <code>jest.mock()</code> work with case-sensitive path (<a
    href="https://redirect.github.com/jestjs/jest/pull/15849">#15849</a>)</li>
    <li>Updated Twitter icon to match the latest brand guidelines (<a
    href="https://redirect.github.com/jestjs/jest/pull/15869">#15869</a>)</li>
    </ul>
    <h2>30.2.0</h2>
    <h3>Chore &amp; Maintenance</h3>
    <ul>
    <li><code>[*]</code> Update example repo for testing React Native
    projects (<a
    href="https://redirect.github.com/jestjs/jest/pull/15832">#15832</a>)</li>
    <li><code>[*]</code> Update <code>jest-watch-typeahead</code> to v3 (<a
    href="https://redirect.github.com/jestjs/jest/pull/15830">#15830</a>)</li>
    </ul>
    <h2>Features</h2>
    <ul>
    <li><code>[jest-environment-jsdom-abstract]</code> Add support for JSDOM
    v27 (<a
    href="https://redirect.github.com/jestjs/jest/pull/15834">#15834</a>)</li>
    </ul>
    <h3>Fixes</h3>
    <ul>
    <li><code>[babel-jest]</code> Export the <code>TransformerConfig</code>
    interface (<a
    href="https://redirect.github.com/jestjs/jest/pull/15820">#15820</a>)</li>
    <li><code>[jest-config]</code> Fix <code>jest.config.ts</code> with TS
    loader specified in docblock pragma (<a
    href="https://redirect.github.com/jestjs/jest/pull/15839">#15839</a>)</li>
    </ul>
    <h2>30.1.3</h2>
    <h3>Fixes</h3>
    <ul>
    <li>Fix <code>unstable_mockModule</code> with <code>node:</code>
    prefixed core modules.</li>
    </ul>
    <h2>30.1.2</h2>
    <h3>Fixes</h3>
    <ul>
    <li><code>[jest-snapshot-utils]</code> Correct snapshot header regexp to
    work with newline across OSes (<a
    href="https://redirect.github.com/jestjs/jest/pull/15803">#15803</a>)</li>
    </ul>
    <h2>30.1.1</h2>
    <h3>Fixes</h3>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/jestjs/jest/blob/main/CHANGELOG.md">expect's
    changelog</a>.</em></p>
    <blockquote>
    <h2>30.3.0</h2>
    <h3>Features</h3>
    <ul>
    <li><code>[jest-config]</code> Add <code>defineConfig</code> and
    <code>mergeConfig</code> helpers for type-safe Jest config (<a
    href="https://redirect.github.com/jestjs/jest/pull/15844">#15844</a>)</li>
    <li><code>[jest-fake-timers]</code> Add <code>setTimerTickMode</code> to
    configure how timers advance</li>
    <li><code>[*]</code> Reduce token usage when run through LLMs (<a
    href="https://github.com/jestjs/jest/commit/3f17932061c0203999451e5852664093de876709"><code>3f17932</code></a>)</li>
    </ul>
    <h3>Fixes</h3>
    <ul>
    <li><code>[jest-config]</code> Keep CLI coverage output when using
    <code>--json</code> with <code>--outputFile</code> (<a
    href="https://redirect.github.com/jestjs/jest/pull/15918">#15918</a>)</li>
    <li><code>[jest-mock]</code> Use <code>Symbol</code> from test
    environment (<a
    href="https://redirect.github.com/jestjs/jest/pull/15858">#15858</a>)</li>
    <li><code>[jest-reporters]</code> Fix issue where console output not
    displayed for GHA reporter even with <code>silent: false</code> option
    (<a
    href="https://redirect.github.com/jestjs/jest/pull/15864">#15864</a>)</li>
    <li><code>[jest-runtime]</code> Fix issue where user cannot utilize
    dynamic import despite specifying <code>--experimental-vm-modules</code>
    Node option (<a
    href="https://redirect.github.com/jestjs/jest/pull/15842">#15842</a>)</li>
    <li><code>[jest-test-sequencer]</code> Fix issue where failed tests due
    to compilation errors not getting re-executed even with
    <code>--onlyFailures</code> CLI option (<a
    href="https://redirect.github.com/jestjs/jest/pull/15851">#15851</a>)</li>
    <li><code>[jest-util]</code> Make sure
    <code>process.features.require_module</code> is <code>false</code> (<a
    href="https://redirect.github.com/jestjs/jest/pull/15867">#15867</a>)</li>
    </ul>
    <h3>Chore &amp; Maintenance</h3>
    <ul>
    <li><code>[*]</code> Replace remaining micromatch uses with
    picomatch</li>
    <li><code>[deps]</code> Update to sinon/fake-timers v15</li>
    <li><code>[docs]</code> Update V30 migration guide to notify users on
    <code>jest.mock()</code> work with case-sensitive path (<a
    href="https://redirect.github.com/jestjs/jest/pull/15849">#15849</a>)</li>
    <li>Updated Twitter icon to match the latest brand guidelines (<a
    href="https://redirect.github.com/jestjs/jest/pull/15869">#15869</a>)</li>
    </ul>
    <h2>30.2.0</h2>
    <h3>Chore &amp; Maintenance</h3>
    <ul>
    <li><code>[*]</code> Update example repo for testing React Native
    projects (<a
    href="https://redirect.github.com/jestjs/jest/pull/15832">#15832</a>)</li>
    <li><code>[*]</code> Update <code>jest-watch-typeahead</code> to v3 (<a
    href="https://redirect.github.com/jestjs/jest/pull/15830">#15830</a>)</li>
    </ul>
    <h2>Features</h2>
    <ul>
    <li><code>[jest-environment-jsdom-abstract]</code> Add support for JSDOM
    v27 (<a
    href="https://redirect.github.com/jestjs/jest/pull/15834">#15834</a>)</li>
    </ul>
    <h3>Fixes</h3>
    <ul>
    <li><code>[jest-matcher-utils]</code> Fix infinite recursion with
    self-referential getters in <code>deepCyclicCopyReplaceable</code> (<a
    href="https://redirect.github.com/jestjs/jest/pull/15831">#15831</a>)</li>
    <li><code>[babel-jest]</code> Export the <code>TransformerConfig</code>
    interface (<a
    href="https://redirect.github.com/jestjs/jest/pull/15820">#15820</a>)</li>
    <li><code>[jest-config]</code> Fix <code>jest.config.ts</code> with TS
    loader specified in docblock pragma (<a
    href="https://redirect.github.com/jestjs/jest/pull/15839">#15839</a>)</li>
    </ul>
    <h2>30.1.3</h2>
    <h3>Fixes</h3>
    <ul>
    <li>Fix <code>unstable_mockModule</code> with <code>node:</code>
    prefixed core modules.</li>
    </ul>
    <h2>30.1.2</h2>
    <h3>Fixes</h3>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/jestjs/jest/commit/efb59c2e81083f8dc941f20d6d20a3af2dc8d068"><code>efb59c2</code></a>
    v30.3.0</li>
    <li><a
    href="https://github.com/jestjs/jest/commit/f7fb2ec8fa55d0fe333950327d9921bdfaad9f46"><code>f7fb2ec</code></a>
    chore: update TSTyche to v5 (<a
    href="https://github.com/jestjs/jest/tree/HEAD/packages/expect/issues/15929">#15929</a>)</li>
    <li><a
    href="https://github.com/jestjs/jest/commit/61bb2eb1d95d86373ab62d39391378c183c5450f"><code>61bb2eb</code></a>
    chore: update &quot;vulnerable&quot; dependencies (<a
    href="https://github.com/jestjs/jest/tree/HEAD/packages/expect/issues/15915">#15915</a>)</li>
    <li><a
    href="https://github.com/jestjs/jest/commit/706871255a32c133c6e2df6f6ebbf302f5678f6f"><code>7068712</code></a>
    fix: prevent infinite recursion with self-referential getters (<a
    href="https://github.com/jestjs/jest/tree/HEAD/packages/expect/issues/15822">#15822</a>)
    (<a
    href="https://github.com/jestjs/jest/tree/HEAD/packages/expect/issues/15831">#15831</a>)</li>
    <li><a
    href="https://github.com/jestjs/jest/commit/855864e3f9751366455246790be2bf912d4d0dac"><code>855864e</code></a>
    v30.2.0</li>
    <li><a
    href="https://github.com/jestjs/jest/commit/ebfa31cc9787303e8698a1a029a162a18e8974aa"><code>ebfa31c</code></a>
    v30.1.2</li>
    <li><a
    href="https://github.com/jestjs/jest/commit/d347c0f3f87f976a1dbd9761d503e45f5ced2a7e"><code>d347c0f</code></a>
    v30.1.1</li>
    <li><a
    href="https://github.com/jestjs/jest/commit/4d5f41d0885c1d9630c81b4fd47f74ab0615e18f"><code>4d5f41d</code></a>
    v30.1.0</li>
    <li><a
    href="https://github.com/jestjs/jest/commit/5884e4a632d3c1342744fc3b6f8642ac96de4756"><code>5884e4a</code></a>
    chore(expect): update docblock for <code>toContain()</code> to display
    info on substring...</li>
    <li><a
    href="https://github.com/jestjs/jest/commit/22236cf58b66039f81893537c90dee290bab427f"><code>22236cf</code></a>
    v30.0.5</li>
    <li>Additional commits viewable in <a
    href="https://github.com/jestjs/jest/commits/v30.3.0/packages/expect">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=expect&package-manager=npm_and_yarn&previous-version=29.7.0&new-version=30.3.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Apr 12, 2026
    Configuration menu
    Copy the full SHA
    486f307 View commit details
    Browse the repository at this point in the history
  6. chore(deps-dev): bump @wdio/spec-reporter from 9.12.6 to 9.27.0 (#862)

    Bumps
    [@wdio/spec-reporter](https://github.com/webdriverio/webdriverio/tree/HEAD/packages/wdio-spec-reporter)
    from 9.12.6 to 9.27.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/webdriverio/webdriverio/releases"><code>@​wdio/spec-reporter</code>'s
    releases</a>.</em></p>
    <blockquote>
    <h2>v9.27.0 (2026-03-23)</h2>
    <h4>:bug: Bug Fix</h4>
    <ul>
    <li><code>wdio-appium-service</code>
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15155">#15155</a>
    fix(appium-service): fix startup failure caused by Appium stderr log
    output (<a
    href="https://github.com/wswebcreation"><code>@​wswebcreation</code></a>)</li>
    </ul>
    </li>
    <li><code>wdio-globals</code>
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15135">#15135</a>
    fix: TypeScript 7 compatibility (<a
    href="https://github.com/mscrivo"><code>@​mscrivo</code></a>)</li>
    </ul>
    </li>
    <li><code>wdio-protocols</code>, <code>webdriverio</code>
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15159">#15159</a>
    fix(webdriverio): revert queryAppState protocol rename and remove mobile
    command wrapper (<a
    href="https://github.com/wswebcreation"><code>@​wswebcreation</code></a>)</li>
    </ul>
    </li>
    </ul>
    <h4>Committers: 2</h4>
    <ul>
    <li>Michael Scrivo (<a
    href="https://github.com/mscrivo"><code>@​mscrivo</code></a>)</li>
    <li>Wim Selles (<a
    href="https://github.com/wswebcreation"><code>@​wswebcreation</code></a>)</li>
    </ul>
    <h2>v9.26.1 (2026-03-15)</h2>
    <h4>:bug: Bug Fix</h4>
    <ul>
    <li><code>webdriverio</code>
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15154">#15154</a>
    fix(webdriverio): fix mobile command argument mismatches for Appium 3
    compatibility (<a
    href="https://github.com/wswebcreation"><code>@​wswebcreation</code></a>)</li>
    </ul>
    </li>
    </ul>
    <h4>Committers: 1</h4>
    <ul>
    <li>Wim Selles (<a
    href="https://github.com/wswebcreation"><code>@​wswebcreation</code></a>)</li>
    </ul>
    <h2>v9.26.0 (2026-03-15)</h2>
    <h4>:rocket: New Feature</h4>
    <ul>
    <li>
    <p><code>wdio-protocols</code>, <code>webdriver</code>,
    <code>webdriverio</code></p>
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15141">#15141</a>
    fix(appium): rename deprecated Appium protocol commands for Appium 3
    compatibility (<a
    href="https://github.com/wswebcreation"><code>@​wswebcreation</code></a>)</li>
    </ul>
    </li>
    <li>
    <p><code>eslint-plugin-wdio</code></p>
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15151">#15151</a>
    feat(eslint-plugin-wdio): Following eslint v9 plugin specification (<a
    href="https://github.com/dprevost-LMI"><code>@​dprevost-LMI</code></a>)</li>
    </ul>
    </li>
    </ul>
    <h4>:house: Internal</h4>
    <ul>
    <li>Ohter
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/14953">#14953</a>
    fix: Upgrade expect-webdriverio to 5.6.5 (<a
    href="https://github.com/dprevost-LMI"><code>@​dprevost-LMI</code></a>)</li>
    </ul>
    </li>
    </ul>
    <h4>Committers: 2</h4>
    <ul>
    <li>David Prevost (<a
    href="https://github.com/dprevost-LMI"><code>@​dprevost-LMI</code></a>)</li>
    <li>Wim Selles (<a
    href="https://github.com/wswebcreation"><code>@​wswebcreation</code></a>)</li>
    </ul>
    <h2>v9.25.0 (2026-03-10)</h2>
    <h4>:rocket: New Feature</h4>
    <ul>
    <li><code>eslint-plugin-wdio</code>
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15084">#15084</a>
    feat: Use no floating promise eslint rule for missing <code>await</code>
    (<a
    href="https://github.com/dprevost-LMI"><code>@​dprevost-LMI</code></a>)</li>
    </ul>
    </li>
    </ul>
    <h4>:bug: Bug Fix</h4>
    <ul>
    <li><code>wdio-browserstack-service</code>
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15117">#15117</a>
    fix: update exit signal for CLI process termination on Unix systems (<a
    href="https://github.com/xxshubhamxx"><code>@​xxshubhamxx</code></a>)</li>
    </ul>
    </li>
    <li><code>webdriverio</code></li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/webdriverio/webdriverio/blob/main/CHANGELOG.md"><code>@​wdio/spec-reporter</code>'s
    changelog</a>.</em></p>
    <blockquote>
    <h2>v9.27.0 (2026-03-23)</h2>
    <h4>:bug: Bug Fix</h4>
    <ul>
    <li><code>wdio-appium-service</code>
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15155">#15155</a>
    fix(appium-service): fix startup failure caused by Appium stderr log
    output (<a
    href="https://github.com/wswebcreation"><code>@​wswebcreation</code></a>)</li>
    </ul>
    </li>
    <li><code>wdio-globals</code>
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15135">#15135</a>
    fix: TypeScript 7 compatibility (<a
    href="https://github.com/mscrivo"><code>@​mscrivo</code></a>)</li>
    </ul>
    </li>
    <li><code>wdio-protocols</code>, <code>webdriverio</code>
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15159">#15159</a>
    fix(webdriverio): revert queryAppState protocol rename and remove mobile
    command wrapper (<a
    href="https://github.com/wswebcreation"><code>@​wswebcreation</code></a>)</li>
    </ul>
    </li>
    </ul>
    <h4>Committers: 2</h4>
    <ul>
    <li>Michael Scrivo (<a
    href="https://github.com/mscrivo"><code>@​mscrivo</code></a>)</li>
    <li>Wim Selles (<a
    href="https://github.com/wswebcreation"><code>@​wswebcreation</code></a>)</li>
    </ul>
    <h2>v9.26.1 (2026-03-15)</h2>
    <h4>:bug: Bug Fix</h4>
    <ul>
    <li><code>webdriverio</code>
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15154">#15154</a>
    fix(webdriverio): fix mobile command argument mismatches for Appium 3
    compatibility (<a
    href="https://github.com/wswebcreation"><code>@​wswebcreation</code></a>)</li>
    </ul>
    </li>
    </ul>
    <h4>Committers: 1</h4>
    <ul>
    <li>Wim Selles (<a
    href="https://github.com/wswebcreation"><code>@​wswebcreation</code></a>)</li>
    </ul>
    <h2>v9.26.0 (2026-03-15)</h2>
    <h4>:rocket: New Feature</h4>
    <ul>
    <li><code>wdio-protocols</code>, <code>webdriver</code>,
    <code>webdriverio</code>
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15141">#15141</a>
    fix(appium): rename deprecated Appium protocol commands for Appium 3
    compatibility (<a
    href="https://github.com/wswebcreation"><code>@​wswebcreation</code></a>)</li>
    </ul>
    </li>
    </ul>
    <h4>Committers: 2</h4>
    <ul>
    <li>David Prevost (<a
    href="https://github.com/dprevost-LMI"><code>@​dprevost-LMI</code></a>)</li>
    <li>Wim Selles (<a
    href="https://github.com/wswebcreation"><code>@​wswebcreation</code></a>)</li>
    </ul>
    <h2>v9.25.0 (2026-03-10)</h2>
    <h4>:rocket: New Feature</h4>
    <ul>
    <li><code>eslint-plugin-wdio</code>
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15084">#15084</a>
    feat: Use no floating promise eslint rule for missing <code>await</code>
    (<a
    href="https://github.com/dprevost-LMI"><code>@​dprevost-LMI</code></a>)</li>
    </ul>
    </li>
    </ul>
    <h4>:bug: Bug Fix</h4>
    <ul>
    <li><code>wdio-browserstack-service</code>
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15117">#15117</a>
    fix: update exit signal for CLI process termination on Unix systems (<a
    href="https://github.com/xxshubhamxx"><code>@​xxshubhamxx</code></a>)</li>
    </ul>
    </li>
    <li><code>webdriverio</code>
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15098">#15098</a>
    fix: Ensure getValue returns a string (<a
    href="https://github.com/dprevost-LMI"><code>@​dprevost-LMI</code></a>)</li>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15131">#15131</a>
    fix(webdriverio): ignore 'no such frame' error in handleUserPrompt (#…
    (<a
    href="https://github.com/mccmrunal"><code>@​mccmrunal</code></a>)</li>
    </ul>
    </li>
    <li><code>wdio-junit-reporter</code>
    <ul>
    <li><a
    href="https://redirect.github.com/webdriverio/webdriverio/pull/15133">#15133</a>
    fix(wdio-junit-reporter): correctly detect Cucumber framework in mult…
    (<a
    href="https://github.com/mccmrunal"><code>@​mccmrunal</code></a>)</li>
    </ul>
    </li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/webdriverio/webdriverio/commit/0149a736235a2fb00f84a50652193bb92c24cd8f"><code>0149a73</code></a>
    v9.26.1</li>
    <li><a
    href="https://github.com/webdriverio/webdriverio/commit/974fb5ead9fe6738af6f5e2306224036de552f33"><code>974fb5e</code></a>
    v9.26.0</li>
    <li><a
    href="https://github.com/webdriverio/webdriverio/commit/1352571ae8709a895c223973f1840f38d8530f4a"><code>1352571</code></a>
    v9.25.0</li>
    <li><a
    href="https://github.com/webdriverio/webdriverio/commit/504e648c88b9660ec70fa8247c25e46369768fd9"><code>504e648</code></a>
    v9.24.0</li>
    <li><a
    href="https://github.com/webdriverio/webdriverio/commit/ae97a13a6f03d0d6c988beb56ec822473fa61c62"><code>ae97a13</code></a>
    v9.23.3</li>
    <li><a
    href="https://github.com/webdriverio/webdriverio/commit/3447f2744e52b367ad1164ff6a920924d830e4ee"><code>3447f27</code></a>
    v9.23.2</li>
    <li><a
    href="https://github.com/webdriverio/webdriverio/commit/19ac2c1dd86f3bdd967bc6c22c5bcdd78907b988"><code>19ac2c1</code></a>
    v9.23.1</li>
    <li><a
    href="https://github.com/webdriverio/webdriverio/commit/6c8694a72b8e173ecdd20dacae5d49d089b2877c"><code>6c8694a</code></a>
    v9.20.0</li>
    <li><a
    href="https://github.com/webdriverio/webdriverio/commit/4ca46771777a0ef20bfd911fbd0da0904059fd9e"><code>4ca4677</code></a>
    v9.19.2</li>
    <li><a
    href="https://github.com/webdriverio/webdriverio/commit/df3ec33741d11d196adad148f4d066a3fcbcd51b"><code>df3ec33</code></a>
    v9.19.1</li>
    <li>Additional commits viewable in <a
    href="https://github.com/webdriverio/webdriverio/commits/v9.27.0/packages/wdio-spec-reporter">compare
    view</a></li>
    </ul>
    </details>
    <details>
    <summary>Maintainer changes</summary>
    <p>This version was pushed to npm by [GitHub Actions](<a
    href="https://www.npmjs.com/~GitHub">https://www.npmjs.com/~GitHub</a>
    Actions), a new releaser for <code>@​wdio/spec-reporter</code> since
    your current version.</p>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@wdio/spec-reporter&package-manager=npm_and_yarn&previous-version=9.12.6&new-version=9.27.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Apr 12, 2026
    Configuration menu
    Copy the full SHA
    9bb6a3d View commit details
    Browse the repository at this point in the history
  7. chore(deps): bump protobufjs from 7.5.4 to 8.0.0 (#860)

    Bumps [protobufjs](https://github.com/protobufjs/protobuf.js) from 7.5.4
    to 8.0.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/protobufjs/protobuf.js/releases">protobufjs's
    releases</a>.</em></p>
    <blockquote>
    <h2>protobufjs: v8.0.0</h2>
    <h2><a
    href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.4...protobufjs-v8.0.0">8.0.0</a>
    (2025-12-16)</h2>
    <h3>⚠ BREAKING CHANGES</h3>
    <ul>
    <li>add Edition 2024 Support (<a
    href="https://redirect.github.com/protobufjs/protobuf.js/issues/2060">#2060</a>)</li>
    </ul>
    <h3>Features</h3>
    <ul>
    <li>add Edition 2024 Support (<a
    href="https://redirect.github.com/protobufjs/protobuf.js/issues/2060">#2060</a>)
    (<a
    href="https://github.com/protobufjs/protobuf.js/commit/53e8492cbaae2c741801fa50b5f908ff5129c3d7">53e8492</a>)</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/protobufjs/protobuf.js/blob/master/CHANGELOG.md">protobufjs's
    changelog</a>.</em></p>
    <blockquote>
    <h2><a
    href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.4...protobufjs-v8.0.0">8.0.0</a>
    (2025-12-16)</h2>
    <h3>⚠ BREAKING CHANGES</h3>
    <ul>
    <li>add Edition 2024 Support (<a
    href="https://redirect.github.com/protobufjs/protobuf.js/issues/2060">#2060</a>)</li>
    </ul>
    <h3>Features</h3>
    <ul>
    <li>add Edition 2024 Support (<a
    href="https://redirect.github.com/protobufjs/protobuf.js/issues/2060">#2060</a>)
    (<a
    href="https://github.com/protobufjs/protobuf.js/commit/53e8492cbaae2c741801fa50b5f908ff5129c3d7">53e8492</a>)</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/protobufjs/protobuf.js/commit/933e8750dcd000c16a621a7344a4beaa034c4019"><code>933e875</code></a>
    chore: release master (<a
    href="https://redirect.github.com/protobufjs/protobuf.js/issues/2116">#2116</a>)</li>
    <li><a
    href="https://github.com/protobufjs/protobuf.js/commit/53e8492cbaae2c741801fa50b5f908ff5129c3d7"><code>53e8492</code></a>
    feat!: add Edition 2024 Support (<a
    href="https://redirect.github.com/protobufjs/protobuf.js/issues/2060">#2060</a>)</li>
    <li>See full diff in <a
    href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.4...protobufjs-v8.0.0">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=protobufjs&package-manager=npm_and_yarn&previous-version=7.5.4&new-version=8.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Apr 12, 2026
    Configuration menu
    Copy the full SHA
    463804b View commit details
    Browse the repository at this point in the history
  8. chore(deps): bump @opentelemetry/api from 1.9.0 to 1.9.1 (#858)

    Bumps
    [@opentelemetry/api](https://github.com/open-telemetry/opentelemetry-js)
    from 1.9.0 to 1.9.1.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/open-telemetry/opentelemetry-js/releases"><code>@​opentelemetry/api</code>'s
    releases</a>.</em></p>
    <blockquote>
    <h2>api/v1.9.1</h2>
    <h2>1.9.1</h2>
    <h3>:bug: (Bug Fix)</h3>
    <ul>
    <li>fix(api): prioritize <code>esnext</code> export condition as it is
    more specific <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/5458">#5458</a></li>
    <li>fix(api): update diag <code>consoleLogger</code> to use original
    console methods to prevent infinite loop when a console instrumentation
    is present <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6395">#6395</a></li>
    <li>fix(api): use <code>Attributes</code> instead of deprecated
    <code>SpanAttributes</code> in <code>SpanOptions</code> <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6478">#6478</a>
    <a
    href="https://github.com/overbalance"><code>@​overbalance</code></a></li>
    <li>fix(diag): change types in <code>DiagComponentLogger</code> from
    <code>any</code> to <code>unknown</code><a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/5478">#5478</a>
    <a
    href="https://github.com/loganrosen"><code>@​loganrosen</code></a></li>
    <li>fix(api): re-introduce fallback chain for global utils <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6523/">#6523</a>
    <a
    href="https://github.com/pichlermarc"><code>@​pichlermarc</code></a></li>
    </ul>
    <h3>:house: (Internal)</h3>
    <ul>
    <li>refactor(api): refactor to avoid circular deps by merging observable
    types into <code>Metric.ts</code> <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6441">#6441</a>
    <a
    href="https://github.com/pichlermarc"><code>@​pichlermarc</code></a></li>
    <li>refactor(api): remove &quot;export *&quot; in favor of explicit
    named exports <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/4880">#4880</a>
    <a href="https://github.com/robbkidd"><code>@​robbkidd</code></a></li>
    <li>chore: enable tsconfig isolatedModules <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/5697">#5697</a>
    <a
    href="https://github.com/legendecas"><code>@​legendecas</code></a></li>
    <li>chore: disallow constructor parameter property syntax <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6187">#6187</a>
    <a
    href="https://github.com/legendecas"><code>@​legendecas</code></a></li>
    <li>refactor(api): remove platform-specific globalThis, use globalThis
    directly <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6208">#6208</a>
    <a
    href="https://github.com/overbalance"><code>@​overbalance</code></a></li>
    <li>chore(api): mark ProxyTracerProvider as deprecated <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6328">#6328</a>
    <a href="https://github.com/cjihrig"><code>@​cjihrig</code></a></li>
    <li>chore: enforce <code>import type</code> for type-only imports via
    ESLint <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6467">#6467</a>
    <a
    href="https://github.com/overbalance"><code>@​overbalance</code></a></li>
    <li>perf(api): improve isValidSpanId, isValidTraceId performance <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/5714">#5714</a>
    <a href="https://github.com/seemk"><code>@​seemk</code></a></li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md"><code>@​opentelemetry/api</code>'s
    changelog</a>.</em></p>
    <blockquote>
    <h2>1.9.1</h2>
    <h3>:bug: (Bug Fix)</h3>
    <ul>
    <li>fix: avoid grpc types dependency <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/3551">#3551</a>
    <a href="https://github.com/flarna"><code>@​flarna</code></a></li>
    <li>fix(otlp-proto-exporter-base): Match Accept header with Content-Type
    in the proto exporter
    <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/3562">#3562</a>
    <a href="https://github.com/scheler"><code>@​scheler</code></a></li>
    <li>fix: include tracestate in export <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/3569">#3569</a>
    <a href="https://github.com/flarna"><code>@​flarna</code></a></li>
    </ul>
    <h3>:house: (Internal)</h3>
    <ul>
    <li>chore: fix cross project links and missing implicitly exported types
    <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/3533">#3533</a>
    <a
    href="https://github.com/legendecas"><code>@​legendecas</code></a></li>
    <li>feat(sdk-metrics): add exponential histogram mapping functions <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/3504">#3504</a>
    <a href="https://github.com/mwear"><code>@​mwear</code></a></li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/279458e7ddf16f7ddca5fe60c78672e05fafce66"><code>279458e</code></a>
    Release 1.9.1 / 0.35.1 (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/3573">#3573</a>)</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/49787433b66a17a1788a20f3a7edda3aa2580890"><code>4978743</code></a>
    fix(http): remove outgoing headers normalization (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/3557">#3557</a>)</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/d1f9594d0c691a0422c0d56fc8243d84c32324e2"><code>d1f9594</code></a>
    chore(deps): update dependency rimraf to v4 (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/3532">#3532</a>)</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/e0abcc0b3fe49545a7d0a62825e9f9399c178f60"><code>e0abcc0</code></a>
    fix: remove JSON syntax error and regenerate tsconfig files (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/3566">#3566</a>)</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/a90c558772e049d614f91c8046b60c49f3211de9"><code>a90c558</code></a>
    fix(sdk-node): register instrumentations early (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/3502">#3502</a>)</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/5b070b80a43f8c29ac1ea87f868b5ba01b11b0a3"><code>5b070b8</code></a>
    fix: include TraceState in trace exports (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/3569">#3569</a>)</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/dcb09b76d1013c8e8c18fcb7b34e73b876a716f9"><code>dcb09b7</code></a>
    chore(deps): update dependency gh-pages to v5 (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/3571">#3571</a>)</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/3bc93a9fa69ad5bcd32966d044781ee7f0eca496"><code>3bc93a9</code></a>
    feat: exponential histogram - part 1 - mapping functions (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/3504">#3504</a>)</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/3670071468f95ccc73bc2e89fe9d2415803ac3dc"><code>3670071</code></a>
    fix: avoid grpc types dependency (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/3551">#3551</a>)</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/b5ef0e4625ad7da67bde80dcb4aa451be98e665a"><code>b5ef0e4</code></a>
    chore: fix proto generation (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/3567">#3567</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/open-telemetry/opentelemetry-js/compare/v1.9.0...v1.9.1">compare
    view</a></li>
    </ul>
    </details>
    <details>
    <summary>Maintainer changes</summary>
    <p>This version was pushed to npm by [GitHub Actions](<a
    href="https://www.npmjs.com/~GitHub">https://www.npmjs.com/~GitHub</a>
    Actions), a new releaser for <code>@​opentelemetry/api</code> since your
    current version.</p>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@opentelemetry/api&package-manager=npm_and_yarn&previous-version=1.9.0&new-version=1.9.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Apr 12, 2026
    Configuration menu
    Copy the full SHA
    2058abd View commit details
    Browse the repository at this point in the history
  9. chore(deps): bump @bufbuild/protobuf from 2.7.0 to 2.11.0 (#857)

    [//]: # (dependabot-start)
    ⚠️  **Dependabot is rebasing this PR** ⚠️ 
    
    Rebasing might not happen immediately, so don't worry if this takes some
    time.
    
    Note: if you make any changes to this PR yourself, they will take
    precedence over the rebase.
    
    ---
    
    [//]: # (dependabot-end)
    
    Bumps
    [@bufbuild/protobuf](https://github.com/bufbuild/protobuf-es/tree/HEAD/packages/protobuf)
    from 2.7.0 to 2.11.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/bufbuild/protobuf-es/releases"><code>@​bufbuild/protobuf</code>'s
    releases</a>.</em></p>
    <blockquote>
    <h2>v2.11.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Support Bun by <a
    href="https://github.com/timostamm"><code>@​timostamm</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1343">bufbuild/protobuf-es#1343</a></li>
    <li>Add plugin option <code>elide_plugin_version=true</code> by <a
    href="https://github.com/timostamm"><code>@​timostamm</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1336">bufbuild/protobuf-es#1336</a></li>
    <li>Add tests for duplicate field ordering and unknown field errors when
    performing JSON deserialization by <a
    href="https://github.com/hudlow"><code>@​hudlow</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1132">bufbuild/protobuf-es#1132</a></li>
    <li>Remove dead branches for null handling in fromJson by <a
    href="https://github.com/hudlow"><code>@​hudlow</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1315">bufbuild/protobuf-es#1315</a></li>
    <li>Fix validation for FieldMask (de-)serialization to/from JSON by <a
    href="https://github.com/hudlow"><code>@​hudlow</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1323">bufbuild/protobuf-es#1323</a></li>
    <li>Cache field maps for fromJson() by <a
    href="https://github.com/hudlow"><code>@​hudlow</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1334">bufbuild/protobuf-es#1334</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/bufbuild/protobuf-es/compare/v2.10.2...v2.11.0">https://github.com/bufbuild/protobuf-es/compare/v2.10.2...v2.11.0</a></p>
    <h2>v2.10.2</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Update to protocolbuffers/protobuf v33.2 by <a
    href="https://github.com/timostamm"><code>@​timostamm</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1308">bufbuild/protobuf-es#1308</a></li>
    <li>Permit <code>google.protobuf.Value.null_value</code> in map values
    in ProtoJSON by <a
    href="https://github.com/timostamm"><code>@​timostamm</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1314">bufbuild/protobuf-es#1314</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/bufbuild/protobuf-es/compare/v2.10.1...v2.10.2">https://github.com/bufbuild/protobuf-es/compare/v2.10.1...v2.10.2</a></p>
    <h2>v2.10.1</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Update <code>@​typescript/vfs</code> to version 1.6.2 by <a
    href="https://github.com/Yovach"><code>@​Yovach</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1274">bufbuild/protobuf-es#1274</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/Yovach"><code>@​Yovach</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1274">bufbuild/protobuf-es#1274</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/bufbuild/protobuf-es/compare/v2.10.0...v2.10.1">https://github.com/bufbuild/protobuf-es/compare/v2.10.0...v2.10.1</a></p>
    <h2>v2.10.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Cache list of sorted fields in WeakMap by <a
    href="https://github.com/cptpcrd"><code>@​cptpcrd</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1240">bufbuild/protobuf-es#1240</a></li>
    <li>Add functions durationFromMS and durationMs by <a
    href="https://github.com/noahbald"><code>@​noahbald</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1244">bufbuild/protobuf-es#1244</a></li>
    <li>Add section for google.protobuf.Duration in MANUAL.md by <a
    href="https://github.com/timostamm"><code>@​timostamm</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1245">bufbuild/protobuf-es#1245</a></li>
    <li>Add additional checks to toJson for Timestamp and Duration by <a
    href="https://github.com/timostamm"><code>@​timostamm</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1263">bufbuild/protobuf-es#1263</a></li>
    <li>Fix nanos sign in durationFromMs() by <a
    href="https://github.com/timostamm"><code>@​timostamm</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1262">bufbuild/protobuf-es#1262</a></li>
    <li>Update to protocolbuffers/protobuf v33 by <a
    href="https://github.com/timostamm"><code>@​timostamm</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1270">bufbuild/protobuf-es#1270</a></li>
    <li>Add Deno example by <a
    href="https://github.com/timostamm"><code>@​timostamm</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1234">bufbuild/protobuf-es#1234</a></li>
    <li>Mention Deno in package README.md by <a
    href="https://github.com/timostamm"><code>@​timostamm</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1258">bufbuild/protobuf-es#1258</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/cptpcrd"><code>@​cptpcrd</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1240">bufbuild/protobuf-es#1240</a></li>
    <li><a href="https://github.com/noahbald"><code>@​noahbald</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1244">bufbuild/protobuf-es#1244</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/bufbuild/protobuf-es/compare/v2.9.0...v2.10.0">https://github.com/bufbuild/protobuf-es/compare/v2.9.0...v2.10.0</a></p>
    <h2>v2.9.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Support Deno by <a
    href="https://github.com/timostamm"><code>@​timostamm</code></a> in <a
    href="https://redirect.github.com/bufbuild/protobuf-es/pull/1233">bufbuild/protobuf-es#1233</a></li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/bufbuild/protobuf-es/commit/55c5eac9e7fedc19d22b040f655f8754b71cdeef"><code>55c5eac</code></a>
    Release 2.11.0 (<a
    href="https://github.com/bufbuild/protobuf-es/tree/HEAD/packages/protobuf/issues/1344">#1344</a>)</li>
    <li><a
    href="https://github.com/bufbuild/protobuf-es/commit/9abe2ec25da002c24200dd0f066a82db35e01eec"><code>9abe2ec</code></a>
    Cache field maps for fromJson() (<a
    href="https://github.com/bufbuild/protobuf-es/tree/HEAD/packages/protobuf/issues/1334">#1334</a>)</li>
    <li><a
    href="https://github.com/bufbuild/protobuf-es/commit/f7f28084ac97e53e05d1998314e3d3e08f37e5ee"><code>f7f2808</code></a>
    Fix validation for FieldMask (de-)serialization to/from JSON (<a
    href="https://github.com/bufbuild/protobuf-es/tree/HEAD/packages/protobuf/issues/1323">#1323</a>)</li>
    <li><a
    href="https://github.com/bufbuild/protobuf-es/commit/8a37beb958a880992b4990d9784d0867ce14ed97"><code>8a37beb</code></a>
    Update license year for 2026 (<a
    href="https://github.com/bufbuild/protobuf-es/tree/HEAD/packages/protobuf/issues/1333">#1333</a>)</li>
    <li><a
    href="https://github.com/bufbuild/protobuf-es/commit/f46353bb6d88617a1f766642550b6a4aaabaa7ec"><code>f46353b</code></a>
    Remove dead branches for null handling in fromJson (<a
    href="https://github.com/bufbuild/protobuf-es/tree/HEAD/packages/protobuf/issues/1315">#1315</a>)</li>
    <li><a
    href="https://github.com/bufbuild/protobuf-es/commit/b34f226ae49fa3b350ad22a929dbd05f28855fb2"><code>b34f226</code></a>
    Update documentation for lowerCamelCase field names (<a
    href="https://github.com/bufbuild/protobuf-es/tree/HEAD/packages/protobuf/issues/1332">#1332</a>)</li>
    <li><a
    href="https://github.com/bufbuild/protobuf-es/commit/05dab19d4fc53bcbc9a57da0095ab7013c9bfce2"><code>05dab19</code></a>
    Release v2.10.2 (<a
    href="https://github.com/bufbuild/protobuf-es/tree/HEAD/packages/protobuf/issues/1317">#1317</a>)</li>
    <li><a
    href="https://github.com/bufbuild/protobuf-es/commit/cedc585083b1d2b8ee4f49448aec68459a93816f"><code>cedc585</code></a>
    Permit google.protobuf.Value.null_value in map values in ProtoJSON (<a
    href="https://github.com/bufbuild/protobuf-es/tree/HEAD/packages/protobuf/issues/1314">#1314</a>)</li>
    <li><a
    href="https://github.com/bufbuild/protobuf-es/commit/16ac7567eb88f48a6abd5fe6b2bc1897452ccfc4"><code>16ac756</code></a>
    Update to protocolbuffers/protobuf v33.2 (<a
    href="https://github.com/bufbuild/protobuf-es/tree/HEAD/packages/protobuf/issues/1308">#1308</a>)</li>
    <li><a
    href="https://github.com/bufbuild/protobuf-es/commit/a2619ec35ee83f51f6571f7298f71bd1b72bf2b2"><code>a2619ec</code></a>
    Update to protocolbuffers/protobuf v33.1 (<a
    href="https://github.com/bufbuild/protobuf-es/tree/HEAD/packages/protobuf/issues/1293">#1293</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/bufbuild/protobuf-es/commits/v2.11.0/packages/protobuf">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@bufbuild/protobuf&package-manager=npm_and_yarn&previous-version=2.7.0&new-version=2.11.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Apr 12, 2026
    Configuration menu
    Copy the full SHA
    7a5aa82 View commit details
    Browse the repository at this point in the history
  10. chore(deps): bump @opentelemetry/semantic-conventions from 1.36.0 to …

    …1.40.0 (#856)
    
    Bumps
    [@opentelemetry/semantic-conventions](https://github.com/open-telemetry/opentelemetry-js)
    from 1.36.0 to 1.40.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/open-telemetry/opentelemetry-js/releases"><code>@​opentelemetry/semantic-conventions</code>'s
    releases</a>.</em></p>
    <blockquote>
    <h2>semconv/v1.40.0</h2>
    <h2>1.40.0</h2>
    <h3>:rocket: Features</h3>
    <ul>
    <li>feat: update semantic conventions to v1.40.0 <a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6438">#6438</a>
    <ul>
    <li>Semantic Conventions v1.40.0: <a
    href="https://github.com/open-telemetry/semantic-conventions/blob/main/CHANGELOG.md#v1400">changelog</a>
    | <a href="https://opentelemetry.io/docs/specs/semconv/">latest
    docs</a></li>
    <li><code>@opentelemetry/semantic-conventions</code> (stable) changes:
    <em>2 added exports</em></li>
    <li><code>@opentelemetry/semantic-conventions/incubating</code>
    (unstable) changes: <em>11 newly deprecated exports, 56 added
    exports</em></li>
    </ul>
    </li>
    </ul>
    <h4>Stable changes in v1.40.0</h4>
    <!-- raw HTML omitted -->
    <pre lang="js"><code>ATTR_SERVICE_INSTANCE_ID // service.instance.id
    ATTR_SERVICE_NAMESPACE   // service.namespace
    </code></pre>
    <!-- raw HTML omitted -->
    <h4>Unstable changes in v1.40.0</h4>
    <!-- raw HTML omitted -->
    <pre lang="js"><code>METRIC_RPC_CLIENT_REQUEST_SIZE //
    rpc.client.request.size: Removed, no replacement at this time.
    METRIC_RPC_CLIENT_RESPONSE_SIZE // rpc.client.response.size: Removed, no
    replacement at this time.
    METRIC_RPC_SERVER_REQUEST_SIZE // rpc.server.request.size: Removed, no
    replacement at this time.
    METRIC_RPC_SERVER_RESPONSE_SIZE // rpc.server.response.size: Removed, no
    replacement at this time.
    METRIC_SYSTEM_MEMORY_SHARED // system.memory.shared: Replaced by
    `system.memory.linux.shared`.
    EVENT_RPC_MESSAGE // rpc.message: Deprecated, no replacement at this
    time.
    ATTR_ERROR_MESSAGE // error.message: Use domain-specific error message
    attribute. For example, use `feature_flag.error.message` for feature
    flag errors.
    ATTR_RPC_MESSAGE_COMPRESSED_SIZE // rpc.message.compressed_size:
    Deprecated, no replacement at this time.
    ATTR_RPC_MESSAGE_ID // rpc.message.id: Deprecated, no replacement at
    this time.
    ATTR_RPC_MESSAGE_TYPE // rpc.message.type: Deprecated, no replacement at
    this time.
    ATTR_RPC_MESSAGE_UNCOMPRESSED_SIZE // rpc.message.uncompressed_size:
    Deprecated, no replacement at this time.
    </code></pre>
    <!-- raw HTML omitted -->
    <!-- raw HTML omitted -->
    <pre lang="js"><code>METRIC_JVM_FILE_DESCRIPTOR_LIMIT //
    jvm.file_descriptor.limit
    <p>METRIC_K8S_SERVICE_ENDPOINT_COUNT // k8s.service.endpoint.count
    &lt;/tr&gt;&lt;/table&gt;
    </code></pre></p>
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/661cd84a25b2cef68169e7ffa4b811cea7406a10"><code>661cd84</code></a>
    chore: update all license headers to SPDX short format (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6447">#6447</a>)</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/ed6bd6d5f3a1f68b65ae25b1a8aae9c285ae83de"><code>ed6bd6d</code></a>
    chore: prepare next release (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6448">#6448</a>)</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/636d1d0b516713fb37576737f6c78a2999f285cb"><code>636d1d0</code></a>
    feat(semantic-conventions): update semantic conventions to v1.40.0 (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6438">#6438</a>)</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/1bffafaf6cdcac297fea7363312be75a19b8f527"><code>1bffafa</code></a>
    fix(instrumentation-http): guard against double-instrumentation if
    loaded wit...</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/f7cd6ab6e2bc6224738b1e7dc78e53794cf64668"><code>f7cd6ab</code></a>
    refactor(api): refactor to avoid circular deps, add dpdm to lint step
    (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6441">#6441</a>)</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/bffd65f6ce9418b7c81c1f1678911d67b9248c98"><code>bffd65f</code></a>
    fix(deps): update dependency google-protobuf to v4 (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6411">#6411</a>)</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/8479a917b52d0ea431b8fb9588ea49722ff01db3"><code>8479a91</code></a>
    chore(deps): update dependency <code>@​types/jquery</code> to v3.5.34
    (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6443">#6443</a>)</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/99d6e15788c80bb0e73a942b7224aab3c5f02ac5"><code>99d6e15</code></a>
    fix(otlp-exporter-base): handle response error event (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6412">#6412</a>)</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/200cf9a9cdf0d93294d7b7e29fa241dd458e8ffd"><code>200cf9a</code></a>
    fix(api): Update DiagLogger to use original console methods (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6395">#6395</a>)</li>
    <li><a
    href="https://github.com/open-telemetry/opentelemetry-js/commit/b1beebbec9af4a21a8b267d6f5ed11cfce7ec0c2"><code>b1beebb</code></a>
    chore(deps): update github/codeql-action digest to 89a39a4 (<a
    href="https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6436">#6436</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/open-telemetry/opentelemetry-js/compare/semconv/v1.36.0...semconv/v1.40.0">compare
    view</a></li>
    </ul>
    </details>
    <details>
    <summary>Maintainer changes</summary>
    <p>This version was pushed to npm by [GitHub Actions](<a
    href="https://www.npmjs.com/~GitHub">https://www.npmjs.com/~GitHub</a>
    Actions), a new releaser for
    <code>@​opentelemetry/semantic-conventions</code> since your current
    version.</p>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@opentelemetry/semantic-conventions&package-manager=npm_and_yarn&previous-version=1.36.0&new-version=1.40.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Apr 12, 2026
    Configuration menu
    Copy the full SHA
    4ea5560 View commit details
    Browse the repository at this point in the history
  11. chore(deps): bump node-forge from 1.3.3 to 1.4.0 (#855)

    Bumps [node-forge](https://github.com/digitalbazaar/forge) from 1.3.3 to
    1.4.0.
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md">node-forge's
    changelog</a>.</em></p>
    <blockquote>
    <h2>1.4.0 - 2026-03-24</h2>
    <h3>Security</h3>
    <ul>
    <li><strong>HIGH</strong>: Denial of Service in
    <code>BigInteger.modInverse()</code>
    <ul>
    <li>A Denial of Service (DoS) vulnerability exists due to an infinite
    loop in
    the <code>BigInteger.modInverse()</code> function (inherited from the
    bundled jsbn
    library). When <code>modInverse()</code> is called with a zero value as
    input, the
    internal Extended Euclidean Algorithm enters an unreachable exit
    condition,
    causing the process to hang indefinitely and consume 100% CPU.</li>
    <li>Reported by Kr0emer.</li>
    <li>CVE ID: <a
    href="https://www.cve.org/CVERecord?id=CVE-2026-33891">CVE-2026-33891</a></li>
    <li>GHSA ID: <a
    href="https://github.com/digitalbazaar/forge/security/advisories/GHSA-5m6q-g25r-mvwx">GHSA-5gfm-wpxj-wjgq</a></li>
    </ul>
    </li>
    <li><strong>HIGH</strong>: Signature forgery in RSA-PKCS due to ASN.1
    extra field.
    <ul>
    <li>RSASSA PKCS#1 v1.5 signature verification accepts forged signatures
    for low
    public exponent keys (e=3). Attackers can forge signatures by stuffing
    &quot;garbage&quot; bytes within the ASN.1 structure in order to
    construct a
    signature that passes verification, enabling Bleichenbacher style
    forgery.
    This issue is similar to CVE-2022-24771, but adds bytes in an addition
    field within the ASN.1 structure, rather than outside of it.</li>
    <li>Additionally, forge does not validate that signatures include a
    minimum of
    8 bytes of padding as defined by the specification, providing attackers
    additional space to construct Bleichenbacher forgeries.</li>
    <li>Reported as part of a U.C. Berkeley security research project by:
    <ul>
    <li>Austin Chu, Sohee Kim, and Corban Villa.</li>
    </ul>
    </li>
    <li>CVE ID: <a
    href="https://www.cve.org/CVERecord?id=CVE-2026-33894">CVE-2026-33894</a></li>
    <li>GHSA ID: <a
    href="https://github.com/digitalbazaar/forge/security/advisories/GHSA-ppp5-5v6c-4jwp">GHSA-ppp5-5v6c-4jwp</a></li>
    </ul>
    </li>
    <li><strong>HIGH</strong>: Signature forgery in Ed25519 due to missing S
    &lt; L check.
    <ul>
    <li>Ed25519 signature verification accepts forged non-canonical
    signatures
    where the scalar S is not reduced modulo the group order (S &gt;= L). A
    valid
    signature and its S + L variant both verify in forge, while Node.js
    crypto.verify (OpenSSL-backed) rejects the S + L variant, as defined by
    the
    specification. This class of signature malleability has been exploited
    in
    practice to bypass authentication and authorization logic (see
    CVE-2026-25793, CVE-2022-35961). Applications relying on signature
    uniqueness (i.e., dedup by signature bytes, replay tracking,
    signed-object
    canonicalization checks) may be bypassed.</li>
    <li>Reported as part of a U.C. Berkeley security research project by:
    <ul>
    <li>Austin Chu, Sohee Kim, and Corban Villa.</li>
    </ul>
    </li>
    <li>CVE ID: <a
    href="https://www.cve.org/CVERecord?id=CVE-2026-33895">CVE-2026-33895</a></li>
    <li>GHSA ID: <a
    href="https://github.com/digitalbazaar/forge/security/advisories/GHSA-q67f-28xg-22rw">GHSA-q67f-28xg-22rw</a></li>
    </ul>
    </li>
    <li><strong>HIGH</strong>: <code>basicConstraints</code> bypass in
    certificate chain verification.
    <ul>
    <li><code>pki.verifyCertificateChain()</code> does not enforce RFC 5280
    <code>basicConstraints</code>
    requirements when an intermediate certificate lacks both the
    <code>basicConstraints</code> and <code>keyUsage</code> extensions. This
    allows any leaf
    certificate (without these extensions) to act as a CA and sign other
    certificates, which node-forge will accept as valid.</li>
    <li>Reported by Doruk Tan Ozturk (<a
    href="https://github.com/peaktwilight"><code>@​peaktwilight</code></a>)
    - doruk.ch</li>
    <li>CVE ID: <a
    href="https://www.cve.org/CVERecord?id=CVE-2026-33896">CVE-2026-33896</a></li>
    <li>GHSA ID: <a
    href="https://github.com/digitalbazaar/forge/security/advisories/GHSA-2328-f5f3-gj25">GHSA-2328-f5f3-gj25</a></li>
    </ul>
    </li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/digitalbazaar/forge/commit/fa385f92440879601240020f158bed68e444e83a"><code>fa385f9</code></a>
    Release 1.4.0.</li>
    <li><a
    href="https://github.com/digitalbazaar/forge/commit/07d4e162762ed4fdab5caca9ebf78237fcf85339"><code>07d4e16</code></a>
    Update changelog.</li>
    <li><a
    href="https://github.com/digitalbazaar/forge/commit/cb90fd92091ee34e4abab3ad0c835eeea3d06c3e"><code>cb90fd9</code></a>
    Update changelog.</li>
    <li><a
    href="https://github.com/digitalbazaar/forge/commit/963e7c5c7b0f03de1b28a1e5a42a6bafda4cf711"><code>963e7c5</code></a>
    Add unit test for &quot;pseudonym&quot;</li>
    <li><a
    href="https://github.com/digitalbazaar/forge/commit/f0b6f5b7c5d1c918240e975e0cade4f47d005446"><code>f0b6f5b</code></a>
    Add pseudonym OID</li>
    <li><a
    href="https://github.com/digitalbazaar/forge/commit/3df48a311d4b53dc6493b7a47a8d07f3669957d9"><code>3df48a3</code></a>
    Fix missing CVE ID.</li>
    <li><a
    href="https://github.com/digitalbazaar/forge/commit/2e492832fb25227e6b647cbe1ac981c123171e90"><code>2e49283</code></a>
    Add x509 <code>basicConstraints</code> check.</li>
    <li><a
    href="https://github.com/digitalbazaar/forge/commit/bdecf11571c9f1a487cc0fe72fe78ff6dfa96b85"><code>bdecf11</code></a>
    Add canonical signature scaler check for S &lt; L.</li>
    <li><a
    href="https://github.com/digitalbazaar/forge/commit/af094e69c60ac5f7b29f2b1957c53ae5e12fd4a0"><code>af094e6</code></a>
    Add RSA padding and DigestInfo length checks.</li>
    <li><a
    href="https://github.com/digitalbazaar/forge/commit/796eeb1673f6ec636fda02dfc295047d9f7aefe0"><code>796eeb1</code></a>
    Improve jsbn fix.</li>
    <li>Additional commits viewable in <a
    href="https://github.com/digitalbazaar/forge/compare/v1.3.3...v1.4.0">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=node-forge&package-manager=npm_and_yarn&previous-version=1.3.3&new-version=1.4.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the
    [Security Alerts
    page](https://github.com/deeplay-io/nice-grpc/network/alerts).
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Apr 12, 2026
    Configuration menu
    Copy the full SHA
    51ff88f View commit details
    Browse the repository at this point in the history
  12. chore(deps): bump yaml from 2.7.0 to 2.8.3 (#854)

    Bumps [yaml](https://github.com/eemeli/yaml) from 2.7.0 to 2.8.3.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/eemeli/yaml/releases">yaml's
    releases</a>.</em></p>
    <blockquote>
    <h2>v2.8.3</h2>
    <ul>
    <li>Add <code>trailingComma</code> ToString option for multiline flow
    formatting (<a
    href="https://redirect.github.com/eemeli/yaml/issues/670">#670</a>)</li>
    <li>Catch stack overflow during node composition (1e84ebb)</li>
    </ul>
    <h2>v2.8.2</h2>
    <ul>
    <li>Serialize -0 as -0 (<a
    href="https://redirect.github.com/eemeli/yaml/issues/638">#638</a>)</li>
    <li>Do not double newlines for empty map values (<a
    href="https://redirect.github.com/eemeli/yaml/issues/642">#642</a>)</li>
    </ul>
    <h2>v2.8.1</h2>
    <ul>
    <li>Preserve empty block literals (<a
    href="https://redirect.github.com/eemeli/yaml/issues/634">#634</a>)</li>
    </ul>
    <h2>v2.8.0</h2>
    <ul>
    <li>Add node cache for faster alias resolution (<a
    href="https://redirect.github.com/eemeli/yaml/issues/612">#612</a>)</li>
    <li>Re-introduce compatibility with Node.js 14.6 (<a
    href="https://redirect.github.com/eemeli/yaml/issues/614">#614</a>)</li>
    <li>Add <code>--merge</code> option to CLI tool (<a
    href="https://redirect.github.com/eemeli/yaml/issues/611">#611</a>)</li>
    <li>Improve error for tag resolution error on null value (<a
    href="https://redirect.github.com/eemeli/yaml/issues/616">#616</a>)</li>
    <li>Allow empty string as plain scalar representation, for failsafe
    schema (<a
    href="https://redirect.github.com/eemeli/yaml/issues/616">#616</a>)</li>
    <li>docs: include cli example (<a
    href="https://redirect.github.com/eemeli/yaml/issues/617">#617</a>)</li>
    </ul>
    <h2>v2.7.1</h2>
    <ul>
    <li>Do not allow seq with single-line collection value on same line with
    map key (<a
    href="https://redirect.github.com/eemeli/yaml/issues/603">#603</a>)</li>
    <li>Improve warning &amp; avoid TypeError on bad YAML 1.1 nodes (<a
    href="https://redirect.github.com/eemeli/yaml/issues/610">#610</a>)</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/eemeli/yaml/commit/ce14587484822bffb0f7d31aefedcaf2dc0d0387"><code>ce14587</code></a>
    2.8.3</li>
    <li><a
    href="https://github.com/eemeli/yaml/commit/1e84ebbea7ec35011a4c61bbb820a529ee4f359b"><code>1e84ebb</code></a>
    fix: Catch stack overflow during node composition</li>
    <li><a
    href="https://github.com/eemeli/yaml/commit/6b24090280eaaab5040112bba41ccef57f39c2d5"><code>6b24090</code></a>
    ci: Include Prettier check in lint action</li>
    <li><a
    href="https://github.com/eemeli/yaml/commit/9424dee38c85163fad53ac27533c7c4bdaf7495d"><code>9424dee</code></a>
    chore: Refresh lockfile</li>
    <li><a
    href="https://github.com/eemeli/yaml/commit/d1aca82bc15a4c261bdc58561d32189a5d3a45ef"><code>d1aca82</code></a>
    Add trailingComma ToString option for multiline flow formatting (<a
    href="https://redirect.github.com/eemeli/yaml/issues/670">#670</a>)</li>
    <li><a
    href="https://github.com/eemeli/yaml/commit/43215099f7fcdac422d778c15e70d83c691b0e41"><code>4321509</code></a>
    ci: Drop the branch filter from GitHub PR actions</li>
    <li><a
    href="https://github.com/eemeli/yaml/commit/47207d0fc7d4f863cd5fbdcff1378637bd93e847"><code>47207d0</code></a>
    chore: Update docs-slate</li>
    <li><a
    href="https://github.com/eemeli/yaml/commit/5212faeed5936d1fa291d2f28672e4a96e2c2c5d"><code>5212fae</code></a>
    chore: Update docs-slate</li>
    <li><a
    href="https://github.com/eemeli/yaml/commit/086fa6b5bae325da18734750cddee231ce578930"><code>086fa6b</code></a>
    2.8.2</li>
    <li><a
    href="https://github.com/eemeli/yaml/commit/95f01e98032ddf199b42bb3ba0737303b35ef752"><code>95f01e9</code></a>
    chore: Add funding to package.json</li>
    <li>Additional commits viewable in <a
    href="https://github.com/eemeli/yaml/compare/v2.7.0...v2.8.3">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=yaml&package-manager=npm_and_yarn&previous-version=2.7.0&new-version=2.8.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the
    [Security Alerts
    page](https://github.com/deeplay-io/nice-grpc/network/alerts).
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Apr 12, 2026
    Configuration menu
    Copy the full SHA
    bedb418 View commit details
    Browse the repository at this point in the history
  13. chore(deps): bump undici from 6.21.1 to 6.24.0 (#851)

    [//]: # (dependabot-start)
    ⚠️  **Dependabot is rebasing this PR** ⚠️ 
    
    Rebasing might not happen immediately, so don't worry if this takes some
    time.
    
    Note: if you make any changes to this PR yourself, they will take
    precedence over the rebase.
    
    ---
    
    [//]: # (dependabot-end)
    
    Bumps [undici](https://github.com/nodejs/undici) from 6.21.1 to 6.24.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/nodejs/undici/releases">undici's
    releases</a>.</em></p>
    <blockquote>
    <h2>v6.24.0</h2>
    <h1>Undici v6.24.0 Security Release Notes (LTS)</h1>
    <p>This release backports fixes for security vulnerabilities affecting
    the v6 line.</p>
    <h2>Upgrade guidance</h2>
    <p>All users on v6 should upgrade to <strong>v6.24.0</strong> or
    later.</p>
    <h2>Fixed advisories</h2>
    <ul>
    <li>
    <p><a
    href="https://github.com/nodejs/undici/security/advisories/GHSA-2mjp-6q6p-2qxm">GHSA-2mjp-6q6p-2qxm</a>
    / CVE-2026-1525 (Medium)<br />
    Inconsistent interpretation of HTTP requests (request/response smuggling
    class issue).</p>
    </li>
    <li>
    <p><a
    href="https://github.com/nodejs/undici/security/advisories/GHSA-f269-vfmq-vjvj">GHSA-f269-vfmq-vjvj</a>
    / CVE-2026-1528 (High)<br />
    Malicious WebSocket 64-bit frame length handling could crash the
    client.</p>
    </li>
    <li>
    <p><a
    href="https://github.com/nodejs/undici/security/advisories/GHSA-4992-7rv2-5pvq">GHSA-4992-7rv2-5pvq</a>
    / CVE-2026-1527 (Medium)<br />
    CRLF injection via the <code>upgrade</code> option.</p>
    </li>
    <li>
    <p><a
    href="https://github.com/nodejs/undici/security/advisories/GHSA-v9p9-hfj2-hcw8">GHSA-v9p9-hfj2-hcw8</a>
    / CVE-2026-2229 (High)<br />
    Unhandled exception from invalid <code>server_max_window_bits</code> in
    WebSocket permessage-deflate negotiation.</p>
    </li>
    <li>
    <p><a
    href="https://github.com/nodejs/undici/security/advisories/GHSA-vrm6-8vpv-qv8q">GHSA-vrm6-8vpv-qv8q</a>
    / CVE-2026-1526 (High)<br />
    Unbounded memory consumption in WebSocket permessage-deflate
    decompression.</p>
    </li>
    </ul>
    <h2>Not applicable to v6</h2>
    <ul>
    <li><a
    href="https://github.com/nodejs/undici/security/advisories/GHSA-phc3-fgpg-7m6h">GHSA-phc3-fgpg-7m6h</a>
    / CVE-2026-2581 affects <code>&gt;= 7.17.0 &lt; 7.24.0</code> only.</li>
    </ul>
    <h2>Affected and patched ranges (v6)</h2>
    <ul>
    <li>CVE-2026-1525: affected <code>&lt; 6.24.0</code>, patched
    <code>6.24.0</code></li>
    <li>CVE-2026-1528: affected <code>&gt;= 6.0.0 &lt; 6.24.0</code>,
    patched <code>6.24.0</code></li>
    <li>CVE-2026-1527: affected <code>&lt; 6.24.0</code>, patched
    <code>6.24.0</code></li>
    <li>CVE-2026-2229: affected <code>&lt; 6.24.0</code>, patched
    <code>6.24.0</code></li>
    <li>CVE-2026-1526: affected <code>&lt; 6.24.0</code>, patched
    <code>6.24.0</code></li>
    </ul>
    <h2>References</h2>
    <ul>
    <li>GitHub Security Advisories: <a
    href="https://github.com/nodejs/undici/security/advisories">https://github.com/nodejs/undici/security/advisories</a></li>
    <li>NVD CVE-2026-1525: <a
    href="https://nvd.nist.gov/vuln/detail/CVE-2026-1525">https://nvd.nist.gov/vuln/detail/CVE-2026-1525</a></li>
    <li>NVD CVE-2026-1528: <a
    href="https://nvd.nist.gov/vuln/detail/CVE-2026-1528">https://nvd.nist.gov/vuln/detail/CVE-2026-1528</a></li>
    <li>NVD CVE-2026-1527: <a
    href="https://nvd.nist.gov/vuln/detail/CVE-2026-1527">https://nvd.nist.gov/vuln/detail/CVE-2026-1527</a></li>
    <li>NVD CVE-2026-2229: <a
    href="https://nvd.nist.gov/vuln/detail/CVE-2026-2229">https://nvd.nist.gov/vuln/detail/CVE-2026-2229</a></li>
    <li>NVD CVE-2026-1526: <a
    href="https://nvd.nist.gov/vuln/detail/CVE-2026-1526">https://nvd.nist.gov/vuln/detail/CVE-2026-1526</a></li>
    </ul>
    <h2>v6.23.0</h2>
    <h2>⚠️ Security Release</h2>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/nodejs/undici/commit/8873c947271faf1ebc455bdc6158ecbc022ecfa9"><code>8873c94</code></a>
    Bumped v6.24.0</li>
    <li><a
    href="https://github.com/nodejs/undici/commit/411bd01a42e7917009bbf686f7628b99d67bbce9"><code>411bd01</code></a>
    test(websocket): use node:assert for Node 18 compatibility</li>
    <li><a
    href="https://github.com/nodejs/undici/commit/844bf59699d778944f78a24ae819c0e8f295766e"><code>844bf59</code></a>
    test: fix http2 lint regressions in backport</li>
    <li><a
    href="https://github.com/nodejs/undici/commit/a444e4f13e8958b4e1ac42bc0d53ace7fba0a9c1"><code>a444e4f</code></a>
    test: stabilize h2 and tls-cert-leak under current test runner</li>
    <li><a
    href="https://github.com/nodejs/undici/commit/dc032a1050d5489b8ce9b4c22aafba98a942f87b"><code>dc032a1</code></a>
    fix: h2 CI (<a
    href="https://redirect.github.com/nodejs/undici/issues/4395">#4395</a>)</li>
    <li><a
    href="https://github.com/nodejs/undici/commit/4cd3f4b3a2ef910ba728c47ae78294d956410450"><code>4cd3f4b</code></a>
    test: increase bitness in <code>test/fixtures/*.pem</code> (<a
    href="https://redirect.github.com/nodejs/undici/issues/3659">#3659</a>)</li>
    <li><a
    href="https://github.com/nodejs/undici/commit/7df6442194b7a54e9ac734335e6e0a56a9bc6666"><code>7df6442</code></a>
    fix: adapt websocket frame-limit handling for v6 parser</li>
    <li><a
    href="https://github.com/nodejs/undici/commit/4e0179ae643e6f4380f24cc3683c1b1ca2afb094"><code>4e0179a</code></a>
    fix: reject duplicate content-length and host headers</li>
    <li><a
    href="https://github.com/nodejs/undici/commit/5a97f0893b53ba7d1d5549d3df7e55d9c2673f89"><code>5a97f08</code></a>
    Fix websocket 64-bit length overflow</li>
    <li><a
    href="https://github.com/nodejs/undici/commit/e43e898603dd5e0c14a75b08b83257598d664a39"><code>e43e898</code></a>
    fix: validate upgrade header to prevent CRLF injection</li>
    <li>Additional commits viewable in <a
    href="https://github.com/nodejs/undici/compare/v6.21.1...v6.24.0">compare
    view</a></li>
    </ul>
    </details>
    <details>
    <summary>Maintainer changes</summary>
    <p>This version was pushed to npm by [GitHub Actions](<a
    href="https://www.npmjs.com/~GitHub">https://www.npmjs.com/~GitHub</a>
    Actions), a new releaser for undici since your current version.</p>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici&package-manager=npm_and_yarn&previous-version=6.21.1&new-version=6.24.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the
    [Security Alerts
    page](https://github.com/deeplay-io/nice-grpc/network/alerts).
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Apr 12, 2026
    Configuration menu
    Copy the full SHA
    32ddfba View commit details
    Browse the repository at this point in the history
  14. Configuration menu
    Copy the full SHA
    aad6294 View commit details
    Browse the repository at this point in the history
  15. chore(release): publish

     - nice-grpc@2.1.15
     - nice-grpc-client-middleware-deadline@2.0.18
     - nice-grpc-client-middleware-devtools@1.0.10
     - nice-grpc-client-middleware-retry@3.1.14
     - nice-grpc-common@2.0.3
     - nice-grpc-error-details@0.2.13
     - nice-grpc-opentelemetry@0.1.21
     - nice-grpc-prometheus@0.2.10
     - nice-grpc-server-health@2.0.18
     - nice-grpc-server-middleware-terminator@2.0.17
     - nice-grpc-server-reflection@3.0.4
     - nice-grpc-web@3.3.10
    aikoven committed Apr 12, 2026
    Configuration menu
    Copy the full SHA
    b906919 View commit details
    Browse the repository at this point in the history
Loading