Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Sep 29, 2025

This PR contains the following updates:

Package Change Age Confidence
happy-dom ^18.0.1 -> ^20.0.7 age confidence

Release Notes

capricorn86/happy-dom (happy-dom)

v20.0.7

Compare Source

πŸ‘·β€β™‚οΈ Patch fixes

v20.0.6

Compare Source

πŸ‘·β€β™‚οΈ Patch fixes
  • Changes implementation for DOMTokenList.forEach(), Headers.forEach() and NodeList.forEach() to be spec compliant - By @​ikeyan in task #​1858

v20.0.5

Compare Source

πŸ‘·β€β™‚οΈ Patch fixes

v20.0.4

Compare Source

πŸ‘·β€β™‚οΈ Patch fixes

v20.0.3

Compare Source

πŸ‘·β€β™‚οΈ Patch fixes
  • Moves URL resolution to after checking if module preloading is enabled to prevent URL errors to be thrown when unresolvable - By @​iam-medvedev in task #​1851
  • Fixes issue where CSS variables aren't parsed correctly when inside CSS functions - By @​fimion in task #​1837

v20.0.2

Compare Source

πŸ‘·β€β™‚οΈ Patch fixes

v20.0.1

Compare Source

πŸ‘·β€β™‚οΈ Patch fixes
  • Adds warning for environment with unfrozen intrinsics (builtins) when JavaScript evaluation is enabled- By @​capricorn86 in task #​1932
    • A security advisory has been reported showing that the recommended preventive measure of running Node.js with --disallow-code-generation-from-strings wasn't enough to protect against attackers escaping the VM context and accessing process-level functions. Big thanks to @​cristianstaicu for reporting this!
    • The documentation for how to run Happy DOM with JavaScript evaluation enabled in a safer way has been updated. Read more about it in the Wiki

v20.0.0

Compare Source

I avoid making breaking changes as much as possible in Happy DOM. When I have to make a breaking change, I try to keep it as minimal as possible. This could be a breaking change that impacts many projects, and I am truly sorry if you are negatively affected by this.

πŸ’£ Breaking Changes
  • Due to security risks, JavaScript evaluation is now disabled by default - By @​capricorn86 in task #​1930
    • A security advisory (GHSA-37j7-fg3j-429f) has been reported that shows a security vulnerability where it's possible to escape the VM context and get access to process level functionality. Big thanks to @​Mas0nShi for reporting this!
    • Due to this security risk, JavaScript evaluation is now disabled by default to prevent that consumers accidentally executes untrusted code without taking precautions
    • JavaScript evaluation can be enabled by setting enableJavaScriptEvaluation to "true". Read more about how to enable this in a safer way in the Wiki

v19.0.2

Compare Source

πŸ‘·β€β™‚οΈ Patch fixes
  • Fixes issue related to CSS pseudo selector :scope that didn't work correctly for direct descendants to root - By @​capricorn86 in task #​1620

v19.0.1

Compare Source

πŸ‘·β€β™‚οΈ Patch fixes

v19.0.0

Compare Source

πŸ’£ Breaking Changes
  • Removes support for CommonJS - By @​capricorn86 in task #​1730
    • Support for CommonJS is no longer needed as Node.js v18 is deprecated and v20 and above supports loading ES modules from CommonJS using require()
  • Updates Jest to v30 in the @happy-dom/jest-environment package - By @​capricorn86 in task #​1730
  • Makes Jest packages peer dependencies to make it easier to align versions with the project using @happy-dom/jest-environment - By @​capricorn86 in task #​1730
🎨 Features
πŸ‘·β€β™‚οΈ Patch fixes
  • Fixes a bug in the ESM compiler that caused it to fail to parse certain code - By @​capricorn86 in task #​1730
  • Disables the same origin policy when navigating a browser frame using BrowserFrame.goto() - By @​capricorn86 in task #​1730
  • Fixes bug where CSS selectors with the pseudos "+" and ">" failed for selectors without arguments - By @​capricorn86 in task #​1730
  • Adds try and catch to listeners for events dispatched from XMLHttpRequest to prevent it from being set to an invalid state if a listener throws an Error - By @​capricorn86 in task #​1730

Configuration

πŸ“… Schedule: Branch creation - "on Monday" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

β™» Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

πŸ”• Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Copy link

netlify bot commented Sep 29, 2025

❌ Deploy Preview for nuxt-tailwindcss failed. Why did it fail? β†’

Name Link
πŸ”¨ Latest commit c849f5a
πŸ” Latest deploy log https://app.netlify.com/projects/nuxt-tailwindcss/deploys/68f5a8cdf456d70008e3e6d6

Copy link

what-the-diff bot commented Sep 29, 2025

PR Summary

  • Updated Dependency Version
    The version of the 'happy-dom' dependency used in the project has been updated. This could enhance the performance of the project and potentially bring new features or bug fixes from the latest version.

@renovate renovate bot force-pushed the renovate/major-happy-dom-monorepo branch from d160542 to e7a2fff Compare September 29, 2025 23:46
@renovate renovate bot changed the title chore(deps): update devdependency happy-dom to v19 chore(deps): update devdependency happy-dom to v20 Oct 9, 2025
@renovate renovate bot force-pushed the renovate/major-happy-dom-monorepo branch 4 times, most recently from 5105494 to 8adc5f3 Compare October 16, 2025 23:15
@renovate renovate bot force-pushed the renovate/major-happy-dom-monorepo branch 3 times, most recently from 9a9e7b2 to 2712c7f Compare October 19, 2025 22:43
@renovate renovate bot force-pushed the renovate/major-happy-dom-monorepo branch from 2712c7f to c849f5a Compare October 20, 2025 03:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants