Skip to content

[master] Michijs Dependabot changes - #170

Merged
lsegurado merged 1 commit into
masterfrom
michijs-dependabot
Jul 13, 2026
Merged

lsegurado merged 1 commit into
masterfrom
michijs-dependabot

Conversation

@michijs

@michijs michijs Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

@michijs

michijs Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor Author

Bump @​michijs/shared-configs from 0.0.36 to 0.0.37

Changelog:
Sourced from releases.
        ### 0.0.37## What's Changed

Full Changelog: https://redirect.github.com/michijs/shared-configs/compare/0.0.36...0.0.37

        ### 0.0.36## What's Changed

New Contributors

Full Changelog: https://redirect.github.com/michijs/shared-configs/compare/0.0.34...0.0.36

Commit history:
  • bf294a Update tsconfig.json (Bump typescript from 5.1.6 to 5.2.2 #16)

    What is the purpose of this pull request?

    Screenshots or example usage

    Types of changes

    • Bug fix (non-breaking change which fixes an issue)
    • New feature (non-breaking change which adds functionality)
    • Quality improvement (tests or refactors)
    • Breaking change (fix or feature that would cause existing
      functionality to change)
    • Trivial change (small fix or feature that doesn't impact
      functionalities)
    • Requires change to documentation, which has been updated
      accordingly

    Signed-off-by: Lucas Segurado <lsegurado1996@​gmail.com>

  • 3c3aca chore: Release v0.0.37

@michijs

michijs Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor Author

Bump @​mdn/browser-compat-data from 7.3.8 to 8.0.6

Changelog:
Sourced from releases.
        ### v8.0.6### Statistics
  • 4 contributors have changed 48 files with 4,770 additions and 4,768 deletions in 5 commits (next...v8.0.6)

  • 19,979 total features

  • 1,257 total contributors

  • 5,698 total stargazers

          ### v8.0.5### Additions
    
  • api.HTMLElement.headingOffset (#29931)

  • api.HTMLElement.headingReset (#29931)

  • api.HTMLModelElement (#29823)

  • api.HTMLModelElement.boundingBoxCenter (#29823)

  • api.HTMLModelElement.boundingBoxExtents (#29823)

  • api.HTMLModelElement.entityTransform (#29823)

  • api.HTMLModelElement.environmentMap (#29823)

  • api.HTMLModelElement.environmentMapReady (#29823)

  • api.HTMLModelElement.ready (#29823)

  • api.HTMLModelElement.stageMode (#29823)

  • api.PerformanceResourceTiming.workerFinalRouterSource (#29823)

  • api.PerformanceResourceTiming.workerMatchedRouterSource (#29823)

  • browsers.edge.releases.153 (#29973)

  • css.properties.position-visibility.anchor-valid (#29823)

  • css.properties.position-visibility.anchor-visible (#29823)

  • html.elements.model (#29823)

  • html.elements.model.autoplay (#29823)

  • html.elements.model.height (#29823)

  • html.elements.model.loop (#29823)

  • html.elements.model.src (#29823)

  • html.elements.model.stagemode (#29823)

  • html.elements.model.width (#29823)

  • html.global_attributes.headingoffset (#29931)

  • html.global_attributes.headingreset (#29931)

  • webextensions.manifest.theme.properties.additional_backgrounds_size (#29910)

Statistics

  • 5 contributors have changed 51 files with 943 additions and 129 deletions in 6 commits (next...v8.0.5)

  • 19,959 total features

  • 1,256 total contributors

  • 5,702 total stargazers

          ### v8.0.4### Removals
    
  • api.MediaCapabilities.decodingInfo.configuration_keySystemConfiguration_parameter (#29739)

Additions

  • api.Element.scroll.returns_promise (#29875)
  • api.Element.scrollBy.returns_promise (#29875)
  • api.Element.scrollIntoView.returns_promise (#29875)
  • api.Element.scrollTo.returns_promise (#29875)
  • api.MediaCapabilities.decodingInfo.configuration_parameter (#29739)
  • api.MediaCapabilities.decodingInfo.configuration_parameter.keySystemConfiguration (#29739)
  • api.MediaCapabilities.decodingInfo.configuration_parameter.type (#29739)
  • api.MediaCapabilities.decodingInfo.configuration_parameter.type.webrtc_option (#29739)
  • api.MediaCapabilities.encodingInfo.configuration_parameter (#29739)
  • api.MediaCapabilities.encodingInfo.configuration_parameter.type (#29739)
  • api.MediaCapabilities.encodingInfo.configuration_parameter.type.transmission_option (#29739)
  • api.MediaCapabilities.encodingInfo.configuration_parameter.type.webrtc_option (#29739)
  • api.MediaSession.setActionHandler.callback (#29868)
  • api.MediaSession.setActionHandler.callback.enterPictureInPictureReason (#29868)
  • api.MediaSession.setActionHandler.enterpictureinpicture_type (#29868)
  • api.WebSocket.local_network_access (#29864)
  • api.WebTransport.local_network_access (#29864)
  • api.Window.scroll.returns_promise (#29875)
  • api.Window.scrollBy.returns_promise (#29875)
  • api.Window.scrollTo.returns_promise (#29875)
  • api.WindowClient.navigate.local_network_access (#29864)
  • webassembly.api.promising_static (#29783)
  • webassembly.api.Suspending (#29783)
  • webassembly.api.Suspending.Suspending (#29783)
  • webdriver.bidi.browsingContext.domContentLoaded_event.userContext_parameter (#29882)
  • webdriver.bidi.browsingContext.downloadEnd_event.userContext_parameter (#29882)
  • webdriver.bidi.browsingContext.downloadWillBegin_event.userContext_parameter (#29882)
  • webdriver.bidi.browsingContext.fragmentNavigated_event.userContext_parameter (#29882)
  • webdriver.bidi.browsingContext.historyUpdated_event.userContext_parameter (#29882)
  • webdriver.bidi.browsingContext.load_event.userContext_parameter (#29882)
  • webdriver.bidi.browsingContext.navigationCommitted_event.userContext_parameter (#29882)
  • webdriver.bidi.browsingContext.navigationFailed_event.userContext_parameter (#29882)
  • webdriver.bidi.browsingContext.navigationStarted_event.userContext_parameter (#29882)
  • webdriver.bidi.browsingContext.userPromptClosed_event.userContext_parameter (#29882)
  • webdriver.bidi.browsingContext.userPromptOpened_event.userContext_parameter (#29882)
  • webdriver.bidi.input.fileDialogOpened_event.userContext_parameter (#29882)
  • webdriver.bidi.network.authRequired_event.userContext_parameter (#29882)
  • webdriver.bidi.network.beforeRequestSent_event.userContext_parameter (#29882)
  • webdriver.bidi.network.fetchError_event.userContext_parameter (#29882)
  • webdriver.bidi.network.responseCompleted_event.userContext_parameter (#29882)
  • webdriver.bidi.network.responseStarted_event.userContext_parameter (#29882)
  • webdriver.bidi.script.realmCreated_event.userContext_parameter (#29882)
  • webextensions.api.proxy.onRequest.documentId (#29853)
  • webextensions.api.proxy.onRequest.parentDocumentId (#29853)
  • webextensions.api.runtime.getContexts.documentId (#29853)
  • webextensions.api.runtime.getDocumentId (#29853)
  • webextensions.api.scripting.executeScript.InjectionResult.documentId (#29853)
  • webextensions.api.scripting.InjectionTarget.documentIds (#29853)
  • webextensions.api.tabs.connect.connectInfo.documentId (#29853)
  • webextensions.api.tabs.sendMessage.options.documentId (#29853)
  • webextensions.api.webRequest.onAuthRequired.details.documentId (#29853)
  • webextensions.api.webRequest.onAuthRequired.details.parentDocumentId (#29853)
  • webextensions.api.webRequest.onBeforeRedirect.details.documentId (#29853)
  • webextensions.api.webRequest.onBeforeRedirect.details.parentDocumentId (#29853)
  • webextensions.api.webRequest.onBeforeRequest.details.documentId (#29853)
  • webextensions.api.webRequest.onBeforeRequest.details.parentDocumentId (#29853)
  • webextensions.api.webRequest.onBeforeSendHeaders.details.documentId (#29853)
  • webextensions.api.webRequest.onBeforeSendHeaders.details.parentDocumentId (#29853)
  • webextensions.api.webRequest.onCompleted.details.documentId (#29853)
  • webextensions.api.webRequest.onCompleted.details.parentDocumentId (#29853)
  • webextensions.api.webRequest.onErrorOccurred.details.documentId (#29853)
  • webextensions.api.webRequest.onErrorOccurred.details.parentDocumentId (#29853)
  • webextensions.api.webRequest.onHeadersReceived.details.documentId (#29853)
  • webextensions.api.webRequest.onHeadersReceived.details.parentDocumentId (#29853)
  • webextensions.api.webRequest.onResponseStarted.details.documentId (#29853)
  • webextensions.api.webRequest.onResponseStarted.details.parentDocumentId (#29853)
  • webextensions.api.webRequest.onSendHeaders.details.documentId (#29853)
  • webextensions.api.webRequest.onSendHeaders.details.parentDocumentId (#29853)

Statistics

  • 9 contributors have changed 20 files with 1,472 additions and 46 deletions in 15 commits (next...v8.0.4)

  • 19,870 total features

  • 1,255 total contributors

  • 5,690 total stargazers

          ### v8.0.3### Removals
    
  • api.Gamepad.secure_context_required (#29808)

  • api.GamepadButton.secure_context_required (#29808)

  • api.GamepadEvent.secure_context_required (#29808)

  • api.GamepadHapticActuator.secure_context_required (#29808)

  • api.GamepadPose.secure_context_required (#29808)

  • api.HTMLMarqueeElement.bounce_event (#29808)

  • api.HTMLMarqueeElement.finish_event (#29808)

  • api.HTMLMarqueeElement.start_event (#29808)

  • api.Navigator.getGamepads.secure_context_required (#29808)

  • api.SVGAElement.text (#29808)

  • api.SVGRenderingIntent (#29808)

Additions

  • browsers.opera_android.releases.99 (#29839)

Statistics

  • 3 contributors have changed 6 files with 40 additions and 60 deletions in 3 commits (next...v8.0.3)

  • 19,803 total features

  • 1,254 total contributors

  • 5,684 total stargazers

          ### v8.0.2### Additions
    
  • api.Request.isReloadNavigation (#29799)

  • browsers.edge.releases.152 (#29803)

  • css.properties.background.border-area (#29799)

  • css.properties.column-rule-inset-cap-end.overlap-join (#29795)

  • css.properties.column-rule-inset-cap-start.overlap-join (#29795)

  • css.properties.column-rule-inset-cap.overlap-join (#29795)

  • css.properties.column-rule-inset-end.overlap-join (#29795)

  • css.properties.column-rule-inset-junction-end.overlap-join (#29795)

  • css.properties.column-rule-inset-junction-start.overlap-join (#29795)

  • css.properties.column-rule-inset-junction.overlap-join (#29795)

  • css.properties.column-rule-inset-start.overlap-join (#29795)

  • css.properties.column-rule-inset.overlap-join (#29795)

  • css.properties.flex-flow.balance (#29799)

  • css.properties.flex-line-count (#29799)

  • css.properties.flex-wrap.balance (#29799)

  • css.properties.overscroll-behavior-block.chain (#29799)

  • css.properties.overscroll-behavior-inline.chain (#29799)

  • css.properties.overscroll-behavior-x.chain (#29799)

  • css.properties.overscroll-behavior-y.chain (#29799)

  • css.properties.overscroll-behavior.chain (#29799)

  • css.properties.row-rule-inset-cap-end.overlap-join (#29795)

  • css.properties.row-rule-inset-cap-start.overlap-join (#29795)

  • css.properties.row-rule-inset-cap.overlap-join (#29795)

  • css.properties.row-rule-inset-end.overlap-join (#29795)

  • css.properties.row-rule-inset-junction-end.overlap-join (#29795)

  • css.properties.row-rule-inset-junction-start.overlap-join (#29795)

  • css.properties.row-rule-inset-junction.overlap-join (#29795)

  • css.properties.row-rule-inset-start.overlap-join (#29795)

  • css.properties.row-rule-inset.overlap-join (#29795)

  • css.properties.rule-inset-cap.overlap-join (#29795)

  • css.properties.rule-inset-end.overlap-join (#29795)

  • css.properties.rule-inset-junction.overlap-join (#29795)

  • css.properties.rule-inset-start.overlap-join (#29795)

  • css.properties.rule-inset.overlap-join (#29795)

  • css.properties.text-fit (#29799)

  • css.properties.text-fit.grow (#29799)

  • css.properties.text-fit.none (#29799)

  • css.properties.text-fit.shrink (#29799)

Statistics

  • 3 contributors have changed 39 files with 1,176 additions and 27 deletions in 4 commits (next...v8.0.2)

  • 19,806 total features

  • 1,254 total contributors

  • 5,681 total stargazers

          ### v8.0.1### Statistics
    
  • 2 contributors have changed 1 file with 89 additions and 0 deletions in 1 commit (next...v8.0.1)

  • 19,752 total features

  • 1,251 total contributors

  • 5,679 total stargazers

          ### v8.0.0### Breaking changes
    

This release introduces two breaking changes in the TypeScript definitions. The shape of the published data.json has not changed.

Summary: The published TypeScript definitions (types.d.ts) now fully match the actual shape of the published data.json. Two existing types are now stricter.

1. source_file is now required on CompatStatement (#29041)

Previously, the CompatStatement.source_file property was optional in the TypeScript definitions, even though it is always present in published data.json releases (it is generated at build time).

Now, source_file is typed as required, matching the actual shape of the data.

Impact: You may need to remove checks for a missing source_file (e.g. if (compat.source_file)).

2. BrowserStatement.upstream is narrowed to UpstreamBrowserName (#29041)

Previously, the BrowserStatement.upstream property was typed as BrowserName, allowing any of the 17 known browser keys.

Now, upstream is typed as the new UpstreamBrowserName, a subset of BrowserName containing only the browsers that other browsers actually derive from: "chrome" | "chrome_android" | "firefox" | "safari" | "safari_ios".

Impact: You may need to widen the type when passing upstream into functions expecting a full BrowserName, or switch on the narrower set.

Statistics

  • 2 contributors have changed 91 files with 1,681 additions and 784 deletions in 1 commit (v7.3.17...v8.0.0)

  • 19,752 total features

  • 1,250 total contributors

  • 5,671 total stargazers

          ### v7.3.17### Additions
    
  • api.Element.getAnimations.options_parameter (#29728)

  • api.Element.getAnimations.options_parameter.pseudoElement_option (#29728)

  • browsers.firefox_android.releases.154 (#29712)

  • browsers.firefox.releases.154 (#29712)

  • mathml.elements.a (#29706)

  • mathml.elements.a.href (#29706)

Statistics

  • 9 contributors have changed 21 files with 260 additions and 73 deletions in 14 commits (next...v7.3.17)

  • 19,752 total features

  • 1,250 total contributors

  • 5,671 total stargazers

          ### v7.3.16### Removals
    
  • webassembly.mutable-globals (#29503)

Additions

  • api.AuthenticatorAttestationResponse.getPublicKey.algorithm_eddsa (#29637)
  • api.AuthenticatorAttestationResponse.getPublicKey.algorithm_es256 (#29637)
  • api.AuthenticatorAttestationResponse.getPublicKey.algorithm_rs256 (#29637)
  • api.Element.attachShadow.options_slotAssignment_parameter (#29681)
  • browsers.bun.releases.1.3.14 (#29675)
  • css.types.url.integrity (#29663)
  • http.headers.Reporting-Endpoints.default (#29539)
  • http.headers.Reporting-Endpoints.default.receives_crash_type (#29539)
  • http.headers.Reporting-Endpoints.default.receives_deprecation_type (#29539)
  • webassembly.api.Global.Global.mutable (#29503)
  • webassembly.definitions.global (#29503)
  • webassembly.definitions.global.mut (#29503)
  • webassembly.instructions.global_get (#29503)
  • webassembly.instructions.global_set (#29503)

Statistics

  • 15 contributors have changed 106 files with 1,549 additions and 386 deletions in 37 commits (v7.3.15...v7.3.16)

  • 19,744 total features

  • 1,249 total contributors

  • 5,663 total stargazers

          ### v7.3.15### Additions
    
  • api.GPUDevice.createTexture.descriptor_usage_parameter (#29470)

  • api.GPUDevice.createTexture.descriptor_usage_parameter.accept_transient_attachment (#29470)

  • api.GPUTexture.createView.descriptor_usage_parameter.transient_attachment (#29470)

  • api.GPUTexture.usage.transient_attachment (#29470)

  • api.LanguageModel.destroy (#29622)

  • api.Sanitizer.allowProcessingInstruction (#29624)

  • api.Sanitizer.removeProcessingInstruction (#29624)

  • browsers.chrome_android.releases.151 (#29605)

  • browsers.chrome.releases.151 (#29605)

  • browsers.edge.releases.151 (#29633)

  • browsers.nodejs.releases.26.0.0 (#29612)

  • browsers.opera_android.releases.98 (#29605)

  • browsers.webview_android.releases.151 (#29605)

  • css.properties.column-rule-break (#29600)

  • css.properties.column-rule-break.intersection (#29600)

  • css.properties.column-rule-break.none (#29600)

  • css.properties.column-rule-break.normal (#29600)

  • css.properties.column-rule-inset (#29600)

  • css.properties.column-rule-inset-cap (#29624)

  • css.properties.column-rule-inset-cap-end (#29624)

  • css.properties.column-rule-inset-cap-start (#29624)

  • css.properties.column-rule-inset-end (#29600)

  • css.properties.column-rule-inset-junction (#29624)

  • css.properties.column-rule-inset-junction-end (#29624)

  • css.properties.column-rule-inset-junction-start (#29624)

  • css.properties.column-rule-inset-start (#29600)

  • css.properties.column-rule-visibility-items (#29600)

  • css.properties.column-rule-visibility-items.all (#29600)

  • css.properties.column-rule-visibility-items.around (#29600)

  • css.properties.column-rule-visibility-items.between (#29600)

  • css.properties.column-rule-visibility-items.normal (#29600)

  • css.properties.row-rule (#29600)

  • css.properties.row-rule-break (#29600)

  • css.properties.row-rule-break.intersection (#29600)

  • css.properties.row-rule-break.none (#29600)

  • css.properties.row-rule-break.normal (#29600)

  • css.properties.row-rule-color (#29600)

  • css.properties.row-rule-color.currentColor (#29600)

  • css.properties.row-rule-color.transparent (#29600)

  • css.properties.row-rule-inset (#29600)

  • css.properties.row-rule-inset-cap (#29624)

  • css.properties.row-rule-inset-cap-end (#29624)

  • css.properties.row-rule-inset-cap-start (#29624)

  • css.properties.row-rule-inset-end (#29600)

  • css.properties.row-rule-inset-junction (#29624)

  • css.properties.row-rule-inset-junction-end (#29624)

  • css.properties.row-rule-inset-junction-start (#29624)

  • css.properties.row-rule-inset-start (#29600)

  • css.properties.row-rule-style (#29600)

  • css.properties.row-rule-style.dashed (#29600)

  • css.properties.row-rule-style.dotted (#29600)

  • css.properties.row-rule-style.double (#29600)

  • css.properties.row-rule-style.groove (#29600)

  • css.properties.row-rule-style.hidden (#29600)

  • css.properties.row-rule-style.inset (#29600)

  • css.properties.row-rule-style.none (#29600)

  • css.properties.row-rule-style.outset (#29600)

  • css.properties.row-rule-style.ridge (#29600)

  • css.properties.row-rule-style.solid (#29600)

  • css.properties.row-rule-visibility-items (#29600)

  • css.properties.row-rule-visibility-items.all (#29600)

  • css.properties.row-rule-visibility-items.around (#29600)

  • css.properties.row-rule-visibility-items.between (#29600)

  • css.properties.row-rule-visibility-items.normal (#29600)

  • css.properties.row-rule-width (#29600)

  • css.properties.row-rule-width.medium (#29600)

  • css.properties.row-rule-width.thick (#29600)

  • css.properties.row-rule-width.thin (#29600)

  • css.properties.row-rule.currentColor (#29600)

  • css.properties.row-rule.dashed (#29600)

  • css.properties.row-rule.dotted (#29600)

  • css.properties.row-rule.double (#29600)

  • css.properties.row-rule.groove (#29600)

  • css.properties.row-rule.hidden (#29600)

  • css.properties.row-rule.inset (#29600)

  • css.properties.row-rule.medium (#29600)

  • css.properties.row-rule.none (#29600)

  • css.properties.row-rule.outset (#29600)

  • css.properties.row-rule.ridge (#29600)

  • css.properties.row-rule.solid (#29600)

  • css.properties.row-rule.thick (#29600)

  • css.properties.row-rule.thin (#29600)

  • css.properties.row-rule.transparent (#29600)

  • css.properties.rule (#29600)

  • css.properties.rule-break (#29600)

  • css.properties.rule-break.intersection (#29600)

  • css.properties.rule-break.none (#29600)

  • css.properties.rule-break.normal (#29600)

  • css.properties.rule-color (#29600)

  • css.properties.rule-color.currentColor (#29600)

  • css.properties.rule-color.transparent (#29600)

  • css.properties.rule-inset (#29600)

  • css.properties.rule-inset-cap (#29624)

  • css.properties.rule-inset-end (#29600)

  • css.properties.rule-inset-junction (#29624)

  • css.properties.rule-inset-start (#29600)

  • css.properties.rule-overlap (#29600)

  • css.properties.rule-overlap.column-over-row (#29600)

  • css.properties.rule-overlap.row-over-column (#29600)

  • css.properties.rule-style (#29600)

  • css.properties.rule-style.dashed (#29600)

  • css.properties.rule-style.dotted (#29600)

  • css.properties.rule-style.double (#29600)

  • css.properties.rule-style.groove (#29600)

  • css.properties.rule-style.hidden (#29600)

  • css.properties.rule-style.inset (#29600)

  • css.properties.rule-style.none (#29600)

  • css.properties.rule-style.outset (#29600)

  • css.properties.rule-style.ridge (#29600)

  • css.properties.rule-style.solid (#29600)

  • css.properties.rule-visibility-items (#29600)

  • css.properties.rule-visibility-items.all (#29600)

  • css.properties.rule-visibility-items.around (#29600)

  • css.properties.rule-visibility-items.between (#29600)

  • css.properties.rule-visibility-items.normal (#29600)

  • css.properties.rule-width (#29600)

  • css.properties.rule-width.medium (#29600)

  • css.properties.rule-width.thick (#29600)

  • css.properties.rule-width.thin (#29600)

  • css.properties.rule.currentColor (#29600)

  • css.properties.rule.dashed (#29600)

  • css.properties.rule.dotted (#29600)

  • css.properties.rule.double (#29600)

  • css.properties.rule.groove (#29600)

  • css.properties.rule.hidden (#29600)

  • css.properties.rule.inset (#29600)

  • css.properties.rule.medium (#29600)

  • css.properties.rule.none (#29600)

  • css.properties.rule.outset (#29600)

  • css.properties.rule.ridge (#29600)

  • css.properties.rule.solid (#29600)

  • css.properties.rule.thick (#29600)

  • css.properties.rule.thin (#29600)

  • css.properties.rule.transparent (#29600)

  • http.headers.X-Frame-Options.DENY (#29614)

  • javascript.builtins.Intl.DateTimeFormat.DateTimeFormat.options_parameter.options_timeZone_parameter.utc_offset (#29563)

Statistics

  • 10 contributors have changed 661 files with 7,325 additions and 3,001 deletions in 34 commits (v7.3.14...v7.3.15)

  • 19,732 total features

  • 1,247 total contributors

  • 5,660 total stargazers

          ### v7.3.14### Renamings
    
  • api.Element.requestFullscreen.options_navigationUI_parameter to api.Element.requestFullscreen.options_parameter.navigationUI_option (#29548)

  • api.Element.requestFullscreen.options_screen_parameter to api.Element.requestFullscreen.options_parameter.screen_option (#29548)

  • api.fetch.body_readablestream to api.fetch.options_parameter.body.accepts_readablestream (#29451)

  • api.fetch.init_attributionReporting_parameter to api.fetch.options_parameter.attributionReporting (#29451)

  • api.fetch.init_browsingTopics_parameter to api.fetch.options_parameter.browsingTopics (#29451)

  • api.fetch.init_duplex_parameter to api.fetch.options_parameter.duplex (#29451)

  • api.fetch.init_keepalive_parameter to api.fetch.options_parameter.keepalive (#29451)

  • api.fetch.init_priority_parameter to api.fetch.options_parameter.priority (#29451)

  • api.fetch.init_privateToken_parameter to api.fetch.options_parameter.privateToken (#29451)

  • api.fetch.init_referrerPolicy_parameter to api.fetch.options_parameter.referrerPolicy (#29451)

  • api.fetch.init_signal_parameter to api.fetch.options_parameter.signal (#29451)

  • api.fetch.init_targetAddressSpace_parameter to api.fetch.options_parameter.targetAddressSpace (#29451)

  • api.Request.Request.init_attributionReporting_parameter to api.Request.Request.options_parameter.attributionReporting (#29451)

  • api.Request.Request.init_browsingTopics_parameter to api.Request.Request.options_parameter.browsingTopics (#29451)

  • api.Request.Request.init_duplex_parameter to api.Request.Request.options_parameter.duplex (#29451)

  • api.Request.Request.init_keepalive_parameter to api.Request.Request.options_parameter.keepalive (#29451)

  • api.Request.Request.init_priority_parameter to api.Request.Request.options_parameter.priority (#29451)

  • api.Request.Request.init_privateToken_parameter to api.Request.Request.options_parameter.privateToken (#29451)

  • api.Request.Request.init_referrer_parameter to api.Request.Request.options_parameter.referrer (#29451)

  • api.Request.Request.init_targetAddressSpace_parameter to api.Request.Request.options_parameter.targetAddressSpace (#29451)

  • api.Request.Request.request_body_readablestream to api.Request.Request.options_parameter.body.accepts_readablestream (#29451)

Additions

  • api.Element.requestFullscreen.options_parameter (#29548)
  • api.Element.requestFullscreen.options_parameter.keyboardLock_option (#29548)
  • api.fetch.options_parameter (#29451)
  • api.fetch.options_parameter.body (#29451)
  • api.GPU.requestAdapter.options_featureLevel (#29551)
  • api.Request.Request.options_parameter (#29451)
  • api.Request.Request.options_parameter.body (#29451)
  • api.SharedWorker.SharedWorker.options_extendedLifetime_parameter (#29562)
  • api.XRSession.visibilitymaskchange_event (#29576)
  • browsers.opera.releases.133 (#29579)
  • css.properties.accent-color.transparent (#29532)
  • css.properties.shape-outside.rect (#29574)
  • css.properties.stop-color.transparent (#29532)
  • css.types.attr.fallback (#29573)
  • html.elements.audio.autoplay (#29571)

Statistics

  • 11 contributors have changed 54 files with 1,555 additions and 924 deletions in 26 commits (v7.3.13...v7.3.14)

  • 19,602 total features

  • 1,245 total contributors

  • 5,651 total stargazers

          ### v7.3.13### Removals
    
  • css.properties.all.revert-rule (#29489)

  • css.properties.font-family.fangsong (#29439)

  • css.properties.font-family.kai (#29439)

  • css.properties.font-family.khmer-mul (#29439)

  • css.properties.font-family.nastaliq (#29439)

Additions

  • api.CSSContainerRule.conditions (#29530)
  • api.LanguageModel (#29474)
  • api.LanguageModel.append (#29474)
  • api.LanguageModel.availability_static (#29474)
  • api.LanguageModel.clone (#29474)
  • api.LanguageModel.contextoverflow_event (#29474)
  • api.LanguageModel.contextUsage (#29474)
  • api.LanguageModel.contextWindow (#29474)
  • api.LanguageModel.create_static (#29474)
  • api.LanguageModel.measureContextUsage (#29474)
  • api.LanguageModel.prompt (#29474)
  • api.LanguageModel.promptStreaming (#29474)
  • browsers.bun.releases.1.3.13 (#29518)
  • browsers.firefox_android.releases.153 (#29518)
  • browsers.firefox.releases.153 (#29518)
  • css.properties.accent-color.currentColor (#29526)
  • css.properties.color.currentColor (#29526)
  • css.properties.column-rule-color.currentColor (#29526)
  • css.properties.column-rule.currentColor (#29526)
  • css.properties.outline-color.currentColor (#29526)
  • css.properties.position-anchor.normal (#29483)
  • css.properties.stop-color.currentColor (#29526)
  • css.types.attr.attr-name_accepts_namespaces (#29482)
  • css.types.global_keywords.revert-rule (#29489)
  • http.headers.Permissions-Policy-Report-Only (#29506)
  • webdriver.bidi.script.getRealms.type_parameter.window (#29517)

Statistics

  • 12 contributors have changed 83 files with 1,509 additions and 511 deletions in 32 commits (v7.3.12...v7.3.13)

  • 19,588 total features

  • 1,245 total contributors

  • 5,644 total stargazers

          ### v7.3.12### Additions
    
  • api.HTMLTemplateElement.shadowRootSlotAssignment (#29457)

  • api.ReportingObserver.ReportingObserver.options_parameter.types_property.permissions-policy-violation (#29500)

  • api.WGSLLanguageFeatures.extension_texture_and_sampler_let (#29469)

  • browsers.bun.releases.1.3.12 (#29463)

  • browsers.edge.releases.150 (#29463)

  • browsers.opera_android.releases.97 (#29490)

  • css.properties.hanging-punctuation.force-end (#29497)

  • css.types.color.light-dark.image_value (#29429)

  • css.types.env.preferred-text-scale (#29453)

  • html.elements.meta.name.text-scale (#29453)

  • html.elements.template.shadowrootslotassignment (#29457)

  • webdriver.bidi.script.getRealms.type_parameter.worker (#29499)

Statistics

  • 14 contributors have changed 192 files with 1,329 additions and 830 deletions in 37 commits (v7.3.11...v7.3.12)

  • 19,570 total features

  • 1,242 total contributors

  • 5,639 total stargazers

          ### v7.3.11### Additions
    
  • api.CustomElementRegistry.define.html_name_validity (#29217)

  • api.CustomElementRegistry.whenDefined.html_name_validity (#29217)

  • api.Document.createAttribute.html_name_validity (#29217)

  • api.Document.createAttributeNS.html_name_validity (#29217)

  • api.Document.createElement.html_name_validity (#29217)

  • api.Document.createElementNS.html_name_validity (#29217)

  • api.Element.setAttribute.html_name_validity (#29217)

  • api.Element.setAttributeNodeNS.html_name_validity (#29217)

  • api.Element.toggleAttribute.html_name_validity (#29217)

  • api.PaymentRequest.getSecurePaymentConfirmationCapabilities_static (#29434)

  • api.WGSLLanguageFeatures.extension_subgroup_uniformity (#29422)

  • browsers.chrome_android.releases.150 (#29413)

  • browsers.chrome.releases.150 (#29413)

  • browsers.opera.releases.126 (#29414)

  • browsers.opera.releases.127 (#29414)

  • browsers.opera.releases.128 (#29414)

  • browsers.opera.releases.129 (#29414)

  • browsers.opera.releases.130 (#29414)

  • browsers.opera.releases.131 (#29414)

  • browsers.opera.releases.132 (#29444)

  • browsers.webview_android.releases.150 (#29413)

  • css.at-rules.container.container-query_optional (#29300)

  • css.types.url.cross-origin (#29440)

  • css.types.url.referrer-policy (#29440)

  • http.headers.Reporting-Endpoints.crash-reporting (#29399)

Statistics

  • 11 contributors have changed 49 files with 950 additions and 300 deletions in 28 commits (v7.3.10...v7.3.11)

  • 19,561 total features

  • 1,240 total contributors

  • 5,628 total stargazers

          ### v7.3.10### Removals
    
  • html.elements.video.autoplay.loading (#29359)

Additions

  • api.Element.attachShadow.options_referenceTarget_parameter (#29261)
  • api.fetch.init_targetAddressSpace_parameter (#29331)
  • api.HTMLTemplateElement.shadowRootReferenceTarget (#29261)
  • api.Permissions.permission_local-network (#29331)
  • api.Permissions.permission_local-network-access (#29331)
  • api.Permissions.permission_loopback-network (#29331)
  • api.Request.Request.init_targetAddressSpace_parameter (#29331)
  • browsers.safari_ios.releases.26.5 (#29370)
  • browsers.safari.releases.26.5 (#29370)
  • browsers.webview_ios.releases.26.5 (#29370)
  • html.elements.video.loading (#29359)
  • http.headers.Permissions-Policy.local-network (#29331)
  • http.headers.Permissions-Policy.local-network-access (#29331)
  • http.headers.Permissions-Policy.loopback-network (#29331)
  • manifests.webapp.migrate_from (#29356)
  • manifests.webapp.migrate_to (#29356)
  • webdriver.bidi.browser.setClientWindowState.height_parameter (#29394)
  • webdriver.bidi.browser.setClientWindowState.state_parameter (#29394)
  • webdriver.bidi.browser.setClientWindowState.width_parameter (#29394)
  • webdriver.bidi.browser.setClientWindowState.x_parameter (#29394)
  • webdriver.bidi.browser.setClientWindowState.y_parameter (#29394)

Statistics

  • 11 contributors have changed 37 files with 986 additions and 282 deletions in 31 commits (v7.3.9...v7.3.10)

  • 19,546 total features

  • 1,239 total contributors

  • 5,628 total stargazers

          ### v7.3.9### Removals
    
  • css.properties.-webkit-margin-after (#29322)

  • css.properties.-webkit-margin-before (#29322)

Additions

  • api.CookieStore.set.maxAge_option (#29197)
  • api.CSSFontFaceDescriptors.ascent-override (#29352)
  • api.CSSFontFaceDescriptors.ascentOverride (#29352)
  • api.CSSFontFaceDescriptors.descent-override (#29352)
  • api.CSSFontFaceDescriptors.descentOverride (#29352)
  • api.CSSFontFaceDescriptors.font-language-override (#29352)
  • api.CSSFontFaceDescriptors.font-variation-settings (#29352)
  • api.CSSFontFaceDescriptors.fontLanguageOverride (#29352)
  • api.CSSFontFaceDescriptors.fontVariationSettings (#29352)
  • api.CSSFontFaceDescriptors.line-gap-override (#29352)
  • api.CSSFontFaceDescriptors.lineGapOverride (#29352)
  • api.Document.createElement.options_parameter.customElementRegistry_option (#29216)
  • api.Document.createElement.options_parameter.options_is_parameter (#29216)
  • api.Document.createElementNS.options_parameter.customElementRegistry_option (#29216)
  • api.Document.createElementNS.options_parameter.options_is_parameter (#29216)
  • api.HTMLMediaElement.loading (#29256)
  • browsers.firefox_android.releases.152 (#29334)
  • browsers.firefox.releases.152 (#29334)
  • css.properties.all.revert-rule (#29352)
  • css.properties.shape-outside.xywh (#29284)
  • css.types.color.color-mix.variadic_color_arguments (#29214)
  • html.elements.audio.loading (#29256)
  • html.elements.video.autoplay.loading (#29256)

Statistics

  • 11 contributors have changed 88 files with 2,426 additions and 1,395 deletions in 29 commits (v7.3.8...v7.3.9)

  • 19,529 total features

  • 1,236 total contributors

  • 5,620 total stargazers

          ### v7.3.8### Additions
    
  • api.HTMLMediaElement.playbackRate.negative_values (#29253)

  • api.VideoFrame.VideoFrame.metadata_option (#29298)

  • browsers.bun.releases.1.3.11 (#29291)

  • browsers.edge.releases.149 (#29263)

  • css.properties.anchor-name.position_after_layout (#29282)

  • css.properties.letter-spacing.percentages (#29200)

  • css.properties.position-area.disables_auto_margins_and_insets (#29280)

  • webdriver.bidi.network.disownData.dataType_parameter.request (#29275)

Statistics

  • 10 contributors have changed 50 files with 926 additions and 295 deletions in 31 commits (v7.3.7...v7.3.8)
  • 19,510 total features
  • 1,234 total contributors
  • 5,616 total stargazers
Commit history:
  • 6644a2 Release v8.0.6 (#29985)
  • 97f284 build(deps-dev): bump eslint from 9.39.1 to 10.5.0 (#29933)
    • build(deps-dev): remove unused eslint-plugin-node

    The plugin is listed in devDependencies but is never referenced in
    eslint.config.js. It is also long-deprecated (superseded by
    eslint-plugin-n) and caps its eslint peer at older majors, which
    would obstruct an ESLint 10 upgrade.

    • build(deps-dev): migrate to eslint-plugin-import-x

    Replace `eslin

@michijs

michijs Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor Author

Bump typescript from 5.9.3 to 7.0.2

Changelog:
Sourced from releases.
        ### v6.0.3For release notes, check out the [release announcement blog post](https://devblogs.microsoft.com/typescript/announcing-typescript-6-0/).

Downloads are available on:

Downloads are available on:

  • npm

          ### v5.9.3Note: this tag was recreated to point at the correct commit. The npm package contained the correct content.
    

For release notes, check out the release announcement

Downloads are available on:

Commit history:
  • 637d57 Fix infinite loop (#63581)

    Co-authored-by: core-dumpling <warble-88seesaws@​icloud.com>
    Co-authored-by: Ryan Cavanaugh <RyanCavanaugh@​users.noreply.redirect.github.com>

  • 7816ae docs: add JSDoc comments to ReadonlySet interface (#63483)
  • 8ef3e2 Bump actions/checkout from 6.0.3 to 7.0.0 in the github-actions group (#63571)

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • 7964e2 Update git identity from typescript-bot to typescript-automation[bot] (#63544)
  • 3e2482 Bump the github-actions group across 1 directory with 7 updates (#63529)

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • 345012 Switch from bot PAT to GitHub App token via Azure Key Vault (#63538)
  • 7539c0 Fix JSDoc grammar typo: 'returns a undefined' → 'returns undefined' (#63525)

    Co-authored-by: Tech-Savvy Builder <tech@​crypto-nite.com>

  • 6fbce8 Update toFixed/toExponential/toPrecision digit range in docs to match the spec (#63516)
  • 2cf042 Delete browser-integration job from ci.yml (#63528)
  • f3d396 lib: fix misleading maxLength param on string pad* methods (#63504)
  • e5509e Fix es2020.intl.d.ts formatting (#63489)
  • 5678c6 Update AI assistance guidelines in CONTRIBUTING.md (#63496)

    Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@​users.noreply.redirect.github.com>

  • 0105bb Fix typo in README: behavorial -> behavioral (#63492)
  • 5d8fbb 63480 (#63491)

    Co-authored-by: Tech-Savvy Builder <tech@​crypto-nite.com>

  • f350b5 Redirect Claude Code to read AGENTS.md (#63446)
  • af087e docs: improve Math.sign JSDoc grammar and clarity (#63433)
  • 55423a Update CONTRIBUTING.md with comment automation policy (#63412)
  • f1a928 Also check package name validity in InstallPackageRequest (#63401)
  • c7a0ae Harden ATA package name filtering (#63368)
  • 5f4350 Require AI disclosure in PR descriptions (#63366)
  • 38c327 Document charCodeAt edge case behavior in first line (#63344)
  • 7b8cb3 Fix redundant leading apostrophe in TS1344 diagnostic message (#63341)

    Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@​users.noreply.redirect.github.com>
    Co-authored-by: RyanCavanaugh <6685088+RyanCavanaugh@​users.noreply.redirect.github.com>

  • 0844c4 Mark class property initializers as outside of CFA containers (#63310)

    Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@​users.noreply.redirect.github.com>
    Co-authored-by: RyanCavanaugh <6685088+RyanCavanaugh@​users.noreply.redirect.github.com>

  • 71586a Bump the github-actions group with 2 updates (#63319)

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • 7881fe Add coding agent instructions: refuse PRs unless maintenance mode is acknowledged (#63305)

    Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@​users.noreply.redirect.github.com>
    Co-authored-by: RyanCavanaugh <6685088+RyanCavanaugh@​users.noreply.redirect.github.com>
    Co-authored-by: Ryan Cavanaugh <RyanCavanaugh@​users.noreply.redirect.github.com>

  • 77ddb5 Update deps (#63296)
  • 864777 Bump the github-actions group with 3 updates (#63285)

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • b103a0 Update readme to note current repo state (#63292)
  • 4f7b41 Bump the github-actions group with 2 updates (#63224)

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • 9059e5 Fix missing lib files in reused programs (#63239)

@michijs

michijs Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor Author

Bump bun-types from 1.3.11 to 1.3.14

Changelog:
Sourced from releases.
        ### bun-v1.3.14To install Bun v1.3.14
curl -fsSL https://bun.sh/install | bash
# or you can use npm
# npm install -g bun

Windows:

powershell -c "irm bun.sh/install.ps1|iex"

To upgrade to Bun v1.3.14:

bun upgrade

Read Bun v1.3.14's release notes on Bun's blog

Thanks to 11 contributors!

curl -fsSL https://bun.sh/install | bash
# or you can use npm
# npm install -g bun

Windows:

powershell -c "irm bun.sh/install.ps1|iex"

To upgrade to Bun v1.3.13:

bun upgrade

Read Bun v1.3.13's release notes on Bun's blog

Thanks to 8 contributors!

curl -fsSL https://bun.sh/install | bash
# or you can use npm
# npm install -g bun

Windows:

powershell -c "irm bun.sh/install.ps1|iex"

To upgrade to Bun v1.3.12:

bun upgrade

Read Bun v1.3.12's release notes on Bun's blog

Thanks to 8 contributors!

curl -fsSL https://bun.sh/install | bash
# or you can use npm
# npm install -g bun

Windows:

powershell -c "irm bun.sh/install.ps1|iex"

To upgrade to Bun v1.3.11:

bun upgrade

Read Bun v1.3.11's release notes on Bun's blog

Thanks to 15 contributors!

Commit history:
  • 8f1a95 FileSystemRouter: skip empty-key query pairs instead of terminating the parse (#34027)

    Repro

    const r = new Bun.FileSystemRouter({ style: "nextjs", dir: "./pages" });
    r.match("/top?=v&x=1&y=2").query   // {} (x and y lost)
    r.match("/top?x=1&=v&y=2").query   // {"x":"1"} (y lost)
    // URLSearchParams keeps everything:
    Object.fromEntries(new URLSearchParams("=v&x=1&y=2"))
    // {"":"v","x":"1","y":"2"}

    A single empty-key pair (=value) anywhere in the query string made
    match().query silently drop every parameter after it.

    Cause

    Scanner::next in src/url/lib.rs has an explicit "skip" branch for
    empty-key pairs, but it was implemented as return None. Every caller
    (QueryStringMap::init, init_with_scanner) loops while let Some(...) = scanner.next(), so None ends the scan instead of skipping the pair.

    Fix

    Advance self.i past the pair and continue 'outer so the scanner
    resumes at the next &, matching the behavior the comment already
    describes and what the adjacent bare-& arm already does.

    Verification

    USE_SYSTEM_BUN=1 bun test test/js/bun/util/filesystem_router.test.ts -t empty-key  # fails
    bun bd test test/js/bun/util/filesystem_router.test.ts                             # 28 pass
    

    no test proof · iteration 1 · Platform-specific test(s) that do not
    run on this machine. Deferring to CI, which covers all platforms:
    test/js/bun/util/filesystem_router.test.ts

  • 005ddf Bun.randomUUIDv7: preserve monotonicity when the 12-bit counter rolls over (#34022)

    What does this PR do?

    Fixes Bun.randomUUIDv7() so it stays monotonic when more than 4096
    UUIDs are generated within a single millisecond.

    Reproduction:

    const ts = 1750000000000;
    let prev = "";
    for (let i = 0; i < 4200; i++) {
      const u = Bun.randomUUIDv7("hex", ts);
      if (i > 0 && u <= prev) console.log(`i=${i}: ${prev} -> ${u}`);
      prev = u;
    }
    // i=4096: 01977420-dc00-7fff-… -> 01977420-dc00-7000-…

    The docs say Bun.randomUUIDv7() "is monotonic and suitable for sorting
    and databases", but call 4097 at the same millisecond sorts before call
    4096. A bare for (;;) Bun.randomUUIDv7() loop clears 4096 calls per
    real millisecond, so this is reachable without pinning the timestamp
    (about 30 ordering breaks per 200k calls).

    UUID7::get_count in src/jsc/uuid.rs returned
    UUID_V7_COUNTER.fetch_add(1, Relaxed) % 4096, silently wrapping the
    12-bit rand_a counter under a constant timestamp. It also reset the
    counter to 0 on a new millisecond, whereas the docs describe a
    pseudo-random reset; the fixed 0 is why the wrap lands deterministically
    at call 4097 and leaks the per-millisecond generation count.

    The new UUID7::next tracks the last emitted timestamp. When the
    requested timestamp has not moved past it, the last emitted timestamp is
    reused and the counter is incremented; when the 12-bit counter has been
    exhausted, the emitted timestamp is bumped by 1 ms and the counter is
    reseeded rather than wrapped. This is the behaviour RFC 9562 section 6.2
    (Fixed Bit-Length Dedicated Counter) specifies for rollover and matches
    npm uuid's v7. When the timestamp does move forward, the counter is
    reseeded from the call's entropy with the high bit of the 12-bit field
    kept clear, so at least 2048 increments remain before the next rollover.

    Because the emitted timestamp never moves backward, passing an explicit
    timestamp older than one already emitted in the same process now
    continues from the newer value (the custom timestamp test was updated
    to use a far-future constant so it still exercises the encoding path).
    The docs paragraph was updated to describe the rollover handling.

    How did you verify your code works?

    USE_SYSTEM_BUN=1 bun test test/js/bun/util/randomUUIDv7.test.ts
      6 pass, 3 fail
      older explicit timestamps do not move UUIDs backward: Expected true, Received false
      monotonic across 12-bit counter rollover: Expected -1, Received 4096
      counter is seeded pseudo-randomly on a new millisecond: Expected > 1, Received 1
    
    bun bd test test/js/bun/util/randomUUIDv7.test.ts
      9 pass, 0 fail
    

    [review] gate passed · iteration 0 · 4 files touched

    fails on main (without fix)
    ASAN without fix: 3 FAILED
    $ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" "test/js/bun/util/randomUUIDv7.test.ts"
    info: syncing channel updates for nightly-2026-05-06-x86_64-unknown-linux-gnu
    info: latest update on 2026-05-06 for version 1.97.0-nightly (e95e73209 2026-05-05)
    info: component rust-src is up to date
    info: checking for self-update (current version: 1.29.0)
    bun test v1.4.0 (828466833)
    
    test/js/bun/util/randomUUIDv7.test.ts:
    (pass) randomUUIDv7 > basic [6.35ms]
    (pass) randomUUIDv7 > timestamp [3.16ms]
    (pass) randomUUIDv7 > base64 format [2.18ms]
    019f556e60227000a823ca80ae281347
    (pass) randomUUIDv7 > buffer output encoding [2.79ms]
    (pass) randomUUIDv7 > monotonic [28.33ms]
    50 |     for (let i = 0; i < 10000; i++) {
    51 |       const u = Bun.randomUUIDv7("hex", ts);
    52 |       if (i > 0 && u <= prev && firstBreak === -1) firstBreak = i;
    53 |       prev = u;
    54 |     }
    55 |     expect(firstBreak).toBe(-1);
                                ^
    error: expect(received).toBe(expected)
    
    Expected: -1
    Received: 4096
    
          at <anonymous> (/workspace/bun/test/js/bun/util/randomUUIDv7.test.ts:55:24)
    (fail) randomUUID
    ... (truncated)
    
    release without fix: all passed
    bun test v1.4.0-canary.1 (dd1b708f9)
    
    test/js/bun/util/randomUUIDv7.test.ts:
    (pass) randomUUIDv7 > basic [0.15ms]
    (pass) randomUUIDv7 > timestamp [0.09ms]
    (pass) randomUUIDv7 > base64 format [0.03ms]
    019f556e686977d28de1825977269f93
    (pass) randomUUIDv7 > buffer output encoding [0.08ms]
    (pass) randomUUIDv7 > monotonic [0.32ms]
    (pass) randomUUIDv7 > monotonic across 12-bit counter rollover [1.88ms]
    (pass) randomUUIDv7 > custom timestamp [11.61ms]
    (pass) randomUUIDv7 > older explicit timestamps do not move UUIDs backward [12.11ms]
    (pass) randomUUIDv7 > counter is seeded pseudo-randomly on a new millisecond [11.76ms]
    
     9 pass
     0 fail
     19 expect() calls
    Ran 9 tests across 1 file. [259.00ms]
    __F:0:S:0
    passes on PR (with fix)
    ASAN with fix: all passed
    $ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" "test/js/bun/util/randomUUIDv7.test.ts"
    info: syncing channel updates for nightly-2026-05-06-x86_64-unknown-linux-gnu
    info: latest update on 2026-05-06 for version 1.97.0-nightly (e95e73209 2026-05-05)
    info: component rust-src is up to date
    info: checking for self-update (current version: 1.29.0)
    bun test v1.4.0 (828466833)
    
    test/js/bun/util/randomUUIDv7.test.ts:
    (pass) randomUUIDv7 > basic [4.85ms]
    (pass) randomUUIDv7 > timestamp [3.17ms]
    (pass) randomUUIDv7 > base64 format [2.21ms]
    019f556ef8907057805601495326935b
    (pass) randomUUIDv7 > buffer output encoding [2.83ms]
    (pass) randomUUIDv7 > monotonic [28.69ms]
    (pass) randomUUIDv7 > monotonic across 12-bit counter rollover [388.81ms]
    (pass) randomUUIDv7 > custom timestamp [513.79ms]
    (pass) randomUUIDv7 > older explicit timestamps do not move UUIDs backward [511.85ms]
    (pass) randomUUIDv7 > counter is seeded pseudo-randomly on a new millisecond [545.57ms]
    
     9 pass
     0 fail
     19 expect() calls
    Ran 9 tests across 1 file. [4.03s]
    __F:0:S:0
    
    release with fix: all passed
    $ bun scripts/build.ts --profile=release
    info: syncing channel updates for nightly-2026-05-06-x86_64-unknown-linux-gnu
    info: latest update on 2026-05-06 for version 1.97.0-nightly (e95e73209 2026-05-05)
    info: component rust-src is up to date
    info: checking for self-update (current version: 1.29.0)
    [configured] bun-profile → bun (stripped) in 677ms (unchanged)
    ninja: Entering directory `/workspace/bun/build/release'
    [1/8] cxx obj/unified/UnifiedSource-src_jsc_bindings-2.cpp.o
    [2/8] gen generated_host_exports.rs
    generated_host_exports.rs: 91 exports (host=3, lazy=10, generic=78, rust=0); 243 extern-C blocks audited
    [3/8] gen cpp.rs (cppbind)
    [3/8] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu)
    info: syncing channel updates for nightly-2026-05-06-x86_64-unknown-linux-gnu
    info: latest update on 2026-05-06 for version 1.97.0-nightly (e95e73209 2026-05-05)
    info: component rust-src is up to date
    info: component rust-std is up to date
    
    info: checking for self-update (current version: 1.29.0)
      nightly-2026-05-06-x86_64-unknown-linux-gnu unchanged - rustc 1.97.0-nightly (e95e73209 2026-05-05)
    
    �[1m�[92m   Compiling�[0m bun_core v0.0.0 (/workspace/bun/s
    ... (truncated)
    diff hotspot
    docs/runtime/utils.mdx                |   2 +-
     src/jsc/uuid.rs                       |  34 ++++++++--
     src/runtime/webcore/Crypto.rs         |   4 +-
     test/js/bun/util/randomUUIDv7.test.ts | 116 ++++++++++++++++++++++++++++------
     4 files changed, 129 insertions(+), 27 deletions(-)
    

    gate history · 1 passed · 0 rejected · iteration 0

    evidence per changed file
    file                                   reads  edits  tests
    docs/runtime/utils.mdx                     1      3      0
    src/jsc/uuid.rs                            3      3      0
    src/runtime/webcore/Crypto.rs              2      1      0
    test/js/bun/util/randomUUIDv7.test.ts      3      8      0
    
  • b4045c sql: reject a MySQL prepare-OK carrying statement_id 0 (#33238)

    What

    A COM_STMT_PREPARE response carrying statement_id = 0 is accepted
    without validation. statement_id == 0 is the client's own "not yet
    prepared" sentinel: handle_prepared_statement keys its packet dispatch
    on statement_id > 0, and bind_and_execute asserts it. Accepting a 0
    therefore marks the cached statement Prepared while leaving it in an
    impossible state. Only the peer controls this value, so a compromised or
    desynced MySQL-compatible server or proxy can trigger it with a single
    frame.

    On assert-enabled builds the very next execute aborts the process:

    panic: statement is not prepared
    bind_and_execute                      src/sql_jsc/mysql/MySQLQuery.rs:173
    run_prepared_query                    src/sql_jsc/mysql/MySQLQuery.rs:398
    check_if_prepared_statement_is_done   src/sql_jsc/mysql/MySQLConnection.rs:1126
    handle_prepared_statement             src/sql_jsc/mysql/MySQLConnection.rs:1228
    

    On release builds the assertion compiles out and the client sends
    COM_STMT_EXECUTE for statement id 0 on the wire, with the poisoned
    entry left in the statement cache.

    Repro

    test/js/sql/sql-mysql-prepare-ok-zero-statement-id.test.ts: a scripted
    node:net MySQL server that completes the handshake and then answers
    COM_STMT_PREPARE with [00][statement_id = 0 (u32)][columns = 0][params = 0]. No fault injection; the client runs in a spawned
    process so the abort is observable, and the mock records the
    statement_id of any COM_STMT_EXECUTE it receives.

    Fix

    Validate the prepare-OK at the response boundary.
    StmtPrepareOKPacket::decode_internal now rejects statement_id == 0
    with InvalidPrepareOKPacket, the same error it already returns for a
    bad status byte, so the connection fails with
    ERR_MYSQL_INVALID_PREPARE_OK_PACKET before any statement state is
    mutated and nothing is written to the socket. The execute-time assertion
    is kept as defense in depth.

    Also deletes PrepareOK in
    src/sql/mysql/protocol/PreparedStatement.rs: an unused duplicate
    decoder of the same packet (zero callers) that would otherwise remain as
    a second, unvalidated parser of it.

    The server-reported param count is already cross-checked against the
    query's placeholder count at bind time and surfaces as a recoverable
    WrongNumberOfParametersProvided, so no change is needed there.

    Verification

    build result
    release 1.4.0, without fix test fails: mock records
    COM_STMT_EXECUTE for statement_id 0
    bun bd debug, without fix test fails: child aborts, `panic:
    statement is not prepared`
    bun bd debug, with fix test passes: query rejects with
    ERR_MYSQL_INVALID_PREPARE_OK_PACKET, no execute sent

    Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@​users.noreply.redirect.github.com>

  • fa1fe9 Bun.serve(http3): send CONNECTION_CLOSE on abrupt stop of an idle connection (#34038)

    Fixes test/js/bun/http/serve-http3.test.ts going intermittently red,
    most often as POST body without Content-Length still reaches the handler failing with HTTP3StreamReset after ~8-10s.

    Reproduction

    // 1. H3 server A at port P, one fetch to warm the client session
    // 2. server.stop(true)               <- conn is idle here
    // 3. H3 server B at the SAME port P
    // 4. fetch with a ReadableStream body
    //    -> HTTP3StreamReset after ~9s

    On a release build step 2 usually runs while the server still has ACKs
    scheduled, so the bug is masked; under debug/ASAN or a loaded CI runner
    the connection is idle and the POST stalls every time.

    Root cause

    server.stop(true) reaches us_quic_listen_socket_close(), which
    called lsquic_conn_close() on each live conn and then closed the UDP
    fd. For a server connection, ietf_full_conn_ci_close sets
    IFC_CLOSING and only schedules SF_SEND_CONN_CLOSE when
    conn_ok_to_close(); the tick that actually packs the frame (the
    end_write block in lsquic_full_conn_ietf.c) additionally requires
    one of:

    • IFC_GOAWAY_CLOSE, or
    • a received CONNECTION_CLOSE, or
    • lsquic_send_ctl_n_scheduled() > 0

    An idle server conn satisfies none of those, so the UDP fd was closed
    with nothing on the wire. The client's pooled session stays in
    ClientContext.sessions until the negotiated idle timeout. If a later
    listener binds the same ephemeral port before that fires,
    fetch({protocol:'http3'}) matches the dead session and enqueues on it.
    Non-stream bodies recover via retry_or_fail; a ReadableStream body
    has already been drained into lsquic's send buffer and retry_or_fail
    refuses on is_streaming_body, so it surfaces HTTP3StreamReset once
    the idle alarm fires.

    The pattern has been present since HTTP/3 support landed (#29768 for the
    server side, #29795 for the pooled client); it turns into a test failure
    whenever two ephemeral ports collide inside one idle-timeout window.

    Fix

    us_quic_listen_socket_close() now calls lsquic_conn_abort() instead
    of lsquic_conn_close(). IFC_ABORTED is in
    IFC_IMMEDIATE_CLOSE_FLAGS, which takes the immediate_close path and
    unconditionally packs a CONNECTION_CLOSE (transport error NO_ERROR,
    "user aborted connection").

    The test file's withCustomServer fixtures now server.stop(true) on
    stdin close and withCustomServer gives them a moment to do so before
    kill(), so every server process in the file exits through this path.

    Verification

    New lifecycle test lets the server conn go idle, stops abruptly, rebinds
    the same port in-process, then POSTs a ReadableStream body:

    # without packages/ change
    (fail) server.stop(true) sends CONNECTION_CLOSE on an idle H3 connection [4766ms]
    # with packages/ change
    (pass) server.stop(true) sends CONNECTION_CLOSE on an idle H3 connection [1713ms]
    

    Across the full file with BUN_DEBUG_h3_client=1 on a debug build,
    client-session close breakdown:

    connects idle-timeout (status=4) CONNECTION_CLOSE (status=8)
    before 43 29 10
    after 46 2 42

    The two remaining timeout closes are the intentional
    AbortSignal.timeout probes against a stopped port; those sessions are
    still handshaking and recover on retransmission.


    [review] gate passed · iteration 1 · 2 files touched

    fails on main (without fix)
    ASAN without fix: 1 FAILED
    $ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" "test/js/bun/http/serve-http3.test.ts"
    info: syncing channel updates for nightly-2026-05-06-x86_64-unknown-linux-gnu
    info: latest update on 2026-05-06 for version 1.97.0-nightly (e95e73209 2026-05-05)
    info: component rust-src is up to date
    info: checking for self-update (current version: 1.29.0)
    bun test v1.4.0 (304079670)
    
    test/js/bun/http/serve-http3.test.ts:
    (pass) Bun.serve HTTP/3 > basic GET [1669.34ms]
    (pass) Bun.serve HTTP/3 > POST echoes body, status, request headers [1769.09ms]
    (pass) Bun.serve HTTP/3 > 204 with no body [1648.64ms]
    (pass) Bun.serve HTTP/3 > query string is preserved [1627.15ms]
    (pass) Bun.serve HTTP/3 > large response body crosses multiple QUIC packets [1726.89ms]
    (pass) Bun.serve HTTP/3 > concurrent requests across separate connections [1872.41ms]
    (pass) Bun.serve HTTP/3 > client abort mid-response does not crash the server [1631.50ms]
    (pass) Bun.serve HTTP/3 > http1: false rejects HTTP/1.1 but accepts HTTP/3 [1631.31ms]
    (pass) Bun.serve HTTP/3 > http1: false — url/address/stop see the QUIC listener [2540.7
    ... (truncated)
    
    release without fix: all passed
    bun test v1.4.0-canary.1 (887d0bef6)
    
    test/js/bun/http/serve-http3.test.ts:
    (pass) Bun.serve HTTP/3 > basic GET [150.04ms]
    (pass) Bun.serve HTTP/3 > POST echoes body, status, request headers [135.34ms]
    (pass) Bun.serve HTTP/3 > 204 with no body [135.24ms]
    (pass) Bun.serve HTTP/3 > query string is preserved [135.18ms]
    (pass) Bun.serve HTTP/3 > large response body crosses multiple QUIC packets [136.75ms]
    (pass) Bun.serve HTTP/3 > concurrent requests across separate connections [134.72ms]
    (pass) Bun.serve HTTP/3 > client abort mid-response does not crash the server [134.80ms]
    (pass) Bun.serve HTTP/3 > http1: false rejects HTTP/1.1 but accepts HTTP/3 [137.19ms]
    (pass) Bun.serve HTTP/3 > http1: false — url/address/stop see the QUIC listener [1035.49ms]
    (pass) Bun.serve HTTP/3 > maxRequestBodySize is enforced for H3 bodies without Content-Length [132.29ms]
    (pass) Bun.serve HTTP/3 > unknown route returns 404 [135.57ms]
    (pass) Bun.serve HTTP/3 > routes: handler with :params [134.53ms]
    (pass) Bun.serve HTTP/3 > routes: per-method handler [135.74ms]
    (pass) Bun.serve HTTP/3 > routes: method-specific '/*' falls through to fetch() on other methods [133.48ms]
    (pass) Bun.serve H
    ... (truncated)
    passes on PR (with fix)
    ASAN with fix: all passed
    $ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" "test/js/bun/http/serve-http3.test.ts"
    info: syncing channel updates for nightly-2026-05-06-x86_64-unknown-linux-gnu
    info: latest update on 2026-05-06 for version 1.97.0-nightly (e95e73209 2026-05-05)
    info: component rust-src is up to date
    info: checking for self-update (current version: 1.29.0)
    bun test v1.4.0 (304079670)
    
    test/js/bun/http/serve-http3.test.ts:
    (pass) Bun.serve HTTP/3 > basic GET [1655.54ms]
    (pass) Bun.serve HTTP/3 > POST echoes body, status, request headers [1688.02ms]
    (pass) Bun.serve HTTP/3 > 204 with no body [1758.76ms]
    (pass) Bun.serve HTTP/3 > query string is preserved [1610.79ms]
    (pass) Bun.serve HTTP/3 > large response body crosses multiple QUIC packets [1732.70ms]
    (pass) Bun.serve HTTP/3 > concurrent requests across separate connections [1708.12ms]
    (pass) Bun.serve HTTP/3 > client abort mid-response does not crash the server [1686.35ms]
    (pass) Bun.serve HTTP/3 > http1: false rejects HTTP/1.1 but accepts HTTP/3 [1675.08ms]
    (pass) Bun.serve HTTP/3 > http1: false — url/address/stop see the QUIC listener [2582.9
    ... (truncated)
    
    release with fix: all passed
    $ bun scripts/build.ts --profile=release
    info: syncing channel updates for nightly-2026-05-06-x86_64-unknown-linux-gnu
    info: latest update on 2026-05-06 for version 1.97.0-nightly (e95e73209 2026-05-05)
    info: component rust-src is up to date
    info: checking for self-update (current version: 1.29.0)
    [configured] bun-profile → bun (stripped) in 688ms (unchanged)
    ninja: Entering directory `/workspace/bun/build/release'
    [1/21] gen JS modules (bundle-modules)
    Preprocess modules (6473ms)
    Bundle modules (27ms)
    Postprocesss modules (21ms)
    Bundle Functions (706ms)
    Generate Code (75ms)
    
    [7.32s] Bundled "src/js" for production
      1912 kb
      162 internal modules
      12 native modules
      90 internal functions across 19 files
    [1/7] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu)
    info: syncing channel updates for nightly-2026-05-06-x86_64-unknown-linux-gnu
    info: latest update on 2026-05-06 for version 1.97.0-nightly (e95e73209 2026-05-05)
    info: component rust-src is up to date
    info: component rust-std is up to date
    
      nightly-2026-05-06-x86_64-unknown-linux-gnu unchanged - rustc 1.97.0-nightly (e95e73209 2026-05-05)
    
    info: checking for self-update (current version:
    ... (truncated)
    diff hotspot
    packages/bun-usockets/src/quic.c     | 14 +++++-
     test/js/bun/http/serve-http3.test.ts | 96 ++++++++++++++++++++++++++++++++++--
     2 files changed, 103 insertions(+), 7 deletions(-)
    

    gate history · 3 passed · 0 rejected · iteration 1

    evidence per changed file
    file                                  reads  edits  tests
    packages/bun-usockets/src/quic.c          6      7      0
    test/js/bun/http/serve-http3.test.ts      3     15      0
    
  • 134838 bake: fix use-after-free in ~DevServerSourceProvider during VM teardown (#34035)

    Fixes test/bake/dev/request-cookies.test.ts going red on the debian 13 x64-asan lane (seen in build
    72183

    and build 71964):

    dev| ==1715==ERROR: AddressSanitizer: SEGV on unknown address 0x000000007490
    error: DevServer panicked
          at gracefulExit (test/bake/bake-harness.ts:614:17)
    ✗  DEV:request-cookies-1: request.cookies.get() basic functionality
    

    Cause

    ~DevServerSourceProvider held a raw Zig::GlobalObject* and called
    m_globalObject->bunVM() to reach Bun__removeDevServerSourceProvider.
    Under BUN_DESTRUCT_VM_ON_EXIT=1 (set by the CI runner for the asan
    lane), the harness's process.exit(0) runs
    Zig__GlobalObject__destructOnExit, which does
    gcUnprotect(globalObject) then collectNow(Sync, Full) then two
    vm.derefSuppressingSaferCPPChecking(). The global object cell is swept
    during collectNow, but the provider's last Ref is only released
    later from ~CodeCache inside ~JSC::VM, so the destructor read
    m_bunVM out of a freed cell.

    With bmalloc the freed cell usually still holds the old value and the
    read happens to work, which is why this was ~0.5% in CI and never
    reproduced locally. When the memory is reused with a zero at that offset
    the Rust side receives a null VirtualMachine* and the next access is
    (null)->source_mappings.mutex, which lands at exactly 0x7490.

    Deterministic ASAN backtrace with Malloc=1:

    ==79839==ERROR: AddressSanitizer: heap-use-after-free ...
        #0  Zig::GlobalObject::bunVM() const  ZigGlobalObject.h:353
        #1  Bake::DevServerSourceProvider::~DevServerSourceProvider()  DevServerSourceProvider.h:65
        ...
        #7  JSC::SourceCodeKey::~SourceCodeKey()
        #12 JSC::CodeCacheMap::~CodeCacheMap()
        #16 JSC::VM::~VM()
        #18 Zig__GlobalObject__destructOnExit  ZigGlobalObject.cpp:4049
        #19 VirtualMachine::global_exit  VirtualMachine.rs:1603
        #20 Bun__Process__exit
    

    Fix

    Store the Rust VirtualMachine* directly (void* m_bunVM), captured in
    create(), so the destructor no longer indirects through a GC cell.
    This mirrors Zig::SourceProvider, which already stores m_bunVM for
    the same reason. The Rust VirtualMachine outlives every GC cell (step
    10 of global_exit is self.destroy(), after destructOnExit has
    finished).

    Verification

    New ASAN-only case in test/bake/dev/server-sourcemap.test.ts runs the
    dev server with Malloc=1 + BUN_DESTRUCT_VM_ON_EXIT=1 so ASAN poisons
    the swept global-object cell, making the UAF deterministic. Added an
    env option to the devTest harness so the test can set those for the
    spawned dev server.

    # fail-before (src/ stashed)
    SUMMARY: AddressSanitizer: heap-use-after-free ZigGlobalObject.h:353:48 in Zig::GlobalObject::bunVM() const
    (fail)  DEV:server-sourcemap-5: DevServerSourceProvider destructor does not touch the swept global object on process exit
    
    # pass-after
    (pass)  DEV:server-sourcemap-5: DevServerSourceProvider destructor does not touch the swept global object on process exit
    

    test/bake/dev/server-sourcemap.test.ts (5 tests) and
    test/bake/dev/request-cookies.test.ts (2 tests) are green.
    request-cookies.test.ts now also passes under the full CI LeakSan
    config (BUN_DESTRUCT_VM_ON_EXIT=1 + detect_leaks=1).

    The bug is from a89e61fcaaa (#22138), which introduced
    DevServerSourceProvider with the raw global-object pointer.


    [review] gate passed · iteration 1 · 3 files touched

    fails on main (without fix)
    ASAN without fix: 1 FAILED
    $ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/bake/dev/request-cookies.test.ts test/bake/dev/server-sourcemap.test.ts
    info: syncing channel updates for nightly-2026-05-06-x86_64-unknown-linux-gnu
    info: latest update on 2026-05-06 for version 1.97.0-nightly (e95e73209 2026-05-05)
    info: component rust-src is up to date
    info: checking for self-update (current version: 1.29.0)
    bun test v1.4.0 (722d6f067)
    
    test/bake/dev/server-sourcemap.test.ts:
    Dev server testing directory: /tmp/bun-dev-test-tI2Y82
    bun add v1.4.0 (722d6f067)
    Resolving dependencies
    Resolved, downloaded and extracted [2]
    Saved lockfile
    
    installed react@&ZeroWidthSpace;0.0.0-experimental-603e6108-20241029
    installed react-dom@&ZeroWidthSpace;0.0.0-experimental-603e6108-20241029
    installed react-server-dom-bun@&ZeroWidthSpace;0.0.0-experimental-603e6108-20241029
    installed react-refresh@&ZeroWidthSpace;0.0.0-experimental-603e6108-20241029
    
    6 packages installed [462.00ms]
    bun install v1.4.0 (722d6f067)
    
    Checked 6 installs across 7 packages (no changes) [167.00ms]
    �[0;30mdev|�[0m Started development server: http://localhost:37377
    �[0;30mdev|�[0m �[32mBundled page in 2125ms�[0m�[2m:�[0
    ... (truncated)
    
    release without fix: all passed
    bun test v1.4.0-canary.1 (1498d7b77)
    
    test/bake/dev/server-sourcemap.test.ts:
    Dev server testing directory: /tmp/bun-dev-test-7LPeWv
    bun add v1.4.0-canary.1 (1498d7b77)
    Resolving dependencies
    Resolved, downloaded and extracted [0]
    Saved lockfile
    
    installed react@&ZeroWidthSpace;0.0.0-experimental-603e6108-20241029
    installed react-dom@&ZeroWidthSpace;0.0.0-experimental-603e6108-20241029
    installed react-server-dom-bun@&ZeroWidthSpace;0.0.0-experimental-603e6108-20241029
    installed react-refresh@&ZeroWidthSpace;0.0.0-experimental-603e6108-20241029
    
    6 packages installed [9.00ms]
    bun install v1.4.0-canary.1 (1498d7b77)
    
    Checked 6 installs across 7 packages (no changes) [0.00ms]
    �[0;30mdev|�[0m Started development server: http://localhost:43275
    �[0;30mdev|�[0m �[32mBundled page in 47ms�[0m�[2m:�[0m pages/[...slug].tsx �[2m+ 2 more�[0m
    �[0;30mdev|�[0m �[0m�[1m1 |�[0m �[0m�[35mexport�[0m �[0m�[35mdefault�[0m �[0m�[35masync�[0m �[0m�[35mfunction�[0m MyPage(params) {
    �[0;30mdev|�[0m �[0m�[1m2 |�[0m   myFunc()�[0m�[2m;�[0m
    �[0;30mdev|�[0m �[0m�[1m3 |�[0m   �[0m�[35mreturn�[0m �[0m<�[0mh1>{JSON�[0m�[3m�[1m.stringify�[0m(params)}�[0m<�[0m/h1>�[0m�[2m;�[0m
    �[0;30mdev|�[0m �[0m�[1m4 |�[0m }
    �[0;30mdev|�[0m �[0m�[1m5 |�[0m 
    �[0;30mdev|�[0m �[0m�
    ... (truncated)
    passes on PR (with fix)
    ASAN with fix: all passed
    $ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/bake/dev/request-cookies.test.ts test/bake/dev/server-sourcemap.test.ts
    info: syncing channel updates for nightly-2026-05-06-x86_64-unknown-linux-gnu
    info: latest update on 2026-05-06 for version 1.97.0-nightly (e95e73209 2026-05-05)
    info: component rust-src is up to date
    info: checking for self-update (current version: 1.29.0)
    bun test v1.4.0 (722d6f067)
    
    test/bake/dev/server-sourcemap.test.ts:
    Dev server testing directory: /tmp/bun-dev-test-dkR1se
    bun add v1.4.0 (722d6f067)
    Resolving dependencies
    Resolved, downloaded and extracted [0]
    Saved lockfile
    
    installed react@&ZeroWidthSpace;0.0.0-experimental-603e6108-20241029
    installed react-dom@&ZeroWidthSpace;0.0.0-experimental-603e6108-20241029
    installed react-server-dom-bun@&ZeroWidthSpace;0.0.0-experimental-603e6108-20241029
    installed react-refresh@&ZeroWidthSpace;0.0.0-experimental-603e6108-20241029
    
    6 packages installed [119.00ms]
    bun install v1.4.0 (722d6f067)
    
    Checked 6 installs across 7 packages (no changes) [97.00ms]
    �[0;30mdev|�[0m Started development server: http://localhost:44249
    �[0;30mdev|�[0m �[32mBundled page in 2351ms�[0m�[2m:�[0m
    ... (truncated)
    
    release with fix: all passed
    $ bun scripts/build.ts --profile=release
    info: syncing channel updates for nightly-2026-05-06-x86_64-unknown-linux-gnu
    info: latest update on 2026-05-06 for version 1.97.0-nightly (e95e73209 2026-05-05)
    info: component rust-src is up to date
    info: checking for self-update (current version: 1.29.0)
    [configured] bun-profile → bun (stripped) in 690ms (unchanged)
    ninja: Entering directory `/workspace/bun/build/release'
    [0/6] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu)
    info: syncing channel updates for nightly-2026-05-06-x86_64-unknown-linux-gnu
    info: latest update on 2026-05-06 for version 1.97.0-nightly (e95e73209 2026-05-05)
    info: component rust-src is up to date
    info: component rust-std is up to date
    
      nightly-2026-05-06-x86_64-unknown-linux-gnu unchanged - rustc 1.97.0-nightly (e95e73209 2026-05-05)
    
    info: checking for self-update (current version: 1.29.0)
    �[1m�[92m   Compiling�[0m bun_core v0.0.0 (/workspace/bun/src/bun_core)
    �[1m�[92m   Compiling�[0m bun_errno v0.0.0 (/workspace/bun/src/errno)
    �[1m�[92m   Compiling�[0m bun_ptr v0.0.0 (/workspace/bun/src/ptr)
    �[1m�[92m   Compiling�[0m bun_boringssl_sys v0.0.0 (/workspace/bun/src/boringssl
    ... (truncated)
    diff hotspot
    src/runtime/bake/DevServerSourceProvider.h | 13 +++++++-----
     test/bake/bake-harness.ts                  |  5 +++++
     test/bake/dev/server-sourcemap.test.ts     | 34 ++++++++++++++++++++++++++++++
     3 files changed, 47 insertions(+), 5 deletions(-)
    

    gate history · 1 passed · 0 rejected · iteration 1

    evidence per changed file
    file                                        reads  edits  tests
    src/runtime/bake/DevServerSourceProvider.h      1      2      0
    test/bake/bake-harness.ts                       8      2      0
    test/bake/dev/server-sourcemap.test.ts          1      4      0
    
  • 042ff0 node:stream: leave Readable.toWeb source non-flowing after EOF (#34031)

    Repro

    import { Readable } from "node:stream";
    const src = Readable.from([Buffer.from("a"), Buffer.from("b")], { objectMode: false });
    const rd = Readable.toWeb(src).getReader();
    for (;;) { const { done } = await rd.read(); if (done) break; }
    await new Promise(r => setTimeout(r, 30));
    console.log(`flowing=${src.readableFlowing} isPaused=${src.isPaused()}`);
    node v26.3.0: flowing=false isPaused=true
    bun 1.4.0:    flowing=true  isPaused=false
    

    readableEnded / destroyed agree; only readableFlowing /
    isPaused() diverge, so code that branches on those after the adapter
    finishes (pooling, reuse logic, diagnostics) observes the wrong state.

    Cause

    The toWeb adapter's pull() calls source.resume(). After the source
    emits 'end' and autoDestroys, Node 26's resume() is a no-op on
    destroyed streams (stream: pause/resume on destroyed streams should be noop nodejs/node#62557), so the late pull()s leave the
    source non-flowing.

    Bun dropped that guard in 6abf57e204 so that fd-slicer-style readables
    (yauzl / extract-zip / puppeteer), which assign this.destroyed = true
    right before push(null), can still be resumed by a piped destination's
    'drain' to flush their buffered tail. With no guard at all, the
    adapter's post-EOF resume() flips readableFlowing back to true.

    Fix

    Narrow the resume() guard to kDestroyed && kEndEmitted instead of
    removing it entirely. In the fd-slicer case 'end' has not yet been
    emitted when drain resumes the source, so the narrowed guard does not
    fire and the buffered tail still flushes. Once 'end' has fired there
    is nothing left to flush, so resume() can become a no-op and keep
    state parity with Node.

    pause() is left unchanged; #33467 addresses the mirrored post-pipe
    divergence on the pause() side.

    Verification

    • New test Readable.toWeb leaves the source paused / non-flowing after EOF fails on main (readableFlowing: true, isPaused: false) and passes
      with this change; the same test body passes on Node v26.3.0.
    • The existing fd-slicer regression test (drain still resumes a source that flagged itself destroyed before EOF) still passes.
    • test/js/node/stream/ and the vendored test-stream-*.js parallel
      suite: no new failures relative to main.

    no test proof · iteration 1 · Platform-specific test(s) that do not
    run on this machine. Deferring to CI, which covers all platforms:
    test/js/node/stream/node-stream.test.js

  • af7faf test: stop deliberate crash tests from uploading to CI's crash-report server (#34024)

    test/integration/next-pages/test/dev-server-ssr-100.test.ts was
    reported RED in build
    72106 on :darwin: 26 aarch64 with 5 crashes reported during this test. The test itself is
    fine on main (last four completed main builds 72110/72020/71943/71860
    have no mention of it). The RED was manufactured by CI's crash-report
    attribution.

    Cause

    scripts/runner.node.mjs exports
    BUN_CRASH_REPORT_URL=http://localhost:<remapPort> to every test so
    real crashes are captured. It only drains /traces when a test exits
    non-zero (the known caveat is documented in the runner at the drain
    site).

    run-crash-handler.test.ts spawns processes that crash on purpose with
    env: bunEnv, which inherits that URL, and native-plugin.test.ts's
    "prints name when plugin crashes" does the same via Bun.$. Both files
    pass (exit 0), so their five crash reports stay on the remap server:

    Segmentation fault at address 0x00000000        # native-plugin
    panic: invoked crashByPanic() handler           # run-crash-handler (x2)
    Bun ran out of memory                           # run-crash-handler
    Segmentation fault at address 0xDEADBEEF        # run-crash-handler
    

    In build 72106 a transient npm-registry hang on one tart agent
    (66790-tart-26) made dev-server-ssr-100's bun i block for 100 s
    and time out. That non-zero exit drained /traces, inherited the five
    deliberate crashes, and became error = "crash reported";
    isAlwaysFailure("crash reported") blocks retries, so one transient
    timeout became a hard RED. next-auth.test.ts hit the same npm hang on
    the same agent minutes later, got normal retries, and passed on attempt
    Bump @vscode/web-custom-data from 0.4.5 to 0.4.6 #4.

    Same five reports pinned on unrelated tests in other recent PR builds:

    • build 72095:
      test/js/node/http/node-http-backpressure-max.test.ts ("5 crashes
      reported", identical list)
    • build 72085:
      test/js/web/fetch/fetch-leak.test.ts (segfault at 0x0 from
      native-plugin)

    Fix

    Set BUN_CRASH_REPORT_URL="" (and BUN_ENABLE_CRASH_REPORTING=0 for
    the fall-through branch in is_reporting_enabled()) on every spawn that
    crashes on purpose but is not asserting on upload behaviour:

    • run-crash-handler.test.ts: the three env: bunEnv spawns now use a
      shared noReportEnv.
    • native-plugin.test.ts: the "prints name when plugin crashes" Bun.$
      command sets the two vars inline.

    The "automatic crash reporter" and "raise ignoring panic handler" tests
    already point BUN_CRASH_REPORT_URL at their own local server and are
    unchanged.

    Verification

    Simulated CI's remap server and ran the test file against it:

    before: CI-server hits: 5  (the /ack uploads listed above)
    after:  CI-server hits: 0, 9 pass / 1 skip / 0 fail
    

    bun bd test test/cli/run/run-crash-handler.test.ts passes.
    native-plugin.test.ts "prints name when plugin crashes" is
    skipIf(isASAN) so it is skipped under the debug build; a neighbouring
    case in the same file still loads, and the inline-env override was
    verified separately (Bun.$\VAR="" ...`reaches the child as an empty string, whichis_reporting_enabled()` treats as disabled).

    Test-only change; no src/ diff because the behaviour being fixed lives
    in the CI runner and the child's env, not in bun itself.


    no test proof · iteration 3 · Platform-specific test-only change;
    deferring to CI.

  • e16e6d jest: fix null deref in useFakeTimers when setTimeout is a non-object cell (#34030)

    What does this PR do?

    Fixes a segfault found by fuzzing. jest.useFakeTimers() sets a clock
    marker property on globalThis.setTimeout so that testing-library/react
    can detect fake timers. The guard before the write used is_cell(), but
    strings, symbols and heap bigints are cells that are not objects.
    JSC__JSValue__put does asCell()->getObject() which returns nullptr
    for those and then calls ->putDirect() on it.

    Repro:

    globalThis.setTimeout = "x";
    Bun.jest().jest.useFakeTimers();
    // panic(main thread): Segmentation fault at address 0x0

    Changed the guard to is_object() so the marker write is simply skipped
    when setTimeout has been replaced with a primitive. The
    useRealTimers side was already safe since
    JSC__JSValue__deleteProperty checks isObject() internally.

    How did you verify your code works?

    Added a test.each over string, symbol and bigint that spawns a
    subprocess, overrides setTimeout, calls
    useFakeTimers()/useRealTimers() and asserts clean exit. Segfaults on
    USE_SYSTEM_BUN=1, passes on this build.


    [stamp-90s] gate passed · iteration 2 · 2 files touched

    fails on main (without fix)
    ASAN without fix: 3 FAILED
    $ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/js/bun/test/test-timers.test.ts
    info: syncing channel updates for nightly-2026-05-06-x86_64-unknown-linux-gnu
    info: latest update on 2026-05-06 for version 1.97.0-nightly (e95e73209 2026-05-05)
    info: component rust-src is up to date
    info: checking for self-update (current version: 1.29.0)
    bun test v1.4.0 (a27a303bf)
    
    test/js/bun/test/test-timers.test.ts:
    (pass) we can go back in time [38.51ms]
    (pass) advanceTimersByTime ticks from the setSystemTime value [5.58ms]
    (pass) setSystemTime accepts pre-epoch and epoch times and resets with no argument [4.56ms]
    91 |     env: bunEnv,
    92 |     stdout: "pipe",
    93 |     stderr: "pipe",
    94 |   });
    95 |   const [stdout, stderr, exitCode] = await Promise.all([proc.stdout.text(), proc.stderr.text(), proc.exited]);
    96 |   expect({ stdout, stderr, exitCode }).toEqual({ stdout: "ok\n", stderr: "", exitCode: 0 });
                                                ^
    error: expect(received).toEqual(expected)
    
      {
    -   "exitCode": 0,
    -   "stderr": "",
    -   "stdout": 
    - "ok
    +   "exitCode": 1,
    +   "stderr": 
    + ".
    ... (truncated)
    
    release without fix: all passed
    bun test v1.4.0-canary.1 (764f47f1d)
    
    test/js/bun/test/test-timers.test.ts:
    (pass) we can go back in time [2.73ms]
    (pass) advanceTimersByTime ticks from the setSystemTime value [0.10ms]
    (pass) setSystemTime accepts pre-epoch and epoch times and resets with no argument [0.06ms]
    (pass) useFakeTimers does not crash when globalThis.setTimeout is 'x' [11.80ms]
    (pass) useFakeTimers does not crash when globalThis.setTimeout is Symbol() [11.13ms]
    (pass) useFakeTimers does not crash when globalThis.setTimeout is 1n [11.85ms]
    (pass) real timer heap is ticked against the real clock under useFakeTimers [36.14ms]
    
     7 pass
     0 fail
     27 expect() calls
    Ran 7 tests across 1 file. [231.00ms]
    __F:0:S:0
    passes on PR (with fix)
    ASAN with fix: all passed
    $ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/js/bun/test/test-timers.test.ts
    info: syncing channel updates for nightly-2026-05-06-x86_64-unknown-linux-gnu
    info: latest update on 2026-05-06 for version 1.97.0-nightly (e95e73209 2026-05-05)
    info: component rust-src is up to date
    info: checking for self-update (current version: 1.29.0)
    bun test v1.4.0 (a27a303bf)
    
    test/js/bun/test/test-timers.test.ts:
    (pass) we can go back in time [49.49ms]
    (pass) advanceTimersByTime ticks from the setSystemTime value [6.51ms]
    (pass) setSystemTime accepts pre-epoch and epoch times and resets with no argument [4.69ms]
    (pass) useFakeTimers does not crash when globalThis.setTimeout is 'x' [538.72ms]
    (pass) useFakeTimers does not crash when globalThis.setTimeout is Symbol() [444.00ms]
    (pass) useFakeTimers does not crash when globalThis.setTimeout is 1n [443.49ms]
    (pass) real timer heap is ticked against the real clock under useFakeTimers [1843.89ms]
    
     7 pass
     0 fail
     27 expect() calls
    Ran 7 tests across 1 file. [5.36s]
    __F:0:S:0
    
    release with fix: all passed
    $ bun scripts/build.ts --profile=release
    info: syncing channel updates for nightly-2026-05-06-x86_64-unknown-linux-gnu
    info: latest update on 2026-05-06 for version 1.97.0-nightly (e95e73209 2026-05-05)
    info: component rust-src is up to date
    info: checking for self-update (current version: 1.29.0)
    [configured] bun-profile → bun (stripped) in 709ms (unchanged)
    ninja: Entering directory `/workspace/bun/build/release'
    [1/21] gen generated_host_exports.rs
    generated_host_exports.rs: 91 exports (host=3, lazy=10, generic=78, rust=0); 243 extern-C blocks audited
    [2/21] gen JS modules (bundle-modules)
    Preprocess modules (6796ms)
    Bundle modules (64ms)
    Postprocesss modules (156ms)
    Bundle Functions (697ms)
    Generate Code (79ms)
    
    [7.81s] Bundled "src/js" for production
      1912 kb
      162 internal modules
      12 native modules
      90 internal functions across 19 files
    [2/6] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu)
    info: syncing channel updates for nightly-2026-05-06-x86_64-unknown-linux-gnu
    info: latest update on 2026-05-06 for version 1.97.0-nightly (e95e73209 2026-05-05)
    info: component rust-src is up to date
    info: component rust-std is up to date
    
      nightl
    ... (truncated)
    diff hotspot
    src/runtime/test_runner/timers/FakeTimers.rs |  2 +-
     test/js/bun/test/test-timers.test.ts         | 20 ++++++++++++++++++++
     2 files changed, 21 insertions(+), 1 deletion(-)
    

    gate history · 2 passed · 0 rejected · iteration 2

    evidence per changed file
    file                                          reads  edits  tests
    src/runtime/test_runner/timers/FakeTimers.rs      2      1      0
    test/js/bun/test/test-timers.test.ts              2      1      0
    

    Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@​users.noreply.redirect.github.com>

  • b0b9f6 napi: finalize threadsafe function when last ref is released after abort (#34026)

    Three related mechanisms could leave an aborted
    napi_threadsafe_function with its finalizer never invoked and its
    event-loop keepalive still held, so the process (or Worker) hung at
    exit. Node v26 finalizes and exits 0 in each case.

    Reproduction

    // create + acquire + abort, then on a later tick release the last ref
    napi_create_threadsafe_function(env, cb, ..., /*initial_thread_count=*/1, ..., fin, ..., &tsfn);
    napi_acquire_threadsafe_function(tsfn);                       // thread_count 2
    napi_release_threadsafe_function(tsfn, napi_tsfn_abort);      // thread_count 1, closing
    // ... next tick ...
    napi_release_threadsafe_function(tsfn, napi_tsfn_release);    // thread_count 0

    timeout 5 bun driver.mjs returns 124; fin never runs. The same hang
    reproduces when items are queued before abort, and when two or more
    producers are parked in napi_call_threadsafe_function(..., napi_tsfn_blocking) on a bounded queue at abort time.

    Cause

    • ThreadSafeFunction::release() only called schedule_dispatch()
      under !is_closing(), so releasing the last reference of an
      already-aborted tsfn never reached dispatch_one's thread_count == 0
      finalize path.
    • dispatch_one() returned has_more = !is_closing(), so once closing
      it processed at most one queued item per scheduled dispatch and never
      drained to the finalize path.
    • enqueue()'s blocking wait loop only checked queue occupancy (Node's
      Push() also checks state == kOpen), and release(abort) used
      signal(), so with multiple blocked producers at most one woke.

    Fix

    • release(): when prev_remaining == 1 and the tsfn is already
      closing, schedule a dispatch so dispatch_one observes thread_count == 0 and queues the finalizer. schedule_dispatch() is idempotent via the
      dispatch_state swap.
    • dispatch_one(): keep returning true after dequeuing so
      on_dispatch loops until the queue is empty, where the existing
      thread_count == 0 branch finalizes.
    • enqueue(): guard the blocking wait on !is_closing() and
      broadcast() on abort so every blocked producer observes closing and
      releases its reference.

    Verification

    $ bun bd test test/napi/napi.test.ts -t "napi_threadsafe_function"
    (pass) napi > napi_threadsafe_function > does not hang on finalize
    (pass) napi > napi_threadsafe_function > keeps the event loop alive without async_work
    (pass) napi > napi_threadsafe_function > runs the finalizer and exits when the last reference is released after abort (0 queued items)
    (pass) napi > napi_threadsafe_function > runs the finalizer and exits when the last reference is released after abort (3 queued items)
    (pass) napi > napi_threadsafe_function > wakes blocked producers, runs the finalizer and exits when aborted with a bounded queue
    

    All three new cases time out on the unfixed build and match Node's
    output (finalized: true, exit 0) with the fix. Node's own
    test_threadsafe_function suite continues to pass.


    no test proof · iteration 1 · Platform-specific test(s) that do not
    run on this machine. Deferring to CI, which covers all platforms:
    test/napi/napi.test.ts

  • 3deda1 test(fs): assert on path segment instead of "1234" substring in tmpdirTestMkdir (#34050)

    Repro

    Build 72286 went red on
    test/js/node/fs/fs.test.ts:

    error: expect(received).not.toInclude(expected)
    Expected to not include: "1234"
    Received: "/tmp/buntmp-isTkgw/fs.test.ts/1783876123471b71a01c3"
          at tmpdirTestMkdir (test/js/node/fs/fs.test.ts:91:19)
    

    Cause

    tmpdirTestMkdir() builds ${tmpdir()}/fs.test.ts/${now}/1234/hi where
    now is Date.now().toString() + <8 hex chars>, then asserts that the
    path mkdirSync({recursive: true}) returns (the first directory it
    created) does not include "1234". That fails whenever the Date.now()
    digits happen to contain 1234 as a substring, as 1783876123471 did
    at 2026-07-12T17:08:43Z. The random hex suffix can also produce it.

    The helper has been in place since #14510; this is a time-dependent
    flake, not a recent regression.

    Fix

    Check path.basename(res) against the two leaf segment names ("1234",
    "hi") instead of a substring of the whole path. Same invariant (the
    returned path is a parent of the leaf), no dependence on the digits of
    now.

    Verification

    With now forced to the failing value "1783876123471b71a01c3",
    mkdirSync returns /tmp/fs.test.ts/1783876123471b71a01c3; the old
    assertion fails on the substring while path.basename is the ${now}
    segment and the new assertion passes.

    $ bun bd test test/js/node/fs/fs.test.ts
     400 pass
     6 skip
     0 fail
    

    no test proof · iteration 0 · Platform-specific test-only change;
    deferring to CI.

  • c07bd5 udp: reject out-of-range connect.port instead of silently clamping to 0 (#34029)

    What does this PR do?

    Bun.udpSocket({connect: {port}}) with a port outside 1..=65535 was
    silently rewritten to 0 in UDPSocketConfig::from_js. The socket
    would kernel-connect to port 0, report remoteAddress === undefined,
    and every send()/sendMany() would return true while 100% of the
    datagrams were dropped.

    const rx = await Bun.udpSocket({ socket: { data() { console.log("got a datagram"); } } });
    const badPort = 65536 + rx.port;
    const tx = await Bun.udpSocket({ connect: { hostname: "127.0.0.1", port: badPort } });
    console.log(tx.remoteAddress);   // undefined, yet "connected"
    console.log(tx.send("hello"));   // true
    // "got a datagram" never prints; /proc/net/udp shows tx connected to 0100007F:0000

    The bind side of the same constructor already throws Expected "port" to be an integer between 0 and 65535 for the same values, and node:dgram
    connect() throws ERR_SOCKET_BAD_PORT before any syscall. This change
    replaces the clamp with a throw, matching both.

    The valid range for connect is 1..=65535 (port 0 is not a connectable
    destination; node rejects it too).

    The same clamp shape exists in UDPSocket::js_connect (the native
    target of node:dgram Socket#connect), but that path is guarded by
    validatePort(port, "Port", false) on the JS side so out-of-range
    values never reach it, and #32274 is already touching that line. Left it
    alone here.

    How did you verify your code works?

    Added a parameterized test covering -1, 0, 65536, 99999, NaN,
    Infinity, and a non-numeric string, plus a boundary test that 1 and
    65535 still connect and populate remoteAddress correctly.

    Before: every out-of-range case resolved to a socket with remoteAddress === undefined.
    After: every out-of-range case throws Expected "connect.port" to be an integer between 1 and 65535.

    bun bd test test/js/bun/udp/udp_socket.test.ts
     195 pass
     0 fail
    

    no test proof · iteration 1 · Platform-specific test(s) that do not
    run on this machine. Deferring to CI, which covers all platforms:
    test/js/bun/udp/udp_socket.test.ts


    Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@​users.noreply.redirect.github.com>

  • 2e2230 node:stream: restore the destroyed-stream guard in Readable.prototype.pause (#33467)
  • 43ee03 bundler: keep onBeforeParse NapiExternal alive across GC (#33999)

    What does this PR do?

    Fixes a use-after-free in the native bundler plugin path: the external
    passed to build.onBeforeParse could be garbage collected while the
    build was still running, and the native plugin would then dereference
    freed memory.

    Crash seen during bun init --react=shadcn on macOS x86_64:

    Segmentation fault at address 0x00000000
    
    - 3 unknown/js code
    - JSBundlerPlugin.cpp:325: Bun::BundlerPlugin::NativePluginList::call
    - JSBundlerPlugin.cpp:729: bun_bundler::parse_task::parse_worker::run_from_thread_pool
    - ThreadPool.rs:1241: <bun_threading::thread_pool::Thread>::run
    

    Root cause

    jsBundlerPluginFunction_onBeforeParse stores the user's napi external
    as a raw NapiExternal* inside NativePluginCallback, but
    JSBundlerPlugin::visitAdditionalChildrenInGCThread never visited those
    pointers. The JS builtin runSetupFunction only holds the external in a
    local onBeforeParsePlugins Map, so once processSetupResult returns
    nothing roots it unless the user happens to capture it in an
    onLoad/onResolve closure.

    When GC runs during the build, ~NapiExternal fires the napi finalizer
    and frees the underlying data. NativePluginList::call then reads
    callbacks[i].external->value() off a freed GC cell and hands that
    pointer to the native callback on a worker thread, which dereferences it
    (heap-use-after-free / segfault). The serve / bake dev server keeps the
    plugin around across rebuilds, which makes the window between setup and
    parse large.

    Fix

    Add a WriteBarrierList<NapiExternal> onBeforeParseExternals to
    BundlerPlugin (mirroring deferredPromises), append the external when
    it is registered, and visit it from visitAdditionalChildrenInGCThread.
    The raw pointer in NativePluginCallback stays valid for the lifetime
    of the JSBundlerPlugin.

    How did you verify your code works?

    New test in test/bundler/native-plugin.test.ts spawns a subprocess
    that:

    • creates the external inline with no other JS references
    • forces Bun.gc(true) from a deferred onLoad while the build is
      running
    • asserts the napi finalizer for the external did not run during the
      build

    native_plugin.cc gained a global finalizer counter and a
    getExternalFinalizedCount() export so the test can observe
    finalization without relying on the UAF to actually crash.

    Before: {"finalizedDuringBuild":1,"finalizedAfterBuild":1}
    After: {"finalizedDuringBuild":0,"finalizedAfterBuild":0}


    no test proof · iteration 0 · Platform-specific test(s) that do not
    run on this machine. Deferring to CI, which covers all platforms:
    test/bundler/native-plugin.test.ts


    Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@​users.noreply.redirect.github.com>

  • a66947 test(spawn-pipe-leak): compare per-batch peak RSS instead of a single post-GC sample (#34012)
  • 2176d8 fs: fix fd leak in ReadStream._destroy for { start, autoClose } (dead kReadStreamFastPath branch) (#30920)
  • b16ca1 fix(napi): leak of WTFStringImpl in napi_create_string_latin1 (#32303)
  • 3a8d55 node:fs: skip zero-fill of 256 KB pre-stat buffer in async readFile (#32295)
  • 4b313c shell: fix $.escape corrupting Latin-1 characters and dropping empty strings (#32933)
  • 669563 crypto: use BoringSSL RAND_bytes for node:crypto random functions (#32348)
  • 8624c2 test(proxy-stress-matrix): share proxy pair across concurrent tests (#33984)

    Problem

    test/js/bun/http/proxy-stress-matrix.test.ts went red on darwin 14
    aarch64 in build 71934:

    error: Unable to connect. Is the computer able to access the url?
      path: "https://localhost:60036/",
     errno: 0,
      code: "ConnectionRefused"
    ✗ response matrix > https-proxy → https-origin chunked/deflate 65536B keepalive=true
    334 pass / 1 fail
    

    The runner additionally labelled it "5 crashes reported", which skipped
    the automatic retry; those crashes are the intentional ones from
    run-crash-handler.test.ts and native_plugin_test earlier in the same
    shard that the crash-report collector misattributed (the traces carry
    0xDEADBEEF / invoked crashByPanic() handler). The single
    ConnectionRefused is the actual failure.

    Cause

    Same mechanism #33975 diagnosed for the sibling
    proxy-stress-headers.test.ts: 335 test.concurrent cases each create
    a fresh adversarial proxy + origin, so the file issues ~676 listen(0, "127.0.0.1") calls in <1s under the runner's rolling concurrency
    window. As early tests dispose their servers, a later test's listen(0)
    can be handed a just-freed port while a sibling is still mid-dial (the
    proxy's net.connect(port, "localhost") goes through autoSelectFamily,
    adding async hops between port capture and connect). #33975 left this
    file alone because it was not yet red in CI; now it is.

    Fix

    Share one {http, https} proxy pair from beforeAll across the 316
    tests that use a default stateless proxy (response / upload / stream /
    method matrices). Tests that pass non-default proxy options or assert on
    the full proxy.connections array (trickled, split-CONNECT,
    CONNECT-headers, hop-by-hop, redirect) keep dedicated proxies. This
    drops per-file listen(0) churn from ~676 to ~362.

    The response matrix's per-test proxy.connections assertions are
    preserved: each test owns a unique origin port for the duration of its
    await using scope, so ownConnections() filters the shared proxy's
    append-only log by that port (sliced from the index captured before the
    fetch) to unambiguously recover this test's record under
    test.concurrent, and asserts exactly-one-connection / CONNECT-vs-GET /
    http:// target on it as before.

    335 tests, 1126 expect() calls: identical to main. Introduced by
    #32635; related sibling fix is #33975.

    Verification

    bun bd test test/js/bun/http/proxy-stress-matrix.test.ts                # 335 pass, 1126 expect() (debug+ASAN)
    bun bd test test/js/bun/http/proxy-stress-matrix.test.ts -t "trickled"  # 2 pass, 333 filtered, 0 fail
    

    10 consecutive release runs on linux, all clean (1126 expect() each).
    Build 71938 ran this file
    clean on every darwin lane (14 aarch64 × 2 shards, 14 x64, 26 aarch64 ×
    2).


    [stamp-90s] gate passed · iteration 1 · 1 files touched

    passes on PR (with fix)
    Test-only change.
    
    Debug/ASAN (expected pass):
    $ bun bd test 'test/js/bun/http/proxy-stress-matrix.test.ts'
    $ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test test/js/bun/http/proxy-stress-matrix.test.ts
    info: syncing channel updates for night

@michijs

michijs Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor Author

Bump compute-baseline from 0.4.0 to 0.5.0

Changelog:
Sourced from releases.
        ### v3.33.0## What's New
  • 1171 features
  • 85.0% coverage of BCD

What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.32.0...v3.33.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.32.0## What's New
  • 1171 features
  • 85.3% coverage of BCD
  • Status changes:
    • field-sizing is now Baseline Newly Available
    • has is now Baseline Widely Available
    • loading-lazy is now Baseline Widely Available

What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.31.0...v3.32.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.31.0## What's New
  • 1171 features
  • 85.5% coverage of BCD
  • 3 new features:
    • gap-decorations
    • service-workers-static-routes
    • anchor-positioning-transforms
  • Status changes:
    • Baseline widely available: canvas-reset, cap, counter-set, createimagebitmap, preloading-responsive-images, preserves-pitch, dir-pseudo, exp-functions, linear-easing, masks, nesting, scripting, url-canparse.

What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.30.0...v3.31.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.30.0## What's New

What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.29.0...v3.30.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### compute-baseline/v0.5.0## Breaking Changes
  • Node.js ≥22.22.0 is now required. (#4005)

What's Changed

  • @&ZeroWidthSpace;mdn/browser-compat-data peer dependency has been updated for v8.0.0. (#4071)
  • The type definition of computeBaseline({ compatKeys }) has been relaxed from [string, ...string[]] to string[]. (#3960)

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/compute-baseline/v0.4.0...compute-baseline/v0.5.0

        ### v3.29.0## What's New
  • 3 features: ad-selection, protected-audience, reporting-crashes-storage
  • 5 status changes:
    • Baseline newly available: container-style-queries
    • Baseline widely available: lh, rlh, user-activation, webauthn-public-key-easy

What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.28.0...v3.29.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.28.0## What's New
  • 2 features: meta-refresh, text-fit
  • 4 status changes:
    • Baseline newly available: baseline-shift, open-pseudo, toggleevent-source, wasm-branch-hinting

What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.27.0...v3.28.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.27.0## What's New
  • 7 features: reporting-coep-violations, reporting-crashes, reporting-csp-violations, reporting-deprecation, reporting-integrity-violations, reporting-interventions, reporting-permissions-policy-violations
  • 1 group: reporting
  • 6 status changes:
    • Baseline widely available: clip-path-boxes, user-pseudos
    • Baseline newly available: crisp-edges, js-modules-shared-workers, shared-workers, text-decoration-skip-ink-all

What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.26.0...v3.27.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.26.0## What's New
  • 2 features: opaquerange and usermedia
  • 1 status change:
    • Baseline newly available: contrast-color

What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.25.0...v3.26.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.25.0## What's New
  • 2 features: light-dark-image and canvas-html
  • 3 status changes:
    • Baseline widely available: aria-attribute-reflection and string-wellformed
    • Limited availability: overscroll-behavior (regressed from Baseline widely available due to new inconsistencies between browsers)

What's Changed

New Contributors

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.24.0...v3.25.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.24.0## What's New
  • 6 features: app-migration, device-bound-session-credentials, subresource-integrity, url-cross-origin, url-integrity, url-referrer-policy
  • 1 group: integrity
  • 4 status changes:
    • Baseline newly available: highlight, math-sum-precise
    • Baseline widely available: search, xslt (reverting an erroneous status change from the previous release)

What's Changed

New Contributors

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.23.1...v3.24.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.23.1## What's New
  • 1 status change: xslt regressed from Baseline widely available to limited availability, due to Chrome withdrawing support for the feature.

What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.23.0...v3.23.1

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.23.0## What's New
  • 1 redirect: rect-xywh replaces rect-xywx due to a typo
  • 8 features: bmp, border-shape, dynamic-range-limit, gif, jpeg, languagemodel, navigation-timing-confidence, and web-animations-iterationcomposite
  • 4 groups: fetch, http, image-formats, and mathml
  • 1 status change: clear-site-data regressed from Baseline newly available to limited availability, due to browser bugs previously untracked in upstream data sources.

What's Changed

New Contributors

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.22.1...v3.23.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.22.1## What's New
  • Status changes:
    • Newly available: font-family-math, iterator-concat, readable-byte-streams, reporting, webtransport

What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.22.0...v3.22.1

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.22.0## What's New
  • 2 features: declarative-webmcp, focusgroup
  • 1 group: reading-order
  • Status changes:
    • Newly available: text-indent-each-line, text-indent-hanging
    • Widely available: contain-intrinsic-size, counter-style, device-orientation-events, hyphenate-character, hyphens, image-set, modulepreload, overflow, storage-manager, subgrid, update

What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.21.0...v3.22.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.21.0## What's New
  • 2 features: fetch-formdata and navigator-modelcontext
  • 1 group: webmcp
  • The Baseline status of font-family-math regressed from newly available to limited availability. The feature advanced to newly available prematurely, due to an incorrect version number in upstream data. It's expected to advance correctly in the near future.

What's Changed

New Contributors

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.20.0...v3.21.0

        ### v3.20.0## What's New
  • Features: loading-lazy-media, mathml-full, signature-based-resource-integrity, text-decoration-skip-ink, text-decoration-skip-ink-all, and text-decoration-spelling-grammar

What's Changed

New Contributors

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.19.0...v3.20.0

        ### v3.19.0## What's New
  • 1 feature: abortsignal-timeout

What's Changed

New Contributors

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.18.0...v3.19.0

        ### v3.18.0## What's New
  • 3 features: install, navigation-precommit-handlers, and wasm-jspi

What's Changed

New Contributors

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.17.0...v3.18.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.17.0## What's New
  • The text-wrap-* features have been reorganized and consolidated into text-wrap, text-wrap-balance, and text-wrap-pretty in https://redirect.github.com/web-platform-dx/web-features/pull/2900
  • 8 features: capture-handle, digital-credentials, geolocation-element, languagedetector, manifest-localization, meta-text-scale, random-function, and translator
  • 1 group: geolocation

What's Changed

New Contributors

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.16.0...v3.17.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.16.0## What's New
  • 1 feature: filter-function
  • 1 group: webgpu
  • The display-mode feature is no longer Baseline. The status changed due to previously incomplete upstream data.

What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.15.0...v3.16.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.15.0## What's New

What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.14.0...v3.15.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.14.0## What's New

What's Changed

New Contributors

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.13.0...v3.14.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.13.0## What's New
  • 2 features: permission-policy and feature-policy

What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.12.0...v3.13.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.12.0## What's New
  • 3 new features:
    • wasm-branch-hinting
    • scroll-target-group
    • scroll-marker-targets
  • 1 moved feature:
    • web-install moved to navigator-install
  • Progressed to Baseline Newly Available:
    • document-caretpositionfrompoint
    • event-timing
    • largest-contentful-paint
    • scrollbar-color
    • scrollend
  • Other changes:
    • hidden-until-found is still Limited Availability, but now marked as unsupported in Firefox due to https://bugzil.la/2006040.

What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.11.1...v3.12.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.11.1## What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.11.0...v3.11.1

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.11.0## What's New
  • 6 features: container-anchor-position-queries, interest-invokers, scroll-into-view-container, style-query-range-syntax, toggleevent-source, and web-install.
  • 2 groups: landmark-elements and resource-hints.

What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.10.0...v3.11.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.10.0## What's New
  • Features with the discouraged property have reason and reason_html string properties. These provide a brief summary of why the feature was discouraged by a specification or vendor.
  • Features with the discouraged property may have a removal_date string property. This property marks a feature as pending removal (for dates in the future) or removed from browsers (for dates in the past).

What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.9.3...v3.10.0

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

        ### v3.9.3## What's Changed

Full Changelog: https://redirect.github.com/web-platform-dx/web-features/compare/v3.9.2...v3.9.3

Subscribe to the Upcoming changes announcements thread for news about upcoming releases, such as breaking changes or major features.

Commit history:
  • 798368 Correct EXT_shader_texture_lod description (#4127)
  • 69c20e Bump web-specs from 4.4.0 to 4.5.0 (#4168)

    Bumps web-specs from 4.4.0 to 4.5.0.


    updated-dependencies:

    • dependency-name: web-specs
      dependency-version: 4.5.0
      dependency-type: direct:development
      update-type: version-update:semver-minor
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • 7ba079 Avoid npm@&ZeroWidthSpace;12 while sigstore bug persists (#4169)

    Issue: https://redirect.github.com/npm/cli/issues/9722

  • c1f7d6 Update draft features (#4164)

    Co-authored-by: Elchi3 <349114+Elchi3@​users.noreply.redirect.github.com>
    Co-authored-by: Patrick Brosset <patrickbrosset@​gmail.com>

  • a0b47d feat: map contextoverflow_event and destroy keys (#4166)

    Co-authored-by: Patrick Brosset <patrickbrosset@​gmail.com>

  • 36ac18 supports-at-rule: map at-rule() compat key (#4165)

    Wire css.at-rules.supports.at-rule into the at-rule() feature so its
    status is computed from BCD instead of resolving to empty support.

  • 168485 Bump caniuse-lite from 1.0.30001802 to 1.0.30001803 (#4161)

    Bumps caniuse-lite from 1.0.30001802 to 1.0.30001803.


    updated-dependencies:

    • dependency-name: caniuse-lite
      dependency-version: 1.0.30001803
      dependency-type: direct:development
      update-type: version-update:semver-patch
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • 4f7cf0 Re-ID and re-name mixins to mxin (#4159)

    • Re-ID and re-name mixins to mxin

    • Just rename, don't move

    • 503402 Initial submission for mixins. (#4149)

    • Initial submission for mixins.

    • Update based on Code Review

    • Adding quotes and a newline to match the functions.yml


    Co-authored-by: John Jansen <johnjansen@​microsoft.com>

  • 2b2610 Add heading offset (#4138)
  • bd9116 Increment minor version to v3.33.0 (#4157)

    Co-authored-by: github-actions <github-actions@​redirect.github.com>

  • 15dbb7 Update draft features (#4156)

    Co-authored-by: captainbrosset <1152698+captainbrosset@​users.noreply.redirect.github.com>

  • 8a9ea0 Bump @​mdn/browser-compat-data from 8.0.4 to 8.0.5 (#4154)

    • Bump @​mdn/browser-compat-data from 8.0.4 to 8.0.5

    Bumps @​mdn/browser-compat-data from 8.0.4 to 8.0.5.


    updated-dependencies:

    • dependency-name: "@​mdn/browser-compat-data"
      dependency-version: 8.0.5
      dependency-type: direct:development
      update-type: version-update:semver-patch
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>

    • Refresh dist

    • Harden failing test (there are now 2 line-clamp chrome entries, so let's not hardcode to 1 entry)


    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>
    Co-authored-by: Patrick Brosset <patrick.brosset@​microsoft.com>
    Co-authored-by: Patrick Brosset <patrickbrosset@​gmail.com>

  • a60c46 Bump caniuse-lite from 1.0.30001799 to 1.0.30001802 (#4155)

    Bumps caniuse-lite from 1.0.30001799 to 1.0.30001802.


    updated-dependencies:

    • dependency-name: caniuse-lite
      dependency-version: 1.0.30001802
      dependency-type: direct:development
      update-type: version-update:semver-patch
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • 7add00 Bump actions/checkout from 6.0.3 to 7.0.0 (#4131)

    Bumps actions/checkout from 6.0.3 to 7.0.0.


    updated-dependencies:

    • dependency-name: actions/checkout
      dependency-version: 7.0.0
      dependency-type: direct:production
      update-type: version-update:semver-major
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>
    Co-authored-by: Patrick Brosset <patrickbrosset@​gmail.com>

  • 491947 Assign UIEvent keys to foundational mouse-events (#4059)

    These could reside with any feature that inherits from UIEvent, but
    to the best of my knowledge no events use UIEvent directly, so it
    makes sense to park these with the oldest, most foundational feature
    that implements UIEvent.

    Co-authored-by: Patrick Brosset <patrickbrosset@​gmail.com>

  • 98a9f7 font-stretch: Add svg.global_attributes.font-stretch compat key (#3925)

    Co-authored-by: Patrick Brosset <patrickbrosset@​gmail.com>

  • 8cd205 Bump the types-node group across 1 directory with 1 update (#4139)

    Bumps the types-node group with 1 update in the /packages/web-features directory: @​types/node.

    Updates @&ZeroWidthSpace;types/node from 22.19.21 to 22.20.0

    Updates @&ZeroWidthSpace;types/node from 22.19.21 to 22.20.0


    updated-dependencies:

    • dependency-name: "@​types/node"
      dependency-version: 22.20.0
      dependency-type: direct:development
      update-type: version-update:semver-minor
      dependency-group: types-node
    • dependency-name: "@​types/node"
      dependency-version: 22.20.0
      dependency-type: direct:development
      update-type: version-update:semver-minor
      dependency-group: types-node
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>
    Co-authored-by: Patrick Brosset <patrickbrosset@​gmail.com>

  • e5bc7c Bump web-specs from 4.2.0 to 4.4.0 (#4141)

    Bumps web-specs from 4.2.0 to 4.4.0.


    updated-dependencies:

    • dependency-name: web-specs
      dependency-version: 4.4.0
      dependency-type: direct:development
      update-type: version-update:semver-minor
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • 141124 Bump the development-dependencies group across 1 directory with 2 updates (#4143)

    Bumps the development-dependencies group with 2 updates in the / directory: @​types/node and typescript-eslint.

    Updates @&ZeroWidthSpace;types/node from 22.19.21 to 22.20.0

    Updates typescript-eslint from 8.61.1 to 8.62.0


    updated-dependencies:

    • dependency-name: "@​types/node"
      dependency-version: 22.20.0
      dependency-type: direct:development
      update-type: version-update:semver-minor
      dependency-group: development-dependencies
    • dependency-name: typescript-eslint
      dependency-version: 8.62.0
      dependency-type: direct:development
      update-type: version-update:semver-minor
      dependency-group: development-dependencies
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • 720a40 Increment minor version to v3.32.0 (#4137)

    Co-authored-by: github-actions <github-actions@​redirect.github.com>

  • 9c8c5a Update draft features (#4136)

    Co-authored-by: captainbrosset <1152698+captainbrosset@​users.noreply.redirect.github.com>

  • 463b0d Bump @​mdn/browser-compat-data from 8.0.3 to 8.0.4 (#4129)

    • Bump @​mdn/browser-compat-data from 8.0.3 to 8.0.4

    Bumps @​mdn/browser-compat-data from 8.0.3 to 8.0.4.


    updated-dependencies:

    • dependency-name: "@​mdn/browser-compat-data"
      dependency-version: 8.0.4
      dependency-type: direct:development
      update-type: version-update:semver-patch
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>

    • Update BCD, fix key rename

    • dist


    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>
    Co-authored-by: Keith Cirkel <keithamus@​users.noreply.redirect.github.com>
    Co-authored-by: Patrick Brosset <patrick.brosset@​microsoft.com>
    Co-authored-by: Patrick Brosset <patrickbrosset@​gmail.com>

  • 01b8c5 Bump typescript-eslint (#4130)

    Bumps the development-dependencies group with 1 update in the / directory: typescript-eslint.

    Updates typescript-eslint from 8.61.0 to 8.61.1


    updated-dependencies:

    • dependency-name: typescript-eslint
      dependency-version: 8.61.1
      dependency-type: direct:development
      update-type: version-update:semver-patch
      dependency-group: development-dependencies
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • b47448 Increment minor version to v3.31.0 (#4126)

    Co-authored-by: github-actions <github-actions@​redirect.github.com>

  • 8b9548 Bump the development-dependencies group across 1 directory with 3 updates (#4122)

    Bumps the development-dependencies group with 3 updates in the / directory: prettier, tsx and typescript-eslint.

    Updates prettier from 3.8.3 to 3.8.4

    Updates tsx from 4.22.3 to 4.22.4

    Updates typescript-eslint from 8.60.0 to 8.61.0


    updated-dependencies:

    • dependency-name: prettier
      dependency-version: 3.8.4
      dependency-type: direct:development
      update-type: version-update:semver-patch
      dependency-group: development-dependencies
    • dependency-name: tsx
      dependency-version: 4.22.4
      dependency-type: direct:development
      update-type: version-update:semver-patch
      dependency-group: development-dependencies
    • dependency-name: typescript-eslint
      dependency-version: 8.61.0
      dependency-type: direct:development
      update-type: version-update:semver-minor
      dependency-group: development-dependencies
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>
    Co-authored-by: Patrick Brosset <patrickbrosset@​gmail.com>

  • 38a73b Update draft features (#4125)

    Co-authored-by: captainbrosset <1152698+captainbrosset@​users.noreply.redirect.github.com>

  • ecf282 Bump @​mdn/browser-compat-data from 8.0.2 to 8.0.3 (#4123)

    • Bump @​mdn/browser-compat-data from 8.0.2 to 8.0.3

    Bumps @​mdn/browser-compat-data from 8.0.2 to 8.0.3.


    updated-dependencies:

    • dependency-name: "@​mdn/browser-compat-data"
      dependency-version: 8.0.3
      dependency-type: direct:development
      update-type: version-update:semver-patch
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>

    • Remove keys that got removed from BCD and run dist

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>
    Co-authored-by: Patrick Brosset <patrick.brosset@​microsoft.com>
    Co-authored-by: Patrick Brosset <patrickbrosset@​gmail.com>

  • e61fd0 Bump the types-node group across 1 directory with 1 update (#4121)

    Bumps the types-node group with 1 update in the /packages/web-features directory: @​types/node.

    Updates @&ZeroWidthSpace;types/node from 22.19.19 to 22.19.21

    Updates @&ZeroWidthSpace;types/node from 22.19.19 to 22.19.21


    updated-dependencies:

    • dependency-name: "@​types/node"
      dependency-version: 22.19.21
      dependency-type: dire

@michijs

michijs Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor Author

Bump @​vscode/vsce from 3.7.1 to 3.9.2

Changelog:
Sourced from releases.
        ### v3.9.3-2

Changes:

  • #1289: chore(deps): bump js-yaml and @​textlint/linter-formatter
  • #1288: chore(deps): bump form-data from 4.0.4 to 4.0.6

This list of changes was auto generated.

        ### v3.9.3-1

Changes:

  • #1288: chore(deps): bump form-data from 4.0.4 to 4.0.6

This list of changes was auto generated.

        ### v3.9.3-0

Changes:

  • #1284: chore(deps): bump tmp from 0.2.6 to 0.2.7

This list of changes was auto generated.

        ### v3.9.2

Changes:

  • #1283: fix: skip APIScan
  • #1282: chore: bump CI to Node 22 and fix build
  • #1279: Bump the uuid test fixture version to 100.0.0
  • #1278: Bump tmp from 0.2.4 to 0.2.6
  • #1277: Bump qs from 6.14.2 to 6.15.2
  • #1276: Bump uuid and @​azure/msal-node
  • #1274: Run npm audit fix
  • #1272: Bump fast-uri from 3.0.6 to 3.1.2
  • #1267: Bump minimatch from 10.2.2 to 10.2.3
  • #1247: Update minimatch dependency to v10

This list of changes was auto generated.

        ### v3.9.2-4

Changes:

  • #1283: fix: skip APIScan
  • #1282: chore: bump CI to Node 22 and fix build
  • #1279: Bump the uuid test fixture version to 100.0.0
  • #1278: Bump tmp from 0.2.4 to 0.2.6
  • #1277: Bump qs from 6.14.2 to 6.15.2
  • #1276: Bump uuid and @​azure/msal-node

This list of changes was auto generated.

        ### v3.9.2-3

Changes:

  • #1274: Run npm audit fix

This list of changes was auto generated.

        ### v3.9.2-2

Changes:

  • #1272: Bump fast-uri from 3.0.6 to 3.1.2

This list of changes was auto generated.

        ### v3.9.2-1

Changes:

  • #1267: Bump minimatch from 10.2.2 to 10.2.3

This list of changes was auto generated.

        ### v3.9.2-0

Changes:

  • #1247: Update minimatch dependency to v10

This list of changes was auto generated.

        ### v3.9.1

Changes:

  • #1266: fix: module type mismatch

This list of changes was auto generated.

        ### v3.9.1-0

Changes:

  • #1266: fix: module type mismatch

This list of changes was auto generated.

        ### v3.9.0

Changes:

  • #1263: fix: build regressions in 3.8.1
  • #1261: Add override for serialize-javascript

This list of changes was auto generated.

        ### v3.8.2-1

Changes:

  • #1263: fix: build regressions in 3.8.1

This list of changes was auto generated.

        ### v3.8.2-0

Changes:

  • #1261: Add override for serialize-javascript

This list of changes was auto generated.

        ### v3.8.1

Changes:

  • #1259: chore: update @​azure/identity to 4.13.1 and modernize TypeScript/Node.js configuration

This list of changes was auto generated.

        ### v3.8.1-0

Changes:

  • #1259: chore: update @​azure/identity to 4.13.1 and modernize TypeScript/Node.js configuration

This list of changes was auto generated.

        ### v3.8.0

Changes:

  • #1258: fix: run npm audit fix
  • #1255: Bump brace-expansion
  • #1253: Bump picomatch from 2.3.1 to 2.3.2
  • #1252: Bump yauzl from 2.10.0 to 3.2.1
  • #1250: Bump underscore from 1.13.1 to 1.13.8
  • #1249: Bump minimatch
  • #1243: Bump markdown-it from 14.1.0 to 14.1.1
  • #1244: Bump qs from 6.14.1 to 6.14.2
  • #1239: Bump @​isaacs/brace-expansion from 5.0.0 to 5.0.1
  • #1238: Bump lodash from 4.17.21 to 4.17.23
See More
  • #1234: Bump qs from 6.11.0 to 6.14.1
  • #1233: Return non-zero exit code when signature verification fails
  • #1232: Audit npm package
  • #1228: Bump jws

This list of changes was auto generated.

        ### v3.7.2-13

Changes:

  • #1258: fix: run npm audit fix

This list of changes was auto generated.

        ### v3.7.2-12

Changes:

  • #1255: Bump brace-expansion

This list of changes was auto generated.

        ### v3.7.2-11

Changes:

  • #1253: Bump picomatch from 2.3.1 to 2.3.2

This list of changes was auto generated.

        ### v3.7.2-10

Changes:

  • #1252: Bump yauzl from 2.10.0 to 3.2.1

This list of changes was auto generated.

        ### v3.7.2-9

Changes:

  • #1250: Bump underscore from 1.13.1 to 1.13.8

This list of changes was auto generated.

        ### v3.7.2-8

Changes:

  • #1249: Bump minimatch

This list of changes was auto generated.

        ### v3.7.2-7

Changes:

  • #1243: Bump markdown-it from 14.1.0 to 14.1.1

This list of changes was auto generated.

        ### v3.7.2-6

Changes:

  • #1244: Bump qs from 6.14.1 to 6.14.2

This list of changes was auto generated.

        ### v3.7.2-5

Changes:

  • #1239: Bump @​isaacs/brace-expansion from 5.0.0 to 5.0.1

This list of changes was auto generated.

        ### v3.7.2-4

Changes:

  • #1238: Bump lodash from 4.17.21 to 4.17.23

This list of changes was auto generated.

        ### v3.7.2-3

Changes:

  • #1234: Bump qs from 6.11.0 to 6.14.1

This list of changes was auto generated.

        ### v3.7.2-2

Changes:

  • #1233: Return non-zero exit code when signature verification fails

This list of changes was auto generated.

        ### v3.7.2-1

Changes:

  • #1232: Audit npm package

This list of changes was auto generated.

Commit history:
  • 9c562e chore(deps): bump js-yaml and @​textlint/linter-formatter (#1289)

    Bumps js-yaml and @​textlint/linter-formatter. These dependencies needed to be updated together.

    Updates js-yaml from 4.1.1 to 4.2.0

    Updates @&ZeroWidthSpace;textlint/linter-formatter from 15.2.1 to 15.7.1


    updated-dependencies:

    • dependency-name: js-yaml
      dependency-version: 4.2.0
      dependency-type: indirect
    • dependency-name: "@​textlint/linter-formatter"
      dependency-version: 15.7.1
      dependency-type: indirect
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • 616527 chore(deps): bump form-data from 4.0.4 to 4.0.6 (#1288)

    Bumps form-data from 4.0.4 to 4.0.6.


    updated-dependencies:

    • dependency-name: form-data
      dependency-version: 4.0.6
      dependency-type: direct:production
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • b4de28 Merge pull request #1287 from microsoft/dependabot/npm_and_yarn/markdown-it-14.2.0

    chore(deps): bump markdown-it from 14.1.1 to 14.2.0

  • 55504f chore(deps): bump markdown-it from 14.1.1 to 14.2.0

    Bumps markdown-it from 14.1.1 to 14.2.0.


    updated-dependencies:

    • dependency-name: markdown-it
      dependency-version: 14.2.0
      dependency-type: direct:production
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>

  • 17bf3e chore(deps): bump tmp from 0.2.6 to 0.2.7 (#1284)

    Bumps tmp from 0.2.6 to 0.2.7.


    updated-dependencies:

    • dependency-name: tmp
      dependency-version: 0.2.7
      dependency-type: direct:production
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • f7501f fix: skip APIScan (#1283)
  • 7cd324 chore: bump CI to Node 22 and fix build (#1282)
  • df1a68 Bump the uuid test fixture version to 100.0.0 (#1279)

    • Initial plan

    • test: bump uuid fixture version

    • chore: remove temporary validation logs


    Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@​users.noreply.redirect.github.com>

  • 3a5786 Merge pull request #1278 from microsoft/dependabot/npm_and_yarn/tmp-0.2.6

    Bump tmp from 0.2.4 to 0.2.6

  • 4954e0 Bump tmp from 0.2.4 to 0.2.6

    Bumps tmp from 0.2.4 to 0.2.6.


    updated-dependencies:

    • dependency-name: tmp
      dependency-version: 0.2.6
      dependency-type: direct:production
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>

  • 54dce8 Bump qs from 6.14.2 to 6.15.2 (#1277)

    Bumps qs from 6.14.2 to 6.15.2.


    updated-dependencies:

    • dependency-name: qs
      dependency-version: 6.15.2
      dependency-type: indirect
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • 86fc2d Bump uuid and @​azure/msal-node (#1276)

    Removes uuid. It's no longer used after updating ancestor dependency @​azure/msal-node. These dependencies need to be updated together.

    Removes uuid

    Updates @&ZeroWidthSpace;azure/msal-node from 5.1.2 to 5.2.2


    updated-dependencies:

    • dependency-name: uuid
      dependency-version:
      dependency-type: indirect
    • dependency-name: "@​azure/msal-node"
      dependency-version: 5.2.2
      dependency-type: indirect
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • 469958 Run npm audit fix and update lockfile (#1274)

    Agent-Logs-Url: https://redirect.github.com/microsoft/vscode-vsce/sessions/f2316742-5e81-44c7-ad59-2785c896ae92

    Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@​users.noreply.redirect.github.com>
    Co-authored-by: rzhao271 <7199958+rzhao271@​users.noreply.redirect.github.com>

  • e003a0 Merge pull request #1272 from microsoft/dependabot/npm_and_yarn/fast-uri-3.1.2

    Bump fast-uri from 3.0.6 to 3.1.2

  • 74ab7a Bump fast-uri from 3.0.6 to 3.1.2

    Bumps fast-uri from 3.0.6 to 3.1.2.


    updated-dependencies:

    • dependency-name: fast-uri
      dependency-version: 3.1.2
      dependency-type: indirect
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>

  • 7a3c1c Bump minimatch from 10.2.2 to 10.2.3 (#1267)

    Bumps minimatch from 10.2.2 to 10.2.3.


    updated-dependencies:

    • dependency-name: minimatch
      dependency-version: 10.2.3
      dependency-type: direct:production
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • 54bea4 update minimatch dependency to v10 (#1247)

    Signed-off-by: Andrew Twydell <andrew.twydell@​ibm.com>

  • 98cca9 fix: module type mismatch (#1266)

    Co-authored-by: Copilot <copilot@​redirect.github.com>

  • 9329b3 fix: build regressions in 3.8.1 (#1263)

    • chore: add serialize-javascript override

    Agent-Logs-Url: https://redirect.github.com/microsoft/vscode-vsce/sessions/542e6132-ca27-4a60-b13f-e4d127bc19db

    Co-authored-by: rzhao271 <7199958+rzhao271@​users.noreply.redirect.github.com>

    • chore: update serialize-javascript override to 7.x

    Agent-Logs-Url: https://redirect.github.com/microsoft/vscode-vsce/sessions/1a55d5b2-81b6-49f5-8caf-f6ccee37a4b5

    Co-authored-by: rzhao271 <7199958+rzhao271@​users.noreply.redirect.github.com>

    • chore: refresh lockfile after serialize-javascript override

    Agent-Logs-Url: https://redirect.github.com/microsoft/vscode-vsce/sessions/13bb15ff-ae4f-4d6f-a53e-c9794578e757

    Co-authored-by: rzhao271 <7199958+rzhao271@​users.noreply.redirect.github.com>

    • fix: downgrade engine and fix build

    Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@​users.noreply.redirect.github.com>

  • 165b0f Add override for serialize-javascript (#1261)

    • chore: add serialize-javascript override

    Agent-Logs-Url: https://redirect.github.com/microsoft/vscode-vsce/sessions/542e6132-ca27-4a60-b13f-e4d127bc19db

    Co-authored-by: rzhao271 <7199958+rzhao271@​users.noreply.redirect.github.com>

    • chore: update serialize-javascript override to 7.x

    Agent-Logs-Url: https://redirect.github.com/microsoft/vscode-vsce/sessions/1a55d5b2-81b6-49f5-8caf-f6ccee37a4b5

    Co-authored-by: rzhao271 <7199958+rzhao271@​users.noreply.redirect.github.com>

    • chore: refresh lockfile after serialize-javascript override

    Agent-Logs-Url: https://redirect.github.com/microsoft/vscode-vsce/sessions/13bb15ff-ae4f-4d6f-a53e-c9794578e757

    Co-authored-by: rzhao271 <7199958+rzhao271@​users.noreply.redirect.github.com>


    Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@​users.noreply.redirect.github.com>
    Co-authored-by: rzhao271 <7199958+rzhao271@​users.noreply.redirect.github.com>

  • 7d124a chore: update @​azure/identity to 4.13.1 and modernize TypeScript/Node.js configuration (#1259)

    • chore: update @​azure/identity to 4.13.1

    Agent-Logs-Url: https://redirect.github.com/microsoft/vscode-vsce/sessions/eaaf7c49-62dc-48e3-a4bc-f0b4286e52d5

    Co-authored-by: rzhao271 <7199958+rzhao271@​users.noreply.redirect.github.com>

    • chore: set moduleResolution to nodenext in tsconfig.json

    Agent-Logs-Url: https://redirect.github.com/microsoft/vscode-vsce/sessions/e9cc90e0-f5ea-49d7-9728-9c667e7835f4

    Co-authored-by: rzhao271 <7199958+rzhao271@​users.noreply.redirect.github.com>

    • chore: bump @​types/node to ^22, update engines and CI workflow to Node 22

    Agent-Logs-Url: https://redirect.github.com/microsoft/vscode-vsce/sessions/2dff95b2-a252-43a9-b142-ae81b52bc6d3

    Co-authored-by: rzhao271 <7199958+rzhao271@​users.noreply.redirect.github.com>


    Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@​users.noreply.redirect.github.com>
    Co-authored-by: rzhao271 <7199958+rzhao271@​users.noreply.redirect.github.com>

  • cbdd40 fix: run npm audit fix to update package-lock.json (#1258)

    Agent-Logs-Url: https://redirect.github.com/microsoft/vscode-vsce/sessions/79064f2b-a533-4e09-ac40-4f8bce617f05

    Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@​users.noreply.redirect.github.com>
    Co-authored-by: rzhao271 <7199958+rzhao271@​users.noreply.redirect.github.com>

  • 13c5fa Merge pull request #1255 from microsoft/dependabot/npm_and_yarn/multi-580a7c2f10

    Bump brace-expansion

  • c6f98d Bump brace-expansion

    Bumps and brace-expansion. These dependencies needed to be updated together.

    Updates brace-expansion from 5.0.3 to 5.0.5

    Updates brace-expansion from 1.1.12 to 1.1.13

    Updates brace-expansion from 2.0.2 to 2.0.3


    updated-dependencies:

    • dependency-name: brace-expansion
      dependency-version: 5.0.5
      dependency-type: indirect
    • dependency-name: brace-expansion
      dependency-version: 1.1.13
      dependency-type: indirect
    • dependency-name: brace-expansion
      dependency-version: 2.0.3
      dependency-type: indirect
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>

  • 01da00 Bump picomatch from 2.3.1 to 2.3.2 (#1253)

    Bumps picomatch from 2.3.1 to 2.3.2.


    updated-dependencies:

    • dependency-name: picomatch
      dependency-version: 2.3.2
      dependency-type: indirect
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.redirect.github.com>

  • bb899f Merge pull request #1252 from microsoft/dependabot/npm_and_yarn/yauzl-3.2.1

    Bump yauzl from 2.10.0 to 3.2.1

  • 3f4fa9 Bump yauzl from 2.10.0 to 3.2.1

    Bumps yauzl from 2.10.0 to 3.2.1.


    updated-dependencies:

    • dependency-name: yauzl
      dependency-version: 3.2.1
      dependency-type: direct:production
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>

  • 72f319 Merge pull request #1250 from microsoft/dependabot/npm_and_yarn/underscore-1.13.8

    Bump underscore from 1.13.1 to 1.13.8

  • c65131 Bump underscore from 1.13.1 to 1.13.8

    Bumps underscore from 1.13.1 to 1.13.8.


    updated-dependencies:

    • dependency-name: underscore
      dependency-version: 1.13.8
      dependency-type: indirect
      ...

    Signed-off-by: dependabot[bot] <support@​redirect.github.com>

  • 82cd05 Merge pull request #1249 from microsoft/dependabot/npm_and_yarn/multi-3189fdc835

    Bump minimatch

@lsegurado
lsegurado merged commit f01cc6b into master Jul 13, 2026
6 of 11 checks passed
@lsegurado
lsegurado deleted the michijs-dependabot branch July 13, 2026 08:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant