chore: merge upstream (21 commits, 2026-09-28) - #17
Merged
Merged
Conversation
## Summary - Add `electron:linuxquickdev` to run Electron through the Vite dev server on Linux/amd64. - Build only the native `wavesrv.x64` with the local C compiler; skip generation and `wsh`. ## Verification - Launched the task on Linux/amd64 under a virtual display; the Wave window opened and Vite returned HTTP 200. - Cached restart reached a visible window in about 5 seconds. - The full-build baseline was not timed (Zig is unavailable in this VM).
…kspaces (wavetermdev#3514) ## Summary `wsh workspace list` and `wsh blocks list`'s default "all workspaces" enumeration are built on `wcore.ListWorkspaces`, which excludes any workspace missing `Name`, `Icon`, or `Color`. That's intentional for its other callers: the frontend workspace switcher (`WorkspaceService.ListWorkspaces`) and, as caught in review, the Electron Workspace menu (`emain-menu.ts`) and `Alt+Ctrl+<N>` workspace-switch shortcuts (`emain-tabview.ts`) — all three rely on unsaved (scratch) workspaces staying excluded, since `CreateWindow` deliberately creates one of those for a new window (`CreateWorkspace(..., applyDefaults=false)`) and `DeleteWorkspace` auto-cleans it up on close unless it's since been named. The bug is that the exact same exclusion also blinds the **CLI** to those workspaces — and everything inside them. Confirmed against a real user's database: a workspace holding their own long-running Claude Code session's active tab had never been named, and was completely invisible to `wsh blocks list` the entire time it was in continuous daily use. ## Fix (revised twice through review) - `wcore.ListWorkspaces` is completely unchanged — still excludes unsaved workspaces, still shared by the frontend switcher. - New `wcore.ListAllWorkspaces` includes them too, without ever writing anything to the database. - **A prior revision of this PR pointed the shared `WorkspaceListCommand` RPC at the new function**, on the claim that it was CLI-only — codex correctly caught that this RPC is also called from `emain-menu.ts` and `emain-tabview.ts` (Electron main-process code, a call-site my original search missed entirely), which would have added blank scratch-workspace entries to the Workspace menu and shifted keyboard-shortcut indices. Fixed by adding a **separate** `WorkspaceListAllCommand` RPC (regenerated through the real codegen: `cmd/generatego`, `cmd/generatets`) and pointing only `wsh workspace list` / `wsh blocks list` at it. `WorkspaceListCommand` itself, and every one of its other callers, is untouched. ## Test plan `pkg/wcore/workspace_test.go` — real (non-mocked) sqlite-backed tests via `wstore.InitWStore()`: - `ListWorkspaces` excludes an unsaved workspace and never mutates it. - `ListAllWorkspaces` includes it too, also without mutating anything. ``` go test ./pkg/wcore/... ./pkg/wshrpc/... ``` Also verified a full `npm run build:prod` (electron-vite, compiles main/preload/renderer together) to confirm `emain-menu.ts`/`emain-tabview.ts` build clean and unaffected against the regenerated bindings. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 3.14.1 to 3.15.2. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md">js-yaml's changelog</a>.</em></p> <blockquote> <h2>3.15.2 - 2026-08-26</h2> <h3>Changed</h3> <ul> <li>[backport] Hard-limit merge sequence size to 100.</li> </ul> <h3>Security</h3> <ul> <li>[backport] Count empty mappings in merge sequences toward <code>maxTotalMergeKeys</code> to limit CPU usage, <a href="https://redirect.github.com/nodeca/js-yaml/issues/797">#797</a>.</li> </ul> <h2>3.15.1 - 2026-07-31</h2> <h3>Security</h3> <ul> <li>[backport] Remove quadratic complexity from <code>!!omap</code> duplicate key detection.</li> </ul> <h2>3.15.0 - 2026-06-27</h2> <h3>Added</h3> <ul> <li>Added <code>maxTotalMergeKeys</code> (10000) loader option to limit the total number of keys processed by YAML merge (<code><<</code>) across one <code>safeLoad()</code> / <code>safeLoadAll()</code> call.</li> </ul> <h2>[3.14.2] - 2025-11-15</h2> <h3>Security</h3> <ul> <li>Fix prototype pollution in merge (<<).</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/nodeca/js-yaml/commit/5c45bd6e960603c13644f5cc8b572ca257723b36"><code>5c45bd6</code></a> 3.15.2 released</li> <li><a href="https://github.com/nodeca/js-yaml/commit/5a708f9f4f22e78b87ebe363848cfa4fa4818c0d"><code>5a708f9</code></a> dist rebuild</li> <li><a href="https://github.com/nodeca/js-yaml/commit/3485bc06ff8a0251505f44a00414d90df2466639"><code>3485bc0</code></a> Backport merge limits from v5.4.1</li> <li><a href="https://github.com/nodeca/js-yaml/commit/f34812f1cea794f8c21e0a4e1f3a2584b720f305"><code>f34812f</code></a> Update .gitignore</li> <li><a href="https://github.com/nodeca/js-yaml/commit/ab85ae2c622bc6d8cdbceccafe9f9b7df80463ed"><code>ab85ae2</code></a> 3.15.1 released</li> <li><a href="https://github.com/nodeca/js-yaml/commit/30a5e7647a4454f7bac969bfbbe7eac9921a4279"><code>30a5e76</code></a> dist rebuild</li> <li><a href="https://github.com/nodeca/js-yaml/commit/22a8071ef032117bc6249c330b240ac3aa2d3ded"><code>22a8071</code></a> Backport quadratic complexity fix for !!omap</li> <li><a href="https://github.com/nodeca/js-yaml/commit/c34b6c40027a769eb0d67958ae615268a1d55f54"><code>c34b6c4</code></a> 3.15.0 released</li> <li><a href="https://github.com/nodeca/js-yaml/commit/21e13d363f33501c7ee6ca988b88c29084999f72"><code>21e13d3</code></a> dist rebuild</li> <li><a href="https://github.com/nodeca/js-yaml/commit/4165c62630d64fe4f25fb0d03139c7e137b24b1c"><code>4165c62</code></a> Add v3-legacy tag for publish</li> <li>Additional commits viewable in <a href="https://github.com/nodeca/js-yaml/compare/3.14.1...3.15.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/wavetermdev/waveterm/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.4 to 3.1.7. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/fastify/fast-uri/releases">fast-uri's releases</a>.</em></p> <blockquote> <h2>v3.1.7</h2> <h2>⚠️ Security Warning</h2> <p>This is a security release that fixes the following high-severity security advisories:</p> <ul> <li><a href="https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3">GHSA-qw65-cvwx-89v3</a> — authority injection via an unvalidated port in <code>serialize()</code></li> <li><a href="https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g">GHSA-58mr-gqgx-xq4g</a> — host confusion via unbalanced or misplaced IP-literal brackets</li> </ul> <p>Users of the v3.x release line should upgrade to v3.1.7.</p> <p><strong>Full Changelog</strong>: <a href="https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7">https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7</a></p> <h2>v3.1.6</h2> <h2>⚠️ Security Warning</h2> <p>This release addresses the following high-severity security advisories:</p> <ul> <li><a href="https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8">GHSA-5jgf-p345-68v8</a> — host confusion via skipped IDN canonicalization on scheme-relative references</li> <li><a href="https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf">GHSA-fph4-wmhf-6fwf</a> — server-side request forgery via repeated hostname percent-decoding</li> <li><a href="https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc">GHSA-f65p-4m7j-42xc</a> — server-side request forgery via malformed IPv6 normalization</li> <li><a href="https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp">GHSA-jqff-g426-hqxp</a> — host confusion via percent-encoded scheme normalization</li> </ul> <p>Users of the v3.x release line should upgrade to v3.1.6.</p> <p><strong>Full Changelog</strong>: <a href="https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6">https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6</a></p> <h2>v3.1.5</h2> <h2>⚠️ Security Warning</h2> <p>Fix for <a href="https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7">https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7</a></p> <p><strong>Full Changelog</strong>: <a href="https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5">https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3"><code>412e40a</code></a> Bumped v3.1.7</li> <li><a href="https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01"><code>9f4c943</code></a> fix: backport port and IP-literal validation to v3.x (<a href="https://redirect.github.com/fastify/fast-uri/issues/216">#216</a>)</li> <li><a href="https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588"><code>1eb3ce4</code></a> fix: treat unterminated bracket hosts as reg-names again (<a href="https://redirect.github.com/fastify/fast-uri/issues/214">#214</a>)</li> <li><a href="https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33"><code>6f970b2</code></a> Bumped v3.1.6</li> <li><a href="https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a"><code>d941579</code></a> fix: never run IDN canonicalization on bracketed IP literals</li> <li><a href="https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba"><code>c0f0279</code></a> test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)</li> <li><a href="https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862"><code>37f3417</code></a> Merge commit from fork</li> <li><a href="https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f"><code>607bfbe</code></a> Merge commit from fork</li> <li><a href="https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514"><code>ae92a4c</code></a> Merge commit from fork</li> <li><a href="https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef"><code>444ecda</code></a> Merge commit from fork</li> <li>Additional commits viewable in <a href="https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.7">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/wavetermdev/waveterm/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…rmdev#3290) DeepSeek V4 enables thinking mode by default and requires that the `reasoning_content` field be passed back unchanged in assistant messages during multi-turn conversations. The openai-chat backend, however, does not support this. This PR adds that support, roughly following the pattern that is employed by the anthropic backend. Fixes wavetermdev#3266 ## Flow <details> <summary>reasoning-start, delta, and end SSE events are captured, sent to the frontend, and included in subsequent API calls</summary><br /> When a stream chunk contains reasoning_content in its delta, we now: 1. Emit reasoning-start / reasoning-delta / reasoning-end SSE events to the frontend 2. Capture the full reasoning string on the stored assistant message 3. Round-trip it in subsequent API calls via reasoning_content on the wire format Non-reasoning providers are unaffected — the stream field is absent, the Go field defaults to "", and the omitempty JSON tag keeps it off the wire. </details> ## Automated Testing - tests for round-trip, omitempty, stream chunk parsing, clean, and partial extraction ## Manual Testing - I manually validated that the issue was resolved - I validated that the three other chat modes that come with Wave still work as expected - I validated that tool calls work - **I did _not_ validate any other openai-style custom chat providers other than deepseek** - Sorry, I don't have an API key for this 😔 - I believe the changes are well-guarded, but it seems worth calling out as an area for extra attention **Is there anything else I should cover?** ## Screenshots <details> <summary>Before screenshot, demonstrating issue reproduction</summary><br /> <img width="1387" height="844" alt="Screenshot 2026-05-04 003906" src="https://github.com/user-attachments/assets/08a2b95c-6909-4690-8789-6d95d541b04f" /> </details> <details> <summary>Afterscreenshot, demonstrating issue resolution</summary><br /> <img width="1338" height="851" alt="Screenshot 2026-05-04 003935" src="https://github.com/user-attachments/assets/4e201719-acec-4b80-890b-8699e7f2cfcd" /> </details>
Bumps [image-size](https://github.com/image-size/image-size) from 2.0.2 to 2.0.4. <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/image-size/image-size/commits">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/wavetermdev/waveterm/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [joi](https://github.com/hapijs/joi) from 17.13.3 to 17.13.7. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/hapijs/joi/commit/ed9d7cdd11ef5f7751fd46886f38dc605c9c3995"><code>ed9d7cd</code></a> 17.13.7</li> <li><a href="https://github.com/hapijs/joi/commit/f2729f71839c57c94ac500b4be9e4b5b26d4e637"><code>f2729f7</code></a> Merge pull request <a href="https://redirect.github.com/hapijs/joi/issues/3145">#3145</a> from hapijs/backport/isodate-timeshift-v17</li> <li><a href="https://github.com/hapijs/joi/commit/c43fc964799c9b5f0c6921bf788162b67066ae81"><code>c43fc96</code></a> chore: add regression test for <a href="https://redirect.github.com/hapijs/joi/issues/3143">#3143</a></li> <li><a href="https://github.com/hapijs/joi/commit/115e7b58d5eaaecc5e9b7093d41899ad6fb053ec"><code>115e7b5</code></a> fix(isoDate): pad a bare-hour timeshift with a colon, not just zeros</li> <li><a href="https://github.com/hapijs/joi/commit/850be1ee24be8d548bb09359bdb0cf9fe41635ff"><code>850be1e</code></a> 17.13.6</li> <li><a href="https://github.com/hapijs/joi/commit/9faeecc48b18ec40e3881467645ae9074f0dfa3c"><code>9faeecc</code></a> Merge pull request <a href="https://redirect.github.com/hapijs/joi/issues/3139">#3139</a> from hapijs/chore/backport-messages-proto</li> <li><a href="https://github.com/hapijs/joi/commit/8d0b808f3e874d28f9078f61b7742290989afb36"><code>8d0b808</code></a> fix: prevent messages proto injection</li> <li><a href="https://github.com/hapijs/joi/commit/566e73fa58e72f0a1dcbb3b110ee2f49f33aece3"><code>566e73f</code></a> 17.13.5</li> <li><a href="https://github.com/hapijs/joi/commit/3f3907cd944257e143b22f3bf3f05e71478fa1b1"><code>3f3907c</code></a> Merge pull request <a href="https://redirect.github.com/hapijs/joi/issues/3135">#3135</a> from hapijs/chore/backport-rename-proto</li> <li><a href="https://github.com/hapijs/joi/commit/172ececa192feda532b743d77bc9d3e523d19b01"><code>172ecec</code></a> fix: prevent proto on renames</li> <li>Additional commits viewable in <a href="https://github.com/hapijs/joi/compare/v17.13.3...v17.13.7">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/wavetermdev/waveterm/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [fflate](https://github.com/101arrowz/fflate) from 0.7.4 to 0.7.5. <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/101arrowz/fflate/commits">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/wavetermdev/waveterm/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) from 0.16.7 to 0.16.8. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/humanwhocodes/humanfs/releases">@humanfs/node's releases</a>.</em></p> <blockquote> <h2>node: v0.16.8</h2> <h2><a href="https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8">0.16.8</a> (2026-04-17)</h2> <h3>Bug Fixes</h3> <ul> <li>Include type dependencies at runtime (<a href="https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138">956ce7a</a>), closes <a href="https://redirect.github.com/humanwhocodes/humanfs/issues/145">#145</a></li> </ul> <h3>Dependencies</h3> <ul> <li>The following workspace dependencies were updated <ul> <li>dependencies <ul> <li><code>@humanfs/core</code> bumped from ^0.19.1 to ^0.19.2</li> </ul> </li> </ul> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md">@humanfs/node's changelog</a>.</em></p> <blockquote> <h2><a href="https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8">0.16.8</a> (2026-04-17)</h2> <h3>Bug Fixes</h3> <ul> <li>Ensure symlinks are copied as symlinks in <code>copy()</code> and <code>copyAll()</code> (<a href="https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404">22bbaa44</a>)</li> <li>Include type dependencies at runtime (<a href="https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138">956ce7a</a>), closes <a href="https://redirect.github.com/humanwhocodes/humanfs/issues/145">#145</a></li> </ul> <h3>Dependencies</h3> <ul> <li>The following workspace dependencies were updated <ul> <li>dependencies <ul> <li><code>@humanfs/core</code> bumped from ^0.19.1 to ^0.19.2</li> </ul> </li> </ul> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/humanwhocodes/humanfs/commit/e96070e897f017ae8abd2b0676d98d14e49665cc"><code>e96070e</code></a> chore: release main (<a href="https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node/issues/146">#146</a>)</li> <li><a href="https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404"><code>22bbaa4</code></a> Merge commit from fork</li> <li><a href="https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138"><code>956ce7a</code></a> fix: Include type dependencies at runtime</li> <li>See full diff in <a href="https://github.com/humanwhocodes/humanfs/commits/node-v0.16.8/packages/node">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/wavetermdev/waveterm/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@xmldom/xmldom](https://github.com/xmldom/xmldom) from 0.8.13 to 0.8.15. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/xmldom/xmldom/releases">@xmldom/xmldom's releases</a>.</em></p> <blockquote> <h2>0.8.15</h2> <p><a href="https://github.com/xmldom/xmldom/compare/0.8.14...0.8.15">Commits</a></p> <h3>Fixed</h3> <ul> <li>Security: parsing a deeply or repeatedly namespaced document no longer consumes quadratic memory; the in-scope namespace map is inherited through the prototype chain instead of being copied for every prefix-declaring element (O(N) instead of O(N²)), preventing a denial-of-service reachable from <code>DOMParser.parseFromString</code> with default options. Serialized output is byte-identical. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-965w-775f-mr7g"><code>GHSA-965w-775f-mr7g</code></a></li> <li>Security: attribute de-duplication during parsing is now O(M) instead of O(M²); the <code>NamedNodeMap</code> parse-time dedup path uses a null-prototype membership index, so a well-formed document with a hostile number of duplicate attributes can no longer wedge the parse. Attribute order and duplicate resolution (last value wins, first position kept) are byte-identical, preserving the XML <a href="https://www.w3.org/TR/xml/#uniqattspec">no-duplicate-attributes well-formedness constraint</a>. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-8344-3jmq-59r6"><code>GHSA-8344-3jmq-59r6</code></a></li> <li>Security: trimming trailing whitespace from an XML end tag (<a href="https://www.w3.org/TR/xml/#NT-ETag"><code>ETag</code></a>) is now anchored so it runs in linear time instead of backtracking quadratically on a long whitespace run, preventing a ReDoS reachable from <code>DOMParser.parseFromString</code>. Trimmed output is byte-identical. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-x4fp-j954-r2f4"><code>GHSA-x4fp-j954-r2f4</code></a></li> <li>Security: malformed-input recovery is now linear instead of quadratic — the malformed tag-name scan terminates at an embedded <code><</code>, and <code>Node.prototype.normalize()</code> merges adjacent text nodes in O(K) instead of O(K²) (also reachable programmatically), per <a href="https://dom.spec.whatwg.org/#dom-node-normalize"><code>normalize()</code></a> in the WHATWG DOM spec. DOM output is unchanged; only the reported error text differs. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-93r5-fhx6-vmg9"><code>GHSA-93r5-fhx6-vmg9</code></a></li> <li>Security: <code>XMLSerializer.serializeToString()</code> under <code>{ requireWellFormed: true }</code> now rejects a DocType <code>name</code> that is not a valid XML <a href="https://www.w3.org/TR/xml/#NT-Name"><code>Name</code></a>, throwing <code>InvalidStateError</code> — matching the sibling <code>publicId</code>/<code>systemId</code>/<code>internalSubset</code> checks and preventing XML injection via <code>DocumentType.name</code>. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-27p8-2357-5qqv"><code>GHSA-27p8-2357-5qqv</code></a></li> <li>Security: <code>XMLSerializer.serializeToString()</code> under <code>{ requireWellFormed: true }</code> now validates a processing-instruction target as an XML <a href="https://www.w3.org/TR/xml-names/#NT-NCName"><code>NCName</code></a> and rejects a case-insensitive <code>xml</code>, throwing <code>InvalidStateError</code> — a check <code>0.8.x</code> did not previously perform, preventing PI-target injection via <code>></code>, <code>?</code>, or whitespace. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-c7q8-3ch8-vqpv"><code>GHSA-c7q8-3ch8-vqpv</code></a></li> <li>Security: <code>Document.createEntityReference()</code> now rejects an invalid XML <a href="https://www.w3.org/TR/xml/#NT-Name"><code>Name</code></a> at creation, and <code>XMLSerializer.serializeToString()</code> under <code>{ requireWellFormed: true }</code> validates an <code>EntityReference</code> <code>nodeName</code> as an XML <code>Name</code>, throwing <code>InvalidStateError</code> — preventing XML injection via an entity-reference name. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-6gmq-8vp8-gcm6"><code>GHSA-6gmq-8vp8-gcm6</code></a></li> <li>Security: the parser now reports a not-well-formed end tag whose valid name is followed by trailing content as a recoverable <code>error</code> instead of accepting it silently, per the XML <a href="https://www.w3.org/TR/xml/#NT-ETag"><code>ETag</code></a> production; parsing recovers to the byte-identical DOM. Consumers that want strict rejection can escalate the reported <code>error</code> to fatal via the parser's <code>errorHandler</code>. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-6h8r-xr42-gp59"><code>GHSA-6h8r-xr42-gp59</code></a></li> </ul> <p>Thank you, <a href="https://github.com/ericchiang"><code>@ericchiang</code></a>, <a href="https://github.com/bhaswanthc"><code>@bhaswanthc</code></a>, <a href="https://github.com/arpitjain099"><code>@arpitjain099</code></a>, <a href="https://github.com/Paranoidgrinch"><code>@Paranoidgrinch</code></a>, for your contributions</p> <h2>0.8.14</h2> <p><a href="https://github.com/xmldom/xmldom/compare/0.8.13...0.8.14">Commits</a></p> <h3>Fixed</h3> <ul> <li>Security: <code>XMLSerializer.serializeToString()</code> now also rejects invalid element and attribute names when <code>{ requireWellFormed: true }</code> is passed, throwing <code>InvalidStateError</code> for a name that is not a valid XML <a href="https://www.w3.org/TR/xml-names/#NT-QName"><code>QName</code></a> (this covers the namespace prefix, which surfaces in the element qualified name or in a synthesized <code>xmlns:</code> declaration). This prevents XML injection via <code>createElement()</code> / <code>setAttribute()</code>, extending the existing <code>requireWellFormed</code> checks to the serialized name set. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-w2rr-34g9-rvrj"><code>GHSA-w2rr-34g9-rvrj</code></a> <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-4w3w-2rp5-g8jm"><code>GHSA-4w3w-2rp5-g8jm</code></a></li> </ul> <p>Thank you, <a href="https://github.com/bhaswanthc"><code>@bhaswanthc</code></a>, <a href="https://github.com/jmestwa-coder"><code>@jmestwa-coder</code></a>, for your contributions</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/xmldom/xmldom/blob/master/CHANGELOG.md">@xmldom/xmldom's changelog</a>.</em></p> <blockquote> <h2><a href="https://github.com/xmldom/xmldom/compare/0.8.14...0.8.15">0.8.15</a></h2> <h3>Fixed</h3> <ul> <li>Security: parsing a deeply or repeatedly namespaced document no longer consumes quadratic memory; the in-scope namespace map is inherited through the prototype chain instead of being copied for every prefix-declaring element (O(N) instead of O(N²)), preventing a denial-of-service reachable from <code>DOMParser.parseFromString</code> with default options. Serialized output is byte-identical. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-965w-775f-mr7g"><code>GHSA-965w-775f-mr7g</code></a></li> <li>Security: attribute de-duplication during parsing is now O(M) instead of O(M²); the <code>NamedNodeMap</code> parse-time dedup path uses a null-prototype membership index, so a well-formed document with a hostile number of duplicate attributes can no longer wedge the parse. Attribute order and duplicate resolution (last value wins, first position kept) are byte-identical, preserving the XML <a href="https://www.w3.org/TR/xml/#uniqattspec">no-duplicate-attributes well-formedness constraint</a>. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-8344-3jmq-59r6"><code>GHSA-8344-3jmq-59r6</code></a></li> <li>Security: trimming trailing whitespace from an XML end tag (<a href="https://www.w3.org/TR/xml/#NT-ETag"><code>ETag</code></a>) is now anchored so it runs in linear time instead of backtracking quadratically on a long whitespace run, preventing a ReDoS reachable from <code>DOMParser.parseFromString</code>. Trimmed output is byte-identical. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-x4fp-j954-r2f4"><code>GHSA-x4fp-j954-r2f4</code></a></li> <li>Security: malformed-input recovery is now linear instead of quadratic — the malformed tag-name scan terminates at an embedded <code><</code>, and <code>Node.prototype.normalize()</code> merges adjacent text nodes in O(K) instead of O(K²) (also reachable programmatically), per <a href="https://dom.spec.whatwg.org/#dom-node-normalize"><code>normalize()</code></a> in the WHATWG DOM spec. DOM output is unchanged; only the reported error text differs. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-93r5-fhx6-vmg9"><code>GHSA-93r5-fhx6-vmg9</code></a></li> <li>Security: <code>XMLSerializer.serializeToString()</code> under <code>{ requireWellFormed: true }</code> now rejects a DocType <code>name</code> that is not a valid XML <a href="https://www.w3.org/TR/xml/#NT-Name"><code>Name</code></a>, throwing <code>InvalidStateError</code> — matching the sibling <code>publicId</code>/<code>systemId</code>/<code>internalSubset</code> checks and preventing XML injection via <code>DocumentType.name</code>. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-27p8-2357-5qqv"><code>GHSA-27p8-2357-5qqv</code></a></li> <li>Security: <code>XMLSerializer.serializeToString()</code> under <code>{ requireWellFormed: true }</code> now validates a processing-instruction target as an XML <a href="https://www.w3.org/TR/xml-names/#NT-NCName"><code>NCName</code></a> and rejects a case-insensitive <code>xml</code>, throwing <code>InvalidStateError</code> — a check <code>0.8.x</code> did not previously perform, preventing PI-target injection via <code>></code>, <code>?</code>, or whitespace. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-c7q8-3ch8-vqpv"><code>GHSA-c7q8-3ch8-vqpv</code></a></li> <li>Security: <code>Document.createEntityReference()</code> now rejects an invalid XML <a href="https://www.w3.org/TR/xml/#NT-Name"><code>Name</code></a> at creation, and <code>XMLSerializer.serializeToString()</code> under <code>{ requireWellFormed: true }</code> validates an <code>EntityReference</code> <code>nodeName</code> as an XML <code>Name</code>, throwing <code>InvalidStateError</code> — preventing XML injection via an entity-reference name. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-6gmq-8vp8-gcm6"><code>GHSA-6gmq-8vp8-gcm6</code></a></li> <li>Security: the parser now reports a not-well-formed end tag whose valid name is followed by trailing content as a recoverable <code>error</code> instead of accepting it silently, per the XML <a href="https://www.w3.org/TR/xml/#NT-ETag"><code>ETag</code></a> production; parsing recovers to the byte-identical DOM. Consumers that want strict rejection can escalate the reported <code>error</code> to fatal via the parser's <code>errorHandler</code>. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-6h8r-xr42-gp59"><code>GHSA-6h8r-xr42-gp59</code></a></li> </ul> <p>Thank you, <a href="https://github.com/ericchiang"><code>@ericchiang</code></a>, <a href="https://github.com/bhaswanthc"><code>@bhaswanthc</code></a>, <a href="https://github.com/arpitjain099"><code>@arpitjain099</code></a>, <a href="https://github.com/Paranoidgrinch"><code>@Paranoidgrinch</code></a>, for your contributions</p> <h2><a href="https://github.com/xmldom/xmldom/compare/0.9.10...0.9.11">0.9.11</a></h2> <h3>Fixed</h3> <ul> <li>Security: <code>XMLSerializer.serializeToString()</code> now also rejects invalid element and attribute names when <code>{ requireWellFormed: true }</code> is passed, throwing <code>InvalidStateError</code> for a name that is not a valid XML <a href="https://www.w3.org/TR/xml-names/#NT-QName"><code>QName</code></a> (this covers the namespace prefix, which surfaces in the element qualified name or in a synthesized <code>xmlns:</code> declaration). This prevents XML injection via <code>createElement()</code> / <code>setAttribute()</code>, extending the existing <code>requireWellFormed</code> checks to the serialized name set. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-w2rr-34g9-rvrj"><code>GHSA-w2rr-34g9-rvrj</code></a> <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-4w3w-2rp5-g8jm"><code>GHSA-4w3w-2rp5-g8jm</code></a></li> <li>Security: the processing-instruction grammar regex no longer backtracks quadratically on an unterminated processing instruction (<code><?…</code> with no closing <code>?></code>), preventing a denial-of-service (ReDoS) reachable from <code>DOMParser.parseFromString</code> with default options. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-g53g-w8rj-fmg7"><code>GHSA-g53g-w8rj-fmg7</code></a></li> <li><code>CharacterData</code> <code>nodeValue</code> and <code>data</code> are now kept in sync <a href="https://redirect.github.com/xmldom/xmldom/pull/990"><code>[#990](https://github.com/xmldom/xmldom/issues/990)</code></a></li> </ul> <h3>Chore</h3> <ul> <li>updated dependencies</li> </ul> <p>Thank you, <a href="https://github.com/bhaswanthc"><code>@bhaswanthc</code></a>, <a href="https://github.com/jmestwa-coder"><code>@jmestwa-coder</code></a>, <a href="https://github.com/stevenobiajulu"><code>@stevenobiajulu</code></a>, for your contributions</p> <h2><a href="https://github.com/xmldom/xmldom/compare/0.8.13...0.8.14">0.8.14</a></h2> <h3>Fixed</h3> <ul> <li>Security: <code>XMLSerializer.serializeToString()</code> now also rejects invalid element and attribute names when <code>{ requireWellFormed: true }</code> is passed, throwing <code>InvalidStateError</code> for a name that is not a valid XML <a href="https://www.w3.org/TR/xml-names/#NT-QName"><code>QName</code></a> (this covers the namespace prefix, which surfaces in the element qualified name or in a synthesized <code>xmlns:</code> declaration). This prevents XML injection via <code>createElement()</code> / <code>setAttribute()</code>, extending the existing <code>requireWellFormed</code> checks to the serialized name set. <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-w2rr-34g9-rvrj"><code>GHSA-w2rr-34g9-rvrj</code></a> <a href="https://github.com/xmldom/xmldom/security/advisories/GHSA-4w3w-2rp5-g8jm"><code>GHSA-4w3w-2rp5-g8jm</code></a></li> </ul> <p>Thank you, <a href="https://github.com/bhaswanthc"><code>@bhaswanthc</code></a>, <a href="https://github.com/jmestwa-coder"><code>@jmestwa-coder</code></a>, for your contributions</p> <h2><a href="https://github.com/xmldom/xmldom/compare/0.9.9...0.9.10">0.9.10</a></h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/xmldom/xmldom/commit/b5b8fb5b579ae1183b34e74b3bc39d7eb50a226a"><code>b5b8fb5</code></a> 0.8.15</li> <li><a href="https://github.com/xmldom/xmldom/commit/327508ea98d169285b2c0559836332a9879de213"><code>327508e</code></a> docs: add 0.8.15 CHANGELOG entry</li> <li><a href="https://github.com/xmldom/xmldom/commit/f40ccb861eee0acbf5ee4feb9a34932e87b329c9"><code>f40ccb8</code></a> fix: prevent quadratic malformed-tag recovery and normalize() adjacent-text m...</li> <li><a href="https://github.com/xmldom/xmldom/commit/3abb0934f5a8a84d83a1f9cde0f2bd04c08b2a09"><code>3abb093</code></a> fix: prevent end-tag whitespace-trim ReDoS via anchored trim (GHSA-x4fp-j954-...</li> <li><a href="https://github.com/xmldom/xmldom/commit/2c548f200cfec991cd5846627ef8f03542309213"><code>2c548f2</code></a> fix: prevent quadratic attribute de-duplication via null-prototype membership...</li> <li><a href="https://github.com/xmldom/xmldom/commit/08a74b47c7f29d2e9b3212682856b959040d1838"><code>08a74b4</code></a> test: characterize NamedNodeMap attribute de-duplication before the index ref...</li> <li><a href="https://github.com/xmldom/xmldom/commit/954370f58c046223faf95ba77efcbc8ce014409d"><code>954370f</code></a> fix: prevent quadratic namespace-map memory consumption via prototype-chain i...</li> <li><a href="https://github.com/xmldom/xmldom/commit/4430189660b0d380ee9c9ee7550a1358688e8828"><code>4430189</code></a> fix: report not-well-formed end-tag trailing content (GHSA-6h8r-xr42-gp59)</li> <li><a href="https://github.com/xmldom/xmldom/commit/6c3fb5ffeafe7901ec928ce9010988dd716c94a0"><code>6c3fb5f</code></a> fix: prevent XML injection via unsafe EntityReference name (GHSA-6gmq-8vp8-gcm6)</li> <li><a href="https://github.com/xmldom/xmldom/commit/3b694872bcb5c7e3cbadba961a4be2488750ce5b"><code>3b69487</code></a> fix: prevent XML injection via unsafe processing instruction target serializa...</li> <li>Additional commits viewable in <a href="https://github.com/xmldom/xmldom/compare/0.8.13...0.8.15">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~karfau">karfau</a>, a new releaser for <code>@xmldom/xmldom</code> since your current version.</p> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/wavetermdev/waveterm/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [browserslist](https://github.com/browserslist/browserslist) from 4.28.1 to 4.28.8. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/browserslist/browserslist/releases">browserslist's releases</a>.</em></p> <blockquote> <h2>4.28.8</h2> <ul> <li>Fixed <code>including kaios</code> in baseline queries (by <a href="https://github.com/Jaybhade"><code>@Jaybhade</code></a>).</li> </ul> <h2>4.28.7</h2> <ul> <li>Improved parsing performance.</li> <li>Fixed unbounded memory growth (by <a href="https://github.com/alanturing881"><code>@alanturing881</code></a>).</li> <li>Fixed prototype write issue (by <a href="https://github.com/alanturing881"><code>@alanturing881</code></a>).</li> </ul> <h2>4.28.6</h2> <ul> <li>Fixed Electron version queries (by <a href="https://github.com/spokodev"><code>@spokodev</code></a>).</li> </ul> <h2>4.28.5</h2> <ul> <li>Fixed <code>></code> and <code>>=</code> queries (by <a href="https://github.com/spokodev"><code>@spokodev</code></a>).</li> </ul> <h2>4.28.4</h2> <ul> <li>Fixed <code>SyntaxError</code> regression of 4.28.3.</li> </ul> <h2>4.28.3</h2> <ul> <li>Fixed baseline query case-insensitivity (by <a href="https://github.com/swwind"><code>@swwind</code></a>).</li> </ul> <h2>4.28.2</h2> <ul> <li>Fix prototype pollution (by <a href="https://github.com/chluo1997"><code>@chluo1997</code></a>).</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md">browserslist's changelog</a>.</em></p> <blockquote> <h2>4.28.8</h2> <ul> <li>Fixed <code>including kaios</code> in baseline queries (by <a href="https://github.com/Jaybhade"><code>@Jaybhade</code></a>).</li> </ul> <h2>4.28.7</h2> <ul> <li>Improved parsing performance.</li> <li>Fixed unbounded memory growth (by <a href="https://github.com/alanturing881"><code>@alanturing881</code></a>).</li> <li>Fixed prototype write issue (by <a href="https://github.com/alanturing881"><code>@alanturing881</code></a>).</li> </ul> <h2>4.28.6</h2> <ul> <li>Fixed Electron version queries (by <a href="https://github.com/spokodev"><code>@spokodev</code></a>).</li> </ul> <h2>4.28.5</h2> <ul> <li>Fixed <code>></code> and <code>>=</code> queries (by <a href="https://github.com/spokodev"><code>@spokodev</code></a>).</li> </ul> <h2>4.28.4</h2> <ul> <li>Fixed <code>SyntaxError</code> regression of 4.28.3.</li> </ul> <h2>4.28.3</h2> <ul> <li>Fixed baseline query case-insensitivity (by <a href="https://github.com/swwind"><code>@swwind</code></a>).</li> </ul> <h2>4.28.2</h2> <ul> <li>Fix prototype pollution (by <a href="https://github.com/chluo1997"><code>@chluo1997</code></a>).</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/browserslist/browserslist/commit/f2f2e6cfb01bb4942941d328737546f4e2ae41ad"><code>f2f2e6c</code></a> Release 4.28.8 version</li> <li><a href="https://github.com/browserslist/browserslist/commit/d0787c88fa29ba895fea51cfe921232c7b5d1377"><code>d0787c8</code></a> Update dependencies</li> <li><a href="https://github.com/browserslist/browserslist/commit/fcf8fa9857b30ccdf801a548f5d09d3c4ff0d43f"><code>fcf8fa9</code></a> Merge pull request <a href="https://redirect.github.com/browserslist/browserslist/issues/939">#939</a> from Jaybhade/fix/baseline-kaios-without-downstream</li> <li><a href="https://github.com/browserslist/browserslist/commit/57ecd64454e9252afdd6a7e76926e13dda48a38c"><code>57ecd64</code></a> fix: support "including kaios" without downstream</li> <li><a href="https://github.com/browserslist/browserslist/commit/093a0f67bb0becda55235d767b134df3197c54a1"><code>093a0f6</code></a> Update EM banner</li> <li><a href="https://github.com/browserslist/browserslist/commit/b637868045806d2fba4c24eb0060e4cc8b1db276"><code>b637868</code></a> Release 4.28.7 version</li> <li><a href="https://github.com/browserslist/browserslist/commit/313f4659b9f985ade89d1d6a54a860371c41cc46"><code>313f465</code></a> Update dependencies</li> <li><a href="https://github.com/browserslist/browserslist/commit/c935c5a206f8b13db8846818bc03643e147dcbdf"><code>c935c5a</code></a> Fix regexp performance</li> <li><a href="https://github.com/browserslist/browserslist/commit/d7e9e653cb53399065943f59f0b3063987b0a008"><code>d7e9e65</code></a> Rewrite structure parsing to make it always fast</li> <li><a href="https://github.com/browserslist/browserslist/commit/ec4a55efd76bdfa506ec7ce4fea1691559e9ca8f"><code>ec4a55e</code></a> Fix import order</li> <li>Additional commits viewable in <a href="https://github.com/browserslist/browserslist/compare/4.28.1...4.28.8">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for browserslist since your current version.</p> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/wavetermdev/waveterm/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.82.1 to 1.83.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/grpc/grpc-go/releases">google.golang.org/grpc's releases</a>.</em></p> <blockquote> <h2>Release 1.83.1</h2> <h1>Security</h1> <ul> <li>xds/rbac: Fix a bug where nested <code>Principal</code> or <code>Permission</code> rules with <code>:scheme</code> or <code>grpc-</code> prefixed header matchers were not rejected, which could cause DENY rules to fail open. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9258">#9258</a>) <ul> <li>Special Thanks: <a href="https://github.com/nvxbug"><code>@nvxbug</code></a></li> </ul> </li> <li>xds/rbac: Fix a bug where the <code>host</code> header matcher was not being replaced with <code>:authority</code> in nested <code>Principal</code> or <code>Permission</code> rules. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9258">#9258</a>) <ul> <li>Special Thanks: <a href="https://github.com/nvxbug"><code>@nvxbug</code></a></li> </ul> </li> <li>xds/rbac: Fix a bug where a header matcher whose name was not lowercase, such as <code>X-Role</code>, matched no header, which could cause DENY rules to fail open. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9332">#9332</a>) <ul> <li>Special Thanks: <a href="https://github.com/alimony"><code>@alimony</code></a></li> </ul> </li> <li>xds/rbac: Fix a bug where a <code>:scheme</code> or <code>grpc-</code> prefixed header matcher was accepted when its name was not lowercase. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9332">#9332</a>) <ul> <li>Special Thanks: <a href="https://github.com/alimony"><code>@alimony</code></a></li> </ul> </li> <li>xds/rbac: Fix a bug where a <code>Host</code> header matcher was not replaced with <code>:authority</code>. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9332">#9332</a>) <ul> <li>Special Thanks: <a href="https://github.com/alimony"><code>@alimony</code></a></li> </ul> </li> </ul> <h1>Performance</h1> <ul> <li>transport: Restrict memory overhead of buffering small data frames. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9331">#9331</a>)</li> </ul> <h2>Release 1.83.0</h2> <h1>Security</h1> <ul> <li>server: Stop reading from connections when flooded by HTTP/2 frames to mitigate resource exhaustion. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable <code>GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT</code>.</li> <li>xds/rbac: Support <code>Metadata</code> and <code>RequestedServerName</code> permissions matcher fields. If present in a DENY rule, previously these would be ignored and fail-open.</li> <li>xds/rbac: Fix panic when parsing unsupported fields in <code>NotRule</code>/<code>NotId</code> permissions.</li> <li>xds/rbac: Support the deprecated <code>source_ip</code> principal identifier by treating it as equivalent to <code>direct_remote_ip</code>.</li> <li>xds: Fix panic when parsing route header matchers configured with empty <code>exact_match</code>, <code>prefix_match</code>, or <code>suffix_match</code> strings. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9223">#9223</a>)</li> </ul> <h1>New Features</h1> <ul> <li>xds/googlec2p: Enable DirectPath over Interconnect support for on-premises clients via the <code>force-xds</code> target URI query parameter. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9133">#9133</a>)</li> <li>xds: Enable xDS configuration to control which fields get propagated from ORCA backend metric reports to LRS load reports. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9145">#9145</a>)</li> <li>authz: Add <code>OnPolicyUpdate</code> callback to <code>FileWatcherOptions</code> to notify when an authz policy is loaded or updated. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9142">#9142</a>) <ul> <li>Special Thanks: <a href="https://github.com/hnefatl"><code>@hnefatl</code></a></li> </ul> </li> <li>xds: Add support for the GCP Authentication HTTP Filter, which automatically fetches and attaches GCP Service Account Identity JWT tokens to outgoing RPCs. <ul> <li>This feature can be enabled by setting environment variable <code>GRPC_EXPERIMENTAL_XDS_GCP_AUTHENTICATION_FILTER=true</code>. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9119">#9119</a>)</li> </ul> </li> <li>xds: Add support for xDS-based HTTP CONNECT proxies. <ul> <li>This feature can be enabled by setting environment variable <code>GRPC_EXPERIMENTAL_XDS_HTTP_CONNECT=true</code>. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9151">#9151</a>)</li> </ul> </li> <li>xds: Add support for <code>contains_match</code> in route header matchers. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9223">#9223</a>)</li> </ul> <h1>Bug Fixes</h1> <ul> <li>credentials/alts: Fix panic when processing malformed frames by validating that the message frame length exceeds the message type field size. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9197">#9197</a>)</li> <li>grpc: Fix compilation on Plan 9 targets (<code>GOOS=plan9</code>), broken since v1.81.0. (<a href="https://redirect.github.com/grpc/grpc-go/issues/9255">#9255</a>) <ul> <li>Special Thanks: <a href="https://github.com/Yusufihsangorgel"><code>@Yusufihsangorgel</code></a></li> </ul> </li> </ul> <h2>Release 1.82.2</h2> <h1>Security</h1> <ul> <li>server: Reject requests missing both <code>:authority</code> and <code>Host</code> headers with HTTP 400 and status <code>Internal</code>. (<a href="https://redirect.github.com/grpc/grpc-go/pull/9365">grpc/grpc-go#9365</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/grpc/grpc-go/commit/1550d9e0cddb30ce99e61a2102e8294a49461e5e"><code>1550d9e</code></a> Change version to 1.83.1 (<a href="https://redirect.github.com/grpc/grpc-go/issues/9336">#9336</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/ebba6f3f1b206e2b4dc4d1d5a96d18430302c2fe"><code>ebba6f3</code></a> Cherry-pick <a href="https://redirect.github.com/grpc/grpc-go/issues/9258">#9258</a> and <a href="https://redirect.github.com/grpc/grpc-go/issues/9332">#9332</a> into v1.83.x (<a href="https://redirect.github.com/grpc/grpc-go/issues/9335">#9335</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77"><code>8cfeca0</code></a> Cherry-pick <a href="https://redirect.github.com/grpc/grpc-go/issues/9331">#9331</a> to v1.83.x (<a href="https://redirect.github.com/grpc/grpc-go/issues/9333">#9333</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/dec6951305e88906696f1d0a00dd2439363bc708"><code>dec6951</code></a> Change version to 1.83.1-dev (<a href="https://redirect.github.com/grpc/grpc-go/issues/9229">#9229</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/4c226daff88f54441d70f710815e07b81fb162b2"><code>4c226da</code></a> Change version to 1.83.0 (<a href="https://redirect.github.com/grpc/grpc-go/issues/9228">#9228</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/c198988aa9297cb9428c7afaaee4363d0082b838"><code>c198988</code></a> Cherrypick 9223 into v1.83.x (<a href="https://redirect.github.com/grpc/grpc-go/issues/9279">#9279</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/8ce3ebf24af3c206bacf279adcf9c3a88981df68"><code>8ce3ebf</code></a> Cherrypick PR 9255 into v1.83.x (<a href="https://redirect.github.com/grpc/grpc-go/issues/9263">#9263</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/e39384978cf59c70634f900a7aa93d7483886696"><code>e393849</code></a> Cherry-pick recent changes from master (<a href="https://redirect.github.com/grpc/grpc-go/issues/9240">#9240</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/2a112a82f5c53ab3b89b5aa4a02b4195e2706879"><code>2a112a8</code></a> authz: add onPolicyUpdate callback to authz file watcher (<a href="https://redirect.github.com/grpc/grpc-go/issues/9142">#9142</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/1a80fca960d39ae4d7d6f2d9323ca2d243fd44bb"><code>1a80fca</code></a> vet: adds a check to disallow usage of regex.Compile in xDS code (<a href="https://redirect.github.com/grpc/grpc-go/issues/9216">#9216</a>)</li> <li>Additional commits viewable in <a href="https://github.com/grpc/grpc-go/compare/v1.82.1...v1.83.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/wavetermdev/waveterm/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [nanoid](https://github.com/ai/nanoid) from 3.3.11 to 3.3.18. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/ai/nanoid/releases">nanoid's releases</a>.</em></p> <blockquote> <h2>3.3.18</h2> <ul> <li>Fixed infinite loop on async for React Native (by <a href="https://github.com/OvergrowthBeards-JB"><code>@OvergrowthBeards-JB</code></a>).</li> </ul> <h2>3.3.17</h2> <ul> <li>Fixed infinite loop on zero size.</li> </ul> <h2>3.3.16</h2> <ul> <li>Fixed infinite loop on negative size (by <a href="https://github.com/greymoth-jp"><code>@greymoth-jp</code></a>).</li> </ul> <h2>3.3.15</h2> <ul> <li>Fixed npm provenance error.</li> </ul> <h2>3.3.14</h2> <ul> <li>Fixed random pool corruption on big ID sizes.</li> </ul> <h2>3.3.13</h2> <ul> <li>Reduced npm package size.</li> </ul> <h2>3.3.12</h2> <ul> <li>Fixed breaking Nano ID by requesting big ID.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/ai/nanoid/blob/3.3.18/CHANGELOG.md">nanoid's changelog</a>.</em></p> <blockquote> <h2>3.3.18</h2> <ul> <li>Fixed infinite loop on async for React Native (by <a href="https://github.com/OvergrowthBeards-JB"><code>@OvergrowthBeards-JB</code></a>).</li> </ul> <h2>3.3.17</h2> <ul> <li>Fixed infinite loop on zero size.</li> </ul> <h2>3.3.16</h2> <ul> <li>Fixed infinite loop on negative size (by <a href="https://github.com/greymoth-jp"><code>@greymoth-jp</code></a>).</li> </ul> <h2>3.3.15</h2> <ul> <li>Fixed npm provenance error.</li> </ul> <h2>3.3.14</h2> <ul> <li>Fixed random pool corruption on big ID sizes.</li> </ul> <h2>3.3.13</h2> <ul> <li>Reduced npm package size.</li> </ul> <h2>3.3.12</h2> <ul> <li>Fixed breaking Nano ID by requesting big ID.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/ai/nanoid/commit/9ad98052b316c5e707f8098ace509d2ae165e54d"><code>9ad9805</code></a> Release 3.3.18 version</li> <li><a href="https://github.com/ai/nanoid/commit/55e50a0621ec084b4bb4000ea4e86e1191bd3da8"><code>55e50a0</code></a> Update CI action</li> <li><a href="https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0"><code>e10f8d4</code></a> Update index.native.js (<a href="https://redirect.github.com/ai/nanoid/issues/606">#606</a>)</li> <li><a href="https://github.com/ai/nanoid/commit/73d67168136b36fd3b644159b0cff149da4905d9"><code>73d6716</code></a> Release 3.3.17 version</li> <li><a href="https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b"><code>f9d13f1</code></a> Sync 0 size behaviour with PostCSS 5</li> <li><a href="https://github.com/ai/nanoid/commit/9760e112757cf7d46a79abd7a133bc4958757bb8"><code>9760e11</code></a> Release 3.3.16 version</li> <li><a href="https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d"><code>e835c9b</code></a> fix(non-secure): clamp negative size to prevent infinite loop (<a href="https://redirect.github.com/ai/nanoid/issues/601">#601</a>)</li> <li><a href="https://github.com/ai/nanoid/commit/96dd086eb24396a275fa93ee78d73b2fece35809"><code>96dd086</code></a> Update CI action</li> <li><a href="https://github.com/ai/nanoid/commit/ba0bc3b6b95a7e8fb97efa248306e0512b340ace"><code>ba0bc3b</code></a> Do not create latest release for v3</li> <li><a href="https://github.com/ai/nanoid/commit/6819724a0ebe3d1980de66980f6bc5df4bf6a41f"><code>6819724</code></a> Release 3.3.15 version</li> <li>Additional commits viewable in <a href="https://github.com/ai/nanoid/compare/3.3.11...3.3.18">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for nanoid since your current version.</p> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) You can trigger a rebase of this PR by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/wavetermdev/waveterm/network/alerts). </details> > **Note** > Automatic rebases have been disabled on this pull request as it has been open for over 30 days. Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.83.1 to 1.83.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/grpc/grpc-go/releases">google.golang.org/grpc's releases</a>.</em></p> <blockquote> <h2>Release 1.83.2</h2> <h1>Security</h1> <ul> <li>server: Reject requests missing both <code>:authority</code> and <code>Host</code> headers with HTTP 400 and status <code>Internal</code>. (<a href="https://redirect.github.com/grpc/grpc-go/pull/9365">grpc/grpc-go#9365</a>) <ul> <li>Special Thanks: <a href="https://github.com/winklemad"><code>@winklemad</code></a></li> </ul> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/grpc/grpc-go/commit/030ee8becb20ce4315d6bf2dfa26bdd876169dc4"><code>030ee8b</code></a> Update version to 1.83.2 (<a href="https://redirect.github.com/grpc/grpc-go/issues/9375">#9375</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/8668b69c167df908b6b3666dcbf40992b9e932a4"><code>8668b69</code></a> cherry-pick <a href="https://redirect.github.com/grpc/grpc-go/issues/9365">#9365</a> to v1.83.x (<a href="https://redirect.github.com/grpc/grpc-go/issues/9366">#9366</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/a3e952d2b7c973b7ec6357676e55a2a9c9faaa0d"><code>a3e952d</code></a> cherry-pick <a href="https://redirect.github.com/grpc/grpc-go/issues/9346">#9346</a> to v1.83.x and update x/net dependency (<a href="https://redirect.github.com/grpc/grpc-go/issues/9369">#9369</a>)</li> <li><a href="https://github.com/grpc/grpc-go/commit/58f8fd9a002536548ac96e34621d761b29cc4f3e"><code>58f8fd9</code></a> Change version to 1.83.2-dev (<a href="https://redirect.github.com/grpc/grpc-go/issues/9337">#9337</a>)</li> <li>See full diff in <a href="https://github.com/grpc/grpc-go/compare/v1.83.1...v1.83.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/wavetermdev/waveterm/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps and [brace-expansion](https://github.com/juliangruber/brace-expansion). These dependencies needed to be updated together. Updates `brace-expansion` from 1.1.13 to 1.1.18 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/juliangruber/brace-expansion/releases">brace-expansion's releases</a>.</em></p> <blockquote> <h2>v1.1.15</h2> <ul> <li>Backport v5.0.6 change to v1 (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/111">#111</a>) 0b09384</li> </ul> <hr /> <p><a href="https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15">https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b"><code>758fcd6</code></a> 1.1.18</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e"><code>27fbeed</code></a> Merge commit from fork</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf"><code>5c57cc2</code></a> 1.1.17</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57"><code>d757f1d</code></a> npm ignore <code>.claude</code></li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031"><code>cb4b9e4</code></a> fix: backport GHSA-mh99-v99m-4gvg (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/129">#129</a>)</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97"><code>447763a</code></a> 1.1.16</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95"><code>d74e630</code></a> fix: v1 backport for CVE-2026-13149 (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/122">#122</a>)</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24"><code>2203f4f</code></a> 1.1.15</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd"><code>0b09384</code></a> Backport v5.0.6 change to v1 (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/111">#111</a>)</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3"><code>10c05fc</code></a> 1.1.14</li> <li>Additional commits viewable in <a href="https://github.com/juliangruber/brace-expansion/compare/v1.1.13...v1.1.18">compare view</a></li> </ul> </details> <br /> Updates `brace-expansion` from 2.0.3 to 2.1.4 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/juliangruber/brace-expansion/releases">brace-expansion's releases</a>.</em></p> <blockquote> <h2>v1.1.15</h2> <ul> <li>Backport v5.0.6 change to v1 (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/111">#111</a>) 0b09384</li> </ul> <hr /> <p><a href="https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15">https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b"><code>758fcd6</code></a> 1.1.18</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e"><code>27fbeed</code></a> Merge commit from fork</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf"><code>5c57cc2</code></a> 1.1.17</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57"><code>d757f1d</code></a> npm ignore <code>.claude</code></li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031"><code>cb4b9e4</code></a> fix: backport GHSA-mh99-v99m-4gvg (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/129">#129</a>)</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97"><code>447763a</code></a> 1.1.16</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95"><code>d74e630</code></a> fix: v1 backport for CVE-2026-13149 (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/122">#122</a>)</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24"><code>2203f4f</code></a> 1.1.15</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd"><code>0b09384</code></a> Backport v5.0.6 change to v1 (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/111">#111</a>)</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3"><code>10c05fc</code></a> 1.1.14</li> <li>Additional commits viewable in <a href="https://github.com/juliangruber/brace-expansion/compare/v1.1.13...v1.1.18">compare view</a></li> </ul> </details> <br /> Updates `brace-expansion` from 5.0.5 to 5.0.9 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/juliangruber/brace-expansion/releases">brace-expansion's releases</a>.</em></p> <blockquote> <h2>v1.1.15</h2> <ul> <li>Backport v5.0.6 change to v1 (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/111">#111</a>) 0b09384</li> </ul> <hr /> <p><a href="https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15">https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b"><code>758fcd6</code></a> 1.1.18</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e"><code>27fbeed</code></a> Merge commit from fork</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf"><code>5c57cc2</code></a> 1.1.17</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57"><code>d757f1d</code></a> npm ignore <code>.claude</code></li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031"><code>cb4b9e4</code></a> fix: backport GHSA-mh99-v99m-4gvg (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/129">#129</a>)</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97"><code>447763a</code></a> 1.1.16</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95"><code>d74e630</code></a> fix: v1 backport for CVE-2026-13149 (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/122">#122</a>)</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24"><code>2203f4f</code></a> 1.1.15</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd"><code>0b09384</code></a> Backport v5.0.6 change to v1 (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/111">#111</a>)</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3"><code>10c05fc</code></a> 1.1.14</li> <li>Additional commits viewable in <a href="https://github.com/juliangruber/brace-expansion/compare/v1.1.13...v1.1.18">compare view</a></li> </ul> </details> <br /> You can trigger a rebase of this PR by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/wavetermdev/waveterm/network/alerts). </details> > **Note** > Automatic rebases have been disabled on this pull request as it has been open for over 30 days. Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.2.0 to 10.4.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/beaugunderson/ip-address/releases">ip-address's releases</a>.</em></p> <blockquote> <h2>v10.4.0</h2> <h2>What's Changed</h2> <ul> <li>Add GitHub Actions CI by <a href="https://github.com/beaugunderson"><code>@beaugunderson</code></a> in <a href="https://redirect.github.com/beaugunderson/ip-address/pull/213">beaugunderson/ip-address#213</a></li> <li>Keep the package loadable on node 12, and enforce it by <a href="https://github.com/beaugunderson"><code>@beaugunderson</code></a> in <a href="https://redirect.github.com/beaugunderson/ip-address/pull/216">beaugunderson/ip-address#216</a></li> <li>Validate the byte arrays Address6 is given by <a href="https://github.com/beaugunderson"><code>@beaugunderson</code></a> in <a href="https://redirect.github.com/beaugunderson/ip-address/pull/217">beaugunderson/ip-address#217</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/beaugunderson/ip-address/compare/v10.3.1...v10.4.0">https://github.com/beaugunderson/ip-address/compare/v10.3.1...v10.4.0</a></p> <h2>v10.3.1</h2> <p><strong>Full Changelog</strong>: <a href="https://github.com/beaugunderson/ip-address/compare/v10.3.0...v10.3.1">https://github.com/beaugunderson/ip-address/compare/v10.3.0...v10.3.1</a></p> <h2>v10.3.0</h2> <p><strong>Full Changelog</strong>: <a href="https://github.com/beaugunderson/ip-address/compare/v10.2.2...v10.3.0">https://github.com/beaugunderson/ip-address/compare/v10.2.2...v10.3.0</a></p> <h2>v10.2.2</h2> <p><strong>Full Changelog</strong>: <a href="https://github.com/beaugunderson/ip-address/compare/v10.2.1...v10.2.2">https://github.com/beaugunderson/ip-address/compare/v10.2.1...v10.2.2</a></p> <h2>v10.2.1</h2> <p><strong>Full Changelog</strong>: <a href="https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.2.1">https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.2.1</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/beaugunderson/ip-address/commit/fbb8db28f1559842b7191cab7d8ea6408ed82f7b"><code>fbb8db2</code></a> 10.4.0</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/45a2b11ec254a2e5620de66e248adcb33d16e669"><code>45a2b11</code></a> Validate the byte arrays Address6 is given (<a href="https://redirect.github.com/beaugunderson/ip-address/issues/217">#217</a>)</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/bac8810b3935cab123316a4bc5ebaa22db140299"><code>bac8810</code></a> Keep the package loadable on node 12, and enforce it (<a href="https://redirect.github.com/beaugunderson/ip-address/issues/216">#216</a>)</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/9b3d8488d15e6bfe5f5503867b088ce056723e08"><code>9b3d848</code></a> Add a security policy and a README section on security posture</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/e84a7b381d02cb97ed114023e44133efae151254"><code>e84a7b3</code></a> Order the README API reference Address4, Address6, AddressError</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/015160b85ee60b39548219817a5de3c4e828a6d6"><code>015160b</code></a> Collapse each class in the README API reference</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/34061a897d526b7a063c3605402cd30a8363a035"><code>34061a8</code></a> Pin checkout and setup-node to commits in the release job</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/c5fae5d9bdfe8ded7f4ca01a3d3ea8d97f8f1277"><code>c5fae5d</code></a> Pin action-gh-release to a commit and move it to 3.0.2</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/e0ef0484193218b0d28cfbb53795bc44ddb3cc21"><code>e0ef048</code></a> Replace CircleCI with GitHub Actions</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/5e3ceb779aee6ad3f33264e66225e8e7584ab612"><code>5e3ceb7</code></a> Add GitHub Actions CI across Node 20, 22, 24 and 25 (<a href="https://redirect.github.com/beaugunderson/ip-address/issues/213">#213</a>)</li> <li>Additional commits viewable in <a href="https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.4.0">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for ip-address since your current version.</p> </details> <details> <summary>Install script changes</summary> <p>This version adds <code>prepare</code> script that runs during installation. Review the package contents before updating.</p> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) You can trigger a rebase of this PR by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/wavetermdev/waveterm/network/alerts). </details> > **Note** > Automatic rebases have been disabled on this pull request as it has been open for over 30 days. Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 6.4.2 to 6.4.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/vitejs/vite/releases">vite's releases</a>.</em></p> <blockquote> <h2>v6.4.3</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v6.4.3/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/vitejs/vite/blob/v6.4.3/packages/vite/CHANGELOG.md">vite's changelog</a>.</em></p> <blockquote> <h2><!-- raw HTML omitted -->6.4.3 (2026-06-01)<!-- raw HTML omitted --></h2> <ul> <li>fix: backport <a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22572">#22572</a>, reject windows alternate paths (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22576">#22576</a>) (<a href="https://github.com/vitejs/vite/commit/96b0c10162e9c55485d922db2cfc6b8227cbc176">96b0c10</a>), closes <a href="https://redirect.github.com/vitejs/vite/issues/22572">#22572</a> <a href="https://redirect.github.com/vitejs/vite/issues/22576">#22576</a></li> <li>fix(deps): backport <a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22571">#22571</a>, reject UNC paths for launch-editor-middleware (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22575">#22575</a>) (<a href="https://github.com/vitejs/vite/commit/8fed5cf540c0d475266787f52072f258478cd42f">8fed5cf</a>), closes <a href="https://redirect.github.com/vitejs/vite/issues/22571">#22571</a> <a href="https://redirect.github.com/vitejs/vite/issues/22575">#22575</a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/vitejs/vite/commit/6c2c881f15495738ff03bc1d67cc052c07e0cac4"><code>6c2c881</code></a> release: v6.4.3</li> <li><a href="https://github.com/vitejs/vite/commit/96b0c10162e9c55485d922db2cfc6b8227cbc176"><code>96b0c10</code></a> fix: backport <a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22572">#22572</a>, reject windows alternate paths (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22576">#22576</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/8fed5cf540c0d475266787f52072f258478cd42f"><code>8fed5cf</code></a> fix(deps): backport <a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22571">#22571</a>, reject UNC paths for launch-editor-middleware (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/2">#2</a>...</li> <li>See full diff in <a href="https://github.com/vitejs/vite/commits/v6.4.3/packages/vite">compare view</a></li> </ul> </details> <br /> > **Note** > Automatic rebases have been disabled on this pull request as it has been open for over 30 days. Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.55.0 to 0.57.0. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/golang/crypto/commit/3f62bf119e84c6e35e8518a2958089ade622d1a3"><code>3f62bf1</code></a> go.mod: update golang.org/x dependencies</li> <li><a href="https://github.com/golang/crypto/commit/86efde54dc7069251a8b007026c500d28e4239ce"><code>86efde5</code></a> ssh: reject unexpected message types on established channels</li> <li><a href="https://github.com/golang/crypto/commit/a6cdac60840750226b15617ac8858be44361b36b"><code>a6cdac6</code></a> ssh: drop traffic on undecided channels</li> <li><a href="https://github.com/golang/crypto/commit/39dc44e69c280a6254fa09ce85477455efeaf6a2"><code>39dc44e</code></a> ssh: don't skip the source-address critical option in CheckCert</li> <li><a href="https://github.com/golang/crypto/commit/afebf4cb4efb2b854282e03160da67120707f8f7"><code>afebf4c</code></a> x509roots/fallback/bundle: make subjectsEqual stricter on Go 1.27+</li> <li><a href="https://github.com/golang/crypto/commit/89f4e9bb5b38861a69b1b26890a6833138d35ace"><code>89f4e9b</code></a> x509roots/fallback: update bundle</li> <li><a href="https://github.com/golang/crypto/commit/71488c48c2dfecf900e52caa55f88ef4fef62d54"><code>71488c4</code></a> ssh/knownhosts: compare only public key portions for revocation</li> <li><a href="https://github.com/golang/crypto/commit/82adefa711cb8d9a1f12c7ea91b491007d21819f"><code>82adefa</code></a> ssh: synchronize unexpected response test</li> <li><a href="https://github.com/golang/crypto/commit/c757c9851f77c470645455f548046ae0ce87ef8d"><code>c757c98</code></a> all: upgrade go directive to at least 1.26.0 [generated]</li> <li><a href="https://github.com/golang/crypto/commit/593c81af8aa6582d85a7faaeb996396f63d712a9"><code>593c81a</code></a> ssh: correctly ignore pre-banner lines</li> <li>Additional commits viewable in <a href="https://github.com/golang/crypto/compare/v0.55.0...v0.57.0">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Summary - Declare `sharp` as a development dependency so `vite-plugin-image-optimizer` can load its optional peer during renderer builds. - Lock the native packages for supported platforms. ## Verification - `npm run build:dev` exited 0 and successfully optimized all four logo images (about 63% total savings). - Sharp loaded and encoded a PNG on Linux x64. - `task check:ts` still fails on existing preview-mock type errors, unrelated to this dependency change.
Bumps [lodash](https://github.com/lodash/lodash) from 4.17.23 to 4.18.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/lodash/lodash/releases">lodash's releases</a>.</em></p> <blockquote> <h2>4.18.1</h2> <h2>Bugs</h2> <p>Fixes a <code>ReferenceError</code> issue in <code>lodash</code> <code>lodash-es</code> <code>lodash-amd</code> and <code>lodash.template</code> when using the <code>template</code> and <code>fromPairs</code> functions from the modular builds. See <a href="https://redirect.github.com/lodash/lodash/issues/6167#issuecomment-4165269769">lodash/lodash#6167</a></p> <p>These defects were related to how lodash distributions are built from the main branch using <a href="https://github.com/lodash-archive/lodash-cli">https://github.com/lodash-archive/lodash-cli</a>. When internal dependencies change inside lodash functions, equivalent updates need to be made to a mapping in the lodash-cli. (hey, it was ahead of its time once upon a time!). We know this, but we missed it in the last release. It's the kind of thing that passes in CI, but fails bc the build is not the same thing you tested.</p> <p>There is no diff on main for this, but you can see the diffs for each of the npm packages on their respective branches:</p> <ul> <li><code>lodash</code>: <a href="https://github.com/lodash/lodash/compare/4.18.0-npm...4.18.1-npm">https://github.com/lodash/lodash/compare/4.18.0-npm...4.18.1-npm</a></li> <li><code>lodash-es</code>: <a href="https://github.com/lodash/lodash/compare/4.18.0-es...4.18.1-es">https://github.com/lodash/lodash/compare/4.18.0-es...4.18.1-es</a></li> <li><code>lodash-amd</code>: <a href="https://github.com/lodash/lodash/compare/4.18.0-amd...4.18.1-amd">https://github.com/lodash/lodash/compare/4.18.0-amd...4.18.1-amd</a></li> <li><code>lodash.template</code><a href="https://github.com/lodash/lodash/compare/4.18.0-npm-packages...4.18.1-npm-packages">https://github.com/lodash/lodash/compare/4.18.0-npm-packages...4.18.1-npm-packages</a></li> </ul> <h2>4.18.0</h2> <h2>v4.18.0</h2> <p><strong>Full Changelog</strong>: <a href="https://github.com/lodash/lodash/compare/4.17.23...4.18.0">https://github.com/lodash/lodash/compare/4.17.23...4.18.0</a></p> <h3>Security</h3> <p><strong><code>_.unset</code> / <code>_.omit</code></strong>: Fixed prototype pollution via <code>constructor</code>/<code>prototype</code> path traversal (<a href="https://github.com/lodash/lodash/security/advisories/GHSA-f23m-r3pf-42rh">GHSA-f23m-r3pf-42rh</a>, <a href="https://github.com/lodash/lodash/commit/fe8d32eda854377349a4f922ab7655c8e5df9a0b">fe8d32e</a>). Previously, array-wrapped path segments and primitive roots could bypass the existing guards, allowing deletion of properties from built-in prototypes. Now <code>constructor</code> and <code>prototype</code> are blocked unconditionally as non-terminal path keys, matching <code>baseSet</code>. Calls that previously returned <code>true</code> and deleted the property now return <code>false</code> and leave the target untouched.</p> <p><strong><code>_.template</code></strong>: Fixed code injection via <code>imports</code> keys (<a href="https://github.com/lodash/lodash/security/advisories/GHSA-r5fr-rjxr-66jc">GHSA-r5fr-rjxr-66jc</a>, CVE-2026-4800, <a href="https://github.com/lodash/lodash/commit/879aaa93132d78c2f8d20c60279da9f8b21576d6">879aaa9</a>). Fixes an incomplete patch for CVE-2021-23337. The <code>variable</code> option was validated against <code>reForbiddenIdentifierChars</code> but <code>importsKeys</code> was left unguarded, allowing code injection via the same <code>Function()</code> constructor sink. <code>imports</code> keys containing forbidden identifier characters now throw <code>"Invalid imports option passed into _.template"</code>.</p> <h3>Docs</h3> <ul> <li>Add security notice for <code>_.template</code> in threat model and API docs (<a href="https://redirect.github.com/lodash/lodash/pull/6099">#6099</a>)</li> <li>Document <code>lower > upper</code> behavior in <code>_.random</code> (<a href="https://redirect.github.com/lodash/lodash/pull/6115">#6115</a>)</li> <li>Fix quotes in <code>_.compact</code> jsdoc (<a href="https://redirect.github.com/lodash/lodash/pull/6090">#6090</a>)</li> </ul> <h3><code>lodash.*</code> modular packages</h3> <p><a href="https://redirect.github.com/lodash/lodash/pull/6157">Diff</a></p> <p>We have also regenerated and published a select number of the <code>lodash.*</code> modular packages.</p> <p>These modular packages had fallen out of sync significantly from the minor/patch updates to lodash. Specifically, we have brought the following packages up to parity w/ the latest lodash release because they have had CVEs on them in the past:</p> <ul> <li><a href="https://www.npmjs.com/package/lodash.orderby">lodash.orderby</a></li> <li><a href="https://www.npmjs.com/package/lodash.tonumber">lodash.tonumber</a></li> <li><a href="https://www.npmjs.com/package/lodash.trim">lodash.trim</a></li> <li><a href="https://www.npmjs.com/package/lodash.trimend">lodash.trimend</a></li> <li><a href="https://www.npmjs.com/package/lodash.sortedindexby">lodash.sortedindexby</a></li> <li><a href="https://www.npmjs.com/package/lodash.zipobjectdeep">lodash.zipobjectdeep</a></li> <li><a href="https://www.npmjs.com/package/lodash.unset">lodash.unset</a></li> <li><a href="https://www.npmjs.com/package/lodash.omit">lodash.omit</a></li> <li><a href="https://www.npmjs.com/package/lodash.template">lodash.template</a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/lodash/lodash/commit/cb0b9b9212521c08e3eafe7c8cb0af1b42b6649e"><code>cb0b9b9</code></a> release(patch): bump main to 4.18.1 (<a href="https://redirect.github.com/lodash/lodash/issues/6177">#6177</a>)</li> <li><a href="https://github.com/lodash/lodash/commit/75535f57883b7225adb96de1cfc1cd4169cfcb51"><code>75535f5</code></a> chore: prune stale advisory refs (<a href="https://redirect.github.com/lodash/lodash/issues/6170">#6170</a>)</li> <li><a href="https://github.com/lodash/lodash/commit/62e91bc6a39c98d85b9ada8c44d40593deaf82a4"><code>62e91bc</code></a> docs: remove n_ Node.js < 6 REPL note from README (<a href="https://redirect.github.com/lodash/lodash/issues/6165">#6165</a>)</li> <li><a href="https://github.com/lodash/lodash/commit/59be2de61f8aa9461c7856533b51d31b7d8babc4"><code>59be2de</code></a> release(minor): bump to 4.18.0 (<a href="https://redirect.github.com/lodash/lodash/issues/6161">#6161</a>)</li> <li><a href="https://github.com/lodash/lodash/commit/af634573030f979194871da7c68f79420992f53d"><code>af63457</code></a> fix: broken tests for _.template 879aaa9</li> <li><a href="https://github.com/lodash/lodash/commit/1073a7693e1727e0cf3641e5f71f75ddcf8de7c0"><code>1073a76</code></a> fix: linting issues</li> <li><a href="https://github.com/lodash/lodash/commit/879aaa93132d78c2f8d20c60279da9f8b21576d6"><code>879aaa9</code></a> fix: validate imports keys in _.template</li> <li><a href="https://github.com/lodash/lodash/commit/fe8d32eda854377349a4f922ab7655c8e5df9a0b"><code>fe8d32e</code></a> fix: block prototype pollution in baseUnset via constructor/prototype traversal</li> <li><a href="https://github.com/lodash/lodash/commit/18ba0a32f42fd02117f096b032f89c984173462d"><code>18ba0a3</code></a> refactor(fromPairs): use baseAssignValue for consistent assignment (<a href="https://redirect.github.com/lodash/lodash/issues/6153">#6153</a>)</li> <li><a href="https://github.com/lodash/lodash/commit/b8190803d48d60b8c80ad45d39125f32fa618cb2"><code>b819080</code></a> ci: add dist sync validation workflow (<a href="https://redirect.github.com/lodash/lodash/issues/6137">#6137</a>)</li> <li>Additional commits viewable in <a href="https://github.com/lodash/lodash/compare/4.17.23...4.18.1">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Summary - Route OSC 8 hyperlinks and detected web URLs through the same terminal link handlers. - Preserve Cmd-click on macOS / Ctrl-click elsewhere, hover tooltip and context-menu state, and the `web:openlinksinternally` behavior in `openLink`. - Leave xterm’s default HTTP(S)-only OSC link filtering in place. Closes wavetermdev#3165. ## Verification - `npm exec -- vitest run frontend/app/view/term/term-links.test.ts frontend/app/view/term/osc-handlers.test.ts --reporter=dot` (6 passed) - Prettier and ESLint on changed files (passed) - `task check:ts` remains blocked by pre-existing type errors in frontend preview mocks, unrelated to these changes. - No runtime click test was performed.
…09-28 # Conflicts: # go.mod # go.sum
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Merges 21 new upstream commits (wavetermdev/waveterm
mainthroughc58bf7f3).Fixes / features
wshCLI sees unsaved/scratch workspaces (ListAllWorkspaces, fix(wcore): add ListAllWorkspaces so wsh CLI sees unsaved/scratch workspaces wavetermdev/waveterm#3514)reasoning_contentfor DeepSeek chat completions (fix: preserve reasoning_content for DeepSeek chat completions wavetermdev/waveterm#3290)sharpdeclared for docsite image optimization (fix: declare sharp for image optimization wavetermdev/waveterm#3524); Linuxquickdevtask (Add Linux quickdev task wavetermdev/waveterm#3521)Dependency bumps: golang.org/x/crypto 0.57.0, grpc 1.83.2, vite 6.4.3, lodash 4.18.1, nanoid, js-yaml, fast-uri, browserslist and others.
Conflicts: only
go.mod/go.sum(both sides bumpedgolang.org/x/*); took upstream's newer versions,go mod tidykept the fork'spkg/sftpv1.13.11 unchanged. No workflow files changed.Checks: codegen (no changes),
go vet ./pkg/... ./cmd/..., Go tests for conncontroller / sftpfs / hostinfo / library / wcore / openaichat,tsc --noEmit, vitest 65/65.🤖 Generated with Claude Code
https://claude.ai/code/session_01JhvhnSTH8EXbTG9wmtY7dd