Skip to content

chore: merge upstream (21 commits, 2026-09-28) - #17

Merged
Atreus-X merged 22 commits into
mainfrom
sync/upstream-2026-09-28
Sep 28, 2026
Merged

Atreus-X merged 22 commits into
mainfrom
sync/upstream-2026-09-28

Conversation

@Atreus-X

Copy link
Copy Markdown
Owner

Merges 21 new upstream commits (wavetermdev/waveterm main through c58bf7f3).

Fixes / features

Dependency bumps: golang.org/x/crypto 0.57.0, grpc 1.83.2, vite 6.4.3, lodash 4.18.1, nanoid, js-yaml, fast-uri, browserslist and others.

Conflicts: only go.mod / go.sum (both sides bumped golang.org/x/*); took upstream's newer versions, go mod tidy kept the fork's pkg/sftp v1.13.11 unchanged. No workflow files changed.

Checks: codegen (no changes), go vet ./pkg/... ./cmd/..., Go tests for conncontroller / sftpfs / hostinfo / library / wcore / openaichat, tsc --noEmit, vitest 65/65.

🤖 Generated with Claude Code

https://claude.ai/code/session_01JhvhnSTH8EXbTG9wmtY7dd

sawka and others added 22 commits September 24, 2026 20:06
## Summary
- Add `electron:linuxquickdev` to run Electron through the Vite dev
server on Linux/amd64.
- Build only the native `wavesrv.x64` with the local C compiler; skip
generation and `wsh`.

## Verification
- Launched the task on Linux/amd64 under a virtual display; the Wave
window opened and Vite returned HTTP 200.
- Cached restart reached a visible window in about 5 seconds.
- The full-build baseline was not timed (Zig is unavailable in this VM).
…kspaces (wavetermdev#3514)

## Summary
`wsh workspace list` and `wsh blocks list`'s default "all workspaces"
enumeration are built on `wcore.ListWorkspaces`, which excludes any
workspace missing `Name`, `Icon`, or `Color`. That's intentional for its
other callers: the frontend workspace switcher
(`WorkspaceService.ListWorkspaces`) and, as caught in review, the
Electron Workspace menu (`emain-menu.ts`) and `Alt+Ctrl+<N>`
workspace-switch shortcuts (`emain-tabview.ts`) — all three rely on
unsaved (scratch) workspaces staying excluded, since `CreateWindow`
deliberately creates one of those for a new window
(`CreateWorkspace(..., applyDefaults=false)`) and `DeleteWorkspace`
auto-cleans it up on close unless it's since been named.

The bug is that the exact same exclusion also blinds the **CLI** to
those workspaces — and everything inside them. Confirmed against a real
user's database: a workspace holding their own long-running Claude Code
session's active tab had never been named, and was completely invisible
to `wsh blocks list` the entire time it was in continuous daily use.

## Fix (revised twice through review)
- `wcore.ListWorkspaces` is completely unchanged — still excludes
unsaved workspaces, still shared by the frontend switcher.
- New `wcore.ListAllWorkspaces` includes them too, without ever writing
anything to the database.
- **A prior revision of this PR pointed the shared
`WorkspaceListCommand` RPC at the new function**, on the claim that it
was CLI-only — codex correctly caught that this RPC is also called from
`emain-menu.ts` and `emain-tabview.ts` (Electron main-process code, a
call-site my original search missed entirely), which would have added
blank scratch-workspace entries to the Workspace menu and shifted
keyboard-shortcut indices. Fixed by adding a **separate**
`WorkspaceListAllCommand` RPC (regenerated through the real codegen:
`cmd/generatego`, `cmd/generatets`) and pointing only `wsh workspace
list` / `wsh blocks list` at it. `WorkspaceListCommand` itself, and
every one of its other callers, is untouched.

## Test plan
`pkg/wcore/workspace_test.go` — real (non-mocked) sqlite-backed tests
via `wstore.InitWStore()`:
- `ListWorkspaces` excludes an unsaved workspace and never mutates it.
- `ListAllWorkspaces` includes it too, also without mutating anything.

```
go test ./pkg/wcore/... ./pkg/wshrpc/...
```
Also verified a full `npm run build:prod` (electron-vite, compiles
main/preload/renderer together) to confirm
`emain-menu.ts`/`emain-tabview.ts` build clean and unaffected against
the regenerated bindings.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 3.14.1 to
3.15.2.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md">js-yaml's
changelog</a>.</em></p>
<blockquote>
<h2>3.15.2 - 2026-08-26</h2>
<h3>Changed</h3>
<ul>
<li>[backport] Hard-limit merge sequence size to 100.</li>
</ul>
<h3>Security</h3>
<ul>
<li>[backport] Count empty mappings in merge sequences toward
<code>maxTotalMergeKeys</code>
to limit CPU usage, <a
href="https://redirect.github.com/nodeca/js-yaml/issues/797">#797</a>.</li>
</ul>
<h2>3.15.1 - 2026-07-31</h2>
<h3>Security</h3>
<ul>
<li>[backport] Remove quadratic complexity from <code>!!omap</code>
duplicate key detection.</li>
</ul>
<h2>3.15.0 - 2026-06-27</h2>
<h3>Added</h3>
<ul>
<li>Added <code>maxTotalMergeKeys</code> (10000) loader option to limit
the total number of
keys processed by YAML merge (<code>&lt;&lt;</code>) across one
<code>safeLoad()</code> / <code>safeLoadAll()</code>
call.</li>
</ul>
<h2>[3.14.2] - 2025-11-15</h2>
<h3>Security</h3>
<ul>
<li>Fix prototype pollution in merge (&lt;&lt;).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/nodeca/js-yaml/commit/5c45bd6e960603c13644f5cc8b572ca257723b36"><code>5c45bd6</code></a>
3.15.2 released</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/5a708f9f4f22e78b87ebe363848cfa4fa4818c0d"><code>5a708f9</code></a>
dist rebuild</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/3485bc06ff8a0251505f44a00414d90df2466639"><code>3485bc0</code></a>
Backport merge limits from v5.4.1</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/f34812f1cea794f8c21e0a4e1f3a2584b720f305"><code>f34812f</code></a>
Update .gitignore</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/ab85ae2c622bc6d8cdbceccafe9f9b7df80463ed"><code>ab85ae2</code></a>
3.15.1 released</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/30a5e7647a4454f7bac969bfbbe7eac9921a4279"><code>30a5e76</code></a>
dist rebuild</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/22a8071ef032117bc6249c330b240ac3aa2d3ded"><code>22a8071</code></a>
Backport quadratic complexity fix for !!omap</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/c34b6c40027a769eb0d67958ae615268a1d55f54"><code>c34b6c4</code></a>
3.15.0 released</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/21e13d363f33501c7ee6ca988b88c29084999f72"><code>21e13d3</code></a>
dist rebuild</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/4165c62630d64fe4f25fb0d03139c7e137b24b1c"><code>4165c62</code></a>
Add v3-legacy tag for publish</li>
<li>Additional commits viewable in <a
href="https://github.com/nodeca/js-yaml/compare/3.14.1...3.15.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=js-yaml&package-manager=npm_and_yarn&previous-version=3.14.1&new-version=3.15.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/wavetermdev/waveterm/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.4 to
3.1.7.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/fastify/fast-uri/releases">fast-uri's
releases</a>.</em></p>
<blockquote>
<h2>v3.1.7</h2>
<h2>⚠️ Security Warning</h2>
<p>This is a security release that fixes the following high-severity
security advisories:</p>
<ul>
<li><a
href="https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3">GHSA-qw65-cvwx-89v3</a>
— authority injection via an unvalidated port in
<code>serialize()</code></li>
<li><a
href="https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g">GHSA-58mr-gqgx-xq4g</a>
— host confusion via unbalanced or misplaced IP-literal brackets</li>
</ul>
<p>Users of the v3.x release line should upgrade to v3.1.7.</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7">https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7</a></p>
<h2>v3.1.6</h2>
<h2>⚠️ Security Warning</h2>
<p>This release addresses the following high-severity security
advisories:</p>
<ul>
<li><a
href="https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8">GHSA-5jgf-p345-68v8</a>
— host confusion via skipped IDN canonicalization on scheme-relative
references</li>
<li><a
href="https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf">GHSA-fph4-wmhf-6fwf</a>
— server-side request forgery via repeated hostname
percent-decoding</li>
<li><a
href="https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc">GHSA-f65p-4m7j-42xc</a>
— server-side request forgery via malformed IPv6 normalization</li>
<li><a
href="https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp">GHSA-jqff-g426-hqxp</a>
— host confusion via percent-encoded scheme normalization</li>
</ul>
<p>Users of the v3.x release line should upgrade to v3.1.6.</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6">https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6</a></p>
<h2>v3.1.5</h2>
<h2>⚠️ Security Warning</h2>
<p>Fix for <a
href="https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7">https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7</a></p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5">https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3"><code>412e40a</code></a>
Bumped v3.1.7</li>
<li><a
href="https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01"><code>9f4c943</code></a>
fix: backport port and IP-literal validation to v3.x (<a
href="https://redirect.github.com/fastify/fast-uri/issues/216">#216</a>)</li>
<li><a
href="https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588"><code>1eb3ce4</code></a>
fix: treat unterminated bracket hosts as reg-names again (<a
href="https://redirect.github.com/fastify/fast-uri/issues/214">#214</a>)</li>
<li><a
href="https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33"><code>6f970b2</code></a>
Bumped v3.1.6</li>
<li><a
href="https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a"><code>d941579</code></a>
fix: never run IDN canonicalization on bracketed IP literals</li>
<li><a
href="https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba"><code>c0f0279</code></a>
test: adapt decoded-scheme handler assertion to 3.x (no mailto
scheme)</li>
<li><a
href="https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862"><code>37f3417</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f"><code>607bfbe</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514"><code>ae92a4c</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef"><code>444ecda</code></a>
Merge commit from fork</li>
<li>Additional commits viewable in <a
href="https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.7">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fast-uri&package-manager=npm_and_yarn&previous-version=3.1.4&new-version=3.1.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/wavetermdev/waveterm/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…rmdev#3290)

DeepSeek V4 enables thinking mode by default and requires that the
`reasoning_content` field be passed back unchanged in assistant messages
during multi-turn conversations. The openai-chat backend, however, does
not support this. This PR adds that support, roughly following the
pattern that is employed by the anthropic backend.

Fixes wavetermdev#3266

 ## Flow
<details>
<summary>reasoning-start, delta, and end SSE events are captured, sent
to the frontend, and included in subsequent API calls</summary><br />

 When a stream chunk contains reasoning_content in its delta, we now:
1. Emit reasoning-start / reasoning-delta / reasoning-end SSE events to
the frontend
 2. Capture the full reasoning string on the stored assistant message
3. Round-trip it in subsequent API calls via reasoning_content on the
wire format

Non-reasoning providers are unaffected — the stream field is absent, the
Go field defaults to "", and the omitempty JSON tag keeps it off the
wire.
</details>

## Automated Testing
- tests for round-trip, omitempty, stream chunk parsing, clean, and
partial extraction

## Manual Testing
- I manually validated that the issue was resolved
- I validated that the three other chat modes that come with Wave still
work as expected
- I validated that tool calls work
- **I did _not_ validate any other openai-style custom chat providers
other than deepseek**
  - Sorry, I don't have an API key for this 😔
- I believe the changes are well-guarded, but it seems worth calling out
as an area for extra attention

**Is there anything else I should cover?**


## Screenshots
<details>
<summary>Before screenshot, demonstrating issue
reproduction</summary><br />
<img width="1387" height="844" alt="Screenshot 2026-05-04 003906"
src="https://github.com/user-attachments/assets/08a2b95c-6909-4690-8789-6d95d541b04f"
/>
</details>

<details>
<summary>Afterscreenshot, demonstrating issue resolution</summary><br />
<img width="1338" height="851" alt="Screenshot 2026-05-04 003935"
src="https://github.com/user-attachments/assets/4e201719-acec-4b80-890b-8699e7f2cfcd"
/>
</details>
Bumps [image-size](https://github.com/image-size/image-size) from 2.0.2
to 2.0.4.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/image-size/image-size/commits">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=image-size&package-manager=npm_and_yarn&previous-version=2.0.2&new-version=2.0.4)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/wavetermdev/waveterm/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [joi](https://github.com/hapijs/joi) from 17.13.3 to 17.13.7.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/hapijs/joi/commit/ed9d7cdd11ef5f7751fd46886f38dc605c9c3995"><code>ed9d7cd</code></a>
17.13.7</li>
<li><a
href="https://github.com/hapijs/joi/commit/f2729f71839c57c94ac500b4be9e4b5b26d4e637"><code>f2729f7</code></a>
Merge pull request <a
href="https://redirect.github.com/hapijs/joi/issues/3145">#3145</a> from
hapijs/backport/isodate-timeshift-v17</li>
<li><a
href="https://github.com/hapijs/joi/commit/c43fc964799c9b5f0c6921bf788162b67066ae81"><code>c43fc96</code></a>
chore: add regression test for <a
href="https://redirect.github.com/hapijs/joi/issues/3143">#3143</a></li>
<li><a
href="https://github.com/hapijs/joi/commit/115e7b58d5eaaecc5e9b7093d41899ad6fb053ec"><code>115e7b5</code></a>
fix(isoDate): pad a bare-hour timeshift with a colon, not just
zeros</li>
<li><a
href="https://github.com/hapijs/joi/commit/850be1ee24be8d548bb09359bdb0cf9fe41635ff"><code>850be1e</code></a>
17.13.6</li>
<li><a
href="https://github.com/hapijs/joi/commit/9faeecc48b18ec40e3881467645ae9074f0dfa3c"><code>9faeecc</code></a>
Merge pull request <a
href="https://redirect.github.com/hapijs/joi/issues/3139">#3139</a> from
hapijs/chore/backport-messages-proto</li>
<li><a
href="https://github.com/hapijs/joi/commit/8d0b808f3e874d28f9078f61b7742290989afb36"><code>8d0b808</code></a>
fix: prevent messages proto injection</li>
<li><a
href="https://github.com/hapijs/joi/commit/566e73fa58e72f0a1dcbb3b110ee2f49f33aece3"><code>566e73f</code></a>
17.13.5</li>
<li><a
href="https://github.com/hapijs/joi/commit/3f3907cd944257e143b22f3bf3f05e71478fa1b1"><code>3f3907c</code></a>
Merge pull request <a
href="https://redirect.github.com/hapijs/joi/issues/3135">#3135</a> from
hapijs/chore/backport-rename-proto</li>
<li><a
href="https://github.com/hapijs/joi/commit/172ececa192feda532b743d77bc9d3e523d19b01"><code>172ecec</code></a>
fix: prevent proto on renames</li>
<li>Additional commits viewable in <a
href="https://github.com/hapijs/joi/compare/v17.13.3...v17.13.7">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=joi&package-manager=npm_and_yarn&previous-version=17.13.3&new-version=17.13.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/wavetermdev/waveterm/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [fflate](https://github.com/101arrowz/fflate) from 0.7.4 to 0.7.5.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/101arrowz/fflate/commits">compare view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fflate&package-manager=npm_and_yarn&previous-version=0.7.4&new-version=0.7.5)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/wavetermdev/waveterm/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps
[@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node)
from 0.16.7 to 0.16.8.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/humanwhocodes/humanfs/releases">@​humanfs/node's
releases</a>.</em></p>
<blockquote>
<h2>node: v0.16.8</h2>
<h2><a
href="https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8">0.16.8</a>
(2026-04-17)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Include type dependencies at runtime (<a
href="https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138">956ce7a</a>),
closes <a
href="https://redirect.github.com/humanwhocodes/humanfs/issues/145">#145</a></li>
</ul>
<h3>Dependencies</h3>
<ul>
<li>The following workspace dependencies were updated
<ul>
<li>dependencies
<ul>
<li><code>@​humanfs/core</code> bumped from ^0.19.1 to ^0.19.2</li>
</ul>
</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md">@​humanfs/node's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8">0.16.8</a>
(2026-04-17)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Ensure symlinks are copied as symlinks in <code>copy()</code> and
<code>copyAll()</code> (<a
href="https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404">22bbaa44</a>)</li>
<li>Include type dependencies at runtime (<a
href="https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138">956ce7a</a>),
closes <a
href="https://redirect.github.com/humanwhocodes/humanfs/issues/145">#145</a></li>
</ul>
<h3>Dependencies</h3>
<ul>
<li>The following workspace dependencies were updated
<ul>
<li>dependencies
<ul>
<li><code>@​humanfs/core</code> bumped from ^0.19.1 to ^0.19.2</li>
</ul>
</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/humanwhocodes/humanfs/commit/e96070e897f017ae8abd2b0676d98d14e49665cc"><code>e96070e</code></a>
chore: release main (<a
href="https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node/issues/146">#146</a>)</li>
<li><a
href="https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404"><code>22bbaa4</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138"><code>956ce7a</code></a>
fix: Include type dependencies at runtime</li>
<li>See full diff in <a
href="https://github.com/humanwhocodes/humanfs/commits/node-v0.16.8/packages/node">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@humanfs/node&package-manager=npm_and_yarn&previous-version=0.16.7&new-version=0.16.8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/wavetermdev/waveterm/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@xmldom/xmldom](https://github.com/xmldom/xmldom) from 0.8.13 to
0.8.15.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/xmldom/xmldom/releases">@​xmldom/xmldom's
releases</a>.</em></p>
<blockquote>
<h2>0.8.15</h2>
<p><a
href="https://github.com/xmldom/xmldom/compare/0.8.14...0.8.15">Commits</a></p>
<h3>Fixed</h3>
<ul>
<li>Security: parsing a deeply or repeatedly namespaced document no
longer consumes quadratic memory; the in-scope namespace map is
inherited through the prototype chain instead of being copied for every
prefix-declaring element (O(N) instead of O(N²)), preventing a
denial-of-service reachable from <code>DOMParser.parseFromString</code>
with default options. Serialized output is byte-identical. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-965w-775f-mr7g"><code>GHSA-965w-775f-mr7g</code></a></li>
<li>Security: attribute de-duplication during parsing is now O(M)
instead of O(M²); the <code>NamedNodeMap</code> parse-time dedup path
uses a null-prototype membership index, so a well-formed document with a
hostile number of duplicate attributes can no longer wedge the parse.
Attribute order and duplicate resolution (last value wins, first
position kept) are byte-identical, preserving the XML <a
href="https://www.w3.org/TR/xml/#uniqattspec">no-duplicate-attributes
well-formedness constraint</a>. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-8344-3jmq-59r6"><code>GHSA-8344-3jmq-59r6</code></a></li>
<li>Security: trimming trailing whitespace from an XML end tag (<a
href="https://www.w3.org/TR/xml/#NT-ETag"><code>ETag</code></a>) is now
anchored so it runs in linear time instead of backtracking quadratically
on a long whitespace run, preventing a ReDoS reachable from
<code>DOMParser.parseFromString</code>. Trimmed output is
byte-identical. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-x4fp-j954-r2f4"><code>GHSA-x4fp-j954-r2f4</code></a></li>
<li>Security: malformed-input recovery is now linear instead of
quadratic — the malformed tag-name scan terminates at an embedded
<code>&lt;</code>, and <code>Node.prototype.normalize()</code> merges
adjacent text nodes in O(K) instead of O(K²) (also reachable
programmatically), per <a
href="https://dom.spec.whatwg.org/#dom-node-normalize"><code>normalize()</code></a>
in the WHATWG DOM spec. DOM output is unchanged; only the reported error
text differs. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-93r5-fhx6-vmg9"><code>GHSA-93r5-fhx6-vmg9</code></a></li>
<li>Security: <code>XMLSerializer.serializeToString()</code> under
<code>{ requireWellFormed: true }</code> now rejects a DocType
<code>name</code> that is not a valid XML <a
href="https://www.w3.org/TR/xml/#NT-Name"><code>Name</code></a>,
throwing <code>InvalidStateError</code> — matching the sibling
<code>publicId</code>/<code>systemId</code>/<code>internalSubset</code>
checks and preventing XML injection via <code>DocumentType.name</code>.
<a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-27p8-2357-5qqv"><code>GHSA-27p8-2357-5qqv</code></a></li>
<li>Security: <code>XMLSerializer.serializeToString()</code> under
<code>{ requireWellFormed: true }</code> now validates a
processing-instruction target as an XML <a
href="https://www.w3.org/TR/xml-names/#NT-NCName"><code>NCName</code></a>
and rejects a case-insensitive <code>xml</code>, throwing
<code>InvalidStateError</code> — a check <code>0.8.x</code> did not
previously perform, preventing PI-target injection via
<code>&gt;</code>, <code>?</code>, or whitespace. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-c7q8-3ch8-vqpv"><code>GHSA-c7q8-3ch8-vqpv</code></a></li>
<li>Security: <code>Document.createEntityReference()</code> now rejects
an invalid XML <a
href="https://www.w3.org/TR/xml/#NT-Name"><code>Name</code></a> at
creation, and <code>XMLSerializer.serializeToString()</code> under
<code>{ requireWellFormed: true }</code> validates an
<code>EntityReference</code> <code>nodeName</code> as an XML
<code>Name</code>, throwing <code>InvalidStateError</code> — preventing
XML injection via an entity-reference name. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-6gmq-8vp8-gcm6"><code>GHSA-6gmq-8vp8-gcm6</code></a></li>
<li>Security: the parser now reports a not-well-formed end tag whose
valid name is followed by trailing content as a recoverable
<code>error</code> instead of accepting it silently, per the XML <a
href="https://www.w3.org/TR/xml/#NT-ETag"><code>ETag</code></a>
production; parsing recovers to the byte-identical DOM. Consumers that
want strict rejection can escalate the reported <code>error</code> to
fatal via the parser's <code>errorHandler</code>. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-6h8r-xr42-gp59"><code>GHSA-6h8r-xr42-gp59</code></a></li>
</ul>
<p>Thank you,
<a href="https://github.com/ericchiang"><code>@​ericchiang</code></a>,
<a href="https://github.com/bhaswanthc"><code>@​bhaswanthc</code></a>,
<a
href="https://github.com/arpitjain099"><code>@​arpitjain099</code></a>,
<a
href="https://github.com/Paranoidgrinch"><code>@​Paranoidgrinch</code></a>,
for your contributions</p>
<h2>0.8.14</h2>
<p><a
href="https://github.com/xmldom/xmldom/compare/0.8.13...0.8.14">Commits</a></p>
<h3>Fixed</h3>
<ul>
<li>Security: <code>XMLSerializer.serializeToString()</code> now also
rejects invalid element and attribute names when <code>{
requireWellFormed: true }</code> is passed, throwing
<code>InvalidStateError</code> for a name that is not a valid XML <a
href="https://www.w3.org/TR/xml-names/#NT-QName"><code>QName</code></a>
(this covers the namespace prefix, which surfaces in the element
qualified name or in a synthesized <code>xmlns:</code> declaration).
This prevents XML injection via <code>createElement()</code> /
<code>setAttribute()</code>, extending the existing
<code>requireWellFormed</code> checks to the serialized name set. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-w2rr-34g9-rvrj"><code>GHSA-w2rr-34g9-rvrj</code></a>
<a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-4w3w-2rp5-g8jm"><code>GHSA-4w3w-2rp5-g8jm</code></a></li>
</ul>
<p>Thank you,
<a href="https://github.com/bhaswanthc"><code>@​bhaswanthc</code></a>,
<a
href="https://github.com/jmestwa-coder"><code>@​jmestwa-coder</code></a>,
for your contributions</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/xmldom/xmldom/blob/master/CHANGELOG.md">@​xmldom/xmldom's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/xmldom/xmldom/compare/0.8.14...0.8.15">0.8.15</a></h2>
<h3>Fixed</h3>
<ul>
<li>Security: parsing a deeply or repeatedly namespaced document no
longer consumes quadratic memory; the in-scope namespace map is
inherited through the prototype chain instead of being copied for every
prefix-declaring element (O(N) instead of O(N²)), preventing a
denial-of-service reachable from <code>DOMParser.parseFromString</code>
with default options. Serialized output is byte-identical. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-965w-775f-mr7g"><code>GHSA-965w-775f-mr7g</code></a></li>
<li>Security: attribute de-duplication during parsing is now O(M)
instead of O(M²); the <code>NamedNodeMap</code> parse-time dedup path
uses a null-prototype membership index, so a well-formed document with a
hostile number of duplicate attributes can no longer wedge the parse.
Attribute order and duplicate resolution (last value wins, first
position kept) are byte-identical, preserving the XML <a
href="https://www.w3.org/TR/xml/#uniqattspec">no-duplicate-attributes
well-formedness constraint</a>. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-8344-3jmq-59r6"><code>GHSA-8344-3jmq-59r6</code></a></li>
<li>Security: trimming trailing whitespace from an XML end tag (<a
href="https://www.w3.org/TR/xml/#NT-ETag"><code>ETag</code></a>) is now
anchored so it runs in linear time instead of backtracking quadratically
on a long whitespace run, preventing a ReDoS reachable from
<code>DOMParser.parseFromString</code>. Trimmed output is
byte-identical. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-x4fp-j954-r2f4"><code>GHSA-x4fp-j954-r2f4</code></a></li>
<li>Security: malformed-input recovery is now linear instead of
quadratic — the malformed tag-name scan terminates at an embedded
<code>&lt;</code>, and <code>Node.prototype.normalize()</code> merges
adjacent text nodes in O(K) instead of O(K²) (also reachable
programmatically), per <a
href="https://dom.spec.whatwg.org/#dom-node-normalize"><code>normalize()</code></a>
in the WHATWG DOM spec. DOM output is unchanged; only the reported error
text differs. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-93r5-fhx6-vmg9"><code>GHSA-93r5-fhx6-vmg9</code></a></li>
<li>Security: <code>XMLSerializer.serializeToString()</code> under
<code>{ requireWellFormed: true }</code> now rejects a DocType
<code>name</code> that is not a valid XML <a
href="https://www.w3.org/TR/xml/#NT-Name"><code>Name</code></a>,
throwing <code>InvalidStateError</code> — matching the sibling
<code>publicId</code>/<code>systemId</code>/<code>internalSubset</code>
checks and preventing XML injection via <code>DocumentType.name</code>.
<a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-27p8-2357-5qqv"><code>GHSA-27p8-2357-5qqv</code></a></li>
<li>Security: <code>XMLSerializer.serializeToString()</code> under
<code>{ requireWellFormed: true }</code> now validates a
processing-instruction target as an XML <a
href="https://www.w3.org/TR/xml-names/#NT-NCName"><code>NCName</code></a>
and rejects a case-insensitive <code>xml</code>, throwing
<code>InvalidStateError</code> — a check <code>0.8.x</code> did not
previously perform, preventing PI-target injection via
<code>&gt;</code>, <code>?</code>, or whitespace. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-c7q8-3ch8-vqpv"><code>GHSA-c7q8-3ch8-vqpv</code></a></li>
<li>Security: <code>Document.createEntityReference()</code> now rejects
an invalid XML <a
href="https://www.w3.org/TR/xml/#NT-Name"><code>Name</code></a> at
creation, and <code>XMLSerializer.serializeToString()</code> under
<code>{ requireWellFormed: true }</code> validates an
<code>EntityReference</code> <code>nodeName</code> as an XML
<code>Name</code>, throwing <code>InvalidStateError</code> — preventing
XML injection via an entity-reference name. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-6gmq-8vp8-gcm6"><code>GHSA-6gmq-8vp8-gcm6</code></a></li>
<li>Security: the parser now reports a not-well-formed end tag whose
valid name is followed by trailing content as a recoverable
<code>error</code> instead of accepting it silently, per the XML <a
href="https://www.w3.org/TR/xml/#NT-ETag"><code>ETag</code></a>
production; parsing recovers to the byte-identical DOM. Consumers that
want strict rejection can escalate the reported <code>error</code> to
fatal via the parser's <code>errorHandler</code>. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-6h8r-xr42-gp59"><code>GHSA-6h8r-xr42-gp59</code></a></li>
</ul>
<p>Thank you,
<a href="https://github.com/ericchiang"><code>@​ericchiang</code></a>,
<a href="https://github.com/bhaswanthc"><code>@​bhaswanthc</code></a>,
<a
href="https://github.com/arpitjain099"><code>@​arpitjain099</code></a>,
<a
href="https://github.com/Paranoidgrinch"><code>@​Paranoidgrinch</code></a>,
for your contributions</p>
<h2><a
href="https://github.com/xmldom/xmldom/compare/0.9.10...0.9.11">0.9.11</a></h2>
<h3>Fixed</h3>
<ul>
<li>Security: <code>XMLSerializer.serializeToString()</code> now also
rejects invalid element and attribute names when <code>{
requireWellFormed: true }</code> is passed, throwing
<code>InvalidStateError</code> for a name that is not a valid XML <a
href="https://www.w3.org/TR/xml-names/#NT-QName"><code>QName</code></a>
(this covers the namespace prefix, which surfaces in the element
qualified name or in a synthesized <code>xmlns:</code> declaration).
This prevents XML injection via <code>createElement()</code> /
<code>setAttribute()</code>, extending the existing
<code>requireWellFormed</code> checks to the serialized name set. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-w2rr-34g9-rvrj"><code>GHSA-w2rr-34g9-rvrj</code></a>
<a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-4w3w-2rp5-g8jm"><code>GHSA-4w3w-2rp5-g8jm</code></a></li>
<li>Security: the processing-instruction grammar regex no longer
backtracks quadratically on an unterminated processing instruction
(<code>&lt;?…</code> with no closing <code>?&gt;</code>), preventing a
denial-of-service (ReDoS) reachable from
<code>DOMParser.parseFromString</code> with default options. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-g53g-w8rj-fmg7"><code>GHSA-g53g-w8rj-fmg7</code></a></li>
<li><code>CharacterData</code> <code>nodeValue</code> and
<code>data</code> are now kept in sync <a
href="https://redirect.github.com/xmldom/xmldom/pull/990"><code>[#990](https://github.com/xmldom/xmldom/issues/990)</code></a></li>
</ul>
<h3>Chore</h3>
<ul>
<li>updated dependencies</li>
</ul>
<p>Thank you,
<a href="https://github.com/bhaswanthc"><code>@​bhaswanthc</code></a>,
<a
href="https://github.com/jmestwa-coder"><code>@​jmestwa-coder</code></a>,
<a
href="https://github.com/stevenobiajulu"><code>@​stevenobiajulu</code></a>,
for your contributions</p>
<h2><a
href="https://github.com/xmldom/xmldom/compare/0.8.13...0.8.14">0.8.14</a></h2>
<h3>Fixed</h3>
<ul>
<li>Security: <code>XMLSerializer.serializeToString()</code> now also
rejects invalid element and attribute names when <code>{
requireWellFormed: true }</code> is passed, throwing
<code>InvalidStateError</code> for a name that is not a valid XML <a
href="https://www.w3.org/TR/xml-names/#NT-QName"><code>QName</code></a>
(this covers the namespace prefix, which surfaces in the element
qualified name or in a synthesized <code>xmlns:</code> declaration).
This prevents XML injection via <code>createElement()</code> /
<code>setAttribute()</code>, extending the existing
<code>requireWellFormed</code> checks to the serialized name set. <a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-w2rr-34g9-rvrj"><code>GHSA-w2rr-34g9-rvrj</code></a>
<a
href="https://github.com/xmldom/xmldom/security/advisories/GHSA-4w3w-2rp5-g8jm"><code>GHSA-4w3w-2rp5-g8jm</code></a></li>
</ul>
<p>Thank you,
<a href="https://github.com/bhaswanthc"><code>@​bhaswanthc</code></a>,
<a
href="https://github.com/jmestwa-coder"><code>@​jmestwa-coder</code></a>,
for your contributions</p>
<h2><a
href="https://github.com/xmldom/xmldom/compare/0.9.9...0.9.10">0.9.10</a></h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/xmldom/xmldom/commit/b5b8fb5b579ae1183b34e74b3bc39d7eb50a226a"><code>b5b8fb5</code></a>
0.8.15</li>
<li><a
href="https://github.com/xmldom/xmldom/commit/327508ea98d169285b2c0559836332a9879de213"><code>327508e</code></a>
docs: add 0.8.15 CHANGELOG entry</li>
<li><a
href="https://github.com/xmldom/xmldom/commit/f40ccb861eee0acbf5ee4feb9a34932e87b329c9"><code>f40ccb8</code></a>
fix: prevent quadratic malformed-tag recovery and normalize()
adjacent-text m...</li>
<li><a
href="https://github.com/xmldom/xmldom/commit/3abb0934f5a8a84d83a1f9cde0f2bd04c08b2a09"><code>3abb093</code></a>
fix: prevent end-tag whitespace-trim ReDoS via anchored trim
(GHSA-x4fp-j954-...</li>
<li><a
href="https://github.com/xmldom/xmldom/commit/2c548f200cfec991cd5846627ef8f03542309213"><code>2c548f2</code></a>
fix: prevent quadratic attribute de-duplication via null-prototype
membership...</li>
<li><a
href="https://github.com/xmldom/xmldom/commit/08a74b47c7f29d2e9b3212682856b959040d1838"><code>08a74b4</code></a>
test: characterize NamedNodeMap attribute de-duplication before the
index ref...</li>
<li><a
href="https://github.com/xmldom/xmldom/commit/954370f58c046223faf95ba77efcbc8ce014409d"><code>954370f</code></a>
fix: prevent quadratic namespace-map memory consumption via
prototype-chain i...</li>
<li><a
href="https://github.com/xmldom/xmldom/commit/4430189660b0d380ee9c9ee7550a1358688e8828"><code>4430189</code></a>
fix: report not-well-formed end-tag trailing content
(GHSA-6h8r-xr42-gp59)</li>
<li><a
href="https://github.com/xmldom/xmldom/commit/6c3fb5ffeafe7901ec928ce9010988dd716c94a0"><code>6c3fb5f</code></a>
fix: prevent XML injection via unsafe EntityReference name
(GHSA-6gmq-8vp8-gcm6)</li>
<li><a
href="https://github.com/xmldom/xmldom/commit/3b694872bcb5c7e3cbadba961a4be2488750ce5b"><code>3b69487</code></a>
fix: prevent XML injection via unsafe processing instruction target
serializa...</li>
<li>Additional commits viewable in <a
href="https://github.com/xmldom/xmldom/compare/0.8.13...0.8.15">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~karfau">karfau</a>, a new releaser for
<code>@​xmldom/xmldom</code> since your current version.</p>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@xmldom/xmldom&package-manager=npm_and_yarn&previous-version=0.8.13&new-version=0.8.15)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/wavetermdev/waveterm/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [browserslist](https://github.com/browserslist/browserslist) from
4.28.1 to 4.28.8.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/browserslist/browserslist/releases">browserslist's
releases</a>.</em></p>
<blockquote>
<h2>4.28.8</h2>
<ul>
<li>Fixed <code>including kaios</code> in baseline queries (by <a
href="https://github.com/Jaybhade"><code>@​Jaybhade</code></a>).</li>
</ul>
<h2>4.28.7</h2>
<ul>
<li>Improved parsing performance.</li>
<li>Fixed unbounded memory growth (by <a
href="https://github.com/alanturing881"><code>@​alanturing881</code></a>).</li>
<li>Fixed prototype write issue (by <a
href="https://github.com/alanturing881"><code>@​alanturing881</code></a>).</li>
</ul>
<h2>4.28.6</h2>
<ul>
<li>Fixed Electron version queries (by <a
href="https://github.com/spokodev"><code>@​spokodev</code></a>).</li>
</ul>
<h2>4.28.5</h2>
<ul>
<li>Fixed <code>&gt;</code> and <code>&gt;=</code> queries (by <a
href="https://github.com/spokodev"><code>@​spokodev</code></a>).</li>
</ul>
<h2>4.28.4</h2>
<ul>
<li>Fixed <code>SyntaxError</code> regression of 4.28.3.</li>
</ul>
<h2>4.28.3</h2>
<ul>
<li>Fixed baseline query case-insensitivity (by <a
href="https://github.com/swwind"><code>@​swwind</code></a>).</li>
</ul>
<h2>4.28.2</h2>
<ul>
<li>Fix prototype pollution (by <a
href="https://github.com/chluo1997"><code>@​chluo1997</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md">browserslist's
changelog</a>.</em></p>
<blockquote>
<h2>4.28.8</h2>
<ul>
<li>Fixed <code>including kaios</code> in baseline queries (by <a
href="https://github.com/Jaybhade"><code>@​Jaybhade</code></a>).</li>
</ul>
<h2>4.28.7</h2>
<ul>
<li>Improved parsing performance.</li>
<li>Fixed unbounded memory growth (by <a
href="https://github.com/alanturing881"><code>@​alanturing881</code></a>).</li>
<li>Fixed prototype write issue (by <a
href="https://github.com/alanturing881"><code>@​alanturing881</code></a>).</li>
</ul>
<h2>4.28.6</h2>
<ul>
<li>Fixed Electron version queries (by <a
href="https://github.com/spokodev"><code>@​spokodev</code></a>).</li>
</ul>
<h2>4.28.5</h2>
<ul>
<li>Fixed <code>&gt;</code> and <code>&gt;=</code> queries (by <a
href="https://github.com/spokodev"><code>@​spokodev</code></a>).</li>
</ul>
<h2>4.28.4</h2>
<ul>
<li>Fixed <code>SyntaxError</code> regression of 4.28.3.</li>
</ul>
<h2>4.28.3</h2>
<ul>
<li>Fixed baseline query case-insensitivity (by <a
href="https://github.com/swwind"><code>@​swwind</code></a>).</li>
</ul>
<h2>4.28.2</h2>
<ul>
<li>Fix prototype pollution (by <a
href="https://github.com/chluo1997"><code>@​chluo1997</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/browserslist/browserslist/commit/f2f2e6cfb01bb4942941d328737546f4e2ae41ad"><code>f2f2e6c</code></a>
Release 4.28.8 version</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/d0787c88fa29ba895fea51cfe921232c7b5d1377"><code>d0787c8</code></a>
Update dependencies</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/fcf8fa9857b30ccdf801a548f5d09d3c4ff0d43f"><code>fcf8fa9</code></a>
Merge pull request <a
href="https://redirect.github.com/browserslist/browserslist/issues/939">#939</a>
from Jaybhade/fix/baseline-kaios-without-downstream</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/57ecd64454e9252afdd6a7e76926e13dda48a38c"><code>57ecd64</code></a>
fix: support &quot;including kaios&quot; without downstream</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/093a0f67bb0becda55235d767b134df3197c54a1"><code>093a0f6</code></a>
Update EM banner</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/b637868045806d2fba4c24eb0060e4cc8b1db276"><code>b637868</code></a>
Release 4.28.7 version</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/313f4659b9f985ade89d1d6a54a860371c41cc46"><code>313f465</code></a>
Update dependencies</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/c935c5a206f8b13db8846818bc03643e147dcbdf"><code>c935c5a</code></a>
Fix regexp performance</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/d7e9e653cb53399065943f59f0b3063987b0a008"><code>d7e9e65</code></a>
Rewrite structure parsing to make it always fast</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/ec4a55efd76bdfa506ec7ce4fea1691559e9ca8f"><code>ec4a55e</code></a>
Fix import order</li>
<li>Additional commits viewable in <a
href="https://github.com/browserslist/browserslist/compare/4.28.1...4.28.8">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for browserslist since your current version.</p>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=browserslist&package-manager=npm_and_yarn&previous-version=4.28.1&new-version=4.28.8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/wavetermdev/waveterm/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from
1.82.1 to 1.83.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/grpc/grpc-go/releases">google.golang.org/grpc's
releases</a>.</em></p>
<blockquote>
<h2>Release 1.83.1</h2>
<h1>Security</h1>
<ul>
<li>xds/rbac: Fix a bug where nested <code>Principal</code> or
<code>Permission</code> rules with <code>:scheme</code> or
<code>grpc-</code> prefixed header matchers were not rejected, which
could cause DENY rules to fail open. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9258">#9258</a>)
<ul>
<li>Special Thanks: <a
href="https://github.com/nvxbug"><code>@​nvxbug</code></a></li>
</ul>
</li>
<li>xds/rbac: Fix a bug where the <code>host</code> header matcher was
not being replaced with <code>:authority</code> in nested
<code>Principal</code> or <code>Permission</code> rules. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9258">#9258</a>)
<ul>
<li>Special Thanks: <a
href="https://github.com/nvxbug"><code>@​nvxbug</code></a></li>
</ul>
</li>
<li>xds/rbac: Fix a bug where a header matcher whose name was not
lowercase, such as <code>X-Role</code>, matched no header, which could
cause DENY rules to fail open. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9332">#9332</a>)
<ul>
<li>Special Thanks: <a
href="https://github.com/alimony"><code>@​alimony</code></a></li>
</ul>
</li>
<li>xds/rbac: Fix a bug where a <code>:scheme</code> or
<code>grpc-</code> prefixed header matcher was accepted when its name
was not lowercase. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9332">#9332</a>)
<ul>
<li>Special Thanks: <a
href="https://github.com/alimony"><code>@​alimony</code></a></li>
</ul>
</li>
<li>xds/rbac: Fix a bug where a <code>Host</code> header matcher was not
replaced with <code>:authority</code>. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9332">#9332</a>)
<ul>
<li>Special Thanks: <a
href="https://github.com/alimony"><code>@​alimony</code></a></li>
</ul>
</li>
</ul>
<h1>Performance</h1>
<ul>
<li>transport: Restrict memory overhead of buffering small data frames.
(<a
href="https://redirect.github.com/grpc/grpc-go/issues/9331">#9331</a>)</li>
</ul>
<h2>Release 1.83.0</h2>
<h1>Security</h1>
<ul>
<li>server: Stop reading from connections when flooded by HTTP/2 frames
to mitigate resource exhaustion. The default value for this limit is 100
frames, excluding DATA and HEADERS, and may be changed by setting
environment variable
<code>GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT</code>.</li>
<li>xds/rbac: Support <code>Metadata</code> and
<code>RequestedServerName</code> permissions matcher fields. If present
in a DENY rule, previously these would be ignored and fail-open.</li>
<li>xds/rbac: Fix panic when parsing unsupported fields in
<code>NotRule</code>/<code>NotId</code> permissions.</li>
<li>xds/rbac: Support the deprecated <code>source_ip</code> principal
identifier by treating it as equivalent to
<code>direct_remote_ip</code>.</li>
<li>xds: Fix panic when parsing route header matchers configured with
empty <code>exact_match</code>, <code>prefix_match</code>, or
<code>suffix_match</code> strings. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9223">#9223</a>)</li>
</ul>
<h1>New Features</h1>
<ul>
<li>xds/googlec2p: Enable DirectPath over Interconnect support for
on-premises clients via the <code>force-xds</code> target URI query
parameter. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9133">#9133</a>)</li>
<li>xds: Enable xDS configuration to control which fields get propagated
from ORCA backend metric reports to LRS load reports. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9145">#9145</a>)</li>
<li>authz: Add <code>OnPolicyUpdate</code> callback to
<code>FileWatcherOptions</code> to notify when an authz policy is loaded
or updated. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9142">#9142</a>)
<ul>
<li>Special Thanks: <a
href="https://github.com/hnefatl"><code>@​hnefatl</code></a></li>
</ul>
</li>
<li>xds: Add support for the GCP Authentication HTTP Filter, which
automatically fetches and attaches GCP Service Account Identity JWT
tokens to outgoing RPCs.
<ul>
<li>This feature can be enabled by setting environment variable
<code>GRPC_EXPERIMENTAL_XDS_GCP_AUTHENTICATION_FILTER=true</code>. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9119">#9119</a>)</li>
</ul>
</li>
<li>xds: Add support for xDS-based HTTP CONNECT proxies.
<ul>
<li>This feature can be enabled by setting environment variable
<code>GRPC_EXPERIMENTAL_XDS_HTTP_CONNECT=true</code>. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9151">#9151</a>)</li>
</ul>
</li>
<li>xds: Add support for <code>contains_match</code> in route header
matchers. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9223">#9223</a>)</li>
</ul>
<h1>Bug Fixes</h1>
<ul>
<li>credentials/alts: Fix panic when processing malformed frames by
validating that the message frame length exceeds the message type field
size. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9197">#9197</a>)</li>
<li>grpc: Fix compilation on Plan 9 targets (<code>GOOS=plan9</code>),
broken since v1.81.0. (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9255">#9255</a>)
<ul>
<li>Special Thanks: <a
href="https://github.com/Yusufihsangorgel"><code>@​Yusufihsangorgel</code></a></li>
</ul>
</li>
</ul>
<h2>Release 1.82.2</h2>
<h1>Security</h1>
<ul>
<li>server: Reject requests missing both <code>:authority</code> and
<code>Host</code> headers with HTTP 400 and status
<code>Internal</code>. (<a
href="https://redirect.github.com/grpc/grpc-go/pull/9365">grpc/grpc-go#9365</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/grpc/grpc-go/commit/1550d9e0cddb30ce99e61a2102e8294a49461e5e"><code>1550d9e</code></a>
Change version to 1.83.1 (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9336">#9336</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/ebba6f3f1b206e2b4dc4d1d5a96d18430302c2fe"><code>ebba6f3</code></a>
Cherry-pick <a
href="https://redirect.github.com/grpc/grpc-go/issues/9258">#9258</a>
and <a
href="https://redirect.github.com/grpc/grpc-go/issues/9332">#9332</a>
into v1.83.x (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9335">#9335</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77"><code>8cfeca0</code></a>
Cherry-pick <a
href="https://redirect.github.com/grpc/grpc-go/issues/9331">#9331</a> to
v1.83.x (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9333">#9333</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/dec6951305e88906696f1d0a00dd2439363bc708"><code>dec6951</code></a>
Change version to 1.83.1-dev (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9229">#9229</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/4c226daff88f54441d70f710815e07b81fb162b2"><code>4c226da</code></a>
Change version to 1.83.0 (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9228">#9228</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/c198988aa9297cb9428c7afaaee4363d0082b838"><code>c198988</code></a>
Cherrypick 9223 into v1.83.x (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9279">#9279</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/8ce3ebf24af3c206bacf279adcf9c3a88981df68"><code>8ce3ebf</code></a>
Cherrypick PR 9255 into v1.83.x (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9263">#9263</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/e39384978cf59c70634f900a7aa93d7483886696"><code>e393849</code></a>
Cherry-pick recent changes from master (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9240">#9240</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/2a112a82f5c53ab3b89b5aa4a02b4195e2706879"><code>2a112a8</code></a>
authz: add onPolicyUpdate callback to authz file watcher (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9142">#9142</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/1a80fca960d39ae4d7d6f2d9323ca2d243fd44bb"><code>1a80fca</code></a>
vet: adds a check to disallow usage of regex.Compile in xDS code (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9216">#9216</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/grpc/grpc-go/compare/v1.82.1...v1.83.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=google.golang.org/grpc&package-manager=go_modules&previous-version=1.82.1&new-version=1.83.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/wavetermdev/waveterm/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [nanoid](https://github.com/ai/nanoid) from 3.3.11 to 3.3.18.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/ai/nanoid/releases">nanoid's
releases</a>.</em></p>
<blockquote>
<h2>3.3.18</h2>
<ul>
<li>Fixed infinite loop on async for React Native (by <a
href="https://github.com/OvergrowthBeards-JB"><code>@​OvergrowthBeards-JB</code></a>).</li>
</ul>
<h2>3.3.17</h2>
<ul>
<li>Fixed infinite loop on zero size.</li>
</ul>
<h2>3.3.16</h2>
<ul>
<li>Fixed infinite loop on negative size (by <a
href="https://github.com/greymoth-jp"><code>@​greymoth-jp</code></a>).</li>
</ul>
<h2>3.3.15</h2>
<ul>
<li>Fixed npm provenance error.</li>
</ul>
<h2>3.3.14</h2>
<ul>
<li>Fixed random pool corruption on big ID sizes.</li>
</ul>
<h2>3.3.13</h2>
<ul>
<li>Reduced npm package size.</li>
</ul>
<h2>3.3.12</h2>
<ul>
<li>Fixed breaking Nano ID by requesting big ID.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/ai/nanoid/blob/3.3.18/CHANGELOG.md">nanoid's
changelog</a>.</em></p>
<blockquote>
<h2>3.3.18</h2>
<ul>
<li>Fixed infinite loop on async for React Native (by <a
href="https://github.com/OvergrowthBeards-JB"><code>@​OvergrowthBeards-JB</code></a>).</li>
</ul>
<h2>3.3.17</h2>
<ul>
<li>Fixed infinite loop on zero size.</li>
</ul>
<h2>3.3.16</h2>
<ul>
<li>Fixed infinite loop on negative size (by <a
href="https://github.com/greymoth-jp"><code>@​greymoth-jp</code></a>).</li>
</ul>
<h2>3.3.15</h2>
<ul>
<li>Fixed npm provenance error.</li>
</ul>
<h2>3.3.14</h2>
<ul>
<li>Fixed random pool corruption on big ID sizes.</li>
</ul>
<h2>3.3.13</h2>
<ul>
<li>Reduced npm package size.</li>
</ul>
<h2>3.3.12</h2>
<ul>
<li>Fixed breaking Nano ID by requesting big ID.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/ai/nanoid/commit/9ad98052b316c5e707f8098ace509d2ae165e54d"><code>9ad9805</code></a>
Release 3.3.18 version</li>
<li><a
href="https://github.com/ai/nanoid/commit/55e50a0621ec084b4bb4000ea4e86e1191bd3da8"><code>55e50a0</code></a>
Update CI action</li>
<li><a
href="https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0"><code>e10f8d4</code></a>
Update index.native.js (<a
href="https://redirect.github.com/ai/nanoid/issues/606">#606</a>)</li>
<li><a
href="https://github.com/ai/nanoid/commit/73d67168136b36fd3b644159b0cff149da4905d9"><code>73d6716</code></a>
Release 3.3.17 version</li>
<li><a
href="https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b"><code>f9d13f1</code></a>
Sync 0 size behaviour with PostCSS 5</li>
<li><a
href="https://github.com/ai/nanoid/commit/9760e112757cf7d46a79abd7a133bc4958757bb8"><code>9760e11</code></a>
Release 3.3.16 version</li>
<li><a
href="https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d"><code>e835c9b</code></a>
fix(non-secure): clamp negative size to prevent infinite loop (<a
href="https://redirect.github.com/ai/nanoid/issues/601">#601</a>)</li>
<li><a
href="https://github.com/ai/nanoid/commit/96dd086eb24396a275fa93ee78d73b2fece35809"><code>96dd086</code></a>
Update CI action</li>
<li><a
href="https://github.com/ai/nanoid/commit/ba0bc3b6b95a7e8fb97efa248306e0512b340ace"><code>ba0bc3b</code></a>
Do not create latest release for v3</li>
<li><a
href="https://github.com/ai/nanoid/commit/6819724a0ebe3d1980de66980f6bc5df4bf6a41f"><code>6819724</code></a>
Release 3.3.15 version</li>
<li>Additional commits viewable in <a
href="https://github.com/ai/nanoid/compare/3.3.11...3.3.18">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for nanoid since your current version.</p>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=nanoid&package-manager=npm_and_yarn&previous-version=3.3.11&new-version=3.3.18)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

You can trigger a rebase of this PR by commenting `@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/wavetermdev/waveterm/network/alerts).

</details>

> **Note**
> Automatic rebases have been disabled on this pull request as it has
been open for over 30 days.

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from
1.83.1 to 1.83.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/grpc/grpc-go/releases">google.golang.org/grpc's
releases</a>.</em></p>
<blockquote>
<h2>Release 1.83.2</h2>
<h1>Security</h1>
<ul>
<li>server: Reject requests missing both <code>:authority</code> and
<code>Host</code> headers with HTTP 400 and status
<code>Internal</code>. (<a
href="https://redirect.github.com/grpc/grpc-go/pull/9365">grpc/grpc-go#9365</a>)
<ul>
<li>Special Thanks: <a
href="https://github.com/winklemad"><code>@​winklemad</code></a></li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/grpc/grpc-go/commit/030ee8becb20ce4315d6bf2dfa26bdd876169dc4"><code>030ee8b</code></a>
Update version to 1.83.2 (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9375">#9375</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/8668b69c167df908b6b3666dcbf40992b9e932a4"><code>8668b69</code></a>
cherry-pick <a
href="https://redirect.github.com/grpc/grpc-go/issues/9365">#9365</a> to
v1.83.x (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9366">#9366</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/a3e952d2b7c973b7ec6357676e55a2a9c9faaa0d"><code>a3e952d</code></a>
cherry-pick <a
href="https://redirect.github.com/grpc/grpc-go/issues/9346">#9346</a> to
v1.83.x and update x/net dependency (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9369">#9369</a>)</li>
<li><a
href="https://github.com/grpc/grpc-go/commit/58f8fd9a002536548ac96e34621d761b29cc4f3e"><code>58f8fd9</code></a>
Change version to 1.83.2-dev (<a
href="https://redirect.github.com/grpc/grpc-go/issues/9337">#9337</a>)</li>
<li>See full diff in <a
href="https://github.com/grpc/grpc-go/compare/v1.83.1...v1.83.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=google.golang.org/grpc&package-manager=go_modules&previous-version=1.83.1&new-version=1.83.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/wavetermdev/waveterm/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps and
[brace-expansion](https://github.com/juliangruber/brace-expansion).
These dependencies needed to be updated together.
Updates `brace-expansion` from 1.1.13 to 1.1.18
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/juliangruber/brace-expansion/releases">brace-expansion's
releases</a>.</em></p>
<blockquote>
<h2>v1.1.15</h2>
<ul>
<li>Backport v5.0.6 change to v1 (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/111">#111</a>)
0b09384</li>
</ul>
<hr />
<p><a
href="https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15">https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b"><code>758fcd6</code></a>
1.1.18</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e"><code>27fbeed</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf"><code>5c57cc2</code></a>
1.1.17</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57"><code>d757f1d</code></a>
npm ignore <code>.claude</code></li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031"><code>cb4b9e4</code></a>
fix: backport GHSA-mh99-v99m-4gvg (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/129">#129</a>)</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97"><code>447763a</code></a>
1.1.16</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95"><code>d74e630</code></a>
fix: v1 backport for CVE-2026-13149 (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/122">#122</a>)</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24"><code>2203f4f</code></a>
1.1.15</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd"><code>0b09384</code></a>
Backport v5.0.6 change to v1 (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/111">#111</a>)</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3"><code>10c05fc</code></a>
1.1.14</li>
<li>Additional commits viewable in <a
href="https://github.com/juliangruber/brace-expansion/compare/v1.1.13...v1.1.18">compare
view</a></li>
</ul>
</details>
<br />

Updates `brace-expansion` from 2.0.3 to 2.1.4
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/juliangruber/brace-expansion/releases">brace-expansion's
releases</a>.</em></p>
<blockquote>
<h2>v1.1.15</h2>
<ul>
<li>Backport v5.0.6 change to v1 (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/111">#111</a>)
0b09384</li>
</ul>
<hr />
<p><a
href="https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15">https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b"><code>758fcd6</code></a>
1.1.18</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e"><code>27fbeed</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf"><code>5c57cc2</code></a>
1.1.17</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57"><code>d757f1d</code></a>
npm ignore <code>.claude</code></li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031"><code>cb4b9e4</code></a>
fix: backport GHSA-mh99-v99m-4gvg (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/129">#129</a>)</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97"><code>447763a</code></a>
1.1.16</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95"><code>d74e630</code></a>
fix: v1 backport for CVE-2026-13149 (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/122">#122</a>)</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24"><code>2203f4f</code></a>
1.1.15</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd"><code>0b09384</code></a>
Backport v5.0.6 change to v1 (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/111">#111</a>)</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3"><code>10c05fc</code></a>
1.1.14</li>
<li>Additional commits viewable in <a
href="https://github.com/juliangruber/brace-expansion/compare/v1.1.13...v1.1.18">compare
view</a></li>
</ul>
</details>
<br />

Updates `brace-expansion` from 5.0.5 to 5.0.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/juliangruber/brace-expansion/releases">brace-expansion's
releases</a>.</em></p>
<blockquote>
<h2>v1.1.15</h2>
<ul>
<li>Backport v5.0.6 change to v1 (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/111">#111</a>)
0b09384</li>
</ul>
<hr />
<p><a
href="https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15">https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b"><code>758fcd6</code></a>
1.1.18</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e"><code>27fbeed</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf"><code>5c57cc2</code></a>
1.1.17</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57"><code>d757f1d</code></a>
npm ignore <code>.claude</code></li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031"><code>cb4b9e4</code></a>
fix: backport GHSA-mh99-v99m-4gvg (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/129">#129</a>)</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97"><code>447763a</code></a>
1.1.16</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95"><code>d74e630</code></a>
fix: v1 backport for CVE-2026-13149 (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/122">#122</a>)</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24"><code>2203f4f</code></a>
1.1.15</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd"><code>0b09384</code></a>
Backport v5.0.6 change to v1 (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/111">#111</a>)</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3"><code>10c05fc</code></a>
1.1.14</li>
<li>Additional commits viewable in <a
href="https://github.com/juliangruber/brace-expansion/compare/v1.1.13...v1.1.18">compare
view</a></li>
</ul>
</details>
<br />


You can trigger a rebase of this PR by commenting `@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/wavetermdev/waveterm/network/alerts).

</details>

> **Note**
> Automatic rebases have been disabled on this pull request as it has
been open for over 30 days.

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from
10.2.0 to 10.4.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/beaugunderson/ip-address/releases">ip-address's
releases</a>.</em></p>
<blockquote>
<h2>v10.4.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Add GitHub Actions CI by <a
href="https://github.com/beaugunderson"><code>@​beaugunderson</code></a>
in <a
href="https://redirect.github.com/beaugunderson/ip-address/pull/213">beaugunderson/ip-address#213</a></li>
<li>Keep the package loadable on node 12, and enforce it by <a
href="https://github.com/beaugunderson"><code>@​beaugunderson</code></a>
in <a
href="https://redirect.github.com/beaugunderson/ip-address/pull/216">beaugunderson/ip-address#216</a></li>
<li>Validate the byte arrays Address6 is given by <a
href="https://github.com/beaugunderson"><code>@​beaugunderson</code></a>
in <a
href="https://redirect.github.com/beaugunderson/ip-address/pull/217">beaugunderson/ip-address#217</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/beaugunderson/ip-address/compare/v10.3.1...v10.4.0">https://github.com/beaugunderson/ip-address/compare/v10.3.1...v10.4.0</a></p>
<h2>v10.3.1</h2>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/beaugunderson/ip-address/compare/v10.3.0...v10.3.1">https://github.com/beaugunderson/ip-address/compare/v10.3.0...v10.3.1</a></p>
<h2>v10.3.0</h2>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/beaugunderson/ip-address/compare/v10.2.2...v10.3.0">https://github.com/beaugunderson/ip-address/compare/v10.2.2...v10.3.0</a></p>
<h2>v10.2.2</h2>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/beaugunderson/ip-address/compare/v10.2.1...v10.2.2">https://github.com/beaugunderson/ip-address/compare/v10.2.1...v10.2.2</a></p>
<h2>v10.2.1</h2>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.2.1">https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.2.1</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/fbb8db28f1559842b7191cab7d8ea6408ed82f7b"><code>fbb8db2</code></a>
10.4.0</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/45a2b11ec254a2e5620de66e248adcb33d16e669"><code>45a2b11</code></a>
Validate the byte arrays Address6 is given (<a
href="https://redirect.github.com/beaugunderson/ip-address/issues/217">#217</a>)</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/bac8810b3935cab123316a4bc5ebaa22db140299"><code>bac8810</code></a>
Keep the package loadable on node 12, and enforce it (<a
href="https://redirect.github.com/beaugunderson/ip-address/issues/216">#216</a>)</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/9b3d8488d15e6bfe5f5503867b088ce056723e08"><code>9b3d848</code></a>
Add a security policy and a README section on security posture</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/e84a7b381d02cb97ed114023e44133efae151254"><code>e84a7b3</code></a>
Order the README API reference Address4, Address6, AddressError</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/015160b85ee60b39548219817a5de3c4e828a6d6"><code>015160b</code></a>
Collapse each class in the README API reference</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/34061a897d526b7a063c3605402cd30a8363a035"><code>34061a8</code></a>
Pin checkout and setup-node to commits in the release job</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/c5fae5d9bdfe8ded7f4ca01a3d3ea8d97f8f1277"><code>c5fae5d</code></a>
Pin action-gh-release to a commit and move it to 3.0.2</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/e0ef0484193218b0d28cfbb53795bc44ddb3cc21"><code>e0ef048</code></a>
Replace CircleCI with GitHub Actions</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/5e3ceb779aee6ad3f33264e66225e8e7584ab612"><code>5e3ceb7</code></a>
Add GitHub Actions CI across Node 20, 22, 24 and 25 (<a
href="https://redirect.github.com/beaugunderson/ip-address/issues/213">#213</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.4.0">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for ip-address since your current version.</p>
</details>
<details>
<summary>Install script changes</summary>
<p>This version adds <code>prepare</code> script that runs during
installation. Review the package contents before updating.</p>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ip-address&package-manager=npm_and_yarn&previous-version=10.2.0&new-version=10.4.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

You can trigger a rebase of this PR by commenting `@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/wavetermdev/waveterm/network/alerts).

</details>

> **Note**
> Automatic rebases have been disabled on this pull request as it has
been open for over 30 days.

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite)
from 6.4.2 to 6.4.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vitejs/vite/releases">vite's
releases</a>.</em></p>
<blockquote>
<h2>v6.4.3</h2>
<p>Please refer to <a
href="https://github.com/vitejs/vite/blob/v6.4.3/packages/vite/CHANGELOG.md">CHANGELOG.md</a>
for details.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vitejs/vite/blob/v6.4.3/packages/vite/CHANGELOG.md">vite's
changelog</a>.</em></p>
<blockquote>
<h2><!-- raw HTML omitted -->6.4.3 (2026-06-01)<!-- raw HTML omitted
--></h2>
<ul>
<li>fix: backport <a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22572">#22572</a>,
reject windows alternate paths (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22576">#22576</a>)
(<a
href="https://github.com/vitejs/vite/commit/96b0c10162e9c55485d922db2cfc6b8227cbc176">96b0c10</a>),
closes <a
href="https://redirect.github.com/vitejs/vite/issues/22572">#22572</a>
<a
href="https://redirect.github.com/vitejs/vite/issues/22576">#22576</a></li>
<li>fix(deps): backport <a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22571">#22571</a>,
reject UNC paths for launch-editor-middleware (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22575">#22575</a>)
(<a
href="https://github.com/vitejs/vite/commit/8fed5cf540c0d475266787f52072f258478cd42f">8fed5cf</a>),
closes <a
href="https://redirect.github.com/vitejs/vite/issues/22571">#22571</a>
<a
href="https://redirect.github.com/vitejs/vite/issues/22575">#22575</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vitejs/vite/commit/6c2c881f15495738ff03bc1d67cc052c07e0cac4"><code>6c2c881</code></a>
release: v6.4.3</li>
<li><a
href="https://github.com/vitejs/vite/commit/96b0c10162e9c55485d922db2cfc6b8227cbc176"><code>96b0c10</code></a>
fix: backport <a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22572">#22572</a>,
reject windows alternate paths (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22576">#22576</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/8fed5cf540c0d475266787f52072f258478cd42f"><code>8fed5cf</code></a>
fix(deps): backport <a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22571">#22571</a>,
reject UNC paths for launch-editor-middleware (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/2">#2</a>...</li>
<li>See full diff in <a
href="https://github.com/vitejs/vite/commits/v6.4.3/packages/vite">compare
view</a></li>
</ul>
</details>
<br />


> **Note**
> Automatic rebases have been disabled on this pull request as it has
been open for over 30 days.

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from
0.55.0 to 0.57.0.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/golang/crypto/commit/3f62bf119e84c6e35e8518a2958089ade622d1a3"><code>3f62bf1</code></a>
go.mod: update golang.org/x dependencies</li>
<li><a
href="https://github.com/golang/crypto/commit/86efde54dc7069251a8b007026c500d28e4239ce"><code>86efde5</code></a>
ssh: reject unexpected message types on established channels</li>
<li><a
href="https://github.com/golang/crypto/commit/a6cdac60840750226b15617ac8858be44361b36b"><code>a6cdac6</code></a>
ssh: drop traffic on undecided channels</li>
<li><a
href="https://github.com/golang/crypto/commit/39dc44e69c280a6254fa09ce85477455efeaf6a2"><code>39dc44e</code></a>
ssh: don't skip the source-address critical option in CheckCert</li>
<li><a
href="https://github.com/golang/crypto/commit/afebf4cb4efb2b854282e03160da67120707f8f7"><code>afebf4c</code></a>
x509roots/fallback/bundle: make subjectsEqual stricter on Go 1.27+</li>
<li><a
href="https://github.com/golang/crypto/commit/89f4e9bb5b38861a69b1b26890a6833138d35ace"><code>89f4e9b</code></a>
x509roots/fallback: update bundle</li>
<li><a
href="https://github.com/golang/crypto/commit/71488c48c2dfecf900e52caa55f88ef4fef62d54"><code>71488c4</code></a>
ssh/knownhosts: compare only public key portions for revocation</li>
<li><a
href="https://github.com/golang/crypto/commit/82adefa711cb8d9a1f12c7ea91b491007d21819f"><code>82adefa</code></a>
ssh: synchronize unexpected response test</li>
<li><a
href="https://github.com/golang/crypto/commit/c757c9851f77c470645455f548046ae0ce87ef8d"><code>c757c98</code></a>
all: upgrade go directive to at least 1.26.0 [generated]</li>
<li><a
href="https://github.com/golang/crypto/commit/593c81af8aa6582d85a7faaeb996396f63d712a9"><code>593c81a</code></a>
ssh: correctly ignore pre-banner lines</li>
<li>Additional commits viewable in <a
href="https://github.com/golang/crypto/compare/v0.55.0...v0.57.0">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Summary
- Declare `sharp` as a development dependency so
`vite-plugin-image-optimizer` can load its optional peer during renderer
builds.
- Lock the native packages for supported platforms.

## Verification
- `npm run build:dev` exited 0 and successfully optimized all four logo
images (about 63% total savings).
- Sharp loaded and encoded a PNG on Linux x64.
- `task check:ts` still fails on existing preview-mock type errors,
unrelated to this dependency change.
Bumps [lodash](https://github.com/lodash/lodash) from 4.17.23 to 4.18.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/lodash/lodash/releases">lodash's
releases</a>.</em></p>
<blockquote>
<h2>4.18.1</h2>
<h2>Bugs</h2>
<p>Fixes a <code>ReferenceError</code> issue in <code>lodash</code>
<code>lodash-es</code> <code>lodash-amd</code> and
<code>lodash.template</code> when using the <code>template</code> and
<code>fromPairs</code> functions from the modular builds. See <a
href="https://redirect.github.com/lodash/lodash/issues/6167#issuecomment-4165269769">lodash/lodash#6167</a></p>
<p>These defects were related to how lodash distributions are built from
the main branch using <a
href="https://github.com/lodash-archive/lodash-cli">https://github.com/lodash-archive/lodash-cli</a>.
When internal dependencies change inside lodash functions, equivalent
updates need to be made to a mapping in the lodash-cli. (hey, it was
ahead of its time once upon a time!). We know this, but we missed it in
the last release. It's the kind of thing that passes in CI, but fails bc
the build is not the same thing you tested.</p>
<p>There is no diff on main for this, but you can see the diffs for each
of the npm packages on their respective branches:</p>
<ul>
<li><code>lodash</code>: <a
href="https://github.com/lodash/lodash/compare/4.18.0-npm...4.18.1-npm">https://github.com/lodash/lodash/compare/4.18.0-npm...4.18.1-npm</a></li>
<li><code>lodash-es</code>: <a
href="https://github.com/lodash/lodash/compare/4.18.0-es...4.18.1-es">https://github.com/lodash/lodash/compare/4.18.0-es...4.18.1-es</a></li>
<li><code>lodash-amd</code>: <a
href="https://github.com/lodash/lodash/compare/4.18.0-amd...4.18.1-amd">https://github.com/lodash/lodash/compare/4.18.0-amd...4.18.1-amd</a></li>
<li><code>lodash.template</code><a
href="https://github.com/lodash/lodash/compare/4.18.0-npm-packages...4.18.1-npm-packages">https://github.com/lodash/lodash/compare/4.18.0-npm-packages...4.18.1-npm-packages</a></li>
</ul>
<h2>4.18.0</h2>
<h2>v4.18.0</h2>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/lodash/lodash/compare/4.17.23...4.18.0">https://github.com/lodash/lodash/compare/4.17.23...4.18.0</a></p>
<h3>Security</h3>
<p><strong><code>_.unset</code> / <code>_.omit</code></strong>: Fixed
prototype pollution via <code>constructor</code>/<code>prototype</code>
path traversal (<a
href="https://github.com/lodash/lodash/security/advisories/GHSA-f23m-r3pf-42rh">GHSA-f23m-r3pf-42rh</a>,
<a
href="https://github.com/lodash/lodash/commit/fe8d32eda854377349a4f922ab7655c8e5df9a0b">fe8d32e</a>).
Previously, array-wrapped path segments and primitive roots could bypass
the existing guards, allowing deletion of properties from built-in
prototypes. Now <code>constructor</code> and <code>prototype</code> are
blocked unconditionally as non-terminal path keys, matching
<code>baseSet</code>. Calls that previously returned <code>true</code>
and deleted the property now return <code>false</code> and leave the
target untouched.</p>
<p><strong><code>_.template</code></strong>: Fixed code injection via
<code>imports</code> keys (<a
href="https://github.com/lodash/lodash/security/advisories/GHSA-r5fr-rjxr-66jc">GHSA-r5fr-rjxr-66jc</a>,
CVE-2026-4800, <a
href="https://github.com/lodash/lodash/commit/879aaa93132d78c2f8d20c60279da9f8b21576d6">879aaa9</a>).
Fixes an incomplete patch for CVE-2021-23337. The <code>variable</code>
option was validated against <code>reForbiddenIdentifierChars</code> but
<code>importsKeys</code> was left unguarded, allowing code injection via
the same <code>Function()</code> constructor sink. <code>imports</code>
keys containing forbidden identifier characters now throw
<code>&quot;Invalid imports option passed into
_.template&quot;</code>.</p>
<h3>Docs</h3>
<ul>
<li>Add security notice for <code>_.template</code> in threat model and
API docs (<a
href="https://redirect.github.com/lodash/lodash/pull/6099">#6099</a>)</li>
<li>Document <code>lower &gt; upper</code> behavior in
<code>_.random</code> (<a
href="https://redirect.github.com/lodash/lodash/pull/6115">#6115</a>)</li>
<li>Fix quotes in <code>_.compact</code> jsdoc (<a
href="https://redirect.github.com/lodash/lodash/pull/6090">#6090</a>)</li>
</ul>
<h3><code>lodash.*</code> modular packages</h3>
<p><a
href="https://redirect.github.com/lodash/lodash/pull/6157">Diff</a></p>
<p>We have also regenerated and published a select number of the
<code>lodash.*</code> modular packages.</p>
<p>These modular packages had fallen out of sync significantly from the
minor/patch updates to lodash. Specifically, we have brought the
following packages up to parity w/ the latest lodash release because
they have had CVEs on them in the past:</p>
<ul>
<li><a
href="https://www.npmjs.com/package/lodash.orderby">lodash.orderby</a></li>
<li><a
href="https://www.npmjs.com/package/lodash.tonumber">lodash.tonumber</a></li>
<li><a
href="https://www.npmjs.com/package/lodash.trim">lodash.trim</a></li>
<li><a
href="https://www.npmjs.com/package/lodash.trimend">lodash.trimend</a></li>
<li><a
href="https://www.npmjs.com/package/lodash.sortedindexby">lodash.sortedindexby</a></li>
<li><a
href="https://www.npmjs.com/package/lodash.zipobjectdeep">lodash.zipobjectdeep</a></li>
<li><a
href="https://www.npmjs.com/package/lodash.unset">lodash.unset</a></li>
<li><a
href="https://www.npmjs.com/package/lodash.omit">lodash.omit</a></li>
<li><a
href="https://www.npmjs.com/package/lodash.template">lodash.template</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/lodash/lodash/commit/cb0b9b9212521c08e3eafe7c8cb0af1b42b6649e"><code>cb0b9b9</code></a>
release(patch): bump main to 4.18.1 (<a
href="https://redirect.github.com/lodash/lodash/issues/6177">#6177</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/75535f57883b7225adb96de1cfc1cd4169cfcb51"><code>75535f5</code></a>
chore: prune stale advisory refs (<a
href="https://redirect.github.com/lodash/lodash/issues/6170">#6170</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/62e91bc6a39c98d85b9ada8c44d40593deaf82a4"><code>62e91bc</code></a>
docs: remove n_ Node.js &lt; 6 REPL note from README (<a
href="https://redirect.github.com/lodash/lodash/issues/6165">#6165</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/59be2de61f8aa9461c7856533b51d31b7d8babc4"><code>59be2de</code></a>
release(minor): bump to 4.18.0 (<a
href="https://redirect.github.com/lodash/lodash/issues/6161">#6161</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/af634573030f979194871da7c68f79420992f53d"><code>af63457</code></a>
fix: broken tests for _.template 879aaa9</li>
<li><a
href="https://github.com/lodash/lodash/commit/1073a7693e1727e0cf3641e5f71f75ddcf8de7c0"><code>1073a76</code></a>
fix: linting issues</li>
<li><a
href="https://github.com/lodash/lodash/commit/879aaa93132d78c2f8d20c60279da9f8b21576d6"><code>879aaa9</code></a>
fix: validate imports keys in _.template</li>
<li><a
href="https://github.com/lodash/lodash/commit/fe8d32eda854377349a4f922ab7655c8e5df9a0b"><code>fe8d32e</code></a>
fix: block prototype pollution in baseUnset via constructor/prototype
traversal</li>
<li><a
href="https://github.com/lodash/lodash/commit/18ba0a32f42fd02117f096b032f89c984173462d"><code>18ba0a3</code></a>
refactor(fromPairs): use baseAssignValue for consistent assignment (<a
href="https://redirect.github.com/lodash/lodash/issues/6153">#6153</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/b8190803d48d60b8c80ad45d39125f32fa618cb2"><code>b819080</code></a>
ci: add dist sync validation workflow (<a
href="https://redirect.github.com/lodash/lodash/issues/6137">#6137</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/lodash/lodash/compare/4.17.23...4.18.1">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Summary
- Route OSC 8 hyperlinks and detected web URLs through the same terminal
link handlers.
- Preserve Cmd-click on macOS / Ctrl-click elsewhere, hover tooltip and
context-menu state, and the `web:openlinksinternally` behavior in
`openLink`.
- Leave xterm’s default HTTP(S)-only OSC link filtering in place.

Closes wavetermdev#3165.

## Verification
- `npm exec -- vitest run frontend/app/view/term/term-links.test.ts
frontend/app/view/term/osc-handlers.test.ts --reporter=dot` (6 passed)
- Prettier and ESLint on changed files (passed)
- `task check:ts` remains blocked by pre-existing type errors in
frontend preview mocks, unrelated to these changes.
- No runtime click test was performed.
@Atreus-X
Atreus-X merged commit 77fbeb7 into main Sep 28, 2026
1 of 3 checks passed
@Atreus-X Atreus-X mentioned this pull request Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants