chore(deps): update karakeep app runtime patch/minor updates #182
No reviewers
Labels
No labels
bug
ci
dependencies
devops
docker
duplicate
enhancement
helm
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
isityael/karakeep!182
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/karakeep-app-runtime-patch-minor"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
3.1068.0→3.1073.02.0.4→2.0.51.1.12→1.2.01.1.13→1.1.142.1.17→2.1.182.1.9→2.1.101.1.9→1.1.101.4.0→1.4.11.2.11→1.2.121.1.9→1.1.101.4.0→1.4.11.3.0→1.3.11.1.14→1.1.151.2.16→1.2.171.1.11→1.1.121.2.9→1.2.101.2.5→1.2.611.17.0→11.18.011.17.0→11.18.011.17.0→11.18.012.10.1→12.11.13.4.10→3.4.114.12.25→4.12.261.18.0→1.21.05.50.6→5.51.15.50.6→5.51.15.50.6→5.51.15.50.6→5.51.15.50.6→5.51.15.50.6→5.51.15.50.6→5.51.15.50.6→5.51.15.50.6→5.51.15.50.6→5.51.15.50.6→5.51.15.50.6→5.51.15.50.6→5.51.15.50.6→5.51.14.2.1→4.5.09.0.0→9.0.16.42.0→6.44.01.60.0→1.61.04.6.0→4.7.07.79.0→7.80.00.35.1→0.35.222.2.1→22.2.20.22.2→0.22.38.4.1→8.5.04.1.8→4.1.9Release Notes
aws/aws-sdk-js-v3 (@aws-sdk/client-s3)
v3.1073.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1072.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1071.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1070.0Compare Source
Features
v3.1069.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
honojs/node-server (@hono/node-server)
v2.0.5Compare Source
Security Fix
Fixed a security issue in Serve Static Middleware where prefix-mounted middleware could be bypassed on Windows. This only affects applications running on Windows that use Serve Static Middleware. Affected users are encouraged to upgrade to this version.
See GHSA-frvp-7c67-39w9 for details.
radix-ui/primitives (@radix-ui/react-avatar)
v1.2.0Avatar.Imagecomponents perAvatar.Rootwas never supported and results in buggy, unpredictable behavior. We now warn about this in development.loading, meaning thatonLoadingStatusChangeis never called once loaded. A zero-sized image now triggers anerrorstatus on load.Other updates
@radix-ui/react-primitive@2.1.6radix-ui/primitives (@radix-ui/react-collapsible)
v1.1.14@radix-ui/react-primitive@2.1.6radix-ui/primitives (@radix-ui/react-dropdown-menu)
v2.1.18@radix-ui/react-menu@2.1.18,@radix-ui/react-primitive@2.1.6radix-ui/primitives (@radix-ui/react-label)
v2.1.10@radix-ui/react-primitive@2.1.6radix-ui/primitives (@radix-ui/react-progress)
v1.1.10@radix-ui/react-primitive@2.1.6radix-ui/primitives (@radix-ui/react-radio-group)
v1.4.1@radix-ui/react-primitive@2.1.6,@radix-ui/react-roving-focus@1.1.13radix-ui/primitives (@radix-ui/react-scroll-area)
v1.2.12Duplicate index signatureerrors that surfaced when consuming multiple packages together.@radix-ui/react-primitive@2.1.6radix-ui/primitives (@radix-ui/react-separator)
v1.1.10@radix-ui/react-primitive@2.1.6radix-ui/primitives (@radix-ui/react-slider)
v1.4.1Duplicate index signatureerrors that surfaced when consuming multiple packages together.@radix-ui/react-primitive@2.1.6,@radix-ui/react-collection@1.1.10radix-ui/primitives (@radix-ui/react-switch)
v1.3.1@radix-ui/react-primitive@2.1.6radix-ui/primitives (@radix-ui/react-tabs)
v1.1.15@radix-ui/react-primitive@2.1.6,@radix-ui/react-roving-focus@1.1.13radix-ui/primitives (@radix-ui/react-toast)
v1.2.17@radix-ui/react-dismissable-layer@1.1.13,@radix-ui/react-primitive@2.1.6,@radix-ui/react-collection@1.1.10,@radix-ui/react-portal@1.1.12,@radix-ui/react-visually-hidden@1.2.6radix-ui/primitives (@radix-ui/react-toggle)
v1.1.12@radix-ui/react-primitive@2.1.6radix-ui/primitives (@radix-ui/react-tooltip)
v1.2.10@radix-ui/react-slot@1.3.0,@radix-ui/react-popper@1.3.1,@radix-ui/react-dismissable-layer@1.1.13,@radix-ui/react-primitive@2.1.6,@radix-ui/react-portal@1.1.12,@radix-ui/react-visually-hidden@1.2.6radix-ui/primitives (@radix-ui/react-visually-hidden)
v1.2.6@radix-ui/react-primitive@2.1.6trpc/trpc (@trpc/client)
v11.18.0Compare Source
What's Changed
New Contributors
Full Changelog: https://github.com/trpc/trpc/compare/v11.17.0...v11.18.0
WiseLibs/better-sqlite3 (better-sqlite3)
v12.11.1Compare Source
What's Changed
Full Changelog: https://github.com/WiseLibs/better-sqlite3/compare/v12.11.0...v12.11.1
cure53/DOMPurify (dompurify)
v3.4.11: DOMPurify 3.4.11Compare Source
setConfig, thanks @trace37labsnpm auditosv-scannersuppression list as no vulnerable dependencies are left for nowhonojs/hono (hono)
v4.12.26Compare Source
What's Changed
Full Changelog: https://github.com/honojs/hono/compare/v4.12.25...v4.12.26
lucide-icons/lucide (lucide-react)
v1.21.0: Version 1.21.0Compare Source
What's Changed
versionscripts in package scripts by @ericfennis in #4479broken-boneicon by @Patolord in #4131New Contributors
Full Changelog: https://github.com/lucide-icons/lucide/compare/1.20.0...1.21.0
v1.20.0: Version 1.20.0Compare Source
What's Changed
square-arrow-*icons by @jguddas in #3926search-icons by @jamiemlaw in #4099save-checkicon by @Konixy in #3120tag-plusandtag-xicons by @adam-kov in #3980banknote-checkicon by @mfjramirezf in #3956clock-arrow-inicon by @jguddas in #2403summaryicon by @jpjacobpadilla in #3114user-round-arrow-inicon by @jguddas in #2283clock-arrow-outicon by @jguddas in #2404pencil-sparklesicon by @jennieboops in #4445New Contributors
Full Changelog: https://github.com/lucide-icons/lucide/compare/1.19.0...1.20.0
v1.19.0: Version 1.19.0Compare Source
What's Changed
star-*icons by @RajnishKMehta in #3918save-penicon by @vaporvee in #4179wrench-officon by @nilsjonsson in #4434adicon by @jamiemlaw in #4323eye-dashedicon by @karsa-mistmere in #4415save-plusicon by @jwlinqx in #4448list-sort-descendingicon by @ericfennis in #4457wallet-cardsicon by @jguddas in #3888podiumicon by @jguddas in #2124New Contributors
Full Changelog: https://github.com/lucide-icons/lucide/compare/1.18.0...1.19.0
microlinkhq/metascraper (metascraper)
v5.51.1Compare Source
Note: Version bump only for package metascraper
microlinkhq/metascraper (metascraper-amazon)
v5.51.1Compare Source
Note: Version bump only for package metascraper-amazon
microlinkhq/metascraper (metascraper-date)
v5.51.1Compare Source
Note: Version bump only for package metascraper-date
microlinkhq/metascraper (metascraper-description)
v5.51.1Compare Source
Note: Version bump only for package metascraper-description
microlinkhq/metascraper (metascraper-image)
v5.51.1Compare Source
Note: Version bump only for package metascraper-image
microlinkhq/metascraper (metascraper-logo)
v5.51.1Compare Source
Note: Version bump only for package metascraper-logo
microlinkhq/metascraper (metascraper-logo-favicon)
v5.51.1Compare Source
Note: Version bump only for package metascraper-logo-favicon
microlinkhq/metascraper (metascraper-publisher)
v5.51.1Compare Source
Note: Version bump only for package metascraper-publisher
microlinkhq/metascraper (metascraper-readability)
v5.51.1Compare Source
Note: Version bump only for package metascraper-readability
microlinkhq/metascraper (metascraper-x)
v5.51.1Compare Source
Note: Version bump only for package metascraper-x
microlinkhq/metascraper (metascraper-youtube)
v5.51.1Compare Source
Note: Version bump only for package metascraper-youtube
node-cron/node-cron (node-cron)
v4.5.0Compare Source
Added
lastRun()introspection getter onScheduledTask: returns{ date, result }aftera successful execution,
{ date, error }after a failed one, ornullbefore the firstrun. ([#557])
<weekday>#<nth>(nth weekday of the month, e.g.1#1for the first Monday) and<weekday>L(last weekday of the month, e.g.5Lfor the last Friday). ([#560])
Performance
Intl.DateTimeFormatinstances per timezone instead of rebuilding on everycall. ([#561])
TimeMatcherinstead of re-parsing inMatcherWalker. ([#562])next-run search). ([#563])
crypto.randomByteswithcrypto.randomUUIDfor internal IDgeneration. ([#564])
setTimeoutjitter wrapper whenmaxRandomDelayis zero. ([#565])time). ([#566])
Fixed
should schedule a tasktest: poll for the first execution instead ofasserting an exact count after a fixed sleep.
Changed
interpretetointerpretandappendSeccondExpressiontoappendSecondExpression. ([#567])(overlap prevention, distributed coordination, background tasks). ([#568])
v4.4.1Compare Source
Changed
distributedTtloption todistributedLease(same meaning:the safety lease, in ms, for lease-based coordinators). The old name was the
only abbreviation in the options API; the new one groups with
distributed.distributedTtlwas introduced in 4.4.0 and is removed without an alias.v4.4.0Compare Source
Added
ScheduledTask:getNextRuns(n)(preview the next Nrun times),
match(date),msToNext(),isBusy(),runsLeft()andgetPattern(). ([#547])cron.parse(expression)andcron.validateDetailed(expression):decompose an expression into its fields, or get every field-level problem
(without throwing) for tooling and richer error messages. ([#548])
distributed: trueruns a task on asingle instance per fire across a fleet. Ships a built-in
NODE_CRON_RUNenv-var default (one designated runner, no dependencies) and a pluggable
RunCoordinator(viasetRunCoordinator, or the per-taskrunCoordinatoroption) for high-availability, per-fire coordination (e.g. a Redis lock).
Adds the
distributedTtloption and anexecution:skippedevent carrying areason('not-elected'|'coordinator-error'). Works for inline andbackground tasks. ([#549])
Fixed
getNextMatchno longer scans every time of day on a day that matches theday-of-month but not the weekday. A dense expression constrained by both
(e.g.
* * * 15 * 1) could take minutes to resolve; it is now instant.Changed
milisecond→millisecondspelling and theconvertion/→conversion/directory name.v4.3.0Compare Source
Added
L(last day of month) in the day-of-month field — e.g.0 0 12 L * *,leap-year aware and combinable with explicit days (
15,L). ([#147])missedExecutionToleranceoption (ms, default1000): a heartbeat thatwakes a little late still runs its slot instead of being reported as missed.
Always capped to the gap to the next slot, so it can never run a slot twice.
([#485])
startTimeoutoption for background tasks (ms, default5000). ([#535])Fixed
getNextMatch: no more ~1-year overshoot when a daily timefalls in the spring-forward gap. ([#518])
unsupported TypeScript syntax, missing file) instead of an opaque timeout, and
a failed or timed-out start no longer leaves an orphaned daemon running.
([#484])
skipped runs on daily/weekly schedules. ([#485])
Changed
>= 20.11); tested on Node20, 22 and 24.
nodemailer/nodemailer (nodemailer)
v9.0.1Compare Source
Bug Fixes
openai/openai-node (openai)
v6.44.0Compare Source
Full Changelog: v6.43.0...v6.44.0
Features
v6.43.0Compare Source
Full Changelog: v6.43.0...v6.44.0
Features
microsoft/playwright (playwright)
v1.61.0Compare Source
🔑 WebAuthn passkeys
New Credentials virtual authenticator, available via browserContext.credentials, lets tests register passkeys and answer
navigator.credentials.create()/navigator.credentials.get()ceremonies in the page — no real hardware key required, works in all browsers:You can also let the app register a passkey once in a setup test, read it back with credentials.get(), and seed it into later tests — see Credentials for details.
🗃️ Web Storage
New WebStorage API, available via page.localStorage and page.sessionStorage, reads and writes the page's storage for the current origin:
New APIs
Network
Browser and Screencast
artifactsDirin browserType.connectOverCDP() controls where artifacts such as traces and downloads are stored when attached to an existing browser.cursorin screencast.showActions() controls the cursor decoration rendered for pointer actions.onFramecallback in screencast.start() now receives atimestampof when the frame was presented by the browser.Test runner
trace: new'on-all-retries','retain-on-first-failure'and'retain-on-failure-and-retries'values. See the video modes table for which runs are recorded and kept in each mode.expect.soft.poll(...).process.argvfrom the runner process, handy for reading custom arguments passed after the--separator.AggregateErroras a separate entry.-Gcommand line shorthand for--grep-invert.🛠️ Other improvements
Browser Versions
This version was also tested against the following stable channels:
react-grid-layout/react-draggable (react-draggable)
v4.7.0Compare Source
nonceprop to support a strict Content Security Policy. It's applied to the dynamically-injected user-select<style>element so astyle-srcpolicy without'unsafe-inline'no longer blocks it. When omitted, webpack's__webpack_nonce__global is used if available.enableUserSelectHack={false}remains a no-prop opt-out. (#808, closes #791)tsccompilation in the build/CI pipeline.react-hook-form/react-hook-form (react-hook-form)
v7.80.0Compare Source
Added
disabledprop support for individual fields withinuseFieldArrayFixed
deepEqualincorrectly treating empty array[]and empty plain object{}as equalPerformance
onChange,setValid, dirty checking,setValue, andsetValuesperformancelovell/sharp (sharp)
v0.35.2Compare Source
TypeScript: Add
mediaTypeto metadata response.#4492
Improve WebAssembly fallback detection.
#4513
Improve code bundler support with stub binaries.
#4543
Verify GIF
effortoption is an integer.#4544
@metsw24-max
Verify
recombmatrix entries are numbers.#4545
@metsw24-max
TypeScript: Replace namespace with named exports for ESM.
#4546
Bound dilate and erode width to avoid mask-size overflow.
#4548
@metsw24-max
Verify
convolvekernel values are numbers.#4549
@metsw24-max
stripe/stripe-node (stripe)
v22.2.2Compare Source
Stripe.ErrorType.StripeErrorincorrectly being usable as a runtime class (reported in #2661)rolldown/tsdown (tsdown)
v0.22.3Compare Source
🚨 Breaking Changes
🐞 Bug Fixes
🏎 Performance
View changes on GitHub
nodejs/undici (undici)
v8.5.0Compare Source
⚠️ Security Release
This release line addresses 8 security advisories. Most are fixed in
v8.5.0; the SOCKS5 pool-reuse issue was fixed earlier in v8.2.0.
Summary
32dbf0b3b4c287b342d49559a516f870cb105d7c5655ea435655ea436ea54ef8High severity
WebSocket DoS via fragment count bypass — CVE-2026-12151
GHSA-vxpw-j846-p89q · CWE-400, CWE-770
Fix:
32dbf0b3websocket: limit the number of fragments in a message (alsoc5ed7875handle empty fragments and stream limits)A malicious WebSocket server can stream a large number of small or empty
continuation frames. Undici enforced a limit on cumulative payload size but did
not limit the number of fragments per message, leading to unbounded memory
growth and denial of service.
new WebSocket(...)orWebSocketStreamagainst untrusted endpoints.
WebSocket DoS via cumulative fragment bypass — CVE-2026-9675
GHSA-38rv-x7px-6hhq · CWE-400, CWE-770
Fix:
b4c287b3fix(websocket): enforce max payload size across fragmentsUndici validated the size of individual frames but did not track cumulative size
across a fragmented message. An attacker could send many small fragments that
each pass per-frame validation but collectively exceed the configured limit,
causing memory exhaustion. This is a regression introduced in 8.1.0 (the
6.x and 7.x lines are not affected).
TLS certificate validation bypass in SOCKS5 ProxyAgent — CVE-2026-9697
GHSA-vmh5-mc38-953g · CWE-295
Fix:
42d49559fix: honor requestTls when proxy is SOCKS5The
ProxyAgentsilently discarded therequestTlsoption when configured witha SOCKS5 proxy. TLS connections through the SOCKS5 tunnel ignored user-configured
parameters such as
ca,cert,key,rejectUnauthorized, andservername,falling back to the default Mozilla CA bundle. Applications relying on
certificate pinning to an internal CA were exposed to man-in-the-middle attacks.
ProxyAgent/Socks5ProxyAgentover SOCKS5 that rely onrequestTls.ProxyAgent, whererequestTlsfunctions correctly.Cross-origin request routing via SOCKS5 proxy pool reuse — CVE-2026-6734
GHSA-hm92-r4w5-c3mj · CWE-346 · Fixed in 8.2.0
Fix:
a516f870fix(socks5-proxy-agent): use per-origin pools to prevent cross-origin routing (#5041)Socks5ProxyAgentreused a single connection pool across different originswithout verifying the pool's origin matched the requested origin. This could
route credentials and request data to unintended destinations, cause responses
from the wrong origin to be trusted, and enable HTTPS→HTTP downgrade.
Socks5ProxyAgentacross multiple origins(introduced via #4385).
Moderate severity
Cross-user information disclosure via shared cache whitespace bypass — CVE-2026-9678
GHSA-pr7r-676h-xcf6 · CWE-524
Fix:
cb105d7cfix(cache): trim qualified field namesThe cache interceptor mishandled responses with whitespace-padded
Cache-Controldirectives such asprivate=" authorization". In shared-cachemode this could cause authenticated data to be cached and served to other users.
Authorizationupstream and receive non-canonical qualified directives.caching authenticated responses, or add
Vary: Authorizationupstream.HTTP header injection via Set-Cookie percent-decoding — CVE-2026-9679
GHSA-p88m-4jfj-68fv · CWE-93
Fix:
5655ea43fix(cookies): preserve values and parse SameSite strictlyparseSetCookieapplied percent-decoding to cookie values, turning encodedsequences like
%0D%0Aand%00into literal bytes, contrary to RFC 6265 §5.4and browser behavior. Applications forwarding parsed Set-Cookie values into
response headers were exposed to header injection, enabling session fixation,
open redirects, and cache poisoning. Introduced in 7.0.0 via
#3789.
NUL,
;, and=.Low severity
Set-Cookie SameSite attribute downgrade — CVE-2026-11525
GHSA-g8m3-5g58-fq7m · CWE-183
Fix:
5655ea43fix(cookies): preserve values and parse SameSite strictlyThe cookie parser accepted
SameSitevalues containingStrict,Lax, orNoneas substrings rather than requiring exact matches per RFC 6265. Valueslike
SameSite=NoneOfYourBusinessparsed asNone, andSameSite=StrictLaxparsed as
Lax, silently weakening cookie security policies for apps thatforward parsed attributes.
HTTP response queue poisoning via keep-alive socket reuse — CVE-2026-6733
GHSA-35p6-xmwp-9g52 · CWE-367 (TOCTOU race condition)
Fix:
6ea54ef8fix: guard idle socket validation to skip fresh sockets, hardened byc9fbe9d2keep idle validation on native timers (#5397) andac5394b8keep idle validation on global timers (#5407)An attacker controlling an upstream HTTP/1.1 server could inject unsolicited
responses onto idle keep-alive sockets. On socket reuse, the injected response
was associated with a new request, delivering responses to the wrong requests.
keep-alive reuse.
keepAliveTimeout: 0on theClient or Pool.
Also in v8.5.0 (non-security)
v8.5.0 shipped the security fixes above alongside the following changes. These
are not security fixes — they are listed for completeness of the release. (The
two queue-poisoning hardening PRs, #5397
and #5407, are covered under
CVE-2026-6733 above and are not repeated here.)
#5408don't rewindkPendingIdxpast in-flight requests ·#5391allow h2 POST request multiplexing ·#5406reap idle HTTP/2 sessions ·#5410preserve h2 queue on out-of-order completion#5416addbodyMixin.textStream()·#5418align EventSource with spec#5413document request header validation ·#5383absorb h2 stream timeout resets (test) ·#5420remove stale repro + lint ·#5426extend Windows CI timeout ·#5427detect available python in WPT runnerFull changelog:
v8.4.1...v8.5.0.Credits
Per-advisory credits (as recorded in each GHSA):
vitest-dev/vitest (vitest)
v4.1.9Compare Source
🐞 Bug Fixes
importOriginalwith optimizer and query import [backport to v4] - by Hiroshi Ogawa, David Harris, Codexand Vladimir in #10546 (a5180)View changes on GitHub
Configuration
📅 Schedule: (in timezone Europe/Berlin)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.
ed7a8b7026b1a4f2d658b1a4f2d6580eb020290f0eb020290f982cea39c3982cea39c30305fe92a30305fe92a3a167ae163ca167ae163ca2dcf85b6fa2dcf85b6ff7a79509cdf7a79509cd7c6fb13e527c6fb13e527bb58376cc7bb58376cca99db02dd8a99db02dd84cbf71d8174cbf71d817682b0fb3bc682b0fb3bc9fdfb7e9759fdfb7e9753863df85093863df85099c4b23d8479c4b23d8477696886b6c7696886b6c791fe16883791fe16883b914551222b914551222714be0d7b5714be0d7b5030f3cc574030f3cc5744b75f88d3b4b75f88d3b63252e68e663252e68e65586c57f605586c57f60f05ec189c4f05ec189c4a24d44849fa24d44849f9913799300991379930015c21f202915c21f20292bc2a871612bc2a87161ccc5afdcf5