chore(devdeps): update dependency verdaccio to v6.10.2 - #829
chore(devdeps): update dependency verdaccio to v6.10.2#829renovate[bot] wants to merge 1 commit into
Conversation
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
View your CI Pipeline Execution ↗ for commit 81cede3
💡 Verify your cache is correct by running tasks in a sandbox. Read docs ↗ ☁️ Nx Cloud last updated this comment at |
@forgerock/davinci-client
@forgerock/device-client
@forgerock/journey-client
@forgerock/oidc-client
@forgerock/protect
@forgerock/sdk-types
@forgerock/sdk-utilities
@forgerock/iframe-manager
@forgerock/sdk-logger
@forgerock/sdk-oidc
@forgerock/sdk-request-middleware
@forgerock/storage
commit: |
|
Deployed dae930e to https://ForgeRock.github.io/ping-javascript-sdk/pr-829/dae930e4234cfa26cd8b155c11b303cb64f2bd0e branch gh-pages in ForgeRock/ping-javascript-sdk |
Codecov Report✅ All modified and coverable lines are covered by tests. ❌ Your project status has failed because the head coverage (24.35%) is below the target coverage (40.00%). You can increase the head coverage or adjust the target coverage. Additional details and impacted files@@ Coverage Diff @@
## main #829 +/- ##
==========================================
+ Coverage 18.07% 24.35% +6.28%
==========================================
Files 155 164 +9
Lines 24398 25823 +1425
Branches 1203 1703 +500
==========================================
+ Hits 4410 6290 +1880
+ Misses 19988 19533 -455 🚀 New features to boost your workflow:
|
📦 Bundle Size Analysis📦 Bundle Size Analysis🆕 New Packages🆕 @forgerock/device-client - 0.0 KB (new) 📊 Minor Changes📈 @forgerock/sdk-types - 9.1 KB (+0.0 KB) ➖ No Changes➖ @forgerock/recognize - 4284.4 KB 15 packages analyzed • Baseline from latest Legend🆕 New package ℹ️ How bundle sizes are calculated
🔄 Updated automatically on each push to this PR |
Renovate Ignore NotificationBecause you closed this PR without merging, Renovate will ignore this update ( If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR. |
This PR contains the following updates:
6.5.2→6.10.2Release Notes
verdaccio/verdaccio (verdaccio)
v6.10.2Compare Source
Patch Changes
6d972d1: fix: resolve fast-uri and brace-expansion security advisoriesfast-uri 3.1.6. Bumps the
ajv/fast-uriresolution from 3.1.5 to 3.1.6, whichfixes four high-severity advisories in the URI parser used by
ajvfor schemaformat validation: host confusion via skipped IDN canonicalization
(GHSA-5jgf-p345-68v8),
SSRF via malformed IPv6 normalization
(GHSA-f65p-4m7j-42xc),
SSRF via repeated hostname percent-decoding
(GHSA-fph4-wmhf-6fwf),
and host confusion via percent-encoded scheme normalization
(GHSA-jqff-g426-hqxp).
brace-expansion DoS cleanup. Updates the remaining vulnerable
brace-expansiontrees (1.1.11 → 1.1.18, 2.0.1 → 2.1.4) forGHSA-mh99-v99m-4gvg and
drops the temporary audit ignores that covered them while the patched
releases were still quarantined by the minimal-age gate.
6d972d1: chore: update e2e libraryca00ee0: fix: stop re-compressing tarballs for gzip-accepting clientsmime-db marks
application/octet-streamas compressible, so the compressionmiddleware re-gzipped every (already gzipped)
.tgzdownload for clientsthat accept gzip — npm and undici do by default — wasting CPU on every
download and stripping the
Content-Lengthheader. Tarball responses arenow excluded from compression; JSON metadata responses stay compressed.
Measured on a 30 MB tarball: ~18x less server CPU and ~20x faster downloads,
with slightly fewer bytes on the wire (gzip over gzip nets negative).
d4b8199: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/ui-theme:9.0.0-next-9.28→9.0.0-next-9.30d94ebff: fix: validate the scope segment on the web package endpointsThe readme and sidebar web endpoints now validate the
:scoperoute segmentand return 404 for malformed requests.
v6.10.1Compare Source
Patch Changes
90d5c20: Import shared helpers from@verdaccio/coreand drop the deprecated@verdaccio/utilsdependencyAll internal usages of
@verdaccio/utilsnow resolve the same helpers from@verdaccio/core(validation, auth, crypto, package and author utilities), andthe
@verdaccio/utilsdependency has been removed.7805d50: Limit web UI search responses to 20 packages.c84070b: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/ui-theme:9.0.0-next-9.27→9.0.0-next-9.28v6.10.0Compare Source
Minor Changes
51c2733: Expose the optional legacy authentication cache for Verdaccio 6.x throughserver.legacyAuthCache.This feature is intended for performance-sensitive installations that still use legacy bearer tokens. When enabled, Verdaccio caches successful legacy token authentication results for a short period of time, so repeated requests using the same token do not need to run password verification through the authentication plugin every time. Concurrent requests for the same legacy token can also share the same in-flight authentication result.
The cache is disabled by default, so existing installations keep their current authentication behavior unless they explicitly opt in. Basic authentication is not cached. If the cache is enabled, changed or revoked credentials may remain valid until the cached entry expires.
Enable it in
config.yaml:Options:
enabled: enables the legacy token authentication cache. Default:false.ttlMs: time in milliseconds before a cached validation expires. Default:15000.maxEntries: maximum number of cached legacy tokens. Default:1000.See #6147 and the original 8.x backport in #6143.
v6.9.3Compare Source
Patch Changes
3c8f391: Reject wildcard characters in package and tarball path validation.ebc08ba: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):This dependency refresh includes
@verdaccio/package-filter13.2.0withexcludeDeprecatedsupport from #6142 by @jotadeveloper, based on the original work by @davidus27. It also includes the@verdaccio/ui-themeupdate containing the homepage action hover fix from #6135 by @pranshuchittora.@verdaccio/auth:8.1.1→8.1.2@verdaccio/config:8.2.1→8.2.2@verdaccio/core:8.2.1→8.2.2@verdaccio/hooks:8.1.2→8.1.3@verdaccio/loaders:8.1.1→8.1.2@verdaccio/local-storage-legacy:11.4.1→11.4.2@verdaccio/logger:8.1.1→8.1.2@verdaccio/middleware:8.1.1→8.1.2@verdaccio/package-filter:13.1.1→13.2.0@verdaccio/signature:8.1.1→8.1.2@verdaccio/tarball:13.1.1→13.1.2@verdaccio/ui-theme:9.0.0-next-9.23→9.0.0-next-9.26@verdaccio/url:13.1.1→13.1.2@verdaccio/utils:8.2.1→8.2.2verdaccio-audit:13.1.1→13.1.2verdaccio-htpasswd:13.1.1→13.1.2v6.9.2Compare Source
Patch Changes
297dc43: fix: apply package access controls to thestarredByUserendpointThe
GET /-/_view/starredByUserview did not enforce the configured packageaccess policy when listing a user's starred packages. Results are now filtered
through
auth.allow_access, so the response only includes packages therequesting client is authorized to see.
05917d5: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/ui-theme:9.0.0-next-9.22→9.0.0-next-9.23v6.9.1Compare Source
Patch Changes
dfe3938: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/auth:8.1.0→8.1.1@verdaccio/config:8.2.0→8.2.1@verdaccio/core:8.2.0→8.2.1@verdaccio/hooks:8.1.1→8.1.2@verdaccio/loaders:8.1.0→8.1.1@verdaccio/local-storage-legacy:11.4.0→11.4.1@verdaccio/logger:8.1.0→8.1.1@verdaccio/middleware:8.1.0→8.1.1@verdaccio/package-filter:13.1.0→13.1.1@verdaccio/signature:8.1.0→8.1.1@verdaccio/tarball:13.1.0→13.1.1@verdaccio/ui-theme:9.0.0-next-9.21→9.0.0-next-9.22@verdaccio/url:13.1.0→13.1.1@verdaccio/utils:8.2.0→8.2.1verdaccio-audit:13.1.0→13.1.1verdaccio-htpasswd:13.1.0→13.1.1v6.9.0Compare Source
Minor Changes
b67a665: feat: require Node.js 22 as the minimum supported versionNode.js 22 or higher is now required (previously the CLI still accepted Node.js 18,
while
enginesalready demanded 20). The CLI refuses to start on older runtimes andenginesis set to>=22; Node.js 24 is the recommended version. CI, e2e, and smoketest matrices now cover Node.js 22, 24, and 26. Registry operators on Node.js 18 or 20
must upgrade the runtime before taking this release.
b67a665: feat: dual CJS + ESM build withexportsfield, migrate build from babel to vite 8Native ESM support. The package now ships both CommonJS (
build/**/*.js) and ESM(
build/**/*.mjs) outputs and declares anexportsfield, soimport { runServer } from 'verdaccio'resolves a real ES module instead of theCommonJS interop.
require('verdaccio')keeps working exactly as before. TheverdaccioCLI now runs on the ESM build, which means ESM-only dependencies can beloaded at runtime on every supported Node.js version.
Build toolchain. Babel has been replaced by vite 8 (rolldown) for transpilation;
type declarations are still emitted by TypeScript. This is not observable in the
registry behavior, but local workflows changed:
yarn startand thedebug/bootstrapscripts now use
tsxinstead ofbabel-node/@babel/register.Patch Changes
b67a665: fix(deps): update @verdaccio/hooks to 8.1.1Restores publish/unpublish webhook notifications when running on the ESM build: hooks
8.1.0 could not send them (the notify client failed silently on every call). The new
version replaces the frozen
got-cjsfork withgot15 loaded in a way that worksfrom both the ESM and CommonJS builds, and reports delivery failures based on the real
HTTP response status.
b67a665: fix(deps): update @verdaccio/* packages to the 2026-07-25 release batchUpdates all
@verdaccio/*andverdaccio-*dependencies (config 8.1.4, core 8.1.4,auth 8.0.6, middleware 8.0.7, htpasswd/audit 13.0.5, among others). Notably
@verdaccio/config8.1.4 moves tojs-yaml4.3.0, resolving the high-severityadvisory GHSA-52cp-r559-cp3m
(YAML merge-key chains forcing quadratic CPU consumption).
2969ec8: fix: migrate uplink/storage URL parsing to the WHATWG URL APIRemoves the
[DEP0169] DeprecationWarning: url.parse()printed at startup onNode.js 22+. The proxy and local-storage layers no longer use the legacy
url.parse()/
url.format()helpers; uplink URL validation, distfile filename extraction, and theremote-protocol tarball rewrite now go through the standardized
URLAPI. Behavior isunchanged for the absolute HTTP(S) URLs used in practice — the default HTTPS port
:443still normalizes to a match, and invalid uplink URLs are treated as not-valid instead of
being parsed leniently.
Because the WHATWG
URLconstructor throws on malformed input (unlike the lenient legacyurl.parse()), a misconfigured uplinkurlnow fails fast at startup with a clear,credential-redacted error, and a malformed
dist.tarballreturned by an upstream registryis skipped (with a warning) instead of aborting the package update. Uplink URL validation
also now compares the uplink's own port when deciding whether to ignore the default HTTPS
port, so an HTTPS uplink on a non-default port no longer matches a default-port tarball.
v6.8.0Compare Source
Minor Changes
962fba8: feat: add unpublish notification hooksPort of #5920 (ref #5328). The
notifywebhook now also fires when a package is unpublished entirely and when a single version (tarball) is removed, not only on publish. Notification templates can distinguish the event through the new{{ publishType }}(publish|unpublish) and{{ publishedPackage }}variables, and the{{ publisher }}object exposes onlyname,groupsandreal_groups, so the remote user auth token can never leak to the notification endpoint (via@verdaccio/hooks8.0.4).Patch Changes
f0684dc: fix: return 403 to client when uplink responds with 403 for tarball requestsPreviously, any non-200/404 response from an uplink (e.g. a security proxy blocking a package download) would result in a generic 500 error being returned to the client. This change propagates 403 responses from the uplink through to the client, including any error detail from the response body, so callers can distinguish authorization failures from other upstream errors.
3a84578: chore: refactor eslintb7a5db1: fix: rate limit and bound the npm search v1 endpointThe
/-/v1/searchendpoint now applies theuserRateLimitrate limiting middleware (matching the login, token and profile endpoints), clamps thesize(max 250, like the public npm registry) andfrom(max 10000) pagination parameters, and stops evaluating package access as soon as the requested page is filled instead of running an auth check over the entire result set. The clamped values are also what gets forwarded to uplink registries (the raw request URL is no longer passed through), so the bounds hold end-to-end. This prevents cheap anonymous requests from triggering unbounded full-catalog scans. As part of this, pagination is fixed: results were sliced withslice(from, size)instead ofslice(from, from + size), so pages beyond the first were wrong.Search results for local packages also emit npm-search-compatible maintainers (
{ username, email }) — npm 11 on Node 24 crashes rendering entries withoutusername(The "str" argument must be of type string. Received undefined) — and thepublisherfield is now populated from_npmUserwhen the publishing client provided it, falling back to the first maintainer, so the npm CLI shows the publishing user instead ofby ???.808d916: fix: pick the right uplink for tarballs and heal missing distfile recordsUplink selection. With several uplinks configured for a package, tarball downloads used the last uplink whose package pattern matched, even when the tarball url belongs to a different one, which could make downloads fail against registries that require authentication. The uplink is now selected by matching the tarball url: the
registryrecorded on the distfile wins, then the uplink whose url serves the file; when none matches, an autogenerated uplink with default settings is used. Single-uplink setups keep the previous behavior for tarballs hosted on another host (a CDN).Missing distfile records. Storages written by other verdaccio versions can carry cached versions without their
_distfilesrecords, which made those tarballs permanently return404 no such file available. The tarball location is now resolved from the version'sdist.tarballmetadata when the record is missing, and the record is restored when the tarball is cached.a2de1d5: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/ui-theme:9.0.0-next-9.20→9.0.0-next-9.21v6.7.4Compare Source
Patch Changes
0205c78: fix: run jwt middleware before middleware pluginsRegister the JWT middleware before middleware plugins are loaded so that
req.remote_user(anonymous by default) is available inside a plugin'sregister_middlewares. The API router keeps its own JWT middleware behind aguard so it is not executed twice.
Backport of #5697
Closes #5167
v6.7.3Compare Source
Patch Changes
f8fdfc2: fix: enforce generated npm token metadataGenerated npm tokens (
POST /-/npm/v1/tokens) stored theirreadonlyandcidr_whitelistrestrictions but never enforced them, and deleting a token didnot revoke it for the package APIs. A token marked read-only or pinned to a CIDR
range could still publish packages and change dist-tags, and a deleted token
remained usable.
Generated tokens now embed a server-issued key (in the JWT claim, or in the
encrypted legacy AES payload) and a new
enforceGeneratedTokenMetadatamiddleware looks that key up on each request, rejecting the token when it is
missing/revoked, used outside its CIDR whitelist, or used for a write while
read-only. Enforcement applies to both AES and JWT API-token modes.
Note: tokens issued before upgrading carry no key and are not retroactively
constrained — regenerate them to apply the restrictions.
be80623: fix: allow npm token create without readonly/cidr_whitelistnpm token createin npm >= 11 (and the npm 12 prereleases) rewrote therequest body: it no longer sends
readonlyand only sendscidr_whitelistwhen
--cidris passed. ThePOST /-/npm/v1/tokensendpoint required both,so modern npm clients failed with
422 the parameters are not valid.The endpoint now defaults
readonlytofalseandcidr_whitelistto[]when they are absent, while still rejecting values of the wrong type.
75c85d5: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/ui-theme:9.0.0-next-9.19→9.0.0-next-9.20d5e5332: chore: update dependenciesUpdates runtime dependencies
@verdaccio/ui-theme(9.0.0-next-9.19) andsemver(7.8.2), along with development dependencies: Babel7.29.7,@changesets/cli2.31.0, ESLint10.4.1, Vitest4.1.8, Cypress15.16.0,Prettier
3.8.3,@verdaccio/test-helper4.0.4,@verdaccio/eslint-config13.1.2, and assorted type definitions.v6.7.2Compare Source
Patch Changes
a89aca1: chore: fix unit testa28cf71: chore: add missing types #5889 by @mbtoolsv6.7.1Compare Source
Patch Changes
a75f9bb: chore: refactor docker publish pipelinev6.7.0Compare Source
Minor Changes
9f1bcc5: feat: update Node.js to 24Bumps the project's Node.js baseline to 24 across runtime and container, and adds a startup warning for users still on an older (but supported) Node.
.nvmrc22→24;Dockerfilebase imagenode:22.22.1-alpine→node:24.15.0-alpine(builder + runtime).RECOMMENDED_NODE_VERSION = '22'andisVersionRecommended()insrc/lib/cli/utils.ts; theinitcommand logs awarnat startup when Node is below the recommendation.MIN_NODE_VERSIONstays at'18'— no hard break.isVersionRecommendedand the init warning path.Compatibility: minimum supported Node remains 18 (warning only); recommended is 22+; Docker images ship Node 24.
v6.6.2Compare Source
6.6.2
Patch Changes
7f7bbde: chore: bump up package test (testing publish provenance)v6.6.0Compare Source
What's Changed
Full Changelog: verdaccio/verdaccio@v6.5.2...v6.6.0
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.