Commit Graph
601 Commits
Author SHA1 Message Date
splitsec2 755f28a6a4 feat(api): add a read-only API key and a /api/stats endpoint (#1419)
This is the read-only API key from #1410, where you said to go ahead.

I run Shelfmark behind Homepage and wanted more on the dashboard tile
than up or down, without putting an admin API key in the dashboard's
config. This adds a second key, `SHELFMARK_API_KEY_READONLY`, that can
read one new endpoint.

`GET /api/stats` returns counts only: books added over the last 7 and 30
days by format, the queue, requests by outcome, and download failures
over the last 7 days. No titles and no user names. The read-only key,
the admin key or an admin session can read it.

The read-only key gets a 403 on every other path and on any write,
including a POST to `/api/stats` itself, and it never gets a session or
a cookie. If a request carries both keys, the admin one wins, so a
proxy's own `Authorization` header can't downgrade a correct
`X-Api-Key`. Unset means off, like the existing key. The endpoint exists
either way, but without a key only an admin session can read it.

It also adds a `db_path` property on `UserDB`, so the stats module can
open the database read-only.

Tests cover the key scope, the 403s for the read-only key, both keys at
once, who can reach the endpoint, and the counters. The full suite
passes, and I broke each rule on purpose to check a test catches it. A
version of this has been running on my own install behind Homepage.

If you'd rather have the stats in a different shape or under a different
path, I'm happy to change it.
2026-10-02 22:45:48 -04:00
adman234andClaude Opus 5.5 32abaff21e feat(naming): {Narrator} placeholder and MyAnonamouse series fallback (#1407)
## Human-Written explanation:

Following up on previous PR to use MAM ID to get nararrator and series
to show up in search, this PR will allow the series and nararrator
fields to be added to the path when saving an audiobook.

I have tested my ghcr.io image on my instance and it seemed to work
properly.

All the text below is written by Claude.

# feat(naming): {Narrator} placeholder and MyAnonamouse series fallback

Follow-up to #1390 and #1399. Related to #605 and #934 (narrator
support).

## Problem

Several narrations of the same audiobook currently land in the same
folder, because nothing in the path template tells them apart. Keeping
more than one version means renaming folders by hand after every
download.

Since #1390, MyAnonamouse results carry the release's narrator and
series in `extra`, but the naming templates can't use them: there is no
`{Narrator}` placeholder, and `{Series}` / `{SeriesPosition}` only come
from the metadata provider.

## Changes

- **`{Narrator}` placeholder** (`core/naming.py`,
`download/postprocess/transfer.py`, `core/models.py`): `DownloadTask`
gains `narrator`, read from `narrator` or `extra.narrator` when a
release is queued, and kept in the restart-safe retry payload. It's
available in audiobook templates like any other placeholder, including
prefix/suffix blocks such as `{ - Narrator}`.
- **Audiobookshelf folder style**: Audiobookshelf reads the narrator
from folder names like `Title {Narrator}`. The template `{Title}
{{Narrator}}` already matches as `{` + `{Narrator}`; the parser now also
drops the closing brace when the narrator is empty, so the folder is
`Title` rather than `Title }`.
- **No stray spaces around `/`**: an empty placeholder at the start or
end of a folder name no longer leaves a space there (e.g. `Title
/Title`). This applies to all templates.
- **Series fallback** (`release_sources/prowlarr/mam.py`, `source.py`,
`download/orchestrator.py`): MAM enrichment also stores the first
series' name and number as `extra.series_name` /
`extra.series_position`, which queueing already falls back to when the
metadata provider has no series. The provider's series still wins. A
release-level series number is only used when it names the same series
as the provider, so a provider series is never paired with the number of
a different MAM series (an omnibus, for example).
- **Settings and preview** (`config/settings.py`,
`namingTemplatePreview.ts`): the audiobook template descriptions list
`{Narrator}` and explain `{{Narrator}}`. The settings page preview
mirrors the parser changes and offers `{Narrator}` under "Insert
variable" for audiobook templates only.
- **Docs**: regenerated `environment-variables.md`. This also picked up
the Library Check settings, which weren't in the generated docs yet;
happy to drop that part to keep the diff focused.

## Example

Audiobook Path Template `{Author}/{Title} {{Narrator}}/{Title}`:

| Narrator | Result |
|----------|--------|
| Samuel Roukin | `Christopher Ruocchio/Empire of Silence {Samuel
Roukin}/Empire of Silence.m4b` |
| none | `Christopher Ruocchio/Empire of Silence/Empire of Silence.m4b`
|

## Testing

- `tests/core/test_narrator_template_variable.py` (new, 16 tests):
`{{Narrator}}` with and without a value, the `{ {Narrator}}` prefix
form, prefix/suffix blocks, sanitizing, `build_library_path`, task
metadata, retry payload round trip, MAM series name/number parsing
(including a `1-3` range having no number), and queueing (narrator from
`extra`, series fallback, no cross-series number, blank narrator).
- `namingTemplatePreview.test.ts`: the same `{{Narrator}}` cases for the
preview.
- Updated `test_generate_env_docs.py` for the new template description.
- Full `pytest -m "not integration and not e2e"` compared with an
upstream `main` worktree on the same machine: no new failures (the
remaining ones are Windows-only on both).
- `ruff check`, `ruff format --check`, `basedpyright` (0 errors) and
`vulture` on touched files; frontend `tsc --noEmit`, `oxlint`, `oxfmt
--check`, `vitest` (218 passed).
- Checked the settings page locally: the audiobook preview renders `...
{Simon Vance}.mp3` and `{Narrator}` is listed for audiobook templates
only.

No behavior change for existing templates, apart from spaces next to `/`
being trimmed.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-02 22:45:10 -04:00
dependabot[bot] 23d7d482d7 build(deps): bump the python-deps group across 1 directory with 3 updates (#1412)
Bumps the python-deps group with 3 updates in the / directory:
[seleniumbase](https://github.com/seleniumbase/SeleniumBase),
[prek](https://github.com/j178/prek) and
[ruff](https://github.com/astral-sh/ruff).

Updates `seleniumbase` from 4.54.10 to 4.54.12
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/seleniumbase/SeleniumBase/releases">seleniumbase's
releases</a>.</em></p>
<blockquote>
<h2>4.54.12 - Dependency update</h2>
<h2>Dependency update</h2>
<ul>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/d37046c342cea47177c96c3f4cdc0914c1ede0fe">Refresh
Python dependencies</a>
--&gt; Upgrade <code>filelock</code>
--&gt; Upgrade <code>soupsieve</code>
--&gt; Drop <code>platformdirs</code> (Looks like nothing was using it
anymore)
--&gt; Update some optional dependencies</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>Dependency update by <a
href="https://github.com/mdmintz"><code>@​mdmintz</code></a> in <a
href="https://redirect.github.com/seleniumbase/SeleniumBase/pull/4512">seleniumbase/SeleniumBase#4512</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/seleniumbase/SeleniumBase/compare/v4.54.11...v4.54.12">https://github.com/seleniumbase/SeleniumBase/compare/v4.54.11...v4.54.12</a></p>
<h2>4.54.11 - MCP Server: Patch 19</h2>
<h2>MCP Server: Patch 19</h2>
<ul>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/67a1543bf4ecd04db5cb649fd92ad948e6b54bd9">Update
the MCP server</a></li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/d49755183d2ad25a73800c34ac23234833ef4d2e">Update
the MCP ReadMe</a></li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/45c3f068ad647cada64f20f3ce580bac35654c2a">Refresh
Python dependencies</a>
--&gt; <code>filelock</code>
--&gt; <code>platformdirs</code>
--&gt; <code>parse</code>
--&gt; <code>uv</code> (optional)</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>MCP Server: Patch 19 by <a
href="https://github.com/mdmintz"><code>@​mdmintz</code></a> in <a
href="https://redirect.github.com/seleniumbase/SeleniumBase/pull/4511">seleniumbase/SeleniumBase#4511</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/seleniumbase/SeleniumBase/compare/v4.54.10...v4.54.11">https://github.com/seleniumbase/SeleniumBase/compare/v4.54.10...v4.54.11</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/67767bb57498dc09db70350f6c05144898cc5200"><code>67767bb</code></a>
Merge pull request <a
href="https://redirect.github.com/seleniumbase/SeleniumBase/issues/4512">#4512</a>
from seleniumbase/dependency-update</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/9ab8de7545e1368b644fd8a084395ce490a31293"><code>9ab8de7</code></a>
Version 4.54.12</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/7d13ec22d7091a7d48ddffae2eb472425cea1cb3"><code>7d13ec2</code></a>
Update server.json</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/61ca74f205c98690f8fb134da4a2ae4983374aec"><code>61ca74f</code></a>
Update the deploy script</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/d37046c342cea47177c96c3f4cdc0914c1ede0fe"><code>d37046c</code></a>
Refresh Python dependencies</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/51d75da1397048ec78a020f270970d12de395cb8"><code>51d75da</code></a>
Update the Petco example</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/e13dadbc570a40ffb79a36fab30b819f63f4f109"><code>e13dadb</code></a>
Add a Petco example</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/44de25decafb56dc53f76c7ea9714e1fb413d7f0"><code>44de25d</code></a>
Update the Yelp example</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/a035346b898546d97abfc12535626f746c44128a"><code>a035346</code></a>
Merge pull request <a
href="https://redirect.github.com/seleniumbase/SeleniumBase/issues/4511">#4511</a>
from seleniumbase/mcp-server-patch-19</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/7b371c2dfe008c0d77460d74a26cbff9a38ce9fe"><code>7b371c2</code></a>
Version 4.54.11</li>
<li>Additional commits viewable in <a
href="https://github.com/seleniumbase/SeleniumBase/compare/v4.54.10...v4.54.12">compare
view</a></li>
</ul>
</details>
<br />

Updates `prek` from 0.5.3 to 0.5.4
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/j178/prek/releases">prek's
releases</a>.</em></p>
<blockquote>
<h2>0.5.4</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-28.</p>
<h3>Highlights</h3>
<h4>Faster builtin hooks</h4>
<p>In our end-to-end benchmark, prek is about 38% faster than 0.5.3,
with some builtin
hooks up to 273% faster (<code>check-yaml</code>: 273%,
<code>check-json</code>: 80%,
<code>check-merge-conflict</code>: 71%).</p>
<h3>Enhancements</h3>
<ul>
<li>Add <code>include_deleted</code> to allow hooks to include deleted
files (<a
href="https://redirect.github.com/j178/prek/pull/2733">#2733</a>)</li>
<li>Add <code>--check</code> and simplify <code>end-of-file-fixer</code>
(<a
href="https://redirect.github.com/j178/prek/pull/2764">#2764</a>)</li>
<li>Add <code>--check</code> to <code>file-contents-sorter</code> (<a
href="https://redirect.github.com/j178/prek/pull/2765">#2765</a>)</li>
<li>Add <code>--check</code> to <code>requirements-txt-fixer</code> (<a
href="https://redirect.github.com/j178/prek/pull/2766">#2766</a>)</li>
<li>Add <code>--check</code> to <code>trailing-whitespace</code> (<a
href="https://redirect.github.com/j178/prek/pull/2763">#2763</a>)</li>
<li>Expose and document <code>prek util generate-shell-completion</code>
(<a
href="https://redirect.github.com/j178/prek/pull/2727">#2727</a>)</li>
<li>Support <code>hide_status</code> in project and user configuration
(<a
href="https://redirect.github.com/j178/prek/pull/2760">#2760</a>)</li>
<li>Support look-around regex in builtin pattern hooks (<a
href="https://redirect.github.com/j178/prek/pull/2732">#2732</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Cache the resolved Git executable on macOS (<a
href="https://redirect.github.com/j178/prek/pull/2726">#2726</a>)</li>
<li>Combine and cache Git repository path queries (<a
href="https://redirect.github.com/j178/prek/pull/2724">#2724</a>)</li>
<li>Optimize common builtin hook execution (<a
href="https://redirect.github.com/j178/prek/pull/2768">#2768</a>)</li>
<li>Optimize scanning in <code>mixed-line-ending</code> and
<code>trailing-whitespace</code> (<a
href="https://redirect.github.com/j178/prek/pull/2769">#2769</a>)</li>
<li>Scan <code>check-merge-conflict</code> files in fixed-size blocks
(<a
href="https://redirect.github.com/j178/prek/pull/2781">#2781</a>)</li>
<li>Use SIMD UTF-8 validation in <code>check-json</code>,
<code>check-toml</code>, and <code>check-yaml</code> (<a
href="https://redirect.github.com/j178/prek/pull/2770">#2770</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Retry transient rename failures on Windows (<a
href="https://redirect.github.com/j178/prek/pull/2756">#2756</a>)</li>
<li>Use PATH to resolve prek in completion scripts (<a
href="https://redirect.github.com/j178/prek/pull/2719">#2719</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Clarify the flow and scope of usage guides (<a
href="https://redirect.github.com/j178/prek/pull/2710">#2710</a>)</li>
<li>Reorganize usage guides and reference documentation (<a
href="https://redirect.github.com/j178/prek/pull/2709">#2709</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Sync latest identify tags (<a
href="https://redirect.github.com/j178/prek/pull/2762">#2762</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/github-actions"><code>@​github-actions</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/j178/prek/blob/master/CHANGELOG.md">prek's
changelog</a>.</em></p>
<blockquote>
<h2>0.5.4</h2>
<p>Released on 2026-09-28.</p>
<h3>Highlights</h3>
<h4>Faster builtin hooks</h4>
<p>In our end-to-end benchmark, prek is about 38% faster than 0.5.3,
with some builtin
hooks up to 273% faster (<code>check-yaml</code>: 273%,
<code>check-json</code>: 80%,
<code>check-merge-conflict</code>: 71%).</p>
<h3>Enhancements</h3>
<ul>
<li>Add <code>include_deleted</code> to allow hooks to include deleted
files (<a
href="https://redirect.github.com/j178/prek/pull/2733">#2733</a>)</li>
<li>Add <code>--check</code> and simplify <code>end-of-file-fixer</code>
(<a
href="https://redirect.github.com/j178/prek/pull/2764">#2764</a>)</li>
<li>Add <code>--check</code> to <code>file-contents-sorter</code> (<a
href="https://redirect.github.com/j178/prek/pull/2765">#2765</a>)</li>
<li>Add <code>--check</code> to <code>requirements-txt-fixer</code> (<a
href="https://redirect.github.com/j178/prek/pull/2766">#2766</a>)</li>
<li>Add <code>--check</code> to <code>trailing-whitespace</code> (<a
href="https://redirect.github.com/j178/prek/pull/2763">#2763</a>)</li>
<li>Expose and document <code>prek util generate-shell-completion</code>
(<a
href="https://redirect.github.com/j178/prek/pull/2727">#2727</a>)</li>
<li>Support <code>hide_status</code> in project and user configuration
(<a
href="https://redirect.github.com/j178/prek/pull/2760">#2760</a>)</li>
<li>Support look-around regex in builtin pattern hooks (<a
href="https://redirect.github.com/j178/prek/pull/2732">#2732</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Cache the resolved Git executable on macOS (<a
href="https://redirect.github.com/j178/prek/pull/2726">#2726</a>)</li>
<li>Combine and cache Git repository path queries (<a
href="https://redirect.github.com/j178/prek/pull/2724">#2724</a>)</li>
<li>Optimize common builtin hook execution (<a
href="https://redirect.github.com/j178/prek/pull/2768">#2768</a>)</li>
<li>Optimize scanning in <code>mixed-line-ending</code> and
<code>trailing-whitespace</code> (<a
href="https://redirect.github.com/j178/prek/pull/2769">#2769</a>)</li>
<li>Scan <code>check-merge-conflict</code> files in fixed-size blocks
(<a
href="https://redirect.github.com/j178/prek/pull/2781">#2781</a>)</li>
<li>Use SIMD UTF-8 validation in <code>check-json</code>,
<code>check-toml</code>, and <code>check-yaml</code> (<a
href="https://redirect.github.com/j178/prek/pull/2770">#2770</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Retry transient rename failures on Windows (<a
href="https://redirect.github.com/j178/prek/pull/2756">#2756</a>)</li>
<li>Use PATH to resolve prek in completion scripts (<a
href="https://redirect.github.com/j178/prek/pull/2719">#2719</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Clarify the flow and scope of usage guides (<a
href="https://redirect.github.com/j178/prek/pull/2710">#2710</a>)</li>
<li>Reorganize usage guides and reference documentation (<a
href="https://redirect.github.com/j178/prek/pull/2709">#2709</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Sync latest identify tags (<a
href="https://redirect.github.com/j178/prek/pull/2762">#2762</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/github-actions"><code>@​github-actions</code></a></li>
<li><a href="https://github.com/j178"><code>@​j178</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/j178/prek/commit/77c4056ce76b600de77d5d425e52844a76652a58"><code>77c4056</code></a>
Summarize builtin hook speedups</li>
<li><a
href="https://github.com/j178/prek/commit/7a6b8d1b4fdc87c6ef11a925177b425feb33d8a7"><code>7a6b8d1</code></a>
Bump version to 0.5.4</li>
<li><a
href="https://github.com/j178/prek/commit/c7ec693f66b37fb5afe7491e36e456c459654ac8"><code>c7ec693</code></a>
Update ubuntu:26.04 Docker digest to da6fc2b (<a
href="https://redirect.github.com/j178/prek/issues/2772">#2772</a>)</li>
<li><a
href="https://github.com/j178/prek/commit/eee58225d1ba5719fdcc0bdf14ec6b563caba8bc"><code>eee5822</code></a>
Scan <code>check-merge-conflict</code> files in fixed-size blocks (<a
href="https://redirect.github.com/j178/prek/issues/2781">#2781</a>)</li>
<li><a
href="https://github.com/j178/prek/commit/4c579dc913e388379579d816b0b99844f9a85505"><code>4c579dc</code></a>
Update dependency uv to v0.12.17 (<a
href="https://redirect.github.com/j178/prek/issues/2773">#2773</a>)</li>
<li><a
href="https://github.com/j178/prek/commit/1f2a621d397004de8e9ba13ef55db2ab6e50c15e"><code>1f2a621</code></a>
Update Rust crate clap to v4.6.7 (<a
href="https://redirect.github.com/j178/prek/issues/2775">#2775</a>)</li>
<li><a
href="https://github.com/j178/prek/commit/aeea7a54343a36625e3f2571a43cd8bda6f867cd"><code>aeea7a5</code></a>
Update GitHub Actions (<a
href="https://redirect.github.com/j178/prek/issues/2778">#2778</a>)</li>
<li><a
href="https://github.com/j178/prek/commit/51ca2dbb1c29b13e3c1c2e5c6531ad23ec52a030"><code>51ca2db</code></a>
Update Rust crate rustix to v1.1.5 (<a
href="https://redirect.github.com/j178/prek/issues/2777">#2777</a>)</li>
<li><a
href="https://github.com/j178/prek/commit/80e8bcce8933a5895a79a8eef54522b166be9569"><code>80e8bcc</code></a>
Update Rust crate clap_complete to v4.6.11 (<a
href="https://redirect.github.com/j178/prek/issues/2776">#2776</a>)</li>
<li><a
href="https://github.com/j178/prek/commit/0f237646fcfe1c99191dc493974deaf4cbb2d31c"><code>0f23764</code></a>
Update Rust crate async-compression to v0.4.48 (<a
href="https://redirect.github.com/j178/prek/issues/2774">#2774</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/j178/prek/compare/v0.5.3...v0.5.4">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.8 to 0.16.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.9</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-24.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Avoid false positives for overloaded division
(<code>RUF069</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-bugbear</code>] Avoid false positives for calls with
keyword arguments (<code>B009</code>, <code>B010</code>,
<code>B043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in
deferred annotations (<code>TID255</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Update LibCST-based fixes for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li>
<li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message
(<code>PYI002</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix horizontal overflow on the rules documentation page (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li>
<li>Update rules table with category information (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li>
<li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code>
checks return types in addition to arguments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li>
<li>[<code>flake8-bugbear</code>] Document type-checker interaction
(<code>B010</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li>
<li>[<code>flake8-comprehensions</code>] Document
<code>map</code>/generator exception behavior (<code>C417</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li>
<li>[<code>ruff</code>] Mention related isort settings
(<code>RUF022</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/qinpei-dev"><code>@​qinpei-dev</code></a></li>
<li><a
href="https://github.com/sanjayrohith"><code>@​sanjayrohith</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/webdevsamran"><code>@​webdevsamran</code></a></li>
<li><a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/spaceone"><code>@​spaceone</code></a></li>
<li><a
href="https://github.com/IbrahimKhan12"><code>@​IbrahimKhan12</code></a></li>
<li><a
href="https://github.com/devtechedge"><code>@​devtechedge</code></a></li>
<li><a
href="https://github.com/GruffElixir"><code>@​GruffElixir</code></a></li>
</ul>
<h2>Install ruff 0.16.9</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh
| sh
</code></pre>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.9</h2>
<p>Released on 2026-09-24.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Avoid false positives for overloaded division
(<code>RUF069</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-bugbear</code>] Avoid false positives for calls with
keyword arguments (<code>B009</code>, <code>B010</code>,
<code>B043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in
deferred annotations (<code>TID255</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Update LibCST-based fixes for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li>
<li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message
(<code>PYI002</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix horizontal overflow on the rules documentation page (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li>
<li>Update rules table with category information (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li>
<li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code>
checks return types in addition to arguments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li>
<li>[<code>flake8-bugbear</code>] Document type-checker interaction
(<code>B010</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li>
<li>[<code>flake8-comprehensions</code>] Document
<code>map</code>/generator exception behavior (<code>C417</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li>
<li>[<code>ruff</code>] Mention related isort settings
(<code>RUF022</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/qinpei-dev"><code>@​qinpei-dev</code></a></li>
<li><a
href="https://github.com/sanjayrohith"><code>@​sanjayrohith</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/webdevsamran"><code>@​webdevsamran</code></a></li>
<li><a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/spaceone"><code>@​spaceone</code></a></li>
<li><a
href="https://github.com/IbrahimKhan12"><code>@​IbrahimKhan12</code></a></li>
<li><a
href="https://github.com/devtechedge"><code>@​devtechedge</code></a></li>
<li><a
href="https://github.com/GruffElixir"><code>@​GruffElixir</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/0be08a206f9c3180afd3e93bcc792ed5cb1f4db1"><code>0be08a2</code></a>
Bump version to 0.16.9 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28882">#28882</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/b4920b72b354e7c715ab861ae23458874683bb02"><code>b4920b7</code></a>
Rename <code>ruff_cli</code> to <code>ruff_command_line</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28881">#28881</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/47c751b95908a4d1f95f9ef8723036aae9da0b18"><code>47c751b</code></a>
Update dependency astral-sh/uv to v0.12.18 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28880">#28880</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/8c244e56a1aeac31c26d2371ef26588e0632235c"><code>8c244e5</code></a>
[<code>flake8-comprehensions</code>] Document <code>map</code>/generator
exception behavior (<code>C417</code>...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/5edf5a1d0a84663079e46983216059f06acea87d"><code>5edf5a1</code></a>
Use <code>target</code> form in <code>rooster.version_files</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28876">#28876</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/915bb2b4bf9ae7eee47cf55646bbfebae254a23b"><code>915bb2b</code></a>
[ty] Prefer existing @ paths over response files in Ruff and ty (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28877">#28877</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/4710e1aa962b13720cf64aa84eb279c5333896d7"><code>4710e1a</code></a>
ci(github): update version number in placeholder of issue template (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28871">#28871</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/eedfc62a75bf1ba86d48959b00eea75ae87eadca"><code>eedfc62</code></a>
[ty] Propagate outer type context through cast calls (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28855">#28855</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/ceaa6a00830e1e350b8a23977a1a10ac467920a1"><code>ceaa6a0</code></a>
[ty] Contain rendered code within Markdown fences (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28869">#28869</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/dba0f30615424b94f94a174bba6ce6cce4bf11ff"><code>dba0f30</code></a>
authorize ruff-pre-commit dispatch via OIDC (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28867">#28867</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.8...0.16.9">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-02 22:38:15 -04:00
dependabot[bot] 33010efa16 build(deps): bump astral-sh/uv from 0.12.19 to 0.12.22 in the docker-base-image-digests group (#1413)
> [!WARNING]
> Cooldown could not be applied because no publication date was
available from the registry.
>

Bumps the docker-base-image-digests group with 1 update:
[astral-sh/uv](https://github.com/astral-sh/uv).

Updates `astral-sh/uv` from 0.12.19 to 0.12.22
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/uv/releases">astral-sh/uv's
releases</a>.</em></p>
<blockquote>
<h2>0.12.22</h2>
<h2>Release Notes</h2>
<p>Released on 2026-10-01.</p>
<h3>Python</h3>
<ul>
<li>Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8 (<a
href="https://redirect.github.com/astral-sh/uv/pull/22147">#22147</a>)</li>
</ul>
<h3>Enhancements</h3>
<ul>
<li>Accept uppercase release suffixes in wheel platform tags (<a
href="https://redirect.github.com/astral-sh/uv/pull/22113">#22113</a>)</li>
<li>Record workspace-member default groups in lockfiles (<a
href="https://redirect.github.com/astral-sh/uv/pull/22010">#22010</a>,
<a
href="https://redirect.github.com/astral-sh/uv/pull/22103">#22103</a>)</li>
<li>Record workspace-member dependency-group Python requirements in
lockfiles (<a
href="https://redirect.github.com/astral-sh/uv/pull/22044">#22044</a>,
<a
href="https://redirect.github.com/astral-sh/uv/pull/22103">#22103</a>)</li>
<li>Record default groups for non-project workspace roots in lockfiles
(<a
href="https://redirect.github.com/astral-sh/uv/pull/22104">#22104</a>)</li>
<li>Record dependency-group Python requirements for non-project
workspace roots in lockfiles (<a
href="https://redirect.github.com/astral-sh/uv/pull/22104">#22104</a>)</li>
<li>Format URLs and paths consistently in CLI messages (<a
href="https://redirect.github.com/astral-sh/uv/pull/21937">#21937</a>)</li>
<li>Hide the unsupported <code>--offline</code> option from <code>uv
publish</code> help (<a
href="https://redirect.github.com/astral-sh/uv/pull/22124">#22124</a>)</li>
</ul>
<h3>Preview features</h3>
<ul>
<li>Honor <code>--no-default-groups</code> in <code>uv audit</code> (<a
href="https://redirect.github.com/astral-sh/uv/pull/22090">#22090</a>)</li>
<li>Report a clear error when <code>uv audit</code> or <code>uv tool
audit</code> runs offline and hide the unsupported option from help (<a
href="https://redirect.github.com/astral-sh/uv/pull/22114">#22114</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>Add <code>UV_PYTHON_ARCH</code> to select an interpreter
architecture independently of its Python version (<a
href="https://redirect.github.com/astral-sh/uv/pull/22098">#22098</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Reduce uv's binary size by compressing embedded Python download
metadata (<a
href="https://redirect.github.com/astral-sh/uv/pull/22126">#22126</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Verify unchanged requirements against existing lockfile hashes when
relocking (<a
href="https://redirect.github.com/astral-sh/uv/pull/22083">#22083</a>)</li>
<li>Honor dependency-group Python requirements at non-project workspace
roots (<a
href="https://redirect.github.com/astral-sh/uv/pull/22101">#22101</a>)</li>
<li>Use each selected workspace member's recorded default groups during
frozen sync (<a
href="https://redirect.github.com/astral-sh/uv/pull/22015">#22015</a>)</li>
<li>Avoid false entry-point warnings for required workspace members (<a
href="https://redirect.github.com/astral-sh/uv/pull/22112">#22112</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Raise the minimum supported Rust version for building uv to 1.97 and
update the toolchain to Rust 1.99 (<a
href="https://redirect.github.com/astral-sh/uv/pull/22121">#22121</a>)</li>
</ul>
<h2>Install uv 0.12.22</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/uv/releases/download/0.12.22/uv-installer.sh
| sh
</code></pre>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/uv/blob/main/CHANGELOG.md">astral-sh/uv's
changelog</a>.</em></p>
<blockquote>
<h2>0.12.22</h2>
<p>Released on 2026-10-01.</p>
<h3>Python</h3>
<ul>
<li>Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8 (<a
href="https://redirect.github.com/astral-sh/uv/pull/22147">#22147</a>)</li>
</ul>
<h3>Enhancements</h3>
<ul>
<li>Accept uppercase release suffixes in wheel platform tags (<a
href="https://redirect.github.com/astral-sh/uv/pull/22113">#22113</a>)</li>
<li>Record workspace-member default groups in lockfiles (<a
href="https://redirect.github.com/astral-sh/uv/pull/22010">#22010</a>,
<a
href="https://redirect.github.com/astral-sh/uv/pull/22103">#22103</a>)</li>
<li>Record workspace-member dependency-group Python requirements in
lockfiles (<a
href="https://redirect.github.com/astral-sh/uv/pull/22044">#22044</a>,
<a
href="https://redirect.github.com/astral-sh/uv/pull/22103">#22103</a>)</li>
<li>Record default groups for non-project workspace roots in lockfiles
(<a
href="https://redirect.github.com/astral-sh/uv/pull/22104">#22104</a>)</li>
<li>Record dependency-group Python requirements for non-project
workspace roots in lockfiles (<a
href="https://redirect.github.com/astral-sh/uv/pull/22104">#22104</a>)</li>
<li>Format URLs and paths consistently in CLI messages (<a
href="https://redirect.github.com/astral-sh/uv/pull/21937">#21937</a>)</li>
<li>Hide the unsupported <code>--offline</code> option from <code>uv
publish</code> help (<a
href="https://redirect.github.com/astral-sh/uv/pull/22124">#22124</a>)</li>
</ul>
<h3>Preview features</h3>
<ul>
<li>Honor <code>--no-default-groups</code> in <code>uv audit</code> (<a
href="https://redirect.github.com/astral-sh/uv/pull/22090">#22090</a>)</li>
<li>Report a clear error when <code>uv audit</code> or <code>uv tool
audit</code> runs offline and hide the unsupported option from help (<a
href="https://redirect.github.com/astral-sh/uv/pull/22114">#22114</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>Add <code>UV_PYTHON_ARCH</code> to select an interpreter
architecture independently of its Python version (<a
href="https://redirect.github.com/astral-sh/uv/pull/22098">#22098</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Reduce uv's binary size by compressing embedded Python download
metadata (<a
href="https://redirect.github.com/astral-sh/uv/pull/22126">#22126</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Verify unchanged requirements against existing lockfile hashes when
relocking (<a
href="https://redirect.github.com/astral-sh/uv/pull/22083">#22083</a>)</li>
<li>Honor dependency-group Python requirements at non-project workspace
roots (<a
href="https://redirect.github.com/astral-sh/uv/pull/22101">#22101</a>)</li>
<li>Use each selected workspace member's recorded default groups during
frozen sync (<a
href="https://redirect.github.com/astral-sh/uv/pull/22015">#22015</a>)</li>
<li>Avoid false entry-point warnings for required workspace members (<a
href="https://redirect.github.com/astral-sh/uv/pull/22112">#22112</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Raise the minimum supported Rust version for building uv to 1.97 and
update the toolchain to Rust 1.99 (<a
href="https://redirect.github.com/astral-sh/uv/pull/22121">#22121</a>)</li>
</ul>
<h2>0.12.21</h2>
<p>Released on 2026-09-29.</p>
<h3>Python</h3>
<ul>
<li>Update CPython to use OpenSSL 3.5.9 (<a
href="https://redirect.github.com/astral-sh/uv/pull/22076">#22076</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/uv/commit/70fe1196a546e49148a73b1c592b2f74c33af80e"><code>70fe119</code></a>
Bump version to 0.12.22 (<a
href="https://redirect.github.com/astral-sh/uv/issues/22148">#22148</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/7e9d252e37065168cd3ed8419bb31da512133604"><code>7e9d252</code></a>
Sync latest Python releases (<a
href="https://redirect.github.com/astral-sh/uv/issues/22147">#22147</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/d644be28bdb7820055801b9796e56b553cfd513c"><code>d644be2</code></a>
Compress embedded Python download metadata (<a
href="https://redirect.github.com/astral-sh/uv/issues/22126">#22126</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/0a41ee38ec6009877a77702265bcd18ceeece5ef"><code>0a41ee3</code></a>
Benchmark Python download catalog loading (<a
href="https://redirect.github.com/astral-sh/uv/issues/22125">#22125</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/cbf610678ba180054ce502ba803bc4403fac630e"><code>cbf6106</code></a>
Use Cargo warning policy for Clippy (<a
href="https://redirect.github.com/astral-sh/uv/issues/22122">#22122</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/60776645b718e5141a6969922c4d027008a9c2b9"><code>6077664</code></a>
Update Rust to 1.99 and MSRV to 1.97 (<a
href="https://redirect.github.com/astral-sh/uv/issues/22121">#22121</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/69025fdd3b437447909dcf71e8e751652873b1b9"><code>69025fd</code></a>
Hide the <code>--offline</code> flag in <code>uv publish</code> (<a
href="https://redirect.github.com/astral-sh/uv/issues/22124">#22124</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/3f70ccf04396802654de142c40925bdad39311e9"><code>3f70ccf</code></a>
Defer cache format changes to 0.13 (<a
href="https://redirect.github.com/astral-sh/uv/issues/22128">#22128</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/e71ab8f9b46398cc2d73f866dd4d1776e9969953"><code>e71ab8f</code></a>
Add <code>UV_PYTHON_ARCH</code> for requesting an interpreter
architecture (<a
href="https://redirect.github.com/astral-sh/uv/issues/22098">#22098</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/d62a205c091f12a90db2c77f596b3a53bca22051"><code>d62a205</code></a>
Hide the <code>--offline</code> flag for uv audit (<a
href="https://redirect.github.com/astral-sh/uv/issues/22114">#22114</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/uv/compare/0.12.19...0.12.22">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=astral-sh/uv&package-manager=docker&previous-version=0.12.19&new-version=0.12.22)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-02 22:38:05 -04:00
dependabot[bot] 3d85b610c0 build(deps): bump the npm-deps group in /src/frontend with 8 updates (#1414)
Bumps the npm-deps group in /src/frontend with 8 updates:

| Package | From | To |
| --- | --- | --- |
| [socket.io-client](https://github.com/socketio/socket.io) | `4.8.3` |
`4.8.4` |
|
[@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)
| `26.6.2` | `26.6.3` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) |
`6.37.0` | `6.38.0` |
| [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) |
`0.70.0` | `0.71.0` |
| [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) |
`1.85.0` | `1.86.0` |
| [oxlint-tsgolint](https://github.com/oxc-project/tsgolint) |
`7.0.2002` | `7.0.2003` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) |
`8.3.0` | `8.3.1` |
|
[vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest)
| `5.0.1` | `5.0.2` |

Updates `socket.io-client` from 4.8.3 to 4.8.4
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/socketio/socket.io/releases">socket.io-client's
releases</a>.</em></p>
<blockquote>
<h2>socket.io-client@4.8.4</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>types:</strong> export ExtendedError for connect_error event
(<a
href="https://redirect.github.com/socketio/socket.io/issues/5548">#5548</a>)
(<a
href="https://github.com/socketio/socket.io/commit/c0d54509fbe7dafd3ed8b5a2f3f74a12810da4a3">c0d5450</a>)</li>
<li><strong>types:</strong> export reserved event interfaces (<a
href="https://redirect.github.com/socketio/socket.io/issues/5533">#5533</a>)
(<a
href="https://github.com/socketio/socket.io/commit/03945df6b750dfa6379305ef29ea4235a424ca47">03945df</a>)</li>
</ul>
<h3>Dependencies</h3>
<ul>
<li><a
href="https://github.com/socketio/socket.io/releases/tag/engine.io-client%406.6.7"><code>engine.io-client@~6.6.1</code></a>
(no change)</li>
<li><a
href="https://github.com/websockets/ws/releases/tag/8.21.0"><code>ws@~8.21.0</code></a>
(<a
href="https://github.com/websockets/ws/compare/8.18.3...8.21.0">diff</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/socketio/socket.io/commit/11a6f561a757264c3231c3383c4cdbf37bcf52de"><code>11a6f56</code></a>
chore(release): socket.io-client@4.8.4</li>
<li><a
href="https://github.com/socketio/socket.io/commit/00e4e73a68505ff0c93d7d9ca8db5dd510428cf4"><code>00e4e73</code></a>
chore(release): engine.io-client@6.6.7</li>
<li><a
href="https://github.com/socketio/socket.io/commit/e387ab116f6904537ccef872ef570a6ef7936e9d"><code>e387ab1</code></a>
chore: use <code>@​rollup/plugin-terser</code> instead of
rollup-plugin-terser</li>
<li><a
href="https://github.com/socketio/socket.io/commit/973833304c7c195c2d0d99b72e4ac9f149e3ca94"><code>9738333</code></a>
chore(release): engine.io@6.6.11</li>
<li><a
href="https://github.com/socketio/socket.io/commit/fc9dd90e2ff26aa358d0cd27bc59ddc93458ae44"><code>fc9dd90</code></a>
docs(eio): rework README</li>
<li><a
href="https://github.com/socketio/socket.io/commit/da008a514ded71e3058a964c831c69abe417b2f5"><code>da008a5</code></a>
fix(eio): refresh ping timeout on incoming packets</li>
<li><a
href="https://github.com/socketio/socket.io/commit/3df3fed075fd2312e84481786235aa14d08b8fe7"><code>3df3fed</code></a>
fix(eio-client): restore default transport resolution</li>
<li><a
href="https://github.com/socketio/socket.io/commit/aaf2af36ec8ad05910f357a788e0e358bad32738"><code>aaf2af3</code></a>
test: upgrade WebdriverIO to v9</li>
<li><a
href="https://github.com/socketio/socket.io/commit/b5da079228666fcabd97166486d5f6a110826bc8"><code>b5da079</code></a>
refactor(sio): simplify packet handling switch</li>
<li><a
href="https://github.com/socketio/socket.io/commit/45873ca93e6e25ac55dc1ba5c9b87853bf19ffba"><code>45873ca</code></a>
docs(protocol): clarify namespace comma restriction for built-in parser
(<a
href="https://redirect.github.com/socketio/socket.io/issues/5545">#5545</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/socketio/socket.io/compare/socket.io-client@4.8.3...socket.io-client@4.8.4">compare
view</a></li>
</ul>
</details>
<br />

Updates `@types/node` from 26.6.2 to 26.6.3
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node">compare
view</a></li>
</ul>
</details>
<br />

Updates `knip` from 6.37.0 to 6.38.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/webpro-nl/knip/releases">knip's
releases</a>.</em></p>
<blockquote>
<h2>Release 6.38.0</h2>
<ul>
<li>Include co-authors in docs contributor list
(0c334100df59d89a512ad598ec50e7f62f6da0c3)</li>
<li>Filter bots and agents from docs contributors
(617f70d8179c6b8668ca41fe5df77ced5e2b37c0)</li>
<li>Update Eve plugin conventions (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2049">#2049</a>)
(260dbb91a85f3a3bc2727e8f255d73df3737552c) - thanks <a
href="https://github.com/matchai"><code>@​matchai</code></a>!</li>
<li>Add <code>args</code> example to that doc page
(50b271b98fc930a05a3b045a2f691486f9f06528)</li>
<li>Add Turborepo plugin (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2055">#2055</a>)
(e49d3db05f1d69ce7db3efcb8467a4af63c27379) - thanks <a
href="https://github.com/changbaebang"><code>@​changbaebang</code></a>!</li>
<li>Support <code>import-x/*</code> settings in ESLint plugin (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2050">#2050</a>)
(1a34cf82a3d6a1202717ef910bedba55838e9dd9) - thanks <a
href="https://github.com/bytedoe"><code>@​bytedoe</code></a>!</li>
<li>Resolve file option in Mocha configuration files (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2051">#2051</a>)
(9b5c5f60468c8a92a3e74adca5c0931f008677af) - thanks <a
href="https://github.com/giaBaoJS"><code>@​giaBaoJS</code></a>!</li>
<li>Support oxlint extends (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2054">#2054</a>)
(a149a98219bb14b15f446fc5f8c4f815e28b2183) - thanks <a
href="https://github.com/matthewnitschke-wk"><code>@​matthewnitschke-wk</code></a>!</li>
<li>Fix import.meta handling in built-in compilers (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2059">#2059</a>)
(8b0c85076bf3dce15ef5f3c0c4e58bfefdf59ded) - thanks <a
href="https://github.com/vdavid"><code>@​vdavid</code></a>!</li>
<li>Fix tag hints for enum and namespace members (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2061">#2061</a>)
(8a8805e48945863248429d18b7f6c4e4b7dc9ebd) - thanks <a
href="https://github.com/devYRPauli"><code>@​devYRPauli</code></a>!</li>
<li>Flag unused member tags in tagged enums and namespaces
(584e53ff3e0846fbfe04fa5b5bfefe2420576a34)</li>
<li>feat: resolve MDX content mapper remarkPlugins (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2060">#2060</a>)
(34dbccf25359f9e9fefe9d0be6ef2ec0252223cc) - thanks <a
href="https://github.com/gioboa"><code>@​gioboa</code></a>!</li>
<li>Refactor and separate concerns w/ new typescript-content-mapper
plugin (11e94509bd0f350d747facf4003fc5b248d1b02d)</li>
<li>Resolve mdx content mapper providerImportSource
(7b5825117f97f2f87b7141509a254f88d0957cf7)</li>
<li>Fix config → entry in plop plugin
(25a380c9e1165b76583d69b48b5fa7cdf5db0ae2)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/webpro-nl/knip/commit/c0e42f83bda7664065465f2f3faca7af97c988ac"><code>c0e42f8</code></a>
Release knip@6.38.0</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/25a380c9e1165b76583d69b48b5fa7cdf5db0ae2"><code>25a380c</code></a>
Fix config → entry in plop plugin</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/7b5825117f97f2f87b7141509a254f88d0957cf7"><code>7b58251</code></a>
Resolve mdx content mapper providerImportSource</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/11e94509bd0f350d747facf4003fc5b248d1b02d"><code>11e9450</code></a>
Refactor and separate concerns w/ new typescript-content-mapper
plugin</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/34dbccf25359f9e9fefe9d0be6ef2ec0252223cc"><code>34dbccf</code></a>
feat: resolve MDX content mapper remarkPlugins (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2060">#2060</a>)</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/584e53ff3e0846fbfe04fa5b5bfefe2420576a34"><code>584e53f</code></a>
Flag unused member tags in tagged enums and namespaces</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/8a8805e48945863248429d18b7f6c4e4b7dc9ebd"><code>8a8805e</code></a>
Fix tag hints for enum and namespace members (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2061">#2061</a>)</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/8b0c85076bf3dce15ef5f3c0c4e58bfefdf59ded"><code>8b0c850</code></a>
Fix import.meta handling in built-in compilers (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2059">#2059</a>)</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/a149a98219bb14b15f446fc5f8c4f815e28b2183"><code>a149a98</code></a>
Support oxlint extends (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2054">#2054</a>)</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/9b5c5f60468c8a92a3e74adca5c0931f008677af"><code>9b5c5f6</code></a>
Resolve file option in Mocha configuration files (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2051">#2051</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/webpro-nl/knip/commits/knip@6.38.0/packages/knip">compare
view</a></li>
</ul>
</details>
<br />

Updates `oxfmt` from 0.70.0 to 0.71.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/oxc-project/oxc/releases">oxfmt's
releases</a>.</em></p>
<blockquote>
<h2>oxfmt v0.71.0</h2>
<h3>🚀 Features</h3>
<ul>
<li>e0b1f9f oxfmt: Bump bundled Prettier version to 3.9.9 (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/27002">#27002</a>)
(leaysgur)</li>
<li>342527d oxfmt: Bump bundled Prettier version to 3.9.8 (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/26999">#26999</a>)
(leaysgur)</li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>eeba1db formatter: Skip test-call layout when arguments have
comments (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/27119">#27119</a>)
(leaysgur)</li>
<li>1f7b8ad oxfmt: Allow repeated CLI calls in the same process (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/27051">#27051</a>)
(Liang)</li>
<li>7bcb807 formatter_markdown: Keep blank line between HTML and nested
list (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/27112">#27112</a>)
(leaysgur)</li>
<li>10b10c5 formatter: Keep comments around <code>=</code> on their side
and line (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/27041">#27041</a>)
(leaysgur)</li>
<li>9aad365 formatter: Keep comments deferred before an assignment
operator (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/26997">#26997</a>)
(waltu)</li>
<li>8fbddb1 formatter/jsdoc: More alignment with original plugin (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/27039">#27039</a>)
(leaysgur)</li>
<li>50be18e formatter: Keep trailing spaces on normal block comments (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/27037">#27037</a>)
(leaysgur)</li>
<li>56d1880 formatter: Nestle adjacent block comments (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/27036">#27036</a>)
(leaysgur)</li>
<li>3be5d94 formatter: Treat <code>/***</code> comments as JSDoc (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/27035">#27035</a>)
(leaysgur)</li>
<li>cd45f71 formatter: Keep trailing double spaces on JSDoc lines (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/26861">#26861</a>)
(John Costa)</li>
<li>fd695f4 formatter_markdown: Fix more mismatches found in
ecosystem-ci repos (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/27003">#27003</a>)
(leaysgur)</li>
<li>4e77d59 formatter_markdown: Keep a math span after a kept line break
from opening a block (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/27001">#27001</a>)
(leaysgur)</li>
<li>584b8b0 formatter_markdown: Keep a shape line after a multi-line
inline node or link title (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/27000">#27000</a>)
(leaysgur)</li>
<li>b939645 formatter_markdown: Keep a line break before an inline
liquid tag under preserve (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/26998">#26998</a>)
(leaysgur)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/oxc-project/oxc/commit/2ae2939bb2fd98796393658b21556b2a2467e047"><code>2ae2939</code></a>
release(apps): oxlint v1.86.0 &amp;&amp; oxfmt v0.71.0 (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/27132">#27132</a>)</li>
<li><a
href="https://github.com/oxc-project/oxc/commit/f158bff061a59d776fd695e4baf7f7497f895612"><code>f158bff</code></a>
chore(deps): update npm packages (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/26865">#26865</a>)</li>
<li>See full diff in <a
href="https://github.com/oxc-project/oxc/commits/oxfmt_v0.71.0/npm/oxfmt">compare
view</a></li>
</ul>
</details>
<br />

Updates `oxlint` from 1.85.0 to 1.86.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/oxc-project/oxc/releases">oxlint's
releases</a>.</em></p>
<blockquote>
<h2>oxlint v1.86.0</h2>
<h3>🚀 Features</h3>
<ul>
<li>9d80eed linter/react/only-export-components: Support
<code>allowCompoundComponents</code> (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/27117">#27117</a>)
(Kuroda Kayn)</li>
<li>e05b155 linter: Add typescript/no-generated-empty-object-type (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26958">#26958</a>)
(camc314)</li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>8306aa4
linter/typescript/no-unnecessary-parameter-property-assignment: Account
for parameter property reassignment (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26955">#26955</a>)
(camc314)</li>
<li>42dfbb5 linter/eslint/one-var: Keep <code>declare</code> when
splitting declarations (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/27081">#27081</a>)
(Cheolhee Lee)</li>
<li>2ba7e33 linter/eslint/require-await: Count <code>await using</code>
as an await (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/27080">#27080</a>)
(Cheolhee Lee)</li>
<li>611e4ed linter/plugins: Include executing selectors in JS plugin
rule timings (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/27111">#27111</a>)
(overlookmotel)</li>
<li>2cac66f react-compiler: Handle recursive function expressions (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26796">#26796</a>)
(Brennan Butler)</li>
<li>e996e6c react-compiler: Treat zero-argument new Date as impure (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26894">#26894</a>)
(Boshen)</li>
<li>571cfa3 oxlint: Skip type-aware lint rules in type-check-only mode
(<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/27076">#27076</a>)
(camc314)</li>
<li>d0b2462 oxlint: Skip undefined children in CFG walker (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/27075">#27075</a>)
(camc314)</li>
<li>5186328 parser: Handle HTML comment values (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/22933">#22933</a>)
(Boshen)</li>
<li>0b630e8 linter/typescript/unified-signatures: Align rule with
upstream (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26956">#26956</a>)
(camc314)</li>
<li>ebb22f1 linter/node/no-exports-assign: Change category from style to
suspicious (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26555">#26555</a>)
(Bartok)</li>
<li>cce28a0 linter/import/no-duplicates: Distinguish import attributes
(<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26936">#26936</a>)
(camc314)</li>
<li>feb733b linter/unicorn/prefer-spread: Stop checking string split
calls (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26935">#26935</a>)
(camc314)</li>
<li>929e154 linter/eslint/no-unused-vars: Honor ignore patterns inside
array rest bindings (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26923">#26923</a>)
(camc314)</li>
<li>5bdb9b8 linter/eslint/no-unused-vars: Recognize consumed update
expressions (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26782">#26782</a>)
(camc314)</li>
<li>5c05bef linter/eslint/prefer-const: Ignore embedded assignments (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26920">#26920</a>)
(camc314)</li>
</ul>
<h3>⚡ Performance</h3>
<ul>
<li>ded4c29 linter/eslint/no-unused-vars: Skip sequence checks when
absent (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26921">#26921</a>)
(camc314)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md">oxlint's
changelog</a>.</em></p>
<blockquote>
<h2>[1.86.0] - 2026-09-28</h2>
<h3>🚀 Features</h3>
<ul>
<li>9d80eed linter/react/only-export-components: Support
<code>allowCompoundComponents</code> (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/27117">#27117</a>)
(Kuroda Kayn)</li>
<li>e05b155 linter: Add typescript/no-generated-empty-object-type (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26958">#26958</a>)
(camc314)</li>
</ul>
<h2>[1.82.0] - 2026-09-07</h2>
<h3>🚀 Features</h3>
<ul>
<li>6a0e19c linter/eslint/no-unmodified-loop-condition: Support
<code>checkConditionalExpressions</code> option (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26249">#26249</a>)
(camc314)</li>
</ul>
<h2>[1.81.0] - 2026-08-31</h2>
<h3>📚 Documentation</h3>
<ul>
<li>d5be037 linter/typescript/switch-exhaustiveness-check: Clarify
default case comment pattern (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26100">#26100</a>)
(camc314)</li>
</ul>
<h2>[1.79.0] - 2026-08-18</h2>
<h3>💥 BREAKING CHANGES</h3>
<ul>
<li>8c4552d linter: [<strong>BREAKING</strong>] Split
react/react-compiler into per-category rules (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25500">#25500</a>)
(Boshen)</li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>228e8e0 linter: Resolve inactive React compiler rules (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25830">#25830</a>)
(Boshen)</li>
<li>aa49d86 linter: Allow spread rule options in config types (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25675">#25675</a>)
(ch3rry)</li>
<li>36f8451 linter/eslint/no-eval: Align indirect default with ESLint
(<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25656">#25656</a>)
(camc314)</li>
<li>beb724d linter/eslint/no-unused-vars: Report bare underscore
parameters (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25663">#25663</a>)
(camc314)</li>
<li>4004c10 linter/eslint/no-irregular-whitespace: Check comments by
default (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25660">#25660</a>)
(camc314)</li>
<li>285820e linter/no-large-snapshots: Precompile and document allowed
snapshot matchers (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25611">#25611</a>)
(Mikhail Baev)</li>
<li>4df5835 linter: Allow capitalized built-in calls (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25516">#25516</a>)
(Boshen)</li>
</ul>
<h2>[1.78.0] - 2026-08-10</h2>
<h3>🚀 Features</h3>
<ul>
<li>ccb8fe8 linter/jsdoc: Implement <code>no-blank-blocks</code> rule
(<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25207">#25207</a>)
(Mikhail Baev)</li>
<li>d4a897c linter/eslint: Implement <code>one-var</code> rule (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/24470">#24470</a>)
(Cole Ellison)</li>
<li>5ab9340 linter/jsx-a11y/anchor-has-content: Add options to match
eslint (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/24571">#24571</a>)
(Cole Ellison)</li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>9573937 linter/typescript: Validate <code>ban-ts-comment</code>
description_format (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25320">#25320</a>)
(Mikhail Baev)</li>
</ul>
<h2>[1.77.0] - 2026-08-03</h2>
<h3>🐛 Bug Fixes</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/oxc-project/oxc/commit/2ae2939bb2fd98796393658b21556b2a2467e047"><code>2ae2939</code></a>
release(apps): oxlint v1.86.0 &amp;&amp; oxfmt v0.71.0 (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/27132">#27132</a>)</li>
<li><a
href="https://github.com/oxc-project/oxc/commit/9d80eeddbd1d84032e258cc3662182b7649b4161"><code>9d80eed</code></a>
feat(linter/react/only-export-components): support
<code>allowCompoundComponents</code> ...</li>
<li><a
href="https://github.com/oxc-project/oxc/commit/e05b155a6d1e7467f58225628705573c34d3cded"><code>e05b155</code></a>
feat(linter): add typescript/no-generated-empty-object-type (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26958">#26958</a>)</li>
<li><a
href="https://github.com/oxc-project/oxc/commit/88a009621499725d891780b04c41f23ebba09f30"><code>88a0096</code></a>
chore(oxlint): require tsgolint 7.0.2003 (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/27021">#27021</a>)</li>
<li>See full diff in <a
href="https://github.com/oxc-project/oxc/commits/oxlint_v1.86.0/npm/oxlint">compare
view</a></li>
</ul>
</details>
<br />

Updates `oxlint-tsgolint` from 7.0.2002 to 7.0.2003
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/oxc-project/tsgolint/releases">oxlint-tsgolint's
releases</a>.</em></p>
<blockquote>
<h2>v7.0.2003</h2>
<h2>What's Changed</h2>
<ul>
<li>docs: update agent development instructions by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1210">oxc-project/tsgolint#1210</a></li>
<li>docs: refresh README benchmarks and wording by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1208">oxc-project/tsgolint#1208</a></li>
<li>chore(deps): update crate-ci/typos action to v1.50.2 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1213">oxc-project/tsgolint#1213</a></li>
<li>chore(deps): update taiki-e/install-action action to v2.87.14 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1216">oxc-project/tsgolint#1216</a></li>
<li>chore(deps): update dependency dprint-json to v0.24.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1217">oxc-project/tsgolint#1217</a></li>
<li>feat(no-unnecessary-condition): implement suggestion by <a
href="https://github.com/baevm"><code>@​baevm</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1218">oxc-project/tsgolint#1218</a></li>
<li>fix(require-array-sort-compare): resolve string element constraints
by <a href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1219">oxc-project/tsgolint#1219</a></li>
<li>fix(no-duplicate-type-constituents): allow undefined on optional
parameter properties by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1222">oxc-project/tsgolint#1222</a></li>
<li>test(no-unnecessary-type-assertion): cover Record alias assertions
by <a href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1226">oxc-project/tsgolint#1226</a></li>
<li>fix(no-misused-spread): omit invalid WeakMap suggestions by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1227">oxc-project/tsgolint#1227</a></li>
<li>fix(no-meaningless-void-operator): allow void on assignments by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1228">oxc-project/tsgolint#1228</a></li>
<li>feat: add no-generated-empty-object-type rule by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1229">oxc-project/tsgolint#1229</a></li>
<li>fix(no-useless-default-assignment): use suggestions for undefined
defaults by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1231">oxc-project/tsgolint#1231</a></li>
<li>fix(unbound-method): treat Intl.Collator compare as bound by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1224">oxc-project/tsgolint#1224</a></li>
<li>fix(no-unnecessary-type-parameters): preserve suggestion type
precedence by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1232">oxc-project/tsgolint#1232</a></li>
<li>fix(no-unnecessary-condition): handle union keys in nullish
assignment by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1230">oxc-project/tsgolint#1230</a></li>
<li>fix: preserve expression syntax when removing await by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1233">oxc-project/tsgolint#1233</a></li>
<li>fix: match package specifiers on whole path components by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1225">oxc-project/tsgolint#1225</a></li>
<li>fix(no-useless-default-assignment): handle tuples with rest elements
by <a href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1223">oxc-project/tsgolint#1223</a></li>
<li>fix(no-deprecated): detect deprecated aliases in object shorthand by
<a href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1235">oxc-project/tsgolint#1235</a></li>
<li>fix(no-unnecessary-condition): check nested logical expressions in
truthiness contexts by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1236">oxc-project/tsgolint#1236</a></li>
<li>perf: avoid singleton union type allocations in hot rules by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1237">oxc-project/tsgolint#1237</a></li>
<li>perf: speed up headless file-to-program assignment by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1239">oxc-project/tsgolint#1239</a></li>
<li>perf(no-unnecessary-type-assertion): reject incompatible types first
by <a href="https://github.com/tony-scio"><code>@​tony-scio</code></a>
in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1181">oxc-project/tsgolint#1181</a></li>
<li>refactor: extract checker workload scheduling by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1241">oxc-project/tsgolint#1241</a></li>
<li>perf: add experimental checker scheduling modes by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1240">oxc-project/tsgolint#1240</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/baevm"><code>@​baevm</code></a> made
their first contribution in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1218">oxc-project/tsgolint#1218</a></li>
<li><a href="https://github.com/tony-scio"><code>@​tony-scio</code></a>
made their first contribution in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1181">oxc-project/tsgolint#1181</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/oxc-project/tsgolint/compare/v7.0.2002...v7.0.2003">https://github.com/oxc-project/tsgolint/compare/v7.0.2002...v7.0.2003</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/eb9339115edde6811ca94c3433adf69ea9852880"><code>eb93391</code></a>
perf: add experimental checker scheduling modes (<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1240">#1240</a>)</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/e3a79a5e04df2400066bbf3abcb707443652e5b1"><code>e3a79a5</code></a>
refactor: extract checker workload scheduling (<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1241">#1241</a>)</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/1fdaa0db360f7e29209805389cd81fd11e56d74f"><code>1fdaa0d</code></a>
perf(no-unnecessary-type-assertion): reject incompatible types first (<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1181">#1181</a>)</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/364b23979e1189a760799738dadc59212e35e899"><code>364b239</code></a>
perf: speed up headless file-to-program assignment (<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1239">#1239</a>)</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/52500be212366860eb56155f6c3b7448feb4c140"><code>52500be</code></a>
perf: avoid singleton union type allocations in hot rules (<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1237">#1237</a>)</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/22b148ad8f78fa2e444bdd6553ae251c6b7d2f6b"><code>22b148a</code></a>
fix(no-unnecessary-condition): check nested logical expressions in
truthiness...</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/356609fdb6c2f118b6e4be22728505631deee5e2"><code>356609f</code></a>
fix(no-deprecated): detect deprecated aliases in object shorthand (<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1235">#1235</a>)</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/cbf39090fe63bed4a7283989995ea4fbf478ee46"><code>cbf3909</code></a>
fix(no-useless-default-assignment): handle tuples with rest elements (<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1223">#1223</a>)</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/7bd5c1180dd1d0ab13b7ed8a5dc5064bba204724"><code>7bd5c11</code></a>
fix: match package specifiers on whole path components (<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1225">#1225</a>)</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/6f2588382b3f039a6a020020c282117260938e44"><code>6f25883</code></a>
fix: preserve expression syntax when removing await (<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1233">#1233</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/oxc-project/tsgolint/compare/v7.0.2002...v7.0.2003">compare
view</a></li>
</ul>
</details>
<br />

Updates `vite` from 8.3.0 to 8.3.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vitejs/vite/releases">vite's
releases</a>.</em></p>
<blockquote>
<h2>v8.3.1</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> update all non-major dependencies (<a
href="https://redirect.github.com/vitejs/vite/issues/23482">#23482</a>)
(<a
href="https://github.com/vitejs/vite/commit/3c752c8932bc0599465ba4a6d8f44aaf1e934c3d">3c752c8</a>)</li>
<li><strong>deps:</strong> update all non-major dependencies (<a
href="https://redirect.github.com/vitejs/vite/issues/23537">#23537</a>)
(<a
href="https://github.com/vitejs/vite/commit/e8990c4d6101dfaca2654ed8ab4d0574ee920248">e8990c4</a>)</li>
<li><strong>deps:</strong> update rolldown-related dependencies (<a
href="https://redirect.github.com/vitejs/vite/issues/23483">#23483</a>)
(<a
href="https://github.com/vitejs/vite/commit/9aecbbfa5fb5da4b9981c099cb9746a9fd210806">9aecbbf</a>)</li>
<li>handle <code>server.ws: false</code> in mergeConfig (<a
href="https://redirect.github.com/vitejs/vite/issues/23511">#23511</a>)
(<a
href="https://github.com/vitejs/vite/commit/f68c0d5a28c96555431413e3e2cbe644337b087f">f68c0d5</a>)</li>
<li>merge <code>build.rolldownOptions.output.comments</code> correctly
(<a
href="https://redirect.github.com/vitejs/vite/issues/23514">#23514</a>)
(<a
href="https://github.com/vitejs/vite/commit/4aba8d8720e82e4c5b694a4b7877755a3f84fc57">4aba8d8</a>)</li>
<li><strong>optimizer:</strong> don't skip imports whose binding starts
with type (<a
href="https://redirect.github.com/vitejs/vite/issues/23540">#23540</a>)
(<a
href="https://github.com/vitejs/vite/commit/39330f489a0ae08923557f0ce10a307d6662a3f5">39330f4</a>)</li>
<li><strong>optimizer:</strong> resolve pending discovered dep
processing on close before init (<a
href="https://redirect.github.com/vitejs/vite/issues/23567">#23567</a>)
(<a
href="https://github.com/vitejs/vite/commit/5f894339d27882fedc86bf6b1076fa6d92e404f3">5f89433</a>)</li>
<li><strong>server:</strong> avoid reinitializing watcher when adding
file after server close (<a
href="https://redirect.github.com/vitejs/vite/issues/23572">#23572</a>)
(<a
href="https://github.com/vitejs/vite/commit/6f831f9b58ebda77638b514042ad8d160edfb928">6f831f9</a>)</li>
<li><strong>sourcemap:</strong> skip URL source roots when injecting
sources content (<a
href="https://redirect.github.com/vitejs/vite/issues/23519">#23519</a>)
(<a
href="https://github.com/vitejs/vite/commit/04fc30a4b91870e65a436b3420620a2e02a94a41">04fc30a</a>)</li>
</ul>
<h3>Miscellaneous Chores</h3>
<ul>
<li>merge prereleases in changelog (<a
href="https://redirect.github.com/vitejs/vite/issues/23466">#23466</a>)
(<a
href="https://github.com/vitejs/vite/commit/99bd9d1d46153fa939f4a304cc0177db42e28776">99bd9d1</a>)</li>
<li><strong>optimizer:</strong> add debug log when waiting for dep
before init (<a
href="https://redirect.github.com/vitejs/vite/issues/23566">#23566</a>)
(<a
href="https://github.com/vitejs/vite/commit/63567c73ac132e6384fef384e6b9f7e8d5a37fff">63567c7</a>)</li>
<li>update <code>optimizeDeps.include</code> comment (<a
href="https://redirect.github.com/vitejs/vite/issues/23489">#23489</a>)
(<a
href="https://github.com/vitejs/vite/commit/6a84c72100da4e4be4badb2d9a0026279b4df136">6a84c72</a>)</li>
</ul>
<h3>Code Refactoring</h3>
<ul>
<li>assets regexp use non-capture (<a
href="https://redirect.github.com/vitejs/vite/issues/23491">#23491</a>)
(<a
href="https://github.com/vitejs/vite/commit/f4b4431a2f9097fd9bbb7aaebbf1b63c4b54dea1">f4b4431</a>)</li>
<li>remove duplicate configurations (<a
href="https://redirect.github.com/vitejs/vite/issues/23532">#23532</a>)
(<a
href="https://github.com/vitejs/vite/commit/9abd99bfdd3117149d6faf87fc37bc9899b1c998">9abd99b</a>)</li>
<li>replace <code>find</code> with <code>some</code> (<a
href="https://redirect.github.com/vitejs/vite/issues/23554">#23554</a>)
(<a
href="https://github.com/vitejs/vite/commit/af7cdf6964f124f58d66037e808fe687654948e2">af7cdf6</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md">vite's
changelog</a>.</em></p>
<blockquote>
<h2><!-- raw HTML omitted --><a
href="https://github.com/vitejs/vite/compare/v8.3.0...v8.3.1">8.3.1</a>
(2026-09-24)<!-- raw HTML omitted --></h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> update all non-major dependencies (<a
href="https://redirect.github.com/vitejs/vite/issues/23482">#23482</a>)
(<a
href="https://github.com/vitejs/vite/commit/3c752c8932bc0599465ba4a6d8f44aaf1e934c3d">3c752c8</a>)</li>
<li><strong>deps:</strong> update all non-major dependencies (<a
href="https://redirect.github.com/vitejs/vite/issues/23537">#23537</a>)
(<a
href="https://github.com/vitejs/vite/commit/e8990c4d6101dfaca2654ed8ab4d0574ee920248">e8990c4</a>)</li>
<li><strong>deps:</strong> update rolldown-related dependencies (<a
href="https://redirect.github.com/vitejs/vite/issues/23483">#23483</a>)
(<a
href="https://github.com/vitejs/vite/commit/9aecbbfa5fb5da4b9981c099cb9746a9fd210806">9aecbbf</a>)</li>
<li>handle <code>server.ws: false</code> in mergeConfig (<a
href="https://redirect.github.com/vitejs/vite/issues/23511">#23511</a>)
(<a
href="https://github.com/vitejs/vite/commit/f68c0d5a28c96555431413e3e2cbe644337b087f">f68c0d5</a>)</li>
<li>merge <code>build.rolldownOptions.output.comments</code> correctly
(<a
href="https://redirect.github.com/vitejs/vite/issues/23514">#23514</a>)
(<a
href="https://github.com/vitejs/vite/commit/4aba8d8720e82e4c5b694a4b7877755a3f84fc57">4aba8d8</a>)</li>
<li><strong>optimizer:</strong> don't skip imports whose binding starts
with type (<a
href="https://redirect.github.com/vitejs/vite/issues/23540">#23540</a>)
(<a
href="https://github.com/vitejs/vite/commit/39330f489a0ae08923557f0ce10a307d6662a3f5">39330f4</a>)</li>
<li><strong>optimizer:</strong> resolve pending discovered dep
processing on close before init (<a
href="https://redirect.github.com/vitejs/vite/issues/23567">#23567</a>)
(<a
href="https://github.com/vitejs/vite/commit/5f894339d27882fedc86bf6b1076fa6d92e404f3">5f89433</a>)</li>
<li><strong>server:</strong> avoid reinitializing watcher when adding
file after server close (<a
href="https://redirect.github.com/vitejs/vite/issues/23572">#23572</a>)
(<a
href="https://github.com/vitejs/vite/commit/6f831f9b58ebda77638b514042ad8d160edfb928">6f831f9</a>)</li>
<li><strong>sourcemap:</strong> skip URL source roots when injecting
sources content (<a
href="https://redirect.github.com/vitejs/vite/issues/23519">#23519</a>)
(<a
href="https://github.com/vitejs/vite/commit/04fc30a4b91870e65a436b3420620a2e02a94a41">04fc30a</a>)</li>
</ul>
<h3>Miscellaneous Chores</h3>
<ul>
<li>merge prereleases in changelog (<a
href="https://redirect.github.com/vitejs/vite/issues/23466">#23466</a>)
(<a
href="https://github.com/vitejs/vite/commit/99bd9d1d46153fa939f4a304cc0177db42e28776">99bd9d1</a>)</li>
<li><strong>optimizer:</strong> add debug log when waiting for dep
before init (<a
href="https://redirect.github.com/vitejs/vite/issues/23566">#23566</a>)
(<a
href="https://github.com/vitejs/vite/commit/63567c73ac132e6384fef384e6b9f7e8d5a37fff">63567c7</a>)</li>
<li>update <code>optimizeDeps.include</code> comment (<a
href="https://redirect.github.com/vitejs/vite/issues/23489">#23489</a>)
(<a
href="https://github.com/vitejs/vite/commit/6a84c72100da4e4be4badb2d9a0026279b4df136">6a84c72</a>)</li>
</ul>
<h3>Code Refactoring</h3>
<ul>
<li>assets regexp use non-capture (<a
href="https://redirect.github.com/vitejs/vite/issues/23491">#23491</a>)
(<a
href="https://github.com/vitejs/vite/commit/f4b4431a2f9097fd9bbb7aaebbf1b63c4b54dea1">f4b4431</a>)</li>
<li>remove duplicate configurations (<a
href="https://redirect.github.com/vitejs/vite/issues/23532">#23532</a>)
(<a
href="https://github.com/vitejs/vite/commit/9abd99bfdd3117149d6faf87fc37bc9899b1c998">9abd99b</a>)</li>
<li>replace <code>find</code> with <code>some</code> (<a
href="https://redirect.github.com/vitejs/vite/issues/23554">#23554</a>)
(<a
href="https://github.com/vitejs/vite/commit/af7cdf6964f124f58d66037e808fe687654948e2">af7cdf6</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vitejs/vite/commit/39ddf7ccf7e7469ff6a3ba37bca38c32ea804d6e"><code>39ddf7c</code></a>
release: v8.3.1 (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23573">#23573</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/f68c0d5a28c96555431413e3e2cbe644337b087f"><code>f68c0d5</code></a>
fix: handle <code>server.ws: false</code> in mergeConfig (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23511">#23511</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/6f831f9b58ebda77638b514042ad8d160edfb928"><code>6f831f9</code></a>
fix(server): avoid reinitializing watcher when adding file after server
close...</li>
<li><a
href="https://github.com/vitejs/vite/commit/04fc30a4b91870e65a436b3420620a2e02a94a41"><code>04fc30a</code></a>
fix(sourcemap): skip URL source roots when injecting sources content (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23519">#23519</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/5f894339d27882fedc86bf6b1076fa6d92e404f3"><code>5f89433</code></a>
fix(optimizer): resolve pending discovered dep processing on close
before ini...</li>
<li><a
href="https://github.com/vitejs/vite/commit/63567c73ac132e6384fef384e6b9f7e8d5a37fff"><code>63567c7</code></a>
chore(optimizer): add debug log when waiting for dep before init (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23566">#23566</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/e8990c4d6101dfaca2654ed8ab4d0574ee920248"><code>e8990c4</code></a>
fix(deps): update all non-major dependencies (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23537">#23537</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/af7cdf6964f124f58d66037e808fe687654948e2"><code>af7cdf6</code></a>
refactor: replace <code>find</code> with <code>some</code> (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23554">#23554</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/39330f489a0ae08923557f0ce10a307d6662a3f5"><code>39330f4</code></a>
fix(optimizer): don't skip imports whose binding starts with type (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23540">#23540</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/9abd99bfdd3117149d6faf87fc37bc9899b1c998"><code>9abd99b</code></a>
refactor: remove duplicate configurations (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23532">#23532</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vitejs/vite/commits/v8.3.1/packages/vite">compare
view</a></li>
</ul>
</details>
<br />

Updates `vitest` from 5.0.1 to 5.0.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vitest-dev/vitest/releases">vitest's
releases</a>.</em></p>
<blockquote>
<h2>v5.0.2</h2>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li>Bind <code>process</code> in case global is overwritten  -  by <a
href="https://github.com/AriPerkkio"><code>@​AriPerkkio</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11343">vitest-dev/vitest#11343</a>
<a href="https://github.com/vitest-dev/vitest/commit/0b79231ad"><!-- raw
HTML omitted -->(0b792)<!-- raw HTML omitted --></a></li>
<li><strong>detect-async-leaks</strong>:
<ul>
<li>Ignore <code>process.stdio</code> handles  -  by <a
href="https://github.com/AriPerkkio"><code>@​AriPerkkio</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11333">vitest-dev/vitest#11333</a>
<a href="https://github.com/vitest-dev/vitest/commit/0fd6b9790"><!-- raw
HTML omitted -->(0fd6b)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>expect</strong>:
<ul>
<li>Fix <code>toMatchObject</code> with asymmetric matchers  -  by <a
href="https://github.com/ShreeBohara"><code>@​ShreeBohara</code></a>,
<strong>Claude Opus 5</strong>, <a
href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a>,
<strong>Hiroshi Ogawa</strong> and <strong>Codex (GPT-5)</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11100">vitest-dev/vitest#11100</a>
<a href="https://github.com/vitest-dev/vitest/commit/42523289e"><!-- raw
HTML omitted -->(42523)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>jsdom</strong>:
<ul>
<li>Fix <code>Request</code> with <code>Blob</code> body on jsdom 28+
 -  by <a
href="https://github.com/harshit-d3v"><code>@​harshit-d3v</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/11295">vitest-dev/vitest#11295</a>
<a href="https://github.com/vitest-dev/vitest/commit/d1c3ecc93"><!-- raw
HTML omitted -->(d1c3e)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>reporter</strong>:
<ul>
<li><code>agent</code> to respect <code>--silent</code>  -  by <a
href="https://github.com/Raj4478"><code>@​Raj4478</code></a> and <a
href="https://github.com/AriPerkkio"><code>@​AriPerkkio</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11271">vitest-dev/vitest#11271</a>
<a href="https://github.com/vitest-dev/vitest/commit/5b95efb6d"><!-- raw
HTML omitted -->(5b95e)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>reporters</strong>:
<ul>
<li>Handle concurrent <code>createReport</code> calls  -  by <a
href="https://github.com/7rulnik"><code>@​7rulnik</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11278">vitest-dev/vitest#11278</a>
<a href="https://github.com/vitest-dev/vitest/commit/e8e556ff7"><!-- raw
HTML omitted -->(e8e55)<!-- raw HTML omitted --></a></li>
<li><code>hanging-process</code> to use ESM entrypoint  -  by <a
href="https://github.com/AriPerkkio"><code>@​AriPerkkio</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11316">vitest-dev/vitest#11316</a>
<a href="https://github.com/vitest-dev/vitest/commit/4e91e5668"><!-- raw
HTML omitted -->(4e91e)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>spy</strong>:
<ul>
<li>Fix stack overflow when spying <code>Set.prototype.add</code>  -  by
<a href="https://github.com/fengmk2"><code>@​fengmk2</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11299">vitest-dev/vitest#11299</a>
<a href="https://github.com/vitest-dev/vitest/commit/a0a939653"><!-- raw
HTML omitted -->(a0a93)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>ui</strong>:
<ul>
<li>Persist authentication cookie beyond current browser session  -  by
<a href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a>,
<strong>Hiroshi Ogawa</strong> and <strong>OpenCode
(gpt-5.6-sol)</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11066">vitest-dev/vitest#11066</a>
<a href="https://github.com/vitest-dev/vitest/commit/f88195e16"><!-- raw
HTML omitted -->(f8819)<!-- raw HTML omitted --></a></li>
</ul>
</li>
</ul>
<h5>    <a
href="https://github.com/vitest-dev/vitest/compare/v5.0.1...v5.0.2">View
changes on GitHub</a></h5>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vitest-dev/vitest/commit/428e2e5043c64635b6b157358bde2fdeaa7b6b3a"><code>428e2e5</code></a>
chore: release v5.0.2 (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11357">#11357</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/0b79231ad7897f03de17940ef16684b63aa217fe"><code>0b79231</code></a>
fix: bind <code>process</code> in case global is overwritten (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11343">#11343</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/597df569aba3e8b24c9ad231aacd3cf641ac3bdf"><code>597df56</code></a>
docs: correct stale config defaults (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11354">#11354</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/ea1c44fb581978421f9f0901ce8c635970ea72fb"><code>ea1c44f</code></a>
docs: <code>sequence.setupFiles</code> default is <code>'list'</code>
(<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11351">#11351</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/0fd6b97902bc828d489385e0a28b82515f57b7cf"><code>0fd6b97</code></a>
fix(detect-async-leaks): ignore <code>process.stdio</code> handles (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11333">#11333</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/4e91e56687de43427fbb664d86a63438ca73b681"><code>4e91e56</code></a>
fix(reporters): <code>hanging-process</code> to use ESM entrypoint (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11316">#11316</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/1a57929a49fb6fb2db02b47e56c4677ca5ae1704"><code>1a57929</code></a>
docs(browser): fix locators.exact default (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11338">#11338</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/5b95efb6dfe378dc6fc8380f5b1e96832f019a5d"><code>5b95efb</code></a>
fix(reporter): <code>agent</code> to respect <code>--silent</code> (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11271">#11271</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/f58a209779ffd3007006481d0c9da0099d5226e6"><code>f58a209</code></a>
docs: correct benchmark.exclude and watch defaults (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11268">#11268</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/d1c3ecc932dcb4cd50420c54aa1f7fa3051deac7"><code>d1c3ecc</code></a>
fix(jsdom): fix <code>Request</code> with <code>Blob</code> body on
jsdom 28+ (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11295">#11295</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/vitest">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-02 22:37:49 -04:00
dependabot[bot] b7d04a1c3e build(deps): bump the gh-actions group with 3 updates (#1415)
Bumps the gh-actions group with 3 updates:
[github/codeql-action/init](https://github.com/github/codeql-action),
[github/codeql-action/autobuild](https://github.com/github/codeql-action)
and
[github/codeql-action/analyze](https://github.com/github/codeql-action).

Updates `github/codeql-action/init` from 4.38.1 to 4.38.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/init's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.2</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/init's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.2 - 24 Sept 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
<h2>4.38.1 - 18 Sept 2026</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2"><code>2892aa5</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4168">#4168</a>
from github/update-v4.38.2-a6ef2c96f</li>
<li><a
href="https://github.com/github/codeql-action/commit/8ad03a333eb88de8ad6833eda208d0fc51a9c571"><code>8ad03a3</code></a>
Trigger workflows</li>
<li><a
href="https://github.com/github/codeql-action/commit/98af865db5041cee73c7185896319367f8c0adf2"><code>98af865</code></a>
Update changelog for v4.38.2</li>
<li><a
href="https://github.com/github/codeql-action/commit/a6ef2c96fc0e37d0b44fb2bd0b32db4bcb89ae24"><code>a6ef2c9</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4156">#4156</a>
from github/mario-campos/fix-validate-cmd</li>
<li><a
href="https://github.com/github/codeql-action/commit/1ef28a1b7603ca158fd774d1ab328cbd6a40b84b"><code>1ef28a1</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4166">#4166</a>
from github/dependabot/github_actions/dot-github/wor...</li>
<li><a
href="https://github.com/github/codeql-action/commit/26cb08bab0037de74cc66ad9ec0dca31d6d9e8a7"><code>26cb08b</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4163">#4163</a>
from github/mbg/fix-getCommitOid-stubs</li>
<li><a
href="https://github.com/github/codeql-action/commit/f035ce3a985a1223a9f59fb719542598640160b2"><code>f035ce3</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4165">#4165</a>
from github/dependabot/npm_and_yarn/npm-minor-8eaed9...</li>
<li><a
href="https://github.com/github/codeql-action/commit/5e4e2550b48d7f3de205c9d752eb5176bf07f6d9"><code>5e4e255</code></a>
Rebuild</li>
<li><a
href="https://github.com/github/codeql-action/commit/b13f5f47d5398d0fb982942ced6fdfc4e3951804"><code>b13f5f4</code></a>
Bump ruby/setup-ruby</li>
<li><a
href="https://github.com/github/codeql-action/commit/c87fe5756c0c0bcd5e0005d2169945cfee9a232f"><code>c87fe57</code></a>
Rebuild</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/1c5b675653bb5c22dbe9b12b556ec555138e09fd...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/codeql-action/autobuild` from 4.38.1 to 4.38.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/autobuild's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.2</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/autobuild's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.2 - 24 Sept 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
<h2>4.38.1 - 18 Sept 2026</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2"><code>2892aa5</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4168">#4168</a>
from github/update-v4.38.2-a6ef2c96f</li>
<li><a
href="https://github.com/github/codeql-action/commit/8ad03a333eb88de8ad6833eda208d0fc51a9c571"><code>8ad03a3</code></a>
Trigger workflows</li>
<li><a
href="https://github.com/github/codeql-action/commit/98af865db5041cee73c7185896319367f8c0adf2"><code>98af865</code></a>
Update changelog for v4.38.2</li>
<li><a
href="https://github.com/github/codeql-action/commit/a6ef2c96fc0e37d0b44fb2bd0b32db4bcb89ae24"><code>a6ef2c9</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4156">#4156</a>
from github/mario-campos/fix-validate-cmd</li>
<li><a
href="https://github.com/github/codeql-action/commit/1ef28a1b7603ca158fd774d1ab328cbd6a40b84b"><code>1ef28a1</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4166">#4166</a>
from github/dependabot/github_actions/dot-github/wor...</li>
<li><a
href="https://github.com/github/codeql-action/commit/26cb08bab0037de74cc66ad9ec0dca31d6d9e8a7"><code>26cb08b</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4163">#4163</a>
from github/mbg/fix-getCommitOid-stubs</li>
<li><a
href="https://github.com/github/codeql-action/commit/f035ce3a985a1223a9f59fb719542598640160b2"><code>f035ce3</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4165">#4165</a>
from github/dependabot/npm_and_yarn/npm-minor-8eaed9...</li>
<li><a
href="https://github.com/github/codeql-action/commit/5e4e2550b48d7f3de205c9d752eb5176bf07f6d9"><code>5e4e255</code></a>
Rebuild</li>
<li><a
href="https://github.com/github/codeql-action/commit/b13f5f47d5398d0fb982942ced6fdfc4e3951804"><code>b13f5f4</code></a>
Bump ruby/setup-ruby</li>
<li><a
href="https://github.com/github/codeql-action/commit/c87fe5756c0c0bcd5e0005d2169945cfee9a232f"><code>c87fe57</code></a>
Rebuild</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/1c5b675653bb5c22dbe9b12b556ec555138e09fd...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/codeql-action/analyze` from 4.38.1 to 4.38.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/analyze's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.2</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/analyze's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.2 - 24 Sept 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
<h2>4.38.1 - 18 Sept 2026</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2"><code>2892aa5</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4168">#4168</a>
from github/update-v4.38.2-a6ef2c96f</li>
<li><a
href="https://github.com/github/codeql-action/commit/8ad03a333eb88de8ad6833eda208d0fc51a9c571"><code>8ad03a3</code></a>
Trigger workflows</li>
<li><a
href="https://github.com/github/codeql-action/commit/98af865db5041cee73c7185896319367f8c0adf2"><code>98af865</code></a>
Update changelog for v4.38.2</li>
<li><a
href="https://github.com/github/codeql-action/commit/a6ef2c96fc0e37d0b44fb2bd0b32db4bcb89ae24"><code>a6ef2c9</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4156">#4156</a>
from github/mario-campos/fix-validate-cmd</li>
<li><a
href="https://github.com/github/codeql-action/commit/1ef28a1b7603ca158fd774d1ab328cbd6a40b84b"><code>1ef28a1</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4166">#4166</a>
from github/dependabot/github_actions/dot-github/wor...</li>
<li><a
href="https://github.com/github/codeql-action/commit/26cb08bab0037de74cc66ad9ec0dca31d6d9e8a7"><code>26cb08b</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4163">#4163</a>
from github/mbg/fix-getCommitOid-stubs</li>
<li><a
href="https://github.com/github/codeql-action/commit/f035ce3a985a1223a9f59fb719542598640160b2"><code>f035ce3</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4165">#4165</a>
from github/dependabot/npm_and_yarn/npm-minor-8eaed9...</li>
<li><a
href="https://github.com/github/codeql-action/commit/5e4e2550b48d7f3de205c9d752eb5176bf07f6d9"><code>5e4e255</code></a>
Rebuild</li>
<li><a
href="https://github.com/github/codeql-action/commit/b13f5f47d5398d0fb982942ced6fdfc4e3951804"><code>b13f5f4</code></a>
Bump ruby/setup-ruby</li>
<li><a
href="https://github.com/github/codeql-action/commit/c87fe5756c0c0bcd5e0005d2169945cfee9a232f"><code>c87fe57</code></a>
Rebuild</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/1c5b675653bb5c22dbe9b12b556ec555138e09fd...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-02 22:36:26 -04:00
CaliBrain 119d3374e3 fix(downloads): reconcile downloads a restart interrupted (#1423) 2026-10-02 22:35:09 -04:00
HeihoffJandClaude Opus 5.5 95d9f1da57 fix(sabnzbd): prefetch NZBs served from the indexer's own domain (#1416)
Indexers often serve NZB downloads from a different host than their API
(e.g. file.indexer.example for indexer.example/api). The exact-origin
check added in #967 rejected those, so SABnzbd silently fell back to
addurl.

Trust any host in the configured indexer's registrable domain, using the
Public Suffix List so shared suffixes like co.uk or duckdns.org never
widen trust. Scheme and port must still match, IP literals and
single-label hosts still require an exact match, and the Prowlarr API
key header is unchanged.

This closes this issue:
https://github.com/calibrain/shelfmark/issues/1411 

Disclaimer: Implemented by Claude and Co-Authored by me. Tested and
verified by me alone (Why is it always this way around and not the
other)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-02 22:25:36 -04:00
splitsec2andCaliBrain 8392b43dd3 fix(downloads): reconcile downloads a restart interrupted (#1409)
I found this while grabbing new books and working on my fork. I
redeployed the container while downloads were running, and it left a
mess in my queue. It's an edge case, but a few rows were stuck until I
cleared them by hand.

The download queue lives in memory, so stopping the process with a
download in flight leaves its history row "active" and its request
"queued", with nothing working on either. The activity API shows that
row as "Interrupted" when it's read, but nothing is stored and nothing
looks at it again. Upstream only reopens an errored request when no
manual retry is offered, and an interrupted row always offers one, so
the request just sits there.

This closes those rows out once at startup, before the coordinator
starts, as an error with the message "Interrupted". The retry payload
stays, so the manual retry still works. A request whose download was
queued in the last 24 hours goes back to pending through
`reopen_failed_request`. Older ones get closed out but their requests
are left alone, because I didn't think a startup should reopen a backlog
or fill an admin's approval queue with old requests. A request that
already arrived is left alone, and running it twice changes nothing.

It assumes a single worker process, which `entrypoint.sh` already sets.

On my install the first start after deploying it closed 53 rows that had
been orphaned for nine days. Tests are in
`tests/core/test_startup_reconcile.py`, and the full suite passes
locally.

If the 24 hour window feels off, or you'd rather handle this another
way, I'm happy to change it or drop the PR.

Co-authored-by: CaliBrain <calibrain@l4n.xyz>
2026-10-02 22:23:28 -04:00
Evan KazakinandEvan Kazakin 7888217380 feat(download): add Remove & Delete Files torrent completion action (#1401)
Closes #1027

## Summary

- add a **Remove & Delete Files** (`remove_and_delete`) option to the
Torrent Completion Action setting
- after a successful import, remove the torrent and ask the client to
delete its downloaded data (`delete_files=True`), matching what the
usenet "move" flow already does
- clarify the setting description so it says **Remove** keeps the
downloaded files (raised in the issue comments)
- regenerate the `PROWLARR_TORRENT_ACTION` entry in
`docs/environment-variables.md`

## Behavior

The deletion runs from `post_process_cleanup`, the same place as the
existing Remove and Change Category actions, so it only happens after
output transfer and post-processing have succeeded. At that point every
file has already been copied or hardlinked into the library, and
transfer size checks have passed. A failed import never removes or
deletes anything. The torrent client deletes its own data, so Shelfmark
does not delete paths itself and remote path mappings are not involved.
Keep, Remove, and Change Category behave as before, and Keep is still
the default.

If a request matched a completed torrent that was already in the client,
this option deletes that torrent's data too. That is the same scope the
existing Remove action already applies to.

## Validation

- `make python-checks` (ruff check, ruff format, basedpyright on backend
and tests, vulture): passed
- `make python-test`: 3363 passed, 5 skipped, 9 failed. All 9 are in
`tests/config/test_entrypoint_permissions.py` and happen because macOS
`/bin/bash` 3.2 does not support `${1,,}` in `entrypoint.sh`. They do
not touch this change.
- new tests in `tests/prowlarr/test_handler.py`:
- Remove passes `delete_files=False` and Remove & Delete Files passes
`delete_files=True`
  - a failed import with Remove & Delete Files does not call the client
  - the delete case fails without the handler change
- manual smoke run: `PROWLARR_TORRENT_ACTION=remove_and_delete` set
through real config loading, with a stub client that deletes its folder.
The torrent folder was deleted and the hardlinked library file stayed
intact.
- pre-commit hooks (prek) passed

---------

Co-authored-by: Evan Kazakin <evan@Evans-MacBook-Pro.local>
2026-10-02 22:15:17 -04:00
splitsec2 d99e9d7c4f fix(download): remove a cancelled torrent that never started (#1421)
Cancelling a torrent download leaves the torrent in the client.
`_safe_remove_download` documents the rule: "torrents: never remove or
delete client data (avoid breaking seeding)". That makes sense for a
torrent that has data. A torrent that is still at 0% has nothing to seed
and nothing to resume, and leaving it behind holds a download slot in
qBittorrent's queue or sits there as a dead entry.

I hit this on a qBittorrent that is shared with Sonarr, Radarr and
Lidarr and has a download limit. Shelfmark cancelled downloads that were
queued (#1420) and left them in the client. Three torrents that never
fetched metadata held every active slot, and each torrent added after
them waited behind them. Removing those by hand freed the slots.

This removes the torrent and its files when a download is cancelled,
Shelfmark added the torrent, and the client reports 0% progress. A
torrent with any data is left alone as before. So is one that was
already in the client when the download started, since Shelfmark didn't
add it. If the removal fails it is logged and the cancel carries on.

Tests cover removal at 0% for a queued and a downloading torrent,
leaving one that has data, leaving one the user already had, and a
failing removal. The full suite passes, and I broke each rule on purpose
to check a test catches it.

This changes a rule you wrote down, so I've kept it apart from the queue
fix. If you'd rather have it as a setting, or only remove a torrent that
is still queued or fetching metadata, I'm happy to rework it.
2026-10-02 22:12:51 -04:00
splitsec2 88f73e3bc3 fix(download): do not cancel a queued torrent as stalled (#1420)
qBittorrent only runs a few downloads at once (`max_active_downloads`
defaults to 3) and holds the rest as `queuedDL`. Shelfmark's stall timer
cancels a download after five minutes without a changed status or
progress. A queued torrent reports "Queued" on every poll, so it looks
idle, and Shelfmark cancels a download that was only waiting for a slot.

I run Shelfmark against the same qBittorrent that Sonarr, Radarr and
Lidarr use, which I assume is a common setup. Their torrents and
Shelfmark's share one limit, so anything that fills the slots makes
Shelfmark's torrent wait. In my case three torrents that never fetched
metadata held every slot. I'd expect a busy Sonarr queue to hold them
the same way, but I haven't reproduced that. Once the stall timer had
cancelled the waiting downloads they stayed in the client, still queued
behind the same blockers. On my instance 10 AudioBookBay downloads were
cancelled while qBittorrent still had them queued.

This changes the torrent poll loop. When the client reports a queued
torrent, it asks for an activity grace (the mechanism `html_get_page`
already uses for protection bypasses) and releases it as soon as the
torrent leaves the queue. The grace is renewed every ten minutes and
stops at two hours, so a queue that never moves still ends. A torrent
that is downloading and moving is timed as before until the new window
below applies.

The second commit sets the stall message before the cancel runs. The
terminal hook copies the message into the history row, and it was set
afterwards, so a download the timer ended was recorded with the last
poll's "Queued". That left no way to tell it apart from a person
cancelling.

The last two commits are about slow torrents. The timer only counts a
change in progress, so a torrent that needs more than five minutes to
fetch metadata or find its first peer is cancelled before it has any
progress to count, and one that moves a few megabytes at a time can be
cancelled between bursts. I hit this with a torrent that had a single
peer. A torrent now gets one 15 minute window the first time it is seen
outside the queue, and each step forward in progress renews it. One that
makes no progress for 15 minutes is still cancelled, so a dead torrent
now takes about 15 minutes to end instead of five. That trade is the
part I'm least sure about, so the number is easy to change.

Tests cover the grace being requested once, released when the torrent
starts, renewed, and capped, the order of the message and the cancel,
and the start and movement windows. The full suite passes, and I broke
each rule on purpose to check a test catches it.

The two hour ceiling is a guess. If you'd rather have a setting for it,
or a different number, I'm happy to change it.
2026-10-02 22:12:25 -04:00
CaliBrain bac0b93566 fix: keep https:// for qBittorrent and hide release sources from non-admins (#1422)
qBittorrent over HTTPS (#1417)

qbittorrent-api ignores the scheme in `host` and probes HTTP and HTTPS
itself. When the HTTPS probe fails, for instance on a certificate
Shelfmark doesn't trust, it falls back to plain HTTP against the TLS
port, and a reverse proxy answers "400 The plain HTTP request was sent
to HTTPS port". The download client and the Test Connection button now
pass FORCE_SCHEME_FROM_HOST for https:// URLs, so the configured scheme
is used as-is and a certificate problem is reported as one. http:// and
bare host:port URLs keep the probe: normalization adds http:// to a bare
host, and the probe follows a proxy's redirect to HTTPS.

Release sources leaked to non-admins (#1418)

A download queued from an approved request carries the release an admin
picked, and the requester could read it from their own activity feed:
the request's release_data (source_id, indexer, info URL, torrent
attributes), the download's full server path, and the download id
itself, which for Prowlarr is "<indexer id>:<guid>" and for a private
tracker is a URL into it. That id keys every status payload, the
/api/localdownload query and the cover proxy URL, so hiding
release_data alone would not have closed the leak.

For non-admin viewers:
- request rows keep only the release fields the activity cards display
- download_path is reduced to the file name, which the browser download
  reveals anyway
- request-linked downloads are addressed by an opaque id (a keyed HMAC
  of the task id) in the snapshot, history, /api/status, queue order,
  active downloads, dismissed keys, cover URLs and the websocket status
  and progress events. Routes that take a download id translate it
  back, searching only the caller's own downloads.

Downloads a user queued directly keep their real id: the user picked
that release from search results that already showed it, and the
release list matches its buttons to the queue by that id. Admin views
are unchanged. The activity sidebar now links a fulfilled request to
its download by request_id instead of release_data.source_id.

Closes #1417
Closes #1418
2026-10-02 20:38:58 -04:00
splitsec2andMichael Ngo fcdc2dfb69 perf(docker): stop shipping build-only content in the runtime image (#1404)
While checking why each build took so much disk on my server, I looked
at what's actually in the runtime image. A good share of it is there for
the build and never used after.

**The C toolchain.** The base stage installs `gcc`, `g++`, `libffi-dev`
and `python3-dev` for building C extensions, and they stay in both the
full and lite images, which is 290 MB installed. Nothing gets compiled
any more. Every compiled dependency in `uv.lock` (cffi, gevent,
greenlet, zope-interface) ships a cp314 manylinux wheel for both amd64
and arm64, and the packages that only have an sdist are pure Python.
`python3-dev` was also pulling Debian's `libpython3.13` into a 3.14
image.

**The build context.** `COPY . .` puts the whole context into `/app`, so
`tests/`, `docs/` and the frontend source ship too. `.dockerignore` now
leaves out the trees nothing reads at runtime. `src/` can't go in
`.dockerignore` because the frontend-builder stage needs it, so both
final stages remove it after the built dist is copied. The venv's own
`pip` goes as well, since uv seeds one and nothing installs at runtime.
This part is @DrNgo's work from his fork, and the commit carries his
name.

Measured by building both targets on native amd64 and arm64 runners:

|  | amd64 full | amd64 lite | arm64 full | arm64 lite |
|---|---|---|---|---|
| before | 1,532 MB | 589 MB | 1,528 MB | 619 MB |
| after | 1,238 MB | 295 MB | 1,251 MB | 342 MB |

Compressed, the full image goes from 617 MB to 504 MB on amd64.

On both architectures the image builds, reaches healthy, and Chromium
starts the same way the bypasser starts it (xvfb,
`_get_browser_args()`). The Python suite passes too. It's also running
on my own install now.

If a dependency ever needs compiling again, the clean fix is a builder
stage that builds the wheel and copies it in, rather than putting the
toolchain back in the runtime image. Happy to add that now if you'd
rather have it in place.

---------

Co-authored-by: Michael Ngo <michaeln56@gmail.com>
2026-10-02 16:30:10 -04:00
vansh 41a4df01c4 fix: hand DiamWall 513 challenges to the bypasser (#1400)
## Summary
Recognize DiamWall interstitials in both the HTTP retry path and the
internal browser helper. HTTP 513 challenge responses go directly to the
configured bypasser, while ordinary 513 responses keep the existing
error behavior.

Fixes #1386

## Testing
- `uv run --frozen --extra browser pytest -q -n 0
tests/download/test_http_challenge_513.py
tests/bypass/test_internal_bypasser.py`: 27 passed
- Ruff lint and format checks passed
2026-10-02 16:26:04 -04:00
CaliBrain d2b4a0290e fix(ui): contain the result count added in #1362 (#1363)
Two regressions from the Anna's Archive search stats feature.

The release modal's count block declared flex-1, so it competed with the
tab strip's own flex-1 and took half the row - including on tabs whose
source reports no total, where it renders nothing at all (only
direct_download exposes total_results). Measured on a 1024px modal with
six sources, the scrollable tab strip fell from 846px to 423px against
601px of tabs; at 375px with two sources it fell from 197px to 44px. It
is now flex-none, and hidden below sm: the label alone is ~150px, which
the full-screen mobile modal cannot spare. Remeasured at 693px on
desktop and back to the pre-feature 197px on mobile.

directTotalResults is only ever written on the direct-mode branch, and
neither the universal branch nor App's resetSearchResultsState cleared
it, so a count from an earlier direct search survived a mode switch and
rendered over unrelated universal results. Both universal-branch reset
blocks now clear it.
v1.4.0
2026-09-25 21:22:42 -04:00
CaliBrain 893f7bdb92 fix(mam): keep the session ID on MAM and rerun Prowlarr's exact search (#1399)
Follow-up to #1390.

- The origin came from each result's infoUrl, matched by a regex that
did
  not check the host, and the mam_id cookie had no domain. Any Prowlarr
  indexer returning a URL like https://evil.example?myanonamouse.net/t/1
  sent the session ID to evil.example. Requests now always go to
https://www.myanonamouse.net (Prowlarr's only MAM URL), with the cookie
  as a header and redirects off. Only results from Prowlarr's
  MyAnonamouse indexer are looked up, and their URLs must be on
  myanonamouse.net.
- The lookup searched every category and read one page, so for common
  titles most of Prowlarr's results were missed (a "Dune" audiobook
  search: 56 audiobooks on the first 100 of 328 matches). It now reruns
  Prowlarr's exact search: the same query clean-up, the MAM main
  categories behind the Torznab categories searched (13/15/16 for
  audiobooks, 14 for e-books, all once expanded), and the MAM indexer's
  own search type, search-in options and languages. Further pages are
  read while IDs are missing, page 1 of every title first, at most 4
  requests per search.
- Failed requests back off for 1, 2, 4 ... up to 30 minutes. The 10th
  consecutive failure stops enrichment until Test MAM Session passes,
  the session ID changes, or Shelfmark restarts.
- The detail cache prunes expired entries instead of growing for as long
  as Shelfmark runs.
2026-09-25 21:21:54 -04:00
dependabot[bot]andCaliBrain efb1f66bc3 build(deps): bump astral-sh/uv from 0.12.16 to 0.12.19 in the docker-base-image-digests group across 1 directory (#1392)
> [!WARNING]
> Cooldown could not be applied because no publication date was
available from the registry.
>

Bumps the docker-base-image-digests group with 1 update in the /
directory: [astral-sh/uv](https://github.com/astral-sh/uv).

Updates `astral-sh/uv` from 0.12.16 to 0.12.19
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/uv/releases">astral-sh/uv's
releases</a>.</em></p>
<blockquote>
<h2>0.12.19</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-24.</p>
<h3>Python</h3>
<ul>
<li>Add PyPy 3.11.16 and 3.12.14 (<a
href="https://redirect.github.com/astral-sh/uv/pull/21847">#21847</a>)</li>
<li>Update GraalPy 3.13.0 to build 25.4.4 (<a
href="https://redirect.github.com/astral-sh/uv/pull/21847">#21847</a>)</li>
</ul>
<h3>Enhancements</h3>
<ul>
<li>Format upload URLs with backticks in <code>uv publish</code> errors
(<a
href="https://redirect.github.com/astral-sh/uv/pull/21934">#21934</a>)</li>
</ul>
<h3>Preview features</h3>
<ul>
<li>Run build-backend hooks with lazy imports on CPython 3.15 and later
using the <code>build-lazy-imports</code> preview feature (<a
href="https://redirect.github.com/astral-sh/uv/pull/21967">#21967</a>)</li>
<li>Omit unused resolution settings from <code>uv.lock</code> and ignore
changes to them when checking lockfile freshness with the
<code>resolution-inputs</code> preview feature (<a
href="https://redirect.github.com/astral-sh/uv/pull/21913">#21913</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Preserve signed and encoded query parameters in direct-URL metadata
to avoid reinstalling unchanged packages (<a
href="https://redirect.github.com/astral-sh/uv/pull/21971">#21971</a>)</li>
<li>Recognize <code>1.0.0</code> as satisfying <code>===1</code> during
installed-package checks, matching resolution (<a
href="https://redirect.github.com/astral-sh/uv/pull/21931">#21931</a>)</li>
<li>Avoid collisions between Git checkout readiness markers and
<code>.ok</code> files in dependencies (<a
href="https://redirect.github.com/astral-sh/uv/pull/21891">#21891</a>)</li>
<li>Preserve always-false <code>python_version</code> markers when
parsing their serialized form (<a
href="https://redirect.github.com/astral-sh/uv/pull/21939">#21939</a>)</li>
</ul>
<h3>Rust API</h3>
<ul>
<li>Restore the public <code>FlatDistributions</code> export and its
<code>BTreeMap</code> conversion for downstream resolvers (<a
href="https://redirect.github.com/astral-sh/uv/pull/21965">#21965</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Make individual preview-feature reference entries linkable by name
(<a
href="https://redirect.github.com/astral-sh/uv/pull/21950">#21950</a>)</li>
</ul>
<h2>Install uv 0.12.19</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/uv/releases/download/0.12.19/uv-installer.sh
| sh
</code></pre>
<h3>Install prebuilt binaries via powershell script</h3>
<pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c &quot;irm
https://releases.astral.sh/github/uv/releases/download/0.12.19/uv-installer.ps1
| iex&quot;
</code></pre>
<h2>Download uv 0.12.19</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/uv/blob/main/CHANGELOG.md">astral-sh/uv's
changelog</a>.</em></p>
<blockquote>
<h2>0.12.19</h2>
<p>Released on 2026-09-24.</p>
<h3>Python</h3>
<ul>
<li>Add PyPy 3.11.16 and 3.12.14 (<a
href="https://redirect.github.com/astral-sh/uv/pull/21847">#21847</a>)</li>
<li>Update GraalPy 3.13.0 to build 25.4.4 (<a
href="https://redirect.github.com/astral-sh/uv/pull/21847">#21847</a>)</li>
</ul>
<h3>Enhancements</h3>
<ul>
<li>Format upload URLs with backticks in <code>uv publish</code> errors
(<a
href="https://redirect.github.com/astral-sh/uv/pull/21934">#21934</a>)</li>
</ul>
<h3>Preview features</h3>
<ul>
<li>Run build-backend hooks with lazy imports on CPython 3.15 and later
using the <code>build-lazy-imports</code> preview feature (<a
href="https://redirect.github.com/astral-sh/uv/pull/21967">#21967</a>)</li>
<li>Omit unused resolution settings from <code>uv.lock</code> and ignore
changes to them when checking lockfile freshness with the
<code>resolution-inputs</code> preview feature (<a
href="https://redirect.github.com/astral-sh/uv/pull/21913">#21913</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Preserve signed and encoded query parameters in direct-URL metadata
to avoid reinstalling unchanged packages (<a
href="https://redirect.github.com/astral-sh/uv/pull/21971">#21971</a>)</li>
<li>Recognize <code>1.0.0</code> as satisfying <code>===1</code> during
installed-package checks, matching resolution (<a
href="https://redirect.github.com/astral-sh/uv/pull/21931">#21931</a>)</li>
<li>Avoid collisions between Git checkout readiness markers and
<code>.ok</code> files in dependencies (<a
href="https://redirect.github.com/astral-sh/uv/pull/21891">#21891</a>)</li>
<li>Preserve always-false <code>python_version</code> markers when
parsing their serialized form (<a
href="https://redirect.github.com/astral-sh/uv/pull/21939">#21939</a>)</li>
</ul>
<h3>Rust API</h3>
<ul>
<li>Restore the public <code>FlatDistributions</code> export and its
<code>BTreeMap</code> conversion for downstream resolvers (<a
href="https://redirect.github.com/astral-sh/uv/pull/21965">#21965</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Make individual preview-feature reference entries linkable by name
(<a
href="https://redirect.github.com/astral-sh/uv/pull/21950">#21950</a>)</li>
</ul>
<h2>0.12.18</h2>
<p>Released on 2026-09-22.</p>
<p>This release addresses <a
href="https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7">GHSA-2cv4-cqwr-gwf7</a>,
which is a path traversal weakness during wheel installation on Windows.
No other platforms are affected by this advisory.</p>
<h3>Enhancements</h3>
<ul>
<li>Add <code>--output-format json</code> to <code>uv pip install</code>
and <code>uv pip sync</code>, including for <code>--dry-run</code> and
<code>--check</code> (<a
href="https://redirect.github.com/astral-sh/uv/pull/21893">#21893</a>)</li>
<li>Add <code>--check</code> to <code>uv pip install</code> and <code>uv
pip sync</code> to report planned changes without modifying the
environment (<a
href="https://redirect.github.com/astral-sh/uv/pull/21844">#21844</a>)</li>
<li>Identify failures from <code>get_requires_for_build_*</code> hooks
correctly in build errors (<a
href="https://redirect.github.com/astral-sh/uv/pull/21881">#21881</a>)</li>
</ul>
<h3>Preview features</h3>
<ul>
<li>Validate build requirements for <code>uv build
--no-build-isolation</code> with <code>--preview-features
build-dependency-check</code>; use <code>--skip-dependency-check</code>
to opt out (<a
href="https://redirect.github.com/astral-sh/uv/pull/21880">#21880</a>)</li>
</ul>
<h3>Performance</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/uv/commit/bea138450f0e620a4ce5765b0e38cff7b9f0799f"><code>bea1384</code></a>
Bump version to 0.12.19 (<a
href="https://redirect.github.com/astral-sh/uv/issues/21975">#21975</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/299a93de4b94e754f260c673d2de456afbdd4fb7"><code>299a93d</code></a>
Sync latest Python releases (<a
href="https://redirect.github.com/astral-sh/uv/issues/21970">#21970</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/30de9e2cc92018c7c16a1ab66bb9b8341fbf0eff"><code>30de9e2</code></a>
Preserve query parameters in direct URL metadata (<a
href="https://redirect.github.com/astral-sh/uv/issues/21971">#21971</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/0e7433eee906fe81709c95c5bde556263367f21f"><code>0e7433e</code></a>
Filter distribution hashes in tests (<a
href="https://redirect.github.com/astral-sh/uv/issues/21941">#21941</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/c73db78f0b00580b3c67279b59b85153a9d0264d"><code>c73db78</code></a>
Omit unused runtime settings from lockfiles (<a
href="https://redirect.github.com/astral-sh/uv/issues/21913">#21913</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/ad123420aaa75b3bdbccf81496aaece8b9045b30"><code>ad12342</code></a>
Add a preview feature for lazy build backend imports (<a
href="https://redirect.github.com/astral-sh/uv/issues/21967">#21967</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/dd965a276182e2d46d80439feecd03216cc6643a"><code>dd965a2</code></a>
Restore <code>FlatDistributions</code> for downstream resolvers (<a
href="https://redirect.github.com/astral-sh/uv/issues/21965">#21965</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/214d7f677585fbb0bb46fadef890335e388641c0"><code>214d7f6</code></a>
Use Astra for PR security reviews (<a
href="https://redirect.github.com/astral-sh/uv/issues/21959">#21959</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/3db665232544183edcb80dd7077b8051b365e236"><code>3db6652</code></a>
Disable incremental compilation when publishing docs (<a
href="https://redirect.github.com/astral-sh/uv/issues/21955">#21955</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/e18f413b23bfe5f33bcc1a3a3de330e4716aedcf"><code>e18f413</code></a>
Reproduce editable project relocation failure (<a
href="https://redirect.github.com/astral-sh/uv/issues/21948">#21948</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/uv/compare/0.12.16...0.12.19">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: CaliBrain <calibrain@l4n.xyz>
2026-09-25 19:18:30 -04:00
a05e002305 feat: narrator, series and bitrate columns for MyAnonamouse results (#1390)
# feat: narrator, series and bitrate columns for MyAnonamouse results

Addresses #605 and #934 (narrator in the release list).

## Problem

Both requests were closed because the narrator isn't in Torznab results,
which is correct. Prowlarr's MyAnonamouse indexer reads `author_info`
but drops the `narrator_info` and `series_info` MAM returns next to it,
and neither Prowlarr's `ReleaseInfo` nor the Torznab output has a field
for them. Shelfmark's size tooltip already looks for a `narrator`
Torznab attribute, but nothing ever sends one.

When a book has several narrations, choosing one means going back and
forth between Shelfmark and the tracker.

## Approach

Optional, opt-in enrichment using the user's own MAM session (`mam_id`),
the same approach AudioBookRequest's MAM indexer uses:

1. After the Prowlarr search, releases whose info URL is
`…myanonamouse.net/t/<id>` are collected.
2. Shelfmark sends the same query text to MAM's JSON search
(`/tor/js/loadSearchJSONbasic.php`, normally one request, at most 3),
and matches torrents back to Prowlarr's results by torrent ID. The MAM
origin is taken from the result URL, so a custom Prowlarr MAM base URL
is respected, and the cookie is only ever sent to `*.myanonamouse.net`.
3. Adds `extra.narrator`, `extra.series` (`The Sun Eater #1`) and
`extra.bitrate` / `extra.bitrate_value`. MAM has no bitrate field, so
it's parsed from the uploader's free-text tags (`64 kbps`) and some
releases won't have one.

Lookups are cached per torrent for an hour, respect the existing
Prowlarr search deadline, go through the configured proxy
(`get_proxies`), and never fail the search: a 403, timeout or bad JSON
is logged and the list renders without the extra details.

## Changes

- **`release_sources/prowlarr/mam.py`** (new): small MAM client
(`search`, and `get_username` for the test button), `narrator_info` /
`series_info` / tags parsing, cached best-effort
`lookup_torrent_details()`. A 403 includes MAM's reply and a note about
the IP/ASN lock.
- **`release_sources/prowlarr/source.py`**: enrichment after the result
loop. Series, Narrator and Bitrate columns only when a MAM ID is
configured, since otherwise they would be empty for every row. A Torznab
`bitrate` attribute from other indexers is also mapped to
`extra.bitrate`.
- **`release_sources/prowlarr/settings.py`**: "MyAnonamouse Enrichment"
section with `PROWLARR_MAM_ID` (password field, env-overridable like
every setting) and a **Test MAM Session** button.
- **`release_sources/__init__.py`**: `ColumnSchema` gains optional
`setting_key` and `content_types`. The new `apply_column_visibility()`
drops gated columns and their grid tracks. Neither field is serialized.
- **`main.py`**: `/api/releases` applies `apply_column_visibility()`
with the request's content type and the user's effective settings.
- **`config/settings.py` / `users_settings.py`**: Search Mode › "Release
List Columns" with `SHOW_SERIES_COLUMN`, `SHOW_NARRATOR_COLUMN` and
`SHOW_BITRATE_COLUMN`, all default on and user-overridable. Narrator and
bitrate are audiobook-only, series shows for both. AudiobookBay's
existing bitrate column now follows the bitrate toggle.
- **Frontend**: text cells truncate with a hover title; the mobile info
line wraps and skips empty text/number cells so blank optional columns
don't leave orphan `·` separators; the size tooltip no longer lists
Bitrate twice.
- **Docs**: new `docs/myanonamouse-enrichment.md` (linked from the
index), and a regenerated `environment-variables.md`. The regeneration
also picked up a few pre-existing drifts from `main` (the Libgen
section, `AA_DEFAULT_SORT` default, a duplicate `BOOK_LANGUAGE` row). I
can drop those if you'd rather keep this diff focused.

## ⚠️ MAM sessions are IP/ASN-locked

MyAnonamouse locks each session to one IP or ASN. Reusing the session
Prowlarr (or a seedbox script) uses will often **403**. **A separate MAM
session for Shelfmark will likely be needed** when Shelfmark reaches MAM
from a different IP (another host, a VPN container, or a proxy in
Shelfmark's Network settings), or when the existing session is
ASN-locked to another network. The setting's description, the error
message and the new doc all say so.

## Testing

- `tests/prowlarr/test_mam_enrichment.py` (new, 19 tests): parsing
(narrator dedupe, multiple series, missing numbers, malformed JSON, tag
bitrate), lookup (stops once all IDs are found, cache, 403 and
connection errors return empty, expired deadline skips the request),
only MAM releases enriched, Torznab bitrate mapping, column config with
and without a MAM ID for audiobook and ebook, toggles, grid-track
removal, and gates not serialized.
- `tests/core/test_admin_users_api.py`: the curated search-preference
key list now includes the three toggles.
- Full `pytest -m "not integration and not e2e"` compared with an
upstream `main` worktree on the same machine: no new failures. The
remaining ~115 failures on both are Windows-only (tor/entrypoint shell
tests, path separators).
- `ruff check` / `ruff format --check` / `basedpyright` (0 errors) /
`vulture` on touched files; frontend `tsc --noEmit`, `oxlint`, `oxfmt
--check`, `vitest` (201 passed).
- Manually verified with a real MAM account on a Docker build of this
branch: the test button, then narrator, series and bitrate on
MyAnonamouse audiobook results.

No behavior change unless `PROWLARR_MAM_ID` is set, apart from the
bitrate toggle on AudiobookBay (default on, same as today).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: CaliBrain <calibrain@l4n.xyz>
2026-09-25 19:17:23 -04:00
dependabot[bot]andCaliBrain bb430dfdbc build(deps): bump seleniumbase from 4.54.9 to 4.54.10 in the python-deps group (#1382)
Bumps the python-deps group with 1 update:
[seleniumbase](https://github.com/seleniumbase/SeleniumBase).

Updates `seleniumbase` from 4.54.9 to 4.54.10
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/seleniumbase/SeleniumBase/releases">seleniumbase's
releases</a>.</em></p>
<blockquote>
<h2>4.54.10 - MCP Server: Patch 18</h2>
<h2>MCP Server: Patch 18</h2>
<ul>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/a010555082f7ef5d1568890c13177f6b60b78f98">Update
the MCP server</a>
--&gt; Make <code>manage_cookies</code> more secure.
--&gt; Update docstrings.</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/fae54471dee9f8925e46235075e8d250972bea10">Refresh
Python dependencies</a>
--&gt; <code>platformdirs</code></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>MCP Server: Patch 18 by <a
href="https://github.com/mdmintz"><code>@​mdmintz</code></a> in <a
href="https://redirect.github.com/seleniumbase/SeleniumBase/pull/4509">seleniumbase/SeleniumBase#4509</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/seleniumbase/SeleniumBase/compare/v4.54.9...v4.54.10">https://github.com/seleniumbase/SeleniumBase/compare/v4.54.9...v4.54.10</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/4c54cb7ffbc11b3a2cde4b85c81eb058b118504e"><code>4c54cb7</code></a>
Merge pull request <a
href="https://redirect.github.com/seleniumbase/SeleniumBase/issues/4509">#4509</a>
from seleniumbase/mcp-server-patch-18</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/df6fc937aae7e1a7f3bf058609f6e31edde38135"><code>df6fc93</code></a>
Version 4.54.10</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/fae54471dee9f8925e46235075e8d250972bea10"><code>fae5447</code></a>
Refresh Python dependencies</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/7cac7c15450feb08948c0f178e8abaad7633e037"><code>7cac7c1</code></a>
Update MCP server versioning</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/a010555082f7ef5d1568890c13177f6b60b78f98"><code>a010555</code></a>
Update the MCP server</li>
<li>See full diff in <a
href="https://github.com/seleniumbase/SeleniumBase/compare/v4.54.9...v4.54.10">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=seleniumbase&package-manager=uv&previous-version=4.54.9&new-version=4.54.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: CaliBrain <calibrain@l4n.xyz>
2026-09-25 19:17:08 -04:00
dependabot[bot]andCaliBrain c11bf99848 build(deps): bump the npm-deps group in /src/frontend with 7 updates (#1394)
Bumps the npm-deps group in /src/frontend with 7 updates:

| Package | From | To |
| --- | --- | --- |
|
[react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom)
| `7.18.3` | `7.18.4` |
|
[@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)
| `26.5.1` | `26.6.2` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) |
`6.35.1` | `6.37.0` |
| [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) |
`0.68.0` | `0.70.0` |
| [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) |
`1.83.0` | `1.85.0` |
| [oxlint-tsgolint](https://github.com/oxc-project/tsgolint) |
`7.0.2001` | `7.0.2002` |
|
[vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest)
| `5.0.0` | `5.0.1` |

Updates `react-router-dom` from 7.18.3 to 7.18.4
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/remix-run/react-router/blob/react-router-dom@7.18.4/packages/react-router-dom/CHANGELOG.md">react-router-dom's
changelog</a>.</em></p>
<blockquote>
<h2>v7.18.4</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies:
<ul>
<li><a
href="https://github.com/remix-run/react-router/releases/tag/react-router@7.18.4"><code>react-router@7.18.4</code></a></li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/remix-run/react-router/commit/1b1e0b0e79b21692ce907933475233babdd16e3e"><code>1b1e0b0</code></a>
Release v7.18.4 (<a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15498">#15498</a>)</li>
<li>See full diff in <a
href="https://github.com/remix-run/react-router/commits/react-router-dom@7.18.4/packages/react-router-dom">compare
view</a></li>
</ul>
</details>
<br />

Updates `@types/node` from 26.5.1 to 26.6.2
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node">compare
view</a></li>
</ul>
</details>
<br />

Updates `knip` from 6.35.1 to 6.37.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/webpro-nl/knip/releases">knip's
releases</a>.</em></p>
<blockquote>
<h2>Release 6.37.0</h2>
<ul>
<li>fix(graphql-codegen): mark near-operation-file outputs as entries,
not the documents directory (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2048">#2048</a>)
(06a68fcf99a90e559daeb0b8fb2d24e173124774) - thanks <a
href="https://github.com/RobHannay"><code>@​RobHannay</code></a>!</li>
<li>fix: enable JSX in the config loader (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/1959">#1959</a>)
(5b21dc9192f773613d1c5db8edf35f0a68820268) - thanks <a
href="https://github.com/addielaruee"><code>@​addielaruee</code></a>!</li>
<li>Match binaries only to their actual dependency providers
(c5bdb69ccbcb7e1056233f346d0ada3495d1013d)</li>
<li>Preserve executable references across package manager commands
(54af171638db22f5d903faae05c37c2ea6adc869)</li>
<li>Correct binary provider metadata in Relay fixtures
(e67dfcb96d055c27be9c8601e077656855bb632b)</li>
<li>Separate shell binary expectations from reporting exemptions
(resolve <a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2022">#2022</a>)
(c1d7d75a3529d9faff7f4c0df11dd0ca1bdfb149)</li>
<li>Respect npx no-install flags before the executable
(4237010c9a834eb8b04f4a528c76d10a5c38ee98)</li>
<li>Update dependencies (038ea179f7d6bf7ca43bc5daf553a68b13a9067c)</li>
<li>Remove npm auth check now that's in release-it
(4aaf77c58004ac64063a1982b98e53107c2ebe93)</li>
<li>Fix --format name resolution in the ESLint plugin (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2046">#2046</a>)
(1269e98bb700384811fadc124d69ea720832037e) - thanks <a
href="https://github.com/bytedoe"><code>@​bytedoe</code></a>!</li>
</ul>
<h2>Release 6.36.0</h2>
<ul>
<li>Add <code>@​tailwindcss/webpack</code> as Tailwind plugin enabler
(<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2027">#2027</a>)
(b5ac0cf734dda3c6c6c51c817981dfc558b7c582) - thanks <a
href="https://github.com/igas"><code>@​igas</code></a>!</li>
<li>Fix Next.js Turbopack loader dependencies
(23419b4edfd48796dd484fa880e1bad49a043d2e)</li>
<li>Explain ambiguous star exports in traces (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2025">#2025</a>)
(3c2c1a53f9c2b7ff3057a4e46761791979e0b09c) - thanks <a
href="https://github.com/gioboa"><code>@​gioboa</code></a>!</li>
<li>Fix eslintrc <code>parserOptions.parser</code> handling in ESLint
plugin (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2028">#2028</a>)
(c79463cec81d09518eda325ec00e6f12327dea8d) - thanks <a
href="https://github.com/bytedoe"><code>@​bytedoe</code></a>!</li>
<li>fix(compilers): require word boundary around import keyword (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2029">#2029</a>)
(68bbe51c39b564022b63942bc83cb570778cca00) - thanks <a
href="https://github.com/thanadolps"><code>@​thanadolps</code></a>!</li>
<li>fix: recover from corrupt cache file (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2034">#2034</a>)
(30ff7568c84e0a6731ca634a52314228d23d1a2b) - thanks <a
href="https://github.com/gioboa"><code>@​gioboa</code></a>!</li>
<li>fix: fix trailing comma on dependency removal (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2033">#2033</a>)
(adfaf4f78878b6d55b0939a92d70a1fbb0ae1240) - thanks <a
href="https://github.com/gioboa"><code>@​gioboa</code></a>!</li>
<li>Document built-in compiler scope
(a05e155276dad4ead16992580d17572cebf045e7)</li>
<li>Add babel, khan and oxc to projects and optimize svgs
(1c26560b98bc3109e93d15761d02f089213bfb6c)</li>
<li>Add section to test preview packages &amp; extension
(d911c18385f0aa41f53653a2a15cc90a1e0251b8)</li>
<li>Fix shared info/exclude handling in linked Git worktrees (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2037">#2037</a>)
(c1f18d5a7d25fc5a614747bbcbd62d043457eb48) - thanks <a
href="https://github.com/kenfdev"><code>@​kenfdev</code></a>!</li>
<li>Shard Node specs on Windows and enable Bun test parallelism
(66e966b6edec4460b40b05847fefa9f90ee69068)</li>
<li>Add Varlock plugin support (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2000">#2000</a>)
(e4fbf46acff08e78370e72b142e795bd81f28561) - thanks <a
href="https://github.com/Joehoel"><code>@​Joehoel</code></a>!</li>
<li>Apply NODE_OPTIONS inputs to package manager binaries (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2038">#2038</a>)
(c8df8a28e9a19484efe7097f984abc0c6556aff5) - thanks <a
href="https://github.com/giaBaoJS"><code>@​giaBaoJS</code></a>!</li>
<li>Handle array form of <code>import/resolver</code> setting in ESLint
plugin (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2041">#2041</a>)
(a80d386a80fdafc89c610d4887ec82184ac178db) - thanks <a
href="https://github.com/bytedoe"><code>@​bytedoe</code></a>!</li>
<li>fix(node): add valueless Node CLI flags to boolean options (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2042">#2042</a>)
(4c6768501f7115a894d7ece9e5c32090b684cc6f) - thanks <a
href="https://github.com/shoutoutuoadi325"><code>@​shoutoutuoadi325</code></a>!</li>
<li>fix(typedoc): accept string form of plugin and theme options (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2043">#2043</a>)
(ce387b05c8f136546e860ec73e29557563c63afa) - thanks <a
href="https://github.com/giaBaoJS"><code>@​giaBaoJS</code></a>!</li>
<li>Add textlint plugin (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2039">#2039</a>)
(532dab595fc9a910e320418dc0390222fb2d7478) - thanks <a
href="https://github.com/anandghegde"><code>@​anandghegde</code></a>!</li>
<li>fix: Correctly resolve Vitest setupFiles from nested configs (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2040">#2040</a>)
(84a494334e125d229dc865893b21d69d0d201e85) - thanks <a
href="https://github.com/CruseCtrl"><code>@​CruseCtrl</code></a>!</li>
<li>Add n8n to projects (3f756a7e70c4164d57a7dbbd58f3604afe4043e2)</li>
<li>Resolve re-export traces to their defining bindings
(43b3f9bbd7701ab44fca0554908f7550fbe84649)</li>
<li>Show ambiguous, shadowed and converged exports
(f1e97b998d80906f0cef3f5e3946833b7166cbdc)</li>
<li>Document export tracing and editor contention
(0188e7da1a481c7f6493d50580dfa8a7ecdf8c72)</li>
<li>Resolve local <code>extends</code> files in eslintrc configs (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2044">#2044</a>)
(62b5bf5aef5e6d3fc4784a1b5ef9933d383609ea) - thanks <a
href="https://github.com/bytedoe"><code>@​bytedoe</code></a>!</li>
<li>docs: link each page to its own OG image (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2045">#2045</a>)
(a85eb4e2aab46c3fa0813b1f1e13e93e134b8be7) - thanks <a
href="https://github.com/bytedoe"><code>@​bytedoe</code></a>!</li>
<li>fix: fix language server bundled knip fallback (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2035">#2035</a>)
(882ba3abb0b99c2bfe3e13a241d889376fe87c4c) - thanks <a
href="https://github.com/gioboa"><code>@​gioboa</code></a>!</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/webpro-nl/knip/commit/675c1b1a3dbed53d57108dc90a060dc3d0c85b0b"><code>675c1b1</code></a>
Release knip@6.37.0</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/1269e98bb700384811fadc124d69ea720832037e"><code>1269e98</code></a>
Fix --format name resolution in the ESLint plugin (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2046">#2046</a>)</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/038ea179f7d6bf7ca43bc5daf553a68b13a9067c"><code>038ea17</code></a>
Update dependencies</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/4237010c9a834eb8b04f4a528c76d10a5c38ee98"><code>4237010</code></a>
Respect npx no-install flags before the executable</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/c1d7d75a3529d9faff7f4c0df11dd0ca1bdfb149"><code>c1d7d75</code></a>
Separate shell binary expectations from reporting exemptions (resolve <a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/2022">#2022</a>)</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/e67dfcb96d055c27be9c8601e077656855bb632b"><code>e67dfcb</code></a>
Correct binary provider metadata in Relay fixtures</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/54af171638db22f5d903faae05c37c2ea6adc869"><code>54af171</code></a>
Preserve executable references across package manager commands</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/c5bdb69ccbcb7e1056233f346d0ada3495d1013d"><code>c5bdb69</code></a>
Match binaries only to their actual dependency providers</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/5b21dc9192f773613d1c5db8edf35f0a68820268"><code>5b21dc9</code></a>
fix: enable JSX in the config loader (<a
href="https://github.com/webpro-nl/knip/tree/HEAD/packages/knip/issues/1959">#1959</a>)</li>
<li><a
href="https://github.com/webpro-nl/knip/commit/06a68fcf99a90e559daeb0b8fb2d24e173124774"><code>06a68fc</code></a>
fix(graphql-codegen): mark near-operation-file outputs as entries, not
the do...</li>
<li>Additional commits viewable in <a
href="https://github.com/webpro-nl/knip/commits/knip@6.37.0/packages/knip">compare
view</a></li>
</ul>
</details>
<br />

Updates `oxfmt` from 0.68.0 to 0.70.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/oxc-project/oxc/releases">oxfmt's
releases</a>.</em></p>
<blockquote>
<h2>oxfmt v0.70.0</h2>
<h3>🚀 Features</h3>
<ul>
<li>415b742 oxlint,oxfmt: Do not discover nested config in Vite+ mode
(<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/26763">#26763</a>)
(leaysgur)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/oxc-project/oxc/commit/288d8cc77984b0a3851c58c423ffe9e6edc79f2e"><code>288d8cc</code></a>
release(apps): oxlint v1.85.0 &amp;&amp; oxfmt v0.70.0 (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/26903">#26903</a>)</li>
<li><a
href="https://github.com/oxc-project/oxc/commit/f02a64a517a69a4eaa4ef83b722a3f10cf633f10"><code>f02a64a</code></a>
release(apps): oxlint v1.84.0 &amp;&amp; oxfmt v0.69.0 (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt/issues/26874">#26874</a>)</li>
<li>See full diff in <a
href="https://github.com/oxc-project/oxc/commits/oxfmt_v0.70.0/npm/oxfmt">compare
view</a></li>
</ul>
</details>
<br />

Updates `oxlint` from 1.83.0 to 1.85.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/oxc-project/oxc/releases">oxlint's
releases</a>.</em></p>
<blockquote>
<h2>oxlint v1.85.0</h2>
<h3>🚀 Features</h3>
<ul>
<li>415b742 oxlint,oxfmt: Do not discover nested config in Vite+ mode
(<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26763">#26763</a>)
(leaysgur)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/oxc-project/oxc/commit/288d8cc77984b0a3851c58c423ffe9e6edc79f2e"><code>288d8cc</code></a>
release(apps): oxlint v1.85.0 &amp;&amp; oxfmt v0.70.0 (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26903">#26903</a>)</li>
<li><a
href="https://github.com/oxc-project/oxc/commit/f02a64a517a69a4eaa4ef83b722a3f10cf633f10"><code>f02a64a</code></a>
release(apps): oxlint v1.84.0 &amp;&amp; oxfmt v0.69.0 (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/26874">#26874</a>)</li>
<li>See full diff in <a
href="https://github.com/oxc-project/oxc/commits/oxlint_v1.85.0/npm/oxlint">compare
view</a></li>
</ul>
</details>
<br />

Updates `oxlint-tsgolint` from 7.0.2001 to 7.0.2002
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/oxc-project/tsgolint/releases">oxlint-tsgolint's
releases</a>.</em></p>
<blockquote>
<h2>v7.0.2002</h2>
<h2>What's Changed</h2>
<ul>
<li>feat(no-misused-promises): improve diagnostics by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1101">oxc-project/tsgolint#1101</a></li>
<li>docs: update benchmarks by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1102">oxc-project/tsgolint#1102</a></li>
<li>docs: declare tsgolint stable by <a
href="https://github.com/Boshen"><code>@​Boshen</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1106">oxc-project/tsgolint#1106</a></li>
<li>ci(semgrep): add scan workflow by <a
href="https://github.com/Boshen"><code>@​Boshen</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1107">oxc-project/tsgolint#1107</a></li>
<li>fix(no-unnecessary-template-expression): preserve expression
precedence by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1108">oxc-project/tsgolint#1108</a></li>
<li>feat(no-unsafe-assignment): improve diagnostics by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1105">oxc-project/tsgolint#1105</a></li>
<li>feat(no-unsafe-return): improve diagnostics by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1110">oxc-project/tsgolint#1110</a></li>
<li>chore: disable typescript-go renovate updates by <a
href="https://github.com/Boshen"><code>@​Boshen</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1116">oxc-project/tsgolint#1116</a></li>
<li>chore(deps): update github actions by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1117">oxc-project/tsgolint#1117</a></li>
<li>chore(deps): update actions/setup-go action to v7 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1118">oxc-project/tsgolint#1118</a></li>
<li>chore(deps): update dependency typescript to v7 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1119">oxc-project/tsgolint#1119</a></li>
<li>chore(deps): update pnpm to v11.17.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1123">oxc-project/tsgolint#1123</a></li>
<li>chore(deps): update github actions by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1124">oxc-project/tsgolint#1124</a></li>
<li>fix(no-misused-promises): guard nil contextual type in return
statements by <a
href="https://github.com/connorshea"><code>@​connorshea</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1121">oxc-project/tsgolint#1121</a></li>
<li>feat(no-unsafe-type-assertion): improve diagnostics by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1111">oxc-project/tsgolint#1111</a></li>
<li>fix(prefer-readonly-parameter-types): ignore private mapped
properties by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1125">oxc-project/tsgolint#1125</a></li>
<li>chore(deps): update crate-ci/typos action to v1.49.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1130">oxc-project/tsgolint#1130</a></li>
<li>chore(deps): update github actions by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1135">oxc-project/tsgolint#1135</a></li>
<li>chore(deps): update module github.com/dlclark/regexp2/v2 to v2.6.0
by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1136">oxc-project/tsgolint#1136</a></li>
<li>ci: remove Semgrep workflow by <a
href="https://github.com/Boshen"><code>@​Boshen</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1138">oxc-project/tsgolint#1138</a></li>
<li>chore(deps): update taiki-e/install-action action to v2.85.13 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1139">oxc-project/tsgolint#1139</a></li>
<li>chore(deps): update gomod by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1140">oxc-project/tsgolint#1140</a></li>
<li>fix(consistent-type-exports): split diagnostic help text by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1144">oxc-project/tsgolint#1144</a></li>
<li>fix(no-confusing-void-expression): split diagnostic help text by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1145">oxc-project/tsgolint#1145</a></li>
<li>fix(no-implied-eval): split diagnostic help text by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1146">oxc-project/tsgolint#1146</a></li>
<li>fix(no-unsafe-type-assertion): split diagnostic help text by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1147">oxc-project/tsgolint#1147</a></li>
<li>fix(no-useless-default-assignment): split diagnostic help text by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1148">oxc-project/tsgolint#1148</a></li>
<li>fix(prefer-readonly): split diagnostic help text by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1149">oxc-project/tsgolint#1149</a></li>
<li>fix(strict-boolean-expressions): split diagnostic help text by <a
href="https://github.com/camc314"><code>@​camc314</code></a> in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1150">oxc-project/tsgolint#1150</a></li>
<li>chore(deps): update github.com/go-json-experiment/json digest to
c27c302 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1151">oxc-project/tsgolint#1151</a></li>
<li>chore(deps): update dependency dprint-toml to v0.8.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1152">oxc-project/tsgolint#1152</a></li>
<li>chore(deps): update npm packages by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1153">oxc-project/tsgolint#1153</a></li>
<li>chore(deps): update taiki-e/install-action action to v2.86.4 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1154">oxc-project/tsgolint#1154</a></li>
<li>chore(deps): update crate-ci/typos action to v1.49.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1157">oxc-project/tsgolint#1157</a></li>
<li>chore(deps): update dependency dprint-markdown to v0.23.2 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1158">oxc-project/tsgolint#1158</a></li>
<li>chore(deps): update taiki-e/install-action action to v2.87.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1159">oxc-project/tsgolint#1159</a></li>
<li>chore(deps): update crate-ci/typos action to v1.50.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1162">oxc-project/tsgolint#1162</a></li>
<li>chore(deps): update pnpm to v11.24.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1164">oxc-project/tsgolint#1164</a></li>
<li>fix(no-unnecessary-boolean-literal-compare): preserve nullable
boolean narrowing by <a
href="https://github.com/sharmila-oai"><code>@​sharmila-oai</code></a>
in <a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1160">oxc-project/tsgolint#1160</a></li>
<li>chore(deps): update crate-ci/typos action to v1.50.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1169">oxc-project/tsgolint#1169</a></li>
<li>chore(deps): update github actions by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1171">oxc-project/tsgolint#1171</a></li>
<li>chore(deps): update module github.com/dlclark/regexp2/v2 to v2.7.2
by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1172">oxc-project/tsgolint#1172</a></li>
<li>chore(deps): update dependency dprint-markdown to v0.23.3 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1170">oxc-project/tsgolint#1170</a></li>
<li>chore(deps): update npm packages by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1173">oxc-project/tsgolint#1173</a></li>
<li>chore(deps): update dependency vitest to v5 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1174">oxc-project/tsgolint#1174</a></li>
<li>chore(deps): update dependency dprint-markdown to v0.24.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1178">oxc-project/tsgolint#1178</a></li>
<li>chore(deps): update taiki-e/install-action action to v2.87.10 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1177">oxc-project/tsgolint#1177</a></li>
<li>chore(deps): update gomod by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/oxc-project/tsgolint/pull/1179">oxc-project/tsgolint#1179</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/acd88e1b1ef8f219e8956f804f2548dafd949705"><code>acd88e1</code></a>
perf(prefer-regexp-exec): defer argument type resolution (<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1207">#1207</a>)</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/14908447a2a1cad72aa8a43faf72170ddd21606e"><code>1490844</code></a>
perf(use-unknown-in-catch-callback-variable): defer annotation fixes (<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1206">#1206</a>)</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/d11b717674dd549832ce2f95654fa76ac1337a2d"><code>d11b717</code></a>
perf(strict-boolean-expressions): avoid temporary variant maps (<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1205">#1205</a>)</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/fe1ecf30b8ab6e6fac25bef55ad25c9296417bd1"><code>fe1ecf3</code></a>
perf(no-unsafe-unary-minus): skip type queries for literals (<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1203">#1203</a>)</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/e42a51052afbdd4787a44740ed44391b695e3bce"><code>e42a510</code></a>
perf(no-deprecated): skip type queries for empty allow lists (<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1202">#1202</a>)</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/94ee8ac38f44244e7a4895d4a8eb55421be06a29"><code>94ee8ac</code></a>
perf(restrict-template-expressions): avoid unnecessary base-type checks
(<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1204">#1204</a>)</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/7bbe34100a66912ff134bbbeda5fd88f456e1e17"><code>7bbe341</code></a>
perf(await-thenable): skip aggregator checks for empty calls (<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1201">#1201</a>)</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/8296505a3a50b26bf5f8d586d7887d2c1c6c1da5"><code>8296505</code></a>
perf(no-base-to-string): avoid temporary certainty slices (<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1200">#1200</a>)</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/636677305c6fbf581241bf2d49b5d217c23c2da1"><code>6366773</code></a>
perf(no-unnecessary-template-expression): defer single-interpolation
fixes (#...</li>
<li><a
href="https://github.com/oxc-project/tsgolint/commit/8300b95c905e44d912896e9a75958e41eb5d8d32"><code>8300b95</code></a>
perf(unbound-method): check native names before resolving symbols (<a
href="https://redirect.github.com/oxc-project/tsgolint/issues/1198">#1198</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/oxc-project/tsgolint/compare/v7.0.2001...v7.0.2002">compare
view</a></li>
</ul>
</details>
<br />

Updates `vitest` from 5.0.0 to 5.0.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vitest-dev/vitest/releases">vitest's
releases</a>.</em></p>
<blockquote>
<h2>v5.0.1</h2>
<h3>   🚀 Features</h3>
<ul>
<li><strong>ui</strong>:
<ul>
<li>Move trace attempts selector to viewer header  -  by <a
href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a>,
<strong>Hiroshi Ogawa</strong> and <strong>Codex</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11189">vitest-dev/vitest#11189</a>
<a href="https://github.com/vitest-dev/vitest/commit/5dc4b5c92"><!-- raw
HTML omitted -->(5dc4b)<!-- raw HTML omitted --></a></li>
<li>Add focused trace view layout mode  -  by <a
href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a>,
<strong>Hiroshi Ogawa</strong>, <strong>OpenCode (gpt-5.6-sol)</strong>
and <strong>Codex</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11190">vitest-dev/vitest#11190</a>
<a href="https://github.com/vitest-dev/vitest/commit/376dc3bc1"><!-- raw
HTML omitted -->(376dc)<!-- raw HTML omitted --></a></li>
</ul>
</li>
</ul>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li>Exit 1 when vitest list fails collection  -  by <a
href="https://github.com/hamed-bavar"><code>@​hamed-bavar</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/11145">vitest-dev/vitest#11145</a>
and <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11146">vitest-dev/vitest#11146</a>
<a href="https://github.com/vitest-dev/vitest/commit/6108b8197"><!-- raw
HTML omitted -->(6108b)<!-- raw HTML omitted --></a></li>
<li>Keep parse error details in static collection  -  by <a
href="https://github.com/hamed-bavar"><code>@​hamed-bavar</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/11150">vitest-dev/vitest#11150</a>
and <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11151">vitest-dev/vitest#11151</a>
<a href="https://github.com/vitest-dev/vitest/commit/7c818153a"><!-- raw
HTML omitted -->(7c818)<!-- raw HTML omitted --></a></li>
<li>Avoid recursive prototype in automocking  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/11195">vitest-dev/vitest#11195</a>
<a href="https://github.com/vitest-dev/vitest/commit/99fc52591"><!-- raw
HTML omitted -->(99fc5)<!-- raw HTML omitted --></a></li>
<li>Prevent false Vitest import resolution  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/11196">vitest-dev/vitest#11196</a>
<a href="https://github.com/vitest-dev/vitest/commit/b426c1976"><!-- raw
HTML omitted -->(b426c)<!-- raw HTML omitted --></a></li>
<li>Keep metadata file when clearing the cache  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/11199">vitest-dev/vitest#11199</a>
<a href="https://github.com/vitest-dev/vitest/commit/73614654a"><!-- raw
HTML omitted -->(73614)<!-- raw HTML omitted --></a></li>
<li>Correct typos in error message and comments  -  by <a
href="https://github.com/shinji00222"><code>@​shinji00222</code></a> and
<strong>Shinji</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11187">vitest-dev/vitest#11187</a>
<a href="https://github.com/vitest-dev/vitest/commit/115c3f6d2"><!-- raw
HTML omitted -->(115c3)<!-- raw HTML omitted --></a></li>
<li>Resolve ResolvedConfig exactOptionalPropertyTypes errors  -  by <a
href="https://github.com/LukeAbby"><code>@​LukeAbby</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11175">vitest-dev/vitest#11175</a>
<a href="https://github.com/vitest-dev/vitest/commit/498fbe922"><!-- raw
HTML omitted -->(498fb)<!-- raw HTML omitted --></a></li>
<li>Share the server on self-referencing <code>extends</code>  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/11034">vitest-dev/vitest#11034</a>
<a href="https://github.com/vitest-dev/vitest/commit/23dda738c"><!-- raw
HTML omitted -->(23dda)<!-- raw HTML omitted --></a></li>
<li>Warn when deprecated <code>deps.optimizer.web</code> is used  -  by
<a href="https://github.com/im10furry"><code>@​im10furry</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/11214">vitest-dev/vitest#11214</a>
<a href="https://github.com/vitest-dev/vitest/commit/2ce29d5fa"><!-- raw
HTML omitted -->(2ce29)<!-- raw HTML omitted --></a></li>
<li><strong>browser</strong>:
<ul>
<li>Avoid double quotes in <code>config.define</code>  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/11198">vitest-dev/vitest#11198</a>
<a href="https://github.com/vitest-dev/vitest/commit/972e24bab"><!-- raw
HTML omitted -->(972e2)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>doctor</strong>:
<ul>
<li>Measure vm pools for custom environments  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/11212">vitest-dev/vitest#11212</a>
<a href="https://github.com/vitest-dev/vitest/commit/91ab1588c"><!-- raw
HTML omitted -->(91ab1)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>expect</strong>:
<ul>
<li>Correct return value in <code>toMatchAriaSnapshot</code>  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/11208">vitest-dev/vitest#11208</a>
<a href="https://github.com/vitest-dev/vitest/commit/c119be016"><!-- raw
HTML omitted -->(c119b)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>fakeTimers</strong>:
<ul>
<li>Force <code>queueMicrotask</code> and <code>nextTick</code> in
<code>toNotFake</code>  -  by <a
href="https://github.com/kingmakeruix"><code>@​kingmakeruix</code></a>,
<strong>kingmakeruix</strong>, <strong>Hiroshi Ogawa</strong>,
<strong>Codex</strong> and <a
href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11261">vitest-dev/vitest#11261</a>
<a href="https://github.com/vitest-dev/vitest/commit/a47d7908f"><!-- raw
HTML omitted -->(a47d7)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>snapshot</strong>:
<ul>
<li>Report obsolete keys next to skipped tests  -  by <a
href="https://github.com/hamed-bavar"><code>@​hamed-bavar</code></a>,
<strong>Hiroshi Ogawa</strong> and <strong>OpenCode
(gpt-5.6-sol)</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11157">vitest-dev/vitest#11157</a>
and <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11158">vitest-dev/vitest#11158</a>
<a href="https://github.com/vitest-dev/vitest/commit/17e2b22dd"><!-- raw
HTML omitted -->(17e2b)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>types</strong>:
<ul>
<li>Make public declarations self-contained  -  by <a
href="https://github.com/ZoeySigel"><code>@​ZoeySigel</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11141">vitest-dev/vitest#11141</a>
<a href="https://github.com/vitest-dev/vitest/commit/455466c16"><!-- raw
HTML omitted -->(45546)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>ui</strong>:
<ul>
<li>Fix collapse/expand suite with file name search  -  by <a
href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a>,
<strong>Hiroshi Ogawa</strong> and <strong>Codex</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11260">vitest-dev/vitest#11260</a>
<a href="https://github.com/vitest-dev/vitest/commit/0a7122daa"><!-- raw
HTML omitted -->(0a712)<!-- raw HTML omitted --></a></li>
<li>Fix explorer file summary count  -  by <a
href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a>,
<strong>Hiroshi Ogawa</strong>, <strong>OpenCode (gpt-5.6-sol)</strong>
and <strong>Codex</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11125">vitest-dev/vitest#11125</a>
<a href="https://github.com/vitest-dev/vitest/commit/05982297d"><!-- raw
HTML omitted -->(05982)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>utils</strong>:
<ul>
<li>Fix <code>deepMerge</code> to handle prototype  -  by <a
href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a>,
<strong>Hiroshi Ogawa</strong> and <strong>Codex</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/11215">vitest-dev/vitest#11215</a>
<a href="https://github.com/vitest-dev/vitest/commit/4944cf498"><!-- raw
HTML omitted -->(4944c)<!-- raw HTML omitted --></a></li>
</ul>
</li>
</ul>
<h5>    <a
href="https://github.com/vitest-dev/vitest/compare/v5.0.0...v5.0.1">View
changes on GitHub</a></h5>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vitest-dev/vitest/commit/03630a5995d10455fa136be53bfb2b2409381106"><code>03630a5</code></a>
chore: release v5.0.1 (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11275">#11275</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/a47d7908f0635e9cba6cbe5e1a209bb6add5e0ab"><code>a47d790</code></a>
fix(fakeTimers): force <code>queueMicrotask</code> and
<code>nextTick</code> in <code>toNotFake</code> (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11261">#11261</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/2ce29d5fa758046e5453bd92b8ed6c9da9709bb5"><code>2ce29d5</code></a>
fix: warn when deprecated <code>deps.optimizer.web</code> is used (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11214">#11214</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/ccd6d057b6e4ca29a5e6b753a2b8e16b0afd8cda"><code>ccd6d05</code></a>
docs: fix typecheck exclude default in documentation (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11223">#11223</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/91ab1588c72c9c5f7c638368a541cd20e0e8a934"><code>91ab158</code></a>
fix(doctor): measure vm pools for custom environments (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11212">#11212</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/23dda738ccacb11682426426cd7b876afd107621"><code>23dda73</code></a>
fix: share the server on self-referencing <code>extends</code> (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11034">#11034</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/498fbe9222eb9aa3d8cf48481e200c16bb693bbd"><code>498fbe9</code></a>
fix: resolve ResolvedConfig exactOptionalPropertyTypes errors (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11175">#11175</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/115c3f6d2bfa6a8672eeab8cc21bbecc6a4ef3d0"><code>115c3f6</code></a>
fix: correct typos in error message and comments (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11187">#11187</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/73614654a46f617c357920eecda439654a561f92"><code>7361465</code></a>
fix: keep metadata file when clearing the cache (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11199">#11199</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/972e24bab5fb96843de72447eb65585628b8dbde"><code>972e24b</code></a>
fix(browser): avoid double quotes in <code>config.define</code> (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/11198">#11198</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/vitest">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: CaliBrain <calibrain@l4n.xyz>
2026-09-25 19:12:12 -04:00
CaliBrain dce91e6972 fix(audiobookbay): reuse the resolved magnet when retrying (#1388) (#1398)
Retrying an AudiobookBay download re-scraped the detail page for the
magnet link before checking the torrent client, so a torrent that had
already finished in the client could not be imported while AudiobookBay
was down.

The handler now keeps the magnet it resolved in the task's retry
context, which is persisted with the download history, and a retry hands
that magnet straight to the client's existing-download check. The
context is handler-owned, so a client-supplied download URL cannot seed
it.

Fixes #1388
2026-09-25 19:11:56 -04:00
dependabot[bot] 0f4342fede build(deps): bump the gh-actions group with 4 updates (#1395)
Bumps the gh-actions group with 4 updates:
[astral-sh/setup-uv](https://github.com/astral-sh/setup-uv),
[github/codeql-action/init](https://github.com/github/codeql-action),
[github/codeql-action/autobuild](https://github.com/github/codeql-action)
and
[github/codeql-action/analyze](https://github.com/github/codeql-action).

Updates `astral-sh/setup-uv` from 10.1.0 to 10.2.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/setup-uv/releases">astral-sh/setup-uv's
releases</a>.</em></p>
<blockquote>
<h2>v10.2.0 🌈 Disable automatic cache saves for merge queues</h2>
<h2>Changes</h2>
<p>This release contains the known-checksum of the most recent uv
releases and also disabled the uploading(saving) of the cache when in a
merge queue since theses caches would almost never be used.</p>
<h2>🚀 Enhancements</h2>
<ul>
<li>Disable automatic cache saves for merge queues <a
href="https://github.com/eifinger"><code>@​eifinger</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1056">#1056</a>)</li>
</ul>
<h2>🧰 Maintenance</h2>
<ul>
<li>chore: update known checksums for 0.12.17 @<a
href="https://github.com/apps/github-actions">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1058">#1058</a>)</li>
<li>chore: update known checksums for 0.12.16 @<a
href="https://github.com/apps/github-actions">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1057">#1057</a>)</li>
<li>chore: update known checksums for 0.12.15 @<a
href="https://github.com/apps/github-actions">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1054">#1054</a>)</li>
<li>chore: update known checksums for 0.12.14 @<a
href="https://github.com/apps/github-actions">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1053">#1053</a>)</li>
<li>chore: update known checksums for 0.12.13 @<a
href="https://github.com/apps/github-actions">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1045">#1045</a>)</li>
</ul>
<h2>📚 Documentation</h2>
<ul>
<li>docs: update version references to v10.1.0 @<a
href="https://github.com/apps/github-actions">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1044">#1044</a>)</li>
</ul>
<h2>⬆️ Dependency updates</h2>
<ul>
<li>chore(deps): roll up Dependabot updates <a
href="https://github.com/eifinger"><code>@​eifinger</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1059">#1059</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/c18668ad3cf93ea998bef934396af7bb5c839dc7"><code>c18668a</code></a>
chore(deps): roll up Dependabot updates (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1059">#1059</a>)</li>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/ffe14763056ca34ecd158146a9fc7e144c8a2753"><code>ffe1476</code></a>
chore: update known checksums for 0.12.17 (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1058">#1058</a>)</li>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/f5548c55522a1db0af3c84f2af3d058bc9bc2de2"><code>f5548c5</code></a>
chore: update known checksums for 0.12.16 (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1057">#1057</a>)</li>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/a761a4e9afd7b2f353ae020bd6d3a3af34c6c4d5"><code>a761a4e</code></a>
Disable automatic cache saves for merge queues (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1056">#1056</a>)</li>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/3377a30666f438759955882b3eba6a92b2b29b12"><code>3377a30</code></a>
chore: update known checksums for 0.12.15 (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1054">#1054</a>)</li>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/dfb5f386776afcea37f271f3b656318d9949b9f1"><code>dfb5f38</code></a>
chore: update known checksums for 0.12.14 (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1053">#1053</a>)</li>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/45c121f982720f3bdf236c2ac06f126ca211949c"><code>45c121f</code></a>
chore: update known checksums for 0.12.13 (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1045">#1045</a>)</li>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/8073452fd4b566e886f04f731bcdbd8332b0b779"><code>8073452</code></a>
docs: update version references to v10.1.0 (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1044">#1044</a>)</li>
<li>See full diff in <a
href="https://github.com/astral-sh/setup-uv/compare/bec219d24cd3e171d82865faccec33120bb574f4...c18668ad3cf93ea998bef934396af7bb5c839dc7">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/codeql-action/init` from 4.38.0 to 4.38.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/init's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.1</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/init's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.2 - 24 Sept 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
<h2>4.38.1 - 18 Sept 2026</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd"><code>1c5b675</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4152">#4152</a>
from github/update-v4.38.1-a65b83a73</li>
<li><a
href="https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17"><code>a97cdca</code></a>
Add changelog entry for <a
href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a></li>
<li><a
href="https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611"><code>cc6c691</code></a>
Update changelog for v4.38.1</li>
<li><a
href="https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258"><code>a65b83a</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a>
from github/henrymercer/per-language-bundles-pr</li>
<li><a
href="https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042"><code>07fa87d</code></a>
Clarify the latest-nightly eligibility exception</li>
<li><a
href="https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae"><code>f18f353</code></a>
Describe the bundle URL resolver</li>
<li><a
href="https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46"><code>ecec9b5</code></a>
Share per-language telemetry fields without renaming</li>
<li><a
href="https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af"><code>79fe3a1</code></a>
Move download telemetry into the status-report directory</li>
<li><a
href="https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607"><code>ead1f7d</code></a>
Rename the platform module</li>
<li><a
href="https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f"><code>549d498</code></a>
Simplify per-language platform eligibility checks</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/codeql-action/autobuild` from 4.38.0 to 4.38.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/autobuild's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.1</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/autobuild's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.2 - 24 Sept 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
<h2>4.38.1 - 18 Sept 2026</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd"><code>1c5b675</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4152">#4152</a>
from github/update-v4.38.1-a65b83a73</li>
<li><a
href="https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17"><code>a97cdca</code></a>
Add changelog entry for <a
href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a></li>
<li><a
href="https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611"><code>cc6c691</code></a>
Update changelog for v4.38.1</li>
<li><a
href="https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258"><code>a65b83a</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a>
from github/henrymercer/per-language-bundles-pr</li>
<li><a
href="https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042"><code>07fa87d</code></a>
Clarify the latest-nightly eligibility exception</li>
<li><a
href="https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae"><code>f18f353</code></a>
Describe the bundle URL resolver</li>
<li><a
href="https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46"><code>ecec9b5</code></a>
Share per-language telemetry fields without renaming</li>
<li><a
href="https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af"><code>79fe3a1</code></a>
Move download telemetry into the status-report directory</li>
<li><a
href="https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607"><code>ead1f7d</code></a>
Rename the platform module</li>
<li><a
href="https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f"><code>549d498</code></a>
Simplify per-language platform eligibility checks</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/codeql-action/analyze` from 4.38.0 to 4.38.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/analyze's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.1</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/analyze's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.2 - 24 Sept 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
<h2>4.38.1 - 18 Sept 2026</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd"><code>1c5b675</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4152">#4152</a>
from github/update-v4.38.1-a65b83a73</li>
<li><a
href="https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17"><code>a97cdca</code></a>
Add changelog entry for <a
href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a></li>
<li><a
href="https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611"><code>cc6c691</code></a>
Update changelog for v4.38.1</li>
<li><a
href="https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258"><code>a65b83a</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a>
from github/henrymercer/per-language-bundles-pr</li>
<li><a
href="https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042"><code>07fa87d</code></a>
Clarify the latest-nightly eligibility exception</li>
<li><a
href="https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae"><code>f18f353</code></a>
Describe the bundle URL resolver</li>
<li><a
href="https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46"><code>ecec9b5</code></a>
Share per-language telemetry fields without renaming</li>
<li><a
href="https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af"><code>79fe3a1</code></a>
Move download telemetry into the status-report directory</li>
<li><a
href="https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607"><code>ead1f7d</code></a>
Rename the platform module</li>
<li><a
href="https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f"><code>549d498</code></a>
Simplify per-language platform eligibility checks</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-25 18:57:45 -04:00
CaliBrain ece6b8f341 fix(auth): fail closed when auth prerequisites are missing (#1387) (#1397)
Auth mode resolution fell back to "none" (anonymous full admin) whenever
the configured method's prerequisites were missing: no local password
admin for builtin/OIDC, no Calibre-Web database, a blank proxy header,
an
unrecognized AUTH_METHOD (including "OIDC" in uppercase), or any error
while reading the config. Deleting or demoting the last local admin was
allowed on purpose because of that fallback, which exposed OIDC
instances publicly.

- Only an explicit AUTH_METHOD=none disables authentication. A
configured
  method stays active when its prerequisites are missing, so sign-in
  fails instead of opening up.
- An unrecognized or unreadable AUTH_METHOD resolves to "unavailable",
  which still requires a session and accepts no login. Values are
  normalized, so AUTH_METHOD=OIDC works.
- Restore the guard against deleting or demoting the last local password
  admin while builtin/OIDC is active (unless DISABLE_LOCAL_AUTH is set).
- Require a local admin before enabling Local auth, as OIDC already did.
- Log a recovery hint at startup when builtin/OIDC runs without a local
  admin, and document recovery via AUTH_METHOD=none.
- Drop the "will fall back to No Authentication" UI toasts and hints.



Fixes https://github.com/calibrain/shelfmark/issues/1387
2026-09-25 18:56:16 -04:00
CaliBrain c7bfb20448 Default to english when no lang is slected (#1396)
Fixes https://github.com/calibrain/shelfmark/issues/1384
2026-09-25 18:38:25 -04:00
splitsec2 37a77e9562 feat(library): mark search results already in a Calibre library (#1377)
Per discussion #1372, where you said you were fine with this specific
implementation: check whether metadata.db exists, read it if so, and
show a check mark saying the book is already there.

Searching for a book you already own gives no hint that you own it, so
the easiest way to end up with a second copy is to not remember you have
the first. This reads a Calibre `metadata.db`, read only, and marks
matching results with an **In library** badge in the card, list and
compact views and in the details dialog.

Off by default. It sits in Settings, General beside the existing Library
URL, with a test button that reports how many books it indexed. No HTTP
call, no token, nothing written back.

Matching runs most to least confident: a shared external id, then an
ISBN compared in both ISBN-10 and ISBN-13 form, then fuzzy title tokens
plus the author surname. The check fails open, so an unreadable database
degrades the badge and never blocks a search, and entries are cached for
ten minutes with an early refresh when the file changes, so a large
library costs one read rather than one per search.

`text_match.py` is new and shared by the index and the provider, so
title, author and ISBN matching stays consistent in one place.

## On the provider interface

`library_index` talks only to a `LibraryProvider` protocol and knows
nothing about Calibre. That is deliberate but it is not speculative
generality, it is what let me send you the Calibre half on its own: I
run an Audiobookshelf provider on the same interface in my fork, which
is where the audiobook side of the badge comes from. I have left that
out because it is a new service integration rather than something
already in the codebase, which is the line your non-goals draw. Happy to
send it separately if you ever want it, and equally happy for the answer
to be no.

Adding a library is a module with the `LibraryProvider` shape plus one
line in `all_providers()`.

## Verification

- `tests/core/test_library_index.py`: id, ISBN and fuzzy matching,
per-content-type provider selection, fail-open on provider errors,
stale-cache reuse, TTL and fingerprint refresh, per-provider cache
isolation, and the test-connection path including unsaved form values.
- `tests/core/test_text_match.py`: ISBN variants and token matching.
- `src/frontend/src/tests/libraryBadge.test.ts` and the added cases in
`bookTransformers.test.ts`.
- Python suite (3269) and frontend suite (206) green, plus ruff, ruff
format, basedpyright, vulture, tsc, oxlint, oxfmt and the production
build.
2026-09-25 18:18:10 -04:00
splitsec2 fe99d4bb5b feat(search): add a configurable default content type (#1371)
Closes #1018.

Worth correcting the issue first: the search tab is not hardcoded.
`useContentTypePreferences` has persisted the user's choice to
localStorage since #564, so a browser that has picked a tab already
keeps it. What is missing is the other half the issue asks for, a
default for a browser that has stored nothing, and a per-user override.

`DEFAULT_CONTENT_TYPE` is a user overridable select next to
`BOOK_LANGUAGE`, so it follows the same path: global value in Settings,
per-user value in Search Preferences, resolved with `user_id` in
`/api/config`. The frontend uses it only when this browser has no stored
choice, which is captured before the existing effect writes one, so
nothing changes for anyone who has already picked a tab.

The resolution is a pure function in `utils/contentTypePreference.ts`
rather than logic inside the hook, since vitest here has no jsdom and
the existing tests cover resolvers like `resolveDefaultLanguageCodes`
the same way.

One small move in `App.tsx`: the `config` state was declared below the
hook that now reads it, so it moved above it.

## Verification

- `tests/core/test_config_api.py`: the payload carries
`default_content_type` and reads it with the user's id.
- `tests/core/test_admin_users_api.py`: the key appears in the per-user
search preferences list.
- `src/frontend/src/tests/contentTypePreference.test.ts`: a stored tab
wins, combined mode survives, the server default applies when nothing is
stored, and an unrecognised value falls back to ebook.
- Python suite (3163) and frontend suite (201) green, plus ruff, ruff
format, basedpyright, vulture, tsc, oxlint, oxfmt and the production
build.
2026-09-25 18:14:42 -04:00
splitsec2 ce1092db7f test(auth): stop proxy provisioning tests depending on run order (#1381)
I hit this while building the Debrid-Link client in #1380. The new tests
there changed the test count, that reshuffled the xdist workers, and
these two went red. They were related to this branch, but were tests
related to another PR I did which didn't have proper tests..

`test_sets_session_from_header` and
`test_reads_remote_user_wsgi_fallback` both assert that a
proxy-authenticated user comes back with `is_admin is True`. Since #1356
that only holds for the bootstrap account, because
`_proxy_default_is_admin` returns True only while `has_admin()` is
False. Both tests assume they're provisioning the first account, and
only one of them can be.

Run with `-n 0` so nothing is sharded:

| | |
|---|---|
| either test alone | passes |
| both, file order | the second fails |
| both, reversed | the second fails |
| both, across 2 workers | both pass |

Reversing the order moving which one breaks is what makes it an ordering
problem rather than a real one.

It stays green on CI because the suite runs with `-n auto` and
`tests/conftest.py` calls `mkdtemp` at module level, which runs once per
worker process. Each worker gets its own `CONFIG_DIR` and its own
`users.db`, the two tests land on different workers, and each one is
genuinely first in its own database. That passed but it's luck rather
than design, and any change to the test count can put them back
together.

So this gives every test in the file an empty user table and stops the
question of who ran first from mattering.

While I was fixed that I added coverage for the rule itself, which I had
failed to test for:

- the bootstrap account is an admin and the next one isn't
- `PROXY_AUTH_DEFAULT_ROLE=admin` promotes later accounts
- a user already in the database keeps its stored role instead of
picking up the default

Tests only, no source changes. The full suite passes serially now, where
it had those two failures before, and it's still green under `-n auto`.
2026-09-25 18:07:46 -04:00
splitsec2 ca25448529 perf(docker): keep the heavy build layers cacheable across builds - save 11minutes per build (#1379)
With the amount of changes and testing I've been doing lately I noticed
how long the builds were taking and how much each one pulled, so I went
and looked at the Dockerfile. I think this balances cache and
efficiency.

Three changes needed to be stacked to make it happen.

**The version stamp sits above everything expensive.** `ARG
BUILD_VERSION` and `ENV BUILD_VERSION` are at the top of the `base`
stage and the value carries the commit sha, so it changes on every
commit. This invalidates the layer and everything below it, which means
the apt install, the dependency sync and the Chromium install. Nothing
in the build reads either variable. They're only used at runtime by
entrypoint.sh, tor.sh, wireguard.sh and genDebug.sh, so they can move to
the end of the final stages.

**`COPY . .` sits above the Chromium install.** It's in `base`, and the
`shelfmark` stage installs Chromium and the seleniumbase drivers after
it, so any source change rebuilds those too. Moving the source copy and
the runtime-paths block to the end of each final stage solves that.

**There's no cross-run cache.** Runners are ephemeral, so without
`cache-from` and `cache-to` every layer is rebuilt on every run whatever
the ordering, and a rebuilt layer gets a new digest even when the
content is identical. That's why reordering on its own doesn't change
the load.

Measured with a source-only change between two builds:

|  | Build | Pull |
|---|---|---|
| before | 13m 20s | 526.5 MB |
| after | 2m 25s | 3.7 MB |

15 of 18 layers get reused where it was 5. The cache sits at 0.86 GB,
which leaves room under the 10 GB repo budget for the uv caches in
ci.yml and e2e-platform.yml. I tried `mode=max` first and it built a bit
quicker at 1m 43s, but it used 5.15 GB of cache and the potential to
impact other workflows so it didn't seem worth 40 seconds, but that is a
single line fix if you want to.

This means the runtime-paths block is now duplicated, once per final
stage, and that's most of the diff. It has to sit below each stage's
heavy layers to do its job and I couldn't find a way around that short
of another shared stage, which looked like more complexity for
complexity's sake. Happy to take another run at it if you'd rather have
it 'DRY'.

I checked the built image against the current one. Same size, it boots,
/api/health returns 200, and BUILD_VERSION and RELEASE_VERSION are still
stamped correctly.

Also, I'll slow down on the PRs. Promise.
2026-09-25 18:07:05 -04:00
splitsec2 b690832659 fix(download): stream a completed book instead of buffering it in RAM - lowering memory needs significantly (#1378)
Credit where it is due: this defect was found and measured by **@DrNgo**
in
[DrNgo/shelfmark-fork@ae2185c](https://github.com/DrNgo/shelfmark-fork/commit/ae2185c8a83d537e55f1dc03f745ab844b5cdcdb).
He recorded a 493 MB audiobook peaking near 963 MB and OOM-killing a 1
GiB container, with the proxy access log showing a single `GET
/api/localdownload` returning 502 at the exact second of the kill. The
analysis is his; I am sending it because it is still open here.

Serving a completed book from the live queue calls `get_book_data`,
which reads the whole file into bytes so the route can wrap it in a
`BytesIO` for `send_file`. That is two copies of the book, with one
resident for the length of the client transfer, to hand over a file that
is already sitting on disk.

`get_book_path` returns the path the task already holds and `send_file`
streams it. The history fallback a few lines up in the same route has
always worked this way, so this makes the two paths consistent rather
than introducing anything new. `get_book_data` stays for callers that
genuinely want the bytes, now documented as the expensive option.

## The fetch side has the same problem, and this PR does not fix it

I should note: `download_url` in `shelfmark/download/http.py` still
builds the inbound file in a `BytesIO` and returns it, so a large
download is fully resident while it fetches. @DrNgo's commit fixes that
too, with a `tempfile.SpooledTemporaryFile(max_size=...)` so small
payloads stay in memory exactly as they do now and large ones spill to
disk.

I left it out deliberately. It changes the return type of `download_url`
from `BytesIO` to a file object, which touches several callers, and it
lands in a file that has been reworked around bypass handling, waiting
rooms and resume since his branch point. That deserves its own PR rather
than riding along with a two-function change. I may send it later; if
@DrNgo sends it first, his should win, and if you would rather have both
together say so and I will hold this one.

## Verification

- `tests/download/test_orchestrator_retry.py`: `get_book_path` returns
the path without opening the file (the test fails the run if it does),
and reports a missing file rather than handing back a dead path.
- The existing `/api/localdownload` tests still pass unchanged,
including the history fallback and the ownership checks.
- Full suite (3222), ruff, ruff format, basedpyright, vulture green.
2026-09-25 18:06:15 -04:00
CaliBrain 2c6d6a02cd ci: debounce dev image builds instead of building nightly (#1376)
Replace the nightly cron and its check-changes job with a debounce.
Every push to main starts dev-image-debounce.yml, which waits out the
60-minute wait timer on the dev-image-debounce environment, then
dispatches the Docker workflow only if main still points at its commit.
A burst of merges now publishes one dev image, an hour after the last
merge.

The Docker workflow keeps only its tag and workflow_dispatch triggers,
so its history holds real builds only. The debounce workflow deletes its
own finished runs, so no-op runs don't pile up either.

Requires the dev-image-debounce environment with a 60-minute wait
timer (Settings → Environments).
2026-09-21 02:38:06 -04:00
dependabot[bot] 4a0675e0d3 build(deps): bump the python-deps group with 4 updates (#1375)
Bumps the python-deps group with 4 updates:
[gevent](https://github.com/gevent/gevent),
[emoji](https://github.com/carpedm20/emoji),
[seleniumbase](https://github.com/seleniumbase/SeleniumBase) and
[ruff](https://github.com/astral-sh/ruff).

Updates `gevent` from 26.8.0 to 26.9.0
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/gevent/gevent/commit/003c77a6f3da41c014dd415022fb61f9d91fc95d"><code>003c77a</code></a>
Preparing release 26.9.0</li>
<li><a
href="https://github.com/gevent/gevent/commit/725ecc3e53dd74f3828f1cf189e1cbeaebbdfae9"><code>725ecc3</code></a>
Merge pull request <a
href="https://redirect.github.com/gevent/gevent/issues/2209">#2209</a>
from bojanz/issue2207-resolve-result-on-setup-failure</li>
<li><a
href="https://github.com/gevent/gevent/commit/a5b68e812e8ddf65d13dfa117d8656fcb713d69b"><code>a5b68e8</code></a>
Adjust the ThreadPool after an unexpected worker exit</li>
<li><a
href="https://github.com/gevent/gevent/commit/67a725659bd622ac476bd39019209e11a1f18f2b"><code>67a7256</code></a>
Resolve the ThreadResult when worker task setup fails</li>
<li><a
href="https://github.com/gevent/gevent/commit/a3b307bb82cd9b875933a964e883015bf0ce18b2"><code>a3b307b</code></a>
Add change note for <a
href="https://redirect.github.com/gevent/gevent/issues/2211">#2211</a> /
<a
href="https://redirect.github.com/gevent/gevent/issues/2039">#2039</a>
[skip ci]</li>
<li><a
href="https://github.com/gevent/gevent/commit/b0ec8d3b4cb7cde5799dc57d35f74267e3b8259a"><code>b0ec8d3</code></a>
Merge pull request <a
href="https://redirect.github.com/gevent/gevent/issues/2211">#2211</a>
from afonsojanu/fix/subprocess-stdin-mode-missing-bi...</li>
<li><a
href="https://github.com/gevent/gevent/commit/29b00308c74a703e26178229f6edacf98a31a1cb"><code>29b0030</code></a>
Merge pull request <a
href="https://redirect.github.com/gevent/gevent/issues/2210">#2210</a>
from Shivakarthikeya23/issue-1946</li>
<li><a
href="https://github.com/gevent/gevent/commit/47ea41c7e2bc8ca50785a60e929e7335c75fc308"><code>47ea41c</code></a>
Merge pull request <a
href="https://redirect.github.com/gevent/gevent/issues/2208">#2208</a>
from bojanz/issue2206-skip-missing-hooks</li>
<li><a
href="https://github.com/gevent/gevent/commit/0ee0c838cf50255c40647109de5391f84630af6a"><code>0ee0c83</code></a>
Report the full binary mode string from FileObjectPosix</li>
<li><a
href="https://github.com/gevent/gevent/commit/3f3dc574d2b1e5381ea70bfea0da565fd4fcd6c8"><code>3f3dc57</code></a>
Fix AsyncResult accumulating traceback frames on repeated get()</li>
<li>Additional commits viewable in <a
href="https://github.com/gevent/gevent/compare/26.8.0...26.9.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `emoji` from 2.15.0 to 2.16.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/carpedm20/emoji/releases">emoji's
releases</a>.</em></p>
<blockquote>
<h2>v2.16.0</h2>
<ul>
<li>Update to Unicode 18.0</li>
<li>Update translations to CLDR release-49-alpha2</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/carpedm20/emoji/blob/master/CHANGES.md">emoji's
changelog</a>.</em></p>
<blockquote>
<h2>v2.16.0 (2026-09-16)</h2>
<ul>
<li>Update to Unicode 18.0</li>
<li>Update translations to CLDR release-49-alpha2</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/carpedm20/emoji/commit/d5d59d591f8590ada989f0bdf31603b3fe84e103"><code>d5d59d5</code></a>
Merge pull request <a
href="https://redirect.github.com/carpedm20/emoji/issues/335">#335</a>
from carpedm20/update-unicode-18.0</li>
<li><a
href="https://github.com/carpedm20/emoji/commit/7acc7f0740b0ded33c7450d788c6641b74e84e16"><code>7acc7f0</code></a>
update to Unicode 18.0.0</li>
<li>See full diff in <a
href="https://github.com/carpedm20/emoji/compare/v2.15.0...v2.16.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `seleniumbase` from 4.54.5 to 4.54.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/seleniumbase/SeleniumBase/releases">seleniumbase's
releases</a>.</em></p>
<blockquote>
<h2>4.54.9 - MCP Server: Patch 17</h2>
<h2>MCP Server: Patch 17</h2>
<ul>
<li><a
href="https://redirect.github.com/seleniumbase/SeleniumBase/pull/4508/changes/e323a9d851b58a99b8b55b041218f415652a9fd6">Update
the MCP server</a></li>
<li><a
href="https://redirect.github.com/seleniumbase/SeleniumBase/pull/4508/commits/bc88accb2909629f7b0af68be73bebf014c17373">Refresh
Python dependencies</a></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>MCP Server: Patch 17 by <a
href="https://github.com/mdmintz"><code>@​mdmintz</code></a> in <a
href="https://redirect.github.com/seleniumbase/SeleniumBase/pull/4508">seleniumbase/SeleniumBase#4508</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/seleniumbase/SeleniumBase/compare/v4.54.8...v4.54.9">https://github.com/seleniumbase/SeleniumBase/compare/v4.54.8...v4.54.9</a></p>
<h2>4.54.8 - Fix command injection and more</h2>
<h2>Fix command injection and more</h2>
<ul>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/7c8744798ed97616fe246effe982b93b0cc1d15e">Fix
command injection in console scripts</a></li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/7c9871c812bf410164b3a6ed14aec9b9cfe2abd3">Fix
issue with clearing a field that has autocomplete</a></li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/969a36c19fb3a05eec50821ad6be63805a68e21a">Fix
typos in behave_sb.py</a></li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/47034f13729e9f24564c18ba1952b1307798f080">Refactor
console scripts</a></li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/f7da99c23471a0f0a1101b0afd9a0a82d38a99ba">Update
the MCP server</a></li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/4bc64fb41dcd6ea6030887456fe97de72a3443a7">Refresh
Python dependencies</a></li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/c1b492a650c8077ae6ef43915b3a455fab8f4e8d">Update
examples</a></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>Fix command injection and more by <a
href="https://github.com/mdmintz"><code>@​mdmintz</code></a> in <a
href="https://redirect.github.com/seleniumbase/SeleniumBase/pull/4507">seleniumbase/SeleniumBase#4507</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/seleniumbase/SeleniumBase/compare/v4.54.7...v4.54.8">https://github.com/seleniumbase/SeleniumBase/compare/v4.54.7...v4.54.8</a></p>
<h2>4.54.7 - MCP Server: Patch 16</h2>
<h2>MCP Server: Patch 16</h2>
<ul>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/534c0c124002bfb48e10a7198194c91c61f4d4db">Update
the MCP server</a>
--&gt; annotations and docstrings</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/4a5453ee14dff60599b058669eaff025488b75d2">Refresh
Python dependencies</a></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>MCP Server: Patch 16 by <a
href="https://github.com/mdmintz"><code>@​mdmintz</code></a> in <a
href="https://redirect.github.com/seleniumbase/SeleniumBase/pull/4505">seleniumbase/SeleniumBase#4505</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/seleniumbase/SeleniumBase/compare/v4.54.6...v4.54.7">https://github.com/seleniumbase/SeleniumBase/compare/v4.54.6...v4.54.7</a></p>
<h2>4.54.6 - MCP Server: Patch 15</h2>
<h2>MCP Server: Patch 15</h2>
<ul>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/fbc665f3cb19ea6e5eb4ed6ffcf4eec32e4d9580">Add
tool annotations to the MCP Server</a>
--&gt; This resolves <a
href="https://redirect.github.com/seleniumbase/SeleniumBase/issues/4503">seleniumbase/SeleniumBase#4503</a></li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/a406b7f277de3a56dc3d83d4b5466dbca34a35e4">Update
the Dockerfile</a></li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/8c9805f870bd1a2a0bb9b8ef79e710848a9e81f2">Update
CDP Mode</a></li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/7f488faed38e8afce01d18b30291906e75dfe72d">Update
uv</a></li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/b4910211a8e801eebab9f0b1a6679bf1077ac53f">Update
CDP Mode examples</a></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>MCP Server: Patch 15 by <a
href="https://github.com/mdmintz"><code>@​mdmintz</code></a> in <a
href="https://redirect.github.com/seleniumbase/SeleniumBase/pull/4504">seleniumbase/SeleniumBase#4504</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/ddd0f047e522c584221176bccf078784cac03b00"><code>ddd0f04</code></a>
Merge pull request <a
href="https://redirect.github.com/seleniumbase/SeleniumBase/issues/4508">#4508</a>
from seleniumbase/mcp-server-patch-17</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/918078082a49b2a57f3a33fc9a4149973f780e64"><code>9180780</code></a>
Version 4.54.9</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/bc88accb2909629f7b0af68be73bebf014c17373"><code>bc88acc</code></a>
Refresh Python dependencies</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/d10f01b50168d62aea34bdc756ae249f75fdf642"><code>d10f01b</code></a>
Update MCP versioning</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/e323a9d851b58a99b8b55b041218f415652a9fd6"><code>e323a9d</code></a>
Update the MCP server</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/52ceddcfbc466c937f88b322cfa69f11600b1e0a"><code>52ceddc</code></a>
Merge pull request <a
href="https://redirect.github.com/seleniumbase/SeleniumBase/issues/4507">#4507</a>
from seleniumbase/fix-command-injection-and-more</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/1b18c10456cc064ce38e7024913b285b3053197a"><code>1b18c10</code></a>
Version 4.54.8</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/c1b492a650c8077ae6ef43915b3a455fab8f4e8d"><code>c1b492a</code></a>
Update examples</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/a64c668254f20c3384c9f0ec1635de7e9eba45ce"><code>a64c668</code></a>
Update MCP versioning</li>
<li><a
href="https://github.com/seleniumbase/SeleniumBase/commit/4bc64fb41dcd6ea6030887456fe97de72a3443a7"><code>4bc64fb</code></a>
Refresh Python dependencies</li>
<li>Additional commits viewable in <a
href="https://github.com/seleniumbase/SeleniumBase/compare/v4.54.5...v4.54.9">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.7 to 0.16.8
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.8</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-16.</p>
<h3>Bug fixes</h3>
<ul>
<li>Visit functional <code>TypedDict</code> keyword arguments correctly
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28584">#28584</a>)</li>
<li>[<code>flake8-simplify</code>] Detect nested <code>async with</code>
under sync parent (<code>SIM117</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27821">#27821</a>)</li>
<li>[<code>flake8-simplify</code>] Preserve operand order in
<code>SIM109</code> fix (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27824">#27824</a>)</li>
<li>[<code>pyupgrade</code>] Preserve required parentheses in multiline
<code>UP040</code> fixes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28164">#28164</a>)</li>
<li>[<code>pyupgrade</code>] Skip <code>TypeVarTuple</code> and
<code>ParamSpec</code> conversions with bounds or constraints
(<code>UP040</code>, <code>UP046</code>, <code>UP047</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28505">#28505</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Add support for <code>__lazy_modules__</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28459">#28459</a>)</li>
<li>Recognize PEP-728 <code>TypedDict</code> class keywords (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28533">#28533</a>)</li>
<li>Recognize quoted types in <code>typing.TypeForm</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28507">#28507</a>)</li>
<li>Support conditional assignment to <code>__lazy_modules__</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28491">#28491</a>)</li>
<li>[<code>flake8-type-checking</code>] Prefer lazy imports over
<code>TYPE_CHECKING</code> on Python 3.15 and later (<code>TC001</code>,
<code>TC002</code>, <code>TC003</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28541">#28541</a>)</li>
<li>[<code>pyupgrade</code>] Make the fix for <code>UP040</code> always
unsafe (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28526">#28526</a>)</li>
<li>[<code>pyupgrade</code>] Stop recommending deprecated
<code>ByteString</code> aliases (<code>UP035</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28498">#28498</a>)</li>
<li>[<code>ruff</code>, <code>flake8-use-pathlib</code>] Recognize the
<code>parent_mode</code> argument (<code>RUF064</code>,
<code>PTH103</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28528">#28528</a>)</li>
<li>[<code>ruff</code>] Detect <code>\Z</code> in
<code>pytest.raises()</code> match patterns (<code>RUF043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28598">#28598</a>)</li>
</ul>
<h3>CLI</h3>
<ul>
<li>Use rule name and code in formatter incompatibility warnings (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28571">#28571</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>[<code>flake8-tidy-imports</code>] Add
<code>extend-banned-api</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28644">#28644</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/VedantMadane"><code>@​VedantMadane</code></a></li>
<li><a href="https://github.com/alzeph"><code>@​alzeph</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/fredrikblau"><code>@​fredrikblau</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/Aniket-a14"><code>@​Aniket-a14</code></a></li>
<li><a href="https://github.com/r-b-1"><code>@​r-b-1</code></a></li>
</ul>
<h2>Install ruff 0.16.8</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/ruff/releases/download/0.16.8/ruff-installer.sh
| sh
&lt;/tr&gt;&lt;/table&gt; 
</code></pre>
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.8</h2>
<p>Released on 2026-09-16.</p>
<h3>Bug fixes</h3>
<ul>
<li>Visit functional <code>TypedDict</code> keyword arguments correctly
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28584">#28584</a>)</li>
<li>[<code>flake8-simplify</code>] Detect nested <code>async with</code>
under sync parent (<code>SIM117</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27821">#27821</a>)</li>
<li>[<code>flake8-simplify</code>] Preserve operand order in
<code>SIM109</code> fix (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27824">#27824</a>)</li>
<li>[<code>pyupgrade</code>] Preserve required parentheses in multiline
<code>UP040</code> fixes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28164">#28164</a>)</li>
<li>[<code>pyupgrade</code>] Skip <code>TypeVarTuple</code> and
<code>ParamSpec</code> conversions with bounds or constraints
(<code>UP040</code>, <code>UP046</code>, <code>UP047</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28505">#28505</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Add support for <code>__lazy_modules__</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28459">#28459</a>)</li>
<li>Recognize PEP-728 <code>TypedDict</code> class keywords (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28533">#28533</a>)</li>
<li>Recognize quoted types in <code>typing.TypeForm</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28507">#28507</a>)</li>
<li>Support conditional assignment to <code>__lazy_modules__</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28491">#28491</a>)</li>
<li>[<code>flake8-type-checking</code>] Prefer lazy imports over
<code>TYPE_CHECKING</code> on Python 3.15 and later (<code>TC001</code>,
<code>TC002</code>, <code>TC003</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28541">#28541</a>)</li>
<li>[<code>pyupgrade</code>] Make the fix for <code>UP040</code> always
unsafe (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28526">#28526</a>)</li>
<li>[<code>pyupgrade</code>] Stop recommending deprecated
<code>ByteString</code> aliases (<code>UP035</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28498">#28498</a>)</li>
<li>[<code>ruff</code>, <code>flake8-use-pathlib</code>] Recognize the
<code>parent_mode</code> argument (<code>RUF064</code>,
<code>PTH103</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28528">#28528</a>)</li>
<li>[<code>ruff</code>] Detect <code>\Z</code> in
<code>pytest.raises()</code> match patterns (<code>RUF043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28598">#28598</a>)</li>
</ul>
<h3>CLI</h3>
<ul>
<li>Use rule name and code in formatter incompatibility warnings (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28571">#28571</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>[<code>flake8-tidy-imports</code>] Add
<code>extend-banned-api</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28644">#28644</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/VedantMadane"><code>@​VedantMadane</code></a></li>
<li><a href="https://github.com/alzeph"><code>@​alzeph</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/fredrikblau"><code>@​fredrikblau</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/Aniket-a14"><code>@​Aniket-a14</code></a></li>
<li><a href="https://github.com/r-b-1"><code>@​r-b-1</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/62914c4b9b79a9e5004374a9c482ad2ed69290e1"><code>62914c4</code></a>
Bump version to 0.16.8 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28648">#28648</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/c47e0cdc665f56536ce7f7a8ac40fa0ff3f79482"><code>c47e0cd</code></a>
[ty] Bound aliased intersection expansion during inference (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28546">#28546</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/ff4747b509ab4fffbe5689fcae39caa7503d1dcf"><code>ff4747b</code></a>
renovate: update uv hashes correctly with setup-uv (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28621">#28621</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/94efeaa28630d80b2a74adf3c3963de99ed4ee29"><code>94efeaa</code></a>
[ty] Compact reachable binding and declaration histories (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28349">#28349</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/50020fb1e8aa83b0826fa6f5f33a1e93c10cc60e"><code>50020fb</code></a>
[ty] Avoid storing constraint nodes twice (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28375">#28375</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/446bb68da50014bb75f5ce1504a80c5883e3b0b2"><code>446bb68</code></a>
[ty] Compare bound-method receivers before signatures (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28384">#28384</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/304ab86be5de6507e276ab09f5b43f44aeb92469"><code>304ab86</code></a>
[<code>flake8-type-checking</code>] Prefer lazy imports over
<code>TYPE_CHECKING</code> on 3.15+ (`...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/d940b244f7512427b0d87c7953e88c60e69f9bdf"><code>d940b24</code></a>
[ty] Watch script dependencies in CLI watch mode (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28125">#28125</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/fe9f065a504127b11da72c2ff6d7813ddf3ce8ac"><code>fe9f065</code></a>
[flake8-tidy-imports] Add <code>extend-banned-api</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28644">#28644</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/31131db44f057cce68fa6b95552b7db54167b0b3"><code>31131db</code></a>
[ty] Support <code>type[A &amp; B]</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27124">#27124</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.7...0.16.8">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-21 00:44:08 -04:00
CaliBrain e1c3f057ab fix: bypass recordings, welib wrong-md5 links, footer build sha (#1364) (#1373)
Debug screen recordings never started. Every bypass logged "Capturearea
1540x1050 at position 0.0 outside the screen size 1440x1880".We ask
ffmpeg for the fingerprint screen size plus margin, the size wealso pass
SeleniumBase as xvfb_metrics. SeleniumBase builds thatdisplay with
use_xauth=True, the image ships no xauth binary, so itfalls back to a
fixed 1440x1880 Xvfb and the requested size neverexists. Drop
-video_size so x11grab records the whole screen, whateversize it turned
out to be.

welib could hand back a link for a different book. Welib
answers/md5/<md5> with a search for that md5; when it does not have the
file,the resolver took the first "Download" on the results page
(md5a2c1dc0c... resolved to auto_download/9c8cf85d...). On an
/md5/<md5>page a GET/Download link is now only taken when its href names
thatmd5; otherwise the source is reported as not having the file.
Alsoremoves _get_download_urls_from_welib and _is_source_enabled:
themd5-template branch in _get_urls_for_source always handles welib
first,so that resolver could never run.

The footer showed the build date instead of the commit. CI
stampsBUILD_VERSION as <yyyy-mm-dd>-<sha> (pr-<sha> for PR images) and
thefooter kept its first seven characters, so dev images read
"Shelfmarkmain (2026-09)". Take the trailing commit sha instead: "main
(1a5b37d)".The full BUILD_VERSION stays in the hover title
2026-09-21 00:15:41 -04:00
CaliBrain d978896142 fix(auth): rename the API_KEY env var to SHELFMARK_API_KEY (#1374) 2026-09-21 00:10:10 -04:00
Gavin McFallandClaude Fable 5.1 3b280009ae feat(auth): static API_KEY (env) accepted as Bearer or X-Api-Key, cookie or key (#1366)
Supersedes #1353, per the discussion in #1352: one `API_KEY` environment
variable; when set, a request carrying it is authenticated as the first
admin, and cookie sessions keep working exactly as before (cookie **or**
key). Nothing else changes. No table, no UI, no settings-tab switch, no
per-user keys.

## What

- `API_KEY` (env). Unset → the feature is off and none of the new code
runs.
- `Authorization: Bearer <key>` or `X-Api-Key: <key>` on any existing
`/api/*` route authenticates that request as the first admin in
`users.db` (`ORDER BY id`), or as a bare admin identity
(`user_id="api"`, `is_admin=True`, no local user row) if the install has
no admin yet. Per request only; nothing is persisted; the admin's role
is read live, so deleting or demoting that user takes effect on the next
request.
- Both headers are checked and either may match. That is what makes the
key usable behind a reverse proxy that injects its own `Authorization`
header (oauth2-proxy, Authelia, forwardAuth): send the key in
`X-Api-Key`.
- A credential that is **not** the key is ignored and the request
continues on the normal session path, so proxy-forwarded tokens are
unaffected. Without a valid session such a request gets the usual `401
{"error": "Unauthorized"}`, identical to a request with no credential,
so there is nothing to probe.

## How

- `shelfmark/config/env.py`: `API_KEY = os.getenv("API_KEY",
"").strip()`.
- `shelfmark/core/api_key.py`: `extract_api_key_candidates()` (Bearer
token if the scheme is Bearer, then `X-Api-Key`) and `matches_api_key()`
using `hmac.compare_digest` on bytes.
- `shelfmark/core/user_db.py`: `UserDB.get_first_admin()`.
- `shelfmark/main.py`: `api_key_auth_middleware` (`before_request`,
registered before `proxy_auth_middleware`, which early-returns for keyed
requests). Only `/api/` paths; `/api/health` and `/api/auth/*` exempt;
no-op when `API_KEY` is unset or the auth mode is `none`. On a match it
mirrors the proxy-auth pattern: `session.clear()` then populate
`user_id` / `is_admin` / `db_user_id` for this request, `permanent =
False`, `modified = False`, `g.api_key_auth = True`. An `after_request`
hook guarantees no `Set-Cookie` is written for a keyed request even if a
handler dirties the session.
- `docs/api-access.md` (new), the `API_KEY` entry in
`docs/environment-variables.md`, and a README link.

## Security

- Constant-time compare; the key is never logged or echoed.
- Keyed requests never mint or refresh a session cookie and ignore any
cookie sent with them (a non-admin cookie plus the key yields admin for
that request; the browser's own session is left untouched and usable).
- The mismatch path touches neither the session nor `g`, so a stray
bearer on a browser request can neither log the user out nor change how
their cookie is refreshed.
- Store errors during the admin lookup fail closed (`500 {"error":
"Authentication error"}`), never to anonymous.
- Verified against Flask's `save_session` / `should_set_cookie`
ordering, and under auth modes `none`, `builtin`, `proxy`.

## Tests

`tests/core/test_api_key_env.py` (36): extraction and matching;
first-admin lookup; middleware behaviour on a guarded route and an admin
route, with and without a user_db, `X-Api-Key`, both-headers
combinations, no `Set-Cookie` when a handler dirties the session,
incoming non-admin cookie ignored, browser cookie still usable after a
keyed request, security headers, store error → 500, mismatch → guard's
401 / cookie path / permanent cookie untouched, unset → off, exempt
paths and path probes, `none` and `proxy` modes, deleted and demoted
first admin, a keyed write passing the guard. Existing auth suites
unchanged. All CI gates green on the fork:
https://github.com/gavinmcfall/shelfmark/pull/2 (CI-only draft).

Also exercised against a running instance: 47 scripted checks including
150 concurrent requests, proxy-mode switching through the key, an
unset-key restart, and a log scan for the key.

## Naming

`API_KEY` as discussed. If you'd rather namespace it
(`SHELFMARK_API_KEY`) to avoid clashing with other tools' env vars in
shared compose files, it is a one-line change; say the word.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-21 00:00:42 -04:00
splitsec2 1a5b37d9d3 fix(deluge): send seeding ratio limit under Deluge's own keys (#1367)
Deluge's per-torrent options are `stop_at_ratio` (bool) and `stop_ratio`
(float), and `torrentmanager` checks `options['stop_at_ratio'] and
get_ratio() >= options['stop_ratio']`. We were putting the indexer's
float into `stop_at_ratio`, which only switched stopping on and left the
daemon's global ratio (default 2.0) as the one actually enforced. A
`ratio_limit` of 0 turned stopping off entirely. `stop_at_ratio_enabled`
is not a Deluge option at all.

Deluge has no per-torrent seeding time limit, `seed_time_limit` is a
global core preference, so the value is logged as unapplied instead of
sent as a key the daemon drops.

qBittorrent and Transmission already honour both indexer limits, so this
removes a silent difference between clients.

## Verification

- `tests/prowlarr/test_deluge_client.py`: the ratio arrives as
`stop_ratio` with `stop_at_ratio` set, and no key Deluge does not define
is sent. Both fail on current main and pass here.
- Full suite (3165), ruff, ruff format, basedpyright, vulture green.
2026-09-20 23:06:14 -04:00
splitsec2 7c8e89c567 fix(googlebooks): page by the capped size, not the raw limit (#1370)
The Google Books search builds `maxResults` as `min(limit, 40)` because
the API caps a page at 40 volumes, but advances `startIndex` by the full
`limit`. The pages then stop tiling. With `limit=50`, page 1 covers
items 0 to 39 and page 2 starts at 50, so items 40 to 49 are never
returned and every later page drops another 10.

This computes the page size once and uses it for both `maxResults` and
`startIndex`. The shipped frontend asks for 40 and is unaffected.
`/api/metadata/search` clamps `limit` to 100, so an API caller passing
41 to 100 was hitting it.

One thing I left alone. The provider uses the base `search_paginated`
heuristic, `has_more = len(books) >= options.limit`, which still reports
`has_more: false` for a limit above 40 since Google can never return
that many. That was already the behaviour before this change, and fixing
it means either touching the shared heuristic or adding a provider
override, so I kept this patch to the stride. Happy to follow up if you
want it.

## Verification

- `tests/metadata/test_googlebooks_parse.py`: pages 1 and 2 at
`limit=50` must tile exactly, plus a guard that `limit=25` still strides
by 25. The first fails on current main and passes here.
- Full suite (3165), ruff, ruff format, basedpyright, vulture green.
2026-09-20 23:05:48 -04:00
splitsec2 bc03ad062e fix(http): keep the host of a protocol-relative download link (#1368)
`get_absolute_url()` replaced both `netloc` and `scheme` whenever either
one was missing. A protocol-relative href such as
`//cdn.example.org/f.epub`, scraped from a page on
`https://annas-archive.org/...`, parses with a netloc and an empty
scheme, so it came back pointing at the page's own host. The download
then 404s and the source is skipped.

Each field now falls back to the base URL only when the parsed URL does
not supply it. Plain relative paths resolve exactly as before, which the
control test covers.

This affects the Z-Library, welib and generic download link handling in
`release_sources/direct_download/annas_archive.py`.

## Verification

- New `tests/download/test_http_absolute_url.py`: a protocol-relative
link keeps its own host, and a plain `/path` still resolves against the
base. The first fails on current main and passes here.
- Full suite (3165), ruff, ruff format, basedpyright, vulture green.
2026-09-20 23:04:22 -04:00
splitsec2 ab3aa9a8b0 fix(requests): reject non-object items in the batch endpoint (#1369)
`POST /api/requests/batch` checks that `requests` is a non-empty list
and then hands each element to the shared preparation helper, which
calls `.get()` on it. A bare string, number or null in the list raises
`AttributeError` and the caller gets a 500, while `POST /api/requests`
answers 400 with a message for the same mistake.

This validates the element type beside the existing list check. One bad
item rejects the whole batch rather than being reported per item, which
matches the endpoint's current contract: every other failure path
already aborts the batch with a single error body, as
`test_batch_create_requests_is_atomic` asserts. Responses for valid
payloads are unchanged.

## Verification

- `tests/core/test_request_routes_api.py`: a case per bad shape (int,
str, null, list), plus a mixed valid and invalid batch that asserts
nothing was created. All fail on current main with a 500 and pass here.
- Full suite (3168), ruff, ruff format, basedpyright, vulture green.
2026-09-20 23:03:31 -04:00
Paul Rimmer d4619be69a Feature: Show the AA search result stats (#1362)
When doing a direct search for a book, show the stats of the AA results.
For example if we search for "The Great Gatsby", AA reports it has 240
hits and shows the first page of 50. Provide this stats info in the
shelfmark webUI via ResultsSection.tsx and ReleaseModal.tsx. This table
shows what should be displayed based on the total number of hits found:

|Total	|Display|
|-------|-------|
|1	|"Result 1 (1 Total)"|
|6	|"Results 1-6 (6 Total)"|
|144	|"Results 1-50 (144 Total)"|
|500+	|"Results 1-50 (500+ Total)"|

Currently, shelfmark also only shows us the first 50 search hits even if
there were more available from AA. This could be added later if
considered desirable.

As usual, a picture is worth a 1000 words:

<img width="1012" height="610" alt="direct-results-stat"
src="https://github.com/user-attachments/assets/8c0c688f-444e-482a-a9a3-2dee5a5563b8"
/>

<img width="1013" height="741" alt="universal-results-info"
src="https://github.com/user-attachments/assets/399bbb79-87f2-4432-a3d0-64937795f5f1"
/>

Coded with llama.cpp, opencode and 🤖
2026-09-20 13:03:32 -04:00
splitsec2 c1315a2b23 fix(download): check task ownership before serving queued files (#1357)
`/api/localdownload` resolves the file through the live queue and
returns it before checking who owns the task; the owner check only runs
on the download-history fallback, once the task has aged out of the
queue. Task ids are source ids, so two users who searched the same book
can end up with the same id.

This applies the same rule on the queue path, reusing the
`_task_owned_by_actor` helper the cancel/retry/priority routes already
use, so both paths answer a non-owner with the same 404. Admin behaviour
is unchanged.

The 404 matches what this endpoint's history path already returns for a
non-owner rather than the 403 `download_not_owned` the
cancel/retry/priority routes use, happy to switch it if you prefer
consistency with the siblings instead.

## Verification

- `tests/core/test_activity_routes_api.py`: the owner still receives
their queued file; a different user receives 404. The new case fails on
current main and passes here; the existing history-fallback test is
unchanged.
- Full suite (3148), ruff, ruff format, basedpyright, vulture green.
2026-09-20 12:56:23 -04:00
splitsec2 7934924678 fix(queue): don't stamp CANCELLED over a finished download (#1361)
`cancel_download` reads the task status under the queue lock, releases
it, and only then writes CANCELLED through `update_status`. A download
that finishes in that window has its COMPLETE overwritten. The queue and
the UI show the task as cancelled while the file is already on disk, and
the terminal hook fires for both statuses.

The check and the write now happen in a single lock hold. Because the
lock is non-reentrant and the terminal hook has to run after it is
released (the stall canceller depends on that), the lock-held part of
`update_status` moved into a small private helper that both paths share;
`update_status` is a thin wrapper over it. A cancel arriving once the
task is already terminal still returns `False`.

## Verification

-
`tests/core/test_queue.py::test_cancel_does_not_overwrite_a_download_that_finished_first`:
a worker thread completes the download while the cancel is in flight,
with the handover driven by events rather than sleeps. The task stays
complete. Fails on main, passes here.
- Full suite (3147), plus `tests/download/` and
`tests/core/test_download_api_guardrails.py`, ruff, ruff format,
basedpyright, vulture green.
2026-09-20 12:54:05 -04:00
splitsec2 a6204a318e fix(oidc): reject backslash paths in the return_to sanitizer (#1359)
The OIDC `return_to` sanitizer rejects values starting with `//` and
then relies on `urlsplit` to catch anything carrying a netloc. A value
such as `/\host` has no netloc, so it is stored in the session and used
as the post-login redirect target and browsers resolve the backslash as
a path separator, which lands the user outside the app after a
successful login.

`_normalize_return_to` now also rejects values whose path contains a
backslash. That matches the frontend sanitizer in `authRedirect.ts`,
which parses with `URL` and already discards those forms, so the two
ends agree again. The check covers the path only, so query and fragment
backslashes still round-trip, and it also catches the script-root case
where `/app/\host` strips to `/\host`.

## Verification

- New cases in `tests/core/test_oidc_routes.py` cover the rejected
forms, including under a script root, and confirm `/`, `/settings` and
`/search?q=x#frag` are unaffected. They fail on current main and pass
here.
- Full suite (3155), ruff, ruff format, basedpyright, vulture green.
2026-09-20 12:51:21 -04:00
splitsec2 545480c557 fix(download): default is_admin to False in the request policy guard (#1358)
`_resolve_policy_mode_for_current_user` reads `session.get("is_admin",
True)`, so a session carrying `user_id` but no `is_admin` key skips the
request policy entirely, while every other admin check in the codebase
defaults the key to `False`.

This uses the same default here. Every authenticated login path
(builtin, CWA, proxy, OIDC) writes `is_admin` into the session, and
`AUTH_METHOD=none` is already short-circuited one line earlier, so
sessions from those flows behave exactly as before.

## Verification

- `tests/core/test_request_routes_api.py::TestDownloadPolicyGuards`: a
session without `is_admin` now gets `policy_requires_request` and
nothing is queued. Fails on current main, passes here.
- Full suite (3147), ruff, ruff format, basedpyright, vulture green.
2026-09-20 12:50:53 -04:00
splitsec2 127dd82615 fix(users): apply user updates only after the payload validates (#1360)
`PUT /api/users/me` and `PUT /api/admin/users/<id>` write the new
password hash, and then the profile fields, before the rest of the
payload is checked. When the request is rejected further down as an
invalid role, an admin-only setting, an invalid settings value, the
route answers 400 with those writes already committed, so the caller
sees an error while the password has in fact changed.

Both routes now validate the whole payload before touching the database,
and the password hash is folded into the same `update_user` call as the
other fields so the field write is a single transaction. Error messages,
status codes and the order they are reported in are unchanged.

## Verification

- New tests in `tests/core/test_self_user_routes.py` and
`tests/core/test_admin_users_api.py` assert that a rejected update
leaves the password, profile fields and role as they were, plus a
positive case that a valid payload still applies all three. They fail on
current main and pass here.
- Full suite (3150), ruff, ruff format, basedpyright, vulture green.
2026-09-20 12:50:14 -04:00
splitsec2 acd59f7cbb feat(auth): provision proxy users as non-admin once an admin exists (#1356)
With `AUTH_METHOD=proxy` and no admin group configured, every user the
proxy authenticates for the first time is provisioned as an admin
(`is_admin = True` unless the user already exists in `users.db`). The
intent to never lock an instance out makes sense, but the effect is that
anyone the SSO gate lets through becomes an administrator. On an
instance shared with family or a small community that is a footgun; I
hit it when the first invited reader landed as an admin.

This keeps the guarantee and removes the footgun: the first account is
still provisioned as an admin while the instance has no admin at all,
and later first-time users follow a new `PROXY_AUTH_DEFAULT_ROLE`
setting (Security tab / env), default `user`. Known users keep their
stored role; the `PROXY_AUTH_ADMIN_GROUP_NAME` path is unchanged and
still takes precedence. I couldn't find a way with Cloudflare access to
pass this along.

Changes: `UserDB.has_admin()`, `_proxy_default_is_admin()` in the proxy
middleware, the new `SelectField` beside the other proxy settings, the
regenerated `docs/environment-variables.md` entry and a row in
`docs/reverse-proxy.md`.

Compatibility: the default moves from "everyone admin" to "first admin,
then users". Accounts already in `users.db` are unaffected; new SSO
users on an existing instance become regular users unless
`PROXY_AUTH_DEFAULT_ROLE=admin` is set. If you would rather ship this
purely opt-in I can flip the default to `admin`.

## Verification

- `tests/core/test_auth_api.py::TestProxyProvisioningRole`: first user
admin / second user not; `PROXY_AUTH_DEFAULT_ROLE=admin` restores the
old behaviour; an admin from another auth source counts as "an admin
exists"; a known user keeps their role whatever the default.
- Full suite (3094), ruff, ruff format, basedpyright, vulture green.
- Running on my own instance since 2026-09-19.
2026-09-19 23:27:13 -04:00
dependabot[bot] c42edac363 build(deps): bump the gh-actions group with 6 updates (#1350)
Bumps the gh-actions group with 6 updates:

| Package | From | To |
| --- | --- | --- |
|
[docker/setup-buildx-action](https://github.com/docker/setup-buildx-action)
| `4.3.0` | `4.4.0` |
|
[docker/build-push-action](https://github.com/docker/build-push-action)
| `7.3.0` | `7.4.0` |
| [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `10.0.1`
| `10.1.0` |
| [github/codeql-action/init](https://github.com/github/codeql-action) |
`4.37.9` | `4.38.0` |
|
[github/codeql-action/autobuild](https://github.com/github/codeql-action)
| `4.37.9` | `4.38.0` |
|
[github/codeql-action/analyze](https://github.com/github/codeql-action)
| `4.37.9` | `4.38.0` |

Updates `docker/setup-buildx-action` from 4.3.0 to 4.4.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/docker/setup-buildx-action/releases">docker/setup-buildx-action's
releases</a>.</em></p>
<blockquote>
<h2>v4.4.0</h2>
<ul>
<li>Use official Buildx releases for cloud driver by <a
href="https://github.com/crazy-max"><code>@​crazy-max</code></a> in <a
href="https://redirect.github.com/docker/setup-buildx-action/pull/606">docker/setup-buildx-action#606</a></li>
<li>Pull BuildKit image before builder creation by <a
href="https://github.com/crazy-max"><code>@​crazy-max</code></a> in <a
href="https://redirect.github.com/docker/setup-buildx-action/pull/609">docker/setup-buildx-action#609</a></li>
<li>Use shared error helpers for Buildx and Docker commands by <a
href="https://github.com/crazy-max"><code>@​crazy-max</code></a> in <a
href="https://redirect.github.com/docker/setup-buildx-action/pull/620">docker/setup-buildx-action#620</a></li>
<li>Bump <code>@​docker/actions-toolkit</code> from 0.95.0 to 0.100.0 in
<a
href="https://redirect.github.com/docker/setup-buildx-action/pull/610">docker/setup-buildx-action#610</a>
<a
href="https://redirect.github.com/docker/setup-buildx-action/pull/618">docker/setup-buildx-action#618</a>
<a
href="https://redirect.github.com/docker/setup-buildx-action/pull/619">docker/setup-buildx-action#619</a></li>
<li>Bump <code>@​humanfs/node</code> from 0.16.7 to 0.16.8 in <a
href="https://redirect.github.com/docker/setup-buildx-action/pull/614">docker/setup-buildx-action#614</a></li>
<li>Bump js-yaml from 5.3.0 to 5.4.2 in <a
href="https://redirect.github.com/docker/setup-buildx-action/pull/608">docker/setup-buildx-action#608</a>
<a
href="https://redirect.github.com/docker/setup-buildx-action/pull/617">docker/setup-buildx-action#617</a></li>
<li>Bump postcss-selector-parser from 7.1.1 to 7.1.5 in <a
href="https://redirect.github.com/docker/setup-buildx-action/pull/611">docker/setup-buildx-action#611</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/docker/setup-buildx-action/compare/v4.3.0...v4.4.0">https://github.com/docker/setup-buildx-action/compare/v4.3.0...v4.4.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/594f3bf4285d9ea8dc53c9a0c9c4092420091003"><code>594f3bf</code></a>
Merge pull request <a
href="https://redirect.github.com/docker/setup-buildx-action/issues/609">#609</a>
from crazy-max/pull-buildkit-image-before-create</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/bd6e702fc33b636671900d5b5edfab64698c9c25"><code>bd6e702</code></a>
chore: update generated content</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/6268c9da9abbd1309c8a16a75f92a878715c3032"><code>6268c9d</code></a>
pull BuildKit image before builder creation</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/e8235251b82e23c90e6fad50016f0a78b7f28f11"><code>e823525</code></a>
Merge pull request <a
href="https://redirect.github.com/docker/setup-buildx-action/issues/621">#621</a>
from docker/dependabot/github_actions/codeql-actions-...</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/533ed8ed095b0b133ef16fb495aad119524e220d"><code>533ed8e</code></a>
build(deps): bump the codeql-actions group with 2 updates</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/bedaf135699075c88620cd30772b9b6eadc9ba99"><code>bedaf13</code></a>
Merge pull request <a
href="https://redirect.github.com/docker/setup-buildx-action/issues/620">#620</a>
from crazy-max/shared-error-helpers</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/d5079fba84d5edd23d25ba7f3045122175ca6ee2"><code>d5079fb</code></a>
chore: update generated content</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/226a61612ab71c26bbd805f955834049a4a9772f"><code>226a616</code></a>
use shared error helpers for Buildx and Docker commands</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/77ce7f4bab9bc462d825001cde7f82d409ee474c"><code>77ce7f4</code></a>
Merge pull request <a
href="https://redirect.github.com/docker/setup-buildx-action/issues/619">#619</a>
from docker/dependabot/npm_and_yarn/docker/actions-to...</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/0dc1dc94f0f7c064e93fda72884ca71e054c0354"><code>0dc1dc9</code></a>
[dependabot skip] chore: update generated content</li>
<li>Additional commits viewable in <a
href="https://github.com/docker/setup-buildx-action/compare/37fe631027851001ddb9b187196cc803df7f5f0e...594f3bf4285d9ea8dc53c9a0c9c4092420091003">compare
view</a></li>
</ul>
</details>
<br />

Updates `docker/build-push-action` from 7.3.0 to 7.4.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/docker/build-push-action/releases">docker/build-push-action's
releases</a>.</em></p>
<blockquote>
<h2>v7.4.0</h2>
<ul>
<li>Use the shared error helper for Buildx commands by <a
href="https://github.com/crazy-max"><code>@​crazy-max</code></a> in <a
href="https://redirect.github.com/docker/build-push-action/pull/1620">docker/build-push-action#1620</a></li>
<li>Prevent workflow command injection in metadata logs by <a
href="https://github.com/crazy-max"><code>@​crazy-max</code></a> in <a
href="https://redirect.github.com/docker/build-push-action/pull/1617">docker/build-push-action#1617</a></li>
<li>Bump <code>@​docker/actions-toolkit</code> from 0.92.0 to 0.100.0 in
<a
href="https://redirect.github.com/docker/build-push-action/pull/1614">docker/build-push-action#1614</a>
<a
href="https://redirect.github.com/docker/build-push-action/pull/1618">docker/build-push-action#1618</a>
<a
href="https://redirect.github.com/docker/build-push-action/pull/1621">docker/build-push-action#1621</a></li>
<li>Bump <code>@​humanfs/node</code> from 0.16.7 to 0.16.8 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1609">docker/build-push-action#1609</a></li>
<li>Bump brace-expansion from 1.1.13 to 1.1.18 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1592">docker/build-push-action#1592</a></li>
<li>Bump csv-parse from 7.0.0 to 7.0.2 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1613">docker/build-push-action#1613</a></li>
<li>Bump js-yaml from 4.3.0 to 4.3.2 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1605">docker/build-push-action#1605</a>
<a
href="https://redirect.github.com/docker/build-push-action/pull/1615">docker/build-push-action#1615</a></li>
<li>Bump nanoid from 3.3.16 to 3.3.18 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1611">docker/build-push-action#1611</a></li>
<li>Bump postcss from 8.5.10 to 8.5.25 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1590">docker/build-push-action#1590</a></li>
<li>Bump postcss-selector-parser from 7.1.1 to 7.1.5 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1606">docker/build-push-action#1606</a></li>
<li>Bump sigstore from 4.1.0 to 4.1.1 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1577">docker/build-push-action#1577</a></li>
<li>Bump undici from 6.27.0 to 6.28.0 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1594">docker/build-push-action#1594</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0">https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc"><code>c3c9e26</code></a>
Merge pull request <a
href="https://redirect.github.com/docker/build-push-action/issues/1621">#1621</a>
from docker/dependabot/npm_and_yarn/docker/actions-t...</li>
<li><a
href="https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42"><code>459b674</code></a>
[dependabot skip] chore: update generated content</li>
<li><a
href="https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e"><code>4dedcb2</code></a>
chore(deps): Bump <code>@​docker/actions-toolkit</code> from 0.99.0 to
0.100.0</li>
<li><a
href="https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952"><code>379bf63</code></a>
Merge pull request <a
href="https://redirect.github.com/docker/build-push-action/issues/1620">#1620</a>
from crazy-max/buildx-error-message</li>
<li><a
href="https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6"><code>9877975</code></a>
chore: update generated content</li>
<li><a
href="https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94"><code>7ed0556</code></a>
use the shared Buildx error summary helper</li>
<li><a
href="https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1"><code>91670ba</code></a>
Merge pull request <a
href="https://redirect.github.com/docker/build-push-action/issues/1618">#1618</a>
from docker/dependabot/npm_and_yarn/docker/actions-t...</li>
<li><a
href="https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a"><code>80dbc86</code></a>
[dependabot skip] chore: update generated content</li>
<li><a
href="https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d"><code>50cac3a</code></a>
chore(deps): Bump <code>@​docker/actions-toolkit</code> from 0.98.0 to
0.99.0</li>
<li><a
href="https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1"><code>03b4d6c</code></a>
Merge pull request <a
href="https://redirect.github.com/docker/build-push-action/issues/1617">#1617</a>
from crazy-max/fix-metadata-workflow-commands</li>
<li>Additional commits viewable in <a
href="https://github.com/docker/build-push-action/compare/53b7df96c91f9c12dcc8a07bcb9ccacbed38856a...c3c9e263c25d99ce0380d002d59b67737d91b0dc">compare
view</a></li>
</ul>
</details>
<br />

Updates `astral-sh/setup-uv` from 10.0.1 to 10.1.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/setup-uv/releases">astral-sh/setup-uv's
releases</a>.</em></p>
<blockquote>
<h2>v10.1.0 🌈 New output <code>python-runtime-id</code>and respect
NO_PROXY</h2>
<h2>Changes</h2>
<p>This release adds more bheind the scene security improvements and
also 2 small improvements.</p>
<h3>NO_PROXY</h3>
<p>This action now respects <code>no_proxy/NO_PROXY</code> environment
variables which were previously ignored.</p>
<h3>New output <code>python-runtime-id</code></h3>
<p>The new output <code>python-runtime-id</code> can be used to know
which python version exactly was installed if you use
<code>activate-environment</code>. See <a
href="https://redirect.github.com/pyca/cryptography/pull/15572#discussion_r3913508686">pyca/cryptography#15572</a>
for details on why this can be useful.</p>
<h2>🐛 Bug fixes</h2>
<ul>
<li>fix: respect no proxy directive <a
href="https://github.com/mj0nez"><code>@​mj0nez</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1037">#1037</a>)</li>
<li>Use JSON + a typed wrapper instead of TS codegen <a
href="https://github.com/woodruffw"><code>@​woodruffw</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1025">#1025</a>)</li>
</ul>
<h2>🚀 Enhancements</h2>
<ul>
<li>Expose a Python &quot;identity&quot; output <a
href="https://github.com/woodruffw"><code>@​woodruffw</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1036">#1036</a>)</li>
<li>Verify downloads with astral-sh/versions checksums <a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1033">#1033</a>)</li>
</ul>
<h2>🧰 Maintenance</h2>
<ul>
<li>chore: update known checksums for 0.12.12 @<a
href="https://github.com/apps/github-actions">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1041">#1041</a>)</li>
<li>chore: update known checksums for 0.12.10/0.12.11 @<a
href="https://github.com/apps/github-actions">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1038">#1038</a>)</li>
<li>chore: update known checksums for 0.12.9 @<a
href="https://github.com/apps/github-actions">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1035">#1035</a>)</li>
<li>chore: update known checksums for 0.12.7/0.12.8 @<a
href="https://github.com/apps/github-actions">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1031">#1031</a>)</li>
<li>chore: update known checksums for 0.12.6 @<a
href="https://github.com/apps/github-actions">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1030">#1030</a>)</li>
<li>chore: update known checksums for 0.12.5 @<a
href="https://github.com/apps/github-actions">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1020">#1020</a>)</li>
<li>Use self-repo syntax for all in-repo actions/reusable workflows <a
href="https://github.com/woodruffw"><code>@​woodruffw</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1024">#1024</a>)</li>
<li>Pin one-shot tools <a
href="https://github.com/woodruffw"><code>@​woodruffw</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1022">#1022</a>)</li>
<li>ci: remove obsolete direct push attempts <a
href="https://github.com/eifinger"><code>@​eifinger</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1019">#1019</a>)</li>
</ul>
<h2>📚 Documentation</h2>
<ul>
<li>docs: update version references to v10.0.1 @<a
href="https://github.com/apps/github-actions">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1018">#1018</a>)</li>
</ul>
<h2>⬆️ Dependency updates</h2>
<ul>
<li>chore(deps-dev): roll up Dependabot updates <a
href="https://github.com/eifinger"><code>@​eifinger</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1043">#1043</a>)</li>
<li>Harden npm install defaults <a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1026">#1026</a>)</li>
<li>Add dependency cooldowns <a
href="https://github.com/woodruffw"><code>@​woodruffw</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1021">#1021</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/bec219d24cd3e171d82865faccec33120bb574f4"><code>bec219d</code></a>
chore(deps-dev): roll up Dependabot updates (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1043">#1043</a>)</li>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/b90ec40d15bfa44c33c6700196eb6efcdddb4373"><code>b90ec40</code></a>
fix: respect no proxy directive (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1037">#1037</a>)</li>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/421feb646df5262e7dd93bc54161edfa30372417"><code>421feb6</code></a>
chore: update known checksums for 0.12.12 (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1041">#1041</a>)</li>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/f634bf473ad85bf3e23a613f52c5fa9f363874fc"><code>f634bf4</code></a>
Expose a Python &quot;identity&quot; output (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1036">#1036</a>)</li>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/a6772c8f0a09dc9e3582c70a994b0c55af921803"><code>a6772c8</code></a>
chore: update known checksums for 0.12.10/0.12.11 (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1038">#1038</a>)</li>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/e105c8fb1d7b13074b851babdaef4185243c6a07"><code>e105c8f</code></a>
chore: update known checksums for 0.12.9 (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1035">#1035</a>)</li>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/cd13f9217092d43a771cf9ba7b09bdd3da8d7c4d"><code>cd13f92</code></a>
Verify downloads with astral-sh/versions checksums (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1033">#1033</a>)</li>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/3aef7b92c52cec135792ea1e95f4c77683d39e61"><code>3aef7b9</code></a>
chore: update known checksums for 0.12.7/0.12.8 (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1031">#1031</a>)</li>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/d08d816a1ea176d61a318eff45abd3dffef415b1"><code>d08d816</code></a>
chore: update known checksums for 0.12.6 (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1030">#1030</a>)</li>
<li><a
href="https://github.com/astral-sh/setup-uv/commit/19b4d1e990bec64818914c40230bde93a0de300b"><code>19b4d1e</code></a>
Harden npm install defaults (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/1026">#1026</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/setup-uv/compare/20cfd1bf945f4377ade1205e4dbc17946fc9a30d...bec219d24cd3e171d82865faccec33120bb574f4">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/codeql-action/init` from 4.37.9 to 4.38.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/init's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.0</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/init's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.2 - 21 Jul 2026</h2>
<ul>
<li>The new address format for the <code>config-file</code> input that
was introduced in CodeQL Action 4.37.0 is now enabled by default. In
addition to the format described there, the <code>remote=</code> prefix
can now be used to explicitly indicate that the input refers to a remote
file. All previous input formats continue to be accepted as well. <a
href="https://redirect.github.com/github/codeql-action/pull/4023">#4023</a></li>
<li>The CodeQL Action can now make use of <a
href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries">configured
private registries</a> in Default Setup to retrieve CodeQL configuration
files from remote repositories that require authentication. This will
allow customers to store their CodeQL configuration in a single
repository that can then be referenced by Default Setup workflows in
other repositories. We expect to roll this and other, related changes
out to everyone in July. <a
href="https://redirect.github.com/github/codeql-action/pull/4007">#4007</a></li>
</ul>
<h2>4.37.1 - 16 Jul 2026</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/b96794f015dfd88f77b49b1c93e0fa7110f94c63"><code>b96794f</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4131">#4131</a>
from github/update-v4.38.0-7e08580a9</li>
<li><a
href="https://github.com/github/codeql-action/commit/02d5093871674ea20274117103ce3038c73c77ef"><code>02d5093</code></a>
Update changelog for v4.38.0</li>
<li><a
href="https://github.com/github/codeql-action/commit/7e08580a93dc4e4b9dda167e364577035cf504c6"><code>7e08580</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4130">#4130</a>
from github/henrymercer/workflow-runner-sizing</li>
<li><a
href="https://github.com/github/codeql-action/commit/bfcc52b4f5d98468a5993daa0bf0e4fb3f3ed698"><code>bfcc52b</code></a>
Run slow macOS checks on larger runners</li>
<li><a
href="https://github.com/github/codeql-action/commit/8c251e757c0260283fc50214a06ac768b61d3af4"><code>8c251e7</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4129">#4129</a>
from github/update-bundle/codeql-bundle-v2.27.0</li>
<li><a
href="https://github.com/github/codeql-action/commit/0b7ca400df35985869d4b9146a067865d4115da1"><code>0b7ca40</code></a>
Add changelog note</li>
<li><a
href="https://github.com/github/codeql-action/commit/40484b339517c6bcf00f81eebc95ca041ddca505"><code>40484b3</code></a>
Update default bundle to codeql-bundle-v2.27.0</li>
<li><a
href="https://github.com/github/codeql-action/commit/977e6ceaea7361825998245d787fa3b4d6b9e5df"><code>977e6ce</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4124">#4124</a>
from github/henrymercer/toolcache-bundle-cleanup</li>
<li><a
href="https://github.com/github/codeql-action/commit/40a6b3824794ae1156e1a5320d32e364bf1dcebc"><code>40a6b38</code></a>
Address toolcache cleanup review feedback</li>
<li><a
href="https://github.com/github/codeql-action/commit/deece8f852f048bc3f52fd42c9cc7a99b1ebb252"><code>deece8f</code></a>
Apply suggestion from <a
href="https://github.com/henrymercer"><code>@​henrymercer</code></a></li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/cdf488f595d80d6e07e03d4674febd5ab45fa938...b96794f015dfd88f77b49b1c93e0fa7110f94c63">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/codeql-action/autobuild` from 4.37.9 to 4.38.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/autobuild's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.0</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/autobuild's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.2 - 21 Jul 2026</h2>
<ul>
<li>The new address format for the <code>config-file</code> input that
was introduced in CodeQL Action 4.37.0 is now enabled by default. In
addition to the format described there, the <code>remote=</code> prefix
can now be used to explicitly indicate that the input refers to a remote
file. All previous input formats continue to be accepted as well. <a
href="https://redirect.github.com/github/codeql-action/pull/4023">#4023</a></li>
<li>The CodeQL Action can now make use of <a
href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries">configured
private registries</a> in Default Setup to retrieve CodeQL configuration
files from remote repositories that require authentication. This will
allow customers to store their CodeQL configuration in a single
repository that can then be referenced by Default Setup workflows in
other repositories. We expect to roll this and other, related changes
out to everyone in July. <a
href="https://redirect.github.com/github/codeql-action/pull/4007">#4007</a></li>
</ul>
<h2>4.37.1 - 16 Jul 2026</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/b96794f015dfd88f77b49b1c93e0fa7110f94c63"><code>b96794f</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4131">#4131</a>
from github/update-v4.38.0-7e08580a9</li>
<li><a
href="https://github.com/github/codeql-action/commit/02d5093871674ea20274117103ce3038c73c77ef"><code>02d5093</code></a>
Update changelog for v4.38.0</li>
<li><a
href="https://github.com/github/codeql-action/commit/7e08580a93dc4e4b9dda167e364577035cf504c6"><code>7e08580</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4130">#4130</a>
from github/henrymercer/workflow-runner-sizing</li>
<li><a
href="https://github.com/github/codeql-action/commit/bfcc52b4f5d98468a5993daa0bf0e4fb3f3ed698"><code>bfcc52b</code></a>
Run slow macOS checks on larger runners</li>
<li><a
href="https://github.com/github/codeql-action/commit/8c251e757c0260283fc50214a06ac768b61d3af4"><code>8c251e7</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4129">#4129</a>
from github/update-bundle/codeql-bundle-v2.27.0</li>
<li><a
href="https://github.com/github/codeql-action/commit/0b7ca400df35985869d4b9146a067865d4115da1"><code>0b7ca40</code></a>
Add changelog note</li>
<li><a
href="https://github.com/github/codeql-action/commit/40484b339517c6bcf00f81eebc95ca041ddca505"><code>40484b3</code></a>
Update default bundle to codeql-bundle-v2.27.0</li>
<li><a
href="https://github.com/github/codeql-action/commit/977e6ceaea7361825998245d787fa3b4d6b9e5df"><code>977e6ce</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4124">#4124</a>
from github/henrymercer/toolcache-bundle-cleanup</li>
<li><a
href="https://github.com/github/codeql-action/commit/40a6b3824794ae1156e1a5320d32e364bf1dcebc"><code>40a6b38</code></a>
Address toolcache cleanup review feedback</li>
<li><a
href="https://github.com/github/codeql-action/commit/deece8f852f048bc3f52fd42c9cc7a99b1ebb252"><code>deece8f</code></a>
Apply suggestion from <a
href="https://github.com/henrymercer"><code>@​henrymercer</code></a></li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/cdf488f595d80d6e07e03d4674febd5ab45fa938...b96794f015dfd88f77b49b1c93e0fa7110f94c63">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/codeql-action/analyze` from 4.37.9 to 4.38.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/analyze's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.0</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/analyze's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.2 - 21 Jul 2026</h2>
<ul>
<li>The new address format for the <code>config-file</code> input that
was introduced in CodeQL Action 4.37.0 is now enabled by default. In
addition to the format described there, the <code>remote=</code> prefix
can now be used to explicitly indicate that the input refers to a remote
file. All previous input formats continue to be accepted as well. <a
href="https://redirect.github.com/github/codeql-action/pull/4023">#4023</a></li>
<li>The CodeQL Action can now make use of <a
href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries">configured
private registries</a> in Default Setup to retrieve CodeQL configuration
files from remote repositories that require authentication. This will
allow customers to store their CodeQL configuration in a single
repository that can then be referenced by Default Setup workflows in
other repositories. We expect to roll this and other, related changes
out to everyone in July. <a
href="https://redirect.github.com/github/codeql-action/pull/4007">#4007</a></li>
</ul>
<h2>4.37.1 - 16 Jul 2026</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/b96794f015dfd88f77b49b1c93e0fa7110f94c63"><code>b96794f</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4131">#4131</a>
from github/update-v4.38.0-7e08580a9</li>
<li><a
href="https://github.com/github/codeql-action/commit/02d5093871674ea20274117103ce3038c73c77ef"><code>02d5093</code></a>
Update changelog for v4.38.0</li>
<li><a
href="https://github.com/github/codeql-action/commit/7e08580a93dc4e4b9dda167e364577035cf504c6"><code>7e08580</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4130">#4130</a>
from github/henrymercer/workflow-runner-sizing</li>
<li><a
href="https://github.com/github/codeql-action/commit/bfcc52b4f5d98468a5993daa0bf0e4fb3f3ed698"><code>bfcc52b</code></a>
Run slow macOS checks on larger runners</li>
<li><a
href="https://github.com/github/codeql-action/commit/8c251e757c0260283fc50214a06ac768b61d3af4"><code>8c251e7</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4129">#4129</a>
from github/update-bundle/codeql-bundle-v2.27.0</li>
<li><a
href="https://github.com/github/codeql-action/commit/0b7ca400df35985869d4b9146a067865d4115da1"><code>0b7ca40</code></a>
Add changelog note</li>
<li><a
href="https://github.com/github/codeql-action/commit/40484b339517c6bcf00f81eebc95ca041ddca505"><code>40484b3</code></a>
Update default bundle to codeql-bundle-v2.27.0</li>
<li><a
href="https://github.com/github/codeql-action/commit/977e6ceaea7361825998245d787fa3b4d6b9e5df"><code>977e6ce</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4124">#4124</a>
from github/henrymercer/toolcache-bundle-cleanup</li>
<li><a
href="https://github.com/github/codeql-action/commit/40a6b3824794ae1156e1a5320d32e364bf1dcebc"><code>40a6b38</code></a>
Address toolcache cleanup review feedback</li>
<li><a
href="https://github.com/github/codeql-action/commit/deece8f852f048bc3f52fd42c9cc7a99b1ebb252"><code>deece8f</code></a>
Apply suggestion from <a
href="https://github.com/henrymercer"><code>@​henrymercer</code></a></li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/cdf488f595d80d6e07e03d4674febd5ab45fa938...b96794f015dfd88f77b49b1c93e0fa7110f94c63">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-19 23:19:16 -04:00
dependabot[bot] d09ec9de25 build(deps): bump the npm-deps group in /src/frontend with 9 updates (#1349)
Bumps the npm-deps group in /src/frontend with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [react](https://github.com/react/react/tree/HEAD/packages/react) |
`19.2.8` | `19.3.0` |
|
[@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react)
| `19.2.18` | `19.3.0` |
|
[react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom)
| `19.2.8` | `19.3.0` |
|
[@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom)
| `19.2.7` | `19.3.0` |
|
[@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)
| `26.5.0` | `26.5.1` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) |
`6.34.0` | `6.35.1` |
| [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) |
`0.67.0` | `0.68.0` |
| [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) |
`1.82.0` | `1.83.0` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) |
`8.2.2` | `8.3.0` |

Updates `react` from 19.2.8 to 19.3.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/react/react/releases">react's
releases</a>.</em></p>
<blockquote>
<h2>19.3.0 (September 9, 2026)</h2>
<p>Below is a list of all new features, APIs, and bug fixes.</p>
<p>Read the <a href="https://react.dev/blog/2026/09/09/react-19-3">React
19.3 release post</a> for more information.</p>
<h2>New React Features</h2>
<ul>
<li><code>&lt;ViewTransition /&gt;</code>: Adds <code>&lt;ViewTransition
/&gt;</code> and <code>addTransitionType</code> APIs to power View
Transition animations in React (<a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a>, <a
href="https://github.com/jackpope"><code>@​jackpope</code></a>, <a
href="https://github.com/gaearon"><code>@​gaearon</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/31975">#31975</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31987">#31987</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31996">#31996</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31999">#31999</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32001">#32001</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32002">#32002</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32028">#32028</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32029">#32029</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32031">#32031</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32034">#32034</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32038">#32038</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32041">#32041</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32050">#32050</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32090">#32090</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32105">#32105</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32254">#32254</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32379">#32379</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32422">#32422</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32462">#32462</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32540">#32540</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32545">#32545</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32585">#32585</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32599">#32599</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32611">#32611</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32612">#32612</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32617">#32617</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32651">#32651</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32653">#32653</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32656">#32656</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32664">#32664</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32699">#32699</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32723">#32723</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32734">#32734</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32751">#32751</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32752">#32752</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32760">#32760</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32761">#32761</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32764">#32764</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32772">#32772</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32790">#32790</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32819">#32819</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32820">#32820</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32822">#32822</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32833">#32833</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32849">#32849</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33094">#33094</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33191">#33191</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33200">#33200</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33206">#33206</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33293">#33293</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33330">#33330</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33331">#33331</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33332">#33332</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33357">#33357</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33362">#33362</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33433">#33433</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33576">#33576</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34374">#34374</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34450">#34450</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34481">#34481</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34500">#34500</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34502">#34502</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34510">#34510</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34511">#34511</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34539">#34539</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35567">#35567</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35564">#35564</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35485">#35485</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35380">#35380</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35063">#35063</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35060">#35060</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34676">#34676</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36917">#36917</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35337">#35337</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35520">#35520</a>)</li>
<li>Fragment Refs: Add Refs to <code>&lt;Fragment /&gt;</code> to
support composable platform behavior (<a
href="https://github.com/jackpope"><code>@​jackpope</code></a>, <a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a>, <a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a>, <a
href="https://github.com/Dhakshin2007"><code>@​Dhakshin2007</code></a>,
<a href="https://github.com/chirokas"><code>@​chirokas</code></a>, <a
href="https://github.com/teamleaderleo"><code>@​teamleaderleo</code></a>,
<a
href="https://github.com/fallintoplace"><code>@​fallintoplace</code></a>:
<a
href="https://redirect.github.com/facebook/react/pull/32465">#32465</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32613">#32613</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32619">#32619</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32654">#32654</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32660">#32660</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32682">#32682</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32722">#32722</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32813">#32813</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32814">#32814</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33056">#33056</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33058">#33058</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33093">#33093</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34069">#34069</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34103">#34103</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34544">#34544</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34545">#34545</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37062">#37062</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37061">#37061</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37060">#37060</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36047">#36047</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36010">#36010</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35642">#35642</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35641">#35641</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35637">#35637</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35630">#35630</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34935">#34935</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37457">#37457</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37408">#37408</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37326">#37326</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37251">#37251</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37171">#37171</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37169">#37169</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37168">#37168</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37167">#37167</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37166">#37166</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37165">#37165</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37164">#37164</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37163">#37163</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37162">#37162</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37161">#37161</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37160">#37160</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37125">#37125</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37063">#37063</a>)</li>
</ul>
<h2>New React DOM Features</h2>
<ul>
<li><code>browser()</code>: a new <code>react-dom</code> API that
returns a usable which errors during server rendering and resolves in
the browser. <code>use(browser())</code> inside a
<code>&lt;Suspense&gt;</code> boundary marks a subtree as browser-only
without reporting a recoverable error (<a
href="https://github.com/gnoff"><code>@​gnoff</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/37143">#37143</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37241">#37241</a>)
<ul>
<li>Added an <code>onBrowserBailout</code> option to the
<code>react-dom/server</code> APIs to observe when a subtree defers to
the browser (<a href="https://github.com/gnoff"><code>@​gnoff</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/37193">#37193</a>)</li>
</ul>
</li>
</ul>
<h2>Notable changes</h2>
<ul>
<li>Enable Trusted Types API integration (<a
href="https://github.com/rickhanlonii"><code>@​rickhanlonii</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/35816">#35816</a>)</li>
<li>Transitions now render independently instead of being entangled into
a single render, so a slow transition no longer holds up unrelated ones
(<a href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/37290">#37290</a>)</li>
<li>Added a DEV-only warning when a component appears to have been
unblocked by calling <code>use()</code> conditionally (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a>, <a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/37104">#37104</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37203">#37203</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37491">#37491</a>)</li>
</ul>
<h2>All Changes</h2>
<h3>React</h3>
<ul>
<li>Fast Refresh Fixes
<ul>
<li>Fix Fast Refresh to find and remount edits to components wrapped
behind <code>lazy()</code> (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36965">#36965</a>)</li>
<li>Fix Fast Refresh so edits to a <code>memo()</code> comparison
function take effect (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36964">#36964</a>)</li>
<li>Fix Fast Refresh crash when an edit changes the kind of a
component's type (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36963">#36963</a>)</li>
<li>Unify hot reload type resolution for Fast Refresh (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36962">#36962</a>)</li>
<li>Fix Fast Refresh to remount correctly when an edit changes the
component kind (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36950">#36950</a>)</li>
<li>Double invoke effects in StrictMode after Fast Refresh (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35962">#35962</a>)</li>
</ul>
</li>
<li>Performance Track Fixes
<ul>
<li>Prevent crash when accessing <code>$$typeof</code> in Performance
Tracks (<a href="https://github.com/eps1lon"><code>@​eps1lon</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/35679">#35679</a>)</li>
<li>Handle non-string function names in Performance Tracks (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35659">#35659</a>)</li>
<li>Use minus (<code>-</code>) instead of en dash for removed props in
Performance Tracks (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35649">#35649</a>)</li>
<li>Handle arrays with bigints in deep objects in Performance Tracks (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35648">#35648</a>)</li>
<li>Don't enumerate typed array props in Performance Tracks in DEV (<a
href="https://github.com/UditDewan"><code>@​UditDewan</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36913">#36913</a>)</li>
<li>Bail out of diffing wide objects and arrays in Performance Tracks
(<a href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34742">#34742</a>)</li>
<li>Clear potentially large performance measures in DEV (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34803">#34803</a>)</li>
<li>Fix missing else branch for renders with no props change in
Performance Tracks (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34837">#34837</a>)</li>
</ul>
</li>
<li>Activity Fixes
<ul>
<li>Fix <code>useSyncExternalStore</code> missing store mutations that
happened while an Activity tree was hidden (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36947">#36947</a>)</li>
<li>Hide portal contents when an Activity is hidden (<a
href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35091">#35091</a>)</li>
<li>Prevent metadata hoisting in hidden <code>&lt;Activity&gt;</code>
trees (<a
href="https://github.com/ronnakamoto"><code>@​ronnakamoto</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34983">#34983</a>)</li>
<li>Prevent errors thrown inside a hidden Activity from escaping to the
visible UI (<a
href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35074">#35074</a>)</li>
<li>Don't unhide a node if a direct parent Offscreen is still hidden (<a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34821">#34821</a>)</li>
<li>Don't show internal <code>&lt;Offscreen&gt;</code> component in
error messages (<a
href="https://github.com/rickhanlonii"><code>@​rickhanlonii</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/35763">#35763</a>)</li>
</ul>
</li>
<li>Warn in DEV when a component appears to have been unblocked by a
conditional <code>use()</code> (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a>, <a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/37104">#37104</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37203">#37203</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37491">#37491</a>)</li>
<li>Render transitions independently instead of entangling them into a
single render (<a
href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/37290">#37290</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/react/react/blob/main/CHANGELOG.md">react's
changelog</a>.</em></p>
<blockquote>
<h2>19.3.0 (September 9, 2026)</h2>
<h3>New React Features</h3>
<ul>
<li><code>&lt;ViewTransition /&gt;</code>: Adds <code>&lt;ViewTransition
/&gt;</code> and <code>addTransitionType</code> APIs to power View
Transition animations in React (<a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a>, <a
href="https://github.com/jackpope"><code>@​jackpope</code></a>, <a
href="https://github.com/gaearon"><code>@​gaearon</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/31975">#31975</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31987">#31987</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31996">#31996</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31999">#31999</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32001">#32001</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32002">#32002</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32028">#32028</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32029">#32029</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32031">#32031</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32034">#32034</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32038">#32038</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32041">#32041</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32050">#32050</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32090">#32090</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32105">#32105</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32254">#32254</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32379">#32379</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32422">#32422</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32462">#32462</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32540">#32540</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32545">#32545</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32585">#32585</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32599">#32599</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32611">#32611</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32612">#32612</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32617">#32617</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32651">#32651</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32653">#32653</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32656">#32656</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32664">#32664</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32699">#32699</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32723">#32723</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32734">#32734</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32751">#32751</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32752">#32752</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32760">#32760</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32761">#32761</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32764">#32764</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32772">#32772</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32790">#32790</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32819">#32819</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32820">#32820</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32822">#32822</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32833">#32833</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32849">#32849</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33094">#33094</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33191">#33191</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33200">#33200</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33206">#33206</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33293">#33293</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33330">#33330</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33331">#33331</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33332">#33332</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33357">#33357</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33362">#33362</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33433">#33433</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33576">#33576</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34374">#34374</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34450">#34450</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34481">#34481</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34500">#34500</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34502">#34502</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34510">#34510</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34511">#34511</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34539">#34539</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35567">#35567</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35564">#35564</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35485">#35485</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35380">#35380</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35063">#35063</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35060">#35060</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34676">#34676</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36917">#36917</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35337">#35337</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35520">#35520</a>)</li>
<li>Fragment Refs: Add Refs to <code>&lt;Fragment /&gt;</code> to
support composable platform behavior (<a
href="https://github.com/jackpope"><code>@​jackpope</code></a>, <a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a>, <a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a>, <a
href="https://github.com/Dhakshin2007"><code>@​Dhakshin2007</code></a>,
<a href="https://github.com/chirokas"><code>@​chirokas</code></a>, <a
href="https://github.com/teamleaderleo"><code>@​teamleaderleo</code></a>,
<a
href="https://github.com/fallintoplace"><code>@​fallintoplace</code></a>:
<a
href="https://redirect.github.com/facebook/react/pull/32465">#32465</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32613">#32613</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32619">#32619</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32654">#32654</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32660">#32660</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32682">#32682</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32722">#32722</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32813">#32813</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32814">#32814</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33056">#33056</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33058">#33058</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33093">#33093</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34069">#34069</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34103">#34103</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34544">#34544</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34545">#34545</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37062">#37062</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37061">#37061</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37060">#37060</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36047">#36047</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36010">#36010</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35642">#35642</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35641">#35641</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35637">#35637</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35630">#35630</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34935">#34935</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37457">#37457</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37408">#37408</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37326">#37326</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37251">#37251</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37171">#37171</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37169">#37169</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37168">#37168</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37167">#37167</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37166">#37166</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37165">#37165</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37164">#37164</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37163">#37163</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37162">#37162</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37161">#37161</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37160">#37160</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37125">#37125</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37063">#37063</a>)</li>
</ul>
<h3>New React DOM Features</h3>
<ul>
<li><code>browser()</code>: a new <code>react-dom</code> API that
returns a usable which errors during server rendering and resolves in
the browser. <code>use(browser())</code> inside a
<code>&lt;Suspense&gt;</code> boundary marks a subtree as browser-only
without reporting a recoverable error (<a
href="https://github.com/gnoff"><code>@​gnoff</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/37143">#37143</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37241">#37241</a>)
<ul>
<li>Added an <code>onBrowserBailout</code> option to the
<code>react-dom/server</code> APIs to observe when a subtree defers to
the browser (<a href="https://github.com/gnoff"><code>@​gnoff</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/37193">#37193</a>)</li>
</ul>
</li>
</ul>
<h3>Notable changes</h3>
<ul>
<li>Enable Trusted Types API integration (<a
href="https://github.com/rickhanlonii"><code>@​rickhanlonii</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/35816">#35816</a>)</li>
<li>Transitions now render independently instead of being entangled into
a single render, so a slow transition no longer holds up unrelated ones
(<a href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/37290">#37290</a>)</li>
<li>Added a DEV-only warning when a component appears to have been
unblocked by calling <code>use()</code> conditionally (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a>, <a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/37104">#37104</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37203">#37203</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37491">#37491</a>)</li>
</ul>
<h3>All Changes</h3>
<h4>React</h4>
<ul>
<li>Fast Refresh Fixes
<ul>
<li>Fix Fast Refresh to find and remount edits to components wrapped
behind <code>lazy()</code> (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36965">#36965</a>)</li>
<li>Fix Fast Refresh so edits to a <code>memo()</code> comparison
function take effect (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36964">#36964</a>)</li>
<li>Fix Fast Refresh crash when an edit changes the kind of a
component's type (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36963">#36963</a>)</li>
<li>Unify hot reload type resolution for Fast Refresh (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36962">#36962</a>)</li>
<li>Fix Fast Refresh to remount correctly when an edit changes the
component kind (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36950">#36950</a>)</li>
<li>Double invoke effects in StrictMode after Fast Refresh (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35962">#35962</a>)</li>
</ul>
</li>
<li>Performance Track Fixes
<ul>
<li>Prevent crash when accessing <code>$$typeof</code> in Performance
Tracks (<a href="https://github.com/eps1lon"><code>@​eps1lon</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/35679">#35679</a>)</li>
<li>Handle non-string function names in Performance Tracks (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35659">#35659</a>)</li>
<li>Use minus (<code>-</code>) instead of en dash for removed props in
Performance Tracks (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35649">#35649</a>)</li>
<li>Handle arrays with bigints in deep objects in Performance Tracks (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35648">#35648</a>)</li>
<li>Don't enumerate typed array props in Performance Tracks in DEV (<a
href="https://github.com/UditDewan"><code>@​UditDewan</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36913">#36913</a>)</li>
<li>Bail out of diffing wide objects and arrays in Performance Tracks
(<a href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34742">#34742</a>)</li>
<li>Clear potentially large performance measures in DEV (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34803">#34803</a>)</li>
<li>Fix missing else branch for renders with no props change in
Performance Tracks (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34837">#34837</a>)</li>
</ul>
</li>
<li>Activity Fixes
<ul>
<li>Fix <code>useSyncExternalStore</code> missing store mutations that
happened while an Activity tree was hidden (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36947">#36947</a>)</li>
<li>Hide portal contents when an Activity is hidden (<a
href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35091">#35091</a>)</li>
<li>Prevent metadata hoisting in hidden <code>&lt;Activity&gt;</code>
trees (<a
href="https://github.com/ronnakamoto"><code>@​ronnakamoto</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34983">#34983</a>)</li>
<li>Prevent errors thrown inside a hidden Activity from escaping to the
visible UI (<a
href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35074">#35074</a>)</li>
<li>Don't unhide a node if a direct parent Offscreen is still hidden (<a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34821">#34821</a>)</li>
<li>Don't show internal <code>&lt;Offscreen&gt;</code> component in
error messages (<a
href="https://github.com/rickhanlonii"><code>@​rickhanlonii</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/35763">#35763</a>)</li>
</ul>
</li>
<li>Warn in DEV when a component appears to have been unblocked by a
conditional <code>use()</code> (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a>, <a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/37104">#37104</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37203">#37203</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37491">#37491</a>)</li>
<li>Render transitions independently instead of entangling them into a
single render (<a
href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/37290">#37290</a>)</li>
<li>Fix hang when updating a dehydrated boundary inside a hidden tree
(<a href="https://github.com/gaearon"><code>@​gaearon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/37135">#37135</a>)</li>
<li>Don't reacquire Host Singletons during dev effect validation (<a
href="https://github.com/gnoff"><code>@​gnoff</code></a> <a
href="https://redirect.github.com/facebook/react/pull/37113">#37113</a>)</li>
<li>Only remove properties from Host Singletons on release (<a
href="https://github.com/gnoff"><code>@​gnoff</code></a> <a
href="https://redirect.github.com/facebook/react/pull/37112">#37112</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/react/react/commit/2dc7da790d6388b95b83198ca9b588b2ad5f5c0b"><code>2dc7da7</code></a>
[test] Bump Jest to 30.4 (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/37382">#37382</a>)</li>
<li><a
href="https://github.com/react/react/commit/4f9389423b7319e1f7acc3d158c84a8365462748"><code>4f93894</code></a>
docs: remove stale parentType param from validateChildKeys JSDoc (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/36928">#36928</a>)</li>
<li><a
href="https://github.com/react/react/commit/dbc37501ffeaf8fec45af5898caf1c3d64ad10bf"><code>dbc3750</code></a>
Update required references to GitHub repo (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/36752">#36752</a>)</li>
<li><a
href="https://github.com/react/react/commit/900ae094d85b11c67d53dd14af50a2bda5db4495"><code>900ae09</code></a>
[flow] Bump flow to v0.317.0 (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/36701">#36701</a>)</li>
<li><a
href="https://github.com/react/react/commit/fbb137059e4aacfaab1d36516e9b55050b4a0454"><code>fbb1370</code></a>
[flow] Bump flow to v0.307.1 (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/36199">#36199</a>)</li>
<li><a
href="https://github.com/react/react/commit/56922cf751fab6c7ab4c12ddbbd15839959fa255"><code>56922cf</code></a>
[react-native-renderer] Delete Paper (legacy) renderer (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/36285">#36285</a>)</li>
<li><a
href="https://github.com/react/react/commit/74568e8627aa43469b74f2972f427a209639d0b6"><code>74568e8</code></a>
[Flight] Transport <code>AggregateErrors.errors</code> (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/36156">#36156</a>)</li>
<li><a
href="https://github.com/react/react/commit/e66ef6480ecd19c6885f2c06dec34fec1fdc0a98"><code>e66ef64</code></a>
[tests] remove withoutStack from assertConsole helpers (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/35498">#35498</a>)</li>
<li><a
href="https://github.com/react/react/commit/db71391c5c70dc113560d1c23d0b6548604d827f"><code>db71391</code></a>
[Fiber] Instrument the lazy initializer thenable in all cases (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/35521">#35521</a>)</li>
<li><a
href="https://github.com/react/react/commit/3e1abcc8d7083a13adf4774feb0d67ecbe4a2bc4"><code>3e1abcc</code></a>
[tests] Require exact error messages in assertConsole helpers (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/35497">#35497</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/react/react/commits/v19.3.0/packages/react">compare
view</a></li>
</ul>
</details>
<br />

Updates `@types/react` from 19.2.18 to 19.3.0
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react">compare
view</a></li>
</ul>
</details>
<br />

Updates `react-dom` from 19.2.8 to 19.3.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/react/react/releases">react-dom's
releases</a>.</em></p>
<blockquote>
<h2>19.3.0 (September 9, 2026)</h2>
<p>Below is a list of all new features, APIs, and bug fixes.</p>
<p>Read the <a href="https://react.dev/blog/2026/09/09/react-19-3">React
19.3 release post</a> for more information.</p>
<h2>New React Features</h2>
<ul>
<li><code>&lt;ViewTransition /&gt;</code>: Adds <code>&lt;ViewTransition
/&gt;</code> and <code>addTransitionType</code> APIs to power View
Transition animations in React (<a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a>, <a
href="https://github.com/jackpope"><code>@​jackpope</code></a>, <a
href="https://github.com/gaearon"><code>@​gaearon</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/31975">#31975</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31987">#31987</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31996">#31996</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31999">#31999</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32001">#32001</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32002">#32002</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32028">#32028</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32029">#32029</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32031">#32031</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32034">#32034</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32038">#32038</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32041">#32041</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32050">#32050</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32090">#32090</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32105">#32105</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32254">#32254</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32379">#32379</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32422">#32422</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32462">#32462</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32540">#32540</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32545">#32545</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32585">#32585</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32599">#32599</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32611">#32611</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32612">#32612</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32617">#32617</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32651">#32651</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32653">#32653</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32656">#32656</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32664">#32664</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32699">#32699</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32723">#32723</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32734">#32734</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32751">#32751</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32752">#32752</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32760">#32760</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32761">#32761</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32764">#32764</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32772">#32772</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32790">#32790</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32819">#32819</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32820">#32820</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32822">#32822</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32833">#32833</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32849">#32849</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33094">#33094</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33191">#33191</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33200">#33200</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33206">#33206</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33293">#33293</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33330">#33330</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33331">#33331</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33332">#33332</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33357">#33357</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33362">#33362</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33433">#33433</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33576">#33576</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34374">#34374</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34450">#34450</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34481">#34481</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34500">#34500</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34502">#34502</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34510">#34510</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34511">#34511</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34539">#34539</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35567">#35567</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35564">#35564</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35485">#35485</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35380">#35380</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35063">#35063</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35060">#35060</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34676">#34676</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36917">#36917</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35337">#35337</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35520">#35520</a>)</li>
<li>Fragment Refs: Add Refs to <code>&lt;Fragment /&gt;</code> to
support composable platform behavior (<a
href="https://github.com/jackpope"><code>@​jackpope</code></a>, <a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a>, <a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a>, <a
href="https://github.com/Dhakshin2007"><code>@​Dhakshin2007</code></a>,
<a href="https://github.com/chirokas"><code>@​chirokas</code></a>, <a
href="https://github.com/teamleaderleo"><code>@​teamleaderleo</code></a>,
<a
href="https://github.com/fallintoplace"><code>@​fallintoplace</code></a>:
<a
href="https://redirect.github.com/facebook/react/pull/32465">#32465</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32613">#32613</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32619">#32619</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32654">#32654</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32660">#32660</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32682">#32682</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32722">#32722</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32813">#32813</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32814">#32814</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33056">#33056</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33058">#33058</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33093">#33093</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34069">#34069</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34103">#34103</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34544">#34544</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34545">#34545</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37062">#37062</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37061">#37061</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37060">#37060</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36047">#36047</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36010">#36010</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35642">#35642</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35641">#35641</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35637">#35637</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35630">#35630</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34935">#34935</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37457">#37457</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37408">#37408</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37326">#37326</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37251">#37251</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37171">#37171</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37169">#37169</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37168">#37168</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37167">#37167</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37166">#37166</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37165">#37165</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37164">#37164</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37163">#37163</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37162">#37162</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37161">#37161</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37160">#37160</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37125">#37125</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37063">#37063</a>)</li>
</ul>
<h2>New React DOM Features</h2>
<ul>
<li><code>browser()</code>: a new <code>react-dom</code> API that
returns a usable which errors during server rendering and resolves in
the browser. <code>use(browser())</code> inside a
<code>&lt;Suspense&gt;</code> boundary marks a subtree as browser-only
without reporting a recoverable error (<a
href="https://github.com/gnoff"><code>@​gnoff</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/37143">#37143</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37241">#37241</a>)
<ul>
<li>Added an <code>onBrowserBailout</code> option to the
<code>react-dom/server</code> APIs to observe when a subtree defers to
the browser (<a href="https://github.com/gnoff"><code>@​gnoff</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/37193">#37193</a>)</li>
</ul>
</li>
</ul>
<h2>Notable changes</h2>
<ul>
<li>Enable Trusted Types API integration (<a
href="https://github.com/rickhanlonii"><code>@​rickhanlonii</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/35816">#35816</a>)</li>
<li>Transitions now render independently instead of being entangled into
a single render, so a slow transition no longer holds up unrelated ones
(<a href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/37290">#37290</a>)</li>
<li>Added a DEV-only warning when a component appears to have been
unblocked by calling <code>use()</code> conditionally (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a>, <a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/37104">#37104</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37203">#37203</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37491">#37491</a>)</li>
</ul>
<h2>All Changes</h2>
<h3>React</h3>
<ul>
<li>Fast Refresh Fixes
<ul>
<li>Fix Fast Refresh to find and remount edits to components wrapped
behind <code>lazy()</code> (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36965">#36965</a>)</li>
<li>Fix Fast Refresh so edits to a <code>memo()</code> comparison
function take effect (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36964">#36964</a>)</li>
<li>Fix Fast Refresh crash when an edit changes the kind of a
component's type (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36963">#36963</a>)</li>
<li>Unify hot reload type resolution for Fast Refresh (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36962">#36962</a>)</li>
<li>Fix Fast Refresh to remount correctly when an edit changes the
component kind (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36950">#36950</a>)</li>
<li>Double invoke effects in StrictMode after Fast Refresh (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35962">#35962</a>)</li>
</ul>
</li>
<li>Performance Track Fixes
<ul>
<li>Prevent crash when accessing <code>$$typeof</code> in Performance
Tracks (<a href="https://github.com/eps1lon"><code>@​eps1lon</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/35679">#35679</a>)</li>
<li>Handle non-string function names in Performance Tracks (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35659">#35659</a>)</li>
<li>Use minus (<code>-</code>) instead of en dash for removed props in
Performance Tracks (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35649">#35649</a>)</li>
<li>Handle arrays with bigints in deep objects in Performance Tracks (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35648">#35648</a>)</li>
<li>Don't enumerate typed array props in Performance Tracks in DEV (<a
href="https://github.com/UditDewan"><code>@​UditDewan</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36913">#36913</a>)</li>
<li>Bail out of diffing wide objects and arrays in Performance Tracks
(<a href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34742">#34742</a>)</li>
<li>Clear potentially large performance measures in DEV (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34803">#34803</a>)</li>
<li>Fix missing else branch for renders with no props change in
Performance Tracks (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34837">#34837</a>)</li>
</ul>
</li>
<li>Activity Fixes
<ul>
<li>Fix <code>useSyncExternalStore</code> missing store mutations that
happened while an Activity tree was hidden (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36947">#36947</a>)</li>
<li>Hide portal contents when an Activity is hidden (<a
href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35091">#35091</a>)</li>
<li>Prevent metadata hoisting in hidden <code>&lt;Activity&gt;</code>
trees (<a
href="https://github.com/ronnakamoto"><code>@​ronnakamoto</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34983">#34983</a>)</li>
<li>Prevent errors thrown inside a hidden Activity from escaping to the
visible UI (<a
href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35074">#35074</a>)</li>
<li>Don't unhide a node if a direct parent Offscreen is still hidden (<a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34821">#34821</a>)</li>
<li>Don't show internal <code>&lt;Offscreen&gt;</code> component in
error messages (<a
href="https://github.com/rickhanlonii"><code>@​rickhanlonii</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/35763">#35763</a>)</li>
</ul>
</li>
<li>Warn in DEV when a component appears to have been unblocked by a
conditional <code>use()</code> (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a>, <a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/37104">#37104</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37203">#37203</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37491">#37491</a>)</li>
<li>Render transitions independently instead of entangling them into a
single render (<a
href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/37290">#37290</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/react/react/blob/main/CHANGELOG.md">react-dom's
changelog</a>.</em></p>
<blockquote>
<h2>19.3.0 (September 9, 2026)</h2>
<h3>New React Features</h3>
<ul>
<li><code>&lt;ViewTransition /&gt;</code>: Adds <code>&lt;ViewTransition
/&gt;</code> and <code>addTransitionType</code> APIs to power View
Transition animations in React (<a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a>, <a
href="https://github.com/jackpope"><code>@​jackpope</code></a>, <a
href="https://github.com/gaearon"><code>@​gaearon</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/31975">#31975</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31987">#31987</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31996">#31996</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31999">#31999</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32001">#32001</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32002">#32002</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32028">#32028</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32029">#32029</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32031">#32031</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32034">#32034</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32038">#32038</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32041">#32041</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32050">#32050</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32090">#32090</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32105">#32105</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32254">#32254</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32379">#32379</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32422">#32422</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32462">#32462</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32540">#32540</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32545">#32545</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32585">#32585</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32599">#32599</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32611">#32611</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32612">#32612</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32617">#32617</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32651">#32651</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32653">#32653</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32656">#32656</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32664">#32664</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32699">#32699</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32723">#32723</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32734">#32734</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32751">#32751</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32752">#32752</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32760">#32760</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32761">#32761</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32764">#32764</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32772">#32772</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32790">#32790</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32819">#32819</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32820">#32820</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32822">#32822</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32833">#32833</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32849">#32849</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33094">#33094</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33191">#33191</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33200">#33200</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33206">#33206</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33293">#33293</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33330">#33330</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33331">#33331</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33332">#33332</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33357">#33357</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33362">#33362</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33433">#33433</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33576">#33576</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34374">#34374</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34450">#34450</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34481">#34481</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34500">#34500</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34502">#34502</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34510">#34510</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34511">#34511</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34539">#34539</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35567">#35567</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35564">#35564</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35485">#35485</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35380">#35380</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35063">#35063</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35060">#35060</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34676">#34676</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36917">#36917</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35337">#35337</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35520">#35520</a>)</li>
<li>Fragment Refs: Add Refs to <code>&lt;Fragment /&gt;</code> to
support composable platform behavior (<a
href="https://github.com/jackpope"><code>@​jackpope</code></a>, <a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a>, <a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a>, <a
href="https://github.com/Dhakshin2007"><code>@​Dhakshin2007</code></a>,
<a href="https://github.com/chirokas"><code>@​chirokas</code></a>, <a
href="https://github.com/teamleaderleo"><code>@​teamleaderleo</code></a>,
<a
href="https://github.com/fallintoplace"><code>@​fallintoplace</code></a>:
<a
href="https://redirect.github.com/facebook/react/pull/32465">#32465</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32613">#32613</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32619">#32619</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32654">#32654</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32660">#32660</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32682">#32682</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32722">#32722</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32813">#32813</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32814">#32814</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33056">#33056</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33058">#33058</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33093">#33093</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34069">#34069</a>,
<a href="https://redirect...

_Description has been truncated_

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-19 23:19:07 -04:00
dependabot[bot] 83f86242b4 build(deps): bump the docker-base-image-digests group with 2 updates (#1348)
> [!WARNING]
> Cooldown could not be applied because no publication date was
available from the registry.
>

Bumps the docker-base-image-digests group with 2 updates: node and
[astral-sh/uv](https://github.com/astral-sh/uv).

Updates `node` from `50c8e8c` to `ebfe2f9`

Updates `astral-sh/uv` from 0.12.13 to 0.12.16
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/uv/releases">astral-sh/uv's
releases</a>.</em></p>
<blockquote>
<h2>0.12.16</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-17.</p>
<h3>Python</h3>
<ul>
<li>Add Pyodide 314.0.7, 0.29.5, and 0.27.8 (<a
href="https://redirect.github.com/astral-sh/uv/pull/21741">#21741</a>)</li>
</ul>
<h3>Enhancements</h3>
<ul>
<li>Verify downloaded wheels and source distributions against hashes
supplied by package indexes (<a
href="https://redirect.github.com/astral-sh/uv/pull/21562">#21562</a>)</li>
<li>Allow <code>build-constraint-dependencies</code> entries to include
hashes for verifying downloaded build dependencies (<a
href="https://redirect.github.com/astral-sh/uv/pull/21467">#21467</a>)</li>
<li>Honor Darwin <code>platform_release</code> markers in
<code>required-environments</code> using macOS wheel deployment targets
(<a
href="https://redirect.github.com/astral-sh/uv/pull/21766">#21766</a>)</li>
<li>Reject unsupported Git URL schemes while parsing lockfiles instead
of panicking during frozen exports (<a
href="https://redirect.github.com/astral-sh/uv/pull/21779">#21779</a>)</li>
</ul>
<h3>Preview features</h3>
<ul>
<li>Support <code>lock-without-metadata</code> across all dependency
types while retaining <code>package.metadata</code> for remote URL
dependencies to enable offline validation (<a
href="https://redirect.github.com/astral-sh/uv/pull/21163">#21163</a>)</li>
<li>Honor configured and command-line index settings, including
credentials, in <code>uv upgrade</code> (<a
href="https://redirect.github.com/astral-sh/uv/pull/21776">#21776</a>)</li>
<li>Allow <code>uv check</code> to run in projects that are not managed
by uv and outside workspaces (<a
href="https://redirect.github.com/astral-sh/uv/pull/21777">#21777</a>)</li>
<li>Respect <code>--python</code> and <code>UV_PYTHON</code> when
selecting the Python version for <code>uv check</code> (<a
href="https://redirect.github.com/astral-sh/uv/pull/21744">#21744</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Redact Azure shared access signatures from displayed and logged URLs
(<a
href="https://redirect.github.com/astral-sh/uv/pull/21755">#21755</a>)</li>
<li>Check archive sizes from <code>pylock.toml</code> before reusing
cached distributions (<a
href="https://redirect.github.com/astral-sh/uv/pull/21609">#21609</a>)</li>
<li>Keep user-authored local dependency paths relative in lockfiles when
backend metadata reports absolute paths (<a
href="https://redirect.github.com/astral-sh/uv/pull/20631">#20631</a>)</li>
<li>Use the bundled <code>uv_build</code> backend only when its version
matches active version pins (<a
href="https://redirect.github.com/astral-sh/uv/pull/21742">#21742</a>)</li>
<li>Handle malformed index URLs without panicking when credentials are
configured (<a
href="https://redirect.github.com/astral-sh/uv/pull/21784">#21784</a>)</li>
<li>Report a configuration error instead of panicking for proxy URLs
without a host (<a
href="https://redirect.github.com/astral-sh/uv/pull/21781">#21781</a>)</li>
<li>Return a credential-redacted error instead of panicking when a URL
cannot be converted to a path (<a
href="https://redirect.github.com/astral-sh/uv/pull/21783">#21783</a>)</li>
</ul>
<h2>Install uv 0.12.16</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/uv/releases/download/0.12.16/uv-installer.sh
| sh
</code></pre>
<h3>Install prebuilt binaries via powershell script</h3>
<pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c &quot;irm
https://releases.astral.sh/github/uv/releases/download/0.12.16/uv-installer.ps1
| iex&quot;
</code></pre>
<h2>Download uv 0.12.16</h2>
<p>|  File  | Platform | Checksum |</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/uv/blob/main/CHANGELOG.md">astral-sh/uv's
changelog</a>.</em></p>
<blockquote>
<h2>0.12.16</h2>
<p>Released on 2026-09-17.</p>
<h3>Python</h3>
<ul>
<li>Add Pyodide 314.0.7, 0.29.5, and 0.27.8 (<a
href="https://redirect.github.com/astral-sh/uv/pull/21741">#21741</a>)</li>
</ul>
<h3>Enhancements</h3>
<ul>
<li>Verify downloaded wheels and source distributions against hashes
supplied by package indexes (<a
href="https://redirect.github.com/astral-sh/uv/pull/21562">#21562</a>)</li>
<li>Allow <code>build-constraint-dependencies</code> entries to include
hashes for verifying downloaded build dependencies (<a
href="https://redirect.github.com/astral-sh/uv/pull/21467">#21467</a>)</li>
<li>Honor Darwin <code>platform_release</code> markers in
<code>required-environments</code> using macOS wheel deployment targets
(<a
href="https://redirect.github.com/astral-sh/uv/pull/21766">#21766</a>)</li>
<li>Reject unsupported Git URL schemes while parsing lockfiles instead
of panicking during frozen exports (<a
href="https://redirect.github.com/astral-sh/uv/pull/21779">#21779</a>)</li>
</ul>
<h3>Preview features</h3>
<ul>
<li>Support <code>lock-without-metadata</code> across all dependency
types while retaining <code>package.metadata</code> for remote URL
dependencies to enable offline validation (<a
href="https://redirect.github.com/astral-sh/uv/pull/21163">#21163</a>)</li>
<li>Honor configured and command-line index settings, including
credentials, in <code>uv upgrade</code> (<a
href="https://redirect.github.com/astral-sh/uv/pull/21776">#21776</a>)</li>
<li>Allow <code>uv check</code> to run in projects that are not managed
by uv and outside workspaces (<a
href="https://redirect.github.com/astral-sh/uv/pull/21777">#21777</a>)</li>
<li>Respect <code>--python</code> and <code>UV_PYTHON</code> when
selecting the Python version for <code>uv check</code> (<a
href="https://redirect.github.com/astral-sh/uv/pull/21744">#21744</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Redact Azure shared access signatures from displayed and logged URLs
(<a
href="https://redirect.github.com/astral-sh/uv/pull/21755">#21755</a>)</li>
<li>Check archive sizes from <code>pylock.toml</code> before reusing
cached distributions (<a
href="https://redirect.github.com/astral-sh/uv/pull/21609">#21609</a>)</li>
<li>Keep user-authored local dependency paths relative in lockfiles when
backend metadata reports absolute paths (<a
href="https://redirect.github.com/astral-sh/uv/pull/20631">#20631</a>)</li>
<li>Use the bundled <code>uv_build</code> backend only when its version
matches active version pins (<a
href="https://redirect.github.com/astral-sh/uv/pull/21742">#21742</a>)</li>
<li>Handle malformed index URLs without panicking when credentials are
configured (<a
href="https://redirect.github.com/astral-sh/uv/pull/21784">#21784</a>)</li>
<li>Report a configuration error instead of panicking for proxy URLs
without a host (<a
href="https://redirect.github.com/astral-sh/uv/pull/21781">#21781</a>)</li>
<li>Return a credential-redacted error instead of panicking when a URL
cannot be converted to a path (<a
href="https://redirect.github.com/astral-sh/uv/pull/21783">#21783</a>)</li>
</ul>
<h2>0.12.15</h2>
<p>Released on 2026-09-15.</p>
<h3>Performance</h3>
<ul>
<li>Speed up cold-cache resolution and HTTP cache revalidation by
batching cache writes (<a
href="https://redirect.github.com/astral-sh/uv/pull/21675">#21675</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Fix regressions in <code>0.12.14</code> when installing to symlinked
destinations or using <code>uv pip install --target .</code> (<a
href="https://redirect.github.com/astral-sh/uv/pull/21699">#21699</a>)</li>
</ul>
<h2>0.12.14</h2>
<p>Released on 2026-09-15.</p>
<h3>Enhancements</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/uv/commit/761ff1379b3b79f61fc8d421dfe4fe064834e084"><code>761ff13</code></a>
Bump version to 0.12.16 (<a
href="https://redirect.github.com/astral-sh/uv/issues/21809">#21809</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/a2f820ad0cebb7118f7686be3619d48df5121f6e"><code>a2f820a</code></a>
Assign release pull requests to the workflow initiator (<a
href="https://redirect.github.com/astral-sh/uv/issues/21808">#21808</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/6dffe7e03898409c04e2f46436bffa60abbae465"><code>6dffe7e</code></a>
Ignore <code>UV_NATIVE_TLS</code> when <code>UV_SYSTEM_CERTS</code> is
set (<a
href="https://redirect.github.com/astral-sh/uv/issues/21805">#21805</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/7bc36767ae3ea0d45e3cc6f219765fdec2992a33"><code>7bc3676</code></a>
Avoid warning when both <code>native-tls</code> and
<code>system-certs</code> are configured (<a
href="https://redirect.github.com/astral-sh/uv/issues/21806">#21806</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/07b838a33179967b87d513825b02504a75b21b3a"><code>07b838a</code></a>
Avoid warning when both <code>UV_NATIVE_TLS</code> and
<code>UV_SYSTEM_CERTS</code> are set (<a
href="https://redirect.github.com/astral-sh/uv/issues/21788">#21788</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/5d64ede21e9e835e59ecd85329ebefd43faa8211"><code>5d64ede</code></a>
Remove Hash API (<a
href="https://redirect.github.com/astral-sh/uv/issues/21786">#21786</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/9ddc4308551335e9c2ab6571ea0cf529eccf3e76"><code>9ddc430</code></a>
Move shared thread initialization into uv-threads (<a
href="https://redirect.github.com/astral-sh/uv/issues/21746">#21746</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/ef1e0689b4612796d7781ebeae7866028c6c9e82"><code>ef1e068</code></a>
Make Git stamping opt-in for development builds (<a
href="https://redirect.github.com/astral-sh/uv/issues/21750">#21750</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/6ce09770cec30b30cdc66c3595517dce2b112562"><code>6ce0977</code></a>
Avoid panics for non-base index URLs (<a
href="https://redirect.github.com/astral-sh/uv/issues/21784">#21784</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/47f19ec154f325ade7d6045c4e785531c24635f7"><code>47f19ec</code></a>
Return an error for failed VerbatimUrl path conversions (<a
href="https://redirect.github.com/astral-sh/uv/issues/21783">#21783</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/uv/compare/0.12.13...0.12.16">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-19 23:18:59 -04:00
splitsec2andInfiniteAvenger 44f4e13cce refactor: extract the per-source release search out of /api/releases (#1355)
The `/api/releases` route carries an inner `_search_source_releases`
helper that builds the search plan for one source, logs the planned
query type, runs the search and turns
`SourceUnavailableError`/operational errors into an error message
instead of raising. Anything outside the route that wants to search one
source with exactly those semantics has to go through Flask today.

This moves that helper into `shelfmark/core/release_search.py` as
`search_source_releases()` and has the route delegate to it. Behaviour
is unchanged: same plan construction (including the caller's `user_id`,
so per-user default languages still apply), same logging, same
error-to-message handling.

It is the refactor half of #1047 by @InfiniteAvenger, split out on its
own as you asked for other PRs (#1318). Their authorship is preserved on
the commit; I rebased it onto current `main` and added tests.

## Verification

- `tests/core/test_release_search.py`: unknown source → `"Unknown
source: …"`, `SourceUnavailableError` and operational errors →
`"<source>: <error>"`, success path forwards `expand_search` /
`content_type` and returns the source instance, the plan receives
languages / manual query / indexers / `user_id`. (These tests are
type-annotated; happy to strip the annotations if you prefer the suite's
bare style.)
- Full suite, ruff, ruff format, basedpyright, vulture green; the
existing `/api/releases` route tests are unchanged and pass.

Co-authored-by: InfiniteAvenger <calebewest02@gmail.com>
2026-09-19 23:16:53 -04:00