Skip to content

chore(deps): update dependency verdaccio to v6.10.5 - #8590

Merged
renovate[bot] merged 2 commits into
mainfrom
renovate/verdaccio-6.x-lockfile
Oct 7, 2026
Merged

renovate[bot] merged 2 commits into
mainfrom
renovate/verdaccio-6.x-lockfile

Conversation

@renovate

@renovate renovate Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
verdaccio (source) 6.9.0 → 6.10.5 age confidence

Release Notes

verdaccio/verdaccio (verdaccio)

v6.10.5

Compare Source

Patch Changes
  • 2ccbacf: Migrate the 6.x release workflow to Changesets action v2 and CLI v3.

  • c159460: Improve validation of Search v1 query parameters.

    size and from now accept only plain string values; anything else falls back to the default page size and offset, as other non-numeric values already did. Only plain string parameters are forwarded to uplinks. An uplink search response that cannot be read now ends that uplink's results, and local results are still returned. Unexpected errors in the search endpoint are reported through the regular error handler. Registry configuration does not need to change.

  • ec341ee: Validate Search v1 query text before starting a search.

    Search requests must provide a single, non-blank text string. Missing or invalid search text now receives HTTP 400 with the JSON error code ERR_TEXT_MISSING, before searching local packages or uplinks.

    Earlier 6.x releases could accept searches without text. Clients that call the search API directly must now supply a non-blank query. Valid query text is preserved, and searches with no matching packages continue to return HTTP 200 with an empty results array.

  • 35e8373: Update verdaccio dependencies to the latest npm dist-tag (@verdaccio/ui-theme tracks next-9):

    • @verdaccio/auth: 8.1.4 → 8.1.5
    • @verdaccio/config: 8.3.1 → 8.3.2
    • @verdaccio/core: 8.3.1 → 8.3.2
    • @verdaccio/hooks: 8.1.5 → 8.1.6
    • @verdaccio/loaders: 8.1.4 → 8.1.5
    • @verdaccio/local-storage-legacy: 11.4.4 → 11.4.5
    • @verdaccio/logger: 8.1.4 → 8.1.5
    • @verdaccio/middleware: 8.1.5 → 8.1.6
    • @verdaccio/package-filter: 13.2.2 → 13.2.3
    • @verdaccio/signature: 8.1.4 → 8.1.5
    • @verdaccio/tarball: 13.1.4 → 13.1.5
    • @verdaccio/ui-theme: 9.0.0-next-9.31 → 9.0.0-next-9.33
    • @verdaccio/url: 13.1.4 → 13.1.5
    • verdaccio-audit: 13.1.5 → 13.1.6
    • verdaccio-htpasswd: 13.1.4 → 13.1.5

    Package name validation now follows the npm rules for existing packages: names that start with an underscore, use @ without a scope, or contain characters that are not URL-friendly are rejected with HTTP 400 instead of being looked up. Packages whose names cannot be stored as a directory of the same name on every platform (for example nul or aux.js) are still served from uplinks, but are not cached locally and cannot be published to local storage; a warning is logged when one is requested. Rename any private package with such a name before upgrading. Registry configuration does not need to change.

  • 3d1ca06: Improve version validation in GET /<package>/<version>.

    The endpoint now resolves only versions and dist-tags that the package actually defines. A version or tag name that the package does not define now returns HTTP 404 (version not found) in every case, instead of an internal server error for some names. Requests for existing versions, ranges and dist-tags behave as before, and registry configuration does not need to change.

    Update the internal @verdaccio/* modules to their latest 8.x releases (@verdaccio/core and @verdaccio/config 8.3.1, @verdaccio/auth 8.1.4, @verdaccio/middleware 8.1.5, verdaccio-htpasswd 13.1.4, @verdaccio/local-storage-legacy 11.4.4, verdaccio-auth-memory 13.1.4, verdaccio-memory 10.5.4, verdaccio-audit 13.1.5 and the rest of the set), which improve validation of user registration, authentication, API tokens and request parameters. When the htpasswd file is reloaded, users removed from it now stop authenticating without a restart.

    Update brace-expansion and ignore two advisories without a published fix (braces, http-cache-semantics) that are not reachable from the registry code paths.

v6.10.4

Compare Source

Patch Changes
  • 7730e60: Update express to 4.22.3 — directly and through @verdaccio/middleware 8.1.4,
    verdaccio-audit 13.1.4 and @verdaccio/test-helper 4.1.4 — so the registry's entire HTTP
    stack resolves qs 6.16.0, which fixes several denial-of-service advisories in query-string
    handling: a remotely triggerable crash in qs.stringify (TypeError on crafted input), an
    arrayLimit bypass through bracket-key comma parsing that allows memory exhaustion, and a
    DoS via an attacker-controlled isBuffer check (GHSA-4mjr-xmp4-gh2g). A body-parser/qs
    resolution covers the one remaining consumer that pins qs below the fix. Query-string
    parsing behaviour is otherwise unchanged and no configuration change is needed.

    The same update refreshes the development dependency tree, clearing every high-severity
    yarn npm audit finding (stale transitive resolutions of tar, minimatch, socks/ip, js-yaml,
    form-data, nanoid, postcss, picomatch, tmp and systeminformation, plus vitest 4.1.11 for the
    @vitest/mocker path-traversal advisory) — none of these ship in the published package.

  • aabb0b4: Fix npm publish failing with request size did not match content length when authenticating with a token created by npm token create.

    The JSON body parser was registered by the API router, which runs after apiJWTmiddleware() and after enforceGeneratedTokenMetadata(). The latter awaits a storage lookup for tokens that carry a server-issued key, so the request body was partially consumed before the parser attached. It is now registered before both, as it already is on master.

  • e2602b3: Update verdaccio dependencies to the latest npm dist-tag (@verdaccio/ui-theme tracks next-9):

    • @verdaccio/ui-theme: 9.0.0-next-9.30 → 9.0.0-next-9.31

v6.10.3

Compare Source

Patch Changes
  • 98b58ef: fix: do not fetch client-controlled dist.tarball urls off-uplink @​cOmrade3267

    Only fetch a tarball url that a configured uplink actually serves. Off-uplink urls are
    fetched without uplink credentials and only for uplink-synced packages (recorded in
    _distfiles); a locally published package returns 404 instead of being fetched. Prevents
    sending an uplink Authorization header to an unrelated host.

v6.10.2

Compare Source

Patch Changes
  • 6d972d1: fix: resolve fast-uri and brace-expansion security advisories

    fast-uri 3.1.6. Bumps the ajv/fast-uri resolution from 3.1.5 to 3.1.6, which
    fixes four high-severity advisories in the URI parser used by ajv for schema
    format validation: host confusion via skipped IDN canonicalization
    (GHSA-5jgf-p345-68v8),
    SSRF via malformed IPv6 normalization
    (GHSA-f65p-4m7j-42xc),
    SSRF via repeated hostname percent-decoding
    (GHSA-fph4-wmhf-6fwf),
    and host confusion via percent-encoded scheme normalization
    (GHSA-jqff-g426-hqxp).

    brace-expansion DoS cleanup. Updates the remaining vulnerable
    brace-expansion trees (1.1.11 → 1.1.18, 2.0.1 → 2.1.4) for
    GHSA-mh99-v99m-4gvg and
    drops the temporary audit ignores that covered them while the patched
    releases were still quarantined by the minimal-age gate.

  • 6d972d1: chore: update e2e library

  • ca00ee0: fix: stop re-compressing tarballs for gzip-accepting clients

    mime-db marks application/octet-stream as compressible, so the compression
    middleware re-gzipped every (already gzipped) .tgz download for clients
    that accept gzip — npm and undici do by default — wasting CPU on every
    download and stripping the Content-Length header. Tarball responses are
    now excluded from compression; JSON metadata responses stay compressed.

    Measured on a 30 MB tarball: ~18x less server CPU and ~20x faster downloads,
    with slightly fewer bytes on the wire (gzip over gzip nets negative).

  • d4b8199: Update verdaccio dependencies to the latest npm dist-tag (@verdaccio/ui-theme tracks next-9):

    • @verdaccio/ui-theme: 9.0.0-next-9.28 → 9.0.0-next-9.30
  • d94ebff: fix: validate the scope segment on the web package endpoints

    The readme and sidebar web endpoints now validate the :scope route segment
    and return 404 for malformed requests.

v6.10.1

Compare Source

Patch Changes
  • 90d5c20: Import shared helpers from @verdaccio/core and drop the deprecated @verdaccio/utils dependency

    All internal usages of @verdaccio/utils now resolve the same helpers from
    @verdaccio/core (validation, auth, crypto, package and author utilities), and
    the @verdaccio/utils dependency has been removed.

  • 7805d50: Limit web UI search responses to 20 packages.

  • c84070b: Update verdaccio dependencies to the latest npm dist-tag (@verdaccio/ui-theme tracks next-9):

    • @verdaccio/ui-theme: 9.0.0-next-9.27 → 9.0.0-next-9.28

v6.10.0

Compare Source

Minor Changes
  • 51c2733: Expose the optional legacy authentication cache for Verdaccio 6.x through server.legacyAuthCache.

    This feature is intended for performance-sensitive installations that still use legacy bearer tokens. When enabled, Verdaccio caches successful legacy token authentication results for a short period of time, so repeated requests using the same token do not need to run password verification through the authentication plugin every time. Concurrent requests for the same legacy token can also share the same in-flight authentication result.

    The cache is disabled by default, so existing installations keep their current authentication behavior unless they explicitly opt in. Basic authentication is not cached. If the cache is enabled, changed or revoked credentials may remain valid until the cached entry expires.

    Enable it in config.yaml:

    server:
      legacyAuthCache:
        enabled: true
        ttlMs: 15000
        maxEntries: 1000

    Options:

    • enabled: enables the legacy token authentication cache. Default: false.
    • ttlMs: time in milliseconds before a cached validation expires. Default: 15000.
    • maxEntries: maximum number of cached legacy tokens. Default: 1000.

    See #​6147 and the original 8.x backport in #​6143.

v6.9.3

Compare Source

Patch Changes
  • 3c8f391: Reject wildcard characters in package and tarball path validation.

  • ebc08ba: Update verdaccio dependencies to the latest npm dist-tag (@verdaccio/ui-theme tracks next-9):

    This dependency refresh includes @verdaccio/package-filter 13.2.0 with excludeDeprecated support from #​6142 by @​jotadeveloper, based on the original work by @​davidus27. It also includes the @verdaccio/ui-theme update containing the homepage action hover fix from #​6135 by @​pranshuchittora.

    • @verdaccio/auth: 8.1.1 → 8.1.2
    • @verdaccio/config: 8.2.1 → 8.2.2
    • @verdaccio/core: 8.2.1 → 8.2.2
    • @verdaccio/hooks: 8.1.2 → 8.1.3
    • @verdaccio/loaders: 8.1.1 → 8.1.2
    • @verdaccio/local-storage-legacy: 11.4.1 → 11.4.2
    • @verdaccio/logger: 8.1.1 → 8.1.2
    • @verdaccio/middleware: 8.1.1 → 8.1.2
    • @verdaccio/package-filter: 13.1.1 → 13.2.0
    • @verdaccio/signature: 8.1.1 → 8.1.2
    • @verdaccio/tarball: 13.1.1 → 13.1.2
    • @verdaccio/ui-theme: 9.0.0-next-9.23 → 9.0.0-next-9.26
    • @verdaccio/url: 13.1.1 → 13.1.2
    • @verdaccio/utils: 8.2.1 → 8.2.2
    • verdaccio-audit: 13.1.1 → 13.1.2
    • verdaccio-htpasswd: 13.1.1 → 13.1.2

v6.9.2

Compare Source

Patch Changes
  • 297dc43: fix: apply package access controls to the starredByUser endpoint

    The GET /-/_view/starredByUser view did not enforce the configured package
    access policy when listing a user's starred packages. Results are now filtered
    through auth.allow_access, so the response only includes packages the
    requesting client is authorized to see.

  • 05917d5: Update verdaccio dependencies to the latest npm dist-tag (@verdaccio/ui-theme tracks next-9):

    • @verdaccio/ui-theme: 9.0.0-next-9.22 → 9.0.0-next-9.23

v6.9.1

Compare Source

Patch Changes
  • dfe3938: Update verdaccio dependencies to the latest npm dist-tag (@verdaccio/ui-theme tracks next-9):

    • @verdaccio/auth: 8.1.0 → 8.1.1
    • @verdaccio/config: 8.2.0 → 8.2.1
    • @verdaccio/core: 8.2.0 → 8.2.1
    • @verdaccio/hooks: 8.1.1 → 8.1.2
    • @verdaccio/loaders: 8.1.0 → 8.1.1
    • @verdaccio/local-storage-legacy: 11.4.0 → 11.4.1
    • @verdaccio/logger: 8.1.0 → 8.1.1
    • @verdaccio/middleware: 8.1.0 → 8.1.1
    • @verdaccio/package-filter: 13.1.0 → 13.1.1
    • @verdaccio/signature: 8.1.0 → 8.1.1
    • @verdaccio/tarball: 13.1.0 → 13.1.1
    • @verdaccio/ui-theme: 9.0.0-next-9.21 → 9.0.0-next-9.22
    • @verdaccio/url: 13.1.0 → 13.1.1
    • @verdaccio/utils: 8.2.0 → 8.2.1
    • verdaccio-audit: 13.1.0 → 13.1.1
    • verdaccio-htpasswd: 13.1.0 → 13.1.1

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 7, 2026
@renovate
renovate Bot requested a review from a team as a code owner October 7, 2026 16:19
@renovate renovate Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 7, 2026
@renovate
renovate Bot enabled auto-merge (squash) October 7, 2026 16:19
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: dd906158-555c-4390-af5e-896e67f4b303

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

📊 Benchmark results

Comparing with 7737fea

  • Dependency count: 1,019 ⬆️ 0.49% increase vs. 7737fea
  • Package size: 380 MB ⬆️ 1.56% increase vs. 7737fea
  • Number of ts-expect-error directives: 331 (no change)

@pkg-pr-new

pkg-pr-new Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/netlify-cli@8590

commit: 84d7317

@sarahetter sarahetter left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lockfile-only verdaccio 6.9.0 → 6.10.5 (dev, e2e registry). Fixes qs (GHSA-4mjr-xmp4-gh2g, GHSA-x5fp-wj9c-mxmx, GHSA-q8mj-m7cp-5q26) and js-yaml 5 (GHSA-r3ph-w7gj-g6xm). Verified undici stays at 7.30.0 after merging main.

@renovate
renovate Bot merged commit 579a171 into main Oct 7, 2026
37 checks passed
@renovate
renovate Bot deleted the renovate/verdaccio-6.x-lockfile branch October 7, 2026 16:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant