Skip to content

chore(deps): update npm dependencies updates - #148

Merged
koromerzhin merged 1 commit into
developfrom
renovate/npm-dependencies-updates
Sep 21, 2026
Merged

koromerzhin merged 1 commit into
developfrom
renovate/npm-dependencies-updates

Conversation

@renovate

@renovate renovate Bot commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
jscpd (source) 5.2.* → 5.3.* age confidence
release-it 21.0.* → 21.1.* age confidence
socket.io (source) 4.6.2 → 4.8.3 age confidence

Release Notes

kucherenko/jscpd (jscpd)

v5.3.0

Compare Source

jscpd 5.3.0 adds a health score for your codebase, a full project dashboard, and a batch of fixes found during a pre-release review.

Highlights

🩺 --health — one score for the codebase. A single 0–100 number (with an A–E grade) built from three shares of the code: duplication, dead code and complexity. Small projects aren't unfairly punished — the score adjusts for project size — and a dimension jscpd can't measure (no JS/TS/Python to check for dead code, say) is left out and labeled n/a rather than silently scored as perfect. Plug in your own metrics — coverage, security scan results, whatever you track — with --health-input.

Health  B   74/100  █████████████████▊░░░░░░  93 lines of code (XS)
  duplication   75  █████████░░░  5.4% in typescript (no text)
  dead code     72  ████████▋░░░  14.0%
  complexity    76  █████████▏░░  0.0% in complex files

📊 --dashboard — the whole picture on one screen. Everything above, plus project size, a duplication breakdown by format, your most complex files, and dead-code findings by category — all in one run, one report. markdown and html reporters are new for both --dashboard and --health, alongside the existing console, json and badge (SVG) output.

⚡ --complexity — just the complexity half of --summary, without a clone scan. Handy when all you want is "what's the most complex file in here," fast.

🎯 --kind — filter clones by how they were found: exact, renamed, or similar (and, for similar, whether it was a near-miss gap merge or a structural match). Typos are caught rather than silently returning a clean report.

🧮 More accurate complexity counting. The --summary --summary-by complexity estimate now tracks real cyclomatic complexity much more closely — short-circuit operators (&&, ||) count properly across every language, branches are counted the way each language actually spells them (Rust match arms, Swift guard, Go select, and so on), and complexity is measured per function instead of per file. Validated against lizard across nine languages, with agreement on file ranking rising from 0.83 to 0.92.

🧟 --dead-code — find code nothing runs. A new engine, basta, builds your project's import graph from its real entry points and reports unused files, exports, and imports across JavaScript, TypeScript, Vue, Svelte, Astro and Python — including monorepo package names, path aliases, and framework conventions (Nuxt, SvelteKit, Astro components). Every finding comes with a confidence score, so you know how much to trust it. It's available inside jscpd as --dead-code, and also ships as its own standalone basta command.

See the full changelog for the details on all of the above.

Fixes

  • A single mistyped field in .jscpd.json no longer throws out the whole config — only the bad field is dropped, everything else still applies.
  • --dashboard/--health and their markdown/html output now escape untrusted values (file paths, custom format names, external metric IDs) before rendering them, closing off ways a crafted file name could break a table or inject content.
  • --dashboard/--health now drop the dead-code section gracefully when --format excludes every language it can analyze, instead of failing the whole report.
  • --complexity --fail-on-empty now writes its reports before failing, matching every other mode.
  • --min-confidence above 100 is now clamped (with a warning) everywhere it's read, not just in the standalone --dead-code mode.
  • Fixed a health-score bug where excluding markup duplication (HTML, CSS, templates, …) from scoring barely moved the number on real projects — it's now a proper exclusion on both sides of the calculation.
  • Windows report paths now use forward slashes consistently, matching every other platform's output.
  • Bumped basta's oxc parser crates to 0.150.

Thanks

Thanks to @​Dev-next-gen for fixing how plain text, log and CSV files handle comments (#​1065) 🙌

Published Packages

  • basta@0.1.1 on crates.io
  • cpd-core@0.1.15 on crates.io
  • cpd-finder@0.1.17 on crates.io
  • cpd-reporter@0.1.16 on crates.io
  • cpd-tokenizer@0.1.17 on crates.io
  • jscpd@5.3.0 on crates.io
  • cpd@5.3.0 on npm
  • jscpd@5.3.0 on npm
  • jscpd-darwin-arm64@5.3.0 on npm
  • jscpd-darwin-x64@5.3.0 on npm
  • jscpd-linux-x64-gnu@5.3.0 on npm
  • jscpd-linux-arm64-gnu@5.3.0 on npm
  • jscpd-linux-x64-musl@5.3.0 on npm
  • jscpd-linux-arm64-musl@5.3.0 on npm
  • jscpd-windows-x64-msvc@5.3.0 on npm
  • jscpd-windows-arm64-msvc@5.3.0 on npm
  • jscpd==5.3.0 on PyPI

Verify

Archives are signed with Sigstore (keyless, <asset>.sigstore.json)
and carry SLSA build provenance. Replace jscpd-linux-x64-gnu.tar.gz with your asset:

cosign verify-blob \
  --bundle jscpd-linux-x64-gnu.tar.gz.sigstore.json \
  --certificate-identity-regexp '^https://github\.com/kucherenko/jscpd/' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  jscpd-linux-x64-gnu.tar.gz
gh attestation verify jscpd-linux-x64-gnu.tar.gz --repo kucherenko/jscpd
sha256sum --check --ignore-missing checksums.txt
release-it/release-it (release-it)

v21.1.0

Compare Source

socketio/socket.io (socket.io)

v4.8.3

Compare Source

Bug Fixes
  • do not throw when calling io.close() on a stopped server (9581f9b)
Dependencies

v4.8.2

Compare Source

The url.parse() function is now deprecated and has been replaced by new URL() (see 8af7019).

Bug Fixes
Dependencies

v4.8.1

Compare Source

Due to a change in the bundler configuration, the production bundle (socket.io.min.js) did not support sending and receiving binary data in version 4.8.0. This is now fixed.

Dependencies

v4.8.0

Compare Source

Bug Fixes
  • allow to join a room in a middleware (uws) (b04fa64)
  • correctly await async close on adapters (#​4971) (e347a3c)
  • expose type of default engine (132d05f)
Dependencies

v4.7.5

Compare Source

Bug Fixes
  • close the adapters when the server is closed (bf64870)
  • remove duplicate pipeline when serving bundle (e426f3e)
Links

v4.7.4

Compare Source

Bug Fixes
  • typings: calling io.emit with no arguments incorrectly errored (cb6d2e0), closes #​4914
Links

v4.7.3

Compare Source

Bug Fixes
  • return the first response when broadcasting to a single socket (#​4878) (df8e70f)
  • typings: allow to bind to a non-secure Http2Server (#​4853) (8c9ebc3)
Links

v4.7.2

Compare Source

Bug Fixes
  • clean up child namespace when client is rejected in middleware (#​4773) (0731c0d)
  • webtransport: properly handle WebTransport-only connections (3468a19)
  • webtransport: add proper framing (a306db0)
Links

v4.7.1

Compare Source

The client bundle contains a few fixes regarding the WebTransport support.

Links

v4.7.0

Compare Source

Bug Fixes
  • remove the Partial modifier from the socket.data type (#​4740) (e5c62ca)
Features
Support for WebTransport

The Socket.IO server can now use WebTransport as the underlying transport.

WebTransport is a web API that uses the HTTP/3 protocol as a bidirectional transport. It's intended for two-way communications between a web client and an HTTP/3 server.

References:

Until WebTransport support lands in Node.js, you can use the @fails-components/webtransport package:

import { readFileSync } from "fs";
import { createServer } from "https";
import { Server } from "socket.io";
import { Http3Server } from "@fails-components/webtransport";

// WARNING: the total length of the validity period MUST NOT exceed two weeks (https://w3c.github.io/webtransport/#custom-certificate-requirements)
const cert = readFileSync("/path/to/my/cert.pem");
const key = readFileSync("/path/to/my/key.pem");

const httpsServer = createServer({
  key,
  cert
});

httpsServer.listen(3000);

const io = new Server(httpsServer, {
  transports: ["polling", "websocket", "webtransport"] // WebTransport is not enabled by default
});

const h3Server = new Http3Server({
  port: 3000,
  host: "0.0.0.0",
  secret: "changeit",
  cert,
  privKey: key,
});

(async () => {
  const stream = await h3Server.sessionStream("/socket.io/");
  const sessionReader = stream.getReader();

  while (true) {
    const { done, value } = await sessionReader.read();
    if (done) {
      break;
    }
    io.engine.onWebTransportSession(value);
  }
})();

h3Server.startServer();

Added in 123b68c.

Client bundles with CORS headers

The bundles will now have the right Access-Control-Allow-xxx headers.

Added in 63f181c.

Links

Configuration

📅 Schedule: (in timezone Europe/Paris)

  • Branch creation
    • "before 8am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/npm-dependencies-updates branch from ca1610b to 7a9e5ee Compare September 21, 2026 09:36
@koromerzhin
koromerzhin merged commit d4a43dc into develop Sep 21, 2026
3 checks passed
@koromerzhin
koromerzhin deleted the renovate/npm-dependencies-updates branch September 21, 2026 10:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant