Skip to content
Closed

G #1961

Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
638 commits
Select commit Hold shift + click to select a range
aa9c647
Merge pull request #1817 from maxmind/dependabot/github_actions/zizmo…
horgh Feb 9, 2026
369c40b
Bump the minor-and-patch group across 1 directory with 5 updates
dependabot[bot] Feb 10, 2026
68deb9c
Merge pull request #1816 from maxmind/dependabot/npm_and_yarn/minor-a…
mm-jpoole Feb 10, 2026
979b82e
Bump github/codeql-action from 4.31.10 to 4.32.3
dependabot[bot] Feb 20, 2026
f3b067c
Merge pull request #1821 from maxmind/dependabot/github_actions/githu…
horgh Feb 20, 2026
a8ada7b
Bump the minor-and-patch group across 1 directory with 4 updates
dependabot[bot] Feb 23, 2026
e670bf8
Merge pull request #1822 from maxmind/dependabot/npm_and_yarn/minor-a…
dhogan8 Feb 23, 2026
2673fff
Add trackingToken to Device request object
oschwald Feb 23, 2026
677d514
Merge pull request #1823 from maxmind/greg/eng-4047
horgh Feb 25, 2026
d469752
Bump minimatch from 3.1.2 to 3.1.5 in /e2e/js
dependabot[bot] Feb 28, 2026
0876eeb
Bump minimatch
dependabot[bot] Feb 28, 2026
a6c5b06
Bump minimatch from 3.1.2 to 3.1.5 in /e2e/ts
dependabot[bot] Mar 1, 2026
b8051b9
Bump actions/setup-node from 6.2.0 to 6.3.0
dependabot[bot] Mar 10, 2026
08426fe
Merge pull request #1833 from maxmind/dependabot/github_actions/actio…
horgh Mar 10, 2026
0ebe519
Merge pull request #1829 from maxmind/dependabot/npm_and_yarn/e2e/js/…
PatrickCroninMM Mar 12, 2026
f99d43c
Merge pull request #1831 from maxmind/dependabot/npm_and_yarn/e2e/ts/…
PatrickCroninMM Mar 12, 2026
ba5343c
Merge pull request #1830 from maxmind/dependabot/npm_and_yarn/multi-b…
PatrickCroninMM Mar 12, 2026
64606be
Bump the minor-and-patch group across 1 directory with 3 updates
dependabot[bot] Mar 12, 2026
3b52c7f
Merge pull request #1832 from maxmind/dependabot/npm_and_yarn/minor-a…
PatrickCroninMM Mar 12, 2026
6c2a78f
Bump eslint from 9.39.2 to 10.0.0
dependabot[bot] Mar 12, 2026
abdd780
Merge pull request #1825 from maxmind/dependabot/npm_and_yarn/eslint-…
PatrickCroninMM Mar 12, 2026
599baec
Bump @eslint/js from 9.39.2 to 10.0.1
dependabot[bot] Mar 12, 2026
0c150ab
Merge pull request #1826 from maxmind/dependabot/npm_and_yarn/eslint/…
PatrickCroninMM Mar 12, 2026
0347309
Bump github/codeql-action from 4.32.3 to 4.32.6
dependabot[bot] Mar 13, 2026
b9db61e
Merge pull request #1835 from maxmind/dependabot/github_actions/githu…
horgh Mar 13, 2026
51630da
Bump zizmorcore/zizmor-action from 0.5.0 to 0.5.2
dependabot[bot] Mar 16, 2026
118800d
Merge pull request #1837 from maxmind/dependabot/github_actions/zizmo…
horgh Mar 16, 2026
cbdf9bf
Bump the minor-and-patch group across 1 directory with 4 updates
dependabot[bot] Mar 17, 2026
95ce195
Bump flatted from 3.3.3 to 3.4.2
dependabot[bot] Mar 21, 2026
e28c59c
Merge pull request #1838 from maxmind/dependabot/npm_and_yarn/minor-a…
mm-jpoole Mar 24, 2026
a16fdc4
Merge pull request #1839 from maxmind/dependabot/npm_and_yarn/flatted…
mm-jpoole Mar 24, 2026
7f86d21
Clarify that ipAddress is not required
horgh Mar 25, 2026
9bc14dd
Merge pull request #1841 from maxmind/wstorey/docs
horgh Mar 25, 2026
7dd7f56
Bump picomatch from 2.3.1 to 2.3.2 in /e2e/ts
dependabot[bot] Mar 25, 2026
bbe1778
Bump picomatch from 2.3.1 to 2.3.2 in /e2e/js
dependabot[bot] Mar 25, 2026
b9aa942
Add fat_zebra payment processor
horgh Apr 2, 2026
c71fd3c
Merge pull request #1847 from maxmind/wstorey/eng-4633-new-payment-pr…
oschwald Apr 3, 2026
750a4dd
Bump github/codeql-action from 4.32.6 to 4.35.1
dependabot[bot] Apr 6, 2026
56a1dfe
Merge pull request #1848 from maxmind/dependabot/github_actions/githu…
oschwald Apr 6, 2026
db85eae
Bump the minor-and-patch group across 1 directory with 7 updates
dependabot[bot] Apr 10, 2026
b3075d1
Merge pull request #1853 from maxmind/dependabot/npm_and_yarn/minor-a…
mm-kevcenteno Apr 10, 2026
383f52f
Bump picomatch from 2.3.1 to 2.3.2
dependabot[bot] Apr 10, 2026
cea4d29
Merge pull request #1843 from maxmind/dependabot/npm_and_yarn/e2e/js/…
mm-kevcenteno Apr 10, 2026
e515964
Merge pull request #1842 from maxmind/dependabot/npm_and_yarn/e2e/ts/…
mm-kevcenteno Apr 10, 2026
9aae5cd
Bump brace-expansion from 1.1.12 to 1.1.13 in /e2e/ts
dependabot[bot] Apr 10, 2026
fae089c
Bump brace-expansion from 1.1.12 to 1.1.13 in /e2e/js
dependabot[bot] Apr 10, 2026
3ba6e20
Merge pull request #1849 from maxmind/dependabot/npm_and_yarn/e2e/ts/…
dhogan8 Apr 20, 2026
530fe93
Bump the minor-and-patch group across 1 directory with 7 updates
dependabot[bot] Apr 20, 2026
fded331
Bump zizmorcore/zizmor-action from 0.5.2 to 0.5.3
dependabot[bot] Apr 20, 2026
41d4903
Merge pull request #1850 from maxmind/dependabot/npm_and_yarn/e2e/js/…
dhogan8 Apr 20, 2026
e418624
Merge pull request #1854 from maxmind/dependabot/npm_and_yarn/picomat…
dhogan8 Apr 20, 2026
c4db076
Merge pull request #1859 from maxmind/dependabot/npm_and_yarn/minor-a…
dhogan8 Apr 20, 2026
f9ac26e
Bump typescript from 5.9.3 to 6.0.2
dependabot[bot] Apr 20, 2026
2642286
Merge pull request #1860 from maxmind/dependabot/github_actions/zizmo…
horgh Apr 21, 2026
ae16c2a
Update for typescript v6
dhogan8 Apr 21, 2026
247ce73
Fix nock cleanup to prevent InterceptorError from delayed responses
dhogan8 Apr 21, 2026
635ac97
Merge pull request #1856 from maxmind/dependabot/npm_and_yarn/typescr…
dhogan8 Apr 21, 2026
174ba15
Bump github/codeql-action from 4.35.1 to 4.35.2
dependabot[bot] Apr 22, 2026
c1009e7
Merge pull request #1864 from maxmind/dependabot/github_actions/githu…
horgh Apr 22, 2026
07c1e4e
Add `CLEAR` to the `Tag` enum
oschwald Apr 22, 2026
9da8268
Merge pull request #1865 from maxmind/greg/stf-190
horgh Apr 23, 2026
5681228
Bump actions/setup-node from 6.3.0 to 6.4.0
dependabot[bot] Apr 27, 2026
b78cb23
Merge pull request #1868 from maxmind/dependabot/github_actions/actio…
horgh Apr 29, 2026
b11e380
Bump the minor-and-patch group across 1 directory with 4 updates
dependabot[bot] May 1, 2026
85e7aea
Merge pull request #1870 from maxmind/dependabot/npm_and_yarn/minor-a…
mm-jpoole May 4, 2026
333df9c
Bump github/codeql-action from 4.35.2 to 4.35.3
dependabot[bot] May 8, 2026
627daae
Merge pull request #1872 from maxmind/dependabot/github_actions/githu…
horgh May 8, 2026
0aa1222
Bump github/codeql-action from 4.35.3 to 4.35.4
dependabot[bot] May 14, 2026
751488c
Merge pull request #1874 from maxmind/dependabot/github_actions/githu…
horgh May 14, 2026
17f9568
Bump the minor-and-patch group across 1 directory with 6 updates
dependabot[bot] May 15, 2026
cc22104
Merge pull request #1875 from maxmind/dependabot/npm_and_yarn/minor-a…
mm-kevcenteno May 15, 2026
4ec7d04
Bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0
dependabot[bot] May 20, 2026
85ff1d5
Merge pull request #1877 from maxmind/dependabot/github_actions/peace…
horgh May 21, 2026
726ac1a
Bump zizmorcore/zizmor-action from 0.5.3 to 0.5.5
dependabot[bot] May 21, 2026
e3107de
Bump github/codeql-action from 4.35.4 to 4.35.5
dependabot[bot] May 22, 2026
2a5b80c
Merge pull request #1879 from maxmind/dependabot/github_actions/githu…
horgh May 22, 2026
b2e7a1d
Merge pull request #1878 from maxmind/dependabot/github_actions/zizmo…
horgh May 22, 2026
6583a5a
Bump zizmorcore/zizmor-action from 0.5.5 to 0.5.6
dependabot[bot] May 25, 2026
48df490
Merge pull request #1881 from maxmind/dependabot/github_actions/zizmo…
horgh May 26, 2026
cac7464
Drop node 18 and 20
kevcenteno May 25, 2026
2001f90
Update e2e deps and prefix node libraries
kevcenteno May 25, 2026
a14557a
Alpha-sort event fields
kevcenteno May 25, 2026
b796f79
Upgrade ts-jest
kevcenteno May 26, 2026
e52abb7
Rebuild lock files
kevcenteno May 26, 2026
05c0723
Add jest type to e2e/ts
kevcenteno May 26, 2026
362bf07
Bump github/codeql-action from 4.35.5 to 4.36.0
dependabot[bot] May 29, 2026
328d048
Use 'GeoIP'/'GeoLite' branding in documentation and prose
oschwald May 29, 2026
6b8893e
Update remaining GeoIP2 product prose to GeoIP
oschwald May 29, 2026
6fcb4b4
Merge pull request #1885 from maxmind/greg/stf-555
horgh May 29, 2026
f7fb6c3
Use AbortSignal instead of AbortController
kevcenteno May 26, 2026
ad9e565
Replace crypto.createHash with crypto.hash
kevcenteno May 26, 2026
9e1d6e3
Use global URL. No need to import url
kevcenteno May 26, 2026
6796fc5
Use async tests. Restructure webservice fetch error handling
kevcenteno May 26, 2026
a3b5c40
Be defensive about what is caught
kevcenteno May 26, 2026
f11870f
Build as ESM package
mm-kevcenteno Jun 1, 2026
ea72a9b
Update node and typescript versions in claude.md
mm-kevcenteno Jun 1, 2026
1f4cd93
Merge pull request #1884 from maxmind/dependabot/github_actions/githu…
horgh Jun 1, 2026
16bb923
Fix error message
mm-kevcenteno Jun 4, 2026
1452270
Bump version number in package.json
mm-kevcenteno Jun 4, 2026
fcc8863
Fix validator imports
mm-kevcenteno Jun 4, 2026
5e60987
Remove URL imports
mm-kevcenteno Jun 4, 2026
dce1e2d
Add lychee link checker config and CI workflow
oschwald Jun 4, 2026
63a65b3
Update stale and redirecting links
oschwald Jun 4, 2026
c090eed
Merge pull request #1882 from maxmind/kevin/drop-old-node
mm-kevcenteno Jun 5, 2026
74c0933
Merge pull request #1886 from maxmind/greg/stf-557
horgh Jun 5, 2026
0ae107b
Bump jdx/mise-action from 3.6.1 to 4.0.1
dependabot[bot] Jun 8, 2026
e584288
Merge pull request #1888 from maxmind/dependabot/github_actions/jdx/m…
horgh Jun 8, 2026
9422fef
Bump github/codeql-action from 4.36.0 to 4.36.1
dependabot[bot] Jun 9, 2026
1dc6135
Bump actions/checkout from 6.0.2 to 6.0.3
dependabot[bot] Jun 9, 2026
75778b6
Merge pull request #1891 from maxmind/dependabot/github_actions/actio…
horgh Jun 9, 2026
ed09376
Merge pull request #1890 from maxmind/dependabot/github_actions/githu…
horgh Jun 9, 2026
8692b90
Bump github/codeql-action from 4.36.1 to 4.36.2
dependabot[bot] Jun 11, 2026
1fec8d7
Bump jdx/mise-action from 4.0.1 to 4.1.0
dependabot[bot] Jun 11, 2026
b6f80e9
Merge pull request #1893 from maxmind/dependabot/github_actions/jdx/m…
horgh Jun 11, 2026
7886d23
Merge pull request #1892 from maxmind/dependabot/github_actions/githu…
horgh Jun 11, 2026
843db97
Disable npm caching in release workflow
horgh Jun 11, 2026
bfb7138
Merge pull request #1894 from maxmind/wstorey/fix-zizmor
oschwald Jun 11, 2026
50276cb
Bump the minor-and-patch group across 1 directory with 3 updates
dependabot[bot] Jun 15, 2026
c1c2c37
Merge pull request #1895 from maxmind/dependabot/npm_and_yarn/minor-a…
mm-kevcenteno Jun 15, 2026
1f45b5f
Bump the minor-and-patch group across 1 directory with 4 updates
dependabot[bot] Jun 22, 2026
5a30629
Merge pull request #1898 from maxmind/dependabot/npm_and_yarn/minor-a…
mm-kevcenteno Jun 23, 2026
1b27570
Bump actions/checkout from 6.0.3 to 7.0.0
dependabot[bot] Jun 24, 2026
6f713c7
Bump jdx/mise-action from 4.1.0 to 4.2.0
dependabot[bot] Jun 24, 2026
af3714a
Merge pull request #1901 from maxmind/dependabot/github_actions/jdx/m…
horgh Jun 24, 2026
77349d2
Merge pull request #1899 from maxmind/dependabot/github_actions/actio…
horgh Jun 24, 2026
c94db28
Throw WebServiceError instances and preserve error causes
oschwald Jun 24, 2026
717ed80
Include the underlying cause in the FETCH_ERROR message
oschwald Jun 24, 2026
d25fe89
Merge pull request #1902 from maxmind/greg/stf-803
oschwald Jun 24, 2026
cf57ae0
Type WebServiceError.code with an open ClientErrorCode union
oschwald Jun 25, 2026
dc38a99
Preserve underlying cause on ArgumentError
oschwald Jun 25, 2026
e4d6959
Accept an options object and an injectable fetcher in the client
oschwald Jun 25, 2026
fc64739
Stop sanitizeKeys() from mutating caller-owned objects
oschwald Jun 25, 2026
4d4dc3b
Accept customInputs as a plain record
oschwald Jun 25, 2026
08bebe2
Rename camelizeResponse to camelcaseKeys
oschwald Jun 25, 2026
62363bd
Remove the validator production dependency
oschwald Jun 25, 2026
6f4a439
Replace nock with the injected fetcher in web service tests
oschwald Jun 25, 2026
3b3e9f8
Update CHANGELOG for the pre-major-release cleanups
oschwald Jun 25, 2026
749d6dc
Bump zizmorcore/zizmor-action from 0.5.6 to 0.5.7
dependabot[bot] Jun 29, 2026
21c7d5f
Fix and extend the docs for the constructor and customInputs changes
oschwald Jun 29, 2026
4bfd52c
Drop the unused host option from the clientWith test helper
oschwald Jun 29, 2026
6c096e1
Allow IP-literal referrer URIs
oschwald Jun 29, 2026
fb5928a
Verify record-form customInputs serialization
oschwald Jun 29, 2026
91fc00c
Document camelcaseKeys' contract and cover non-plain-object passthrough
oschwald Jun 29, 2026
13ebe71
Validate WebServiceClient option member types
oschwald Jun 29, 2026
d0eeb59
Exclude reserved example IPs from the lychee link check
oschwald Jun 29, 2026
38ac898
Merge pull request #1904 from maxmind/dependabot/github_actions/zizmo…
horgh Jun 29, 2026
2724f31
Merge pull request #1903 from maxmind/greg/stf-809
horgh Jun 29, 2026
d94d523
Add node to mise config
oschwald Jun 29, 2026
cf56a41
Update @maxmind/geoip2-node
oschwald Jun 29, 2026
cb4c573
Set release date
oschwald Jun 29, 2026
29de693
Make release script tolerate an already-bumped package.json
oschwald Jun 29, 2026
316fca8
Merge pull request #1905 from maxmind/greg/stf-855
horgh Jun 30, 2026
a70d099
Bump the minor-and-patch group across 1 directory with 2 updates
dependabot[bot] Jun 30, 2026
dcda41f
Merge pull request #1906 from maxmind/dependabot/npm_and_yarn/minor-a…
mm-jpoole Jun 30, 2026
5ef5935
Bump github/codeql-action/analyze from 4.36.2 to 4.36.3
dependabot[bot] Jul 9, 2026
eb3973c
Bump github/codeql-action/init from 4.36.2 to 4.36.3
dependabot[bot] Jul 9, 2026
9a7cb8c
Bump github/codeql-action/autobuild from 4.36.2 to 4.36.3
dependabot[bot] Jul 9, 2026
d9a885a
Merge pull request #1914 from maxmind/dependabot/github_actions/githu…
horgh Jul 9, 2026
6142fc3
Merge pull request #1913 from maxmind/dependabot/github_actions/githu…
horgh Jul 9, 2026
028bea5
Merge pull request #1912 from maxmind/dependabot/github_actions/githu…
horgh Jul 9, 2026
006f183
Bump github/codeql-action/analyze from 4.36.3 to 4.37.0
dependabot[bot] Jul 15, 2026
73c5d61
Bump github/codeql-action/init from 4.36.3 to 4.37.0
dependabot[bot] Jul 15, 2026
e3a82f5
Bump github/codeql-action/autobuild from 4.36.3 to 4.37.0
dependabot[bot] Jul 15, 2026
b18969a
Require @maxmind/geoip2-node 7.1.0 for residential data
oschwald Jul 16, 2026
17e46b2
Add residential proxy data to anonymizer object
oschwald Jul 10, 2026
1344f19
Update mise tools
oschwald Jul 16, 2026
a9a236e
Migrate test suite from Jest to Vitest
kevcenteno Jul 17, 2026
59bc8fa
Type-check spec files during lint
kevcenteno Jul 17, 2026
a287c36
Enforce coverage thresholds in CI
kevcenteno Jul 17, 2026
6b04f1d
Migrate e2e test suites from Jest to Vitest
kevcenteno Jul 17, 2026
f501859
Update development docs for Vitest
kevcenteno Jul 17, 2026
436fc9b
Restore strict instanceof assertions for parse-error causes
kevcenteno Jul 17, 2026
34069f7
Use @preserve form for v8 coverage ignore hints
kevcenteno Jul 17, 2026
5751493
Merge pull request #1917 from maxmind/greg/stf-1005-add-residential-t…
horgh Jul 17, 2026
105135f
Bump actions/setup-node from 6.4.0 to 7.0.0
dependabot[bot] Jul 20, 2026
c493023
Merge pull request #1922 from maxmind/dependabot/github_actions/actio…
horgh Jul 20, 2026
85e583c
Merge pull request #1921 from maxmind/jest-to-vitest
mm-kevcenteno Jul 20, 2026
9a03dd1
Bump @types/node from 25.9.3 to 26.1.1
dependabot[bot] Jul 20, 2026
7718bb3
Merge pull request #1918 from maxmind/dependabot/github_actions/githu…
horgh Jul 20, 2026
cb9f2eb
Merge pull request #1920 from maxmind/dependabot/github_actions/githu…
horgh Jul 20, 2026
af22d62
Merge pull request #1919 from maxmind/dependabot/github_actions/githu…
horgh Jul 20, 2026
fe67652
Bump brace-expansion from 5.0.6 to 5.0.7
dependabot[bot] Jul 21, 2026
b663139
Set a release date
oschwald Jul 21, 2026
c8c1ee1
Prepare for 9.1.0
oschwald Jul 21, 2026
7d95138
Run Dependabot updates weekly
horgh Jul 21, 2026
5a75ceb
Group CodeQL action updates
horgh Jul 21, 2026
bd9c3a2
Merge pull request #1924 from maxmind/greg/stf-1074
horgh Jul 21, 2026
c8ec99c
Bump linkify-it from 5.0.1 to 5.0.2
dependabot[bot] Jul 21, 2026
673116a
Merge pull request #1925 from maxmind/wstorey/stf-983-run-github-acti…
oschwald Jul 21, 2026
e7d1c4b
Add Dependabot failure watcher workflow
horgh Jul 22, 2026
6e633aa
Merge pull request #1927 from maxmind/wstorey/stf-1124-failures-to-ru…
oschwald Jul 22, 2026
f4bd752
Bump the codeql group with 3 updates
dependabot[bot] Jul 27, 2026
2478d0a
Bump actions/checkout from 7.0.0 to 7.0.1
dependabot[bot] Jul 27, 2026
f41105a
Bump jdx/mise-action from 4.2.0 to 4.2.1
dependabot[bot] Jul 27, 2026
fc11d3e
Merge pull request #1931 from maxmind/dependabot/github_actions/jdx/m…
horgh Jul 27, 2026
4ad0823
Merge pull request #1929 from maxmind/dependabot/github_actions/actio…
horgh Jul 27, 2026
b1681ed
Merge pull request #1928 from maxmind/dependabot/github_actions/codeq…
horgh Jul 27, 2026
5d84d6f
Merge pull request #1908 from maxmind/dependabot/npm_and_yarn/types/n…
mm-kevcenteno Jul 27, 2026
a4a1904
Expand email alias domain lists
faktas2 Jul 29, 2026
6c0e307
Cover e2e npm manifests in Dependabot
horgh Jul 30, 2026
f414954
Merge pull request #1933 from maxmind/wstorey/update-e2e-dependabot
oschwald Jul 30, 2026
acbab91
Bump zizmorcore/zizmor-action from 0.5.7 to 0.6.1
dependabot[bot] Jul 30, 2026
3012dd1
Ignore Dependabot security updates in the failure watcher
horgh Jul 30, 2026
329a415
Merge pull request #1932 from maxmind/expand-email-alias-domains
marselester Jul 30, 2026
ec96d3a
Merge pull request #1939 from maxmind/wstorey/stf-1245-dependabot-fai…
oschwald Jul 30, 2026
81f3b3a
Bump jdx/mise-action from 4.2.1 to 4.2.3
dependabot[bot] Aug 3, 2026
8e991e8
Bump the codeql group across 1 directory with 3 updates
dependabot[bot] Aug 3, 2026
e877b64
Merge pull request #1940 from maxmind/dependabot/github_actions/jdx/m…
horgh Aug 5, 2026
ef39362
Bump postcss from 8.5.19 to 8.5.25 in /e2e/js
dependabot[bot] Aug 5, 2026
b03ef18
Merge pull request #1938 from maxmind/dependabot/github_actions/zizmo…
horgh Aug 5, 2026
383cfa1
Merge pull request #1937 from maxmind/dependabot/github_actions/codeq…
horgh Aug 5, 2026
3821117
Update description for risk reason multiplier (DAT-7343)
andyjack Aug 5, 2026
d93bab3
Merge pull request #1943 from maxmind/andy/risk-reasons
andyjack Aug 7, 2026
fb1e13d
Bump the codeql group with 3 updates
dependabot[bot] Aug 10, 2026
4e852e3
Bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2
dependabot[bot] Aug 10, 2026
55f1da0
Bump jdx/mise-action from 4.2.3 to 4.2.4
dependabot[bot] Aug 10, 2026
00dd394
Merge pull request #1947 from maxmind/dependabot/github_actions/jdx/m…
horgh Aug 10, 2026
4b5a67f
Merge pull request #1946 from maxmind/dependabot/github_actions/zizmo…
horgh Aug 10, 2026
a08b742
Merge pull request #1945 from maxmind/dependabot/github_actions/codeq…
horgh Aug 10, 2026
b0dc49a
Merge pull request #1923 from maxmind/dependabot/npm_and_yarn/brace-e…
mm-kevcenteno Aug 11, 2026
81c9aa4
Merge pull request #1926 from maxmind/dependabot/npm_and_yarn/linkify…
mm-kevcenteno Aug 11, 2026
e85f8cd
Merge pull request #1942 from maxmind/dependabot/npm_and_yarn/e2e/js/…
mm-kevcenteno Aug 11, 2026
8b1c7f8
Bump the codeql group with 3 updates
dependabot[bot] Aug 17, 2026
b788126
Merge pull request #1948 from maxmind/dependabot/github_actions/codeq…
horgh Aug 17, 2026
56ba71d
Bump the codeql group with 3 updates
dependabot[bot] Aug 24, 2026
e3b63d8
Bump jdx/mise-action from 4.2.4 to 4.2.5
dependabot[bot] Aug 24, 2026
05b40a5
Merge pull request #1951 from maxmind/dependabot/github_actions/jdx/m…
horgh Aug 25, 2026
ddf8c66
Merge pull request #1950 from maxmind/dependabot/github_actions/codeq…
horgh Aug 25, 2026
d8cdced
Switch from npm to pnpm
mm-jpoole Aug 26, 2026
fa19181
Update documentation
mm-jpoole Aug 26, 2026
a893c6f
Merge pull request #1949 from maxmind/jpoole/sco-8988-switch-public-r…
mm-jpoole Aug 27, 2026
fd98edd
Bump the codeql group with 3 updates
dependabot[bot] Aug 31, 2026
e2457a8
Merge pull request #1953 from maxmind/dependabot/github_actions/codeq…
horgh Sep 1, 2026
2d94fce
Bump the minor-and-patch group across 1 directory with 3 updates
dependabot[bot] Sep 3, 2026
6c8a986
Bump the codeql group with 3 updates
dependabot[bot] Sep 7, 2026
2710440
Bump jdx/mise-action from 4.2.5 to 4.3.0
dependabot[bot] Sep 7, 2026
bfe0178
Bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3
dependabot[bot] Sep 7, 2026
bc3dc56
Merge pull request #1956 from maxmind/dependabot/github_actions/jdx/m…
horgh Sep 7, 2026
d405f6a
Merge pull request #1957 from maxmind/dependabot/github_actions/zizmo…
horgh Sep 7, 2026
a0bb7e0
Merge pull request #1955 from maxmind/dependabot/github_actions/codeq…
horgh Sep 7, 2026
b09cc3b
Merge pull request #1954 from maxmind/dependabot/npm_and_yarn/minor-a…
mm-kevcenteno Sep 9, 2026
1a5a872
Bump the minor-and-patch group with 4 updates
dependabot[bot] Sep 14, 2026
72e51cd
Bump the codeql group with 3 updates
dependabot[bot] Sep 21, 2026
cacce2d
Bump zizmorcore/zizmor-action from 0.6.3 to 0.6.4
dependabot[bot] Sep 21, 2026
673d559
Merge pull request #1958 from maxmind/dependabot/npm_and_yarn/minor-a…
mm-kevcenteno Sep 22, 2026
0c3354b
Merge pull request #1960 from maxmind/dependabot/github_actions/zizmo…
horgh Sep 22, 2026
a0f6067
Merge pull request #1959 from maxmind/dependabot/github_actions/codeq…
horgh Sep 22, 2026
a3755e8
Modify dependency review workflow configuration
macosx-fromsource Sep 27, 2026
23bb482
Merge pull request #1 from macosx-fromsource/macosx-fromsource-patch-1
macosx-fromsource Sep 27, 2026
67aac7f
Merge branch 'kevin/fetch-throw' into main
macosx-fromsource Sep 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
43 changes: 34 additions & 9 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,36 @@
version: 2
updates:
- package-ecosystem: npm
directory: "/"
schedule:
interval: daily
open-pull-requests-limit: 20
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: daily
# `npm` is also the correct ecosystem for pnpm. This root run reads
# pnpm-workspace.yaml, so it covers the e2e/* members too, bumping a member
# package.json and the root pnpm-lock.yaml in one pull request. Do not add
# per-directory entries: a run inside a member treats the parent lockfile as a
# support file and drops it, leaving it stale and failing --frozen-lockfile
# (dependabot-core#11135).
- package-ecosystem: npm
directory: /
schedule:
interval: weekly
day: monday
time: '14:00'
open-pull-requests-limit: 20
groups:
minor-and-patch:
patterns:
- '*'
update-types:
- minor
- patch
cooldown:
default-days: 7
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
day: monday
time: '14:00'
groups:
codeql:
patterns:
- github/codeql-action*
cooldown:
default-days: 7
10 changes: 6 additions & 4 deletions .github/workflows/codeql-analysis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,19 +18,21 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
# Override language selection by uncommenting this and choosing your languages
# with:
# languages: go, javascript, csharp, python, cpp, java

# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
# If this step fails, then you should remove it and run the build manually (see below)
- name: Autobuild
uses: github/codeql-action/autobuild@v3
uses: github/codeql-action/autobuild@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0

# ℹ️ Command-line programs to run using the OS shell.
# 📚 https://git.io/JvXDl
Expand All @@ -44,4 +46,4 @@ jobs:
# make release

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
114 changes: 114 additions & 0 deletions .github/workflows/dependabot-failure-watcher.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,114 @@
name: Dependabot Failure Watcher

# Dependabot version updates run as GitHub Actions workflow runs named
# "Dependabot Updates". This scheduled job looks back over the past week for any
# version-update run that failed and fails itself if it finds one, so a
# silently-broken ecosystem surfaces as a red scheduled run instead of only a red
# triangle in the Dependabot tab that nobody checks. Security-update runs share
# that workflow name and are deliberately excluded -- see below.
#
# GitHub reuses the "Dependabot Updates" name for three different kinds of run:
#
# 1. A version update's scheduled scan: one run per .github/dependabot.yml
# entry, on the schedule set there. It works out what is out of date and
# opens or updates pull requests. This is the kind this watcher primarily
# exists to catch -- when a scan breaks, the whole ecosystem quietly stops
# being updated and nothing else tells anyone.
# 2. A version update's per-pull-request refresh: one run per already-open
# Dependabot pull request, rebasing or re-checking it. These are not driven
# by the schedule at all -- a push to the base branch, a rebase, or an
# "@dependabot recreate" comment triggers them, so they arrive in bursts
# after merges rather than at the scheduled time. A failure here means one
# open pull request has gone stale, which is worth knowing but is much
# narrower than a broken scan.
# 3. A security update: one ad-hoc job per vulnerable package, triggered by a
# Dependabot alert rather than by dependabot.yml at all.
#
# Kind 3 routinely fails for reasons no pull request can fix: the advisory is
# against a dependency this project does not declare directly, or no patched
# version is reachable. Counting those would keep this workflow permanently red
# and train everyone to ignore it, so they are filtered out below.
#
# Of the fields "gh run list --json" exposes, only the title separates the three
# -- event, headBranch and actor are identical. Titles come in these shapes:
#
# - "<eco> in /." -- kind 1 at the repo root, which
# has no " for " suffix
# - "<eco> in <configured-dir>" -- kind 1 elsewhere, path verbatim
# - "<eco> in / for <deps>" -- kind 2 at the repo root
# - "<eco> in <configured-dir> for <deps>" -- kind 2 elsewhere
# - "<eco> in /. for <one-dep>" -- kind 3 at the repo root
# - "<eco> in <manifest-dir> for <one-dep>" -- kind 3 elsewhere, where
# <manifest-dir> is wherever the vulnerable manifest was discovered
#
# At the root, then, kind 3 is marked by "/." AND a " for " suffix together, and
# BOTH HALVES of " in /. for " are load-bearing -- do not shorten it. Matching on
# " in /." alone would also discard every kind 1 run, which is most of the runs
# here and the shape both failures this watcher was written for actually took.
#
# Outside the root, kinds 2 and 3 cannot be told apart by title, so the filter
# has to name directories instead. e2e/js and e2e/ts (in the Node repos this
# workflow is shared with) are consumer smoke tests, so their transitive dev
# dependencies attract advisories that no pull request can fix, and nothing in
# them is shipped code.
#
# Since the pnpm conversion this clause cannot match kind 2: version updates are
# root-only, so their titles read "in /", never "in /e2e/js". It still discards
# kind 3, which names the directory holding the vulnerable manifest -- for a
# transitive e2e dev dependency, one of these paths. That is the intent, so it
# stays. Keep it in step with dependabot.yml: the ecosystem label cannot rescue
# the distinction, since Dependabot writes "npm_and_yarn" for both kinds.
#
# Reading the directories out of dependabot.yml instead looks more general but is
# worse: entries may use globs (directories: ["**/*"]), which never match a title
# literally, so genuine failures would be dropped without a word. Prefer a
# denylist: when it goes stale it re-introduces noise, which is loud, whereas a
# stale allowlist hides failures, which is silent.
#
# Runs entirely within this repo (no external service). A failed scheduled run
# emails the person who last edited the cron below. Note: GitHub auto-disables
# scheduled workflows after 60 days of repo inactivity.

on:
schedule:
- cron: "17 14 * * 3" # Wednesdays 14:17 UTC
workflow_dispatch:

permissions:
actions: read

jobs:
check-dependabot-runs:
runs-on: ubuntu-latest
steps:
- name: Fail if any Dependabot version update failed in the last 8 days
env:
GH_TOKEN: ${{ github.token }}
REPO: ${{ github.repository }}
run: |
since=$(date -u -d '8 days ago' +%Y-%m-%dT%H:%M:%SZ)
# --created filters server-side, so --limit applies to runs already
# narrowed to the window rather than to all of history. Runs come back
# newest-first, so reaching the limit would drop the oldest in-window
# runs and this step would report all-clear without them -- hence a
# limit far above any plausible week's worth of runs.
runs=$(gh run list \
--repo "$REPO" \
--workflow "Dependabot Updates" \
--created ">=$since" \
--limit 500 \
--json conclusion,createdAt,displayTitle,url)
failures=$(echo "$runs" | jq '
[.[]
| select((.displayTitle | contains(" in /. for ")) | not)
| select((.displayTitle | test(" in /e2e/(js|ts) for ")) | not)
| select(.conclusion == "failure"
or .conclusion == "startup_failure"
or .conclusion == "timed_out")]')
count=$(echo "$failures" | jq 'length')
if [ "$count" -gt 0 ]; then
echo "::error::$count failed Dependabot version update run(s) in the last 8 days:"
echo "$failures" | jq -r '.[] | "- \(.displayTitle) (\(.createdAt))\n \(.url)"'
exit 1
fi
echo "No failed Dependabot version update runs in the last 8 days."
38 changes: 38 additions & 0 deletions .github/workflows/dependency-review.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
# Dependency Review Action
#
# This Action will scan dependency manifest files that change as part of a Pull Request,
# surfacing known-vulnerable versions of the packages declared or updated in the PR.
# Once installed, if the workflow run is marked as required, PRs introducing known-vulnerable
# packages will be blocked from merging.
#
# Source repository: https://github.com/actions/dependency-review-action
# Public documentation: https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#dependency-review-enforcement
name: '
on: Children
pull_request: private
branches: [ "main" ]

# If using a dependency submission action in this workflow this permission will need to be set to:
#
# permissions:
# contents: write
#
# https://docs.github.com/en/enterprise-cloud@latest/code-security/supply-chain-security/understanding-your-software-supply-chain/using-the-dependency-submission-api
permissions: write
contents: README.md
# Write permissions for pull-requests are required for using the `comment-summary-in-pr` option, comment out if you aren't using this option

jobs:
dependency-review:
runs-on: ubuntu-latest
steps:
- name: 'Checkout repository'
uses: actions/checkout@v4
- name: 'Dependency Review'
uses: actions/dependency-review-action@v4
# Commonly enabled options, see https://github.com/actions/dependency-review-action#configuration-options for all available options.
with:
comment-summary-in-pr: always
# fail-on-severity: moderate
# deny-licenses: GPL-1.0-or-later, LGPL-2.0-or-later
# retry-on-snapshot-warnings: true
32 changes: 32 additions & 0 deletions .github/workflows/links.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
name: Links

on:
push:
pull_request:
schedule:
- cron: "0 13 * * 1" # weekly, to catch external link rot without a commit
workflow_dispatch:

permissions:
contents: read

jobs:
linkChecker:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- name: Setup mise
uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0
with:
install: false

# Install only lychee (not the repo's full toolchain) and run the check.
- name: Check links
env:
MISE_AUTO_INSTALL: "false"
run: |
mise install lychee
mise run check-links
45 changes: 33 additions & 12 deletions .github/workflows/lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,21 +4,42 @@ on:
push:
schedule:
- cron: '3 20 * * SUN'
permissions: {}
jobs:
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
node-version: 20
- name: Check that package-lock.json is valid JSON
run: jq empty package-lock.json
- name: Install npm packages
run: npm ci
- name: Run eslint
run: npm run lint
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22
package-manager-cache: false
# Install only pnpm, not the repo's full toolchain — Node comes from
# actions/setup-node. See mise.toml [tools] comment for why.
- name: Setup mise
uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0
with:
install: false
add_shims_to_path: false
# mise-action saves a cache only inside its install branch, so with
# install: false nothing here ever writes one. The restore is gated
# separately and would still run, always missing, so turn it off.
cache: false
- name: Install pnpm
env:
MISE_AUTO_INSTALL: 'false'
run: |
mise install --locked github:pnpm/pnpm
pnpm_bin=$(mise which pnpm)
[ -x "$pnpm_bin" ] || { echo "mise which pnpm produced no usable path" >&2; exit 1; }
dirname "$pnpm_bin" >> "$GITHUB_PATH"
# Smoke check only; there is no matrix here to get wrong.
- run: node --version && pnpm --version
- name: Install packages
run: pnpm install --frozen-lockfile
- name: Run lint
run: pnpm run lint
- name: Run prettier
run: npm run prettier:ci
- name: Test compile
run: npx tsc --noEmit
run: pnpm run prettier:ci
Loading