Update dependency @fedify/cli to v1.8.13 #1379
Open
+5
−5
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.7.8
->1.8.13
Release Notes
fedify-dev/fedify (@fedify/cli)
v1.8.13
Compare Source
Released on October 10, 2025.
@fedify/fedify
special characters. Updated uri-template-router to version 1.0.0,
which properly decodes percent-encoded characters in URI template variables
according to RFC 6570. This resolves issues where identifiers containing
URIs (e.g.,
https%3A%2F%2Fexample.com
) were being inconsistently decodedin dispatcher callbacks and double-encoded in collection URLs. [#416]
v1.8.12
Compare Source
Released on September 20, 2025.
@fedify/sqlite
included in the bundled output. The @js-temporal/polyfill dependency
was moved from
devDependencies
todependencies
to ensure properbundling.
v1.8.11
Compare Source
Released on September 17, 2025.
edge cases. The fix now properly percent-encodes any authority component
in
at://
URIs, supportingdid:web
,did:key
, and other DID methodsbeyond just
did:plc
. Also handles URIs without path componentscorrectly. [[#436]]
v1.8.10
Compare Source
Released on September 17, 2025.
@fedify/fedify
URIs like
at://did:plc:...
that violate RFC 3986 URI syntax are nowautomatically URL-encoded to
at://did%3Aplc%3A...
to prevent parsingfailures when processing bridged Bluesky content. [[#436]]
v1.8.9
Compare Source
Released on September 10, 2025.
@fedify/express, @fedify/h3, @fedify/nestjs, @fedify/postgres,
@fedify/redis, @fedify/sqlite, @fedify/testing) now specify explicit
version ranges for the @fedify/fedify peer dependency instead of
accepting any version, improving compatibility guarantees.
v1.8.8
Compare Source
Released on August 25, 2025.
@fedify/fedify
verifyRequest()
function threw aTypeError
whenverifying HTTP Signatures with
created
orexpires
fields inthe
Signature
header as defined in draft-cavage-http-signatures-12,causing
500 Internal Server Error
responses in inbox handlers.Now it correctly handles these fields as unquoted integers according
to the specification.
v1.8.7
Compare Source
Released on August 25, 2025.
@fedify/fedify
self-closing
<link>
tags. The HTML/XHTML parser now correctly handleswhitespace before the self-closing slash (
/>
), improving compatibilitywith XHTML documents that follow the self-closing tag format.
v1.8.6
Compare Source
Released on August 24, 2025.
@fedify/nestjs
ActivityPub requests in NestJS applications. The middleware now correctly
handles request bodies that have been pre-processed by other NestJS
middleware or interceptors. [#279, #386 by Jaeyeol Lee]
@fedify/testing
Updated exports to include context creation functions.
[#382 by Colin Mitchell]
createContext()
function.createInboxContext()
function.createRequestContext()
function.v1.8.5
Compare Source
Released on August 8, 2025.
@fedify/fedify
that allowed unauthenticated attackers to impersonate any ActivityPub actor.
The vulnerability occurred because activities were processed before
verifying that the HTTP Signatures key belonged to the claimed actor.
Now authentication verification is performed before activity processing to
prevent actor impersonation attacks. [[CVE-2025-54888]]
@fedify/cli
fedify nodeinfo
color support in Windows Terminal.[#358, #360 by KeunHyeong Park]
v1.8.4
Compare Source
Released on August 7, 2025.
@fedify/cli
fedify lookup
command's-r
/--raw
,-C
/--compact
, and-e
/--expand
options to properly output valid JSON format instead ofDeno's object inspection format. [#357]
v1.8.3
Compare Source
Released on August 6, 2025.
@fedify/cli
Restored image resizing functionality in
fedify lookup
command by usingthe existing Jimp library for image manipulation. This properly displays
icon
andimage
fields with appropriate sizing in terminals.Added support for Ghostty terminal emulator for image rendering in
fedify lookup
command.v1.8.2
Compare Source
Released on August 6, 2025.
@fedify/cli
Fixed
npx @​fedify/cli
command not working on various platforms bycorrecting the binary path resolution in the Node.js wrapper script.
Temporarily removed Sharp dependency to resolve installation issues
across different platforms. As a result,
fedify lookup
command will nolonger resize images when displaying them in the terminal. This is a
temporary workaround and image resizing functionality will be restored
in a future patch version using an alternative approach.
Fixed build artifact paths in GitHub Actions workflow to correctly
reference CLI package location in the monorepo structure.
v1.8.1
Compare Source
Released on October 10, 2025.
@fedify/fedify
special characters. Updated uri-template-router to version 1.0.0,
which properly decodes percent-encoded characters in URI template variables
according to RFC 6570. This resolves issues where identifiers containing
URIs (e.g.,
https%3A%2F%2Fexample.com
) were being inconsistently decodedin dispatcher callbacks and double-encoded in collection URLs. [#416]
v1.7.13
Compare Source
Released on September 17, 2025.
edge cases. The fix now properly percent-encodes any authority component
in
at://
URIs, supportingdid:web
,did:key
, and other DID methodsbeyond just
did:plc
. Also handles URIs without path componentscorrectly. [[#436]]
v1.7.12
Compare Source
Released on September 17, 2025.
URIs like
at://did:plc:...
that violate RFC 3986 URI syntax are nowautomatically URL-encoded to
at://did%3Aplc%3A...
to prevent parsingfailures when processing bridged Bluesky content. [[#436]]
v1.7.11
Compare Source
Released on August 25, 2025.
verifyRequest()
function threw aTypeError
whenverifying HTTP Signatures with
created
orexpires
fields inthe
Signature
header as defined in draft-cavage-http-signatures-12,causing
500 Internal Server Error
responses in inbox handlers.Now it correctly handles these fields as unquoted integers according
to the specification.
v1.7.10
Compare Source
Released on August 25, 2025.
self-closing
<link>
tags. The HTML/XHTML parser now correctly handleswhitespace before the self-closing slash (
/>
), improving compatibilitywith XHTML documents that follow the self-closing tag format.
v1.7.9
Compare Source
Released on August 8, 2025.
that allowed unauthenticated attackers to impersonate any ActivityPub actor.
The vulnerability occurred because activities were processed before
verifying that the HTTP Signatures key belonged to the claimed actor.
Now authentication verification is performed before activity processing to
prevent actor impersonation attacks. [[CVE-2025-54888]]
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - Between 08:00 AM and 11:59 AM, only on Monday, Tuesday, Wednesday, and Thursday ( * 8-11 * * 1,2,3,4 ) (UTC).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.