Skip to content

Upcoming Release Changes - #3505

Merged
ardatan merged 1 commit into
masterfrom
changeset-release/master
Sep 21, 2026
Merged

ardatan merged 1 commit into
masterfrom
changeset-release/master

Conversation

@github-actions

@github-actions github-actions Bot commented Aug 12, 2026 •

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to master, this PR will be updated.

Releases

@whatwg-node/promise-helpers@2.0.0

Major Changes

  • #3561
    52a5bf6
    Thanks @ardatan! - Drop support for Node.js 18
    and 20. The minimum supported Node.js version is now 22.15.

    Why

    Node.js 18 and 20 are end-of-life and no longer receive security updates.
    Keeping them in our support matrix forced version-specific workarounds and
    slowed adoption of newer Node TLS APIs.

    The floor is set to 22.15 (not just 22.0) so we can rely on
    tls.getCACertificates() (Node.js 22.15 / 23.10) and always-on zlib zstd
    helpers (createZstdCompress / createZstdDecompress, Node.js 22.15 / 23.8).
    That matches the oldest currently supported LTS line (22 Maintenance) while
    dropping only EOL majors.

    SemVer

    • 0.x packages: minor bump (breaking changes are allowed in minors while
      major is 0).
    • 1.x packages (@whatwg-node/promise-helpers,
      @whatwg-node/server-plugin-cookies): major bump, since dropping
      supported Node versions is a breaking engines change for SemVer >=1.0.0
      consumers.

    What changed

    • engines.node: all published packages now declare >=22.15.0
      (including @whatwg-node/promise-helpers, which was still on >=16).
    • @whatwg-node/events: removed. Native CustomEvent / Event /
      EventTarget are available on Node.js 22+, so the ponyfill is no longer
      maintained; use the platform globals.
    • @whatwg-node/fetch: dropped the require("crypto").webcrypto
      fallback; crypto is always globalThis.crypto on supported runtimes.
    • @whatwg-node/server: removed the Node 18 setHeaders workaround
      (isNode1x); ServerResponse#setHeaders is used whenever it exists.
    • @whatwg-node/node-fetch: Runtime guards for zlib.createZstdCompress
      / createZstdDecompress are removed; zstd is always included in
      Accept-Encoding.
    • CI / e2e: unit matrix is [22, 24, 26]; AWS Lambda runtime and Azure
      Function target moved from Node 20 to Node 22.

    If you are still on Node 18 or 20, upgrade to Node.js 22.15+ (or 24 / 26)
    before installing this release.

  • #3565
    ba977d4
    Thanks @ardatan! - Breaking Change: Remove
    deprecated mapMaybePromise in favor of handleMaybePromise.

    mapMaybePromise(input, onSuccess, onError?) is gone. Use
    handleMaybePromise, which takes an input factory (thunk) instead of a
    bare value so sync throws are handled the same way as promise rejections.

    Before:

    import { mapMaybePromise } from "@whatwg-node/promise-helpers";
    
    const result = mapMaybePromise(
      maybeValue,
      (value) => transform(value),
      (err) => fallback(err),
    );

    After:

    import { handleMaybePromise } from "@whatwg-node/promise-helpers";
    
    const result = handleMaybePromise(
      () => maybeValue,
      (value) => transform(value),
      (err) => fallback(err),
    );

    handleMaybePromise also accepts an optional fourth finallyFactory argument
    if you need cleanup.

@whatwg-node/server-plugin-cookies@2.0.0

Major Changes

  • #3561
    52a5bf6
    Thanks @ardatan! - Drop support for Node.js 18
    and 20. The minimum supported Node.js version is now 22.15.

    Why

    Node.js 18 and 20 are end-of-life and no longer receive security updates.
    Keeping them in our support matrix forced version-specific workarounds and
    slowed adoption of newer Node TLS APIs.

    The floor is set to 22.15 (not just 22.0) so we can rely on
    tls.getCACertificates() (Node.js 22.15 / 23.10) and always-on zlib zstd
    helpers (createZstdCompress / createZstdDecompress, Node.js 22.15 / 23.8).
    That matches the oldest currently supported LTS line (22 Maintenance) while
    dropping only EOL majors.

    SemVer

    • 0.x packages: minor bump (breaking changes are allowed in minors while
      major is 0).
    • 1.x packages (@whatwg-node/promise-helpers,
      @whatwg-node/server-plugin-cookies): major bump, since dropping
      supported Node versions is a breaking engines change for SemVer >=1.0.0
      consumers.

    What changed

    • engines.node: all published packages now declare >=22.15.0
      (including @whatwg-node/promise-helpers, which was still on >=16).
    • @whatwg-node/events: removed. Native CustomEvent / Event /
      EventTarget are available on Node.js 22+, so the ponyfill is no longer
      maintained; use the platform globals.
    • @whatwg-node/fetch: dropped the require("crypto").webcrypto
      fallback; crypto is always globalThis.crypto on supported runtimes.
    • @whatwg-node/server: removed the Node 18 setHeaders workaround
      (isNode1x); ServerResponse#setHeaders is used whenever it exists.
    • @whatwg-node/node-fetch: Runtime guards for zlib.createZstdCompress
      / createZstdDecompress are removed; zstd is always included in
      Accept-Encoding.
    • CI / e2e: unit matrix is [22, 24, 26]; AWS Lambda runtime and Azure
      Function target moved from Node 20 to Node 22.

    If you are still on Node 18 or 20, upgrade to Node.js 22.15+ (or 24 / 26)
    before installing this release.

Patch Changes

@whatwg-node/cookie-store@0.3.0

Minor Changes

  • #3561
    52a5bf6
    Thanks @ardatan! - Drop support for Node.js 18
    and 20. The minimum supported Node.js version is now 22.15.

    Why

    Node.js 18 and 20 are end-of-life and no longer receive security updates.
    Keeping them in our support matrix forced version-specific workarounds and
    slowed adoption of newer Node TLS APIs.

    The floor is set to 22.15 (not just 22.0) so we can rely on
    tls.getCACertificates() (Node.js 22.15 / 23.10) and always-on zlib zstd
    helpers (createZstdCompress / createZstdDecompress, Node.js 22.15 / 23.8).
    That matches the oldest currently supported LTS line (22 Maintenance) while
    dropping only EOL majors.

    SemVer

    • 0.x packages: minor bump (breaking changes are allowed in minors while
      major is 0).
    • 1.x packages (@whatwg-node/promise-helpers,
      @whatwg-node/server-plugin-cookies): major bump, since dropping
      supported Node versions is a breaking engines change for SemVer >=1.0.0
      consumers.

    What changed

    • engines.node: all published packages now declare >=22.15.0
      (including @whatwg-node/promise-helpers, which was still on >=16).
    • @whatwg-node/events: removed. Native CustomEvent / Event /
      EventTarget are available on Node.js 22+, so the ponyfill is no longer
      maintained; use the platform globals.
    • @whatwg-node/fetch: dropped the require("crypto").webcrypto
      fallback; crypto is always globalThis.crypto on supported runtimes.
    • @whatwg-node/server: removed the Node 18 setHeaders workaround
      (isNode1x); ServerResponse#setHeaders is used whenever it exists.
    • @whatwg-node/node-fetch: Runtime guards for zlib.createZstdCompress
      / createZstdDecompress are removed; zstd is always included in
      Accept-Encoding.
    • CI / e2e: unit matrix is [22, 24, 26]; AWS Lambda runtime and Azure
      Function target moved from Node 20 to Node 22.

    If you are still on Node 18 or 20, upgrade to Node.js 22.15+ (or 24 / 26)
    before installing this release.

Patch Changes

  • Updated dependencies
    [52a5bf6,
    ba977d4]:
    • @whatwg-node/promise-helpers@2.0.0

@whatwg-node/disposablestack@0.1.0

Minor Changes

  • #3561
    52a5bf6
    Thanks @ardatan! - Drop support for Node.js 18
    and 20. The minimum supported Node.js version is now 22.15.

    Why

    Node.js 18 and 20 are end-of-life and no longer receive security updates.
    Keeping them in our support matrix forced version-specific workarounds and
    slowed adoption of newer Node TLS APIs.

    The floor is set to 22.15 (not just 22.0) so we can rely on
    tls.getCACertificates() (Node.js 22.15 / 23.10) and always-on zlib zstd
    helpers (createZstdCompress / createZstdDecompress, Node.js 22.15 / 23.8).
    That matches the oldest currently supported LTS line (22 Maintenance) while
    dropping only EOL majors.

    SemVer

    • 0.x packages: minor bump (breaking changes are allowed in minors while
      major is 0).
    • 1.x packages (@whatwg-node/promise-helpers,
      @whatwg-node/server-plugin-cookies): major bump, since dropping
      supported Node versions is a breaking engines change for SemVer >=1.0.0
      consumers.

    What changed

    • engines.node: all published packages now declare >=22.15.0
      (including @whatwg-node/promise-helpers, which was still on >=16).
    • @whatwg-node/events: removed. Native CustomEvent / Event /
      EventTarget are available on Node.js 22+, so the ponyfill is no longer
      maintained; use the platform globals.
    • @whatwg-node/fetch: dropped the require("crypto").webcrypto
      fallback; crypto is always globalThis.crypto on supported runtimes.
    • @whatwg-node/server: removed the Node 18 setHeaders workaround
      (isNode1x); ServerResponse#setHeaders is used whenever it exists.
    • @whatwg-node/node-fetch: Runtime guards for zlib.createZstdCompress
      / createZstdDecompress are removed; zstd is always included in
      Accept-Encoding.
    • CI / e2e: unit matrix is [22, 24, 26]; AWS Lambda runtime and Azure
      Function target moved from Node 20 to Node 22.

    If you are still on Node 18 or 20, upgrade to Node.js 22.15+ (or 24 / 26)
    before installing this release.

Patch Changes

  • Updated dependencies
    [52a5bf6,
    ba977d4]:
    • @whatwg-node/promise-helpers@2.0.0

@whatwg-node/fetch@0.11.0

Minor Changes

  • #3561
    52a5bf6
    Thanks @ardatan! - Drop support for Node.js 18
    and 20. The minimum supported Node.js version is now 22.15.

    Why

    Node.js 18 and 20 are end-of-life and no longer receive security updates.
    Keeping them in our support matrix forced version-specific workarounds and
    slowed adoption of newer Node TLS APIs.

    The floor is set to 22.15 (not just 22.0) so we can rely on
    tls.getCACertificates() (Node.js 22.15 / 23.10) and always-on zlib zstd
    helpers (createZstdCompress / createZstdDecompress, Node.js 22.15 / 23.8).
    That matches the oldest currently supported LTS line (22 Maintenance) while
    dropping only EOL majors.

    SemVer

    • 0.x packages: minor bump (breaking changes are allowed in minors while
      major is 0).
    • 1.x packages (@whatwg-node/promise-helpers,
      @whatwg-node/server-plugin-cookies): major bump, since dropping
      supported Node versions is a breaking engines change for SemVer >=1.0.0
      consumers.

    What changed

    • engines.node: all published packages now declare >=22.15.0
      (including @whatwg-node/promise-helpers, which was still on >=16).
    • @whatwg-node/events: removed. Native CustomEvent / Event /
      EventTarget are available on Node.js 22+, so the ponyfill is no longer
      maintained; use the platform globals.
    • @whatwg-node/fetch: dropped the require("crypto").webcrypto
      fallback; crypto is always globalThis.crypto on supported runtimes.
    • @whatwg-node/server: removed the Node 18 setHeaders workaround
      (isNode1x); ServerResponse#setHeaders is used whenever it exists.
    • @whatwg-node/node-fetch: Runtime guards for zlib.createZstdCompress
      / createZstdDecompress are removed; zstd is always included in
      Accept-Encoding.
    • CI / e2e: unit matrix is [22, 24, 26]; AWS Lambda runtime and Azure
      Function target moved from Node 20 to Node 22.

    If you are still on Node 18 or 20, upgrade to Node.js 22.15+ (or 24 / 26)
    before installing this release.

  • #3604
    b726b83
    Thanks @ardatan! - Drop the optional
    node-libcurl dependency.

    The ponyfill HTTP transport now always uses node:http / node:https. The
    fetchCurl code path and the globalThis.libcurl runtime check have been
    removed.

    HTTP/2 support that previously came from node-libcurl is no longer available
    in this release; a follow-up adds optional undici-based transport (including
    HTTP/2).

    If you were relying on node-libcurl being picked up automatically, the
    ponyfill will now use the built-in Node.js HTTP stack instead.

Patch Changes

fetchache@0.2.0

Minor Changes

  • #3561
    52a5bf6
    Thanks @ardatan! - Drop support for Node.js 18
    and 20. The minimum supported Node.js version is now 22.15.

    Why

    Node.js 18 and 20 are end-of-life and no longer receive security updates.
    Keeping them in our support matrix forced version-specific workarounds and
    slowed adoption of newer Node TLS APIs.

    The floor is set to 22.15 (not just 22.0) so we can rely on
    tls.getCACertificates() (Node.js 22.15 / 23.10) and always-on zlib zstd
    helpers (createZstdCompress / createZstdDecompress, Node.js 22.15 / 23.8).
    That matches the oldest currently supported LTS line (22 Maintenance) while
    dropping only EOL majors.

    SemVer

    • 0.x packages: minor bump (breaking changes are allowed in minors while
      major is 0).
    • 1.x packages (@whatwg-node/promise-helpers,
      @whatwg-node/server-plugin-cookies): major bump, since dropping
      supported Node versions is a breaking engines change for SemVer >=1.0.0
      consumers.

    What changed

    • engines.node: all published packages now declare >=22.15.0
      (including @whatwg-node/promise-helpers, which was still on >=16).
    • @whatwg-node/events: removed. Native CustomEvent / Event /
      EventTarget are available on Node.js 22+, so the ponyfill is no longer
      maintained; use the platform globals.
    • @whatwg-node/fetch: dropped the require("crypto").webcrypto
      fallback; crypto is always globalThis.crypto on supported runtimes.
    • @whatwg-node/server: removed the Node 18 setHeaders workaround
      (isNode1x); ServerResponse#setHeaders is used whenever it exists.
    • @whatwg-node/node-fetch: Runtime guards for zlib.createZstdCompress
      / createZstdDecompress are removed; zstd is always included in
      Accept-Encoding.
    • CI / e2e: unit matrix is [22, 24, 26]; AWS Lambda runtime and Azure
      Function target moved from Node 20 to Node 22.

    If you are still on Node 18 or 20, upgrade to Node.js 22.15+ (or 24 / 26)
    before installing this release.

@whatwg-node/node-fetch@0.9.0

Minor Changes

  • #3561
    52a5bf6
    Thanks @ardatan! - Drop support for Node.js 18
    and 20. The minimum supported Node.js version is now 22.15.

    Why

    Node.js 18 and 20 are end-of-life and no longer receive security updates.
    Keeping them in our support matrix forced version-specific workarounds and
    slowed adoption of newer Node TLS APIs.

    The floor is set to 22.15 (not just 22.0) so we can rely on
    tls.getCACertificates() (Node.js 22.15 / 23.10) and always-on zlib zstd
    helpers (createZstdCompress / createZstdDecompress, Node.js 22.15 / 23.8).
    That matches the oldest currently supported LTS line (22 Maintenance) while
    dropping only EOL majors.

    SemVer

    • 0.x packages: minor bump (breaking changes are allowed in minors while
      major is 0).
    • 1.x packages (@whatwg-node/promise-helpers,
      @whatwg-node/server-plugin-cookies): major bump, since dropping
      supported Node versions is a breaking engines change for SemVer >=1.0.0
      consumers.

    What changed

    • engines.node: all published packages now declare >=22.15.0
      (including @whatwg-node/promise-helpers, which was still on >=16).
    • @whatwg-node/events: removed. Native CustomEvent / Event /
      EventTarget are available on Node.js 22+, so the ponyfill is no longer
      maintained; use the platform globals.
    • @whatwg-node/fetch: dropped the require("crypto").webcrypto
      fallback; crypto is always globalThis.crypto on supported runtimes.
    • @whatwg-node/server: removed the Node 18 setHeaders workaround
      (isNode1x); ServerResponse#setHeaders is used whenever it exists.
    • @whatwg-node/node-fetch: Runtime guards for zlib.createZstdCompress
      / createZstdDecompress are removed; zstd is always included in
      Accept-Encoding.
    • CI / e2e: unit matrix is [22, 24, 26]; AWS Lambda runtime and Azure
      Function target moved from Node 20 to Node 22.

    If you are still on Node 18 or 20, upgrade to Node.js 22.15+ (or 24 / 26)
    before installing this release.

  • #3604
    b726b83
    Thanks @ardatan! - Drop the optional
    node-libcurl dependency.

    The ponyfill HTTP transport now always uses node:http / node:https. The
    fetchCurl code path and the globalThis.libcurl runtime check have been
    removed.

    HTTP/2 support that previously came from node-libcurl is no longer available
    in this release; a follow-up adds optional undici-based transport (including
    HTTP/2).

    If you were relying on node-libcurl being picked up automatically, the
    ponyfill will now use the built-in Node.js HTTP stack instead.

Patch Changes

  • #3504
    b4c83ab
    Thanks @ardatan! - Fix HTTPS verification for
    IPv6 address literals in the node-http ponyfill.

    Work around a Node.js regression (tls.checkServerIdentity + domainToASCII)
    that rejects valid IP Address SANs for hosts like ::1 on Node.js 22.23+ /
    24.17+ (TLS verification fails for IPv6 IP subjectAltName in v22.23.0 and v24.17.0 nodejs/node#64032).

    The override is installed lazily on the first HTTPS request, and only when a
    one-time probe shows the running Node build is affected; healthy Node versions
    keep the built-in verifier.

  • #3612
    f16ad4a
    Thanks @ardatan! - Avoid
    stream/promises.pipeline in ReadableStream.pipeTo / pipeThrough. The
    promise pipeline allocates and aborts an AbortController on teardown
    (expensive DOMException stack capture), which dominated cost for short
    TransformStream pipes such as request body size limiting. Use Node .pipe()
    with explicit error/finish handling instead, while still rejecting when the
    destination write fails.

  • #3569
    3f44041
    Thanks @ardatan! - Make
    ReadableStream.cancel(reason) resolve successfully instead of rejecting when
    waiting for close after destroy.

  • #3012
    3e55abc
    Thanks @gmaclennan! - Destroy the Node
    response when the response body stream errors or is aborted, and propagate
    Readable.destroy(err) in the node-fetch stream ponyfill so piped sockets
    close with RST / ECONNRESET instead of hanging.

    Also make ponyfill ReadableStream.pipeTo() reject when the destination write
    fails (after aborting the writer), instead of resolving successfully.

  • Updated dependencies
    [52a5bf6,
    ba977d4]:

    • @whatwg-node/disposablestack@0.1.0
    • @whatwg-node/promise-helpers@2.0.0

@whatwg-node/server@0.12.0

Minor Changes

  • #3561
    52a5bf6
    Thanks @ardatan! - Drop support for Node.js 18
    and 20. The minimum supported Node.js version is now 22.15.

    Why

    Node.js 18 and 20 are end-of-life and no longer receive security updates.
    Keeping them in our support matrix forced version-specific workarounds and
    slowed adoption of newer Node TLS APIs.

    The floor is set to 22.15 (not just 22.0) so we can rely on
    tls.getCACertificates() (Node.js 22.15 / 23.10) and always-on zlib zstd
    helpers (createZstdCompress / createZstdDecompress, Node.js 22.15 / 23.8).
    That matches the oldest currently supported LTS line (22 Maintenance) while
    dropping only EOL majors.

    SemVer

    • 0.x packages: minor bump (breaking changes are allowed in minors while
      major is 0).
    • 1.x packages (@whatwg-node/promise-helpers,
      @whatwg-node/server-plugin-cookies): major bump, since dropping
      supported Node versions is a breaking engines change for SemVer >=1.0.0
      consumers.

    What changed

    • engines.node: all published packages now declare >=22.15.0
      (including @whatwg-node/promise-helpers, which was still on >=16).
    • @whatwg-node/events: removed. Native CustomEvent / Event /
      EventTarget are available on Node.js 22+, so the ponyfill is no longer
      maintained; use the platform globals.
    • @whatwg-node/fetch: dropped the require("crypto").webcrypto
      fallback; crypto is always globalThis.crypto on supported runtimes.
    • @whatwg-node/server: removed the Node 18 setHeaders workaround
      (isNode1x); ServerResponse#setHeaders is used whenever it exists.
    • @whatwg-node/node-fetch: Runtime guards for zlib.createZstdCompress
      / createZstdDecompress are removed; zstd is always included in
      Accept-Encoding.
    • CI / e2e: unit matrix is [22, 24, 26]; AWS Lambda runtime and Azure
      Function target moved from Node 20 to Node 22.

    If you are still on Node 18 or 20, upgrade to Node.js 22.15+ (or 24 / 26)
    before installing this release.

  • #1505
    36ef02b
    Thanks @EmrysMyrddin! - Breaking
    Change:
    Remove deprecated handleNodeRequest in favor of
    handleNodeRequestAndResponse.

    adapter.handleNodeRequest(nodeRequest, ...ctx) is gone. Prefer
    handleNodeRequestAndResponse, which also receives the Node response so
    request normalization (abort wiring, etc.) can use it.

    Before:

    const response = await adapter.handleNodeRequest(req, { userId: "1" });

    After:

    const response = await adapter.handleNodeRequestAndResponse(req, res, {
      userId: "1",
    });

    Notes:

    • Pass the real ServerResponse / Http2ServerResponse (or a container with
      { raw: res }) as the second argument.
    • Like before, this returns a WHATWG Response and does not write it to
      res. Use adapter(req, res), adapter.requestListener, or
      adapter.handle(req, res) when you want the adapter to send the response.
  • #3610
    72dad02
    Thanks @ardatan! - Add useLimitRequestBodySize
    to reject oversized request bodies early via Content-Length, and while
    streaming with a byte-counting TransformStream (so a short or missing
    Content-Length cannot bypass the limit).

    Optional responseFromError customizes the early-reject Response (e.g.
    GraphQL error JSON in Yoga).

    If you also use useContentEncoding, put it before useLimitRequestBodySize
    in the plugins array so the limit applies to decoded body bytes.

Patch Changes

  • #3568
    205d949
    Thanks @ardatan! - Omit
    Access-Control-Allow-Origin when the request Origin is not in the
    allowlist, instead of sending the string null.

    Returning Access-Control-Allow-Origin: null is discouraged (MDN / W3C CORS
    for developers): the browser should simply not see an ACAO header and enforce
    the Same-Origin Policy.

    Browser coverage for this CORS behavior and for
    @whatwg-node/server-plugin-cookies is covered by Puppeteer tests
    (npm run test:browser).

  • #3611
    ebb2ab6
    Thanks @ardatan! - Discard unread Node/uWS
    request bodies when responding (e.g. early endResponse), so keep-alive
    connections are not stalled and large rejected uploads are not buffered for
    the lifetime of the response.

  • #3012
    3e55abc
    Thanks @gmaclennan! - Destroy the Node
    response when the response body stream errors or is aborted, and propagate
    Readable.destroy(err) in the node-fetch stream ponyfill so piped sockets
    close with RST / ECONNRESET instead of hanging.

    Also make ponyfill ReadableStream.pipeTo() reject when the destination write
    fails (after aborting the writer), instead of resolving successfully.

  • #3590
    d3b2c17
    Thanks @ardatan! - Fix native Request handling
    in the server adapter and pass the active fetch implementation to the request
    handler and plugins.

    When a request originated from the runtime's native Request implementation,
    the server adapter could still use the ponyfill/default Fetch API during later
    pipeline stages. That could lead to mismatched Request / Response
    constructors and inconsistent behavior across runtimes such as Node, Bun, and
    Deno. For example in Next.js, the incoming request object is the native
    Request while the returning Response object is ponyfilled which causes an
    error since Next.js expects it to be a native Response object. As a
    workaround, you had to provide fetchAPI: { Response } on your own. With this
    patch, this workaround is no longer needed.

    • Native Request instances are now detected correctly and routed through the
      matching runtime fetch API.
    • The request pipeline keeps using the correct Request, Response, and
      stream constructors for the active runtime.
    • useErrorHandling() now passes the resolved fetchAPI into custom error
      handlers so they can construct responses with the correct runtime
      primitives.
    • Request handlers now take fetchAPI as a third argument, so that you don't
      need to worry about which fetch implementation to take.
    createServerAdapter((request, context, fetchAPI) => fetchAPI.Response.json());

    This keeps adapter behavior consistent and avoids subtle incompatibilities
    when handling native requests or custom fetch implementations.

    It also avoids issues like this in GraphQL Yoga ->
    5.24.0: request body size limit breaks yoga.fetch() with a native Request on Node (ponyfill TransformStream piped into native body) graphql-hive/graphql-yoga#4583 So that the
    TransformStream implementation given by fetchAPI will be compatible with
    the given request instance automatically.

  • #3504
    b4c83ab
    Thanks @ardatan! - Trim values when parsing
    Accept-Encoding / Content-Encoding header lists.

    Native HTTPS clients (e.g. undici) send values like br, gzip, deflate;
    without trimming, encodings after the first comma never matched and response
    compression was skipped.

  • Updated dependencies
    [52a5bf6,
    b726b83,
    ba977d4]:

    • @whatwg-node/fetch@0.11.0
    • @whatwg-node/disposablestack@0.1.0
    • @whatwg-node/promise-helpers@2.0.0

@github-actions
github-actions Bot force-pushed the changeset-release/master branch 8 times, most recently from 6a55ed9 to 3329bcc Compare August 17, 2026 06:56
@github-actions
github-actions Bot force-pushed the changeset-release/master branch 6 times, most recently from 3d823b8 to a0c31ef Compare August 24, 2026 07:02
@github-actions
github-actions Bot force-pushed the changeset-release/master branch 6 times, most recently from 4ad202e to b8a93c0 Compare September 1, 2026 01:37
@github-actions
github-actions Bot force-pushed the changeset-release/master branch 9 times, most recently from 1e7a0a7 to c4e9fe1 Compare September 4, 2026 09:48
@github-actions
github-actions Bot force-pushed the changeset-release/master branch 4 times, most recently from 034c73a to 87ac4ee Compare September 10, 2026 15:24
@coderabbitai

coderabbitai Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 239b9e7e-3a69-41e1-9d55-d3c090dd982f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions
github-actions Bot force-pushed the changeset-release/master branch 14 times, most recently from 520c327 to e0366a5 Compare September 14, 2026 23:35
@github-actions
github-actions Bot force-pushed the changeset-release/master branch 9 times, most recently from aa30c23 to 26ea70e Compare September 17, 2026 21:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant