Repository navigation
Upcoming Release Changes - #3505
Merged
Merged
Conversation
github-actions
Bot
force-pushed
the
changeset-release/master
branch
8 times, most recently
from
August 17, 2026 06:56
6a55ed9 to
3329bcc
Compare
github-actions
Bot
force-pushed
the
changeset-release/master
branch
6 times, most recently
from
August 24, 2026 07:02
3d823b8 to
a0c31ef
Compare
github-actions
Bot
force-pushed
the
changeset-release/master
branch
6 times, most recently
from
September 1, 2026 01:37
4ad202e to
b8a93c0
Compare
github-actions
Bot
force-pushed
the
changeset-release/master
branch
9 times, most recently
from
September 4, 2026 09:48
1e7a0a7 to
c4e9fe1
Compare
github-actions
Bot
force-pushed
the
changeset-release/master
branch
4 times, most recently
from
September 10, 2026 15:24
034c73a to
87ac4ee
Compare
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
github-actions
Bot
force-pushed
the
changeset-release/master
branch
14 times, most recently
from
September 14, 2026 23:35
520c327 to
e0366a5
Compare
github-actions
Bot
force-pushed
the
changeset-release/master
branch
9 times, most recently
from
September 17, 2026 21:40
aa30c23 to
26ea70e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to master, this PR will be updated.
Releases
@whatwg-node/promise-helpers@2.0.0
Major Changes
#3561
52a5bf6Thanks @ardatan! - Drop support for Node.js 18
and 20. The minimum supported Node.js version is now 22.15.
Why
Node.js 18 and 20 are end-of-life and no longer receive security updates.
Keeping them in our support matrix forced version-specific workarounds and
slowed adoption of newer Node TLS APIs.
The floor is set to 22.15 (not just 22.0) so we can rely on
tls.getCACertificates()(Node.js 22.15 / 23.10) and always-onzlibzstdhelpers (
createZstdCompress/createZstdDecompress, Node.js 22.15 / 23.8).That matches the oldest currently supported LTS line (22 Maintenance) while
dropping only EOL majors.
SemVer
major is 0).
@whatwg-node/promise-helpers,@whatwg-node/server-plugin-cookies): major bump, since droppingsupported Node versions is a breaking engines change for SemVer
>=1.0.0consumers.
What changed
engines.node: all published packages now declare>=22.15.0(including
@whatwg-node/promise-helpers, which was still on>=16).@whatwg-node/events: removed. NativeCustomEvent/Event/EventTargetare available on Node.js 22+, so the ponyfill is no longermaintained; use the platform globals.
@whatwg-node/fetch: dropped therequire("crypto").webcryptofallback;
cryptois alwaysglobalThis.cryptoon supported runtimes.@whatwg-node/server: removed the Node 18setHeadersworkaround(
isNode1x);ServerResponse#setHeadersis used whenever it exists.@whatwg-node/node-fetch: Runtime guards forzlib.createZstdCompress/
createZstdDecompressare removed;zstdis always included inAccept-Encoding.[22, 24, 26]; AWS Lambda runtime and AzureFunction target moved from Node 20 to Node 22.
If you are still on Node 18 or 20, upgrade to Node.js 22.15+ (or 24 / 26)
before installing this release.
#3565
ba977d4Thanks @ardatan! - Breaking Change: Remove
deprecated
mapMaybePromisein favor ofhandleMaybePromise.mapMaybePromise(input, onSuccess, onError?)is gone. UsehandleMaybePromise, which takes an input factory (thunk) instead of abare value so sync throws are handled the same way as promise rejections.
Before:
After:
handleMaybePromisealso accepts an optional fourthfinallyFactoryargumentif you need cleanup.
@whatwg-node/server-plugin-cookies@2.0.0
Major Changes
#3561
52a5bf6Thanks @ardatan! - Drop support for Node.js 18
and 20. The minimum supported Node.js version is now 22.15.
Why
Node.js 18 and 20 are end-of-life and no longer receive security updates.
Keeping them in our support matrix forced version-specific workarounds and
slowed adoption of newer Node TLS APIs.
The floor is set to 22.15 (not just 22.0) so we can rely on
tls.getCACertificates()(Node.js 22.15 / 23.10) and always-onzlibzstdhelpers (
createZstdCompress/createZstdDecompress, Node.js 22.15 / 23.8).That matches the oldest currently supported LTS line (22 Maintenance) while
dropping only EOL majors.
SemVer
major is 0).
@whatwg-node/promise-helpers,@whatwg-node/server-plugin-cookies): major bump, since droppingsupported Node versions is a breaking engines change for SemVer
>=1.0.0consumers.
What changed
engines.node: all published packages now declare>=22.15.0(including
@whatwg-node/promise-helpers, which was still on>=16).@whatwg-node/events: removed. NativeCustomEvent/Event/EventTargetare available on Node.js 22+, so the ponyfill is no longermaintained; use the platform globals.
@whatwg-node/fetch: dropped therequire("crypto").webcryptofallback;
cryptois alwaysglobalThis.cryptoon supported runtimes.@whatwg-node/server: removed the Node 18setHeadersworkaround(
isNode1x);ServerResponse#setHeadersis used whenever it exists.@whatwg-node/node-fetch: Runtime guards forzlib.createZstdCompress/
createZstdDecompressare removed;zstdis always included inAccept-Encoding.[22, 24, 26]; AWS Lambda runtime and AzureFunction target moved from Node 20 to Node 22.
If you are still on Node 18 or 20, upgrade to Node.js 22.15+ (or 24 / 26)
before installing this release.
Patch Changes
[
205d949,ebb2ab6,52a5bf6,36ef02b,3e55abc,d3b2c17,b4c83ab,72dad02]:@whatwg-node/cookie-store@0.3.0
Minor Changes
#3561
52a5bf6Thanks @ardatan! - Drop support for Node.js 18
and 20. The minimum supported Node.js version is now 22.15.
Why
Node.js 18 and 20 are end-of-life and no longer receive security updates.
Keeping them in our support matrix forced version-specific workarounds and
slowed adoption of newer Node TLS APIs.
The floor is set to 22.15 (not just 22.0) so we can rely on
tls.getCACertificates()(Node.js 22.15 / 23.10) and always-onzlibzstdhelpers (
createZstdCompress/createZstdDecompress, Node.js 22.15 / 23.8).That matches the oldest currently supported LTS line (22 Maintenance) while
dropping only EOL majors.
SemVer
major is 0).
@whatwg-node/promise-helpers,@whatwg-node/server-plugin-cookies): major bump, since droppingsupported Node versions is a breaking engines change for SemVer
>=1.0.0consumers.
What changed
engines.node: all published packages now declare>=22.15.0(including
@whatwg-node/promise-helpers, which was still on>=16).@whatwg-node/events: removed. NativeCustomEvent/Event/EventTargetare available on Node.js 22+, so the ponyfill is no longermaintained; use the platform globals.
@whatwg-node/fetch: dropped therequire("crypto").webcryptofallback;
cryptois alwaysglobalThis.cryptoon supported runtimes.@whatwg-node/server: removed the Node 18setHeadersworkaround(
isNode1x);ServerResponse#setHeadersis used whenever it exists.@whatwg-node/node-fetch: Runtime guards forzlib.createZstdCompress/
createZstdDecompressare removed;zstdis always included inAccept-Encoding.[22, 24, 26]; AWS Lambda runtime and AzureFunction target moved from Node 20 to Node 22.
If you are still on Node 18 or 20, upgrade to Node.js 22.15+ (or 24 / 26)
before installing this release.
Patch Changes
[
52a5bf6,ba977d4]:@whatwg-node/disposablestack@0.1.0
Minor Changes
#3561
52a5bf6Thanks @ardatan! - Drop support for Node.js 18
and 20. The minimum supported Node.js version is now 22.15.
Why
Node.js 18 and 20 are end-of-life and no longer receive security updates.
Keeping them in our support matrix forced version-specific workarounds and
slowed adoption of newer Node TLS APIs.
The floor is set to 22.15 (not just 22.0) so we can rely on
tls.getCACertificates()(Node.js 22.15 / 23.10) and always-onzlibzstdhelpers (
createZstdCompress/createZstdDecompress, Node.js 22.15 / 23.8).That matches the oldest currently supported LTS line (22 Maintenance) while
dropping only EOL majors.
SemVer
major is 0).
@whatwg-node/promise-helpers,@whatwg-node/server-plugin-cookies): major bump, since droppingsupported Node versions is a breaking engines change for SemVer
>=1.0.0consumers.
What changed
engines.node: all published packages now declare>=22.15.0(including
@whatwg-node/promise-helpers, which was still on>=16).@whatwg-node/events: removed. NativeCustomEvent/Event/EventTargetare available on Node.js 22+, so the ponyfill is no longermaintained; use the platform globals.
@whatwg-node/fetch: dropped therequire("crypto").webcryptofallback;
cryptois alwaysglobalThis.cryptoon supported runtimes.@whatwg-node/server: removed the Node 18setHeadersworkaround(
isNode1x);ServerResponse#setHeadersis used whenever it exists.@whatwg-node/node-fetch: Runtime guards forzlib.createZstdCompress/
createZstdDecompressare removed;zstdis always included inAccept-Encoding.[22, 24, 26]; AWS Lambda runtime and AzureFunction target moved from Node 20 to Node 22.
If you are still on Node 18 or 20, upgrade to Node.js 22.15+ (or 24 / 26)
before installing this release.
Patch Changes
[
52a5bf6,ba977d4]:@whatwg-node/fetch@0.11.0
Minor Changes
#3561
52a5bf6Thanks @ardatan! - Drop support for Node.js 18
and 20. The minimum supported Node.js version is now 22.15.
Why
Node.js 18 and 20 are end-of-life and no longer receive security updates.
Keeping them in our support matrix forced version-specific workarounds and
slowed adoption of newer Node TLS APIs.
The floor is set to 22.15 (not just 22.0) so we can rely on
tls.getCACertificates()(Node.js 22.15 / 23.10) and always-onzlibzstdhelpers (
createZstdCompress/createZstdDecompress, Node.js 22.15 / 23.8).That matches the oldest currently supported LTS line (22 Maintenance) while
dropping only EOL majors.
SemVer
major is 0).
@whatwg-node/promise-helpers,@whatwg-node/server-plugin-cookies): major bump, since droppingsupported Node versions is a breaking engines change for SemVer
>=1.0.0consumers.
What changed
engines.node: all published packages now declare>=22.15.0(including
@whatwg-node/promise-helpers, which was still on>=16).@whatwg-node/events: removed. NativeCustomEvent/Event/EventTargetare available on Node.js 22+, so the ponyfill is no longermaintained; use the platform globals.
@whatwg-node/fetch: dropped therequire("crypto").webcryptofallback;
cryptois alwaysglobalThis.cryptoon supported runtimes.@whatwg-node/server: removed the Node 18setHeadersworkaround(
isNode1x);ServerResponse#setHeadersis used whenever it exists.@whatwg-node/node-fetch: Runtime guards forzlib.createZstdCompress/
createZstdDecompressare removed;zstdis always included inAccept-Encoding.[22, 24, 26]; AWS Lambda runtime and AzureFunction target moved from Node 20 to Node 22.
If you are still on Node 18 or 20, upgrade to Node.js 22.15+ (or 24 / 26)
before installing this release.
#3604
b726b83Thanks @ardatan! - Drop the optional
node-libcurldependency.The ponyfill HTTP transport now always uses
node:http/node:https. ThefetchCurlcode path and theglobalThis.libcurlruntime check have beenremoved.
HTTP/2 support that previously came from
node-libcurlis no longer availablein this release; a follow-up adds optional undici-based transport (including
HTTP/2).
If you were relying on
node-libcurlbeing picked up automatically, theponyfill will now use the built-in Node.js HTTP stack instead.
Patch Changes
[
52a5bf6,b726b83,b4c83ab,f16ad4a,3f44041,3e55abc]:fetchache@0.2.0
Minor Changes
#3561
52a5bf6Thanks @ardatan! - Drop support for Node.js 18
and 20. The minimum supported Node.js version is now 22.15.
Why
Node.js 18 and 20 are end-of-life and no longer receive security updates.
Keeping them in our support matrix forced version-specific workarounds and
slowed adoption of newer Node TLS APIs.
The floor is set to 22.15 (not just 22.0) so we can rely on
tls.getCACertificates()(Node.js 22.15 / 23.10) and always-onzlibzstdhelpers (
createZstdCompress/createZstdDecompress, Node.js 22.15 / 23.8).That matches the oldest currently supported LTS line (22 Maintenance) while
dropping only EOL majors.
SemVer
major is 0).
@whatwg-node/promise-helpers,@whatwg-node/server-plugin-cookies): major bump, since droppingsupported Node versions is a breaking engines change for SemVer
>=1.0.0consumers.
What changed
engines.node: all published packages now declare>=22.15.0(including
@whatwg-node/promise-helpers, which was still on>=16).@whatwg-node/events: removed. NativeCustomEvent/Event/EventTargetare available on Node.js 22+, so the ponyfill is no longermaintained; use the platform globals.
@whatwg-node/fetch: dropped therequire("crypto").webcryptofallback;
cryptois alwaysglobalThis.cryptoon supported runtimes.@whatwg-node/server: removed the Node 18setHeadersworkaround(
isNode1x);ServerResponse#setHeadersis used whenever it exists.@whatwg-node/node-fetch: Runtime guards forzlib.createZstdCompress/
createZstdDecompressare removed;zstdis always included inAccept-Encoding.[22, 24, 26]; AWS Lambda runtime and AzureFunction target moved from Node 20 to Node 22.
If you are still on Node 18 or 20, upgrade to Node.js 22.15+ (or 24 / 26)
before installing this release.
@whatwg-node/node-fetch@0.9.0
Minor Changes
#3561
52a5bf6Thanks @ardatan! - Drop support for Node.js 18
and 20. The minimum supported Node.js version is now 22.15.
Why
Node.js 18 and 20 are end-of-life and no longer receive security updates.
Keeping them in our support matrix forced version-specific workarounds and
slowed adoption of newer Node TLS APIs.
The floor is set to 22.15 (not just 22.0) so we can rely on
tls.getCACertificates()(Node.js 22.15 / 23.10) and always-onzlibzstdhelpers (
createZstdCompress/createZstdDecompress, Node.js 22.15 / 23.8).That matches the oldest currently supported LTS line (22 Maintenance) while
dropping only EOL majors.
SemVer
major is 0).
@whatwg-node/promise-helpers,@whatwg-node/server-plugin-cookies): major bump, since droppingsupported Node versions is a breaking engines change for SemVer
>=1.0.0consumers.
What changed
engines.node: all published packages now declare>=22.15.0(including
@whatwg-node/promise-helpers, which was still on>=16).@whatwg-node/events: removed. NativeCustomEvent/Event/EventTargetare available on Node.js 22+, so the ponyfill is no longermaintained; use the platform globals.
@whatwg-node/fetch: dropped therequire("crypto").webcryptofallback;
cryptois alwaysglobalThis.cryptoon supported runtimes.@whatwg-node/server: removed the Node 18setHeadersworkaround(
isNode1x);ServerResponse#setHeadersis used whenever it exists.@whatwg-node/node-fetch: Runtime guards forzlib.createZstdCompress/
createZstdDecompressare removed;zstdis always included inAccept-Encoding.[22, 24, 26]; AWS Lambda runtime and AzureFunction target moved from Node 20 to Node 22.
If you are still on Node 18 or 20, upgrade to Node.js 22.15+ (or 24 / 26)
before installing this release.
#3604
b726b83Thanks @ardatan! - Drop the optional
node-libcurldependency.The ponyfill HTTP transport now always uses
node:http/node:https. ThefetchCurlcode path and theglobalThis.libcurlruntime check have beenremoved.
HTTP/2 support that previously came from
node-libcurlis no longer availablein this release; a follow-up adds optional undici-based transport (including
HTTP/2).
If you were relying on
node-libcurlbeing picked up automatically, theponyfill will now use the built-in Node.js HTTP stack instead.
Patch Changes
#3504
b4c83abThanks @ardatan! - Fix HTTPS verification for
IPv6 address literals in the node-http ponyfill.
Work around a Node.js regression (
tls.checkServerIdentity+domainToASCII)that rejects valid
IP AddressSANs for hosts like::1on Node.js 22.23+ /24.17+ (TLS verification fails for IPv6 IP subjectAltName in v22.23.0 and v24.17.0 nodejs/node#64032).
The override is installed lazily on the first HTTPS request, and only when a
one-time probe shows the running Node build is affected; healthy Node versions
keep the built-in verifier.
#3612
f16ad4aThanks @ardatan! - Avoid
stream/promises.pipelineinReadableStream.pipeTo/pipeThrough. Thepromise pipeline allocates and aborts an
AbortControlleron teardown(expensive
DOMExceptionstack capture), which dominated cost for shortTransformStream pipes such as request body size limiting. Use Node
.pipe()with explicit error/finish handling instead, while still rejecting when the
destination write fails.
#3569
3f44041Thanks @ardatan! - Make
ReadableStream.cancel(reason)resolve successfully instead of rejecting whenwaiting for close after destroy.
#3012
3e55abcThanks @gmaclennan! - Destroy the Node
response when the response body stream errors or is aborted, and propagate
Readable.destroy(err)in the node-fetch stream ponyfill so piped socketsclose with RST / ECONNRESET instead of hanging.
Also make ponyfill
ReadableStream.pipeTo()reject when the destination writefails (after aborting the writer), instead of resolving successfully.
Updated dependencies
[
52a5bf6,ba977d4]:@whatwg-node/server@0.12.0
Minor Changes
#3561
52a5bf6Thanks @ardatan! - Drop support for Node.js 18
and 20. The minimum supported Node.js version is now 22.15.
Why
Node.js 18 and 20 are end-of-life and no longer receive security updates.
Keeping them in our support matrix forced version-specific workarounds and
slowed adoption of newer Node TLS APIs.
The floor is set to 22.15 (not just 22.0) so we can rely on
tls.getCACertificates()(Node.js 22.15 / 23.10) and always-onzlibzstdhelpers (
createZstdCompress/createZstdDecompress, Node.js 22.15 / 23.8).That matches the oldest currently supported LTS line (22 Maintenance) while
dropping only EOL majors.
SemVer
major is 0).
@whatwg-node/promise-helpers,@whatwg-node/server-plugin-cookies): major bump, since droppingsupported Node versions is a breaking engines change for SemVer
>=1.0.0consumers.
What changed
engines.node: all published packages now declare>=22.15.0(including
@whatwg-node/promise-helpers, which was still on>=16).@whatwg-node/events: removed. NativeCustomEvent/Event/EventTargetare available on Node.js 22+, so the ponyfill is no longermaintained; use the platform globals.
@whatwg-node/fetch: dropped therequire("crypto").webcryptofallback;
cryptois alwaysglobalThis.cryptoon supported runtimes.@whatwg-node/server: removed the Node 18setHeadersworkaround(
isNode1x);ServerResponse#setHeadersis used whenever it exists.@whatwg-node/node-fetch: Runtime guards forzlib.createZstdCompress/
createZstdDecompressare removed;zstdis always included inAccept-Encoding.[22, 24, 26]; AWS Lambda runtime and AzureFunction target moved from Node 20 to Node 22.
If you are still on Node 18 or 20, upgrade to Node.js 22.15+ (or 24 / 26)
before installing this release.
#1505
36ef02bThanks @EmrysMyrddin! - Breaking
Change: Remove deprecated
handleNodeRequestin favor ofhandleNodeRequestAndResponse.adapter.handleNodeRequest(nodeRequest, ...ctx)is gone. PreferhandleNodeRequestAndResponse, which also receives the Node response sorequest normalization (abort wiring, etc.) can use it.
Before:
After:
Notes:
ServerResponse/Http2ServerResponse(or a container with{ raw: res }) as the second argument.Responseand does not write it tores. Useadapter(req, res),adapter.requestListener, oradapter.handle(req, res)when you want the adapter to send the response.#3610
72dad02Thanks @ardatan! - Add
useLimitRequestBodySizeto reject oversized request bodies early via
Content-Length, and whilestreaming with a byte-counting
TransformStream(so a short or missingContent-Lengthcannot bypass the limit).Optional
responseFromErrorcustomizes the early-rejectResponse(e.g.GraphQL error JSON in Yoga).
If you also use
useContentEncoding, put it beforeuseLimitRequestBodySizein the
pluginsarray so the limit applies to decoded body bytes.Patch Changes
#3568
205d949Thanks @ardatan! - Omit
Access-Control-Allow-Originwhen the requestOriginis not in theallowlist, instead of sending the string
null.Returning
Access-Control-Allow-Origin: nullis discouraged (MDN / W3C CORSfor developers): the browser should simply not see an ACAO header and enforce
the Same-Origin Policy.
Browser coverage for this CORS behavior and for
@whatwg-node/server-plugin-cookiesis covered by Puppeteer tests(
npm run test:browser).#3611
ebb2ab6Thanks @ardatan! - Discard unread Node/uWS
request bodies when responding (e.g. early
endResponse), so keep-aliveconnections are not stalled and large rejected uploads are not buffered for
the lifetime of the response.
#3012
3e55abcThanks @gmaclennan! - Destroy the Node
response when the response body stream errors or is aborted, and propagate
Readable.destroy(err)in the node-fetch stream ponyfill so piped socketsclose with RST / ECONNRESET instead of hanging.
Also make ponyfill
ReadableStream.pipeTo()reject when the destination writefails (after aborting the writer), instead of resolving successfully.
#3590
d3b2c17Thanks @ardatan! - Fix native
Requesthandlingin the server adapter and pass the active fetch implementation to the request
handler and plugins.
When a request originated from the runtime's native
Requestimplementation,the server adapter could still use the ponyfill/default Fetch API during later
pipeline stages. That could lead to mismatched
Request/Responseconstructors and inconsistent behavior across runtimes such as Node, Bun, and
Deno. For example in Next.js, the incoming request object is the native
Request while the returning
Responseobject is ponyfilled which causes anerror since Next.js expects it to be a native
Responseobject. As aworkaround, you had to provide
fetchAPI: { Response }on your own. With thispatch, this workaround is no longer needed.
Requestinstances are now detected correctly and routed through thematching runtime fetch API.
Request,Response, andstream constructors for the active runtime.
useErrorHandling()now passes the resolvedfetchAPIinto custom errorhandlers so they can construct responses with the correct runtime
primitives.
fetchAPIas a third argument, so that you don'tneed to worry about which fetch implementation to take.
This keeps adapter behavior consistent and avoids subtle incompatibilities
when handling native requests or custom fetch implementations.
It also avoids issues like this in GraphQL Yoga ->
5.24.0: request body size limit breaks
yoga.fetch()with a native Request on Node (ponyfill TransformStream piped into native body) graphql-hive/graphql-yoga#4583 So that theTransformStreamimplementation given byfetchAPIwill be compatible withthe given
requestinstance automatically.#3504
b4c83abThanks @ardatan! - Trim values when parsing
Accept-Encoding/Content-Encodingheader lists.Native HTTPS clients (e.g. undici) send values like
br, gzip, deflate;without trimming, encodings after the first comma never matched and response
compression was skipped.
Updated dependencies
[
52a5bf6,b726b83,ba977d4]: