chore(deps): update dependency @whatwg-node/fetch to v0.12.1 - #1637
Merged
Merged
Conversation
|
renovate
Bot
force-pushed
the
renovate/whatwg-node
branch
from
October 1, 2026 03:50
3e73ff0 to
f92a64b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.12.0→0.12.1Release Notes
ardatan/whatwg-node (@whatwg-node/fetch)
v0.12.1Compare Source
Patch Changes
#3642
ed29dc2Thanks @ardatan! - Follow the Fetch standard
when the Node HTTP transport follows redirects.
fetchNodeHttprecursed on every 3xxLocationwhileredirectwas'follow'(the default) and never counted hops. A response that alwaysredirects could keep one
fetchcall issuing requests until the process ranout of memory. Following now stops after 20 redirects. The promise rejects
with
TypeError: Fetch failed: Maximum number of redirects (20) reachedandcodeTooManyRedirects. A chain of 20 redirects that then returns a normalresponse still completes.
That path also reused the previous request's
Headersobject for the nexthop. A cross-origin
Locationtherefore receivedAuthorization,Proxy-Authorization,Cookie,Cookie2, and an explicitHost. Thoseheaders are removed when the origin changes. The scheme is part of the origin,
so an
httpstohttpredirect drops them too. Same-origin redirects stillsend them. Removal happens on a new header list, so the caller's own
Headersobject is left unchanged.
301and302responses toPOST, and303responses to any method otherthan
GETorHEAD, are resent asGETwith no body. The request-bodyheaders go with the body:
Content-Encoding,Content-Language,Content-Location,Content-Type, andContent-Length.307and308keepthe method and body when that body can be sent again. A one-shot stream
cannot, and that redirect rejects.
A cross-origin redirect whose URL includes a username or password is rejected
with
TypeErrorwhen the request mode iscors. Following it would sendthose URL credentials to the new origin as
Authorization.A resent
FormDatabody is encoded again with a new multipart boundary of thesame length, so its
Content-Lengthstays valid.Content-Typeis replacedbecause that header names the boundary.
redirect: 'error'rejects with aTypeError. A redirect whose target schemeis not
httporhttpsalso rejects with aTypeError.redirect: 'manual'still returns the redirect response.
Response.redirect()serializes an absolute URL into theLocationheaderand throws
TypeErrorwhen that URL cannot be parsed. A relative URL isstored as given, so
Response.redirect('/')setsLocationto/. Thestatus must be
301,302,303,307, or308; any other status throwsRangeError. The response status text is empty.@whatwg-node/fetchuses this transport on Node, so the same limits applythere.
Updated dependencies
[
ed29dc2]:Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.