Skip to content

chore(deps): update dependency @whatwg-node/fetch to v0.12.1 - #1637

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/whatwg-node
Oct 4, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/whatwg-node

Conversation

@renovate

@renovate renovate Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@whatwg-node/fetch (source) 0.12.0 → 0.12.1 age confidence

Release Notes

ardatan/whatwg-node (@​whatwg-node/fetch)

v0.12.1

Compare Source

Patch Changes
  • #​3642
    ed29dc2
    Thanks @​ardatan! - Follow the Fetch standard
    when the Node HTTP transport follows redirects.

    fetchNodeHttp recursed on every 3xx Location while redirect was
    'follow' (the default) and never counted hops. A response that always
    redirects could keep one fetch call issuing requests until the process ran
    out of memory. Following now stops after 20 redirects. The promise rejects
    with TypeError: Fetch failed: Maximum number of redirects (20) reached and
    code TooManyRedirects. A chain of 20 redirects that then returns a normal
    response still completes.

    That path also reused the previous request's Headers object for the next
    hop. A cross-origin Location therefore received Authorization,
    Proxy-Authorization, Cookie, Cookie2, and an explicit Host. Those
    headers are removed when the origin changes. The scheme is part of the origin,
    so an https to http redirect drops them too. Same-origin redirects still
    send them. Removal happens on a new header list, so the caller's own Headers
    object is left unchanged.

    301 and 302 responses to POST, and 303 responses to any method other
    than GET or HEAD, are resent as GET with no body. The request-body
    headers go with the body: Content-Encoding, Content-Language,
    Content-Location, Content-Type, and Content-Length. 307 and 308 keep
    the method and body when that body can be sent again. A one-shot stream
    cannot, and that redirect rejects.

    A cross-origin redirect whose URL includes a username or password is rejected
    with TypeError when the request mode is cors. Following it would send
    those URL credentials to the new origin as Authorization.

    A resent FormData body is encoded again with a new multipart boundary of the
    same length, so its Content-Length stays valid. Content-Type is replaced
    because that header names the boundary.

    redirect: 'error' rejects with a TypeError. A redirect whose target scheme
    is not http or https also rejects with a TypeError. redirect: 'manual'
    still returns the redirect response.

    Response.redirect() serializes an absolute URL into the Location header
    and throws TypeError when that URL cannot be parsed. A relative URL is
    stored as given, so Response.redirect('/') sets Location to /. The
    status must be 301, 302, 303, 307, or 308; any other status throws
    RangeError. The response status text is empty.

    @whatwg-node/fetch uses this transport on Node, so the same limits apply
    there.

  • Updated dependencies
    [ed29dc2]:


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Oct 1, 2026
@changeset-bot

changeset-bot Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: f92a64b

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@renovate
renovate Bot force-pushed the renovate/whatwg-node branch from 3e73ff0 to f92a64b Compare October 1, 2026 03:50
@renovate
renovate Bot merged commit 17afec6 into main Oct 4, 2026
15 checks passed
@renovate
renovate Bot deleted the renovate/whatwg-node branch October 4, 2026 19:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants