Skip to content

upgrade dependencies#12

Closed
gms1 wants to merge 68 commits intomasterfrom
main
Closed

upgrade dependencies#12
gms1 wants to merge 68 commits intomasterfrom
main

Conversation

@gms1
Copy link
Copy Markdown
Owner

@gms1 gms1 commented Apr 17, 2026

No description provided.

MatheusBaldi and others added 30 commits March 13, 2026 10:03
This reverts commit 7a1e985.
This reverts commit 008327d.
when copying from null pointer
as pointed out here:
TryGhost#1832
This fixes the contradictory configuration where compiler flags enabled
C++ exceptions but NAPI_DISABLE_CPP_EXCEPTIONS=1 told node-addon-api to
disable them. Now C++ exceptions are properly enabled throughout the
stack.
This fixes the contradictory configuration
pointed out here: microsoft#47
where compiler flags enabled C++ exceptions but NAPI_DISABLE_CPP_EXCEPTIONS=1 told node-addon-api to disable them. Now C++ exceptions are properly enabled throughout the stack.
- Linux hardening flags (all builds):
  -fstack-protector-strong - Stack canary protection
  -fPIC - Position Independent Code
  -Wl,-z,relro,-z,now - Full RELRO (Read-only GOT)

- Linux Release-only flags (via configurations.Release):

  _FORTIFY_SOURCE=2 - Buffer overflow detection
  -fcf-protection=full - Control Flow Integrity (Intel CET)

- macOS hardening flags (all builds):

  -fstack-protector-strong in OTHER_CFLAGS

- Windows hardening flags (all builds):

  BufferSecurityCheck: "true" (/GS)
  ControlFlowGuard: "Guard" (/guard:cf)
  /DYNAMICBASE - ASLR support
  /NXCOMPAT - DEP/NX bit support

- Windows Release-only flags:

  /sdl - Additional security checks
gms1 and others added 29 commits April 4, 2026 14:14
fix potential crash during shutdown
Bumps [axios](https://github.com/axios/axios) from 1.14.0 to 1.15.0.
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.14.0...v1.15.0)

---
updated-dependencies:
- dependency-name: axios
  dependency-version: 1.15.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…n permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Potential fix for code scanning alert no. 4: Workflow does not contain permissions
…mark

benchmark for comparing event loop utilization for different sqlite d…
Bumps the npm_and_yarn group with 1 update in the / directory: [follow-redirects](https://github.com/follow-redirects/follow-redirects).


Updates `follow-redirects` from 1.15.11 to 1.16.0
- [Release notes](https://github.com/follow-redirects/follow-redirects/releases)
- [Commits](follow-redirects/follow-redirects@v1.15.11...v1.16.0)

---
updated-dependencies:
- dependency-name: follow-redirects
  dependency-version: 1.16.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
…-85af2c71bb

Bump follow-redirects from 1.15.11 to 1.16.0 in the npm_and_yarn group across 1 directory
@gms1 gms1 closed this Apr 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants