Skip to content

chore(deps): update dependency ovsx to v1.2.0 - #386

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/npm-packages
Sep 13, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/npm-packages

Conversation

@renovate

@renovate renovate Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
ovsx (source) 1.1.11.2.0 age adoption passing confidence

Release Notes

eclipse-openvsx/openvsx (ovsx)

v1.2.0

Compare Source

Added
  • Add --follow-symlinks to publish, forwarding vsce's option of the same name so that the file walk recurses into symlinked directories instead of packing each symlink as a file. Needed for a node_modules assembled out of symlinks, as pnpm's is (#​368)
  • Add search command to search the registry for extensions, mirroring the web UI's search: --category, --target, --sort-by and --sort-order narrow the query, --size and --offset page through the results, and --json prints the registry's raw response (#​2154)
  • Add list command to print the extensions a namespace holds, sorted by name so the output stays stable across registries, with --json for the raw namespace metadata (#​2154)
  • Add show command to print an extension's metadata, mirroring vsce show: identity, publisher, rating, notices and a version history listing each version's target platforms (#​2149). namespace.extension@version reports a single version, --target scopes the report to one target platform, --all-versions lists every published version instead of the most recent few, and --json prints the registry's raw metadata
  • Add unpublish command to delete an extension or some of its versions, mirroring vsce unpublish (#​1958); requires a registry running version 1.2.0 or later, which unpublish checks for before deleting
  • publish checks the packaged extension's size against the limit reported by the registry's /api/version endpoint before uploading, instead of failing only after the upload completes (#​1953)
  • Add verify command to check a downloaded .vsix package's signature against the registry's public key, mirroring vsce verify-signature (#​993)
  • Add verify-signature command, verifying an already-extracted package/manifest/signature file trio entirely offline (no registry involved), matching vsce verify-signature's own command shape (#​993)
Fixed
  • Error messages naming a URL no longer include its query string, which for createNamespace, verifyPat, publish and delete carried the personal access token straight to stderr and into CI logs (#​2186)

  • A connection lost after a JSON response has started no longer leaves the command waiting on a body that is not coming: the response's own error is now what settles the request, so it fails with the reset rather than hanging (#​2186)

  • Requests now give up after 30 seconds without progress instead of hanging indefinitely when a server accepts a connection and then says nothing. OVSX_TIMEOUT overrides the duration in milliseconds and OVSX_TIMEOUT=0 disables it; it measures inactivity, so a large extension downloading slowly is unaffected, and it covers the trusted-publishing ID token request as well as the registry's own (#​2186)

  • Fix downloads that could be read before they were written. download resolved when the response ended rather than when the file was closed, and a write stream opens and flushes asynchronously, so a caller reading the path immediately afterwards could find the file empty or absent - which verify did, intermittently failing to read the public key it had just fetched. A failed download no longer touches the target path: the body is written beside it and renamed into place only once it has arrived whole, so a 404 or a dropped connection leaves what was there alone. A connection dropped mid-download now rejects rather than leaving the caller waiting forever (#​2185)

Changed
  • publish --trusted-publishing retries the token exchange when the registry answers that it could not verify the ID token (502, 503, 504), rather than failing the build on a blip reaching the identity provider. A refusal is never retried
  • publish --trusted-publishing requests a new token and retries once when the registry refuses the one it was publishing with. The issued token is short-lived and shared by every target platform of a release, so publishing a wide fan-out of large packages could outlive it and fail partway through. Targets that are refused together share one new token, and a token supplied with --pat is never retried
  • Bump minimum supported Node.js version to 22, matching the webui component

Configuration

📅 Schedule: (in timezone Asia/Shanghai)

  • Branch creation
    • "before 10am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge (squash) September 13, 2026 16:22
@renovate
renovate Bot merged commit fa59699 into main Sep 13, 2026
5 checks passed
@renovate
renovate Bot deleted the renovate/npm-packages branch September 13, 2026 16:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants