Skip to content

release: v1.3.0 - a per-call requested context on the call frame,… - #78

Open
cldmv-bot[bot] wants to merge 10 commits into
masterfrom
next
Open

cldmv-bot[bot] wants to merge 10 commits into
masterfrom
next

Conversation

@cldmv-bot

@cldmv-bot cldmv-bot Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

🚀 What's Changed

💥 Breaking Changes

No breaking changes

✨ Features

🐛 Bug Fixes

No bug fixes

📦 Dependencies

🔧 Other Changes

👥 Contributors

coverage

Metric Coverage
Statements 98.3%
Branches 97.0%
Functions 98.7%
Lines 99.1%

Avg: 98.2% · 6bea6a4 · Node lts/*

Co-authored-by: Shinrai Shinrai@users.noreply.github.com

dependabot Bot and others added 3 commits October 5, 2026 14:11
Bumps the minor group with 1 update: [globals](https://github.com/sindresorhus/globals).


Updates `globals` from 17.12.0 to 17.13.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.12.0...v17.13.0)

---
updated-dependencies:
- dependency-name: globals
  dependency-version: 17.13.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps the minor group with 1 update:
[globals](https://github.com/sindresorhus/globals).

Updates `globals` from 17.12.0 to 17.13.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/sindresorhus/globals/releases">globals's
releases</a>.</em></p>
<blockquote>
<h2>v17.13.0</h2>
<ul>
<li>Update globals (2026-10-01) (<a
href="https://redirect.github.com/sindresorhus/globals/issues/354">#354</a>)
b007369</li>
</ul>
<hr />
<p><a
href="https://github.com/sindresorhus/globals/compare/v17.12.0...v17.13.0">https://github.com/sindresorhus/globals/compare/v17.12.0...v17.13.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/sindresorhus/globals/commit/ce512bc1949f918ad6c17cc864a63ab6b077764f"><code>ce512bc</code></a>
17.13.0</li>
<li><a
href="https://github.com/sindresorhus/globals/commit/b0073695ad35ad0cb34504f3152a20a8411306e7"><code>b007369</code></a>
Update globals (2026-10-01) (<a
href="https://redirect.github.com/sindresorhus/globals/issues/354">#354</a>)</li>
<li><a
href="https://github.com/sindresorhus/globals/commit/16cb1fe4a57062e8b3844b0c74b4d554f53af803"><code>16cb1fe</code></a>
Meta tweaks</li>
<li>See full diff in <a
href="https://github.com/sindresorhus/globals/compare/v17.12.0...v17.13.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=globals&package-manager=npm_and_yarn&previous-version=17.12.0&new-version=17.13.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>
@cldmv-bot cldmv-bot Bot added ! release → master v4 flow: persistent next → master release PR (carries the next feature release) release Marks a pull request as a pending release — merge to publish a new version semver: patch This release contains only backwards-compatible bug fixes type: dependencies Relates to dependency updates, version bumps, or package management labels Oct 5, 2026
@cldmv-bot

cldmv-bot Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor Author

🔒 Dependency Review

  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses
  • ✅ 0 denied package(s)
  • ✅ 0 package(s) with OpenSSF Scorecard score < 3

Full job summary

@cldmv-bot

cldmv-bot Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Bundle size increased

File Raw Δ Raw Gzipped Δ Gzipped
schemas/frame.schema.json 1.9 kB +423 B (+28.0%) ⚠️ 684 B +172 B
src/grow.mjs 29.8 kB +7.3 kB (+32.5%) ⚠️ 10.7 kB +2.2 kB
src/index.mjs 1.7 kB — 924 B —
src/lib/errors.mjs 9.7 kB +542 B (+5.8%) ⚠️ 3.8 kB +215 B
src/lib/events.mjs 16.5 kB — 5.7 kB —
src/lib/frame.mjs 17.5 kB +2.9 kB (+20.0%) ⚠️ 6.1 kB +969 B
src/lib/inbox.mjs 2.3 kB — 1.0 kB —
src/lib/link.mjs 7.5 kB — 2.9 kB —
src/lib/principal.mjs 12.1 kB +327 B (+2.7%) 4.4 kB +13 B
src/serve.mjs 32.2 kB +7.0 kB (+27.7%) ⚠️ 11.0 kB +1.7 kB
src/testing/conformance.mjs 10.6 kB — 3.3 kB —
src/transport/loopback.mjs 4.8 kB — 1.9 kB —
src/transport/post-message.mjs 11.8 kB — 4.4 kB —
src/transport/process.mjs 12.1 kB — 4.5 kB —
src/transport/websocket.mjs 11.8 kB — 4.4 kB —
src/transport/worker-threads.mjs 10.4 kB — 3.8 kB —
Total 192.8 kB +18.5 kB 69.3 kB +5.3 kB

📊 Generated by bundle-size. Brotli sizes also measured but omitted from the table for brevity.

Shinrai and others added 6 commits October 7, 2026 00:01
…, narrowed or refused by a serve({ context }) host check and merged under the principal's keys, all protected, into the call's scope (#79)

The call frame gains an optional, data-only context and the surface frame an
optional context: true flag, advertised only by a serve with a check; no
FRAME_VERSION change. The check runs after the principal is resolved and before
the gate, fails closed (a throw or a non-plain-object answer is VINE_DENIED),
and a serve without a check refuses a frame that carries one. around receives
the accepted context.
…all requested context, refused locally when the far side does not accept one (#79)
…eck configured, data-only violations, old/new interop, loopback and websocket (#79)
…and link.with()/grow({ context }), the refuse-without-a-check default, interop, and no context on subscriptions in v1 (#79)
…distinct from VINE_DENIED for a rules refusal (#79)

The serve's context check refusing (a non-object answer, a throw or a
rejection), a serve with no check, and the grow's local refusal when the far
side does not accept requested contexts now answer VINE_CONTEXT. VINE_DENIED
stays the principal/permission refusal, including for an accepted context the
rules then refuse.
…wed or refused by a serve({ context }) host check and merged under the principal's keys, all protected, into the call's scope (#79) (#80)
@cldmv-bot cldmv-bot Bot added area: core Touches core library / runtime source code area: tests Touches test files, fixtures, or test infrastructure type: documentation Relates to docs, README updates, guides, or inline code comments labels Oct 8, 2026
@cldmv-bot cldmv-bot Bot changed the title release: v1.2.3 - bump globals from 17.12.0 to 17.13.0 in the minor group release: v1.3.0 - a per-call requested context on the call frame,… Oct 8, 2026
@cldmv-bot cldmv-bot Bot added semver: minor This release adds new functionality in a backwards-compatible way type: feature Implements new functionality — a PR or issue that adds a feature and removed semver: patch This release contains only backwards-compatible bug fixes labels Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: core Touches core library / runtime source code area: tests Touches test files, fixtures, or test infrastructure ! release → master v4 flow: persistent next → master release PR (carries the next feature release) release Marks a pull request as a pending release — merge to publish a new version semver: minor This release adds new functionality in a backwards-compatible way type: dependencies Relates to dependency updates, version bumps, or package management type: documentation Relates to docs, README updates, guides, or inline code comments type: feature Implements new functionality — a PR or issue that adds a feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant