Skip to content

chore(deps): bump @morojs/engine from 1.1.4 to 1.1.9 - #27

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/morojs/engine-1.1.9
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/morojs/engine-1.1.9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps @morojs/engine from 1.1.4 to 1.1.9.

Release notes

Sourced from @​morojs/engine's releases.

v1.1.9

@​morojs/engine 1.1.9

A routing release with two new native functions. Nothing on the wire changes, nothing in the API is removed or renamed, and the one new capability is additive and feature-detected through probe().capabilities. A 1.8.x MoroJS keeps working on this binary; a MoroJS that calls the new functions checks the flag first.

A TLS release with one new native function. Nothing on the wire changes, nothing in the API is removed or renamed, and the one new capability is additive and feature-detected through probe().capabilities. A 1.8.x MoroJS keeps working on this binary; a MoroJS that calls the new function checks the flag first and reports a clear error on 1.1.7.

New — certificate rotation without a restart

updateSsl(serverId, ssl) replaces the certificate and key of a running TLS server for every handshake that starts afterwards (capabilities.tlsReload). Until now the material was read once in serve(), so an ACME renewal or a rotated secret meant a listener restart; in-process TLS was the only place in the engine where that was still true.

  • ssl is the full serve() ssl shape, not a diff: file paths or inline PEM, passphrase, minVersion, requestCert/rejectUnauthorized, ciphers/ciphersuites/ecdhCurve, ticketKeys. Inline wins over a file path for the same slot, as in serve().
  • Validated before the swap. The new context is built and checked (readable files, parsable PEM, key matching certificate, protocol floor) while the current one keeps serving; any failure throws with the same messages serve() uses and leaves the live context untouched.
  • Established connections are unaffected. A TlsSession holds its own reference to the SSL_CTX it handshaked with, so a kept-alive socket or an in-flight request finishes on the old context while the next handshake gets the new one. The old context is freed when its last session closes.
  • Session-ticket keys carry over when the update omits them, so tickets minted before a rotation still resume afterwards; an update that names new keys ends resumption of the old tickets. The ALPN policy carries over the same way.
  • Throws for a server that was not started with ssl (TLS cannot be turned on after the fact), for an unknown serverId, and for a missing options object.
  • The swap runs on the server's loop thread, the only thread that handshakes, so there is no lock and no window in which a handshake sees a half-built context. The per-connection path is unchanged: sessions still derive from the live context pointer; the rotation itself costs one context build.

Internally serve() and updateSsl() share one option parser and one

... (truncated)

Commits
  • f57fdac chore: release v1.1.9
  • 30a8de9 # @​morojs/engine 1.1.9
  • d5d59c3 feat: add parameter route support with setParamRoute and clearParamRoutes fun...
  • 798fc82 chore: release v1.1.8
  • c784804 # @​morojs/engine 1.1.8
  • e2ecd4e feat: enhance loop behavior to reap pending tasks and improve wake efficiency...
  • de71951 feat: enhance server stats to include transport mode and improve task handlin...
  • a2e1976 chore: release v1.1.7
  • 075c793 feat: add callback scope for JS callbacks and improve io_uring transport
  • 8171fa2 feat: enhance batch dispatch test to handle client abort scenarios more robustly
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@morojs/engine](https://github.com/Moro-JS/engine) from 1.1.4 to 1.1.9.
- [Release notes](https://github.com/Moro-JS/engine/releases)
- [Commits](Moro-JS/engine@v1.1.4...v1.1.9)

---
updated-dependencies:
- dependency-name: "@morojs/engine"
  dependency-version: 1.1.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
@dependabot
dependabot Bot requested a review from M-Chris as a code owner September 28, 2026 03:08
@dependabot dependabot Bot added the javascript Pull requests that update javascript code label Sep 28, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #29.

@dependabot dependabot Bot closed this Oct 5, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/morojs/engine-1.1.9 branch October 5, 2026 03:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants