Skip to content

chore(deps-dev): bump bson from 4.7.2 to 6.10.3 #41

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github May 1, 2025

Bumps bson from 4.7.2 to 6.10.3.

Release notes

Sourced from bson's releases.

v6.10.3

6.10.3 (2025-02-19)

The MongoDB Node.js team is pleased to announce version 6.10.3 of the bson package!

Release Notes

⚠️ Fixed potential data corruption bug when useBigInt64 is enabled

After refactoring to improve deserialization performance in #649, we inadvertently introduced a bug that manifested when deserializing Long values with the useBigInt64 flag enabled. The bug would lead to negative Long values being deserialized as unsigned integers. This issue has been resolved here.

Thanks to @​rkistner for reporting this bug!

Bug Fixes

  • NODE-6764: incorrect negative bigint handling (#752) (b3212b4)

Documentation

We invite you to try the bson library immediately, and report any issues to the NODE project.

v6.10.2

6.10.2 (2025-01-29)

The MongoDB Node.js team is pleased to announce version 6.10.2 of the bson package!

Release Notes

Fix calculateObjectSize not accounting for BigInt value size

BSON.calculateObjectSize was missing a condition for BigInt values, meaning it did not account for them in the same way that it would for Long values. This has been corrected so that Bigint values contribute 8 bytes worth of size to the total count.

We also added a new default condition that will catch any new values that may be returned by typeof in the future and will throw an error rather than returning an inaccurate size.

Bug Fixes

  • NODE-6608: calculateObjectSize returns the wrong value for bigint (#742) (1fed073)

Documentation

We invite you to try the bson library immediately, and report any issues to the NODE project.

v6.10.1

6.10.1 (2024-11-27)

... (truncated)

Changelog

Sourced from bson's changelog.

6.10.3 (2025-02-19)

Bug Fixes

  • NODE-6764: incorrect negative bigint handling (#752) (b3212b4)

6.10.2 (2025-01-29)

Bug Fixes

  • NODE-6608: calculateObjectSize returns the wrong value for bigint (#742) (1fed073)

6.10.1 (2024-11-27)

Bug Fixes

  • NODE-6552: remove cache and use toStringTag in type helpers (#740) (3ede13e)

Performance Improvements

  • NODE-6450: Lazy objectId hex string cache (#722) (7c37580)

6.10.0 (2024-11-18)

Features

  • NODE-6537: add support for binary vectors (#730) (d7bdcec)

Bug Fixes

  • NODE-6536: Binary.read never returns number[] and reads beyond content (#727) (f99fdfd)

6.9.0 (2024-10-15)

Features

Performance Improvements

  • NODE-6344: improve ObjectId.isValid(string) performance (#708) (064ba91)
  • NODE-6356: Improve serialization performance (#709) (61537f5)

... (truncated)

Commits
  • d22dee9 chore(main): release 6.10.3 [skip-ci] (#754)
  • 689212f ci(NODE-6769): regenerate lockfile (#755)
  • b3212b4 fix(NODE-6764): incorrect negative bigint handling (#752)
  • 011e85e chore(deps): bump serialize-javascript and mocha in /etc/eslint/no-bigint-usa...
  • b5ad49a chore(deps-dev): bump the development-dependencies group across 1 directory w...
  • bd326a8 chore: Add CODEOWNERS file [skip-ci]
  • 306b607 chore(main): release 6.10.2 [skip-ci] (#743)
  • bf5b66e test(NODE-6679): restore node latest testing (#746)
  • eca63c9 chore(NODE-6634): pin NPM to 10 when Node version is 18 (#745)
  • 1fed073 fix(NODE-6608): calculateObjectSize returns the wrong value for bigint (#742)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by dbx-node, a new releaser for bson since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [bson](https://github.com/mongodb/js-bson) from 4.7.2 to 6.10.3.
- [Release notes](https://github.com/mongodb/js-bson/releases)
- [Changelog](https://github.com/mongodb/js-bson/blob/main/HISTORY.md)
- [Commits](mongodb/js-bson@v4.7.2...v6.10.3)

---
updated-dependencies:
- dependency-name: bson
  dependency-version: 6.10.3
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels May 1, 2025
@dependabot dependabot bot requested a review from a team as a code owner May 1, 2025 11:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants