From 593dc5dd1e956114d6bd717f4b910b2fa501c9d2 Mon Sep 17 00:00:00 2001 From: dormouse-bot <287024035+dormouse-bot@users.noreply.github.com> Date: Mon, 14 Sep 2026 14:38:25 +0000 Subject: [PATCH 1/4] chore(renovate): bump the node-datachannel prebuild family as one group --- .github/renovate.json | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/.github/renovate.json b/.github/renovate.json index b403625a3..9de92bc6f 100644 --- a/.github/renovate.json +++ b/.github/renovate.json @@ -89,6 +89,14 @@ "groupSlug": "xterm", "separateMajorMinor": false }, + { + "description": "node-datachannel publishes one prebuilt package per platform from one repository at one version, and the sidecar declares all six beside the core package. website/scripts/generate-deps.js describes the five platforms pnpm did not install from whichever sibling it did — matching on the exact version string — and throws when no sibling sits at that version, so a split bump fails the `Dependency disclosure is current` CI step and cannot go green on its own (docs/specs/security-supply-chain.md -> Disclosure). The core package belongs in the group too: it declares its own optionalDependencies at its own version and the addon resolves the platform binary relative to its own directory, so bumping the platform packages alone ships a prebuild nothing loads", + "matchManagers": ["npm"], + "matchPackageNames": ["node-datachannel", "@node-datachannel/**"], + "groupName": "node-datachannel", + "groupSlug": "node-datachannel", + "separateMajorMinor": false + }, { "description": "@types/node must track the pinned Node runtime major and must not expose APIs newer than the runtime we bundle", "matchManagers": ["npm"], From 8c6d3f460be7ef628652e3be2b137c6692d4ba9f Mon Sep 17 00:00:00 2001 From: Ned Twigg Date: Mon, 14 Sep 2026 14:59:38 -0700 Subject: [PATCH 2/4] chore(deps): update the node-datachannel family to v0.33.4 Lands the whole 0.33.2 -> 0.33.4 bump in one commit: the core package plus all six prebuilt platform packages the sidecar declares beside it, the lockfile, and the regenerated dependency disclosure. Renovate split this round into seven PRs (#637, #639, #640, #643, #644, #645, #647) and every one of them is red on its own, because website/scripts/generate-deps.js requires the declared siblings to sit at the same version. The renovate.json group in the previous commit prevents the next round from splitting; this commit clears the current one. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01HHoyvmFzcmMyFbsTSp8FmL --- pnpm-lock.yaml | 106 ++++++++++++------------- standalone/sidecar/package.json | 14 ++-- website/src/data/dependencies-npm.json | 14 ++-- 3 files changed, 67 insertions(+), 67 deletions(-) diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 88bed0ada..8614da6cb 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -313,30 +313,30 @@ importers: specifier: 2.1.2 version: 2.1.2 node-datachannel: - specifier: 0.33.2 - version: 0.33.2 + specifier: 0.33.4 + version: 0.33.4 node-pty: specifier: 1.2.0-beta.15 version: 1.2.0-beta.15 optionalDependencies: '@node-datachannel/darwin-arm64': - specifier: 0.33.2 - version: 0.33.2 + specifier: 0.33.4 + version: 0.33.4 '@node-datachannel/darwin-x64': - specifier: 0.33.2 - version: 0.33.2 + specifier: 0.33.4 + version: 0.33.4 '@node-datachannel/linux-arm64-gnu': - specifier: 0.33.2 - version: 0.33.2 + specifier: 0.33.4 + version: 0.33.4 '@node-datachannel/linux-x64-gnu': - specifier: 0.33.2 - version: 0.33.2 + specifier: 0.33.4 + version: 0.33.4 '@node-datachannel/win32-arm64-msvc': - specifier: 0.33.2 - version: 0.33.2 + specifier: 0.33.4 + version: 0.33.4 '@node-datachannel/win32-x64-msvc': - specifier: 0.33.2 - version: 0.33.2 + specifier: 0.33.4 + version: 0.33.4 vscode-ext: dependencies: @@ -1250,52 +1250,52 @@ packages: resolution: {integrity: sha512-AnjFn0Jv92laAkvMrghlFZq4qQCIN/4DxFV/eooqtC2YTjB7kBeLMS2T9KJX4Dn+ZVXLOwK0lSgqDtx9gvxtiw==} engines: {node: '>= 20.19.0'} - '@node-datachannel/android-arm64@0.33.2': - resolution: {integrity: sha512-I71a0jICUNYgh4ZI5AcINEMuRtQSVyrpp4FV3kJZMcx31xS0vKKtf06tpsUAtW5uS+uRXbZR+vlMEqS1h710wQ==} + '@node-datachannel/android-arm64@0.33.4': + resolution: {integrity: sha512-Kd1K+drJlxdGmZYBlzh5HHX2E7les99eTWlt7WldZgvJmcGf2z9L/bnUVn4zbhNm2q/MtNZ2tPX2bd+fGlDDpQ==} cpu: [arm64] os: [android] - '@node-datachannel/darwin-arm64@0.33.2': - resolution: {integrity: sha512-EwBGiaMh3MX6zjYoZHuK02Q6hmQQIvR39335Kb/ZnP3fXZU0/VWx6ksHLM6K0XFFYRfP+yJeVgU79g++xoeQpw==} + '@node-datachannel/darwin-arm64@0.33.4': + resolution: {integrity: sha512-bkIA+IbModz/NUmbVYTSWj8dZvkiab+cU4zOa6rhfKsNcW3EkdD2/DDoJjUrRrw+LbEZ40V7NuAKUlMNFDXFsw==} cpu: [arm64] os: [darwin] - '@node-datachannel/darwin-x64@0.33.2': - resolution: {integrity: sha512-a1nvL6MiskSjV3TWTNXdVpI/2kHNIOP2AbuBZjR5eC7VSrH/6hCFfHIBW4SFKXGFm8LOGliY9Df10UnJUutjwA==} + '@node-datachannel/darwin-x64@0.33.4': + resolution: {integrity: sha512-+dLnwiwC3GdWqW0OQShZcSFYrx3hRx0+7U85swoiP3iiRqtDUARME6AIAmW3glpP0vmus1jv5KhPCy/Q+jAvqw==} cpu: [x64] os: [darwin] - '@node-datachannel/linux-arm64-gnu@0.33.2': - resolution: {integrity: sha512-YWAu3EiMl2HRi/fwWlfFTW30wFTkRVYJWRHQcI1uDSeZYG/tfyBqBy6CRy9Sgrb0xjOYZ6XhLDj8cdX0foPlpg==} + '@node-datachannel/linux-arm64-gnu@0.33.4': + resolution: {integrity: sha512-rR4yjwxpI1miLSrruLGcfR9yfw0Qebw+Twt+u+lKsL9SwmXxTm5pJhUAa9RU+c35oZ98IyAxGFjRwwq85BTbog==} cpu: [arm64] os: [linux] libc: [glibc] - '@node-datachannel/linux-arm64-musl@0.33.2': - resolution: {integrity: sha512-16o3Ny5hbxTTjDmhsZog/t7p2tRP6s/Oa/V9kKzZfiGlCqvxxCE4ACOWw/MWHOhN0xI9/63IIRfrrnQnPxjK8g==} + '@node-datachannel/linux-arm64-musl@0.33.4': + resolution: {integrity: sha512-MR4o1F0aREj/AtbNlXL20YiNx8/pDI8L/5B4Vr9ldiEDottD0IOdCd0khB8fpr5Np2CW7WwU9QG+uto00QGVdw==} cpu: [arm64] os: [linux] libc: [musl] - '@node-datachannel/linux-x64-gnu@0.33.2': - resolution: {integrity: sha512-grLRAbZgSIX8nmObciblyCmnevDCst0snhV+z1fvDmUlzXIVXeDmv6lEzAaWs3KRleagqwSsFg5d1td1bwMT9w==} + '@node-datachannel/linux-x64-gnu@0.33.4': + resolution: {integrity: sha512-xN0x3lcQ87qwOAmf1dBLVWrYY40LQ7pM4Y9wuNjP+EtN4IwiXqrhPdgupzGAElxna+n2NgBG0gT60dZpgoYU2Q==} cpu: [x64] os: [linux] libc: [glibc] - '@node-datachannel/linux-x64-musl@0.33.2': - resolution: {integrity: sha512-PlpgvYjo+gmBhIkRFaZWIhCF335FMTJmCpl+FVa4XliEgyOqD+cvjQPWcbnlrA2Jd+QnLiZt+NxT7nv4QXpoiQ==} + '@node-datachannel/linux-x64-musl@0.33.4': + resolution: {integrity: sha512-FWqJEjL7TqOPmsqdfwmG/BUwOXQN7MfpEU8kzw6ePbglUbwgdc3976Ls9BCBUXyPgEJyLo8YE1LJyWAlbXWyvA==} cpu: [x64] os: [linux] libc: [musl] - '@node-datachannel/win32-arm64-msvc@0.33.2': - resolution: {integrity: sha512-8NpHkm7R8EY0jHGHOXdK7K0wjWY34PJ+PJY++2VDHTAtXGazNm28zcnVE/4IU0N26YGdCDSSWat3OO3W6nwoRw==} + '@node-datachannel/win32-arm64-msvc@0.33.4': + resolution: {integrity: sha512-TeDV2tSPm+qAnF6MIPlLFTIlobSYLwOVe3/wQl+8hD/q3cEPTQi7vByFaQQ5lRULKKdnjKRR5iDMsxMilqbtXA==} cpu: [arm64] os: [win32] - '@node-datachannel/win32-x64-msvc@0.33.2': - resolution: {integrity: sha512-aLk0O/M1JNVpzxx4RVBXMJTMlpswE04Cz5baayKwuEN+qk9hO6DSJgYMR6Wq9a5zGYAmvLFlOg+LsePyXkWliA==} + '@node-datachannel/win32-x64-msvc@0.33.4': + resolution: {integrity: sha512-eU0w/9ykrNaA5vWs5gjVs3Qxa45jbQ8mYoMyh5OWnRCE5GzXKxHCpfhFUnO+jGqi0KxkyP0hSA6fiwXXkirk6g==} cpu: [x64] os: [win32] @@ -3765,8 +3765,8 @@ packages: resolution: {integrity: sha512-Jx5lPaaLdIaOsj2mVLWMWulXF6GQVdyLvNSxmiYCvZ8Ma2hfKX0POoR2kgKOqz+oFsRreq0yYZjQ2wjE9VNzCA==} engines: {node: '>=v0.6.5'} - node-datachannel@0.33.2: - resolution: {integrity: sha512-WRL+uqYG2eSvpnKuCOKueaMiyKlDjkJFd6pFH/f2SbD/EiXLMXwmYNU5z+TDQPrAv+BMgkuC40UESeRRL+4zBw==} + node-datachannel@0.33.4: + resolution: {integrity: sha512-qiUrdh8vY9XhglEnx91HK0N2JEAAu8qTZl0fcR3yQd0fFrdO39NwDeJD/KpG+WKUb9/o4p2UwnP+/HftA/xMbQ==} engines: {node: '>=18.20.0'} node-pty@1.2.0-beta.15: @@ -5547,31 +5547,31 @@ snapshots: '@noble/ciphers@2.4.0': {} - '@node-datachannel/android-arm64@0.33.2': + '@node-datachannel/android-arm64@0.33.4': optional: true - '@node-datachannel/darwin-arm64@0.33.2': + '@node-datachannel/darwin-arm64@0.33.4': optional: true - '@node-datachannel/darwin-x64@0.33.2': + '@node-datachannel/darwin-x64@0.33.4': optional: true - '@node-datachannel/linux-arm64-gnu@0.33.2': + '@node-datachannel/linux-arm64-gnu@0.33.4': optional: true - '@node-datachannel/linux-arm64-musl@0.33.2': + '@node-datachannel/linux-arm64-musl@0.33.4': optional: true - '@node-datachannel/linux-x64-gnu@0.33.2': + '@node-datachannel/linux-x64-gnu@0.33.4': optional: true - '@node-datachannel/linux-x64-musl@0.33.2': + '@node-datachannel/linux-x64-musl@0.33.4': optional: true - '@node-datachannel/win32-arm64-msvc@0.33.2': + '@node-datachannel/win32-arm64-msvc@0.33.4': optional: true - '@node-datachannel/win32-x64-msvc@0.33.2': + '@node-datachannel/win32-x64-msvc@0.33.4': optional: true '@node-rs/crc32-android-arm-eabi@1.10.7': @@ -7962,19 +7962,19 @@ snapshots: node-bitmap@0.0.1: {} - node-datachannel@0.33.2: + node-datachannel@0.33.4: dependencies: detect-libc: 2.1.2 optionalDependencies: - '@node-datachannel/android-arm64': 0.33.2 - '@node-datachannel/darwin-arm64': 0.33.2 - '@node-datachannel/darwin-x64': 0.33.2 - '@node-datachannel/linux-arm64-gnu': 0.33.2 - '@node-datachannel/linux-arm64-musl': 0.33.2 - '@node-datachannel/linux-x64-gnu': 0.33.2 - '@node-datachannel/linux-x64-musl': 0.33.2 - '@node-datachannel/win32-arm64-msvc': 0.33.2 - '@node-datachannel/win32-x64-msvc': 0.33.2 + '@node-datachannel/android-arm64': 0.33.4 + '@node-datachannel/darwin-arm64': 0.33.4 + '@node-datachannel/darwin-x64': 0.33.4 + '@node-datachannel/linux-arm64-gnu': 0.33.4 + '@node-datachannel/linux-arm64-musl': 0.33.4 + '@node-datachannel/linux-x64-gnu': 0.33.4 + '@node-datachannel/linux-x64-musl': 0.33.4 + '@node-datachannel/win32-arm64-msvc': 0.33.4 + '@node-datachannel/win32-x64-msvc': 0.33.4 node-pty@1.2.0-beta.15: dependencies: diff --git a/standalone/sidecar/package.json b/standalone/sidecar/package.json index ac799408f..712efbf0f 100644 --- a/standalone/sidecar/package.json +++ b/standalone/sidecar/package.json @@ -8,15 +8,15 @@ }, "dependencies": { "detect-libc": "2.1.2", - "node-datachannel": "0.33.2", + "node-datachannel": "0.33.4", "node-pty": "1.2.0-beta.15" }, "optionalDependencies": { - "@node-datachannel/darwin-arm64": "0.33.2", - "@node-datachannel/darwin-x64": "0.33.2", - "@node-datachannel/linux-arm64-gnu": "0.33.2", - "@node-datachannel/linux-x64-gnu": "0.33.2", - "@node-datachannel/win32-arm64-msvc": "0.33.2", - "@node-datachannel/win32-x64-msvc": "0.33.2" + "@node-datachannel/darwin-arm64": "0.33.4", + "@node-datachannel/darwin-x64": "0.33.4", + "@node-datachannel/linux-arm64-gnu": "0.33.4", + "@node-datachannel/linux-x64-gnu": "0.33.4", + "@node-datachannel/win32-arm64-msvc": "0.33.4", + "@node-datachannel/win32-x64-msvc": "0.33.4" } } diff --git a/website/src/data/dependencies-npm.json b/website/src/data/dependencies-npm.json index 1a3b78122..2be32e335 100644 --- a/website/src/data/dependencies-npm.json +++ b/website/src/data/dependencies-npm.json @@ -22,42 +22,42 @@ }, { "name": "@node-datachannel/darwin-arm64", - "version": "0.33.2", + "version": "0.33.4", "license": "MPL 2.0", "author": "Murat Doğan, Paul-Louis Ageneau", "homepage": "https://github.com/murat-dogan/node-datachannel" }, { "name": "@node-datachannel/darwin-x64", - "version": "0.33.2", + "version": "0.33.4", "license": "MPL 2.0", "author": "Murat Doğan, Paul-Louis Ageneau", "homepage": "https://github.com/murat-dogan/node-datachannel" }, { "name": "@node-datachannel/linux-arm64-gnu", - "version": "0.33.2", + "version": "0.33.4", "license": "MPL 2.0", "author": "Murat Doğan, Paul-Louis Ageneau", "homepage": "https://github.com/murat-dogan/node-datachannel" }, { "name": "@node-datachannel/linux-x64-gnu", - "version": "0.33.2", + "version": "0.33.4", "license": "MPL 2.0", "author": "Murat Doğan, Paul-Louis Ageneau", "homepage": "https://github.com/murat-dogan/node-datachannel" }, { "name": "@node-datachannel/win32-arm64-msvc", - "version": "0.33.2", + "version": "0.33.4", "license": "MPL 2.0", "author": "Murat Doğan, Paul-Louis Ageneau", "homepage": "https://github.com/murat-dogan/node-datachannel" }, { "name": "@node-datachannel/win32-x64-msvc", - "version": "0.33.2", + "version": "0.33.4", "license": "MPL 2.0", "author": "Murat Doğan, Paul-Louis Ageneau", "homepage": "https://github.com/murat-dogan/node-datachannel" @@ -309,7 +309,7 @@ }, { "name": "node-datachannel", - "version": "0.33.2", + "version": "0.33.4", "license": "MPL 2.0", "author": "Murat Doğan, Paul-Louis Ageneau", "homepage": "https://github.com/murat-dogan/node-datachannel#readme" From fadb34c734557a708050a4130823345aecbae81c Mon Sep 17 00:00:00 2001 From: Ned Twigg Date: Mon, 14 Sep 2026 15:12:53 -0700 Subject: [PATCH 3/4] chore(renovate): say the grouped node-datachannel PR still needs a disclosure commit MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Renovate never runs website/scripts/generate-deps.js, so the grouped PR arrives with a stale website/src/data/dependencies-npm.json and a red `Dependency disclosure is current` step — one commit to clear, where a split bump throws before it can produce a snapshot at all. Without the note the next session reads that red as the grouping not working. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01HHoyvmFzcmMyFbsTSp8FmL --- .github/renovate.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/renovate.json b/.github/renovate.json index 9de92bc6f..f9fadbd75 100644 --- a/.github/renovate.json +++ b/.github/renovate.json @@ -90,7 +90,7 @@ "separateMajorMinor": false }, { - "description": "node-datachannel publishes one prebuilt package per platform from one repository at one version, and the sidecar declares all six beside the core package. website/scripts/generate-deps.js describes the five platforms pnpm did not install from whichever sibling it did — matching on the exact version string — and throws when no sibling sits at that version, so a split bump fails the `Dependency disclosure is current` CI step and cannot go green on its own (docs/specs/security-supply-chain.md -> Disclosure). The core package belongs in the group too: it declares its own optionalDependencies at its own version and the addon resolves the platform binary relative to its own directory, so bumping the platform packages alone ships a prebuild nothing loads", + "description": "node-datachannel publishes one prebuilt package per platform from one repository at one version, and the sidecar declares all six beside the core package. website/scripts/generate-deps.js describes the five platforms pnpm did not install from whichever sibling it did — matching on the exact version string — and throws when no sibling sits at that version, so a split bump fails the `Dependency disclosure is current` CI step and cannot go green on its own (docs/specs/security-supply-chain.md -> Disclosure). The core package belongs in the group too: it declares its own optionalDependencies at its own version and the addon resolves the platform binary relative to its own directory, so bumping the platform packages alone ships a prebuild nothing loads. The grouped PR still arrives red: Renovate does not run the generator, so website/src/data/dependencies-npm.json is stale until someone commits `node website/scripts/generate-deps.js`. That red is expected and is one commit to clear — unlike a split bump, which throws before it can produce a snapshot at all", "matchManagers": ["npm"], "matchPackageNames": ["node-datachannel", "@node-datachannel/**"], "groupName": "node-datachannel", From cddbfd6bd33764cc2542bd1effb1e25288c603c9 Mon Sep 17 00:00:00 2001 From: Ned Twigg Date: Mon, 14 Sep 2026 15:20:54 -0700 Subject: [PATCH 4/4] chore(renovate): name both node-datachannel failure modes, not just the throw MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit A prebuild-only bump throws, because no declared sibling sits at the new version. A core-only bump does not: it installs cleanly, the prebuild then resolves twice — once from the root pin, once nested under the new core — and the regenerated disclosure lists every prebuild at both versions, as #647's `Build & Test` shows ("version": "0.33.2, 0.33.4" on all six rows). The description covered only the first half. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01HHoyvmFzcmMyFbsTSp8FmL --- .github/renovate.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/renovate.json b/.github/renovate.json index f9fadbd75..462846f68 100644 --- a/.github/renovate.json +++ b/.github/renovate.json @@ -90,7 +90,7 @@ "separateMajorMinor": false }, { - "description": "node-datachannel publishes one prebuilt package per platform from one repository at one version, and the sidecar declares all six beside the core package. website/scripts/generate-deps.js describes the five platforms pnpm did not install from whichever sibling it did — matching on the exact version string — and throws when no sibling sits at that version, so a split bump fails the `Dependency disclosure is current` CI step and cannot go green on its own (docs/specs/security-supply-chain.md -> Disclosure). The core package belongs in the group too: it declares its own optionalDependencies at its own version and the addon resolves the platform binary relative to its own directory, so bumping the platform packages alone ships a prebuild nothing loads. The grouped PR still arrives red: Renovate does not run the generator, so website/src/data/dependencies-npm.json is stale until someone commits `node website/scripts/generate-deps.js`. That red is expected and is one commit to clear — unlike a split bump, which throws before it can produce a snapshot at all", + "description": "node-datachannel publishes one prebuilt package per platform from one repository at one version, and the sidecar declares all six beside the core package. website/scripts/generate-deps.js describes the five platforms pnpm did not install from whichever sibling it did — matching on the exact version string — and throws when no sibling sits at that version, so a prebuild-only bump fails the `Dependency disclosure is current` CI step and cannot go green on its own (docs/specs/security-supply-chain.md -> Disclosure). The core package belongs in the group too: it declares its own optionalDependencies at its own version and the addon resolves the platform binary relative to its own directory, so bumping the platform packages alone ships a prebuild nothing loads. A core-only bump does not throw — the prebuild then resolves twice, once from the root pin and once nested under the new core, and the disclosure regenerates with every prebuild listed at both versions. The grouped PR still arrives red: Renovate does not run the generator, so website/src/data/dependencies-npm.json is stale until someone commits `node website/scripts/generate-deps.js`. That red is expected and is one commit to clear — unlike a prebuild-only bump, which throws before it can produce a snapshot at all", "matchManagers": ["npm"], "matchPackageNames": ["node-datachannel", "@node-datachannel/**"], "groupName": "node-datachannel",