Skip to content

release: v1.2.0 - make UUID generation zero-node-builtin for browser… - #20

Merged
Shinrai merged 6 commits into
masterfrom
next
Aug 17, 2026
Merged

release: v1.2.0 - make UUID generation zero-node-builtin for browser…#20
Shinrai merged 6 commits into
masterfrom
next

Conversation

@cldmv-bot

@cldmv-bot cldmv-bot Bot commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

🚀 What's Changed

💥 Breaking Changes

No breaking changes

✨ Features

🐛 Bug Fixes

No bug fixes

📦 Dependencies

🔧 Other Changes

No other changes

👥 Contributors

coverage

Metric Coverage
Statements 85.8%
Branches 84.9%
Functions 92.5%
Lines 85.5%

Avg: 87.2% · e297a4a · Node lts/*

dependabot Bot and others added 3 commits August 12, 2026 12:05
Bumps the patch group with 1 update: [@cldmv/fix-headers](https://github.com/CLDMV/fix-headers).


Updates `@cldmv/fix-headers` from 1.3.7 to 1.3.9
- [Release notes](https://github.com/CLDMV/fix-headers/releases)
- [Commits](CLDMV/fix-headers@v1.3.7...v1.3.9)

---
updated-dependencies:
- dependency-name: "@cldmv/fix-headers"
  dependency-version: 1.3.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch
...

Signed-off-by: dependabot[bot] <support@github.com>
…19)

Bumps the patch group with 1 update:
[@cldmv/fix-headers](https://github.com/CLDMV/fix-headers).

Updates `@cldmv/fix-headers` from 1.3.7 to 1.3.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/CLDMV/fix-headers/releases">@​cldmv/fix-headers's
releases</a>.</em></p>
<blockquote>
<h2>v1.3.9</h2>
<h2>🚀 What's Changed</h2>
<h3>💥 Breaking Changes</h3>
<p><em>No breaking changes</em></p>
<h3>✨ Features</h3>
<p><em>No new features</em></p>
<h3>🐛 Bug Fixes</h3>
<p><em>No bug fixes</em></p>
<h3>📦 Dependencies</h3>
<ul>
<li>release: v1.3.9 - bump <code>@​types/node</code> from 26.1.1 to
26.1.2 in the patch… (<a
href="https://redirect.github.com/CLDMV/fix-headers/issues/23">#23</a>)
(6210b35)</li>
</ul>
<h3>🔧 Other Changes</h3>
<p><em>No other changes</em></p>
<h3>🏷️ Release Information</h3>
<ul>
<li>release: v1.3.9 - bump <code>@​types/node</code> from 26.1.1 to
26.1.2 in the patch… (<a
href="https://redirect.github.com/CLDMV/fix-headers/issues/23">#23</a>)
(6210b35)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/CLDMV/fix-headers/commit/6210b35223a3f23954a596c335bd482951bb8726"><code>6210b35</code></a>
release: v1.3.9 - bump <code>@​types/node</code> from 26.1.1 to 26.1.2
in the patch… (<a
href="https://redirect.github.com/CLDMV/fix-headers/issues/23">#23</a>)</li>
<li><a
href="https://github.com/CLDMV/fix-headers/commit/495b36083c8c0d1437fdfeb37e0265fca07720bc"><code>495b360</code></a>
release: v1.3.8 - never supersede release-relevant CI runs so release…
(<a
href="https://redirect.github.com/CLDMV/fix-headers/issues/20">#20</a>)</li>
<li>See full diff in <a
href="https://github.com/CLDMV/fix-headers/compare/v1.3.7...v1.3.9">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@cldmv/fix-headers&package-manager=npm_and_yarn&previous-version=1.3.7&new-version=1.3.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>
@cldmv-bot cldmv-bot Bot added ! release → master v4 flow: persistent next → master release PR (carries the next feature release) release Marks a pull request as a pending release — merge to publish a new version semver: patch This release contains only backwards-compatible bug fixes type: dependencies Relates to dependency updates, version bumps, or package management labels Aug 12, 2026
@cldmv-bot

cldmv-bot Bot commented Aug 12, 2026

Copy link
Copy Markdown
Contributor Author

🔒 Dependency Review

  • 0 vulnerable package(s)
  • 0 package(s) with incompatible licenses
  • 0 package(s) with invalid SPDX license definitions
  • 0 package(s) with unknown licenses
  • 0 denied package(s)
  • 0 package(s) with OpenSSF Scorecard score < 3

Full job summary

Shinrai and others added 2 commits August 17, 2026 07:11
…dlers

The static `import crypto from "crypto"` in uuid.mjs and every RFC/timestamp
version file made the package unbundlable for browser targets (esbuild
platform:"browser" fails to resolve "crypto"), and the internal Buffer-based
representation would still throw ReferenceError at runtime even past that.

Splits crypto/hex/hash access into isomorphic node+browser module pairs
(./rng, ./bytes, ./hash) selected via the package's "browser" export
condition, self-referenced from within the package. Node keeps its native
Buffer/crypto-backed fast paths; the browser variants use
globalThis.crypto.getRandomValues and hand-rolled MD5/SHA-1 (crypto.subtle
is async, which would break v3/v5's synchronous API). The internal UUID
buffer representation moves from Buffer to plain Uint8Array so it works in
both runtimes.

versions/timestamp/*, versions/issuer/*, and entropy-sources.mjs are dead
code never imported by uuid.mjs and were left untouched.

Verified against RFC 1321 (MD5) / FIPS 180-1 (SHA-1) test vectors, node:crypto
cross-checks, and an actual headless-Chromium run confirming zero Buffer/
node:crypto references and correct output (including the standard v3/v5 DNS
namespace vectors).

Fixes #21
@cldmv-bot cldmv-bot Bot added area: core Touches core library / runtime source code area: tests Touches test files, fixtures, or test infrastructure labels Aug 17, 2026
@cldmv-bot cldmv-bot Bot changed the title release: v1.1.8 - bump @cldmv/fix-headers from 1.3.7 to 1.3.9 in the… release: v1.2.0 - make UUID generation zero-node-builtin for browser… Aug 17, 2026
@cldmv-bot cldmv-bot Bot added semver: minor This release adds new functionality in a backwards-compatible way type: feature Implements new functionality — a PR or issue that adds a feature and removed semver: patch This release contains only backwards-compatible bug fixes labels Aug 17, 2026
@Shinrai
Shinrai merged commit ac54632 into master Aug 17, 2026
47 of 51 checks passed
@cldmv-bot
cldmv-bot Bot deleted the next branch August 17, 2026 17:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: core Touches core library / runtime source code area: tests Touches test files, fixtures, or test infrastructure ! release → master v4 flow: persistent next → master release PR (carries the next feature release) release Marks a pull request as a pending release — merge to publish a new version semver: minor This release adds new functionality in a backwards-compatible way type: dependencies Relates to dependency updates, version bumps, or package management type: feature Implements new functionality — a PR or issue that adds a feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant