Bump @noble/hashes from 1.8.0 to 2.3.0 - #7
Conversation
Bumps [@noble/hashes](https://github.com/paulmillr/noble-hashes) from 1.8.0 to 2.3.0. - [Release notes](https://github.com/paulmillr/noble-hashes/releases) - [Commits](paulmillr/noble-hashes@1.8.0...2.3.0) --- updated-dependencies: - dependency-name: "@noble/hashes" dependency-version: 2.3.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
17f2c40 to
ebf3945
Compare
|
Not landed — @noble/hashes stays pinned at ^1.8.0. This bump was re-tested on its own against current main (d2641a1) and it fails the first step of this repo's gate, v2 drops the per-algorithm export subpaths ('./sha256', './sha512') that both of those modules import. It fails alone, with the @noble/ed25519 v3 bump held back, so it is not collateral from that PR — it is a genuine breaking change for this lab. Clearing it means rewriting src/, and the standing policy here is to pin a dependency back rather than edit demo source to suit it. So this stays an open question for a human: it needs an intentional migration of the two import sites to v2's entry points, not an automated bump. The rest of this repo's Dependabot batch did land on main in d2641a1 — vitest 3.2.6 -> 4.1.10, @axe-core/playwright 4.12.1 -> 4.13.0, and dependabot/fetch-metadata v2 -> v3 — verified against the full local gate (typecheck; 132 unit tests; vite build; 11 Playwright a11y/behavior tests incl. axe WCAG A/AA at desktop and 380px). Closing rather than leaving it open: Dependabot will reopen this bump if it is still applicable. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps @noble/hashes from 1.8.0 to 2.3.0.
Release notes
Sourced from @noble/hashes's releases.
... (truncated)
Commits
8060cc8Release 2.3.0.16f8af9Update workflow and benchmarks734220fUpdate jsbt to 0.6.5fd3d3c3Minor improvements3654405test: use new syntaxe222e2dutils: minor fixesef7ae52Improve speed. Reduce bundle size. Reduce mem usage.26b194aRename npm actione89d6faBump jsbt to v0.6de8098aMove benchmarks top-levelMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@noble/hashessince your current version.