Skip to content

chore(deps): update dependency ovsx to v1.2.0 - #248

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/ovsx-1.x-lockfile
Open

chore(deps): update dependency ovsx to v1.2.0#248
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/ovsx-1.x-lockfile

Conversation

@renovate

@renovate renovate Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
ovsx (source) 1.0.21.2.0 age confidence

Release Notes

eclipse-openvsx/openvsx (ovsx)

v1.2.0

Compare Source

Added
  • Add --follow-symlinks to publish, forwarding vsce's option of the same name so that the file walk recurses into symlinked directories instead of packing each symlink as a file. Needed for a node_modules assembled out of symlinks, as pnpm's is (#​368)
  • Add search command to search the registry for extensions, mirroring the web UI's search: --category, --target, --sort-by and --sort-order narrow the query, --size and --offset page through the results, and --json prints the registry's raw response (#​2154)
  • Add list command to print the extensions a namespace holds, sorted by name so the output stays stable across registries, with --json for the raw namespace metadata (#​2154)
  • Add show command to print an extension's metadata, mirroring vsce show: identity, publisher, rating, notices and a version history listing each version's target platforms (#​2149). namespace.extension@version reports a single version, --target scopes the report to one target platform, --all-versions lists every published version instead of the most recent few, and --json prints the registry's raw metadata
  • Add unpublish command to delete an extension or some of its versions, mirroring vsce unpublish (#​1958); requires a registry running version 1.2.0 or later, which unpublish checks for before deleting
  • publish checks the packaged extension's size against the limit reported by the registry's /api/version endpoint before uploading, instead of failing only after the upload completes (#​1953)
  • Add verify command to check a downloaded .vsix package's signature against the registry's public key, mirroring vsce verify-signature (#​993)
  • Add verify-signature command, verifying an already-extracted package/manifest/signature file trio entirely offline (no registry involved), matching vsce verify-signature's own command shape (#​993)
Fixed
  • Error messages naming a URL no longer include its query string, which for createNamespace, verifyPat, publish and delete carried the personal access token straight to stderr and into CI logs (#​2186)

  • A connection lost after a JSON response has started no longer leaves the command waiting on a body that is not coming: the response's own error is now what settles the request, so it fails with the reset rather than hanging (#​2186)

  • Requests now give up after 30 seconds without progress instead of hanging indefinitely when a server accepts a connection and then says nothing. OVSX_TIMEOUT overrides the duration in milliseconds and OVSX_TIMEOUT=0 disables it; it measures inactivity, so a large extension downloading slowly is unaffected, and it covers the trusted-publishing ID token request as well as the registry's own (#​2186)

  • Fix downloads that could be read before they were written. download resolved when the response ended rather than when the file was closed, and a write stream opens and flushes asynchronously, so a caller reading the path immediately afterwards could find the file empty or absent - which verify did, intermittently failing to read the public key it had just fetched. A failed download no longer touches the target path: the body is written beside it and renamed into place only once it has arrived whole, so a 404 or a dropped connection leaves what was there alone. A connection dropped mid-download now rejects rather than leaving the caller waiting forever (#​2185)

Changed
  • publish --trusted-publishing retries the token exchange when the registry answers that it could not verify the ID token (502, 503, 504), rather than failing the build on a blip reaching the identity provider. A refusal is never retried
  • publish --trusted-publishing requests a new token and retries once when the registry refuses the one it was publishing with. The issued token is short-lived and shared by every target platform of a release, so publishing a wide fan-out of large packages could outlive it and fail partway through. Targets that are refused together share one new token, and a token supplied with --pat is never retried
  • Bump minimum supported Node.js version to 22, matching the webui component

v1.1.1

Compare Source

v1.1.0

Compare Source

Added
  • Add an encrypted filestore as fallback to the system keychain if it cant be accessed (#​1950)
  • Add --allow-missing-repository option to the publish command, passed on to vsce to package an extension whose package.json has no repository field without asking for confirmation (#​1735)
  • Support trusted publishing: publish can exchange an OIDC ID token for a short-lived publishing token, via --trusted-publishing, --idToken and --oidcAudience
Changed
  • Replace keytar with cross-keychain to store credentials in the system keychain (#​1950)
  • Mask token input when using login command (#​1966
Dependencies
  • Bump js-yaml from 4.2.0 to 4.3.0 (#​1976)
  • Bump tar from 7.5.16 to 7.5.21 (#​1987)
  • Bump brace-expansion from 1.1.16 to 1.1.18 (#​2031)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/ovsx-1.x-lockfile branch from f1b3323 to 98723c5 Compare August 9, 2026 17:42
@renovate renovate Bot changed the title chore(deps): update dependency ovsx to v1.1.0 chore(deps): update dependency ovsx to v1.1.1 Aug 9, 2026
@renovate
renovate Bot force-pushed the renovate/ovsx-1.x-lockfile branch from 98723c5 to 711cb0b Compare September 10, 2026 13:17
@renovate renovate Bot changed the title chore(deps): update dependency ovsx to v1.1.1 chore(deps): update dependency ovsx to v1.2.0 Sep 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants