Skip to content

chore(deps): bump piscina from 3.2.0 to 5.2.0 - #174

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/piscina-5.2.0
Closed

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/piscina-5.2.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 12, 2026

Copy link
Copy Markdown
Contributor

Bumps piscina from 3.2.0 to 5.2.0.

Release notes

Sourced from piscina's releases.

v5.1.4

What's Changed

Full Changelog: piscinajs/piscina@v5.1.3...v5.1.4

v5.1.3

What's Changed

Full Changelog: piscinajs/piscina@v5.1.2...v5.1.3

v5.1.2

What's Changed

Full Changelog: piscinajs/piscina@v5.1.1...v5.1.2

v5.1.1

Full Changelog: piscinajs/piscina@v5.1.0...v5.1.1

v5.1.0

What's Changed

... (truncated)

Changelog

Sourced from piscina's changelog.

5.2.0 (2026-06-12)

Features

Bug Fixes

  • eagerly spawn workers up to maxThreads on cold-pool burst (#1043) (779c640)
  • include skipQueue in queueSize calculation (#1030) (b7d4d61)
  • interface name and add missing curly brace (#951) (8cd51f2)
  • onWorkerMessage gets skipped in Jest environment (#968) (54de192)

5.1.4 (2025-11-07)

Bug Fixes

5.1.3 (2025-07-09)

Features

5.1.2 (2025-06-26)

5.1.1 (2025-06-19)

Bug Fixes

  • prevent race condition in idle worker cleanup (#818) (cafae5d)

5.1.0 (2025-06-15)

Features

  • add explicit resource management support (#810) (d625bba)

Bug Fixes

... (truncated)

Commits
  • 8baaa1b chore(release): 5.2.0
  • 107b09a Merge commit from fork
  • 3eeaa37 docs: correct typo 'maintanance' in CONTRIBUTING.md (#1071)
  • b7d4d61 fix: include skipQueue in queueSize calculation (#1030)
  • 6beabe0 feat: Add idleThreads getter (#1059)
  • e104a89 chore(deps): Bump fast-uri from 3.0.6 to 3.1.2 in /docs in the npm_and_yarn g...
  • 779c640 fix: eagerly spawn workers up to maxThreads on cold-pool burst (#1043)
  • 469cb93 docs: Update Fastify listen() calls to use { port: 3000 } in docs and example...
  • d752afd [Backport v5] chore(deps): docs: Bump lodash from 4.17.23 to 4.18.1 in /docs ...
  • 6ed6284 chores: gh actions least privilege (#1013) (#1015)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by metcoder95, a new releaser for piscina since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [piscina](https://github.com/piscinajs/piscina) from 3.2.0 to 5.2.0.
- [Release notes](https://github.com/piscinajs/piscina/releases)
- [Changelog](https://github.com/piscinajs/piscina/blob/v5.2.0/CHANGELOG.md)
- [Commits](piscinajs/piscina@v3.2.0...v5.2.0)

---
updated-dependencies:
- dependency-name: piscina
  dependency-version: 5.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 12, 2026
@esp-edocg

Copy link
Copy Markdown

Hi @tuananh , unfortunately it looks like your 1 dependency, piscina, has a fairly serious vulnerability that breaks our audit checks, and the fix by updating to 5.2.0 doesn't work in Node 16 and 17 (Piscina now supports Node.js 20.x and higher). Node 16/17 reached EOL about 3 years ago, 22 is the current LTS version of node. Would you consider dropping 16/17 support and pushing out this fix?

@tuananh

tuananh commented Jun 23, 2026

Copy link
Copy Markdown
Owner

ive been meaning to do that for awhile.

@dependabot @github

dependabot Bot commented on behalf of github Jun 23, 2026

Copy link
Copy Markdown
Contributor Author

Looks like piscina is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Jun 23, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/piscina-5.2.0 branch June 23, 2026 12:23
@tuananh

tuananh commented Jun 23, 2026

Copy link
Copy Markdown
Owner

@esp-edocg Fixed in latest release

@esp-edocg

Copy link
Copy Markdown

Great! Thanks!
Just FYI in case someone else runs into this, after the update we had a few tests failing that were expecting NaN but now get null. Presumably this is due to some difference in the new version of piscina. In our case it didn't matter functionally so we just updated our tests.
Thanks again.

@tuananh

tuananh commented Jun 24, 2026

Copy link
Copy Markdown
Owner

Great! Thanks!
Just FYI in case someone else runs into this, after the update we had a few tests failing that were expecting NaN but now get null. Presumably this is due to some difference in the new version of piscina. In our case it didn't matter functionally so we just updated our tests.
Thanks again.

can you share the failed tests. i would like to take a look at that

@esp-edocg

Copy link
Copy Markdown

can you share the failed tests. i would like to take a look at that

Difficult to share because these are integration tests parsing large XML files in a private code base, but for example for the following XML:

        <element year="118">
            <money>
                9342
            </money>
            <money>
                0
            </money>
            <money>
                488294
            </money>
            <money repeat="6">
                0
            </money>
            <money>
                497636
            </money>
        </element>

We had a test that would look at the 3rd money node and expect value to be 488294 and repeat to be NaN using the jasmine expect toBeNaN matcher. That test used to pass but after the update repeat is now null and we switched to the toBeNull matcher so the test passes. In our case, whether it's NaN or null makes no functional difference so this is no problem.

@tuananh

tuananh commented Jun 24, 2026

Copy link
Copy Markdown
Owner

are you using number() xpath function to parse?

@esp-edocg

Copy link
Copy Markdown

Yes: number(@repeat)

@tuananh

tuananh commented Jun 24, 2026

Copy link
Copy Markdown
Owner

i added a test for that here

t.test('number() is NaN when absent', async (t) => {

can you try with npm install camaro@next to see if it fixes that problem.

i also add some perf improvement in there so see if it works for your use cases.

@esp-edocg

Copy link
Copy Markdown

Hm, I get an error when trying to run tests after installing that version Error: Cannot find module './lean-pool'
I'm not sure why that would happen...

@tuananh

tuananh commented Jun 24, 2026

Copy link
Copy Markdown
Owner

i forgot to publish some new files. my bad

@tuananh

tuananh commented Jun 24, 2026

Copy link
Copy Markdown
Owner

@esp-edocg i cut a test release npm i camaro@6.5.0-rc4.

      File: index.js
─────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
   1  const { transform } = require('camaro')
   2  
   3  async function main() {
   4      const result = await transform('<item value="42"/>', {
   5          present: 'number(/item/@value)',
   6          absent: 'number(/item/@missing)',
   7})
   8  
   9      console.log(result)
  10  }
  11  
  12  main()

output

{ present: 42, absent: NaN }

@esp-edocg

Copy link
Copy Markdown

That seems to work! Our tests are broken again 😄
Yes, it looks like you restored the previous functionality. We are now getting the NaN in the same 3 tests that had failed before and we had switched to expect nulls. All other tests in our suite pass.

@tuananh

tuananh commented Jun 24, 2026

Copy link
Copy Markdown
Owner

That seems to work! Our tests are broken again 😄 Yes, it looks like you restored the previous functionality. We are now getting the NaN in the same 3 tests that had failed before and we had switched to expect nulls. All other tests in our suite pass.

release 6.5.0

@esp-edocg

Copy link
Copy Markdown

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants