Skip to content

fix(deps): bump iconv-lite from 0.5.0 to 0.7.0#173

Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/iconv-lite-0.7.0
Closed

fix(deps): bump iconv-lite from 0.5.0 to 0.7.0#173
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/iconv-lite-0.7.0

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Aug 27, 2025

Bumps iconv-lite from 0.5.0 to 0.7.0.

Release notes

Sourced from iconv-lite's releases.

v0.7.0

🐞 Bug fixes

  • Handle split surrogate pairs when encoding utf8 - by @​yosion-p and @​ashtuchkin in #282:

    Handle a case where streaming utf8 encoder (converting js strings -> buffers) encounters surrogate pairs split between chunks (last character of one chunk is high surrogate and first character of the next chunk is a low surrogate).

  • Avoid false positives in encodingExists by using objects without a prototype - by @​bjohansebas in #328

    The encodingExists method could return incorrect results if the lookup matched properties inherited from the prototype of the object that stores the encodings, such as constructor and others. This change replaces that object with one that has no prototype, ensuring that only explicitly defined valid encodings in the library are considered. In addition, the fix is applied to the internal cache system to avoid the same kind of false positives

🚀 Improvements

  • Make explicit that decode() method supports Uint8Array input - by @​jardicc in #271
  • Remove compatibility check for StringDecoder.end method - by @​bjohansebas in #331

Other changes

New Contributors

Full Changelog: pillarjs/iconv-lite@v0.6.3...v0.7.0

Changelog

Sourced from iconv-lite's changelog.

0.7.0

🐞 Bug fixes

  • Handle split surrogate pairs when encoding utf8 - by @​yosion-p and @​ashtuchkin in #282:

    Handle a case where streaming utf8 encoder (converting js strings -> buffers) encounters surrogate pairs split between chunks (last character of one chunk is high surrogate and first character of the next chunk is a low surrogate).

  • Avoid false positives in encodingExists by using objects without a prototype - by @​bjohansebas in #328

    The encodingExists method could return incorrect results if the lookup matched properties inherited from the prototype of the object that stores the encodings, such as constructor and others. This change replaces that object with one that has no prototype, ensuring that only explicitly defined valid encodings in the library are considered. In addition, the fix is applied to the internal cache system to avoid the same kind of false positives

🚀 Improvements

  • Make explicit that decode() method supports Uint8Array input - by @​jardicc in #271
  • Remove compatibility check for StringDecoder.end method - by @​bjohansebas in #331

0.6.3 / 2021-05-23

  • Fix HKSCS encoding to prefer Big5 codes if both Big5 and HKSCS codes are possible (#264)

0.6.2 / 2020-07-08

  • Support Uint8Array-s decoding without conversion to Buffers, plus fix an edge case.

0.6.1 / 2020-06-28

  • Support Uint8Array-s directly when decoding (#246, by @​gyzerok)
  • Unify package.json version ranges to be strictly semver-compatible (#241)
  • Fix minor issue in UTF-32 decoder's endianness detection code.

0.6.0 / 2020-06-08

  • Updated 'gb18030' encoding to :2005 edition (see whatwg/encoding#22).
  • Removed iconv.extendNodeEncodings() mechanism. It was deprecated 5 years ago and didn't work in recent Node versions.
  • Reworked Streaming API behavior in browser environments to fix #204. Streaming API will be excluded by default in browser packs, saving ~100Kb bundle size, unless enabled explicitly using iconv.enableStreamingAPI(require('stream')).
  • Updates to development environment & tests:
    • Added ./test/webpack private package to test complex new use cases that need custom environment. It's tested as a separate job in Travis CI.
    • Updated generation code for the new EUC-KR index file format from Encoding Standard.
    • Removed Buffer() constructor in tests (#197 by @​gabrielschulhof).

... (truncated)

Commits
  • 165af71 release: 0.7.0 (#334)
  • ec88aea chore: remove object-assign (#338)
  • d8647ea docs(package.json): update repo name and add funding field (#337)
  • fc5925a Revert "chore: support node.js >=6, remove safe-buffer (#335)" (#336)
  • 4c2842a chore: support node.js >=6, remove safe-buffer (#335)
  • 1c2250f fix: add .git-blame-ignore-revs file for lint change
  • 2a31790 feat: adopt linter (#333)
  • 503f435 chore: update performance tests to use bench-node for benchmarking (#332)
  • 3aed296 docs: reorganize README
  • 0a2f8c5 fix: remove compatibility check for StringDecoder.end method (#331)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by bsebas, a new releaser for iconv-lite since your current version.


Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [iconv-lite](https://github.com/pillarjs/iconv-lite) from 0.5.0 to 0.7.0.
- [Release notes](https://github.com/pillarjs/iconv-lite/releases)
- [Changelog](https://github.com/pillarjs/iconv-lite/blob/master/Changelog.md)
- [Commits](pillarjs/iconv-lite@v0.5.0...v0.7.0)

---
updated-dependencies:
- dependency-name: iconv-lite
  dependency-version: 0.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 27, 2025
@github-actions github-actions bot enabled auto-merge August 27, 2025 19:52
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Dec 17, 2025

Superseded by #183.

@dependabot dependabot bot closed this Dec 17, 2025
auto-merge was automatically disabled December 17, 2025 12:01

Pull request was closed

@dependabot dependabot bot deleted the dependabot/npm_and_yarn/iconv-lite-0.7.0 branch December 17, 2025 12:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants