Skip to content

fix(deps): bump iconv-lite from 0.5.0 to 0.7.1#183

Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/iconv-lite-0.7.1
Closed

fix(deps): bump iconv-lite from 0.5.0 to 0.7.1#183
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/iconv-lite-0.7.1

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 17, 2025

Bumps iconv-lite from 0.5.0 to 0.7.1.

Release notes

Sourced from iconv-lite's releases.

v0.7.1

What's Changed

🚀 Improvements

Other changes

New Contributors

Full Changelog: pillarjs/iconv-lite@v0.7.0...v0.7.1

v0.7.0

🐞 Bug fixes

  • Handle split surrogate pairs when encoding utf8 - by @​yosion-p and @​ashtuchkin in #282:

    Handle a case where streaming utf8 encoder (converting js strings -> buffers) encounters surrogate pairs split between chunks (last character of one chunk is high surrogate and first character of the next chunk is a low surrogate).

  • Avoid false positives in encodingExists by using objects without a prototype - by @​bjohansebas in #328

    The encodingExists method could return incorrect results if the lookup matched properties inherited from the prototype of the object that stores the encodings, such as constructor and others. This change replaces that object with one that has no prototype, ensuring that only explicitly defined valid encodings in the library are considered. In addition, the fix is applied to the internal cache system to avoid the same kind of false positives

🚀 Improvements

  • Make explicit that decode() method supports Uint8Array input - by @​jardicc in #271
  • Remove compatibility check for StringDecoder.end method - by @​bjohansebas in #331

Other changes

... (truncated)

Changelog

Sourced from iconv-lite's changelog.

0.7.1

🚀 Improvements

0.7.0

🐞 Bug fixes

  • Handle split surrogate pairs when encoding utf8 - by @​yosion-p and @​ashtuchkin in #282:

    Handle a case where streaming utf8 encoder (converting js strings -> buffers) encounters surrogate pairs split between chunks (last character of one chunk is high surrogate and first character of the next chunk is a low surrogate).

  • Avoid false positives in encodingExists by using objects without a prototype - by @​bjohansebas in #328

    The encodingExists method could return incorrect results if the lookup matched properties inherited from the prototype of the object that stores the encodings, such as constructor and others. This change replaces that object with one that has no prototype, ensuring that only explicitly defined valid encodings in the library are considered. In addition, the fix is applied to the internal cache system to avoid the same kind of false positives

🚀 Improvements

  • Make explicit that decode() method supports Uint8Array input - by @​jardicc in #271
  • Remove compatibility check for StringDecoder.end method - by @​bjohansebas in #331

0.6.3 / 2021-05-23

  • Fix HKSCS encoding to prefer Big5 codes if both Big5 and HKSCS codes are possible (#264)

0.6.2 / 2020-07-08

  • Support Uint8Array-s decoding without conversion to Buffers, plus fix an edge case.

0.6.1 / 2020-06-28

  • Support Uint8Array-s directly when decoding (#246, by @​gyzerok)
  • Unify package.json version ranges to be strictly semver-compatible (#241)
  • Fix minor issue in UTF-32 decoder's endianness detection code.

0.6.0 / 2020-06-08

  • Updated 'gb18030' encoding to :2005 edition (see whatwg/encoding#22).
  • Removed iconv.extendNodeEncodings() mechanism. It was deprecated 5 years ago and didn't work in recent Node versions.
  • Reworked Streaming API behavior in browser environments to fix #204. Streaming API will be excluded by default in browser packs, saving ~100Kb bundle size, unless enabled explicitly using iconv.enableStreamingAPI(require('stream')).

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by bsebas, a new releaser for iconv-lite since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [iconv-lite](https://github.com/pillarjs/iconv-lite) from 0.5.0 to 0.7.1.
- [Release notes](https://github.com/pillarjs/iconv-lite/releases)
- [Changelog](https://github.com/pillarjs/iconv-lite/blob/master/Changelog.md)
- [Commits](pillarjs/iconv-lite@v0.5.0...v0.7.1)

---
updated-dependencies:
- dependency-name: iconv-lite
  dependency-version: 0.7.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Dec 17, 2025
@github-actions github-actions bot enabled auto-merge December 17, 2025 12:01
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Jan 14, 2026

Superseded by #184.

@dependabot dependabot bot closed this Jan 14, 2026
auto-merge was automatically disabled January 14, 2026 12:02

Pull request was closed

@dependabot dependabot bot deleted the dependabot/npm_and_yarn/iconv-lite-0.7.1 branch January 14, 2026 12:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants