Skip to content

build(deps-dev): bump canonicalize from 4.0.0 to 5.1.0 in /packages/trilean - #59

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/packages/trilean/canonicalize-5.0.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/packages/trilean/canonicalize-5.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown

Bumps canonicalize from 4.0.0 to 5.1.0.

Release notes

Sourced from canonicalize's releases.

v5.0.0

Breaking Changes

  • Output that was not valid JSON is fixed. Properties whose value has no JSON representation emitted the bare token undefined, and sparse arrays emitted holes — neither parses:
    • { key: undefined } produced {"key":undefined}, now {}
    • [ , , 1] produced [,,1], now [null,null,1]
    • [function () {}] produced [] — losing an element — now [null]
  • Boxed primitives now serialize as their primitive value, as JSON.stringify does: new Number(5) was {} and is now 5; new String('x') was {"0":"x"} and is now "x".
  • toJSON() returning undefined now drops the property instead of emitting {"k":undefined}.
  • Node.js 22 or later is required. The previous >=18 floor was already broken, since String.prototype.isWellFormed() needs Node 20+.

Any of these change the canonical form, and therefore any signature over it. If you have stored signatures produced by 4.0.0 over documents in these shapes, they will not verify against 5.0.0 output.

Fixes

  • Deep nesting no longer overflows the stack. The serializer is now iterative, so nesting depth is bounded by heap rather than call stack. 4.0.0 threw above ~1,000 levels; 50,000+ now works. This closes a denial-of-service vector for untrusted input.

Performance

~1.3x faster than 4.0.0 depending on payload

Documentation

  • New README section: best practices for signw duplicate property names are resolved before canonicalize() sees the data.
Commits
  • 31fb117 Stage releases instead of publishing them directly
  • 30454e1 5.1.0
  • cc99a8b Install with npm install when publishing
  • 9faeed3 Publish from CI with trusted publishing and provenance
  • 80f1cb7 Link the JCS library comparison from the README
  • c5ac53e Cover and document the CommonJS entry point
  • 94c201c Add a default export to package.json
  • 7d97c70 Drop the introductory paragraph
  • e7b5eeb Correct what the duplicate-key case actually costs
  • 3fe620d Document best practices for signature schemes
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for canonicalize since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 21, 2026
@dependabot dependabot Bot changed the title build(deps-dev): bump canonicalize from 4.0.0 to 5.0.0 in /packages/trilean build(deps-dev): bump canonicalize from 4.0.0 to 5.1.0 in /packages/trilean Sep 29, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/packages/trilean/canonicalize-5.0.0 branch from c08a3eb to 61e223f Compare September 29, 2026 22:57
Bumps [canonicalize](https://github.com/erdtman/canonicalize) from 4.0.0 to 5.1.0.
- [Release notes](https://github.com/erdtman/canonicalize/releases)
- [Commits](erdtman/canonicalize@v4.0.0...v5.1.0)

---
updated-dependencies:
- dependency-name: canonicalize
  dependency-version: 5.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/packages/trilean/canonicalize-5.0.0 branch from 61e223f to ba7a2d6 Compare September 29, 2026 23:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants