ui: Bump npm package versions (#4406)

Bumps the npm_and_yarn group with 4 updates in the /ui directory:
[@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk),
[vega](https://github.com/vega/vega),
[js-yaml](https://github.com/nodeca/js-yaml) and
[jws](https://github.com/brianloveswords/node-jws).

Also update zod from v3->v4 to fix an unmet peer dependency

Updates `@modelcontextprotocol/sdk` from 1.17.1 to 1.25.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/modelcontextprotocol/typescript-sdk/releases"><code>@​modelcontextprotocol/sdk</code>'s
releases</a>.</em></p>
<blockquote>
<h2>v1.25.2</h2>
<h2>What's Changed</h2>
<ul>
<li>ci: trigger workflow on v1.x branch by <a
href="https://github.com/felixweinberger"><code>@​felixweinberger</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1319">modelcontextprotocol/typescript-sdk#1319</a></li>
<li>fix: README badges links destinations by <a
href="https://github.com/antonpk1"><code>@​antonpk1</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/907">modelcontextprotocol/typescript-sdk#907</a></li>
<li>fix: prevent ReDoS in UriTemplate regex patterns (v1.x backport) by
<a href="https://github.com/pcarleton"><code>@​pcarleton</code></a> in
<a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1365">modelcontextprotocol/typescript-sdk#1365</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/antonpk1"><code>@​antonpk1</code></a>
made their first contribution in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/907">modelcontextprotocol/typescript-sdk#907</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/modelcontextprotocol/typescript-sdk/compare/1.25.1...v1.25.2">https://github.com/modelcontextprotocol/typescript-sdk/compare/1.25.1...v1.25.2</a></p>
<h2>1.25.1</h2>
<h2>What's Changed</h2>
<ul>
<li>spec types - backwards compatibility changes by <a
href="https://github.com/KKonstantinov"><code>@​KKonstantinov</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1306">modelcontextprotocol/typescript-sdk#1306</a></li>
<li>chore: bump version for patch fix by <a
href="https://github.com/felixweinberger"><code>@​felixweinberger</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1307">modelcontextprotocol/typescript-sdk#1307</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/modelcontextprotocol/typescript-sdk/compare/1.25.0...1.25.1">https://github.com/modelcontextprotocol/typescript-sdk/compare/1.25.0...1.25.1</a></p>
<h2>1.25.0</h2>
<h2>What's Changed</h2>
<ul>
<li>list changed handlers on client constructor by <a
href="https://github.com/mattzcarey"><code>@​mattzcarey</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1206">modelcontextprotocol/typescript-sdk#1206</a></li>
<li>Role - moved from inline to reusable type by <a
href="https://github.com/KKonstantinov"><code>@​KKonstantinov</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1221">modelcontextprotocol/typescript-sdk#1221</a></li>
<li>fix: use versioned npm tag for non-main branch releases by <a
href="https://github.com/pcarleton"><code>@​pcarleton</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1236">modelcontextprotocol/typescript-sdk#1236</a></li>
<li>No automatic completion support unless needed - Revisited yet again
by <a href="https://github.com/cliffhall"><code>@​cliffhall</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1237">modelcontextprotocol/typescript-sdk#1237</a></li>
<li>fix: Support updating output schema by <a
href="https://github.com/vincent0426"><code>@​vincent0426</code></a> in
<a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1048">modelcontextprotocol/typescript-sdk#1048</a></li>
<li>Remove type dependency on <code>@​cfworker/json-schema</code> by <a
href="https://github.com/LucaButBoring"><code>@​LucaButBoring</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1229">modelcontextprotocol/typescript-sdk#1229</a></li>
<li>Relocate tests under <code>/test</code> by <a
href="https://github.com/KKonstantinov"><code>@​KKonstantinov</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1220">modelcontextprotocol/typescript-sdk#1220</a></li>
<li>Fix tsconfig: remove tests by <a
href="https://github.com/KKonstantinov"><code>@​KKonstantinov</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1240">modelcontextprotocol/typescript-sdk#1240</a></li>
<li>tsconfig - tests and build fix by <a
href="https://github.com/KKonstantinov"><code>@​KKonstantinov</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1243">modelcontextprotocol/typescript-sdk#1243</a></li>
<li>fix a typo in examples README by <a
href="https://github.com/DaleSeo"><code>@​DaleSeo</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1246">modelcontextprotocol/typescript-sdk#1246</a></li>
<li>Protocol date validation by <a
href="https://github.com/mattzcarey"><code>@​mattzcarey</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1247">modelcontextprotocol/typescript-sdk#1247</a></li>
<li>Flaky test fix on Types.test.ts by <a
href="https://github.com/KKonstantinov"><code>@​KKonstantinov</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1244">modelcontextprotocol/typescript-sdk#1244</a></li>
<li>SPEC COMPLIANCE: Remove loose/passthrough types not allowed/defined
by MCP spec + Task types by <a
href="https://github.com/KKonstantinov"><code>@​KKonstantinov</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1242">modelcontextprotocol/typescript-sdk#1242</a></li>
<li>Follow-up fixes for PR <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1242">#1242</a>
by <a
href="https://github.com/felixweinberger"><code>@​felixweinberger</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1274">modelcontextprotocol/typescript-sdk#1274</a></li>
<li>Update server examples and docs by <a
href="https://github.com/DaleSeo"><code>@​DaleSeo</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1285">modelcontextprotocol/typescript-sdk#1285</a></li>
<li>Update TypeScript config to ES2020 to fix AJV imports by <a
href="https://github.com/mattzcarey"><code>@​mattzcarey</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1297">modelcontextprotocol/typescript-sdk#1297</a></li>
<li>Fix Zod v4 schema description extraction by <a
href="https://github.com/felixweinberger"><code>@​felixweinberger</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1296">modelcontextprotocol/typescript-sdk#1296</a></li>
<li>Add optional description field to Implementation schema by <a
href="https://github.com/calclavia"><code>@​calclavia</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1295">modelcontextprotocol/typescript-sdk#1295</a></li>
<li>Add theme property to Icon schema by <a
href="https://github.com/DaleSeo"><code>@​DaleSeo</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1290">modelcontextprotocol/typescript-sdk#1290</a></li>
<li>feat: fetch transport by <a
href="https://github.com/mattzcarey"><code>@​mattzcarey</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1209">modelcontextprotocol/typescript-sdk#1209</a></li>
<li>chore: bump version for release by <a
href="https://github.com/felixweinberger"><code>@​felixweinberger</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1301">modelcontextprotocol/typescript-sdk#1301</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/vincent0426"><code>@​vincent0426</code></a>
made their first contribution in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1048">modelcontextprotocol/typescript-sdk#1048</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/modelcontextprotocol/typescript-sdk/compare/1.24.3...1.25.0">https://github.com/modelcontextprotocol/typescript-sdk/compare/1.24.3...1.25.0</a></p>
<h2>1.24.3</h2>
<h2>What's Changed</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/modelcontextprotocol/typescript-sdk/commit/b392f02ffcf37c088dbd114fedf25026ec3913d3"><code>b392f02</code></a>
fix: prevent ReDoS in UriTemplate regex patterns (v1.x backport) (<a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1365">#1365</a>)</li>
<li><a
href="https://github.com/modelcontextprotocol/typescript-sdk/commit/a0c9b13484748acab9e5dc8317a7e89c06b52e37"><code>a0c9b13</code></a>
fix: README badges links destinations (<a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/907">#907</a>)</li>
<li><a
href="https://github.com/modelcontextprotocol/typescript-sdk/commit/6dd08ac60804f30fd3c4ff71d60699c1fcbf5f68"><code>6dd08ac</code></a>
ci: trigger workflow on v1.x branch (<a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1319">#1319</a>)</li>
<li><a
href="https://github.com/modelcontextprotocol/typescript-sdk/commit/384311b9b8452017f5f81819c133dc45c667cfa4"><code>384311b</code></a>
chore: bump version for patch fix (<a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1307">#1307</a>)</li>
<li><a
href="https://github.com/modelcontextprotocol/typescript-sdk/commit/fb07af810b51003c338dc4885a9e42f54519f9af"><code>fb07af8</code></a>
spec types - backwards compatibility changes (<a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1306">#1306</a>)</li>
<li><a
href="https://github.com/modelcontextprotocol/typescript-sdk/commit/2b20ca95735e82a2ba7c47c9bd303057601b7f8e"><code>2b20ca9</code></a>
chore: bump version for release (<a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1301">#1301</a>)</li>
<li><a
href="https://github.com/modelcontextprotocol/typescript-sdk/commit/67ba7adbb73a0e40c2c350c74280ae3ac0aa47d6"><code>67ba7ad</code></a>
feat: fetch transport (<a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1209">#1209</a>)</li>
<li><a
href="https://github.com/modelcontextprotocol/typescript-sdk/commit/1d425471342ceb414aa47eaca0173d3f35014633"><code>1d42547</code></a>
Add theme property to Icon schema (<a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1290">#1290</a>)</li>
<li><a
href="https://github.com/modelcontextprotocol/typescript-sdk/commit/54303b4f8c94c5ce0fdc6598d5957e7db5f9eccb"><code>54303b4</code></a>
Add optional description field to Implementation schema (<a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1295">#1295</a>)</li>
<li><a
href="https://github.com/modelcontextprotocol/typescript-sdk/commit/9941294df9c3b9121c042a72419248bf83d45c5c"><code>9941294</code></a>
Fix Zod v4 schema description extraction (<a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1296">#1296</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/modelcontextprotocol/typescript-sdk/compare/1.17.1...v1.25.2">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~pcarleton">pcarleton</a>, a new releaser
for <code>@​modelcontextprotocol/sdk</code> since your current
version.</p>
</details>
<br />

Updates `vega` from 5.30.0 to 5.32.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vega/vega/releases">vega's
releases</a>.</em></p>
<blockquote>
<h2>v5.32.0</h2>
<p>Changes since v5.31.0</p>
<p><strong>vega-expression</strong></p>
<ul>
<li>Add base64 string encoder/decoder to <code>vega-expression</code>
and <code>vega-interpreter</code> (via <a
href="https://redirect.github.com/vega/vega/issues/4009">#4009</a>).
(Thanks <a
href="https://github.com/hydrosquall"><code>@​hydrosquall</code></a>!)</li>
</ul>
<p><strong>vega-typings</strong></p>
<ul>
<li>Add Typescript Types for <code>vega-loader</code> (via <a
href="https://redirect.github.com/vega/vega/issues/4000">#4000</a>).
(Thanks <a
href="https://github.com/hydrosquall"><code>@​hydrosquall</code></a>!)</li>
</ul>
<p><strong>docs</strong></p>
<ul>
<li>Correct data year citation in dorling-cartogram example (via <a
href="https://redirect.github.com/vega/vega/issues/4006">#4006</a>).
(Thanks <a
href="https://github.com/dsmedia"><code>@​dsmedia</code></a>!)</li>
<li>Update typo in vega.timeFloor description (via <a
href="https://redirect.github.com/vega/vega/issues/4010">#4010</a>).
(Thanks <a
href="https://github.com/hydrosquall"><code>@​hydrosquall</code></a>!)</li>
<li>Add Security Advisory Policy for Vega (via <a
href="https://redirect.github.com/vega/vega/issues/4008">#4008</a>).
(Thanks <a
href="https://github.com/hydrosquall"><code>@​hydrosquall</code></a>!)</li>
<li>Replace redirect url in <code>expressions.md</code> (via <a
href="https://redirect.github.com/vega/vega/issues/3996">#3996</a>).
(Thanks <a
href="https://github.com/dangotbanned"><code>@​dangotbanned</code></a>!)</li>
<li>correct queries to query in <code>crossfilter.md</code> (via <a
href="https://redirect.github.com/vega/vega/issues/4005">#4005</a>).
(Thanks <a
href="https://github.com/danmarshall"><code>@​danmarshall</code></a>!)</li>
</ul>
<h2>v5.31.0</h2>
<p>changes since v5.30.0</p>
<p><strong>vega-utils</strong></p>
<ul>
<li>use <code>Object.hasOwn</code> instead of
<code>Object.prototype.hasOwnProperty</code> (via <a
href="https://redirect.github.com/vega/vega/issues/3951">#3951</a>).
(Thanks <a
href="https://github.com/domoritz"><code>@​domoritz</code></a>!)</li>
</ul>
<p><strong>vega-parser</strong></p>
<ul>
<li>Add discrete legend type (via <a
href="https://redirect.github.com/vega/vega/issues/3957">#3957</a>).
(Thanks <a
href="https://github.com/hydrosquall"><code>@​hydrosquall</code></a>!)</li>
</ul>
<p><strong>vega-functions</strong></p>
<ul>
<li>Add sort function to vega-functions (and vega-interpreter) (via <a
href="https://redirect.github.com/vega/vega/issues/3973">#3973</a>).
(Thanks <a
href="https://github.com/hydrosquall"><code>@​hydrosquall</code></a>!)</li>
</ul>
<p><strong>vega-selections</strong></p>
<ul>
<li>Add field predicate types to selectionTest (via <a
href="https://redirect.github.com/vega/vega/issues/3675">#3675</a>).
(Thanks <a
href="https://github.com/jonathanzong"><code>@​jonathanzong</code></a>!)</li>
</ul>
<p><strong>monorepo</strong></p>
<ul>
<li>Replace flights-5k.json external reference (via <a
href="https://redirect.github.com/vega/vega/issues/3999">#3999</a>).
(Thanks <a
href="https://github.com/dwootton"><code>@​dwootton</code></a>!)</li>
</ul>
<p><strong>docs</strong></p>
<ul>
<li>Update packed bubble example (via <a
href="https://redirect.github.com/vega/vega/issues/3955">#3955</a>).
(Thanks <a
href="https://github.com/PBI-David"><code>@​PBI-David</code></a>!)</li>
<li>Correct typo in production rules documentation (via <a
href="https://redirect.github.com/vega/vega/issues/3958">#3958</a>).
(Thanks <a
href="https://github.com/shanebruggeman"><code>@​shanebruggeman</code></a>!)</li>
<li>Update README.md to fix broken link to current roadmap (via <a
href="https://redirect.github.com/vega/vega/issues/3979">#3979</a>).
(Thanks <a href="https://github.com/cahogan"><code>@​cahogan</code></a>
&amp; <a
href="https://github.com/joelostblom"><code>@​joelostblom</code></a>!)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vega/vega/commit/c46889df45c5ea4286e7cef1ac3041c4a3d82c78"><code>c46889d</code></a>
chore: update vega-cli to v5.32.0 (<a
href="https://redirect.github.com/vega/vega/issues/4015">#4015</a>)</li>
<li><a
href="https://github.com/vega/vega/commit/2fe2e63de54821d858bdcbe2aa38e72a9f2e6234"><code>2fe2e63</code></a>
chore: v5.32.0 (<a
href="https://redirect.github.com/vega/vega/issues/4014">#4014</a>)</li>
<li><a
href="https://github.com/vega/vega/commit/81ed01185b6b27a31ad6677bf5a0462b280b5964"><code>81ed011</code></a>
chore: remove extra space in test name</li>
<li><a
href="https://github.com/vega/vega/commit/6026887a306557d7569bab290be072304f6e13f6"><code>6026887</code></a>
fix: correct data year citation in dorling-cartogram example (<a
href="https://redirect.github.com/vega/vega/issues/4006">#4006</a>)</li>
<li><a
href="https://github.com/vega/vega/commit/a3af49e9d7004895d1c06417718611106dcb5418"><code>a3af49e</code></a>
feat: Add base64 string encoder/decoder to <code>vega-expression</code>
and `vega-interp...</li>
<li><a
href="https://github.com/vega/vega/commit/cd88cc89e4238d2384f32118896a662a09feb5a8"><code>cd88cc8</code></a>
fix(docs): Update typo in vega.timeFloor description (<a
href="https://redirect.github.com/vega/vega/issues/4010">#4010</a>)</li>
<li><a
href="https://github.com/vega/vega/commit/694560c0aa576df8b6c5f0f7d202ac82233e6966"><code>694560c</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/vega/vega/commit/560aeecbbe99edb3022071fbe8c756d04f2e57bc"><code>560aeec</code></a>
docs: Add Security Advisory Policy for <code>vega</code> (<a
href="https://redirect.github.com/vega/vega/issues/4008">#4008</a>)</li>
<li><a
href="https://github.com/vega/vega/commit/0b6a11433a7344763d70f2cb7224efa45556834d"><code>0b6a114</code></a>
feat(vega-typings): add Typescript Types for <code>vega-loader</code>
(<a
href="https://redirect.github.com/vega/vega/issues/4000">#4000</a>)</li>
<li><a
href="https://github.com/vega/vega/commit/b83b8e5c420e13a1a2ccb820ada4c05e3f076510"><code>b83b8e5</code></a>
docs: Replace redirect url in <code>expressions.md</code> (<a
href="https://redirect.github.com/vega/vega/issues/3996">#3996</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vega/vega/compare/v5.30.0...v5.32.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `body-parser` from 2.2.0 to 2.2.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/expressjs/body-parser/releases">body-parser's
releases</a>.</em></p>
<blockquote>
<h2>v2.2.2</h2>
<h2>What's Changed</h2>
<ul>
<li>docs: update README links by <a
href="https://github.com/efekrskl"><code>@​efekrskl</code></a> in <a
href="https://redirect.github.com/expressjs/body-parser/pull/673">expressjs/body-parser#673</a></li>
<li>docs: release notes for the v1.20.4 release by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/674">expressjs/body-parser#674</a></li>
<li>docs: update URL-encoded parser description to include ISO-8859-1
encoding support by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/679">expressjs/body-parser#679</a></li>
<li>docs: use standard jsdoc tags everywhere by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/677">expressjs/body-parser#677</a></li>
<li>deps: qs@^6.14.1 by <a
href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a>
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/689">expressjs/body-parser#689</a></li>
<li>refactor(json): simplify strict mode error string construction by <a
href="https://github.com/jonchurch"><code>@​jonchurch</code></a> in <a
href="https://redirect.github.com/expressjs/body-parser/pull/693">expressjs/body-parser#693</a></li>
<li>Release: 2.2.2 by <a
href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a>
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/691">expressjs/body-parser#691</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/efekrskl"><code>@​efekrskl</code></a>
made their first contribution in <a
href="https://redirect.github.com/expressjs/body-parser/pull/673">expressjs/body-parser#673</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/expressjs/body-parser/compare/v2.2.1...v2.2.2">https://github.com/expressjs/body-parser/compare/v2.2.1...v2.2.2</a></p>
<h2>v2.2.1</h2>
<h2>Important: Security</h2>
<ul>
<li>Security fix for <a
href="https://www.cve.org/CVERecord?id=CVE-2025-13466">CVE-2025-13466</a>
(<a
href="https://github.com/expressjs/body-parser/security/advisories/GHSA-wqch-xfxh-vrr4">GHSA-wqch-xfxh-vrr4</a>)</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>ci: add dependabot by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/593">expressjs/body-parser#593</a></li>
<li>ci: use full SHAs for github action versions by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/594">expressjs/body-parser#594</a></li>
<li>deps: type-is@^2.0.1 by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/599">expressjs/body-parser#599</a></li>
<li>build(deps): bump actions/setup-node from 4.3.0 to 4.4.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/609">expressjs/body-parser#609</a></li>
<li>build(deps): bump github/codeql-action from 3.28.13 to 3.28.15 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/610">expressjs/body-parser#610</a></li>
<li>build(deps-dev): bump eslint-plugin-promise from 6.1.1 to 6.6.0 by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/611">expressjs/body-parser#611</a></li>
<li>build(deps-dev): bump eslint-plugin-import from 2.27.5 to 2.31.0 by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/613">expressjs/body-parser#613</a></li>
<li>build(deps-dev): bump eslint-plugin-markdown from 3.0.0 to 3.0.1 by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/612">expressjs/body-parser#612</a></li>
<li>ci: add codeql github workflows scanning by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/614">expressjs/body-parser#614</a></li>
<li>ci: update CodeQL config to ignore the test directory by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/615">expressjs/body-parser#615</a></li>
<li>build(deps): bump actions/download-artifact from 4.2.1 to 4.3.0 by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/620">expressjs/body-parser#620</a></li>
<li>build(deps): bump github/codeql-action from 3.28.15 to 3.28.16 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/619">expressjs/body-parser#619</a></li>
<li>chore(deps): unpin devDependencies by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/616">expressjs/body-parser#616</a></li>
<li>ci: add node.js 24 to test matrix by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/621">expressjs/body-parser#621</a></li>
<li>build(deps): bump github/codeql-action from 3.28.16 to 3.28.18 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/623">expressjs/body-parser#623</a></li>
<li>build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/624">expressjs/body-parser#624</a></li>
<li>chore: add funding to package.json by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/617">expressjs/body-parser#617</a></li>
<li>build(deps): bump github/codeql-action from 3.28.18 to 3.29.2 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/625">expressjs/body-parser#625</a></li>
<li>build(deps): bump github/codeql-action from 3.29.2 to 3.29.5 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/630">expressjs/body-parser#630</a></li>
<li>refactor: move common request validation to read function by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/600">expressjs/body-parser#600</a></li>
<li>deps: bump iconv-lite by <a
href="https://github.com/bjohansebas"><code>@​bjohansebas</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/631">expressjs/body-parser#631</a></li>
<li>doc: pull beta changelog forward into 2.0.0 by <a
href="https://github.com/jonchurch"><code>@​jonchurch</code></a> in <a
href="https://redirect.github.com/expressjs/body-parser/pull/629">expressjs/body-parser#629</a></li>
<li>refactor: optimize raw and text parsers with shared passthrough
function by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/634">expressjs/body-parser#634</a></li>
<li>build(deps): bump actions/checkout from 4.2.2 to 5.0.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/640">expressjs/body-parser#640</a></li>
<li>build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/639">expressjs/body-parser#639</a></li>
<li>build(deps): bump actions/setup-node from 4.4.0 to 5.0.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/636">expressjs/body-parser#636</a></li>
<li>build(deps): bump actions/download-artifact from 4.3.0 to 5.0.0 by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/637">expressjs/body-parser#637</a></li>
<li>build(deps): bump github/codeql-action from 3.29.7 to 3.30.5 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/638">expressjs/body-parser#638</a></li>
<li>deps: raw-body@^3.0.1 by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/641">expressjs/body-parser#641</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/expressjs/body-parser/blob/master/HISTORY.md">body-parser's
changelog</a>.</em></p>
<blockquote>
<h1>2.2.2 / 2026-01-07</h1>
<ul>
<li>deps: qs@^6.14.1</li>
<li>refactor(json): simplify strict mode error string construction</li>
</ul>
<h1>2.2.1 / 2025-11-24</h1>
<ul>
<li>Security fix for <a
href="https://github.com/expressjs/body-parser/security/advisories/GHSA-wqch-xfxh-vrr4">GHSA-wqch-xfxh-vrr4</a></li>
<li>deps:
<ul>
<li>type-is@^2.0.1</li>
<li>iconv-lite@^0.7.0
<ul>
<li>Handle split surrogate pairs when encoding UTF-8</li>
<li>Avoid false positives in <code>encodingExists</code> by using
prototype-less objects</li>
</ul>
</li>
<li>raw-body@^3.0.1</li>
<li>debug@^4.4.3</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/expressjs/body-parser/commit/3d248660b2e8b66732b232d7c758517fbf2420a6"><code>3d24866</code></a>
2.2.2 (<a
href="https://redirect.github.com/expressjs/body-parser/issues/691">#691</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/8474a984c3ba36a1b4328ce019833b99caa0f08f"><code>8474a98</code></a>
refactor(json): simplify strict mode error string construction (<a
href="https://redirect.github.com/expressjs/body-parser/issues/693">#693</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/03f17c2538552a57e6be537afca8c7587bd40aaa"><code>03f17c2</code></a>
deps: qs@^6.14.1 (<a
href="https://redirect.github.com/expressjs/body-parser/issues/689">#689</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/ea1f25e503c1b2f7ba6f8562724ae0fcd247fb75"><code>ea1f25e</code></a>
docs: use standard jsdoc tags everywhere (<a
href="https://redirect.github.com/expressjs/body-parser/issues/677">#677</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/d7deef8ec61307fa28c22bc443cf8ed2f267945a"><code>d7deef8</code></a>
docs: update URL-encoded parser description to include ISO-8859-1
encoding su...</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/b6f52aabc65137c5227c8a462bddb761daeb96e7"><code>b6f52aa</code></a>
docs: release notes for the v1.20.4 release (<a
href="https://redirect.github.com/expressjs/body-parser/issues/674">#674</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/2965ca4af4883109cb2f651f4ce12da310902a0c"><code>2965ca4</code></a>
docs: update links (<a
href="https://redirect.github.com/expressjs/body-parser/issues/673">#673</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/d96b63da8d7445de317736471633bac83ec76cbb"><code>d96b63d</code></a>
2.2.1 (<a
href="https://redirect.github.com/expressjs/body-parser/issues/659">#659</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/b204886a6744b0b6d297cd0e849d75de836f3b63"><code>b204886</code></a>
sec: security patch for CVE-2025-13466</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/e20e3512e085c1162e8ffe36ac65c705a8017251"><code>e20e351</code></a>
feat: remove <code>history.md</code> from being packaged on publish (<a
href="https://redirect.github.com/expressjs/body-parser/issues/660">#660</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/expressjs/body-parser/compare/v2.2.0...v2.2.2">compare
view</a></li>
</ul>
</details>
<br />

Updates `js-yaml` from 3.14.1 to 3.14.2
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md">js-yaml's
changelog</a>.</em></p>
<blockquote>
<h2>[3.14.2] - 2025-11-15</h2>
<h3>Security</h3>
<ul>
<li>Backported v4.1.1 fix to v3</li>
</ul>
<h2>[4.1.1] - 2025-11-12</h2>
<h3>Security</h3>
<ul>
<li>Fix prototype pollution issue in yaml merge (&lt;&lt;)
operator.</li>
</ul>
<h2>[4.1.0] - 2021-04-15</h2>
<h3>Added</h3>
<ul>
<li>Types are now exported as <code>yaml.types.XXX</code>.</li>
<li>Every type now has <code>options</code> property with original
arguments kept as they were
(see <code>yaml.types.int.options</code> as an example).</li>
</ul>
<h3>Changed</h3>
<ul>
<li><code>Schema.extend()</code> now keeps old type order in case of
conflicts
(e.g. Schema.extend([ a, b, c ]).extend([ b, a, d ]) is now ordered as
<code>abcd</code> instead of <code>cbad</code>).</li>
</ul>
<h2>[4.0.0] - 2021-01-03</h2>
<h3>Changed</h3>
<ul>
<li>Check <a
href="https://github.com/nodeca/js-yaml/blob/master/migrate_v3_to_v4.md">migration
guide</a> to see details for all breaking changes.</li>
<li>Breaking: &quot;unsafe&quot; tags <code>!!js/function</code>,
<code>!!js/regexp</code>, <code>!!js/undefined</code> are
moved to <a
href="https://github.com/nodeca/js-yaml-js-types">js-yaml-js-types</a>
package.</li>
<li>Breaking: removed <code>safe*</code> functions. Use
<code>load</code>, <code>loadAll</code>, <code>dump</code>
instead which are all now safe by default.</li>
<li><code>yaml.DEFAULT_SAFE_SCHEMA</code> and
<code>yaml.DEFAULT_FULL_SCHEMA</code> are removed, use
<code>yaml.DEFAULT_SCHEMA</code> instead.</li>
<li><code>yaml.Schema.create(schema, tags)</code> is removed, use
<code>schema.extend(tags)</code> instead.</li>
<li><code>!!binary</code> now always mapped to <code>Uint8Array</code>
on load.</li>
<li>Reduced nesting of <code>/lib</code> folder.</li>
<li>Parse numbers according to YAML 1.2 instead of YAML 1.1
(<code>01234</code> is now decimal,
<code>0o1234</code> is octal, <code>1:23</code> is parsed as string
instead of base60).</li>
<li><code>dump()</code> no longer quotes <code>:</code>, <code>[</code>,
<code>]</code>, <code>(</code>, <code>)</code> except when necessary, <a
href="https://redirect.github.com/nodeca/js-yaml/issues/470">#470</a>,
<a
href="https://redirect.github.com/nodeca/js-yaml/issues/557">#557</a>.</li>
<li>Line and column in exceptions are now formatted as
<code>(X:Y)</code> instead of
<code>at line X, column Y</code> (also present in compact format), <a
href="https://redirect.github.com/nodeca/js-yaml/issues/332">#332</a>.</li>
<li>Code snippet created in exceptions now contains multiple lines with
line numbers.</li>
<li><code>dump()</code> now serializes <code>undefined</code> as
<code>null</code> in collections and removes keys with
<code>undefined</code> in mappings, <a
href="https://redirect.github.com/nodeca/js-yaml/issues/571">#571</a>.</li>
<li><code>dump()</code> with <code>skipInvalid=true</code> now
serializes invalid items in collections as null.</li>
<li>Custom tags starting with <code>!</code> are now dumped as
<code>!tag</code> instead of <code>!&lt;!tag&gt;</code>, <a
href="https://redirect.github.com/nodeca/js-yaml/issues/576">#576</a>.</li>
<li>Custom tags starting with <code>tag:yaml.org,2002:</code> are now
shorthanded using <code>!!</code>, <a
href="https://redirect.github.com/nodeca/js-yaml/issues/258">#258</a>.</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added <code>.mjs</code> (es modules) support.</li>
<li>Added <code>quotingType</code> and <code>forceQuotes</code> options
for dumper to configure
string literal style, <a
href="https://redirect.github.com/nodeca/js-yaml/issues/290">#290</a>,
<a
href="https://redirect.github.com/nodeca/js-yaml/issues/529">#529</a>.</li>
<li>Added <code>styles: { '!!null': 'empty' }</code> option for dumper
(serializes <code>{ foo: null }</code> as &quot;<code>foo:
</code>&quot;), <a
href="https://redirect.github.com/nodeca/js-yaml/issues/570">#570</a>.</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/nodeca/js-yaml/commit/9963d366dfbde0c69722452bcd40b41e7e4160a0"><code>9963d36</code></a>
3.14.2 released</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/10d3c8e70a6888543f5cdb656bb39f73e0ea77c1"><code>10d3c8e</code></a>
dist rebuild</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/5278870a17454fe8621dbd8c445c412529525266"><code>5278870</code></a>
fix prototype pollution in merge (&lt;&lt;) (<a
href="https://redirect.github.com/nodeca/js-yaml/issues/731">#731</a>)</li>
<li>See full diff in <a
href="https://github.com/nodeca/js-yaml/compare/3.14.1...3.14.2">compare
view</a></li>
</ul>
</details>
<br />

Updates `jws` from 4.0.0 to 4.0.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/brianloveswords/node-jws/releases">jws's
releases</a>.</em></p>
<blockquote>
<h2>v4.0.1</h2>
<h3>Changed</h3>
<ul>
<li>Fix advisory GHSA-869p-cjfg-cm3x: createSign and createVerify now
require
that a non empty secret is provided (via opts.secret, opts.privateKey or
opts.key)
when using HMAC algorithms.</li>
<li>Upgrading JWA version to 2.0.1, addressing a compatibility issue for
Node &gt;= 25.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/auth0/node-jws/blob/master/CHANGELOG.md">jws's
changelog</a>.</em></p>
<blockquote>
<h2>[4.0.1]</h2>
<h3>Changed</h3>
<ul>
<li>Fix advisory GHSA-869p-cjfg-cm3x: createSign and createVerify now
require
that a non empty secret is provided (via opts.secret, opts.privateKey or
opts.key)
when using HMAC algorithms.</li>
<li>Upgrading JWA version to 2.0.1, adressing a compatibility issue for
Node &gt;= 25.</li>
</ul>
<h2>[3.2.3]</h2>
<h3>Changed</h3>
<ul>
<li>Fix advisory GHSA-869p-cjfg-cm3x: createSign and createVerify now
require
that a non empty secret is provided (via opts.secret, opts.privateKey or
opts.key)
when using HMAC algorithms.</li>
<li>Upgrading JWA version to 1.4.2, adressing a compatibility issue for
Node &gt;= 25.</li>
</ul>
<h2>[3.0.0]</h2>
<h3>Changed</h3>
<ul>
<li><strong>BREAKING</strong>: <code>jwt.verify</code> now requires an
<code>algorithm</code> parameter, and
<code>jws.createVerify</code> requires an <code>algorithm</code> option.
The <code>&quot;alg&quot;</code> field
signature headers is ignored. This mitigates a critical security flaw
in the library which would allow an attacker to generate signatures with
arbitrary contents that would be accepted by <code>jwt.verify</code>.
See
<a
href="https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries/">https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries/</a>
for details.</li>
</ul>
<h2><a
href="https://github.com/brianloveswords/node-jws/compare/v1.0.1...v2.0.0">2.0.0</a>
- 2015-01-30</h2>
<h3>Changed</h3>
<ul>
<li>
<p><strong>BREAKING</strong>: Default payload encoding changed from
<code>binary</code> to
<code>utf8</code>. <code>utf8</code> is a is a more sensible default
than <code>binary</code> because
many payloads, as far as I can tell, will contain user-facing
strings that could be in any language. (<!-- raw HTML omitted
-->[6b6de48]<!-- raw HTML omitted -->)</p>
</li>
<li>
<p>Code reorganization, thanks [<a
href="https://github.com/fearphage"><code>@​fearphage</code></a>]! (<!--
raw HTML omitted --><a
href="https://github.com/brianloveswords/node-jws/commit/7880050">7880050</a><!--
raw HTML omitted -->)</p>
</li>
</ul>
<h3>Added</h3>
<ul>
<li>Option in all relevant methods for <code>encoding</code>. For those
few users
that might be depending on a <code>binary</code> encoding of the
messages, this
is for them. (<!-- raw HTML omitted -->[6b6de48]<!-- raw HTML omitted
-->)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/auth0/node-jws/commit/34c45b2c04434f925b638de6a061de9339c0ea2e"><code>34c45b2</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/auth0/node-jws/commit/49bc39b1f5509a630e0c6849527d8bc66b29ddf5"><code>49bc39b</code></a>
version 4.0.1</li>
<li><a
href="https://github.com/auth0/node-jws/commit/d42350ccab74db06c95f2279d1674d7d6a1692f4"><code>d42350c</code></a>
Enhance tests for HMAC streaming sign and verify</li>
<li><a
href="https://github.com/auth0/node-jws/commit/5cb007cf826c70f178c9975d31e949adff75e61b"><code>5cb007c</code></a>
Improve secretOrKey initialization in VerifyStream</li>
<li><a
href="https://github.com/auth0/node-jws/commit/f9a2e1c8c61ed80d1aa97f03ec32ccb920cf51cb"><code>f9a2e1c</code></a>
Improve secret handling in SignStream</li>
<li><a
href="https://github.com/auth0/node-jws/commit/b9fb8d30e9c009ade6379f308590f1b0703eefc3"><code>b9fb8d3</code></a>
Merge pull request <a
href="https://redirect.github.com/brianloveswords/node-jws/issues/102">#102</a>
from auth0/SRE-57-Upload-opslevel-yaml</li>
<li><a
href="https://github.com/auth0/node-jws/commit/95b75ee56c64d4f8c09c70e9e9662d813bab5685"><code>95b75ee</code></a>
Upload OpsLevel YAML</li>
<li><a
href="https://github.com/auth0/node-jws/commit/8857ee77623104e5cf9955932165ddf9cea1b72c"><code>8857ee7</code></a>
test: remove unused variable (<a
href="https://redirect.github.com/brianloveswords/node-jws/issues/96">#96</a>)</li>
<li>See full diff in <a
href="https://github.com/brianloveswords/node-jws/compare/v4.0.0...v4.0.1">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~julien.wollscheid">julien.wollscheid</a>, a
new releaser for jws since your current version.</p>
</details>
<br />

Updates `qs` from 6.14.0 to 6.14.1
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/ljharb/qs/blob/main/CHANGELOG.md">qs's
changelog</a>.</em></p>
<blockquote>
<h2><strong>6.14.1</strong></h2>
<ul>
<li>[Fix] ensure arrayLength applies to <code>[]</code> notation as
well</li>
<li>[Fix] <code>parse</code>: when a custom decoder returns
<code>null</code> for a key, ignore that key</li>
<li>[Refactor] <code>parse</code>: extract key segment splitting
helper</li>
<li>[meta] add threat model</li>
<li>[actions] add workflow permissions</li>
<li>[Tests] <code>stringify</code>: increase coverage</li>
<li>[Dev Deps] update <code>eslint</code>,
<code>@ljharb/eslint-config</code>, <code>npmignore</code>,
<code>es-value-fixtures</code>, <code>for-each</code>,
<code>object-inspect</code></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/ljharb/qs/commit/3fa11a5f643c76896387bd2d86904a2d0141fdf7"><code>3fa11a5</code></a>
v6.14.1</li>
<li><a
href="https://github.com/ljharb/qs/commit/a62670423c1ccab0dd83c621bfb98c7c024e314d"><code>a626704</code></a>
[Dev Deps] update <code>npmignore</code></li>
<li><a
href="https://github.com/ljharb/qs/commit/3086902ecf7f088d0d1803887643ac6c03d415b9"><code>3086902</code></a>
[Fix] ensure arrayLength applies to <code>[]</code> notation as
well</li>
<li><a
href="https://github.com/ljharb/qs/commit/fc7930e86c2264c1568c9f5606830e19b0bc2af2"><code>fc7930e</code></a>
[Dev Deps] update <code>eslint</code>,
<code>@ljharb/eslint-config</code></li>
<li><a
href="https://github.com/ljharb/qs/commit/0b06aac566abee45ef0327667a7cc89e7aed8b58"><code>0b06aac</code></a>
[Dev Deps] update <code>@ljharb/eslint-config</code></li>
<li><a
href="https://github.com/ljharb/qs/commit/64951f6200a1fb72cc003c6e8226dde3d2ef591f"><code>64951f6</code></a>
[Refactor] <code>parse</code>: extract key segment splitting helper</li>
<li><a
href="https://github.com/ljharb/qs/commit/e1bd2599cdff4c936ea52fb1f16f921cbe7aa88c"><code>e1bd259</code></a>
[Dev Deps] update <code>@ljharb/eslint-config</code></li>
<li><a
href="https://github.com/ljharb/qs/commit/f4b3d39709fef6ddbd85128d1ba4c6b566c4902e"><code>f4b3d39</code></a>
[eslint] add eslint 9 optional peer dep</li>
<li><a
href="https://github.com/ljharb/qs/commit/6e94d9596ca50dffafcef40a5f64eca89962cf34"><code>6e94d95</code></a>
[Dev Deps] update <code>eslint</code>,
<code>@ljharb/eslint-config</code>, <code>npmignore</code></li>
<li><a
href="https://github.com/ljharb/qs/commit/973dc3c51c86da9f4e30edeb4b1725158d439102"><code>973dc3c</code></a>
[actions] add workflow permissions</li>
<li>Additional commits viewable in <a
href="https://github.com/ljharb/qs/compare/v6.14.0...v6.14.1">compare
view</a></li>
</ul>
</details>
<br />

Updates `vega-functions` from 5.15.0 to 5.17.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vega/vega/releases">vega-functions's
releases</a>.</em></p>
<blockquote>
<h2>v5.17.0</h2>
<p>Changes from <a
href="https://github.com/vega/vega/releases/tag/v5.16.1">v5.16.1</a>:</p>
<p><strong>vega-canvas</strong></p>
<ul>
<li>Fix browser index route for ES modules. (<a
href="https://redirect.github.com/vega/vega/issues/2907">#2907</a>)</li>
</ul>
<p><strong>vega-loader</strong></p>
<ul>
<li>Add <a
href="https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Iteration_protocols#The_iterable_protocol">iterable</a>
support to JSON loader. Iterable inputs are expanded to arrays, then
ingested.</li>
<li>Fix browser index route for ES modules. (<a
href="https://redirect.github.com/vega/vega/issues/2907">#2907</a>)</li>
</ul>
<p><strong>vega-util</strong></p>
<ul>
<li>Add <code>isIterable</code> utility.</li>
</ul>
<h2>v5.16.1</h2>
<p>Changes from <a
href="https://github.com/vega/vega/releases/tag/v5.16.0">v5.16.0</a>:</p>
<p><strong>monorepo</strong></p>
<ul>
<li>Fix rollup config to use umd rather than iife bundles. (<a
href="https://redirect.github.com/vega/vega/issues/2896">#2896</a>)</li>
</ul>
<h2>v5.16.0</h2>
<h3>Notable Changes</h3>
<ul>
<li>The new <a
href="https://vega.github.io/vega/docs/transforms/label/"><code>label</code>
transform</a> automatically positions labels without overlapping other
marks. (Thanks <a
href="https://github.com/chanwutk"><code>@​chanwutk</code></a>!)</li>
<li>Completes the transition to using vega-datasets 2.0+, including
swapping out the Iris dataset for a more adorable Penguins dataset.
🐧</li>
<li>Major update of build system to use a centralized rollup
configuration. (Thanks <a
href="https://github.com/domoritz"><code>@​domoritz</code></a>!)</li>
</ul>
<h3>Changelog</h3>
<p>Changes from <a
href="https://github.com/vega/vega/releases/tag/v5.15.0">v5.15.0</a>:</p>
<p><strong>docs</strong></p>
<ul>
<li>Add <a
href="https://vega.github.io/vega/examples/calendar-view/">Calendar
View</a> example.</li>
<li>Add <a
href="https://vega.github.io/vega/examples/labeled-scatter-plot/">Labeled
Scatter Plot</a> example.</li>
<li>Update <a href="https://vega.github.io/vega/examples/box-plot/">Box
Plot</a> example to use penguins data.</li>
<li>Update <a
href="https://vega.github.io/vega/examples/violin-plot/">Violin Plot</a>
example to use penguins data.</li>
</ul>
<p><strong>monorepo</strong></p>
<ul>
<li>Complete transition to vega-datasets 2.0.</li>
<li>Use centralized rollup config. (thanks <a
href="https://github.com/domoritz"><code>@​domoritz</code></a>!)</li>
</ul>
<p><strong>vega</strong></p>
<ul>
<li>Use centralized rollup config. (thanks <a
href="https://github.com/domoritz"><code>@​domoritz</code></a>!)</li>
<li>Update and extend test specifications.</li>
</ul>
<p><strong>vega-canvas</strong></p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vega/vega/commit/c58de105bb4cd33ed74d2b6a02d551f5c11d72c7"><code>c58de10</code></a>
docs: Update docs build files.</li>
<li><a
href="https://github.com/vega/vega/commit/554b8227b233e27765c9e9c191352f11e4f9eece"><code>554b822</code></a>
chore: v5.17.0.</li>
<li><a
href="https://github.com/vega/vega/commit/102ccaf5395d5b55bb7e78fc7986cede777d6e5a"><code>102ccaf</code></a>
docs: Document isIterable utility.</li>
<li><a
href="https://github.com/vega/vega/commit/2ffa0d1796993dfe6202eacd5d1d2c0c6a0b0e64"><code>2ffa0d1</code></a>
fix: Fix browser build routes.</li>
<li><a
href="https://github.com/vega/vega/commit/25bb661a88f12db31870998a9ae6b10eb3f2ffb4"><code>25bb661</code></a>
feat: Add iterable support to json loader.</li>
<li><a
href="https://github.com/vega/vega/commit/f0c23dfba70c5b43486ac730102d2ef942136394"><code>f0c23df</code></a>
build(deps-dev): bump rollup from 2.28.1 to 2.28.2</li>
<li><a
href="https://github.com/vega/vega/commit/cb0a966e33f11fc43a4a00af2c5fcb4f5d374129"><code>cb0a966</code></a>
build(deps-dev): bump terser from 5.3.2 to 5.3.3</li>
<li><a
href="https://github.com/vega/vega/commit/f6f2d19f57b2340b442cc056c74161afc7a5367e"><code>f6f2d19</code></a>
build(deps-dev): bump dtslint from 4.0.2 to 4.0.4</li>
<li><a
href="https://github.com/vega/vega/commit/1382f06b72f0b0c08d74d157137a78da4a6b7906"><code>1382f06</code></a>
chore: bump vega-typings version</li>
<li><a
href="https://github.com/vega/vega/commit/30fc399b26d76791cfdcf11bfd1e810296b9c8d3"><code>30fc399</code></a>
docs: remove format annotation from union type</li>
<li>Additional commits viewable in <a
href="https://github.com/vega/vega/compare/v5.15.0...v5.17.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `vega-selections` from 5.4.2 to 5.6.3
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vega/vega/releases">vega-selections's
releases</a>.</em></p>
<blockquote>
<h2>v5.6.0</h2>
<p>Changes from <a
href="https://github.com/vega/vega/releases/tag/v5.5.3">v5.5.3</a>:</p>
<p><strong>vega</strong></p>
<ul>
<li>Add overview-detail-bins test specification.</li>
<li>Update font-size-steps test specification to include config
signals.</li>
<li>Update dependencies, including d3-format. (Thanks <a
href="https://github.com/benib"><code>@​benib</code></a>!)</li>
</ul>
<p><strong>vega-encode</strong></p>
<ul>
<li>Fix bin boundary generation to respect scale domain.</li>
<li>Add test cases for scale <em>bins</em> parameter.</li>
</ul>
<p><strong>vega-parser</strong></p>
<ul>
<li>Fix config signal parsing bug. (<a
href="https://redirect.github.com/vega/vega/issues/1989">#1989</a>)</li>
</ul>
<p><strong>vega-statistics</strong></p>
<ul>
<li>Add <em>span</em> parameter to <code>bin</code> method.</li>
<li>Add test cases using <code>bin</code> <em>span</em> parameter.</li>
</ul>
<p><strong>vega-transforms</strong></p>
<ul>
<li>Add <em>span</em> parameter to <code>Bin</code> transform.</li>
</ul>
<p><strong>vega-typings</strong></p>
<ul>
<li>Update <code>Bin</code> transform typing.</li>
<li>Add overview-detail-bins test specification.</li>
</ul>
<p><strong>vega-util</strong></p>
<ul>
<li>Fix null input handling for <code>span</code> method.</li>
</ul>
<h2>v5.5.3</h2>
<p>Changes from <a
href="https://github.com/vega/vega/releases/tag/v5.5.2">v5.5.2</a>:</p>
<p><strong>vega</strong></p>
<ul>
<li>Update <code>movies-sort</code> test scene to reflect new stable
sorting.</li>
</ul>
<p><strong>vega-dataflow</strong></p>
<ul>
<li>Add <code>stableCompare</code> method to Tuple utilities.</li>
</ul>
<p><strong>vega-encode</strong></p>
<ul>
<li>Update <code>SortItems</code> transform to use stable
comparator.</li>
<li>Update <code>Stack</code> transform to use stable comparator.</li>
</ul>
<p><strong>vega-hierarchy</strong></p>
<ul>
<li>Update <code>HierarchyLayout</code> to use stable comparator.</li>
<li>Remove internal assignment of tupleid to tree nodes.</li>
</ul>
<p><strong>vega-parser</strong></p>
<ul>
<li>Update sort parameter for SortItems transform.</li>
<li>Update sort parameter for generated scale dataflows.</li>
<li>Fix negative axis <code>labelFlushOffset</code> bug.</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/vega/vega/commits">compare view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~hydrosquall">hydrosquall</a>, a new
releaser for vega-selections since your current version.</p>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/google/perfetto/network/alerts).

</details>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
10 files changed
tree: b31687c463d747093b2bd9bab5dba1e3a80b9477
  1. .github/
  2. bazel/
  3. build_overrides/
  4. buildtools/
  5. contrib/
  6. docs/
  7. examples/
  8. gn/
  9. include/
  10. infra/
  11. protos/
  12. python/
  13. src/
  14. test/
  15. third_party/
  16. tools/
  17. ui/
  18. .bazelignore
  19. .bazelrc
  20. .bazelversion
  21. .clang-format
  22. .clang-tidy
  23. .git-blame-ignore-revs
  24. .gitallowed
  25. .gitattributes
  26. .gitignore
  27. .gn
  28. .style.yapf
  29. Android.bp
  30. Android.bp.extras
  31. BUILD
  32. BUILD.extras
  33. BUILD.gn
  34. CHANGELOG
  35. CONTRIBUTORS.txt
  36. DIR_METADATA
  37. heapprofd.rc
  38. LICENSE
  39. meson.build
  40. METADATA
  41. MODULE.bazel
  42. MODULE.bazel.lock
  43. MODULE_LICENSE_APACHE2
  44. OWNERS
  45. OWNERS.github
  46. perfetto.rc
  47. perfetto_flags.aconfig
  48. PerfettoIntegrationTests.xml
  49. persistent_cfg.pbtxt
  50. README.chromium
  51. README.md
  52. TEST_MAPPING
  53. traced_perf.rc
  54. WORKSPACE
README.md

Perfetto - System profiling, app tracing and trace analysis

Perfetto is an open-source suite of SDKs, daemons and tools which use tracing to help developers understand the behaviour of complex systems and root-cause functional and performance issues on client and embedded systems.

It is a production-grade tool that is the default tracing system for the Android operating system and the Chromium browser.

Core Components

Perfetto is not a single tool, but a collection of components that work together:

  • High-performance tracing daemons: For capturing tracing information from many processes on a single machine into a unified trace file.
  • Low-overhead tracing SDK: A C++17 library for direct userspace-to-userspace tracing of timings and state changes in your application.
  • Extensive OS-level probes: For capturing system-wide context on Android and Linux (e.g. scheduling states, CPU frequencies, memory profiling, callstack sampling).
  • Browser-based UI: A powerful, fully local UI for visualizing and exploring large, multi-GB traces on a timeline. It works in all major browsers, requires no installation, and can open traces from other tools.
  • SQL-based analysis library: A powerful engine that allows you to programmatically query traces using SQL to automate analysis and extract custom metrics.

Why Use Perfetto?

Perfetto was designed to be a versatile and powerful tracing system for a wide range of use cases.

  • For Android App & Platform Developers: Debug and root-cause functional and performance issues like slow startups, dropped frames (jank), animation glitches, low memory kills, and ANRs. Profile both Java/Kotlin and native C++ memory usage with heap dumps and profiles.
  • For C/C++ Developers (Linux, macOS, Windows): Use the Tracing SDK to instrument your application with custom trace points to understand its execution flow, find performance bottlenecks, and debug complex behavior. On Linux, you can also perform detailed CPU and native heap profiling.
  • For Linux Kernel & System Developers: Get deep insights into kernel behavior. Perfetto acts as an efficient userspace daemon for ftrace, allowing you to visualize scheduling, syscalls, interrupts, and custom kernel tracepoints on a timeline.
  • For Chromium Developers: Perfetto is the tracing backend for chrome://tracing. Use it to debug and root-cause issues in the browser, V8, and Blink.
  • For Performance Engineers & SREs: Analyze and visualize a wide range of profiling and tracing formats, not just Perfetto's. Use the powerful SQL interface to programmatically analyze traces from tools like Linux perf, macOS Instruments, Chrome JSON traces, and more.

Getting Started

We‘ve designed our documentation to guide you to the right information as quickly as possible, whether you’re a newcomer to performance analysis or an experienced developer.

  1. New to tracing? If you're unfamiliar with concepts like tracing and profiling, start here:

  2. Ready to dive in? Our “Getting Started” guide is the main entry point for all users. It will help you find the right tutorials and documentation for your specific needs:

  3. Want the full overview? For a comprehensive look at what Perfetto is, why it's useful, and who uses it, see our main documentation page:

Debian Distribution

For users interested in the Debian distribution of Perfetto, the official source of truth and packaging efforts are maintained at Debian Perfetto Salsa Repository

Community & Support

Have questions? Need help?

We follow Google's Open Source Community Guidelines.