Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: middleapi/orpc
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v1.13.9
Choose a base ref
...
head repository: middleapi/orpc
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v1.13.10
Choose a head ref
  • 4 commits
  • 97 files changed
  • 6 contributors

Commits on Mar 20, 2026

  1. chore(deps-dev): bump next from 16.1.6 to 16.1.7 (#1484)

    Bumps [next](https://github.com/vercel/next.js) from 16.1.6 to 16.1.7.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/vercel/next.js/releases">next's
    releases</a>.</em></p>
    <blockquote>
    <h2>v16.1.7</h2>
    <blockquote>
    <p>[!NOTE]
    This release is backporting bug fixes. It does <strong>not</strong>
    include all pending features/changes on canary.</p>
    </blockquote>
    <h3>Core Changes</h3>
    <ul>
    <li>[Cache Components] Prevent streaming fetch calls from hanging in dev
    (<a
    href="https://redirect.github.com/vercel/next.js/issues/89194">#89194</a>)</li>
    <li>Apply server actions transform to node_modules in route handlers (<a
    href="https://redirect.github.com/vercel/next.js/issues/89380">#89380</a>)</li>
    <li>ensure <code>maxPostponedStateSize</code> is always respected (See:
    <a
    href="https://github.com/vercel/next.js/security/advisories/GHSA-h27x-g6w4-24gq">CVE-2026-27979</a>)</li>
    <li>feat(next/image): add lru disk cache and
    <code>images.maximumDiskCacheSize</code> (See: <a
    href="https://github.com/vercel/next.js/security/advisories/GHSA-3x4c-7xq6-9pq8">CVE-2026-27980</a>)</li>
    <li>Allow blocking cross-site dev-only websocket connections from
    privacy-sensitive origins (See: <a
    href="https://github.com/vercel/next.js/security/advisories/GHSA-jcc7-9wpm-mj36">CVE-2026-27977</a>)</li>
    <li>Disallow Server Action submissions from privacy-sensitive contexts
    by default (See: <a
    href="https://github.com/vercel/next.js/security/advisories/GHSA-mq59-m269-xvcx">CVE-2026-27978</a>)</li>
    <li>fix: patch http-proxy to prevent request smuggling in rewrites (See:
    <a
    href="https://github.com/vercel/next.js/security/advisories/GHSA-ggv3-7p47-pfv8">CVE-2026-29057</a>)</li>
    </ul>
    <h3>Credits</h3>
    <p>Huge thanks to <a
    href="https://github.com/unstubbable"><code>@​unstubbable</code></a>, <a
    href="https://github.com/styfle"><code>@​styfle</code></a>, <a
    href="https://github.com/eps1lon"><code>@​eps1lon</code></a>, and <a
    href="https://github.com/ztanner"><code>@​ztanner</code></a> for
    helping!</p>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/vercel/next.js/commit/bdf3e3577a6d55ea186a48238d61fbd8da07a626"><code>bdf3e35</code></a>
    v16.1.7</li>
    <li><a
    href="https://github.com/vercel/next.js/commit/dc98c04f376c6a1df76ec3e0a2d07edf4abdabd6"><code>dc98c04</code></a>
    [backport]: fix: patch http-proxy to prevent request smuggling in
    rewrites (#...</li>
    <li><a
    href="https://github.com/vercel/next.js/commit/9023c0ab70235cdf68e88c14b66290500efa9f7f"><code>9023c0a</code></a>
    [backport] Disallow Server Action submissions from privacy-sensitive
    contexts...</li>
    <li><a
    href="https://github.com/vercel/next.js/commit/36a97b9b64e263f2340afcc1c12fc01323b2cfc0"><code>36a97b9</code></a>
    Allow blocking cross-site dev-only websocket connections from
    privacy-sensiti...</li>
    <li><a
    href="https://github.com/vercel/next.js/commit/93c3993a8e3f4952508a2f6da87c1533c76b5365"><code>93c3993</code></a>
    [backport]: feat(next/image): add lru disk cache and
    `images.maximumDiskCache...</li>
    <li><a
    href="https://github.com/vercel/next.js/commit/c68d62d5d4786fe89ab241f895b7821fcb730373"><code>c68d62d</code></a>
    Backport documentation fixes for 16.1.x (<a
    href="https://redirect.github.com/vercel/next.js/issues/90655">#90655</a>)</li>
    <li><a
    href="https://github.com/vercel/next.js/commit/5214ac1513f4d2f2315d35a81a7e249e2815d90c"><code>5214ac1</code></a>
    [backport]: ensure maxPostponedStateSize is always respected (<a
    href="https://redirect.github.com/vercel/next.js/issues/90060">#90060</a>)
    (<a
    href="https://redirect.github.com/vercel/next.js/issues/90471">#90471</a>)</li>
    <li><a
    href="https://github.com/vercel/next.js/commit/c95e357f195c5d6c54d9dd599b89916f7217c9c5"><code>c95e357</code></a>
    Backport/docs fixes 16.1.x (<a
    href="https://redirect.github.com/vercel/next.js/issues/90125">#90125</a>)</li>
    <li><a
    href="https://github.com/vercel/next.js/commit/cba6144edd14f1a8c8c8663feb632cfbd50d4e2e"><code>cba6144</code></a>
    [backport] Apply server actions transform to <code>node_modules</code>
    in route handlers...</li>
    <li><a
    href="https://github.com/vercel/next.js/commit/3db90632a7957a1bbda98ebb228e57618bbb7032"><code>3db9063</code></a>
    [backport] [Cache Components] Prevent streaming fetch calls from hanging
    in d...</li>
    <li>Additional commits viewable in <a
    href="https://github.com/vercel/next.js/compare/v16.1.6...v16.1.7">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=next&package-manager=npm_and_yarn&previous-version=16.1.6&new-version=16.1.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the
    [Security Alerts
    page](https://github.com/middleapi/orpc/network/alerts).
    
    </details>
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Mar 20, 2026
    Configuration menu
    Copy the full SHA
    401936e View commit details
    Browse the repository at this point in the history

Commits on Mar 22, 2026

  1. Configuration menu
    Copy the full SHA
    f30210a View commit details
    Browse the repository at this point in the history

Commits on Mar 24, 2026

  1. fix(node-adapter): handle utf-8 characters split across stream chunks (

    …#1496)
    
    ## Summary
    - use `StringDecoder` to decode stream content safely across chunk
    boundaries
    - add tests for JSON and text bodies with UTF-8 characters split between
    chunks
    
      ## Problem
    Direct `chunk.toString()` decoding can corrupt UTF-8 characters when
    multi-byte sequences are split across stream chunks.
    
      ## Testing
      - added unit tests for chunk-boundary UTF-8 decoding in JSON body
      - added unit tests for chunk-boundary UTF-8 decoding in text body
    
    <!-- This is an auto-generated comment: release notes by coderabbit.ai
    -->
    ## Summary by CodeRabbit
    
    * **Bug Fixes**
    * Improved UTF‑8 decoding for streamed request bodies so multi‑byte
    characters split across chunks are decoded correctly and incomplete
    final bytes are handled gracefully (replacement character used).
    
    * **Tests**
    * Added tests validating JSON and plain‑text payloads with multi‑byte
    UTF‑8 characters split across stream boundaries, including an incomplete
    final byte scenario.
    <!-- end of auto-generated comment: release notes by coderabbit.ai -->
    
    ---------
    
    Co-authored-by: zxhyc131 <[email protected]>
    Co-authored-by: Dinh Le <[email protected]>
    3 people authored Mar 24, 2026
    Configuration menu
    Copy the full SHA
    6bc474e View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    cb6363b View commit details
    Browse the repository at this point in the history
Loading