fix(deps): update dependency rate-limiter-flexible to v11 - #16572
Open
renovate[bot] wants to merge 1 commit into
Open
fix(deps): update dependency rate-limiter-flexible to v11#16572renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
2 Skipped Deployments
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.0.5→11.2.0Release Notes
animir/node-rate-limiter-flexible (rate-limiter-flexible)
v11.2.0: Expiring Queue itemsCompare Source
What's Changed
feat: add expiresUnixAt deadline option to RateLimiterQueue.removeTokens (#212) by @Ruby-Leung in #365
Queue with
removeTokens(tokens, key, expiresUnixAt)orremoveTokens(tokens, expiresUnixAt)calls.Read more on RateLimiterQueue wiki.
fix(postgres): don't name the one-off create-table prepared statement (#196) by @Ruby-Leung in #366
New Contributors
Full Changelog: animir/node-rate-limiter-flexible@v11.1.1...v11.2.0
🌠
v11.1.1: Dynamic execEvenlyMinDelayMsCompare Source
What's Changed
New Contributors
Full Changelog: animir/node-rate-limiter-flexible@v11.1.0...v11.1.1
🚉
v11.1.0: Dump and restore for Memory limiterCompare Source
What's Changed
This is a best-effort persistence mechanism for graceful restarts (SIGTERM/SIGINT), blue/green deploys, or writing a snapshot to disk on shutdown.
Use this when losing up to 1% of request counts won’t affect security or finances, such as in overload or DoS protection.
New Contributors
Full Changelog: animir/node-rate-limiter-flexible@v11.0.2...v11.1.0
🔶
v11.0.2: Drizzle-orm v1 supportCompare Source
What's Changed
Full Changelog: animir/node-rate-limiter-flexible@v11.0.1...v11.0.2
😉
v11.0.1: Fix msBeforeNext delayed responseCompare Source
What's Changed
Full Changelog: animir/node-rate-limiter-flexible@v11.0.0...v11.0.1
👀
v11.0.0: Wrappers don't require points and duration optionsCompare Source
What's Changed
RateLimiterCompatibleAbstractlightweight base class for custom wrappersAdded a minimal abstract class that defines the core interface (consume, get, set, delete, penalty, reward, block, getKey) without requiring the full RateLimiterAbstract implementation. This makes it easy to build custom wrappers that work seamlessly with RateLimiterUnion, RLWrapperTimeouts, and insurance limiters.
[BREAKING CHANGES]
RLWrapperBlackAndWhitenow extendsRateLimiterCompatibleAbstract, and all union/wrapper/insurance classes accept both abstract types via a new isRateLimiterCompatible helper.⏲️
Full Changelog: animir/node-rate-limiter-flexible@v10.0.1...v11.0.0
v10.0.1: AI docs fixCompare Source
Full Changelog: animir/node-rate-limiter-flexible@v10.0.0...v10.0.1
v10.0.0: Require points and duration optsCompare Source
What's Changed
[BREAKING CHANGES]
Require
pointsanddurationoptions by @animir in #354No default values are set for
pointsanddurationoptions starting from v10. Negativepointswill not be replaced by default points value4.Validation rules apply.
Error is thrown during limiter creation if points or duration is invalid:
pointsmust be number.Any limiter accepts negative
pointsas valid option starting from v10. If you migrate from older version, be careful: If in your codepointsoption is set to negative value and that works for your project now then you should review the logic in your project. After update to version 10, negativepointsvalue will not be replaced by4by default as it was prior to version 10.When your limiter has negative or zero points
consumemethod call is always rejected since there is always not enough points to consume. You can setpointsto negative and play withrewardandconsumecalls, that could be useful sometimes.durationmust be non-negative number>= 0. Error is thrown during limiter creation ifdurationoption has invalid value.Requiring
pointsanddurationseems logical for security package. We don't want our apps working not as we expect even if there is no security threat. This update removes uncertaincy about negative duration and zero points.[OTHER UPDATES]
Faster memory limiter and block mechanism by @animir in #355
Internal memory storage implementation refactored for Map with timestamps instead of Date objects.
Memory limiter is faster on 10-15% now on high traffic with diverse keys. Tests show performance improvement from
2569948 ops/secto2885688 ops/secon my laptop.Full Changelog: animir/node-rate-limiter-flexible@v9.1.1...v10.0.0
🐚
v9.1.1: Sequelize v7 supportCompare Source
What's Changed
🔔
v9.1.0: Non atomic Redis limiterCompare Source
What's Changed
💬
v9.0.1: Fixes: Queue and DynamoDBCompare Source
What's Changed
{}by @sevauni in #340New Contributors
Full Changelog: animir/node-rate-limiter-flexible@v9.0.0...v9.0.1
📶
v9.0.0: Mongoose 9 supportCompare Source
What's Changed
BREAKING CHANGES
4.0.05.2.0😋
v8.3.0: Timeouts wrapper fixedCompare Source
RLWrapperTimeouts can be imported from defaults:
Use it with or without
insuranceLimiterto handle long requests to a storage.Read more in docs.
Thank you @florian-schunk
💧
v8.2.1: Fix Insurance StrategyCompare Source
This patch reverts v8.2.0 changes. Timeouts Wrapper changed how Insurance Strategy treats rejected promises from working stores.
If you're on the version 8.2.0, please update to v8.2.1.
The impact of 8.2.0 changes is that when main limiter rejected consume or any other method call because there were not enough points on store, insurance limiter consume method was mistakenly called. This logic is incorrect as Insurance Strategy should handle only store errors.
v8.2.0: Timeouts wrapperCompare Source
Added a new RLWrapperTimeouts.
It can be used with or without insuranceLimiter to handle long requests to a storage.
Thanks to @florian-schunk .
✌️
v8.1.0: fix node-redis v4+ client is ready checksCompare Source
node-redispackage client is ready checks. All versions and cluster mode is supported now.Thanks to @Neumann-Nils
v8.0.1: Fix TS definitionsCompare Source
v8.0.0 [BREAKING CHANGES]
RateLimiterQueueErrorimport was changed in TypeScript projects.It should be imported from defaults now.
TS definition for RateLimiterQueueError was moved to types.d.ts.
v8.0.1:
index.d.tsfile was moved outside of lib directory and renamed totypes.d.ts.Thanks @wildfluss and @PaulAnnekov for help.
💿
v8.0.0Compare Source
v7.4.0: Drizzle ORM supportCompare Source
In version
7.2.0RateLimiterDrizzlelimiter was added. Read about it on wikiThanks @Nayanchandrakar !
In version
7.3.0disableIndexesCreation option added toRateLimiterMongo.In version
7.3.1conditional require of drizzle-orm was replaced with dynamic import to avoid issues with linters and tree-shakers.In version
7.3.2drizzle-orm lazy import is hidden behind function call and string concatenation to avoid unnecessary tree-shaking and statistical analysis in different bundlers.In version
7.4.0RateLimiterDrizzleNonAtomic was added. It doesn't guarantee precise events count under race conditions, but much faster than atomic limiter.💫
v7.3.2Compare Source
v7.3.1Compare Source
v7.3.0Compare Source
v7.2.0Compare Source
v7.1.1: Check points before upserting with RedisCompare Source
2.1.Thank you @roggervalf
🌞
v7.1.0: Etcd supportCompare Source
RateLimiterEtcdandRateLimiterEtcdNonAtomicwere added. Read more on Wiki https://github.com/animir/node-rate-limiter-flexible/wiki/Etcd.This is the first time we add atomic and non-atomic limiters for the same storage. Atomic increments are necessary to count sensitive things like incorrect password or PIN tries while non-atomic increments may be better (because they are faster) when exact count doesn't matter, e.g. to protect a service against DDoS attack.
Thank you @Tobias4872
🍇
v7.0.0Compare Source
What's Changed
RateLimiterValkeyGlideto support Valkey Glide @avifenesh in #302 Thank you!X-RateLimit-Resetheader example was fixed. It should beMath.ceil((Date.now() + rateLimiterRes.msBeforeNext) / 1000). Thanks to @Fdavidtr.New Contributors
Full Changelog: animir/node-rate-limiter-flexible@v6.2.1...v7.0.0
🐆
v6.2.1: SQLite: fix Knex connection issueCompare Source
RateLimiterSQLite: This fixes an issue where an unused Knex connection remained open, causing pool connection problems. Additionally, this adds functions to run tests against Knex.Thanks to @muco-rolle
📌
v6.2.0: Multiple SQLite clients supportCompare Source
RateLimiterSQLitesupportssqlite3,better-sqlite3andknexclients now.Set
storeTypeoption to one ofsqlite3,better-sqlite3orknex, defaults tosqlite3if not set.Thank you @muco-rolle
🎁
v6.1.0: SQLite supportCompare Source
RateLimiterSQLiteadded. Thanks to @no-on3 and @muco-rollerate-limiter-flexiblesupports SQLite now! 🐬Check SQLite example.
Just a day after Valkey limiter release we are releasing SQLite support. One new database and one old (but still good) added to the list of the big family. Congrats!
v6.0.0: Valkey support [zap]Compare Source
RateLimiterValkeyadded. Thanks to @gurgundayrate-limiter-flexiblesupports Valkey now! ⚡It can be used with iovalkey package.
[breaking] Node.js support for version 16 was dropped.
Configuration
📅 Schedule: (in timezone America/Los_Angeles)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.