/
/
Bumps [deno](https://github.com/denoland/deno) from 2.7.12 to 2.9.5. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/denoland/deno/releases">deno's releases</a>.</em></p> <blockquote> <h2>v2.9.5</h2> <h3>2.9.5 / 2026.08.06</h3> <ul> <li>feat(add): <code>--unscoped</code> flag to alias packages by their unscoped name (<a href="https://redirect.github.com/denoland/deno/issues/36319">#36319</a>)</li> <li>feat(task): add --members flag to run tasks in workspace members only (<a href="https://redirect.github.com/denoland/deno/issues/35748">#35748</a>)</li> <li>feat: add Blob/Body textStream() (<a href="https://redirect.github.com/denoland/deno/issues/35616">#35616</a>)</li> <li>feat: add experimental QuickJS backend (<a href="https://redirect.github.com/denoland/deno/issues/36194">#36194</a>)</li> <li>fix(bundle): avoid esbuild protocol deadlock (<a href="https://redirect.github.com/denoland/deno/issues/36427">#36427</a>)</li> <li>fix(bundle): respect runtime file permissions (<a href="https://redirect.github.com/denoland/deno/issues/36107">#36107</a>)</li> <li>fix(cjs): use loader sources for recursive analysis (<a href="https://redirect.github.com/denoland/deno/issues/36111">#36111</a>)</li> <li>fix(cli): escape control characters in external metadata (<a href="https://redirect.github.com/denoland/deno/issues/36198">#36198</a>)</li> <li>fix(core): don't resolve internal module imports with the user's import map (<a href="https://redirect.github.com/denoland/deno/issues/36303">#36303</a>)</li> <li>fix(crypto): add <code>"raw-secret"</code> to <code>KeyFormat</code> type (<a href="https://redirect.github.com/denoland/deno/issues/35708">#35708</a>)</li> <li>fix(desktop): handle colored HMR URLs and page loads (<a href="https://redirect.github.com/denoland/deno/issues/36316">#36316</a>)</li> <li>fix(desktop): retain update signature verification op (<a href="https://redirect.github.com/denoland/deno/issues/36152">#36152</a>)</li> <li>fix(ext/crypto): allow deriveBits with length 0 (<a href="https://redirect.github.com/denoland/deno/issues/36283">#36283</a>)</li> <li>fix(ext/napi): polyfill <code>uv_handle_size</code> and <code>uv_strerror</code> (<a href="https://redirect.github.com/denoland/deno/issues/36308">#36308</a>)</li> <li>fix(ext/net): release completed QUIC stream resources (<a href="https://redirect.github.com/denoland/deno/issues/36247">#36247</a>)</li> <li>fix(ext/net): require --allow-sys for node:dns.getServers() (<a href="https://redirect.github.com/denoland/deno/issues/35941">#35941</a>)</li> <li>fix(ext/node): Node compat for web streams (<a href="https://redirect.github.com/denoland/deno/issues/36285">#36285</a>)</li> <li>fix(ext/node): apply backpressure in Readable.toWeb() (<a href="https://redirect.github.com/denoland/deno/issues/36321">#36321</a>)</li> <li>fix(ext/node): defer TLS write completion callback to avoid reentrancy panic (<a href="https://redirect.github.com/denoland/deno/issues/35867">#35867</a>)</li> <li>fix(ext/node): don't fire http2 settings callback after session destroy (<a href="https://redirect.github.com/denoland/deno/issues/36230">#36230</a>)</li> <li>fix(ext/node): gate constrained memory cgroup reads (<a href="https://redirect.github.com/denoland/deno/issues/36218">#36218</a>)</li> <li>fix(ext/node): handle pre-quoted shell arguments (<a href="https://redirect.github.com/denoland/deno/issues/36371">#36371</a>)</li> <li>fix(ext/node): implement node:test tags (<a href="https://redirect.github.com/denoland/deno/issues/36292">#36292</a>)</li> <li>fix(ext/node): implement util.diff (<a href="https://redirect.github.com/denoland/deno/issues/36289">#36289</a>)</li> <li>fix(ext/node): implement v8.promiseHooks API (<a href="https://redirect.github.com/denoland/deno/issues/36281">#36281</a>)</li> <li>fix(ext/node): sort fs.readdir entries to match Node.js (<a href="https://redirect.github.com/denoland/deno/issues/36341">#36341</a>)</li> <li>fix(ext/node): stop http2 file reads after stream close (<a href="https://redirect.github.com/denoland/deno/issues/36300">#36300</a>)</li> <li>fix(ext/node): store blocklist ranges compactly (<a href="https://redirect.github.com/denoland/deno/issues/36212">#36212</a>)</li> <li>fix(ext/node): support the fs <code>flush</code> option for writes (<a href="https://redirect.github.com/denoland/deno/issues/36290">#36290</a>)</li> <li>fix(ext/node): use signatureAlgorithm digest for X509 ECDSA verify (<a href="https://redirect.github.com/denoland/deno/issues/36326">#36326</a>)</li> <li>fix(ext/node_crypto): use named group exponent sizes (<a href="https://redirect.github.com/denoland/deno/issues/36347">#36347</a>)</li> <li>fix(ext/web): attach Node error codes to WHATWG API validation errors (<a href="https://redirect.github.com/denoland/deno/issues/36288">#36288</a>)</li> <li>fix(ext/websocket): disable HTTP/2 server push on wss upgrade path (<a href="https://redirect.github.com/denoland/deno/issues/36327">#36327</a>)</li> <li>fix(fetch): scope redirect-sensitive headers by origin (<a href="https://redirect.github.com/denoland/deno/issues/36361">#36361</a>)</li> <li>fix(ffi): reject resizable buffers in nonblocking calls (<a href="https://redirect.github.com/denoland/deno/issues/36259">#36259</a>)</li> <li>fix(fmt): accept xml and svg extensions for stdin (<a href="https://redirect.github.com/denoland/deno/issues/36149">#36149</a>)</li> <li>fix(fmt): update lax-markup to 0.3.2, lax-css and lax-sql to 0.3.0 (<a href="https://redirect.github.com/denoland/deno/issues/36397">#36397</a>)</li> <li>fix(http): preserve stripped headers across redirects (<a href="https://redirect.github.com/denoland/deno/issues/36360">#36360</a>)</li> <li>fix(inspector): validate request host headers (<a href="https://redirect.github.com/denoland/deno/issues/36348">#36348</a>)</li> <li>fix(net): cancel pending writes on stream close (<a href="https://redirect.github.com/denoland/deno/issues/36369">#36369</a>)</li> <li>fix(net): clean up concurrently dropped load-balanced listeners (<a href="https://redirect.github.com/denoland/deno/issues/36246">#36246</a>)</li> <li>fix(net): handle malformed DNS record text (<a href="https://redirect.github.com/denoland/deno/issues/36374">#36374</a>)</li> <li>fix(node): clean up Web Stream finished listeners (<a href="https://redirect.github.com/denoland/deno/issues/36227">#36227</a>)</li> <li>fix(node): retain consumed HTTP stream wrapper (<a href="https://redirect.github.com/denoland/deno/issues/36254">#36254</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/denoland/deno/blob/main/Releases.md">deno's changelog</a>.</em></p> <blockquote> <h3>2.9.5 / 2026.08.06</h3> <ul> <li>feat(add): <code>--unscoped</code> flag to alias packages by their unscoped name (<a href="https://redirect.github.com/denoland/deno/issues/36319">#36319</a>)</li> <li>feat(task): add --members flag to run tasks in workspace members only (<a href="https://redirect.github.com/denoland/deno/issues/35748">#35748</a>)</li> <li>feat: add Blob/Body textStream() (<a href="https://redirect.github.com/denoland/deno/issues/35616">#35616</a>)</li> <li>feat: add experimental QuickJS backend (<a href="https://redirect.github.com/denoland/deno/issues/36194">#36194</a>)</li> <li>fix(bundle): avoid esbuild protocol deadlock (<a href="https://redirect.github.com/denoland/deno/issues/36427">#36427</a>)</li> <li>fix(bundle): respect runtime file permissions (<a href="https://redirect.github.com/denoland/deno/issues/36107">#36107</a>)</li> <li>fix(cjs): use loader sources for recursive analysis (<a href="https://redirect.github.com/denoland/deno/issues/36111">#36111</a>)</li> <li>fix(cli): escape control characters in external metadata (<a href="https://redirect.github.com/denoland/deno/issues/36198">#36198</a>)</li> <li>fix(core): don't resolve internal module imports with the user's import map (<a href="https://redirect.github.com/denoland/deno/issues/36303">#36303</a>)</li> <li>fix(crypto): add <code>"raw-secret"</code> to <code>KeyFormat</code> type (<a href="https://redirect.github.com/denoland/deno/issues/35708">#35708</a>)</li> <li>fix(desktop): handle colored HMR URLs and page loads (<a href="https://redirect.github.com/denoland/deno/issues/36316">#36316</a>)</li> <li>fix(desktop): retain update signature verification op (<a href="https://redirect.github.com/denoland/deno/issues/36152">#36152</a>)</li> <li>fix(ext/crypto): allow deriveBits with length 0 (<a href="https://redirect.github.com/denoland/deno/issues/36283">#36283</a>)</li> <li>fix(ext/napi): polyfill <code>uv_handle_size</code> and <code>uv_strerror</code> (<a href="https://redirect.github.com/denoland/deno/issues/36308">#36308</a>)</li> <li>fix(ext/net): release completed QUIC stream resources (<a href="https://redirect.github.com/denoland/deno/issues/36247">#36247</a>)</li> <li>fix(ext/net): require --allow-sys for node:dns.getServers() (<a href="https://redirect.github.com/denoland/deno/issues/35941">#35941</a>)</li> <li>fix(ext/node): Node compat for web streams (<a href="https://redirect.github.com/denoland/deno/issues/36285">#36285</a>)</li> <li>fix(ext/node): apply backpressure in Readable.toWeb() (<a href="https://redirect.github.com/denoland/deno/issues/36321">#36321</a>)</li> <li>fix(ext/node): defer TLS write completion callback to avoid reentrancy panic (<a href="https://redirect.github.com/denoland/deno/issues/35867">#35867</a>)</li> <li>fix(ext/node): don't fire http2 settings callback after session destroy (<a href="https://redirect.github.com/denoland/deno/issues/36230">#36230</a>)</li> <li>fix(ext/node): gate constrained memory cgroup reads (<a href="https://redirect.github.com/denoland/deno/issues/36218">#36218</a>)</li> <li>fix(ext/node): handle pre-quoted shell arguments (<a href="https://redirect.github.com/denoland/deno/issues/36371">#36371</a>)</li> <li>fix(ext/node): implement node:test tags (<a href="https://redirect.github.com/denoland/deno/issues/36292">#36292</a>)</li> <li>fix(ext/node): implement util.diff (<a href="https://redirect.github.com/denoland/deno/issues/36289">#36289</a>)</li> <li>fix(ext/node): implement v8.promiseHooks API (<a href="https://redirect.github.com/denoland/deno/issues/36281">#36281</a>)</li> <li>fix(ext/node): sort fs.readdir entries to match Node.js (<a href="https://redirect.github.com/denoland/deno/issues/36341">#36341</a>)</li> <li>fix(ext/node): stop http2 file reads after stream close (<a href="https://redirect.github.com/denoland/deno/issues/36300">#36300</a>)</li> <li>fix(ext/node): store blocklist ranges compactly (<a href="https://redirect.github.com/denoland/deno/issues/36212">#36212</a>)</li> <li>fix(ext/node): support the fs <code>flush</code> option for writes (<a href="https://redirect.github.com/denoland/deno/issues/36290">#36290</a>)</li> <li>fix(ext/node): use signatureAlgorithm digest for X509 ECDSA verify (<a href="https://redirect.github.com/denoland/deno/issues/36326">#36326</a>)</li> <li>fix(ext/node_crypto): use named group exponent sizes (<a href="https://redirect.github.com/denoland/deno/issues/36347">#36347</a>)</li> <li>fix(ext/web): attach Node error codes to WHATWG API validation errors (<a href="https://redirect.github.com/denoland/deno/issues/36288">#36288</a>)</li> <li>fix(ext/websocket): disable HTTP/2 server push on wss upgrade path (<a href="https://redirect.github.com/denoland/deno/issues/36327">#36327</a>)</li> <li>fix(fetch): scope redirect-sensitive headers by origin (<a href="https://redirect.github.com/denoland/deno/issues/36361">#36361</a>)</li> <li>fix(ffi): reject resizable buffers in nonblocking calls (<a href="https://redirect.github.com/denoland/deno/issues/36259">#36259</a>)</li> <li>fix(fmt): accept xml and svg extensions for stdin (<a href="https://redirect.github.com/denoland/deno/issues/36149">#36149</a>)</li> <li>fix(fmt): update lax-markup to 0.3.2, lax-css and lax-sql to 0.3.0 (<a href="https://redirect.github.com/denoland/deno/issues/36397">#36397</a>)</li> <li>fix(http): preserve stripped headers across redirects (<a href="https://redirect.github.com/denoland/deno/issues/36360">#36360</a>)</li> <li>fix(inspector): validate request host headers (<a href="https://redirect.github.com/denoland/deno/issues/36348">#36348</a>)</li> <li>fix(net): cancel pending writes on stream close (<a href="https://redirect.github.com/denoland/deno/issues/36369">#36369</a>)</li> <li>fix(net): clean up concurrently dropped load-balanced listeners (<a href="https://redirect.github.com/denoland/deno/issues/36246">#36246</a>)</li> <li>fix(net): handle malformed DNS record text (<a href="https://redirect.github.com/denoland/deno/issues/36374">#36374</a>)</li> <li>fix(node): clean up Web Stream finished listeners (<a href="https://redirect.github.com/denoland/deno/issues/36227">#36227</a>)</li> <li>fix(node): retain consumed HTTP stream wrapper (<a href="https://redirect.github.com/denoland/deno/issues/36254">#36254</a>)</li> <li>fix(npm): ignore invalid package bin targets (<a href="https://redirect.github.com/denoland/deno/issues/36354">#36354</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/denoland/deno/commit/17fadf33a8df3af9488b9f42efd1f2290d6dc7a3"><code>17fadf3</code></a> chore(release): publish dependency crates with --no-verify</li> <li><a href="https://github.com/denoland/deno/commit/5dfadcebf35d86f27e916a25c4109b5aa233ded7"><code>5dfadce</code></a> 2.9.5 (<a href="https://redirect.github.com/denoland/deno/issues/36448">#36448</a>)</li> <li><a href="https://github.com/denoland/deno/commit/9906e8e90cca5a4ec6234ab03af365da2fb1da98"><code>9906e8e</code></a> chore(release): handle renamed deno_v8 dep in version bump</li> <li><a href="https://github.com/denoland/deno/commit/76792720c2e38074dd1abb1d7407c5c6b9aed2c3"><code>7679272</code></a> fix(bundle): avoid esbuild protocol deadlock (<a href="https://redirect.github.com/denoland/deno/issues/36427">#36427</a>)</li> <li><a href="https://github.com/denoland/deno/commit/139b1084c7318a39e047097b310794cd28ff8422"><code>139b108</code></a> fix(cli): escape control characters in external metadata (<a href="https://redirect.github.com/denoland/deno/issues/36198">#36198</a>)</li> <li><a href="https://github.com/denoland/deno/commit/736c9112507706891e8f7a8570df9bb3597a101e"><code>736c911</code></a> test: isolate package imports specs (<a href="https://redirect.github.com/denoland/deno/issues/36416">#36416</a>)</li> <li><a href="https://github.com/denoland/deno/commit/2903cf1195ef604cd8558fc05d9fa8b2fe848153"><code>2903cf1</code></a> ci: repair QuickJS Windows builds and CLI parser lint (<a href="https://redirect.github.com/denoland/deno/issues/36414">#36414</a>)</li> <li><a href="https://github.com/denoland/deno/commit/cec65f9ac0bf9f9360d6e24b07765a7227323103"><code>cec65f9</code></a> fix(npm): ignore invalid package bin targets (<a href="https://redirect.github.com/denoland/deno/issues/36354">#36354</a>)</li> <li><a href="https://github.com/denoland/deno/commit/a6cecbdcb48075723dc372819912cb4b83c966e4"><code>a6cecbd</code></a> perf(ext/web): implement base64url encode/decode as simdutf ops (<a href="https://redirect.github.com/denoland/deno/issues/36398">#36398</a>)</li> <li><a href="https://github.com/denoland/deno/commit/95857ffa7d37566f3e93dc021727fe3654c770e6"><code>95857ff</code></a> fix(inspector): validate request host headers (<a href="https://redirect.github.com/denoland/deno/issues/36348">#36348</a>)</li> <li>Additional commits viewable in <a href="https://github.com/denoland/deno/compare/v2.7.12...v2.9.5">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> --------- Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>