Skip to content

build(deps): bump @kikobeats/got to ~11.8.8 - #287

Merged
Kikobeats merged 1 commit into
masterfrom
Kikobeats/got-11.8.8-f8fa318b
Sep 16, 2026
Merged

Kikobeats merged 1 commit into
masterfrom
Kikobeats/got-11.8.8-f8fa318b

Conversation

@Kikobeats

@Kikobeats Kikobeats commented Sep 16, 2026 •

Copy link
Copy Markdown
Member

Picks up @kikobeats/got@11.8.8, which fixes issues found by seven adversarial reviews of the fork after 11.8.7 shipped:

  • Write lock restored (Kikobeats/got#6). In 11.8.7 a stray write() on a stream that already had a body was accepted and reached the server as a second request on a keep-alive connection. It throws again, as in got 11.8.6.
  • Retries on Node.js 24.20+ (#6, #7). Errors reported through the end() callback (ECANCELED, ERR_SOCKET_CLOSED) are handled after the request's own error, so connection failures retry instead of failing once.
  • Cache (#4). Cached requests no longer crash with cacheable-request forks that bundle clone-response@2. html-get does not use the cache option, so this one does not affect it directly.
  • Uploads (#7). end() while a body stream is still sending throws instead of truncating the upload, and the source tracking no longer leaks listeners.

Testing

Node.js Result
24.16.0 141 passed, 54 skipped
24.20.0 (CI lts/*) 141 passed, 54 skipped

standard is clean. The fork's own suite passes 552 tests on Node.js LTS and latest, and html-get, reachable-url, oembed-spec, metascraper and the microlink-api unit suite were each run against this build with no failures that stock got does not also have.

🤖 Generated with Claude Code

https://claude.ai/code/session_01VZiY7VMgg1nEMkCezwMXEC


Note

Low Risk
Single dependency patch with no application code changes; risk is limited to HTTP client behavior fixes in the fork used for all fetches.

Overview
Bumps @kikobeats/got from ~11.8.7 to ~11.8.8 — the only code change is in package.json. html-get still loads the fork from src/index.js for page fetches; behavior comes from the updated dependency.

11.8.8 restores the write-lock guard (avoids a stray second request on keep-alive after 11.8.7), improves retry handling on Node.js 24.20+ for ECANCELED / ERR_SOCKET_CLOSED, fixes cache crashes with certain cacheable-request forks (html-get does not use cache), and tightens upload/end() handling so bodies are not truncated and listeners do not leak.

PR testing reports the existing suite passing on Node 24.16 and 24.20.

Reviewed by Cursor Bugbot for commit 72288ed. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Chores
    • Updated the bundled networking dependency to a newer patch version for maintenance and compatibility improvements.

11.8.8 restores the 11.8.6 write lock (11.8.7 let a stray write inject a
second request on a keep-alive connection), keeps retrying connection
errors reported through the end callback on Node.js 24.20+, and fixes
cached requests crashing with cacheable-request forks bundling
clone-response@2.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VZiY7VMgg1nEMkCezwMXEC
@coderabbitai

coderabbitai Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: c44915f3-7369-4d7a-853d-ce3cb2afc588

📥 Commits

Reviewing files that changed from the base of the PR and between 77a0ecf and 72288ed.

📒 Files selected for processing (1)
  • package.json

Included review availability: Your plan provides up to 2 included reviews per hour; 1 remains after this review.


📝 Walkthrough

Walkthrough

The pull request updates the @kikobeats/got dependency specifier in package.json from ~11.8.7 to ~11.8.8.

Changes

Dependency Update

Layer / File(s) Summary
Update dependency specifier
package.json
The @kikobeats/got dependency specifier changes from ~11.8.7 to ~11.8.8.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~2 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 72288

No actionable merge-blocking risk is established by the dependency-only change.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the dependency update from @kikobeats/got to ~11.8.8. It matches the main change.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch Kikobeats/got-11.8.8-f8fa318b

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Kikobeats
Kikobeats merged commit 07ad894 into master Sep 16, 2026
4 checks passed
@Kikobeats
Kikobeats deleted the Kikobeats/got-11.8.8-f8fa318b branch September 16, 2026 15:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant