Skip to content

Bump limiter from 2.1.0 to 4.1.0 - #8030

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/limiter-4.1.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/limiter-4.1.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps limiter from 2.1.0 to 4.1.0.

Release notes

Sourced from limiter's releases.

limiter 4.1.0

[4.1.0] — 2026-09-10

  • Add RateLimiter.getWaitTime(count) to estimate cooldowns across both the bucket and interval allowance (#88).
  • Add regressions for positive bucket balances during interval exhaustion and the 5,000-request backlog report.
  • Replace placeholder README snippets with complete examples and clarify sequential limiter composition.
  • Allow npm to build distribution archives without requiring Yarn globally.

limiter 4.0.0

limiter@4.0.0 fixes concurrent rate-limit accounting, atomic parent/child debits, and bounded FIFO waiting. It is a major release because invalid numeric inputs now reject and request ordering changes.

Before upgrading, review the 3.x migration guide. Check configuration for negative, non-finite, or unsafe token values; handle rejected asynchronous calls; and account for FIFO head-of-line waiting. Remaining fractional balances may differ slightly due to improved clock precision.

No runtime dependencies are added. Both CommonJS and ESM distributions remain available. The npm archive now includes the changelog and excludes tests and TypeScript build caches.

Validation: all 27 tests, lint, both builds, and CommonJS/ESM imports from the packed package passed locally; CI covers Node 20, 22, and 24.

Changes: #103 and #104. See the changelog for details.

Changelog

Sourced from limiter's changelog.

[4.1.0] — 2026-09-10

  • Add RateLimiter.getWaitTime(count) to estimate cooldowns across both the bucket and interval allowance (#88).
  • Add regressions for positive bucket balances during interval exhaustion and the 5,000-request backlog report.
  • Replace placeholder README snippets with complete examples and clarify sequential limiter composition.
  • Allow npm to build distribution archives without requiring Yarn globally.

[4.0.0] - 2026-09-08

This is a major release because input validation and asynchronous request ordering change observable behavior. See Upgrading from 3.x before upgrading.

Fixed

  • Reserve interval allowance before asynchronous calls yield; recheck it after waiting.
  • Debit parent and child buckets together, avoiding double charges under contention.
  • Serialize waiting requests per instance with one active timer, and reject cyclic parents.
  • Reject invalid token values and intervals; cap long timers and avoid NaN balances for very short intervals.
  • Correct the byte-throttling example and document interval, queue, zero-value, and floating-point behavior.

Compatibility

  • Invalid numeric inputs now throw RangeError (or reject the returned promise).
  • Async requests on one instance now run FIFO; synchronous requests can still consume capacity first.
  • Fractional millisecond clock precision is retained, so remaining balances may differ slightly from earlier versions.

Maintenance

  • Refresh development dependencies within their existing declared ranges; no runtime dependencies are added.
  • Build both module distributions in CI and include this changelog in the npm package.
  • Exclude test files and TypeScript build caches from the published package.

[3.0.0] - 2025-01-24

Added

  • Dual Module Support: Distributed as both CommonJS and ES Module, with separate package.json files for each format (no need for custom transformers). This improves compatibility with modern bundlers and frameworks.

Changed

  • Build and Dependencies: Updated build pipeline and dependencies (Babel, TypeScript, Jest, ESLint, etc.) to latest versions. The library targets Node.js ES2019 syntax for broader runtime support.
  • Monotonic Timing: Removed the just-performance dependency in favor of Node’s built-in high-resolution timers. Timing now relies on process.hrtime/performance APIs, ensuring monotonic behavior without external packages.

Fixed

  • ESM Import Stability: Resolved issues with ES Module imports. Consumers no longer need workarounds to import the ESM build. The removal of "type": "module" from the main package and the introduction of a dedicated ESM build fix the ERR_MODULE_NOT_FOUND and Unexpected token errors in Node 16+.
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [limiter](https://github.com/jhurliman/node-rate-limiter) from 2.1.0 to 4.1.0.
- [Release notes](https://github.com/jhurliman/node-rate-limiter/releases)
- [Changelog](https://github.com/jhurliman/node-rate-limiter/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jhurliman/node-rate-limiter/commits/v4.1.0)

---
updated-dependencies:
- dependency-name: limiter
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 1, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 1, 2026 11:04
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants