Skip to content

Bump limiter from 2.1.0 to 4.1.0 - #8030

Merged
code-asher merged 1 commit into
mainfrom
dependabot/npm_and_yarn/limiter-4.1.0
Oct 8, 2026
Merged

code-asher merged 1 commit into
mainfrom
dependabot/npm_and_yarn/limiter-4.1.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps limiter from 2.1.0 to 4.1.0.

Release notes

Sourced from limiter's releases.

limiter 4.1.0

[4.1.0] — 2026-09-10

  • Add RateLimiter.getWaitTime(count) to estimate cooldowns across both the bucket and interval allowance (#88).
  • Add regressions for positive bucket balances during interval exhaustion and the 5,000-request backlog report.
  • Replace placeholder README snippets with complete examples and clarify sequential limiter composition.
  • Allow npm to build distribution archives without requiring Yarn globally.

limiter 4.0.0

limiter@4.0.0 fixes concurrent rate-limit accounting, atomic parent/child debits, and bounded FIFO waiting. It is a major release because invalid numeric inputs now reject and request ordering changes.

Before upgrading, review the 3.x migration guide. Check configuration for negative, non-finite, or unsafe token values; handle rejected asynchronous calls; and account for FIFO head-of-line waiting. Remaining fractional balances may differ slightly due to improved clock precision.

No runtime dependencies are added. Both CommonJS and ESM distributions remain available. The npm archive now includes the changelog and excludes tests and TypeScript build caches.

Validation: all 27 tests, lint, both builds, and CommonJS/ESM imports from the packed package passed locally; CI covers Node 20, 22, and 24.

Changes: #103 and #104. See the changelog for details.

Changelog

Sourced from limiter's changelog.

[4.1.0] — 2026-09-10

  • Add RateLimiter.getWaitTime(count) to estimate cooldowns across both the bucket and interval allowance (#88).
  • Add regressions for positive bucket balances during interval exhaustion and the 5,000-request backlog report.
  • Replace placeholder README snippets with complete examples and clarify sequential limiter composition.
  • Allow npm to build distribution archives without requiring Yarn globally.

[4.0.0] - 2026-09-08

This is a major release because input validation and asynchronous request ordering change observable behavior. See Upgrading from 3.x before upgrading.

Fixed

  • Reserve interval allowance before asynchronous calls yield; recheck it after waiting.
  • Debit parent and child buckets together, avoiding double charges under contention.
  • Serialize waiting requests per instance with one active timer, and reject cyclic parents.
  • Reject invalid token values and intervals; cap long timers and avoid NaN balances for very short intervals.
  • Correct the byte-throttling example and document interval, queue, zero-value, and floating-point behavior.

Compatibility

  • Invalid numeric inputs now throw RangeError (or reject the returned promise).
  • Async requests on one instance now run FIFO; synchronous requests can still consume capacity first.
  • Fractional millisecond clock precision is retained, so remaining balances may differ slightly from earlier versions.

Maintenance

  • Refresh development dependencies within their existing declared ranges; no runtime dependencies are added.
  • Build both module distributions in CI and include this changelog in the npm package.
  • Exclude test files and TypeScript build caches from the published package.

[3.0.0] - 2025-01-24

Added

  • Dual Module Support: Distributed as both CommonJS and ES Module, with separate package.json files for each format (no need for custom transformers). This improves compatibility with modern bundlers and frameworks.

Changed

  • Build and Dependencies: Updated build pipeline and dependencies (Babel, TypeScript, Jest, ESLint, etc.) to latest versions. The library targets Node.js ES2019 syntax for broader runtime support.
  • Monotonic Timing: Removed the just-performance dependency in favor of Node’s built-in high-resolution timers. Timing now relies on process.hrtime/performance APIs, ensuring monotonic behavior without external packages.

Fixed

  • ESM Import Stability: Resolved issues with ES Module imports. Consumers no longer need workarounds to import the ESM build. The removal of "type": "module" from the main package and the introduction of a dedicated ESM build fix the ERR_MODULE_NOT_FOUND and Unexpected token errors in Node 16+.
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 1, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 1, 2026 11:04
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 1, 2026
Bumps [limiter](https://github.com/jhurliman/node-rate-limiter) from 2.1.0 to 4.1.0.
- [Release notes](https://github.com/jhurliman/node-rate-limiter/releases)
- [Changelog](https://github.com/jhurliman/node-rate-limiter/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jhurliman/node-rate-limiter/commits/v4.1.0)

---
updated-dependencies:
- dependency-name: limiter
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/limiter-4.1.0 branch from 6ae29e5 to c6480e7 Compare October 8, 2026 00:41
@code-asher
code-asher merged commit 5244097 into main Oct 8, 2026
14 of 15 checks passed
@code-asher
code-asher deleted the dependabot/npm_and_yarn/limiter-4.1.0 branch October 8, 2026 01:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant