chore(deps): update dependency @vercel/blob to ^2.6.1 - #35
Merged
Conversation
|
Preview Deployment |
renovate
Bot
force-pushed
the
renovate/vercel-blob-2.x
branch
7 times, most recently
from
August 8, 2026 05:05
70dabae to
24046fe
Compare
renovate
Bot
force-pushed
the
renovate/vercel-blob-2.x
branch
from
August 8, 2026 06:03
24046fe to
15b146a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^2.3.0→^2.6.1Release Notes
vercel/storage (@vercel/blob)
v2.6.1Compare Source
Patch Changes
d0118c4: Add auseCacheoption topresignUrl()forgetoperations. WhenuseCache: false, the presigned URL includes acache=0query param so fetches bypass the CDN cache and read the latest content directly from origin storage. Likeget(), the bypass only applies to private blobs. The param is not part of the signed payload, so holders of a presigned URL can also add or remove it manually.v2.6.0Compare Source
Minor Changes
c4976ba: Addrename(fromUrlOrPathname, toPathname, options)to move a blob to another pathname. The blob is copied to the new pathname and the source is deleted afterwards; if the copy fails the source is left untouched. By default renaming onto an existing blob throws — passallowOverwrite: trueto replace it, oraddRandomSuffix: trueto generate a unique destination. Requires a read-write token (client tokens are not supported).89d94e9: Restore theuseCacheoption onget(). PassinguseCache: falsebypasses the CDN cache and serves the blob directly from origin storage (via thecache=0query parameter), guaranteeing the latest content at the cost of slower reads. Defaults totrue.v2.5.0Compare Source
Minor Changes
31a8b8f: Deprecate theuseCacheoption onget(). The backend no longer honors thecache=0query parameter it produced, so the option is now a no-op — reads always go through the standard caching path. The option is still accepted (and ignored) to avoid breaking existing callers, and will be removed in a future major version.Patch Changes
9ac2586: Read the Vercel OIDC token via@vercel/oidc's refreshinggetVercelOidcTokeninstead of the non-refreshinggetVercelOidcTokenSync. This refreshes an expired token in development environments. In production with a valid token, behavior is unchanged. If a refresh is needed but fails, the token is treated as absent so callers still fall back toBLOB_READ_WRITE_TOKEN.v2.4.1Compare Source
Patch Changes
b7027de: Read the Vercel OIDC token via the@vercel/oidcpackage (getVercelOidcTokenSync) instead of an inlined copy. This makes the dependency explicit and discoverable, and matches how other Vercel packages consume OIDC. Behavior is unchanged except for one edge case: a blankx-vercel-oidc-tokenrequest-context header now resolves to no token rather than falling back toVERCEL_OIDC_TOKEN.v2.4.0Compare Source
Minor Changes
20eeaff: Add Vercel OIDC auth and presigned URLsv2.3.3Compare Source
Patch Changes
d2ea7cf: EnforcemaximumSizeInBytesclient-side for multipart uploads. Bodies with a known size (Blob, File, Buffer) are now checked before the upload starts, avoiding wasted API calls.949e994: Fix multipart upload hanging forever on empty streams, and fixcreateChunkTransformStreambypassing backpressure by removing incorrectqueueMicrotaskwrapping.v2.3.2Compare Source
Patch Changes
c9d9a1a: ApplyifMatch/allowOverwritevalidation tohandleUploadandgenerateClientTokenFromReadWriteToken. WhenifMatchis set viaonBeforeGenerateTokenor direct token generation,allowOverwriteis now implicitly enabled. Explicitly passingallowOverwrite: falsewithifMatchthrows a clear error.6dcecb8: MakeifMatchimplyallowOverwrite: trueonput(). Previously, usingifMatchwithout explicitly settingallowOverwrite: truewould cause the server to send conflicting conditional headers to S3, resulting in 500 errors. Now the SDK implicitly enablesallowOverwritewhenifMatchis set, and throws a clear error ifallowOverwrite: falseis explicitly combined withifMatch.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.