Update dependency @opensearch-project/opensearch to v3.9.0 #179

Open
MaidFox wants to merge 1 commit from renovate/opensearch-project-opensearch-3.x-lockfile into main
Member

This PR contains the following updates:

Package Change Age Confidence
@opensearch-project/opensearch (source) 3.6.0 → 3.9.0 age confidence

Release Notes

opensearch-project/opensearch-js (@​opensearch-project/opensearch)

v3.9.0

Compare Source

Versions 3.7.0 and 3.8.0 are skipped. The numbers were used by the malicious packages described in GHSA-27f5-xjrr-q9ff, and npm does not allow a version number to be used again.

Added
  • Api Generator: support x-is-generic-type-parameter. Types that use a generic marker now take a type parameter with an any default, for example HitsMetadata<TDocument = any> (#​1129)
Dependencies
  • Remove hpagent. The client now uses its own proxy agent, derived from hpagent 1.2.0 (#​1147)
Changed
  • Updated API to match the OpenSearch spec from Sep 23, 2026 (#​1150)
  • Updated API spec download URL to https://api-spec.opensearch.org (#​1141)
  • CI: test against OpenSearch 1.3.20, 2.19.6 and 3.8.0, and Node.js 22.x, 24.x and 26.x (#​1147)
  • CI: use the reusable backport-pr workflow from opensearch-build (#​1123)
Fixed
  • Fix HTTPS proxy with an IP address on Node.js 26 (ERR_INVALID_ARG_VALUE for TLS servername) (#​1147)
  • CI: wait for the security plugin to initialize before the secure integration tests run (#​1147)
  • Api Generator: fix invalid extends syntax generated for nested allOf inside object properties (#​1128)
  • Api Generator: Add parentheses around array element types that contain intersections or unions, fixing the HitsMetadata.hits, bulk request body and search suggest types (#​1112, #​1114)
  • Replace GitHub App token with opensearch-ci-bot PAT in generate_api workflow (#​1130)
  • Api Generator: Lazily instantiate API namespaces to fix Client construction performance (#​1133)
  • Fix bulk helper mapping response items to variable-width bulkBody when mixing delete and index/create/update operations, which caused incorrect operation/document pairing and undefined deserialization (#​1125, #​1126)
  • Upgrade webpack to v5 in bundler test to support the nullish coalescing operator emitted by the API generator (#​1138)
  • Declare the Connection agent property as agent, not _agent, to match the runtime (#​1146)
Security
  • Fix CVEs in diff, lodash, and yaml dependencies (#​1131)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@opensearch-project/opensearch](https://www.opensearch.org/) ([source](https://github.com/opensearch-project/opensearch-js)) | [`3.6.0` → `3.9.0`](https://renovatebot.com/diffs/npm/@opensearch-project%2fopensearch/3.6.0/3.9.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@opensearch-project%2fopensearch/3.9.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@opensearch-project%2fopensearch/3.6.0/3.9.0?slim=true) | --- ### Release Notes <details> <summary>opensearch-project/opensearch-js (@&#8203;opensearch-project/opensearch)</summary> ### [`v3.9.0`](https://github.com/opensearch-project/opensearch-js/blob/HEAD/CHANGELOG.md#390) [Compare Source](https://github.com/opensearch-project/opensearch-js/compare/3.6.0...3.9.0) Versions 3.7.0 and 3.8.0 are skipped. The numbers were used by the malicious packages described in [GHSA-27f5-xjrr-q9ff](https://github.com/opensearch-project/opensearch-js/security/advisories/GHSA-27f5-xjrr-q9ff), and npm does not allow a version number to be used again. ##### Added - Api Generator: support `x-is-generic-type-parameter`. Types that use a generic marker now take a type parameter with an `any` default, for example `HitsMetadata<TDocument = any>` ([#&#8203;1129](https://github.com/opensearch-project/opensearch-js/pull/1129)) ##### Dependencies - Remove `hpagent`. The client now uses its own proxy agent, derived from `hpagent` 1.2.0 ([#&#8203;1147](https://github.com/opensearch-project/opensearch-js/pull/1147)) ##### Changed - Updated API to match the OpenSearch spec from Sep 23, 2026 ([#&#8203;1150](https://github.com/opensearch-project/opensearch-js/pull/1150)) - Updated API spec download URL to `https://api-spec.opensearch.org` ([#&#8203;1141](https://github.com/opensearch-project/opensearch-js/pull/1141)) - CI: test against OpenSearch 1.3.20, 2.19.6 and 3.8.0, and Node.js 22.x, 24.x and 26.x ([#&#8203;1147](https://github.com/opensearch-project/opensearch-js/pull/1147)) - CI: use the reusable backport-pr workflow from opensearch-build ([#&#8203;1123](https://github.com/opensearch-project/opensearch-js/pull/1123)) ##### Fixed - Fix HTTPS proxy with an IP address on Node.js 26 (`ERR_INVALID_ARG_VALUE` for TLS servername) ([#&#8203;1147](https://github.com/opensearch-project/opensearch-js/pull/1147)) - CI: wait for the security plugin to initialize before the secure integration tests run ([#&#8203;1147](https://github.com/opensearch-project/opensearch-js/pull/1147)) - Api Generator: fix invalid extends syntax generated for nested allOf inside object properties ([#&#8203;1128](https://github.com/opensearch-project/opensearch-js/pull/1128)) - Api Generator: Add parentheses around array element types that contain intersections or unions, fixing the `HitsMetadata.hits`, bulk request body and search `suggest` types ([#&#8203;1112](https://github.com/opensearch-project/opensearch-js/issues/1112), [#&#8203;1114](https://github.com/opensearch-project/opensearch-js/pull/1114)) - Replace GitHub App token with opensearch-ci-bot PAT in generate\_api workflow ([#&#8203;1130](https://github.com/opensearch-project/opensearch-js/pull/1130)) - Api Generator: Lazily instantiate API namespaces to fix Client construction performance ([#&#8203;1133](https://github.com/opensearch-project/opensearch-js/pull/1133)) - Fix bulk helper mapping response items to variable-width `bulkBody` when mixing delete and index/create/update operations, which caused incorrect operation/document pairing and undefined deserialization ([#&#8203;1125](https://github.com/opensearch-project/opensearch-js/issues/1125), [#&#8203;1126](https://github.com/opensearch-project/opensearch-js/pull/1126)) - Upgrade webpack to v5 in bundler test to support the nullish coalescing operator emitted by the API generator ([#&#8203;1138](https://github.com/opensearch-project/opensearch-js/pull/1138)) - Declare the `Connection` agent property as `agent`, not `_agent`, to match the runtime ([#&#8203;1146](https://github.com/opensearch-project/opensearch-js/pull/1146)) ##### Security - Fix CVEs in diff, lodash, and yaml dependencies ([#&#8203;1131](https://github.com/opensearch-project/opensearch-js/pull/1131)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTAuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjExMC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Update dependency @opensearch-project/opensearch to v3.9.0
Some checks failed
NodeJS check / check-nodejs (pull_request) Failing after 39s
Nix check / check-nix (pull_request) Failing after 1m27s
e11d38acd4
MaidFox force-pushed renovate/opensearch-project-opensearch-3.x-lockfile from e11d38acd4
Some checks failed
NodeJS check / check-nodejs (pull_request) Failing after 39s
Nix check / check-nix (pull_request) Failing after 1m27s
to 5f3b0c4e1a
Some checks failed
Nix check / check-nix (pull_request) Failing after 1m13s
NodeJS check / check-nodejs (pull_request) Failing after 1m20s
2026-09-25 12:11:07 -07:00
Compare
MaidFox force-pushed renovate/opensearch-project-opensearch-3.x-lockfile from 5f3b0c4e1a
Some checks failed
Nix check / check-nix (pull_request) Failing after 1m13s
NodeJS check / check-nodejs (pull_request) Failing after 1m20s
to 913b57c66a
Some checks failed
NodeJS check / check-nodejs (pull_request) Failing after 52s
Nix check / check-nix (pull_request) Failing after 1m21s
2026-09-26 13:07:37 -07:00
Compare
Some checks failed
NodeJS check / check-nodejs (pull_request) Failing after 52s
Nix check / check-nix (pull_request) Failing after 1m21s
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/opensearch-project-opensearch-3.x-lockfile:renovate/opensearch-project-opensearch-3.x-lockfile
git switch renovate/opensearch-project-opensearch-3.x-lockfile

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff renovate/opensearch-project-opensearch-3.x-lockfile
git switch renovate/opensearch-project-opensearch-3.x-lockfile
git rebase main
git switch main
git merge --ff-only renovate/opensearch-project-opensearch-3.x-lockfile
git switch renovate/opensearch-project-opensearch-3.x-lockfile
git rebase main
git switch main
git merge --no-ff renovate/opensearch-project-opensearch-3.x-lockfile
git switch main
git merge --squash renovate/opensearch-project-opensearch-3.x-lockfile
git switch main
git merge --ff-only renovate/opensearch-project-opensearch-3.x-lockfile
git switch main
git merge renovate/opensearch-project-opensearch-3.x-lockfile
git push origin main
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
FoxDen/fadumper!179
No description provided.