Commit Graph

98 Commits

Author SHA1 Message Date
Dominik Ferber b64b6bccdb chore: override nanoid@3 to fix Dependabot alert (#471)
`hypertune` and `@vercel/microfrontends` resolved to nanoid 3.3.16, which
is vulnerable to an infinite loop when a custom generator is called with
size zero. The existing `nanoid@>=4` override did not cover the v3 range,
so add a matching `nanoid@3: ^3.3.18` override.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 11:22:17 +03:00
Dominik Ferber 2532e99ea8 chore: fix open Dependabot security alerts (#470)
Bumps the vulnerable transitive dependencies flagged by Dependabot via
pnpm overrides, and the direct nanoid dependency in the examples.

- nanoid >= 4 -> ^5.1.16 (GHSA infinite loop on negative/zero size)
- brace-expansion >= 4 -> ^5.0.9 (DoS via unbounded intermediate arrays)
- dompurify -> ^3.4.13 (XSS via detached subtree after IN_PLACE hook removal)
- fast-uri -> ^3.1.5 (host confusion via backslash authority introducer)
- js-yaml 3 -> ^3.15.1, js-yaml 4 -> ^4.3.1 (quadratic CPU in !!omap)
- mermaid -> ^11.16.1 (DoS, prototype pollution, CSS injection)
- postcss -> ^8.5.23 (arbitrary .map file read via sourceMappingURL)
- @sveltejs/kit -> ^2.70.2 (ReDoS in Accept header content negotiation)

image-size (alerts #979, #980) has no patched release yet, so it is left
as-is. It is only used at build time by the docs site.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-11 20:14:54 +02:00
Andy 8913cf1578 Bump @vercel/global-config to 1.5.1 (#464)
* Bump Global Config SDK

* Add changeset
2026-08-07 16:00:05 +02:00
christopherkindl db7ce9aa66 [docs] upgrade geistdocs to 1.19.4 (#463) 2026-08-05 09:51:51 +03:00
Luis Meyer 58e1f5bcdf Rename Edge Config packages to Global Config (#452)
* Rename edge config packages

* Rename Global Config APIs

* Fix Global Config environment setup

* Rename Global Config endpoints

* Update Global Config documentation links

* Undo lockfile changes

* Update lockfile

* Undo lockfile changes

* Update lockfile

* Fall back to EDGE_CONFIG

---------

Co-authored-by: Andy Bitz <artzbitz@gmail.com>
2026-08-04 12:36:41 +02:00
christopherkindl 6ddb6b75aa [docs] upgrade geistdocs to 1.19 and rework the homepage layout (#457) 2026-07-31 16:25:46 +02:00
Dominik Ferber aec3c03430 @flags-sdk/posthog: upgrade posthog-node; explicit evaluation modes (#436)
* @flags-sdk/posthog: upgrade posthog-node

* @flags-sdk/posthog: make local vs remote evaluation explicit

The default adapter passed POSTHOG_PERSONAL_API_KEY into the runtime
posthog-node client, which enabled local evaluation and started a
feature-flag poller in every warm process. On serverless this produced
large, traffic-independent PostHog feature flag request volume.

Local evaluation is now opt-in via POSTHOG_SECRET_KEY; without it the
adapter evaluates remotely. POSTHOG_PERSONAL_API_KEY is used only by
getProviderData (Flags Explorer) and no longer affects runtime
evaluation. Drops the forced 10s poll interval in favor of the v5
default. Updates docs, README, and tests.

* remove unused @vercel/edge-config dependency

* add remote vs local tradeoffs

* rm edge config tag

* modernize

* rm trimKey

* lockfile

* update

* fixes

* reword changeset

* merge changesets

* reword changelog
2026-07-29 14:54:40 +00:00
Dominik Ferber 6dbf589e0c upgrade toolbar and others (#447) 2026-07-26 13:42:26 +00:00
Dominik Ferber 42cc02cacd upgrade more packages (#446) 2026-07-26 13:20:24 +00:00
Dominik Ferber 1f000784e5 upgrade vite & vitest (#445) 2026-07-26 08:25:37 -04:00
Dominik Ferber 0cf1f2b201 upgrade next and postcss (#444)
* upgrade postcss

* [snippets] upgrade postcss

* upgrade next

* upgrade postcss

* upgrade pnpm-lock
2026-07-26 07:35:48 -04:00
Dominik Ferber 622d56e608 fix(flags): remove @sveltejs/kit from peer dependencies (#442)
@sveltejs/kit was declared as an optional peer with a "*" range, causing
npm to auto-install the newest @sveltejs/kit and pull in its transitive
@sveltejs/vite-plugin-svelte → vite peer chain. In non-SvelteKit projects
already on Vite 7 (via Vitest, Storybook, etc.) this produced a hard
ERESOLVE error requiring `npm install --force`.

Move @sveltejs/kit to devDependencies so the sveltekit entrypoint still
builds and type-generates in the monorepo. SvelteKit consumers always have
@sveltejs/kit installed as the framework, so flags/sveltekit continues to
resolve it from their own tree.

fixes #440
2026-07-24 17:39:25 +03:00
Rich Haines f04785a0a1 Update Geistdocs to 1.14.2 (#437) 2026-07-21 13:38:34 +03:00
christopherkindl edbc76408d docs: update to geistdocs 1.8.0 and drop Flags from OSS dropdown (#407)
* docs: update to geistdocs 1.8.0 and drop Flags from OSS dropdown

Bump @vercel/geistdocs to 1.8.0 (eve logo, Streamdown dropped, AI Elements
last) and override navbarOssProducts to exclude Flags SDK on its own site.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* docs: link eve to /docs in OSS dropdown

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-23 14:29:20 -07:00
Rich Haines d8ed11ef08 Migrate docs app to @vercel/geistdocs (#391)
* Migrate docs app to Geistdocs canary

* Fix docs proxy matcher

* Use Geistdocs UI exports

* Update Geistdocs to 1.3.0

* upgrade geistdocs and fix svelte logo

* add copy prompt to certain docs pages

* migrate to 1.5.0

* refactor(docs): use geistdocs v1.5 Badge, CommandPrompt, ThemeAwareImage

Remove the local copies now exported by @vercel/geistdocs@1.5 and import
them from the package instead:

- Badge -> @vercel/geistdocs/components/badge (provider-list)
- CommandPrompt -> @vercel/geistdocs/components/command-prompt (install-command)
- ThemeAwareImage -> @vercel/geistdocs/components/theme-aware-image
  (docs MDX components); migrate the SvelteKit MDX call site to the new
  src={{ light, dark }} API.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(docs): restore install switcher width animation

The hero "For humans / For agents" switcher called router.refresh() on
every toggle (added in #366). That remounts/reconciles the switcher
subtree mid-toggle, resetting the CommandPrompt's measured width state so
the command-line width spring never plays — the line snapped instead of
growing.

Drop the refresh: this flag's only consumer is the switcher itself, so the
optimistic override already shows the correct command and the cookie
persists the choice across reloads (the server reads it and renders the
matching prebuilt `[code]`). The refresh changed nothing visible and only
broke the animation. startTransition() does not help, since router.refresh
already runs as a transition.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* refactor(docs): render home code blocks with geistdocs CodeBlock

Replace the hand-rolled shiki token renderer in HighlightedCode with
fumadocs highlight() + the geistdocs CodeBlock, highlighting with the
shared geistShikiTheme so the home page "Effortless setup" blocks match
the documentation (same syntax colors, header, language icon, copy
button, radius). transformerIcon() fills the filename icon slot; the
caption is preserved below.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(docs): equal-height home code blocks

Grow each HighlightedCode block to fill its grid cell (h-full root +
flex-1 wrapper forcing the Card to h-full) so both columns share the
taller block's height and their captions align. The Card and its <pre>
share bg-background-100, so the shorter block fills seamlessly.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* chore(docs): drop dead shadcn tokens (chart-*, sidebar-primary)

Only chart-1..5 and sidebar-primary are unused by both the app and the
geistdocs/fumadocs package CSS. The other shadcn tokens (secondary,
card-foreground, the remaining sidebar-* set, etc.) must stay: the package
stylesheet consumes them via var(--token) for its fd-* utility mappings
and the #nd-sidebar rule, and does not self-define them — the consuming
app has to provide them.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* refactor(docs): migrate consumers off shadcn tokens to Geist scale

Switch every shadcn-token consumer (select, switch, iframe-browser, the
home marketing pages, and the illustrations SVGs) to the Geist --ds-*
scale using the geistdocs PR #75 mapping (foreground->gray-1000,
muted->gray-100, muted-foreground->gray-800, border/input->gray-alpha-400,
ring->gray-600, destructive->red-800, background/card/popover->
background-100, accent->gray-100, etc.).

With no consumers left, drop the entire local shadcn layer from
geistdocs.css (the @theme --color-* mappings and the :root/.dark oklch
palette) and instead override fumadocs --color-fd-* and #nd-sidebar to
--ds-* (so the package's docs UI keeps working without the raw palette),
matching the geistdocs template. The geist utilities themselves come from
@vercel/geistdocs/styles.css.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Update geistdocs.css

* migrate to 1.6.0

* chore(docs): bump @vercel/geistdocs to 1.6.1

Picks up the Next.js logo gradient-id fix so the framework logo renders
correctly in the mobile docs menu.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Update pnpm-lock.yaml

* fix(docs): drop language icons from landing-page code blocks

The home "Effortless setup" snippets are Next.js examples, but the
language-based transformerIcon rendered a React glyph for the .tsx block.
Remove the icons (these blocks never had them) and hide the now-empty
header icon slot so the filename stays flush.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* chore(docs): drop redundant streamdown @source

The streamdown @source pointed at a transitive dep path that doesn't
resolve under pnpm (matched nothing). Streamdown is now sourced upstream
from @vercel/geistdocs's own styles.css, so this line is unneeded.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* update

* bump @vercel/geistdocs

* Update pnpm-lock.yaml

* update

---------

Co-authored-by: christopherkindl <53372002+christopherkindl@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-18 18:37:35 +02:00
Dominik Ferber 201f9d5988 Add bulk evaluation (#385)
* [flags] avoid re-imports

Avoid re-importing next/headers since it adds unnecessary microtask queue overhead

* [flags] avoid iife microtask queue overhead

* [flags] skip awaits where possible

* [flags] allow bulk eval

* wip

* add bulk mode to playground

* first try of bulk eval

* add bulk evaluation to adapters

* reuse

* simplify

* versions

* rm outdated changeset

* rm outdated changeset

* revert playground

* revert playground flags

* rm logs

* reuse cache of resolved flags for bulk

* simplify

* changesets

* support bulk([]) and bulk({})

* flagKey → key

* allow any type in expectPermutations

* avoid unnecessary mapping

* fix changeset

* validate package.json fields

* update package.json fields

* keep covariant

* adjust adapter types

* Merge bulk into evaluate (#392)

* merge bulk into evaluate

* add pages router compatibility

* better types

* add array test

* add test

* changesets

* use type import

* fix import

* extract readOverrides

* fix import of reportValue

* tracing

* skip bulkDecide for overwritten flags

* update changesets

* [changesets] onlyUpdatePeerDependentsWhenOutOfRange

* add type guard

* adjust changeset
2026-06-05 08:14:29 +00:00
Luis Meyer 7b5ea9a808 Reapply OIDC (#390)
* Reapply "Add oidc support (#374)" (#389)

This reverts commit 357ca676c6.

* bump oidc package

* review

* comments
2026-06-04 16:37:03 +02:00
Luis Meyer 357ca676c6 Revert "Add oidc support (#374)" (#389)
This reverts commit 72d36511d0.
2026-05-28 10:16:43 +03:00
Luis Meyer 72d36511d0 Add oidc support (#374)
* Add oidc support

* changeset

* update tests

* update def script

* fix provider data

* update changeset

* fix createVercelAdapter

* comments

* error
2026-05-28 08:59:00 +02:00
Dominik Ferber 9d425ebba0 set up trusted publisher and sign commits (#370) 2026-05-04 16:06:54 +02:00
Andy f4b2ec29f0 Update axios to 1.15.0 via lockfile (CVE-2026-40175) (#363) 2026-04-15 23:46:22 +02:00
github-actions[bot] 471e0048b6 Version Packages (#342)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-20 21:19:04 +02:00
Dominik Ferber 44460570d4 [vercel/flags-core] allow json flags (#335)
* rm unused import

* [vercel-flags] allow json flags

* add flags-playground

* wip

* clean up type

* reword changeset

* rm examples/flags-playground
2026-03-20 14:03:53 +02:00
Dominik Ferber 84e38d47aa adds an playground app we can use during development (#341)
* add flags-playground

* clarify

* move

* update lockfile
2026-03-20 11:45:27 +01:00
Vincent Derks c63be2d147 Added check to check skills size (#338)
* Added check to check skills size

* Change glob -> readdirSync

* Shorten description length

* Added check for name, compatibility and body

* Added back some parts that were removed to avoid regressions

* More cleanup

* Feedback: Used grey-matter for frontmatter parsing

* Added pnpm setup and install deps in Skills Quality job

* Refine triggers
2026-03-19 09:36:31 +00:00
github-actions[bot] 0af37593bd Version Packages (#331)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-12 21:53:04 +02:00
Dominik Ferber c9934fda03 [@vercel/flags-core] drop dependency on flags pkg (#332) 2026-03-12 21:24:11 +02:00
Anthony Shew 8b5af40701 chore: Upgrade turbo version (#323) 2026-03-10 15:51:39 +02:00
github-actions[bot] e44eedf0cf Version Packages (#315)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-09 19:08:17 +02:00
Dominik Ferber df427e0e7a use catalog for react & react-dom (#318)
* use catalog for react & react-dom

this guarantees the same version for all packages and thus avoids type errors

* update lockfile
2026-03-09 19:01:30 +02:00
Dominik Ferber e5f3e34428 [docs] depend on workspace version of flags (#314)
* fix dep

* add packageManager

* move devDeps to top-level
2026-03-09 18:26:11 +02:00
Dominik Ferber 2db1530275 Upgrade dependencies (#313)
* upgrade

* update biome

* upgrade more
2026-03-09 12:24:42 +00:00
Luis Meyer 96ba1226c8 Extract @vercel/prepare-flags-definitions package (#301)
* Extract @vercel/prepare-flags-definitions package

Extract the core flag definitions preparation logic from the Vercel CLI into a standalone, reusable package. This includes:
- prepareFlagsDefinitions() function that collects SDK keys from env, fetches definitions, and writes to node_modules
- hashSdkKey() helper for SHA-256 hashing
- generateDefinitionsModule() for JS module generation with deduplication and lazy parsing

Follows repo conventions: pnpm workspaces, tsup, vitest, ES modules with CJS fallback.

* Add JSDoc comments from original CLI source

* Add inline comments from original CLI source

* Add optional output parameter with debug logging

* Add output.time for datafile fetching

* Add changeset for @vercel/prepare-flags-definitions
2026-03-06 10:10:01 +01:00
Dominik Ferber b70c2ea466 Control (#278)
* refactor

* remove retries

* simplify

* simplify options

* before

* rename DataSource to Controller

* refactor and better tests

* avoid double polling

* rename

* fix

* simplify test setup

* wip

* unify

* wip

* only track 1 read per build

* make BundledSource lazy

* clean up fallback behavior

* add mode

* mutually exclusive streaming & polling

* rely more on black box testing

* simplify

* Update CLAUDE.md

* various fixes

* add tests

* more fixes

* Update CLAUDE.md

* more fixes

* resolve more issues

* unite black box tests

* tests

* progress

* adjust

* don't report on 401s; use Response.json

* enforce min polling interval

* progress

* types

* capture all logs

* throw with prefix

* added a minimum gap of `BASE_DELAY_MS` (1 second) between connection
 attempts

* step

* progress

* use request context in tests

* add separate tests depending on context

* tests

* rm unused option

* add state machine chart

* rm sources

* use fake timers for more tests

* swap remaining tests from msw to mocked fetch

* update comments

* Update CLAUDE.md

* update comment

* fix comment

* fix types

* rm peek

* adds ping checks and sending x-revision header  (#282)

* abort on missed pings

* use revision from bundled definitions

* tests

* simplify

* send x-revsion on reconnects too

* simplify StreamSource

* rename

* rename in test

* wait for stream

* replace startBackgroundUpdates with explicit call

* Update CLAUDE.md

* restore stronger tests

* Update CLAUDE.md

* convert

* simplify tests

* fix test

* fixes

* rm state machine

* await first poll before resoliving init

* rm outdated comment

* avoid leaking _origin

* changeset

* avoid log on reconnect due to missed pings

* don't warn on missed pings

* Update event reporting for control rewrite (#289)

* Update event reporting for control rewrite

* Log ingest response

* Use string for revision

* Add retries when ingesting events

* adapt changeset

* adjust test

---------

Co-authored-by: Luis Meyer <luis.meyer@vercel.com>
Co-authored-by: Andy <AndyBitz@users.noreply.github.com>
Co-authored-by: Andy Bitz <artzbitz@gmail.com>
2026-03-06 10:05:01 +02:00
Vincent Derks 689b1575f6 Flags core as normal dep (#298)
* Changed @vercel/flags-core to dependency from peerDependency

* Updated docs and skills

* More explanation

* Updated skill with singleton explanation and example

* update README

* FLAGS_SDK_KEY → FLAGS

* update skill

* update changeset

---------

Co-authored-by: Dominik Ferber <dominik.ferber@gmail.com>
2026-03-05 12:53:04 +01:00
Dominik Ferber 42e07a19a0 fix flags explorer (#285)
* fix id warning

* set up toolbar & flags explorer

* fix discovery endpoint
2026-02-25 10:55:33 +02:00
github-actions[bot] fa58c6900d Version Packages (#275)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-02-13 15:19:35 +02:00
Dominik Ferber 7d7719a255 [@vercel/flags-core] deduplicate concurrent initialize() calls (#274)
* add shop

* wip

* fix parallel init initialize

* avoid double polling

* add tests

* rm shirt-shop-vercel

* ignore

* refactor

* rm unnecessary fix

* minimal

* changeset

* fix tests
2026-02-13 14:34:46 +02:00
Hayden Bleasel cf9ccd0076 Open Source Docs (#272)
* Scaffold Geistdocs instance

* Update biome.json

* Replace content

* Re-path docs

* Update docs package name

* Misc fixes

* Update geistdocs.tsx

* Move content to correct folder

* Start migrating custom components

* Finish migrating custom components

* Migrate existing redirects

* Remove #next suffixes from code blocks

* Migrate homepage and flags

* Remove duplicate lockfiles

* Start fixing homepage

* Replace Geist components

* Fix colors

* Improve layout

* Fix code blocks

* Fix hero

* Fix illustrations

* Fix redirect

* Fix nav links

* Patch in FrameworkSwitcher

* Bump Next.js in docs

* Delete turbo.json

* Misc fixes

* More logo fixes
2026-02-13 09:06:03 +02:00
Dominik Ferber 53149f5e81 add client (#255)
* prepare

* origin

* prepare script

* step

* redo peer deps

* wip

* continue

* every 5 secs

* connect flag network

* add shirt-shop-vercel

* upgrade

* push

* update endpoint

* add vercel getProviderData

* fix importts

* Add retries to flag network datasource (#237)

* Fix React Server Components CVE vulnerabilities (#235)

Updated dependencies to fix Next.js and React CVE vulnerabilities.

The fix-react2shell-next tool automatically updated the following packages to their secure versions:
- next
- react-server-dom-webpack
- react-server-dom-parcel  
- react-server-dom-turbopack

All package.json files have been scanned and vulnerable versions have been patched to the correct fixed versions based on the official React advisory.

Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>

* Add retries to flag network datasource when stream closes

Implements automatic retry logic with exponential backoff when the flag network
stream unexpectedly closes. The stream will retry with delays increasing from
1s to a maximum of 30s, allowing the datasource to recover from temporary
network issues while falling back to bundled definitions if initial connection
fails.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Revert package.json and pnpm-lock changes

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: vercel[bot] <35613825+vercel[bot]@users.noreply.github.com>
Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>
Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>

* use ndjson (#238)

* try

* try

* use debugLog

* replace testkey

* never retry on 4xx

* Track FLAG_CONFIG_READ events

* update @biomejs/biome

* send user-agent, rm terminate handling, fix tests

* extract usage-tracker and add tests

* rm EdgeConfigDataSource

* export EvaluationParams and EvaluationResult

* drop edge-config dep

* drop edge config from @flags-sdk/vercel

* adapt @flags-sdk/vercel

* fix integration tests

* wip

* assert ingest requests

* race initial connection, retry in background, abort on shutdown

* rm store

* make readBundledDefinitions async

* read from @vercel/flags-definitions/definitions.json

* add ensureFallback fn

* getDefaultFlagsClient() → flagsClient

* rm process.pid

* rm webpackIgnore: true

* require fallbacks at build time on vercel only

* test in layout

* vercel-flags prepare --verbose

* rm prebuild script

* ensure fallback from instrumentation.ts

* rm last process.pid

* print warning

* Track duration and cache status for config reads

* add tests

* await stream in initialize method

* consumeStream → runStreamLoop

* replace subscribe with doInitialize

* add webpackIgnore

* make @vercel/flags-core a peer dep

* fresh start

* debug

* step

* next-connection

* avoid opening stream during builds

* undo next specific exports

* handle abort

* fake

* poc

* clean up imports

* next-js exports

* upgrade next

* move "use cache" up

* move "use cache" handling to client

* split index.default.ts and index.next-js.ts

* separate

* jsdoc

* use scoped map instead of passing ref

* move jsdoc

* rename

* keep dataSource private, clean clientMap

* reset retryCount on connection; abort on 401

* break after 10 retries

* add backoff with jitter + limit

* add usage tracking and read fallback

* refactor

* extract stream-connection, update tests

* add tests

* reduce test amount

* add perf metadata

* add BaseEvaluationResult

* getData → read

* rm shirt-shop-vercel

* drop next-connection

* update pnpm-lock

* getMetadata → getInfo

* add getDatafile

* DataSourceData → Datafile

* merge metrics into datafile

* simplify metrics

* use embed for getDatafile

* add comment

* comment

* bring shirt-shop-vercel back

* try setCacheLife

* support cache components in OpenFeature import

* use new format

* rm cli

* fix origin

* use bundler

* simplify

* ensure warning is highlighted in build logs

* warn only once

* ensureFallback → getFallbackDatafile

* improve perf

* avoid creating new objects

* fix type issues

* stop exposing createRawClient

* fix: mark stream reconnection loop as intentional fire-and-forget

Add void operator before async IIFE to explicitly indicate the floating
promise is intentional, preventing linter warnings and making the code
intent clearer to future maintainers.

* fix: handle malformed JSON in stream messages gracefully

Wrap JSON.parse in try/catch to prevent crashes from malformed server
responses. Logs a warning and skips the invalid message instead of
crashing the stream connection handler.

* fix: add bounds checking for variant index access

Add getVariant() helper that throws a descriptive error if the variant
index is out of bounds. This prevents silent undefined returns when
variant indices are invalid, making issues easier to debug in production.

* fix: prevent concurrent initialization race condition

Add initializingPromise to coordinate concurrent initialize() calls.
The fast boolean check is preserved for the hot path, while concurrent
calls during initialization now await the same promise instead of
triggering multiple initializations.

* fix: add timeout and retry logic to fetchDatafile

- Add 10-second timeout using AbortController to prevent indefinite hangs
- Add exponential backoff retry (up to 3 attempts) for transient failures
- Skip retries for 4xx client errors (except 429 rate limiting)
- Improves resilience against network issues in production

* fix: prevent race condition in ensureStream

Use local variable for abortController and store streamPromise
immediately after creation. This prevents concurrent calls from
creating multiple streams or overwriting the abort controller
before the promise is stored.

* fix: prevent race condition in read() by capturing data reference

Capture this.data reference at the start of read() to ensure consistent
state throughout the method. The onMessage callback from the stream can
update this.data during async operations, which could cause inconsistent
behavior if the reference changes mid-operation.

* comments

* add streaming connectionState

* update usage

* fix init

* try to avoid hanging promise

* update attw, add types

* get rid of unnecessary async/await

* avoid printing the warning

* distinct warnings

* don't export cachedFns

* add CLAUDE.md

* jsdoc

* clear timeout

* export Datafile

* avoid exposing data sources

* simplify

* types

* avoid dangling timeout

* more options

* tests

* allow options in createClient

* DatafileInput

* better options

* Update event tracking to use streams

* Revert "Update event tracking to use streams"

This reverts commit cff740a18c.

* fix datafile input type

* type

* handle shutdown and re-init

* defensive

* retry stream for up to 15 minutes

* Update event reporting to use ndjson for more events

* Revert "Update event reporting to use ndjson for more events"

This reverts commit f70a7bfc59.

* Add debug logs to the usage tracker

* [adapter-vercel] fix getProviderData

* [adapter-vercel] only return vercel flags from getProviderData

* fix

* rm getInfo

* rm tgz

* rm example

* rm next/connection from gitignore

* rm unused deps

* use DatafileInput type

* fix tests

* ensure pollCount > 0

* fix type issues

* fix retry logic

* upgrade @sveltejs/kit

* resolve ci issues

---------

Co-authored-by: Luis Meyer <luis.meyer@vercel.com>
Co-authored-by: vercel[bot] <35613825+vercel[bot]@users.noreply.github.com>
Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>
Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>
Co-authored-by: Andy Bitz <artzbitz@gmail.com>
2026-02-09 11:45:00 +02:00
Vincent Derks 9e2432073d Updated @changeset/cli to 2.29.8 (#253) 2026-02-06 12:08:46 +01:00
Vincent Derks ab71eb271c Updated optional peer dep @sveltesj/kit to 2.49.5 (#251) 2026-02-06 11:21:23 +01:00
Vincent Derks 170364de7e Updated rimraf to 6.1.2 (#252) 2026-02-06 11:20:48 +01:00
Vincent Derks 4577689667 Updated @playwright/test to 1.58.1 (#249) 2026-02-06 10:43:44 +01:00
dependabot[bot] 4003a93198 Bump @sveltejs/kit from 2.47.3 to 2.49.5 (#250)
* Bump @sveltejs/kit from 2.47.3 to 2.49.5

Bumps [@sveltejs/kit](https://github.com/sveltejs/kit/tree/HEAD/packages/kit) from 2.47.3 to 2.49.5.
- [Release notes](https://github.com/sveltejs/kit/releases)
- [Changelog](https://github.com/sveltejs/kit/blob/main/packages/kit/CHANGELOG.md)
- [Commits](https://github.com/sveltejs/kit/commits/@sveltejs/kit@2.49.5/packages/kit)

---
updated-dependencies:
- dependency-name: "@sveltejs/kit"
  dependency-version: 2.49.5
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>

* Trigger CI

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Vincent Derks <vincent.derks@vercel.com>
2026-02-06 10:37:34 +01:00
Vincent Derks a1b77293c5 Updated tsup to 8.5.1 (#248) 2026-02-06 10:28:32 +01:00
dependabot[bot] 1d59ce11de Bump next from 16.0.10 to 16.1.5 in /packages/flags (#247)
* Bump next from 16.0.10 to 16.1.5 in /packages/flags

Bumps [next](https://github.com/vercel/next.js) from 16.0.10 to 16.1.5.
- [Release notes](https://github.com/vercel/next.js/releases)
- [Changelog](https://github.com/vercel/next.js/blob/canary/release.js)
- [Commits](https://github.com/vercel/next.js/compare/v16.0.10...v16.1.5)

---
updated-dependencies:
- dependency-name: next
  dependency-version: 16.1.5
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>

* Updated lockfile

* Bump to 16.1.5 in other packages

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Vincent Derks <vincent.derks@vercel.com>
2026-02-06 10:07:56 +01:00
dependabot[bot] d496766623 Bump next from 15.5.9 to 15.5.10 in /tests/next-15 (#246)
* Bump next from 15.5.9 to 15.5.10 in /tests/next-15

Bumps [next](https://github.com/vercel/next.js) from 15.5.9 to 15.5.10.
- [Release notes](https://github.com/vercel/next.js/releases)
- [Changelog](https://github.com/vercel/next.js/blob/canary/release.js)
- [Commits](https://github.com/vercel/next.js/compare/v15.5.9...v15.5.10)

---
updated-dependencies:
- dependency-name: next
  dependency-version: 15.5.10
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Updated lockfile

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Vincent Derks <vincent.derks@vercel.com>
2026-02-06 09:46:45 +01:00
dependabot[bot] 51fb9fdff4 Bump vite from 6.0.3 to 6.4.1 (#245)
* Bump vite from 6.0.3 to 6.4.1

Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 6.0.3 to 6.4.1.
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/create-vite@6.4.1/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 6.4.1
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>

* Trigger CI

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Vincent Derks <vincent.derks@vercel.com>
2026-02-06 09:37:15 +01:00
dependabot[bot] 61dbb7d157 Bump vite from 6.2.5 to 6.4.1 (#244)
* Bump vite from 6.2.5 to 6.4.1

Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 6.2.5 to 6.4.1.
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/create-vite@6.4.1/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 6.4.1
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>

* Trigger CI

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Vincent Derks <vincent.derks@vercel.com>
2026-02-06 09:25:16 +01:00