Yang Jun
df943f471e
fix: round negative half away from zero to match Ruby/Shopify behavior
...
Math.round(-2.5) returns -2 in JS (toward zero), but Ruby rounds to -3 (away from zero). Use sign-preserving abs+round to match Shopify Liquid.
Closes #871
Made-with: Cursor
2026-04-08 00:44:50 +08:00
Timmy Braun and GitHub
4f9a49988a
fix: null date should return empty ( #868 ) ( #872 )
2026-04-08 00:10:33 +08:00
Yang Jun and GitHub
f41c1fc02f
fix: enforce root containment for renderFile/parseFile lookups ( #870 )
...
Made-with: Cursor
2026-04-07 23:18:53 +08:00
semantic-release-bot
db4348507e
chore(release): 10.25.4 [skip ci]
...
## [10.25.4](https://github.com/harttle/liquidjs/compare/v10.25.3...v10.25.4 ) (2026-04-07)
### Bug Fixes
* sort and sort_natural filters bypass ownPropertyOnly ([#869 ](https://github.com/harttle/liquidjs/issues/869 )) ([e743da0 ](https://github.com/harttle/liquidjs/commit/e743da0020d34e2ee547e1cc1a86b58377ebe1ce ))
v10.25.4
2026-04-07 13:02:49 +00:00
Yang Jun and GitHub
e743da0020
fix: sort and sort_natural filters bypass ownPropertyOnly ( #869 )
...
Use _getFromScope for property access in sort/sort_natural filters to respect the ownPropertyOnly security option, preventing prototype chain traversal that could leak sensitive inherited properties.
Also extract shared sortBy helper, add orderedCompare with nil handling consistent with caseInsensitiveCompare and Ruby Liquid.
Made-with: Cursor
2026-04-07 21:01:20 +08:00
semantic-release-bot
8f69a08399
chore(release): 10.25.3 [skip ci]
...
## [10.25.3](https://github.com/harttle/liquidjs/compare/v10.25.2...v10.25.3 ) (2026-04-06)
### Bug Fixes
* precise memoryLimit for string replace ([abc058b ](https://github.com/harttle/liquidjs/commit/abc058be0f33d6372cd2216f4945183167abeb25 ))
* use realpath for fs.contains ([#867 ](https://github.com/harttle/liquidjs/issues/867 )) ([529dd67 ](https://github.com/harttle/liquidjs/commit/529dd67eeb6b125637623d6a723601f0938d3613 ))
v10.25.3
2026-04-06 06:45:50 +00:00
Yang Jun and GitHub
529dd67eeb
fix: use realpath for fs.contains ( #867 )
...
* fix: use realpath for fs.contains
* chore: reset file mode changes
Made-with: Cursor
* fix: Windows compat for contains/containsSync and toLiquidAsync arg order
Made-with: Cursor
2026-04-06 14:40:35 +08:00
Harttle
abc058be0f
fix: precise memoryLimit for string replace
2026-03-26 19:36:31 +08:00
semantic-release-bot
521177e3f6
chore(release): 10.25.2 [skip ci]
...
## [10.25.2](https://github.com/harttle/liquidjs/compare/v10.25.1...v10.25.2 ) (2026-03-25)
### Bug Fixes
* handle undefined replacement argument in replace filter ([#864 ](https://github.com/harttle/liquidjs/issues/864 )) ([0ad2b11 ](https://github.com/harttle/liquidjs/commit/0ad2b11ab15e7da608a9ef936b2a00a6a6517038 ))
v10.25.2
2026-03-25 17:20:39 +00:00
75e06eff92
docs: add joecottam as a contributor for code ( #865 )
...
* docs: update README.md [skip ci]
* docs: update .all-contributorsrc [skip ci]
---------
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
2026-03-26 01:19:19 +08:00
Joe Cottam and GitHub
0ad2b11ab1
fix: handle undefined replacement argument in replace filter ( #864 )
2026-03-26 01:18:40 +08:00
semantic-release-bot
97d829116c
chore(release): 10.25.1 [skip ci]
...
## [10.25.1](https://github.com/harttle/liquidjs/compare/v10.25.0...v10.25.1 ) (2026-03-22)
### Bug Fixes
* mem limiter for invalid ranges ([95ddefc ](https://github.com/harttle/liquidjs/commit/95ddefc056a11a44d9e753fd47a39db2c241e578 ))
* treat args for replace_first as literal ([35d5230 ](https://github.com/harttle/liquidjs/commit/35d523026345d80458df24c72e653db78b5d061d ))
v10.25.1
2026-03-22 14:18:52 +00:00
Harttle
35d5230263
fix: treat args for replace_first as literal
2026-03-22 22:16:45 +08:00
Harttle
94440a0653
chore: more strict mem limit for string filters
2026-03-22 22:10:39 +08:00
Yang Jun and Harttle
95ddefc056
fix: mem limiter for invalid ranges
2026-03-22 10:24:03 +08:00
Yang Jun and GitHub
1b85fdaa9c
docs: update contact in security.md ( #862 )
2026-03-08 15:41:45 +08:00
semantic-release-bot
93c38c7c6d
chore(release): 10.25.0 [skip ci]
...
# [10.25.0](https://github.com/harttle/liquidjs/compare/v10.24.0...v10.25.0 ) (2026-03-07)
### Bug Fixes
* path traversal vulnerability, [#851 ](https://github.com/harttle/liquidjs/issues/851 ) ([#855 ](https://github.com/harttle/liquidjs/issues/855 )) ([3cd024d ](https://github.com/harttle/liquidjs/commit/3cd024d652dc883c46307581e979fe32302adbac ))
### Features
* export error types, resolving [#837 ](https://github.com/harttle/liquidjs/issues/837 ) ([#840 ](https://github.com/harttle/liquidjs/issues/840 )) ([71aa1b1 ](https://github.com/harttle/liquidjs/commit/71aa1b1998a3a66e536af67c6ea8947a28616eaf ))
v10.25.0
2026-03-07 20:01:42 +00:00
Yang Jun and GitHub
c7a291b46b
chore: update semantic-release dependencies ( #861 )
2026-03-08 04:00:26 +08:00
Yang Jun and GitHub
eb4683ee3f
chore: update to NPM Trusted Release ( #860 )
2026-03-08 03:35:49 +08:00
Yang Jun and GitHub
f1fc573a65
docs: state differences regarding inspect array/hash, #852 , #853 ( #858 )
2026-03-08 03:14:13 +08:00
524cd92cfe
docs: add peaktwilight as a contributor for code ( #857 )
...
* docs: update README.md [skip ci]
* docs: update .all-contributorsrc [skip ci]
---------
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
2026-03-08 02:40:16 +08:00
0d9e797889
docs: add MorielHarush as a contributor for code ( #856 )
...
* docs: update README.md [skip ci]
* docs: update .all-contributorsrc [skip ci]
---------
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
2026-03-08 02:39:45 +08:00
3cd024d652
fix: path traversal vulnerability, #851 ( #855 )
...
* Fix Path Traversal fallback
* Update loader.ts
Fixed nested
* Update loader.ts
padding fix
* refactor: reuse root enforcing
* docs: update test case and docs
---------
Co-authored-by: MorielHarush <[email protected] >
2026-03-08 02:36:09 +08:00
Yang Jun and GitHub
85233e0568
docs: update testmu sponsor link ( #850 )
2026-02-14 13:54:03 +08:00
Yang Jun and GitHub
02403a1879
docs: Change LambdaTest to TestMu AI ( #848 )
2026-01-19 23:26:49 +08:00
Yang Jun and GitHub
1c6316111d
docs: update docs for operators ( #847 )
2026-01-10 22:09:10 +08:00
Yang Jun and GitHub
71aa1b1998
feat: export error types, resolving #837 ( #840 )
2025-11-22 00:27:44 +08:00
350f95c8f7
docs: add rongjiecomputer as a contributor for code ( #835 )
...
* docs: update README.md [skip ci]
* docs: update .all-contributorsrc [skip ci]
---------
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
2025-11-11 13:59:45 +08:00
Loo Rong Jie and GitHub
955b7971c0
Support having new line and other whitespace after include filename ( #834 )
2025-11-11 13:58:12 +08:00
8686876067
docs: add immerrr as a contributor for doc ( #831 )
...
* docs: update README.md [skip ci]
* docs: update .all-contributorsrc [skip ci]
---------
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
2025-10-31 09:35:15 +08:00
immerrr again and GitHub
3a02eb12bf
docs: update tutorial on operators and precedence ( #830 )
2025-10-31 09:34:05 +08:00
semantic-release-bot
906707833e
chore(release): 10.24.0 [skip ci]
...
# [10.24.0](https://github.com/harttle/liquidjs/compare/v10.23.0...v10.24.0 ) (2025-10-27)
### Features
* **filters:** Add base64_encode and base64_decode filters for Shopify compatibility ([#828 ](https://github.com/harttle/liquidjs/issues/828 )) ([86fc135 ](https://github.com/harttle/liquidjs/commit/86fc135d9ec0137689faf150535b9315e75ecc30 ))
v10.24.0
2025-10-27 14:53:37 +00:00
a2da822cb8
docs: add rosomri as a contributor for code ( #829 )
...
* docs: update README.md [skip ci]
* docs: update .all-contributorsrc [skip ci]
---------
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
2025-10-27 22:42:15 +08:00
Omri Rosner and GitHub
86fc135d9e
feat(filters): Add base64_encode and base64_decode filters for Shopify compatibility ( #828 )
...
* feat(filters): add base64 encode and decode
* fix: use Object.defineProperty for cross-platform btoa/atob mocking
* docs(filters): update docs
* docs(filters): update version
2025-10-27 22:40:31 +08:00
Yang Jun and GitHub
5d953132e8
docs: add lambdatest to sponsors ( #826 )
2025-10-26 15:00:27 +08:00
2858271c8f
docs: add skynetigor as a contributor for code ( #825 )
...
* docs: update README.md [skip ci]
* docs: update .all-contributorsrc [skip ci]
---------
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
2025-10-23 22:23:52 +08:00
semantic-release-bot
d22945ed5f
chore(release): 10.23.0 [skip ci]
...
# [10.23.0](https://github.com/harttle/liquidjs/compare/v10.22.0...v10.23.0 ) (2025-10-23)
### Features
* Export specific tokens as types ([#824 ](https://github.com/harttle/liquidjs/issues/824 )) ([4f7d2fd ](https://github.com/harttle/liquidjs/commit/4f7d2fd84a8884e1009b13346d331a99b9721149 ))
v10.23.0
2025-10-23 13:38:41 +00:00
Ihor Panasiuk and GitHub
4f7d2fd84a
feat: Export specific tokens as types ( #824 )
...
* Export specific tokens as types
* Update index.ts
2025-10-23 21:37:20 +08:00
semantic-release-bot
597ce7305f
chore(release): 10.22.0 [skip ci]
...
# [10.22.0](https://github.com/harttle/liquidjs/compare/v10.21.1...v10.22.0 ) (2025-10-06)
### Bug Fixes
* math filters coerce invalid string to 0, [#813 ](https://github.com/harttle/liquidjs/issues/813 ) ([#819 ](https://github.com/harttle/liquidjs/issues/819 )) ([e8e502c ](https://github.com/harttle/liquidjs/commit/e8e502c5854c9649bf7611a671a068dc260011d1 ))
### Features
* allow context access in liquidMethodMissing, [#808 ](https://github.com/harttle/liquidjs/issues/808 ) ([#820 ](https://github.com/harttle/liquidjs/issues/820 )) ([e551288 ](https://github.com/harttle/liquidjs/commit/e55128850e507687f9d85a012fc3a72ac2550f3b ))
v10.22.0
2025-10-06 14:45:55 +00:00
Yang Jun
d7fa8ba5f1
chore: update node version for release workflow
2025-10-06 22:44:24 +08:00
Yang Jun and GitHub
1b356d350d
chore: fix Github artifact name ( #821 )
2025-10-06 22:32:34 +08:00
Yang Jun and GitHub
e55128850e
feat: allow context access in liquidMethodMissing, #808 ( #820 )
2025-10-06 18:34:08 +08:00
Yang Jun and GitHub
e8e502c585
fix: math filters coerce invalid string to 0, #813 ( #819 )
2025-10-06 18:31:43 +08:00
b8bc4db46c
docs: add StreakingMan as a contributor for doc ( #812 )
...
* docs: update README.md [skip ci]
* docs: update .all-contributorsrc [skip ci]
---------
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
2025-08-13 19:15:43 +08:00
裸奔狂甩丁丁 and GitHub
68d500c18a
docs: operators.md zh-cn translation ( #811 )
2025-08-13 19:14:47 +08:00
semantic-release-bot
de12359bfd
chore(release): 10.21.1 [skip ci]
...
## [10.21.1](https://github.com/harttle/liquidjs/compare/v10.21.0...v10.21.1 ) (2025-05-14)
### Bug Fixes
* block.super with strictVariables, [#806 ](https://github.com/harttle/liquidjs/issues/806 ) ([#807 ](https://github.com/harttle/liquidjs/issues/807 )) ([025c40f ](https://github.com/harttle/liquidjs/commit/025c40f0f2f13efa62193c61d2fa56943917ac3c ))
v10.21.1
2025-05-14 17:49:27 +00:00
Yang Jun and GitHub
025c40f0f2
fix: block.super with strictVariables, #806 ( #807 )
2025-05-15 01:47:57 +08:00
Vlad GURDIGA and GitHub
2f414f8e40
docs: Fix formatting bug in echo.md ( #805 )
...
DISCLAIMER: This may not be the proper way to approach the issue.
Although the Markdown code is proper, on the website itself it is incorrectly rendered as "{{` and `}}".
The reason for the disclaimer above is that I’m imagining this may be an issue at the content rendering level, and my fix here is just a workaround of that issue. — Given this, I’ll not be offended if this PR of mine is rejected and closed. 🙂
2025-05-10 20:35:07 +08:00
Vlad GURDIGA and GitHub
40c52124d7
docs: Fix typo in options.md ( #802 )
...
Looks like just a typo.
2025-05-09 21:16:08 +08:00
ae0c07e60b
docs: add gurdiga as a contributor for doc ( #804 )
...
* docs: update README.md [skip ci]
* docs: update .all-contributorsrc [skip ci]
---------
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
2025-05-09 20:37:59 +08:00