Releases: webdriverio/visual-testing
@wdio/visual-service@9.2.2
Patch Changes
-
db33fa7: ####
@wdio/image-comparison-coreand@wdio/ocr-serviceSecurity: update jimp (CVE infile-typetransitive dep)Bumped
jimpto the latest version to resolve a reported vulnerability in itsfile-typetransitive dependency (see #1130, raised by @denis-sokolov, thank you!).Actual impact on these packages
file-typeis used by@jimp/coresolely to detect image MIME types when reading a buffer. In both@wdio/image-comparison-coreand@wdio/ocr-service, every image passed to jimp originates from either WebDriver screenshots (browser-controlled base64 data) or local files written by the framework itself. There is no code path where untrusted external input is fed directly into jimp, which removes the exploitability that the CVE describes.That said, the reputational and compliance risk was real, security scanners flag the package as vulnerable, enterprise users hit audit failures, and some organisations block installation of packages with known CVEs. The update addresses all of that.
@wdio/visual-reporterand@wdio/visual-serviceUpdated internal dependencies to pick up the jimp bump in
@wdio/image-comparison-core.Committers: 1
- Wim Selles (@wswebcreation)
-
Updated dependencies [db33fa7]
- @wdio/image-comparison-core@1.2.2
@wdio/visual-reporter@0.4.13
Patch Changes
-
db33fa7: ####
@wdio/image-comparison-coreand@wdio/ocr-serviceSecurity: update jimp (CVE infile-typetransitive dep)Bumped
jimpto the latest version to resolve a reported vulnerability in itsfile-typetransitive dependency (see #1130, raised by @denis-sokolov, thank you!).Actual impact on these packages
file-typeis used by@jimp/coresolely to detect image MIME types when reading a buffer. In both@wdio/image-comparison-coreand@wdio/ocr-service, every image passed to jimp originates from either WebDriver screenshots (browser-controlled base64 data) or local files written by the framework itself. There is no code path where untrusted external input is fed directly into jimp, which removes the exploitability that the CVE describes.That said, the reputational and compliance risk was real, security scanners flag the package as vulnerable, enterprise users hit audit failures, and some organisations block installation of packages with known CVEs. The update addresses all of that.
@wdio/visual-reporterand@wdio/visual-serviceUpdated internal dependencies to pick up the jimp bump in
@wdio/image-comparison-core.Committers: 1
- Wim Selles (@wswebcreation)
@wdio/ocr-service@2.2.9
Patch Changes
-
db33fa7: ####
@wdio/image-comparison-coreand@wdio/ocr-serviceSecurity: update jimp (CVE infile-typetransitive dep)Bumped
jimpto the latest version to resolve a reported vulnerability in itsfile-typetransitive dependency (see #1130, raised by @denis-sokolov, thank you!).Actual impact on these packages
file-typeis used by@jimp/coresolely to detect image MIME types when reading a buffer. In both@wdio/image-comparison-coreand@wdio/ocr-service, every image passed to jimp originates from either WebDriver screenshots (browser-controlled base64 data) or local files written by the framework itself. There is no code path where untrusted external input is fed directly into jimp, which removes the exploitability that the CVE describes.That said, the reputational and compliance risk was real, security scanners flag the package as vulnerable, enterprise users hit audit failures, and some organisations block installation of packages with known CVEs. The update addresses all of that.
@wdio/visual-reporterand@wdio/visual-serviceUpdated internal dependencies to pick up the jimp bump in
@wdio/image-comparison-core.Committers: 1
- Wim Selles (@wswebcreation)
@wdio/image-comparison-core@1.2.2
Patch Changes
-
db33fa7: ####
@wdio/image-comparison-coreand@wdio/ocr-serviceSecurity: update jimp (CVE infile-typetransitive dep)Bumped
jimpto the latest version to resolve a reported vulnerability in itsfile-typetransitive dependency (see #1130, raised by @denis-sokolov, thank you!).Actual impact on these packages
file-typeis used by@jimp/coresolely to detect image MIME types when reading a buffer. In both@wdio/image-comparison-coreand@wdio/ocr-service, every image passed to jimp originates from either WebDriver screenshots (browser-controlled base64 data) or local files written by the framework itself. There is no code path where untrusted external input is fed directly into jimp, which removes the exploitability that the CVE describes.That said, the reputational and compliance risk was real, security scanners flag the package as vulnerable, enterprise users hit audit failures, and some organisations block installation of packages with known CVEs. The update addresses all of that.
@wdio/visual-reporterand@wdio/visual-serviceUpdated internal dependencies to pick up the jimp bump in
@wdio/image-comparison-core.Committers: 1
- Wim Selles (@wswebcreation)
@wdio/visual-service@9.2.1
Patch Changes
-
d5afb54: ## #1129 Fix
TypeError: element.getBoundingClientRect is not a functionwhen aChainablePromiseElementis passed tocheckElementWhen
checkElement(orsaveElement) was called with aChainablePromiseElement, the lazy promise-based element reference that WebdriverIO's$()returns, the element was passed directly as an argument tobrowser.execute()without being awaited first.browser.execute()serializes its arguments for transfer to the browser context and cannot handle a pending Promise, so it arrived in the browser as a plain empty object{}instead of a WebElement reference. This causedelement.getBoundingClientRect is not a functionbecause the browser-sidescrollElementIntoViewscript received{}rather than a DOM element.Committers: 1
- Wim Selles (@wswebcreation)
-
Updated dependencies [d5afb54]
- @wdio/image-comparison-core@1.2.1
@wdio/image-comparison-core@1.2.1
Patch Changes
-
d5afb54: ## #1129 Fix
TypeError: element.getBoundingClientRect is not a functionwhen aChainablePromiseElementis passed tocheckElementWhen
checkElement(orsaveElement) was called with aChainablePromiseElement, the lazy promise-based element reference that WebdriverIO's$()returns, the element was passed directly as an argument tobrowser.execute()without being awaited first.browser.execute()serializes its arguments for transfer to the browser context and cannot handle a pending Promise, so it arrived in the browser as a plain empty object{}instead of a WebElement reference. This causedelement.getBoundingClientRect is not a functionbecause the browser-sidescrollElementIntoViewscript received{}rather than a DOM element.Committers: 1
- Wim Selles (@wswebcreation)
@wdio/visual-service@9.2.0
Minor Changes
-
994f4da: ## #857 Support ignore regions for web screenshots
Add
ignoresupport to all web screenshot methods (saveScreen/checkScreen,saveElement/checkElement,saveFullPageScreen/checkFullPageScreen) so that specified elements can be blocked out during visual comparison. This brings web parity with the native-app ignore-region support that already existed.Changes
- Ignore regions for full-page screenshots: new
determineWebFullPageIgnoreRegionsfunction that calculates ignore-region rectangles for full-page screenshots, including afullPageCropTopPaddingCSScorrection for mobile scroll-and-stitch scenarios where the address-bar shadow padding shifts element positions - Consolidated
ignoreRegionPadding: movedignoreRegionPaddingintoBaseWebScreenshotOptionsso it is inherited by all web methods instead of being duplicated per method - Fix
isAndroidNativeWebScreenshottype: ensurenativeWebScreenshotis always a boolean (was accidentally an object for LambdaTest capabilities), preventing ignore-region DPR scaling failures - Fix viewport rounding for mobile: restore
Math.round()ininjectWebviewOverlayand removeMath.minclamping ingetMobileViewPortPositionto prevent 1-pixel crop shifts during full-page stitching - Fix
scrollElementIntoViewfor scrolled pages: account forcurrentPosition(existing scroll offset) when computing the target scroll position, so elements are scrolled into view correctly when the page is already scrolled - Dismiss Chrome Start Surface on Android: when Chrome's tab-overview UI blocks the webview overlay, automatically press the Android Back button (up to 4 retries) to restore the active tab before measuring the viewport
- Add hybrid status bar blockout: on hybrid apps the statusbar was not blocked out which could result in flaky tests regarding battery and reception
Committers: 1
- Wim Selles (@wswebcreation)
- Ignore regions for full-page screenshots: new
Patch Changes
- Updated dependencies [994f4da]
- @wdio/image-comparison-core@1.2.0
@wdio/image-comparison-core@1.2.0
Minor Changes
-
994f4da: ## #857 Support ignore regions for web screenshots
Add
ignoresupport to all web screenshot methods (saveScreen/checkScreen,saveElement/checkElement,saveFullPageScreen/checkFullPageScreen) so that specified elements can be blocked out during visual comparison. This brings web parity with the native-app ignore-region support that already existed.Changes
- Ignore regions for full-page screenshots: new
determineWebFullPageIgnoreRegionsfunction that calculates ignore-region rectangles for full-page screenshots, including afullPageCropTopPaddingCSScorrection for mobile scroll-and-stitch scenarios where the address-bar shadow padding shifts element positions - Consolidated
ignoreRegionPadding: movedignoreRegionPaddingintoBaseWebScreenshotOptionsso it is inherited by all web methods instead of being duplicated per method - Fix
isAndroidNativeWebScreenshottype: ensurenativeWebScreenshotis always a boolean (was accidentally an object for LambdaTest capabilities), preventing ignore-region DPR scaling failures - Fix viewport rounding for mobile: restore
Math.round()ininjectWebviewOverlayand removeMath.minclamping ingetMobileViewPortPositionto prevent 1-pixel crop shifts during full-page stitching - Fix
scrollElementIntoViewfor scrolled pages: account forcurrentPosition(existing scroll offset) when computing the target scroll position, so elements are scrolled into view correctly when the page is already scrolled - Dismiss Chrome Start Surface on Android: when Chrome's tab-overview UI blocks the webview overlay, automatically press the Android Back button (up to 4 retries) to restore the active tab before measuring the viewport
- Add hybrid status bar blockout: on hybrid apps the statusbar was not blocked out which could result in flaky tests regarding battery and reception
Committers: 1
- Wim Selles (@wswebcreation)
- Ignore regions for full-page screenshots: new
@wdio/visual-service@9.1.6
Patch Changes
-
0a19d78: Fix
clearRuntimeFolderclearing the actual and diff folders after each spec/feature execution instead of once before all workers start. This caused only the last spec's visual data to be present in the output when running multiple specs.Committers: 1
- Wim Selles (@wswebcreation)
-
ed0bea6: Fix
EISDIRerror when usingresolveSnapshotPathwith the visual service. The service now usesdirname()of the resolved path as the baseline folder, preventing it from creating a directory at a path thatexpect-webdriverio's snapshot service expects to be a file. Fixes #984.Committers: 1
- Wim Selles (@wswebcreation)
-
cbf1d22: Fix incomplete
wdio-ics:optionstype augmentation onWebdriverIO.Capabilities. The global type declaration now uses theWdioIcsOptionsinterface directly, ensuring all supported properties (logName,name) are available to TypeScript users in both standalone and multiremote configurations. Fixes #732.Committers: 1
- Wim Selles (@wswebcreation)
-
Updated dependencies [0a19d78]
-
Updated dependencies [ce74703]
- @wdio/image-comparison-core@1.1.4
@wdio/visual-service@9.1.5
Patch Changes
-
6ed0469: ## Fix: support
appium:optionsnested capability format andavdfallback (#1118)Appium caps need to be prefixed with
appium:, but this can feel redundant when you have a lot of caps. So you can also put them inside theappium:options-object. This was not supported by the visual module and was reported in #1118. It is now supported.The following capabilities are now correctly read from both
appium:-prefixed top-level format and the nestedappium:optionsformat:deviceNamenativeWebScreenshotavd(new, see below)
Second issue that is fixed is that for Android the
deviceNamecould be left away and theavdcould be provided. This is now also supported wheredeviceNametakes priority overavdif both are provided.Committers: 1
- Wim Selles (@wswebcreation)