Skip to content

chore(deps): bump mp4box from 2.3.0 to 2.4.1 in /fe - #356

Merged
dos1in merged 1 commit into
mainfrom
dependabot/npm_and_yarn/fe/mp4box-2.4.1
Oct 5, 2026
Merged

dos1in merged 1 commit into
mainfrom
dependabot/npm_and_yarn/fe/mp4box-2.4.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor

Bumps mp4box from 2.3.0 to 2.4.1.

Release notes

Sourced from mp4box's releases.

v2.4.1

Patch Changes

  • bbf55fe Thanks @​DenizUgur! - Fix import paths and add a test to verify the tarball is installable.

    Release v2.4.0 upgraded tsdown, which apparently changed the output extensions from .js to .mjs and from .d.ts to .d.mts. This made the package uninstallable because the import paths were not updated. This patch fixes those import paths and adds a test to verify that the tarball installs correctly.

    fixes #561

v2.4.0

Minor Changes

Patch Changes

  • #550 fdbdf11 Thanks @​lideen! - fix: include nested QuickTime wave esds when deriving mp4a codec strings

  • #543 a08dba1 Thanks @​rbouqueau! - fix: tfra box parsing didn't allow to display all information

  • #535 5b72b08 Thanks @​dukesook! - add entry_count to saio box

  • c6227fd Thanks @​plantysnake! - fixes to pass 7 ignored test files from File Format Conformance

  • #548 fe69a56 Thanks @​lideen! - fix: reset fragmentation state on seek to prevent invalid fragment ranges

  • #539 871def4 Thanks @​dukesook! - warn if primary item id is invalid

  • #550 fdbdf11 Thanks @​lideen! - fix: normalize QuickTime wave esds in fragmented init segments for MSE compatibility

    By default, segmentation writes MSE-compatible mp4a.esds sample entries when source QuickTime files store AAC decoder config under mp4a.wave.esds. This behavior can be disabled with setSegmentOptions(..., { normalizeAudioSampleEntriesForMSE: false }) to preserve nested QuickTime wave.esds sample entries in initialization segments.

Changelog

Sourced from mp4box's changelog.

2.4.1

Patch Changes

  • bbf55fe Thanks @​DenizUgur! - Fix import paths and add a test to verify the tarball is installable.

    Release v2.4.0 upgraded tsdown, which apparently changed the output extensions from .js to .mjs and from .d.ts to .d.mts. This made the package uninstallable because the import paths were not updated. This patch fixes those import paths and adds a test to verify that the tarball installs correctly.

    fixes #561

2.4.0

Minor Changes

Patch Changes

  • #550 fdbdf11 Thanks @​lideen! - fix: include nested QuickTime wave esds when deriving mp4a codec strings

  • #543 a08dba1 Thanks @​rbouqueau! - fix: tfra box parsing didn't allow to display all information

  • #535 5b72b08 Thanks @​dukesook! - add entry_count to saio box

  • c6227fd Thanks @​plantysnake! - fixes to pass 7 ignored test files from File Format Conformance

  • #548 fe69a56 Thanks @​lideen! - fix: reset fragmentation state on seek to prevent invalid fragment ranges

  • #539 871def4 Thanks @​dukesook! - warn if primary item id is invalid

  • #550 fdbdf11 Thanks @​lideen! - fix: normalize QuickTime wave esds in fragmented init segments for MSE compatibility

    By default, segmentation writes MSE-compatible mp4a.esds sample entries when source QuickTime files store AAC decoder config under mp4a.wave.esds. This behavior can be disabled with setSegmentOptions(..., { normalizeAudioSampleEntriesForMSE: false }) to preserve nested QuickTime wave.esds sample entries in initialization segments.

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for mp4box since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [mp4box](https://github.com/gpac/mp4box.js) from 2.3.0 to 2.4.1.
- [Release notes](https://github.com/gpac/mp4box.js/releases)
- [Changelog](https://github.com/gpac/mp4box.js/blob/main/CHANGELOG.md)
- [Commits](gpac/mp4box.js@v2.3.0...v2.4.1)

---
updated-dependencies:
- dependency-name: mp4box
  dependency-version: 2.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added the pnpm-dependencies fe update label for robot label Oct 3, 2026
@dos1in
dos1in merged commit d6d76f0 into main Oct 5, 2026
3 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/fe/mp4box-2.4.1 branch October 5, 2026 01:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pnpm-dependencies fe update label for robot

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant