Skip to content

upstream-sync: sync Prebid.js 11.2.0 → 11.3.0 - #85

Merged
khang-vu-ttd merged 16 commits into
masterfrom
prebid-sync-11.3.0
Aug 7, 2026
Merged

upstream-sync: sync Prebid.js 11.2.0 → 11.3.0#85
khang-vu-ttd merged 16 commits into
masterfrom
prebid-sync-11.3.0

Conversation

@openads-sync-bot

@openads-sync-bot openads-sync-bot Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Prebid.js Sync: 11.2.011.3.0

📊 Run summary

This PR was auto-generated by the Sync with Upstream Prebid.js workflow.
Prebid 11.3.0 Release Page

Upstream diff: prebid/Prebid.js@11.2.0...11.3.0

✅ Applied Commits

  • f1f85e9c2 | Start.io: setting buyeruid on the OpenRTB request, md files updated #14650 (auto-resolved)
  • 5ecc8092c | Bump path-to-regexp #14654
  • 5ce10debc | Bump handlebars from 4.7.8 to 4.7.9 #14651
  • b5a0a2132 | CI: fix windows failing to create symlinks #14656
  • feed5efd9 | userId: fix optout flags to disable userId as a whole rather than storage #14667
  • 7c3683480 | Bump @xmldom/xmldom from 0.8.10 to 0.8.12 #14662
  • 698a238eb | Bump nick-fields/retry from 3 to 4 #14669
  • e227f2a88 | Core: skipLibCheck avoidance adjustments in TS build #14599 (auto-resolved)
  • 4edd91f0e | Remove the statusMess #14648 (auto-resolved)
  • 0429e66a7 | Build system: remove metadata override for categoryTranslation #14678
  • aeddd1d20 | Bump lodash from 4.17.23 to 4.18.1 #14677
  • e93c101 | Prebid Version Update (OpenAds Upstream Sync Bot)

⏭️ Skipped Commits

These commits were intentionally skipped because they made changes to files matching BidAdapter:

  • a9e4783ee | Increment version to 11.3.0-pre (unneeded changes)
  • 7eee31788 | New adapter - Playstream #14523
  • 84e72e58e | Adnuntius Bid Adapter: send network ID along with ad request #14628 (bid adapter change)
  • 4a6d4e193 | adgenerationBidAdapter: Set mediaType=BANNER for banner bids, bump version to 1.6.6 #14659 (bid adapter change)
  • e7eba3154 | Msft Bid Adapter - Documentation update in md file #14660 (bid adapter change)
  • 16e68e2d4 | Jixie Bid Adapter: send site and user in request #14641 (bid adapter change)
  • f08142a9a | Adquery Bid Adapter: added video outstream/instream support #14588 (bid adapter change)
  • 0c71ba11c | TTD Bid Adapter: Remove the test HTTP2 endpoint and set alwaysHasCapacity #14665 (bid adapter change)
  • d9558691f | LimeLight: new alias pgamrtb #14561
  • 6eebd29e2 | Prebid 11.3.0 release (will cause merge conflicts)

❌ Conflicting Commits (require manual resolution)

  • 1d8b5fe28 | Overtone: changing internal API endpoint #14625 (resolved: dropped spec, kept module)
  • 176fa0112 | Bump brace-expansion #14653 (resolved: via npm update)
  • 4ecaeb43e | Bump picomatch #14647 (resolved: via npm update)
  • 8832db70a | wurfl rtd: add storage control disclaimer #14629 (resolved: superseded by prior sync's WURFL v2.9.0 update)
  • 65fdb4e5c | Bump release-drafter/release-drafter from 6 to 7 #14670 (resolved: workflow rewritten, no longer uses this action)
  • 7f0b02868 | Bump actions/create-github-app-token from 2 to 3 #14668 (resolved: workflow file deleted in this fork)
  • a16f79b29 | Core: Removing cdep (Chrome cookie deprecation label) support #14664 (resolved: rubiconBidAdapter.js re-applied mechanically, rest adapter-only)

Post Sync Commits

  • 28aeac6 | drawbridge.ts: import isNumber directly from utils/objects.js (post-sync follow-up to #14599)

IlliaMil and others added 12 commits August 7, 2026 18:42
…#14650)

* Start.io - Create User ID submodule and improve adapter

* Update modules/startioIdSystem.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Fix: Adjust spacing formatting in getStorageManager parameters

* Fix: Adjust spacing formatting in getStorageManager parameters (#2)

* Refactor: Remove unused storage management logic from StartIO ID module and set default storage expiration

* Refactor: Remove unused storage management logic from StartIO ID module and set default storage expiration

* Enhance: Add configurable storage options and expiration to StartIO ID module

* Docs: Update StartIO ID module documentation with storage configuration details

* Docs: Update StartIO ID module documentation with storage configuration details

* Docs: Add build instructions and module details to Start.io ID system file (#4)

* Docs: Add build instructions and module details to Start.io ID system documentation (#5)

* Apply suggestion from @IlliaMil

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Matan Arbel <matan.arbel@start.io>
Bumps  and [path-to-regexp](https://github.com/pillarjs/path-to-regexp). These dependencies needed to be updated together.

Updates `path-to-regexp` from 0.1.12 to 0.1.13
- [Release notes](https://github.com/pillarjs/path-to-regexp/releases)
- [Changelog](https://github.com/pillarjs/path-to-regexp/blob/v.0.1.13/History.md)
- [Commits](pillarjs/path-to-regexp@v0.1.12...v.0.1.13)

Updates `path-to-regexp` from 8.2.0 to 8.4.0
- [Release notes](https://github.com/pillarjs/path-to-regexp/releases)
- [Changelog](https://github.com/pillarjs/path-to-regexp/blob/v.0.1.13/History.md)
- [Commits](pillarjs/path-to-regexp@v0.1.12...v.0.1.13)

---
updated-dependencies:
- dependency-name: path-to-regexp
  dependency-version: 0.1.13
  dependency-type: indirect
- dependency-name: path-to-regexp
  dependency-version: 8.4.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Patrick McCann <patmmccann@gmail.com>
Bumps [handlebars](https://github.com/handlebars-lang/handlebars.js) from 4.7.8 to 4.7.9.
- [Release notes](https://github.com/handlebars-lang/handlebars.js/releases)
- [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.9/release-notes.md)
- [Commits](handlebars-lang/handlebars.js@v4.7.8...v4.7.9)

---
updated-dependencies:
- dependency-name: handlebars
  dependency-version: 4.7.9
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Patrick McCann <patmmccann@gmail.com>
…rage (#14667)

* userId: fix optout flags to disable userId as a whole rather than storage

* fix refresh behavior
Bumps [@xmldom/xmldom](https://github.com/xmldom/xmldom) from 0.8.10 to 0.8.12.
- [Release notes](https://github.com/xmldom/xmldom/releases)
- [Changelog](https://github.com/xmldom/xmldom/blob/master/CHANGELOG.md)
- [Commits](xmldom/xmldom@0.8.10...0.8.12)

---
updated-dependencies:
- dependency-name: "@xmldom/xmldom"
  dependency-version: 0.8.12
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [nick-fields/retry](https://github.com/nick-fields/retry) from 3 to 4.
- [Release notes](https://github.com/nick-fields/retry/releases)
- [Commits](nick-fields/retry@v3...v4)

---
updated-dependencies:
- dependency-name: nick-fields/retry
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Core: skipLibCheck avoidance adjustments in TS build

* linting

* fixing order

* package-lock

* change googletag to any

* allowJs: false

* clean up

* clean up
Bumps [lodash](https://github.com/lodash/lodash) from 4.17.23 to 4.18.1.
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.23...4.18.1)

---
updated-dependencies:
- dependency-name: lodash
  dependency-version: 4.18.1
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
khang-vu-ttd and others added 4 commits August 7, 2026 12:04
…ync follow-up to #14599)

allowJs:false in this sync's tsconfig.json change means TS can no longer see
through the utils.js re-export to preserve isNumber's type-guard signature,
so isNumber(hostDelay) stopped narrowing unknown to number here. Import it
directly from the .ts source instead.
…14647)

Both cherry-picks conflicted on package-lock.json; some nested entries were
already newer than upstream's target due to organic drift, so resolved via
npm update instead of hand-merging the lockfile.
* overtoneRtdProvider and overtoneRtdProvider_spec

* Added markdown

* Updated overtoneRtdProvider.md with relevant changes

* Update overtoneRtdProvider.md

Updated markdown text for clarification

* Update overtoneRtdProvider_spec.mjs

Removed timeout and added additional tests

* Modified for getBidRequestData test case

* Switch RTD module from /contextual to /VendorService endpoint

- Endpoint: prebid-1.overtone.ai/contextual → prebid-1.overtone.ai/VendorService
- URL param: ?URL={url}&InApp=False → ?pageUrl={url}
- Response parsing: extract segment IDs from sources[0].segments[].id
- Output format unchanged: { categories: ["ovtn_001", ...] }
- Updated tests to match new response format

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Namespace Overtone data under site.ext.data.overtone to avoid overwriting

Uses Prebid mergeDeep utility to safely merge into ortb2Fragments
instead of replacing site.ext.data. Preserves pre-existing FPD
and data from other RTD modules.

Added tests verifying merge behavior with and without existing data.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix lint errors: merge utils imports, use log helper instead of reassigning logMessage

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Subiksha <bikshaaa@gmail.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
@khang-vu-ttd

Copy link
Copy Markdown
Contributor

Resolved conflict for 1d8b5fe28 (Overtone: changing internal API endpoint, #14625): module merged cleanly; only conflict was on the spec file, which doesn't exist in this fork — explained by the known fork commit 512b153 (#26, 'remove unneeded test'). Dropped the spec, kept the module change.

@khang-vu-ttd

Copy link
Copy Markdown
Contributor

Resolved conflicts for 176fa0112 (Bump brace-expansion, #14653) and 4ecaeb43e (Bump picomatch, #14647): both conflicted purely on package-lock.json's nested dependency tree — some entries were already newer than upstream's target due to organic drift over time, others were behind. Hand-merging that JSON is error-prone, so resolved via npm update brace-expansion picomatch instead, which brought every entry to at least upstream's target version. Committed as c9748ee.

@khang-vu-ttd

Copy link
Copy Markdown
Contributor

Resolved conflict for 8832db70a (wurfl rtd: add storage control disclaimer, #14629): this commit's actual content (the disclosureURL field on wurflSubmodule and the metadata/disclosures/modules/wurflRtdProvider.json file) already exists in this fork from the later WURFL v2.9.0 update applied in a prior sync (upstream-sync #81). Its version-bump portion (2.7.0→2.8.0) is stale since this fork is already at 2.9.0. Verified the cherry-pick reduces to an empty diff once resolved to HEAD; skipped it.

@khang-vu-ttd

Copy link
Copy Markdown
Contributor

Resolved conflicts for 65fdb4e5c (Bump release-drafter/release-drafter from 6 to 7, #14670) and 7f0b02868 (Bump actions/create-github-app-token from 2 to 3, #14668): both are GitHub Actions version bumps to workflow files this fork no longer uses in their upstream form. .github/workflows/release-drafter.yml was completely rewritten to a custom GitHub-App-token-based release process (no longer invokes release-drafter/release-drafter at all), and .github/workflows/PR-assignment.yml was deleted entirely. Both cherry-picks reduce to empty/moot changes; resolved by keeping HEAD's state.

@khang-vu-ttd

Copy link
Copy Markdown
Contributor

Resolved conflict for a16f79b29 (Core: Removing cdep support, #14664): ~13 of the conflicts were routine modify/delete on bid-adapter files and analytics-adapter specs this fork doesn't ship or already dropped (512b153, #26). One real content conflict in modules/rubiconBidAdapter.js (a bid adapter this fork genuinely keeps) — removed only the 'o_cdep' query-param key this commit targets, kept the unrelated 'o_ae' key that was on the same line. Verified via Drawbridge trace (matching the same check from upstream-sync #84) that this only touches ACTIVITY_ACCESS_DEVICE/UFPD redaction, not Drawbridge's ACTIVITY_ENRICH_EIDS/eids surface.

@khang-vu-ttd
khang-vu-ttd merged commit 7a5380b into master Aug 7, 2026
318 of 321 checks passed
@khang-vu-ttd
khang-vu-ttd deleted the prebid-sync-11.3.0 branch August 7, 2026 20:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants