Skip to content

v1.2.0

Latest

Choose a tag to compare

@artemo-brd artemo-brd released this 02 Aug 12:40
0fd51aa

Highlights

  • Crawler API — new client.crawler service for full-page crawling.
  • Zero-config auth — new bdclient() now picks up credentials from the Bright Data CLI (brightdata login) if no apiKey/env token is set.
  • Security fix (CWE-22) — path traversal in file-saving APIs closed, while still supporting legitimate relative subfolders.
  • Bun runtime support — new bdclient() (and real requests) now work under Bun; previously crashed at construction.

New Features

  • Crawler API (client.crawler): crawl() (sync), trigger()/download() (async via snapshots). CrawlJob is an alias of ScrapeJob for parity with the Python SDK's vocabulary.
  • CLI-credential auth resolution: API token resolved by precedence — apiKey param → BRIGHTDATA_API_TOKEN/BRIGHTDATA_API_KEY env → credentials stored by brightdata login → actionable AuthenticationError. The resolved source is appended to the User-Agent ((auth=<source>)) for onboarding visibility.

Fixes

  • Path traversal (CWE-22) in saveResults / SnapshotAPI.download: filenames can no longer escape the working directory via ../ or absolute paths — both are now rejected with a clear ValidationError. Legitimate relative subfolders (e.g. filename: 'output/data.json') are still fully supported and actually created, backed by a real filesystem-level containment + symlink-escape check (getAbsAndEnsureDir), not just a blanket path.basename(). result.save()'s long-standing support for explicit absolute destinations is unchanged.
  • Bun compatibility: Transport no longer crashes on Bun. Bun's bundled undici is a bare, largely-inert Agent stub (no compose(), no close(), no dispatch()) and its request()/stream() ignore the dispatcher option entirely, routing through Bun's own native HTTP client instead. The SDK now capability-detects this instead of calling those methods unconditionally. Practical effect: requests succeed under Bun, but Transport's tuning (connection pooling, timeouts, automatic retry, DNS caching) has no effect there — Bun's own defaults apply.
  • nodenext / node16 type resolution: explicit .js extensions added to all relative import/export specifiers under src/, so the shipped .d.ts resolve correctly for consumers on moduleResolution: "node16"/"nodenext" (previously TS2834 / silent any). A build-time smoke test now loads all 4 published entry points in both ESM and CJS from the actual dist/ output.
  • Snapshot polling: accepts any non-empty status string instead of a closed enum, so new lifecycle values from the API (e.g. starting, collecting) no longer throw mid-poll. cancelled is now also treated as a terminal status.
  • discover() ergonomics, dataFormat/env aliases, and a Transport listener leak fix (shared beforeExit listener instead of one per instance — fixes MaxListenersExceededWarning when an app creates many clients).

Docs

  • Troubleshooting section and geo-targeting notes.
  • Crawl API usage in the README.

Internal

  • SnapshotStatus is now an open union (KnownSnapshotStatus | (string & {})) instead of a bare string, keeping editor autocomplete for known lifecycle values while still accepting values the API may add later.
  • Removed the one-time add-js-extensions codemod script (already did its job, not wired into build/test/CI).

Full Changelog: v1.1.0...v1.2.0