Repository navigation
fix(deps): update all non-major dependencies - #142
Merged
Merged
Conversation
github-actions Bot
pushed a commit
that referenced
this pull request
Oct 5, 2026
## [1.12.8](v1.12.7...v1.12.8) (2026-10-05) ### Bug Fixes * **deps:** update all non-major dependencies ([#142](#142)) ([b53f199](b53f199))
|
🎉 This PR is included in version 1.12.8 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
21.2.2→21.2.321.2.2→21.2.312.0.9→12.0.1013.1.5→13.2.05.0.1→5.0.3v1.7.11→v1.7.16^0.57.0→^0.58.00.60.1(+2)5.11.1→5.11.21.83.0→1.86.012.4.2→12.8.212.9.1(+1)5.0.1→5.0.3Release Notes
conventional-changelog/commitlint (@commitlint/cli)
v21.2.3Compare Source
Bug Fixes
conventional-changelog/commitlint (@commitlint/config-conventional)
v21.2.3Compare Source
Bug Fixes
semantic-release/github (@semantic-release/github)
v12.0.10Compare Source
Bug Fixes
semantic-release/npm (@semantic-release/npm)
v13.2.0Compare Source
Features
vitest-dev/vitest (@vitest/coverage-v8)
v5.0.3Compare Source
🐞 Bug Fixes
result.statusbetweenrepeatsruns - by @hi-ogawa, Hiroshi Ogawa and Codex (GPT-6) in #11218 (5dbeb)test.failsexpectedly failed - by @hi-ogawa, Hiroshi Ogawa and Codex (GPT-6) in #11219 (b2458)listenuntil tests start running - by @sheremet-va in #11366 (7d8ed)toMatchScreenshotuses wrong reference on retried tests - by @macarie in #11393 (c22ab)why-is-node-runningto3.2.1to avoid users running intoERR_PNPM_TRUST_DOWNGRADE- by @AriPerkkio in #11403 (f6c9a)expect.extendasymmetric matchers - by @hi-ogawa, Hiroshi Ogawa and Claude in #11401 (3e794)groupOrderis set - by @mtorp in #11392 (50312)View changes on GitHub
v5.0.2Compare Source
🐞 Bug Fixes
processin case global is overwritten - by @AriPerkkio in #11343 (0b792)process.stdiohandles - by @AriPerkkio in #11333 (0fd6b)toMatchObjectwith asymmetric matchers - by @ShreeBohara, Claude Opus 5, @hi-ogawa, Hiroshi Ogawa and Codex (GPT-5) in #11100 (42523)RequestwithBlobbody on jsdom 28+ - by @harshit-d3v in #11295 (d1c3e)agentto respect--silent- by @Raj4478 and @AriPerkkio in #11271 (5b95e)createReportcalls - by @7rulnik in #11278 (e8e55)hanging-processto use ESM entrypoint - by @AriPerkkio in #11316 (4e91e)Set.prototype.add- by @fengmk2 in #11299 (a0a93)View changes on GitHub
JetBrains/junie-github-action (JetBrains/junie-github-action)
v1.7.16Compare Source
What's Changed
Full Changelog: JetBrains/junie-github-action@v1.7.15...v1.7.16
v1.7.15Compare Source
What's Changed
Full Changelog: JetBrains/junie-github-action@v1.7.14...v1.7.15
v1.7.14Compare Source
What's Changed
Full Changelog: JetBrains/junie-github-action@v1.7.13...v1.7.14
v1.7.13Compare Source
What's Changed
Full Changelog: JetBrains/junie-github-action@v1.7.12...v1.7.13
v1.7.12Compare Source
What's Changed
Full Changelog: JetBrains/junie-github-action@v1.7.11...v1.7.12
dprint/dprint (dprint)
v0.58.0Compare Source
Changes
--configfile patterns relative to the config file's directory (#1257)dprint initwhen a config file already exists (#1241)dprint init(#1252)neverPreselectin the plugin info file (#1253)This release features a breaking change for glob patterns in config files specified with
--config <file-path>. Previously in this case, the patterns would be relative to the cwd, but this was bad because it would cause things to work in unexpected ways based on what the cwd is (fragile). See #1257 for workarounds and please open an issue if this really breaks you and I'll try to come up with a solution. Remote configs will continue to work like before where the patterns are relative to the cwd.Install
Run
dprint upgradeor see https://dprint.dev/install/Verification
These artifacts have build provenance attestations.
Verify a download with the GitHub CLI:
Checksums
NaturalIntelligence/fast-xml-parser (fast-xml-parser)
v5.11.2Compare Source
What's Changed
New Contributors
Full Changelog: NaturalIntelligence/fast-xml-parser@v5.11.1...v5.11.2
oxc-project/oxc (oxlint)
v1.86.0Compare Source
🚀 Features
9d80eedlinter/react/only-export-components: SupportallowCompoundComponents(#27117) (Kuroda Kayn)e05b155linter: Add typescript/no-generated-empty-object-type (#26958) (camc314)v1.85.0Compare Source
v1.84.0Compare Source
pnpm/pnpm (pnpm)
v12.8.2: pnpm 12.8.2Compare Source
pnpm 12.8.2 fixes a startup crash on Linux ppc64le and
UnknownIssuererrors on systems without CA certificates.pnpm runno longer installs before every script on CI whenautoDedupeis enabled, and resolution and hoisted installs on macOS are faster.Patch Changes
Platforms and environments
Fixed pnpm crashing on startup on Linux ppc64le #16380.
Fixed installs failing with
UnknownIssueron Linux systems without CA certificates, such asnode:24-slim, whenNODE_EXTRA_CA_CERTSis set. The extra certificates now extend the bundled CA roots #16365.pnpm now creates its store operation locks and other per-user lock files in
$XDG_RUNTIME_DIRwhen it points to a directory only the user can write to. Otherwise, pnpm still uses/tmpon Linux and macOS. Sandboxes that block writes to/tmpcan pointXDG_RUNTIME_DIRat a writable directory #16390.POSIX bin shims and the
pnpm,pn,pnpx, andpnxlaunchers now run inside a Nix build, where the system default path holds none of the utilities they call. Installing again replaces the shims already innode_modules#16377.In a project that pins another pnpm version, pnpm now passes a command with an option it does not know to the pinned version. Before, pnpm rejected the option before switching, so
pnpm install --auto-dedupefailed with "Unknown option" even though the pinned pnpm supports it #16353.Installing and resolving dependencies
pnpm install --frozen-lockfilenow fails whenCargo.lockdoes not satisfy a dependency requirement inCargo.toml. The error names the crate and the version the lockfile holds #16355.pnpm installreturns "Already up to date" again in a workspace with injected workspace dependencies and a shared lockfile. Since 12.7.0 every repeat install in such a workspace ran the full install and copied the injected projects again.With
injectWorkspacePackages: true, a freshpnpm installnow records a workspace dependency aslink:when its injected copy differs from the project only by an optional peer that peer-dependent dedupe merges. It was recorded as a peer-suffixedfile:copy #16354.pnpm dedupe --checknow passes right afterpnpm dedupewhen deduplication merges variants of a package that differ only in their peers. A lockfile key whose peer suffix named a merged variant now names the variant that replaced it #16356.When
minimumReleaseAgehides the version thatlatestpoints to, pnpm now falls back to a prerelease of the same major before a stable version of an older major. A stable version of the same major is still preferred. Before, while a new1.0.0was too new,latestfell back to an old0.0.1even though1.0.0-beta.4had beenlatestuntil then #16388.Git-hosted dependencies now respect
pmOnFail. If it is set to anything other thandownload, a git-hosted dependency that pins a pnpm version is prepared by the running pnpm, and pnpm does not download the pinned version #16376.pnpmfile hooks such as
readPackagenow run once for a dependency that several packages request at the same time. They could run twice for it before.childConcurrencynow defaults to 5, the documented value. It used to be capped at 4 and to follow the host's CPU count.Running scripts
pnpm runandpnpm execno longer install dependencies before every script on CI whenautoDedupeis enabled.pnpm install --frozen-lockfilenow keeps the deduplication record left by an earlier install #16374.On macOS and Linux, lifecycle scripts and
pnpm runnow always getPATHfrom thePATHvariable. When the environment also held aPathvariable, a script sometimes gotPath's value, and failed withnode: not found#16308.pnpm runnow exits after aSIGTERMin a container where pnpm is PID 1 and the script runs pnpm again, as"start": "pnpm serve"does. Since 12.6.0 it kept waiting after the script had shut down, until the container runtime killed it.Other commands and settings
pnpm config get globalShims,pnpm shim list, and global installs no longer readglobalShimsfrom a project'spnpm-workspace.yaml. Only the global config file, the pnpm home's ownpnpm-workspace.yaml, andPNPM_CONFIG_GLOBAL_SHIMSset it, so a repository cannot choose which globally installed packages get project-aware shims.pnpm config set --location=projectrefuses a machine-level setting such asstateDirorscopewithERR_PNPM_CONFIG_SET_NOT_A_PROJECT_SETTING, which names where the setting belongs.pnpm config deletestill clears such a key from a project'spnpm-workspace.yaml.pnpm deployno longer fails withERR_PNPM_DEPLOY_AMBIGUOUS_PEERin a workspace withinjectWorkspacePackages: truewhen a workspace package lists its peer dependency as a dev dependency too #16375.pnpm deployno longer copies the workspace root'spackageManageranddevEngines.packageManagerfields into the deployedpackage.json#16403.pnpm publishnow includes bareREADMEfiles and README files with Markdown extensions such asreadme.markdownin registry metadata #12704.pnpm store prunenow removes the packages that only expiredpnpm dlxcache entries used. They were left in the store until the nextpnpm store prune#16383.Performance
Sped up dependency resolution in large workspaces, and when many dependencies request different ranges of the same package. Resolution also uses less memory.
Sped up
pnpm installwithnodeLinker: hoistedon macOS when the lockfile is re-resolved, such as withautoDedupeenabled #16397.Sped up extracting package tarballs.
pnpm installwithout--frozen-lockfileis faster on some machines in projects with apnpm-workspace.yaml. Those installs linked with one worker thread per core, half of what a frozen install uses.On Windows, warm
pnpm install --frozen-lockfileruns are 4-5% faster on 4- and 8-core machines. pnpm now links with one worker thread per core on Windows, between 4 and 16. This changes frozen installs and installs in projects without apnpm-workspace.yamlon machines with 3 to 15 cores.Platinum Sponsors
Gold Sponsors
v12.8.1: pnpm 12.8.1Compare Source
pnpm 12.8.1 fixes
pnpm install --frozen-lockfilerejecting lockfiles with injected workspace packages that have peers, restores the executable bit on files of local directory dependencies, makespnpm dedupeconverge, and uses less CPU on many-core machines.Patch Changes
pnpm install --frozen-lockfileno longer rejects a freshly generated lockfile when an injected workspace package has peer dependencies #16332.Executable files in a
file:directory dependency or an injected workspace package keep their executable bit again. Since 12.8.0, pnpm installed these files without the permissions they have in their project.pnpm dedupenow reaches a stable lockfile when a package's peer suffix is long enough to be hashed. Before, each run could switch that package's key between the hashed and the spelled-out suffix, sopnpm dedupe --checkalways failed #16331.pnpm install --frozen-lockfile, the default in CI, now uses less CPU on machines with more than 8 cores. Warm installs on many-core Windows machines got up to 10% faster. Frozen installs now link with at most 16 worker threads.verifyDepsBeforeRunno longer reports dependencies as outdated after a filtered install just becausepnpm-lock.yamlhas a newer modification time. It checks the lockfile against the packages that install put in place. Before,pnpm runreinstalled the whole workspace with lifecycle scripts on, for example after a DockerCOPYbrought in a lockfile with a newer mtime #16322.After a filtered install,
verifyDepsBeforeRunnow also checks that the install put the selected projects' dependencies in place. Anode_modulesdirectory alone no longer counts as proof.pnpm runandpnpm execno longer install a project that has never been installed and has nothing to install. Such a project declares no dependencies, no peer dependencies thatautoInstallPeerswould fetch, and no install lifecycle scripts. The command now runs without writingnode_modulesorpnpm-lock.yaml#16313.pnpm update -g --latestnow upgrades globally installed packages beyond their saved version ranges #16320.Platinum Sponsors
Gold Sponsors
v12.8.0: pnpm 12.8Compare Source
pnpm 12.8.0 warns when
pnpm packorpnpm publishwould ship a.envfile thatfilesdoes not list, installssharedWorkspaceLockfile: falseworkspaces concurrently, applies every setting passed as--config.<name>=<value>, and no longer leaves the Windows terminal stuck after Ctrl+C in a script.Minor Changes
pnpm packandpnpm publishnow warn when the tarball includes a.envor.env.*file that thefilesfield ofpackage.jsondoes not list. Templates such as.env.exampleare not reported. List the file infilesto publish it on purpose, or exclude it in.npmignoreor.gitignore#7826.pnpm packnow honors--silent,--reporter=silent, and--loglevel=silentto hide the tarball contents and summary. With--json, lifecycle script output and the final JSON output remain visible #10297.Patch Changes
Installing packages
Installing through a
pnprserver now records the pnpmfile checksum in the lockfile, so a laterpnpm install --frozen-lockfileaccepts that lockfile #14460. A frozen install through the pnpr server now fails if the pnpmfile changed. If the pnpmfile defines areadPackage,afterAllResolvedorpreResolutionhook or custom resolvers, pnpm resolves dependencies locally and prints a warning that the pnpr server was not used.Installing through a
pnprserver also links a workspace project at the directory itspublishConfig.directorynames. A server that does not forward the setting makes the install fail withERR_PNPM_PNPR_PUBLISH_DIRECTORY_MISMATCH, so pnpm never writes a lockfile that points at the wrong directory. The server rejects apublishConfig.directorythat points outside its project.Installing a git-hosted dependency that has to be built no longer fails when that dependency's own dependencies have build scripts nobody approved. pnpm skips those builds while preparing the dependency, as it does without
strictDepBuilds#9764.A git-hosted dependency that is a pnpm workspace with no committed lockfile is now detected as a pnpm project #14011.
pnpm install --devandpnpm fetch --devnow install the optional dependencies of devDependencies, such as the platform binaries of Biome and oxlint. The project's ownoptionalDependenciesare still skipped #9678.pnpm install --offlineandpnpm add --offlinenow resolve a version range to the newest matching version whose tarball is already in the store. They used to pick the newest version in the cached metadata and fail withERR_PNPM_NO_OFFLINE_TARBALLwhen its tarball was missing #10715.If an offline install fails because the registry metadata cache uses the layout from before pnpm 11.27 and 12.4, the error now names the older mirror on disk and explains that one online install repopulates the cache. The error also carries the
ERR_PNPM_NO_OFFLINE_METAcode.pnpm cache prune --helpnow says that pnpm 11.26 and earlier, and pnpm 12.3 and earlier, depend on the directories it removes #15656.Running
pnpm installnow refreshes dependencies when a package declared with a localfile:directory changes its dependencies #4623.A repeat
pnpm installnow keeps its fast up-to-date check when an override replaces a declared localfile:dependency #12892.pnpm installnow removes an optional dependency fromnode_modulesif its install script fails. Code that checks whether the package is installed no longer finds a package that cannot load #8756.With
nodeLinker: hoisted,pnpm installnow restores a workspace project'snode_modulesafter it was deleted. Before, the install printed "Already up to date" and left the project without the dependencies nested under it. On Windows, the install also no longer fails with "Access is denied" when another project's copy of a shared dependency links to the deleted directory.Under
nodeLinker: hoisted,pnpm installnow clears orphaned package directories that an interrupted or failed install leaves in a project'snode_modules. A directory recorded by the previous install is removed, while an unrecorded directory is moved tonode_modules/.ignored. A copy already in.ignoredis never overwritten #13676.Concurrent installs no longer fail when they replace the same stale hoisted dependency link. Virtual store cleanup now keeps the temporary lockfiles that concurrent installs write.
Resolving and linking dependencies
pnpm installno longer aborts on a failed allocation of many gigabytes when peer dependency ranges combine overlapping||alternatives #15867.pnpm installno longer fails when a package from the registry declares afile:dependency on a directory inside itself, such as"@types/css-tree": "file:./typings/css-tree". pnpm links that dependency to the directory inside the package, as npm and Yarn do. The lockfile records it aslink:<root>/typings/css-tree#9141.An
npm:alias written byoverridesnow stays in place when a change elsewhere makes pnpm re-resolve the aliased dependency. Before, pnpm could look up the alias name at the aliased version, which failed withERR_PNPM_NO_MATCHING_VERSIONor locked an unrelated package #16309.A peer dependency no longer resolves to two different versions for one package. This happened when the package peer-depends on another package and on one of that package's peers, and it is installed deeper than a direct dependency of the package that provides them #12098.
An optional peer dependency is no longer resolved from another workspace project's package when the project provides one of that package's own peers at a version it rejects. This avoids bogus unmet peer errors #13989.
pnpm dedupeno longer changes the lockfile on every run when a nested peer dependency is provided through an npm alias #15709.With
resolutionMode: time-basedandminimumReleaseAgeboth set,pnpm installno longer reports a subdependency as too new when only the time-based cutoff excludes it. Such subdependencies used to fail a strict install withERR_PNPM_NO_MATURE_MATCHING_VERSION, or were added tominimumReleaseAgeExclude#13569. A transitive dependency that has no matching version published before the time-based cutoff now resolves to the lowest matching version allowed byminimumReleaseAge. pnpm picks a version younger thanminimumReleaseAgeonly if no older version matches #16298.pnpm installretries registry metadata fetches that fail with a timeout, a dropped connection, or an interrupted response body before it appliestrustPolicyorminimumReleaseAge. A transient fetch failure is not reported asTRUST_DOWNGRADEorMINIMUM_RELEASE_AGE_VIOLATION#12031.pnpm's built-in package compatibility database no longer applies to a project's own manifest. A project named like a published package, such as
vue-loader, no longer gains dependencies onpnpm installorpnpm update. User-configuredpackageExtensionsstill apply to project manifests #11700.Packages in an external
virtualStoreDircan resolve the project's direct dependencies selected byhoistPattern. Runpnpm install --forceto repair an existing installation #5652.pnpm installnow links the executables of auto-installed peer dependencies into the workspace root'snode_modules/.bin, including after a frozen-lockfile reinstall #8511.Lockfiles and frozen installs
pnpm install --frozen-lockfilenow works on a detached HEAD whengitBranchLockfileis enabled. The install reads the lockfiles of the local and remote-tracking branches that contain the checked-out commit. It still writes the sharedpnpm-lock.yaml#7672.pnpm install --frozen-lockfilenow accepts a lockfile that has no importer entry for a workspace package without dependencies. Such a package addeConfiguration
📅 Schedule: (in timezone America/New_York)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.