Skip to content

fix(deps): update all non-major dependencies - #142

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/all-minor-patch
Oct 5, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
@commitlint/cli (source) 21.2.2 → 21.2.3 age confidence devDependencies patch
@commitlint/config-conventional (source) 21.2.2 → 21.2.3 age confidence devDependencies patch
@semantic-release/github 12.0.9 → 12.0.10 age confidence devDependencies patch
@semantic-release/npm 13.1.5 → 13.2.0 age confidence devDependencies minor
@vitest/coverage-v8 (source) 5.0.1 → 5.0.3 age confidence devDependencies patch
JetBrains/junie-github-action v1.7.11 → v1.7.16 age confidence action patch
dprint ^0.57.0 → ^0.58.0 age confidence devDependencies minor 0.60.1 (+2)
fast-xml-parser 5.11.1 → 5.11.2 age confidence dependencies patch
oxlint (source) 1.83.0 → 1.86.0 age confidence devDependencies minor
pnpm (source) 12.4.2 → 12.8.2 age confidence uses-with minor 12.9.1 (+1)
vitest (source) 5.0.1 → 5.0.3 age confidence devDependencies patch

Release Notes

conventional-changelog/commitlint (@​commitlint/cli)

v21.2.3

Compare Source

Bug Fixes
  • lint: trim trailing whitespace off the message handed to ignore matchers (#​4960) (a6f279b)
conventional-changelog/commitlint (@​commitlint/config-conventional)

v21.2.3

Compare Source

Bug Fixes
  • rules: report the case that matched in case rule failure messages (#​4962) (9f5f7bc)
semantic-release/github (@​semantic-release/github)

v12.0.10

Compare Source

Bug Fixes
semantic-release/npm (@​semantic-release/npm)

v13.2.0

Compare Source

Features
  • trusted-publishing: add support for CircleCI (fb35b81)
vitest-dev/vitest (@​vitest/coverage-v8)

v5.0.3

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v5.0.2

Compare Source

   🐞 Bug Fixes
    View changes on GitHub
JetBrains/junie-github-action (JetBrains/junie-github-action)

v1.7.16

Compare Source

What's Changed

Full Changelog: JetBrains/junie-github-action@v1.7.15...v1.7.16

v1.7.15

Compare Source

What's Changed

Full Changelog: JetBrains/junie-github-action@v1.7.14...v1.7.15

v1.7.14

Compare Source

What's Changed

Full Changelog: JetBrains/junie-github-action@v1.7.13...v1.7.14

v1.7.13

Compare Source

What's Changed

Full Changelog: JetBrains/junie-github-action@v1.7.12...v1.7.13

v1.7.12

Compare Source

What's Changed

Full Changelog: JetBrains/junie-github-action@v1.7.11...v1.7.12

dprint/dprint (dprint)

v0.58.0

Compare Source

Changes

  • fix(BREAKING): make --config file patterns relative to the config file's directory (#​1257)
  • feat(BREAKING): evaluate associations and override files in order where the last match wins (#​1258)
  • feat: add plugins with dprint init when a config file already exists (#​1241)
  • feat: additive plugins (#​1249)
  • feat: always pre-select a json plugin with dprint init (#​1252)
  • feat: support neverPreselect in the plugin info file (#​1253)
  • fix(development): harden range markers in specs (#​1256)

This release features a breaking change for glob patterns in config files specified with --config <file-path>. Previously in this case, the patterns would be relative to the cwd, but this was bad because it would cause things to work in unexpected ways based on what the cwd is (fragile). See #​1257 for workarounds and please open an issue if this really breaks you and I'll try to come up with a solution. Remote configs will continue to work like before where the patterns are relative to the cwd.

Install

Run dprint upgrade or see https://dprint.dev/install/

Verification

These artifacts have build provenance attestations.
Verify a download with the GitHub CLI:

gh attestation verify dprint-x86_64-unknown-linux-gnu.zip --repo dprint/dprint

Checksums

Artifact SHA-256 Checksum
dprint-x86_64-apple-darwin.zip 47e0c48127c9ac306bc66c4af0c3146ef41bd008c5eccc956691c09e2661f077
dprint-aarch64-apple-darwin.zip 06a7ea017e4d7da296f8a44fabb2f3d6ffafa91bbd5fddd4830bdc418bacb46d
dprint-x86_64-pc-windows-msvc.zip 6ab827fba525918670ff666edb5fc50917157c803c9abdc463131f75b5df0840
dprint-x86_64-pc-windows-msvc-installer.exe 9ce61595a0c55dfe56dfa6fa9f9dfb7e1bf4fa1953734c2dcda95805a5558157
dprint-aarch64-pc-windows-msvc.zip de86d320f0753f8803ef957baec766be18858e4021ddcf2d0584142a8ace1bae
dprint-x86_64-unknown-linux-gnu.zip 3047dcabe684fe32868d1959f7fad4ccbc2996a393d639bbb6634668fa08dc49
dprint-x86_64-unknown-linux-musl.zip 06c2a239a1214d5f9e76c364cadbd0ffaee710fdb516ca6448b08860364db6e2
dprint-aarch64-unknown-linux-gnu.zip f161161399b5ef62b3b68570ea1df24d16687adfbb88c125c8c4355e5780c407
dprint-aarch64-unknown-linux-musl.zip c74dd4f48dd9b8d6d595acfb238dd32ede67bdf792e8c6e2b8760cdaff9d80fb
dprint-riscv64gc-unknown-linux-gnu.zip 81b2e4138324b1bb78bafc13e72d8073e001c7164a579ede11128534ec41bfe4
dprint-loongarch64-unknown-linux-gnu.zip 3c7771c4026c2769c0d77675caa4a426d025e7403e6c911d51a3f36385c8f1a4
dprint-loongarch64-unknown-linux-musl.zip 76aa022f9722f94222240cb84b44df9e8e64d9b4a4a6acde01f8aa9b7cc4e776
dprint-powerpc64le-unknown-linux-gnu.zip 1cf739e5b89d6a82ea16c42131aca07e767ff086437262680310b905f41bb271
dprint-powerpc64le-unknown-linux-musl.zip b9616bd309b562ab2a263b2c8555e65237c8c9db4ad6936cff1c04b1173b6bef
dprint-aarch64-linux-android.zip b44b7620087d9e9ddeecac0929aa5be19f1ff4a971df15747294f03345647979
dprint-x86_64-linux-android.zip f85b1998119f0d369397828a8c1262160b27d9b9b92ca75ab7952e444c344e8b
NaturalIntelligence/fast-xml-parser (fast-xml-parser)

v5.11.2

Compare Source

What's Changed

New Contributors

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.11.1...v5.11.2

oxc-project/oxc (oxlint)

v1.86.0

Compare Source

🚀 Features
  • 9d80eed linter/react/only-export-components: Support allowCompoundComponents (#​27117) (Kuroda Kayn)
  • e05b155 linter: Add typescript/no-generated-empty-object-type (#​26958) (camc314)

v1.85.0

Compare Source

v1.84.0

Compare Source

pnpm/pnpm (pnpm)

v12.8.2: pnpm 12.8.2

Compare Source

pnpm 12.8.2 fixes a startup crash on Linux ppc64le and UnknownIssuer errors on systems without CA certificates. pnpm run no longer installs before every script on CI when autoDedupe is enabled, and resolution and hoisted installs on macOS are faster.

Patch Changes
Platforms and environments
  • Fixed pnpm crashing on startup on Linux ppc64le #​16380.

  • Fixed installs failing with UnknownIssuer on Linux systems without CA certificates, such as node:24-slim, when NODE_EXTRA_CA_CERTS is set. The extra certificates now extend the bundled CA roots #​16365.

  • pnpm now creates its store operation locks and other per-user lock files in $XDG_RUNTIME_DIR when it points to a directory only the user can write to. Otherwise, pnpm still uses /tmp on Linux and macOS. Sandboxes that block writes to /tmp can point XDG_RUNTIME_DIR at a writable directory #​16390.

  • POSIX bin shims and the pnpm, pn, pnpx, and pnx launchers now run inside a Nix build, where the system default path holds none of the utilities they call. Installing again replaces the shims already in node_modules #​16377.

  • In a project that pins another pnpm version, pnpm now passes a command with an option it does not know to the pinned version. Before, pnpm rejected the option before switching, so pnpm install --auto-dedupe failed with "Unknown option" even though the pinned pnpm supports it #​16353.

Installing and resolving dependencies
  • pnpm install --frozen-lockfile now fails when Cargo.lock does not satisfy a dependency requirement in Cargo.toml. The error names the crate and the version the lockfile holds #​16355.

  • pnpm install returns "Already up to date" again in a workspace with injected workspace dependencies and a shared lockfile. Since 12.7.0 every repeat install in such a workspace ran the full install and copied the injected projects again.

  • With injectWorkspacePackages: true, a fresh pnpm install now records a workspace dependency as link: when its injected copy differs from the project only by an optional peer that peer-dependent dedupe merges. It was recorded as a peer-suffixed file: copy #​16354.

  • pnpm dedupe --check now passes right after pnpm dedupe when deduplication merges variants of a package that differ only in their peers. A lockfile key whose peer suffix named a merged variant now names the variant that replaced it #​16356.

  • When minimumReleaseAge hides the version that latest points to, pnpm now falls back to a prerelease of the same major before a stable version of an older major. A stable version of the same major is still preferred. Before, while a new 1.0.0 was too new, latest fell back to an old 0.0.1 even though 1.0.0-beta.4 had been latest until then #​16388.

  • Git-hosted dependencies now respect pmOnFail. If it is set to anything other than download, a git-hosted dependency that pins a pnpm version is prepared by the running pnpm, and pnpm does not download the pinned version #​16376.

  • pnpmfile hooks such as readPackage now run once for a dependency that several packages request at the same time. They could run twice for it before.

  • childConcurrency now defaults to 5, the documented value. It used to be capped at 4 and to follow the host's CPU count.

Running scripts
  • pnpm run and pnpm exec no longer install dependencies before every script on CI when autoDedupe is enabled. pnpm install --frozen-lockfile now keeps the deduplication record left by an earlier install #​16374.

  • On macOS and Linux, lifecycle scripts and pnpm run now always get PATH from the PATH variable. When the environment also held a Path variable, a script sometimes got Path's value, and failed with node: not found #​16308.

  • pnpm run now exits after a SIGTERM in a container where pnpm is PID 1 and the script runs pnpm again, as "start": "pnpm serve" does. Since 12.6.0 it kept waiting after the script had shut down, until the container runtime killed it.

Other commands and settings
  • pnpm config get globalShims, pnpm shim list, and global installs no longer read globalShims from a project's pnpm-workspace.yaml. Only the global config file, the pnpm home's own pnpm-workspace.yaml, and PNPM_CONFIG_GLOBAL_SHIMS set it, so a repository cannot choose which globally installed packages get project-aware shims.

  • pnpm config set --location=project refuses a machine-level setting such as stateDir or scope with ERR_PNPM_CONFIG_SET_NOT_A_PROJECT_SETTING, which names where the setting belongs. pnpm config delete still clears such a key from a project's pnpm-workspace.yaml.

  • pnpm deploy no longer fails with ERR_PNPM_DEPLOY_AMBIGUOUS_PEER in a workspace with injectWorkspacePackages: true when a workspace package lists its peer dependency as a dev dependency too #​16375.

  • pnpm deploy no longer copies the workspace root's packageManager and devEngines.packageManager fields into the deployed package.json #​16403.

  • pnpm publish now includes bare README files and README files with Markdown extensions such as readme.markdown in registry metadata #​12704.

  • pnpm store prune now removes the packages that only expired pnpm dlx cache entries used. They were left in the store until the next pnpm store prune #​16383.

Performance
  • Sped up dependency resolution in large workspaces, and when many dependencies request different ranges of the same package. Resolution also uses less memory.

  • Sped up pnpm install with nodeLinker: hoisted on macOS when the lockfile is re-resolved, such as with autoDedupe enabled #​16397.

  • Sped up extracting package tarballs.

  • pnpm install without --frozen-lockfile is faster on some machines in projects with a pnpm-workspace.yaml. Those installs linked with one worker thread per core, half of what a frozen install uses.

  • On Windows, warm pnpm install --frozen-lockfile runs are 4-5% faster on 4- and 8-core machines. pnpm now links with one worker thread per core on Windows, between 4 and 16. This changes frozen installs and installs in projects without a pnpm-workspace.yaml on machines with 3 to 15 cores.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.8.1: pnpm 12.8.1

Compare Source

pnpm 12.8.1 fixes pnpm install --frozen-lockfile rejecting lockfiles with injected workspace packages that have peers, restores the executable bit on files of local directory dependencies, makes pnpm dedupe converge, and uses less CPU on many-core machines.

Patch Changes
  • pnpm install --frozen-lockfile no longer rejects a freshly generated lockfile when an injected workspace package has peer dependencies #​16332.

  • Executable files in a file: directory dependency or an injected workspace package keep their executable bit again. Since 12.8.0, pnpm installed these files without the permissions they have in their project.

  • pnpm dedupe now reaches a stable lockfile when a package's peer suffix is long enough to be hashed. Before, each run could switch that package's key between the hashed and the spelled-out suffix, so pnpm dedupe --check always failed #​16331.

  • pnpm install --frozen-lockfile, the default in CI, now uses less CPU on machines with more than 8 cores. Warm installs on many-core Windows machines got up to 10% faster. Frozen installs now link with at most 16 worker threads.

  • verifyDepsBeforeRun no longer reports dependencies as outdated after a filtered install just because pnpm-lock.yaml has a newer modification time. It checks the lockfile against the packages that install put in place. Before, pnpm run reinstalled the whole workspace with lifecycle scripts on, for example after a Docker COPY brought in a lockfile with a newer mtime #​16322.

    After a filtered install, verifyDepsBeforeRun now also checks that the install put the selected projects' dependencies in place. A node_modules directory alone no longer counts as proof.

  • pnpm run and pnpm exec no longer install a project that has never been installed and has nothing to install. Such a project declares no dependencies, no peer dependencies that autoInstallPeers would fetch, and no install lifecycle scripts. The command now runs without writing node_modules or pnpm-lock.yaml #​16313.

  • pnpm update -g --latest now upgrades globally installed packages beyond their saved version ranges #​16320.

Platinum Sponsors
Bit OpenAI Notion
CodeRabbit
Gold Sponsors
Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.8.0: pnpm 12.8

Compare Source

pnpm 12.8.0 warns when pnpm pack or pnpm publish would ship a .env file that files does not list, installs sharedWorkspaceLockfile: false workspaces concurrently, applies every setting passed as --config.<name>=<value>, and no longer leaves the Windows terminal stuck after Ctrl+C in a script.

Minor Changes
  • pnpm pack and pnpm publish now warn when the tarball includes a .env or .env.* file that the files field of package.json does not list. Templates such as .env.example are not reported. List the file in files to publish it on purpose, or exclude it in .npmignore or .gitignore #​7826.

  • pnpm pack now honors --silent, --reporter=silent, and --loglevel=silent to hide the tarball contents and summary. With --json, lifecycle script output and the final JSON output remain visible #​10297.

Patch Changes
Installing packages
  • Installing through a pnpr server now records the pnpmfile checksum in the lockfile, so a later pnpm install --frozen-lockfile accepts that lockfile #​14460. A frozen install through the pnpr server now fails if the pnpmfile changed. If the pnpmfile defines a readPackage, afterAllResolved or preResolution hook or custom resolvers, pnpm resolves dependencies locally and prints a warning that the pnpr server was not used.

    Installing through a pnpr server also links a workspace project at the directory its publishConfig.directory names. A server that does not forward the setting makes the install fail with ERR_PNPM_PNPR_PUBLISH_DIRECTORY_MISMATCH, so pnpm never writes a lockfile that points at the wrong directory. The server rejects a publishConfig.directory that points outside its project.

  • Installing a git-hosted dependency that has to be built no longer fails when that dependency's own dependencies have build scripts nobody approved. pnpm skips those builds while preparing the dependency, as it does without strictDepBuilds #​9764.

  • A git-hosted dependency that is a pnpm workspace with no committed lockfile is now detected as a pnpm project #​14011.

  • pnpm install --dev and pnpm fetch --dev now install the optional dependencies of devDependencies, such as the platform binaries of Biome and oxlint. The project's own optionalDependencies are still skipped #​9678.

  • pnpm install --offline and pnpm add --offline now resolve a version range to the newest matching version whose tarball is already in the store. They used to pick the newest version in the cached metadata and fail with ERR_PNPM_NO_OFFLINE_TARBALL when its tarball was missing #​10715.

  • If an offline install fails because the registry metadata cache uses the layout from before pnpm 11.27 and 12.4, the error now names the older mirror on disk and explains that one online install repopulates the cache. The error also carries the ERR_PNPM_NO_OFFLINE_META code. pnpm cache prune --help now says that pnpm 11.26 and earlier, and pnpm 12.3 and earlier, depend on the directories it removes #​15656.

  • Running pnpm install now refreshes dependencies when a package declared with a local file: directory changes its dependencies #​4623.

  • A repeat pnpm install now keeps its fast up-to-date check when an override replaces a declared local file: dependency #​12892.

  • pnpm install now removes an optional dependency from node_modules if its install script fails. Code that checks whether the package is installed no longer finds a package that cannot load #​8756.

  • With nodeLinker: hoisted, pnpm install now restores a workspace project's node_modules after it was deleted. Before, the install printed "Already up to date" and left the project without the dependencies nested under it. On Windows, the install also no longer fails with "Access is denied" when another project's copy of a shared dependency links to the deleted directory.

  • Under nodeLinker: hoisted, pnpm install now clears orphaned package directories that an interrupted or failed install leaves in a project's node_modules. A directory recorded by the previous install is removed, while an unrecorded directory is moved to node_modules/.ignored. A copy already in .ignored is never overwritten #​13676.

  • Concurrent installs no longer fail when they replace the same stale hoisted dependency link. Virtual store cleanup now keeps the temporary lockfiles that concurrent installs write.

Resolving and linking dependencies
  • pnpm install no longer aborts on a failed allocation of many gigabytes when peer dependency ranges combine overlapping || alternatives #​15867.

  • pnpm install no longer fails when a package from the registry declares a file: dependency on a directory inside itself, such as "@types/css-tree": "file:./typings/css-tree". pnpm links that dependency to the directory inside the package, as npm and Yarn do. The lockfile records it as link:<root>/typings/css-tree #​9141.

  • An npm: alias written by overrides now stays in place when a change elsewhere makes pnpm re-resolve the aliased dependency. Before, pnpm could look up the alias name at the aliased version, which failed with ERR_PNPM_NO_MATCHING_VERSION or locked an unrelated package #​16309.

  • A peer dependency no longer resolves to two different versions for one package. This happened when the package peer-depends on another package and on one of that package's peers, and it is installed deeper than a direct dependency of the package that provides them #​12098.

  • An optional peer dependency is no longer resolved from another workspace project's package when the project provides one of that package's own peers at a version it rejects. This avoids bogus unmet peer errors #​13989.

  • pnpm dedupe no longer changes the lockfile on every run when a nested peer dependency is provided through an npm alias #​15709.

  • With resolutionMode: time-based and minimumReleaseAge both set, pnpm install no longer reports a subdependency as too new when only the time-based cutoff excludes it. Such subdependencies used to fail a strict install with ERR_PNPM_NO_MATURE_MATCHING_VERSION, or were added to minimumReleaseAgeExclude #​13569. A transitive dependency that has no matching version published before the time-based cutoff now resolves to the lowest matching version allowed by minimumReleaseAge. pnpm picks a version younger than minimumReleaseAge only if no older version matches #​16298.

  • pnpm install retries registry metadata fetches that fail with a timeout, a dropped connection, or an interrupted response body before it applies trustPolicy or minimumReleaseAge. A transient fetch failure is not reported as TRUST_DOWNGRADE or MINIMUM_RELEASE_AGE_VIOLATION #​12031.

  • pnpm's built-in package compatibility database no longer applies to a project's own manifest. A project named like a published package, such as vue-loader, no longer gains dependencies on pnpm install or pnpm update. User-configured packageExtensions still apply to project manifests #​11700.

  • Packages in an external virtualStoreDir can resolve the project's direct dependencies selected by hoistPattern. Run pnpm install --force to repair an existing installation #​5652.

  • pnpm install now links the executables of auto-installed peer dependencies into the workspace root's node_modules/.bin, including after a frozen-lockfile reinstall #​8511.

Lockfiles and frozen installs
  • pnpm install --frozen-lockfile now works on a detached HEAD when gitBranchLockfile is enabled. The install reads the lockfiles of the local and remote-tracking branches that contain the checked-out commit. It still writes the shared pnpm-lock.yaml #​7672.

  • pnpm install --frozen-lockfile now accepts a lockfile that has no importer entry for a workspace package without dependencies. Such a package adde

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • "before 9am on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner October 5, 2026 05:42
@renovate
renovate Bot requested review from dawsontoth and removed request for a team October 5, 2026 05:42
@renovate
renovate Bot merged commit b53f199 into main Oct 5, 2026
35 checks passed
@renovate
renovate Bot deleted the renovate/all-minor-patch branch October 5, 2026 09:47
github-actions Bot pushed a commit that referenced this pull request Oct 5, 2026
## [1.12.8](v1.12.7...v1.12.8) (2026-10-05)

### Bug Fixes

* **deps:** update all non-major dependencies ([#142](#142)) ([b53f199](b53f199))
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

🎉 This PR is included in version 1.12.8 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants