chore(deps): update all non-major dependencies#39
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
|
|
commit: |
9aea6eb to
dac8bec
Compare
c4e0483 to
558f461
Compare
|
All alerts resolved. Learn more about Socket for GitHub. This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. |
1f5110d to
f7e4fcd
Compare
ecb4aca to
3c4b791
Compare
5855856 to
fa38aa7
Compare
8224c6b to
8b74bc2
Compare
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
7.0.0-dev.20260122.3→7.0.0-dev.20260512.111.0.9→11.1.0^0.20.0→^0.22.0^0.3.1→^0.6.0Release Notes
microsoft/typescript-go (@typescript/native-preview)
v7.0.0-dev.20260512.1Compare Source
v7.0.0-dev.20260511.1Compare Source
v7.0.0-dev.20260510.1Compare Source
v7.0.0-dev.20260509.2Compare Source
v7.0.0-dev.20260508.1Compare Source
v7.0.0-dev.20260507.1Compare Source
v7.0.0-dev.20260506.1Compare Source
v7.0.0-dev.20260505.1Compare Source
v7.0.0-dev.20260504.1Compare Source
v7.0.0-dev.20260503.1Compare Source
v7.0.0-dev.20260502.1Compare Source
v7.0.0-dev.20260501.1Compare Source
v7.0.0-dev.20260430.1Compare Source
v7.0.0-dev.20260429.1Compare Source
v7.0.0-dev.20260428.1Compare Source
v7.0.0-dev.20260427.1Compare Source
v7.0.0-dev.20260426.1Compare Source
v7.0.0-dev.20260425.1Compare Source
v7.0.0-dev.20260424.2Compare Source
v7.0.0-dev.20260424.1Compare Source
v7.0.0-dev.20260423.1Compare Source
v7.0.0-dev.20260422.1Compare Source
v7.0.0-dev.20260421.2Compare Source
v7.0.0-dev.20260421.1Compare Source
v7.0.0-dev.20260420.1Compare Source
v7.0.0-dev.20260419.1Compare Source
v7.0.0-dev.20260418.1Compare Source
v7.0.0-dev.20260417.1Compare Source
v7.0.0-dev.20260416.2Compare Source
v7.0.0-dev.20260416.1Compare Source
v7.0.0-dev.20260415.1Compare Source
v7.0.0-dev.20260414.1Compare Source
v7.0.0-dev.20260413.1Compare Source
v7.0.0-dev.20260412.1Compare Source
v7.0.0-dev.20260411.1Compare Source
v7.0.0-dev.20260410.1Compare Source
v7.0.0-dev.20260409.1Compare Source
v7.0.0-dev.20260408.1Compare Source
v7.0.0-dev.20260407.1Compare Source
v7.0.0-dev.20260406.1Compare Source
v7.0.0-dev.20260405.1Compare Source
v7.0.0-dev.20260404.1Compare Source
v7.0.0-dev.20260403.1Compare Source
v7.0.0-dev.20260401.1Compare Source
v7.0.0-dev.20260331.1Compare Source
v7.0.0-dev.20260330.1Compare Source
v7.0.0-dev.20260329.1Compare Source
v7.0.0-dev.20260328.1Compare Source
v7.0.0-dev.20260327.2Compare Source
v7.0.0-dev.20260326.1Compare Source
v7.0.0-dev.20260325.1Compare Source
v7.0.0-dev.20260324.1Compare Source
v7.0.0-dev.20260323.1Compare Source
v7.0.0-dev.20260322.1Compare Source
v7.0.0-dev.20260321.1Compare Source
v7.0.0-dev.20260320.1Compare Source
v7.0.0-dev.20260319.1Compare Source
v7.0.0-dev.20260318.1Compare Source
v7.0.0-dev.20260317.1Compare Source
v7.0.0-dev.20260316.1Compare Source
v7.0.0-dev.20260315.1Compare Source
v7.0.0-dev.20260314.1Compare Source
v7.0.0-dev.20260313.1Compare Source
v7.0.0-dev.20260312.1Compare Source
v7.0.0-dev.20260311.1Compare Source
v7.0.0-dev.20260310.1Compare Source
v7.0.0-dev.20260309.1Compare Source
v7.0.0-dev.20260308.1Compare Source
v7.0.0-dev.20260307.1Compare Source
v7.0.0-dev.20260306.1Compare Source
v7.0.0-dev.20260305.1Compare Source
v7.0.0-dev.20260304.1Compare Source
v7.0.0-dev.20260303.1Compare Source
v7.0.0-dev.20260302.1Compare Source
v7.0.0-dev.20260301.1Compare Source
v7.0.0-dev.20260228.1Compare Source
v7.0.0-dev.20260227.1Compare Source
v7.0.0-dev.20260226.1Compare Source
v7.0.0-dev.20260225.1Compare Source
v7.0.0-dev.20260224.1Compare Source
v7.0.0-dev.20260223.1Compare Source
v7.0.0-dev.20260222.1Compare Source
v7.0.0-dev.20260221.1Compare Source
v7.0.0-dev.20260220.1Compare Source
v7.0.0-dev.20260219.1Compare Source
v7.0.0-dev.20260218.1Compare Source
v7.0.0-dev.20260217.1Compare Source
v7.0.0-dev.20260216.1Compare Source
v7.0.0-dev.20260215.1Compare Source
v7.0.0-dev.20260214.1Compare Source
v7.0.0-dev.20260213.1Compare Source
v7.0.0-dev.20260212.1Compare Source
v7.0.0-dev.20260211.1Compare Source
v7.0.0-dev.20260210.1Compare Source
v7.0.0-dev.20260209.1Compare Source
v7.0.0-dev.20260208.1Compare Source
v7.0.0-dev.20260207.1Compare Source
v7.0.0-dev.20260206.1Compare Source
v7.0.0-dev.20260205.1Compare Source
v7.0.0-dev.20260204.1Compare Source
v7.0.0-dev.20260203.1Compare Source
v7.0.0-dev.20260202.1Compare Source
v7.0.0-dev.20260201.1Compare Source
v7.0.0-dev.20260131.1Compare Source
v7.0.0-dev.20260130.1Compare Source
v7.0.0-dev.20260129.1Compare Source
v7.0.0-dev.20260128.1Compare Source
v7.0.0-dev.20260127.1Compare Source
v7.0.0-dev.20260126.1Compare Source
v7.0.0-dev.20260124.1Compare Source
v7.0.0-dev.20260123.3Compare Source
v7.0.0-dev.20260122.4Compare Source
pnpm/pnpm (pnpm)
v11.1.0Compare Source
Minor Changes
Added
pnpm audit signaturesto verify ECDSA registry signatures for installed packages against keys from/-/npm/v1/keys#7909. Scoped registries are respected, and registries without signing keys are skipped.Added support for installing packages from the GitHub Packages npm registry via a built-in
gh:prefix (e.g.pnpm add gh:@​acme/private), and, more broadly, for arbitrary named registries in the style of vlt's named-registry aliases. Authentication is picked up from the existing per-URL.npmrcentries (e.g.//npm.pkg.github.com/:_authToken=...), so no separate auth mechanism is required.Additional aliases — or an override for the built-in
ghalias, for GitHub Enterprise Server — can be configured undernamedRegistriesinpnpm-workspace.yaml:With this,
work:@​corp/lib@^2.0.0resolves againsthttps://npm.work.example.com/. #8941.Allow setting sbom spec version using
--sbom-spec-version#11389.Add
--no-runtimeflag (config:runtime=false) to skip installing runtime entries (e.g. Node.js downloaded viadevEngines.runtime) without modifying the lockfile. The lockfile keeps the runtime entry so frozen-lockfile validation still passes; only the runtime fetch and.binlinking are skipped. Useful in CI matrices where the runtime is provisioned externally (e.g. viapnpm runtime -g set node <version>) beforepnpm installruns.Added the
pnpm bugscommand that opens a package's bug tracker URL in the browser. With no arguments, it reads the current project'spackage.json; with one or more package names, it fetches each package's metadata from the registry and opens its bug tracker. Falls back to<repository>/issueswhen thebugsfield is missing #11279.Added
pnpm ownercommand to manage package owners on the registry.Patch Changes
Added "published X ago by Y" information to the
pnpm viewcommand output, similar tonpm view. This is useful when comparing againstminimumReleaseAge.For example,
pnpm view pnpmnow shows:pnpm publishnow honors the configured HTTP/HTTPS proxy (includinghttps_proxy/http_proxy/no_proxyenvironment variables) when polling the registry'sdoneUrlduring the web-based authentication flow. Previously the poll bypassed the proxy, causing the registry to respond403from a different source IP and the login to never complete #11561.pnpm add -gnow installs each space-separated package into its own isolated directory by default. To bundle multiple packages into the same isolated install (so that they share dependencies and are removed together), pass them as a comma-separated list. For example:pnpm add -g foo barinstallsfooandbaras two independent globals — removing one does not affect the other.pnpm add -g foo,bar qarbundlesfooandbarinto a single isolated install whileqaris installed on its own.Related: #11587.
pnpm runtime set <name> <version>no longer fails in the root of a multi-package workspace with theADDING_TO_ROOTerror. Installing the workspace root is a valid target for a runtime, so the command now bypasses that safety check.Fix
pnpm --versionhanging for the lifetime of the worker pool after the version was printed.main.ts's--versionshort-circuit returned before reaching the command-handlerfinallythat callsfinishWorkers(), so the worker pool thatswitchCliVersionhad spawned during integrity resolution stayed alive and held the Node event loop open. The CLI entry now runsfinishWorkers()from its ownfinally, so every exit path tears the pool down.Repro:
pnpm --versionin a workspace whosedevEngines.packageManagerversion already matches the running pnpm +onFail: "download".switchCliVersionresolves the integrity (spawning workers), finds nothing to swap, returns. The version prints, then the process hangs.rolldown/tsdown (tsdown)
v0.22.0Compare Source
🚨 Breaking Changes
🚀 Features
🐞 Bug Fixes
🔄 Migration Guide
Node.js version
Upgrade to Node.js 22.18.0 or later. Bun and Deno remain supported (experimental).
unrunis no longer bundledIf your environment relies on the
unrunconfig loader (i.e. you're on a Node version without native TypeScript support and use the defaultautoloader), install it manually:npm i -D unrun # or, alternatively, the new tsx loader: npm i -D tsxIf you use Node.js 22.18.0+ with native TypeScript support, no change is needed — the
autoloader will picknative.dtsauto-enabled from tsconfigIf your
tsconfig.jsonhascompilerOptions.declaration: truebut you do not want tsdown to emit.d.tsfiles, opt out explicitly:exports.binauto-detectionAny entry chunk containing a shebang (e.g.
#!/usr/bin/env node) now causes tsdown to write abinfield inpackage.jsonautomatically. The semantics differ slightly from explicitbin: true:truefalseTo opt out entirely:
Links
v0.21.10Compare Source
🚀 Features
View changes on GitHub
v0.21.9Compare Source
🚀 Features
tsdownConfigandtsdownConfigResolvedplugin hooks - by @sxzz in #918 (665e5)🐞 Bug Fixes
View changes on GitHub
v0.21.8Compare Source
🚀 Features
ignoreRulestype to autocomplete known values - by @mrlubos in #892 (c8f5c)extensionsoption for subpath export keys - by @SinhSinhAn and @sxzz in #899 (1bb7a)baseline-widely-availabletarget - by @sxzz in #896 (d6a16)🐞 Bug Fixes
View changes on GitHub
v0.21.7Compare Source
🚀 Features
moduleoption for attw and publint to allow passing imported modules directly - by @sxzz (31e90)🐞 Bug Fixes
View changes on GitHub
v0.21.6Compare Source
🚀 Features
cjsReexportoption to eliminate dual module type hazard - by @mandarini and @sxzz in #856 (875c1)binoption to auto-generate package.json bin field - by @sxzz in #869 (7ebd6)🐞 Bug Fixes
.modulefrom CSS output filenames - by @sxzz in #866 (03ade)Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.