Skip to content

chore(deps): update patch/minor dependencies - #1472

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/all-non-major
Open

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/all-non-major

Conversation

@renovate

@renovate renovate Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
Bun (source) 1.4.2 → 1.4.3 age confidence patch
actions/download-artifact v8.0.1 → v8.0.2 age confidence action patch
actions/setup-node v7.0.0 → v7.1.0 age confidence action minor
actions/upload-artifact v7.0.1 → v7.0.2 age confidence action patch
oxlint (source) 1.86.0 → 1.87.0 age confidence devDependencies minor
pnpm (source) 12.8.1 → 12.11.2 age confidence packageManager minor
pnpm (source) 12.8.1 → 12.11.2 age confidence volta minor
pnpm (source) 12.6.0 → 12.11.2 age confidence devEngines.packageManager minor

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

oven-sh/bun (Bun)

v1.4.3: Bun v1.4.3

Compare Source

To install Bun v1.4.3

curl -fsSL https://bun.sh/install | bash

# or you can use npm
# npm install -g bun

Windows:

powershell -c "irm bun.sh/install.ps1|iex"

To upgrade to Bun v1.4.3:

bun upgrade
Read Bun v1.4.3's release notes on Bun's blog
Thanks to 8 contributors!
actions/download-artifact (actions/download-artifact)

v8.0.2

Compare Source

What's Changed
New Contributors

Full Changelog: actions/download-artifact@v8.0.1...v8.0.2

actions/setup-node (actions/setup-node)

v7.1.0

Compare Source

What's Changed

Enhancements:
Bug fixes:
Documentation updates:
Dependency updates:

New Contributors

Full Changelog: actions/setup-node@v7.0.0...v7.1.0

actions/upload-artifact (actions/upload-artifact)

v7.0.2

Compare Source

What's Changed

  • Improves artifact download retries when the service returns HTTP 429 (rate limiting), including honoring valid Retry-After headers.
  • Updates @​actions/artifact to v6.3.1.

New Contributors

Full Changelog: actions/upload-artifact@v7.0.1...v7.0.2

oxc-project/oxc (oxlint)

v1.87.0: oxlint v1.87.0

Compare Source

🚀 Features
  • 42dcfd2 linter/react/no-unescaped-entities: Implement suggestion (#​27292) (Mikhail Baev)
  • cd4510d linter/unicorn/no-useless-switch-case: Implement suggestion (#​27245) (Mikhail Baev)
  • 1a7c902 linter/react/jsx-no-target-blank: Implement suggestion (#​27181) (Mikhail Baev)
🐛 Bug Fixes
  • 176b4b9 linter/jsx-a11y/label-has-associated-control: Validate label attribute values (#​27302) (sama Pyb)
  • 7d381c3 linter/jsx-a11y/mouse-events-have-key-events: Handle nullish event handlers (#​27306) (sama Pyb)
  • 4e09837 linter/jsx-a11y/lang: Validate lang expression strings (#​27304) (sama Pyb)
  • 7d28a66 linter/unicorn/numeric-separators-style: Report misgrouped BigInt literals (#​27207) (breken)
  • e928322 linter/unicorn/no-zero-fractions: Parenthesize separator and large integers in fixer (#​27206) (breken)
  • 3d61a59 parser: Validate TypeScript type member separators (#​27222) (camc314)
  • f08236b linter/eslint/prefer-exponentiation-operator: Preserve autofix precedence (#​27150) (camc314)
  • 7d60ae3 linter/valid-title: Continue checks after allowed words (#​27146) (Cameron)
  • ad5dd5d linter/eslint/no-unused-vars: Respect disabled argument checks for used ignore patterns (#​26925) (camc314)
pnpm/pnpm (pnpm)

v12.11.2: pnpm 12.11.2

Compare Source

This release fixes --workspace-concurrency=Infinity, filters set by an updateConfig hook, and store fetches with enable-modules-dir=false.

Patch Changes
  • --workspace-concurrency=Infinity now runs workspace projects with no concurrency limit. It used to fail with invalid digit found in string #​16793.

  • pnpm install and other recursive commands now apply the filter and filterProd that an updateConfig hook sets. They used to run on every workspace project #​16792.

  • enable-modules-dir=false now also fetches the packages an install reuses from an existing lockfile, so the store holds every package the lockfile lists.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.11.1: pnpm 12.11.1

Compare Source

This release fixes two ways pnpm install could fail, runs tools of any Rust release through pnx, and treats registry.npmjs.com as an alias of the npm registry.

Patch Changes
  • pnpm install no longer fails when packageManager pins the pnpm version that is already running and the registry does not publish that version. pnpm warns and continues. A registry mirror that has not synced a release no longer blocks the commands of a project pinned to it.

  • pnpm install no longer fails with ERR_PNPM_CMD_SHIM_CHMOD when node_modules/.bin holds a shim that another user created, if everyone can already execute it and it is not world-writable. This happens when several users share one checkout.

  • enable-modules-dir=false (enableModulesDir: false through the Node.js addon) fetches the registry packages the host can install into the store again, as pnpm v10 did, while still writing nothing under node_modules. The setting exists for a node_modules that something else mounts from the store, such as a FUSE daemon, and that consumer no longer has to download each package on first access. A plain --lockfile-only run still fetches nothing.

  • pnpm pack and pnpm publish no longer put .npmignore and .gitignore files in the tarball. A files entry that names one still ships it.

  • pnpm now treats https://registry.npmjs.com/ as an alias of https://registry.npmjs.org/. Registry requests, credentials, and trusted publishing use the canonical hostname.

  • pnx --package=rust@<channel> <tool> runs a tool of that Rust release, for example pnx --package=rust@nightly-2026-01-01 cargo build. pnpm installs the release with the components and targets from rust-toolchain.toml and the target of each --target argument.

  • pnpm install now links agent skills for more coding agents. It detects the agent from ANTIGRAVITY_AGENT, COPILOT_AGENT, COPILOT_CLI, CODEX_THREAD_ID, CODEX_SANDBOX, AI_AGENT, and CLAUDE_CODE pnpm/tasks#116.

  • When the registry rejects pnpm stage publish, the error message now starts with "Failed to stage package".

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.11.0: pnpm 12.11.0

Compare Source

This release adds Rust toolchain management, links the agent skills that dependencies ship, adds the permissions setting, and keeps the colors of streamed script output.

Minor Changes
  • pnpm install now links the agent skills that direct dependencies ship under skills/<name>/SKILL.md into the project's agent skill directories, such as .claude/skills. A package's skills are linked only after you approve them with pnpm approve. The skills.dirs setting chooses the directories pnpm/rfcs#35.

    Added the permissions setting, which records what each dependency may do. Its build capability works like allowBuilds and takes precedence over it. pnpm approve-builds writes to permissions when pnpm-workspace.yaml already has it, and to allowBuilds otherwise.

    Added pnpm permissions, which lists the granted and denied permissions and the packages awaiting approval. pnpm approve reviews build scripts and agent skills in one prompt pnpm/rfcs#36.

  • pnpm now installs and runs Rust toolchains.

    • With cargo.enabled, pnpm install installs the toolchain named in rust-toolchain.toml. pnpm verifies the release signature, stores the toolchain once per machine, and links it into .pnpm/rust. pnpm run and pnpm exec put its cargo and rustc on the PATH.
    • pnpm add -g rust@<channel> installs a toolchain globally. The cargo and rustc commands run it outside projects that pin their own. pnpm update -g, pnpm ls -g, and pnpm remove -g manage it like any global package.
    • In a project, pnpm add rust@<channel> pins the toolchain in rust-toolchain.toml.
    • pnpm shim add rust adds project-aware shims for cargo, rustc, and the other Rust tools. In a project with a rust-toolchain.toml, they run the toolchain the file names and install it on first use. Elsewhere, the next command of the same name on PATH runs, such as rustup's.
  • pnpm run and pnpm exec now keep the colors of script output that they print under the project's name, such as with --stream. pnpm sets FORCE_COLOR=1 for these scripts when its own output is in color, unless FORCE_COLOR is already set.

    Script output is also rendered more cleanly:

    • A line that a progress bar redraws with \r shows only its last state.
    • Escape codes that move the cursor or clear the screen are dropped.
    • Long colored lines are cut at the terminal width.
    • pnpm -r run no longer garbles its live output when a script fails while other scripts are still running.
Patch Changes
Installing packages
  • pnpm no longer panics with "unexpected error when polling the I/O driver" when it runs under QEMU user-mode emulation, such as a linux/amd64 container on an Apple Silicon Mac #​16696.

  • pnpm view, pnpm update, and other commands that read registry metadata now work behind proxies that end a response by closing the connection without a TLS close_notify alert #​16704.

  • pnpm now switches to the version a project pins in packageManager or devEngines.packageManager even when pnpm-workspace.yaml has a setting the running pnpm cannot read, such as a lockfile.includeResolutionSettings section. If pnpm does not switch, it still reports that setting #​16675.

  • When the pnpm package has to download its native binary on first run, it now uses the registry and credentials from .npmrc and from the npm_config_registry and pnpm_config_registry environment variables. COREPACK_NPM_REGISTRY still takes precedence. A project .npmrc is not read when COREPACK_INTEGRITY_KEYS turns off the signature check #​16655.

  • pnpm install and pnpm add --config now apply minimumReleaseAge when they resolve a config dependency. A config dependency range resolves to the newest version that is old enough, so a later clean pnpm install --frozen-lockfile accepts the lockfile #​16660.

  • pnpm remove with catalogPrune no longer removes catalog entries that pnpm-lock.yaml still records for workspace projects missing from disk. Before, a following frozen install failed with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH #​16679.

  • With cargo.enabled, pnpm install now writes the source replacement for vendored crates into .pnpm/crates/config.toml and includes it as optional from .cargo/config.toml. A checkout without .pnpm builds with plain Cargo #​16659.

  • With nodeLinker.type set to loaded, Node.js now stops with ERR_PNPM_LOADER_UNSUPPORTED_NODE when it preloads the store loader on a version the loader cannot serve. The supported versions are ^24.18.0 || >=26.2.0. On other versions, CommonJS packages imported from ESM failed with Cannot find module on their first relative require().

  • On Windows, pnpm install no longer fails with "The filename, directory name, or volume label syntax is incorrect" when a package contains a file whose name is invalid on Windows, such as icon.svg?as=metadata.d.ts. pnpm removes the invalid characters from the name and prints a warning that lists the renamed files.

  • On Windows, hoisting no longer fails intermittently with link errors when a junction is created or replaced concurrently pnpm/tasks#53.

Resolving dependencies
  • pnpm install --no-optional now installs the peer dependencies a project declares when autoInstallPeers is on. The lockfile marked such a peer optional: true when another dependency had it as an optional peer.

  • pnpm install and pnpm dedupe now link an optional peer to the workspace package that the workspace root depends on when the picked version matches it. They installed the registry package with the same name and version #​16706.

  • Removal overrides such as "debug>supports-color": "-" now also apply to an optional peer that a package declares only in peerDependenciesMeta #​16681.

  • pnpm add and other installs that re-resolve dependencies now keep the locked devEngines.runtime version while it still satisfies the declared range #​16764.

  • pnpm audit --fix update now updates only the dependencies whose locked version is vulnerable #​14928.

  • pnpm outdated and pnpm update --interactive now apply overrides before they look up the latest version. Before, a dependency overridden to an npm alias was compared with the latest version of the package the override replaces #​16719.

Patched dependencies
  • Patches saved with CRLF line endings now apply, including a patch that creates or deletes a file. pnpm rejected the git headers of such a patch with ERR_PNPM_INVALID_PATCH and the message invalid file mode: 100644 #​16641.

  • A patch that changes a file's mode, such as adding or removing the executable bit, now applies the new mode on Unix pnpm/tasks#110.

Injected dependencies and deploy
  • With sharedWorkspaceLockfile: false, an injected workspace package installed in the same run as its dependent now holds only the files its files field selects. The copy also held other files of the project, such as tsconfig.json #​16683.

  • A script listed in syncInjectedDepsAfterScripts no longer fails when it rewrites package.json while pnpm is copying its edits into the injected copies. The sync after the script now replaces a half-copied manifest.

  • pnpm deploy with a shared lockfile no longer fails with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH for settings.dedupeInjectedDeps or settings.dedupePeerDependents when lockfile.includeResolutionSettings is enabled. The deployed lockfile now records both settings as false, the values the deploy installs with.

  • pnpm deploy now writes the dependencies in the deployed package.json sorted by name. It also sorts the allowBuilds entries in the deployed pnpm-workspace.yaml. Repeated deploys of the same lockfile now produce identical files #​16687.

Packing and publishing
  • pnpm pack and pnpm publish now match .npmignore and .gitignore rules the way npm does. A negation such as !lib/** or !lib/**/!(*.map) re-includes files under a directory that an earlier * rule excluded #​16743.

  • pnpm pack and pnpm publish no longer always include root files that merely start with README, LICENSE, or LICENCE, such as README_INTERNAL.md. Only README, LICENSE, LICENCE, and COPYING, with or without an extension, ship regardless of files and .npmignore, as in npm #​16753.

  • pnpm publish --provenance=false and --no-provenance now turn off provenance under trusted publishing, so a package can be published from a self-hosted runner. Setting provenance: false in pnpm-workspace.yaml does the same #​16721.

Speed and resource use
  • pnpm install hardlinks files from a group-writable or world-writable store again. pnpm copied every file from such a store into node_modules #​16677.

  • A repeat pnpm install no longer imports patched packages and packages with build scripts again when nothing changed. Their builds no longer run again either. This happened when recursiveInstall was false or the project had a file: dependency #​16705.

  • Verifying the lockfile against trustPolicy and minimumReleaseAge uses less memory. pnpm no longer keeps every published version's manifest of each checked package in memory until the install ends #​16656.

  • pnpm rebuild <pkg> and pnpm rebuild --pending no longer read the manifest of every installed package to find build scripts. Only the selected packages are inspected and built. On a large node_modules served lazily, such as over a network or FUSE mount, this turned a rebuild of a few packages into a fetch of every package.

  • pnpm rebuild no longer removes and recreates node_modules when the settings recorded in node_modules/.modules.yaml differ from the current configuration. The rebuild runs the build scripts against the installed packages as they are.

  • pnpm store prune now compacts the store's index.db after removing package entries, so the file shrinks again #​16717.

Registry commands
  • pnpm whoami, pnpm bugs, pnpm docs, pnpm repo, pnpm star, pnpm unstar, and pnpm stars now honor the --registry option.

  • --registry now takes precedence over a scope's configured registry for scoped packages in pnpm access, pnpm view, pnpm repo, pnpm star, pnpm unstar, pnpm owner, pnpm deprecate, pnpm undeprecate, pnpm unpublish, pnpm dist-tag, pnpm team, and pnpm stage. Without --registry, pnpm access now sends a scoped package or scope to the registry configured for that scope.

  • Registry commands now keep the path of a registry URL such as https://example.com/npm/ when they build request URLs. This applies to pnpm access, pnpm owner, pnpm ping, pnpm search, pnpm star, pnpm stars, pnpm team, pnpm unstar, and pnpm whoami.

  • pnpm view now honors the network retry settings.

  • pnpm repo now fetches the repository URLs of several packages in parallel.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.10.1: pnpm 12.10.1

Compare Source

This release fixes pnpm install failures after an overrides change and on a filtered frozen install with catalogPrune. It also fixes several bugs in the experimental nodeLinker.type: loaded, which now keeps its generated files in node_modules.

Patch Changes
  • With nodeLinker.type: loaded, pnpm now writes its generated files to node_modules, which projects already ignore in git. The store manifest and loader are node_modules/.pnpm/.store-manifest.json and node_modules/.pnpm/.store-loader.mjs. Bin shims are in node_modules/.bin.

    Earlier versions wrote .pnpm-store.json and .pnpm-store-loader.mjs to the project root, and a .pnpm directory to the root and to each workspace package. Delete them after reinstalling.

  • With nodeLinker.type: loaded, packages that ship their own node_modules directory, such as npm with its bundled dependencies, now load from the store. Before, one such package in the install stopped every Node.js process from starting.

  • With nodeLinker.type: loaded, scripts can now run a Node.js runtime installed through devEngines.runtime. Before, every script that called node re-ran its own shim until it failed with "Argument list too long".

  • With nodeLinker.type: loaded, Node.js processes start faster. In a project with 13,000 stored files, the startup overhead per process dropped from 67 ms to 18 ms.

  • pnpm install no longer fails with ERR_PNPM_NO_MATCHING_VERSION after a change to overrides when the lockfile resolves an optional peer dependency to an npm alias of another package #​16654.

  • A frozen install with catalogPrune no longer removes catalog entries that pnpm-lock.yaml still records. Before, pnpm install --frozen-lockfile --filter failed with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH when some workspace projects were missing from disk #​16638.

  • pnpm install --fix-lockfile no longer removes the deprecated and hasBin fields from lockfile entries #​6600.

  • With enableGlobalVirtualStore, an install that updates node_modules now repairs a package in the global virtual store that an interrupted install left without some of its dependency links or package files. Before, such an install kept the incomplete package if the project's node_modules already recorded it #​16642.

  • pnpm install now skips the Cargo and Python projects inside a nested directory that has its own pnpm-workspace.yaml or .git directory, such as a git worktree of the same workspace or a separate clone.

  • The Request took warning for package metadata now starts timing when pnpm sends the request. Before, it also counted the time the request waited for a free request slot, so large installs printed it for requests the registry answered quickly.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.10.0: pnpm 12.10.0

Compare Source

This r

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "every weekday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested review from DaveHanns and l2ysho as code owners October 5, 2026 06:43
@renovate

renovate Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@renovate
renovate Bot force-pushed the renovate/all-non-major branch 3 times, most recently from eee0886 to b42b6b5 Compare October 6, 2026 11:48
@renovate renovate Bot changed the title chore(deps): update pnpm to v12.9.1 chore(deps): update patch/minor dependencies Oct 6, 2026
@renovate
renovate Bot force-pushed the renovate/all-non-major branch 9 times, most recently from 3edd4fe to d9350b0 Compare October 10, 2026 18:18
@renovate
renovate Bot force-pushed the renovate/all-non-major branch from d9350b0 to e0ee6e5 Compare October 11, 2026 06:15

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant