Repository navigation
chore(deps): update all non-major dependencies - #875
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
✅ Deploy Preview for html-validator ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
9 times, most recently
from
September 14, 2026 07:56
7f74c57 to
8853482
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
4 times, most recently
from
September 23, 2026 02:23
ddcaa9c to
2aa5221
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
8 times, most recently
from
October 4, 2026 00:33
4f2a78f to
9356d8a
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
5 times, most recently
from
October 6, 2026 10:56
e077c4e to
b304af3
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
7 times, most recently
from
October 11, 2026 08:57
4a57dfd to
54c35f6
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
October 11, 2026 12:24
54c35f6 to
cc6c9a8
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
12.2.2→12.3.0v0.6.9→v0.6.115.13.0→5.14.0~11.11.0→~11.16.017.4.1→17.6.012.9.1→12.11.2Release Notes
antfu-collective/bumpp (bumpp)
v12.3.0Compare Source
🚀 Features
View changes on GitHub
v12.2.3Compare Source
🐞 Bug Fixes
allis set - by @antfu (016c8)View changes on GitHub
danielroe/uppt (danielroe/uppt)
v0.6.11Compare Source
compare changes
🚀 Enhancements
🩹 Fixes
💅 Refactors
❤️ Contributors
v0.6.10Compare Source
compare changes
🚀 Enhancements
🩹 Fixes
🏡 Chore
✅ Tests
🤖 CI
❤️ Contributors
nuxt-content/docus (docus)
v5.14.0Compare Source
Features
nuxt-agent-discovery(#1435) (acb72f4)nuxt-schema-organduseCanonical(#1439) (6090b7e)Bug Fixes
markdown/html(#1449) (6881e06)site.urlfor llms.txt domain (#1447) (c229a86)html-validate/html-validate (html-validate)
v11.16.2Compare Source
Bug Fixes
v11.16.1Compare Source
Bug Fixes
v11.16.0Compare Source
Features
HtmlValidate.autofix()and deprecate all other variants (40c67f0)minSectioningRootInitialRankoption toheading-level(7b9629f)Bug Fixes
v11.15.0Compare Source
Features
insertTextBefore()andinsertTextAfter() methods toErrorFixer` (ac6ca62)v11.14.0Compare Source
Features
fixableErrorCountandfixableWarningCounttoReportobject (5bad2dd)fixableErrorCountandfixableWarningCounttoResultobject (edc169f)stylishandcodeframeformatters output number of fixable errors and warnings (6f230fc)v11.13.0Compare Source
Features
autofixCollectEditsfor integrations to support autofix (b7de9fa)v11.12.0Compare Source
Features
removeText()method toErrorFixer(3484ed3)no-redundant-for(6798b9c)missing-doctypeautofixable (2c4c2e7)no-raw-charactersautofixable (b7e28aa)script-typeautofixable (e15cb1a)tel-non-breakingautofixable (d91bc8c)Bug Fixes
lint-staged/lint-staged (lint-staged)
v17.6.0Compare Source
Minor Changes
#1850
938d3f4- Task functions like{ title, task }can now use a logger functionlog()to emit output while the task runs. By default, the output will only be visible if the task fails, unless the--verboseoption was used. Additionally, when the task rejects, the error will be shown in the output.#1854
30562bc- lint-staged now stages changes to all tracked files modified by tasks, including files that weren’t originally staged or didn’t match the configured globs. This can happen when your task has side-effects, or it's a function that ignores the staged files like() => "prettier --write .".If you have unstaged changes in a file and the task also edits that file, your unstaged changes will be staged too. Use
--hide-unstagedto hide your changes while tasks run.Patch Changes
#1860
4296532- The assignment of staged files to lint-staged configuration files (when using multiple, for example in a monorepo) has been rewritten to be more efficient. As a reminder, each staged file is assigned to exactly one configuration (the closest one), even if that config doesn't match the file in its globs.#1861
c45f28a- Fix running parallel tasks for a single glob, when tasks are created by a function. Nesting one level of arrays inside an array of tasks will result in the inner tasks running in parallel. This behavior should now be consistent when creating tasks using functions. In the following exampleeslintandprettierwill run in parallel (for all files, when any JS files are staged):#1859
f0ea69d- Various performance improvements from skipping redundant internal Git calls.#1856
69d7d17- Partially staged changes are hidden in a uniquely-named patch file to avoid multiple invocations of lint-staged overwriting it. This makes it safer to run lint-staged in multiple worktrees at the same time.v17.5.1Compare Source
Patch Changes
#1852
bfcca94- Fix TypeScript issueTS1254fromdefineConfig()by changing the signature fromconstto afunction:v17.5.0Compare Source
Minor Changes
f9063b7- Lint-staged now refuses to run when files were staged with--intent-to-add, because Git stash doesn't support them. Previously this was an unhandled error.Patch Changes
#1848
d718ccc- Lint-staged now handles color support better in non-TTY streams, and honors theFORCE_COLORenvironment variable.#1845
7e5ece8- Updatetinyexec@1.3.1so that local binaries fromnode_modules/.binare resolved starting from the directory of each lint-staged configuration file (in monorepo setups). This behavior was broken inlint-staged@16.3.0where they were only resolved from the current working directory and up.#1845
eb8a4e3- Do not try to restore untracked files when using--hide-alland there is no initial commit yet.pnpm/pnpm (pnpm)
v12.11.2: pnpm 12.11.2Compare Source
This release fixes
--workspace-concurrency=Infinity, filters set by anupdateConfighook, and store fetches withenable-modules-dir=false.Patch Changes
--workspace-concurrency=Infinitynow runs workspace projects with no concurrency limit. It used to fail withinvalid digit found in string#16793.pnpm installand other recursive commands now apply thefilterandfilterProdthat anupdateConfighook sets. They used to run on every workspace project #16792.enable-modules-dir=falsenow also fetches the packages an install reuses from an existing lockfile, so the store holds every package the lockfile lists.Platinum Sponsors
Gold Sponsors
v12.11.1: pnpm 12.11.1Compare Source
This release fixes two ways
pnpm installcould fail, runs tools of any Rust release throughpnx, and treatsregistry.npmjs.comas an alias of the npm registry.Patch Changes
pnpm installno longer fails whenpackageManagerpins the pnpm version that is already running and the registry does not publish that version. pnpm warns and continues. A registry mirror that has not synced a release no longer blocks the commands of a project pinned to it.pnpm installno longer fails withERR_PNPM_CMD_SHIM_CHMODwhennode_modules/.binholds a shim that another user created, if everyone can already execute it and it is not world-writable. This happens when several users share one checkout.enable-modules-dir=false(enableModulesDir: falsethrough the Node.js addon) fetches the registry packages the host can install into the store again, as pnpm v10 did, while still writing nothing undernode_modules. The setting exists for anode_modulesthat something else mounts from the store, such as a FUSE daemon, and that consumer no longer has to download each package on first access. A plain--lockfile-onlyrun still fetches nothing.pnpm packandpnpm publishno longer put.npmignoreand.gitignorefiles in the tarball. Afilesentry that names one still ships it.pnpm now treats
https://registry.npmjs.com/as an alias ofhttps://registry.npmjs.org/. Registry requests, credentials, and trusted publishing use the canonical hostname.pnx --package=rust@<channel> <tool>runs a tool of that Rust release, for examplepnx --package=rust@nightly-2026-01-01 cargo build. pnpm installs the release with the components and targets fromrust-toolchain.tomland the target of each--targetargument.pnpm installnow links agent skills for more coding agents. It detects the agent fromANTIGRAVITY_AGENT,COPILOT_AGENT,COPILOT_CLI,CODEX_THREAD_ID,CODEX_SANDBOX,AI_AGENT, andCLAUDE_CODEpnpm/tasks#116.When the registry rejects
pnpm stage publish, the error message now starts with "Failed to stage package".Platinum Sponsors
Gold Sponsors
v12.11.0: pnpm 12.11.0Compare Source
This release adds Rust toolchain management, links the agent skills that dependencies ship, adds the
permissionssetting, and keeps the colors of streamed script output.Minor Changes
pnpm installnow links the agent skills that direct dependencies ship underskills/<name>/SKILL.mdinto the project's agent skill directories, such as.claude/skills. A package's skills are linked only after you approve them withpnpm approve. Theskills.dirssetting chooses the directories pnpm/rfcs#35.Added the
permissionssetting, which records what each dependency may do. Itsbuildcapability works likeallowBuildsand takes precedence over it.pnpm approve-buildswrites topermissionswhenpnpm-workspace.yamlalready has it, and toallowBuildsotherwise.Added
pnpm permissions, which lists the granted and denied permissions and the packages awaiting approval.pnpm approvereviews build scripts and agent skills in one prompt pnpm/rfcs#36.pnpm now installs and runs Rust toolchains.
cargo.enabled,pnpm installinstalls the toolchain named inrust-toolchain.toml. pnpm verifies the release signature, stores the toolchain once per machine, and links it into.pnpm/rust.pnpm runandpnpm execput itscargoandrustcon thePATH.pnpm add -g rust@<channel>installs a toolchain globally. Thecargoandrustccommands run it outside projects that pin their own.pnpm update -g,pnpm ls -g, andpnpm remove -gmanage it like any global package.pnpm add rust@<channel>pins the toolchain inrust-toolchain.toml.pnpm shim add rustadds project-aware shims forcargo,rustc, and the other Rust tools. In a project with arust-toolchain.toml, they run the toolchain the file names and install it on first use. Elsewhere, the next command of the same name onPATHruns, such as rustup's.pnpm runandpnpm execnow keep the colors of script output that they print under the project's name, such as with--stream. pnpm setsFORCE_COLOR=1for these scripts when its own output is in color, unlessFORCE_COLORis already set.Script output is also rendered more cleanly:
\rshows only its last state.pnpm -r runno longer garbles its live output when a script fails while other scripts are still running.Patch Changes
Installing packages
pnpm no longer panics with "unexpected error when polling the I/O driver" when it runs under QEMU user-mode emulation, such as a
linux/amd64container on an Apple Silicon Mac #16696.pnpm view,pnpm update, and other commands that read registry metadata now work behind proxies that end a response by closing the connection without a TLSclose_notifyalert #16704.pnpm now switches to the version a project pins in
packageManagerordevEngines.packageManagereven whenpnpm-workspace.yamlhas a setting the running pnpm cannot read, such as alockfile.includeResolutionSettingssection. If pnpm does not switch, it still reports that setting #16675.When the
pnpmpackage has to download its native binary on first run, it now uses the registry and credentials from.npmrcand from thenpm_config_registryandpnpm_config_registryenvironment variables.COREPACK_NPM_REGISTRYstill takes precedence. A project.npmrcis not read whenCOREPACK_INTEGRITY_KEYSturns off the signature check #16655.pnpm installandpnpm add --confignow applyminimumReleaseAgewhen they resolve a config dependency. A config dependency range resolves to the newest version that is old enough, so a later cleanpnpm install --frozen-lockfileaccepts the lockfile #16660.pnpm removewithcatalogPruneno longer removes catalog entries thatpnpm-lock.yamlstill records for workspace projects missing from disk. Before, a following frozen install failed withERR_PNPM_LOCKFILE_CONFIG_MISMATCH#16679.With
cargo.enabled,pnpm installnow writes the source replacement for vendored crates into.pnpm/crates/config.tomland includes it as optional from.cargo/config.toml. A checkout without.pnpmbuilds with plain Cargo #16659.With
nodeLinker.typeset toloaded, Node.js now stops withERR_PNPM_LOADER_UNSUPPORTED_NODEwhen it preloads the store loader on a version the loader cannot serve. The supported versions are^24.18.0 || >=26.2.0. On other versions, CommonJS packages imported from ESM failed withCannot find moduleon their first relativerequire().On Windows,
pnpm installno longer fails with "The filename, directory name, or volume label syntax is incorrect" when a package contains a file whose name is invalid on Windows, such asicon.svg?as=metadata.d.ts. pnpm removes the invalid characters from the name and prints a warning that lists the renamed files.On Windows, hoisting no longer fails intermittently with link errors when a junction is created or replaced concurrently pnpm/tasks#53.
Resolving dependencies
pnpm install --no-optionalnow installs the peer dependencies a project declares whenautoInstallPeersis on. The lockfile marked such a peeroptional: truewhen another dependency had it as an optional peer.pnpm installandpnpm dedupenow link an optional peer to the workspace package that the workspace root depends on when the picked version matches it. They installed the registry package with the same name and version #16706.Removal overrides such as
"debug>supports-color": "-"now also apply to an optional peer that a package declares only inpeerDependenciesMeta#16681.pnpm addand other installs that re-resolve dependencies now keep the lockeddevEngines.runtimeversion while it still satisfies the declared range #16764.pnpm audit --fix updatenow updates only the dependencies whose locked version is vulnerable #14928.pnpm outdatedandpnpm update --interactivenow applyoverridesbefore they look up the latest version. Before, a dependency overridden to an npm alias was compared with the latest version of the package the override replaces #16719.Patched dependencies
Patches saved with CRLF line endings now apply, including a patch that creates or deletes a file. pnpm rejected the git headers of such a patch with
ERR_PNPM_INVALID_PATCHand the messageinvalid file mode: 100644#16641.A patch that changes a file's mode, such as adding or removing the executable bit, now applies the new mode on Unix pnpm/tasks#110.
Injected dependencies and deploy
With
sharedWorkspaceLockfile: false, an injected workspace package installed in the same run as its dependent now holds only the files itsfilesfield selects. The copy also held other files of the project, such astsconfig.json#16683.A script listed in
syncInjectedDepsAfterScriptsno longer fails when it rewritespackage.jsonwhile pnpm is copying its edits into the injected copies. The sync after the script now replaces a half-copied manifest.pnpm deploywith a shared lockfile no longer fails withERR_PNPM_LOCKFILE_CONFIG_MISMATCHforsettings.dedupeInjectedDepsorsettings.dedupePeerDependentswhenlockfile.includeResolutionSettingsis enabled. The deployed lockfile now records both settings asfalse, the values the deploy installs with.pnpm deploynow writes the dependencies in the deployedpackage.jsonsorted by name. It also sorts theallowBuildsentries in the deployedpnpm-workspace.yaml. Repeated deploys of the same lockfile now produce identical files #16687.Packing and publishing
pnpm packandpnpm publishnow match.npmignoreand.gitignorerules the way npm does. A negation such as!lib/**or!lib/**/!(*.map)re-includes files under a directory that an earlier*rule excluded #16743.pnpm packandpnpm publishno longer always include root files that merely start withREADME,LICENSE, orLICENCE, such asREADME_INTERNAL.md. OnlyREADME,LICENSE,LICENCE, andCOPYING, with or without an extension, ship regardless offilesand.npmignore, as in npm #16753.pnpm publish --provenance=falseand--no-provenancenow turn off provenance under trusted publishing, so a package can be published from a self-hosted runner. Settingprovenance: falseinpnpm-workspace.yamldoes the same #16721.Speed and resource use
pnpm installhardlinks files from a group-writable or world-writable store again. pnpm copied every file from such a store intonode_modules#16677.A repeat
pnpm installno longer imports patched packages and packages with build scripts again when nothing changed. Their builds no longer run again either. This happened whenrecursiveInstallwasfalseor the project had afile:dependency #16705.Verifying the lockfile against
trustPolicyandminimumReleaseAgeuses less memory. pnpm no longer keeps every published version's manifest of each checked package in memory until the install ends #16656.pnpm rebuild <pkg>andpnpm rebuild --pendingno longer read the manifest of every installed package to find build scripts. Only the selected packages are inspected and built. On a largenode_modulesserved lazily, such as over a network or FUSE mount, this turned a rebuild of a few packages into a fetch of every package.pnpm rebuildno longer removes and recreatesnode_moduleswhen the settings recorded innode_modules/.modules.yamldiffer from the current configuration. The rebuild runs the build scripts against the installed packages as they are.pnpm store prunenow compacts the store'sindex.dbafter removing package entries, so the file shrinks again #16717.Registry commands
pnpm whoami,pnpm bugs,pnpm docs,pnpm repo,pnpm star,pnpm unstar, andpnpm starsnow honor the--registryoption.--registrynow takes precedence over a scope's configured registry for scoped packages inpnpm access,pnpm view,pnpm repo,pnpm star,pnpm unstar,pnpm owner,pnpm deprecate,pnpm undeprecate,pnpm unpublish,pnpm dist-tag,pnpm team, andpnpm stage. Without--registry,pnpm accessnow sends a scoped package or scope to the registry configured for that scope.Registry commands now keep the path of a registry URL such as
https://example.com/npm/when they build request URLs. This applies topnpm access,pnpm owner,pnpm ping,pnpm search,pnpm star,pnpm stars,pnpm team,pnpm unstar, andpnpm whoami.pnpm viewnow honors the network retry settings.pnpm reponow fetches the repository URLs of several packages in parallel.Platinum Sponsors
Gold Sponsors
v12.10.1: pnpm 12.10.1Compare Source
This release fixes
pnpm installfailures after anoverrideschange and on a filtered frozen install withcatalogPrune. It also fixes several bugs in the experimentalnodeLinker.type: loaded, which now keeps its generated files innode_modules.Patch Changes
With
nodeLinker.type: loaded, pnpm now writes its generated files tonode_modules, which projects already ignore in git. The store manifest and loader arenode_modules/.pnpm/.store-manifest.jsonandnode_modules/.pnpm/.store-loader.mjs. Bin shims are innode_modules/.bin.Earlier versions wrote
.pnpm-store.jsonand.pnpm-store-loader.mjsto the project root, and a.pnpmdirectory to the root and to each workspace package. Delete them after reinstalling.With
nodeLinker.type: loaded, packages that ship their ownnode_modulesdirectory, such asnpmwith its bundled dependencies, now load from the store. Before, one such package in the install stopped every Node.js process from starting.With
nodeLinker.type: loaded, scripts can now run a Node.js runtime installed throughdevEngines.runtime. Before, every script that callednodere-ran its own shim until it failed with "Argument list too long".With
nodeLinker.type: loaded, Node.js processes start faster. In a project with 13,000 stored files, the startup overhead per process dropped from 67 ms to 18 ms.pnpm installno longer fails withERR_PNPM_NO_MATCHING_VERSIONafter a change tooverrideswhen the lockfile resolves an optional peer dependency to an npm alias of another package #16654.A frozen install with
catalogPruneno longer removes catalog entries thatpnpm-lock.yamlstill records. Before,pnpm install --frozen-lockfile --filterfailed withERR_PNPM_LOCKFILE_CONFIG_MISMATCHwhen some workspace projects were missing from disk #16638.pnpm install --fix-lockfileno longer removes thedeprecatedandhasBinfields from lockfile entries #6600.With
enableGlobalVirtualStore, an install that updatesnode_modulesnow repairs a package in the global virtual store that an interrupted install left without some of its dependency links or package files. Before, such an install kept the incomplete package if the project'snode_modulesalready recorded it #16642.pnpm installnow skips the Cargo and Python projects inside a nested directory that has its ownpnpm-workspace.yamlor.gitdirectory, such as a git worktree of the same workspace or a separate clone.The
Request tookwarning for package metadata now starts timing when pnpm sends the request. Before, it also counted the time the request waited for a free request slot, so large installs printed it for requests the registry answered quickly.Platinum Sponsors
This PR was generated by Mend Renovate. View the repository job log.