Skip to content

fix(deps): update all non-major dependencies - #84

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Jun 28, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
@commitlint/cli (source) ^21.2.2 → ^21.2.3 age confidence devDependencies patch
@commitlint/config-conventional (source) ^21.2.2 → ^21.2.3 age confidence devDependencies patch
@types/node (source) ^24.13.5 → ^24.19.0 age confidence devDependencies minor
@wolfstar/env-utilities (source) ^2.1.1 → ^2.2.0 age confidence dependencies minor 2.2.1
@wolfstar/http-framework (source) ^5.0.0 → ^5.1.1 age confidence pnpm-workspace.overrides minor 5.1.2
@wolfstar/http-framework (source) ^5.0.0 → ^5.1.1 age confidence dependencies minor 5.1.2
@wolfstar/plugin-api (source) ^1.1.5 → ^1.1.6 age confidence dependencies patch 1.1.7
@wolfstar/plugin-i18next (source) 2.0.3 → 2.1.0 age confidence pnpm-workspace.overrides minor 2.1.1
@wolfstar/plugin-i18next (source) 2.0.3 → 2.1.0 age confidence dependencies minor 2.1.1
@wolfstar/shared-http-pieces (source) 2.0.4 → 2.0.7 age confidence dependencies patch 2.0.9
actions/checkout v7.0.0 → v7.0.1 age confidence action patch
ansi-regex ^6.2.2 → ^6.3.0 age confidence pnpm-workspace.overrides minor 6.4.0
eslint (source) ^10.10.0 → ^10.11.0 age confidence devDependencies minor
eslint-plugin-regexp ^3.3.0 → ^3.3.1 age confidence devDependencies patch
oxfmt (source) ^0.68.0 → ^0.70.0 age confidence devDependencies minor 0.71.0
oxlint (source) ^1.83.0 → ^1.85.0 age confidence devDependencies minor 1.86.0
pnpm (source) 12.4.2 → 12.7.0 age confidence packageManager minor 12.8.1 (+1)
pnpm/action-setup v6.0.9 → v6.1.0 age confidence action minor

Release Notes

conventional-changelog/commitlint (@​commitlint/cli)

v21.2.3

Compare Source

Bug Fixes
  • lint: trim trailing whitespace off the message handed to ignore matchers (#​4960) (a6f279b)
conventional-changelog/commitlint (@​commitlint/config-conventional)

v21.2.3

Compare Source

Bug Fixes
  • rules: report the case that matched in case rule failure messages (#​4962) (9f5f7bc)
wolfstar-project/stars-components (@​wolfstar/env-utilities)

v2.2.0

Minor Changes
  • #​198 95a5fa1 - feat: add experimental support for varlock as an alternative to dotenv, opt-in via the loader: 'varlock' option (or the DOTENV_LOADER environment variable) Thanks @​RedStar071!
wolfstar-project/stars-components (@​wolfstar/http-framework)

v5.1.1

Patch Changes
  • #​222 4c4138e - fix(auto-imports): stop auto-importing @wolfstar/env-utilities' setup, which clashed with the setup() scaffolded projects export from src/lib/setup/all.ts and printed a duplicated import warning on every build (#​219) Thanks @​RedStar071!

v5.1.0

Minor Changes
  • #​209 6d970e5 - Align configuration entry points with Nuxt: add framework schema and package metadata exports, provide a lightweight schema/config helper, and separate schema input types from config resolution while preserving existing exports. Thanks @​RedStar071!

  • #​209 6d970e5 - Split the stars.config.* schema and loader (defineConfig, loadStarsConfig, configDiagnostics and friends) out
    of @wolfstar/http-framework into a new package, @wolfstar/schema,
    and made @wolfstar/http-framework depend on @wolfstar/cli for its own stars binary — the same split Nuxt has
    between nuxt, @nuxt/cli and @nuxt/schema.

    • @wolfstar/http-framework/config re-exports @wolfstar/schema's public surface unchanged, so existing
      import { defineConfig } from '@wolfstar/http-framework/config' code keeps working with no changes needed.
    • @wolfstar/http-framework now depends on @wolfstar/cli and ships a stars bin (bin/stars.mjs, re-exporting
      @wolfstar/cli/cli), the way nuxt ships nuxi's binary — installing @wolfstar/http-framework is now enough to
      get the stars command, no separate @wolfstar/cli install required.
    • Breaking for @wolfstar/cli: it no longer depends on @wolfstar/http-framework (matching @nuxt/cli having no
      dependency on nuxt) — it now depends on @wolfstar/schema for the config schema/loader instead. Projects
      that installed @wolfstar/cli without also depending on @wolfstar/http-framework directly (uncommon, since the
      CLI has nothing to build without it) now need to add @wolfstar/http-framework themselves; every project scaffolded
      by @wolfstar/create-http-framework, or that already depends on @wolfstar/http-framework, is unaffected.
      @wolfstar/cli's own public exports (loadStarsConfig, configDiagnostics, ConfigDiagnosticCode,
      ResolvedStarsConfig, re-exported from @wolfstar/schema) are unchanged.

    This was needed because @wolfstar/cli already depended on @wolfstar/http-framework: adding the reverse dependency
    (for the new stars bin) without this split would have made the two packages depend on each other, which this
    monorepo's build graph (and any tool resolving workspace dependencies) cannot build. Thanks @​RedStar071!

Patch Changes
wolfstar-project/plugins (@​wolfstar/plugin-api)

v1.1.6

Compare Source

Patch Changes
wolfstar-project/plugins (@​wolfstar/plugin-i18next)

v2.1.0

Compare Source

Minor Changes
  • #​116 56ead81 - feat: export T, FT, resolveKey, resolveUserKey, TypedT and TypedFT again as deprecated compatibility shims with @wolfstar/http-framework-i18n's names and signatures, so a migration only has to rename the module specifier instead of failing at load time with does not provide an export named 'T' (#​114)
Patch Changes
  • #​60 0540e1c - fix(deps): update dependency i18next to v26 Thanks @​renovate!

  • #​116 56ead81 - fix: accept @wolfstar/http-framework v5 as a peer dependency (^3.1.0 || ^5.0.0), so v5 projects no longer install the plugin with an unmet peer (#​115)

v2.0.4

Compare Source

Patch Changes
  • #​86 15332ef - Fix TypeScript overload resolution in getSupportedLanguageT, getSupportedUserLanguageT, and fetchKey when key is a union type (such as a ternary expression).

    Previously, these functions used a single generic signature with a union-typed rest parameter. When key was a union, TypeScript failed to resolve the candidate tuple properly and rejected valid options objects as if they were positional defaultValue strings. Each call shape is now declared as an independent overload, while the original generic signature is retained as a deprecated trailing overload for full backward compatibility.

wolfstar-project/stars-components (@​wolfstar/shared-http-pieces)

v2.0.7

Patch Changes

v2.0.6

Patch Changes

v2.0.5

Patch Changes
actions/checkout (actions/checkout)

v7.0.1

Compare Source

chalk/ansi-regex (ansi-regex)

v6.3.0

Compare Source


eslint/eslint (eslint)

v10.11.0

Compare Source

ota-meshi/eslint-plugin-regexp (eslint-plugin-regexp)

v3.3.1

Compare Source

Patch Changes
  • Updates unicode property alias resource with latest (#​1052)
oxc-project/oxc (oxfmt)

v0.70.0: oxfmt v0.70.0

Compare Source

🚀 Features
  • 415b742 oxlint,oxfmt: Do not discover nested config in Vite+ mode (#​26763) (leaysgur)

v0.69.0

Compare Source

oxc-project/oxc (oxlint)

v1.85.0

Compare Source

v1.84.0

Compare Source

pnpm/pnpm (pnpm)

v12.7.0: pnpm 12.7

Compare Source

pnpm 12.7.0 ships with .nvmrc and .node-version support in the global node shim, pnpm install --allow-build, pnpm publish --publish-wait-timeout, and pnpm-workspace.yaml created from the workspaces field. pnpm install --force no longer installs optional dependencies built for other platforms. This release also carries security fixes for bin shims on Nix, for lifecycle scripts of packages in a storeDir inside the workspace, and for userAgent placeholders in pnpm-workspace.yaml.

Minor Changes
  • pnpm install --force now keeps skipping optional dependencies whose os, cpu or libc do not match the host. It still refetches every package and lifts engineStrict. The new forceIgnoresPlatform setting restores the previous behaviour, installing optional dependencies of every platform under --force #​6133.

  • The global node shim created by pnpm now uses the Node.js version from the nearest .nvmrc or .node-version file when the project does not declare a Node.js runtime in devEngines.runtime or engines.runtime #​4471. The nearest directory with a Node.js runtime declaration decides the version. Within one directory, package.json takes precedence over .node-version, which takes precedence over .nvmrc. An .nvmrc value that only nvm can act on, such as system or a custom alias, is ignored.

  • pnpm install now supports the --allow-build option to selectively allow or deny package lifecycle scripts and record them in pnpm-workspace.yaml #​15388.

  • Added pnpm publish --publish-wait-timeout <milliseconds> to wait for published versions and their tarballs to become available from the registry. Set publishWaitTimeout in pnpm-workspace.yaml to configure a default. A value of 0 disables the check.

    Recursive publishing confirms availability before publishing dependent packages. If confirmation times out, the command fails.

    When pnpm publish -r --report-summary fails after some uploads were accepted, the summary file now lists those packages.

  • pnpm install now creates pnpm-workspace.yaml from the workspaces field of the root package.json when the repository has no pnpm-workspace.yaml. The projects the field lists are linked on that same install. An existing pnpm-workspace.yaml is never changed. With --ignore-workspace, no file is created. If the workspaces field later differs from packages in pnpm-workspace.yaml, pnpm prints a warning #​2255.

  • When a project pins a pnpm version or a runtime that another pnpm process is installing at that moment, pnpm now waits a few seconds and then installs and runs a private copy of its own. It used to wait up to five minutes and then use the shared install directory without the lock. The private copy is removed once the command has run. pnpm store prune removes any private copy that a killed process left behind #​15413.

  • pnpm now keeps the blank lines between entries of package.json when it updates the file, for example on pnpm add #​5602.

Patch Changes
Security
  • pnpm no longer expands environment variables in a userAgent set in a project's pnpm-workspace.yaml. A userAgent with a placeholder in that file is now ignored. Before this fix, pnpm sent the variable's value to the configured registry #​15415.

  • On Nix, a dependency's bin named like a system utility such as sed can no longer redirect a POSIX bin shim or the pnpm, pn, pnpx, and pnx launchers. The shims and launchers now ignore node_modules and relative PATH entries while they locate their own files. Installing again replaces the shims already in node_modules #​14883.

  • pnpm no longer treats manifests inside its store, cache, state, or modules directories as workspace projects. Before, a storeDir inside the workspace could let lifecycle scripts of packages in the store run without allowBuilds approval #​15033.

  • Packages that run a lifecycle script are no longer hard-linked into the virtual store, so a build script can no longer rewrite the workspace source of an injected package or the store copy it was imported from #​15483.

Installing packages
  • Fixed pnpm install, pnpm add, pnpm remove, and pnpm peers check running out of memory when many packages share a missing peer dependency. This mostly affected projects with autoInstallPeers: false #​15362.

  • pnpm no longer hangs for up to 5 minutes after a pnpm process was killed while setting up the pnpm version pinned in packageManager or devEngines #​15360, #​15393. The killed process left behind a lock that every later pnpm command in the project waited on. pnpm now detects that the process holding a lock is gone and takes the lock over at once. The same applies to the locks pnpm takes while installing a managed runtime or writing the global bin directory. Two pnpm processes that are both still running keep waiting for each other as before.

  • Requests to a registry or tarball server whose TLS certificate fails verification now fail at once. Such requests were retried for more than a minute without any output #​9134.

  • On macOS, pnpm now falls back to its bundled CA roots when system trust evaluation is unavailable, such as in a sandbox or when macOS cannot create an SSL policy for a registry connection. Installs failed or crashed on the first registry request in that case. Custom ca certificates are now honored directly #​15329, #​14461.

  • pnpm install now caps concurrent connections to a proxy at 50 sockets by default #​15280. It also immediately retries transient connection resets when downloading package archives.

  • pnpm install now reuses a package already present in the store when an existing lockfile entry satisfies the dependency, avoiding registry requests that fail without authorization #​2522.

  • Installing or adding dependencies no longer fails when a previously installed local tarball file was deleted from disk #​8367.

  • pnpm install now installs the new version of a local tarball dependency whose file was replaced at the same path #​2437. pnpm install --frozen-lockfile rejects such a changed tarball, even when the previous archive contents are in the store #​1889.

  • pnpm install now fetches committed submodules of git dependencies #​1470.

  • pnpm install now applies patches produced by pnpm patch-commit when an edit removes the trailing lines of a file along with its newline. The install no longer fails with ERR_PNPM_INVALID_PATCH ("expected end of hunk") #​12451.

  • pnpm install now preserves existing node_modules directories when a cross-device move reports EXDEV #​14504.

  • pnpm install no longer fails when writing the workspace state file encounters an error. Failures to update the state file now emit a warning instead of aborting the install #​14550.

  • Interrupting pnpm install with Ctrl+C or SIGTERM no longer leaves a temporary lockfile (.pnpm-lock.yaml.*.tmp) behind in the project #​1418.

  • pnpm install now relinks a direct dependency whose link in node_modules points to a missing target. Before, it reported "Already up to date" and left the broken link #​9758.

  • pnpm install uses less CPU when it links packages from a warm store. On Windows, a warm install could take several times longer than with pnpm 11 #​15439.

  • pnpm install now runs node --version once per run. A workspace whose projects keep their own lockfiles (sharedWorkspaceLockfile: false) previously ran the probe once or twice for every project, and on macOS the concurrent launches waited on each other, so a project could wait several seconds before its linking started.

  • A repeat pnpm install --frozen-lockfile with nodeLinker: hoisted in a workspace no longer re-links node_modules when nothing changed.

  • Custom fetcher hooks no longer run a second time during installation when an archive was already fetched during dependency resolution #​15025.

  • Fixed a package resolved by a resolvers pnpmfile hook installing without its own dependencies. This happened when the hook returned no manifest and a fetchers hook handled the resolution #​15552.

  • pnpm install --prod and other installs that skip devDependencies no longer run the pnpm:devPreinstall script #​7065. They skip prepare lifecycle scripts too, as do installs given package arguments.

  • pnpm prune --prod and production installs now remove devDependencies when lockfile: false is configured #​2677.

  • pnpm install --prod, pnpm fetch --prod and pnpm deploy --prod no longer install a devDependency that is only there to satisfy an optional peer dependency of a production dependency. pnpm list, pnpm why, pnpm licenses, pnpm sbom and pnpm audit leave it out of --prod results too. The same applies to --dev. A peer that is not optional is still installed and audited #​15344.

  • pnpm install no longer skips optional dependencies that the Node.js version locked for a devEngines.runtime range supports, when the range uses onFail: download. An explicitly set nodeVersion still takes priority #​14628.

  • pnpm fetch now also installs the pnpm version that pnpm-lock.yaml pins, when it differs from the running pnpm. A later pnpm install --offline that switches to the pinned version no longer fails because that version is missing from the store #​11808.

  • A dependency that ships a binding.gyp and sets gypfile: false no longer gets the node-gyp rebuild install script pnpm synthesizes for it. Such a dependency needs no allowBuilds entry and is no longer listed under "Ignored build scripts".

  • pnpm install no longer adds allowBuilds placeholder entries to pnpm-workspace.yaml when it runs in CI or without a terminal. Interactive installs still add them #​11574.

  • pnpm now detects the same CI environments as pnpm 11, including AWS CodeBuild, which does not set CI. On these services pnpm install uses a frozen lockfile by default and fails with ERR_PNPM_OUTDATED_LOCKFILE when the lockfile is outdated.

Resolving and linking dependencies
  • Installing through a pnpr server now installs a project's peer dependencies when autoInstallPeers is enabled. A project that declared only peer dependencies failed with ERR_PNPM_OUTDATED_LOCKFILE or skipped its peers #​14833.

  • pnpm now installs a dependency that a package also declares as an optional peer dependency, for example lightningcss in some vite builds. The dependency was missing from node_modules, so the package failed to import it #​8912.

  • Removal overrides such as "parent>peer": "-" now prevent optional peers from being installed from another workspace package #​15008.

  • Removing an entry from overrides now re-resolves the packages it targeted. A version the override had locked is no longer kept just because the declared range still accepts it #​4587.

  • packageExtensions and overrides entries with a ranged selector (such as @<X or @*) no longer match a dependency that has no package.json, such as a local directory dependency #​15007.

  • Trim leading and trailing whitespace from dependency override selectors in pnpm.overrides #​6356.

  • With trustPolicy: no-downgrade, pnpm now resolves the newest matching version that is not a trust downgrade. Previously a dependency failed with ERR_PNPM_TRUST_DOWNGRADE even when an older version satisfied its range. pnpm self-update picks its target version the same way. A request for an exact version still fails #​14176.

  • pnpm install now re-resolves a dependency when its manifest range is updated from a prerelease to a stable version. The lockfile previously retained the prerelease version and caused --frozen-lockfile to fail #​15528.

  • pnpm install --ignore-pnpmfile no longer removes pnpmfileChecksum from an up-to-date pnpm-lock.yaml. pnpm install --frozen-lockfile --ignore-pnpmfile no longer fails with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH when the lockfile records a pnpmfileChecksum. A command that resolves dependencies with the pnpmfile ignored still writes the lockfile without it #​10944.

  • pnpm install and pnpm peers check now use local tarball packages' actual versions when checking peer dependencies. Compatible packages no longer fail with strictPeerDependencies enabled.

  • pnpm peers check and the install-time peer dependency check now resolve peer dependencies from the workspace root when resolvePeersFromWorkspaceRoot is enabled #​14982.

  • autoDedupe and pnpm dedupe now move transitive dependencies to the version a catalog: dependency pins, as they already did for versions written directly in package.json. Previously they could move those dependencies to a higher version and keep both versions in the lockfile.

  • pnpm dedupe now produces a stable lockfile when a dependency's range matches both a direct dependency and an npm: alias of the same package. The dependency resolves to the version of the direct dependency. Repeated runs previously alternated between two lockfiles #​15588.

  • Merging lockfiles now preserves recorded configuration fields such as overrides, neverBuiltDependencies, patchedDependencies, packageExtensionsChecksum, settings, and catalogs #​8366.

  • A lockfile entry whose resolution is unchanged now keeps its recorded deprecated message #​5772.

  • pnpm no longer writes a package's legacy array-form engines, such as ["node >= 0.8"], to the lockfile. It was recorded as an object keyed by index, such as {'0': node >= 0.8} #​4518.

  • Tarball URLs recorded in the lockfile now strip default HTTP and HTTPS ports (:80 and :443) #​15539.

  • node_modules/.package-map.json no longer contains entries that point at directories that do not exist. Such entries appeared for packages installed only with peer dependencies, most visibly with enableGlobalVirtualStore #​14938.

  • With nodeLinker: hoisted, hoistWorkspacePackages now links each workspace project that hoistPattern or publicHoistPattern selects into the root node_modules, unless a hoisted package or a root dependency already uses its name. The project's bins are linked into the root node_modules/.bin #​7553.

  • With nodeLinker: hoisted, pnpm install now removes the commands of the packages it removes from node_modules/.bin, such as a nested copy deduped into the root node_modules #​7568.

  • pnpm install no longer puts a dependency's bin on PATH for that dependency's own lifecycle scripts before the bin's file exists. pnpm links such a bin after the dependency's build has run. It also removes such a bin left by an earlier install. This fixes installing the node package on Windows #​15501.

  • Dependencies and executable binaries are now correctly linked and accessible for workspace packages using publishConfig.directory and publishConfig.linkDirectory #​8338.

  • Bin linking leaves workspace and linked dependency files outside node_modules unchanged. Already executable bin files no longer receive redundant permission changes.

Workspaces and filtering
  • pnpm install now finds workspace projects reached through a symlink, such as a packages directory that links to a folder outside the workspace. It installs their dependencies, and the links in their node_modules resolve #​1044.

  • A dependency declared with catalog: now counts as a workspace dependency when its catalog entry points at a workspace project, for example workspace:* #​15587. With linkWorkspacePackages enabled, so does an npm: alias of a workspace project, such as "math-alias": "npm:math@^1.0.0". pnpm -r run runs that project first. --filter <pkg>... selects it.

  • A workspace: dependency now resolves to a workspace project whose version is not valid semver, such as 1 or 1.0. workspace:*, workspace:^, and workspace:~ match it. A range identical to the version also matches it #​4567.

  • A workspace: dependency with an exact version now resolves to a workspace project whose version carries SemVer build metadata. For example, workspace:0.5.6-next.3 matches a project at 0.5.6-next.3+f60facc #​6483.

  • Secondary dependencies now prefer the version resolved by the local project's direct dependencies over versions from sibling workspace projects #​7191.

  • pnpm install now re-resolves a workspace project's auto-installed peer dependency when another workspace project changes its specifier for that package to one that excludes the locked version but still overlaps the peer range. The peer then resolves to the version a fresh install would pick #​11800.

  • pnpm install --frozen-lockfile now fails with ERR_PNPM_OUTDATED_LOCKFILE when pnpm-lock.yaml lists a workspace project whose directory or manifest file is missing. The install used to report success without installing that project's dependencies #​7667.

  • pnpm install -r now installs every workspace project when recursiveInstall is set to false in pnpm-workspace.yaml #​7504.

  • pnpm install with --filter now installs only the dependencies of the selected projects when using nodeLinker: hoisted #​8882.

  • pnpm install now updates an injected workspace dependency after that package's own dependencies change, when shared-workspace-lockfile is false #​7209.

  • pnpm install now copies the output of a workspace package's own prepare, install, or postinstall script into the injected copies of that package. Before, the injected copies kept only the files that existed before the script ran. syncInjectedDepsAfterScripts now also works when modulesDir is set #​9464.

  • syncInjectedDepsAfterScripts now copies files into injected dependencies when node_modules is on another filesystem than the package sources. The sync previously failed with a cross-device link error and made the script run exit with an error #​14703.

  • A modulesDir with several path segments, such as www/modules, now puts each workspace project's dependencies in <project>/www/modules on both fresh and frozen installs, and pnpm bin prints <project>/www/modules/.bin #​15484.

  • With nodeLinker: hoisted, pnpm now installs the root project's dependencies into a custom modulesDir instead of node_modules. With a custom modulesDir, the virtual store and its lock.yaml now default to <modulesDir>/.pnpm.

  • A repeat pnpm install in a workspace with a custom modulesDir now takes the up-to-date fast path. Before, pnpm looked for each workspace project's dependencies in node_modules and ran a full install every time.

  • pnpm now warns when a workspace install covers a project that has its own pnpm-workspace.yaml. The nested file's settings, such as patchedDependencies, do not apply when the outer workspace installs that project. pnpm reads settings only from the pnpm-workspace.yaml at the workspace root #​11724.

  • The [<since>] filter selector now compares against the commit where the current branch forked from <since>. Projects changed only by newer commits on <since> are no longer selected. Uncommitted changes are still included. In a shallow clone without that commit, pnpm compares against <since> directly, as before #​9907.

  • --filter "[<since>]" now selects workspace packages when dependency versions change in a catalog in pnpm-workspace.yaml #​8718. It also selects projects that files were moved out of when git detects the move as a rename #​15481.

  • --filter now evaluates selectors in order, so later inclusion filters can re-include packages that an earlier exclusion filter excluded #​9354.

Adding, updating, and removing dependencies
  • pnpm add now saves changes to package.json before running lifecycle scripts, so a postinstall script failure leaves the added dependency in package.json #​8627.

  • pnpm add now saves the requested exact version when adding a dependency, even when the manifest already contains a version range #​6040.

  • pnpm add <pkg>@<version> and pnpm update <pkg>@<version> now move the catalog entry onto the named version when the entry's range already covers it. For example, ^7.22.17 becomes ^7.29.6, the same way pnpm update <pkg> moves an entry to the version it resolves #​13715.

  • pnpm add and pnpm install keep an empty peerDependencies, dependencies, devDependencies, or optionalDependencies field that was already in package.json. pnpm still drops such a field when it removes the last entry itself, as pnpm remove does #​5096.

  • pnpm update now keeps a version range whose shape has no save prefix, such as <= 3.0.0 or >=1.0.0 <2.0.0, when the updated version still satisfies it. Before, <= 3.0.0 became ^3.0.0 #​6714.

  • pnpm update <pkg> now moves a package off a locked version the registry no longer serves, such as an unpublished release. The lockfile check for supply-chain policies such as minimumReleaseAge used to reject that version before the update could replace it #​9953.

  • pnpm update --prod no longer installs devDependencies when run in a project installed with --prod #​8038.

  • pnpm update --interactive --workspace now allows external dependencies to be updated.

  • pnpm outdated and pnpm update now apply minimumReleaseAge to GitHub Actions. minimumReleaseAgeExclude entries match action names such as actions/checkout #​13923.

  • pnpm remove now accepts --trust-lockfile and --no-trust-lockfile to control supply-chain policy checks while removing a package #​14406.

  • pnpm unlink now removes the link: dependency that pnpm link <dir> added to package.json. The linked package is removed from node_modules and the lockfile. A link: dependency to another directory is kept #​4219.

  • pnpm install now prunes unreferenced catalog entries from pnpm-workspace.yaml when catalogPrune: true is configured #​15273.

  • minimumReleaseAgeExcludePrune and trustPolicyExcludePrune now work in workspaces with shared-workspace-lockfile=false. Once every project has been installed, pnpm drops an entry only if no project lockfile records it. Undecided allowBuilds entries are pruned the same way #​14612.

  • Exclude entries that pnpm writes to pnpm-workspace.yaml now match the file's list indentation and dominant quote style #​15571, #​15079.

  • pnpm import now converts dependencies that use Yarn's patch: protocol. The dependency keeps the version it patches, and the patch file is added to patchedDependencies in pnpm-workspace.yaml. If the patch file is missing, pnpm prints a warning and imports the dependency without the patch #​10278.

  • pnpm import in a workspace now keeps the versions pinned by the root yarn.lock, package-lock.json, or npm-shrinkwrap.json when another workspace project's range allows a newer version. Before, the root project got the newest version in its range #​4385.

  • pnpm patch, pnpm patch-commit, and pnpm patch-remove now work in a project of a workspace with sharedWorkspaceLockfile: false. pnpm patch failed there with ERR_PNPM_PATCH_NO_LOCKFILE after a successful install. The reinstall after committing or removing a patch left the project's own node_modules unchanged #​9926.

  • pnpm patch-commit now resolves default patch directory locations when passed a package name or package specifier (such as pnpm patch-commit <pkg> or pnpm patch-commit <pkg>@<version>).

  • pnpm patch-commit now updates the lockfile snapshot and prunes removed dependencies when the patch modifies package.json #​6866.

  • pnpm patch-commit now falls back to copying package files when hard linking fails.

Running scripts and commands
  • A script that pnpm runs without a terminal now ends when pnpm itself is killed. Killing pnpm's process group, as Playwright's webServer does to stop the command it started, used to leave the script running and holding the caller's output pipes open #​15555.

  • pnpm --filter <project> <command> and pnpm -r <command> now run a command installed in the selected projects' dependencies when none of them has a script by that name. This matches pnpm <command> in a single project. pnpm run with --filter or -r still reports the missing script #​10151.

  • pnpm exec and pnpm dlx now set npm_execpath, INIT_CWD, npm_node_execpath, and NODE in child environments when Node.js is available. Stale inherited NODE and npm_node_execpath variables are cleared when Node.js cannot be found on PATH #​7037. Scripts that pnpx and pnx run now get pnpm itself as npm_execpath. A script that ran $npm_execpath install there ran pnpm dlx install.

  • pnpm exec now sets the PWD environment variable to the directory the command runs in. Shells and tools that read PWD now report the logical path of a workspace package reached through a symlink #​1550.

  • A script that runs pnpm run no longer adds duplicate node_modules/.bin and node-gyp-bin entries to PATH #​5352.

  • Concurrent pnpm run and pnpm exec commands now serialize their dependency installs #​14551.

  • pnpm run and pnpm exec with verifyDepsBeforeRun now accept a moved project whose store is on the project's volume. Before, the check reported that the workspace structure had changed whenever the default store was not on the home volume.

  • verifyDepsBeforeRun checks now account for project-specific packageConfigs overrides in workspaces with sharedWorkspaceLockfile: false [#​15545](https://redirect.github.

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 12pm on Sunday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 612ce7b to 9ab60b6 Compare June 28, 2026 09:38
@renovate renovate Bot changed the title chore(deps): update all non-major dependencies fix(deps): update all non-major dependencies Jun 28, 2026
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 6 times, most recently from 01b64f6 to e4a662b Compare July 2, 2026 18:45
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 6 times, most recently from 195cdea to 642ba6a Compare July 8, 2026 11:09
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 11 times, most recently from 0565bf3 to 46abfe8 Compare July 16, 2026 20:54
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from 7afb255 to 75d61f4 Compare July 19, 2026 16:34
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from 72a3a50 to d917bc4 Compare August 5, 2026 10:45
Comment thread package.json Outdated
Comment on lines 33 to 47
"@prisma/adapter-pg": "^7.9.1",
"@prisma/client": "^7.9.1",
"@sapphire/result": "^2.8.0",
"@sapphire/utilities": "^3.18.2",
"@wolfstar/env-utilities": "^2.0.2",
"@wolfstar/http-framework": "^3.0.0",
"@wolfstar/http-framework-i18n": "^1.2.2",
"@wolfstar/logger": "^2.0.5",
"@wolfstar/env-utilities": "^2.0.5",
"@wolfstar/http-framework": "^3.1.2",
"@wolfstar/http-framework-i18n": "^1.2.5",
"@wolfstar/logger": "^2.1.3",
"@wolfstar/plugin-api": "^1.0.0",
"@wolfstar/shared-http-pieces": "^1.2.6",
"@wolfstar/start-banner": "^2.0.3",
"@wolfstar/shared-http-pieces": "^1.2.8",
"@wolfstar/start-banner": "^2.0.6",
"discord-api-types": "^0.38.47",
"gradient-string": "^3.0.0",
"husky": "^9.1.7",
"ioredis": "^5.11.1",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚨 Bug: package.json bumped but pnpm-lock.yaml not updated

package.json (and pnpm-workspace.yaml override) were bumped to new versions, but pnpm-lock.yaml was not updated in this PR — it still pins the old specifiers/versions (e.g. untun specifier ^0.1.3, @prisma/adapter-pg/@prisma/client/prisma 7.8.0, @wolfstar/env-utilities 2.0.2, etc.). The CI step pnpm install --filter . --ignore-scripts runs with pnpm's CI default of --frozen-lockfile, so this mismatch will fail with ERR_PNPM_OUTDATED_LOCKFILE. Regenerate and commit pnpm-lock.yaml (pnpm install --lockfile-only) so the lockfile matches the updated manifests.

Was this helpful? React with 👍 / 👎

Comment thread package.json Outdated
"nano-staged": "^1.0.2",
"tslib": "^2.8.1",
"untun": "^0.1.3"
"untun": "^0.2.2"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Edge Case: untun 0.1.x→0.2.x is a pre-1.0 minor that may break tunnel

untun moves from ^0.1.3 to ^0.2.2; for 0.x packages a minor bump can contain breaking API changes. tsdown.config.ts relies on startTunnel({ port, acceptCloudflareNotice }) and tunnel.getURL(). If that surface changed, the --tunnel dev flow breaks. This is dev-only tooling, so impact is limited, but verify the tunnel still starts after the bump.

Was this helpful? React with 👍 / 👎

@gitar-bot

gitar-bot Bot commented Aug 5, 2026

Copy link
Copy Markdown
Code Review 🚫 Blocked 0 resolved / 2 findings

Updates non-major project dependencies and actions across the workspace. Blocked due to a missing lockfile update for package.json and a pre-1.0 minor version change in untun.

🚨 Bug: package.json bumped but pnpm-lock.yaml not updated

📄 package.json:33-47 📄 package.json:92 📄 pnpm-workspace.yaml:4

package.json (and pnpm-workspace.yaml override) were bumped to new versions, but pnpm-lock.yaml was not updated in this PR — it still pins the old specifiers/versions (e.g. untun specifier ^0.1.3, @prisma/adapter-pg/@prisma/client/prisma 7.8.0, @wolfstar/env-utilities 2.0.2, etc.). The CI step pnpm install --filter . --ignore-scripts runs with pnpm's CI default of --frozen-lockfile, so this mismatch will fail with ERR_PNPM_OUTDATED_LOCKFILE. Regenerate and commit pnpm-lock.yaml (pnpm install --lockfile-only) so the lockfile matches the updated manifests.

💡 Edge Case: untun 0.1.x→0.2.x is a pre-1.0 minor that may break tunnel

📄 package.json:50

untun moves from ^0.1.3 to ^0.2.2; for 0.x packages a minor bump can contain breaking API changes. tsdown.config.ts relies on startTunnel({ port, acceptCloudflareNotice }) and tunnel.getURL(). If that surface changed, the --tunnel dev flow breaks. This is dev-only tooling, so impact is limited, but verify the tunnel still starts after the bump.

🤖 Prompt for agents
Code Review: Updates non-major project dependencies and actions across the workspace. Blocked due to a missing lockfile update for package.json and a pre-1.0 minor version change in untun.

1. 🚨 Bug: package.json bumped but pnpm-lock.yaml not updated
   Files: package.json:33-47, package.json:92, pnpm-workspace.yaml:4

   package.json (and pnpm-workspace.yaml override) were bumped to new versions, but pnpm-lock.yaml was not updated in this PR — it still pins the old specifiers/versions (e.g. `untun` specifier ^0.1.3, `@prisma/adapter-pg`/`@prisma/client`/`prisma` 7.8.0, `@wolfstar/env-utilities` 2.0.2, etc.). The CI step `pnpm install --filter . --ignore-scripts` runs with pnpm's CI default of `--frozen-lockfile`, so this mismatch will fail with `ERR_PNPM_OUTDATED_LOCKFILE`. Regenerate and commit pnpm-lock.yaml (`pnpm install --lockfile-only`) so the lockfile matches the updated manifests.

2. 💡 Edge Case: untun 0.1.x→0.2.x is a pre-1.0 minor that may break tunnel
   Files: package.json:50

   `untun` moves from ^0.1.3 to ^0.2.2; for 0.x packages a minor bump can contain breaking API changes. tsdown.config.ts relies on `startTunnel({ port, acceptCloudflareNotice })` and `tunnel.getURL()`. If that surface changed, the `--tunnel` dev flow breaks. This is dev-only tooling, so impact is limited, but verify the tunnel still starts after the bump.

Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@gitar-bot gitar-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ This PR is blocked due to unresolved code review findings.

Configure merge blocking · Maintainers can dismiss this review.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 6 times, most recently from be44399 to efc0da5 Compare August 13, 2026 16:16
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from efc0da5 to bd2cb9d Compare August 15, 2026 11:47
@socket-security

socket-security Bot commented Aug 15, 2026 •

Copy link
Copy Markdown

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 7 times, most recently from f5820b6 to 48298b1 Compare August 21, 2026 18:11
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from 19514b2 to 22dcb2a Compare August 27, 2026 22:51
@coldtea-pr-lens

coldtea-pr-lens Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

◈ PR Lens

Note

This drawing shows 2ad86a7, and the branch has new commits since. Tick Redraw to draw the latest one

  • Redraw

🟢 +0 new · 🟠 ~0 changed · 🔴 -0 removed · 0 flows · 0 files · commit 2ad86a7


Architecture

Architecture diagram for wolfstar-project/ring at 2ad86a7

0 components touched across 4 lanes.

Open the interactive canvas


Data flow

No data-flow sequence changed in this PR.


View

  • Architecture lens
  • Data flow lens
  • Expand every detail

Tip

Switch GitHub to dark mode and the diagrams follow. The moving dots are this pull request's data in motion.

🪧 More tips
  • Run npx skills add coldteadotai/pr-lens, then tell your coding agent: "Diagram the change you just made with PR Lens and attach it to the pull request."
  • Run npx @coldtea/pr-lens-cli analyze --base origin/main on a branch, then npx @coldtea/pr-lens-cli render .pr-lens/graph.json. Same lenses, your own model key, before the pull request exists.
  • Untick Architecture lens or Data flow lens under View to hide a diagram, or tick Expand every detail to open every section. The comment redraws in a few seconds.
  • Click the link under each diagram to open it on a canvas you can zoom, pan and step through.
  • The diagrams are links. Click one to open it on the canvas, then press W or click play to walk through the change.
  • Open a diagram on the canvas, then press W or click play to walk through the change one step at a time.
  • The CLI's render reads .github/pr-lens.yml and applies your renames, exclusions and lane pins at draw time.
  • Set github.comment.collapsed: true in .github/pr-lens.yml to fold the comment behind one View architecture and data flow row. Drawing still runs on every push.
  • Add .github/workflows/pr-lens.yml with coldteadotai/pr-lens/packages/action@v0 and your model provider's key as its api-key to run PR Lens from your own CI. Any /chat/completions endpoint works.
  • Push a commit and the comment redraws for the new head. A slow older run never overwrites a newer one.

Thanks for using PR Lens! It's built by Coldtea, free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

@socket-security

socket-security Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants