Skip to content

chore(deps): update all non-major dependencies#8

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/all-minor-patch
Open

chore(deps): update all non-major dependencies#8
renovate[bot] wants to merge 1 commit intomainfrom
renovate/all-minor-patch

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jul 22, 2024

This PR contains the following updates:

Package Change Age Confidence
@types/node (source) ^22.16.5^22.19.10 age confidence
pnpm (source) 10.24.010.29.2 age confidence

Release Notes

pnpm/pnpm (pnpm)

v10.29.2

Compare Source

v10.29.1: pnpm 10.29.1

Compare Source

Minor Changes

  • The pnpm dlx / pnpx command now supports the catalog: protocol. Example: pnpm dlx shx@catalog:.
  • Support configuring auditLevel in the pnpm-workspace.yaml file #​10540.
  • Support bare workspace: protocol without version specifier. It is now treated as workspace:* and resolves to the concrete version during publish #​10436.

Patch Changes

  • Fixed pnpm list --json returning incorrect paths when using global virtual store #​10187.

  • Fix pnpm store path and pnpm store status using workspace root for path resolution when storeDir is relative #​10290.

  • Fixed pnpm run -r failing with "No projects matched the filters" when an empty pnpm-workspace.yaml exists #​10497.

  • Fixed a bug where catalogMode: strict would write the literal string "catalog:" to pnpm-workspace.yaml instead of the resolved version specifier when re-adding an existing catalog dependency #​10176.

  • Fixed the documentation URL shown in pnpm completion --help to point to the correct page at https://pnpm.io/completion #​10281.

  • Skip local file: protocol dependencies during pnpm fetch. This fixes an issue where pnpm fetch would fail in Docker builds when local directory dependencies were not available #​10460.

  • Fixed pnpm audit --json to respect the --audit-level setting for both exit code and output filtering #​10540.

  • update tar to version 7.5.7 to fix security issue

    Updating the version of dependency tar to 7.5.7 because the previous one have a security vulnerability reported here: CVE-2026-24842

  • Fix pnpm audit --fix replacing reference overrides (e.g. $foo) with concrete versions #​10325.

  • Fix shamefullyHoist set via updateConfig in .pnpmfile.cjs not being converted to publicHoistPattern #​10271.

  • pnpm help should correctly report if the currently running pnpm CLI is bundled with Node.js #​10561.

  • Add a warning when the current directory contains the PATH delimiter character. On macOS, folder names containing forward slashes (/) appear as colons (:) at the Unix layer. Since colons are PATH separators in POSIX systems, this breaks PATH injection for node_modules/.bin, causing binaries to not be found when running commands like pnpm exec #​10457.

Platinum Sponsors

Bit

Gold Sponsors

Discord CodeRabbit Workleap
Stackblitz Vite

v10.28.2: pnpm 10.28.2

Compare Source

Patch Changes

  • Security fix: prevent path traversal in directories.bin field.

  • When pnpm installs a file: or git: dependency, it now validates that symlinks point within the package directory. Symlinks to paths outside the package root are skipped to prevent local data from being leaked into node_modules.

    This fixes a security issue where a malicious package could create symlinks to sensitive files (e.g., /etc/passwd, ~/.ssh/id_rsa) and have their contents copied when the package is installed.

    Note: This only affects file: and git: dependencies. Registry packages (npm) have symlinks stripped during publish and are not affected.

  • Fixed optional dependencies to request full metadata from the registry to get the libc field, which is required for proper platform compatibility checks #​9950.

Platinum Sponsors

Bit

Gold Sponsors

Discord CodeRabbit Workleap
Stackblitz Vite

v10.28.1

Compare Source

v10.28.0

Compare Source

v10.27.0

Compare Source

v10.26.2: pnpm 10.26.2

Compare Source

Patch Changes

  • Improve error message when a package version exists but does not meet the minimumReleaseAge constraint. The error now clearly states that the version exists and shows a human-readable time since release (e.g., "released 6 hours ago") #​10307.

  • Fix installation of Git dependencies using annotated tags #​10335.

    Previously, pnpm would store the annotated tag object's SHA in the lockfile instead of the actual commit SHA. This caused ERR_PNPM_GIT_CHECKOUT_FAILED errors because the checked-out commit hash didn't match the stored tag object hash.

  • Binaries of runtime engines (Node.js, Deno, Bun) are written to node_modules/.bin before lifecycle scripts (install, postinstall, prepare) are executed #​10244.

  • Try to avoid making network calls with preferOffline #​10334.

Platinum Sponsors

Bit

Gold Sponsors

Discord CodeRabbit Workleap
Stackblitz Vite

v10.26.1: pnpm 10.26.1

Compare Source

Patch Changes

  • Don't fail on pnpm add, when blockExoticSubdeps is set to true #​10324.
  • Always resolve git references to full commits and ensure HEAD points to the commit after checkout #​10310.

Platinum Sponsors

Bit

Gold Sponsors

Discord CodeRabbit Workleap
Stackblitz Vite

v10.26.0

Compare Source

v10.25.0

Compare Source


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, on day 1 of the month ( * 0-3 1 * * ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Jul 22, 2024
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 8a2af8b to 4def863 Compare July 23, 2024 19:20
@renovate renovate bot changed the title chore(deps): update pnpm to v9.6.0 chore(deps): update all non-major dependencies Jul 23, 2024
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 0bdaccd to 66bc994 Compare August 2, 2024 11:12
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from c7bc8b3 to cbe418c Compare August 9, 2024 21:53
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from 4f41b63 to e46a98d Compare August 19, 2024 04:54
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from 14e9295 to b6532c4 Compare August 28, 2024 01:12
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from 740692f to 38e1e99 Compare September 4, 2024 23:05
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 38e1e99 to f8f782b Compare September 9, 2024 14:42
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from 5a8ac55 to 3d2cbb5 Compare September 25, 2024 22:39
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from a47c6a3 to f07e238 Compare October 2, 2024 14:09
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 8e9f331 to 7f60ffa Compare October 8, 2024 01:38
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from 268455f to c139192 Compare October 19, 2024 04:39
@renovate renovate bot changed the title chore(deps): update dependency @types/node to ^22.18.12 chore(deps): update all non-major dependencies Oct 21, 2025
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from b94dab3 to 3bd90a0 Compare November 3, 2025 06:46
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from ba0c938 to 045bf69 Compare November 12, 2025 14:10
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 0c9a170 to 20a391d Compare November 27, 2025 17:00
@renovate renovate bot changed the title chore(deps): update all non-major dependencies chore(deps): update dependency @types/node to ^22.19.1 Dec 7, 2025
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from bfc4025 to 4590f57 Compare December 8, 2025 19:58
@renovate renovate bot changed the title chore(deps): update dependency @types/node to ^22.19.1 chore(deps): update all non-major dependencies Dec 8, 2025
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from c2515fd to 544fa28 Compare December 15, 2025 14:01
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 5a5e934 to 4307eac Compare December 23, 2025 17:13
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 4307eac to 62be408 Compare December 30, 2025 22:32
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from 7e4fd0a to f1ba918 Compare January 15, 2026 18:33
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from f1ba918 to 32ee213 Compare January 19, 2026 13:03
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 32ee213 to 6d6e0c2 Compare January 26, 2026 17:08
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from 771f783 to dbcc824 Compare February 8, 2026 01:57
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from dbcc824 to c467d71 Compare February 9, 2026 06:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants