Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jun 8, 2022

Bumps lerna from 3.22.1 to 5.1.0.

Release notes

Sourced from lerna's releases.

v5.1.0

5.1.0 (2022-06-07)

Bug Fixes

  • utils: orphaned child process on Windows (#3156) (7e69e9e)
  • handle the edge cases in the lerna-nx integration (c6808fc)

Features

  • add experimental support to run tasks via Nx (1c35828)

v5.0.0

5.0.0 (2022-05-24)

Lerna workspaces no longer have dependency deprecation warnings.

Bug Fixes

  • replace read-package-tree with @​npmcli/arborist (#3133) (f1c10a4)
  • resolve most dependency audit issues (#3127) (2b3b191)

BREAKING CHANGES

  • Node v10.x and v12.x are no longer supported.

    • Please upgrade to the latest LTS release of Node (we recommend either v14 or v16).
  • Internally npm lifecycle scripts are now invoked using @npmcli/run-script instead of npm-lifecycle in order to modernize the package and fix package vulnerabilities and deprecations.

    • We are classing this as a breaking change because the APIs of npm-lifecycle and @npmcli/run-script are significantly different, despite @npmcli/run-script being the official successor to npm-lifecycle.

      We have successfully made the integration test suite we inherited pass with this change, but there may potentially be aspects related to it which are not covered by the tests and are breaking. If you encounter any issues you believe are related to this change please open a new issue with a dedicated reproduction for us to look into!

v4.0.0

4.0.0 (2021-02-10)

Notable Changes

  • Node v6.x & v8.x are no longer supported. The minimum supported version is now v10.18.0 (LTS Dubnium).
  • Dependencies updated across the board, should no longer trigger audit warnings.
  • Lots of JSDoc type annotations were added. Maybe they're helpful?

Nothing was newly deprecated, nothing previously deprecated was removed. Migrating to v4 should be straightforward.

Bug Fixes

  • version: Ensure --create-release environment variables are present during initialization (2d0a97a)

... (truncated)

Changelog

Sourced from lerna's changelog.

5.1.0 (2022-06-07)

Note: Version bump only for package lerna

5.1.0-alpha.0 (2022-05-25)

Note: Version bump only for package lerna

5.0.0 (2022-05-24)

Note: Version bump only for package lerna

4.0.0 (2021-02-10)

Features

  • Consume named exports of sibling modules (63499e3)
  • deps: import-local@^3.0.2 (e0e74d4)
  • Drop support for Node v6.x & v8.x (ff4bb4d)

BREAKING CHANGES

  • Node v6.x & v8.x are no longer supported. Please upgrade to the latest LTS release.

Here's the gnarly one-liner I used to make these changes:

npx lerna exec --concurrency 1 --stream -- 'json -I -f package.json -e '"'"'this.engines=this.engines||{};this.engines.node=">= 10.18.0"'"'"

(requires npm i -g json beforehand)

Commits
  • 6b9c375 chore(release): v5.1.0
  • ff27ccb chore(release): v5.1.0-alpha.0
  • f69480e chore(release): v5.0.0
  • 5b2228f fix!: drop support for EOL node versions prior to 14 (#3136)
  • 4582c47 chore(release): v4.0.0
  • 1f17e0c chore(lerna): Set top-level package tag -> next
  • 63499e3 feat: Consume named exports of sibling modules
  • e0e74d4 feat(deps): import-local@^3.0.2
  • 1500d31 chore(dev-deps): Prettier 2
  • ff4bb4d feat: Drop support for Node v6.x & v8.x
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by jameshenry, a new releaser for lerna since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [lerna](https://github.com/lerna/lerna/tree/HEAD/core/lerna) from 3.22.1 to 5.1.0.
- [Release notes](https://github.com/lerna/lerna/releases)
- [Changelog](https://github.com/lerna/lerna/blob/main/core/lerna/CHANGELOG.md)
- [Commits](https://github.com/lerna/lerna/commits/v5.1.0/core/lerna)

---
updated-dependencies:
- dependency-name: lerna
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Jun 8, 2022
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Jun 9, 2022

Superseded by #57.

@dependabot dependabot bot closed this Jun 9, 2022
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/lerna-5.1.0 branch June 9, 2022 14:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants