chore: bump up all non-major dependencies - #26
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 31, 2026 12:53
cc85211 to
c6b269f
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
April 1, 2026 05:04
c6b269f to
5def669
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
April 8, 2026 20:03
5def669 to
9690617
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
April 17, 2026 12:11
9878ccb to
80fe502
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
May 20, 2026 01:36
80fe502 to
9749189
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
June 8, 2026 18:30
289ece2 to
2a064ad
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
3 times, most recently
from
June 18, 2026 11:54
6913039 to
add4919
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
June 23, 2026 19:28
e6f8d11 to
6eac70e
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
July 9, 2026 23:13
2f1a392 to
c5cf4d4
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
5 times, most recently
from
July 18, 2026 20:38
2423129 to
a6ee949
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
3 times, most recently
from
July 23, 2026 19:10
f656b89 to
abd12b1
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
August 3, 2026 19:34
08776e4 to
863ac7c
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
August 10, 2026 12:40
b5ff1ce to
3029db3
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 15, 2026 18:00
3029db3 to
9c3e0a7
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
4 times, most recently
from
August 28, 2026 20:05
cf72e19 to
8fca597
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
September 7, 2026 01:44
f341e31 to
b3dfbde
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
3 times, most recently
from
September 12, 2026 22:07
25ada5d to
3b4072e
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
3 times, most recently
from
September 25, 2026 11:16
a6c2bf6 to
6ea217f
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
3 times, most recently
from
October 3, 2026 21:56
c7462a4 to
00c0983
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
October 6, 2026 10:53
00c0983 to
a894d43
Compare
This branch was previously deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.3.0→v1.6.011.17.0→11.28.5Release Notes
cross-platform-actions/action (cross-platform-actions/action)
v1.6.0: Cross Platform Action 1.6.0Compare Source
Added
Fixed
connectivity (#164).
The image configured its interface with
dhclient, which daemonizes beforethe DHCP exchange finishes, so the boot never waited for the network and the
first step could run while the guest still had no route off its own subnet.
The image now configures the interface statically, from the lease user mode
networking hands out identically on every boot
v1.5.0: Cross Platform Action 1.5.0Compare Source
Changed
268 MiB -- which is most of what a NetBSD job spends on setup
(#151)
longer waits on a readiness probe it sent before the guest was listening
and no resources disk is built to carry one. A custom image supplied through
image_urlstill gets both, since it may expect themAdded
(#165)
variantinput, selecting a named configuration of a platform. Defaults todefault, which boots exactly as before, so no existing workflow changes.See Variants
microvmvariant for NetBSD onx86-64, which reaches a usable guest inroughly half the time. It is opt-in because it changes the hardware the guest
sees: the root disk becomes
ld0rather thansd0, there is no PCI bus toinspect, and
uname -vreports aMICROVMkernel. Asking for it where itcannot be booted is an error, not a slow boot
with how long the VM took to become reachable over SSH
Fixed
(#158).
FreeBSD 13.0 enables 5-level paging whenever the CPU reports it and panics
in the trampoline that switches to it, so every job that landed on an Intel
runner from Ice Lake onwards failed to boot
(#158). Some
of the AMD runners report it without the STIBP and IBRS bits that normally
come with it, which made DragonFly BSD write
IA32_SPEC_CTRLand take ageneral protection fault while booting
Security
previously bound to every interface, making the guest reachable from anything
that could reach the runner
v1.4.0: Cross Platform Action 1.4.0Compare Source
Added
riscv64) (#36)Changed
uefi.fd) asevery other ARM64 guest, instead of a separate Linaro UEFI build. The QEMU
machine type for OpenBSD on ARM64 is now
virt,acpi=off, which makes thekernel fall back to the device tree instead of hanging during ACPI attach.
This removes the dependency on the Linaro release server, which no longer
exists
Fixed
Tearing down VMgroup whenshutdown_vmisfalse, sincethe VM is not being torn down in that case
(#109)
(#158).
Waiting for the VM to become ready is now bounded by an actual wall clock
timeout, instead of by a number of connection attempts, and a single SSH
connection attempt is bounded by
ConnectTimeout.empty, instead of silently printing nothing
(#158)
20 seconds, instead of after 13 minutes. The SSH session that issues the
reboot is bounded by
ServerAliveInterval, so it no longer blocks for thefull TCP retransmission time, and waiting for the VM to come back up is
given up on as soon as the guest announces a kernel panic on its serial
console
x86-64, so which runner a job happens to get no longer decides whether the
VM boots
(#158).
Kernels released before AMX existed fault as soon as userland starts, which
affected NetBSD 9.4 and 10.1 and FreeBSD 12.4 on the runners that have it
pnpm/pnpm (pnpm)
v11.28.5: pnpm 11.28.5Compare Source
This release reads cached registry metadata faster and makes
pnpm config get --globalignore project settings. It also carries several security fixes for package archives, git dependencies, and config dependencies.Patch Changes
Security
pnpm now verifies locked config dependencies against their registry before installing them. Config dependencies must come from an npm registry. The lockfile can no longer replace the integrity of a config dependency pinned with
version+integrity.Lockfile verification now checks the tarballs inside a
variationsresolution against the registry. Aname@versionlockfile entry with an emptyvariationsresolution is now rejected.pnpm audit signaturesnow verifies signatures against the integrity recorded in the lockfile. Packages without a recorded integrity cannot pass signature verification.pnpm now rejects a git dependency whose lockfile repository is empty, begins with
-, or contains a null byte. Git can no longer read such a value as a command-line option pnpm/tasks#84.A git dependency with a
#path:subpath can no longer reach files outside the repository through a symlink in the subpath.pnpm pack,pnpm publish, and installs of git and local directory dependencies now leave out files that a directory symlink or abundleDependenciesentry points to outside the package directory pnpm/tasks#83 pnpm/tasks#93.pnpm deploywithdeployAllFilesnow rejects symlinks that point outside the package directory. Local package installs with this setting apply the same check.pnpm no longer hangs on a package archive with a negative PAX record length or an entry of 4 GiB or more pnpm/tasks#78 pnpm/tasks#79.
Large package downloads and large files inside gzip and bzip2 package archives now use bounded memory during installation. Package manifests and archive metadata larger than 64 MiB are rejected.
pnpm publishalso rejects manifests and README files larger than 64 MiB in pre-built tarballs before reading them into memory.Two URL or local path dependencies no longer share a virtual store directory when one URL has
+,#,:, or?where the other has/. Such dependencies, including git dependencies pinned with#, now get a hash suffix on their directory name.pnpm licensesnow removes terminal control characters from package metadata in table output.The warnings about ignored project
.npmrcregistry and auth settings no longer print the username and password of a URL-scoped key such as//user:password@registry.example.com/:_authToken.Installing and resolving dependencies
Dependency resolution reads cached registry metadata faster. The metadata cache moved to
<cache-dir>/v12/, so the first install after upgrading downloads registry metadata again. A damaged cache entry is downloaded again, or reported as an error when--offlineis set #13512.pnpm installnow fails withERR_PNPM_UNSUPPORTED_PROTOCOLwhen a dependency uses a specifier with a protocol pnpm does not support, such as Yarn'spatch:. pnpm linked such a dependency to a directory that does not exist #16590.When a dependency moves an exact dependency of its own to an older version, a peer dependency that pnpm installed automatically now moves with it. Before,
pnpm installandpnpm dedupekept the newer locked version of the peer, so the lockfile held two copies of it, for example two copies ofvuepnpm/tasks#61.pnpm addandpnpm installnow keep the peer dependencies thatpnpm-lock.yamlrecords for a package they did not update. A registry whose metadata disagrees with the package'spackage.json, for example by omittingpeerDependenciesMeta, madepnpm addandpnpm dedupewrite different lockfiles, sopnpm dedupe --checkfailed afterpnpm add#16615.Configuration
pnpm config getandpnpm config listwith--globalor--location=globalnow show only the global configuration. Both flags included the project's.npmrcbefore.--location=globalalso included the project'spnpm-workspace.yaml.pnpm config get --globalfailed when the global bin directory was not in PATH #16598.pnpm now prints config warnings, such as an unset environment variable in
.npmrc, when loading the config fails.pnpm now fails when
httpProxyorhttpsProxyinpnpm-workspace.yamlor the global configuration is not a string.pnpm dlxnow uses thereleaseentry ofnodeDownloadMirrorsfrom the workspace configuration when downloading Node.js runtimes #11281. Mirrors for other channels, such asrcandnightly, still apply only from the global configuration.Commands
pnpm runandpnpm execnow forward--config.*command-line flags to the install started byverifyDepsBeforeRunpnpm/tasks#60.pnpm dlxwith--packagebut no command now fails with'pnpm dlx' requires a command to run. Before, it installed the package and then crashed trying to run an empty command.pnpm unpublish <pkg>@<version>now deletes the tarball under the registry's path when the registry is served under one, such as Gitea's npm registry. It used to send the delete to the host root and report success without removing the version #16568. It also no longer mistakes a sibling path such as/npm-mirror/for the registry path/npm/pnpm/tasks#94.The interactive
pnpm audit --fixpicker now shows each patched version with thesaveExactandsavePrefixstyle that the override is written with #13209.pnpm listnow reports the correct package paths whennodeLinkerishoisted#9593.pnpm setupnow puts$PNPM_HOME/binfirst onPATHin login shells that inherited it further down, such as the VS Code terminal on macOS. Before, anothernodetook precedence over the one installed bypnpm runtime set node -g. Runpnpm setupagain to update the block in your shell config #16635.pnpm setupnow names the shell config file even if it is already up to date #16608.Output and messages
A warning about a project's
devEnginesorpackageManagerpin is now printed to stderr. A command such aspnpm cache pathorpnpm list --jsonkeeps only its own output on stdout #16584.The warning for a non-root
resolutionsfield now points at theoverridesfield inpnpm-workspace.yaml#11757.Platinum Sponsors
Gold Sponsors
v11.28.4: pnpm 11.28.4Compare Source
pnpm 11.28.4 fixes two ways credentials could leak, makes
pnpm install --frozen-lockfileaccept several lockfiles it rejected, warns when an optional dependency cannot be fetched, and stopspnpm self-updatefrom installing a second pnpm next to a Homebrew one.Patch Changes
pnpm loginno longer forwards credentials in its request body to another origin during redirects.The error for a tarball that fails its integrity check no longer prints credentials, query strings, or fragments from the tarball URL.
Installing packages
pnpm install --frozen-lockfilenow succeeds in a project with no dependencies whenpnpm-lock.yamlrecords only the pinned pnpm version. Other commands write such a lockfile when they run before the first install. A lockfile missing the---line after that section is accepted too #16477.pnpm install --frozen-lockfileagain succeeds when a workspace project recorded inpnpm-lock.yamlhas no directory, such as a project left out of a Docker build context. It still fails if the project's directory exists without apackage.json#16453.pnpm install --frozen-lockfileno longer fails withERR_PNPM_OUTDATED_LOCKFILEfor a workspace project that declaresdependenciesMetaand whose dependencies are all workspace links. pnpm now records that project'sdependenciesMetainpnpm-lock.yaml#16457.Fixed frozen installs replacing a hoisted dependency with a workspace package of the same name. A later
pnpm dedupethen removed the hoisted link #16485.With
enableGlobalVirtualStoreon, scripts can run entry points that a CommonJS require hook loads again, such asts-node index.ts. They failed withERR_UNKNOWN_FILE_EXTENSIONon Node.js versions without built-in TypeScript support #16436.Optional dependencies
pnpm installnow prints a warning with the error when an optional dependency cannot be fetched and is skipped. The skipped package is no longer linked intonode_modulesas a broken symlink or listed among the added dependencies. Thepnpm:skipped-optional-dependencylog reports the skip with thefetch_failurereason #16514.When an optional dependency fails to build, pnpm now removes its link from
node_modules. A repeatpnpm installthen reports "Already up to date" and no longer reruns the failing build #16468.Fixed frozen installs creating symlinks to the working directory for skipped optional dependencies and unresolved peer dependencies #16454.
Hoisted node_modules
With
nodeLinker: hoisted, a filtered install now keeps the packages of the workspace projects an earlier install put innode_modules. This also covers the install thatpnpm --filter <selector> runandpnpm --filter <selector> execstart before the command. Before, these installs removed every package that only the unselected projects needed #16483.A filtered install of a workspace project also no longer fails with
ERR_PNPM_LOCKFILE_MISSING_DEPENDENCYafter a filtered install of another project.pnpm installwithnodeLinker: hoistednow refreshes directories supplied by custom fetchers when reinstalling.Speed and network
pnpm now revalidates cached registry metadata with a conditional request, so the registry can answer
304 Not Modified. Before, pnpm downloaded the whole document again for registries whose responses forbid caching, such asCache-Control: no-store#16528, and for packages published withinminimumReleaseAge#16506.A fetch timeout while other downloads from the same host are still running now lowers concurrency for that host to one connection. Retries of that request, and later downloads from that host, use the lower concurrency. Other hosts keep the configured concurrency #12791.
Running scripts
Scripts run without a terminal no longer start a second
sheach. One watchdog per pnpm command now ends every script's process group if pnpm is killed, sopnpm -r runacross many projects starts half as many processes #16489.pnpm runandpnpm execnow warn and run the command when the install thatverifyDepsBeforeRunstarts fails. This lets scripts run in sandboxes where pnpm cannot install, such as containers with a read-only store or no network #15173.A filtered
pnpm runorpnpm execnow finds dependencies out of date when a workspace dependency of a selected project has nonode_modulesdirectory, as after a filtered install. WithverifyDepsBeforeRun: install, pnpm installs that dependency before running the command pnpm/tasks#45.pnpm rebuildandpnpm approve-buildsrefresh command launchers when a build changes a command's interpreter or replaces it with a native executable. Dependent packages' build scripts use the refreshed launchers.Updating pnpm
pnpm self-updatenow fails for Homebrew-installed pnpm and prints thebrew upgradecommand for the installed formula, such asbrew upgrade pnpmorbrew upgrade pnpm@11. It used to install a second copy of pnpm that the Homebrew one kept shadowing #16547.On Windows,
pnpm self-updatenow replaces apnpm.exeleft inPNPM_HOMEor inPNPM_HOME\bin. InPNPM_HOME, that executable kept running the old version after a successful update. InPNPM_HOME\bin, the update failed withEPERM. If the executable was inPNPM_HOME,self-updatenow asks you to runpnpm setup#9094.pnpm can now switch to a
packageManagerversion below 11 on x64 musl Linux, such as Alpine #16467.A
devEngines.packageManagerrange now records the running pnpm inpnpm-lock.yamlonly if it meetsminimumReleaseAge. Otherwise pnpm records the newest version in the range that meets it. If no version in the range does, pnpm still records the running pnpm #16431.Filtering, settings, and other commands
The
[<since>]filter selector works again with Git 2.24 through 2.27 #16561. With Git older than 2.24, the selector now fails with an error that names the required Git version.Package-name filters now support
?to match one character #2817.pnpm -r pkg getnow reports every selected project when several share a package name. Projects with the same name are keyed by their directory relative to the workspace root. Before, only one of them appeared in the output.pnpm now reports an
INVALID_SETTINGerror whenallowUnusedPatchesinpnpm-workspace.yamlis not a boolean, or whenignoredOptionalDependenciesorrequiredScriptsis not an array of strings. A quotedallowUnusedPatchesvalue such as"false"was treated astrue.pnpm store path,pnpm store status, and other commands that look up the default store no longer fail when the current directory is not writable. pnpm now uses the store in the pnpm home directory in that case #16554.Platinum Sponsors
Gold Sponsors
v11.28.3: pnpm 11.28.3Compare Source
pnpm 11.28.3 updates
undicito clear a security advisory, fixes "database disk image is malformed" errors when several pnpm processes share a store, and makes packages, catalogs, projects, and commands named likeconstructorwork.Patch Changes
Installing packages
pnpm now ships
undici7.29.1, so security scans of pnpm no longer report GHSA-3wwx-pv8p-q78v.pnpm no longer fails with "database disk image is malformed" or reads stale store entries while another pnpm process writes to the same store.
Names that match built-in JavaScript object properties, such as
constructor,toString, or__proto__, now work like any other name. pnpm crashed, wrote a wrong lockfile, or silently skipped such names in:pnpm add,pnpm install, andpnpm import, for dependencies, peer dependencies, andfile:dependencies that point to a directory namedconstructor.toStringwas not written.$toString.pnpm list, andpnpm why.pnpm constructorruns theconstructorscript like any other unknown command, andpnpm help constructorno longer crashes.constructor.pnpm installno longer re-resolves an up-to-date lockfile on every run when a patched package is a peer in a peer cycle #16418.POSIX bin shims and the
pnpm,pn,pnpx, andpnxlaunchers now run inside a Nix build, where the system default path holds none of the utilities they call. Installing again replaces the shims already innode_modules#16377.In a project that pins another pnpm version, pnpm now passes a command with an option it does not know to the pinned version. Before,
pnpm install --auto-dedupefailed with "Unknown option" even though the pinned pnpm supports it #16353.pnpm now fails with
ERR_PNPM_INVALID_ALLOW_BUILDSwhenallowBuildsis not an object or one of its values is nottrue,false, or a string. Such values used to be ignored silently.Removing a dependency whose bins are declared through
directories.binno longer leaves broken shims innode_modules/.bin.A custom resolver's
shouldRefreshResolutionhook that rejects no longer crashes pnpm with an unhandled rejection when another hook has already asked for a refresh.Updating dependencies
When
minimumReleaseAgehides the version thatlatestpoints to, pnpm now falls back to a prerelease of the same major before a stable version of an older major. A stable version of the same major is still preferred. For example, while a new1.0.0is too new, pnpm picks1.0.0-beta.4rather than an old0.0.1#16388.pnpm --filter <project> update <pkg>now fails withERR_PNPM_NO_PACKAGE_IN_DEPENDENCIESwhen the selected projects do not depend on<pkg>, also in a workspace with a shared lockfile and a root project. It used to exit successfully.pnpm audit --fixnow updates vulnerable packages in a single project that setsupdateConfig.ignoreDependencies. It used to leave them on the vulnerable version.pnpm update --globalnow removes hard-linked executables fromPNPM_HOMEwhen migrating packages from the old global layout #16420.Updating a pinned GitHub Action now rewrites the version in its
# vX.Y.Zcomment even when the action name contains the same version text. The action name used to change while the comment kept the old version.Workspaces and deploy
pnpm deployno longer fails withERR_PNPM_DEPLOY_AMBIGUOUS_PEERin a workspace withinjectWorkspacePackages: truewhen a workspace package also lists its peer dependency as a dev dependency #16375.pnpm deployno longer copies the workspace root'spackageManageranddevEngines.packageManagerfields into the deployedpackage.json#16403.--filterfixes:...pkg...selector combined with another dependents selector, such as--filter ...a --filter ...b..., no longer adds the dependencies of the other selector's dependents.--filter "[<since>]"now detects changes in projects whose directory names contain non-ASCII characters. The change used to be credited to the parent project.Running scripts
After relaying a signal to a script, pnpm keeps waiting for a process in the script's process group whose main thread has exited while its other threads still run. Linux reports such a process as a zombie, so the wait used to end before those threads finished pnpm/tasks#56.
A lifecycle script run with
unsafePerm: falsenow fails with an error when pnpm cannot createnode_modules/.tmp. It used to hang.pnpm runwithverifyDepsBeforeRunno longer crashes with an unhandled rejection when a lockfile it did not need to compare fails to load.pnpm run -rnow closes the collapsible CI log section of a project whose script fails, so the output of later projects is no longer nested inside it.pnpm run --resume-fromno longer crashes when a saved run state file containsnull.Store
pnpm store prunenow removes the packages that only expiredpnpm dlxcache entries used, as long as the store still has another registered project. They used to stay until the nextpnpm store prune#16383.pnpm store prunenow stops with an error when it cannot read a project directory for a reason other than the directory missing, such as a permission error. It used to skip the directory.Publishing and registry output
pnpm publishnow includes bareREADMEfiles and README files with Markdown extensions such asreadme.markdownin registry metadata #12704.pnpm pack-appnow accepts an entry file or output directory inside the project whose name starts with two dots, such as..build/entry.cjs. It used to fail withERR_PNPM_PACK_APP_ENTRY_OUTSIDE_PROJECT.Registry error messages now always say "(response body truncated)" when pnpm cut the response body short. The marker was missing when the body was cut at exactly 64 KiB.
Platinum Sponsors
Gold Sponsors
v11.28.2: pnpm 11.28.2Compare Source
pnpm 11.28.2 fixes
pnpm installskipping every workspace project whose common ancestor is the filesystem root, and stopspnpm runfrom reinstalling or installing when nothing needs it.Patch Changes
pnpm installreported success without installing anything when the workspace projects' common ancestor was the filesystem root, such as/or a drive root likeC:\. It now installs these projects #16328.verifyDepsBeforeRunno longer reports dependencies as outdated after a filtered install just becausepnpm-lock.yamlhas a newer modification time. It checks the lockfile against the packages that install put in place. Before,pnpm runreinstalled the whole workspace with lifecycle scripts on, for example after a DockerCOPYbrought in a lockfile with a newer mtime #16322.After a filtered install,
verifyDepsBeforeRunnow also checks that the install put the selected projects' dependencies in place. Anode_modulesdirectory alone no longer counts as proof.pnpm runandpnpm execno longer install a project that has never been installed and has nothing to install. Such a project declares no dependencies, no peer dependencies thatautoInstallPeerswould fetch, and no install lifecycle scripts. The command now runs without writingnode_modulesorpnpm-lock.yaml#16313.Platinum Sponsors
Gold Sponsors
v11.28.1: pnpm 11.28.1Compare Source
pnpm 11.28.1 makes
pnpm installwork in StackBlitz WebContainers, repairs lockfiles whose patch hashes disagree withpatchedDependencies, and fixes many bugs in Windows command shims, injected workspace dependencies, andpnpm deploy.Patch Changes
Installing packages
pnpm installnow works in StackBlitz WebContainers. On projects without a lockfile, it used to fail withENOENT ... pnpm-lock.yaml, because pnpm did not recognize the errors that WebContainers return from asynchronous file system calls. It also failed with "this.db.exec is not a function", becausenode:sqlitethere lacksDatabaseSync.exec. Whennode:sqlitecannot prepare statements either, pnpm stores the index inindex.fallback#15649.pnpm installnow completes after downloading a Node.js runtime specified bydevEngines.runtimewhen pnpm runs on Node.js 24.4.x #14667.pnpm installno longer fails when a package from the registry declares afile:dependency on a directory inside itself, such as"@types/css-tree": "file:./typings/css-tree". pnpm links that dependency to the directory inside the package, as npm and Yarn do. The lockfile records it aslink:<root>/typings/css-tree#9141.Installing a git-hosted dependency that has to be built no longer fails when that dependency's own dependencies have build scripts nobody approved. pnpm skips those builds while preparing the dependency, as it does without
strictDepBuilds#9764.pnpm now uses pnpm to prepare a git-hosted dependency that is a pnpm workspace without a committed lockfile. It used npm before, which could skip the dependency's build #14011.
When installing a git dependency over SSH fails with
Permission denied (publickey), pnpm suggests checking the loaded keys withssh-add -l. Resolving an SSH URL that refuses the key also shows a local HTTPS rewriteConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.