Skip to content

chore: bump up all non-major dependencies - #26

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Mar 19, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Age Confidence
cross-platform-actions/action action minor v1.3.0 → v1.6.0 age confidence
pnpm (source) packageManager minor 11.17.0 → 11.28.5 age confidence

Release Notes

cross-platform-actions/action (cross-platform-actions/action)

v1.6.0: Cross Platform Action 1.6.0

Compare Source

Added
  • Add support for FreeBSD 14.5 (#​168)
  • Add support for NetBSD 9.5
Fixed
  • DragonFly BSD guests no longer occasionally start a job without working
    connectivity (#​164).
    The image configured its interface with dhclient, which daemonizes before
    the DHCP exchange finishes, so the boot never waited for the network and the
    first step could run while the guest still had no route off its own subnet.
    The image now configures the interface statically, from the lease user mode
    networking hands out identically on every boot

v1.5.0: Cross Platform Action 1.5.0

Compare Source

Changed
  • NetBSD images download around 45% smaller -- 11.0 x86-64 goes from 497 MiB to
    268 MiB -- which is most of what a NetBSD job spends on setup
    (#​151)
  • Every guest becomes usable sooner, by up to 8 seconds, because the action no
    longer waits on a readiness probe it sent before the guest was listening
  • NetBSD guests are logged into without a credential, so no SSH key is generated
    and no resources disk is built to carry one. A custom image supplied through
    image_url still gets both, since it may expect them
Added
  • Add support for Haiku R1/beta6
    (#​165)
  • A variant input, selecting a named configuration of a platform. Defaults to
    default, which boots exactly as before, so no existing workflow changes.
    See Variants
  • The microvm variant for NetBSD on x86-64, which reaches a usable guest in
    roughly half the time. It is opt-in because it changes the hardware the guest
    sees: the root disk becomes ld0 rather than sd0, there is no PCI bus to
    inspect, and uname -v reports a MICROVM kernel. Asking for it where it
    cannot be booted is an error, not a slow boot
  • Log a breakdown of how long each phase of setting up the VM took, together
    with how long the VM took to become reachable over SSH
Fixed
  • 5-level paging (LA57) is no longer exposed to the guests on x86-64
    (#​158).
    FreeBSD 13.0 enables 5-level paging whenever the CPU reports it and panics
    in the trampoline that switches to it, so every job that landed on an Intel
    runner from Ice Lake onwards failed to boot
  • STIBP always-on mode is no longer exposed to the guests on x86-64
    (#​158). Some
    of the AMD runners report it without the STIBP and IBRS bits that normally
    come with it, which made DragonFly BSD write IA32_SPEC_CTRL and take a
    general protection fault while booting
Security
  • The guest's SSH port is only forwarded to the runner's loopback address. It was
    previously bound to every interface, making the guest reachable from anything
    that could reach the runner

v1.4.0: Cross Platform Action 1.4.0

Compare Source

Added
  • Add support for FreeBSD on RISC-V 64 (riscv64) (#​36)
  • Add support for NetBSD on VAX, running on the SIMH simulator
  • Add support for NetBSD 11.0 (#​154)
Changed
  • OpenBSD on ARM64 now boots with the same EDK II UEFI firmware (uefi.fd) as
    every other ARM64 guest, instead of a separate Linaro UEFI build. The QEMU
    machine type for OpenBSD on ARM64 is now virt,acpi=off, which makes the
    kernel fall back to the device tree instead of hanging during ACPI attach.
    This removes the dependency on the Linaro release server, which no longer
    exists
Fixed
  • Don't log the Tearing down VM group when shutdown_vm is false, since
    the VM is not being torn down in that case
    (#​109)
  • The "Start VM" step could keep running for hours when the VM failed to boot
    (#​158).
    Waiting for the VM to become ready is now bounded by an actual wall clock
    timeout, instead of by a number of connection attempts, and a single SSH
    connection attempt is bounded by ConnectTimeout.
  • The post job step now reports when the console log of the VM is missing or
    empty, instead of silently printing nothing
    (#​158)
  • A reboot of a guest that dies instead of rebooting now fails after roughly
    20 seconds, instead of after 13 minutes. The SSH session that issues the
    reboot is bounded by ServerAliveInterval, so it no longer blocks for the
    full TCP retransmission time, and waiting for the VM to come back up is
    given up on as soon as the guest announces a kernel panic on its serial
    console
  • Advanced Matrix Extensions (AMX) is no longer exposed to the guests on
    x86-64, so which runner a job happens to get no longer decides whether the
    VM boots
    (#​158).
    Kernels released before AMX existed fault as soon as userland starts, which
    affected NetBSD 9.4 and 10.1 and FreeBSD 12.4 on the runners that have it
pnpm/pnpm (pnpm)

v11.28.5: pnpm 11.28.5

Compare Source

This release reads cached registry metadata faster and makes pnpm config get --global ignore project settings. It also carries several security fixes for package archives, git dependencies, and config dependencies.

Patch Changes
Security
  • pnpm now verifies locked config dependencies against their registry before installing them. Config dependencies must come from an npm registry. The lockfile can no longer replace the integrity of a config dependency pinned with version+integrity.

  • Lockfile verification now checks the tarballs inside a variations resolution against the registry. A name@version lockfile entry with an empty variations resolution is now rejected.

  • pnpm audit signatures now verifies signatures against the integrity recorded in the lockfile. Packages without a recorded integrity cannot pass signature verification.

  • pnpm now rejects a git dependency whose lockfile repository is empty, begins with -, or contains a null byte. Git can no longer read such a value as a command-line option pnpm/tasks#84.

  • A git dependency with a #path: subpath can no longer reach files outside the repository through a symlink in the subpath.

  • pnpm pack, pnpm publish, and installs of git and local directory dependencies now leave out files that a directory symlink or a bundleDependencies entry points to outside the package directory pnpm/tasks#83 pnpm/tasks#93.

  • pnpm deploy with deployAllFiles now rejects symlinks that point outside the package directory. Local package installs with this setting apply the same check.

  • pnpm no longer hangs on a package archive with a negative PAX record length or an entry of 4 GiB or more pnpm/tasks#78 pnpm/tasks#79.

  • Large package downloads and large files inside gzip and bzip2 package archives now use bounded memory during installation. Package manifests and archive metadata larger than 64 MiB are rejected. pnpm publish also rejects manifests and README files larger than 64 MiB in pre-built tarballs before reading them into memory.

  • Two URL or local path dependencies no longer share a virtual store directory when one URL has +, #, :, or ? where the other has /. Such dependencies, including git dependencies pinned with #, now get a hash suffix on their directory name.

  • pnpm licenses now removes terminal control characters from package metadata in table output.

  • The warnings about ignored project .npmrc registry and auth settings no longer print the username and password of a URL-scoped key such as //user:password@registry.example.com/:_authToken.

Installing and resolving dependencies
  • Dependency resolution reads cached registry metadata faster. The metadata cache moved to <cache-dir>/v12/, so the first install after upgrading downloads registry metadata again. A damaged cache entry is downloaded again, or reported as an error when --offline is set #​13512.

  • pnpm install now fails with ERR_PNPM_UNSUPPORTED_PROTOCOL when a dependency uses a specifier with a protocol pnpm does not support, such as Yarn's patch:. pnpm linked such a dependency to a directory that does not exist #​16590.

  • When a dependency moves an exact dependency of its own to an older version, a peer dependency that pnpm installed automatically now moves with it. Before, pnpm install and pnpm dedupe kept the newer locked version of the peer, so the lockfile held two copies of it, for example two copies of vue pnpm/tasks#61.

  • pnpm add and pnpm install now keep the peer dependencies that pnpm-lock.yaml records for a package they did not update. A registry whose metadata disagrees with the package's package.json, for example by omitting peerDependenciesMeta, made pnpm add and pnpm dedupe write different lockfiles, so pnpm dedupe --check failed after pnpm add #​16615.

Configuration
  • pnpm config get and pnpm config list with --global or --location=global now show only the global configuration. Both flags included the project's .npmrc before. --location=global also included the project's pnpm-workspace.yaml. pnpm config get --global failed when the global bin directory was not in PATH #​16598.

  • pnpm now prints config warnings, such as an unset environment variable in .npmrc, when loading the config fails.

  • pnpm now fails when httpProxy or httpsProxy in pnpm-workspace.yaml or the global configuration is not a string.

  • pnpm dlx now uses the release entry of nodeDownloadMirrors from the workspace configuration when downloading Node.js runtimes #​11281. Mirrors for other channels, such as rc and nightly, still apply only from the global configuration.

Commands
  • pnpm run and pnpm exec now forward --config.* command-line flags to the install started by verifyDepsBeforeRun pnpm/tasks#60.

  • pnpm dlx with --package but no command now fails with 'pnpm dlx' requires a command to run. Before, it installed the package and then crashed trying to run an empty command.

  • pnpm unpublish <pkg>@<version> now deletes the tarball under the registry's path when the registry is served under one, such as Gitea's npm registry. It used to send the delete to the host root and report success without removing the version #​16568. It also no longer mistakes a sibling path such as /npm-mirror/ for the registry path /npm/ pnpm/tasks#94.

  • The interactive pnpm audit --fix picker now shows each patched version with the saveExact and savePrefix style that the override is written with #​13209.

  • pnpm list now reports the correct package paths when nodeLinker is hoisted #​9593.

  • pnpm setup now puts $PNPM_HOME/bin first on PATH in login shells that inherited it further down, such as the VS Code terminal on macOS. Before, another node took precedence over the one installed by pnpm runtime set node -g. Run pnpm setup again to update the block in your shell config #​16635.

  • pnpm setup now names the shell config file even if it is already up to date #​16608.

Output and messages
  • A warning about a project's devEngines or packageManager pin is now printed to stderr. A command such as pnpm cache path or pnpm list --json keeps only its own output on stdout #​16584.

  • The warning for a non-root resolutions field now points at the overrides field in pnpm-workspace.yaml #​11757.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v11.28.4: pnpm 11.28.4

Compare Source

pnpm 11.28.4 fixes two ways credentials could leak, makes pnpm install --frozen-lockfile accept several lockfiles it rejected, warns when an optional dependency cannot be fetched, and stops pnpm self-update from installing a second pnpm next to a Homebrew one.

Patch Changes
  • pnpm login no longer forwards credentials in its request body to another origin during redirects.

  • The error for a tarball that fails its integrity check no longer prints credentials, query strings, or fragments from the tarball URL.

Installing packages
  • pnpm install --frozen-lockfile now succeeds in a project with no dependencies when pnpm-lock.yaml records only the pinned pnpm version. Other commands write such a lockfile when they run before the first install. A lockfile missing the --- line after that section is accepted too #​16477.

  • pnpm install --frozen-lockfile again succeeds when a workspace project recorded in pnpm-lock.yaml has no directory, such as a project left out of a Docker build context. It still fails if the project's directory exists without a package.json #​16453.

  • pnpm install --frozen-lockfile no longer fails with ERR_PNPM_OUTDATED_LOCKFILE for a workspace project that declares dependenciesMeta and whose dependencies are all workspace links. pnpm now records that project's dependenciesMeta in pnpm-lock.yaml #​16457.

  • Fixed frozen installs replacing a hoisted dependency with a workspace package of the same name. A later pnpm dedupe then removed the hoisted link #​16485.

  • With enableGlobalVirtualStore on, scripts can run entry points that a CommonJS require hook loads again, such as ts-node index.ts. They failed with ERR_UNKNOWN_FILE_EXTENSION on Node.js versions without built-in TypeScript support #​16436.

Optional dependencies
  • pnpm install now prints a warning with the error when an optional dependency cannot be fetched and is skipped. The skipped package is no longer linked into node_modules as a broken symlink or listed among the added dependencies. The pnpm:skipped-optional-dependency log reports the skip with the fetch_failure reason #​16514.

  • When an optional dependency fails to build, pnpm now removes its link from node_modules. A repeat pnpm install then reports "Already up to date" and no longer reruns the failing build #​16468.

  • Fixed frozen installs creating symlinks to the working directory for skipped optional dependencies and unresolved peer dependencies #​16454.

Hoisted node_modules
  • With nodeLinker: hoisted, a filtered install now keeps the packages of the workspace projects an earlier install put in node_modules. This also covers the install that pnpm --filter <selector> run and pnpm --filter <selector> exec start before the command. Before, these installs removed every package that only the unselected projects needed #​16483.

    A filtered install of a workspace project also no longer fails with ERR_PNPM_LOCKFILE_MISSING_DEPENDENCY after a filtered install of another project.

  • pnpm install with nodeLinker: hoisted now refreshes directories supplied by custom fetchers when reinstalling.

Speed and network
  • pnpm now revalidates cached registry metadata with a conditional request, so the registry can answer 304 Not Modified. Before, pnpm downloaded the whole document again for registries whose responses forbid caching, such as Cache-Control: no-store #​16528, and for packages published within minimumReleaseAge #​16506.

  • A fetch timeout while other downloads from the same host are still running now lowers concurrency for that host to one connection. Retries of that request, and later downloads from that host, use the lower concurrency. Other hosts keep the configured concurrency #​12791.

Running scripts
  • Scripts run without a terminal no longer start a second sh each. One watchdog per pnpm command now ends every script's process group if pnpm is killed, so pnpm -r run across many projects starts half as many processes #​16489.

  • pnpm run and pnpm exec now warn and run the command when the install that verifyDepsBeforeRun starts fails. This lets scripts run in sandboxes where pnpm cannot install, such as containers with a read-only store or no network #​15173.

  • A filtered pnpm run or pnpm exec now finds dependencies out of date when a workspace dependency of a selected project has no node_modules directory, as after a filtered install. With verifyDepsBeforeRun: install, pnpm installs that dependency before running the command pnpm/tasks#45.

  • pnpm rebuild and pnpm approve-builds refresh command launchers when a build changes a command's interpreter or replaces it with a native executable. Dependent packages' build scripts use the refreshed launchers.

Updating pnpm
  • pnpm self-update now fails for Homebrew-installed pnpm and prints the brew upgrade command for the installed formula, such as brew upgrade pnpm or brew upgrade pnpm@11. It used to install a second copy of pnpm that the Homebrew one kept shadowing #​16547.

  • On Windows, pnpm self-update now replaces a pnpm.exe left in PNPM_HOME or in PNPM_HOME\bin. In PNPM_HOME, that executable kept running the old version after a successful update. In PNPM_HOME\bin, the update failed with EPERM. If the executable was in PNPM_HOME, self-update now asks you to run pnpm setup #​9094.

  • pnpm can now switch to a packageManager version below 11 on x64 musl Linux, such as Alpine #​16467.

  • A devEngines.packageManager range now records the running pnpm in pnpm-lock.yaml only if it meets minimumReleaseAge. Otherwise pnpm records the newest version in the range that meets it. If no version in the range does, pnpm still records the running pnpm #​16431.

Filtering, settings, and other commands
  • The [<since>] filter selector works again with Git 2.24 through 2.27 #​16561. With Git older than 2.24, the selector now fails with an error that names the required Git version.

  • Package-name filters now support ? to match one character #​2817.

  • pnpm -r pkg get now reports every selected project when several share a package name. Projects with the same name are keyed by their directory relative to the workspace root. Before, only one of them appeared in the output.

  • pnpm now reports an INVALID_SETTING error when allowUnusedPatches in pnpm-workspace.yaml is not a boolean, or when ignoredOptionalDependencies or requiredScripts is not an array of strings. A quoted allowUnusedPatches value such as "false" was treated as true.

  • pnpm store path, pnpm store status, and other commands that look up the default store no longer fail when the current directory is not writable. pnpm now uses the store in the pnpm home directory in that case #​16554.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v11.28.3: pnpm 11.28.3

Compare Source

pnpm 11.28.3 updates undici to clear a security advisory, fixes "database disk image is malformed" errors when several pnpm processes share a store, and makes packages, catalogs, projects, and commands named like constructor work.

Patch Changes
Installing packages
  • pnpm now ships undici 7.29.1, so security scans of pnpm no longer report GHSA-3wwx-pv8p-q78v.

  • pnpm no longer fails with "database disk image is malformed" or reads stale store entries while another pnpm process writes to the same store.

  • Names that match built-in JavaScript object properties, such as constructor, toString, or __proto__, now work like any other name. pnpm crashed, wrote a wrong lockfile, or silently skipped such names in:

    • pnpm add, pnpm install, and pnpm import, for dependencies, peer dependencies, and file: dependencies that point to a directory named constructor.
    • Catalog entries and catalog names. Pruning unused entries crashed, and a new catalog named toString was not written.
    • Workspace projects, project directories, and files inside injected packages.
    • Registry prefixes and override version references such as $toString.
    • Hoisting, pnpm list, and pnpm why.
    • Command names. pnpm constructor runs the constructor script like any other unknown command, and pnpm help constructor no longer crashes.
    • Resolving through a pnpr server when a project lives in a directory named constructor.
  • pnpm install no longer re-resolves an up-to-date lockfile on every run when a patched package is a peer in a peer cycle #​16418.

  • POSIX bin shims and the pnpm, pn, pnpx, and pnx launchers now run inside a Nix build, where the system default path holds none of the utilities they call. Installing again replaces the shims already in node_modules #​16377.

  • In a project that pins another pnpm version, pnpm now passes a command with an option it does not know to the pinned version. Before, pnpm install --auto-dedupe failed with "Unknown option" even though the pinned pnpm supports it #​16353.

  • pnpm now fails with ERR_PNPM_INVALID_ALLOW_BUILDS when allowBuilds is not an object or one of its values is not true, false, or a string. Such values used to be ignored silently.

  • Removing a dependency whose bins are declared through directories.bin no longer leaves broken shims in node_modules/.bin.

  • A custom resolver's shouldRefreshResolution hook that rejects no longer crashes pnpm with an unhandled rejection when another hook has already asked for a refresh.

Updating dependencies
  • When minimumReleaseAge hides the version that latest points to, pnpm now falls back to a prerelease of the same major before a stable version of an older major. A stable version of the same major is still preferred. For example, while a new 1.0.0 is too new, pnpm picks 1.0.0-beta.4 rather than an old 0.0.1 #​16388.

  • pnpm --filter <project> update <pkg> now fails with ERR_PNPM_NO_PACKAGE_IN_DEPENDENCIES when the selected projects do not depend on <pkg>, also in a workspace with a shared lockfile and a root project. It used to exit successfully.

  • pnpm audit --fix now updates vulnerable packages in a single project that sets updateConfig.ignoreDependencies. It used to leave them on the vulnerable version.

  • pnpm update --global now removes hard-linked executables from PNPM_HOME when migrating packages from the old global layout #​16420.

  • Updating a pinned GitHub Action now rewrites the version in its # vX.Y.Z comment even when the action name contains the same version text. The action name used to change while the comment kept the old version.

Workspaces and deploy
  • pnpm deploy no longer fails with ERR_PNPM_DEPLOY_AMBIGUOUS_PEER in a workspace with injectWorkspacePackages: true when a workspace package also lists its peer dependency as a dev dependency #​16375.

  • pnpm deploy no longer copies the workspace root's packageManager and devEngines.packageManager fields into the deployed package.json #​16403.

  • --filter fixes:

    • A ...pkg... selector combined with another dependents selector, such as --filter ...a --filter ...b..., no longer adds the dependencies of the other selector's dependents.
    • --filter "[<since>]" now detects changes in projects whose directory names contain non-ASCII characters. The change used to be credited to the parent project.
Running scripts
  • After relaying a signal to a script, pnpm keeps waiting for a process in the script's process group whose main thread has exited while its other threads still run. Linux reports such a process as a zombie, so the wait used to end before those threads finished pnpm/tasks#56.

  • A lifecycle script run with unsafePerm: false now fails with an error when pnpm cannot create node_modules/.tmp. It used to hang.

  • pnpm run with verifyDepsBeforeRun no longer crashes with an unhandled rejection when a lockfile it did not need to compare fails to load.

  • pnpm run -r now closes the collapsible CI log section of a project whose script fails, so the output of later projects is no longer nested inside it.

  • pnpm run --resume-from no longer crashes when a saved run state file contains null.

Store
  • pnpm store prune now removes the packages that only expired pnpm dlx cache entries used, as long as the store still has another registered project. They used to stay until the next pnpm store prune #​16383.

  • pnpm store prune now stops with an error when it cannot read a project directory for a reason other than the directory missing, such as a permission error. It used to skip the directory.

Publishing and registry output
  • pnpm publish now includes bare README files and README files with Markdown extensions such as readme.markdown in registry metadata #​12704.

  • pnpm pack-app now accepts an entry file or output directory inside the project whose name starts with two dots, such as ..build/entry.cjs. It used to fail with ERR_PNPM_PACK_APP_ENTRY_OUTSIDE_PROJECT.

  • Registry error messages now always say "(response body truncated)" when pnpm cut the response body short. The marker was missing when the body was cut at exactly 64 KiB.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v11.28.2: pnpm 11.28.2

Compare Source

pnpm 11.28.2 fixes pnpm install skipping every workspace project whose common ancestor is the filesystem root, and stops pnpm run from reinstalling or installing when nothing needs it.

Patch Changes
  • pnpm install reported success without installing anything when the workspace projects' common ancestor was the filesystem root, such as / or a drive root like C:\. It now installs these projects #​16328.

  • verifyDepsBeforeRun no longer reports dependencies as outdated after a filtered install just because pnpm-lock.yaml has a newer modification time. It checks the lockfile against the packages that install put in place. Before, pnpm run reinstalled the whole workspace with lifecycle scripts on, for example after a Docker COPY brought in a lockfile with a newer mtime #​16322.

    After a filtered install, verifyDepsBeforeRun now also checks that the install put the selected projects' dependencies in place. A node_modules directory alone no longer counts as proof.

  • pnpm run and pnpm exec no longer install a project that has never been installed and has nothing to install. Such a project declares no dependencies, no peer dependencies that autoInstallPeers would fetch, and no install lifecycle scripts. The command now runs without writing node_modules or pnpm-lock.yaml #​16313.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v11.28.1: pnpm 11.28.1

Compare Source

pnpm 11.28.1 makes pnpm install work in StackBlitz WebContainers, repairs lockfiles whose patch hashes disagree with patchedDependencies, and fixes many bugs in Windows command shims, injected workspace dependencies, and pnpm deploy.

Patch Changes
Installing packages
  • pnpm install now works in StackBlitz WebContainers. On projects without a lockfile, it used to fail with ENOENT ... pnpm-lock.yaml, because pnpm did not recognize the errors that WebContainers return from asynchronous file system calls. It also failed with "this.db.exec is not a function", because node:sqlite there lacks DatabaseSync.exec. When node:sqlite cannot prepare statements either, pnpm stores the index in index.fallback #​15649.

  • pnpm install now completes after downloading a Node.js runtime specified by devEngines.runtime when pnpm runs on Node.js 24.4.x #​14667.

  • pnpm install no longer fails when a package from the registry declares a file: dependency on a directory inside itself, such as "@types/css-tree": "file:./typings/css-tree". pnpm links that dependency to the directory inside the package, as npm and Yarn do. The lockfile records it as link:<root>/typings/css-tree #​9141.

  • Installing a git-hosted dependency that has to be built no longer fails when that dependency's own dependencies have build scripts nobody approved. pnpm skips those builds while preparing the dependency, as it does without strictDepBuilds #​9764.

  • pnpm now uses pnpm to prepare a git-hosted dependency that is a pnpm workspace without a committed lockfile. It used npm before, which could skip the dependency's build #​14011.

  • When installing a git dependency over SSH fails with Permission denied (publickey), pnpm suggests checking the loaded keys with ssh-add -l. Resolving an SSH URL that refuses the key also shows a local HTTPS rewrite

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from cc85211 to c6b269f Compare March 31, 2026 12:53
@renovate renovate Bot changed the title chore: bump up Yarn to v4.13.0 chore: bump up all non-major dependencies Mar 31, 2026
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from c6b269f to 5def669 Compare April 1, 2026 05:04
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 5def669 to 9690617 Compare April 8, 2026 20:03
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 9878ccb to 80fe502 Compare April 17, 2026 12:11
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 80fe502 to 9749189 Compare May 20, 2026 01:36
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 289ece2 to 2a064ad Compare June 8, 2026 18:30
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from 6913039 to add4919 Compare June 18, 2026 11:54
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from e6f8d11 to 6eac70e Compare June 23, 2026 19:28
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 2f1a392 to c5cf4d4 Compare July 9, 2026 23:13
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from 2423129 to a6ee949 Compare July 18, 2026 20:38
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from f656b89 to abd12b1 Compare July 23, 2026 19:10
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 08776e4 to 863ac7c Compare August 3, 2026 19:34
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from b5ff1ce to 3029db3 Compare August 10, 2026 12:40
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 3029db3 to 9c3e0a7 Compare August 15, 2026 18:00
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from cf72e19 to 8fca597 Compare August 28, 2026 20:05
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from f341e31 to b3dfbde Compare September 7, 2026 01:44
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from 25ada5d to 3b4072e Compare September 12, 2026 22:07
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from a6c2bf6 to 6ea217f Compare September 25, 2026 11:16
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from c7462a4 to 00c0983 Compare October 3, 2026 21:56
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 00c0983 to a894d43 Compare October 6, 2026 10:53

This branch was previously deployed

1 inactive (outdated) deployment
Release — cc852119 Deployed Mar 19, 2026 by renovate[bot] via Publish #73
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants