Update npm dependencies - #115
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/npm-dependencies
branch
from
September 28, 2026 21:45
f21f56b to
1395d10
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies
branch
from
September 29, 2026 04:06
1395d10 to
3314933
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies
branch
from
September 29, 2026 17:45
3314933 to
4a104c0
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies
branch
from
September 29, 2026 23:22
4a104c0 to
2ccb547
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies
branch
from
October 1, 2026 04:14
2ccb547 to
681442c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.85.0→1.86.05.12.0→5.12.15.20.8→5.23.35.20.8→5.23.35.20.8→5.23.35.20.8→5.23.34.2.1→4.2.217.12.0→17.13.0^0.70.0→^0.71.01.85.0→1.86.07.0.2002→7.0.200312.6.0→12.8.18.70.1→8.71.0Release Notes
oxc-project/eslint-plugin-oxlint (eslint-plugin-oxlint)
v1.86.0Compare Source
What's Changed
import type DummyRulefor vite config by @camc314 in #786Full Changelog: oxc-project/eslint-plugin-oxlint@v1.85.0...v1.86.0
azat-io/eslint-plugin-perfectionist (eslint-plugin-perfectionist)
v5.12.1Compare Source
compare changes
🐞 Bug Fixes
(41b088e)
❤️ Contributors
Rel1cx/eslint-react (eslint-plugin-react-dom)
v5.23.3Compare Source
🐞 Fixes
react-x/immutability: reassigning a binding that resolves to component props or state (value = value + "!",count++, including destructuring andfor...ofrebinding forms) is now reported as a direct mutation, matching upstreamreact-hooks/immutability; rebinding iterator or shallow-copy bindings remains allowed. (#1979)react-x/set-state-in-effect: ref reads traced through intermediate local computations (ex:const dv = visible - prevVisible.current) are now recognized as ref-derived values, and a preceding early-return guard whose test is ref-derived (ex:if (dv === 0) return;) now exempts thesetStatecalls that follow it — previously onlysetStatenested directly inside a ref-gatedif/conditional was exempted. Aligns withreact-hooks7.1.1. (#1979)📝 Documentation
react-x/no-unstable-context-value: documented the React 19<Context>provider detection heuristic and its name-based limitations. (#1979)eslint-plugin-react-x.Full Changelog: Rel1cx/eslint-react@v5.23.2...v5.23.3
v5.23.2Compare Source
🏗️ Internal
nextto16.3.7,fumadocs-coreandfumadocs-uito16.15.16, andeslint-plugin-package-jsonto1.10.1.Full Changelog: Rel1cx/eslint-react@v5.23.1...v5.23.2
v5.23.1Compare Source
🏗️ Internal
react-xrules. (#1977, #1978)react-x/error-boundariesreact-x/globalsreact-x/immutabilityreact-x/purityreact-x/refsreact-x/set-state-in-effectreact-x/set-state-in-renderreact-x/use-memotypescript-eslintto8.71.0,tsl-dxto0.13.7, andpnpmto12.8.1.📝 Documentation
Full Changelog: Rel1cx/eslint-react@v5.23.0...v5.23.1
v5.23.0Compare Source
✨ New
react-x/static-components: dynamic creation-site tracing now follows both sides of logical expressions (ex:const C = DefaultComponent || (() => <div />)) and the last element of sequence expressions (ex:const C = (setup(), () => <div />)), in initializers and reassignments alike. (#1975)🐞 Fixes
react-x/static-components: parameters of nested non-component functions (ex:function render(Comp) { return <Comp /> }) are no longer mistaken for render-created components; definitions are judged by definition type instead of AST node type. (#1975)react-x/static-components:createdHereis now reported once per creation site instead of once per JSX usage; thedefaultdiagnostic remains per usage. (#1975)🏗️ Internal
react-x/static-components: restructured the rule to the fact-based implementation pattern —collect.ts(usage facts),origins.ts(creation-site resolution), andeffects.ts(effect inference) are now separate modules, with reporting centralized inProgram:exit; added 14 boundary test cases covering creation-site resolution, render boundaries, and per-usage reporting. (#1975)lib.tstohelpers.tsin the fact-basedreact-xrules (globals,immutability,refs). (#1976)@effect/language-serviceto0.87.3andoxlintto1.86.0.Full Changelog: Rel1cx/eslint-react@v5.22.1...v5.23.0
v5.22.1Compare Source
🐞 Fixes
react-x/use-state: directly returning theuseStateresult (ex:return React.useState()) is now allowed regardless of the rule's options, matching the exemption in the originalreact/hook-use-staterule. Covers explicit, implicit (arrow function), and type-asserted returns; lazy initialization checks still apply. (#1974, closes #1963)📝 Documentation
eslintbeing an optional peer dependency to the READMEs and the website's getting-started guides.@eslint-react/kitREADME to point to the full documentation.Full Changelog: Rel1cx/eslint-react@v5.22.0...v5.22.1
v5.22.0Compare Source
✨ New
react-dom/no-unknown-property: added React 19.3 properties to the known property allowlist. (#1973)closedbyondialogonFullscreenChange,onFullscreenError(and theirCapturevariants),credentialless, andmaskType— gated on React version>= 19.3.0onLoadonbodyonScrollEnd(and itsCapturevariant)shadowrootmode,shadowrootclonable,shadowrootdelegatesfocus, andshadowrootserializableontemplate🏗️ Internal
fumadocs-coreandfumadocs-uito16.15.15.Full Changelog: Rel1cx/eslint-react@v5.21.3...v5.22.0
v5.21.3Compare Source
🐞 Fixes
react-x/purity: reverted the v5.21.2 exemption for impure calls inuseRefinitializer arguments (ex:useRef(document.createElement("div"))); such calls are reported again. (#1972)Full Changelog: Rel1cx/eslint-react@v5.21.2...v5.21.3
v5.21.2Compare Source
🐞 Fixes
react-x/no-unnecessary-use-prefix: hooks that call other hooks only within nested callbacks, functions named exactlyuse, and hooks defined in test mock module registrations are no longer reported. (#1971)react-x/no-unused-class-component-members: methods invoked by host environments through refs (React Native'sNativeMethods) are no longer reported as unused. (#1971)react-x/purity: async function components in modules without ause clientdirective and impure calls inuseRefinitializer arguments are no longer reported. (#1971)react-x/set-state-in-effect: local variables initialized from nested member expressions rooted at a ref are now recognized as ref-derived values and no longer reported. (#1971)🏗️ Internal
@eslint-react/ast: predefined and exported common node-type helpers in theChecknamespace and migrated call sites to them.📝 Documentation
## Versionssection; a rule's changelog can be viewed directly via theRule Changeloglink under the## Resourcessection of each rule doc.Full Changelog: Rel1cx/eslint-react@v5.21.1...v5.21.2
v5.21.1Compare Source
🐞 Fixes
react-web-api/no-leaked-timeoutreact-web-api/no-leaked-intervalreact-web-api/no-leaked-fetchreact-web-api/no-leaked-resize-observerreact-web-api/no-leaked-intersection-observer🏗️ Internal
react-web-apileaked-resource rules by replacing manual function-context stack tracking withTraverse.findParentancestor lookup, and added boundary tests covering deeply nested callbacks, cross-effect pairing, and wrapped or referenced setup callbacks. (#1969) Affected rules:react-web-api/no-leaked-timeoutreact-web-api/no-leaked-intervalreact-web-api/no-leaked-fetchreact-web-api/no-leaked-event-listenerreact-web-api/no-leaked-resize-observerreact-web-api/no-leaked-intersection-observer@eslint-react/var:isAssignmentTargetEqualno longer short-circuits same-name identifiers through structural equality; identifier pairs are compared with scope-aware value equality. (#1969)react-x/no-unused-class-component-members: removed the manual class and method context stacks; the enclosing class and method are now resolved at the hit point withTraverse.findParentancestor lookup, and the per-class member definition/usage maps are initialized lazily. (#1970)Full Changelog: Rel1cx/eslint-react@v5.21.0...v5.21.1
v5.21.0Compare Source
✨ New
eslintinstallation:eslintis now an optional peer dependency across all published packages, and the rule utilities no longer eagerly load theeslintpackage at import time. (#1965)🏗️ Internal
@eslint-react/core: removed the unusedisAssignmentToThisStatehelper, and simplified thereact-xclass-component rules (no-access-state-in-setstate,no-class-component,no-direct-mutation-state,no-set-state-in-*) accordingly.@eslint-react/eslint: added a localgetConstrainedTypeAtLocationhelper (adapted from@typescript-eslint/type-utils) so consumers don't need to load@typescript-eslint/type-utils, whose entry point eagerly loads theeslintpackage. (#1965)typescript-eslintto8.70.1,fumadocsto16.15.14,fumadocs-mdxto15.4.5,viteto8.3.1, and other dependencies.New Contributors
Full Changelog: Rel1cx/eslint-react@v5.20.8...v5.21.0
SonarSource/SonarJS (eslint-plugin-sonarjs)
v4.2.2Compare Source
sindresorhus/globals (globals)
v17.13.0Compare Source
b007369oxc-project/oxc (oxfmt)
v0.71.0: oxfmt v0.71.0Compare Source
🚀 Features
e0b1f9foxfmt: Bump bundled Prettier version to 3.9.9 (#27002) (leaysgur)342527doxfmt: Bump bundled Prettier version to 3.9.8 (#26999) (leaysgur)🐛 Bug Fixes
eeba1dbformatter: Skip test-call layout when arguments have comments (#27119) (leaysgur)1f7b8adoxfmt: Allow repeated CLI calls in the same process (#27051) (Liang)7bcb807formatter_markdown: Keep blank line between HTML and nested list (#27112) (leaysgur)10b10c5formatter: Keep comments around=on their side and line (#27041) (leaysgur)9aad365formatter: Keep comments deferred before an assignment operator (#26997) (waltu)8fbddb1formatter/jsdoc: More alignment with original plugin (#27039) (leaysgur)50be18eformatter: Keep trailing spaces on normal block comments (#27037) (leaysgur)56d1880formatter: Nestle adjacent block comments (#27036) (leaysgur)3be5d94formatter: Treat/***comments as JSDoc (#27035) (leaysgur)cd45f71formatter: Keep trailing double spaces on JSDoc lines (#26861) (John Costa)fd695f4formatter_markdown: Fix more mismatches found in ecosystem-ci repos (#27003) (leaysgur)4e77d59formatter_markdown: Keep a math span after a kept line break from opening a block (#27001) (leaysgur)584b8b0formatter_markdown: Keep a shape line after a multi-line inline node or link title (#27000) (leaysgur)b939645formatter_markdown: Keep a line break before an inline liquid tag under preserve (#26998) (leaysgur)oxc-project/oxc (oxlint)
v1.86.0Compare Source
🚀 Features
9d80eedlinter/react/only-export-components: SupportallowCompoundComponents(#27117) (Kuroda Kayn)e05b155linter: Add typescript/no-generated-empty-object-type (#26958) (camc314)pnpm/pnpm (pnpm)
v12.8.1: pnpm 12.8.1Compare Source
pnpm 12.8.1 fixes
pnpm install --frozen-lockfilerejecting lockfiles with injected workspace packages that have peers, restores the executable bit on files of local directory dependencies, makespnpm dedupeconverge, and uses less CPU on many-core machines.Patch Changes
pnpm install --frozen-lockfileno longer rejects a freshly generated lockfile when an injected workspace package has peer dependencies #16332.Executable files in a
file:directory dependency or an injected workspace package keep their executable bit again. Since 12.8.0, pnpm installed these files without the permissions they have in their project.pnpm dedupenow reaches a stable lockfile when a package's peer suffix is long enough to be hashed. Before, each run could switch that package's key between the hashed and the spelled-out suffix, sopnpm dedupe --checkalways failed #16331.pnpm install --frozen-lockfile, the default in CI, now uses less CPU on machines with more than 8 cores. Warm installs on many-core Windows machines got up to 10% faster. Frozen installs now link with at most 16 worker threads.verifyDepsBeforeRunno longer reports dependencies as outdated after a filtered install just becausepnpm-lock.yamlhas a newer modification time. It checks the lockfile against the packages that install put in place. Before,pnpm runreinstalled the whole workspace with lifecycle scripts on, for example after a DockerCOPYbrought in a lockfile with a newer mtime #16322.After a filtered install,
verifyDepsBeforeRunnow also checks that the install put the selected projects' dependencies in place. Anode_modulesdirectory alone no longer counts as proof.pnpm runandpnpm execno longer install a project that has never been installed and has nothing to install. Such a project declares no dependencies, no peer dependencies thatautoInstallPeerswould fetch, and no install lifecycle scripts. The command now runs without writingnode_modulesorpnpm-lock.yaml#16313.pnpm update -g --latestnow upgrades globally installed packages beyond their saved version ranges #16320.Platinum Sponsors
Gold Sponsors
v12.8.0: pnpm 12.8Compare Source
pnpm 12.8.0 warns when
pnpm packorpnpm publishwould ship a.envfile thatfilesdoes not list, installssharedWorkspaceLockfile: falseworkspaces concurrently, applies every setting passed as--config.<name>=<value>, and no longer leaves the Windows terminal stuck after Ctrl+C in a script.Minor Changes
pnpm packandpnpm publishnow warn when the tarball includes a.envor.env.*file that thefilesfield ofpackage.jsondoes not list. Templates such as.env.exampleare not reported. List the file infilesto publish it on purpose, or exclude it in.npmignoreor.gitignore#7826.pnpm packnow honors--silent,--reporter=silent, and--loglevel=silentto hide the tarball contents and summary. With--json, lifecycle script output and the final JSON output remain visible #10297.Patch Changes
Installing packages
Installing through a
pnprserver now records the pnpmfile checksum in the lockfile, so a laterpnpm install --frozen-lockfileaccepts that lockfile #14460. A frozen install through the pnpr server now fails if the pnpmfile changed. If the pnpmfile defines areadPackage,afterAllResolvedorpreResolutionhook or custom resolvers, pnpm resolves dependencies locally and prints a warning that the pnpr server was not used.Installing through a
pnprserver also links a workspace project at the directory itspublishConfig.directorynames. A server that does not forward the setting makes the install fail withERR_PNPM_PNPR_PUBLISH_DIRECTORY_MISMATCH, so pnpm never writes a lockfile that points at the wrong directory. The server rejects apublishConfig.directorythat points outside its project.Installing a git-hosted dependency that has to be built no longer fails when that dependency's own dependencies have build scripts nobody approved. pnpm skips those builds while preparing the dependency, as it does without
strictDepBuilds#9764.A git-hosted dependency that is a pnpm workspace with no committed lockfile is now detected as a pnpm project #14011.
pnpm install --devandpnpm fetch --devnow install the optional dependencies of devDependencies, such as the platform binaries of Biome and oxlint. The project's ownoptionalDependenciesare still skipped #9678.pnpm install --offlineandpnpm add --offlinenow resolve a version range to the newest matching version whose tarball is already in the store. They used to pick the newest version in the cached metadata and fail withERR_PNPM_NO_OFFLINE_TARBALLwhen its tarball was missing #10715.If an offline install fails because the registry metadata cache uses the layout from before pnpm 11.27 and 12.4, the error now names the older mirror on disk and explains that one online install repopulates the cache. The error also carries the
ERR_PNPM_NO_OFFLINE_METAcode.pnpm cache prune --helpnow says that pnpm 11.26 and earlier, and pnpm 12.3 and earlier, depend on the directories it removes #15656.Running
pnpm installnow refreshes dependencies when a package declared with a localfile:directory changes its dependencies #4623.A repeat
pnpm installnow keeps its fast up-to-date check when an override replaces a declared localfile:dependency #12892.pnpm installnow removes an optional dependency fromnode_modulesif its install script fails. Code that checks whether the package is installed no longer finds a package that cannot load #8756.With
nodeLinker: hoisted,pnpm installnow restores a workspace project'snode_modulesafter it was deleted. Before, the install printed "Already up to date" and left the project without the dependencies nested under it. On Windows, the install also no longer fails with "Access is denied" when another project's copy of a shared dependency links to the deleted directory.Under
nodeLinker: hoisted,pnpm installnow clears orphaned package directories that an interrupted or failed install leaves in a project'snode_modules. A directory recorded by the previous install is removed, while an unrecorded directory is moved tonode_modules/.ignored. A copy already in.ignoredis never overwritten #13676.Concurrent installs no longer fail when they replace the same stale hoisted dependency link. Virtual store cleanup now keeps the temporary lockfiles that concurrent installs write.
Resolving and linking dependencies
pnpm installno longer aborts on a failed allocation of many gigabytes when peer dependency ranges combine overlapping||alternatives #15867.pnpm installno longer fails when a package from the registry declares afile:dependency on a directory inside itself, such as"@types/css-tree": "file:./typings/css-tree". pnpm links that dependency to the directory inside the package, as npm and Yarn do. The lockfile records it aslink:<root>/typings/css-tree#9141.An
npm:alias written byoverridesnow stays in place when a change elsewhere makes pnpm re-resolve the aliased dependency. Before, pnpm could look up the alias name at the aliased version, which failed withERR_PNPM_NO_MATCHING_VERSIONor locked an unrelated package #16309.A peer dependency no longer resolves to two different versions for one package. This happened when the package peer-depends on another package and on one of that package's peers, and it is installed deeper than a direct dependency of the package that provides them #12098.
An optional peer dependency is no longer resolved from another workspace project's package when the project provides one of that package's own peers at a version it rejects. This avoids bogus unmet peer errors #13989.
pnpm dedupeno longer changes the lockfile on every run when a nested peer dependency is provided through an npm alias #15709.With
resolutionMode: time-basedandminimumReleaseAgeboth set,pnpm installno longer reports a subdependency as too new when only the time-based cutoff excludes it. Such subdependencies used to fail a strict install withERR_PNPM_NO_MATURE_MATCHING_VERSION, or were added tominimumReleaseAgeExclude#13569. A transitive dependency that has no matching version published before the time-based cutoff now resolves to the lowest matching version allowed byminimumReleaseAge. pnpm picks a version younger thanminimumReleaseAgeonly if no older version matches #16298.pnpm installretries registry metadata fetches that fail with a timeout, a dropped connection, or an interrupted response body before it appliestrustPolicyorminimumReleaseAge. A transient fetch failure is not reported asTRUST_DOWNGRADEorMINIMUM_RELEASE_AGE_VIOLATION#12031.pnpm's built-in package compatibility database no longer applies to a project's own manifest. A project named like a published package, such as
vue-loader, no longer gains dependencies onpnpm installorpnpm update. User-configuredpackageExtensionsstill apply to project manifests #11700.Packages in an external
virtualStoreDircan resolve the project's direct dependencies selected byhoistPattern. Runpnpm install --forceto repair an existing installation #5652.pnpm installnow links the executables of auto-installed peer dependencies into the workspace root'snode_modules/.bin, including after a frozen-lockfile reinstall #8511.Lockfiles and frozen installs
pnpm install --frozen-lockfilenow works on a detached HEAD whengitBranchLockfileis enabled. The install reads the lockfiles of the local and remote-tracking branches that contain the checked-out commit. It still writes the sharedpnpm-lock.yaml#7672.pnpm install --frozen-lockfilenow accepts a lockfile that has no importer entry for a workspace package without dependencies. Such a package added after the lockfile was written made the install fail withERR_PNPM_PACKAGE_MANAGER_NO_IMPORTER#15875.pnpm installnow fails withERR_PNPM_LOCKFILE_MISSING_DEPENDENCYwhen an importer references a dependency version that has no snapshot entry. Before, the install succeeded and left anode_modulessymlink pointing at a missing virtual-store directory #14764.pnpm installon CI now fails on an outdated lockfile whenpreferFrozenLockfileis explicitly set totrue. Setting it totrueused to let CI update the lockfile #9072.With
gitBranchLockfileenabled, each emoji or other character outside the Basic Multilingual Plane in a branch name now becomes!!in the lockfile name. Before, each such character became one!.Workspaces and filtering
pnpm installin a workspace withsharedWorkspaceLockfile: falsenow installs projects concurrently, up toworkspaceConcurrencyat a time #14480. A project is resolved, fetched, and written to its virtual store without waiting for the workspace projects it depends on. It waits for them only before it links its dependencies and runs its lifecycle scripts, so its scripts still run after theirs. A project with apreinstallorpnpm:devPreinstallscript, or with an injected orfile:workspace dependency, waits for its workspace dependencies before it starts.The installs of the projects also share their package metadata, lockfile verification, and store caches, so they use less CPU and memory when several projects depend on the same packages. An install with a pnpmfile no longer starts an extra Node.js process when the pnpmfile has no
preResolutionhook.With
enableGlobalVirtualStoreandsharedWorkspaceLockfile: false, each project now keeps its current lockfile and its hidden hoisted dependencies in its ownnode_modules/.pnpm. Before, every project wrote them to the workspace root'snode_modules/.pnpm, so each repeat install treated the other projects' packages as its own and relinked them #14480.pnpm rebuild,pnpm approve-builds, andpnpm ignored-buildsnow work on the current project'snode_moduleswhen they run inside a project of a workspace withsharedWorkspaceLockfile: false. They used to read the workspace root'snode_modules, sopnpm rebuilddid not rebuild the project's dependencies and created a second virtual store at the workspace root #9402.pnpm installno longer creates anode_modulessymlink inside thepublishConfig.directoryof a workspace package linked withlinkDirectory. A build tool that cleaned its output directory through that symlink deleted the files of the package's dependencies.pnpm installalso removes a symlink that an earlier install left there #16226. It also no longer fails withERR_PNPM_CMD_SHIM_RESOLVE_PATHwhen such a package has abinfield and itspublishConfig.directorydoes not exist yet.pnpm installno longer fails for an injected workspace dependency whose package publishes from apublishConfig.directorythat its ownpreparescript builds. The injected copy now picks up that directory oncepreparefinishes building it.pnpm install --frozen-lockfileno longer reports the dependency as outdated while the directory has not been built yet #7811.An in-place edit to the source of an injected workspace package now shows up in its injected copy, unless a build writes to that package or
packageImportMethodis set. pnpm hardlinks such packages under the default import method #4410. Scripts listed insyncInjectedDepsAfterScriptsnow update injected dependencies while they run, so a watcher on the injected package, such as a dev server, sees each change before the script exits.With
sharedWorkspaceLockfile: false, an injected workspace package that has lifecycle scripts is now hard linked into the projects that depend on it. Before, pnpm left a plain copy, so later edits to the package did not reach those projects #9828.injectWorkspacePackagesnow hard links a workspace dependency declared with a relative path, such asworkspace:../foo, the same way it already does forworkspace:*#10446.Workspace discovery prunes dot-prefixed directories, so a
packagespattern such as**no longer matches projects inside.cacheand other hidden directories #16250.pnpm importin a workspace now keeps the versions pinned by ayarn.lockinside a workspace project #4385.Store and caches
Files imported from the store now follow the umask of the install that writes them. Installing with a umask of
077no longer leaves imported files readable by the group and others #3807.pnpm installkeeps the owner, group, and mode of files already in a shared store, includingindex.db. New store files and directories inherit the store directory's group-write bit. When that directory is setgid, new files inherit its group. pnpm does not change a file's owner or group #12765.When
pnpm installrepairs a store file that was modified through a hard link innode_modules, the repair now keeps the file's inode on Linux and macOS, so hard-linked copies in other projects are healed at the same time. On Windows the repair still replaces the file, so other projects are healed on their next install #3445.pnpm installnow reports a full store at once when writing package files fails. It no longer retries the tarball #8581.pnpm now warns when it cannot hard link packages from an existing store in the pnpm home directory and falls back to a store on the project's filesystem. This can happen when the project is on another filesystem, such as a bind-mounted workspace in a container. The warning names both stores and suggests setting
storeDir#14505.The side-effects cache now restores the symlinks that a build script creates inside a package. A warm install used to replace each of them with a copy of its target #12859.
After upgrading, every package with a build script is built once more.
The global virtual store and the side-effects cache now key built packages by the Node.js version that the root project's
devEngines.runtimeorengines.runtimepins. That is the Node.js their build scripts run with. A dependency that declares its ownengines.runtimeno longer changes the key for every other package.With
enableGlobalVirtualStore, an install into a freshnode_modulesno longer runs the build scripts of a dependency whose global virtual store slot an earlier install already built.pnpm rebuildstill runs them #14480.Concurrent installs that share a global virtual store now run a package's build in its shared slot one at a time. A failed build leaves the slot in place and marks it for the next install to rebuild #15568.
A warm
pnpm installreuses on-disk package metadata for five minutes when the registry does not send an ETag. Registries that send an ETag, including the public npm registry, still revalidate with a conditional request.pnpm updatestill fetches current metadata #13976.pnpm no longer revalidates cached registry metadata when the registry sends
Cache-Control: max-age=0,no-cache, orno-store. It downloads the metadata again, so a version newly published to such a registry is visible on the next install #13487.pnpm installhonorsCache-Controlfor dependencies named with anhttp:orhttps:tarball URL. A fresh response is taken from the store with no request, and a stale one is revalidated withIf-None-Match#15648.Patched dependencies
pnpm installnow repairs apnpm-lock.yamlwhose(patch_hash=<hash>)dependency paths disagree with itspatchedDependenciesmap, including paths that lack the hash their patch calls for. Before, pnpm accepted such a lockfile as up to date and kept the old patched files.pnpm install --frozen-lockfilenow fails on such a lockfile withERR_PNPM_INCONSISTENT_PATCH_HASH. It fails withERR_PNPM_UNCHECKABLE_PATCH_HASHwhen a patch hash in the lockfile is malformed, or when the lockfile lacks the package version or patch entry that the check needs #15336.pnpm installwithnodeLinker: hoistednow applies a patch once to each copy of a patched dependency in a workspace. Before, a copy that several workspace projects shared could receive the patch twice and end up with the patched content duplicated #7565.pnpm installandpnpm fetchnow fail withERR_PNPM_PATCH_NOT_FOUNDwhen a patch file listed inpatchedDependenciesdoes not exist #5268.engineStrictnow checks the patchedpackage.jsonwhen apatchedDependenciesentry changesengines. A patch that relaxesengines.nodeno longer fails the install against the published range #9603.pnpm patchnow applies the existing patch file to the edit directory of a git-hosted dependency, as it already does for packages from the registry #9699.Adding, updating, and removing dependencies
pnpm add <dir>now warns when the added directory declares peer dependencies, aspnpm linkdoes. The directory is saved as alink:dependency, and its peers are not resolved from the project that adds it. Use thefile:protocol to have them resolved #5523.pnpm add --save-typesno longer adds a@types/*package whose resolved version is deprecated. DefinitelyTyped publishes such stubs for packages that ship their own types, such as@types/typescriptfortypescript#15636.pnpm version,pnpm add, andpnpm pkg setkeep JSON5 style when they updatepackage.json5. ASCII identifier keys stay unquoted, strings keep JSON5 quotes, and indented files keep trailing commas #15717.Running scripts and commands
pnpm runandpnpm execno longer install dependencies automatically when the rootpackage.jsonstill keepsoverrides,packageExtensions,patchedDependencies, orignoredOptionalDependenciesin itspnpmfield. pnpm no longer reads that field, so the install rewrote the lockfile without those settings. The command now fails and asks to move the settings topnpm-workspace.yaml#16278.When
verifyDepsBeforeRuntriggers an install before a filteredpnpm runorpnpm exec, pnpm now installs only the selected projects and their dependencies. A later filtered command also installs a selected project that an earlier filtered install skipped #11865.`pnpm
Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.