Skip to content

fix(deps): update all non-major dependencies - #61

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/all-minor-patch
Sep 16, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@rspack/browser (source) 2.2.2 → 2.2.4 age confidence
@types/react (source) ^19.2.18 → ^19.3.0 age confidence
@types/react-dom (source) ^19.2.7 → ^19.3.0 age confidence
ansis ^4.3.1 → ^4.4.0 age confidence
jszip ^3.10.1 → ^3.10.2 age confidence
lucide-react (source) ^1.40.0 → ^1.46.0 age confidence
pnpm (source) 11.24.0 → 11.26.0 age confidence
react (source) ^19.2.8 → ^19.3.0 age confidence
react-dom (source) ^19.2.8 → ^19.3.0 age confidence
rstack (source) ^0.7.2 → ^0.7.4 age confidence
tailwind-merge (source) ^3.6.0 → ^3.7.0 age confidence

Release Notes

web-infra-dev/rspack (@​rspack/browser)

v2.2.4

Compare Source

Highlights

CSS-only entry bundling

CSS-only entries using native CSS support now emit standalone stylesheets without an unnecessary JavaScript bundle. Standalone runtime chunks are also omitted when no JavaScript entry needs them, making it easier to build CSS assets directly. See #​14879.

Ignore magic comments in CSS

Native CSS support now recognizes webpackIgnore and its rspackIgnore alias for @import, url(), and image-set() dependencies. This lets you leave selected references for the browser to load instead of resolving and bundling them. See #​15314.

Reliable persistent caching for child compilers

With experiments.newCache, parent and child compilers now coordinate access to shared persistent cache storage while keeping their entries separate. This prevents conflicting writes and cleanup from losing cached data, and allows both parent and child modules to be restored across compiler restarts. See #​15616.

What's Changed

New Features 🎉
Performance 🚀
Bug Fixes 🐞
Refactor 🔨
Document 📖
Other Changes

New Contributors

Full Changelog: web-infra-dev/rspack@v2.2.3...v2.2.4

v2.2.3

Compare Source

Highlights

CSS Import and Asset URL Externals

Rspack now supports asset, asset-url, and css-import external types, allowing CSS to reference stylesheets and assets hosted elsewhere. External @import statements preserve layer, supports, and media conditions, so conditional styles stay conditional in the emitted CSS. #​15431, #​15522.

More Flexible and Reliable Native Watching

With experiments.nativeWatcher enabled, watchOptions.ignored now accepts a function, making it easier to reuse existing ignore rules when switching to the native watcher. File event processing has also been improved to reduce event loss during large bursts of changes on Linux. #​15254.

Lower Resolution Overhead for TypeScript Projects

Relative imports such as ./utils and ../shared no longer trigger unnecessary tsconfig loading or tracking of its project-reference tree. This reduces configuration reads and dependency tracking, especially in large TypeScript projects with many project references. #​15492.

What's Changed

New Features 🎉
Performance 🚀
Bug Fixes 🐞
Refactor 🔨
Document 📖
Other Changes

Full Changelog: web-infra-dev/rspack@v2.2.2...v2.2.3

webdiscus/ansis (ansis)

v4.4.0

Compare Source

  • fix(color-support): treat TERM=dumb as no color before applying COLORTERM, #​49.

    COLORTERM is a color level hint.
    When TERM=dumb, Ansis now disables ANSI color output even if color environment variables such as COLORTERM=truecolor were inherited from a parent process (e.g. in Emacs M-x compile).

    FORCE_COLOR keeps the highest priority and can still explicitly enable colors.

    Auto-detection behavior changes after the fix

    Use case v4.3.1 v4.4.0 Notes
    TERM=dumb ✅ may allow colors * ❌ no color TERM=dumb now has higher priority in autoDetectLevel.
    TERM=dumb + COLORTERM=truecolor ✅ allow colors ❌ no color COLORTERM no longer overrides TERM=dumb.
    TERM=dumb + CI ✅ allow colors ❌ no color CI detection runs after TERM=dumb.
    TERM=dumb + PM2 ✅ may allow colors * ❌ no color PM2 detection runs after TERM=dumb.
    TERM=dumb + Next.js runtime ✅ may allow colors * ❌ no color Next.js detection runs after TERM=dumb.
    COLORTERM without TERM=dumb ✅ allow colors ✅ allow colors Unchanged.
    CI without TERM=dumb ✅ allow colors ✅ allow colors Unchanged.
    PM2 without TERM=dumb ✅ allow colors ✅ allow colors Unchanged.
    Next.js without TERM=dumb ✅ allow colors ✅ allow colors Unchanged.

    * - Depends on additional conditions.

  • test(color-support): add regression coverage for TERM=dumb with inherited COLORTERM=truecolor

    The tests also cover PM2 and Next.js edge behavior where stdout.isTTY is not exposed.

  • test: add a manual color support checker

    Run npm run color-checker to print the environment values used by color detection and visually inspect ANSI 16, ANSI 256, and Truecolor rendering.

  • test(deno): run CI against Deno 2.3+ and the current LTS

    Deno 2.0-2.2 are no longer tested in the CI matrix because they cannot use the same deno.lock v5 format as Deno 2.3+.
    Runtime compatibility with Deno 2.0-2.2 remains supported.

Stuk/jszip (jszip)

v3.10.2

Compare Source

  • Fix cross-realm binary type detection in getTypeOf. Fixes #​759 (see #​578)
  • Add missing types for JSZip.defaults. Fixes #​690 (see #​927)
  • Fix Blob support in Node.js 18 and up. Fixes #​941 (see #​955)
lucide-icons/lucide (lucide-react)

v1.46.0: Version 1.46.0

Compare Source

What's Changed

Full Changelog: lucide-icons/lucide@1.45.0...1.46.0

v1.45.0: Version 1.45.0

Compare Source

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.44.0...1.45.0

v1.44.0: Version 1.44.0

Compare Source

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.43.0...1.44.0

v1.43.0: Version 1.43.0

Compare Source

What's Changed

Full Changelog: lucide-icons/lucide@1.42.0...1.43.0

v1.42.0: Version 1.42.0

Compare Source

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.41.0...1.42.0

v1.41.0: Version 1.41.0

Compare Source

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.40.0...1.41.0

pnpm/pnpm (pnpm)

v11.26.0

Compare Source

v11.25.0: pnpm 11.25

Compare Source

Minor Changes

  • Added an opt-in proof of concept that lets installs reuse a dependency's build output across machines, by publishing and restoring signed, organization-scoped artifacts through pnpr instead of running the lifecycle scripts locally.

    Configure it with the new remoteSideEffectsCache setting. A workspace names the eligible organization and packages; everything describing the act of signing — publish, keyId, builderId, trustedKeys, privateKey and the provenance fields — is refused in pnpm-workspace.yaml and read from the global config file or the environment instead.

  • Added macOS and Windows x64 and arm64 support to remote shared build artifacts pnpm/pnpm#13771.

  • Added the audit.ignorePrune setting. When set to true, pnpm audit --fix removes ignored GHSA entries that no longer appear in the audit report.

  • Generalized the experimental shared-artifact protocol so candidates and signed payloads identify a discriminated subject. Dependency side effects use package and source-integrity subjects, while workspace tasks use project and task subjects.

    This changes shared-artifact request bodies and signed payloads. A pnpr server and its clients have to be on matching versions.

  • pnpm init now pins the latest pnpm version, instead of the version of pnpm that ran the command. A project scaffolded by an outdated pnpm therefore no longer inherits that staleness through its own devEngines.packageManager / packageManager pin #​7490.

    The version is read from the latest tag on the package-manager registries. When that lookup cannot answer — no network, an unreachable or slow registry, offline, or a latest that the minimumReleaseAge / trustPolicy settings reject — pnpm init pins the running version as before, and never fails or hangs on the lookup. A latest that is older than the running pnpm is never pinned either.

  • A scope set in a project's pnpm-workspace.yaml is now ignored, with a warning naming where to set it instead. pnpm login records the scope as a @scope:registry route in the machine-global auth.ini, which outranks ~/.npmrc in every project — so a repository-committed file co

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Asia/Shanghai)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, on day 1 and 15 of the month (* 0-3 1,15 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Deploying rspack-playground with  Cloudflare Pages  Cloudflare Pages

Latest commit: 5c3b4a7
Status: ✅  Deploy successful!
Preview URL: https://41228bef.rspack-playground.pages.dev
Branch Preview URL: https://renovate-all-minor-patch.rspack-playground.pages.dev

View logs

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from aca347b to 5c3b4a7 Compare September 15, 2026 18:43
@renovate
renovate Bot merged commit ad6c432 into main Sep 16, 2026
3 checks passed
@renovate
renovate Bot deleted the renovate/all-minor-patch branch September 16, 2026 01:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants