Repository navigation
Update all non-major dependencies - #21
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 2, 2026 17:22
b597811 to
87964bb
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
September 4, 2026 19:15
991f462 to
d2c1334
Compare
Contributor
Author
|
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
4 times, most recently
from
September 12, 2026 18:25
571d495 to
039b0b2
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
6 times, most recently
from
September 21, 2026 22:04
19fab58 to
ab9d917
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
3 times, most recently
from
September 28, 2026 23:49
dc23a82 to
09e03fd
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
5 times, most recently
from
October 7, 2026 01:29
2f2637f to
46c03c7
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
October 9, 2026 11:00
46c03c7 to
0182142
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^3.1117.0→^3.1124.03.1149.0(+1)^10.4.1→^10.4.1^16.3.2→^16.3.2^24.0.0→^24.19.124.19.2^19.2.18→^19.3.0^19.1.6→^19.3.0^30.0.1→^30.0.111.24.0→11.28.5^0.3.24→^0.3.24^19.2.8→^19.3.01.20.0→1.21.11.22.1(+1)^19.2.8→^19.3.00.3.0→0.3.30.3.0→0.3.3v1.18.0→v1.21.1Release Notes
aws/aws-sdk-js-v3 (@aws-sdk/client-s3)
v3.1147.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1146.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1145.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1144.0Compare Source
Features
v3.1143.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1142.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1141.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1140.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1139.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1138.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1137.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1136.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1135.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1134.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1133.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1132.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1131.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1130.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1129.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1128.0Compare Source
Features
v3.1127.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1126.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1125.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
testing-library/dom-testing-library (@testing-library/dom)
v10.4.2Compare Source
Bug Fixes
testing-library/react-testing-library (@testing-library/react)
v16.3.3Compare Source
Bug Fixes
jsdom/jsdom (jsdom)
v30.1.2Compare Source
initialreset. (@scttcper)getComputedStyle()returning stale results after editing stylesheet declarations, selectors, or media queries, including in imported stylesheets.:focus,:focus-visible,:focus-within, and selectors containing them after focus changes, including inside focus and blur listeners. (@asamuzaK)element.focus()incorrectly focusing elements hidden by 'display', including through shadow hosts and slots, and elements excluded by shadow DOM slot assignment. (@asamuzaK)getComputedStyle()throwing for elements without inline-style support, including XML and MathML elements.window.close().MutationObserverinstances retaining bookkeeping for garbage-collected nodes. (@scttcper)select.selectedOptionscollections becoming stale after selection changes and form resets.color-mix()expressions, including exceptions during color resolution. (@asamuzaK)v30.1.1Compare Source
blurandfocusoutevents and incorrectevent.relatedTargetvalues when focusing an element after removing the previously focused element, which regressed in v30.1.0. (@asamuzaK)document.documentElement.focus(). (@asamuzaK)blurlisteners becoming active, and text selections made by focus and blur listeners being overwritten. (@asamuzaK)element.focus()incorrectly focusing disabled form controls and<input type="hidden">elements withtabindex="". (@scttcper)style.setProperty()calls changing existing!importantpriorities, serialized styles, or mutation records. (@FedgeNo)!importanthandling when updating CSS longhands after shorthands, using variables or CSS-wide keywords, and assigning style properties directly. (@FedgeNo)<noscript>parsing withincludeNodeLocations: trueor inside frames to honor therunScriptsoption.storageQuotaoption being ignored by frames.charsetparameters in<meta>elements, and encoding detection incorrectly using incomplete<meta>tags. (@FedgeNo)constructor,toString,__proto__, or"null", and incorrect reuse of namespace prefixes declared on sibling elements.element.innerHTMLandelement.outerHTMLin XML documents to reject invalid characters in attribute values and avoid stack overflows on large strings.:lang(),:nth-child(... of ...)after mutations, and:has()with duplicate IDs or nested logical pseudo-classes. (@asamuzaK)v30.1.0Compare Source
jsdom is feeling the AGI!
This release is dedicated to @scttcper, who unleashed @codex upon jsdom and found tons of performance improvements. Along the way, he found and fixed many correctness issues as well.
We really appreciate his thoughtful PRs, which did a great job following the project's contribution guidelines, and were clearly human-curated, with their PR descriptions edited to be brief and respectful of the maintainers' time.
Thanks to @scttcper, as well as all the other contributors of this release (most of whom were AI-assisted).
document, such asdocument.myFormfor<form name="myForm">. (@vojtisprime11)QuotaExceededError, including its use for storage quota errors and oversizedcrypto.getRandomValues()requests.getComputedStyle(), style changes, and CSS serialization. (@scttcper, @jhult)<select>elements and radio button groups. (@scttcper)window.close()to preserve access to the document and its DOM through retained references.element.querySelectorAll()returning no matches when the first part of the selector matches the element itself, which regressed in v30.0.0. (@asamuzaK)data-state="",title="", and other case-sensitive values. (@asamuzaK)document.querySelector()failing to find a matching element when an earlier element has the same ID but does not match the rest of the selector. (@vojtisprime11):focusmatching in shadow trees. (@asamuzaK)document.replaceChildren()calls, invalid document element and doctype placements, and mutations duringelement.replaceWith().window.close()or iframe removal, and prevented new scripts, resource loads, timers, and animation frames from starting in destroyed documents. (@scttcper)requestInterceptor()callbacks, and when reusing anXMLHttpRequestafter aborting it.JSDOM.fromURL()potentially hanging when response handling throws and response stream cleanup does not finish.getComputedStyle()anddocument.styleSheetsusing the wrong stylesheet order after inserting or updating<style>elements.getComputedStyle()ignoring nested@importand@mediarules in imported stylesheets, and returning stale results after imports finish loading.getComputedStyle()calls changing case-sensitive background URLs, and inconsistent resolution of border shorthands containing system colors. (@scttcper)16px, which regressed in v30.0.0. (@Alberto-BaseNet)getComputedStyle()to resolve'font-weight'keywords to numeric values. (@tianrking)getComputedStyle()to convert lengths to pixels inside CSS math functions containing percentages, and to resolve percentages in'font-size'math functions. (@soroushm)min()andmax()containing nestedcalc(), which regressed in v30.0.0. (@asamuzaK)'grid-template-columns'values containing both100pxandcalc(). (@rome-xi)'background'and'border'shorthands with adjacent components, such asurl(a.png)no-repeat, including a crash when parsing inline styles. Also fixed handling of invalid shorthand assignments and escaped or unusual characters in CSS declarations. (@asamuzaK)'flex'shorthands, such as35 1 0, and rejection of negative'flex-basis'lengths and percentages. (@asamuzaK)RangeandSelectionhandling of CDATA sections, including boundary offsets and range cloning, extraction, deletion, insertion, and stringification. (@scttcper)text.normalize()incorrectly removing the text node or merging its siblings. (@scttcper)window, and incorrect named access from empty or namespacedid=""andname=""values. (@scttcper)DOMParserordocument.implementation.createHTMLDocument()appearing as named properties onwindowand being retained in memory. (@Iaotle)storageevents being sent to windows created after the storage change, and ensured surviving recipients still receive events when the source document is destroyed.input.listin detached element trees. (@scttcper)attr.ownerDocumentafter setting an attribute node on an element in another document or adopting its element. (@Kjubikstronk)element.getElementsByTagName()calls using the previous document's case-sensitivity rules after adoption between HTML and XML documents. (@Kjubikstronk)element.tagNamereturning stale casing after adoption between HTML and XML documents.<select>selection updates when moving options, and unintended selection resets when moving a whole<select>or changing unrelated descendants.<input>elements to preserveinput.indeterminate.<script>. (@Kjubikstronk)src="", and handling oftype="",for="", andevent="".document.currentScriptduring nested script execution and scripts in shadow trees.window.event, and default passive listener handling for non-node event targets, and event dispatch when user code modifieswindow.constructor.volumechangeandratechangeevents to fire asynchronously. (@christianaurichzm)NodeIteratortraversal when its filter removes nodes.fileReader.readAsText()to honor the blob's MIME type charset when no supported explicit encoding is supplied.input.valueAsNumberassignments for time and local date/time inputs.<textarea>values to use the numerictextarea.colsvalue.document.readyStateto be"complete"for documents created withdocument.implementation.createDocument()anddocument.implementation.createHTMLDocument().element.translatefor emptytranslate=""values and elements without a parent.node.lookupNamespaceURI()for thexmlandxmlnsprefixes. (@vojtisprime11)<base>elements to ignoredata:andjavascript:URLs. (@vojtisprime11)svgElement.viewportElementinside<symbol>elements.blobEvent.timecodeto beNaN.CSS.pnpm/pnpm (pnpm)
v11.28.5: pnpm 11.28.5Compare Source
This release reads cached registry metadata faster and makes
pnpm config get --globalignore project settings. It also carries several security fixes for package archives, git dependencies, and config dependencies.Patch Changes
Security
pnpm now verifies locked config dependencies against their registry before installing them. Config dependencies must come from an npm registry. The lockfile can no longer replace the integrity of a config dependency pinned with
version+integrity.Lockfile verification now checks the tarballs inside a
variationsresolution against the registry. Aname@versionlockfile entry with an emptyvariationsresolution is now rejected.pnpm audit signaturesnow verifies signatures against the integrity recorded in the lockfile. Packages without a recorded integrity cannot pass signature verification.pnpm now rejects a git dependency whose lockfile repository is empty, begins with
-, or contains a null byte. Git can no longer read such a value as a command-line option pnpm/tasks#84.A git dependency with a
#path:subpath can no longer reach files outside the repository through a symlink in the subpath.pnpm pack,pnpm publish, and installs of git and local directory dependencies now leave out files that a directory symlink or abundleDependenciesentry points to outside the package directory pnpm/tasks#83 pnpm/tasks#93.pnpm deploywithdeployAllFilesnow rejects symlinks that point outside the package directory. Local package installs with this setting apply the same check.pnpm no longer hangs on a package archive with a negative PAX record length or an entry of 4 GiB or more pnpm/tasks#78 pnpm/tasks#79.
Large package downloads and large files inside gzip and bzip2 package archives now use bounded memory during installation. Package manifests and archive metadata larger than 64 MiB are rejected.
pnpm publishalso rejects manifests and README files larger than 64 MiB in pre-built tarballs before reading them into memory.Two URL or local path dependencies no longer share a virtual store directory when one URL has
+,#,:, or?where the other has/. Such dependencies, including git dependencies pinned with#, now get a hash suffix on their directory name.pnpm licensesnow removes terminal control characters from package metadata in table output.The warnings about ignored project
.npmrcregistry and auth settings no longer print the username and password of a URL-scoped key such as//user:password@registry.example.com/:_authToken.Installing and resolving dependencies
Dependency resolution reads cached registry metadata faster. The metadata cache moved to
<cache-dir>/v12/, so the first install after upgrading downloads registry metadata again. A damaged cache entry is downloaded again, or reported as an error when--offlineis set #13512.pnpm installnow fails withERR_PNPM_UNSUPPORTED_PROTOCOLwhen a dependency uses a specifier with a protocol pnpm does not support, such as Yarn'spatch:. pnpm linked such a dependency to a directory that does not exist #16590.When a dependency moves an exact dependency of its own to an older version, a peer dependency that pnpm installed automatically now moves with it. Before,
pnpm installandpnpm dedupekept the newer locked version of the peer, so the lockfile held two copies of it, for example two copies ofvuepnpm/tasks#61.pnpm addandpnpm installnow keep the peer dependencies thatpnpm-lock.yamlrecords for a package they did not update. A registry whose metadata disagrees with the package'spackage.json, for example by omittingpeerDependenciesMeta, madepnpm addandpnpm dedupewrite different lockfiles, sopnpm dedupe --checkfailed afterpnpm add#16615.Configuration
pnpm config getandpnpm config listwith--globalor--location=globalnow show only the global configuration. Both flags included the project's.npmrcbefore.--location=globalalso included the project'spnpm-workspace.yaml.pnpm config get --globalfailed when the global bin directory was not in PATH #16598.pnpm now prints config warnings, such as an unset environment variable in
.npmrc, when loading the config fails.pnpm now fails when
httpProxyorhttpsProxyinpnpm-workspace.yamlor the global configuration is not a string.pnpm dlxnow uses thereleaseentry ofnodeDownloadMirrorsfrom the workspace configuration when downloading Node.js runtimes #11281. Mirrors for other channels, such asrcandnightly, still apply only from the global configuration.Commands
pnpm runandpnpm execnow forward--config.*command-line flags to the install started byverifyDepsBeforeRunpnpm/tasks#60.pnpm dlxwith--packagebut no command now fails with'pnpm dlx' requires a command to run. Before, it installed the package and then crashed trying to run an empty command.pnpm unpublish <pkg>@<version>now deletes the tarball under the registry's path when the registry is served under one, such as Gitea's npm registry. It used to send the delete to the host root and report success without removing the version #16568. It also no longer mistakes a sibling path such as/npm-mirror/for the registry path/npm/pnpm/tasks#94.The interactive
pnpm audit --fixpicker now shows each patched version with thesaveExactandsavePrefixstyle that the override is written with #13209.pnpm listnow reports the correct package paths whennodeLinkerishoisted#9593.pnpm setupnow puts$PNPM_HOME/binfirst onPATHin login shells that inherited it further down, such as the VS Code terminal on macOS. Before, anothernodetook precedence over the one installed bypnpm runtime set node -g. Runpnpm setupagain to update the block in your shell config #16635.pnpm setupnow names the shell config file even if it is already up to date #16608.Output and messages
A warning about a project's
devEnginesorpackageManagerpin is now printed to stderr. A command such aspnpm cache pathorpnpm list --jsonkeeps only its own output on stdout #16584.The warning for a non-root
resolutionsfield now points at theoverridesfield inpnpm-workspace.yaml#11757.Platinum Sponsors
Gold Sponsors
v11.28.4: pnpm 11.28.4Compare Source
pnpm 11.28.4 fixes two ways credentials could leak, makes
pnpm install --frozen-lockfileaccept several lockfiles it rejected, warns when an optional dependency cannot be fetched, and stopspnpm self-updatefrom installing a second pnpm next to a Homebrew one.Patch Changes
pnpm loginno longer forwards credentials in its request body to another origin during redirects.The error for a tarball that fails its integrity check no longer prints credentials, query strings, or fragments from the tarball URL.
Installing packages
pnpm install --frozen-lockfilenow succeeds in a project with no dependencies whenpnpm-lock.yamlrecords only the pinned pnpm version. Other commands write such a lockfile when they run before the first install. A lockfile missing the---line after that section is accepted too #16477.pnpm install --frozen-lockfileagain succeeds when a workspace project recorded inpnpm-lock.yamlhas no directory, such as a project left out of a Docker build context. It still fails if the project's directory exists without apackage.json#16453.pnpm install --frozen-lockfileno longer fails withERR_PNPM_OUTDATED_LOCKFILEfor a workspace project that declaresdependenciesMetaand whose dependencies are all workspace links. pnpm now records that project'sdependenciesMetainpnpm-lock.yaml#16457.Fixed frozen installs replacing a hoisted dependency with a workspace package of the same name. A later
pnpm dedupethen removed the hoisted link #16485.With
enableGlobalVirtualStoreon, scripts can run entry points that a CommonJS require hook loads again, such asts-node index.ts. They failed withERR_UNKNOWN_FILE_EXTENSIONon Node.js versions without built-in TypeScript support #16436.Optional dependencies
pnpm installnow prints a warning with the error when an optional dependency cannot be fetched and is skipped. The skipped package is no longer linked intonode_modulesas a broken symlink or listed among the added dependencies. Thepnpm:skipped-optional-dependencylog reports the skip with thefetch_failurereason #16514.When an optional dependency fails to build, pnpm now removes its link from
node_modules. A repeatpnpm installthen reports "Already up to date" and no longer reruns the failing build #16468.Fixed frozen installs creating symlinks to the working directory for skipped optional dependencies and unresolved peer dependencies #16454.
Hoisted node_modules
With
nodeLinker: hoisted, a filtered install now keeps the packages of the workspace projects an earlier install put innode_modules. This also covers the install thatpnpm --filter <selector> runandpnpm --filter <selector> execstart before the command. Before, these installs removed every package that only the unselected projects needed #16483.A filtered install of a workspace project also no longer fails with
ERR_PNPM_LOCKFILE_MISSING_DEPENDENCYafter a filtered install of another project.pnpm installwithnodeLinker: hoistednow refreshes directories supplied by custom fetchers when reinstalling.Speed and network
pnpm now revalidates cached registry metadata with a conditional request, so the registry can answer
304 Not Modified. Before, pnpm downloaded the whole document again for registries whose responses forbid caching, such asCache-Control: no-store#16528, and for packages published withinminimumReleaseAge#16506.A fetch timeout while other downloads from the same host are still running now lowers concurrency for that host to one connection. Retries of that request, and later downloads from that host, use the lower concurrency. Other hosts keep the configured concurrency #12791.
Running scripts
Scripts run without a terminal no longer start a second
sheach. One watchdog per pnpm command now ends every script's process group if pnpm is killed, sopnpm -r runacross many projects starts half as many processes #16489.pnpm runandpnpm execnow warn and run the command when the install thatverifyDepsBeforeRunstarts fails. This lets scripts run in sandboxes where pnpm cannot install, such as containers with a read-only store or no network #15173.A filtered
pnpm runorpnpm execnow finds dependencies out of date when a workspace dependency of a selected project has nonode_modulesdirectory, as after a filtered install. WithverifyDepsBeforeRun: install, pnpm installs that dependency before running the command pnpm/tasks#45.pnpm rebuildandpnpm approve-buildsrefresh command launchers when a build changes a command's interpreter or replaces it with a native executable. Dependent packages' build scripts use the refreshed launchers.Updating pnpm
pnpm self-updatenow fails for Homebrew-installed pnpm and prints thebrew upgradecommand for the installed formula, such asbrew upgrade pnpmorbrew upgrade pnpm@11. It used to install a second copy of pnpm that the Homebrew one kept shadowing #16547.On Windows,
pnpm self-updatenow replaces apnpm.exeleft inPNPM_HOMEor inPNPM_HOME\bin. InPNPM_HOME, that executable kept running the old version after a successful update. InPNPM_HOME\bin, the update failed withEPERM. If the executable was inPNPM_HOME,self-updatenow asks you to runpnpm setup#9094.pnpm can now switch to a
packageManagerversion below 11 on x64 musl Linux, such as Alpine #16467.A
devEngines.packageManagerrange now records the running pnpm inpnpm-lock.yamlonly if it meetsminimumReleaseAge. Otherwise pnpm records the newest version in the range that meets it. If no version in the range does, pnpm still records the running pnpm #16431.Filtering, settings, and other commands
The
[<since>]filter selector works again with Git 2.24 through 2.27 #16561. With Git older than 2.24, the selector now fails with an error that names the required Git version.Package-name filters now support
?to match one character #2817.pnpm -r pkg getnow reports every selected project when several share a package name. Projects with the same name are keyed by their directory relative to the workspace root. Before, only one of them appeared in the output.pnpm now reports an
INVALID_SETTINGerror whenallowUnusedPatchesinpnpm-workspace.yamlis not a boolean, or whenignoredOptionalDependenciesorrequiredScriptsis not an array of strings. A quotedallowUnusedPatchesvalue such as"false"was treated astrue.pnpm store path,pnpm store status, and other commands that look up the default store no longer fail when the current directory is not writable. pnpm now uses the store in the pnpm home directory in that case #16554.Platinum Sponsors
Gold Sponsors
This PR was generated by Mend Renovate. View the repository job log.