Skip to content

Update all non-major dependencies - #21

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Pending OpenSSF
@aws-sdk/client-s3 (source) devDependencies minor ^3.1117.0 → ^3.1124.0 3.1149.0 (+1) OpenSSF Scorecard
@testing-library/dom devDependencies patch ^10.4.1 → ^10.4.1 OpenSSF Scorecard
@testing-library/react devDependencies patch ^16.3.2 → ^16.3.2 OpenSSF Scorecard
@types/node (source) devDependencies minor ^24.0.0 → ^24.19.1 24.19.2 OpenSSF Scorecard
@types/react (source) devDependencies minor ^19.2.18 → ^19.3.0 OpenSSF Scorecard
@types/react-dom (source) devDependencies minor ^19.1.6 → ^19.3.0 OpenSSF Scorecard
jsdom devDependencies minor ^30.0.1 → ^30.0.1 OpenSSF Scorecard
pnpm (source) packageManager minor 11.24.0 → 11.28.5 OpenSSF Scorecard
publint (source) devDependencies patch ^0.3.24 → ^0.3.24 OpenSSF Scorecard
react (source) devDependencies minor ^19.2.8 → ^19.3.0 OpenSSF Scorecard
react-aria-components dependencies minor 1.20.0 → 1.21.1 1.22.1 (+1) OpenSSF Scorecard
react-dom (source) devDependencies minor ^19.2.8 → ^19.3.0 OpenSSF Scorecard
vite (source) pnpm.catalog.default patch 0.3.0 → 0.3.3 OpenSSF Scorecard
vite-plus (source) pnpm.catalog.default patch 0.3.0 → 0.3.3 OpenSSF Scorecard
voidzero-dev/setup-vp action minor v1.18.0 → v1.21.1 OpenSSF Scorecard

Release Notes

aws/aws-sdk-js-v3 (@​aws-sdk/client-s3)

v3.1147.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1146.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1145.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1144.0

Compare Source

Features
  • client-s3: Amazon S3 adds a new optional S3 Inventory field, IntelligentTieringReferenceDate, reporting the reference date S3 Intelligent-Tiering uses to evaluate an object's tier-transition eligibility. The value is populated for objects in the Intelligent-Tiering storage class and left blank for others. (82bbbdc)

v3.1143.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1142.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1141.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1140.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1139.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1138.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1137.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1136.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1135.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1134.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1133.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1132.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1131.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1130.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1129.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1128.0

Compare Source

Features
  • client-s3: Adds support for Amazon S3 Object Lock variable retention. Existing S3 APIs that support S3 Object Lock parameters now support two new parameters EventHold and EventHoldDuration at the object level, and DefaultEventHoldDuration at the bucket level. (8b58987)

v3.1127.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1126.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1125.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

testing-library/dom-testing-library (@​testing-library/dom)

v10.4.2

Compare Source

Bug Fixes
testing-library/react-testing-library (@​testing-library/react)

v16.3.3

Compare Source

Bug Fixes
jsdom/jsdom (jsdom)

v30.1.2

Compare Source

  • Updated URLs to support Unicode v18.0.0 in internationalized domain names.
  • Reduced package size and memory use for CSS property definitions. (@​scttcper)
  • Fixed severe slowdowns when building large DOM trees, including SVG charts with D3, which regressed in v30.1.0. (@​cmdcolin)
  • Fixed exponentially slow reads of empty inherited CSS custom properties in deeply nested documents, and custom properties incorrectly inheriting past an initial reset. (@​scttcper)
  • Fixed getComputedStyle() returning stale results after editing stylesheet declarations, selectors, or media queries, including in imported stylesheets.
  • Fixed selector matching and computed styles after changes to form control checkedness, indeterminacy, selection, values, and validity, including during form resets and canceled clicks.
  • Fixed computed styles for :focus, :focus-visible, :focus-within, and selectors containing them after focus changes, including inside focus and blur listeners. (@​asamuzaK)
  • Fixed element.focus() incorrectly focusing elements hidden by 'display', including through shadow hosts and slots, and elements excluded by shadow DOM slot assignment. (@​asamuzaK)
  • Fixed getComputedStyle() throwing for elements without inline-style support, including XML and MathML elements.
  • Fixed a memory leak where stylesheet parsing retained the last parsed stylesheet's window after window.close().
  • Fixed memory growth from long-lived MutationObserver instances retaining bookkeeping for garbage-collected nodes. (@​scttcper)
  • Fixed retained select.selectedOptions collections becoming stale after selection changes and form resets.
  • Fixed rejection of negative CSS sizing values, including for 'min-width', 'min-height', 'max-width', and 'max-height', which regressed in v30.1.0.
  • Fixed handling of deeply nested color-mix() expressions, including exceptions during color resolution. (@​asamuzaK)

v30.1.1

Compare Source

  • Fixed spurious window blur and focusout events and incorrect event.relatedTarget values when focusing an element after removing the previously focused element, which regressed in v30.1.0. (@​asamuzaK)
  • Fixed focus and blur behavior across frames, and focusing the document's viewport through document.documentElement.focus(). (@​asamuzaK)
  • Fixed focus targets removed or disabled by blur listeners becoming active, and text selections made by focus and blur listeners being overwritten. (@​asamuzaK)
  • Fixed element.focus() incorrectly focusing disabled form controls and <input type="hidden"> elements with tabindex="". (@​scttcper)
  • Fixed invalid style.setProperty() calls changing existing !important priorities, serialized styles, or mutation records. (@​FedgeNo)
  • Fixed !important handling when updating CSS longhands after shorthands, using variables or CSS-wide keywords, and assigning style properties directly. (@​FedgeNo)
  • Fixed <noscript> parsing with includeNodeLocations: true or inside frames to honor the runScripts option.
  • Fixed the storageQuota option being ignored by frames.
  • Fixed encoding detection of HTML and XML byte input to honor XML encoding declarations and detect UTF-16 without a byte order mark.
  • Fixed exceptions caused by truncated charset parameters in <meta> elements, and encoding detection incorrectly using incomplete <meta> tags. (@​FedgeNo)
  • Fixed XML serialization errors for namespaces named constructor, toString, __proto__, or "null", and incorrect reuse of namespace prefixes declared on sibling elements.
  • Fixed element.innerHTML and element.outerHTML in XML documents to reject invalid characters in attribute values and avoid stack overflows on large strings.
  • Fixed selector matching for :lang(), :nth-child(... of ...) after mutations, and :has() with duplicate IDs or nested logical pseudo-classes. (@​asamuzaK)

v30.1.0

Compare Source

jsdom is feeling the AGI!

This release is dedicated to @​scttcper, who unleashed @​codex upon jsdom and found tons of performance improvements. Along the way, he found and fixed many correctness issues as well.

We really appreciate his thoughtful PRs, which did a great job following the project's contribution guidelines, and were clearly human-curated, with their PR descriptions edited to be brief and respectful of the maintainers' time.

Thanks to @​scttcper, as well as all the other contributors of this release (most of whom were AI-assisted).

  • Added named access to elements on document, such as document.myForm for <form name="myForm">. (@​vojtisprime11)
  • Added QuotaExceededError, including its use for storage quota errors and oversized crypto.getRandomValues() requests.
  • Added support for the relaxed DOM naming rules when creating elements, attributes, and document types.
  • Improved performance of DOM construction, tree mutations, range operations, and live collection access, especially on large documents. (@​scttcper, @​erezrokah)
  • Improved performance of getComputedStyle(), style changes, and CSS serialization. (@​scttcper, @​jhult)
  • Improved performance of event dispatch, form control and label lookups, and updates to <select> elements and radio button groups. (@​scttcper)
  • Reduced memory use when creating and working with DOM nodes, attributes, event listeners, and mutation observers. (@​scttcper)
  • Changed window.close() to preserve access to the document and its DOM through retained references.
  • Fixed element.querySelectorAll() returning no matches when the first part of the selector matches the element itself, which regressed in v30.0.0. (@​asamuzaK)
  • Fixed case sensitivity in CSS attribute selectors, including selectors matching data-state="", title="", and other case-sensitive values. (@​asamuzaK)
  • Fixed document.querySelector() failing to find a matching element when an earlier element has the same ID but does not match the rest of the selector. (@​vojtisprime11)
  • Fixed :focus matching in shadow trees. (@​asamuzaK)
  • Fixed DOM insertion and replacement, including valid document.replaceChildren() calls, invalid document element and doctype placements, and mutations during element.replaceWith().
  • Fixed the ordering of script execution, custom element callbacks, iframe loading, and mutation observer notifications during DOM insertion, including in shadow trees.
  • Fixed queued events and navigation continuing after window.close() or iframe removal, and prevented new scripts, resource loads, timers, and animation frames from starting in destroyed documents. (@​scttcper)
  • Fixed parent documents waiting indefinitely for loading to finish when a child iframe removes itself during loading.
  • Fixed request cancellation across redirects, during pending requestInterceptor() callbacks, and when reusing an XMLHttpRequest after aborting it.
  • Fixed resource loading and JSDOM.fromURL() potentially hanging when response handling throws and response stream cleanup does not finish.
  • Fixed successful cached resource loads being treated as aborted.
  • Fixed getComputedStyle() and document.styleSheets using the wrong stylesheet order after inserting or updating <style> elements.
  • Fixed getComputedStyle() ignoring nested @import and @media rules in imported stylesheets, and returning stale results after imports finish loading.
  • Fixed style invalidation, stylesheet removal, and frame source updates in shadow trees.
  • Fixed repeated getComputedStyle() calls changing case-sensitive background URLs, and inconsistent resolution of border shorthands containing system colors. (@​scttcper)
  • Fixed computed border widths, including borderless elements incorrectly reporting 16px, which regressed in v30.0.0. (@​Alberto-BaseNet)
  • Fixed getComputedStyle() to resolve 'font-weight' keywords to numeric values. (@​tianrking)
  • Fixed getComputedStyle() to convert lengths to pixels inside CSS math functions containing percentages, and to resolve percentages in 'font-size' math functions. (@​soroushm)
  • Fixed serialization of min() and max() containing nested calc(), which regressed in v30.0.0. (@​asamuzaK)
  • Fixed CSS values mixing lengths or percentages with math functions, such as 'grid-template-columns' values containing both 100px and calc(). (@​rome-xi)
  • Fixed parsing of 'background' and 'border' shorthands with adjacent components, such as url(a.png)no-repeat, including a crash when parsing inline styles. Also fixed handling of invalid shorthand assignments and escaped or unusual characters in CSS declarations. (@​asamuzaK)
  • Fixed parsing of unitless zero values in 'flex' shorthands, such as 35 1 0, and rejection of negative 'flex-basis' lengths and percentages. (@​asamuzaK)
  • Fixed shorthand style assignments producing extra mutation records and custom element callbacks for intermediate values. (@​scttcper)
  • Fixed Range and Selection handling of CDATA sections, including boundary offsets and range cloning, extraction, deletion, insertion, and stringification. (@​scttcper)
  • Fixed text.normalize() incorrectly removing the text node or merging its siblings. (@​scttcper)
  • Fixed cloning and importing CDATA sections and processing instructions whose contents have been modified, and serialization of CDATA sections adopted into HTML documents.
  • Fixed stale named-property collections on window, and incorrect named access from empty or namespaced id="" and name="" values. (@​scttcper)
  • Fixed elements in documents created with DOMParser or document.implementation.createHTMLDocument() appearing as named properties on window and being retained in memory. (@​Iaotle)
  • Fixed memory leaks from mutation observers retaining observed nodes, abort signals retaining removed event listeners, and storage event tracking retaining closed windows. (@​scttcper)
  • Fixed storage events being sent to windows created after the storage change, and ensured surviving recipients still receive events when the source document is destroyed.
  • Fixed attribute lookups after namespace prefix changes, and namespaced attributes incorrectly affecting ID lookups and element behavior. (@​scttcper)
  • Fixed input.list in detached element trees. (@​scttcper)
  • Fixed attr.ownerDocument after setting an attribute node on an element in another document or adopting its element. (@​Kjubikstronk)
  • Fixed fresh element.getElementsByTagName() calls using the previous document's case-sensitivity rules after adoption between HTML and XML documents. (@​Kjubikstronk)
  • Fixed element.tagName returning stale casing after adoption between HTML and XML documents.
  • Fixed radio button grouping and checkedness updates for controls with different form owners, controls outside their form, unnamed controls, and canceled clicks.
  • Fixed <select> selection updates when moving options, and unintended selection resets when moving a whole <select> or changing unrelated descendants.
  • Fixed cloning <input> elements to preserve input.indeterminate.
  • Fixed focus state after removing a focused element or its ancestor, including inside shadow trees.
  • Fixed script execution when inserting children into a connected, empty <script>. (@​Kjubikstronk)
  • Fixed incorrect script execution after changes to src="", and handling of type="", for="", and event="".
  • Fixed document.currentScript during nested script execution and scripts in shadow trees.
  • Fixed event dispatch, window.event, and default passive listener handling for non-node event targets, and event dispatch when user code modifies window.constructor.
  • Fixed volumechange and ratechange events to fire asynchronously. (@​christianaurichzm)
  • Fixed DOM APIs accepting user-created proxies around DOM objects where genuine DOM objects are required.
  • Fixed XPath iterator invalidation after DOM mutations and errors for invalid result types.
  • Fixed NodeIterator traversal when its filter removes nodes.
  • Fixed fileReader.readAsText() to honor the blob's MIME type charset when no supported explicit encoding is supplied.
  • Fixed fractional seconds in time input parsing and serialization. (@​Jaybhade)
  • Fixed large input.valueAsNumber assignments for time and local date/time inputs.
  • Fixed hard wrapping of <textarea> values to use the numeric textarea.cols value.
  • Fixed document.readyState to be "complete" for documents created with document.implementation.createDocument() and document.implementation.createHTMLDocument().
  • Fixed element.translate for empty translate="" values and elements without a parent.
  • Fixed XML parsing of lone surrogates to replace them with the Unicode replacement character.
  • Fixed node.lookupNamespaceURI() for the xml and xmlns prefixes. (@​vojtisprime11)
  • Fixed <base> elements to ignore data: and javascript: URLs. (@​vojtisprime11)
  • Fixed svgElement.viewportElement inside <symbol> elements.
  • Fixed the default blobEvent.timecode to be NaN.
  • Fixed the object shape and property descriptors of CSS.
pnpm/pnpm (pnpm)

v11.28.5: pnpm 11.28.5

Compare Source

This release reads cached registry metadata faster and makes pnpm config get --global ignore project settings. It also carries several security fixes for package archives, git dependencies, and config dependencies.

Patch Changes
Security
  • pnpm now verifies locked config dependencies against their registry before installing them. Config dependencies must come from an npm registry. The lockfile can no longer replace the integrity of a config dependency pinned with version+integrity.

  • Lockfile verification now checks the tarballs inside a variations resolution against the registry. A name@version lockfile entry with an empty variations resolution is now rejected.

  • pnpm audit signatures now verifies signatures against the integrity recorded in the lockfile. Packages without a recorded integrity cannot pass signature verification.

  • pnpm now rejects a git dependency whose lockfile repository is empty, begins with -, or contains a null byte. Git can no longer read such a value as a command-line option pnpm/tasks#84.

  • A git dependency with a #path: subpath can no longer reach files outside the repository through a symlink in the subpath.

  • pnpm pack, pnpm publish, and installs of git and local directory dependencies now leave out files that a directory symlink or a bundleDependencies entry points to outside the package directory pnpm/tasks#83 pnpm/tasks#93.

  • pnpm deploy with deployAllFiles now rejects symlinks that point outside the package directory. Local package installs with this setting apply the same check.

  • pnpm no longer hangs on a package archive with a negative PAX record length or an entry of 4 GiB or more pnpm/tasks#78 pnpm/tasks#79.

  • Large package downloads and large files inside gzip and bzip2 package archives now use bounded memory during installation. Package manifests and archive metadata larger than 64 MiB are rejected. pnpm publish also rejects manifests and README files larger than 64 MiB in pre-built tarballs before reading them into memory.

  • Two URL or local path dependencies no longer share a virtual store directory when one URL has +, #, :, or ? where the other has /. Such dependencies, including git dependencies pinned with #, now get a hash suffix on their directory name.

  • pnpm licenses now removes terminal control characters from package metadata in table output.

  • The warnings about ignored project .npmrc registry and auth settings no longer print the username and password of a URL-scoped key such as //user:password@registry.example.com/:_authToken.

Installing and resolving dependencies
  • Dependency resolution reads cached registry metadata faster. The metadata cache moved to <cache-dir>/v12/, so the first install after upgrading downloads registry metadata again. A damaged cache entry is downloaded again, or reported as an error when --offline is set #​13512.

  • pnpm install now fails with ERR_PNPM_UNSUPPORTED_PROTOCOL when a dependency uses a specifier with a protocol pnpm does not support, such as Yarn's patch:. pnpm linked such a dependency to a directory that does not exist #​16590.

  • When a dependency moves an exact dependency of its own to an older version, a peer dependency that pnpm installed automatically now moves with it. Before, pnpm install and pnpm dedupe kept the newer locked version of the peer, so the lockfile held two copies of it, for example two copies of vue pnpm/tasks#61.

  • pnpm add and pnpm install now keep the peer dependencies that pnpm-lock.yaml records for a package they did not update. A registry whose metadata disagrees with the package's package.json, for example by omitting peerDependenciesMeta, made pnpm add and pnpm dedupe write different lockfiles, so pnpm dedupe --check failed after pnpm add #​16615.

Configuration
  • pnpm config get and pnpm config list with --global or --location=global now show only the global configuration. Both flags included the project's .npmrc before. --location=global also included the project's pnpm-workspace.yaml. pnpm config get --global failed when the global bin directory was not in PATH #​16598.

  • pnpm now prints config warnings, such as an unset environment variable in .npmrc, when loading the config fails.

  • pnpm now fails when httpProxy or httpsProxy in pnpm-workspace.yaml or the global configuration is not a string.

  • pnpm dlx now uses the release entry of nodeDownloadMirrors from the workspace configuration when downloading Node.js runtimes #​11281. Mirrors for other channels, such as rc and nightly, still apply only from the global configuration.

Commands
  • pnpm run and pnpm exec now forward --config.* command-line flags to the install started by verifyDepsBeforeRun pnpm/tasks#60.

  • pnpm dlx with --package but no command now fails with 'pnpm dlx' requires a command to run. Before, it installed the package and then crashed trying to run an empty command.

  • pnpm unpublish <pkg>@<version> now deletes the tarball under the registry's path when the registry is served under one, such as Gitea's npm registry. It used to send the delete to the host root and report success without removing the version #​16568. It also no longer mistakes a sibling path such as /npm-mirror/ for the registry path /npm/ pnpm/tasks#94.

  • The interactive pnpm audit --fix picker now shows each patched version with the saveExact and savePrefix style that the override is written with #​13209.

  • pnpm list now reports the correct package paths when nodeLinker is hoisted #​9593.

  • pnpm setup now puts $PNPM_HOME/bin first on PATH in login shells that inherited it further down, such as the VS Code terminal on macOS. Before, another node took precedence over the one installed by pnpm runtime set node -g. Run pnpm setup again to update the block in your shell config #​16635.

  • pnpm setup now names the shell config file even if it is already up to date #​16608.

Output and messages
  • A warning about a project's devEngines or packageManager pin is now printed to stderr. A command such as pnpm cache path or pnpm list --json keeps only its own output on stdout #​16584.

  • The warning for a non-root resolutions field now points at the overrides field in pnpm-workspace.yaml #​11757.

Platinum Sponsors
Bit OpenAI Notion
CodeRabbit
Gold Sponsors
Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v11.28.4: pnpm 11.28.4

Compare Source

pnpm 11.28.4 fixes two ways credentials could leak, makes pnpm install --frozen-lockfile accept several lockfiles it rejected, warns when an optional dependency cannot be fetched, and stops pnpm self-update from installing a second pnpm next to a Homebrew one.

Patch Changes
  • pnpm login no longer forwards credentials in its request body to another origin during redirects.

  • The error for a tarball that fails its integrity check no longer prints credentials, query strings, or fragments from the tarball URL.

Installing packages
  • pnpm install --frozen-lockfile now succeeds in a project with no dependencies when pnpm-lock.yaml records only the pinned pnpm version. Other commands write such a lockfile when they run before the first install. A lockfile missing the --- line after that section is accepted too #​16477.

  • pnpm install --frozen-lockfile again succeeds when a workspace project recorded in pnpm-lock.yaml has no directory, such as a project left out of a Docker build context. It still fails if the project's directory exists without a package.json #​16453.

  • pnpm install --frozen-lockfile no longer fails with ERR_PNPM_OUTDATED_LOCKFILE for a workspace project that declares dependenciesMeta and whose dependencies are all workspace links. pnpm now records that project's dependenciesMeta in pnpm-lock.yaml #​16457.

  • Fixed frozen installs replacing a hoisted dependency with a workspace package of the same name. A later pnpm dedupe then removed the hoisted link #​16485.

  • With enableGlobalVirtualStore on, scripts can run entry points that a CommonJS require hook loads again, such as ts-node index.ts. They failed with ERR_UNKNOWN_FILE_EXTENSION on Node.js versions without built-in TypeScript support #​16436.

Optional dependencies
  • pnpm install now prints a warning with the error when an optional dependency cannot be fetched and is skipped. The skipped package is no longer linked into node_modules as a broken symlink or listed among the added dependencies. The pnpm:skipped-optional-dependency log reports the skip with the fetch_failure reason #​16514.

  • When an optional dependency fails to build, pnpm now removes its link from node_modules. A repeat pnpm install then reports "Already up to date" and no longer reruns the failing build #​16468.

  • Fixed frozen installs creating symlinks to the working directory for skipped optional dependencies and unresolved peer dependencies #​16454.

Hoisted node_modules
  • With nodeLinker: hoisted, a filtered install now keeps the packages of the workspace projects an earlier install put in node_modules. This also covers the install that pnpm --filter <selector> run and pnpm --filter <selector> exec start before the command. Before, these installs removed every package that only the unselected projects needed #​16483.

    A filtered install of a workspace project also no longer fails with ERR_PNPM_LOCKFILE_MISSING_DEPENDENCY after a filtered install of another project.

  • pnpm install with nodeLinker: hoisted now refreshes directories supplied by custom fetchers when reinstalling.

Speed and network
  • pnpm now revalidates cached registry metadata with a conditional request, so the registry can answer 304 Not Modified. Before, pnpm downloaded the whole document again for registries whose responses forbid caching, such as Cache-Control: no-store #​16528, and for packages published within minimumReleaseAge #​16506.

  • A fetch timeout while other downloads from the same host are still running now lowers concurrency for that host to one connection. Retries of that request, and later downloads from that host, use the lower concurrency. Other hosts keep the configured concurrency #​12791.

Running scripts
  • Scripts run without a terminal no longer start a second sh each. One watchdog per pnpm command now ends every script's process group if pnpm is killed, so pnpm -r run across many projects starts half as many processes #​16489.

  • pnpm run and pnpm exec now warn and run the command when the install that verifyDepsBeforeRun starts fails. This lets scripts run in sandboxes where pnpm cannot install, such as containers with a read-only store or no network #​15173.

  • A filtered pnpm run or pnpm exec now finds dependencies out of date when a workspace dependency of a selected project has no node_modules directory, as after a filtered install. With verifyDepsBeforeRun: install, pnpm installs that dependency before running the command pnpm/tasks#45.

  • pnpm rebuild and pnpm approve-builds refresh command launchers when a build changes a command's interpreter or replaces it with a native executable. Dependent packages' build scripts use the refreshed launchers.

Updating pnpm
  • pnpm self-update now fails for Homebrew-installed pnpm and prints the brew upgrade command for the installed formula, such as brew upgrade pnpm or brew upgrade pnpm@11. It used to install a second copy of pnpm that the Homebrew one kept shadowing #​16547.

  • On Windows, pnpm self-update now replaces a pnpm.exe left in PNPM_HOME or in PNPM_HOME\bin. In PNPM_HOME, that executable kept running the old version after a successful update. In PNPM_HOME\bin, the update failed with EPERM. If the executable was in PNPM_HOME, self-update now asks you to run pnpm setup #​9094.

  • pnpm can now switch to a packageManager version below 11 on x64 musl Linux, such as Alpine #​16467.

  • A devEngines.packageManager range now records the running pnpm in pnpm-lock.yaml only if it meets minimumReleaseAge. Otherwise pnpm records the newest version in the range that meets it. If no version in the range does, pnpm still records the running pnpm #​16431.

Filtering, settings, and other commands
  • The [<since>] filter selector works again with Git 2.24 through 2.27 #​16561. With Git older than 2.24, the selector now fails with an error that names the required Git version.

  • Package-name filters now support ? to match one character #​2817.

  • pnpm -r pkg get now reports every selected project when several share a package name. Projects with the same name are keyed by their directory relative to the workspace root. Before, only one of them appeared in the output.

  • pnpm now reports an INVALID_SETTING error when allowUnusedPatches in pnpm-workspace.yaml is not a boolean, or when ignoredOptionalDependencies or requiredScripts is not an array of strings. A quoted allowUnusedPatches value such as "false" was treated as true.

  • pnpm store path, pnpm store status, and other commands that look up the default store no longer fail when the current directory is not writable. pnpm now uses the store in the pnpm home directory in that case #​16554.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from b597811 to 87964bb Compare September 2, 2026 17:22
@renovate renovate Bot changed the title Update pnpm to v11.25.0 Update all non-major dependencies Sep 2, 2026
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 991f462 to d2c1334 Compare September 4, 2026 19:15
@renovate

renovate Bot commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pnpm-lock.yaml
? Verifying lockfile against supply-chain policies (349 entries)...
Progress: resolved 1, reused 0, downloaded 0, added 0
Progress: resolved 4, reused 0, downloaded 0, added 0
Progress: resolved 8, reused 0, downloaded 0, added 0
Progress: resolved 12, reused 0, downloaded 0, added 0
Progress: resolved 13, reused 0, downloaded 0, added 0
Progress: resolved 15, reused 0, downloaded 0, added 0
Progress: resolved 16, reused 0, downloaded 0, added 0
Progress: resolved 17, reused 0, downloaded 0, added 0
[WARN] Request took 10014ms: https://registry.npmjs.org/@types%2Fnode
Progress: resolved 19, reused 0, downloaded 0, added 0
[WARN] Request took 11850ms: https://registry.npmjs.org/typescript
Progress: resolved 20, reused 0, downloaded 0, added 0
Progress: resolved 116, reused 0, downloaded 0, added 0
Progress: resolved 143, reused 0, downloaded 0, added 0
Progress: resolved 210, reused 0, downloaded 0, added 0
✓ Lockfile passes supply-chain policies (349 entries in 16.8s)
Progress: resolved 304, reused 0, downloaded 0, added 0
Progress: resolved 352, reused 0, downloaded 0, added 0
[ERR_PNPM_NO_MATURE_MATCHING_VERSION] 1 version does not meet the minimumReleaseAge constraint:
  @types/node@24.19.1 was published at 2026-10-01T22:38:02.894Z, within the minimumReleaseAge cutoff (2026-09-26T01:13:13.299Z)

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from 571d495 to 039b0b2 Compare September 12, 2026 18:25
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 6 times, most recently from 19fab58 to ab9d917 Compare September 21, 2026 22:04
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from dc23a82 to 09e03fd Compare September 28, 2026 23:49
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from 2f2637f to 46c03c7 Compare October 7, 2026 01:29
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 46c03c7 to 0182142 Compare October 9, 2026 11:00

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants