Skip to content

chore(deps): update all non-major dependencies - #343

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@vitest/coverage-v8 (source) ^5.0.1 → ^5.0.3 age confidence
eslint (source) ^10.11.0 → ^10.12.0 age confidence
h3 (source) 2.0.1-rc.32 → 2.0.1 age confidence
obuild ^0.4.40 → ^0.4.43 age confidence
oxc-minify (source) ^0.151.0 → ^0.152.0 age confidence
pnpm (source) 11.27.1 → 11.28.4 age confidence
sharp (source, changelog) ^0.35.4 → ^0.35.5 age confidence
vitest (source) ^5.0.1 → ^5.0.3 age confidence

⚠️ Renovate does not enforce Minimum Release Age for bump, lockfileUpdate, or rollback updates, so these are raised without a Minimum Release Age check. You will need to manually validate the Minimum Release Age for these package(s).


Release Notes

vitest-dev/vitest (@​vitest/coverage-v8)

v5.0.3

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v5.0.2

Compare Source

   🐞 Bug Fixes
    View changes on GitHub
eslint/eslint (eslint)

v10.12.0

Compare Source

Features
  • 4618052 feat: handle astral letters in new-cap (#​21357) (sary)
  • 4ec5168 feat: allow SourceCode#getText() to accept tokens and comments (#​21340) (electrohyun)
Bug Fixes
  • bc51eee fix: prefer-arrow-callback false positive in conditional test (#​21373) (Daniel Pinto)
  • bbff86c fix: skip lines with multiple comments in max-lines-per-function (#​21332) (xbinaryx)
  • efc4d6b fix: astral letters in consistent-return, no-eval, no-invalid-this (#​21360) (lumir)
  • 93de066 fix: prefer-exponentiation-operator autofix for async function base (#​21322) (Vladimir Babin)
  • 02e34ff fix: add missing space after else in curly autofix (#​21355) (Pixel)
  • b14b8bc fix: correct id-length message for long private names (#​21348) (Pixel)
  • 69aac01 fix: support TSFunctionType in getFunctionHeadLoc (#​21335) (xbinaryx)
  • 686630e fix: no-loss-of-precision false positive with 0.e5 (#​21337) (sethamus)
Documentation
  • 67eb586 docs: Update README (GitHub Actions Bot)
  • 5370d7e docs: clarify one-var separateRequires matches any require() call (#​21192) (sethamus)
  • 8816c1d docs: Update README (GitHub Actions Bot)
  • 3d2e7ce docs: fix typo in no-unused-expressions documentation (#​21346) (bytedoe)
Chores
  • 152067f chore: update ecosystem plugins (#​21362) (ESLint Bot)
  • b56d58e chore: update github/codeql-action action to v4.38.2 (#​21376) (renovate[bot])
  • bfaea12 perf: cache normalized config globals per languageOptions (#​21364) (James Ross)
  • 322209e ci: avoid Nx cache in ecosystem tests and disable failing test (#​21369) (Francesco Trotta)
  • d166567 chore: update dependency prettier to v3.9.9 (#​21371) (renovate[bot])
  • 29585ce chore: update dependency eslint-plugin-expect-type to ^0.7.0 (#​21359) (renovate[bot])
  • 39d79ba chore: update github/codeql-action action to v4.38.1 (#​21354) (renovate[bot])
  • 182a6e9 chore: update dependency prettier to v3.9.8 (#​21352) (renovate[bot])
  • f995127 chore: remove CLAUDE.md in favor of AGENTS.md (#​21339) (Jarren)
  • b95fb6c chore: update dependency prettier to v3.9.7 (#​21347) (renovate[bot])
  • 3782dd4 chore: update ecosystem plugins (#​21342) (ESLint Bot)
h3js/h3 (h3)

v2.0.1

Compare Source

compare changes

🚀 Enhancements
  • rules: Skip redirect when the request is already at the target (#​1559)
🩹 Fixes
  • cookie: Include partitioned in the distinct-cookie key (#​1553)
  • sse: Preserve buffered events during overlapping flushes (#​1555)
  • static: Set vary header when a single encoding is accepted (#​1556)
  • static: Honor q-values and case in accept-encoding (#​1560)
  • mime: Add .mjs and .cjs to COMMON_MIME_TYPES (#​1566)
  • rules: Normalize rule keys like routes and tighten the shape guard (7cbf21c)
  • rules: Let a narrower pattern reinstate a rule reset on another reading (3f1c9e5)
  • rules: Allow headers: false in RouteRuleConfig (edcc329)
  • validate: Preserve repeated query values in defineValidatedHandler (#​1562)
  • cookie: Size cookie chunks by their encoded length (#​1565)
  • static: Resolve the MIME type of a precompressed variant from the requested asset (#​1564)
  • mount: Reject // after base (1161eb7)
  • session: Keep loaded session data prototype-free (46bc1a2)
💅 Refactors
📖 Documentation
  • Document raw query access via event.url.search (#​1551)
🌊 Types
  • auth: BasicAuth context fields are always set (#​1550)
🏡 Chore
❤️ Contributors

v2.0.1-rc.33

Compare Source

compare changes

🚀 Enhancements
  • rules: Skip redirect when the request is already at the target (#​1559)
🩹 Fixes
  • cookie: Include partitioned in the distinct-cookie key (#​1553)
  • sse: Preserve buffered events during overlapping flushes (#​1555)
  • static: Set vary header when a single encoding is accepted (#​1556)
  • static: Honor q-values and case in accept-encoding (#​1560)
  • mime: Add .mjs and .cjs to COMMON_MIME_TYPES (#​1566)
  • rules: Normalize rule keys like routes and tighten the shape guard (7cbf21c)
  • rules: Let a narrower pattern reinstate a rule reset on another reading (3f1c9e5)
  • rules: Allow headers: false in RouteRuleConfig (edcc329)
  • validate: Preserve repeated query values in defineValidatedHandler (#​1562)
  • cookie: Size cookie chunks by their encoded length (#​1565)
  • static: Resolve the MIME type of a precompressed variant from the requested asset (#​1564)
  • mount: Reject // after base (1161eb7)
  • session: Keep loaded session data prototype-free (46bc1a2)
💅 Refactors
📖 Documentation
  • Document raw query access via event.url.search (#​1551)
🌊 Types
  • auth: BasicAuth context fields are always set (#​1550)
🏡 Chore
❤️ Contributors
oxc-project/oxc (oxc-minify)

v0.152.0

🚀 Features
pnpm/pnpm (pnpm)

v11.28.4: pnpm 11.28.4

Compare Source

pnpm 11.28.4 fixes two ways credentials could leak, makes pnpm install --frozen-lockfile accept several lockfiles it rejected, warns when an optional dependency cannot be fetched, and stops pnpm self-update from installing a second pnpm next to a Homebrew one.

Patch Changes
  • pnpm login no longer forwards credentials in its request body to another origin during redirects.

  • The error for a tarball that fails its integrity check no longer prints credentials, query strings, or fragments from the tarball URL.

Installing packages
  • pnpm install --frozen-lockfile now succeeds in a project with no dependencies when pnpm-lock.yaml records only the pinned pnpm version. Other commands write such a lockfile when they run before the first install. A lockfile missing the --- line after that section is accepted too #​16477.

  • pnpm install --frozen-lockfile again succeeds when a workspace project recorded in pnpm-lock.yaml has no directory, such as a project left out of a Docker build context. It still fails if the project's directory exists without a package.json #​16453.

  • pnpm install --frozen-lockfile no longer fails with ERR_PNPM_OUTDATED_LOCKFILE for a workspace project that declares dependenciesMeta and whose dependencies are all workspace links. pnpm now records that project's dependenciesMeta in pnpm-lock.yaml #​16457.

  • Fixed frozen installs replacing a hoisted dependency with a workspace package of the same name. A later pnpm dedupe then removed the hoisted link #​16485.

  • With enableGlobalVirtualStore on, scripts can run entry points that a CommonJS require hook loads again, such as ts-node index.ts. They failed with ERR_UNKNOWN_FILE_EXTENSION on Node.js versions without built-in TypeScript support #​16436.

Optional dependencies
  • pnpm install now prints a warning with the error when an optional dependency cannot be fetched and is skipped. The skipped package is no longer linked into node_modules as a broken symlink or listed among the added dependencies. The pnpm:skipped-optional-dependency log reports the skip with the fetch_failure reason #​16514.

  • When an optional dependency fails to build, pnpm now removes its link from node_modules. A repeat pnpm install then reports "Already up to date" and no longer reruns the failing build #​16468.

  • Fixed frozen installs creating symlinks to the working directory for skipped optional dependencies and unresolved peer dependencies #​16454.

Hoisted node_modules
  • With nodeLinker: hoisted, a filtered install now keeps the packages of the workspace projects an earlier install put in node_modules. This also covers the install that pnpm --filter <selector> run and pnpm --filter <selector> exec start before the command. Before, these installs removed every package that only the unselected projects needed #​16483.

    A filtered install of a workspace project also no longer fails with ERR_PNPM_LOCKFILE_MISSING_DEPENDENCY after a filtered install of another project.

  • pnpm install with nodeLinker: hoisted now refreshes directories supplied by custom fetchers when reinstalling.

Speed and network
  • pnpm now revalidates cached registry metadata with a conditional request, so the registry can answer 304 Not Modified. Before, pnpm downloaded the whole document again for registries whose responses forbid caching, such as Cache-Control: no-store #​16528, and for packages published within minimumReleaseAge #​16506.

  • A fetch timeout while other downloads from the same host are still running now lowers concurrency for that host to one connection. Retries of that request, and later downloads from that host, use the lower concurrency. Other hosts keep the configured concurrency #​12791.

Running scripts
  • Scripts run without a terminal no longer start a second sh each. One watchdog per pnpm command now ends every script's process group if pnpm is killed, so pnpm -r run across many projects starts half as many processes #​16489.

  • pnpm run and pnpm exec now warn and run the command when the install that verifyDepsBeforeRun starts fails. This lets scripts run in sandboxes where pnpm cannot install, such as containers with a read-only store or no network #​15173.

  • A filtered pnpm run or pnpm exec now finds dependencies out of date when a workspace dependency of a selected project has no node_modules directory, as after a filtered install. With verifyDepsBeforeRun: install, pnpm installs that dependency before running the command pnpm/tasks#45.

  • pnpm rebuild and pnpm approve-builds refresh command launchers when a build changes a command's interpreter or replaces it with a native executable. Dependent packages' build scripts use the refreshed launchers.

Updating pnpm
  • pnpm self-update now fails for Homebrew-installed pnpm and prints the brew upgrade command for the installed formula, such as brew upgrade pnpm or brew upgrade pnpm@11. It used to install a second copy of pnpm that the Homebrew one kept shadowing #​16547.

  • On Windows, pnpm self-update now replaces a pnpm.exe left in PNPM_HOME or in PNPM_HOME\bin. In PNPM_HOME, that executable kept running the old version after a successful update. In PNPM_HOME\bin, the update failed with EPERM. If the executable was in PNPM_HOME, self-update now asks you to run pnpm setup #​9094.

  • pnpm can now switch to a packageManager version below 11 on x64 musl Linux, such as Alpine #​16467.

  • A devEngines.packageManager range now records the running pnpm in pnpm-lock.yaml only if it meets minimumReleaseAge. Otherwise pnpm records the newest version in the range that meets it. If no version in the range does, pnpm still records the running pnpm #​16431.

Filtering, settings, and other commands
  • The [<since>] filter selector works again with Git 2.24 through 2.27 #​16561. With Git older than 2.24, the selector now fails with an error that names the required Git version.

  • Package-name filters now support ? to match one character #​2817.

  • pnpm -r pkg get now reports every selected project when several share a package name. Projects with the same name are keyed by their directory relative to the workspace root. Before, only one of them appeared in the output.

  • pnpm now reports an INVALID_SETTING error when allowUnusedPatches in pnpm-workspace.yaml is not a boolean, or when ignoredOptionalDependencies or requiredScripts is not an array of strings. A quoted allowUnusedPatches value such as "false" was treated as true.

  • pnpm store path, pnpm store status, and other commands that look up the default store no longer fail when the current directory is not writable. pnpm now uses the store in the pnpm home directory in that case #​16554.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v11.28.3: pnpm 11.28.3

Compare Source

pnpm 11.28.3 updates undici to clear a security advisory, fixes "database disk image is malformed" errors when several pnpm processes share a store, and makes packages, catalogs, projects, and commands named like constructor work.

Patch Changes
Installing packages
  • pnpm now ships undici 7.29.1, so security scans of pnpm no longer report GHSA-3wwx-pv8p-q78v.

  • pnpm no longer fails with "database disk image is malformed" or reads stale store entries while another pnpm process writes to the same store.

  • Names that match built-in JavaScript object properties, such as constructor, toString, or __proto__, now work like any other name. pnpm crashed, wrote a wrong lockfile, or silently skipped such names in:

    • pnpm add, pnpm install, and pnpm import, for dependencies, peer dependencies, and file: dependencies that point to a directory named constructor.
    • Catalog entries and catalog names. Pruning unused entries crashed, and a new catalog named toString was not written.
    • Workspace projects, project directories, and files inside injected packages.
    • Registry prefixes and override version references such as $toString.
    • Hoisting, pnpm list, and pnpm why.
    • Command names. pnpm constructor runs the constructor script like any other unknown command, and pnpm help constructor no longer crashes.
    • Resolving through a pnpr server when a project lives in a directory named constructor.
  • pnpm install no longer re-resolves an up-to-date lockfile on every run when a patched package is a peer in a peer cycle #​16418.

  • POSIX bin shims and the pnpm, pn, pnpx, and pnx launchers now run inside a Nix build, where the system default path holds none of the utilities they call. Installing again replaces the shims already in node_modules #​16377.

  • In a project that pins another pnpm version, pnpm now passes a command with an option it does not know to the pinned version. Before, pnpm install --auto-dedupe failed with "Unknown option" even though the pinned pnpm supports it #​16353.

  • pnpm now fails with ERR_PNPM_INVALID_ALLOW_BUILDS when allowBuilds is not an object or one of its values is not true, false, or a string. Such values used to be ignored silently.

  • Removing a dependency whose bins are declared through directories.bin no longer leaves broken shims in node_modules/.bin.

  • A custom resolver's shouldRefreshResolution hook that rejects no longer crashes pnpm with an unhandled rejection when another hook has already asked for a refresh.

Updating dependencies
  • When minimumReleaseAge hides the version that latest points to, pnpm now falls back to a prerelease of the same major before a stable version of an older major. A stable version of the same major is still preferred. For example, while a new 1.0.0 is too new, pnpm picks 1.0.0-beta.4 rather than an old 0.0.1 #​16388.

  • pnpm --filter <project> update <pkg> now fails with ERR_PNPM_NO_PACKAGE_IN_DEPENDENCIES when the selected projects do not depend on <pkg>, also in a workspace with a shared lockfile and a root project. It used to exit successfully.

  • pnpm audit --fix now updates vulnerable packages in a single project that sets updateConfig.ignoreDependencies. It used to leave them on the vulnerable version.

  • pnpm update --global now removes hard-linked executables from PNPM_HOME when migrating packages from the old global layout #​16420.

  • Updating a pinned GitHub Action now rewrites the version in its # vX.Y.Z comment even when the action name contains the same version text. The action name used to change while the comment kept the old version.

Workspaces and deploy
  • pnpm deploy no longer fails with ERR_PNPM_DEPLOY_AMBIGUOUS_PEER in a workspace with injectWorkspacePackages: true when a workspace package also lists its peer dependency as a dev dependency #​16375.

  • pnpm deploy no longer copies the workspace root's packageManager and devEngines.packageManager fields into the deployed package.json #​16403.

  • --filter fixes:

    • A ...pkg... selector combined with another dependents selector, such as --filter ...a --filter ...b..., no longer adds the dependencies of the other selector's dependents.
    • --filter "[<since>]" now detects changes in projects whose directory names contain non-ASCII characters. The change used to be credited to the parent project.
Running scripts
  • After relaying a signal to a script, pnpm keeps waiting for a process in the script's process group whose main thread has exited while its other threads still run. Linux reports such a process as a zombie, so the wait used to end before those threads finished pnpm/tasks#56.

  • A lifecycle script run with unsafePerm: false now fails with an error when pnpm cannot create node_modules/.tmp. It used to hang.

  • pnpm run with verifyDepsBeforeRun no longer crashes with an unhandled rejection when a lockfile it did not need to compare fails to load.

  • pnpm run -r now closes the collapsible CI log section of a project whose script fails, so the output of later projects is no longer nested inside it.

  • pnpm run --resume-from no longer crashes when a saved run state file contains null.

Store
  • pnpm store prune now removes the packages that only expired pnpm dlx cache entries used, as long as the store still has another registered project. They used to stay until the next pnpm store prune #​16383.

  • pnpm store prune now stops with an error when it cannot read a project directory for a reason other than the directory missing, such as a permission error. It used to skip the directory.

Publishing and registry output
  • pnpm publish now includes bare README files and README files with Markdown extensions such as readme.markdown in registry metadata #​12704.

  • pnpm pack-app now accepts an entry file or output directory inside the project whose name starts with two dots, such as ..build/entry.cjs. It used to fail with ERR_PNPM_PACK_APP_ENTRY_OUTSIDE_PROJECT.

  • Registry error messages now always say "(response body truncated)" when pnpm cut the response body short. The marker was missing when the body was cut at exactly 64 KiB.

Platinum Sponsors
Bit OpenAI Notion
CodeRabbit
Gold Sponsors
Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v11.28.2: pnpm 11.28.2

Compare Source

pnpm 11.28.2 fixes pnpm install skipping every workspace project whose common ancestor is the filesystem root, and stops pnpm run from reinstalling or installing when nothing needs it.

Patch Changes
  • pnpm install reported success without installing anything when the workspace projects' common ancestor was the filesystem root, such as / or a drive root like C:\. It now installs these projects #​16328.

  • verifyDepsBeforeRun no longer reports dependencies as outdated after a filtered install just because pnpm-lock.yaml has a newer modification time. It checks the lockfile against the packages that install put in place. Before, pnpm run reinstalled the whole workspace with lifecycle scripts on, for example after a Docker COPY brought in a lockfile with a newer mtime #​16322.

    After a filtered install, verifyDepsBeforeRun now also checks that the install put the selected projects' dependencies in place. A node_modules directory alone no longer counts as proof.

  • pnpm run and pnpm exec no longer install a project that has never been installed and has nothing to install. Such a project declares no dependencies, no peer dependencies that autoInstallPeers would fetch, and no install lifecycle scripts. The command now runs without writing node_modules or pnpm-lock.yaml #​16313.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "after 1am and before 5am"
  • Automerge
    • "after 2am and before 5am"

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from pi0 as a code owner September 29, 2026 02:53
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: b0283d8e-e4cb-4e73-9204-fb3c53434f2a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 92.52%. Comparing base (e450892) to head (37442a7).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #343   +/-   ##
=======================================
  Coverage   92.52%   92.52%           
=======================================
  Files           9        9           
  Lines         950      950           
  Branches      330      330           
=======================================
  Hits          879      879           
  Misses         62       62           
  Partials        9        9           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 8 times, most recently from bb6aaab to 246131b Compare October 6, 2026 12:30
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 246131b to 37442a7 Compare October 7, 2026 00:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants