fix(deps): update npm dependencies (non-major) - #121
Merged
Conversation
renovate
Bot
requested review from
a team,
iryotakadowaki-hash and
reiichii
and removed request for
a team
July 9, 2026 18:41
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 10, 2026 00:11
efa996b to
5a8d644
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 14, 2026 00:37
5a8d644 to
7f2b597
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 14, 2026 20:15
7f2b597 to
fcfed5c
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 15, 2026 08:07
fcfed5c to
886a8a0
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 15, 2026 20:06
886a8a0 to
60dd600
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 16, 2026 02:49
60dd600 to
54dcbce
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 17, 2026 03:34
54dcbce to
08d8176
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 17, 2026 23:03
08d8176 to
b2b3172
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 20, 2026 23:52
b2b3172 to
b74d8ea
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 21, 2026 15:03
b74d8ea to
a9172da
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 21, 2026 21:51
a9172da to
e4d29b4
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 22, 2026 19:06
e4d29b4 to
59f48ea
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 27, 2026 23:41
3333126 to
a3f19b2
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 28, 2026 18:14
a3f19b2 to
2692219
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 28, 2026 23:48
2692219 to
070b69b
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 29, 2026 19:32
070b69b to
e2076a0
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 29, 2026 23:02
e2076a0 to
eccb0c3
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
July 30, 2026 19:16
eccb0c3 to
1888c06
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
August 1, 2026 00:00
1888c06 to
ebc4231
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
August 3, 2026 17:37
ebc4231 to
604ffae
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
August 3, 2026 23:40
604ffae to
6f5fb61
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
August 4, 2026 19:34
6f5fb61 to
d5443c6
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
August 5, 2026 07:50
d5443c6 to
bb8db6d
Compare
renovate
Bot
force-pushed
the
renovate/npm-dependencies-(non-major)
branch
from
August 5, 2026 07:51
bb8db6d to
747f1dd
Compare
yukin01
approved these changes
Aug 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.1078.0→3.1097.07.18.0→7.19.01.15.43→1.15.4625.9.4→25.9.510.2.3→10.2.60.57.0→0.61.01.72.0→1.76.011.10.0→11.18.0Release Notes
aws/aws-sdk-js-v3 (@aws-sdk/client-ssm)
v3.1097.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1096.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1095.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1094.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1093.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1092.0Compare Source
Features
v3.1091.0Compare Source
3.1091.0(2026-07-20)
Documentation Changes
New Features
Tests
For list of updated packages, view updated-packages.md in assets-3.1091.0.zip
v3.1090.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1089.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1088.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1087.0Compare Source
Features
v3.1086.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1085.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1084.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1083.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1082.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1081.0Compare Source
Features
v3.1080.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1079.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
slackapi/node-slack-sdk (@slack/web-api)
v7.19.0Compare Source
Minor Changes
a795b86: feat: expand app manifest types — addagent_viewandassistant_viewfeatures, recent agent events (app_context_changed,assistant_thread_started,assistant_thread_context_changed), optional OAuth scopes (bot_optional/user_optional), and eventmetadata_subscriptionsswc-project/swc (@swc/core)
v1.15.46Compare Source
Bug Fixes
(deps) Update crossbeam-epoch to 0.9.20 (#12004) (fababa1)
(es/fixer) Normalize for-head ident patterns (#11968) (af681bc)
(es/fixer) Preserve parens around PURE-annotated receivers (#12022) (73d8941)
(es/hygiene) Ignore eval in default hygiene pass (#12003) (dd43ad6)
(es/minifier) Eliminate unused classes with cyclic references (#11963) (63a94b9)
(es/minifier) Preserve switch fallthrough termination (#11971) (a5d19ae)
(es/minifier) Check last case (#11972) (060c7ac)
(es/minifier) Disable IIFE invoke when there's eval (#11984) (eabe4be)
(es/minifier) Invoke IIFE when has eval (#11987) (457df11)
(es/minifier) Make Infect Collect collect every used ident (#11998) (fb9ebee)
(es/minifier) Measure number length precisely (#12026) (54d139a)
(es/module) Rewrite
.tsximports to.jsunless JSX is preserved (#11995) (c341d9c)(es/module) Rewrite SystemJS transform (#11996) (2f47530)
(es/modules) Resolve relative symlinked inputs from cwd (#11883) (01e857d)
(es/react) Emit jsxdev source for fragments (#11993) (a70ce24)
(es/react-compiler) Correct catch and parameter scope resolution (#11985) (3867e57)
(react-compiler) Remove React-like prefilter (#12007) (ab66869)
(ts/fast-strip) Handle generic arrow line breaks (#12034) (3d82701)
Documentation
Features
(bindings) Add
lint/lintSyncAPI to@swc/react-compiler(#11965) (ab4ce67)(es/minifier) Remove unused param for new Function or Class Expr (#12017) (be56e09)
(es/minifier) Remove unused param for new expr (#12027) (661067c)
(wasm) Add @swc/nodejs-support-wasm (#11975) (b617562)
Refactor
(es/helpers) Generate inline helpers from canonical ESM sources (#12006) (f36e4b6)
(es/helpers) Remove unused jsx helper (#12009) (ccbc906)
(es/lexer) Remove smartstring dependency (#12013) (d6833cc)
(es/minifier) Remove ProgramData.top (#12031) (a72571f)
(es/module) Align module transform records with spec terms (#11992) (f680df5)
(es/module) Introduce source module lowering pipeline (#11999) (9609b7f)
Remove direct rkyv dependencies (#12010) (5761a2b)
Testing
Build
Ci
Allow publish milestone PR updates (#11960) (885d3e2)
Allow memmap2 advisory (#11961) (0be5872)
Update rust-toolchain action pin (#12021) (78b41b5)
Use Node.js 24 by default (#12035) (d658d08)
Update rust-toolchain action pin (#12036) (d1a1e23)
Use Node.js 24 for wasm publishing (#12038) (516bf3c)
isaacs/minimatch (minimatch)
v10.2.6Compare Source
v10.2.5Compare Source
v10.2.4Compare Source
oxc-project/oxc (oxfmt)
v0.61.0Compare Source
v0.60.0Compare Source
v0.59.0Compare Source
🐛 Bug Fixes
415fe1eoxfmt: Error on ignorePatterns that cannot match files outside the config directory (#24286) (leaysgur)v0.58.0Compare Source
oxc-project/oxc (oxlint)
v1.76.0Compare Source
🚀 Features
8d31dfalinter: Verify eslint/no-restricted-globals config schema (#24598) (vigneshwar)7069621linter: Verify jest/vitest prefer-lowercase-title config schema (#24724) (Bartok)016cf2alinter/oxc: Add bad-match-all-arg rule (#24900) (camc314)cdc941elinter/n: Implementexports-stylerule (#24087) (Mikhail Baev)1ad6f6clinter/eslint: Implementid-denylistrule (#24632) (Mikhail Baev)📚 Documentation
3ff2e0elinter: Clarify config extends types (#24936) (Boshen)v1.75.0Compare Source
🚀 Features
dd18383linter/node: Implement no-top-level-await rule (#24634) (Connor Shea)16a65f2linter/react: Implement function-component-definition rule (#24471) (Cole Ellison)7f1f585linter: Reusejest/padding-around-test-blocksforvitest/padding-around-test-blocks(#24519) (Mikhail Baev)99978a8linter/import/consistent-type-specifier-style: Supportprefer-top-level-if-only-type-importsoption (#24502) (camc314)🐛 Bug Fixes
8694167linter/eslint/prefer-destructuring: Handle typed declarations (#24616) (camc314)v1.74.0Compare Source
🚀 Features
0433a83linter/eslint/no-inner-declarations: Addnamespacesoption (#24044) (Boshen)🐛 Bug Fixes
8337835linter: Error onignorePatternsthat cannot match files aoutside the config directory (#24341) (leaysgur)2ce5a33linter: ResolveignorePatternsrelative to the config dir (#24339) (leaysgur)⚡ Performance
7f80caclinter/vue/prop-name-casing: PrecompileignorePropsregex pattern (#24413) (connorshea)6272051linter/typescript/no-require-imports: Compile allow patterns once (#24417) (connorshea)33805b9linter/jsdoc/require-param: Compile checkTypesPattern regex once (#24420) (connorshea)v1.73.0Compare Source
🚀 Features
a2c97f3linter/unicorn: Implementexplicit-timer-delayrule (#23612) (Mikhail Baev)85735cblinter/unicorn: Implementno-confusing-array-withrule (#23638) (Shekhucb4fbb9linter/eslint: Implement no-unreachable-loop rule (#23975) (Todor Andonov)dc32112linter/eslint/no-constant-binary-expression: Check relational comparisons (#24088) (camc314)d963967linter/unicorn/no-array-sort: AddallowAfterSpreadoption (#24043) (Boshen)0a75682linter: Add per-rule timings for type-aware linting (#22488) (camchenry)743e222linter/react: AdddisallowedValuesoption forforbid-dom-propsrule (#23970) (Mikhail Baev)🐛 Bug Fixes
bdb51c7linter/jest/prefer-ending-with-an-expect: Validate config patterns (#24122) (camc314)45d607dlinter/react/forbid-component-props: Make allow/disallow lists optional in schema (#24024) (Boshen)pnpm/pnpm (pnpm)
v11.18.0: pnpm 11.18Compare Source
Minor Changes
Fixed an installed optional dependency being left without one of its own required dependencies. When a package reached through
optionalDependenciesis installable on the current system but one of its regulardependenciesis not, a lockfile-based install skipped that dependency and installed the parent anyway, so importing the parent failed withMODULE_NOT_FOUND. The dependency is now installed, and an install-check warning reports the incompatibility. A dependency is still only skipped when every path to it is optional, or when the package that pulls it in was itself skipped #13286.pnpm setupnow appendsPNPM_HOMEand the global bin directory to the GitHub Actions environment files (GITHUB_ENVandGITHUB_PATH), so later steps in the same job can runpnpm add --globaland other global commands #9191.Added support for
publishConfig.name, which publishes a package under a different name than the one its manifest carries in the workspace. It is for a project whose published name is already taken by a sibling project, which otherwise has to be renamed by a build step just before publishing. Only the published artifact is renamed — dependents,pnpm-lock.yaml, and release tooling keep addressing the project by its manifest name — and the new name reaches the packed manifest, the tarball filename, and everything that addresses the package at the registry: the already-published check ofpnpm publish -r, its registry selection, and the release-planning probes ofpnpm change statusandpnpm version -r#13345.pnpm self-updateno longer takes any instruction from the project it is run in:.npmrcorpnpm-workspace.yamlcan no longer redirect the download or attach credentials to it, and the project's default.pnpmfile.(c|m)jsis no longer loaded. Pnpmfiles from trusted sources (thepnpmfilesetting, the global pnpmfile, config dependencies) still apply.minimumReleaseAgesettings inpnpm-workspace.yamlno longer affectself-update. They still govern the project's own dependencies; forself-updatethe cooldown now comes from the built-in default, your global config, aPNPM_CONFIG_*environment variable, or a command-line flag. This fixesself-updatefailing inside a workspace that raises the cutoff while succeeding everywhere else, and stops a repository from either waiving the cooldown or keeping you on an outdated pnpm by raising it.trustPolicysettings and toci: a project can no longer weaken the trust check that guards the pnpm download, nor re-enable the confirmation prompt that a CI run suppresses.When
self-updaterefuses a version that is younger than the cutoff, an interactive run now offers to update anyway; non-interactive runs still fail. CI never prompts, even on a runner that attaches a TTY.Patch Changes
Fixed
pnpm licenses listto report every version when the same package is installed under multiple aliases pnpm/pnpm#13438.Sort
pnpm dedupe --checksnapshot changes for stable output across pnpm implementations.Strip Unicode formatting characters from registry- and manifest-derived terminal output.
Speed up installs after compatible catalog or direct dependency range changes by retaining the locked version without resolving the dependency graph again.
Speed up installs after safe override changes by reusing unambiguous compatible dependency resolutions, pruning obsolete dependencies, applying independent replacements and removals together, and handling parent-scoped
"-"overrides without full lockfile resolution.Installing a local
file:directory dependency with the global virtual store enabled no longer fails withTypeError: Cannot read properties of undefined (reading 'split')#13335.Local directory dependencies —
file:directories and injected workspace packages — now get a global-virtual-store slot of their own per project. They used to share one slot across every project that depended on a directory of the same name, so a project could end up linked to another project's copy of the dependency.The
Workspacecolumn ofpnpm update --interactivenow falls back to the project's path when itsnameis only whitespace, as it already did for a missing or empty one — all three render an equally blank label otherwise.Checking GitHub Actions dependencies for updates is now opt-in for every command. Neither
pnpm outdatednorpnpm updatereads the workflow files unless--include-github-actionsis passed orupdate.githubActionsis set totrueinpnpm-workspace.yaml. Reading them runsgit ls-remoteagainst every referenced repository, which fails in environments where GitHub is not reachable the way pnpm assumes (a GitHub Enterprise Server, a custom certificate authority, or an offline network) #13254.pnpm outdatedaccepts the--include-github-actionsoption too.pnpm update --interactivenow measures its table in terminal columns rather than in characters. A package name, workspace name, or version containing wide characters (CJK, most emoji) no longer knocks its row's columns out of line with the rest of the group, and a wide character in a version no longer aborts the command withSubject parameter value width cannot be greater than the container width#13357.The
Workspacecolumn ofpnpm update --interactiveis more informative in two cases. A dependency outdated at the same version in several workspace projects is offered as one choice, since selecting it updates every project — that choice now names all of them instead of only the first. And a workspace project without anameis now labelled with its path rather than left blank, so several unnamed projects can be told apart.An auto-installed optional peer is no longer hoisted at a version the workspace root's own dependency on that package excludes.
resolvePeersFromWorkspaceRootalready made the workspace root's specifier decide which version a missing required peer is installed at; the optional-peer picker ignored it and always took the highest version present anywhere in the graph. In a workspace whose root pinspostcss: 8.5.10, an importer that depends onwebpackand declares nopostcssof its own gotpostcss@8.5.22hoisted forterser-webpack-plugin's optionalpostcsspeer, leaving twopostcss@8.5.xinstances in the graph #13320.overridesnow also govern peers that pnpm auto-installs. Previously an override only rewrote dependencies declared in a manifest, so a peer nobody declares — installed becauseautoInstallPeersis on — resolved against its declared peer range and could bring in a second copy of the very package the override pinned. For example, withoverrides: { react: npm:react@19.2.0 }and a lonelucide-reactdependency, pnpm installedreact@18.3.1; it now installs the pinnedreact@19.2.0#13320.Under
resolvePeersFromWorkspaceRoot, a workspace root dependency declared withlink:orfile:(or the path form ofworkspace:, such asworkspace:../pkg) now satisfies another project's missing peer dependency at the linked package's own version, instead of being hoisted as a path. Those specifiers are relative to the project that declares them, so the same specifier reached a different directory — or none — from the project the peer was hoisted into, leaving a broken link. The root now has the same authority over the peer as it has when it declares the package with a version range #13373.Installs through a pnpr server now apply the project's whole verification policy.
minimumReleaseAgeExclude,minimumReleaseAgeIgnoreMissingTime,trustPolicy,trustPolicyExclude,trustPolicyIgnoreAfter, andtrustLockfilewere ignored, so excluded packages were still held back and a lockfile containing them could be rejected.trustPolicy: no-downgradeno longer fails withTRUST_POLICY_INCOMPATIBLE_WITH_PNPRwhen a pnpr server is configured.--frozen-lockfileand--no-prefer-frozen-lockfileare now honored on the pnpr path, instead of resolving and rewriting the lockfile anyway. SincefrozenLockfiledefaults totrueon CI, a CI install through a pnpr server now fails on an out-of-date lockfile rather than updating it.Workspace installs through a pnpr server no longer crash with
Cannot read properties of undefined (reading 'filter')after linking, whenminimumReleaseAgeis active #13275.Fixed
pnpm dedupeupdating valid catalog resolutions when another matching version exists in the lockfile.pnpm -r run "/pattern/" --no-bailno longer exits zero when one of a project's matched scripts fails and a later one passes. The run summary carries a single status per project, and the passing script overwrote the recorded failure.Restored the store block a first install prints, naming how packages were materialized and where the stores live #13315:
The root project's
pnpm:devPreinstallscript now runs before resolution and linking, as it does in pnpm 11. It is skipped under--ignore-scripts,--lockfile-onlyand--dry-run, bypnpm fetchandpnpm rebuild, and by a repeat install that is already up to date. Workspaces that use the hook to prepare state the install depends on — such as next.js, which generates a placeholdernextbin with it — were left with dependents linked against files that were never created #13313.Prevented
pnpm dedupe --checkfrom removing an incompatiblenode_modulesdirectory.pnpm update --workspaceno longer links dependencies the user never named:updateConfig.ignoreDependenciesconfigured no longer fails withERR_PNPM_WORKSPACE_PACKAGE_NOT_FOUNDfor a dependency that is only published to the registry. Such dependencies keep their specifiers, as they already did when no dependencies were ignored.Platinum Sponsors
Gold Sponsors
v11.17.0: pnpm 11.17Compare Source
Minor Changes
Added a new setting,
update.githubActionsServer, for specifying the base URL of the GitHub server that hosts the repositories of the GitHub Actions referenced by the workflow files (for example, a GitHub Enterprise Server). When the setting is not defined, the URL is read from theGITHUB_SERVER_URLenvironment variable, falling back tohttps://github.com. The URL must use thehttps://orhttp://protocol #13220.pnpm outdatedandpnpm updateno longer fail when the refs of a GitHub Action's repository cannot be read (for example, when the action's repository is private or hosted on a different GitHub server). Such actions are now skipped with a warning.Setting
update.githubActionstofalsenow makespnpm outdatedand the interactivepnpm updateskip GitHub Actions dependencies.Patch Changes
The token poll for web-based authentication no longer reads the body of non-OK or still-pending (HTTP 202) responses, and caps the token response body it does read at 64 KiB, so a malicious or compromised registry cannot exhaust memory through the poll pnpm/pnpm#12721.
Fixed
catalog:references in dependencies and overrides failing to resolve when installing through a pnpr server, which errored with "No catalog entry '' was found for catalog 'default'." even though the catalog entry existed. Also fixed a crash on Windows when installing a nested workspace member (e.g.packages/foo) through a pnpr server #13232.Republished every package: the tarballs published by the v11.13.1 through v11.16.0 releases were missing most of their compiled files due to a packing bug #13164.
Revert script ordering change for
pnpm run --sequential /regex/Support the
from-gitargument in thepnpm versioncommand.When the authentication URL cannot be rendered as a QR code (for example when it exceeds the maximum QR data capacity), web-based login now displays the URL alone with a warning instead of aborting authentication pnpm/pnpm#12721.
Platinum Sponsors
Gold Sponsors
v11.16.0: pnpm 11.16Compare Source
Minor Changes
pnpm version -randpnpm change statuscheck the registry for each release's current version; when that version is not yet publishedConfiguration
📅 Schedule: (in timezone Asia/Tokyo)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.