Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Feb 19, 2024

This PR contains the following updates:

Package Change Age Confidence Type Update
@nx/devkit (source) 22.3.122.3.3 age confidence pnpm.catalog.default patch
@nx/eslint-plugin (source) 22.3.122.3.3 age confidence pnpm.catalog.default patch
@nx/jest (source) 22.3.122.3.3 age confidence pnpm.catalog.default patch
@nx/js (source) 22.3.122.3.3 age confidence pnpm.catalog.default patch
@nx/plugin (source) 22.3.122.3.3 age confidence pnpm.catalog.default patch
@nx/react (source) 22.3.122.3.3 age confidence pnpm.catalog.default patch
@nx/storybook (source) 22.3.122.3.3 age confidence pnpm.catalog.default patch
@nx/vite (source) 22.3.122.3.3 age confidence pnpm.catalog.default patch
@nx/web (source) 22.3.122.3.3 age confidence pnpm.catalog.default patch
@nx/workspace (source) 22.3.122.3.3 age confidence pnpm.catalog.default patch
@types/node (source) 20.9.020.9.5 age confidence pnpm.catalog.default patch
node (source) 20.11.020.11.1 age confidence patch
nx (source) 22.3.122.3.3 age confidence pnpm.catalog.default patch
pnpm (source) 10.26.010.26.2 age confidence packageManager patch
pnpm (source) 8.10.28.10.5 age confidence uses-with patch
pnpm/action-setup v2.4.0v2.4.1 age confidence action patch
ts-jest (source) 29.4.129.4.6 age confidence pnpm.catalog.default patch

Release Notes

nrwl/nx (@​nx/devkit)

v22.3.3

Compare Source

22.3.3 (2025-12-19)

🩹 Fixes
  • misc: remove CNW A/B testing flow branching (#​33967)
❤️ Thank You

v22.3.2

Compare Source

22.3.2 (2025-12-19)
🚀 Features
  • angular: support ngrx v21 (#​33940)
  • angular: support cypress component testing with zoneless projects (#​33941)
🩹 Fixes
❤️ Thank You
nodejs/node (node)

v20.11.1: 2024-02-14, Version 20.11.1 'Iron' (LTS), @​RafaelGSS prepared by @​marco-ippolito

Compare Source

Notable changes

This is a security release.

Notable changes
  • CVE-2024-21892 - Code injection and privilege escalation through Linux capabilities- (High)
  • CVE-2024-22019 - http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks- (High)
  • CVE-2024-21896 - Path traversal by monkey-patching Buffer internals- (High)
  • CVE-2024-22017 - setuid() does not drop all privileges due to io_uring - (High)
  • CVE-2023-46809 - Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) - (Medium)
  • CVE-2024-21891 - Multiple permission model bypasses due to improper path traversal sequence sanitization - (Medium)
  • CVE-2024-21890 - Improper handling of wildcards in --allow-fs-read and --allow-fs-write (Medium)
  • CVE-2024-22025 - Denial of Service by resource exhaustion in fetch() brotli decoding - (Medium)
  • undici version 5.28.3
  • libuv version 1.48.0
  • OpenSSL version 3.0.13+quic1
Commits
pnpm/pnpm (pnpm)

v10.26.2: pnpm 10.26.2

Compare Source

Patch Changes

  • Improve error message when a package version exists but does not meet the minimumReleaseAge constraint. The error now clearly states that the version exists and shows a human-readable time since release (e.g., "released 6 hours ago") #​10307.

  • Fix installation of Git dependencies using annotated tags #​10335.

    Previously, pnpm would store the annotated tag object's SHA in the lockfile instead of the actual commit SHA. This caused ERR_PNPM_GIT_CHECKOUT_FAILED errors because the checked-out commit hash didn't match the stored tag object hash.

  • Binaries of runtime engines (Node.js, Deno, Bun) are written to node_modules/.bin before lifecycle scripts (install, postinstall, prepare) are executed #​10244.

  • Try to avoid making network calls with preferOffline #​10334.

Platinum Sponsors

Bit

Gold Sponsors

Discord CodeRabbit Workleap
Stackblitz Vite

v10.26.1: pnpm 10.26.1

Compare Source

Patch Changes

  • Don't fail on pnpm add, when blockExoticSubdeps is set to true #​10324.
  • Always resolve git references to full commits and ensure HEAD points to the commit after checkout #​10310.

Platinum Sponsors

Bit

Gold Sponsors

Discord CodeRabbit Workleap
Stackblitz Vite
pnpm/action-setup (pnpm/action-setup)

v2.4.1

Compare Source

Updated the bundled pnpm version to v7 to fix the ERR_INVALID_THIS error.

kulshekhar/ts-jest (ts-jest)

v29.4.6

Compare Source

Bug Fixes

v29.4.5

Compare Source

Bug Fixes
  • allow filtering modern module warning message with diagnostic code (c290d4d), , closes #​5013

v29.4.4

Compare Source

Bug Fixes

v29.4.3

Compare Source

Bug Fixes

v29.4.2

Compare Source


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from sullivanpj as a code owner February 19, 2024 02:09
@renovate renovate bot enabled auto-merge (rebase) February 19, 2024 02:09
stormie-bot
stormie-bot previously approved these changes Feb 19, 2024
@renovate renovate bot changed the title chore(deps): update dependency node to v20.11.1 chore(deps): update dependencies-non-major (patch) Jul 8, 2024
@renovate renovate bot force-pushed the renovate/patch-dependencies-non-major branch from 12f61a3 to 3367f76 Compare July 8, 2024 01:16
stormie-bot
stormie-bot previously approved these changes Jul 8, 2024
@renovate renovate bot force-pushed the renovate/patch-dependencies-non-major branch from 3367f76 to 0a17a43 Compare August 11, 2025 00:50
@renovate renovate bot force-pushed the renovate/patch-dependencies-non-major branch from 0a17a43 to 065be16 Compare December 29, 2025 00:44
@renovate renovate bot requested a review from a team December 29, 2025 00:44
@deepsource-io
Copy link

deepsource-io bot commented Dec 29, 2025

Here's the code health analysis summary for commits fb59a67..83c30f2. View details on DeepSource ↗.

Analysis Summary

AnalyzerStatusSummaryLink
DeepSource JavaScript LogoJavaScript✅ SuccessView Check ↗
DeepSource Shell LogoShell✅ SuccessView Check ↗

💡 If you’re a repository administrator, you can configure the quality gates from the settings.

@socket-security
Copy link

socket-security bot commented Dec 29, 2025

@renovate renovate bot force-pushed the renovate/patch-dependencies-non-major branch from 065be16 to a515467 Compare January 5, 2026 02:42
@renovate renovate bot force-pushed the renovate/patch-dependencies-non-major branch from a515467 to 83c30f2 Compare January 12, 2026 00:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants