Update npm dependencies - #109
Merged
Merged
Conversation
No767
approved these changes
Sep 14, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
19.2.18→19.3.019.2.7→19.3.01.81.0→1.82.026.8.1→26.8.21.81.0→1.82.00.9.13→0.9.1412.3.4→12.4.119.2.8→19.3.019.2.8→19.3.08.69.0→8.70.0Release Notes
oxc-project/eslint-plugin-oxlint (eslint-plugin-oxlint)
v1.82.0Compare Source
What's Changed
Full Changelog: oxc-project/eslint-plugin-oxlint@v1.81.0...v1.82.0
nodejs/node (node)
v26.8.2: 2026-09-09, Version 26.8.2 (Current), @aduh95Compare Source
Notable Changes
616bd3fa26] - doc: deprecateServer.prototype._listen2innode:net(Antoine du Hamel) #65593ae1801eb55] - meta: refine the security vuln posture for experimental features (James M Snell) #6543809feba74c8] - deps: update Undici to 8.10.2 (Node.js GitHub Bot) #657887efdbe3eb9] - deps: update OpenSSL to 3.5.8 (Node.js GitHub Bot) #65542Commits
d8aedd6584] - build: skip dockit on riscv64 (Stewart X Addison) #622511899c274eb] - build: activate correct default flags for riscv64 (Stewart X Addison) #65708ec8a3be996] - build: derive NODE_ARCH from target_cpu in the GN build (Shelley Vohr) #65491b73118a507] - build,win: remove LTO parallelisation limit (Stefan Stojanovic) #6553509feba74c8] - deps: update undici to 8.10.2 (Node.js GitHub Bot) #65788e47c432dd6] - deps: upgrade npm to 11.19.1 (npm team) #655732fd6ce36a9] - deps: update corepack to 0.36.0 (Node.js GitHub Bot) #6565349dec2767a] - deps: update googletest to36ba75f(Node.js GitHub Bot) #65654676174a071] - deps: update simdjson to 4.6.9 (Node.js GitHub Bot) #656552f1b7fa0bb] - deps: update perfetto to 58.2 (Node.js GitHub Bot) #6565612acd0ad15] - deps: update zlib to 1.3.2.1-motley-5eb4d7e (Node.js GitHub Bot) #6549448631c80fb] - deps: update archs files for openssl-3.5.8 (Node.js GitHub Bot) #655427efdbe3eb9] - deps: upgrade openssl sources to openssl-3.5.8 (Node.js GitHub Bot) #65542bdc75900ee] - doc: replacenode:modulesdocumentation header (René) #6580044c8a499ba] - doc: clarify return type offs.mkdtemp*(Antoine du Hamel) #65743025fb5eeb0] - doc: updatechangelog-makerinstructions for releasing (Juan José) #657075f64847afa] - doc: add stability status tocrypto.setEngine(Antoine du Hamel) #65746299dee0cb9] - doc: remove outdated TLS authorized warning (Tim Perry) #65597e97dcc0278] - doc: fix brokenusinglink in ffi.md (Soul Lee) #656322c9cc7d237] - doc: fix some broken links (Antoine du Hamel) #655830c330ec329] - doc: fix stale TOC in maintaining-dependencies (greenhead) #655239c522a3a69] - doc: refactor the AI guidelines (Joyee Cheung) #6526946cbf1bf8c] - doc: fix triggerAsyncId() comment in async_hooks example (soreavis) #64583788904ff78] - doc: fix fsPromises.watch overflow value (Matt Radbourne) #646053d06ff19e8] - doc: clarify stream direction in options.stdio note (Avocado) #65236d334838379] - doc: clarify signal listener behavior (Som Samantray) #65243d55a2bd56a] - doc: add test reporter event lifecycle diagram (sangwook) #63780c17dfc87de] - doc: discourage AbortSignal cleanup for long-lived resources (Efe Karasakal) #64342616bd3fa26] - doc: deprecateServer.prototype._listen2innode:net(Antoine du Hamel) #655934e6d7e0ca6] - meta: cleanup targos emeritus changes (Antoine du Hamel) #65738a70cfe1747] - meta: bump github/codeql-action/init from 4.37.3 to 4.37.9 (dependabot[bot]) #65714e43a0ad4ce] - meta: bump github/codeql-action/autobuild from 4.37.3 to 4.37.9 (dependabot[bot]) #6571799e06288f1] - meta: bump actions/checkout from 7.0.0 to 7.0.1 (dependabot[bot]) #6571889662762b3] - meta: bump cachix/install-nix-action from 31.11.0 to 31.11.1 (dependabot[bot]) #657196b8f078672] - meta: bump actions/setup-node from 6.4.0 to 7.0.0 (dependabot[bot]) #657206c6fb18e63] - meta: bump step-security/harden-runner from 2.20.0 to 2.21.0 (dependabot[bot]) #657210e002e859f] - meta: bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.9 (dependabot[bot]) #6572298aaffe4b9] - meta: bump github/codeql-action/analyze from 4.37.3 to 4.37.9 (dependabot[bot]) #65723d247cb2975] - meta: document collaborator automation (Filip Skokan) #65671ae1801eb55] - meta: refine the security vuln posture for experimental features (James M Snell) #65438fab81d15c3] - test: widen the gap in the resolver maxTimeout comparison (Shelley Vohr) #6578062e2a6265c] - test: fix the thread-spawn handshake in the WASI threads fixture (Shelley Vohr) #657807eb20b1810] - test: only count restarts after the write in watch emit-restarted test (Shelley Vohr) #6578014c3a77bc5] - test: ignore tunnel resets in proxy invalid-char-in-url test (Shelley Vohr) #65780ebc99e0560] - test: handle EPIPE in closed channel test (Christian Aurich) #657705e73a2ca79] - test: deflake test-permission-net-udp-handle (Christian Aurich) #65767beb669f7de] - test: deflake test-runner-coverage (Christian Aurich) #65728ef4b6bfa62] - test: set type=none on IBM i for empty source (Abdirahim Musse) #65545027eef0691] - test: deflake WASI poll timing checks (Filip Skokan) #65672a352b0e2fe] - test: skipfs-watch-recursive-delete-raceon AIX (Antoine du Hamel) #65698f9ce35aa43] - test: deflake test-inspect-async-hook-setup-at-inspect (Christian Aurich) #6558432281cec7b] - test: deflake test-watch-mode-restart-esm-loading-error (Christian Aurich) #6562379be5d61be] - test: avoid orphaned child on Windows abort test (Kirill Saied) #654518972b8540b] - test: fix link-local dgram scope assertion (Filip Skokan) #65629b7cd1d96de] - test: riscv64: skip node-api sea test (Stewart X Addison) #655697eeb9d0e57] - test: mark platform-specific tests as flaky (Filip Skokan) #65562649ac82bda] - test: account for varied OpenSSL CCM final behaviours (Filip Skokan) #65542050fb1a15d] - tools: bump @humanfs/node from 0.16.7 to 0.16.8 in /tools/eslint (dependabot[bot]) #657575314dda396] - tools: bump browserslist from 4.28.4 to 4.28.8 in /tools/eslint (dependabot[bot]) #657585938a08929] - tools: do not hardcodeyamllintpath (Antoine du Hamel) #65747d8408f7415] - tools: refine contributor guidance workflow (Filip Skokan) #65745196e372b69] - tools: bump the eslint group in /tools/eslint with 4 updates (dependabot[bot]) #657167e986b09f6] - tools: do not flag force push as invalid message (Antoine du Hamel) #65700837ce2ccef] - tools: do not hardcode path to Ruff (Antoine du Hamel) #656811c7149a96a] - tools: retry first-time contributor query (Filip Skokan) #65648bd310a2bea] - tools: query first-time contributor status (Filip Skokan) #65592ab7b57e547] - tools: offset GitHub crons by 3 minutes (Michaël Zasso) #6561262ece28eae] - tools: label PRs lacking second approval (Filip Skokan) #6553868227b4029] - tools: welcome first-time contributors (Filip Skokan) #65533490dc93e37] - tools: enable concurrency for eslint (Huáng Jùnliàng) #62352d794676217] - typings: fix fs_event_wrap start filename type (leah-1ee) #6566129e2b5a325] - typings: add fs_event_wrap internal binding types (leah-1ee) #656616357c8f56e] - typings: add stream_pipe internal binding types (Seongeun Lee) #65664569720ac7f] - typings: add profiler internal binding types (Seongeun Lee) #6566052ae89c69d] - typings: add ffi internal binding types (Donghoon Kang) #6573422c7469062] - typings: update zlib binding declarations (이혜미) #65639oxc-project/oxc (oxlint)
v1.82.0Compare Source
🚀 Features
6a0e19clinter/eslint/no-unmodified-loop-condition: SupportcheckConditionalExpressionsoption (#26249) (camc314)millionco/react-doctor (oxlint-plugin-react-doctor)
v0.9.14Compare Source
Patch Changes
#1783
1239043Thanks @aidenybai! - Upgrade oxlint to 1.81 and oxc-parser to 0.148.#1762
ff7dd67Thanks @skoshx! - Avoideffect-needs-cleanupdiagnostics for owned chained timers, guarded post-await timers, and listeners released through an abort handler.#1763
0fbef9bThanks @skoshx! - Fix anasync-defer-awaitfalse positive on exactliveandisLiveliveness guards without exempting unrelated names that only contain the same text.#1761
6ac8b71Thanks @skoshx! - Fix false positive innextjs-no-side-effect-in-get-handlerwhen locally-builtHeadersobject is passed to a same-file helper that mutates it.The rule now transfers locally-created response object safety through the exact same-file helper call. Calls that pass external state to the same helper remain reportable.
Fixes #1757
#1781
dfcde10Thanks @aidenybai! - Speed up large-repository scans: reuse warm oxlint worker processes across projects, overlap project discovery with linting, and trim rule hot paths (2.4–5.5x faster wall-clock on the large-repo corpus).#1801
fd64d26Thanks @aidenybai! - Stop reporting local service.use()methods as React hooks. Preserve diagnostics for React namespace calls, including aliases and CommonJS imports.Only recommend
setAnimationLoopwhen a recursive animation frame callback renders through a known Three.js renderer. Leave independent 2D canvas and DOM loops alone, including files that also import Three.js.#1750
576d756Thanks @skoshx! - fix: respect "use no memo" directive in react-compiler-no-manual-memoization ruleWhen a function or module has a React Compiler opt-out directive, the compiler skips optimization, so manual memoization can still be necessary. The rule now respects
"use no memo", its"use no forget"alias, and local components passed tomemo.Fixes #1749
#1760
2e3f6ebThanks @skoshx! - Exempt magic-link delivery mutations fromquery-mutation-missing-invalidationwhile keeping generic send, notification, and email mutations reportable.#1802
c9e3e15Thanks @aidenybai! - Retire 33 low-value rule IDs while keeping them registered as silent compatibility entries. Make 26 cleanup, migration, performance, and security-review rules opt-in. Existing rule configurations still load; default scans no longer report these recommendations as defects.pnpm/pnpm (pnpm)
v12.4.1: pnpm 12.4.1Compare Source
pnpm 12.4.1 fixes installs that failed on filesystems refusing hard links or clones, on Android, and under
nodeLinker: hoisted. Repeat installs are faster.Patch Changes
Installing packages
pnpm installno longer fails withOperation not permittedwhen the filesystem refuses a hard link or a copy-on-write clone #14722. UnderpackageImportMethod: autoandclone-or-copy, pnpm copies the file instead. EdenFS checkouts, which have no hard links, and rootless containers, which refuse the clone syscall, both hit this. An explicitpackageImportMethod: hardlinkorclonestill reports the error.pnpm also copies a package file whose store entry has reached the filesystem's limit on names for one file, 1024 on NTFS and 65000 on ext4. Such a file failed the install under
packageImportMethod: hardlink, and underautoit stopped pnpm hard linking for the rest of the install.pnpm installno longer writes a package file through a symlink left at the path it is importing to. Copying such a file overwrote whatever the link pointed at, and created that file when the link pointed nowhere. An executable package file also made the link's target executable.Fixed
pnpm installandpnpm dlxon Android. Registry requests crashed because pnpm found no system CA certificates, so pnpm uses bundled ones there #14777. Imports also failed with "Permission denied" on filesystems that deny hard links and reflinks, and now fall back to copying #14780.pnpm installno longer fails with "Invalid cross-device link" while preserving a package's nestednode_modulesdirectory during a Docker build #14758.pnpm installno longer fails on a package tarball that carries a file at the archive root, such as the._*entries macOStaradds #14701. The file is installed at the root of the package.A
file:tarball packed without the usualpackage/directory is now recorded under the name and version from its ownpackage.json. It was recorded under the alias the dependency was given, at version 0.0.0.Under
nodeLinker: hoisted,pnpm installno longer re-imports packages that are already in place. A repeat install replaced the wholenode_modulestree and reportedPackages: +N. A package is still imported when its directory is missing, when itspackage.jsonno longer carries the installed version, when it is afile:dependency, and when it is patched. Lifecycle scripts no longer run again for a package left in place, andpnpm rebuildand a change toallowBuildsstill reach it.pnpm installnow runs a dependency's build scripts again when its side-effects cache entry has no files to restore #14717. Such builds were skipped and nothing was put in their place, so a script whose whole effect lands outside its own package directory, such as a git hook installer, never took effect. pnpm no longer publishes empty artifacts to the shared side-effects cache either.Resolving and linking dependencies
pnpm install,pnpm add, andpnpm dedupenow applyignoredOptionalDependencies#14729. Matching optional dependencies are left out of the lockfile and are not installed. pnpm 12 installed them whenever it resolved dependencies from scratch.pnpm installno longer links a transitive dependency to a workspace package whenlinkWorkspacePackagesistrueand the dependency is declared with a plain version range #14781. EnablingpreferWorkspacePackagesdoes not change this. SetlinkWorkspacePackages: deepto link them.pnpm installno longer leaves dangling dependency links in workspace packages located above the workspace root #14726.pnpm installandpnpm addno longer leave a dangling symlink innode_moduleswhen a project starts depending directly on a package that the lockfile holds only as a transitive dependency with resolved peer dependencies #14714.pnpm dedupenow keeps a compatible auto-installed peer when another workspace project depends on a newer major #14697. Repeated runs alternated between compatible and incompatible peer versions.pnpm peers checkno longer reports a peer dependency declared asworkspace:^,workspace:~, or a bareworkspace:as unmet #14770. pnpm reported these as unmet whatever version the linked workspace project supplied.Performance
Sped up repeat installs #14540. pnpm checks the store's files only for the packages it links into
node_modules, instead of every package in the lockfile. Creating the command shims innode_modules/.binmakes about 1,500 fewer filesystem calls in a 76 project workspace. Installs that use the global virtual store read their slot paths from the cache directory instead of deriving them every time. Verifying a large lockfile also allocates less memory.Sped up
pnpm installin Cargo workspaces with many member crates. Repeated installs reuse verified Cargo checksum metadata.Installing several packages from the same Git repository and commit now downloads the source once per install #14725. Each package still runs its prepare scripts in its own copy of the checkout.
Running scripts and tasks
pnpm now passes Ctrl+C on to the script or command it started and waits for it to shut down #14723. pnpm exited first, so a script that was still writing landed on the shell prompt.
pnpm run "/pattern/" --no-bailnow lets every matched script finish after one of them fails #14718. The command exits withERR_PNPM_RUN_FAILED, and its message lists the scripts that failed in the order they were selected.pnpm pipelineno longer fails on a project that tracks a symlink, such as aCLAUDE.mdpointing atAGENTS.md#14692. Changing a symlinked input's target invalidates that task's cache, andpnpm pipeline --no-cacheno longer hashes task inputs.Commands
pnpm add -g,pnpm update -g, andpnpm remove -gno longer change global bins or install directories after reading only part of an installed package group #13796. If any declared package manifest is missing, malformed, or unreadable, pnpm now fails before it activates or removes anything and leaves the existing global installation intact.pnpm dedupenow processes every workspace project by default, including workspaces that keep a separate lockfile per project #14732. Workspace filters select which projects it processes, and--fail-if-no-matchexits with an error when no project matches.pnpm update <name>@<version>now keeps the range operator the manifest declares #14745. Runningpnpm update react@19.3.0on"react": "^19.2.8"writes"react": "^19.3.0". Ajsr:entry keeps itsjsr:prefix, and a plainpnpm updatenow moves ajsr:range the way it moves an npm range.pnpm --filterdirectory selectors now support?wildcards and character classes such as[ab]. A*or?wildcard no longer selects a directory whose name starts with a dot, as on pnpm 11.pnpm deploy --legacynow prefers the dependency versions pinned in the source workspace lockfile when they still satisfy the deployed project's range #13857.pnpm sbomnow leaves out a package's author field when the manifest author name is empty or contains only whitespace #14685. In a filtered or split workspace run, only a project with noauthorfield inherits the workspace root's author.pnpm sbom --sbom-format spdxnow writescreationInfo.createdwith whole seconds, such as2026-09-08T10:38:21Z#14684. The fractional seconds it carried were rejected by strict SPDX consumers.Configuration
The
updateConfigpnpmfile hook now receives the resolved configuration, including settings that came from.npmrc, the command line, or a default #14676. Scoped registries are reported underregistriesByScope, and a hook may rewrite that map to change where packages are fetched from. Registry credentials are reported underconfigByUri, as pnpm 11 reports them. An unset setting is left out rather than reported asnull.pnpm audit --fixand theminimumReleaseAgeStrictapproval prompt now keep the comments inminimumReleaseAgeExcludewhen they append an entry to it inpnpm-workspace.yaml. The rest of the list is left as written, and thetrustPolicyExcludePruneandminimumReleaseAgeExcludePrunecleanups keep the comments of the entries they retain.pnpm installandpnpm dedupenow run those cleanups too #14759. Onlypnpm add,pnpm update, andpnpm removepruned the entries that the freshly written lockfile no longer resolves.pnpm config set --global node-download-mirrorsno longer rejects the key #13611. The global config file already acceptednodeDownloadMirrors, but the command refused to write it.NO_PROXYentries that start with a dot, such as.npmjs.org, now bypass the proxy for the domain and its subdomains #14686.pnpm no longer creates a project
pnpm-lock.yamlwhendevEngines.packageManager.onFailisdownloadand lockfile writing is off throughlockfile: falseor--no-lockfile#14728. pnpm still switches to the pinned version.pnpm now writes
node_modules/.package-map.jsononly whennodeExperimentalPackageMapis enabled. Nothing reads the file without that setting, and an install that stops writing the map removes the one a previous install left.Windows
pnpm pipelineno longer fails with intermittent access denied errors when concurrent tasks save their cache entries on Windows.Windows filesystem operations now retry permission errors for up to one second #14682. A permanent permission error delayed the failure by a minute. Sharing and lock violations keep their one minute retry budget.
Messages and output
pnpm now warns when the root
package.jsondeclares a non-emptyworkspacesarray and the project has nopnpm-workspace.yaml#2255. Such an install linked no project and said nothing about why.ERR_PNPM_PACKAGE_MANAGER_REMOVE_MODULES_DIRnow names the file or directory innode_modulesthat pnpm could not clean up. It reported only the underlying OS error, such as "Access is denied (os error 5)".pnpm --helpno longer describes pnpm as experimental.Platinum Sponsors
Gold Sponsors
v12.4.0: pnpm 12.4Compare Source
Minor Changes
pnpm can now manage npm, Python, and Cargo dependencies in the same workspace. Enable
python.enabledorcargo.enabledinpnpm-workspace.yaml, then usepnpm installto install them together.pnpm add pypi:<package>. pnpm usespyproject.toml,pylock.toml, and a managed.venv. Frozen and offline installs are supported, andpnpm runandpnpm execmake the environment's executables available #14566.pnpm add crate:<package>. pnpm supports crates.io and custom sparse registries configured withcargo.indexUrl. Registry authentication supports pnpm credentials and, for crates.io,CARGO_REGISTRY_TOKENor$CARGO_HOME/credentials.toml.Both ecosystems support faster dependency resolution through
pnprServer, with local resolution as a fallback when the server does not support it.Added
pnpm pipeline [name]to install frozen dependencies and run workspace tasks declared inpipelines. It selects affected projects, runs their task graph, and continues running tasks after a task fails.Tasks support
inputs,outputs,env, andcachesettings. Cached results restore task outputs and replay logs. Cargo tasks can reuse local build state between worktrees withtasks.<name>.cargoTargetDir. SetincludeWorkspaceRoot: trueto include root tasks.Use
pnpm pipeline --dry-runto preview the task graph without installing configuration dependencies or running workspace hooks.Added support for Android on arm64 and x64, FreeBSD on x64, and Linux on ppc64le, s390x, and RISC-V (riscv64 with glibc) #14431, #14597, #7582.
Added
trustPolicyExcludePruneto automatically remove unused versions and packages fromtrustPolicyExcludewhen runningpnpm add,pnpm update, orpnpm remove. It is disabled by default. Package name patterns such as@scope/*are kept, and cleanup is skipped whensharedWorkspaceLockfileisfalse.Added
pnpm change checkfor CI validation of package versions against theversioning.epicsbands andversioning.fixedgroups inpnpm-workspace.yaml. It reports all violations, including packages that are not part of the current release.Patch Changes
Registry metadata is now kept separate for registries with different URL paths or schemes. This prevents installs from using another registry's package versions or tarball URLs, and keeps metadata fetched over HTTP from being reused for HTTPS #13558.
The first install after upgrading refetches registry metadata. The package store is unchanged.
pnpm cache viewnow shows full registry URLs. Scripts that parse the directory names frompnpm cache list-registriesorpnpm cache listneed updating.Patches that add build scripts or a
binding.gypnow trigger a build, subject to build approval. Unapproved builds appear under "Ignored build scripts" #14648.Build scripts can now be rejected before installing a package with
pnpm add --allow-build=!<pkg>, including global installs.pnpm approve-builds <pkg>andpnpm approve-builds !<pkg>also save decisions when no packages are awaiting approval. They warn if the named package is not awaiting approval #14067.A registry configured in
.npmrcnow takes precedence over registry settings saved bypnpm loginin the globalconfig.yaml. This fixes installs using the wrong registry after login #14614.Large downloads over slow connections no longer time out while data is still arriving.
fetch-timeoutnow limits how long a request can go without making progress #14604.Sped up installs in workspaces with many projects when reusing a warm global virtual store #14540.
pnpm deployis faster in large workspaces and no longer fails withERR_PNPM_LOCKFILE_CONFIG_MISMATCHwhen the project includes a.pnpmfile.mjs#14539, #14671.pnpm add --workspace <pkg>works again. It saves the dependency with theworkspace:protocol and links it from the workspace. The command fails if no workspace project provides the package #14602.pnpm addandpnpm installnow accept protocol-prefixed selectors such asjsr:@scope/pkg,npm:pkg@^1.0.0, andworkspace:pkg@*#14590. Installs with JSR dependencies in the lockfile also no longer fail withERR_PNPM_META_FETCH_FAIL#14649.Boolean flags now accept explicit inline values. For example,
pnpm install --prod=falseinstalls devDependencies, while--prod=trueskips them #14553.pnpm install <pkg>now accepts--offlineand--prefer-offline, aspnpm add <pkg>already did #14194.Fixed
pnpm install --frozen-lockfilerejecting a freshly generated lockfile when overrides use relativefile:orlink:paths in a workspace #14555.Fixed installs with config dependencies failing on symlinked lockfiles, such as those used by Bazel and Nix, when the config dependencies have not changed. Updates that would write through a symlink remain disallowed. Updating config dependencies also preserves lockfiles that start with a byte order mark #14372.
Fixed package manager version pins being written to the wrong lockfile when
lockfileDiris set. The pins also remain consistent across commands when version switching is disabled, avoiding unnecessary lockfile changes #14633, #14575.pnpm importnow respectslockfileDirand branch lockfiles without modifying other lockfiles. Failed imports restore the destination lockfile #14563.pnpm patch-commitnow produces valid patches when files are added or deleted.pnpm installalso accepts patches that delete files without listing their contents, and patch files with CRLF line endings #14559, #14557.Fixed version ranges with partial upper bounds. For example,
<=16now includes all 16.x versions, and>=0.11 <=3correctly accepts 3.0.1 #14419.Workspace package patterns now support
.and..segments and repeated slashes. Patterns such as./packages/*and exclusions such as!./packages/foonow match correctly #14571.packageConfigssettings now apply to the specified projects whensharedWorkspaceLockfileisfalse, includingoverrides,hoist,modulesDir,saveExact, andsavePrefix. Workspaces with a shared lockfile report which entries were ignored #14556.pnpm runandpnpm execno longer report a changed workspace structure after a successful install whensharedWorkspaceLockfileisfalseandverifyDepsBeforeRunis enabled #14588.Commands run from a project's subdirectory now find the nearest ancestor with a manifest. This fixes commands such as
pnpm binreturning paths under the wrong directory.pnpm initstill creates its manifest in the current directory, andpnpm execstill runs there #14622.Relative
scriptShellpaths inpnpm-workspace.yamlnow resolve from the workspace root, including when scripts run in nested packages. Bare command names such asbashstill usePATH#14422.Fixed installing the pnpm version pinned in
packageManagerwhennodeLinkerishoisted. Managed Node.js, Deno, and Bun installations also work when the global config usesnodeLinker: hoisted#14595.The JavaScript pnpm can again switch to a project's pinned pnpm version on platforms without a native binary for that version, such as Alpine Linux with pnpm 10 or Intel Macs with pnpm 11. If a native pnpm version does not support the platform, the error now names the missing target #13622.
Provisioning Yarn 6 now uses
GH_TOKENorGITHUB_TOKENwhen available to avoid GitHub's anonymous API rate limit in CI. Tokens are only sent whenstrict-sslis enabled.Fixed concurrent installs sharing a global virtual store on macOS failing with "failed to import ... No such file or directory" #14560.
Fixed
pnpm setupfailing withERR_PNPM_DIRECTORY_FETCHER_PATH_ESCAPEon Windows. Localfile:dependencies whose directories are symlinks or junctions are now packed correctly #14618.On Windows, installs now retry replacing command shims temporarily locked by another process [#14549](https://redirect.github.com/pnpm/pnp
Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.