Skip to content

chore(deps): update all non-major dependencies - #137

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/all-minor-patch
Sep 7, 2026
Merged

chore(deps): update all non-major dependencies#137
renovate[bot] merged 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Pending Age Confidence
JetBrains/junie-github-action action patch v1.7.5v1.7.7 v1.7.8 age confidence
argue-cli devDependencies minor 3.1.03.2.0 age confidence
dprint devDependencies minor ^0.56.0^0.57.0 0.57.4 (+2) age confidence
oxlint (source) devDependencies minor 1.80.01.81.0 age confidence
pnpm (source) uses-with minor 11.24.011.25.0 11.26.0 age confidence

Release Notes

JetBrains/junie-github-action (JetBrains/junie-github-action)

v1.7.7

Compare Source

What's Changed

Full Changelog: JetBrains/junie-github-action@v1.7.6...v1.7.7

v1.7.6

Compare Source

What's Changed

Full Changelog: JetBrains/junie-github-action@v1.7.5...v1.7.6

TrigenSoftware/Argue (argue-cli)

v3.2.0

Compare Source

Features
  • add [String] and [Number] option types to collect repeated options (#​396) (23d6fb9)
dprint/dprint (dprint)

v0.57.1

Compare Source

Changes

  • fix: scan hidden directories with dprint init (#​1240)
  • fix: recommend --minimum-dependency-age=0 when an older version is selected (#​1238)
  • fix: accept --minimum-release-age as an alias of --minimum-dependency-age (#​1239)
  • ci: generate GitHub artifact attestations (#​1067)

Install

Run dprint upgrade or see https://dprint.dev/install/

Verification

These artifacts have build provenance attestations.
Verify a download with the GitHub CLI:

gh attestation verify dprint-x86_64-unknown-linux-gnu.zip --repo dprint/dprint

Checksums

Artifact SHA-256 Checksum
dprint-x86_64-apple-darwin.zip f1529d394126ebf0104af12290345b662196f8b9604d2d578cef91a8b6057f9d
dprint-aarch64-apple-darwin.zip 3113fb58a126df96c95653638f068fe430f342623dfdf08e3fa32d4e704194ea
dprint-x86_64-pc-windows-msvc.zip 28aa22ea2b009a3d49f9c570bc2a1697af8dff9117cd1cbb7c39deab9f5d5269
dprint-x86_64-pc-windows-msvc-installer.exe 8e10f452e73abed2d25769fc23ec0d17a45cf84931cf04a6c2afd77361bb945d
dprint-aarch64-pc-windows-msvc.zip 08b93837ea90488dbb23ab115fffd3699427b8917013b3b33bd7aedda5b07ca5
dprint-x86_64-unknown-linux-gnu.zip 4117443cc5fade617dd5f4850cc2fa6b2902136052ef313ee20947036c3554cc
dprint-x86_64-unknown-linux-musl.zip d956144fa8d873dc43c37d1811b3f8c42701f74bb0be7c25c543b189ab53d6c0
dprint-aarch64-unknown-linux-gnu.zip a73695f6407c6c36adef5971053f81ccef13b0a04b6b1da98312ae0ee5332edd
dprint-aarch64-unknown-linux-musl.zip 371b63109cbd7b34e179fc3af0815f65a5d9f3a560d2a245a78ef99ec71b3f9e
dprint-riscv64gc-unknown-linux-gnu.zip 1dcf69d277c044e1e52afdb23fa0fb5152678955b41952721d801d3407d3ddaa
dprint-loongarch64-unknown-linux-gnu.zip 147ca90b1348036344c9e4e45f0985acb37c18f36a9d3a1f37d4f553ebb80d58
dprint-loongarch64-unknown-linux-musl.zip 5f61c6898dfb3db8e54f9405727d168eb512a403d941ddd5b725c328bb8d5bc6
dprint-powerpc64le-unknown-linux-gnu.zip a7d21498b38598c9898e61b1dc8a37cdaab15499c58390bbf9100da1864342f7
dprint-powerpc64le-unknown-linux-musl.zip b9f1d4f89b51f3d291d2be61132f81f451d06e9a3e33aab2510b69564a8d3648
dprint-aarch64-linux-android.zip bc8b058ab2d4df47b0e04ddbae47d522569ba744372cd2e399df30cf20783fc1
dprint-x86_64-linux-android.zip ccdf05807e50256dd1ffbb13a8ec101042e654680e2713ff58fe1b2b6855c0c0

v0.57.0

Compare Source

Changes

  • feat: add a shebangs config for routing extensionless scripts to a plugin (#​1230)
  • feat: add --minimum-dependency-age for npm dependencies (#​1228)
  • feat: add --diff-format unified to dprint check and dprint fmt --diff (#​1232)
  • feat: add dprint check --json flag (#​1231)
  • perf: match glob patterns on the reader threads (#​1234)
  • perf: cheaper per-file plugin resolution (#​1233)

Install

Run dprint upgrade or see https://dprint.dev/install/

Checksums

Artifact SHA-256 Checksum
dprint-x86_64-apple-darwin.zip 41b6bb07d121d0506edd85d8176caf3d3909648089ee6c0b8b4f9c896791c14f
dprint-aarch64-apple-darwin.zip 14bdbfb9b1e3ebd614d5ec08a068b04b0d0370d70c112723003dd9103a4c0c3a
dprint-x86_64-pc-windows-msvc.zip 90e81a6106af4571893587acb4a1b1baa6b0879c60eec36497a08c03127410d1
dprint-x86_64-pc-windows-msvc-installer.exe f023d1770c2cf8a92471e7c95e2db184359911c14c2c070c9efc6cbb70ccc030
dprint-aarch64-pc-windows-msvc.zip 42db2e31a7434c6d205fb71ec39b76a5dc1bd09781376ed082f804946cf5f391
dprint-x86_64-unknown-linux-gnu.zip f6275d992123e94a96ebfd0a0921aee6c7f37314e54f30ff360764cde44677bc
dprint-x86_64-unknown-linux-musl.zip 981a98fd4d245be8dda9bfb3d52a826d532b3290a559cb335970cebca7bf0b45
dprint-aarch64-unknown-linux-gnu.zip 76f01495dae94d531e9ebd5e97977ae9a8edc8d7fc8ae8a479d34715617cb69d
dprint-aarch64-unknown-linux-musl.zip 4458fb5ad357c2735210470a91e3f2a95abafcd7f2d7840cb94afc96dd11fbfe
dprint-riscv64gc-unknown-linux-gnu.zip 74eb0b910e6de3baa814d67da8cc8cf0774725d7cb652c9ade56904b78bcfad0
dprint-loongarch64-unknown-linux-gnu.zip b93091e0113d877dd4cc72ae161d63bea7e02407008c3bb1e2442f9dd11f6a22
dprint-loongarch64-unknown-linux-musl.zip 5ea6e8459078d9bf1959fe2362cabdcb317e2cd7ef44e70e29e3300e623f6fba
dprint-powerpc64le-unknown-linux-gnu.zip b754b6fdc4f4f3ebdf53b02b41eb75ca272a7f641ac508913d595446453fdb56
dprint-powerpc64le-unknown-linux-musl.zip 239999452ff79f6325e178be69913dd95ed428c05d1e8840e53ae42d5eed268d
dprint-aarch64-linux-android.zip 1a702314e82f7544ef932f1fdfa597f9c65192e5a15c3f10c57288bd0dab5030
dprint-x86_64-linux-android.zip b4de632316883ab95b4d286baee26ed09b0b6b4da11f899bffc210ed7c4dbd7c
oxc-project/oxc (oxlint)

v1.81.0

Compare Source

📚 Documentation
  • d5be037 linter/typescript/switch-exhaustiveness-check: Clarify default case comment pattern (#​26100) (camc314)
pnpm/pnpm (pnpm)

v11.25.0: pnpm 11.25

Compare Source

Minor Changes

  • Added an opt-in proof of concept that lets installs reuse a dependency's build output across machines, by publishing and restoring signed, organization-scoped artifacts through pnpr instead of running the lifecycle scripts locally.

    Configure it with the new remoteSideEffectsCache setting. A workspace names the eligible organization and packages; everything describing the act of signing — publish, keyId, builderId, trustedKeys, privateKey and the provenance fields — is refused in pnpm-workspace.yaml and read from the global config file or the environment instead.

  • Added macOS and Windows x64 and arm64 support to remote shared build artifacts pnpm/pnpm#13771.

  • Added the audit.ignorePrune setting. When set to true, pnpm audit --fix removes ignored GHSA entries that no longer appear in the audit report.

  • Generalized the experimental shared-artifact protocol so candidates and signed payloads identify a discriminated subject. Dependency side effects use package and source-integrity subjects, while workspace tasks use project and task subjects.

    This changes shared-artifact request bodies and signed payloads. A pnpr server and its clients have to be on matching versions.

  • pnpm init now pins the latest pnpm version, instead of the version of pnpm that ran the command. A project scaffolded by an outdated pnpm therefore no longer inherits that staleness through its own devEngines.packageManager / packageManager pin #​7490.

    The version is read from the latest tag on the package-manager registries. When that lookup cannot answer — no network, an unreachable or slow registry, offline, or a latest that the minimumReleaseAge / trustPolicy settings reject — pnpm init pins the running version as before, and never fails or hangs on the lookup. A latest that is older than the running pnpm is never pinned either.

  • A scope set in a project's pnpm-workspace.yaml is now ignored, with a warning naming where to set it instead. pnpm login records the scope as a @scope:registry route in the machine-global auth.ini, which outranks ~/.npmrc in every project — so a repository-committed file could redirect a scope such as @acme for all of a user's other projects after one routine login. Use --scope, the PNPM_CONFIG_SCOPE environment variable, or the global config file instead #​13557.

  • Verified remote build artifacts are persisted in the shared store with their signed origin metadata. Later installs reverify the artifact against current trust, policy, platform, and source before reuse, while invalid remote variants are quarantined per channel (pnpm/pnpm#13771).

  • Persist completed recursive tasks so --resume-from skips exactly the work that passed during a matching interrupted or failed pnpm -r run / pnpm -r exec invocation. When no compatible state exists, pnpm retains its graph-based resume behavior.

  • Allowed pnpm update --patches to refresh registry revisions through a configured pnpr server while retaining locked package versions.

  • Added explicit registry revision selection with <version>+rN and pnpm update --patches for refreshing revision artifacts without changing package versions. Registry-backed lockfile policy checks recognize historical revisions, and pnpr now preserves safe revision histories from upstream registries.

  • Workspace install, rebuild, pack, publish, stage, and lifecycle work now starts as soon as its dependencies finish instead of waiting for an unrelated topological group.

  • pnpm stage approve now approves several staged packages at once. Run it without a stage id to pick from the staged versions interactively, or pass a list of stage ids. The whole batch is approved with a single one-time password, and pnpm asks for a new one only once the registry stops accepting it. Inside a workspace, the selected packages are approved in dependency order, and a package whose workspace dependency could not be approved is skipped instead of being published against a dependency that never reached the registry.

  • Added per-task concurrency limits to workspace task orchestration. Set tasks.<name>.concurrency in pnpm-workspace.yaml to limit how many instances of that task may run across workspace projects at once:

    tasks:
      build:
        concurrency: 2
  • Added support for registry replacement tarballs using standard integrity values, explicit revision fields, registry routing from the registries setting, non-redirecting integrity-addressed URLs, canonical safe-integer revision numbers, and pnpr proxying for immutable upstream revision artifacts.

  • sideEffectsCache now declares the whole of how a package's build output is reused — whether one is restored, whether one is saved, and the remote tier that shares it between machines:

    sideEffectsCache:
      read: true
      write: true
      remote:
        org: acme
        packages: ['native-addon']

    sideEffectsCache: true, sideEffectsCacheReadonly, remoteSideEffectsCache, and its organization field all keep working. Where a field is set under both spellings the one above wins; where it is set under only one, it is kept.

    Two behaviors change, both bringing this CLI in line with what the Rust one already did: sideEffectsCacheReadonly: true now blocks writing to the cache, and setting it alongside sideEffectsCache: false gives a read-only view rather than switching the cache off entirely. A cache can also be declared write-only now, to populate one the run does not read.

  • Workspace task orchestration (pnpm/rfcs#23). pnpm -r run and pnpm -r exec now schedule per task instead of in topological chunks: a task starts as soon as the tasks it depends on have finished, so a project no longer waits for unrelated projects that happen to share its chunk.

    A new tasks section in pnpm-workspace.yaml declares what a task depends on, using the ^ convention:

    tasks:
      build:
        dependsOn: ['^build']
      test:
        dependsOn: ['build']
      lint: {}

    ^name means the named task in each of the project's workspace dependencies; a bare name means the task in the same project; an entry with no dependsOn declares an empty dependency list. A task with no entry behaves as dependsOn: ['^<its own name>'], which is exactly what the previous chunked ordering implied — an unconfigured workspace gets the scheduler improvement and nothing else changes meaning. A project without the script is reported skipped and passes its edges through to its own dependencies, so a scriptless package does not sever a chain.

    Also part of this change:

    • A dependency cycle among the tasks of a run is now an error naming the participating tasks (ERR_PNPM_TASK_CYCLE) instead of silently running in an arbitrary order. Setting ignoreWorkspaceCycles: true downgrades the error to a warning: the cycle's tasks run in an arbitrary order relative to each other.
    • --resume-from now skips exactly the transitive dependencies of the anchor package; work unrelated to the anchor still runs.
    • Under --no-bail, tasks whose dependencies failed are reported as skipped, not failed, and do not add to the exit code.
    • With --bail (the default), the first failure still ends the run at once and nothing new is dispatched — including scripts already queued behind the concurrency limit.
    • pnpm -r run --dry-run <script> prints the task graph that would execute without running anything (including skipping the verifyDepsBeforeRun check); --json emits the tasks and their resolved dependency edges.
    • Output is inherited rather than piped only when at most one script can ever be in flight (--workspace-concurrency=1, or the graph forces the scripts to run one after another).

Patch Changes

  • An _auth entry in the global config file no longer decides which registry packages come from when something else says. A registry or registries declared in pnpm-workspace.yaml or the global config now wins over the route inferred from a stored credential, which still applies where nothing else declares one. The pnpm_config__auth environment variable is unchanged: it stays the way to point a CI runner at a mandated proxy, and still overrides what a repository declares.

  • Prevent installs through a symlinked node_modules directory from rewriting the target checkout pnpm/pnpm#14286.

  • Treat empty scripts selected by a regular expression as missing before running dependent tasks.

  • The options type of the fetch command now declares allowBuilds, a setting its handler already forwarded to the installer. Type-level only — what pnpm fetch does is unchanged.

  • Filter hidden scripts matched by a regular expression during recursive runs when a visible script also matches.

  • Fixed automatically switched pnpm versions forcing all descendant pnpm processes to use the same version pnpm/pnpm#14309.

  • Fixed ERR_PNPM_UNUSED_PATCH validation during incremental installs pnpm/pnpm#13692.

  • Fixed pnpm deploy --prod failing when an excluded dev dependency was also declared as an optional peer dependency pnpm/pnpm#14302.

  • pnpm update -g no longer downgrades a global package. --latest resolves the latest dist-tag, which can point at an older release than the one installed — after pnpm add -g <pkg>@next, for instance #​14270.

    pnpm update -g also no longer changes the pnpm version. pnpm's own global install belongs to pnpm self-update #​14270.

  • Copying a built package to its other hoisted locations no longer replaces the destination directory. With nodeLinker: hoisted, that replacement deleted the dependencies nested inside the destination's node_modules, and made concurrent copies of the same build chunk fail with ERR_PNPM_ENOENT: no such file or directory, rename '.../node_modules/_tmp_...' #​12880.

  • pnpm update no longer replaces the specifier a project declares for a dependency that is also listed in overrides. A catalog: reference stays a catalog: reference, and a declared range stays as written, instead of being rewritten to the version the override resolved to #​12115.

  • pnpm update no longer moves the range a project declares for a dependency that overrides also lists, even when the override repeats that range verbatim. Previously the updated package.json disagreed with the lockfile, so the next pnpm install --frozen-lockfile failed with a specifier mismatch #​14224.

  • Make pnpm add --lockfile-only skip dependency linking pnpm/pnpm#14286.

  • --production is accepted again as an alias of --prod on install, fetch, prune, update, list, why, and sbom, and the install that verifyDepsBeforeRun reproduces is now spelled with --prod. pnpm run no longer aborts with "unexpected argument '--production' found" after a production-only install #​14147.

  • The progress output no longer overwrites the lines above it once it grows taller than the terminal window #​14270.

  • Restoring a dependency's build from the remote side-effects cache no longer downloads files the store already holds.

  • Forward patchedDependencies hashes and packageExtensions to pnpr so server-side resolution preserves patches and package extensions in the lockfile and installed packages.

  • Published the workspace task graph and scheduler as @pnpm/workspace.task-scheduler so other workspace commands can use the same dependency-aware scheduling as recursive run and exec.

  • The environment variables for the remote side-effects cache are named for the setting they configure: PNPM_SIDE_EFFECTS_CACHE_REMOTE_KEY_ID, ..._BUILDER_ID, ..._IMAGE_DIGEST, ..._ARCHITECTURE_BASELINE, ..._PRIVATE_KEY, ..._BUILD_ENV, ..._TRUSTED_KEYS and ..._PUBLISH. The PNPM_REMOTE_SIDE_EFFECTS_CACHE_* names keep working, and the new one wins when both are set.

  • A devEngines.packageManager range pin on pnpm is now recorded in pnpm-lock.yaml's packageManagerDependencies when the running pnpm already satisfies it, using the running version and keeping the range as the recorded specifier. Previously only an exact pin — or a range resolved on the way through a version switch — reached the lockfile, so a range pin written by hand (or by any tool other than pnpm add / pnpm self-update) left the project without the shared resolution the pin exists to provide.

  • Fixed recursive run cleanup on Windows when a lifecycle script fails while another script's process tree is still running.

  • The update notification now suggests pnpm self-update when PNPM_HOME manages the pnpm in use, and the standalone install script otherwise — under Corepack, or when another package manager installed pnpm. pnpm self-update under Corepack names the standalone install script too.

  • Enforce allowBuilds when a prepared git dependency is reused from the shared store, and use the lockfile's canonical git resolution ID in approval suggestions.

  • Topologically sorting workspace projects now runs in linear time, fixing installs and lockfile updates that stalled for seconds on workspaces with thousands of projects forming deep dependency chains #​14149, #​14151.

Platinum Sponsors

Bit OpenAI Notion

Gold Sponsors

Sanity Discord Vite
SerpApi CodeRabbit Stackblitz
Workleap Nx Latitude

Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • "before 9am on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner September 7, 2026 05:25
@renovate
renovate Bot requested review from dawsontoth and removed request for a team September 7, 2026 05:25
@renovate
renovate Bot merged commit de37ca7 into main Sep 7, 2026
35 checks passed
@renovate
renovate Bot deleted the renovate/all-minor-patch branch September 7, 2026 13:06
github-actions Bot pushed a commit that referenced this pull request Sep 7, 2026
## [1.12.3](v1.12.2...v1.12.3) (2026-09-07)

### Dependency Updates

* **deps:** update all non-major dependencies ([#137](#137)) ([de37ca7](de37ca7))
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

🎉 This PR is included in version 1.12.3 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants