Skip to content

chore(deps): update all non-major dependencies - #875

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence Type Update
bumpp 12.2.2 → 12.3.0 age confidence devDependencies minor
danielroe/uppt v0.6.9 → v0.6.11 age confidence action patch
docus 5.13.0 → 5.14.0 age confidence dependencies minor
html-validate (source) ~11.11.0 → ~11.16.0 age confidence dependencies minor
lint-staged 17.4.1 → 17.6.0 age confidence devDependencies minor
pnpm (source) 12.9.1 → 12.10.1 age confidence devEngines.packageManager minor

Release Notes

antfu-collective/bumpp (bumpp)

v12.3.0

Compare Source

   🚀 Features
    View changes on GitHub

v12.2.3

Compare Source

   🐞 Bug Fixes
    View changes on GitHub
danielroe/uppt (danielroe/uppt)

v0.6.11

Compare Source

compare changes

🚀 Enhancements
  • Add nightly publishing (#​75)
  • Respect hand-edited release pr versions (00ffbe0)
  • pr: Run on pushes to release branches (800be04)
🩹 Fixes
  • publish: Tolerate E403 when republishing nightlies (3934767)
  • pr: Tighten hand-edited version pinning and surface warnings (113eb4c)
  • pr: Paginate open release PR lookups and keep updating PRs with extra commits (6ec2714)
💅 Refactors
  • Sync lockstep release branches via syncReleaseBranch (c777f2b)
❤️ Contributors

v0.6.10

Compare Source

compare changes

🚀 Enhancements
  • pr: Treat revert commits as release-worthy (#​70)
🩹 Fixes
  • pr,release: Use correct diff link + strip pending timetable line (6959b96)
🏡 Chore
  • Pin README example to v0.6.9 (e01133f)
  • Add back zizmor-ignore comment (83d5a78)
✅ Tests
  • Add some additional tests (d79b75d)
🤖 CI
  • Use pnpm/setup and devEngines (#​64)
  • Replace agentscan action with the github app (511fe92)
❤️ Contributors
nuxt-content/docus (docus)

v5.14.0

Compare Source

Features
Bug Fixes
html-validate/html-validate (html-validate)

v11.16.2

Compare Source

Bug Fixes
  • cli: handle writing formatter output directly to file descriptors (8014966)
  • deps: update dependency ignore to v7.0.11 (c227d47)
  • deps: update dependency ignore to v7.0.12 (b1f84d7)

v11.16.1

Compare Source

Bug Fixes
  • deps: update dependency ignore to v7.0.10 (b3540ce)
  • fix serialization error when jest or vitest worker got an autofixable result (69b9728), closes #​372

v11.16.0

Compare Source

Features
  • api: unified HtmlValidate.autofix() and deprecate all other variants (40c67f0)
  • rules: add minSectioningRootInitialRank option to heading-level (7b9629f)
Bug Fixes
  • deps: update dependency ignore to v7.0.9 (0337345)

v11.15.0

Compare Source

Features
  • api: add new insertTextBefore() and insertTextAfter() methods to ErrorFixer` (ac6ca62)

v11.14.0

Compare Source

Features
  • api: add fixableErrorCount and fixableWarningCount to Report object (5bad2dd)
  • api: add fixableErrorCount and fixableWarningCount to Result object (edc169f)
  • cli: stylish and codeframe formatters output number of fixable errors and warnings (6f230fc)
  • deps: support vitest v5 (9bc1709)

v11.13.0

Compare Source

Features
  • api: expose autofixCollectEdits for integrations to support autofix (b7de9fa)

v11.12.0

Compare Source

Features
  • api: add new removeText() method to ErrorFixer (3484ed3)
  • rules: add suggestions to no-redundant-for (6798b9c)
  • rules: make missing-doctype autofixable (2c4c2e7)
  • rules: make no-raw-characters autofixable (b7e28aa)
  • rules: make script-type autofixable (e15cb1a)
  • rules: make tel-non-breaking autofixable (d91bc8c)
Bug Fixes
  • deps: update dependency ignore to v7.0.7 (77151ba)
  • deps: update dependency ignore to v7.0.8 (17b64af)
lint-staged/lint-staged (lint-staged)

v17.6.0

Compare Source

Minor Changes
  • #​1850 938d3f4 - Task functions like { title, task } can now use a logger function log() to emit output while the task runs. By default, the output will only be visible if the task fails, unless the --verbose option was used. Additionally, when the task rejects, the error will be shown in the output.

    import { defineConfig } from 'lint-staged/config'
    
    export default defineConfig({
      '*': {
        title: 'Fail if PDF files are committed',
        task: async (filepaths, { log }) => {
          const pdfFiles = filepaths.filter((f) => f.toLowerCase().endsWith('.pdf'))
          if (pdfFiles.length > 0) {
            log('PDF files should not be committed: %s', pdfFiles)
            throw new Error('Failed')
          }
        },
      },
    })
  • #​1854 30562bc - lint-staged now stages changes to all tracked files modified by tasks, including files that weren’t originally staged or didn’t match the configured globs. This can happen when your task has side-effects, or it's a function that ignores the staged files like () => "prettier --write .".

    If you have unstaged changes in a file and the task also edits that file, your unstaged changes will be staged too. Use --hide-unstaged to hide your changes while tasks run.

Patch Changes
  • #​1860 4296532 - The assignment of staged files to lint-staged configuration files (when using multiple, for example in a monorepo) has been rewritten to be more efficient. As a reminder, each staged file is assigned to exactly one configuration (the closest one), even if that config doesn't match the file in its globs.

  • #​1861 c45f28a - Fix running parallel tasks for a single glob, when tasks are created by a function. Nesting one level of arrays inside an array of tasks will result in the inner tasks running in parallel. This behavior should now be consistent when creating tasks using functions. In the following example eslint and prettier will run in parallel (for all files, when any JS files are staged):

    import { defineConfig } from 'lint-staged/config'
    
    export default defineConfig({
      '*.js': () => [['eslint --max-warnings=0 .', 'prettier --list-different .']],
    })
  • #​1859 f0ea69d - Various performance improvements from skipping redundant internal Git calls.

  • #​1856 69d7d17 - Partially staged changes are hidden in a uniquely-named patch file to avoid multiple invocations of lint-staged overwriting it. This makes it safer to run lint-staged in multiple worktrees at the same time.

v17.5.1

Compare Source

Patch Changes
  • #​1852 bfcca94 - Fix TypeScript issue TS1254 from defineConfig() by changing the signature from const to a function:

    A 'const' initializer in an ambient context must be a string or numeric literal or literal enum reference.

v17.5.0

Compare Source

Minor Changes
  • #​1847 f9063b7 - Lint-staged now refuses to run when files were staged with --intent-to-add, because Git stash doesn't support them. Previously this was an unhandled error.
Patch Changes
  • #​1848 d718ccc - Lint-staged now handles color support better in non-TTY streams, and honors the FORCE_COLOR environment variable.

  • #​1845 7e5ece8 - Update tinyexec@1.3.1 so that local binaries from node_modules/.bin are resolved starting from the directory of each lint-staged configuration file (in monorepo setups). This behavior was broken in lint-staged@16.3.0 where they were only resolved from the current working directory and up.

  • #​1845 eb8a4e3 - Do not try to restore untracked files when using --hide-all and there is no initial commit yet.

pnpm/pnpm (pnpm)

v12.10.1: pnpm 12.10.1

Compare Source

This release fixes pnpm install failures after an overrides change and on a filtered frozen install with catalogPrune. It also fixes several bugs in the experimental nodeLinker.type: loaded, which now keeps its generated files in node_modules.

Patch Changes
  • With nodeLinker.type: loaded, pnpm now writes its generated files to node_modules, which projects already ignore in git. The store manifest and loader are node_modules/.pnpm/.store-manifest.json and node_modules/.pnpm/.store-loader.mjs. Bin shims are in node_modules/.bin.

    Earlier versions wrote .pnpm-store.json and .pnpm-store-loader.mjs to the project root, and a .pnpm directory to the root and to each workspace package. Delete them after reinstalling.

  • With nodeLinker.type: loaded, packages that ship their own node_modules directory, such as npm with its bundled dependencies, now load from the store. Before, one such package in the install stopped every Node.js process from starting.

  • With nodeLinker.type: loaded, scripts can now run a Node.js runtime installed through devEngines.runtime. Before, every script that called node re-ran its own shim until it failed with "Argument list too long".

  • With nodeLinker.type: loaded, Node.js processes start faster. In a project with 13,000 stored files, the startup overhead per process dropped from 67 ms to 18 ms.

  • pnpm install no longer fails with ERR_PNPM_NO_MATCHING_VERSION after a change to overrides when the lockfile resolves an optional peer dependency to an npm alias of another package #​16654.

  • A frozen install with catalogPrune no longer removes catalog entries that pnpm-lock.yaml still records. Before, pnpm install --frozen-lockfile --filter failed with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH when some workspace projects were missing from disk #​16638.

  • pnpm install --fix-lockfile no longer removes the deprecated and hasBin fields from lockfile entries #​6600.

  • With enableGlobalVirtualStore, an install that updates node_modules now repairs a package in the global virtual store that an interrupted install left without some of its dependency links or package files. Before, such an install kept the incomplete package if the project's node_modules already recorded it #​16642.

  • pnpm install now skips the Cargo and Python projects inside a nested directory that has its own pnpm-workspace.yaml or .git directory, such as a git worktree of the same workspace or a separate clone.

  • The Request took warning for package metadata now starts timing when pnpm sends the request. Before, it also counted the time the request waited for a free request slot, so large installs printed it for requests the registry answered quickly.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.10.0: pnpm 12.10.0

Compare Source

This release adds an experimental loaded node linker, lets pnpm-lock.yaml record resolution settings, and reads cached registry metadata faster. It also carries several security fixes, including one that stops a dependency version from writing files outside the global virtual store.

Minor Changes
  • Added experimental nodeLinker: { type: loaded } installation. Compatible dependencies load directly from the content-addressable store through an automatically registered Node.js loader. nodeLinker.excluded selects packages and their dependency trees to install in the global virtual store.

  • lockfile.includeResolutionSettings: true makes pnpm-lock.yaml record autoDedupe, dedupeInjectedDeps, dedupePeerDependents and linkWorkspacePackages. Installs then treat a lockfile that records other values as outdated. A lockfile that records autoDedupe is reused by later installs on any machine, so pnpm run after pnpm install --frozen-lockfile no longer starts another install #​16583.

Patch Changes
Security
  • pnpm install now prevents dependency versions with path traversal from writing files outside the global virtual store.

  • pnpm now verifies locked config dependencies against their registry before installing them. Config dependencies must come from an npm registry. The lockfile can no longer replace the integrity of a config dependency pinned with version+integrity.

  • Lockfile verification now checks the tarballs inside a variations resolution against the registry. A name@version lockfile entry with an empty variations resolution is now rejected.

  • pnpm audit signatures now verifies signatures against the integrity recorded in the lockfile. Packages without a recorded integrity cannot pass signature verification.

  • pnpm install and pnpm publish now reject archive metadata larger than 64 MiB before reading it into memory. Publishing a pre-built tarball also rejects manifests and README files larger than 64 MiB.

  • Two URL or local path dependencies no longer share a virtual store directory when one URL has +, #, :, or ? where the other has /. Such dependencies, including git dependencies pinned with #, now get a hash suffix on their directory name.

  • The warning about an ignored project .npmrc registry setting no longer prints the username and password of a URL-scoped key such as //user:password@registry.example.com/${PATH}/:_authToken.

Installing and resolving dependencies
  • pnpm install now fails with ERR_PNPM_UNSUPPORTED_PROTOCOL when a dependency uses a specifier with a protocol pnpm does not support, such as Yarn's patch:. On Windows, such a specifier failed with os error 123. On other platforms, pnpm linked it to a directory that does not exist. Reading a package.json that fails now names the file #​16590.

  • pnpm install now fails with ERR_PNPM_PACKAGE_MANIFEST_INVALID_ATTRIBUTE when a project declares a dependency whose specifier is not a string, such as "is-positive": 42. Before, the dependency was silently left out of the lockfile. A readPackage hook can still correct the specifier.

  • Fixed pnpm install failing with ERR_PNPM_CMD_SHIM_RESOLVE_PATH when an executable's parent directory contains a dangling symlink.

  • pnpm install --frozen-lockfile no longer fails with ERR_PNPM_RESOLUTION_SHAPE_MISMATCH when a name@version lockfile entry has a resolution served by a custom fetcher pnpm/tasks#108.

  • pnpm install --fix-lockfile repairs a lockfile whose importer references a package that has no snapshot entry, as left by a badly merged lockfile. It failed with ERR_PNPM_LOCKFILE_MISSING_DEPENDENCY since 12.8.0 #​16618.

  • When a dependency moves an exact dependency of its own to an older version, a peer dependency that pnpm installed automatically now moves with it. Before, pnpm install and pnpm dedupe kept the newer locked version of the peer, so the lockfile held two copies of it, for example two copies of vue pnpm/tasks#61.

  • pnpm dedupe now reads registry metadata for a dependency pinned to an exact version, as pnpm install does. If the registry metadata disagreed with the package's package.json, the lockfile it wrote depended on whether minimumReleaseAge was set #​16615.

Speed and size
  • Dependency resolution reads cached registry metadata faster. The metadata cache moved to <cache-dir>/v12/, so the first install after upgrading downloads registry metadata again. A damaged cache entry is downloaded again, or reported as an error when --offline is set. pnpm cache prune also removes the metadata cache that older pnpm versions wrote under <cache-dir>/v11/ #​13512.

  • Package metadata requests no longer wait behind queued tarball downloads when maxSockets or a proxy limits the connections to a registry. Large installs resolve faster and print fewer Request took warnings.

  • Sped up installs in large workspaces on macOS when the dependency links already exist. pnpm now keeps a link that already points at the right package without trying to create it first. Relinking the direct dependencies of 1,000 workspace projects took 45 ms, down from 116 ms pnpm/tasks#65.

  • Commands in a project that pins a different pnpm version start about 13 ms faster on macOS. pnpm now runs the pinned version's binary directly, without the shell script in front of it pnpm/tasks#66.

  • The pnpm binary is about 0.9 MB smaller, and the arm64 Linux binary is about 1 MB smaller still.

Running scripts and commands
  • pnpm run no longer prints [ELIFECYCLE] Command failed ... after Ctrl+C ends the script. pnpm still exits the way the script's shell did: on Windows with the shell's exit code (cmd reports -1073741510, PowerShell 1), on Unix by re-raising SIGINT #​16579.

  • pnpm run "/<regex>/" now accepts JavaScript regular expression syntax such as lookahead and lookbehind. A selector like "/^hello:(?!b).*$/" failed with ERR_PNPM_NO_SCRIPT #​16604.

  • pnpm run and pnpm exec now forward --config.* command-line flags to the install started by verifyDepsBeforeRun pnpm/tasks#60.

  • On Windows, a process started by pnpm run or pnpm exec can again start a child with CREATE_BREAKAWAY_FROM_JOB. That child keeps running after pnpm exits, even if the command fails #​16628.

  • Empty nodeOptions values from command-line flags and environment variables now override lower-priority settings. Scripts retain NODE_OPTIONS from the parent environment or extraEnv when nodeOptions is empty.

  • pnpm now reads the failIfNoMatch setting from pnpm-workspace.yaml, so a filter that matches no workspace project exits with code 1 when the setting is true. The new --no-fail-if-no-match flag turns the setting off for one command #​16577.

Configuration, setup, and pnpm versions
  • pnpm config get --global and pnpm config list --global now show only the global configuration, also when run inside a project. Settings from the project's pnpm-workspace.yaml and .npmrc were included before. The same applies to --location=global #​16598.

  • pnpm now prints config warnings, such as an unset environment variable in .npmrc, when loading the config fails.

  • pnpm 11 releases older than 11.28.4 can run pnpm 12 again when the packageManager field pins it. Since 12.9.0 they failed with SyntaxError: Invalid or unexpected token #​16594.

  • On Windows, pnpm self-update no longer runs the update a second time when it replaces a pnpm.cmd linked by pnpm 12.8 or older. cmd.exe read on in the replaced pnpm.cmd, printed an error about a command that is not recognized, and ran the new pnpm once more #​16573.

  • pnpm setup now puts $PNPM_HOME/bin first on PATH in login shells that inherited it further down, such as the VS Code terminal on macOS. Before, another node took precedence over the one installed by pnpm runtime set node -g. Run pnpm setup again to update the block in your shell config #​16635.

  • pnpm setup now names the shell config file even if it is already up to date #​16608.

Updating, auditing, and publishing
  • pnpm update --latest now applies the savePrefix setting when it rewrites a dependency whose range has no operator of its own, such as <2.0.0.

  • The interactive pnpm audit --fix picker now shows each patched version with the saveExact and savePrefix style that the override is written with #​13209.

  • pnpm unpublish <pkg>@<version> now deletes the tarball under the registry's path when the registry is served under one, such as Gitea's npm registry. It used to send the delete to the host root and report success without removing the version #​16568. It also no longer mistakes a sibling path such as /npm-mirror/ for the registry path /npm/ pnpm/tasks#94.

Output and messages
  • A warning about a project's devEngines or packageManager pin is now printed to stderr. A command such as pnpm cache path or pnpm list --json keeps only its own output on stdout #​16584.

  • pnpm list now reports the correct package paths when nodeLinker is hoisted #​9593.

  • Resolution errors now name the failing dependency and its parent packages. Fatal errors appear as structured error records with their error codes when using --reporter=ndjson.

  • The error for an invalid git repository in the lockfile now has the code ERR_PNPM_INVALID_GIT_REPOSITORY. Its message now lists every rejected form of the value.

  • pnpm runtime --help and pnpm help runtime now name the set subcommand and the runtimes it accepts #​16580.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@netlify

netlify Bot commented Sep 7, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for html-validator ready!

Name Link
🔨 Latest commit ff08c50
🔍 Latest deploy log https://app.netlify.com/projects/html-validator/deploys/6ac699273c07c50008b5f5fb
😎 Deploy Preview https://deploy-preview-875--html-validator.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 9 times, most recently from 7f74c57 to 8853482 Compare September 14, 2026 07:56
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from ddcaa9c to 2aa5221 Compare September 23, 2026 02:23
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 8 times, most recently from 4f2a78f to 9356d8a Compare October 4, 2026 00:33
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from e077c4e to b304af3 Compare October 6, 2026 10:56
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 8a400bc to 8320a65 Compare October 7, 2026 12:25
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 8320a65 to ff08c50 Compare October 7, 2026 19:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants