Skip to content

chore(deps): update all non-major dependencies - #875

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
bumpp 12.2.2 → 12.3.0 age confidence devDependencies minor
danielroe/uppt v0.6.9 → v0.6.11 age confidence action patch
docus 5.13.0 → 5.14.0 age confidence dependencies minor
html-validate (source) ~11.11.0 → ~11.16.0 age confidence dependencies minor
lint-staged 17.4.1 → 17.6.0 age confidence devDependencies minor
pnpm (source) 12.9.1 → 12.11.2 age confidence devEngines.packageManager minor

Release Notes

antfu-collective/bumpp (bumpp)

v12.3.0

Compare Source

   🚀 Features
    View changes on GitHub

v12.2.3

Compare Source

   🐞 Bug Fixes
    View changes on GitHub
danielroe/uppt (danielroe/uppt)

v0.6.11

Compare Source

compare changes

🚀 Enhancements
  • Add nightly publishing (#​75)
  • Respect hand-edited release pr versions (00ffbe0)
  • pr: Run on pushes to release branches (800be04)
🩹 Fixes
  • publish: Tolerate E403 when republishing nightlies (3934767)
  • pr: Tighten hand-edited version pinning and surface warnings (113eb4c)
  • pr: Paginate open release PR lookups and keep updating PRs with extra commits (6ec2714)
💅 Refactors
  • Sync lockstep release branches via syncReleaseBranch (c777f2b)
❤️ Contributors

v0.6.10

Compare Source

compare changes

🚀 Enhancements
  • pr: Treat revert commits as release-worthy (#​70)
🩹 Fixes
  • pr,release: Use correct diff link + strip pending timetable line (6959b96)
🏡 Chore
  • Pin README example to v0.6.9 (e01133f)
  • Add back zizmor-ignore comment (83d5a78)
✅ Tests
  • Add some additional tests (d79b75d)
🤖 CI
  • Use pnpm/setup and devEngines (#​64)
  • Replace agentscan action with the github app (511fe92)
❤️ Contributors
nuxt-content/docus (docus)

v5.14.0

Compare Source

Features
Bug Fixes
html-validate/html-validate (html-validate)

v11.16.2

Compare Source

Bug Fixes
  • cli: handle writing formatter output directly to file descriptors (8014966)
  • deps: update dependency ignore to v7.0.11 (c227d47)
  • deps: update dependency ignore to v7.0.12 (b1f84d7)

v11.16.1

Compare Source

Bug Fixes
  • deps: update dependency ignore to v7.0.10 (b3540ce)
  • fix serialization error when jest or vitest worker got an autofixable result (69b9728), closes #​372

v11.16.0

Compare Source

Features
  • api: unified HtmlValidate.autofix() and deprecate all other variants (40c67f0)
  • rules: add minSectioningRootInitialRank option to heading-level (7b9629f)
Bug Fixes
  • deps: update dependency ignore to v7.0.9 (0337345)

v11.15.0

Compare Source

Features
  • api: add new insertTextBefore() and insertTextAfter() methods to ErrorFixer` (ac6ca62)

v11.14.0

Compare Source

Features
  • api: add fixableErrorCount and fixableWarningCount to Report object (5bad2dd)
  • api: add fixableErrorCount and fixableWarningCount to Result object (edc169f)
  • cli: stylish and codeframe formatters output number of fixable errors and warnings (6f230fc)
  • deps: support vitest v5 (9bc1709)

v11.13.0

Compare Source

Features
  • api: expose autofixCollectEdits for integrations to support autofix (b7de9fa)

v11.12.0

Compare Source

Features
  • api: add new removeText() method to ErrorFixer (3484ed3)
  • rules: add suggestions to no-redundant-for (6798b9c)
  • rules: make missing-doctype autofixable (2c4c2e7)
  • rules: make no-raw-characters autofixable (b7e28aa)
  • rules: make script-type autofixable (e15cb1a)
  • rules: make tel-non-breaking autofixable (d91bc8c)
Bug Fixes
  • deps: update dependency ignore to v7.0.7 (77151ba)
  • deps: update dependency ignore to v7.0.8 (17b64af)
lint-staged/lint-staged (lint-staged)

v17.6.0

Compare Source

Minor Changes
  • #​1850 938d3f4 - Task functions like { title, task } can now use a logger function log() to emit output while the task runs. By default, the output will only be visible if the task fails, unless the --verbose option was used. Additionally, when the task rejects, the error will be shown in the output.

    import { defineConfig } from 'lint-staged/config'
    
    export default defineConfig({
      '*': {
        title: 'Fail if PDF files are committed',
        task: async (filepaths, { log }) => {
          const pdfFiles = filepaths.filter((f) => f.toLowerCase().endsWith('.pdf'))
          if (pdfFiles.length > 0) {
            log('PDF files should not be committed: %s', pdfFiles)
            throw new Error('Failed')
          }
        },
      },
    })
  • #​1854 30562bc - lint-staged now stages changes to all tracked files modified by tasks, including files that weren’t originally staged or didn’t match the configured globs. This can happen when your task has side-effects, or it's a function that ignores the staged files like () => "prettier --write .".

    If you have unstaged changes in a file and the task also edits that file, your unstaged changes will be staged too. Use --hide-unstaged to hide your changes while tasks run.

Patch Changes
  • #​1860 4296532 - The assignment of staged files to lint-staged configuration files (when using multiple, for example in a monorepo) has been rewritten to be more efficient. As a reminder, each staged file is assigned to exactly one configuration (the closest one), even if that config doesn't match the file in its globs.

  • #​1861 c45f28a - Fix running parallel tasks for a single glob, when tasks are created by a function. Nesting one level of arrays inside an array of tasks will result in the inner tasks running in parallel. This behavior should now be consistent when creating tasks using functions. In the following example eslint and prettier will run in parallel (for all files, when any JS files are staged):

    import { defineConfig } from 'lint-staged/config'
    
    export default defineConfig({
      '*.js': () => [['eslint --max-warnings=0 .', 'prettier --list-different .']],
    })
  • #​1859 f0ea69d - Various performance improvements from skipping redundant internal Git calls.

  • #​1856 69d7d17 - Partially staged changes are hidden in a uniquely-named patch file to avoid multiple invocations of lint-staged overwriting it. This makes it safer to run lint-staged in multiple worktrees at the same time.

v17.5.1

Compare Source

Patch Changes
  • #​1852 bfcca94 - Fix TypeScript issue TS1254 from defineConfig() by changing the signature from const to a function:

    A 'const' initializer in an ambient context must be a string or numeric literal or literal enum reference.

v17.5.0

Compare Source

Minor Changes
  • #​1847 f9063b7 - Lint-staged now refuses to run when files were staged with --intent-to-add, because Git stash doesn't support them. Previously this was an unhandled error.
Patch Changes
  • #​1848 d718ccc - Lint-staged now handles color support better in non-TTY streams, and honors the FORCE_COLOR environment variable.

  • #​1845 7e5ece8 - Update tinyexec@1.3.1 so that local binaries from node_modules/.bin are resolved starting from the directory of each lint-staged configuration file (in monorepo setups). This behavior was broken in lint-staged@16.3.0 where they were only resolved from the current working directory and up.

  • #​1845 eb8a4e3 - Do not try to restore untracked files when using --hide-all and there is no initial commit yet.

pnpm/pnpm (pnpm)

v12.11.2: pnpm 12.11.2

Compare Source

This release fixes --workspace-concurrency=Infinity, filters set by an updateConfig hook, and store fetches with enable-modules-dir=false.

Patch Changes
  • --workspace-concurrency=Infinity now runs workspace projects with no concurrency limit. It used to fail with invalid digit found in string #​16793.

  • pnpm install and other recursive commands now apply the filter and filterProd that an updateConfig hook sets. They used to run on every workspace project #​16792.

  • enable-modules-dir=false now also fetches the packages an install reuses from an existing lockfile, so the store holds every package the lockfile lists.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.11.1: pnpm 12.11.1

Compare Source

This release fixes two ways pnpm install could fail, runs tools of any Rust release through pnx, and treats registry.npmjs.com as an alias of the npm registry.

Patch Changes
  • pnpm install no longer fails when packageManager pins the pnpm version that is already running and the registry does not publish that version. pnpm warns and continues. A registry mirror that has not synced a release no longer blocks the commands of a project pinned to it.

  • pnpm install no longer fails with ERR_PNPM_CMD_SHIM_CHMOD when node_modules/.bin holds a shim that another user created, if everyone can already execute it and it is not world-writable. This happens when several users share one checkout.

  • enable-modules-dir=false (enableModulesDir: false through the Node.js addon) fetches the registry packages the host can install into the store again, as pnpm v10 did, while still writing nothing under node_modules. The setting exists for a node_modules that something else mounts from the store, such as a FUSE daemon, and that consumer no longer has to download each package on first access. A plain --lockfile-only run still fetches nothing.

  • pnpm pack and pnpm publish no longer put .npmignore and .gitignore files in the tarball. A files entry that names one still ships it.

  • pnpm now treats https://registry.npmjs.com/ as an alias of https://registry.npmjs.org/. Registry requests, credentials, and trusted publishing use the canonical hostname.

  • pnx --package=rust@<channel> <tool> runs a tool of that Rust release, for example pnx --package=rust@nightly-2026-01-01 cargo build. pnpm installs the release with the components and targets from rust-toolchain.toml and the target of each --target argument.

  • pnpm install now links agent skills for more coding agents. It detects the agent from ANTIGRAVITY_AGENT, COPILOT_AGENT, COPILOT_CLI, CODEX_THREAD_ID, CODEX_SANDBOX, AI_AGENT, and CLAUDE_CODE pnpm/tasks#116.

  • When the registry rejects pnpm stage publish, the error message now starts with "Failed to stage package".

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.11.0: pnpm 12.11.0

Compare Source

This release adds Rust toolchain management, links the agent skills that dependencies ship, adds the permissions setting, and keeps the colors of streamed script output.

Minor Changes
  • pnpm install now links the agent skills that direct dependencies ship under skills/<name>/SKILL.md into the project's agent skill directories, such as .claude/skills. A package's skills are linked only after you approve them with pnpm approve. The skills.dirs setting chooses the directories pnpm/rfcs#35.

    Added the permissions setting, which records what each dependency may do. Its build capability works like allowBuilds and takes precedence over it. pnpm approve-builds writes to permissions when pnpm-workspace.yaml already has it, and to allowBuilds otherwise.

    Added pnpm permissions, which lists the granted and denied permissions and the packages awaiting approval. pnpm approve reviews build scripts and agent skills in one prompt pnpm/rfcs#36.

  • pnpm now installs and runs Rust toolchains.

    • With cargo.enabled, pnpm install installs the toolchain named in rust-toolchain.toml. pnpm verifies the release signature, stores the toolchain once per machine, and links it into .pnpm/rust. pnpm run and pnpm exec put its cargo and rustc on the PATH.
    • pnpm add -g rust@<channel> installs a toolchain globally. The cargo and rustc commands run it outside projects that pin their own. pnpm update -g, pnpm ls -g, and pnpm remove -g manage it like any global package.
    • In a project, pnpm add rust@<channel> pins the toolchain in rust-toolchain.toml.
    • pnpm shim add rust adds project-aware shims for cargo, rustc, and the other Rust tools. In a project with a rust-toolchain.toml, they run the toolchain the file names and install it on first use. Elsewhere, the next command of the same name on PATH runs, such as rustup's.
  • pnpm run and pnpm exec now keep the colors of script output that they print under the project's name, such as with --stream. pnpm sets FORCE_COLOR=1 for these scripts when its own output is in color, unless FORCE_COLOR is already set.

    Script output is also rendered more cleanly:

    • A line that a progress bar redraws with \r shows only its last state.
    • Escape codes that move the cursor or clear the screen are dropped.
    • Long colored lines are cut at the terminal width.
    • pnpm -r run no longer garbles its live output when a script fails while other scripts are still running.
Patch Changes
Installing packages
  • pnpm no longer panics with "unexpected error when polling the I/O driver" when it runs under QEMU user-mode emulation, such as a linux/amd64 container on an Apple Silicon Mac #​16696.

  • pnpm view, pnpm update, and other commands that read registry metadata now work behind proxies that end a response by closing the connection without a TLS close_notify alert #​16704.

  • pnpm now switches to the version a project pins in packageManager or devEngines.packageManager even when pnpm-workspace.yaml has a setting the running pnpm cannot read, such as a lockfile.includeResolutionSettings section. If pnpm does not switch, it still reports that setting #​16675.

  • When the pnpm package has to download its native binary on first run, it now uses the registry and credentials from .npmrc and from the npm_config_registry and pnpm_config_registry environment variables. COREPACK_NPM_REGISTRY still takes precedence. A project .npmrc is not read when COREPACK_INTEGRITY_KEYS turns off the signature check #​16655.

  • pnpm install and pnpm add --config now apply minimumReleaseAge when they resolve a config dependency. A config dependency range resolves to the newest version that is old enough, so a later clean pnpm install --frozen-lockfile accepts the lockfile #​16660.

  • pnpm remove with catalogPrune no longer removes catalog entries that pnpm-lock.yaml still records for workspace projects missing from disk. Before, a following frozen install failed with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH #​16679.

  • With cargo.enabled, pnpm install now writes the source replacement for vendored crates into .pnpm/crates/config.toml and includes it as optional from .cargo/config.toml. A checkout without .pnpm builds with plain Cargo #​16659.

  • With nodeLinker.type set to loaded, Node.js now stops with ERR_PNPM_LOADER_UNSUPPORTED_NODE when it preloads the store loader on a version the loader cannot serve. The supported versions are ^24.18.0 || >=26.2.0. On other versions, CommonJS packages imported from ESM failed with Cannot find module on their first relative require().

  • On Windows, pnpm install no longer fails with "The filename, directory name, or volume label syntax is incorrect" when a package contains a file whose name is invalid on Windows, such as icon.svg?as=metadata.d.ts. pnpm removes the invalid characters from the name and prints a warning that lists the renamed files.

  • On Windows, hoisting no longer fails intermittently with link errors when a junction is created or replaced concurrently pnpm/tasks#53.

Resolving dependencies
  • pnpm install --no-optional now installs the peer dependencies a project declares when autoInstallPeers is on. The lockfile marked such a peer optional: true when another dependency had it as an optional peer.

  • pnpm install and pnpm dedupe now link an optional peer to the workspace package that the workspace root depends on when the picked version matches it. They installed the registry package with the same name and version #​16706.

  • Removal overrides such as "debug>supports-color": "-" now also apply to an optional peer that a package declares only in peerDependenciesMeta #​16681.

  • pnpm add and other installs that re-resolve dependencies now keep the locked devEngines.runtime version while it still satisfies the declared range #​16764.

  • pnpm audit --fix update now updates only the dependencies whose locked version is vulnerable #​14928.

  • pnpm outdated and pnpm update --interactive now apply overrides before they look up the latest version. Before, a dependency overridden to an npm alias was compared with the latest version of the package the override replaces #​16719.

Patched dependencies
  • Patches saved with CRLF line endings now apply, including a patch that creates or deletes a file. pnpm rejected the git headers of such a patch with ERR_PNPM_INVALID_PATCH and the message invalid file mode: 100644 #​16641.

  • A patch that changes a file's mode, such as adding or removing the executable bit, now applies the new mode on Unix pnpm/tasks#110.

Injected dependencies and deploy
  • With sharedWorkspaceLockfile: false, an injected workspace package installed in the same run as its dependent now holds only the files its files field selects. The copy also held other files of the project, such as tsconfig.json #​16683.

  • A script listed in syncInjectedDepsAfterScripts no longer fails when it rewrites package.json while pnpm is copying its edits into the injected copies. The sync after the script now replaces a half-copied manifest.

  • pnpm deploy with a shared lockfile no longer fails with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH for settings.dedupeInjectedDeps or settings.dedupePeerDependents when lockfile.includeResolutionSettings is enabled. The deployed lockfile now records both settings as false, the values the deploy installs with.

  • pnpm deploy now writes the dependencies in the deployed package.json sorted by name. It also sorts the allowBuilds entries in the deployed pnpm-workspace.yaml. Repeated deploys of the same lockfile now produce identical files #​16687.

Packing and publishing
  • pnpm pack and pnpm publish now match .npmignore and .gitignore rules the way npm does. A negation such as !lib/** or !lib/**/!(*.map) re-includes files under a directory that an earlier * rule excluded #​16743.

  • pnpm pack and pnpm publish no longer always include root files that merely start with README, LICENSE, or LICENCE, such as README_INTERNAL.md. Only README, LICENSE, LICENCE, and COPYING, with or without an extension, ship regardless of files and .npmignore, as in npm #​16753.

  • pnpm publish --provenance=false and --no-provenance now turn off provenance under trusted publishing, so a package can be published from a self-hosted runner. Setting provenance: false in pnpm-workspace.yaml does the same #​16721.

Speed and resource use
  • pnpm install hardlinks files from a group-writable or world-writable store again. pnpm copied every file from such a store into node_modules #​16677.

  • A repeat pnpm install no longer imports patched packages and packages with build scripts again when nothing changed. Their builds no longer run again either. This happened when recursiveInstall was false or the project had a file: dependency #​16705.

  • Verifying the lockfile against trustPolicy and minimumReleaseAge uses less memory. pnpm no longer keeps every published version's manifest of each checked package in memory until the install ends #​16656.

  • pnpm rebuild <pkg> and pnpm rebuild --pending no longer read the manifest of every installed package to find build scripts. Only the selected packages are inspected and built. On a large node_modules served lazily, such as over a network or FUSE mount, this turned a rebuild of a few packages into a fetch of every package.

  • pnpm rebuild no longer removes and recreates node_modules when the settings recorded in node_modules/.modules.yaml differ from the current configuration. The rebuild runs the build scripts against the installed packages as they are.

  • pnpm store prune now compacts the store's index.db after removing package entries, so the file shrinks again #​16717.

Registry commands
  • pnpm whoami, pnpm bugs, pnpm docs, pnpm repo, pnpm star, pnpm unstar, and pnpm stars now honor the --registry option.

  • --registry now takes precedence over a scope's configured registry for scoped packages in pnpm access, pnpm view, pnpm repo, pnpm star, pnpm unstar, pnpm owner, pnpm deprecate, pnpm undeprecate, pnpm unpublish, pnpm dist-tag, pnpm team, and pnpm stage. Without --registry, pnpm access now sends a scoped package or scope to the registry configured for that scope.

  • Registry commands now keep the path of a registry URL such as https://example.com/npm/ when they build request URLs. This applies to pnpm access, pnpm owner, pnpm ping, pnpm search, pnpm star, pnpm stars, pnpm team, pnpm unstar, and pnpm whoami.

  • pnpm view now honors the network retry settings.

  • pnpm repo now fetches the repository URLs of several packages in parallel.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.10.1: pnpm 12.10.1

Compare Source

This release fixes pnpm install failures after an overrides change and on a filtered frozen install with catalogPrune. It also fixes several bugs in the experimental nodeLinker.type: loaded, which now keeps its generated files in node_modules.

Patch Changes
  • With nodeLinker.type: loaded, pnpm now writes its generated files to node_modules, which projects already ignore in git. The store manifest and loader are node_modules/.pnpm/.store-manifest.json and node_modules/.pnpm/.store-loader.mjs. Bin shims are in node_modules/.bin.

    Earlier versions wrote .pnpm-store.json and .pnpm-store-loader.mjs to the project root, and a .pnpm directory to the root and to each workspace package. Delete them after reinstalling.

  • With nodeLinker.type: loaded, packages that ship their own node_modules directory, such as npm with its bundled dependencies, now load from the store. Before, one such package in the install stopped every Node.js process from starting.

  • With nodeLinker.type: loaded, scripts can now run a Node.js runtime installed through devEngines.runtime. Before, every script that called node re-ran its own shim until it failed with "Argument list too long".

  • With nodeLinker.type: loaded, Node.js processes start faster. In a project with 13,000 stored files, the startup overhead per process dropped from 67 ms to 18 ms.

  • pnpm install no longer fails with ERR_PNPM_NO_MATCHING_VERSION after a change to overrides when the lockfile resolves an optional peer dependency to an npm alias of another package #​16654.

  • A frozen install with catalogPrune no longer removes catalog entries that pnpm-lock.yaml still records. Before, pnpm install --frozen-lockfile --filter failed with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH when some workspace projects were missing from disk #​16638.

  • pnpm install --fix-lockfile no longer removes the deprecated and hasBin fields from lockfile entries #​6600.

  • With enableGlobalVirtualStore, an install that updates node_modules now repairs a package in the global virtual store that an interrupted install left without some of its dependency links or package files. Before, such an install kept the incomplete package if the project's node_modules already recorded it #​16642.

  • pnpm install now skips the Cargo and Python projects inside a nested directory that has its own pnpm-workspace.yaml or .git directory, such as a git worktree of the same workspace or a separate clone.

  • The Request took warning for package metadata now starts timing when pnpm sends the request. Before, it also counted the time the request waited for a free request slot, so large installs printed it for requests the registry answered quickly.

Platinum Sponsors

config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@netlify

netlify Bot commented Sep 7, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for html-validator ready!

Name Link
🔨 Latest commit 54c35f6
🔍 Latest deploy log https://app.netlify.com/projects/html-validator/deploys/6acb4f78592b7200083608a3
😎 Deploy Preview https://deploy-preview-875--html-validator.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 9 times, most recently from 7f74c57 to 8853482 Compare September 14, 2026 07:56
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from ddcaa9c to 2aa5221 Compare September 23, 2026 02:23
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 8 times, most recently from 4f2a78f to 9356d8a Compare October 4, 2026 00:33
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from e077c4e to b304af3 Compare October 6, 2026 10:56
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 6 times, most recently from c777e35 to 4a57dfd Compare October 11, 2026 04:25
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 4a57dfd to 54c35f6 Compare October 11, 2026 08:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants