Repository navigation
fix: bump non-breaking dependencies to latest - #674
Merged
Merged
Conversation
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Automated non-major dependency bump (deps-train).
package.json
packages/static-server/package.json
packages/secret/package.json
packages/bundlecheck/package.json
Transitive refresh (
pnpm update) — 23 package(s) movedShow transitive changes
What changed
@versini/dev-dependencies-common14.0.14 → 14.0.15dev-dependencies-common: v14.0.15
14.0.15 (2026-09-13)
Bug Fixes
compare 14.0.14…14.0.15 · npm
pnpm11.25.0 → 11.27.0pnpm 11.27
Minor Changes
nodeDownloadMirrorscan now be set in the global config file (config.yaml) and through thePNPM_CONFIG_NODE_DOWNLOAD_MIRRORSenvironment variable, so a Node.js download mirror can be configured once for a machine instead of in every workspace #12124, #13611.PNPM_CONFIG_NODE_DOWNLOAD_MIRRORS='{"release":"https://npmmirror.com/mirrors/node/"}'Added a new setting
trustPolicyExcludePrune(default:false). When enabled,pnpm add,pnpm update, andpnpm removeprune the entries oftrustPolicyExcludeinpnpm-workspace.yamlthat the freshly written lockfile no longer resolves: versions that are gone are dropped (an entry is removed once none of its versions remain), and entries for packages that are no longer in the lockfile are removed too. Name patterns (@scope/*) are always kept. The cleanup is skipped when the install's lockfile does not cover the whole workspace (sharedWorkspaceLockfile: false), since entries another project still needs would look stale.Patch Changes
pnpm now reads the
packageManager,devEngines.packageManagerand runtime pins from the workspace root'spackage.jsonwhenlockfileDiris set. A project that moved its lockfile lost the pins it declared there #14633.Fixed
pnpm add -g,pnpm update -g, andpnpm remove -gmutating glo…notes truncated.
pnpm 11.26
Minor Changes
Catalogs can now resolve workspace dependencies through the
workspace:protocol.pnpm removeandpnpm updatenow accept--trust-lockfile,--no-trust-lockfile,--trust-policy,--trust-policy-exclude, and--trust-policy-ignore-after.pnpm removechecks the whole lockfile against the active policies unless--trust-lockfileis set.Added
pnpm change checkfor CI validation of package versions against theversioning.epicsbands andversioning.fixedgroups inpnpm-workspace.yaml.Patch Changes
Fetch and tarball errors and retry logs now hide URL credentials, query strings, and fragments that could expose secrets.
Fixed a race during config dependency updates that could redirect a lockfile write through a symlink #14322.
pnpm add --allow-build=!<pkg>now correctly denies builds, including in global installs.pnpm approve-builds <pkg>andpnpm approve-builds !<pkg>now save decisions even when the package is not awaiting approval, with a warning #14067.Fixed
pnpm audit --fixfailing without a value or when followed by another flag.pnpm audit --fix=overridenow respectssaveExactandsavePrefixwhen writing overrides #13261, #11523.pnpm auditnow excludes ignored advisories from vulnerability totals…notes truncated.
compare 11.25.0…11.27.0 · npm
fastify5.12.3 → 5.12.4v5.12.4
Fixed the
fastify.jsversion mismatch.Full Changelog: fastify/fastify@v5.12.2...v5.12.4
compare 5.12.3…5.12.4 · npm
open11.0.2 → 11.0.3v11.0.3
sindresorhus/open@v11.0.2...v11.0.3
compare 11.0.2…11.0.3 · npm
inquirer14.2.1 → 14.2.2inquirer@14.2.2
inquirer@14.2.2
The umbrella package, bundling
@inquirer/promptsand@inquirer/core.What's new
@inquirer/core, #2255, closes #1816).confirm()now trims surrounding whitespace from answers before matching yes/no keywords (@inquirer/confirm, #2254).Included
@inquirer/core@^12.0.3@inquirer/prompts@^8.7.2compare 14.2.1…14.2.2 · npm
@inquirer/select5.2.4 → 5.2.5releases · npm