Renovate: Update miscellaneous packages - #299
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
|
Contributor
|
renovate
Bot
force-pushed
the
renovate/miscellaneous-packages
branch
13 times, most recently
from
August 28, 2026 09:40
c987b5a to
02b1429
Compare
renovate
Bot
force-pushed
the
renovate/miscellaneous-packages
branch
from
August 28, 2026 19:05
02b1429 to
29ed885
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.0.0→3.0.15.101.4→5.102.816.3.2→16.3.314.6.5→14.6.630.4.1→30.5.015.21.0→15.21.130.4.2→30.5.030.4.1→30.5.011.22.0→11.24.08.3.0→8.3.11.102.0→1.103.1Release Notes
changesets/changesets (@changesets/cli)
v3.0.1Compare Source
Patch Changes
fdfdc93Thanks @bluwy! - Update links in default generated.changeset/README.mdfiled0386b6]:TanStack/query (@tanstack/react-query)
v5.102.8Compare Source
Patch Changes
v5.102.7Compare Source
Patch Changes
v5.102.6Compare Source
Patch Changes
#11305
ac2b612- fix(react-query): throw falsy errors fromuseQueriesanduseSuspenseQueriesto the error boundaryUpdated dependencies []:
v5.102.5Compare Source
Patch Changes
578e5c2]:v5.102.4Compare Source
Patch Changes
a05df6a]:v5.102.3Compare Source
Patch Changes
v5.102.2Compare Source
Patch Changes
80fbf73]:v5.102.1Compare Source
Patch Changes
134890d]:v5.102.0Compare Source
Minor Changes
e674826- react-query: update usePrefetchQuery and usePrefetchInfiniteQuery to use queryClient.query and queryClient.infiniteQueryPatch Changes
#11245
37127db- revert: remove NoInfer from useQuery return types#10373
6e3d521- fix(types): propagate generic type parameters touseMutationStateselect callback#11224
294d4e6- FixqueryOptionsandinfiniteQueryOptionsreturn types so exported inferred options can be emitted in declaration files without leaking internal data tag symbols.#11147
cb6c9d3- DefaultTDataofUseInfiniteQueryOptionsandUseSuspenseInfiniteQueryOptionstoInfiniteData<TQueryFnData>so it matches the hook generics.#8737
2215bb0- fix: make mutation variables optional whenundefined extends TVariables#11221
1ef4208- Remove experimental render-time prefetching and thepromiseproperty from query results.#11228
fb6c3fa- Avoid emitting a runtime import for React Query's type-only exports.#11130
8834267- fix(react-query): don't show optimistic fetching for unsubscribed useQueries#11233
b866a95- remove unused experimental_beforeQuery and experimental_afterQuery hooks#11144
e546d03- fix: remove placeholderData from suspense infinite queryUpdated dependencies [
34f7cee,b4368c4,5bb089d,ba4650c,294d4e6,1f631b3,01a02bf,18c1c1e,5448063,2215bb0,1ef4208,5981771,4a9bef6,bef4bc7,9656dc4,326aaf1,3e83601,c6fc17c]:testing-library/react-testing-library (@testing-library/react)
v16.3.3Compare Source
Bug Fixes
testing-library/user-event (@testing-library/user-event)
v14.6.6Compare Source
Bug Fixes
jestjs/jest (babel-jest)
v30.5.0Compare Source
Features
[@jest/expect-utils, jest-mock]AddmockFn.whenCalledWith(...args)for configuring return values per argument list, with first-class asymmetric-matcher support (#16053)[@jest/expect-utils]ExportAsymmetricMatcherandFunctionParameterstypes (previously private toexpect) (#16053)[jest-circus, jest-core, jest-jasmine2, jest-test-result, jest-types]--collectTestsnow expandstest.each/describe.eachcases and reports per-status counts (skipped/todo via the newwouldRunflag for selected tests) plus a summary line that match a real run, including under--testNamePatternand.only/fdescribefocus on both the circus and jasmine2 runners (#16259)[jest-circus, jest-environment, jest-runtime, jest-types]Add describe-level retries viajest.retryTimes(..., {entireDescribe: true})(#16322)[jest-circus, jest-message-util, jest-reporters, jest-types]AddretryMessagestoAssertionResultand exportformatErrorStack, so the retry log renders nestedcauseandAggregateErrorsections with code frames instead of serialized[cause]:/[errors]:markers (#16316)[jest-circus, jest-types]AddunhandledErrorsDetailedtoCircus.RunResult, so an unhandled rejection reports itscausechain andAggregateErrorentries with code frames instead of a pre-serialized stack (#16316)[jest-haste-map]ReplaceNodeWatcherandFSEventsWatcherwith@parcel/watcherfor the non-watchman watch path (#16188)[jest-resolve]Bumpunrs-resolverto 1.12.1, removejest-pnp-resolverand unnecessary checks (#15721)[jest-resolve]Honor Node's--preserve-symlinks/NODE_PRESERVE_SYMLINKSin the default resolver by passingsymlinks: falsetounrs-resolver(#16260)[jest-runtime]Apply automocking and manual__mocks__files to synchronously evaluable ESM graphs on Node 24.9+ - static imports, dynamicimport()andrequire()of an ESM file now generate an automock from the real module's namespace instead of failing with "Attempting to import a mock without a factory". Graphs that need async evaluation (top-level await) or an async-only resolver or transformer still throw (#16391)[jest-runtime]Routeprocess.getBuiltinModulethrough the sandbox, so it returns the sandboxprocessand the hookednode:moduleinstead of the host's (#16391)[jest-runtime]Throw an actionable error frommodule.register()andmodule.registerHooks()inside a test - the hooks attached to the loader running Jest itself, never saw the sandboxed requires they were meant for, and stayed registered for every later test file in the worker (#16391)[jest-runtime]Surface resolution and import-attribute errors in an ESM graph before executing any of its CJS dependencies on Node 24.9+, matching Node's run-nothing-on-a-broken-graph behavior; the legacy loader on older versions keeps its linking-time execution order (#16391)[jest-runtime]ThrowERR_SOURCE_PHASE_NOT_DEFINEDwith an actionable message forimport sourceandimport.source(), instead of failing at instantiation with V8's bare "Source phase import object is not defined" (#16391)[jest-runtime]Emit the JSON-without-import-attribute deprecation warning once per test file instead of once per worker, so it is no longer silently swallowed for every file after the first (#16391)[jest-runtime]Setimport.meta.maintotruein the test file andfalsein every module it loads, matching Node 24+ (#16367)[jest-runtime]Resolve themodule-syncexport condition, so a package that exposes its ESM entry point forrequire()loads the same file Node would (#16336)[jest-snapshot]Add external snapshot paths to custom reporter failure details (#16374)Fixes
[jest-console, jest-reporters]CustomConsolenow buffers console output soTestResult.consoleis populated for reporters whenverboseis enabled, whileGitHubActionsReporteravoids replaying buffered output in verbose mode (#16155)[expect, jest-message-util, jest-pattern, jest-regex-util, jest-util]Revertnode:protocol imports to restore webpack/browser-bundle compatibility (#16167)[expect]WidentoMatchObjectandobjectContainingparameter type fromRecord<string, unknown>toobjectso class instances are accepted (#16196)[jest-circus]Call a generator test body with the shared test context, sothismatches what a regular test function receives (#16347)[jest-circus]Capture the error listeners of the parent process instead of the in-sandboxprocess, so listeners registered before the test file survive teardown and sandbox listeners no longer leak onto the parent (#16347)[jest-circus]ClearcurrentlyRunningTestafter skipped and todo tests (#16342)[jest-circus]Prevent latedone()callbacks from affecting later test or hook invocations (#16343)[jest-circus, jest-jasmine2]Honor--expandwhen formattingnode:assertfailures, instead of always collapsing the diff (#16347)[jest-circus, jest-jasmine2, jest-message-util]Serialize the inner errors of anAggregateErrorintofailureMessages,retryReasonsandunhandledErrors, so--jsonoutput and reporter annotations include them (#16316)[jest-circus, jest-snapshot]Keep snapshot state and counts correct when a test retries (#16344)[@jest/create-cache-key-function]Include the caller support flags in the generated key, so a transformer that emits ESM or CJS based on them no longer shares one cache entry between the two (#16331)[@jest/create-cache-key-function]Include the stringified project config in the generated key, so editing a transformer's own settings invalidates what it cached (#16331)[@jest/transform]Include the caller support flags in a transform's cache key, so a file transformed both as ESM and as CJS no longer serves one shape's output for the other (#16331)[jest-config]Add missingfindRelatedTests,outputFile, andreplnameentries toValidConfigso they no longer trigger spurious "Unknown option" warnings (#16224)[jest-config]Use--configfor the global config when multiple--projectsare specified (#16273)[jest-core]Serializebigintvalues in--jsonand--outputFileoutput as their literal form (4n), instead of failing the run withTypeError: Do not know how to serialize a BigInt(#16338)[jest-core]Do not report aCustomGCasync resource (used by N-API addons such as napi-rs for per-isolate GC bookkeeping) as an open handle, since it isnapi_unref'd by the addon and can never keep the event loop alive (#16379)[jest-each]Keep a$&,$`,$'or$$inside a%pparam value out of the replacement, so the title shows the value instead of the text around it (#16338)[jest-each]Interpolate abigintinto a%jtitle as its literal form ("4n") at any depth, instead of throwingTypeError: Do not know how to serialize a BigIntwhile collecting the tests (#16338)[jest-environment, jest-runtime]BindsandboxInjectedGlobalsto the right values wheninjectGlobalsisfalse, instead of shifting every one of them by a position (#16377)[jest-environment-node, jest-util]Only warn about a conflictingglobalsCleanupmode when one was explicitly configured, and follow the mode that is actually in effect (#16323)[jest-environment-node, jest-util]Stop resolving lazy globals when setting up an environment, so Node 26's builtin module globals are no longer loaded (and no longer emit their deprecation warnings) for every test file (#16324)[jest-haste-map]Keep watch mode alive when an outside process briefly makes a file unreadable on Windows, instead of tearing the watcher down onEPERM(#16295)[jest-haste-map]Keep indexing when an outside process holds a file open on Windows, instead of failing the whole crawl onEPERM(#16358)[jest-haste-map]Keep a duplicated manual mock resolving when the file it pointed at is deleted in watch mode (#16360)[jest-haste-map]Shut the worker farm down when a duplicate manual mock aborts the build underthrowOnModuleCollision(#16354)[jest-haste-map]Attach the watchman client'serrorlistener before the first command, so a watchman failure falls back to the node crawler instead of crashing on an unhandlederrorevent, and always end the client (#16355)[jest-haste-map]Stop delivering watch events afterWatchmanWatcheris closed, and route its warnings through the configured console (#16355)[jest-haste-map]Restore the nestedduplicatesindex correctly inModuleMap.fromJSON, so a haste collision reported inside a test worker raisesDuplicateHasteCandidatesErrorinstead of aTypeError(#16353)[jest-haste-map]Match watched files on a full extension, somoduleFileExtensions: ['js']no longer acceptsfoo.mjs(#16352)[jest-haste-map]Delimit the fields that make up the haste map cache key, so two different option sets cannot hash to the same cache file (#16352)[jest-message-util]Print the inner errors of anAggregateErrorthrown inside a test (#16316)[jest-message-util]Indent nestedcauseandAggregateErrorsections of a test failure by one level per depth, so the nesting is legible instead of rendering flat (#16316)[jest-message-util]Color stack traces line by line so blank lines stay blank (#16316)[jest-message-util]Detect Jest's own frames without assuming the checkout directory's name, and cover@jest/*packages, so stack traces and code frames point at user code (#16326)[jest-mock]mockResolvedValue/mockRejectedValuenow see all overload return types, so a Promise-returning overload survives even when a later overload returns a non-Promise (e.g.pg.Client['end']) (#16237)[@jest-environment/jsdom-abstract]Make@types/jsdoma peer dependency (#16166)[jest-mock]Remove the leftover own accessor descriptor when restoring aspyOnof an inherited getter or setter, so the instance keeps reflecting the prototype (#16226)[jest-resolve]IncludeextensionsToTreatAsEsmin theshouldLoadAsEsmcache key, so projects with different extension lists don't read each other's answers (#16369)[jest-resolve]MakegetModuleIDAsyncbuild and cachedata:URI module IDs the same way asgetModuleID(#16370)[jest-resolve]Keep thenode:prefix when resolving a core module asynchronously, so a builtin that only exists prefixed (node:sea,node:sqlite,node:test,node:test/reporters) resolves instead of failing as a missing bare package (#16388)[jest-resolve]Look up manual mocks fornode:protocol specifiers under the unprefixed name they are stored as (#16388)[jest-resolve]ApplymoduleNameMapperconsistently to both spellings of core module specifiers (fsvsnode:fs) (#16390)[jest-resolve]Keep virtual and ordinary mock module IDs isolated across test files (#16296)[jest-resolve]Guard missingrequire.resolve.paths(#16052)[jest-resolve, jest-config, jest-runner]Support a user resolver written as an ES module (#16332)[jest-resolve, jest-runtime]Throw the CJS parse error for ESM syntax in a"type": "commonjs"package or a.cjsfile instead of loading it as ESM, matching Node (#16368)[@jest/source-map]Keep source map sources that name a scheme, such aswebpack:///, instead of resolving them into a path that does not exist (#16327)[@jest/source-map]Look up--testLocationInResultspositions at the right column, and keep a mapping to the first column instead of discarding it (#16327)[@jest/source-map]Warn when a source map cannot be parsed, instead of silently leaving its frames untranslated (#16327)[jest-runner, @jest/source-map]Keep a source-mapped stack for an error thrown after the test environment was torn down (#16327)[jest-runtime, @jest/source-map]Keep source maps past teardown and past the next test file'sinstall, so a stack from a file no earlier stack mentioned still points at the original source (#16330)[jest-runtime]Report that no coverage was collected whengetAllV8CoverageInfoCopyis called afterteardown, instead of returning an empty result (#16385)[jest-runtime]Cache a CJS module's parsed exports before walking its re-exports, so two modules that re-export each other no longer overflow the stack when imported from ESM (#16363)[jest-runtime]Keep a re-exported ES module's parse failure from marking the re-exporting CommonJS file as ESM, somodule.exports = require('./dep.mjs')loads instead of failing withmodule is not defined(#16363)[jest-runtime]Scope module mocks instantiated insidejest.isolateModules/isolateModulesAsyncto that block, so a mock first imported there no longer outlives it - matching how CommonJS mocks already behave (#16365)[jest-runtime]Suspend module isolation while generating an automock, so loading the real module to read its shape no longer populates the isolated registry (#16365)[jest-runtime]Check a cached ES module's status beforerequire()returns it, so a module whose evaluation threw rethrows that error and one left linked by a failed sibling is evaluated instead of returning uninitialized bindings (#16364)[jest-runtime]Report the originalERR_REQUIRE_ASYNC_MODULEwhen arequire()of a top-level-await graph is retried, instead of a spurious "concurrentimport()" error (#16364)[jest-runtime]Throw the evaluation error when another caller'simport()of the same module failed while we awaited it, instead of resolving with the errored module (#16364)[jest-runtime]Mark the result ofrequire()ing an ES module that has a default export with__esModule: truethrough a live-binding facade, and serve the same object fromrequire.cache, matching Node (#16367)[jest-runtime]Provide a CommonJS module's exports under the'module.exports'named export when imported from ESM, matching Node 23+ (#16367)[jest-runtime]Give the test file itself a non-nullrequire.main(#16367)[jest-runtime]Populatemodule.childrenwith the modules a file loads, matching Node (#16368)[jest-runtime]Provideimport.meta.resolveandimport.meta.jestindata:URI modules, accept any-case mediatype parameters, and use Node's error codes for invaliddata:URIs (#16368)[jest-runtime]Key ES modules by full URL, so query and fragment suffixes create the same module instances as Node and show up inimport.meta.url(#16375)[jest-runtime]Share modules between overlapping graphs when a CommonJS modulerequire()s an ES module mid-load, instead of evaluating shared dependencies twice (#16375)[jest-runtime]ThrowERR_REQUIRE_CYCLE_MODULElike Node when a CommonJS modulerequire()s an ES module that is still being loaded, instead of evaluating the module a second time (#16366)[jest-runtime]Key builtin modules in the ESM registry by one canonical specifier (#16341)[jest-runtime]import.meta.resolve()for a builtin uses itsnode:specifier (#16341)[jest-runtime]Fall back to native ESM when a.jsfile contains ESM syntax but has no"type":"module"marker (#16152)[jest-runtime]Allowrequire()of ESM-marked files on Node < 24.9 via transform fallback (#16244)[jest-runtime, @jest/transform]Surface actionableERR_REQUIRE_ESMerror for files with untransformed ESM syntax instead of the generic "unexpected token" message (#16244)[jest-runtime]Support older test environments whosemoduleMockerdoes not implementclearMocksOnScope(#16169)[jest-runtime]Applyjest.unstable_mockModulewhen the mocked file itself isrequire()d, not only when it is imported as a dependency (#16389)[jest-runtime]Applyjest.unstable_mockModuleto statically importeddata:URIs on Node 24.9+, matching dynamicimport()(#16389)[jest-runtime]Run an asyncjest.unstable_mockModulefactory once per module instead of twice, and fail the import instead of crashing the worker when the factory rejects (#16389)[jest-runtime]Hide arequire(esm)module that failed to evaluate fromrequire.cache, as Node does, instead of exposing a namespace with uninitialized bindings (#16389)[jest-runtime]Strip the byte-order mark when importing a JSON module, matchingrequire()and Node (#16389)[jest-runtime]ThrowERR_REQUIRE_ASYNC_MODULEwhenrequire(esm)runs under an async-only custom resolver, instead of silently resolving with the default resolver (#16389)[jest-runtime]Parse imported JSON modules with the test realm'sJSON, so their objects passinstanceof Objectinside the test likerequire()d JSON does (#16389)[jest-runtime]Accept everyfile:URL string in the sandboxedmodule.createRequire, including one with alocalhostauthority, as Node does (#16389)[jest-runtime]Point at{virtual: true}whenjest.mockorjest.unstable_mockModuleis given a module that cannot be resolved (#16389)[jest-reporters]Fix coverage report table formatting in CI/GitHub Actions environments whereprocess.stdout.columnsis undefined by falling back to theCOLUMNSenv var or80columns in CI, preserving existing behaviour in other non-TTY environments (#16227)[jest-runtime]Support CJS-in-ESM exports via"module.exports"named exports (#16277)[jest-snapshot]Keep a skipped or failed test's hinted snapshots, instead of reporting them obsolete (#16348)[jest-util]StopglobsToMatcherreusing a cached matcher compiled with different picomatch options, and keep itsdot: truedefault whendotis passed asundefined(#16381)[pretty-format]Move thereact-isaliases into the@jestscope, so they cannot be shadowed by unrelated packages published under the alias names (#16333)Chore & Maintenance
[docs]Document the intentional divergences from Node's module system in the ECMAScript Modules page (#16368)[docs]Note deprecation ofreact-test-rendererin React Native tutorial andpretty-formatREADME (#16294)[docs]Use@testing-library/react-nativein the React Native tutorial instead of the deprecatedreact-test-renderer(#16318)[babel-jest, @jest/transform]Updatebabel-plugin-istanbulto v8 (#16049)[jest-config, @jest/reporters, jest-runtime]Updateglobto v13 (#16397)[jest-haste-map]Refactor massive class into multiple files (#16180)[jest-haste-map]Dropwalkerdependency; replace hand-rolled directory recursion in the JS crawler and watcher startup withfdir(#16187)[jest-haste-map]Reuse cached metadata for files whose haste name is a known duplicate, instead of re-reading and re-parsing them on every startup (#16351)[jest-haste-map]Cache the watchman socket path and replace thewatchman --versionprobe withget-sockname, so warm runs spawn no watchman processes (#16386)[jest-resolve]Store the per-directory package-type lookup in the cache it reads, so it actually memoizes (#16369)[jest-resolve, jest-runtime]Cut repeated work on the resolution hot path: hoist the platform-extension list to construction, memoizeisCoreModuleand the options cache-key serialization, skip mapper preparation when nomoduleNameMapperis configured, run each mapper regex once, and stop re-parsingNODE_OPTIONSon every default-resolver call (#16371)[jest-resolve]Cut warm resolution cost to about a third: reuse oneunrs-resolverfactory per options shape instead of cloning per resolution, compose the factory cache key from per-array cached strings instead of serializing options, and stop constructing anErrorfor misses thatfindNodeModuleswallows; add a__benchmarks__suite for the default resolver (#16373)[jest-runner, @jest/source-map]Replacesource-map-supportwith an implementation in@jest/source-map(#16327)[jest-snapshot]Load babel, semver and synckit lazily, so requiring the package (which every test process does through@jest/expect) no longer loads ~200 modules that only writing inline snapshots needs (#16387)[jest-runtime]Reduce per-require overhead: skip module ID resolution when no mock can apply, answer core modules before probing for a manual mock, share onerequire.cacheproxy across modules, and cache empty files (#16376)[@jest/source-map]DeprecategetCallsitein favour ofSourceMapSupport#getCallsite(#16327)[jest-runtime]Avoid magicalnullvalue in ESM loader (#16160)cypress-io/cypress (cypress)
v15.21.1Compare Source
Changelog: https://docs.cypress.io/app/references/changelog#15-21-1
pnpm/pnpm (pnpm)
v11.24.0: pnpm 11.24Compare Source
Minor Changes
Patch Changes
Fixed pnpm v11 incorrectly reporting
confirmModulesPurgeas unrecognized when set inpnpm-workspace.yaml. The Rust CLI now identifies the unsupported option as a pnpm v11 setting instead of suggesting an unrelated setting.pnpm install --frozen-lockfileno longer fails withERR_PNPM_FROZEN_LOCKFILE_WITH_OUTDATED_LOCKFILEwhen the pinned pnpm version recorded inpnpm-lock.yamlhas to be re-resolved before it can be installed. It runs the pnpm version the lockfile pins and leaves the lockfile unchanged #14124.Under
nodeLinker: hoisted, peer-resolution variants of an injected directory dependency (afile:snapshot) are materialized as separate copies again instead of collapsing onto the first-seen variant. Each copy keeps its own peer-resolved dependency set, so a project pinning one peer version no longer resolves another project's variant — Bit root components with conflicting peers across injected copies rely on this.Fixed
pnpm install --merge-git-branch-lockfiles --frozen-lockfilefailing withERR_PNPM_OUTDATED_LOCKFILEwhen a branch lockfile predates the removal of a dependency, or its move to another dependency group #13966. A dependency that no project declares anymore is no longer reinstated by the merge, and the packages it was the only path to are dropped with it.Batch workspace publishing accepts a shared scope-specific credential, rejects mismatched credentials for a registry before publishing, and runs the
publishandpostpublishscripts after each completed registry group pnpm/pnpm#14101.The Rust CLI now honors five settings it recognized but ignored:
updateNotifier,legacyDirFiltering,initAuthorName/initAuthorEmail/initAuthorUrl,initLicense, andinitVersion.pnpm installandpnpm addcheck once a day for a newer pnpm and print how to get it (turn it off withupdateNotifier: false); a{<dir>}filter selector can go back to matching the subtree below the directory withlegacyDirFiltering: true; andpnpm initwrites the configured author, license, and version into thepackage.jsonit scaffolds.PNPM_CONFIG_INIT_VERSIONis now read as well.maxsockets, npm's spelling ofmaxSockets, is no longer ignored: both spellings are read frompnpm-workspace.yaml, the global config file, the environment, and the command line, in that increasing order of precedence — a value passed on the command line now wins even when the two sides spelled the setting differently.A
lastUpdateChecktimestamp dated in the future — after a clock change, a restored snapshot, or a hand-edited state file — no longer silences the update check until that time comes around.legacyDirFilteringno longer reaches the workspace-root selectors pnpm generates for itself: the!{<workspace-root>}exclusion a recursiverun/exec/add/testappends, and the{<workspace-root>}inclusion--workspace-rootappends. Read as subtree matches they named every project below the root, so a recursive command under the setting selected nothing at all, and--workspace-rootpulled in every project below the root instead of the root alone #14101.pnpm install --frozen-lockfileno longer fails whenpnpm-lock.yamlrecords the pinned pnpm version alongside an engine package the running pnpm does not install it from. An entry pinning another version is still refused, and a plain install rewrites the block #14124.v11.23.0: pnpm 11.23Compare Source
Minor Changes
pnpm config getandpnpm config listnow show the settings pnpm acts on under their documented names:registriesshows the registries pnpm resolves from, merged across every source (.npmrc,pnpm-workspace.yaml, the global config, CLI flags), in the shape the setting is written in: keyed by registry URL, with the default registry declared as the bare@scope. Built-in routes are included — the@jsrscope and thenpmjsandghprefixes — unless pointed elsewhere. Previouslypnpm config get registriesprintedundefined.updateandauditshow the effective sections, whichever spelling set them. The deprecated internal spellings (updateConfig,auditConfig,auditLevel) are no longer listed.catalogsshows the complete resolved catalog set — the singularcatalogblock is itsdefaultentry — whichever spelling declared it.registryand@scope:registryentries show the merged routes rather than raw.npmrcvalues, so they always agree with theregistriesview.Settings that no supported pnpm version recognizes get their own warning. A key in the global config file that this version of pnpm does not read is no longer reported with advice to move it to a project-level
pnpm-workspace.yaml(where it would be ignored too); the warning now says the setting is not recognized by this version of pnpm, names the pnpm version that does read it when there is one (for example,globalShimsis a pnpm v12 setting), and suggests the closest real setting name when the key looks like a typo. Unrecognized and non-camelCase keys in a project'spnpm-workspace.yaml, previously ignored silently, are now reported the same way.pnpm config get <key>andpnpm get <key>no longer print config-load warnings, so a script capturing the value gets the value alone.The
importPackagepnpmfile hook is deprecated. pnpm now prints a warning when a pnpmfile defines it, and the hook will be removed in the next major version. It also opts the installation out of the parallel package importer, making installation slower. If you rely on this hook, comment on #14101.node_modules/.modules.yamlno longer records the registries an install resolved from, and the recorded copy is dropped from the file on the first install that rewrites it.It dated from the lockfile format that spelled a dependency's path relative to its registry, where reading an installed tree meant knowing the registries it was installed with. Dependency paths have not carried a registry for several major versions, and the recorded copy outlived its use:
pnpm list,pnpm why, and single-project installs preferred it over the project's own configuration, so a project whose registry had changed since its last install was still read through the old one.They now use the configured registries, like every other command already did.
When
enableGlobalVirtualStoreis on, every process pnpm spawns for the project (pnpm run,pnpm exec, lifecycle scripts) now receives aNODE_PATHpointing at the project's hoistednode_modules, plus aNODE_OPTIONS--importflag that registers a resolve hook restoringNODE_PATHlookups for ESM imports. Dependencies that import undeclared ("phantom") packages keep resolving under the global virtual store — for both CommonJS and ESM — without installing the@pnpm/plugin-esm-node-pathconfig dependency pnpm/pnpm#9618. Tools run bypnpm dlxresolve such dependencies too: the JS CLI passes them the same environment, while the Rust CLI's dlx cache is self-contained, so its layout already exposes them.A registry can now declare that its abbreviated metadata carries the
timefield, soresolutionMode: time-basedreads the full metadata document only from the registries that need it:registry.npmjs.orgomitstimefrom abbreviated metadata, so a time-based resolution has to fall back to the much larger full document. That fallback used to be all-or-nothing:registrySupportsTimeFieldanswered for every registry at once, so a project resolving from both the public registry and a Verdaccio instance either paid for full metadata everywhere or claimed atimefield npmjs does not serve. The answer is now per registry, andregistrySupportsTimeFieldremains the answer for every registry that does not declare one.The declaration is also sent to a pnpr server, which applies it to the resolution it runs on the client's behalf.
A pnpr resolve request now carries the client's registries the way the
registriessetting declares them — keyed by URL, with the scopes routed to each, the bare-specifier prefix each answers to, and each one'sserverType— in place of the prefix map it used to send.The server routes them through the same inversion the config reader runs, so a pnpr-served install resolves a scoped dependency from the registry that scope is routed to, which it previously could not: only the default registry and the prefix-addressed ones reached the server. A declared
serverTypereaches it too, so the tarball URLs pnpr omits from the lockfile match the ones the client reconstructs.Built-in scope routes the project has not pointed elsewhere are not declared, so a pnpr server's allowlist is not as
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.