Repository navigation
chore(deps): update all non-major dependencies - #320
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Cloudflare preview✅ Preview deployed: https://libroo-pr-320.00doggies-revers.workers.dev Worker: |
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
October 6, 2026 08:40
8223458 to
1a298d8
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
October 6, 2026 15:26
1a298d8 to
9739d27
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
October 7, 2026 20:07
9739d27 to
cc902d3
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
October 7, 2026 23:31
cc902d3 to
60cdae8
Compare
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^1.7.6→^1.7.71.3.0→1.3.7^1.2.137→^1.2.140^1.2.97→^1.2.991.3.9→1.3.12^4.3.2→^4.3.3^4.11.2→^4.11.3^3.4.1→^3.4.2^1.7.6→^1.7.7^10.11.0→^10.12.0^10.0.11→^10.0.1512.6.0→12.10.1^3.3.11→^3.3.124.142.0→4.148.0Release Notes
better-auth/better-auth (@better-auth/passkey)
v1.7.7Compare Source
cloudflare/workers-sdk (@cloudflare/vitest-plugin)
v1.3.7Compare Source
Patch Changes
b4e1299,b75421f,0ec13b7,2b1a0ca,c492d63,ba52118,946aaa7,48f3c04,14f0339,5606a74,4d308f6,f8cdcb9,e44cf6b,aa2f9b7,42c7219,2dde890,26e03e2,2dde890,0b51fec]:v1.3.6Compare Source
Patch Changes
7f700ef,90e6a1b,7f57b1c,6a4b0fe]:v1.3.5Compare Source
Patch Changes
b8e7cc3,b00ef4f,9d7b08e,464a582,aee2842,efd67e6]:v1.3.4Compare Source
Patch Changes
b9f1cdc,ddaa558,8468487,a0712e5,a0712e5]:v1.3.3Compare Source
Patch Changes
91a3606,2a15ae2]:v1.3.2Compare Source
Patch Changes
7bb6eae,60ccdbd,62fd03a,06ed9c8,86211fe,c2bb4c8,eb1efe0,485cfb3]:v1.3.1Compare Source
Patch Changes
7f0734c]:nuxt/scripts (@nuxt/scripts)
v1.3.12Compare Source
🐞 Bug Fixes
View changes on GitHub
v1.3.11Compare Source
🐞 Bug Fixes
View changes on GitHub
v1.3.10Compare Source
🐞 Bug Fixes
View changes on GitHub
nuxt/test-utils (@nuxt/test-utils)
v4.3.3Compare Source
👉 Changelog
compare changes
🔥 Performance
toWebHandlerinstead ofnode-mock-http(abe8ad944)h3from the project (b5d802f03)estree-walkerwithoxc-walker(8e8ca5e8b)local-pkgwithexsolve(38938a879)c12with native dotenv parsing (26c72afa0)destrandsculeusage (e4bfd2ebe)node-fetch-nativepolyfill (6b654de5c)nypmwithpackage-manager-detector(#1828)🩹 Fixes
registerEndpointagainst the projecth3(#1831)🏡 Chore
vueto peer dependencies (e70592ffa)nuxtversions as peer dependency (b473892c9)🤖 CI
0ad46c892)pnpm/setupanddevEngines(#1814)❤️ Contributors
nuxt/ui (@nuxt/ui)
v4.11.3Compare Source
Bug Fixes
dirprop to the provided locale (#6767) (93c40df)method="post"to prevent input leaking via GET before hydration (#7078) (57f7699)aria-labelon icon-only buttons (#7009) (7f0250e)dirtystate (#6545) (8977394)usePrefix(#7074) (77c92de)@custom-variantforlightanddarkvariants (#7023) (584016b)setandsetAtPath(#7077) (4bfd115)unjs/unhead (@unhead/vue)
v3.4.2Compare Source
🐞 Bug Fixes
View changes on GitHub
better-auth/better-auth (better-auth)
v1.7.7Compare Source
Patch Changes
#11476
4186e36Thanks @bytaesu! - Return CAPTCHA errors with the correct JSON Content-Type header.#11469
8620aa9Thanks @aryan1306! - Return rate limit errors with a JSON Content-Type header.#11491
55cb92eThanks @bytaesu! - Respect social providerdisableSignUpwhen signing in with an ID token.#11375
69defbcThanks @bytaesu! - Refresh the active organization after sign-in when a session hook selects the initial organization.#11494
ac54bfdThanks @gustavovalverde! - Isolate OAuth state cookies and each OAuth Proxy payload with purpose-specific encryption keys. TheoAuthProxyoptions and supported configuration remain unchanged.Upgrade all Better Auth nodes that handle the same cookie-backed OAuth or SAML relay-state flow together. Upgrade every OAuth Proxy participant, including production and preview or development deployments, in the same cutover. OAuth sign-in, account-linking, and cookie-backed SAML sign-in flows started before the upgrade must be restarted. Mixed old and new participants cannot exchange existing state or proxy payloads, and there is no fallback to the previous shared key.
#11494
ac54bfdThanks @gustavovalverde! - Magic Link verification now accepts only records issued for Magic Link. MagicLink records and database-backed OAuth or SAML state use separate verification
identifier prefixes. Links and database-backed sign-ins started before the
upgrade cannot complete; request new Magic Links and restart those sign-ins.
Upgrade servers sharing verification storage together, and update
verification.storeIdentifier.overridesrules for these flows to match the newmagic-link:andauth-state:prefixes. The link token, callback state,endpoints, and public option types are unchanged.
Upgrade installed Better Auth adapters, plugins, and integrations released
with
better-authalongside it so participating packages use the same releaseversion.
Updated dependencies [
35d7cd3,07bdf7e]:eslint/eslint (eslint)
v10.12.0Compare Source
Features
4618052feat: handle astral letters innew-cap(#21357) (sary)4ec5168feat: allowSourceCode#getText()to accept tokens and comments (#21340) (electrohyun)Bug Fixes
bc51eeefix:prefer-arrow-callbackfalse positive in conditional test (#21373) (Daniel Pinto)bbff86cfix: skip lines with multiple comments inmax-lines-per-function(#21332) (xbinaryx)efc4d6bfix: astral letters inconsistent-return,no-eval,no-invalid-this(#21360) (lumir)93de066fix: prefer-exponentiation-operator autofix for async function base (#21322) (Vladimir Babin)02e34fffix: add missing space afterelseincurlyautofix (#21355) (Pixel)b14b8bcfix: correctid-lengthmessage for long private names (#21348) (Pixel)69aac01fix: supportTSFunctionTypeingetFunctionHeadLoc(#21335) (xbinaryx)686630efix:no-loss-of-precisionfalse positive with0.e5(#21337) (sethamus)Documentation
67eb586docs: Update README (GitHub Actions Bot)5370d7edocs: clarifyone-varseparateRequiresmatches anyrequire()call (#21192) (sethamus)8816c1ddocs: Update README (GitHub Actions Bot)3d2e7cedocs: fix typo in no-unused-expressions documentation (#21346) (bytedoe)Chores
152067fchore: update ecosystem plugins (#21362) (ESLint Bot)b56d58echore: update github/codeql-action action to v4.38.2 (#21376) (renovate[bot])bfaea12perf: cache normalized config globals per languageOptions (#21364) (James Ross)322209eci: avoid Nx cache in ecosystem tests and disable failing test (#21369) (Francesco Trotta)d166567chore: update dependency prettier to v3.9.9 (#21371) (renovate[bot])29585cechore: update dependency eslint-plugin-expect-type to ^0.7.0 (#21359) (renovate[bot])39d79bachore: update github/codeql-action action to v4.38.1 (#21354) (renovate[bot])182a6e9chore: update dependency prettier to v3.9.8 (#21352) (renovate[bot])f995127chore: remove CLAUDE.md in favor of AGENTS.md (#21339) (Jarren)b95fb6cchore: update dependency prettier to v3.9.7 (#21347) (renovate[bot])3782dd4chore: update ecosystem plugins (#21342) (ESLint Bot)nodemailer/nodemailer (nodemailer)
v10.0.15Compare Source
Bug Fixes
v10.0.14Compare Source
Bug Fixes
v10.0.13Compare Source
Bug Fixes
v10.0.12Compare Source
Bug Fixes
pnpm/pnpm (pnpm)
v12.10.1: pnpm 12.10.1Compare Source
This release fixes
pnpm installfailures after anoverrideschange and on a filtered frozen install withcatalogPrune. It also fixes several bugs in the experimentalnodeLinker.type: loaded, which now keeps its generated files innode_modules.Patch Changes
With
nodeLinker.type: loaded, pnpm now writes its generated files tonode_modules, which projects already ignore in git. The store manifest and loader arenode_modules/.pnpm/.store-manifest.jsonandnode_modules/.pnpm/.store-loader.mjs. Bin shims are innode_modules/.bin.Earlier versions wrote
.pnpm-store.jsonand.pnpm-store-loader.mjsto the project root, and a.pnpmdirectory to the root and to each workspace package. Delete them after reinstalling.With
nodeLinker.type: loaded, packages that ship their ownnode_modulesdirectory, such asnpmwith its bundled dependencies, now load from the store. Before, one such package in the install stopped every Node.js process from starting.With
nodeLinker.type: loaded, scripts can now run a Node.js runtime installed throughdevEngines.runtime. Before, every script that callednodere-ran its own shim until it failed with "Argument list too long".With
nodeLinker.type: loaded, Node.js processes start faster. In a project with 13,000 stored files, the startup overhead per process dropped from 67 ms to 18 ms.pnpm installno longer fails withERR_PNPM_NO_MATCHING_VERSIONafter a change tooverrideswhen the lockfile resolves an optional peer dependency to an npm alias of another package #16654.A frozen install with
catalogPruneno longer removes catalog entries thatpnpm-lock.yamlstill records. Before,pnpm install --frozen-lockfile --filterfailed withERR_PNPM_LOCKFILE_CONFIG_MISMATCHwhen some workspace projects were missing from disk #16638.pnpm install --fix-lockfileno longer removes thedeprecatedandhasBinfields from lockfile entries #6600.With
enableGlobalVirtualStore, an install that updatesnode_modulesnow repairs a package in the global virtual store that an interrupted install left without some of its dependency links or package files. Before, such an install kept the incomplete package if the project'snode_modulesalready recorded it #16642.pnpm installnow skips the Cargo and Python projects inside a nested directory that has its ownpnpm-workspace.yamlor.gitdirectory, such as a git worktree of the same workspace or a separate clone.The
Request tookwarning for package metadata now starts timing when pnpm sends the request. Before, it also counted the time the request waited for a free request slot, so large installs printed it for requests the registry answered quickly.Platinum Sponsors
Gold Sponsors
v12.10.0: pnpm 12.10.0Compare Source
This release adds an experimental
loadednode linker, letspnpm-lock.yamlrecord resolution settings, and reads cached registry metadata faster. It also carries several security fixes, including one that stops a dependency version from writing files outside the global virtual store.Minor Changes
Added experimental
nodeLinker: { type: loaded }installation. Compatible dependencies load directly from the content-addressable store through an automatically registered Node.js loader.nodeLinker.excludedselects packages and their dependency trees to install in the global virtual store.lockfile.includeResolutionSettings: truemakespnpm-lock.yamlrecordautoDedupe,dedupeInjectedDeps,dedupePeerDependentsandlinkWorkspacePackages. Installs then treat a lockfile that records other values as outdated. A lockfile that recordsautoDedupeis reused by later installs on any machine, sopnpm runafterpnpm install --frozen-lockfileno longer starts another install #16583.Patch Changes
Security
pnpm installnow prevents dependency versions with path traversal from writing files outside the global virtual store.pnpm now verifies locked config dependencies against their registry before installing them. Config dependencies must come from an npm registry. The lockfile can no longer replace the integrity of a config dependency pinned with
version+integrity.Lockfile verification now checks the tarballs inside a
variationsresolution against the registry. Aname@versionlockfile entry with an emptyvariationsresolution is now rejected.pnpm audit signaturesnow verifies signatures against the integrity recorded in the lockfile. Packages without a recorded integrity cannot pass signature verification.pnpm installandpnpm publishnow reject archive metadata larger than 64 MiB before reading it into memory. Publishing a pre-built tarball also rejects manifests and README files larger than 64 MiB.Two URL or local path dependencies no longer share a virtual store directory when one URL has
+,#,:, or?where the other has/. Such dependencies, including git dependencies pinned with#, now get a hash suffix on their directory name.The warning about an ignored project
.npmrcregistry setting no longer prints the username and password of a URL-scoped key such as//user:password@registry.example.com/${PATH}/:_authToken.Installing and resolving dependencies
pnpm installnow fails withERR_PNPM_UNSUPPORTED_PROTOCOLwhen a dependency uses a specifier with a protocol pnpm does not support, such as Yarn'spatch:. On Windows, such a specifier failed withos error 123. On other platforms, pnpm linked it to a directory that does not exist. Reading apackage.jsonthat fails now names the file #16590.pnpm installnow fails withERR_PNPM_PACKAGE_MANIFEST_INVALID_ATTRIBUTEwhen a project declares a dependency whose specifier is not a string, such as"is-positive": 42. Before, the dependency was silently left out of the lockfile. AreadPackagehook can still correct the specifier.Fixed
pnpm installfailing withERR_PNPM_CMD_SHIM_RESOLVE_PATHwhen an executable's parent directory contains a dangling symlink.pnpm install --frozen-lockfileno longer fails withERR_PNPM_RESOLUTION_SHAPE_MISMATCHwhen aname@versionlockfile entry has a resolution served by a custom fetcher pnpm/tasks#108.pnpm install --fix-lockfilerepairs a lockfile whose importer references a package that has no snapshot entry, as left by a badly merged lockfile. It failed withERR_PNPM_LOCKFILE_MISSING_DEPENDENCYsince 12.8.0 #16618.When a dependency moves an exact dependency of its own to an older version, a peer dependency that pnpm installed automatically now moves with it. Before,
pnpm installandpnpm dedupekept the newer locked version of the peer, so the lockfile held two copies of it, for example two copies ofvuepnpm/tasks#61.pnpm dedupenow reads registry metadata for a dependency pinned to an exact version, aspnpm installdoes. If the registry metadata disagreed with the package'spackage.json, the lockfile it wrote depended on whetherminimumReleaseAgewas set #16615.Speed and size
Dependency resolution reads cached registry metadata faster. The metadata cache moved to
<cache-dir>/v12/, so the first install after upgrading downloads registry metadata again. A damaged cache entry is downloaded again, or reported as an error when--offlineis set.pnpm cache prunealso removes the metadata cache that older pnpm versions wrote under<cache-dir>/v11/#13512.Package metadata requests no longer wait behind queued tarball downloads when
maxSocketsor a proxy limits the connections to a registry. Large installs resolve faster and print fewerRequest tookwarnings.Sped up installs in large workspaces on macOS when the dependency links already exist. pnpm now keeps a link that already points at the right package without trying to create it first. Relinking the direct dependencies of 1,000 workspace projects took 45 ms, down from 116 ms pnpm/tasks#65.
Commands in a project that pins a different pnpm version start about 13 ms faster on macOS. pnpm now runs the pinned version's binary directly, without the shell script in front of it pnpm/tasks#66.
The pnpm binary is about 0.9 MB smaller, and the arm64 Linux binary is about 1 MB smaller still.
Running scripts and commands
pnpm runno longer prints[ELIFECYCLE] Command failed ...after Ctrl+C ends the script. pnpm still exits the way the script's shell did: on Windows with the shell's exit code (cmdreports-1073741510, PowerShell1), on Unix by re-raisingSIGINT#16579.pnpm run "/<regex>/"now accepts JavaScript regular expression syntax such as lookahead and lookbehind. A selector like"/^hello:(?!b).*$/"failed withERR_PNPM_NO_SCRIPT#16604.pnpm runandpnpm execnow forward--config.*command-line flags to the install started byverifyDepsBeforeRunpnpm/tasks#60.On Windows, a process started by
pnpm runorpnpm execcan again start a child withCREATE_BREAKAWAY_FROM_JOB. That child keeps running after pnpm exits, even if the command fails #16628.Empty
nodeOptionsvalues from command-line flags and environment variables now override lower-priority settings. Scripts retainNODE_OPTIONSfrom the parent environment orextraEnvwhennodeOptionsis empty.pnpm now reads the
failIfNoMatchsetting frompnpm-workspace.yaml, so a filter that matches no workspace project exits with code 1 when the setting istrue. The new--no-fail-if-no-matchflag turns the setting off for one command #16577.Configuration, setup, and pnpm versions
pnpm config get --globalandpnpm config list --globalnow show only the global configuration, also when run inside a project. Settings from the project'spnpm-workspace.yamland.npmrcwere included before. The same applies to--location=global#16598.pnpm now prints config warnings, such as an unset environment variable in
.npmrc, when loading the config fails.pnpm 11 releases older than 11.28.4 can run pnpm 12 again when the
packageManagerfield pins it. Since 12.9.0 they failed withSyntaxError: Invalid or unexpected token#16594.On Windows,
pnpm self-updateno longer runs the update a second time when it replaces apnpm.cmdlinked by pnpm 12.8 or older. cmd.exe read on in the replacedpnpm.cmd, printed an error about a command that is not recognized, and ran the new pnpm once more #16573.pnpm setupnow puts$PNPM_HOME/binfirst onPATHin login shells that inherited it further down, such as the VS Code terminal on macOS. Before, anothernodetook precedence over the one installed bypnpm runtime set node -g. Runpnpm setupagain to update the block in your shell config [#16635](httConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.