Skip to content

fix(deps): update all non-major dependencies - #2823

Open
renovate-bot wants to merge 1 commit into
ghiscoding:masterfrom
renovate-bot:renovate/all-minor-patch
Open

renovate-bot wants to merge 1 commit into
ghiscoding:masterfrom
renovate-bot:renovate/all-minor-patch

Conversation

@renovate-bot

@renovate-bot renovate-bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@hono/node-server ^2.1.3 → ^2.1.4 age confidence
@microsoft/api-extractor (source) ^7.59.3 → ^7.59.4 age confidence
cssnano ^9.3.2 → ^9.4.0 age confidence
pnpm (source) 11.28.4 → 11.28.5 age confidence
vite (source) ^8.3.2 → ^8.3.4 age confidence
vue-router (source) ^5.3.1 → ^5.4.0 age confidence

Release Notes

honojs/node-server (@​hono/node-server)

v2.1.4

Compare Source

What's Changed

Full Changelog: honojs/node-server@v2.1.3...v2.1.4

microsoft/rushstack (@​microsoft/api-extractor)

v7.59.4

Tue, 06 Oct 2026 00:04:37 GMT

Version update only

cssnano/cssnano (cssnano)

v9.4.0: v9.4.0

Compare Source

What's Changed

New Features
  • feat(cssnano-preset-default): merge more overridden declarations in #​2033

Full Changelog: https://github.com/cssnano/cssnano/compare/cssnano@9.3.2...cssnano@9.4.0

pnpm/pnpm (pnpm)

v11.28.5: pnpm 11.28.5

Compare Source

This release reads cached registry metadata faster and makes pnpm config get --global ignore project settings. It also carries several security fixes for package archives, git dependencies, and config dependencies.

Patch Changes
Security
  • pnpm now verifies locked config dependencies against their registry before installing them. Config dependencies must come from an npm registry. The lockfile can no longer replace the integrity of a config dependency pinned with version+integrity.

  • Lockfile verification now checks the tarballs inside a variations resolution against the registry. A name@version lockfile entry with an empty variations resolution is now rejected.

  • pnpm audit signatures now verifies signatures against the integrity recorded in the lockfile. Packages without a recorded integrity cannot pass signature verification.

  • pnpm now rejects a git dependency whose lockfile repository is empty, begins with -, or contains a null byte. Git can no longer read such a value as a command-line option pnpm/tasks#84.

  • A git dependency with a #path: subpath can no longer reach files outside the repository through a symlink in the subpath.

  • pnpm pack, pnpm publish, and installs of git and local directory dependencies now leave out files that a directory symlink or a bundleDependencies entry points to outside the package directory pnpm/tasks#83 pnpm/tasks#93.

  • pnpm deploy with deployAllFiles now rejects symlinks that point outside the package directory. Local package installs with this setting apply the same check.

  • pnpm no longer hangs on a package archive with a negative PAX record length or an entry of 4 GiB or more pnpm/tasks#78 pnpm/tasks#79.

  • Large package downloads and large files inside gzip and bzip2 package archives now use bounded memory during installation. Package manifests and archive metadata larger than 64 MiB are rejected. pnpm publish also rejects manifests and README files larger than 64 MiB in pre-built tarballs before reading them into memory.

  • Two URL or local path dependencies no longer share a virtual store directory when one URL has +, #, :, or ? where the other has /. Such dependencies, including git dependencies pinned with #, now get a hash suffix on their directory name.

  • pnpm licenses now removes terminal control characters from package metadata in table output.

  • The warnings about ignored project .npmrc registry and auth settings no longer print the username and password of a URL-scoped key such as //user:password@registry.example.com/:_authToken.

Installing and resolving dependencies
  • Dependency resolution reads cached registry metadata faster. The metadata cache moved to <cache-dir>/v12/, so the first install after upgrading downloads registry metadata again. A damaged cache entry is downloaded again, or reported as an error when --offline is set #​13512.

  • pnpm install now fails with ERR_PNPM_UNSUPPORTED_PROTOCOL when a dependency uses a specifier with a protocol pnpm does not support, such as Yarn's patch:. pnpm linked such a dependency to a directory that does not exist #​16590.

  • When a dependency moves an exact dependency of its own to an older version, a peer dependency that pnpm installed automatically now moves with it. Before, pnpm install and pnpm dedupe kept the newer locked version of the peer, so the lockfile held two copies of it, for example two copies of vue pnpm/tasks#61.

  • pnpm add and pnpm install now keep the peer dependencies that pnpm-lock.yaml records for a package they did not update. A registry whose metadata disagrees with the package's package.json, for example by omitting peerDependenciesMeta, made pnpm add and pnpm dedupe write different lockfiles, so pnpm dedupe --check failed after pnpm add #​16615.

Configuration
  • pnpm config get and pnpm config list with --global or --location=global now show only the global configuration. Both flags included the project's .npmrc before. --location=global also included the project's pnpm-workspace.yaml. pnpm config get --global failed when the global bin directory was not in PATH #​16598.

  • pnpm now prints config warnings, such as an unset environment variable in .npmrc, when loading the config fails.

  • pnpm now fails when httpProxy or httpsProxy in pnpm-workspace.yaml or the global configuration is not a string.

  • pnpm dlx now uses the release entry of nodeDownloadMirrors from the workspace configuration when downloading Node.js runtimes #​11281. Mirrors for other channels, such as rc and nightly, still apply only from the global configuration.

Commands
  • pnpm run and pnpm exec now forward --config.* command-line flags to the install started by verifyDepsBeforeRun pnpm/tasks#60.

  • pnpm dlx with --package but no command now fails with 'pnpm dlx' requires a command to run. Before, it installed the package and then crashed trying to run an empty command.

  • pnpm unpublish <pkg>@<version> now deletes the tarball under the registry's path when the registry is served under one, such as Gitea's npm registry. It used to send the delete to the host root and report success without removing the version #​16568. It also no longer mistakes a sibling path such as /npm-mirror/ for the registry path /npm/ pnpm/tasks#94.

  • The interactive pnpm audit --fix picker now shows each patched version with the saveExact and savePrefix style that the override is written with #​13209.

  • pnpm list now reports the correct package paths when nodeLinker is hoisted #​9593.

  • pnpm setup now puts $PNPM_HOME/bin first on PATH in login shells that inherited it further down, such as the VS Code terminal on macOS. Before, another node took precedence over the one installed by pnpm runtime set node -g. Run pnpm setup again to update the block in your shell config #​16635.

  • pnpm setup now names the shell config file even if it is already up to date #​16608.

Output and messages
  • A warning about a project's devEngines or packageManager pin is now printed to stderr. A command such as pnpm cache path or pnpm list --json keeps only its own output on stdout #​16584.

  • The warning for a non-root resolutions field now points at the overrides field in pnpm-workspace.yaml #​11757.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude
vitejs/vite (vite)

v8.3.4

Compare Source

Features
Bug Fixes
Performance Improvements
  • module-runner: skip cloning call sites that have no source map (#​23646) (3d67486)
Code Refactoring

v8.3.3

Compare Source

Bug Fixes
vuejs/router (vue-router)

v5.4.0

Compare Source

   🚨 Breaking Changes
   🚀 Features
   🐞 Bug Fixes
   🏎 Performance
    View changes on GitHub

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "every 4 weeks on friday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@forking-renovate forking-renovate Bot added 📦 dependencies Pull requests that update a dependency file 🤖 bot labels Oct 9, 2026
@renovate-bot renovate-bot added 📦 dependencies Pull requests that update a dependency file 🤖 bot labels Oct 9, 2026
@codecov

codecov Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.0%. Comparing base (c57b269) to head (f47a0bf).

Additional details and impacted files
@@           Coverage Diff           @@
##           master    #2823   +/-   ##
=======================================
  Coverage   100.0%   100.0%           
=======================================
  Files         202      202           
  Lines       27472    27472           
  Branches     9588     9588           
=======================================
  Hits        27472    27472           
Flag Coverage Δ
angular 100.0% <ø> (ø)
universal 100.0% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@pkg-pr-new

pkg-pr-new Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
angular-slickgrid

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/angular-slickgrid@2823

aurelia-slickgrid

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/aurelia-slickgrid@2823

slickgrid-react

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/slickgrid-react@2823

slickgrid-vue

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/slickgrid-vue@2823

@slickgrid-universal/angular-row-detail-plugin

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/angular-row-detail-plugin@2823

@slickgrid-universal/aurelia-row-detail-plugin

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/aurelia-row-detail-plugin@2823

@slickgrid-universal/react-row-detail-plugin

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/react-row-detail-plugin@2823

@slickgrid-universal/vue-row-detail-plugin

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/vue-row-detail-plugin@2823

@slickgrid-universal/binding

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/binding@2823

@slickgrid-universal/common

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/common@2823

@slickgrid-universal/composite-editor-component

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/composite-editor-component@2823

@slickgrid-universal/custom-footer-component

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/custom-footer-component@2823

@slickgrid-universal/custom-tooltip-plugin

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/custom-tooltip-plugin@2823

@slickgrid-universal/empty-warning-component

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/empty-warning-component@2823

@slickgrid-universal/event-pub-sub

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/event-pub-sub@2823

@slickgrid-universal/excel-export

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/excel-export@2823

@slickgrid-universal/graphql

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/graphql@2823

@slickgrid-universal/odata

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/odata@2823

@slickgrid-universal/pagination-component

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/pagination-component@2823

@slickgrid-universal/pdf-export

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/pdf-export@2823

@slickgrid-universal/row-detail-plugin

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/row-detail-plugin@2823

@slickgrid-universal/rxjs-observable

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/rxjs-observable@2823

@slickgrid-universal/sql

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/sql@2823

@slickgrid-universal/text-export

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/text-export@2823

@slickgrid-universal/utils

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/utils@2823

@slickgrid-universal/vanilla-bundle

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/vanilla-bundle@2823

@slickgrid-universal/vanilla-force-bundle

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/vanilla-force-bundle@2823

@slickgrid-universal/web-mcp

npm i https://pkg.pr.new/ghiscoding/slickgrid-universal/@slickgrid-universal/web-mcp@2823

commit: f47a0bf

@renovate-bot
renovate-bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from fcbe6d2 to 3759382 Compare October 9, 2026 18:40
@renovate-bot renovate-bot changed the title chore(deps): update all non-major dependencies fix(deps): update all non-major dependencies Oct 9, 2026
@renovate-bot
renovate-bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 0cbaa23 to 2f69d50 Compare October 10, 2026 13:28
@renovate-bot
renovate-bot force-pushed the renovate/all-minor-patch branch from 2f69d50 to f47a0bf Compare October 10, 2026 17:05

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🤖 bot 📦 dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant