Update all non-major dependencies - #106
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
3 times, most recently
from
September 14, 2026 01:17
a982d7b to
0e398a4
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 14, 2026 14:08
0e398a4 to
36274ee
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 14, 2026 19:12
36274ee to
231bd4d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^1.20.4→^1.20.6^25.9.5→^25.9.6^19.2.18→^19.3.0^19.2.5→^19.3.016.3.3→16.3.5^1.35.0→^1.45.011.24.0→11.26.0^19.2.8→^19.3.0^19.2.8→^19.3.0^4.19.0→^4.21.0^4.127.1→^4.131.1bump,lockfileUpdate, orrollbackupdates, so these are raised without a Minimum Release Age check. You will need to manually validate the Minimum Release Age for these package(s).Release Notes
opennextjs/opennextjs-cloudflare (@opennextjs/cloudflare)
v1.20.6Compare Source
Patch Changes
#1378
7a990e7Thanks @vicb! - Bump Next to 16.3.4 and@opennextjs/awsto 4.1.4See details at https://github.com/opennextjs/opennextjs-aws/releases/tag/v4.1.4
v1.20.5Compare Source
Patch Changes
#1374
64a69ecThanks @conico974! - chore: bump@opennextjs/awsto 4.1.3See details at https://github.com/opennextjs/opennextjs-aws/releases/tag/v4.1.3
vercel/next.js (eslint-config-next)
v16.3.5Compare Source
v16.3.4Compare Source
lucide-icons/lucide (lucide-react)
v1.45.0: Version 1.45.0Compare Source
What's Changed
calendar-chevrons-righticon by @AlexandrePhilibert in #3565building-complex-plusicon by @tylerkade in #4758mouth&mouth-offby @karsa-mistmere in #4787iv-bagicon by @karsa-mistmere in #4821lecternicon by @UsamaKhan in #2925layout-arrow-rightandlayout-arrow-downby @samuelalake in #4541parkicon by @skajosborn in #3177album,book-marked,folder-bookmarkicons by @karsa-mistmere in #3043housesicon by @danielbayley in #3241notebook-doticon by @elenakovelskikh in #3228messages-circleicon by @Mirazstudio-offical in #4754plant-poticon by @vqh2602 in #3122cookieicon by @karsa-mistmere in #4815globe-codeicon by @AleksejDix in #3722New Contributors
Full Changelog: lucide-icons/lucide@1.44.0...1.45.0
v1.44.0: Version 1.44.0Compare Source
What's Changed
door-openby @karsa-mistmere in #4826satellite-dishicon by @karsa-mistmere in #4813toothbrushicon by @karsa-mistmere in #4755New Contributors
Full Changelog: lucide-icons/lucide@1.43.0...1.44.0
v1.43.0: Version 1.43.0Compare Source
What's Changed
tic-tac-toeicon by @karsa-mistmere in #4772id-cardicon by @karsa-mistmere in #4820id-card-lanyardicon by @karsa-mistmere in #4819carton/carton-offfrom lab by @karsa-mistmere in #4818Full Changelog: lucide-icons/lucide@1.42.0...1.43.0
v1.42.0: Version 1.42.0Compare Source
What's Changed
trash-officon by @lx3133584 in #4788circle-dashed-checkicon by @karsa-mistmere in #4796equal-approximately-noticon by @ryck in #4802@lucide/sharedby @karsa-mistmere in #4409computericon by @karsa-mistmere in #4607table-2icon by @jguddas in #4810user-groupicons by @karsa-mistmere in #4782New Contributors
Full Changelog: lucide-icons/lucide@1.41.0...1.42.0
v1.41.0: Version 1.41.0Compare Source
What's Changed
germandgerm-offby @rrod497 in #4056door-stairwellicon & updateddoor-*icons by @jguddas in #3554credit-card-readericon by @jguddas in #4616germ&germ-offby @karsa-mistmere in #4789virus/virus-officon by @karsa-mistmere in #4765can-sodaicon by @jaynewey in #4718square-alertIcon by @viralcodex in #3687lab/bottle-toothbrush-combicon by @karsa-mistmere in #4756@lucide/labby @ericfennis in #4792trashicon in favour oftrash-2by @jguddas in #3141leaficon by @karsa-mistmere in #4801New Contributors
Full Changelog: lucide-icons/lucide@1.40.0...1.41.0
v1.40.0: Version 1.40.0Compare Source
What's Changed
canicon by @l0uisgrange in #4767bridgeicon by @Nykoula in #3949shrimp-officon by @jguddas in #3613shopping-cart-plus&shopping-cart-minusicons by @Ajay199210 in #4248lighthouseicon by @Xougui in #4507New Contributors
Full Changelog: lucide-icons/lucide@1.39.0...1.40.0
v1.39.0: Version 1.39.0Compare Source
What's Changed
whistleicon by @timmy471 in #3006mail-penicon by @jennieboops in #4399Full Changelog: lucide-icons/lucide@1.38.0...1.39.0
v1.38.0: Version 1.38.0Compare Source
What's Changed
Full Changelog: lucide-icons/lucide@1.36.0...1.38.0
pnpm/pnpm (pnpm)
v11.26.0Compare Source
v11.25.0: pnpm 11.25Compare Source
Minor Changes
Added an opt-in proof of concept that lets installs reuse a dependency's build output across machines, by publishing and restoring signed, organization-scoped artifacts through pnpr instead of running the lifecycle scripts locally.
Configure it with the new
remoteSideEffectsCachesetting. A workspace names the eligibleorganizationandpackages; everything describing the act of signing —publish,keyId,builderId,trustedKeys,privateKeyand the provenance fields — is refused inpnpm-workspace.yamland read from the global config file or the environment instead.Added macOS and Windows x64 and arm64 support to remote shared build artifacts pnpm/pnpm#13771.
Added the
audit.ignorePrunesetting. When set totrue,pnpm audit --fixremoves ignored GHSA entries that no longer appear in the audit report.Generalized the experimental shared-artifact protocol so candidates and signed payloads identify a discriminated subject. Dependency side effects use package and source-integrity subjects, while workspace tasks use project and task subjects.
This changes shared-artifact request bodies and signed payloads. A pnpr server and its clients have to be on matching versions.
pnpm initnow pins the latest pnpm version, instead of the version of pnpm that ran the command. A project scaffolded by an outdated pnpm therefore no longer inherits that staleness through its owndevEngines.packageManager/packageManagerpin #7490.The version is read from the
latesttag on the package-manager registries. When that lookup cannot answer — no network, an unreachable or slow registry,offline, or alatestthat theminimumReleaseAge/trustPolicysettings reject —pnpm initpins the running version as before, and never fails or hangs on the lookup. Alatestthat is older than the running pnpm is never pinned either.A
scopeset in a project'spnpm-workspace.yamlis now ignored, with a warning naming where to set it instead.pnpm loginrecords the scope as a@scope:registryroute in the machine-globalauth.ini, which outranks~/.npmrcin every project — so a repository-committed file could redirect a scope such as@acmefor all of a user's other projects after one routine login. Use--scope, thePNPM_CONFIG_SCOPEenvironment variable, or the global config file instead #13557.Verified remote build artifacts are persisted in the shared store with their signed origin metadata. Later installs reverify the artifact against current trust, policy, platform, and source before reuse, while invalid remote variants are quarantined per channel (pnpm/pnpm#13771).
Persist completed recursive tasks so
--resume-fromskips exactly the work that passed during a matching interrupted or failedpnpm -r run/pnpm -r execinvocation. When no compatible state exists, pnpm retains its graph-based resume behavior.Allowed
pnpm update --patchesto refresh registry revisions through a configured pnpr server while retaining locked package versions.Added explicit registry revision selection with
<version>+rNandpnpm update --patchesfor refreshing revision artifacts without changing package versions. Registry-backed lockfile policy checks recognize historical revisions, and pnpr now preserves safe revision histories from upstream registries.Workspace install, rebuild, pack, publish, stage, and lifecycle work now starts as soon as its dependencies finish instead of waiting for an unrelated topological group.
pnpm stage approvenow approves several staged packages at once. Run it without a stage id to pick from the staged versions interactively, or pass a list of stage ids. The whole batch is approved with a single one-time password, and pnpm asks for a new one only once the registry stops accepting it. Inside a workspace, the selected packages are approved in dependency order, and a package whose workspace dependency could not be approved is skipped instead of being published against a dependency that never reached the registry.Added per-task concurrency limits to workspace task orchestration. Set
tasks.<name>.concurrencyinpnpm-workspace.yamlto limit how many instances of that task may run across workspace projects at once:Added support for registry replacement tarballs using standard integrity values, explicit revision fields, registry routing from the
registriessetting, non-redirecting integrity-addressed URLs, canonical safe-integer revision numbers, and pnpr proxying for immutable upstream revision artifacts.sideEffectsCachenow declares the whole of how a package's build output is reused — whether one is restored, whether one is saved, and the remote tier that shares it between machines:sideEffectsCache: true,sideEffectsCacheReadonly,remoteSideEffectsCache, and itsorganizationfield all keep working. Where a field is set under both spellings the one above wins; where it is set under only one, it is kept.Two behaviors change, both bringing this CLI in line with what the Rust one already did:
sideEffectsCacheReadonly: truenow blocks writing to the cache, and setting it alongsidesideEffectsCache: falsegives a read-only view rather than switching the cache off entirely. A cache can also be declared write-only now, to populate one the run does not read.Workspace task orchestration (pnpm/rfcs#23).
pnpm -r runandpnpm -r execnow schedule per task instead of in topological chunks: a task starts as soon as the tasks it depends on have finished, so a project no longer waits for unrelated projects that happen to share its chunk.A new
taskssection inpnpm-workspace.yamldeclares what a task depends on, using the^convention:^namemeans the named task in each of the project's workspace dependencies; a barenamemeans the task in the same project; an entry with nodependsOndeclares an empty dependency list. A task with no entry behaves asdependsOn: ['^<its own name>'], which is exactly what the previous chunked ordering implied — an unconfigured workspace gets the scheduler improvement and nothing else changes meaning. A project without the script is reported skipped and passes its edges through to its own dependencies, so a scriptless package does not sever a chain.Also part of this change:
ERR_PNPM_TASK_CYCLE) instead of silently running in an arbitrary order. SettingignoreWorkspaceCycles: truedowngrades the error to a warning: the cycle's tasks run in an arbitrary order relative to each other.--resume-fromnow skips exactly the transitive dependencies of the anchor package; work unrelated to the anchor still runs.--no-bail, tasks whose dependencies failed are reported as skipped, not failed, and do not add to the exit code.--bail(the default), the first failure still ends the run at once and nothing new is dispatched — including scripts already queued behind the concurrency limit.pnpm -r run --dry-run <script>prints the task graph that would execute without running anything (including skipping theverifyDepsBeforeRuncheck);--jsonemits the tasks and their resolved dependency edges.--workspace-concurrency=1, or the graph forces the scripts to run one after another).Patch Changes
An
_authentry in the global config file no longer decides which registry packages come from when something else says. Aregistryorregistriesdeclared inpnpm-workspace.yamlor the global config now wins over the route inferred from a stored credential, which still applies where nothing else declares one. Thepnpm_config__authenvironment variable is unchanged: it stays the way to point a CI runner at a mandated proxy, and still overrides what a repository declares.Prevent installs through a symlinked
node_modulesdirectory from rewriting the target checkout pnpm/pnpm#14286.Treat empty scripts selected by a regular expression as missing before running dependent tasks.
The options type of the
fetchcommand now declaresallowBuilds, a setting its handler already forwarded to the installer. Type-level only — whatpnpm fetchdoes is unchanged.Filter hidden scripts matched by a regular expression during recursive runs when a visible script also matches.
Fixed automatically switched pnpm versions forcing all descendant pnpm processes to use the same version pnpm/pnpm#14309.
Fixed
ERR_PNPM_UNUSED_PATCHvalidation during incremental installs pnpm/pnpm#13692.Fixed
pnpm deploy --prodfailing when an excluded dev dependency was also declared as an optional peer dependency pnpm/pnpm#14302.pnpm update -gno longer downgrades a global package.--latestresolves thelatestdist-tag, which can point at an older release than the one installed — afterpnpm add -g <pkg>@next, for instance #14270.pnpm update -galso no longer changes the pnpm version. pnpm's own global install belongs topnpm self-update#14270.Copying a built package to its other hoisted locations no longer replaces the destination directory. With
nodeLinker: hoisted, that replacement deleted the dependencies nested inside the destination'snode_modules, and made concurrent copies of the same build chunk fail withERR_PNPM_ENOENT: no such file or directory, rename '.../node_modules/_tmp_...'#12880.pnpm updateno longer replaces the specifier a project declares for a dependency that is also listed inoverrides. Acatalog:reference stays acatalog:reference, and a declared range stays as written, instead of being rewritten to the version the override resolved to #12115.pnpm updateno longer moves the range a project declares for a dependency thatoverridesalso lists, even when the override repeats that range verbatim. Previously the updatedpackage.jsondisagreed with the lockfile, so the nextpnpm install --frozen-lockfilefailed with a specifier mismatch #14224.Make
pnpm add --lockfile-onlyskip dependency linking pnpm/pnpm#14286.--productionis accepted again as an alias of--prodoninstall,fetch,prune,update,list,why, andsbom, and the install thatverifyDepsBeforeRunreproduces is now spelled with--prod.pnpm runno longer aborts with "unexpected argument '--production' found" after a production-only install #14147.The progress output no longer overwrites the lines above it once it grows taller than the terminal window #14270.
Restoring a dependency's build from the remote side-effects cache no longer downloads files the store already holds.
Forward
patchedDependencieshashes andpackageExtensionsto pnpr so server-side resolution preserves patches and package extensions in the lockfile and installed packages.Published the workspace task graph and scheduler as
@pnpm/workspace.task-schedulerso other workspace commands can use the same dependency-aware scheduling as recursive run and exec.The environment variables for the remote side-effects cache are named for the setting they configure:
PNPM_SIDE_EFFECTS_CACHE_REMOTE_KEY_ID,..._BUILDER_ID,..._IMAGE_DIGEST,..._ARCHITECTURE_BASELINE,..._PRIVATE_KEY,..._BUILD_ENV,..._TRUSTED_KEYSand..._PUBLISH. ThePNPM_REMOTE_SIDE_EFFECTS_CACHE_*names keep working, and the new one wins when both are set.A
devEngines.packageManagerrange pin on pnpm is now recorded inpnpm-lock.yaml'spackageManagerDependencieswhen the running pnpm already satisfies it, using the running version and keeping the range as the recorded specifier. Previously only an exact pin — or a range resolved on the way through a version switch — reached the lockfile, so a range pin written by hand (or by any tool other thanpnpm add/pnpm self-update) left the project without the shared resolution the pin exists to provide.Fixed recursive
runcleanup on Windows when a lifecycle script fails while another script's process tree is still running.The update notification now suggests
pnpm self-updatewhenPNPM_HOMEmanages the pnpm in use, and the standalone install script otherwise — under Corepack, or when another package manager installed pnpm.pnpm self-updateunder Corepack names the standalone install script too.Enforce
allowBuildswhen a prepared git dependency is reused from the shared store, and use the lockfile's canonical git resolution ID in approval suggestions.Topologically sorting workspace projects now runs in linear time, fixing installs and lockfile updates that stalled for seconds on workspaces with thousands of projects forming deep dependency chains #14149, #14151.
Platinum Sponsors
Gold Sponsors
react/react (react)
v19.3.0Compare Source
react/react (react-dom)
v19.3.0Compare Source
shadcn-ui/ui (shadcn)
v4.21.0Compare Source
Minor Changes
c257f688cf4de7ec10cc1be84cad29cd4631182cThanks @shadcn! - installcnand generateexport { cn } from "cn"forlib/utilson init. Registry components now importcnfrom thecnpackage.Patch Changes
8720dec73f5aebed9f649ea58636f54599fdedf1Thanks @shadcn! - usetwMergefromcninstead oftailwind-mergeinternally.v4.20.1Compare Source
Patch Changes
04bb134c52af23af7d77673618ef4e3862b7c310Thanks @shadcn! - preserve leading comments when runningshadcn migrate cn.v4.20.0Compare Source
Minor Changes
51f3e12203b0026ea106cafb4f770bda9abead87Thanks @shadcn! - addnpx shadcn migrate cnto replaceclsx,tailwind-mergeandcnfastin Tailwind CSS v4 projects.v4.19.1Compare Source
Patch Changes
f9ea1e600ea5dd7b1b79769b7b25cafa400cee6fThanks @shadcn! - Add the official shadcn/ui website to the package metadata.cloudflare/workers-sdk (wrangler)
v4.131.1Compare Source
Patch Changes
#15592
945aaa3Thanks @WillTaylorDev! - Add a provisioning delay note when custom domain Preview URLs changeWrangler now explains that DNS and TLS certificate provisioning may continue after a deploy adds a custom domain or enables its Preview URLs. Stable redeploys don't repeat the note.
This assumes that a request which matches the stored custom domain state doesn't restart provisioning. The client infers this from the API changeset and current domain record because this repository can't verify the backend behavior.
#15592
945aaa3Thanks @WillTaylorDev! - Clarify production status labels for custom domain routesWrangler now prefixes explicit custom domain production states with
production:so they match Preview labels. The updated labels appear in deployed trigger output andWRANGLER_OUTPUT_FILE_PATH.#15602
47d906fThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15592
945aaa3Thanks @WillTaylorDev! - Avoid replacement prompts for custom domains already on the WorkerWrangler now updates Preview settings without asking to replace a custom domain when that domain already belongs to the deployed Worker. It still asks before replacing domains attached to another Worker.
#15592
945aaa3Thanks @WillTaylorDev! - Explain how to enable Preview URLs when a Preview deployment has nonewrangler previewnow shows URL shapes and configuration snippets for Workers.dev and custom domains. The custom domain snippet preserves every configured route, and the guidance distinguishes missing settings from disabled ones.This changes a private beta feature. The warning also makes clear that
wrangler deploypublishes code from the current checkout.Updated dependencies [
47d906f,c2699bf]:v4.131.0Compare Source
Minor Changes
#15480
36aed7fThanks @skepticfx! - Add Durable Object-managed Containers to top-level container configurationWrangler now accepts
scheduling_policy: "durable_object"in the top-levelcontainersarray and creates its namespace-backed application after the Worker upload resolves the Durable Object namespace ID. The namespace ID is also the application ID, so repeated deploys idempotently ensure the same application without name-based lookup, modification, or a Containers rollout.Durable Object-managed entries accept
class_name,scheduling_policy, an optionalname, and an optional namedimagesmap. Scheduler-only fields are rejected. Each image provides either a localdockerfileor a digest-pinned managed-registryimage. Wrangler builds or resolves each image, waits while Cloudflare prepares it for the Containers runtime, and uploads the resulting references with the Worker version for access throughctx.container.imagesandenv.EXPERIMENTAL_CLOUDFLARE_CONTAINER_IMAGES. Local development support for these entries is deferred to a follow-up.Existing scheduler-backed entries and Durable Object migrations continue to work unchanged.
With
--containers-rollout=none, existing Workers retain their deployed Container metadata and imageConfiguration
📅 Schedule: (UTC)
* * * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.