You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Authorization token should be found in the configuration, when the requested URL is explicitly specified with a default port (443 on HTTPS or 80 on HTTP) #6863.
When the same file is appended multiple times into a tarball, the last occurrence is selected when unpacking the tarball.
Added support for publishConfig.registry in package.json for publishing #6775.
Fixed a bug in which pnpm passed the wrong scheme to git ls-remote, causing a fallback to git+ssh and resulting in a 'host key verification failed' issue #6805
In cases where both aliased and non-aliased dependencies exist to the same package, non-aliased dependencies will be used for resolving peer dependencies, addressing issue #6588.
Don't crash when the APPDATA env variable is not set on Windows #6659.
Don't fail when a package is archived in a tarball with malformed tar headers #5362.
Peer dependencies of subdependencies should be installed, when node-linker is set to hoisted#6680.
Ignore the port in the URL, while searching for authentication token in the .npmrc file #6354.
Throw a meaningful error when applying a patch to a dependency fails.
When dedupe-peer-dependents is enabled, use the path (not id) to determine compatibility.
When multiple dependency groups can be deduplicated, the latter ones are sorted according to number of peers to allow them to benefit from deduplication.
Some settings influence the structure of the lockfile, so we cannot reuse the lockfile if those settings change. As a result, we need to store such settings in the lockfile. This way we will know with which settings the lockfile has been created.
A new field will now be present in the lockfile: settings. It will store the values of two settings: autoInstallPeers and excludeLinksFromLockfile. If someone tries to perform a frozen-lockfile installation and their active settings don't match the ones in the lockfile, then an error message will be thrown.
The lockfile format version is bumped from v6.0 to v6.1.
Allow env variables to be specified with default values in .npmrc. This is a convention used by Yarn too.
Using ${NAME-fallback} will return fallback if NAME isn't set. ${NAME:-fallback} will return fallback if NAME isn't set, or is an empty string #6018.
Patch Changes
pnpm config get <key> returns empty when the value is a boolean
Don't print an info message about linked dependencies if they are real linked dependencies specified via the link: protocol in package.json.
Add -g to mismatch registries error info when original command has -g option #6224.
uses: soos-io/soos-dast-github-action@98033e0e7fa4af5eee1a56f73d8fc1367294b4c8 # Use latest version from https://github.com/marketplace/actions/soos-dast
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer TIP This summary will be updated as you push new changes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
7.0.0→7.33.7Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
pnpm/pnpm (pnpm)
v7.33.7Compare Source
Patch Changes
v7.33.6Compare Source
Patch Changes
Our Gold Sponsors
Our Silver Sponsors
v7.33.5Compare Source
Patch Changes
Our Gold Sponsors
Our Silver Sponsors
v7.33.4Compare Source
Patch Changes
publishConfig.registryinpackage.jsonfor publishing #6775.git ls-remote, causing a fallback togit+sshand resulting in a 'host key verification failed' issue #6805Our Gold Sponsors
Our Silver Sponsors
v7.33.3Compare Source
Patch Changes
package.jsonshould not fail, when the dependency is read from cache #6721.Our Gold Sponsors
Our Silver Sponsors
v7.33.2Compare Source
Patch Changes
node-linkeris set tohoisted#6680..npmrcfile #6354.pnpm update --global --latestshould work #3779.Our Gold Sponsors
Our Silver Sponsors
v7.33.1Compare Source
Patch Changes
When
dedupe-peer-dependentsis enabled, use the path (not id) to determine compatibility.When multiple dependency groups can be deduplicated, the latter ones are sorted according to number of peers to allow them to benefit from deduplication.
Resolves: #6605
Change lockfile version back to 6.0 as previous versions of pnpm fail to parse the version correctly.
Our Gold Sponsors
Our Silver Sponsors
v7.33.0Compare Source
Minor Changes
Some settings influence the structure of the lockfile, so we cannot reuse the lockfile if those settings change. As a result, we need to store such settings in the lockfile. This way we will know with which settings the lockfile has been created.
A new field will now be present in the lockfile:
settings. It will store the values of two settings:autoInstallPeersandexcludeLinksFromLockfile. If someone tries to perform afrozen-lockfileinstallation and their active settings don't match the ones in the lockfile, then an error message will be thrown.The lockfile format version is bumped from v6.0 to v6.1.
Related PR: #6557
Related issue: #6312
Patch Changes
npm:foo@1.0.0becomesnpm:foo@1.1.0.workspace:protocol is not found in the workspace #4477.updateConfig.ignoreDependencies#6548Our Gold Sponsors
Our Silver Sponsors
v7.32.5Compare Source
Patch Changes
pnpm rebuildshould not fail whennode-linkeris set tohoistedand there are skipped optional dependencies #6553.Our Gold Sponsors
Our Silver Sponsors
v7.32.4Compare Source
Patch Changes
pnpm link -g <pkg-name>should not modify thepackage.jsonfile #4341.enginesfield should match prerelease versions #6509.pnpm publish --otpshould work #6514.Our Gold Sponsors
Our Silver Sponsors
v7.32.3Compare Source
Patch Changes
node-linkeris set tohoisted6486.Our Gold Sponsors
Our Silver Sponsors
v7.32.2Compare Source
Patch Changes
Our Gold Sponsors
Our Silver Sponsors
v7.32.1Compare Source
Patch Changes
publishConfig.directoryof an injected workspace dependency does not exist #6396.Our Gold Sponsors
Our Silver Sponsors
v7.32.0Compare Source
Minor Changes
.npmrc. This is a convention used by Yarn too.Using
${NAME-fallback}will returnfallbackifNAMEisn't set.${NAME:-fallback}will returnfallbackifNAMEisn't set, or is an empty string #6018.Patch Changes
pnpm config get <key>returns empty when the value is a booleanlink:protocol inpackage.json.Our Gold Sponsors
Our Silver Sponsors
v7.31.0Compare Source
Minor Changes
ignore-workspace-cyclesto silence workspace cycle warning #6308.Patch Changes
@yarnpkg/shellto fix issues in the shell emulator #6320.@char #6332.Our Gold Sponsors
Our Silver Sponsors
v7.30.5Compare Source
Patch Changes
pnpm auditshould work even if there are nopackage.jsonfile, just apnpm-lock.yamlfile.dedupe-peer-dependentsistrue#6154.Our Gold Sponsors
Our Silver Sponsors
v7.30.4Compare Source
v7.30.3Compare Source
Patch Changes
Our Gold Sponsors
Our Silver Sponsors
v7.30.2[Compare Source](https://redirect.github.com/pnpm/pnpm/compare/v7.30.1...v7
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.