Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

chore(deps): update all non-major dependencies#314

Merged
pi0 merged 1 commit intomainunjs/c12:mainfrom
renovate/all-minor-patchunjs/c12:renovate/all-minor-patchCopy head branch name to clipboard
May 6, 2026
Merged

chore(deps): update all non-major dependencies#314
pi0 merged 1 commit intomainunjs/c12:mainfrom
renovate/all-minor-patchunjs/c12:renovate/all-minor-patchCopy head branch name to clipboard

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented May 6, 2026

This PR contains the following updates:

Package Change Age Confidence
@typescript/native-preview (source) ^7.0.0-dev.20260505.1^7.0.0-dev.20260506.1 age confidence
pnpm (source) 10.33.310.33.4 age confidence

Release Notes

microsoft/typescript-go (@​typescript/native-preview)

v7.0.0-dev.20260506.1

Compare Source

pnpm/pnpm (pnpm)

v10.33.4: pnpm 10.33.4

Compare Source

Patch Changes

  • Pin the integrity of git-hosted tarballs (codeload.github.com, gitlab.com, bitbucket.org) in the lockfile so that subsequent installs detect a tampered or substituted tarball and refuse to install it. Previously the lockfile only stored the tarball URL for git dependencies, so a compromised git host or a man-in-the-middle could serve arbitrary code on later installs without lockfile changes.

    A new gitHosted: true field is recorded on git-hosted tarball resolutions in the lockfile, letting every reader/writer route them by a single typed check instead of pattern-matching the tarball URL in each call site. Lockfiles written by older pnpm versions are enriched on load (URL fallback) so the field can be relied on uniformly across the codebase.

  • Fix a regression where pnpm --recursive --filter '!<pkg>' run/exec/test/add would include the workspace root in the matched projects. The workspace root is now correctly excluded by default when only negative --filter arguments are provided, matching the documented behavior. To include the root, pass --include-workspace-root #​11341.

Platinum Sponsors

Bit

Gold Sponsors

Sanity Discord Vite
SerpApi CodeRabbit Stackblitz
Workleap Nx

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "after 2am and before 3am"
  • Automerge
    • "after 1am and before 2am"

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from ff6470d to 0f70654 Compare May 6, 2026 10:43
@renovate renovate Bot changed the title chore(deps): update devdependency jiti to ^2.7.0 chore(deps): update all non-major dependencies May 6, 2026
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from ecd8d78 to a973fca Compare May 6, 2026 17:26
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from a973fca to d2f6bc9 Compare May 6, 2026 17:28
@pi0 pi0 merged commit a2704d2 into main May 6, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

Morty Proxy This is a proxified and sanitized view of the page, visit original site.