build: update all non-major dependencies (main) - #71109
Open
angular-robot wants to merge 1 commit into
Open
angular-robot wants to merge 1 commit into
angular-robot wants to merge 1 commit into
Conversation
JeanMeche
approved these changes
Oct 1, 2026
angular-robot
force-pushed
the
ng-renovate/main-all-non-major-dependencies
branch
5 times, most recently
from
October 2, 2026 08:45
82936ef to
7ef5c38
Compare
alan-agius4
approved these changes
Oct 2, 2026
angular-robot
force-pushed
the
ng-renovate/main-all-non-major-dependencies
branch
3 times, most recently
from
October 3, 2026 12:53
486be91 to
ff80130
Compare
See associated pull request for more information.
angular-robot
force-pushed
the
ng-renovate/main-all-non-major-dependencies
branch
from
October 3, 2026 17:44
ff80130 to
a73d7b2
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.4.0→3.4.34.2.3→4.2.61.5.2→1.5.31.2.3→1.2.51.5.5→1.5.624.13.6→24.19.116.1.0→16.1.112.0.0→12.1.012.0.2→12.0.311.27.1→11.28.36.7.0→6.8.04.63.4→4.64.04.4.3→4.5.01.0.14→1.0.15Release Notes
csstools/postcss-plugins (@csstools/css-calc)
v3.4.3Compare Source
October 2, 2026
random().v3.4.2Compare Source
October 1, 2026
@csstools/css-parser-algorithmsto4.0.2(patch)v3.4.1Compare Source
September 25, 2026
tan()at asymptote values beyond the first period (270deg,-270deg, ...) to match the specificationround(line-width, ...)to choose the non-zero candidate multiple whenAis negativeround(down/up, ...)with a negative step to choose the correct candidate multiplelog(A, 0)to returnNaNas specified (onlyBvalues between 0 and 1, or greater than 1, are valid)log(1, B)to return0⁺as specified, except whenBisNaN(NaN stays infectious, solog(1, NaN)is nowNaN)random()to not mutate the caller'soptionsobjectrandom(fixed <number>, ...)to clamp the value to the highest representable value less than 1random()to treatmax < minasmax = mininstead of swapping the argumentsrandom()to not return an unreachablemaxwhen astepis givenrandom()to returnA(the minimum) whenAis infinite, instead ofNaNNaNprecisionoption to not round values that serialize in scientific notation(e.g.
calc(1e-10 * 1e-10)was rounded to0, it is now left untouched)random()to not round values that serialize in scientific notation(e.g.
random(fixed 0.5, 1e-20, 1e-10)returned0)@csstools/css-tokenizerto4.0.1(patch)@csstools/css-tokenizerto4.0.2(patch)@csstools/css-parser-algorithmsto4.0.1(patch)csstools/postcss-plugins (@csstools/css-color-parser)
v4.2.6Compare Source
October 2, 2026
@csstools/css-calcto3.4.3(patch)v4.2.5Compare Source
October 1, 2026
@csstools/css-parser-algorithmsto4.0.2(patch)@csstools/css-calcto3.4.2(patch)v4.2.4Compare Source
September 25, 2026
@csstools/css-tokenizerto4.0.1(patch)@csstools/color-helpersto6.1.2(patch)@csstools/css-tokenizerto4.0.2(patch)@csstools/css-parser-algorithmsto4.0.1(patch)@csstools/css-calcto3.4.1(patch)cypress-io/cypress (cypress)
v16.1.1Compare Source
Changelog: https://docs.cypress.io/app/references/changelog#16-1-1
mermaid-js/mermaid (mermaid)
v12.1.0Compare Source
Minor Changes
#8303
9140716Thanks @filipsajdak! - feat: add theelk.orientFeedbackEdgesoption, enabled by default. With the ELK layout, an edge from a node that a subgraph feeds back into that subgraph is now routed downstream instead of around the subgraph. This changes the layout of existing ELK diagrams that contain such edges; setelk.orientFeedbackEdges: falseto keep the previous routing.#8250
fd4f5f2Thanks @kartben! - feat: add abitOrderoption to packet diagrams. It defaults toascending, which is the currentbehaviour, and
descendingmirrors every row so it reads from that row's highest bit down to itslowest. Fields are still declared lowest bit first and keep their width, so switching a diagram
between the two conventions only means changing
bitOrder.Patch Changes
#8330
50c9e55Thanks @ashishjain0512! - fix: upgrade chevrotain to 13 so mermaid no longer pulls in vulnerable[email protected]#8259
4c90f5cThanks @afonsojanu! - fix(sequence): allow whitespace between an actor name and its@{ ... }config objectparticipant Bob@{ "type" : "database" }parsed fine, but adding a single space before theconfig object (
participant Bob @{ "type" : "database" }) failed with a confusing parse error,even though the plain form without a config object tolerates trailing whitespace just fine.
#8339
c7fa1a5Thanks @ashishjain0512! - fix: keep ELK class-diagram cardinalities off namespace frames#8334
d67331dThanks @ashishjain0512! - fix(class): place cardinality labels beside their relation ends on dagre's sides with ELK, centre dagre's end labels, and stop clipping their text#8344
99a050bThanks @pbrolin47! - fix: with the ELK layout, an edge label could sit up to 16px beside its edge instead of centred on it, when the edge's terminal jog was straightened after the label's position was computed. The label is now re-projected onto the straightened route#8276
3101c7dThanks @mir-ashiq! - fix(error): show the actual error message in the error diagramWhen a diagram fails to parse, the error diagram now draws the real error message below the
"Syntax error in text" headline, wrapped to at most four lines. Hosts that only show the SVG
(GitHub, GitLab, Obsidian, exported images) no longer hide what actually went wrong, e.g. that the
flowchart edge limit was exceeded and
maxEdgesneeds raising viamermaid.initialize.#8296
aa29345Thanks @pentaoa! - fix: preserve explicit source relations on event modeling reset frames#8297
967bbdeThanks @pentaoa! - fix: reject duplicate event modeling frame IDs before rendering#8337
147f343Thanks @knsv-bot! - fix: a flowchart that declares the same subgraph id more than once now renders as one merged subgraph with the ELK layout instead of producing NaN geometry. Classes andview: collapsedset on a repeated subgraph now apply to it, whichever declaration they follow.#8203
40ef7b4Thanks @MFA-G! - perf(frontmatter): replace the quadratic front matter regex on hot pathsfrontMatterRegexbacktracks polynomially on whitespace-heavy input, so adiagram well inside the default
maxTextSizecould stall parsing for over asecond.
detectTypeandextractFrontMatternow use a linear scanner thatmatches the regex result exactly, leaving no document stripped differently.
#8254
351d7d2Thanks @galshir! - fix: warn when a gantt task references an unknownafter/untiltask id, or when its end value is neither a valid date nor a valid duration#8249
b657a2cThanks @mir-ashiq! - fix(sequence): allow hyphenated actor and participant names when a config object is attached#8300
c38a565Thanks @filipsajdak! - fix: A partial override of an object-valued theme variable such asxyChart,radarorcynefinkeeps the values the theme generates for the keys it leaves out#8333
8afd83cThanks @ashishjain0512! - fix: upgrade the parser to langium 4.4 / chevrotain 13 so bundles no longer include[email protected]#8285
859f1f8Thanks @mir-ashiq! - fix(sequence): allow actor-menu keywords as participant ids in messagesA participant declared as
Link(orLinks,Properties,Details) could not be used as amessage endpoint: the lexer matched the name as the
linkstatement keyword and the parse failed.The
link,links,propertiesanddetailskeywords are now only recognized when an actorfollows them on the same line, so participant ids that happen to spell these words work in
messages, while the statements themselves keep parsing as before.
#8282
b6d952dThanks @belomaxorka! - fix(sequence): allowLinkas a participant ID in messages and actor menusPreserve the ID's case and alias while keeping the
linkandlinksmenu commands supported.#8345
7917c1aThanks @knsv-bot! - fix: xychart measures text in SVG units so legends no longer clip on wide charts scaled to fit their container, and the chart title is dropped instead of overflowing when the chart is too short for it#8338
4a722fbThanks @ashishjain0512! - fix: Centre the xychart title over the plot area instead of the whole chartUpdated dependencies [
8afd83c]:mochajs/mocha (mocha)
v12.0.3Compare Source
🩹 Fixes
--Xone-char aliases (#6391) (1227939)📚 Documentation
🧹 Chores
pnpm/pnpm (pnpm)
v11.28.3: pnpm 11.28.3Compare Source
pnpm 11.28.3 updates
undicito clear a security advisory, fixes "database disk image is malformed" errors when several pnpm processes share a store, and makes packages, catalogs, projects, and commands named likeconstructorwork.Patch Changes
Installing packages
pnpm now ships
undici7.29.1, so security scans of pnpm no longer report GHSA-3wwx-pv8p-q78v.pnpm no longer fails with "database disk image is malformed" or reads stale store entries while another pnpm process writes to the same store.
Names that match built-in JavaScript object properties, such as
constructor,toString, or__proto__, now work like any other name. pnpm crashed, wrote a wrong lockfile, or silently skipped such names in:pnpm add,pnpm install, andpnpm import, for dependencies, peer dependencies, andfile:dependencies that point to a directory namedconstructor.toStringwas not written.$toString.pnpm list, andpnpm why.pnpm constructorruns theconstructorscript like any other unknown command, andpnpm help constructorno longer crashes.constructor.pnpm installno longer re-resolves an up-to-date lockfile on every run when a patched package is a peer in a peer cycle #16418.POSIX bin shims and the
pnpm,pn,pnpx, andpnxlaunchers now run inside a Nix build, where the system default path holds none of the utilities they call. Installing again replaces the shims already innode_modules#16377.In a project that pins another pnpm version, pnpm now passes a command with an option it does not know to the pinned version. Before,
pnpm install --auto-dedupefailed with "Unknown option" even though the pinned pnpm supports it #16353.pnpm now fails with
ERR_PNPM_INVALID_ALLOW_BUILDSwhenallowBuildsis not an object or one of its values is nottrue,false, or a string. Such values used to be ignored silently.Removing a dependency whose bins are declared through
directories.binno longer leaves broken shims innode_modules/.bin.A custom resolver's
shouldRefreshResolutionhook that rejects no longer crashes pnpm with an unhandled rejection when another hook has already asked for a refresh.Updating dependencies
When
minimumReleaseAgehides the version thatlatestpoints to, pnpm now falls back to a prerelease of the same major before a stable version of an older major. A stable version of the same major is still preferred. For example, while a new1.0.0is too new, pnpm picks1.0.0-beta.4rather than an old0.0.1#16388.pnpm --filter <project> update <pkg>now fails withERR_PNPM_NO_PACKAGE_IN_DEPENDENCIESwhen the selected projects do not depend on<pkg>, also in a workspace with a shared lockfile and a root project. It used to exit successfully.pnpm audit --fixnow updates vulnerable packages in a single project that setsupdateConfig.ignoreDependencies. It used to leave them on the vulnerable version.pnpm update --globalnow removes hard-linked executables fromPNPM_HOMEwhen migrating packages from the old global layout #16420.Updating a pinned GitHub Action now rewrites the version in its
# vX.Y.Zcomment even when the action name contains the same version text. The action name used to change while the comment kept the old version.Workspaces and deploy
pnpm deployno longer fails withERR_PNPM_DEPLOY_AMBIGUOUS_PEERin a workspace withinjectWorkspacePackages: truewhen a workspace package also lists its peer dependency as a dev dependency #16375.pnpm deployno longer copies the workspace root'spackageManageranddevEngines.packageManagerfields into the deployedpackage.json#16403.--filterfixes:...pkg...selector combined with another dependents selector, such as--filter ...a --filter ...b..., no longer adds the dependencies of the other selector's dependents.--filter "[<since>]"now detects changes in projects whose directory names contain non-ASCII characters. The change used to be credited to the parent project.Running scripts
After relaying a signal to a script, pnpm keeps waiting for a process in the script's process group whose main thread has exited while its other threads still run. Linux reports such a process as a zombie, so the wait used to end before those threads finished pnpm/tasks#56.
A lifecycle script run with
unsafePerm: falsenow fails with an error when pnpm cannot createnode_modules/.tmp. It used to hang.pnpm runwithverifyDepsBeforeRunno longer crashes with an unhandled rejection when a lockfile it did not need to compare fails to load.pnpm run -rnow closes the collapsible CI log section of a project whose script fails, so the output of later projects is no longer nested inside it.pnpm run --resume-fromno longer crashes when a saved run state file containsnull.Store
pnpm store prunenow removes the packages that only expiredpnpm dlxcache entries used, as long as the store still has another registered project. They used to stay until the nextpnpm store prune#16383.pnpm store prunenow stops with an error when it cannot read a project directory for a reason other than the directory missing, such as a permission error. It used to skip the directory.Publishing and registry output
pnpm publishnow includes bareREADMEfiles and README files with Markdown extensions such asreadme.markdownin registry metadata #12704.pnpm pack-appnow accepts an entry file or output directory inside the project whose name starts with two dots, such as..build/entry.cjs. It used to fail withERR_PNPM_PACK_APP_ENTRY_OUTSIDE_PROJECT.Registry error messages now always say "(response body truncated)" when pnpm cut the response body short. The marker was missing when the body was cut at exactly 64 KiB.
Platinum Sponsors
Gold Sponsors
v11.28.2: pnpm 11.28.2Compare Source
pnpm 11.28.2 fixes
pnpm installskipping every workspace project whose common ancestor is the filesystem root, and stopspnpm runfrom reinstalling or installing when nothing needs it.Patch Changes
pnpm installreported success without installing anything when the workspace projects' common ancestor was the filesystem root, such as/or a drive root likeC:\. It now installs these projects #16328.verifyDepsBeforeRunno longer reports dependencies as outdated after a filtered install just becausepnpm-lock.yamlhas a newer modification time. It checks the lockfile against the packages that install put in place. Before,pnpm runreinstalled the whole workspace with lifecycle scripts on, for example after a DockerCOPYbrought in a lockfile with a newer mtime #16322.After a filtered install,
verifyDepsBeforeRunnow also checks that the install put the selected projects' dependencies in place. Anode_modulesdirectory alone no longer counts as proof.pnpm runandpnpm execno longer install a project that has never been installed and has nothing to install. Such a project declares no dependencies, no peer dependencies thatautoInstallPeerswould fetch, and no install lifecycle scripts. The command now runs without writingnode_modulesorpnpm-lock.yaml#16313.Platinum Sponsors
Gold Sponsors
v11.28.1: pnpm 11.28.1Compare Source
pnpm 11.28.1 makes
pnpm installwork in StackBlitz WebContainers, repairs lockfiles whose patch hashes disagree withpatchedDependencies, and fixes many bugs in Windows command shims, injected workspace dependencies, andpnpm deploy.Patch Changes
Installing packages
pnpm installnow works in StackBlitz WebContainers. On projects without a lockfile, it used to fail withENOENT ... pnpm-lock.yaml, because pnpm did not recognize the errors that WebContainers return from asynchronous file system calls. It also failed with "this.db.exec is not a function", becausenode:sqlitethere lacksDatabaseSync.exec. Whennode:sqlitecannot prepare statements either, pnpm stores the index inindex.fallback#15649.pnpm installnow completes after downloading a Node.js runtime specified bydevEngines.runtimewhen pnpm runs on Node.js 24.4.x #14667.pnpm installno longer fails when a package from the registry declares afile:dependency on a directory inside itself, such as"@types/css-tree": "file:./typings/css-tree". pnpm links that dependency to the directory inside the package, as npm and Yarn do. The lockfile records it aslink:<root>/typings/css-tree#9141.Installing a git-hosted dependency that has to be built no longer fails when that dependency's own dependencies have build scripts nobody approved. pnpm skips those builds while preparing the dependency, as it does without
strictDepBuilds#9764.pnpm now uses pnpm to prepare a git-hosted dependency that is a pnpm workspace without a committed lockfile. It used npm before, which could skip the dependency's build #14011.
When installing a git dependency over SSH fails with
Permission denied (publickey), pnpm suggests checking the loaded keys withssh-add -l. Resolving an SSH URL that refuses the key also shows a local HTTPS rewrite that leaves the recorded URL alone #13743.pnpm install --devandpnpm fetch --devnow install the optional dependencies of devDependencies, such as the platform binaries of Biome and oxlint. The project's ownoptionalDependenciesare still skipped #9678.pnpm install --frozen-lockfilenow works on a detached HEAD whengitBranchLockfileis enabled. The install now reads the lockfiles of the local and remote-tracking branches that contain the checked-out commit. It still writes the sharedpnpm-lock.yaml#7672.pnpm installon CI now fails on an outdated lockfile whenpreferFrozenLockfileis explicitly set totrue. Setting it totrueused to let CI update the lockfile #9072.pnpm installnow fails withERR_PNPM_IGNORED_BUILDSon a repeat install whenstrictDepBuildsis on and a dependency's build is still undecided. A repeat install against an existingnode_modulesreported success where a fresh install failed #10450.pnpm installnow removes an optional dependency fromnode_modulesif its install script fails. Code that checks whether the package is installed no longer finds a package that cannot load #8756.pnpm install --offlineandpnpm add --offlinenow resolve a version range to the newest matching version whose tarball is already in the store. They used to pick the newest version in the cached metadata and fail withERR_PNPM_NO_OFFLINE_TARBALLwhen its tarball was missing #10715.If an offline install fails because the registry metadata cache uses the layout from before pnpm 11.27 and 12.4, the error now names the older mirror on disk and explains that one online install repopulates the cache #15656.
pnpm installnow fails right away when writing package files fails because the store is full. It no longer retries the tarball download first #8581.With
nodeLinker: hoisted,pnpm installnow restores a workspace project'snode_modulesafter it was deleted. Before, the install printed "Already up to date" and left the project without the dependencies nested under it.Under
nodeLinker: hoisted,pnpm installnow clears orphaned package directories that an interrupted or failed install leaves in a project'snode_modules. A directory recorded by the previous install is removed, while an unrecorded directory is moved tonode_modules/.ignored. A copy already in.ignoredis never overwritten #13676.Packages in an external
virtualStoreDircan resolve the project's direct dependencies selected byhoistPattern. Runpnpm install --forceto repair an existing installation #5652.A repeat install now keeps the fast path when a declared local file dependency is replaced by an override #12892.
Store, build cache, and global virtual store
Files imported from the store now follow the umask of the install that writes them. Installing with a umask of
077no longer leaves imported files readable by the group and others #3807.With the global virtual store,
pnpm rebuildno longer modifies packages shared with projects that have not approved their build scripts #12302.The side-effects cache now restores the symlinks that a build script creates inside a package. A warm install used to replace each of them with a copy of its target #12859.
After upgrading, every package with a build script is built once more.
pnpm installnow restores cached build artifacts when reinstalling a workspace that uses separate lockfiles #12942.The global virtual store and the side-effects cache now key built packages by the Node.js version that the root project's
devEngines.runtimeorengines.runtimepins. That is the Node.js their build scripts run with. A dependency that declares its ownengines.runtimeno longer changes the key for every other package.Concurrent installs that share a global virtual store now run a package's build in its shared slot one at a time. A failed build leaves the slot in place and marks it for the next install to rebuild #15568.
Concurrent installs no longer fail when they replace the same stale hoisted dependency link. Virtual store cleanup now keeps the temporary lockfiles that concurrent installs are still writing.
pnpm installkeeps the owner, group, and mode of files already in a shared store, includingindex.db. New store files and directories inherit the store directory's group-write bit. When that directory is setgid, new files inherit its group. pnpm does not change a file's owner or group #12765.When
pnpm installrepairs a store file that was modified through a hard link innode_modules, the repair now keeps the file's inode on Linux and macOS. Hard-linked copies in other projects are healed at the same time. Before, only the project running the install received the restored content. On Windows the repair still replaces the file, so other projects are healed on their next install #3445.A tarball whose integrity pnpm computed during download is now found in the store on the next install. Before, that install downloaded the tarball again once the lockfile recorded the integrity #12562.
pnpm now warns when it cannot hard link packages from an existing store in the pnpm home directory and uses a store on the project's filesystem. This can happen when the project is on another filesystem, such as a bind-mounted workspace in a container. The warning names both stores and suggests setting
storeDir#14505.Resolving and linking dependencies
A peer dependency no longer resolves to two different versions for one package. This happened when the package peer-depends on another package and on one of that package's peers, and it is installed deeper than a direct dependency of the package that provides them #12098.
An optional peer dependency is no longer resolved from another workspace project's package when the project provides one of that package's own peers at a version it rejects. This avoids bogus unmet peer errors #13989.
pnpm no longer reports unmet peer dependency warnings for aliased
npm:peer ranges that a tarball dependency satisfies #11126.pnpm installnow links the executables of auto-installed peer dependencies into the workspace root'snode_modules/.bin, including after a frozen-lockfile reinstall [#8511](https://redirect.github.com/pnpm/pnpm/