Skip to content

build: update all non-major dependencies (main) - #71109

Open
angular-robot wants to merge 1 commit into
angular:mainfrom
angular-robot:ng-renovate/main-all-non-major-dependencies
Open

angular-robot wants to merge 1 commit into
angular:mainfrom
angular-robot:ng-renovate/main-all-non-major-dependencies

Conversation

@angular-robot

@angular-robot angular-robot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@csstools/css-calc (source) 3.4.0 → 3.4.3 age adoption passing confidence
@csstools/css-color-parser (source) 4.2.3 → 4.2.6 age adoption passing confidence
@​lezer/common 1.5.2 → 1.5.3 age adoption passing confidence
@​lezer/highlight 1.2.3 → 1.2.5 age adoption passing confidence
@​lezer/javascript 1.5.5 → 1.5.6 age adoption passing confidence
@types/node (source) 24.13.6 → 24.19.1 age adoption passing confidence
cypress (source) 16.1.0 → 16.1.1 age adoption passing confidence
mermaid 12.0.0 → 12.1.0 age adoption passing confidence
mocha (source) 12.0.2 → 12.0.3 age adoption passing confidence
pnpm (source) 11.27.1 → 11.28.3 age adoption passing confidence
preact-render-to-string 6.7.0 → 6.8.0 age adoption passing confidence
rollup (source) 4.63.4 → 4.64.0 age adoption passing confidence
shiki (source) 4.4.3 → 4.5.0 age adoption passing confidence
vscode-languageserver-textdocument (source) 1.0.14 → 1.0.15 age adoption passing confidence

  • If you want to rebase/retry this PR, check this box

Release Notes

csstools/postcss-plugins (@​csstools/css-calc)

v3.4.3

Compare Source

October 2, 2026

  • Precompute the CRC32 lookup table instead of parsing a hex substring for every character, avoiding quadratic work when hashing random().

v3.4.2

Compare Source

October 1, 2026

v3.4.1

Compare Source

September 25, 2026

  • Improve performance and avoid a stack overflow when solving deeply nested calculations
  • Throw when a math function exceeds the maximum number of nodes
  • Fixed tan() at asymptote values beyond the first period (270deg, -270deg, ...) to match the specification
  • Fixed round(line-width, ...) to choose the non-zero candidate multiple when A is negative
  • Fixed round(down/up, ...) with a negative step to choose the correct candidate multiple
  • Fixed log(A, 0) to return NaN as specified (only B values between 0 and 1, or greater than 1, are valid)
  • Fixed log(1, B) to return 0⁺ as specified, except when B is NaN (NaN stays infectious, so log(1, NaN) is now NaN)
  • Fixed random() to not mutate the caller's options object
  • Fixed random(fixed <number>, ...) to clamp the value to the highest representable value less than 1
  • Fixed random() to treat max < min as max = min instead of swapping the arguments
  • Fixed random() to not return an unreachable max when a step is given
  • Fixed random() to return A (the minimum) when A is infinite, instead of NaN
  • Fix infectious NaN
  • Fixed the precision option to not round values that serialize in scientific notation
    (e.g. calc(1e-10 * 1e-10) was rounded to 0, it is now left untouched)
  • Fixed random() to not round values that serialize in scientific notation
    (e.g. random(fixed 0.5, 1e-20, 1e-10) returned 0)
  • Updated @csstools/css-tokenizer to 4.0.1 (patch)
  • Updated @csstools/css-tokenizer to 4.0.2 (patch)
  • Updated @csstools/css-parser-algorithms to 4.0.1 (patch)
csstools/postcss-plugins (@​csstools/css-color-parser)

v4.2.6

Compare Source

October 2, 2026

v4.2.5

Compare Source

October 1, 2026

v4.2.4

Compare Source

September 25, 2026

cypress-io/cypress (cypress)

v16.1.1

Compare Source

Changelog: https://docs.cypress.io/app/references/changelog#16-1-1

mermaid-js/mermaid (mermaid)

v12.1.0

Compare Source

Minor Changes
  • #​8303 9140716 Thanks @​filipsajdak! - feat: add the elk.orientFeedbackEdges option, enabled by default. With the ELK layout, an edge from a node that a subgraph feeds back into that subgraph is now routed downstream instead of around the subgraph. This changes the layout of existing ELK diagrams that contain such edges; set elk.orientFeedbackEdges: false to keep the previous routing.

  • #​8250 fd4f5f2 Thanks @​kartben! - feat: add a bitOrder option to packet diagrams. It defaults to ascending, which is the current
    behaviour, and descending mirrors every row so it reads from that row's highest bit down to its
    lowest. Fields are still declared lowest bit first and keep their width, so switching a diagram
    between the two conventions only means changing bitOrder.

Patch Changes
  • #​8330 50c9e55 Thanks @​ashishjain0512! - fix: upgrade chevrotain to 13 so mermaid no longer pulls in vulnerable [email protected]

  • #​8259 4c90f5c Thanks @​afonsojanu! - fix(sequence): allow whitespace between an actor name and its @{ ... } config object

    participant Bob@{ "type" : "database" } parsed fine, but adding a single space before the
    config object (participant Bob @{ "type" : "database" }) failed with a confusing parse error,
    even though the plain form without a config object tolerates trailing whitespace just fine.

  • #​8339 c7fa1a5 Thanks @​ashishjain0512! - fix: keep ELK class-diagram cardinalities off namespace frames

  • #​8334 d67331d Thanks @​ashishjain0512! - fix(class): place cardinality labels beside their relation ends on dagre's sides with ELK, centre dagre's end labels, and stop clipping their text

  • #​8344 99a050b Thanks @​pbrolin47! - fix: with the ELK layout, an edge label could sit up to 16px beside its edge instead of centred on it, when the edge's terminal jog was straightened after the label's position was computed. The label is now re-projected onto the straightened route

  • #​8276 3101c7d Thanks @​mir-ashiq! - fix(error): show the actual error message in the error diagram

    When a diagram fails to parse, the error diagram now draws the real error message below the
    "Syntax error in text" headline, wrapped to at most four lines. Hosts that only show the SVG
    (GitHub, GitLab, Obsidian, exported images) no longer hide what actually went wrong, e.g. that the
    flowchart edge limit was exceeded and maxEdges needs raising via mermaid.initialize.

  • #​8296 aa29345 Thanks @​pentaoa! - fix: preserve explicit source relations on event modeling reset frames

  • #​8297 967bbde Thanks @​pentaoa! - fix: reject duplicate event modeling frame IDs before rendering

  • #​8337 147f343 Thanks @​knsv-bot! - fix: a flowchart that declares the same subgraph id more than once now renders as one merged subgraph with the ELK layout instead of producing NaN geometry. Classes and view: collapsed set on a repeated subgraph now apply to it, whichever declaration they follow.

  • #​8203 40ef7b4 Thanks @​MFA-G! - perf(frontmatter): replace the quadratic front matter regex on hot paths

    frontMatterRegex backtracks polynomially on whitespace-heavy input, so a
    diagram well inside the default maxTextSize could stall parsing for over a
    second. detectType and extractFrontMatter now use a linear scanner that
    matches the regex result exactly, leaving no document stripped differently.

  • #​8254 351d7d2 Thanks @​galshir! - fix: warn when a gantt task references an unknown after/until task id, or when its end value is neither a valid date nor a valid duration

  • #​8249 b657a2c Thanks @​mir-ashiq! - fix(sequence): allow hyphenated actor and participant names when a config object is attached

  • #​8300 c38a565 Thanks @​filipsajdak! - fix: A partial override of an object-valued theme variable such as xyChart, radar or cynefin keeps the values the theme generates for the keys it leaves out

  • #​8333 8afd83c Thanks @​ashishjain0512! - fix: upgrade the parser to langium 4.4 / chevrotain 13 so bundles no longer include [email protected]

  • #​8285 859f1f8 Thanks @​mir-ashiq! - fix(sequence): allow actor-menu keywords as participant ids in messages

    A participant declared as Link (or Links, Properties, Details) could not be used as a
    message endpoint: the lexer matched the name as the link statement keyword and the parse failed.
    The link, links, properties and details keywords are now only recognized when an actor
    follows them on the same line, so participant ids that happen to spell these words work in
    messages, while the statements themselves keep parsing as before.

  • #​8282 b6d952d Thanks @​belomaxorka! - fix(sequence): allow Link as a participant ID in messages and actor menus

    Preserve the ID's case and alias while keeping the link and links menu commands supported.

  • #​8345 7917c1a Thanks @​knsv-bot! - fix: xychart measures text in SVG units so legends no longer clip on wide charts scaled to fit their container, and the chart title is dropped instead of overflowing when the chart is too short for it

  • #​8338 4a722fb Thanks @​ashishjain0512! - fix: Centre the xychart title over the plot area instead of the whole chart

  • Updated dependencies [8afd83c]:

mochajs/mocha (mocha)

v12.0.3

Compare Source

🩹 Fixes
📚 Documentation
🧹 Chores
pnpm/pnpm (pnpm)

v11.28.3: pnpm 11.28.3

Compare Source

pnpm 11.28.3 updates undici to clear a security advisory, fixes "database disk image is malformed" errors when several pnpm processes share a store, and makes packages, catalogs, projects, and commands named like constructor work.

Patch Changes
Installing packages
  • pnpm now ships undici 7.29.1, so security scans of pnpm no longer report GHSA-3wwx-pv8p-q78v.

  • pnpm no longer fails with "database disk image is malformed" or reads stale store entries while another pnpm process writes to the same store.

  • Names that match built-in JavaScript object properties, such as constructor, toString, or __proto__, now work like any other name. pnpm crashed, wrote a wrong lockfile, or silently skipped such names in:

    • pnpm add, pnpm install, and pnpm import, for dependencies, peer dependencies, and file: dependencies that point to a directory named constructor.
    • Catalog entries and catalog names. Pruning unused entries crashed, and a new catalog named toString was not written.
    • Workspace projects, project directories, and files inside injected packages.
    • Registry prefixes and override version references such as $toString.
    • Hoisting, pnpm list, and pnpm why.
    • Command names. pnpm constructor runs the constructor script like any other unknown command, and pnpm help constructor no longer crashes.
    • Resolving through a pnpr server when a project lives in a directory named constructor.
  • pnpm install no longer re-resolves an up-to-date lockfile on every run when a patched package is a peer in a peer cycle #​16418.

  • POSIX bin shims and the pnpm, pn, pnpx, and pnx launchers now run inside a Nix build, where the system default path holds none of the utilities they call. Installing again replaces the shims already in node_modules #​16377.

  • In a project that pins another pnpm version, pnpm now passes a command with an option it does not know to the pinned version. Before, pnpm install --auto-dedupe failed with "Unknown option" even though the pinned pnpm supports it #​16353.

  • pnpm now fails with ERR_PNPM_INVALID_ALLOW_BUILDS when allowBuilds is not an object or one of its values is not true, false, or a string. Such values used to be ignored silently.

  • Removing a dependency whose bins are declared through directories.bin no longer leaves broken shims in node_modules/.bin.

  • A custom resolver's shouldRefreshResolution hook that rejects no longer crashes pnpm with an unhandled rejection when another hook has already asked for a refresh.

Updating dependencies
  • When minimumReleaseAge hides the version that latest points to, pnpm now falls back to a prerelease of the same major before a stable version of an older major. A stable version of the same major is still preferred. For example, while a new 1.0.0 is too new, pnpm picks 1.0.0-beta.4 rather than an old 0.0.1 #​16388.

  • pnpm --filter <project> update <pkg> now fails with ERR_PNPM_NO_PACKAGE_IN_DEPENDENCIES when the selected projects do not depend on <pkg>, also in a workspace with a shared lockfile and a root project. It used to exit successfully.

  • pnpm audit --fix now updates vulnerable packages in a single project that sets updateConfig.ignoreDependencies. It used to leave them on the vulnerable version.

  • pnpm update --global now removes hard-linked executables from PNPM_HOME when migrating packages from the old global layout #​16420.

  • Updating a pinned GitHub Action now rewrites the version in its # vX.Y.Z comment even when the action name contains the same version text. The action name used to change while the comment kept the old version.

Workspaces and deploy
  • pnpm deploy no longer fails with ERR_PNPM_DEPLOY_AMBIGUOUS_PEER in a workspace with injectWorkspacePackages: true when a workspace package also lists its peer dependency as a dev dependency #​16375.

  • pnpm deploy no longer copies the workspace root's packageManager and devEngines.packageManager fields into the deployed package.json #​16403.

  • --filter fixes:

    • A ...pkg... selector combined with another dependents selector, such as --filter ...a --filter ...b..., no longer adds the dependencies of the other selector's dependents.
    • --filter "[<since>]" now detects changes in projects whose directory names contain non-ASCII characters. The change used to be credited to the parent project.
Running scripts
  • After relaying a signal to a script, pnpm keeps waiting for a process in the script's process group whose main thread has exited while its other threads still run. Linux reports such a process as a zombie, so the wait used to end before those threads finished pnpm/tasks#56.

  • A lifecycle script run with unsafePerm: false now fails with an error when pnpm cannot create node_modules/.tmp. It used to hang.

  • pnpm run with verifyDepsBeforeRun no longer crashes with an unhandled rejection when a lockfile it did not need to compare fails to load.

  • pnpm run -r now closes the collapsible CI log section of a project whose script fails, so the output of later projects is no longer nested inside it.

  • pnpm run --resume-from no longer crashes when a saved run state file contains null.

Store
  • pnpm store prune now removes the packages that only expired pnpm dlx cache entries used, as long as the store still has another registered project. They used to stay until the next pnpm store prune #​16383.

  • pnpm store prune now stops with an error when it cannot read a project directory for a reason other than the directory missing, such as a permission error. It used to skip the directory.

Publishing and registry output
  • pnpm publish now includes bare README files and README files with Markdown extensions such as readme.markdown in registry metadata #​12704.

  • pnpm pack-app now accepts an entry file or output directory inside the project whose name starts with two dots, such as ..build/entry.cjs. It used to fail with ERR_PNPM_PACK_APP_ENTRY_OUTSIDE_PROJECT.

  • Registry error messages now always say "(response body truncated)" when pnpm cut the response body short. The marker was missing when the body was cut at exactly 64 KiB.

Platinum Sponsors
Bit OpenAI Notion
CodeRabbit
Gold Sponsors
Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v11.28.2: pnpm 11.28.2

Compare Source

pnpm 11.28.2 fixes pnpm install skipping every workspace project whose common ancestor is the filesystem root, and stops pnpm run from reinstalling or installing when nothing needs it.

Patch Changes
  • pnpm install reported success without installing anything when the workspace projects' common ancestor was the filesystem root, such as / or a drive root like C:\. It now installs these projects #​16328.

  • verifyDepsBeforeRun no longer reports dependencies as outdated after a filtered install just because pnpm-lock.yaml has a newer modification time. It checks the lockfile against the packages that install put in place. Before, pnpm run reinstalled the whole workspace with lifecycle scripts on, for example after a Docker COPY brought in a lockfile with a newer mtime #​16322.

    After a filtered install, verifyDepsBeforeRun now also checks that the install put the selected projects' dependencies in place. A node_modules directory alone no longer counts as proof.

  • pnpm run and pnpm exec no longer install a project that has never been installed and has nothing to install. Such a project declares no dependencies, no peer dependencies that autoInstallPeers would fetch, and no install lifecycle scripts. The command now runs without writing node_modules or pnpm-lock.yaml #​16313.

Platinum Sponsors
Bit OpenAI Notion
CodeRabbit
Gold Sponsors
Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v11.28.1: pnpm 11.28.1

Compare Source

pnpm 11.28.1 makes pnpm install work in StackBlitz WebContainers, repairs lockfiles whose patch hashes disagree with patchedDependencies, and fixes many bugs in Windows command shims, injected workspace dependencies, and pnpm deploy.

Patch Changes
Installing packages
  • pnpm install now works in StackBlitz WebContainers. On projects without a lockfile, it used to fail with ENOENT ... pnpm-lock.yaml, because pnpm did not recognize the errors that WebContainers return from asynchronous file system calls. It also failed with "this.db.exec is not a function", because node:sqlite there lacks DatabaseSync.exec. When node:sqlite cannot prepare statements either, pnpm stores the index in index.fallback #​15649.

  • pnpm install now completes after downloading a Node.js runtime specified by devEngines.runtime when pnpm runs on Node.js 24.4.x #​14667.

  • pnpm install no longer fails when a package from the registry declares a file: dependency on a directory inside itself, such as "@types/css-tree": "file:./typings/css-tree". pnpm links that dependency to the directory inside the package, as npm and Yarn do. The lockfile records it as link:<root>/typings/css-tree #​9141.

  • Installing a git-hosted dependency that has to be built no longer fails when that dependency's own dependencies have build scripts nobody approved. pnpm skips those builds while preparing the dependency, as it does without strictDepBuilds #​9764.

  • pnpm now uses pnpm to prepare a git-hosted dependency that is a pnpm workspace without a committed lockfile. It used npm before, which could skip the dependency's build #​14011.

  • When installing a git dependency over SSH fails with Permission denied (publickey), pnpm suggests checking the loaded keys with ssh-add -l. Resolving an SSH URL that refuses the key also shows a local HTTPS rewrite that leaves the recorded URL alone #​13743.

  • pnpm install --dev and pnpm fetch --dev now install the optional dependencies of devDependencies, such as the platform binaries of Biome and oxlint. The project's own optionalDependencies are still skipped #​9678.

  • pnpm install --frozen-lockfile now works on a detached HEAD when gitBranchLockfile is enabled. The install now reads the lockfiles of the local and remote-tracking branches that contain the checked-out commit. It still writes the shared pnpm-lock.yaml #​7672.

  • pnpm install on CI now fails on an outdated lockfile when preferFrozenLockfile is explicitly set to true. Setting it to true used to let CI update the lockfile #​9072.

  • pnpm install now fails with ERR_PNPM_IGNORED_BUILDS on a repeat install when strictDepBuilds is on and a dependency's build is still undecided. A repeat install against an existing node_modules reported success where a fresh install failed #​10450.

  • pnpm install now removes an optional dependency from node_modules if its install script fails. Code that checks whether the package is installed no longer finds a package that cannot load #​8756.

  • pnpm install --offline and pnpm add --offline now resolve a version range to the newest matching version whose tarball is already in the store. They used to pick the newest version in the cached metadata and fail with ERR_PNPM_NO_OFFLINE_TARBALL when its tarball was missing #​10715.

  • If an offline install fails because the registry metadata cache uses the layout from before pnpm 11.27 and 12.4, the error now names the older mirror on disk and explains that one online install repopulates the cache #​15656.

  • pnpm install now fails right away when writing package files fails because the store is full. It no longer retries the tarball download first #​8581.

  • With nodeLinker: hoisted, pnpm install now restores a workspace project's node_modules after it was deleted. Before, the install printed "Already up to date" and left the project without the dependencies nested under it.

  • Under nodeLinker: hoisted, pnpm install now clears orphaned package directories that an interrupted or failed install leaves in a project's node_modules. A directory recorded by the previous install is removed, while an unrecorded directory is moved to node_modules/.ignored. A copy already in .ignored is never overwritten #​13676.

  • Packages in an external virtualStoreDir can resolve the project's direct dependencies selected by hoistPattern. Run pnpm install --force to repair an existing installation #​5652.

  • A repeat install now keeps the fast path when a declared local file dependency is replaced by an override #​12892.

Store, build cache, and global virtual store
  • Files imported from the store now follow the umask of the install that writes them. Installing with a umask of 077 no longer leaves imported files readable by the group and others #​3807.

  • With the global virtual store, pnpm rebuild no longer modifies packages shared with projects that have not approved their build scripts #​12302.

  • The side-effects cache now restores the symlinks that a build script creates inside a package. A warm install used to replace each of them with a copy of its target #​12859.

    After upgrading, every package with a build script is built once more.

  • pnpm install now restores cached build artifacts when reinstalling a workspace that uses separate lockfiles #​12942.

  • The global virtual store and the side-effects cache now key built packages by the Node.js version that the root project's devEngines.runtime or engines.runtime pins. That is the Node.js their build scripts run with. A dependency that declares its own engines.runtime no longer changes the key for every other package.

  • Concurrent installs that share a global virtual store now run a package's build in its shared slot one at a time. A failed build leaves the slot in place and marks it for the next install to rebuild #​15568.

  • Concurrent installs no longer fail when they replace the same stale hoisted dependency link. Virtual store cleanup now keeps the temporary lockfiles that concurrent installs are still writing.

  • pnpm install keeps the owner, group, and mode of files already in a shared store, including index.db. New store files and directories inherit the store directory's group-write bit. When that directory is setgid, new files inherit its group. pnpm does not change a file's owner or group #​12765.

  • When pnpm install repairs a store file that was modified through a hard link in node_modules, the repair now keeps the file's inode on Linux and macOS. Hard-linked copies in other projects are healed at the same time. Before, only the project running the install received the restored content. On Windows the repair still replaces the file, so other projects are healed on their next install #​3445.

  • A tarball whose integrity pnpm computed during download is now found in the store on the next install. Before, that install downloaded the tarball again once the lockfile recorded the integrity #​12562.

  • pnpm now warns when it cannot hard link packages from an existing store in the pnpm home directory and uses a store on the project's filesystem. This can happen when the project is on another filesystem, such as a bind-mounted workspace in a container. The warning names both stores and suggests setting storeDir #​14505.

Resolving and linking dependencies
  • A peer dependency no longer resolves to two different versions for one package. This happened when the package peer-depends on another package and on one of that package's peers, and it is installed deeper than a direct dependency of the package that provides them #​12098.

  • An optional peer dependency is no longer resolved from another workspace project's package when the project provides one of that package's own peers at a version it rejects. This avoids bogus unmet peer errors #​13989.

  • pnpm no longer reports unmet peer dependency warnings for aliased npm: peer ranges that a tarball dependency satisfies #​11126.

  • pnpm install now links the executables of auto-installed peer dependencies into the workspace root's node_modules/.bin, including after a frozen-lockfile reinstall [#​8511](https://redirect.github.com/pnpm/pnpm/

❗ Important

✂ PR body was truncated to here.

@angular-robot angular-robot added action: merge The PR is ready for merge by the caretaker area: build & ci Related the build and CI infrastructure of the project target: automation This PR is targeted to only merge into the branch defined in Github [bot use only] labels Oct 1, 2026
@ngbot ngbot Bot modified the milestone: Backlog Oct 1, 2026
@pullapprove
pullapprove Bot requested a review from crisbeto October 1, 2026 06:58
@JeanMeche
JeanMeche removed the request for review from crisbeto October 1, 2026 14:40
@pullapprove
pullapprove Bot requested a review from crisbeto October 1, 2026 14:40
@angular-robot
angular-robot force-pushed the ng-renovate/main-all-non-major-dependencies branch 5 times, most recently from 82936ef to 7ef5c38 Compare October 2, 2026 08:45
@alan-agius4
alan-agius4 removed the request for review from crisbeto October 2, 2026 12:29
@angular-robot
angular-robot force-pushed the ng-renovate/main-all-non-major-dependencies branch 3 times, most recently from 486be91 to ff80130 Compare October 3, 2026 12:53
See associated pull request for more information.
@angular-robot
angular-robot force-pushed the ng-renovate/main-all-non-major-dependencies branch from ff80130 to a73d7b2 Compare October 3, 2026 17:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action: merge The PR is ready for merge by the caretaker area: build & ci Related the build and CI infrastructure of the project target: automation This PR is targeted to only merge into the branch defined in Github [bot use only]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants