Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump pnpm to 7.29.3 #5

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Aug 22, 2022

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
pnpm (source) 7.3.0 -> 7.29.3 age adoption passing confidence

Release Notes

pnpm/pnpm

v7.29.3

Compare Source

Patch Changes

  • Command shim should not set higher priority to the node_modules/.pnpm/node_modules directory through the NODE_PATH env variable, then the command's own node_modules directory #​5176.
  • extend-node-path is set back to true by default. It was set to false in v7.29.2 in order to fix issues with multiple versions of Jest in one workspace. It has caused other issues, so now we keep extending NODE_PATH. We have fixed the Jest issue with a different solution #​6213.

Our Gold Sponsors

Our Silver Sponsors

v7.29.2

Compare Source

v7.29.1

Compare Source

Patch Changes
  • Settings related to authorization should be set/deleted by npm CLI #​6181.
Our Gold Sponsors
Our Silver Sponsors

v7.29.0

Compare Source

Minor Changes

  • A new setting is now supported: dedupe-peer-dependents.

    When this setting is set to true, packages with peer dependencies will be deduplicated after peers resolution.

    For instance, let's say we have a workspace with two projects and both of them have webpack in their dependencies. webpack has esbuild in its optional peer dependencies, and one of the projects has esbuild in its dependencies. In this case, pnpm will link two instances of webpack to the node_modules/.pnpm directory: one with esbuild and another one without it:

    node_modules
      .pnpm
        [email protected][email protected]
        [email protected]
    project1
      node_modules
        webpack -> ../../node_modules/.pnpm/[email protected]/node_modules/webpack
    project2
      node_modules
        webpack -> ../../node_modules/.pnpm/[email protected][email protected]/node_modules/webpack
        esbuild
    

    This makes sense because webpack is used in two projects, and one of the projects doesn't have esbuild, so the two projects cannot share the same instance of webpack. However, this is not what most developers expect, especially since in a hoisted node_modules, there would only be one instance of webpack. Therefore, you may now use the dedupe-peer-dependents setting to deduplicate webpack when it has no conflicting peer dependencies (explanation at the end). In this case, if we set dedupe-peer-dependents to true, both projects will use the same webpack instance, which is the one that has esbuild resolved:

    node_modules
      .pnpm
        [email protected][email protected]
    project1
      node_modules
        webpack -> ../../node_modules/.pnpm/[email protected][email protected]/node_modules/webpack
    project2
      node_modules
        webpack -> ../../node_modules/.pnpm/[email protected][email protected]/node_modules/webpack
        esbuild
    

    What are conflicting peer dependencies? By conflicting peer dependencies we mean a scenario like the following one:

    node_modules
      .pnpm
        [email protected][email protected][email protected]
        [email protected][email protected]
    project1
      node_modules
        webpack -> ../../node_modules/.pnpm/[email protected]/node_modules/webpack
        react (v17)
    project2
      node_modules
        webpack -> ../../node_modules/.pnpm/[email protected][email protected]/node_modules/webpack
        esbuild
        react (v16)
    

    In this case, we cannot dedupe webpack as webpack has react in its peer dependencies and react is resolved from two different versions in the context of the two projects.

Patch Changes

  • The configuration added by pnpm setup should check if the pnpm home directory is already in the PATH before adding to the PATH.

    Before this change, this code was added to the shell:

    export PNPM_HOME="$HOME/Library/pnpm"
    export PATH="$PNPM_HOME:$PATH"

    Now this will be added:

    export PNPM_HOME="$HOME/Library/pnpm"
    case ":$PATH:" in
      *":$PNPM_HOME:"*) ;;
      *) export PATH="$PNPM_HOME:$PATH" ;;
    esac
  • Add skipped status in exec report summary when script is missing #​6139.

  • pnpm env -g should fail with a meaningful error message if pnpm cannot find the pnpm home directory, which is the directory into which Node.js is installed.

  • Should not throw an error when local dependency use file protocol #​6115.

  • Fix the incorrect error block when subproject has been patched #​6183

Our Gold Sponsors

Our Silver Sponsors

v7.28.0

Compare Source

Minor Changes

  • Add --report-summary for pnpm exec and pnpm run #​6008.
  • Show path info for pnpm why --json or --long #​6103.
  • Extend the pnpm.peerDependencyRules.allowedVersions package.json option to support the parent>child selector syntax. This syntax allows for extending specific peerDependencies #​6108.

Patch Changes

  • Update the lockfile if a workspace has a new project with no dependencies.
  • Fix a case of installs not being deterministic and causing lockfile changes between repeat installs. When a dependency only declares peerDependenciesMeta and not peerDependencies, dependencies, or optionalDependencies, the dependency's peers were not considered deterministically before.
  • patch-commit should auto apply patches in workspaces #​6048
  • Automatically fix conflicts in v6 lockfile.
  • pnpm config set should write to the global config file by default #​5877.

Our Gold Sponsors

Our Silver Sponsors

v7.27.1

Compare Source

Patch Changes

  • Add store path description to the pnpm cli help.
  • Print a hint that suggests to run pnpm store prune, when a tarball integrity error happens.
  • Don't retry installation if the integrity checksum of a package failed and no lockfile was present.
  • Fail with a meaningful error message when cannot parse a proxy URL.
  • The strict-ssl, ca, key, and cert settings should work with HTTPS proxy servers #​4689.

Our Gold Sponsors

Our Silver Sponsors

v7.27.0

Compare Source

Minor Changes

  • A new resolution-mode added: lowest-direct. With this resolution mode direct dependencies will be resolved to their lowest versions. So if there is foo@^1.1.0 in the dependencies, then 1.1.0 will be installed, even if the latest version of foo is 1.2.0.
  • Support script selector with RegExp such as pnpm run /build:.*/ and execute the matched scripts with the RegExp #​5871.

Patch Changes

  • Fix version number replacing for namespaced workspace packages. workspace:@&#8203;foo/bar@* should be replaced with npm:@&#8203;foo/bar@<version> on publish #​6052.

  • When resolving dependencies, prefer versions that are already used in the root of the project. This is important to minimize the number of packages that will be nested during hoisting #​6054.

  • Deduplicate direct dependencies.

    Let's say there are two projects in the workspace that dependend on foo. One project has [email protected] in the dependencies while another one has foo@^1.0.0 in the dependencies. In this case, [email protected] should be installed to both projects as satisfies the version specs of both projects.

  • Use Map rather than Object in createPackageExtender to prevent read the prototype property to native function

Our Gold Sponsors

Our Silver Sponsors

v7.26.3

Compare Source

Patch Changes

  • Directories inside the virtual store should not contain the ( or ) chars. This is to fix issues with storybook and the new v6 pnpm-lock.yaml lockfile format #​5976.
  • The update command should not replace dependency versions specified via dist-tags #​5996.
  • Fixed an issue that was causing pnpm to stuck forever during installation #​5909.

Our Gold Sponsors

Our Silver Sponsors

v7.26.2

Compare Source

Patch Changes
  • Wrap text in pnpm audit output for better readability #​5981
  • Fix "cross-device link not permitted" error when node-linker is set to hoisted #​5992.
Our Gold Sponsors
Our Silver Sponsors

v7.26.1

Compare Source

Patch Changes

  • Fixed out of memory error that sometimes happens when node-linker is set to hoisted #​5988.
  • Fixed EMFILE: too many open files by using graceful-fs for reading bin files of dependencies #​5887.
  • Fix lockfile v6 on projects that use patched dependencies #​5967.

Our Gold Sponsors

Our Silver Sponsors

v7.26.0

Compare Source

Minor Changes

Patch Changes

  • Packages hoisted to the virtual store are not removed on repeat install, when the non-headless algorithm runs the installation #​5971.
  • prepublishOnly and prepublish should not be executed on pnpm pack #​2941.

Our Gold Sponsors

Our Silver Sponsors

v7.25.1

Compare Source

Patch Changes

  • Show dependency paths info in pnpm audit output #​3073
  • The store integrity check should validate the side effects cache of the installed package. If the side effects cache is broken, the package needs to be rebuilt #​4997.
  • Add more info to the description of the --force option in the pnpm install command #​5932.
  • Don't crash when a bin file is not found and prefer-symlinked-executables is true #​5946.
  • pnpm install --fix-lockfile should not fail if the package has no dependencies #​5878.

Our Gold Sponsors

Our Silver Sponsors

v7.25.0

Compare Source

Minor Changes

  • When patching a dependency that is already patched, the existing patch is applied to the dependency, so that the new edit are applied on top of the existing ones. To ignore the existing patches, run the patch command with the --ignore-existing option #​5632.
  • When extend-node-path is set to false, the NODE_PATH environment variable is not set in the command shims #​5910

Patch Changes

  • Ensure the permission of bin file when prefer-symlinked-executables is set to true #​5913.
  • If an external tool or a user have removed a package from node_modules, pnpm should add it back on install. This was only an issue with node-linker=hoisted.

Our Gold Sponsors

Our Silver Sponsors

v7.24.3

Compare Source

Patch Changes

  • Don't break lockfile v6 on repeat install if use-lockfile-v6 is not set to true.

Our Gold Sponsors

Our Silver Sponsors


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/pnpm-7.x branch 2 times, most recently from 3bdefcc to 2a9b885 Compare August 23, 2022 11:36
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.9.3 chore(deps): bump pnpm to 7.9.4 Aug 23, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.9.4 chore(deps): bump pnpm to 7.9.5 Aug 24, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.9.5 chore(deps): bump pnpm to 7.10.0 Sep 4, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.10.0 chore(deps): bump pnpm to 7.11.0 Sep 5, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.11.0 chore(deps): bump pnpm to 7.12.0 Sep 18, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.12.0 chore(deps): bump pnpm to 7.12.1 Sep 20, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.12.1 chore(deps): bump pnpm to 7.11.0 Sep 22, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.11.0 chore(deps): bump pnpm to 7.12.2 Sep 23, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.12.2 chore(deps): bump pnpm to 7.13.0 Oct 3, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.13.0 chore(deps): bump pnpm to 7.13.1 Oct 4, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.13.1 chore(deps): bump pnpm to 7.13.2 Oct 5, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.13.2 chore(deps): bump pnpm to 7.13.3 Oct 9, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.13.3 chore(deps): bump pnpm to 7.13.4 Oct 10, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.13.4 chore(deps): bump pnpm to 7.13.5 Oct 16, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.14.0 chore(deps): bump pnpm to 7.14.1 Oct 29, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.14.1 chore(deps): bump pnpm to 7.14.2 Nov 2, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.14.2 chore(deps): bump pnpm to 7.15.0 Nov 10, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.15.0 chore(deps): bump pnpm to 7.16.0 Nov 14, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.16.0 chore(deps): bump pnpm to 7.16.1 Nov 16, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.16.1 chore(deps): bump pnpm to 7.17.0 Nov 20, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.17.0 chore(deps): bump pnpm to 7.17.1 Nov 27, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.17.1 chore(deps): bump pnpm to 7.18.0 Dec 4, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.18.0 chore(deps): bump pnpm to 7.18.1 Dec 6, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.18.1 chore(deps): bump pnpm to 7.18.2 Dec 12, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.18.2 Bump pnpm to 7.18.2 Dec 17, 2022
@renovate renovate bot changed the title Bump pnpm to 7.18.2 chore(deps): bump pnpm to 7.18.2 Dec 17, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.18.2 chore(deps): bump pnpm to 7.19.0 Dec 21, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.19.0 chore(deps): bump pnpm to 7.20.0 Dec 26, 2022
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.20.0 chore(deps): bump pnpm to 7.29.1 Mar 9, 2023
@renovate renovate bot changed the title chore(deps): bump pnpm to 7.29.1 chore(deps): bump pnpm to 7.29.3 Mar 16, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant