Skip to content

chore(deps): update all non-major dependencies - #84

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

chore(deps): update all non-major dependencies#84
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@changesets/cli (source) ^3.0.1^3.0.2 age confidence devDependencies patch
@changesets/get-github-info (source) ^1.0.0^1.0.1 age confidence devDependencies patch
@swc/core (source) ^1.16.1^1.16.2 age confidence devDependencies patch
@wolfstar/http-framework (source) ^3.2.1^3.6.0 age confidence devDependencies minor
@wolfstar/http-framework (source) ^3.4.0^3.6.0 age confidence devDependencies minor
@wolfstar/i18next-type-generator (source) 3.1.03.1.2 age confidence devDependencies patch
changesets/action v2.1.1v2.1.2 age confidence action patch
evlog (source) ^2.28.1^2.29.0 age confidence devDependencies minor
knip (source) 6.34.06.35.1 age confidence devDependencies minor
oxfmt (source) 0.66.00.67.0 age confidence devDependencies minor
oxlint (source) 1.81.01.82.0 age confidence devDependencies minor
pnpm (source) 12.3.112.4.1 age confidence packageManager minor
pnpm/action-setup v6.0.10v6.1.0 age confidence action minor
tsdown (source) ^0.22.14^0.23.0 age confidence devDependencies minor
zizmorcore/zizmor-action v0.6.3v0.6.4 age confidence action patch

Release Notes

changesets/changesets (@​changesets/cli)

v3.0.2

Compare Source

Patch Changes
changesets/changesets (@​changesets/get-github-info)

v1.0.1

Compare Source

Patch Changes
swc-project/swc (@​swc/core)

v1.16.2

Compare Source

Bug Fixes
Features
  • (es/minifier) Evaluate Math.floor, Math.ceil, Math.round and Mat… (#​12117) (e876e80)

  • (es/parser) Add opt-in parser-only TSRX lowering (#​12120) (61ff097)

Miscellaneous Tasks
Refactor
Testing
Ci
wolfstar-project/stars-components (@​wolfstar/http-framework)

v3.6.0

Compare Source

Minor Changes
  • #​168 b516cad - feat: align the stars dev terminal UI with Nuxt's pinned panel and folded logs

    The tsdown builder now leaves dependencies external with deps.neverBundle, removing the deprecated option and
    keeping shared dependencies external for dynamically loaded pieces. Its entry list, target and output-size table
    are suppressed; warnings and errors remain available in the log browser and log file.

    The bottom-aligned panel displays an animated Stars wordmark, aligned URLs, actual build-phase progress and elapsed
    time, then readiness timing and diagnostic counts. dev.banner accepts custom text/lines or false to hide the
    wordmark. Log, help and session-info views use the alternate screen and restore the panel when closed. Logs support
    search, source/level filters, selection, copying, and jumping to the last error with context. Stack frames are dimmed
    and no longer counted as separate errors; Node warnings are classified as warnings rather than errors.

    Rebuild state and duration now reset on Rolldown's per-build hook, including recovery from a failed build. Reduced
    motion preserves the elapsed clock, and redirected input, dumb terminals and small panes get a safe plain fallback. Thanks @​RedStar071!

Patch Changes

v3.5.0

Compare Source

Minor Changes
  • #​164 05fca34 - feat(config): configure the tsdown build from stars.config

    The tsdown block is now the project's build configuration rather than a bag of options merged into a separate
    tsdown.config.ts, and it is typed with the options a bot actually reaches for (entry, format, unbundle,
    plugins, alias, define, deps, hooks, …) instead of Record<string, unknown>. What stars.config already
    says — the entry's directory, build.outDir, build.tsconfig, the extension build.output implies — fills in the
    rest, so most projects need nothing in it at all.

    build.tsconfig is now resolved for tsdown builds too, not only tsc ones (src/tsconfig.json, else
    tsconfig.json): tsdown alone looks only next to the project root, so a bot keeping its sources' tsconfig in
    src/ — the layout the scaffold and the examples use — silently built without its paths and target.

    build.configFile on the resolved configuration reports which file the build tool is configured from
    (tsdown.config.*, package.json#tsdown, vite.config.*), or null when stars.config is the only one.

    Two options are also validated against the build tool they belong to: a non-empty tsdown block with another tool
    raises TSDOWN_OPTIONS_REQUIRE_TSDOWN, and vite likewise raises VITE_OPTIONS_REQUIRE_VITE. A project that only
    declares tsdown: {} now resolves build.tool: 'auto' to tsdown, the way depending on it already did. Thanks @​RedStar071!

  • #​164 05fca34 - feat(config): add future.compatibilityVersion, with auto imports on from 4

    future carries the defaults of the next major, the way Nuxt's own future.compatibilityVersion does: a project
    opts into them one major early, and they become the default when that major ships. Where experimental guards work
    that is still landing, everything in future is already decided.

    future: { compatibilityVersion: 4 } changes three things:

    • Auto imports are on with the tsdown build tool, and stars wires the autoImports() plugin into the build
      itself — until now the default said true but nothing injected the transform unless the project's own
      tsdown.config.ts did. At 3 they stay off unless asked for, so the promise matches what the build does.
    • tsdown is configured from stars.config alone. A tsdown.config.* (or a package.json#tsdown field) raises
      TSDOWN_CONFIG_FILE_UNSUPPORTED naming the file, rather than being silently ignored and quietly dropping the
      plugins it declares.
    • build.tool: 'auto' resolves to tsdown for any TypeScript entry, without looking for a tsdown.config.* or a
      tsdown dependency first. tsc stays available as an explicit choice.

    3 is the default and keeps today's behaviour, including loading a tsdown.config.* and merging the tsdown block
    over it. An unknown version raises INVALID_COMPATIBILITY_VERSION. Thanks @​RedStar071!

wolfstar-project/stars-components (@​wolfstar/i18next-type-generator)

v3.1.2

Compare Source

Patch Changes

v3.1.1

Compare Source

Patch Changes
  • #​163 a697108 - Enable npm provenance for published releases (publishConfig.provenance), matching every other package in this workspace. Thanks @​RedStar071!
changesets/action (changesets/action)

v2.1.2

Compare Source

Patch Changes
evloghq/evlog (evlog)

v2.29.0

Compare Source

What's Changed

Features 🚀
Bug Fixes 🐞
Documentation 📚
  • docs: add logger comparisons and OpenTelemetry integration guide by @​evlogai[bot] in #​680
Dependency Updates 📦

Full Changelog: https://github.com/evloghq/evlog/compare/evlog@2.28.1...evlog@2.29.0

webpro-nl/knip (knip)

v6.35.1: Release 6.35.1

Compare Source

v6.35.0: Release 6.35.0

Compare Source

oxc-project/oxc (oxfmt)

v0.67.0

Compare Source

🛡️ Security
oxc-project/oxc (oxlint)

v1.82.0

Compare Source

🚀 Features
  • 6a0e19c linter/eslint/no-unmodified-loop-condition: Support checkConditionalExpressions option (#​26249) (camc314)
pnpm/pnpm (pnpm)

v12.4.1: pnpm 12.4.1

Compare Source

pnpm 12.4.1 fixes installs that failed on filesystems refusing hard links or clones, on Android, and under nodeLinker: hoisted. Repeat installs are faster.

Patch Changes

Installing packages
  • pnpm install no longer fails with Operation not permitted when the filesystem refuses a hard link or a copy-on-write clone #​14722. Under packageImportMethod: auto and clone-or-copy, pnpm copies the file instead. EdenFS checkouts, which have no hard links, and rootless containers, which refuse the clone syscall, both hit this. An explicit packageImportMethod: hardlink or clone still reports the error.

    pnpm also copies a package file whose store entry has reached the filesystem's limit on names for one file, 1024 on NTFS and 65000 on ext4. Such a file failed the install under packageImportMethod: hardlink, and under auto it stopped pnpm hard linking for the rest of the install.

  • pnpm install no longer writes a package file through a symlink left at the path it is importing to. Copying such a file overwrote whatever the link pointed at, and created that file when the link pointed nowhere. An executable package file also made the link's target executable.

  • Fixed pnpm install and pnpm dlx on Android. Registry requests crashed because pnpm found no system CA certificates, so pnpm uses bundled ones there #​14777. Imports also failed with "Permission denied" on filesystems that deny hard links and reflinks, and now fall back to copying #​14780.

  • pnpm install no longer fails with "Invalid cross-device link" while preserving a package's nested node_modules directory during a Docker build #​14758.

  • pnpm install no longer fails on a package tarball that carries a file at the archive root, such as the ._* entries macOS tar adds #​14701. The file is installed at the root of the package.

    A file: tarball packed without the usual package/ directory is now recorded under the name and version from its own package.json. It was recorded under the alias the dependency was given, at version 0.0.0.

  • Under nodeLinker: hoisted, pnpm install no longer re-imports packages that are already in place. A repeat install replaced the whole node_modules tree and reported Packages: +N. A package is still imported when its directory is missing, when its package.json no longer carries the installed version, when it is a file: dependency, and when it is patched. Lifecycle scripts no longer run again for a package left in place, and pnpm rebuild and a change to allowBuilds still reach it.

  • pnpm install now runs a dependency's build scripts again when its side-effects cache entry has no files to restore #​14717. Such builds were skipped and nothing was put in their place, so a script whose whole effect lands outside its own package directory, such as a git hook installer, never took effect. pnpm no longer publishes empty artifacts to the shared side-effects cache either.

Resolving and linking dependencies
  • pnpm install, pnpm add, and pnpm dedupe now apply ignoredOptionalDependencies #​14729. Matching optional dependencies are left out of the lockfile and are not installed. pnpm 12 installed them whenever it resolved dependencies from scratch.

  • pnpm install no longer links a transitive dependency to a workspace package when linkWorkspacePackages is true and the dependency is declared with a plain version range #​14781. Enabling preferWorkspacePackages does not change this. Set linkWorkspacePackages: deep to link them.

  • pnpm install no longer leaves dangling dependency links in workspace packages located above the workspace root #​14726.

  • pnpm install and pnpm add no longer leave a dangling symlink in node_modules when a project starts depending directly on a package that the lockfile holds only as a transitive dependency with resolved peer dependencies #​14714.

  • pnpm dedupe now keeps a compatible auto-installed peer when another workspace project depends on a newer major #​14697. Repeated runs alternated between compatible and incompatible peer versions.

  • pnpm peers check no longer reports a peer dependency declared as workspace:^, workspace:~, or a bare workspace: as unmet #​14770. pnpm reported these as unmet whatever version the linked workspace project supplied.

Performance
  • Sped up repeat installs #​14540. pnpm checks the store's files only for the packages it links into node_modules, instead of every package in the lockfile. Creating the command shims in node_modules/.bin makes about 1,500 fewer filesystem calls in a 76 project workspace. Installs that use the global virtual store read their slot paths from the cache directory instead of deriving them every time. Verifying a large lockfile also allocates less memory.

  • Sped up pnpm install in Cargo workspaces with many member crates. Repeated installs reuse verified Cargo checksum metadata.

  • Installing several packages from the same Git repository and commit now downloads the source once per install #​14725. Each package still runs its prepare scripts in its own copy of the checkout.

Running scripts and tasks
  • pnpm now passes Ctrl+C on to the script or command it started and waits for it to shut down #​14723. pnpm exited first, so a script that was still writing landed on the shell prompt.

  • pnpm run "/pattern/" --no-bail now lets every matched script finish after one of them fails #​14718. The command exits with ERR_PNPM_RUN_FAILED, and its message lists the scripts that failed in the order they were selected.

  • pnpm pipeline no longer fails on a project that tracks a symlink, such as a CLAUDE.md pointing at AGENTS.md #​14692. Changing a symlinked input's target invalidates that task's cache, and pnpm pipeline --no-cache no longer hashes task inputs.

Commands
  • pnpm add -g, pnpm update -g, and pnpm remove -g no longer change global bins or install directories after reading only part of an installed package group #​13796. If any declared package manifest is missing, malformed, or unreadable, pnpm now fails before it activates or removes anything and leaves the existing global installation intact.

  • pnpm dedupe now processes every workspace project by default, including workspaces that keep a separate lockfile per project #​14732. Workspace filters select which projects it processes, and --fail-if-no-match exits with an error when no project matches.

  • pnpm update <name>@<version> now keeps the range operator the manifest declares #​14745. Running pnpm update react@19.3.0 on "react": "^19.2.8" writes "react": "^19.3.0". A jsr: entry keeps its jsr: prefix, and a plain pnpm update now moves a jsr: range the way it moves an npm range.

  • pnpm --filter directory selectors now support ? wildcards and character classes such as [ab]. A * or ? wildcard no longer selects a directory whose name starts with a dot, as on pnpm 11.

  • pnpm deploy --legacy now prefers the dependency versions pinned in the source workspace lockfile when they still satisfy the deployed project's range #​13857.

  • pnpm sbom now leaves out a package's author field when the manifest author name is empty or contains only whitespace #​14685. In a filtered or split workspace run, only a project with no author field inherits the workspace root's author.

    pnpm sbom --sbom-format spdx now writes creationInfo.created with whole seconds, such as 2026-09-08T10:38:21Z #​14684. The fractional seconds it carried were rejected by strict SPDX consumers.

Configuration
  • The updateConfig pnpmfile hook now receives the resolved configuration, including settings that came from .npmrc, the command line, or a default #​14676. Scoped registries are reported under registriesByScope, and a hook may rewrite that map to change where packages are fetched from. Registry credentials are reported under configByUri, as pnpm 11 reports them. An unset setting is left out rather than reported as null.

  • pnpm audit --fix and the minimumReleaseAgeStrict approval prompt now keep the comments in minimumReleaseAgeExclude when they append an entry to it in pnpm-workspace.yaml. The rest of the list is left as written, and the trustPolicyExcludePrune and minimumReleaseAgeExcludePrune cleanups keep the comments of the entries they retain.

    pnpm install and pnpm dedupe now run those cleanups too #​14759. Only pnpm add, pnpm update, and pnpm remove pruned the entries that the freshly written lockfile no longer resolves.

  • pnpm config set --global node-download-mirrors no longer rejects the key #​13611. The global config file already accepted nodeDownloadMirrors, but the command refused to write it.

  • NO_PROXY entries that start with a dot, such as .npmjs.org, now bypass the proxy for the domain and its subdomains #​14686.

  • pnpm no longer creates a project pnpm-lock.yaml when devEngines.packageManager.onFail is download and lockfile writing is off through lockfile: false or --no-lockfile #​14728. pnpm still switches to the pinned version.

  • pnpm now writes node_modules/.package-map.json only when nodeExperimentalPackageMap is enabled. Nothing reads the file without that setting, and an install that stops writing the map removes the one a previous install left.

Windows
  • pnpm pipeline no longer fails with intermittent access denied errors when concurrent tasks save their cache entries on Windows.

  • Windows filesystem operations now retry permission errors for up to one second #​14682. A permanent permission error delayed the failure by a minute. Sharing and lock violations keep their one minute retry budget.

Messages and output
  • pnpm now warns when the root package.json declares a non-empty workspaces array and the project has no pnpm-workspace.yaml #​2255. Such an install linked no project and said nothing about why.

  • ERR_PNPM_PACKAGE_MANAGER_REMOVE_MODULES_DIR now names the file or directory in node_modules that pnpm could not clean up. It reported only the underlying OS error, such as "Access is denied (os error 5)".

  • pnpm --help no longer describes pnpm as experimental.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.4.0: pnpm 12.4

Compare Source

Minor Changes
  • pnpm can now manage npm, Python, and Cargo dependencies in the same workspace. Enable python.enabled or cargo.enabled in pnpm-workspace.yaml, then use pnpm install to install them together.

    • Add Python packages with pnpm add pypi:<package>. pnpm uses pyproject.toml, pylock.toml, and a managed .venv. Frozen and offline installs are supported, and pnpm run and pnpm exec make the environment's executables available #​14566.
    • Add Rust crates with pnpm add crate:<package>. pnpm supports crates.io and custom sparse registries configured with cargo.indexUrl. Registry authentication supports pnpm credentials and, for crates.io, CARGO_REGISTRY_TOKEN or $CARGO_HOME/credentials.toml.

    Both ecosystems support faster dependency resolution through pnprServer, with local resolution as a fallback when the server does not support it.

  • Added pnpm pipeline [name] to install frozen dependencies and run workspace tasks declared in pipelines. It selects affected projects, runs their task graph, and continues running tasks after a task fails.

    Tasks support inputs, outputs, env, and cache settings. Cached results restore task outputs and replay logs. Cargo tasks can reuse local build state between worktrees with tasks.<name>.cargoTargetDir. Set includeWorkspaceRoot: true to include root tasks.

    Use pnpm pipeline --dry-run to preview the task graph without installing configuration dependencies or running workspace hooks.

  • Added support for Android on arm64 and x64, FreeBSD on x64, and Linux on ppc64le, s390x, and RISC-V (riscv64 with glibc) #​14431, #​14597, #​7582.

  • Added trustPolicyExcludePrune to automatically remove unused versions and packages from trustPolicyExclude when running pnpm add, pnpm update, or pnpm remove. It is disabled by default. Package name patterns such as @scope/* are kept, and cleanup is skipped when sharedWorkspaceLockfile is false.

  • Added pnpm change check for CI validation of package versions against the versioning.epics bands and versioning.fixed groups in pnpm-workspace.yaml. It reports all violations, including packages that are not part of the current release.

Patch Changes
  • Registry metadata is now kept separate for registries with different URL paths or schemes. This prevents installs from using another registry's package versions or tarball URLs, and keeps metadata fetched over HTTP from being reused for HTTPS #​13558.

    The first install after upgrading refetches registry metadata. The package store is unchanged. pnpm cache view now shows full registry URLs. Scripts that parse the directory names from pnpm cache list-registries or pnpm cache list need updating.

  • Patches that add build scripts or a binding.gyp now trigger a build, subject to build approval. Unapproved builds appear under "Ignored build scripts" #​14648.

  • Build scripts can now be rejected before installing a package with pnpm add --allow-build=!<pkg>, including global installs. pnpm approve-builds <pkg> and pnpm approve-builds !<pkg> also save decisions when no packages are awaiting approval. They warn if the named package is not awaiting approval #​14067.

  • A registry configured in .npmrc now takes precedence over registry settings saved by pnpm login in the global config.yaml. This fixes installs using the wrong registry after login #​14614.

  • Large downloads over slow connections no longer time out while data is still arriving. fetch-timeout now limits how long a request can go without making progress #​14604.

  • Sped up installs in workspaces with many projects when reusing a warm global virtual store #​14540.

  • pnpm deploy is faster in large workspaces and no longer fails with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH when the project includes a .pnpmfile.mjs #​14539, #​14671.

  • pnpm add --workspace <pkg> works again. It saves the dependency with the workspace: protocol and links it from the workspace. The command fails if no workspace project provides the package #​14602.

  • pnpm add and pnpm install now accept protocol-prefixed selectors such as jsr:@scope/pkg, npm:pkg@^1.0.0, and workspace:pkg@* #​14590. Installs with JSR dependencies in the lockfile als

Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 12pm on Sunday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from RedStar071 as a code owner September 13, 2026 01:59
@coldtea-pr-lens

coldtea-pr-lens Bot commented Sep 13, 2026

Copy link
Copy Markdown

◈ PR Lens

🟢 +0 new · 🟠 ~6 changed · 🔴 -0 removed · 0 flows · 8 files · commit d18f0a3


Architecture

Architecture diagram for wolfstar-project/plugins at d18f0a3

6 components touched across 5 lanes.

Open the interactive canvas


Data flow

No data-flow sequence changed in this PR.


View

  • Architecture lens
  • Data flow lens
  • Expand every detail

Tip

The diagrams are links. Click one to open it on the canvas, then press W or click play to walk through the change.

🪧 More tips
  • Run npx skills add coldteadotai/pr-lens, then tell your coding agent: "Diagram the change you just made with PR Lens and attach it to the pull request."
  • Run npx @coldtea/pr-lens-cli analyze --base origin/main on a branch, then npx @coldtea/pr-lens-cli render .pr-lens/graph.json. Same lenses, your own model key, before the pull request exists.
  • Untick Architecture lens or Data flow lens under View to hide a diagram, or tick Expand every detail to open every section. The comment redraws in a few seconds.
  • Click the link under each diagram to open it on a canvas you can zoom, pan and step through.
  • Open a diagram on the canvas, then press W or click play to walk through the change one step at a time.
  • The CLI's render reads .github/pr-lens.yml and applies your renames, exclusions and lane pins at draw time.
  • Set github.comment.collapsed: true in .github/pr-lens.yml to fold the comment behind one View architecture and data flow row. Drawing still runs on every push.
  • Add .github/workflows/pr-lens.yml with coldteadotai/pr-lens/packages/action@v0 and your model provider's key as its api-key to run PR Lens from your own CI. Any /chat/completions endpoint works.
  • Push a commit and the comment redraws for the new head. A slow older run never overwrites a newer one.
  • Switch GitHub to dark mode and the diagrams follow. The moving dots are this pull request's data in motion.

Thanks for using PR Lens! It's built by Coldtea, free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

@wolfstarbot wolfstarbot added packages:plugin-api packages:plugin-i18next Changes in plugin-i18next packages:plugin-logger Changes in plugin-logger labels Sep 13, 2026
@socket-security

socket-security Bot commented Sep 13, 2026

Copy link
Copy Markdown

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 19814b1 to ca10a4c Compare September 13, 2026 07:56
@pkg-pr-new

pkg-pr-new Bot commented Sep 13, 2026

Copy link
Copy Markdown

Open in StackBlitz

pnpm add https://pkg.pr.new/@wolfstar/plugin-api@84
pnpm add https://pkg.pr.new/@wolfstar/plugin-i18next@84
pnpm add https://pkg.pr.new/@wolfstar/plugin-logger@84
pnpm add https://pkg.pr.new/@wolfstar/plugin-subcommands-advanced@84

commit: d18f0a3

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from ca10a4c to abe505a Compare September 13, 2026 17:51
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from abe505a to d18f0a3 Compare September 14, 2026 01:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant