Update npm deps (major) - #975
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
|
renovate
Bot
force-pushed
the
renovate/major-npm-deps
branch
from
February 23, 2025 07:17
ec20fba to
5984392
Compare
renovate
Bot
force-pushed
the
renovate/major-npm-deps
branch
3 times, most recently
from
May 19, 2025 18:38
7b9a50a to
55c3842
Compare
renovate
Bot
force-pushed
the
renovate/major-npm-deps
branch
4 times, most recently
from
June 26, 2025 21:51
9044dc8 to
960beec
Compare
renovate
Bot
force-pushed
the
renovate/major-npm-deps
branch
from
July 9, 2025 13:48
960beec to
fdf43be
Compare
renovate
Bot
force-pushed
the
renovate/major-npm-deps
branch
2 times, most recently
from
July 23, 2025 18:14
7c4eb9d to
dd539cf
Compare
renovate
Bot
force-pushed
the
renovate/major-npm-deps
branch
from
July 31, 2025 18:05
dd539cf to
461c094
Compare
renovate
Bot
force-pushed
the
renovate/major-npm-deps
branch
2 times, most recently
from
August 10, 2025 13:21
c930a95 to
e5cfad8
Compare
renovate
Bot
force-pushed
the
renovate/major-npm-deps
branch
6 times, most recently
from
August 19, 2025 22:00
609c1c4 to
ba36706
Compare
renovate
Bot
force-pushed
the
renovate/major-npm-deps
branch
2 times, most recently
from
September 2, 2025 15:56
ee8c002 to
1d306d0
Compare
renovate
Bot
force-pushed
the
renovate/major-npm-deps
branch
from
September 8, 2025 00:52
1d306d0 to
534afe9
Compare
renovate
Bot
force-pushed
the
renovate/major-npm-deps
branch
5 times, most recently
from
September 18, 2025 19:52
583aa24 to
d656845
Compare
renovate
Bot
force-pushed
the
renovate/major-npm-deps
branch
4 times, most recently
from
September 29, 2025 12:33
9937424 to
672d652
Compare
renovate
Bot
force-pushed
the
renovate/major-npm-deps
branch
6 times, most recently
from
October 2, 2025 17:33
09d3612 to
436a405
Compare
renovate
Bot
force-pushed
the
renovate/major-npm-deps
branch
from
August 17, 2026 19:12
8b59252 to
ef810f6
Compare
renovate
Bot
force-pushed
the
renovate/major-npm-deps
branch
from
August 17, 2026 19:13
ef810f6 to
c2e9427
Compare
Generated by renovateBot
renovate
Bot
force-pushed
the
renovate/major-npm-deps
branch
from
August 17, 2026 19:18
c2e9427 to
1725a30
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^7.27.1→^8.0.0^1.10.0→^2.0.0^1.10.0→^2.0.03.15.1→5.2.310.34.5→11.20.05.9.3→7.0.2Release Notes
babel/babel (@babel/core)
v8.0.1Compare Source
💥 Breaking Change
babel-core,babel-plugin-transform-object-rest-spread,babel-plugin-transform-runtime,babel-preset-env,babel-standalonepreset-env'suseBuiltIns(@nicolo-ribaudo)v8.0.0Compare Source
👓 Spec Compliance
babel-core💥 Breaking Change
babel-cli,babel-node,babel-plugin-proposal-decorators,babel-plugin-transform-classes,babel-plugin-transform-function-name,babel-plugin-transform-modules-commonjs,babel-plugin-transform-object-rest-spread,babel-plugin-transform-parameters,babel-plugin-transform-react-constant-elements,babel-plugin-transform-regenerator,babel-preset-env,babel-registermodules: auto(@nicolo-ribaudo)babel-plugin-transform-runtime,babel-runtime-corejs3,babel-runtime@babe/runtime-corejs3(@liuxingbaoyu)babel-parserlocations: "packed"(@liuxingbaoyu)🐛 Bug Fix
babel-generatorbabel-plugin-transform-modules-systemjs📝 Documentation
🏠 Internal
🏃♀️ Performance
babel-corebufbuild/protobuf-es (@bufbuild/protobuf)
v2.13.0Compare Source
What's Changed
Full Changelog: bufbuild/protobuf-es@v2.12.1...v2.13.0
v2.12.1Compare Source
What's Changed
New Contributors
Full Changelog: bufbuild/protobuf-es@v2.12.0...v2.12.1
v2.12.0Compare Source
What's Changed
exactOptionalPropertyTypesby @haines in #1371utf8_validationby @emcfarlane in #1386New Contributors
Full Changelog: bufbuild/protobuf-es@v2.11.0...v2.12.0
v2.11.0Compare Source
What's Changed
elide_plugin_version=trueby @timostamm in #1336Full Changelog: bufbuild/protobuf-es@v2.10.2...v2.11.0
v2.10.2Compare Source
What's Changed
google.protobuf.Value.null_valuein map values in ProtoJSON by @timostamm in #1314Full Changelog: bufbuild/protobuf-es@v2.10.1...v2.10.2
v2.10.1Compare Source
What's Changed
New Contributors
Full Changelog: bufbuild/protobuf-es@v2.10.0...v2.10.1
v2.10.0Compare Source
What's Changed
New Contributors
Full Changelog: bufbuild/protobuf-es@v2.9.0...v2.10.0
v2.9.0Compare Source
What's Changed
Full Changelog: bufbuild/protobuf-es@v2.8.0...v2.9.0
v2.8.0Compare Source
What's Changed
Full Changelog: bufbuild/protobuf-es@v2.7.0...v2.8.0
v2.7.0Compare Source
What's Changed
Uint8ArraytoUint8Array<ArrayBuffer>by @timostamm in #1200Full Changelog: bufbuild/protobuf-es@v2.6.3...v2.7.0
v2.6.3Compare Source
What's Changed
New Contributors
Full Changelog: bufbuild/protobuf-es@v2.6.2...v2.6.3
v2.6.2Compare Source
What's Changed
roundinstead ofceilwhen converting Timestamp to milliseconds by @srikrsna-buf in #1178Full Changelog: bufbuild/protobuf-es@v2.6.1...v2.6.2
v2.6.1Compare Source
What's Changed
Full Changelog: bufbuild/protobuf-es@v2.6.0...v2.6.1
v2.6.0Compare Source
What's Changed
Full Changelog: bufbuild/protobuf-es@v2.5.2...v2.6.0
v2.5.2Compare Source
What's Changed
Full Changelog: bufbuild/protobuf-es@v2.5.1...v2.5.2
v2.5.1Compare Source
What's Changed
Full Changelog: bufbuild/protobuf-es@v2.5.0...v2.5.1
v2.5.0Compare Source
What's Changed
Full Changelog: bufbuild/protobuf-es@v2.4.0...v2.5.0
v2.4.0Compare Source
What's Changed
Full Changelog: bufbuild/protobuf-es@v2.3.0...v2.3.1
v2.3.0Compare Source
What's Changed
Full Changelog: bufbuild/protobuf-es@v2.2.5...v2.3.0
v2.2.5Compare Source
What's Changed
Full Changelog: bufbuild/protobuf-es@v2.2.4...v2.2.5
v2.2.4Compare Source
What's Changed
New Contributors
Full Changelog: bufbuild/protobuf-es@v2.2.3...v2.2.4
v2.2.3Compare Source
What's Changed
Full Changelog: bufbuild/protobuf-es@v2.2.2...v2.2.3
v2.2.2Compare Source
What's Changed
New Contributors
Full Changelog: bufbuild/protobuf-es@v2.2.1...v2.2.2
v2.2.1Compare Source
What's Changed
Full Changelog: bufbuild/protobuf-es@v2.2.0...v2.2.1
v2.2.0Compare Source
What's Changed
DescMethodvariants by @srikrsna-buf in #985New Contributors
Full Changelog: bufbuild/protobuf-es@v2.1.0...v2.2.0
v2.1.0Compare Source
What's Changed
Full Changelog: bufbuild/protobuf-es@v2.0.0...v2.1.0
v2.0.0Compare Source
What's new in version 2
To support Protobuf editions, we have to make breaking changes that also affect users of proto2 and proto3. This prompted us to make more extensive changes that take feedback from version 1 into account:
We no longer use classes. Instead, we generate a schema object and a type for every message. To create a new instance, to serialize, and for other concerns, we provide functions. Here is a simple example:
If you use proto3, messages are now plain objects. Files with proto2 and editions use the prototype chain to track field presence.
This approach solves several outstanding issues, such as:
Contributors
Thanks to @srikrsna-buf for his contributions to v2!
nodeca/js-yaml (js-yaml)
v5.2.3Compare Source
Fixed
!!timestampyears 0000-0099 correctly, #775.unpaired mapping event streams, #784.
parsed AST through
present();dump()and loading are unaffected, #780.v5.2.2Compare Source
Fixed
Security
v5.2.1Compare Source
Fixed
Mapsupport to !!omap (should work whenrealMapTagused)Security
addItem. Regression from v5(usually not critical, because YAML11_SCHEMA is not default anymore).
v5.2.0Compare Source
Added
maxTotalMergeKeys(10000) loader option to limit the total number ofkeys processed by YAML merge (
<<) across oneload()/loadAll()call.maxAliases(-1) loader option to limit the number of YAML aliases perdocument.
Removed
maxMergeSeqLengthreplaced withmaxTotalMergeKeysfor limiting YAML mergeprocessing.
Fixed
1e21)v5.1.0Compare Source
Added
different result value.
Changed
quoteStylenow selects the preferred quote style; use therestored
forceQuotesoption to force quoting non-key strings.v5.0.0Compare Source
Added
JSON_SCHEMAandCORE_SCHEMAwith spec-compliant scalar resolutionrules, and added
YAML11_SCHEMA.realMapTagfor lossless mappings with non-string and complex keys.Object-based mappings now reject complex keys instead of stringifying them.
dump()transformoption for changing the generated AST beforerendering.
dump()optionsseqInlineFirst,flowBracketPadding,flowSkipCommaSpace,flowSkipColonSpace,quoteFlowKeys,quoteStyleandtagBeforeAnchor.test set.
Changed
exports.
CORE_SCHEMA(loader default),JSON_SCHEMA,FAILSAFE_SCHEMA.YAML11_SCHEMA, a combination of all YAML 1.1 tags (YAML 1.1 does notspecify a schema, only "types").
load/dumpdefault behaviour is now specified exactly via schemas:loadusesCORE_SCHEMA, without!!mergeby default.dumpusesYAML11_SCHEMA+CORE_SCHEMAfor the quoting check, toguarantee backward compatibility by default.
!!setis now loaded as a JavaScriptSet.TypeAPI with a tags API. Similar, but more precise andsimpler. See examples for details. Tags can be defined via
defineScalarTag(),defineSequenceTag()anddefineMappingTag(), or as aspread + override of an existing tag.
Schema.extend()toSchema.withTags().markers, block keys, multiline scalars, tag syntax and other things.
load()now throws on empty input instead of returningundefined.js-yaml/browserexport.loadAllsignature with an iterator (still works, but is acandidate for removal).
Removed
safeLoad(),safeLoadAll()andsafeDump()exports.DEFAULT_SCHEMAand the nestedtypesexport.onWarning,legacyandlistener.styles,replacer,noCompatMode,condenseFlow,quotingTypeandforceQuotes. RenamednoArrayIndenttoseqNoIndent.Formatting and representation are now configured through presenter options,
schemas and tag definitions. See migration guide on how to replace.
lib/.v4.3.1Compare Source
v4.3.0Compare Source
v4.2.0Compare Source
Added
docs/safety.mdwith notes about processing untrusted YAML.maxDepth(100) loader option. Not a problem, but gives a betterexception instead of RangeError on stack overflow.
maxMergeSeqLength(20) loader option. Not a problem aftermergefix,but an additional restriction for safety.
dist/builds.Changed
dist/files are no longer kept in the repository.Fixed
Security
elements (makes sense for malformed files > 10K).
v4.1.1Compare Source
Security
v4.1.0Compare Source
Added
yaml.types.XXX.optionsproperty with original arguments kept as they were(see
yaml.types.int.optionsas an example).Changed
Schema.extend()now keeps old type order in case of conflicts(e.g. Schema.extend([ a, b, c ]).extend([ b, a, d ]) is now ordered as
abcdinstead ofcbad).v4.0.0Compare Source
Changed
!!js/function,!!js/regexp,!!js/undefinedaremoved to js-yaml-js-types package.
safe*functions. Useload,loadAll,dumpinstead which are all now safe by default.
yaml.DEFAULT_SAFE_SCHEMAandyaml.DEFAULT_FULL_SCHEMAare removed, useyaml.DEFAULT_SCHEMAinstead.yaml.Schema.create(schema, tags)is removed, useschema.extend(tags)instead.!!binarynow always mapped toUint8Arrayon load./libfolder.01234is now decimal,0o1234is octal,1:23is parsed as string instead of base60).dump()no longer quotes:,[,],(,)except when necessary, #470, #557.(X:Y)instead ofat line X, column Y(also present in compact format), #332.dump()now serializesundefinedasnullin collections and removes keys withundefinedin mappings, #571.dump()withskipInvalid=truenow serializes invalid items in collections as null.!are now dumped as!taginstead of!<!tag>, #576.tag:yaml.org,2002:are now shorthanded using!!, #258.Added
.mjs(es modules) support.quotingTypeandforceQuotesoptions for dumper to configurestring literal style, #290, #529.
styles: { '!!null': 'empty' }option for dumper(serializes
{ foo: null }as "foo:"), #570.replaceroption (similar to option in JSON.stringify), #339.Tagcan now handle all tags or multiple tags with the same prefix, #385.Fixed
dump(), #587.[foo,,bar]) now throw an exceptioninstead of producing null, #321.
__proto__key no longer overrides object prototype, #164.bower.json.load()and url-encoded indump()(previously usage of custom non-ascii tags may have led to invalid YAML that can't be parsed).
pnpm/pnpm (pnpm)
v11.20.0: pnpm 11.20Compare Source
Minor Changes
Security fix. Affects projects using
namedRegistrieson pnpm 11.1.0–11.19.x. It is semi-breaking for those projects — see "If you use named registries" below.The lockfile recorded no marker for which registry a package came from. Packages were keyed by
name@versionalone, and entry lookup went throughrefToRelative(ref, name), so a dependency you declared against one registry could be satisfied by an entry that was actually resolved from another. When two registries served the same name and version, both collapsed onto a singlepackages:entry and whichever resolved first decided the tarball every consumer got.That is a package-substitution risk: a package you expect from your private registry could be installed from a different registry that publishes the same name and version, and the lockfile recorded nothing that would let you tell.
Packages resolved from a named registry are now recorded under registry-qualified keys (
<name>@<registryName>:<version>, e.g.foo@work:1.0.0), so each registry gets its own entry and the lockfile pins which one a dependency came from.The lockfile format version is unchanged. Registry-qualified keys appear only for packages resolved from a named registry, so a project that does not use
namedRegistriessees no difference, and older pnpm versions keep reading the file.If you use named registries
Your next non-frozen install re-keys those entries, which shows up as a lockfile diff. Commit it — that diff is the fix being applied. Review it: an entry that moves to a registry you did not expect is worth investigating.
Everyone working on the project should be on this version or newer before you do. An older pnpm reads the re-keyed lockfile fine — frozen installs are unaffected — but it does not produce registry-qualified keys itself, so any install that updates the lockfile writes those entries back to the old shape, and the next install on a current pnpm re-qualifies them. The result is a lockfile that flips back and forth, and while it is in the old shape the project is exposed again. Because the lockfile format version is deliberately unchanged, pnpm cannot detect this and warn you about it.
There is no setting to keep the old behavior: the old shape is the vulnerability.
Tarball URLs that follow the standard registry layout are no longer written to the lockfile for named-registry packages; they are recomputed from the
namedRegistriessetting on demand.To use named registries, map your aliases in
pnpm-workspace.yaml:New built-in
npmjs:aliasnpmjs:now resolves tohttps://registry.npmjs.org/with no configuration, alongside the existinggh:alias for GitHub Packages. It pins a dependency to the public registry even whenregistrypoints elsewhere, such as an internal proxy:{ "dependencies": { "left-pad": "npmjs:^1.3.0" } }npm:cannot do this — it is the alias protocol (npm:<name>@<range>) and resolves through whateverregistrypoints at.If you mirror or proxy npmjs, point the alias at your mirror:
Built-in registry URLs are also the prefixes a lockfile's recorded tarball URL is matched against when pnpm verifies a package. Without the override, an entry whose tarball URL is on
registry.npmjs.orgis verified against the public registry rather than your mirror. This only affects lockfiles that record such URLs — a canonical URL for your configured registry is omitted from the lockfile and unaffected — and only when a tarball-URL,minimumReleaseAge, ortrustPolicycheck runs. Overriding the alias is the same escape hatch GHES users already have forgh.Every alias the lockfile references must stay in
namedRegistries: reading an entry whose alias is gone fails withERR_PNPM_MISSING_NAMED_REGISTRYrather than silently falling back to the default registry, since that would fetch a different package. Renaming an alias re-resolves the packages that used it.Named registry aliases that shadow a reserved dependency specifier prefix (
file,link,workspace,runtime,npm,jsr, ...) are now rejected withERR_PNPM_RESERVED_NAMED_REGISTRY_NAMEinstead of being silently shadowed by the corresponding resolver.pnpm licensesandpnpm sbomnow keep the two artifacts apart as well: license records carry the registry alias, and SBOM components carry the purlrepository_urlqualifier.Patch Changes
An empty
http-proxy,https-proxy,proxy, orno-proxyvalue — from the.npmrc,pnpm-workspace.yaml, the CLI, or theHTTP_PROXY/HTTPS_PROXY/PROXY/NO_PROXYenvironment variables — no longer fails the install withERR_PNPM_INVALID_PROXY. Empty settings read as unset, so a shell exportingHTTP_PROXY=disables the proxy, and an emptyproxy=in the.npmrcno longer suppressesHTTPS_PROXY#13533.proxy=falsein the.npmrcorproxy: falseinpnpm-workspace.yamlnow turns proxying off instead of being read as a proxy host namedfalse.falseandnullonhttps-proxy/http-proxy/no-proxyread as unset, and on the command line they are ordinary host names, since a flag carries its value verbatim.The env lockfile no longer pins
@pnpm/exealongsidepnpmwhen the wanted pnpm version is 12 or newer. From v12 the unscopedpnpmpackage is itself the native executable, so@pnpm/exeis not published for it and resolving it would fail. The engine identity check now verifies the native binary through whichever package ships it.lexCompareandnerfDartare now published as@pnpm/text.ordinal-comparatorand@pnpm/config.registry-auth-key. Use these instead of@pnpm/util.lex-comparatorand@pnpm/config.nerf-dart.Fixed the order in which pnpm matches a lockfile's recorded tarball URL against known registry URLs. Two registry URLs of equal length were previously ordered arbitrarily, so which one a tarball URL matched could differ between runs.
Dependency resolution is faster: package metadata is now filtered once per packument instead of once per dependency edge when
minimumReleaseAgeis active, and parsed semver versions and ranges are reused instead of re-parsed on every comparison.Security:
pnpm rebuildnow refuses a lockfile whosepackageskey carries a path traversal in the package name (e.g.../../../escaped@1.0.0), instead of running that package's lifecycle scripts and linking its bins in a directory outside the virtual store. Such a name is rejected withERR_PNPM_INVALID_DEPENDENCY_NAME.Platinum Sponsors
Gold Sponsors
This PR was generated by Mend Renovate. View the repository job log.