Skip to content

chore(deps): lock file maintenance npm packages#694

Merged
renovate[bot] merged 3 commits intomainfrom
renovate/npm-packages
Sep 15, 2025
Merged

chore(deps): lock file maintenance npm packages#694
renovate[bot] merged 3 commits intomainfrom
renovate/npm-packages

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented Sep 14, 2025

This PR contains the following updates:

Package Type Update Change Age Adoption Passing Confidence
lockFileMaintenance All locks refreshed
@napi-rs/cli devDependencies minor 3.1.5 -> 3.2.0 age adoption passing confidence
@napi-rs/wasm-runtime (source) devDependencies patch 1.0.3 -> 1.0.5 age adoption passing confidence
@types/node (source) devDependencies minor 24.3.1 -> 24.4.0 age adoption passing confidence
pnpm (source) packageManager minor 10.15.1 -> 10.16.1 age adoption passing confidence

🔧 This Pull Request updates lock files to use the latest dependency versions.


Release Notes

napi-rs/napi-rs (@​napi-rs/cli)

v3.2.0

Compare Source

What's Changed

New Contributors

Full Changelog: https://github.com/napi-rs/napi-rs/compare/napi-v3.3.0...@​napi-rs/[email protected]

napi-rs/napi-rs (@​napi-rs/wasm-runtime)

v1.0.5

Compare Source

v1.0.4

Compare Source

pnpm/pnpm (pnpm)

v10.16.1

Compare Source

Patch Changes
  • The full metadata cache should be stored not at the same location as the abbreviated metadata. This fixes a bug where pnpm was loading the abbreviated metadata from cache and couldn't find the "time" field as a result #​9963.
  • Forcibly disable ANSI color codes when generating patch diff #​9914.

v10.16.0

Compare Source

Minor Changes
  • There have been several incidents recently where popular packages were successfully attacked. To reduce the risk of installing a compromised version, we are introducing a new setting that delays the installation of newly released dependencies. In most cases, such attacks are discovered quickly and the malicious versions are removed from the registry within an hour.

    The new setting is called minimumReleaseAge. It specifies the number of minutes that must pass after a version is published before pnpm will install it. For example, setting minimumReleaseAge: 1440 ensures that only packages released at least one day ago can be installed.

    If you set minimumReleaseAge but need to disable this restriction for certain dependencies, you can list them under the minimumReleaseAgeExclude setting. For instance, with the following configuration pnpm will always install the latest version of webpack, regardless of its release time:

    minimumReleaseAgeExclude:
      - webpack

    Related issue: #​9921.

  • Added support for finders #​9946.

    In the past, pnpm list and pnpm why could only search for dependencies by name (and optionally version). For example:

    pnpm why minimist
    

    prints the chain of dependencies to any installed instance of minimist:

    verdaccio 5.20.1
    ├─┬ handlebars 4.7.7
    │ └── minimist 1.2.8
    └─┬ mv 2.1.1
      └─┬ mkdirp 0.5.6
        └── minimist 1.2.8
    

    What if we want to search by other properties of a dependency, not just its name? For instance, find all packages that have react@17 in their peer dependencies?

    This is now possible with "finder functions". Finder functions can be declared in .pnpmfile.cjs and invoked with the --find-by=<function name> flag when running pnpm list or pnpm why.

    Let's say we want to find any dependencies that have React 17 in peer dependencies. We can add this finder to our .pnpmfile.cjs:

    module.exports = {
      finders: {
        react17: (ctx) => {
          return ctx.readManifest().peerDependencies?.react === "^17.0.0";
        },
      },
    };

    Now we can use this finder function by running:

    pnpm why --find-by=react17
    

    pnpm will find all dependencies that have this React in peer dependencies and print their exact locations in the dependency graph.

    @&#8203;apollo/client 4.0.4
    ├── @&#8203;graphql-typed-document-node/core 3.2.0
    └── graphql-tag 2.12.6
    

    It is also possible to print out some additional information in the output by returning a string from the finder. For example, with the following finder:

    module.exports = {
      finders: {
        react17: (ctx) => {
          const manifest = ctx.readManifest();
          if (manifest.peerDependencies?.react === "^17.0.0") {
            return `license: ${manifest.license}`;
          }
          return false;
        },
      },
    };

    Every matched package will also print out the license from its package.json:

    @&#8203;apollo/client 4.0.4
    ├── @&#8203;graphql-typed-document-node/core 3.2.0
    │   license: MIT
    └── graphql-tag 2.12.6
        license: MIT
    
Patch Changes
  • Fix deprecation warning printed when executing pnpm with Node.js 24 #​9529.
  • Throw an error if nodeVersion is not set to an exact semver version #​9934.
  • pnpm publish should be able to publish a .tar.gz file #​9927.
  • Canceling a running process with Ctrl-C should make pnpm run return a non-zero exit code #​9626.

Configuration

📅 Schedule: Branch creation - "before 9am on monday" in timezone Asia/Shanghai, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot enabled auto-merge (squash) September 14, 2025 17:02
@graphite-app
Copy link
Copy Markdown

graphite-app bot commented Sep 14, 2025

How to use the Graphite Merge Queue

Add the label merge to this PR to add it to the merge queue.

You must have a Graphite account in order to use the merge queue. Sign up using this link.

An organization admin has enabled the Graphite Merge Queue in this repository.

Please do not merge from GitHub as this will restart CI on PRs being processed by the merge queue.

@renovate
Copy link
Copy Markdown
Contributor Author

renovate bot commented Sep 14, 2025

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@renovate renovate bot merged commit 49cc7d0 into main Sep 15, 2025
11 checks passed
@renovate renovate bot deleted the renovate/npm-packages branch September 15, 2025 10:43
shulaoda pushed a commit to shulaoda/oxc-resolver that referenced this pull request Mar 28, 2026
## 🤖 New release

* `oxc_resolver`: 8.0.0 -> 9.0.0 (⚠ API breaking changes)
* `oxc_napi_resolver`: 8.0.0

### ⚠ `oxc_resolver` breaking changes

```text
--- failure constructible_struct_adds_field: externally-constructible struct adds field ---

Description:
A pub struct constructible with a struct literal has a new pub field. Existing struct literals must be updated to include the new field.
        ref: https://doc.rust-lang.org/reference/expressions/struct-expr.html
       impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.40.0/src/lints/constructible_struct_adds_field.ron

Failed in:
  field ResolveOptions.modules in /tmp/.tmpTBvVad/oxc-resolver/src/options.rs:114

--- failure trait_method_added: pub trait method added ---

Description:
A non-sealed public trait added a new method without a default implementation, which breaks downstream implementations of the trait
        ref: https://doc.rust-lang.org/cargo/reference/semver.html#trait-new-item-no-default
       impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.40.0/src/lints/trait_method_added.ron

Failed in:
  trait method oxc_resolver::CachedPath::module_directory in file /tmp/.tmpTBvVad/oxc-resolver/src/cache.rs:69
  trait method oxc_resolver::CachedPath::cached_node_modules in file /tmp/.tmpTBvVad/oxc-resolver/src/cache.rs:76
```

<details><summary><i><b>Changelog</b></i></summary><p>

## `oxc_resolver`

<blockquote>

##
[9.0.0](oxc-project/oxc-resolver@oxc_resolver-v8.0.0...oxc_resolver-v9.0.0)
- 2025-05-09

### <!-- 1 -->Bug Fixes

- hash import does not need to load from node_modules
([oxc-project#501](oxc-project#501))

### <!-- 7 -->Chore

- add `--tsconfig` to example
([oxc-project#505](oxc-project#505))
- publish `oxc_napi_resolver`
([oxc-project#496](oxc-project#496))
</blockquote>

## `oxc_napi_resolver`

<blockquote>

##
[8.0.0](https://github.com/oxc-project/oxc-resolver/releases/tag/oxc_napi_resolver-v8.0.0)
- 2025-05-09

### <!-- 0 -->Features

- *(napi)* add mimalloc
([oxc-project#423](oxc-project#423))
- [**breaking**] Rust Edition 2024
([oxc-project#402](oxc-project#402))
- expose `package_json_path`
([oxc-project#376](oxc-project#376))
- *(napi)* expose module type info in ResolveResult
([oxc-project#223](oxc-project#223))
- *(napi)* add tracing via `OXC_LOG:DEBUG`
([oxc-project#202](oxc-project#202))
- *(napi)* add async API
([oxc-project#191](oxc-project#191))
- add `imports_fields` option
([oxc-project#138](oxc-project#138))
- add more builder functions for options
([oxc-project#110](oxc-project#110))
- *(napi)* support wasi target
([oxc-project#31](oxc-project#31))
- add file_dependencies and missing_dependencies API
([oxc-project#50](oxc-project#50))
- *(napi)* expose cloneWithOptions and clearCache methods
([oxc-project#40](oxc-project#40))
- *(napi)* update the doc and type for tsconfig references
([oxc-project#24](oxc-project#24))
- *(napi)* add options
([oxc-project#19](oxc-project#19))
- *(resolver)* add tracing-subscriber feature
([oxc-project#904](oxc-project#904))
- *(resolver)* tsconfig project references
([oxc-project#862](oxc-project#862))
- *(resolver)* add thiserror
([oxc-project#847](oxc-project#847))
- *(resolver)* implement nested alias field
([oxc-project#795](oxc-project#795))
- *(resolver)* implement tsconfig-paths
([oxc-project#750](oxc-project#750))
- *(resolver)* implement configurable `exports_fields` option
([oxc-project#733](oxc-project#733))
- *(resolver)* implement `main_fields`
- *(resolver)* implement resolveToContext
([oxc-project#694](oxc-project#694))
- *(resolver)* implement restrictions (path only)
([oxc-project#693](oxc-project#693))
- *(resolver)* implement fully specified
([oxc-project#687](oxc-project#687))
- *(resolver)* imports field
([oxc-project#681](oxc-project#681))
- *(resolver)* finish most of exports field
([oxc-project#674](oxc-project#674))
- *(resolver)* port the rest of the exports field tests
([oxc-project#659](oxc-project#659))
- *(resolver)* implement symlinks
([oxc-project#582](oxc-project#582))
- *(resolver)* complete query and fragment parsing
([oxc-project#579](oxc-project#579))
- *(resolver)* add preferRelative and preferAbsolute
([oxc-project#577](oxc-project#577))
- *(resolver)* implement roots
([oxc-project#576](oxc-project#576))
- *(resolver)* implement fallback
([oxc-project#572](oxc-project#572))
- *(resolver)* implement enforceExtension
([oxc-project#566](oxc-project#566))
- *(resolver)* implement descriptionFiles option
([oxc-project#565](oxc-project#565))
- *(resolver)* implement the basics of path alias
([oxc-project#564](oxc-project#564))
- *(resolver)* accept different file system implementations
([oxc-project#562](oxc-project#562))
- *(resolver)* implement browser field
([oxc-project#561](oxc-project#561))
- *(resolver)* implement scoped packages
([oxc-project#558](oxc-project#558))
- *(resolver)* port incorrect description file test
([oxc-project#557](oxc-project#557))
- *(resolver)* implement extension_alias
([oxc-project#556](oxc-project#556))
- *(resolver)* port resolve tests
([oxc-project#555](oxc-project#555))
- *(resolver)* resolve extensions
([oxc-project#549](oxc-project#549))
- *(resolver)* add resolver test fixtures
([oxc-project#542](oxc-project#542))

### <!-- 1 -->Bug Fixes

- hash import does not need to load from node_modules
([oxc-project#501](oxc-project#501))
- *(napi)* `new ResolverFactory()` options should be optional
([oxc-project#256](oxc-project#256))
- *(napi)* update buggy NAPI-RS versions
([oxc-project#225](oxc-project#225))
- canonicalize is not supported on wasi target
([oxc-project#124](oxc-project#124))
- resolve "browser" field when "exports" is present
([oxc-project#59](oxc-project#59))

### <!-- 4 -->Refactor

- [**breaking**] remove `description_files` option
([oxc-project#488](oxc-project#488))
- [**breaking**] remove `modules` options
([oxc-project#484](oxc-project#484))
- vitest ([oxc-project#380](oxc-project#380))
- apply latest `cargo +nightly fmt`
([oxc-project#281](oxc-project#281))
- selectively parse package_json fields instead of parsing everything
([oxc-project#103](oxc-project#103))
- *(resolver)* clean up some code and tests
- *(resolver)* change internal funcs to non-pub by moving to unit tests
([oxc-project#682](oxc-project#682))

### <!-- 7 -->Chore

- publish `oxc_napi_resolver`
([oxc-project#496](oxc-project#496))
- *(napi)* make mimalloc optional to build
([oxc-project#495](oxc-project#495))
- *(README)* add wasm usage example
- *(README)* crates.io badge use recent downloads
- *(napi)* auto download wasm binding on webcontainer
([oxc-project#471](oxc-project#471))
- use root package.json for napi build
([oxc-project#469](oxc-project#469))
- *(deps)* update github-actions
([oxc-project#444](oxc-project#444))
- *(deps)* lock file maintenance npm packages
([oxc-project#436](oxc-project#436))
- bump napi
([oxc-project#404](oxc-project#404))
- *(deps)* lock file maintenance npm packages
([oxc-project#391](oxc-project#391))
- *(deps)* lock file maintenance rust crates
([oxc-project#390](oxc-project#390))
- *(README)* clarify Rust and node.js usages
- add dprint
([oxc-project#326](oxc-project#326))
- *(deps)* update napi-rs to 3.0.0-alpha
- `cargo upgrade` && `pnpm upgrade`
- *(deps)* update napi-rs to 3.0.0-alpha
- update napi changes
- *(deps)* update rust crate napi-derive to 3.0.0-alpha
- *(deps)* update rust crate napi to 3.0.0-alpha
- *(deps)* update napi-rs to 2.16.8
- *(napi)* make napi binary smaller with minimal tracing features
([oxc-project#213](oxc-project#213))
- *(napi)* remove tokio
([oxc-project#212](oxc-project#212))
- document directory is an absolute path for `resolve(directory,
specifier)`
([oxc-project#206](oxc-project#206))
- re-enable the wasi build
([oxc-project#193](oxc-project#193))
- use pnpm workspace
([oxc-project#182](oxc-project#182))
- *(deps)* update rust crates
([oxc-project#176](oxc-project#176))
- *(napi)* update NAPI-RS cli version and binding template
([oxc-project#111](oxc-project#111))
- update project github url
- *(deps)* update pnpm to v8.14.1
([oxc-project#52](oxc-project#52))
- *(deps)* update pnpm to v8.14.0
([oxc-project#48](oxc-project#48))
- *(deps)* update pnpm to v8.13.1
([oxc-project#42](oxc-project#42))
- remove FIXME comments
- *(napi)* align `*Fields` user options with enhanced-resolve
([oxc-project#35](oxc-project#35))
- *(deps)* update pnpm to v8.12.1
([oxc-project#21](oxc-project#21))
- add some doc for napi TsconfigOptions
([oxc-project#20](oxc-project#20))
- *(deps)* update pnpm to v8.12.0
([oxc-project#18](oxc-project#18))
- *(README)* adding debugging command from Rspack
- *(deps)* update pnpm to v8.11.0
([oxc-project#9](oxc-project#9))
- *(resolver)* remove tracing_subscriber
([#1362](https://github.com/oxc-project/oxc-resolver/pull/1362))
- *(resolver)* improve documentation
([oxc-project#591](oxc-project#591))

### <!-- 8 -->CI

- check for napi .d.index changes
([oxc-project#491](oxc-project#491))
- *(release-napi)* support `riscv64gc-unknown-linux-gnu` and
`s390x-unknown-linux-gnu`
([oxc-project#451](oxc-project#451))
</blockquote>


</p></details>

---
This PR was generated with
[release-plz](https://github.com/release-plz/release-plz/).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant