Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 27, 2025

Bumps pnpm from 8.9.2 to 10.5.2.

Release notes

Sourced from pnpm's releases.

pnpm 10.5.2

Patch Changes

  • The pnpm config set command should change the global .npmrc file by default. This was a regression introduced by #9151 and shipped in pnpm v10.5.0.

Platinum Sponsors

Gold Sponsors

... (truncated)

Changelog

Sourced from pnpm's changelog.

10.5.2

Patch Changes

  • The pnpm config set command should change the global .npmrc file by default. This was a regression introduced by #9151 and shipped in pnpm v10.5.0.

10.5.1

Patch Changes

  • Throw an error message if a pnpm-workspaces.yaml or pnpm-workspaces.yml file is found instead of a pnpm-workspace.yaml #9170.
  • Fix the update of pnpm-workspace.yaml by the pnpm approve-builds command #9168.
  • Normalize generated link paths in package.json #9163
  • Specifying overrides in pnpm-workspace.yaml should work.
  • pnpm dlx should ignore settings from the package.json file in the current working directory #9178.

10.5.0

Minor Changes

  • Allow to set the "pnpm" settings from package.json via the pnpm-workspace.yaml file #9121.

  • Added support for automatically syncing files of injected workspace packages after pnpm run #9081. Use the sync-injected-deps-after-scripts setting to specify which scripts build the workspace package. This tells pnpm when syncing is needed. The setting should be defined in a .npmrc file at the root of the workspace. Example:

    sync-injected-deps-after-scripts[]=compile
  • The packages field in pnpm-workspace.yaml became optional.

Patch Changes

  • pnpm link with no parameters should work as if --global is specified #9151.
  • Allow scope registry CLI option without --config. prefix such as --@scope:registry=https://scope.example.com/npm #9089.
  • pnpm link <path> should calculate relative path from the root of the workspace directory #9132.
  • Fix a bug causing catalog snapshots to be removed from the pnpm-lock.yaml file when using --fix-lockfile and --filter. #8639
  • Fix a bug causing catalog protocol dependencies to not re-resolve on a filtered install #8638.

10.4.1

Patch Changes

  • Throws an error when the value provided by the --allow-build option overlaps with the pnpm.ignoredBuildDependencies list #9105.
  • Print pnpm's version after the execution time at the end of the console output.
  • Print warning about ignored builds of dependencies on repeat install #9106.
  • Setting init-package-manager should work.

10.4.0

Minor Changes

... (truncated)

Commits
  • fcb01a1 chore(release): 10.5.2
  • c334834 fix: config set should be global by default (#9185)
  • 70d565c chore(release): 10.5.1
  • 0e9fff7 chore(release): 10.5.0
  • b352d2a fix: pnpm link: imply global mode when no arguments are specified (#9151)
  • e32b1a2 feat: update injected packages after run (#9100)
  • 8fcc221 feat: reading settings from pnpm-workspace.yaml (#9121)
  • ee72c62 chore(release): 10.4.1
  • 546ab37 fix: --allow-build=\<pkg> overlaps with ignoredBuiltDependencies (#9105)
  • 0205498 fix: print warning about ignored builds on repeat install (#9116)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [pnpm](https://github.com/pnpm/pnpm/tree/HEAD/pnpm) from 8.9.2 to 10.5.2.
- [Release notes](https://github.com/pnpm/pnpm/releases)
- [Changelog](https://github.com/pnpm/pnpm/blob/main/pnpm/CHANGELOG.md)
- [Commits](https://github.com/pnpm/pnpm/commits/v10.5.2/pnpm)

---
updated-dependencies:
- dependency-name: pnpm
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Feb 27, 2025
@vercel
Copy link

vercel bot commented Feb 27, 2025

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
devs-in-tech ✅ Ready (Inspect) Visit Preview 💬 Add feedback Feb 27, 2025 8:31pm

@netlify
Copy link

netlify bot commented Feb 27, 2025

Deploy Preview for devsintech failed.

Name Link
🔨 Latest commit 5badc06
🔍 Latest deploy log https://app.netlify.com/sites/devsintech/deploys/67c0cb65ceef60000829fda0

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Mar 6, 2025

Superseded by #783.

@dependabot dependabot bot closed this Mar 6, 2025
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/pnpm-10.5.2 branch March 6, 2025 20:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant