Commit 60a2c71
authored
chore(deps): update pnpm to v11.19.0 (#41)
> ℹ️ **Note**
>
> This PR body was truncated due to platform limits.
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Adoption](https://docs.renovatebot.com/merge-confidence/) |
[Passing](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|---|---|
| [pnpm](https://pnpm.io)
([source](https://redirect.github.com/pnpm/pnpm/tree/HEAD/pnpm11/pnpm))
| [`11.10.0` →
`11.19.0`](https://renovatebot.com/diffs/npm/pnpm/11.10.0/11.19.0) |

|

|

|

|
---
### Release Notes
<details>
<summary>pnpm/pnpm (pnpm)</summary>
###
[`v11.19.0`](https://redirect.github.com/pnpm/pnpm/releases/tag/v11.19.0):
pnpm 11.19
[Compare
Source](https://redirect.github.com/pnpm/pnpm/compare/v11.18.0...v11.19.0)
#### Minor Changes
- `pnpm login` no longer requires an interactive terminal when the
registry supports web-based login: without a TTY it prints the
authentication URL (skipping the QR code and the "Press ENTER to open
the URL in your browser" prompt) and polls the registry until the
browser approval completes. Only the classic username/password login
still fails with `ERR_PNPM_LOGIN_NON_INTERACTIVE` in a non-interactive
terminal.
- The `save-prefix` setting now accepts `=`: newly added dependencies
are saved with an explicit `=` operator (`=1.2.3`) instead of the
setting being silently treated as the default `^`.
#### Patch Changes
- `allowBuilds` entries can now approve git-hosted packages that pnpm
downloads as a tarball, such as `github:` dependencies (which are
fetched from `codeload.github.com` rather than cloned), by their
repository URL without the resolved commit hash. This matches the
hashless `git+` matching already supported for cloned git dependencies.
For example:
```yaml
allowBuilds:
"foo@git+https://github.com/org/foo.git": true
```
This approves the package whether pnpm clones it or downloads a tarball,
so the entry no longer has to be updated every time the pinned commit
changes. GitLab and Bitbucket tarball downloads are matched the same
way. Approving or denying a specific resolved commit by its full tarball
dep path continues to work.
- `pnpm outdated --include-github-actions` no longer blocks on an
interactive git credential prompt when a workflow uses a private action
repo.
- Prevented `minimumReleaseAge` from replacing `latest` with a
SemVer-greater version than the registry tag target
[#​13034](https://redirect.github.com/pnpm/pnpm/issues/13034).
- Fixed empty `bundledDependencies` and `bundleDependencies` arrays
causing nondeterministic lockfile changes. See
[#​13123](https://redirect.github.com/pnpm/pnpm/issues/13123).
- The install summary no longer prints `(X is available)` when the
registry's `dist-tags.latest` is still held back by the active
`minimumReleaseAge` policy. The hint only ever names the actual latest
tag, so an immature latest suppresses the hint instead of advertising
the version pnpm just refused to install
[#​11698](https://redirect.github.com/pnpm/pnpm/issues/11698).
- `pnpm update` keeps the explicit `=` operator of an exact version pin:
a dependency saved as `=3.5.1` now updates to `=3.5.2` instead of the
bare `3.5.2`. See
[#​13168](https://redirect.github.com/pnpm/pnpm/issues/13168).
- Preserve a workspace dependency's `link:` entry when a run does not
target it — e.g. `pnpm update <other-pkg>` (with or without
`--recursive`), or a plain install after a root/catalog dependency
change — with `injectWorkspacePackages`, instead of spuriously rewriting
it to a peer-suffixed `file:` protocol. See
[#​10433](https://redirect.github.com/pnpm/pnpm/issues/10433).
- Workspace dependencies declared with a relative path (e.g. `"foo":
"workspace:../foo"`) are no longer silently dropped from the workspace
projects graph, so `--filter` selection and the topological order of
recursive commands take them into account.
<!-- sponsors -->
#### Platinum Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/openai_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/openai_light.svg" />
<img src="https://pnpm.io/img/users/openai_dark.svg" width="160"
alt="OpenAI" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
#### Gold Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/sanity.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/sanity_light.svg" />
<img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity"
/>
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/discord.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/discord_light.svg" />
<img src="https://pnpm.io/img/users/discord.svg" width="220"
alt="Discord" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/serpapi_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/serpapi_light.svg" />
<img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160"
alt="SerpApi" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/coderabbit.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/coderabbit_light.svg" />
<img src="https://pnpm.io/img/users/coderabbit.svg" width="220"
alt="CodeRabbit" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/stackblitz.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/stackblitz_light.svg" />
<img src="https://pnpm.io/img/users/stackblitz.svg" width="190"
alt="Stackblitz" />
</picture>
</a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/workleap.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/workleap_light.svg" />
<img src="https://pnpm.io/img/users/workleap.svg" width="190"
alt="Workleap" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://nx.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/nx.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/nx_light.svg" />
<img src="https://pnpm.io/img/users/nx.svg" width="50" alt="Nx" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
<!-- sponsors end -->
###
[`v11.18.0`](https://redirect.github.com/pnpm/pnpm/releases/tag/v11.18.0):
pnpm 11.18
[Compare
Source](https://redirect.github.com/pnpm/pnpm/compare/v11.17.0...v11.18.0)
#### Minor Changes
- Fixed an installed optional dependency being left without one of its
own required dependencies. When a package reached through
`optionalDependencies` is installable on the current system but one of
its regular `dependencies` is not, a lockfile-based install skipped that
dependency and installed the parent anyway, so importing the parent
failed with `MODULE_NOT_FOUND`. The dependency is now installed, and an
install-check warning reports the incompatibility. A dependency is still
only skipped when every path to it is optional, or when the package that
pulls it in was itself skipped
[#​13286](https://redirect.github.com/pnpm/pnpm/issues/13286).
- `pnpm setup` now appends `PNPM_HOME` and the global bin directory to
the GitHub Actions environment files (`GITHUB_ENV` and `GITHUB_PATH`),
so later steps in the same job can run `pnpm add --global` and other
global commands
[#​9191](https://redirect.github.com/pnpm/pnpm/issues/9191).
- Added support for `publishConfig.name`, which publishes a package
under a different name than the one its manifest carries in the
workspace. It is for a project whose published name is already taken by
a sibling project, which otherwise has to be renamed by a build step
just before publishing. Only the published artifact is renamed —
dependents, `pnpm-lock.yaml`, and release tooling keep addressing the
project by its manifest name — and the new name reaches the packed
manifest, the tarball filename, and everything that addresses the
package at the registry: the already-published check of `pnpm publish
-r`, its registry selection, and the release-planning probes of `pnpm
change status` and `pnpm version -r`
[#​13345](https://redirect.github.com/pnpm/pnpm/issues/13345).
- `pnpm self-update` no longer takes any instruction from the project it
is run in:
- pnpm is fetched through the same trusted registry and auth
configuration used when switching pnpm versions, so a project `.npmrc`
or `pnpm-workspace.yaml` can no longer redirect the download or attach
credentials to it, and the project's default `.pnpmfile.(c|m)js` is no
longer loaded. Pnpmfiles from trusted sources (the `pnpmfile` setting,
the global pnpmfile, config dependencies) still apply.
- The `minimumReleaseAge` settings in `pnpm-workspace.yaml` no longer
affect `self-update`. They still govern the project's own dependencies;
for `self-update` the cooldown now comes from the built-in default, your
global config, a `PNPM_CONFIG_*` environment variable, or a command-line
flag. This fixes `self-update` failing inside a workspace that raises
the cutoff while succeeding everywhere else, and stops a repository from
either waiving the cooldown or keeping you on an outdated pnpm by
raising it.
- The same applies to the `trustPolicy` settings and to `ci`: a project
can no longer weaken the trust check that guards the pnpm download, nor
re-enable the confirmation prompt that a CI run suppresses.
When `self-update` refuses a version that is younger than the cutoff, an
interactive run now offers to update anyway; non-interactive runs still
fail. CI never prompts, even on a runner that attaches a TTY.
#### Patch Changes
- Fixed `pnpm licenses list` to report every version when the same
package is installed under multiple aliases
[pnpm/pnpm#13438](https://redirect.github.com/pnpm/pnpm/issues/13438).
- Sort `pnpm dedupe --check` snapshot changes for stable output across
pnpm implementations.
- Strip Unicode formatting characters from registry- and
manifest-derived terminal output.
- Speed up installs after compatible catalog or direct dependency range
changes by retaining the locked version without resolving the dependency
graph again.
- Speed up installs after safe override changes by reusing unambiguous
compatible dependency resolutions, pruning obsolete dependencies,
applying independent replacements and removals together, and handling
parent-scoped `"-"` overrides without full lockfile resolution.
- Installing a local `file:` directory dependency with the global
virtual store enabled no longer fails with `TypeError: Cannot read
properties of undefined (reading 'split')`
[#​13335](https://redirect.github.com/pnpm/pnpm/issues/13335).
Local directory dependencies — `file:` directories and injected
workspace packages — now get a global-virtual-store slot of their own
per project. They used to share one slot across every project that
depended on a directory of the same name, so a project could end up
linked to another project's copy of the dependency.
- The `Workspace` column of `pnpm update --interactive` now falls back
to the project's path when its `name` is only whitespace, as it already
did for a missing or empty one — all three render an equally blank label
otherwise.
- Checking GitHub Actions dependencies for updates is now opt-in for
every command. Neither `pnpm outdated` nor `pnpm update` reads the
workflow files unless `--include-github-actions` is passed or
`update.githubActions` is set to `true` in `pnpm-workspace.yaml`.
Reading them runs `git ls-remote` against every referenced repository,
which fails in environments where GitHub is not reachable the way pnpm
assumes (a GitHub Enterprise Server, a custom certificate authority, or
an offline network)
[#​13254](https://redirect.github.com/pnpm/pnpm/issues/13254).
`pnpm outdated` accepts the `--include-github-actions` option too.
- `pnpm update --interactive` now measures its table in terminal columns
rather than in characters. A package name, workspace name, or version
containing wide characters (CJK, most emoji) no longer knocks its row's
columns out of line with the rest of the group, and a wide character in
a version no longer aborts the command with `Subject parameter value
width cannot be greater than the container width`
[#​13357](https://redirect.github.com/pnpm/pnpm/issues/13357).
- The `Workspace` column of `pnpm update --interactive` is more
informative in two cases. A dependency outdated at the same version in
several workspace projects is offered as one choice, since selecting it
updates every project — that choice now names all of them instead of
only the first. And a workspace project without a `name` is now labelled
with its path rather than left blank, so several unnamed projects can be
told apart.
- An auto-installed *optional* peer is no longer hoisted at a version
the workspace root's own dependency on that package excludes.
`resolvePeersFromWorkspaceRoot` already made the workspace root's
specifier decide which version a missing *required* peer is installed
at; the optional-peer picker ignored it and always took the highest
version present anywhere in the graph. In a workspace whose root pins
`postcss: 8.5.10`, an importer that depends on `webpack` and declares no
`postcss` of its own got `postcss@8.5.22` hoisted for
`terser-webpack-plugin`'s optional `postcss` peer, leaving two
`postcss@8.5.x` instances in the graph
[#​13320](https://redirect.github.com/pnpm/pnpm/issues/13320).
- `overrides` now also govern peers that pnpm auto-installs. Previously
an override only rewrote dependencies declared in a manifest, so a peer
nobody declares — installed because `autoInstallPeers` is on — resolved
against its declared peer range and could bring in a second copy of the
very package the override pinned. For example, with `overrides: { react:
npm:react@19.2.0 }` and a lone `lucide-react` dependency, pnpm installed
`react@18.3.1`; it now installs the pinned `react@19.2.0`
[#​13320](https://redirect.github.com/pnpm/pnpm/issues/13320).
- Under `resolvePeersFromWorkspaceRoot`, a workspace root dependency
declared with `link:` or `file:` (or the path form of `workspace:`, such
as `workspace:../pkg`) now satisfies another project's missing peer
dependency at the linked package's own version, instead of being hoisted
as a path. Those specifiers are relative to the project that declares
them, so the same specifier reached a different directory — or none —
from the project the peer was hoisted into, leaving a broken link. The
root now has the same authority over the peer as it has when it declares
the package with a version range
[#​13373](https://redirect.github.com/pnpm/pnpm/issues/13373).
- Installs through a pnpr server now apply the project's whole
verification policy. `minimumReleaseAgeExclude`,
`minimumReleaseAgeIgnoreMissingTime`, `trustPolicy`,
`trustPolicyExclude`, `trustPolicyIgnoreAfter`, and `trustLockfile` were
ignored, so excluded packages were still held back and a lockfile
containing them could be rejected.
`trustPolicy: no-downgrade` no longer fails with
`TRUST_POLICY_INCOMPATIBLE_WITH_PNPR` when a pnpr server is configured.
`--frozen-lockfile` and `--no-prefer-frozen-lockfile` are now honored on
the pnpr path, instead of resolving and rewriting the lockfile anyway.
Since `frozenLockfile` defaults to `true` on CI, a CI install through a
pnpr server now fails on an out-of-date lockfile rather than updating
it.
- Workspace installs through a pnpr server no longer crash with `Cannot
read properties of undefined (reading 'filter')` after linking, when
`minimumReleaseAge` is active
[#​13275](https://redirect.github.com/pnpm/pnpm/issues/13275).
- Fixed `pnpm dedupe` updating valid catalog resolutions when another
matching version exists in the lockfile.
- `pnpm -r run "/pattern/" --no-bail` no longer exits zero when one of a
project's matched scripts fails and a later one passes. The run summary
carries a single status per project, and the passing script overwrote
the recorded failure.
- Restored the store block a first install prints, naming how packages
were materialized and where the stores live
[#​13315](https://redirect.github.com/pnpm/pnpm/issues/13315):
```text
Packages are hard linked from the content-addressable store to the
virtual store.
Content-addressable store is at: ~/.local/share/pnpm/store/v11
Virtual store is at: node_modules/.pnpm
```
- The root project's `pnpm:devPreinstall` script now runs before
resolution and linking, as it does in pnpm 11. It is skipped under
`--ignore-scripts`, `--lockfile-only` and `--dry-run`, by `pnpm fetch`
and `pnpm rebuild`, and by a repeat install that is already up to date.
Workspaces that use the hook to prepare state the install depends on —
such as [next.js](https://redirect.github.com/vercel/next.js), which
generates a placeholder `next` bin with it — were left with dependents
linked against files that were never created
[#​13313](https://redirect.github.com/pnpm/pnpm/issues/13313).
- Prevented `pnpm dedupe --check` from removing an incompatible
`node_modules` directory.
- `pnpm update --workspace` no longer links dependencies the user never
named:
- Running it with `updateConfig.ignoreDependencies` configured no longer
fails with `ERR_PNPM_WORKSPACE_PACKAGE_NOT_FOUND` for a dependency that
is only published to the registry. Such dependencies keep their
specifiers, as they already did when no dependencies were ignored.
- Passing package selectors that match no direct dependency no longer
falls back to linking every workspace dependency.
<!-- sponsors -->
#### Platinum Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/openai_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/openai_light.svg" />
<img src="https://pnpm.io/img/users/openai_dark.svg" width="160"
alt="OpenAI" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
#### Gold Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/sanity.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/sanity_light.svg" />
<img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity"
/>
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/discord.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/discord_light.svg" />
<img src="https://pnpm.io/img/users/discord.svg" width="220"
alt="Discord" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/serpapi_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/serpapi_light.svg" />
<img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160"
alt="SerpApi" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/coderabbit.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/coderabbit_light.svg" />
<img src="https://pnpm.io/img/users/coderabbit.svg" width="220"
alt="CodeRabbit" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/stackblitz.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/stackblitz_light.svg" />
<img src="https://pnpm.io/img/users/stackblitz.svg" width="190"
alt="Stackblitz" />
</picture>
</a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/workleap.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/workleap_light.svg" />
<img src="https://pnpm.io/img/users/workleap.svg" width="190"
alt="Workleap" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://nx.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/nx.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/nx_light.svg" />
<img src="https://pnpm.io/img/users/nx.svg" width="50" alt="Nx" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
<!-- sponsors end -->
###
[`v11.17.0`](https://redirect.github.com/pnpm/pnpm/releases/tag/v11.17.0):
pnpm 11.17
[Compare
Source](https://redirect.github.com/pnpm/pnpm/compare/v11.16.0...v11.17.0)
##### Minor Changes
- Added a new setting, `update.githubActionsServer`, for specifying the
base URL of the GitHub server that hosts the repositories of the GitHub
Actions referenced by the workflow files (for example, a GitHub
Enterprise Server). When the setting is not defined, the URL is read
from the `GITHUB_SERVER_URL` environment variable, falling back to
`https://github.com`. The URL must use the `https://` or `http://`
protocol
[#​13220](https://redirect.github.com/pnpm/pnpm/issues/13220).
`pnpm outdated` and `pnpm update` no longer fail when the refs of a
GitHub Action's repository cannot be read (for example, when the
action's repository is private or hosted on a different GitHub server).
Such actions are now skipped with a warning.
Setting `update.githubActions` to `false` now makes `pnpm outdated` and
the interactive `pnpm update` skip GitHub Actions dependencies.
##### Patch Changes
- The token poll for web-based authentication no longer reads the body
of non-OK or still-pending (HTTP 202) responses, and caps the token
response body it does read at 64 KiB, so a malicious or compromised
registry cannot exhaust memory through the poll
[pnpm/pnpm#12721](https://redirect.github.com/pnpm/pnpm/issues/12721).
- Fixed `catalog:` references in dependencies and overrides failing to
resolve when installing through a pnpr server, which errored with "No
catalog entry '<name>' was found for catalog 'default'." even though the
catalog entry existed. Also fixed a crash on Windows when installing a
nested workspace member (e.g. `packages/foo`) through a pnpr server
[#​13232](https://redirect.github.com/pnpm/pnpm/issues/13232).
- Republished every package: the tarballs published by the v11.13.1
through v11.16.0 releases were missing most of their compiled files due
to a packing bug
[#​13164](https://redirect.github.com/pnpm/pnpm/issues/13164).
- Revert script ordering change for `pnpm run --sequential /regex/`
- Support the `from-git` argument in the `pnpm version` command.
- When the authentication URL cannot be rendered as a QR code (for
example when it exceeds the maximum QR data capacity), web-based login
now displays the URL alone with a warning instead of aborting
authentication
[pnpm/pnpm#12721](https://redirect.github.com/pnpm/pnpm/issues/12721).
<!-- sponsors -->
##### Platinum Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/openai_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/openai_light.svg" />
<img src="https://pnpm.io/img/users/openai_dark.svg" width="160"
alt="OpenAI" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
##### Gold Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/sanity.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/sanity_light.svg" />
<img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity"
/>
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/discord.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/discord_light.svg" />
<img src="https://pnpm.io/img/users/discord.svg" width="220"
alt="Discord" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/serpapi_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/serpapi_light.svg" />
<img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160"
alt="SerpApi" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/coderabbit.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/coderabbit_light.svg" />
<img src="https://pnpm.io/img/users/coderabbit.svg" width="220"
alt="CodeRabbit" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/stackblitz.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/stackblitz_light.svg" />
<img src="https://pnpm.io/img/users/stackblitz.svg" width="190"
alt="Stackblitz" />
</picture>
</a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/workleap.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/workleap_light.svg" />
<img src="https://pnpm.io/img/users/workleap.svg" width="190"
alt="Workleap" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://nx.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/nx.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/nx_light.svg" />
<img src="https://pnpm.io/img/users/nx.svg" width="50" alt="Nx" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
<!-- sponsors end -->
###
[`v11.16.0`](https://redirect.github.com/pnpm/pnpm/releases/tag/v11.16.0):
pnpm 11.16
[Compare
Source](https://redirect.github.com/pnpm/pnpm/compare/v11.15.1...v11.16.0)
#### Minor Changes
- The first release of a package now publishes the version written in
its manifest verbatim, instead of bumping off it. `pnpm version -r` and
`pnpm change status` check the registry for each release's current
version; when that version is not yet published, the package debuts at
it and its pending changesets apply only from the next release. A newly
added package seeded at `1100.0.0` with a `minor` changeset is therefore
published as `1100.0.0` rather than skipping straight to `1100.1.0`.
- Added a `--changeset` flag to `pnpm update`. Set `update.changeset` to
`true` in `pnpm-workspace.yaml` to enable this behavior by default, and
use `--no-changeset` to override the setting for one update. After the
update completes, pnpm writes a `.changeset/pnpm-update-<suffix>.md`
file declaring a patch bump for every workspace package whose
`dependencies` or `optionalDependencies` were changed by the update and
a major bump when `peerDependencies` changed, including packages that
consume an updated catalog entry via the `catalog:` protocol. Private
packages, packages without a name, and packages listed in the `ignore`
array of `.changeset/config.json` are skipped. If
`.changeset/config.json` does not exist, a warning is printed and no
changeset is generated.
- Added GitHub Actions dependencies to `pnpm outdated` and interactive
`pnpm update`. Non-interactive updates can include them with
`--include-github-actions` or by setting `update.githubActions` to
`true` in `pnpm-workspace.yaml`. Updated actions are pinned to exact
commit hashes with their release tags preserved in comments.
- Added `update` and `audit` settings sections to `pnpm-workspace.yaml`,
superseding the awkwardly named `updateConfig`, `auditConfig`, and
top-level `auditLevel` settings:
```yaml
update:
ignoreDeps: # was updateConfig.ignoreDependencies
- webpack
- "@babel/*"
audit:
level: high # was auditLevel
ignore: # was auditConfig.ignoreGhsas
- GHSA-xxxx-yyyy-zzzz
```
`update.ignoreDeps` lists dependency name patterns that `pnpm update`
and `pnpm outdated` should skip. `audit.level` and `audit.ignore` tune
`pnpm audit`.
The deprecated `updateConfig`, `auditConfig`, and `auditLevel` settings
keep working until the next major version. When both a new section value
and its deprecated counterpart are set, the new section takes precedence
and a warning is printed. Both the TypeScript CLI and the Rust config
surface (pacquet) recognize the new sections.
#### Patch Changes
- Fixed `pnpm add --save-exact`/`--save-prefix` and `pnpm update`
writing a package's version with the `peerDependencies` range's prefix
(e.g. `^19.2.7` instead of the requested `19.2.7`) whenever the same
package also appeared in `peerDependencies`. A real
`dependencies`/`devDependencies`/`optionalDependencies` entry now takes
precedence over a same-named `peerDependencies` entry when computing the
current specifiers
[#​13108](https://redirect.github.com/pnpm/pnpm/issues/13108).
<!-- sponsors -->
#### Platinum Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/openai_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/openai_light.svg" />
<img src="https://pnpm.io/img/users/openai_dark.svg" width="160"
alt="OpenAI" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
#### Gold Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/sanity.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/sanity_light.svg" />
<img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity"
/>
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/discord.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/discord_light.svg" />
<img src="https://pnpm.io/img/users/discord.svg" width="220"
alt="Discord" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/serpapi_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/serpapi_light.svg" />
<img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160"
alt="SerpApi" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/coderabbit.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/coderabbit_light.svg" />
<img src="https://pnpm.io/img/users/coderabbit.svg" width="220"
alt="CodeRabbit" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/stackblitz.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/stackblitz_light.svg" />
<img src="https://pnpm.io/img/users/stackblitz.svg" width="190"
alt="Stackblitz" />
</picture>
</a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/workleap.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/workleap_light.svg" />
<img src="https://pnpm.io/img/users/workleap.svg" width="190"
alt="Workleap" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://nx.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/nx.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/nx_light.svg" />
<img src="https://pnpm.io/img/users/nx.svg" width="50" alt="Nx" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
<!-- sponsors end -->
###
[`v11.15.1`](https://redirect.github.com/pnpm/pnpm/compare/v11.15.0...v11.15.1)
[Compare
Source](https://redirect.github.com/pnpm/pnpm/compare/v11.15.0...v11.15.1)
###
[`v11.15.0`](https://redirect.github.com/pnpm/pnpm/releases/tag/v11.15.0):
pnpm 11.15
[Compare
Source](https://redirect.github.com/pnpm/pnpm/compare/v11.14.0...v11.15.0)
##### Minor Changes
- Optional peer dependencies declared only via `peerDependenciesMeta`
(for example `debug`'s `supports-color` peer) are now resolved from a
satisfying version already present in the dependency graph, the same way
explicitly declared optional peer dependencies are. Previously such
peers were only resolved this way when the package's metadata was read
back from the lockfile, so an unrelated dependency change could rewrite
peer resolutions across the whole lockfile.
##### Patch Changes
- Updated `adm-zip` to prevent crafted ZIP archives from causing
excessive memory allocation.
- `pnpm version -r` no longer writes a versioning-ledger entry with no
consumed intents as a bare `intents:` key, which the next run failed to
read with `ERR_PNPM_INVALID_VERSIONING_LEDGER`. Empty intent lists are
now written as `intents: []`, and the ledger reader accepts the bare
form left by earlier releases.
- Fixed pnpr workspace resolution to preserve project names and versions
for `workspace:` dependencies.
<!-- sponsors -->
#### Platinum Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/openai_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/openai_light.svg" />
<img src="https://pnpm.io/img/users/openai_dark.svg" width="160"
alt="OpenAI" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
#### Gold Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/sanity.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/sanity_light.svg" />
<img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity"
/>
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/discord.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/discord_light.svg" />
<img src="https://pnpm.io/img/users/discord.svg" width="220"
alt="Discord" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/serpapi_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/serpapi_light.svg" />
<img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160"
alt="SerpApi" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/coderabbit.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/coderabbit_light.svg" />
<img src="https://pnpm.io/img/users/coderabbit.svg" width="220"
alt="CodeRabbit" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/stackblitz.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/stackblitz_light.svg" />
<img src="https://pnpm.io/img/users/stackblitz.svg" width="190"
alt="Stackblitz" />
</picture>
</a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/workleap.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/workleap_light.svg" />
<img src="https://pnpm.io/img/users/workleap.svg" width="190"
alt="Workleap" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://nx.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/nx.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/nx_light.svg" />
<img src="https://pnpm.io/img/users/nx.svg" width="50" alt="Nx" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
<!-- sponsors end -->
###
[`v11.14.0`](https://redirect.github.com/pnpm/pnpm/releases/tag/v11.14.0):
pnpm 11.14
[Compare
Source](https://redirect.github.com/pnpm/pnpm/compare/v11.13.1...v11.14.0)
#### Minor Changes
- `peerDependencies` now accept dependency specifiers that carry a
scheme — a named-registry spec (`<registry>:<version>`), an `npm:`
alias, or a `file:`/git/URL spec — instead of rejecting them with
`ERR_PNPM_INVALID_PEER_DEPENDENCY_SPECIFICATION`
[#​13095](https://redirect.github.com/pnpm/pnpm/issues/13095).
Such a peer is matched against the semver range carried by the specifier
(`work:5.x.x` is checked as `5.x.x`, `npm:bar@^5` as `^5`), or against
`*` when it carries no version, while the original specifier still
selects the package to auto-install. Bare `name@version` values, which
are almost always a mistake, are still rejected.
- Added `pnpm doctor`, which diagnoses the pnpm installation and the
environment it runs in: the versions and install method, whether the
global bin directory is on `PATH`, whether the store and cache are
writable, which link strategies (reflink, hardlink, symlink) the store's
filesystem supports, registry connectivity, and an offline `file:`
install that exercises the resolve/store/link path end to end. Each
check reports how to fix what it finds, and the command exits non-zero
when any check fails.
Use `--offline` to skip the checks that need network access, `--json`
for machine-readable output, and `--benchmark` to time the filesystem
and install checks.
- Added support for executing multiple scripts matching a RegExp passed
to `pnpm run` (e.g., `pnpm run "/^build:.*/"`), running matched scripts
in deterministic lexicographical order. Restored the `--sequential`
(`-s`) CLI option for `pnpm run`, which forces `workspaceConcurrency` to
1 so that matched scripts run sequentially one by one across and within
packages.
#### Patch Changes
- Fixed `pnpm install` failing with `ERR_PNPM_LOCKFILE_IS_SYMLINK` when
`pnpm-lock.yaml` is a symlink, as build sandboxes such as Bazel and Nix
stage it
[#​13073](https://redirect.github.com/pnpm/pnpm/issues/13073).
Reading a lockfile through a symlink is allowed again, and an install
that leaves the lockfile unchanged no longer rewrites it, so
`--frozen-lockfile` no longer needs to write at all. Writing a *changed*
lockfile through a symlink is still refused, as that would redirect the
write onto the symlink's target.
- Fixed frozen installs incorrectly treating equivalent Git dependency
specifiers as a stale lockfile. See
[#​13039](https://redirect.github.com/pnpm/pnpm/issues/13039).
- `pnpm owner ls` now reports authentication and authorization failures
(401/403) as dedicated errors that include the registry's response body,
matching `pnpm owner add`/`rm`, instead of a generic `Failed to fetch
owners` message.
- Recover from a metadata cache entry that disappears (concurrent cache
cleanup, antivirus) after the registry has already answered the
conditional request with `304 Not Modified`. The metadata is
re-requested once without cache validators instead of failing the
install with `ERR_PNPM_CACHE_MISSING_AFTER_304`.
- A project pinned to a broken pnpm release via `packageManager` or
`devEngines.packageManager` now reports which release is broken and what
to do about it, instead of failing inside the installer. `pnpm
self-update` already refused these releases; the version switch does
too.
- Prevent broken-lockfile errors from including snippets of the
lockfile's contents.
- `pnpm self-update` now checks that the version it installed can run
before making it the active pnpm. A release that installs but cannot
execute is discarded with an error instead of replacing a working
installation.
- Fixed an out-of-memory regression when workspace projects concurrently
resolve a package with large registry metadata
[pnpm/pnpm#13077](https://redirect.github.com/pnpm/pnpm/issues/13077).
- Fixed `pnpm update` rewriting exact version pins that use the `=`
operator (for example `=3.5.1`) to a caret range (`^3.5.1`). Exact pins
are now preserved and written back as the bare version. See
[#​12745](https://redirect.github.com/pnpm/pnpm/issues/12745).
<!-- sponsors -->
#### Platinum Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/openai_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/openai_light.svg" />
<img src="https://pnpm.io/img/users/openai_dark.svg" width="160"
alt="OpenAI" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
#### Gold Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/sanity.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/sanity_light.svg" />
<img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity"
/>
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/discord.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/discord_light.svg" />
<img src="https://pnpm.io/img/users/discord.svg" width="220"
alt="Discord" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/serpapi_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/serpapi_light.svg" />
<img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160"
alt="SerpApi" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/coderabbit.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/coderabbit_light.svg" />
<img src="https://pnpm.io/img/users/coderabbit.svg" width="220"
alt="CodeRabbit" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/stackblitz.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/stackblitz_light.svg" />
<img src="https://pnpm.io/img/users/stackblitz.svg" width="190"
alt="Stackblitz" />
</picture>
</a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/workleap.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/workleap_light.svg" />
<img src="https://pnpm.io/img/users/workleap.svg" width="190"
alt="Workleap" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href=
> ✂ **Note**
>
> PR body was truncated to here.
</details>
---
### Configuration
📅 **Schedule**: (in timezone Asia/Shanghai)
- Branch creation
- "before 10am on the first day of the month"
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/voidzero-dev/setup.viteplus.dev).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4xMi4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>1 parent d669ba0 commit 60a2c71
2 files changed
Lines changed: 3 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
| 15 | + | |
16 | 16 | | |
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments