Skip to content

fix(deps): update dependencies - #36

Open
tannevaled wants to merge 1 commit into
mainfrom
renovate/deps
Open

tannevaled wants to merge 1 commit into
mainfrom
renovate/deps

Conversation

@tannevaled

@tannevaled tannevaled commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@bufbuild/protobuf (source) 2.15.0 → 2.16.0 age confidence dependencies minor
@bufbuild/protoc-gen-es (source) 2.15.0 → 2.16.0 age confidence devDependencies minor
@types/node (source) 24.19.0 → 24.19.1 age confidence devDependencies patch
eslint (source) 10.11.0 → 10.12.0 age confidence devDependencies minor
github.com/gophercloud/gophercloud/v2 v2.14.0 → v2.15.0 age confidence require minor
github.com/gophercloud/utils/v2 42b9474 → b4759ea age confidence require digest
globals 17.12.0 → 17.13.0 age confidence devDependencies minor
go.opentelemetry.io/contrib/bridges/otelslog v0.20.1 → v0.21.0 age confidence require minor
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.71.0 → v0.72.0 age confidence require minor
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.71.0 → v0.72.0 age confidence require minor
go.opentelemetry.io/contrib/instrumentation/runtime v0.71.0 → v0.72.0 age confidence require minor
go.opentelemetry.io/otel v1.46.0 → v1.47.0 age confidence require minor
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.22.0 → v0.23.0 age confidence require minor
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.46.0 → v1.47.0 age confidence require minor
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.46.0 → v1.47.0 age confidence require minor
go.opentelemetry.io/otel/sdk v1.46.0 → v1.47.0 age confidence require minor
go.opentelemetry.io/otel/sdk/metric v1.46.0 → v1.47.0 age confidence require minor
golang.org/x/crypto v0.56.0 → v0.57.0 age confidence require minor
google.golang.org/grpc v1.83.2 → v1.84.0 age confidence require minor
gorm.io/driver/postgres v1.6.2 → v1.6.3 age confidence require patch
grafana/grafana 13.2.1 → 13.2.3 age confidence patch
grafana/loki 3.7.7 → 3.7.8 age confidence patch
grafana/tempo 3.0.3 → 3.1.0 age confidence minor
otel/opentelemetry-collector-contrib 0.160.0 → 0.162.0 age confidence minor
prom/alertmanager v0.34.0 → v0.34.1 age confidence patch
prom/prometheus v3.14.0 → v3.15.0 age confidence minor
svelte (source) 5.57.1 → 5.57.2 age confidence devDependencies patch
typescript-eslint (source) 8.70.1 → 8.71.1 age confidence devDependencies minor
vite (source) 8.3.1 → 8.3.3 age confidence devDependencies patch

Release Notes

bufbuild/protobuf-es (@​bufbuild/protobuf)

v2.16.0

Compare Source

What's Changed
New Contributors

Full Changelog: bufbuild/protobuf-es@v2.15.0...v2.16.0

eslint/eslint (eslint)

v10.12.0

Compare Source

Features

  • 4618052 feat: handle astral letters in new-cap (#​21357) (sary)
  • 4ec5168 feat: allow SourceCode#getText() to accept tokens and comments (#​21340) (electrohyun)

Bug Fixes

  • bc51eee fix: prefer-arrow-callback false positive in conditional test (#​21373) (Daniel Pinto)
  • bbff86c fix: skip lines with multiple comments in max-lines-per-function (#​21332) (xbinaryx)
  • efc4d6b fix: astral letters in consistent-return, no-eval, no-invalid-this (#​21360) (lumir)
  • 93de066 fix: prefer-exponentiation-operator autofix for async function base (#​21322) (Vladimir Babin)
  • 02e34ff fix: add missing space after else in curly autofix (#​21355) (Pixel)
  • b14b8bc fix: correct id-length message for long private names (#​21348) (Pixel)
  • 69aac01 fix: support TSFunctionType in getFunctionHeadLoc (#​21335) (xbinaryx)
  • 686630e fix: no-loss-of-precision false positive with 0.e5 (#​21337) (sethamus)

Documentation

  • 67eb586 docs: Update README (GitHub Actions Bot)
  • 5370d7e docs: clarify one-var separateRequires matches any require() call (#​21192) (sethamus)
  • 8816c1d docs: Update README (GitHub Actions Bot)
  • 3d2e7ce docs: fix typo in no-unused-expressions documentation (#​21346) (bytedoe)

Chores

  • 152067f chore: update ecosystem plugins (#​21362) (ESLint Bot)
  • b56d58e chore: update github/codeql-action action to v4.38.2 (#​21376) (renovate[bot])
  • bfaea12 perf: cache normalized config globals per languageOptions (#​21364) (James Ross)
  • 322209e ci: avoid Nx cache in ecosystem tests and disable failing test (#​21369) (Francesco Trotta)
  • d166567 chore: update dependency prettier to v3.9.9 (#​21371) (renovate[bot])
  • 29585ce chore: update dependency eslint-plugin-expect-type to ^0.7.0 (#​21359) (renovate[bot])
  • 39d79ba chore: update github/codeql-action action to v4.38.1 (#​21354) (renovate[bot])
  • 182a6e9 chore: update dependency prettier to v3.9.8 (#​21352) (renovate[bot])
  • f995127 chore: remove CLAUDE.md in favor of AGENTS.md (#​21339) (Jarren)
  • b95fb6c chore: update dependency prettier to v3.9.7 (#​21347) (renovate[bot])
  • 3782dd4 chore: update ecosystem plugins (#​21342) (ESLint Bot)
gophercloud/gophercloud (github.com/gophercloud/gophercloud/v2)

v2.15.0

Compare Source

What's Changed

Full Changelog: gophercloud/gophercloud@v2.14.0...v2.15.0

sindresorhus/globals (globals)

v17.13.0

Compare Source


open-telemetry/opentelemetry-go-contrib (go.opentelemetry.io/contrib/bridges/otelslog)

v0.21.0

0.21.0 - 2021-06-18
Fixed
  • Dockerfile based examples for otelgin and otelmacaron. (#​767)
Changed
  • Supported minimum version of Go bumped from 1.14 to 1.15. (#​787)
  • EKS Resource Detector now use the Kubernetes Go client to obtain the ConfigMap. (#​813)
Removed
  • Remove service name from otelmongodb configuration and span attributes. (#​763)
open-telemetry/opentelemetry-go (go.opentelemetry.io/otel)

v1.47.0: /v0.69.0/v0.23.0/v0.1.0

Compare Source

This release contains the first stable release of the OpenTelemetry Go Logs API and SDK.
Our project stability guarantees now apply to the following modules:

  • go.opentelemetry.io/otel/log
  • go.opentelemetry.io/otel/sdk/log

See our versioning policy for more information about these stability guarantees.

Added
  • Add String method for KeyValue type in go.opentelemetry.io/otel/attribute. (#​8205)
  • Add String method for Set type in go.opentelemetry.io/otel/attribute. (#​8347)
  • Add WithMaxExportBatchSize to go.opentelemetry.io/otel/sdk/metric to configure the maximum export batch size for PeriodicReader. (#​8960)
  • Add WithAttributeValueDepthLimit, DefaultAttributeValueDepthLimit, and SpanLimits.AttributeValueDepthLimit in go.opentelemetry.io/otel/sdk/trace to configure the maximum depth of span, event, link, and instrumentation scope attribute values. (#​8938)
  • Add WithAttributeValueDepthLimit in go.opentelemetry.io/otel/sdk/log to configure the maximum depth of log record and instrumentation scope attribute values. (#​8938)
  • Add WithMaxResponseSize to go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp,
    go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp, and
    go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp. (#​8941)
  • Add experimental ProbabilitySampler in go.opentelemetry.io/otel/sdk/trace/x that conforms to the OpenTelemetry specification's threshold-based sampling algorithm. (#​8123)
  • Add experimental *Binder extension interfaces in go.opentelemetry.io/otel/metric/x for instruments that support binding attributes ahead of time. (#​8760)
  • Add the experimental Finisher synchronous metric instrument extension interface to go.opentelemetry.io/otel/metric/x. (#​8906)
Changed
  • Use the OpenTelemetry Attribute Collection representation for non-OTLP protocols for metric data diffs in go.opentelemetry.io/otel/sdk/metric/metricdata/metricdatatest. (#​8993)
  • Apply a maximum depth of 64 by default to span, event, link, log record, and instrumentation scope attribute values in go.opentelemetry.io/otel/sdk/trace and go.opentelemetry.io/otel/sdk/log. (#​8938)
  • Reduce allocations when applying attribute value length limits in go.opentelemetry.io/otel/sdk/trace and go.opentelemetry.io/otel/sdk/log by rebuilding composite values only when truncation is needed. (#​8912)
  • Decode traceparent using a hex lookup table in go.opentelemetry.io/otel/propagation, which rejects the specification-disallowed upper-case characters without a separate scan of the header. (#​8739)
  • Decode all characters at constant indices in TraceIDFromHex and SpanIDFromHex in go.opentelemetry.io/otel/trace to eliminate bounds checks. (#​8740)
Fixed
  • Count valid U+FFFD replacement characters toward attribute value length limits in go.opentelemetry.io/otel/trace, go.opentelemetry.io/otel/sdk/trace, and go.opentelemetry.io/otel/sdk/log.
  • Truncate string attribute values to empty strings when the configured length limit is zero, including malformed UTF-8, in go.opentelemetry.io/otel/trace, go.opentelemetry.io/otel/sdk/trace, and go.opentelemetry.io/otel/sdk/log. (#​9054)
  • Fix a data race in NewPeriodicReader where r.inst was assigned after the background goroutine was launched in go.opentelemetry.io/otel/sdk/metric. (#​9028)
  • Prevent precision loss for large int64 values in Sum, Histogram, and ExponentialHistogram aggregations in go.opentelemetry.io/otel/sdk/metric. (#​8981)
  • Ensure grpc.DialOption values passed via WithDialOption take precedence over conflicting internally-computed defaults in
    go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc,
    go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc, and
    go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc. (#​8805, #​8834, #​8836)
  • Treat overflowing OTEL_METRIC_EXPORT_INTERVAL and OTEL_METRIC_EXPORT_TIMEOUT values as invalid in go.opentelemetry.io/otel/sdk/metric. (#​8800)
  • Prevent a panic in NewFixedSizeReservoir and FixedSizeReservoirProvider when given a negative size in go.opentelemetry.io/otel/sdk/metric/exemplar; negative sizes are now clamped to zero, consistent with a size of zero. (#​8832)
  • Preserve exponential histogram ZeroThreshold during OTLP metric export in go.opentelemetry.io/otel/exporters/otlp/otlpmetric. (#​8801)
  • Ensure metric helpers in go.opentelemetry.io/otel/semconv/v1.32.0, go.opentelemetry.io/otel/semconv/v1.33.0, and go.opentelemetry.io/otel/semconv/v1.34.0 record measurements only once when no attributes are provided. (#​8849)
  • Treat empty OTEL_TRACES_SAMPLER and OTEL_TRACES_SAMPLER_ARG values as unset in go.opentelemetry.io/otel/sdk/trace. (#​8873)
  • Normalize global OTEL_EXPORTER_OTLP_ENDPOINT path joining in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp so trailing-slash base URLs do not produce double-slash log export paths. (#​8864)
  • Prevent a deadlock when formatting an error passed to RecordError calls back into the span in go.opentelemetry.io/otel/sdk/trace. (#​8815)
  • Prevent SimpleSpanProcessor.Shutdown from panicking when constructed with a nil exporter in go.opentelemetry.io/otel/sdk/trace. (#​8844)
  • Propagate invalid exponential histogram scale errors to Prometheus exporter self-observability metrics in go.opentelemetry.io/otel/exporters/prometheus. (#​8839)
  • Retain instrument advisory attributes configured with go.opentelemetry.io/otel/metric/x.WithDefaultAttributes when a matching View in go.opentelemetry.io/otel/sdk/metric does not specify an attribute filter. (#​8859)
  • Ignore HTTP URL paths when building OTLP/gRPC metric exporter targets from OTEL_EXPORTER_OTLP_ENDPOINT and OTEL_EXPORTER_OTLP_METRICS_ENDPOINT, while preserving unix:// and unix-abstract:// targets; treat unix-abstract:// endpoints as insecure in go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc and go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp. (#​8862)
  • Ignore HTTP(S) paths when deriving gRPC trace exporter endpoints from OTEL_EXPORTER_OTLP_ENDPOINT and OTEL_EXPORTER_OTLP_TRACES_ENDPOINT in go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc. (#​8852)
  • Bound memory used while parsing dense W3C property metadata by storing it compactly and materializing Property values on demand in go.opentelemetry.io/otel/baggage and go.opentelemetry.io/otel/propagation.
Removed
  • Remove the experimental OTEL_GO_X_METRIC_EXPORT_BATCH_SIZE environment variable in go.opentelemetry.io/otel/sdk/metric.
    Use the WithMaxExportBatchSize option instead. (#​8960)
What's Changed

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@tannevaled

tannevaled commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: frontend/package-lock.json
npm warn Unknown env config "store". This will error in a future major version of npm. See `npm help npmrc` for supported config options.
npm error code EALLOWREMOTE
npm error Fetching packages of type "remote" have been disabled
npm error Refusing to fetch "https://registry.npmjs.org/@tailwindcss/oxide-wasm32-wasi/-/oxide-wasm32-wasi-4.3.3.tgz"
npm error A complete log of this run can be found in: /tmp/renovate/cache/others/npm/_logs/2026-10-07T16_06_45_031Z-debug-0.log

@tannevaled
tannevaled force-pushed the renovate/deps branch 5 times, most recently from 887a350 to 4b55327 Compare September 19, 2026 12:52
@tannevaled
tannevaled force-pushed the renovate/deps branch 2 times, most recently from d484684 to c52ae40 Compare September 25, 2026 14:26
tannevaled added a commit that referenced this pull request Sep 28, 2026
… quietly (#37)

`npm install` has failed on main since #22 took typescript to 7:

    npm error ERESOLVE could not resolve
    npm error Found: typescript@7.0.2
    npm error peer typescript@"^5.0.0 || ^6.0.0" from svelte-check@4.7.6

svelte-check does not admit that major, and no published version does.
The consequence is wider than the frontend: Renovate cannot regenerate
a lockfile it cannot install, so every dependency pull request since
then reports "Artifact file update failure" and carries no npm change
at all. #36 lists fifteen npm updates in its body and changes no
package.json -- the table is what Renovate intended, not what it did.

Nothing caught this because no job here installs the frontend. The
three jobs are Go. So this does two things:

  - typescript ^7.0.0 -> ^6.0.0, the newest major svelte-check accepts,
    and the lockfile regenerated against it;
  - a frontend job, taken from the sibling repository's rather than
    invented, running npm ci / build / check.

Verified by running exactly what that job runs, with node_modules
deleted before each step:

    npx npm@10 ci   ok
    npm run build   ok
    npm run check   494 files, 0 errors, 22 warnings

The warnings are the accessibility ones already in the tree.

The lockfile is generated with npm 10, not the npm 11 on this machine.
The two majors describe platform-specific packages differently, and the
npm 11 file had 26 entries carrying an "os" field with no "optional",
which npm 10 treats as required and refuses:

    npm error notsup Unsupported platform for @esbuild/aix-ppc64

Checked as a property of the file rather than by reading a green log:
26 such entries with npm 11, 0 with npm 10. The job pins node 22, which
ships npm 10, so that mismatch would have failed its first run.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
@tannevaled

Copy link
Copy Markdown
Contributor Author

The renovate/artifacts failure here was not about any package in the table — it was that frontend/ could not be installed at all:

npm error peer typescript@"^5.0.0 || ^6.0.0" from svelte-check@4.7.6

Renovate cannot regenerate a lockfile it cannot install, which is why this pull request lists fifteen npm updates and changes no package.json. The body was the intention; the diff was what happened.

#37 has landed: typescript is back to ^6.0.0, the lockfile is regenerated, and there is now a frontend job so the next time this happens CI says so instead of Renovate going quiet. The npm half of this update should come through on the next Renovate run.

Leaving this open rather than closing it — closing a Renovate pull request tells it to skip those versions, and they are wanted.

🤖 Generated with Claude Code

@tannevaled
tannevaled force-pushed the renovate/deps branch 5 times, most recently from caaff12 to 1cfb1e9 Compare October 3, 2026 14:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant