Update all non-major dependencies - #103
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 20, 2026 17:59
114db6b to
4425a5e
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 24, 2026 18:17
4425a5e to
9010e8f
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 26, 2026 18:42
9010e8f to
caf567d
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 26, 2026 22:10
caf567d to
31c3a29
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 30, 2026 17:43
31c3a29 to
bb375bf
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
April 1, 2026 20:45
bb375bf to
75b3640
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
April 15, 2026 11:51
75b3640 to
9e6f3b2
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
April 16, 2026 09:49
9e6f3b2 to
c94da6c
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
April 17, 2026 15:11
c94da6c to
b85d376
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
April 18, 2026 14:07
b85d376 to
fe72c90
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
April 21, 2026 23:33
fe72c90 to
646b4a4
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
April 22, 2026 16:10
646b4a4 to
958c843
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
April 22, 2026 21:43
958c843 to
f8b69af
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
April 23, 2026 16:37
f8b69af to
555c9bf
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
May 6, 2026 14:43
810cad9 to
118c929
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
May 8, 2026 06:10
118c929 to
8547f46
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
May 10, 2026 05:24
8547f46 to
888b7ec
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
May 12, 2026 01:54
888b7ec to
c9f5a24
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
May 12, 2026 10:47
c9f5a24 to
dc96442
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
May 13, 2026 21:49
dc96442 to
02852c1
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
May 14, 2026 18:12
02852c1 to
5d80f39
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
May 18, 2026 15:04
5d80f39 to
71dd543
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
May 26, 2026 22:43
71dd543 to
a84c95d
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
May 27, 2026 17:42
a84c95d to
da07a22
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
May 28, 2026 02:53
da07a22 to
07471d5
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
May 28, 2026 15:14
07471d5 to
740780f
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
June 1, 2026 20:03
740780f to
2931ef0
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
June 4, 2026 11:40
2931ef0 to
bf97326
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
June 6, 2026 02:06
bf97326 to
fc85e68
Compare
| datasource | package | from | to | | ---------- | ----------------------- | ------- | ------- | | npm | @astrojs/check | 0.9.8 | 0.9.10 | | npm | @astrojs/mdx | 5.0.2 | 5.0.6 | | npm | @astrojs/sitemap | 3.7.1 | 3.7.3 | | npm | @fontsource/roboto-mono | 5.2.8 | 5.3.0 | | npm | @fontsource/roboto-slab | 5.2.8 | 5.3.0 | | npm | @types/node | 24.12.0 | 24.13.3 | | npm | astro-embed | 0.12.0 | 0.13.1 | | npm | astro-expressive-code | 0.41.7 | 0.44.1 | | npm | pnpm | 10.32.1 | 10.34.5 | | npm | rehype-pretty-code | 0.14.3 | 0.14.5 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.9.8→0.9.105.0.2→5.0.63.7.1→3.7.35.2.8→5.3.05.2.8→5.3.024.12.0→24.13.3^0.12.0→^0.13.0^0.41.5→^0.44.010.32.1→10.34.50.14.3→0.14.5Release Notes
withastro/astro (@astrojs/check)
v0.9.10Compare Source
Patch Changes
b01a692Thanks @ocavue! - Update dependencyyargsto version 18. See the yargs changelog for details.v0.9.9Compare Source
Patch Changes
#16471
f56bb3fThanks @delucis! - Adds support for TypeScript v6 to peer dependencies rangeUpdated dependencies [
8c62159]:withastro/astro (@astrojs/mdx)
v5.0.6Compare Source
Patch Changes
49e10e3Thanks @igor-koop! - Fixes an issue where thesmartypantsoption was ignored.v5.0.5Compare Source
Patch Changes
9256345]:v5.0.4Compare Source
Patch Changes
f3485c3]:v5.0.3Compare Source
Patch Changes
10a1a5a]:withastro/astro (@astrojs/sitemap)
v3.7.3Compare Source
Patch Changes
783c4a6Thanks @jdevalk! - Improves<lastmod>accuracy in the sitemap index. Each<sitemap>entry insitemap-index.xmlis now stamped with the most recentlastmodof the URLs in the child sitemap it points to, instead of repeating a single global date on every entry. When a child sitemap has no per-URLlastmod, the entry falls back to thelastmodoption as before. This gives search engines a per-file freshness signal, so they can tell which child sitemaps actually changed without refetching all of them.v3.7.2Compare Source
Patch Changes
babf57fThanks @AhmadYasser1! - Fixes i18n fallback pages missing from the generated sitemap when usingfallbackType: 'rewrite'.fontsource/font-files (@fontsource/roboto-mono)
v5.3.0Compare Source
v5.2.9Compare Source
fontsource/font-files (@fontsource/roboto-slab)
v5.3.0Compare Source
delucis/astro-embed (astro-embed)
v0.13.1Compare Source
Patch Changes
#423
9940e77Thanks @renovate! - Adds support for Astro 7Updated dependencies [
9940e77]:v0.13.0Compare Source
Minor Changes
#261
eb53671Thanks @delucis! - Reduces install size of@astro-community/astro-embed-blueskyby ~60%The
<Bluesky>component now uses atcute instead of@atproto/apiinternally. Because of this, thePostTypeScript type has changed slightly. If you were passing Bluesky data directly to the component (instead of a post URL), it should still work, but in some circumstances you may see type errors and need to adjust things slightly. Let us know if you run into issues upgrading.Patch Changes
eb53671]:expressive-code/expressive-code (astro-expressive-code)
v0.44.1Compare Source
Patch Changes
ef538d8: Prevent a white corner from appearing when themed horizontal and vertical scrollbars are both visible.ef538d8]v0.44.0Compare Source
Minor Changes
9169010: Adds support for Astro v7 and Sätteri v0.9Patch Changes
v0.43.1Compare Source
Patch Changes
d9a3942: Avoids Astro 6.4 deprecation warnings by registering Expressive Code with the Unified Markdown processor when available.v0.43.0Compare Source
Minor Changes
ce8d751: Adds support for the Sätteri Markdown processor introduced in Astro 6.4.When your Astro config sets
markdown.processortosatteri()(from@astrojs/markdown-satteri), code blocks are now processed by Expressive Code through an equivalent Sätteri HAST plugin instead of the rehype plugin, which Sätteri does not run. The default unified pipeline keeps working exactly as before, and no configuration changes are required to benefit from this.Thank you @Princesseuh!
Patch Changes
v0.42.0Compare Source
Patch Changes
pnpm/pnpm (pnpm)
v10.34.5: pnpm 10.34.5Compare Source
Patch Changes
78e29fe: Prevent a craftedpnpm-lock.yamlfrom writing package content outside the virtual store. A dependency path key whose name reconstructs to a path-traversal sequence (e.g.../../../tmp/x@1.0.0) is now rejected by the isolated (virtual-store) linker and the Plug'n'Play resolver map, matching the containment already applied to the hoisted linker. Under the global virtual store, a traversal in the version-derived path segment (e.g. a snapshotversion: "../../x") is now rejected atiterateHashedGraphNodes, the single point every global-virtual-store slot path funnels through.78e29fe: Fixed a path traversal vulnerability where a dependency whose manifestnamewas a scoped path traversal (e.g.@x/../../../<path>) could be written outsidenode_modulesto an attacker-controlled location duringpnpm install, even with--ignore-scripts. The isolated linker now validates the package name before using it as a directory name, matching the existing protection in the hoisted linker.47ef6f0: Fixed switching to and self-updating to pnpm v12. pnpm v12 (the Rust port) ships as thepnpmand@pnpm/exenpm packages whose bins are placeholders replaced at install time by the host's native binary from a@pnpm/exe.<platform>-<arch>[-musl]optional dependency. Because pnpm installs its own engine with--ignore-scripts, that relinking never ran, leaving a non-executable placeholder. pnpm now relinks the native binary itself for v12 (recognizing the new platform-package naming scheme and the nativepnpmpackage), and verifies the native binary's npm registry signature before running it.36928be:${...}environment-variable placeholders in thehttpProxy,httpsProxy,noProxy,proxy, andnoproxysettings are no longer expanded when these settings come from a project'spnpm-workspace.yaml. They now receive the same protection already applied toregistry.Platinum Sponsors
Gold Sponsors
v10.34.4: pnpm 10.34.4Compare Source
Patch Changes
352ae48: Security: validate config dependency names and versions before using them to build filesystem paths. Apnpm-workspace.yamlwith a traversal-shapedconfigDependenciesname (such as../../PWNED) or version (such as../../../PWNED) could previously causepnpm installto create symlinks or write package files outsidenode_modules/.pnpm-configand the store. Names must now be valid npm package names and versions must be exact semver versions. See GHSA-qrv3-253h-g69c.352ae48: Reject path-traversal and reserved dependency aliases (such as../../../escape,.bin,.pnpm, ornode_modules) that come from a lockfile rather than a freshly resolved manifest. A crafted lockfile alias could otherwise be joined directly under a hoistednode_modulesdirectory, letting package files be written outside the intended install root or overwrite pnpm-owned layout.The
nodeLinker: hoistedgraph builder now validates each alias at the directory sink (safeJoinModulesDir), matching the validation pnpm already performs when resolving aliases from manifests. See GHSA-fr4h-3cph-29xv.352ae48: Preventpnpm patch-removefrom removing files outside the configured patches directory.217fbe0: Hardened the warning printed when a project.npmrcuses environment variables in registry/auth settings: the suggestedpnpm config setcommand is now only included for keys made up of shell-inert characters. Because the key comes from a repository-controlled.npmrcand a shell expands$(...), backticks, and$VAReven inside double quotes, a crafted key could otherwise have turned the suggested copy-paste command into command execution.Platinum Sponsors
Gold Sponsors
v10.34.3: pnpm 10.34.3Compare Source
.npmrc(action may be required)Following GHSA-3qhv-2rgh-x77r, pnpm no longer expands
${ENV_VAR}placeholders that come from a repository-controlled config file, because a malicious repository could otherwise use them to leak your environment secrets (npm tokens, CI job tokens, etc.) to an attacker-controlled registry during install. This applies to:.npmrc—registry,@scope:registry, proxy URLs, URL-scoped keys (//host/…), and credential values (_authToken,_auth,_password,username,tokenHelper,cert,key);pnpm-workspace.yaml.This release also closes a bypass where a project
.npmrccould setuserconfig,globalconfig, orprefixto make pnpm load a repo-supplied file as trusted config (via@pnpm/npm-conf@3.0.3).Environment variables are still expanded in trusted config: your user-level
~/.npmrc, the global config, CLI options, and environment config.If your authentication broke after upgrading, move the token out of the committed
.npmrc:Or keep the
${NPM_TOKEN}line but put it in your user-level~/.npmrcinstead of the repo. In GitHub Actions,actions/setup-nodewithregistry-urlalready writes a user-level.npmrc, soNODE_AUTH_TOKENkeeps working. For other CI where editing each pipeline is hard, setNPM_CONFIG_USERCONFIG=.npmrcin the CI environment to declare the project.npmrctrusted.See https://pnpm.io/npmrc for full migration details.
Patch Changes
.npmrcuses an environment variable in a registry/proxy URL or in registry credentials. The message now explains why the setting was ignored and how to migrate it to a trusted source — for example by runningpnpm config set "<key>" <value>to store it in the global config, or by keeping the${...}line in the user-level~/.npmrc— with a link to https://pnpm.io/npmrc..npmrccan no longer redirect which files pnpm loads as its trusted user and global configuration. Previously such a file could setuserconfig,globalconfig, orprefixto point at an attacker-supplied file shipped in the repository, and pnpm would load it as a trusted config source — bypassing the protection that prevents repository config from expanding environment variables into registry request destinations and credentials, and allowing it to settokenHelper. The user/global config file locations are now resolved only from trusted sources (CLI options, environment config, the npm builtin config, and defaults) before the project and workspace.npmrcfiles are read. Fixed by upgrading@pnpm/npm-confto3.0.3.Platinum Sponsors
Gold Sponsors
v10.34.2: pnpm 10.34.2Compare Source
.npmrc(action may be required)Following GHSA-3qhv-2rgh-x77r, pnpm no longer expands
${ENV_VAR}placeholders that come from a repository-controlled config file, because a malicious repository could otherwise use them to leak your environment secrets (npm tokens, CI job tokens, etc.) to an attacker-controlled registry during install. This applies to:.npmrc—registry,@scope:registry, proxy URLs, URL-scoped keys (//host/…), and credential values (_authToken,_auth,_password,username,tokenHelper,cert,key);pnpm-workspace.yaml.This release also closes a bypass where a project
.npmrccould setuserconfig,globalconfig, orprefixto make pnpm load a repo-supplied file as trusted config (via@pnpm/npm-conf@3.0.3).Environment variables are still expanded in trusted config: your user-level
~/.npmrc, the global config, CLI options, and environment config.If your authentication broke after upgrading, move the token out of the committed
.npmrc:Or keep the
${NPM_TOKEN}line but put it in your user-level~/.npmrcinstead of the repo. In GitHub Actions,actions/setup-nodewithregistry-urlalready writes a user-level.npmrc, soNODE_AUTH_TOKENkeeps working. For other CI where editing each pipeline is hard, setNPM_CONFIG_USERCONFIG=.npmrcin the CI environment to declare the project.npmrctrusted.See https://pnpm.io/npmrc for full migration details.
Patch Changes
packageManagerfield, the registry it fetches from (and the proxy/TLS settings used for that traffic) now come exclusively from trusted config sources — CLI options, env config, user and global.npmrc— defaulting to the public npm registry, instead of the repository's project/workspace settings.packageManagerfield (orpnpm self-update) makes pnpm download another pnpm version, the staged install is verified corepack-style: the integrity recorded in the staged lockfile must carry a valid npm registry signature for the exactname@version, validated against npm's public signing keys that ship embedded in the pnpm CLI. Verification fails closed — a tampered download, an unsigned package, or an unreachable registry refuses the version switch rather than running an unverified binary. It runs only when the wanted version is actually downloaded (a tools-directory cache miss), so repeated commands pay no extra network round trip..npmrcandpnpm-workspace.yaml) can no longer expand${...}placeholders in registry/proxy request destinations, URL-scoped keys, or registry credential values, preventing repository-controlled configuration from exfiltrating environment secrets through request URLs. Trusted user/global/CLI/env config keeps full env expansion, so existing token and registry setup flows continue to work.binnames ("",".","..", and scoped forms such as@scope/..) when resolving a package's bins. These names previously passed the bin-name guard and, when joined to the global bin directory during global remove/update/add operations, could resolve to the global bin directory itself or its parent and have it recursively deleted.onlyBuiltDependencies(andallowBuilds) entries can approve lifecycle scripts for git, git-hosted tarball, direct tarball, and local directory artifacts. To approve one of those artifacts explicitly, use its peer-suffix-free lockfile depPath as the key. Lockfile entries are now rejected when a registry-style dependency path (name@semver) is backed by a git, directory, or git-hosted tarball resolution (ERR_PNPM_RESOLUTION_SHAPE_MISMATCH), so the dependency path is a reliable artifact identity by the time scripts can run.SHASUMS256.txtagainst the Node.js release team's public keys (embedded in the pnpm CLI) before trusting its hashes. The Node.js download mirror is repository-configurable (node-mirror:<channel>in.npmrc), and the integrity check previously trusted aSHASUMS256.txtfetched from that same mirror — a circular check that a malicious mirror could satisfy with a tampered binary and matching hashes. A mirror that proxies the real signed SHASUMS keeps working unchanged. Only thereleasechannel publishes signed SHASUMS files, so pre-release channels (rc, nightly, …) remain unverified.Platinum Sponsors
Gold Sponsors
v10.34.1: pnpm 10.34.1Compare Source
Patch Changes
pnpm-lock.yamlentries whose remote tarballresolution:block is missing theintegrityfield. Previously the worker that extracts a downloaded tarball skipped hash verification when no integrity was supplied and minted a fresh one from the unverified bytes, so an attacker who could both alter the lockfile (e.g. via a pull request that stripsintegrity:) and serve modified content at the referenced tarball URL could install a tampered package without any error — including under--frozen-lockfile. pnpm now fails closed at lockfile-read time withERR_PNPM_MISSING_TARBALL_INTEGRITY. Git-hosted tarballs (gitHosted: trueor a URL on codeload.github.com / bitbucket.org / gitlab.com) andfile:tarballs are exempt — the commit SHA in a git-host URL and the user-controlled local path already anchor the bytes.Platinum Sponsors
Gold Sponsors
v10.34.0: pnpm 10.34Compare Source
Minor Changes
Treat tarball-integrity mismatches against the lockfile as a hard failure by default. Previously,
pnpm install(non-frozen) would logERR_PNPM_TARBALL_INTEGRITY, silently re-resolve from the registry, and overwrite the locked integrity — which meant a compromised registry, proxy, or republished version could substitute attacker-controlled content on a clean machine even though the project shipped a committed lockfile.pnpm installnow exits withERR_PNPM_TARBALL_INTEGRITYand a hint pointing at the new opt-in flag.The only opt-in is
pnpm install --update-checksums— narrowly scoped to refreshing the locked integrity values from what the registry currently serves. Mirrors yarn's flag of the same name. A warning still prints when the bypass takes effect so the operation is auditable.--forceandpnpm updatedeliberately do not bypass the integrity check. They are routine refresh operations; silently overwriting a locked integrity in those flows would erase the protection a committed lockfile is supposed to provide.--frozen-lockfilebehavior is unchanged.--fix-lockfilekeeps its documented purpose (filling in missing lockfile entries) and is also not a bypass.Patch Changes
_authToken,_auth,username/_password,tokenHelper, inlinecert/key) to the registry declared in the same config source at load time, so a later layer overridingregistry=(workspace.npmrc,pnpm-workspace.yaml, CLI--registry) cannot redirect a credential or client certificate authored for a different host. A deprecation warning is emitted whenever an unscoped per-registry setting is encountered, naming the source and the URL it was pinned to. Reported by JUNYI LIU.minimumReleaseAgehandling when cached metadata is abbreviated. The npm registry returns abbreviated package metadata (without the per-versiontimefield) by default, which made the maturity check throwERR_PNPM_MISSING_TIMEwhenever cached abbreviated metadata was reused. pnpm now upgrades cached abbreviated metadata to the full document via a follow-up fetch whenminimumReleaseAgeis active, persists the upgrade to the on-disk cache so subsequent installs skip the extra fetch, and letsERR_PNPM_MISSING_TIMEfrom the cache fast-path fall through to the network fetch even under strict mode.commitfield is not a 40-character hexadecimal SHA before invokinggit. A malicious lockfile could otherwise smuggle a value such as--upload-pack=<command>throughgit fetch/git checkout, which on SSH or local-file transports executes the supplied command.diff --githeaders reference paths outside the patched package directory. Previously a malicious.patchfile added via a pull request could write, delete, or rename arbitrary files reachable by the user runningpnpm install.--prefix=<dir>not being honored when locating the workspace root. The--prefix → dirrename was applied after workspace detection, so workspace settings declared in<dir>/pnpm-workspace.yamlwere not loaded when pnpm was invoked from outside<dir>#11535.@x/../../../../../.git/hooks) when reading them from a package manifest or symlinking them intonode_modules. A malicious registry package could otherwise use a transitive dependency key to makepnpm installcreate symlinks at attacker-chosen paths outside the intendednode_modulesdirectory.Platinum Sponsors
Gold Sponsors
This PR was generated by Mend Renovate. View the repository job log.