Commit a1cdf18
authored
chore(deps): update pnpm to v11.17.0 (#706)
> ℹ️ **Note**
>
> This PR body was truncated due to platform limits.
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Adoption](https://docs.renovatebot.com/merge-confidence/) |
[Passing](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|---|---|
| [pnpm](https://pnpm.io)
([source](https://redirect.github.com/pnpm/pnpm/tree/HEAD/pnpm11/pnpm))
| [`11.9.0` →
`11.17.0`](https://renovatebot.com/diffs/npm/pnpm/11.9.0/11.17.0) |

|

|

|

|
---
### Release Notes
<details>
<summary>pnpm/pnpm (pnpm)</summary>
###
[`v11.17.0`](https://redirect.github.com/pnpm/pnpm/releases/tag/v11.17.0):
pnpm 11.17
[Compare
Source](https://redirect.github.com/pnpm/pnpm/compare/v11.16.0...v11.17.0)
##### Minor Changes
- Added a new setting, `update.githubActionsServer`, for specifying the
base URL of the GitHub server that hosts the repositories of the GitHub
Actions referenced by the workflow files (for example, a GitHub
Enterprise Server). When the setting is not defined, the URL is read
from the `GITHUB_SERVER_URL` environment variable, falling back to
`https://github.com`. The URL must use the `https://` or `http://`
protocol
[#​13220](https://redirect.github.com/pnpm/pnpm/issues/13220).
`pnpm outdated` and `pnpm update` no longer fail when the refs of a
GitHub Action's repository cannot be read (for example, when the
action's repository is private or hosted on a different GitHub server).
Such actions are now skipped with a warning.
Setting `update.githubActions` to `false` now makes `pnpm outdated` and
the interactive `pnpm update` skip GitHub Actions dependencies.
##### Patch Changes
- The token poll for web-based authentication no longer reads the body
of non-OK or still-pending (HTTP 202) responses, and caps the token
response body it does read at 64 KiB, so a malicious or compromised
registry cannot exhaust memory through the poll
[pnpm/pnpm#12721](https://redirect.github.com/pnpm/pnpm/issues/12721).
- Fixed `catalog:` references in dependencies and overrides failing to
resolve when installing through a pnpr server, which errored with "No
catalog entry '<name>' was found for catalog 'default'." even though the
catalog entry existed. Also fixed a crash on Windows when installing a
nested workspace member (e.g. `packages/foo`) through a pnpr server
[#​13232](https://redirect.github.com/pnpm/pnpm/issues/13232).
- Republished every package: the tarballs published by the v11.13.1
through v11.16.0 releases were missing most of their compiled files due
to a packing bug
[#​13164](https://redirect.github.com/pnpm/pnpm/issues/13164).
- Revert script ordering change for `pnpm run --sequential /regex/`
- Support the `from-git` argument in the `pnpm version` command.
- When the authentication URL cannot be rendered as a QR code (for
example when it exceeds the maximum QR data capacity), web-based login
now displays the URL alone with a warning instead of aborting
authentication
[pnpm/pnpm#12721](https://redirect.github.com/pnpm/pnpm/issues/12721).
<!-- sponsors -->
##### Platinum Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/openai_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/openai_light.svg" />
<img src="https://pnpm.io/img/users/openai_dark.svg" width="160"
alt="OpenAI" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
##### Gold Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/sanity.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/sanity_light.svg" />
<img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity"
/>
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/discord.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/discord_light.svg" />
<img src="https://pnpm.io/img/users/discord.svg" width="220"
alt="Discord" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/serpapi_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/serpapi_light.svg" />
<img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160"
alt="SerpApi" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/coderabbit.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/coderabbit_light.svg" />
<img src="https://pnpm.io/img/users/coderabbit.svg" width="220"
alt="CodeRabbit" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/stackblitz.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/stackblitz_light.svg" />
<img src="https://pnpm.io/img/users/stackblitz.svg" width="190"
alt="Stackblitz" />
</picture>
</a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/workleap.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/workleap_light.svg" />
<img src="https://pnpm.io/img/users/workleap.svg" width="190"
alt="Workleap" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://nx.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/nx.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/nx_light.svg" />
<img src="https://pnpm.io/img/users/nx.svg" width="50" alt="Nx" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
<!-- sponsors end -->
###
[`v11.16.0`](https://redirect.github.com/pnpm/pnpm/releases/tag/v11.16.0):
pnpm 11.16
[Compare
Source](https://redirect.github.com/pnpm/pnpm/compare/v11.15.1...v11.16.0)
#### Minor Changes
- The first release of a package now publishes the version written in
its manifest verbatim, instead of bumping off it. `pnpm version -r` and
`pnpm change status` check the registry for each release's current
version; when that version is not yet published, the package debuts at
it and its pending changesets apply only from the next release. A newly
added package seeded at `1100.0.0` with a `minor` changeset is therefore
published as `1100.0.0` rather than skipping straight to `1100.1.0`.
- Added a `--changeset` flag to `pnpm update`. Set `update.changeset` to
`true` in `pnpm-workspace.yaml` to enable this behavior by default, and
use `--no-changeset` to override the setting for one update. After the
update completes, pnpm writes a `.changeset/pnpm-update-<suffix>.md`
file declaring a patch bump for every workspace package whose
`dependencies` or `optionalDependencies` were changed by the update and
a major bump when `peerDependencies` changed, including packages that
consume an updated catalog entry via the `catalog:` protocol. Private
packages, packages without a name, and packages listed in the `ignore`
array of `.changeset/config.json` are skipped. If
`.changeset/config.json` does not exist, a warning is printed and no
changeset is generated.
- Added GitHub Actions dependencies to `pnpm outdated` and interactive
`pnpm update`. Non-interactive updates can include them with
`--include-github-actions` or by setting `update.githubActions` to
`true` in `pnpm-workspace.yaml`. Updated actions are pinned to exact
commit hashes with their release tags preserved in comments.
- Added `update` and `audit` settings sections to `pnpm-workspace.yaml`,
superseding the awkwardly named `updateConfig`, `auditConfig`, and
top-level `auditLevel` settings:
```yaml
update:
ignoreDeps: # was updateConfig.ignoreDependencies
- webpack
- "@​babel/*"
audit:
level: high # was auditLevel
ignore: # was auditConfig.ignoreGhsas
- GHSA-xxxx-yyyy-zzzz
```
`update.ignoreDeps` lists dependency name patterns that `pnpm update`
and `pnpm outdated` should skip. `audit.level` and `audit.ignore` tune
`pnpm audit`.
The deprecated `updateConfig`, `auditConfig`, and `auditLevel` settings
keep working until the next major version. When both a new section value
and its deprecated counterpart are set, the new section takes precedence
and a warning is printed. Both the TypeScript CLI and the Rust config
surface (pacquet) recognize the new sections.
#### Patch Changes
- Fixed `pnpm add --save-exact`/`--save-prefix` and `pnpm update`
writing a package's version with the `peerDependencies` range's prefix
(e.g. `^19.2.7` instead of the requested `19.2.7`) whenever the same
package also appeared in `peerDependencies`. A real
`dependencies`/`devDependencies`/`optionalDependencies` entry now takes
precedence over a same-named `peerDependencies` entry when computing the
current specifiers
[#​13108](https://redirect.github.com/pnpm/pnpm/issues/13108).
<!-- sponsors -->
#### Platinum Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/openai_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/openai_light.svg" />
<img src="https://pnpm.io/img/users/openai_dark.svg" width="160"
alt="OpenAI" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
#### Gold Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/sanity.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/sanity_light.svg" />
<img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity"
/>
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/discord.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/discord_light.svg" />
<img src="https://pnpm.io/img/users/discord.svg" width="220"
alt="Discord" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/serpapi_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/serpapi_light.svg" />
<img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160"
alt="SerpApi" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/coderabbit.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/coderabbit_light.svg" />
<img src="https://pnpm.io/img/users/coderabbit.svg" width="220"
alt="CodeRabbit" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/stackblitz.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/stackblitz_light.svg" />
<img src="https://pnpm.io/img/users/stackblitz.svg" width="190"
alt="Stackblitz" />
</picture>
</a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/workleap.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/workleap_light.svg" />
<img src="https://pnpm.io/img/users/workleap.svg" width="190"
alt="Workleap" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://nx.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/nx.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/nx_light.svg" />
<img src="https://pnpm.io/img/users/nx.svg" width="50" alt="Nx" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
<!-- sponsors end -->
###
[`v11.15.1`](https://redirect.github.com/pnpm/pnpm/compare/v11.15.0...v11.15.1)
[Compare
Source](https://redirect.github.com/pnpm/pnpm/compare/v11.15.0...v11.15.1)
###
[`v11.15.0`](https://redirect.github.com/pnpm/pnpm/releases/tag/v11.15.0):
pnpm 11.15
[Compare
Source](https://redirect.github.com/pnpm/pnpm/compare/v11.14.0...v11.15.0)
##### Minor Changes
- Optional peer dependencies declared only via `peerDependenciesMeta`
(for example `debug`'s `supports-color` peer) are now resolved from a
satisfying version already present in the dependency graph, the same way
explicitly declared optional peer dependencies are. Previously such
peers were only resolved this way when the package's metadata was read
back from the lockfile, so an unrelated dependency change could rewrite
peer resolutions across the whole lockfile.
##### Patch Changes
- Updated `adm-zip` to prevent crafted ZIP archives from causing
excessive memory allocation.
- `pnpm version -r` no longer writes a versioning-ledger entry with no
consumed intents as a bare `intents:` key, which the next run failed to
read with `ERR_PNPM_INVALID_VERSIONING_LEDGER`. Empty intent lists are
now written as `intents: []`, and the ledger reader accepts the bare
form left by earlier releases.
- Fixed pnpr workspace resolution to preserve project names and versions
for `workspace:` dependencies.
<!-- sponsors -->
#### Platinum Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/openai_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/openai_light.svg" />
<img src="https://pnpm.io/img/users/openai_dark.svg" width="160"
alt="OpenAI" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
#### Gold Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/sanity.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/sanity_light.svg" />
<img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity"
/>
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/discord.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/discord_light.svg" />
<img src="https://pnpm.io/img/users/discord.svg" width="220"
alt="Discord" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/serpapi_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/serpapi_light.svg" />
<img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160"
alt="SerpApi" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/coderabbit.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/coderabbit_light.svg" />
<img src="https://pnpm.io/img/users/coderabbit.svg" width="220"
alt="CodeRabbit" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/stackblitz.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/stackblitz_light.svg" />
<img src="https://pnpm.io/img/users/stackblitz.svg" width="190"
alt="Stackblitz" />
</picture>
</a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/workleap.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/workleap_light.svg" />
<img src="https://pnpm.io/img/users/workleap.svg" width="190"
alt="Workleap" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://nx.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/nx.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/nx_light.svg" />
<img src="https://pnpm.io/img/users/nx.svg" width="50" alt="Nx" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
<!-- sponsors end -->
###
[`v11.14.0`](https://redirect.github.com/pnpm/pnpm/releases/tag/v11.14.0):
pnpm 11.14
[Compare
Source](https://redirect.github.com/pnpm/pnpm/compare/v11.13.1...v11.14.0)
#### Minor Changes
- `peerDependencies` now accept dependency specifiers that carry a
scheme — a named-registry spec (`<registry>:<version>`), an `npm:`
alias, or a `file:`/git/URL spec — instead of rejecting them with
`ERR_PNPM_INVALID_PEER_DEPENDENCY_SPECIFICATION`
[#​13095](https://redirect.github.com/pnpm/pnpm/issues/13095).
Such a peer is matched against the semver range carried by the specifier
(`work:5.x.x` is checked as `5.x.x`, `npm:bar@^5` as `^5`), or against
`*` when it carries no version, while the original specifier still
selects the package to auto-install. Bare `name@version` values, which
are almost always a mistake, are still rejected.
- Added `pnpm doctor`, which diagnoses the pnpm installation and the
environment it runs in: the versions and install method, whether the
global bin directory is on `PATH`, whether the store and cache are
writable, which link strategies (reflink, hardlink, symlink) the store's
filesystem supports, registry connectivity, and an offline `file:`
install that exercises the resolve/store/link path end to end. Each
check reports how to fix what it finds, and the command exits non-zero
when any check fails.
Use `--offline` to skip the checks that need network access, `--json`
for machine-readable output, and `--benchmark` to time the filesystem
and install checks.
- Added support for executing multiple scripts matching a RegExp passed
to `pnpm run` (e.g., `pnpm run "/^build:.*/"`), running matched scripts
in deterministic lexicographical order. Restored the `--sequential`
(`-s`) CLI option for `pnpm run`, which forces `workspaceConcurrency` to
1 so that matched scripts run sequentially one by one across and within
packages.
#### Patch Changes
- Fixed `pnpm install` failing with `ERR_PNPM_LOCKFILE_IS_SYMLINK` when
`pnpm-lock.yaml` is a symlink, as build sandboxes such as Bazel and Nix
stage it
[#​13073](https://redirect.github.com/pnpm/pnpm/issues/13073).
Reading a lockfile through a symlink is allowed again, and an install
that leaves the lockfile unchanged no longer rewrites it, so
`--frozen-lockfile` no longer needs to write at all. Writing a *changed*
lockfile through a symlink is still refused, as that would redirect the
write onto the symlink's target.
- Fixed frozen installs incorrectly treating equivalent Git dependency
specifiers as a stale lockfile. See
[#​13039](https://redirect.github.com/pnpm/pnpm/issues/13039).
- `pnpm owner ls` now reports authentication and authorization failures
(401/403) as dedicated errors that include the registry's response body,
matching `pnpm owner add`/`rm`, instead of a generic `Failed to fetch
owners` message.
- Recover from a metadata cache entry that disappears (concurrent cache
cleanup, antivirus) after the registry has already answered the
conditional request with `304 Not Modified`. The metadata is
re-requested once without cache validators instead of failing the
install with `ERR_PNPM_CACHE_MISSING_AFTER_304`.
- A project pinned to a broken pnpm release via `packageManager` or
`devEngines.packageManager` now reports which release is broken and what
to do about it, instead of failing inside the installer. `pnpm
self-update` already refused these releases; the version switch does
too.
- Prevent broken-lockfile errors from including snippets of the
lockfile's contents.
- `pnpm self-update` now checks that the version it installed can run
before making it the active pnpm. A release that installs but cannot
execute is discarded with an error instead of replacing a working
installation.
- Fixed an out-of-memory regression when workspace projects concurrently
resolve a package with large registry metadata
[pnpm/pnpm#13077](https://redirect.github.com/pnpm/pnpm/issues/13077).
- Fixed `pnpm update` rewriting exact version pins that use the `=`
operator (for example `=3.5.1`) to a caret range (`^3.5.1`). Exact pins
are now preserved and written back as the bare version. See
[#​12745](https://redirect.github.com/pnpm/pnpm/issues/12745).
<!-- sponsors -->
#### Platinum Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/openai_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/openai_light.svg" />
<img src="https://pnpm.io/img/users/openai_dark.svg" width="160"
alt="OpenAI" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
#### Gold Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/sanity.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/sanity_light.svg" />
<img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity"
/>
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/discord.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/discord_light.svg" />
<img src="https://pnpm.io/img/users/discord.svg" width="220"
alt="Discord" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/serpapi_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/serpapi_light.svg" />
<img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160"
alt="SerpApi" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/coderabbit.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/coderabbit_light.svg" />
<img src="https://pnpm.io/img/users/coderabbit.svg" width="220"
alt="CodeRabbit" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/stackblitz.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/stackblitz_light.svg" />
<img src="https://pnpm.io/img/users/stackblitz.svg" width="190"
alt="Stackblitz" />
</picture>
</a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/workleap.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/workleap_light.svg" />
<img src="https://pnpm.io/img/users/workleap.svg" width="190"
alt="Workleap" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://nx.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/nx.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/nx_light.svg" />
<img src="https://pnpm.io/img/users/nx.svg" width="50" alt="Nx" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
<!-- sponsors end -->
###
[`v11.13.1`](https://redirect.github.com/pnpm/pnpm/releases/tag/v11.13.1):
pnpm 11.13.1
[Compare
Source](https://redirect.github.com/pnpm/pnpm/compare/v11.13.0...v11.13.1)
#### Patch Changes
- Fixed `pnpm pack` applying workspace-root ignore rules when a
workspace package has its own `.npmignore` file.
- Keep the interactive `minimumReleaseAge` approval prompt visible
during `pnpm install`. The progress reporter now pauses its redraws
while a prompt is waiting for input instead of overwriting it, so the
install no longer hangs on a question the user cannot see
[#​13019](https://redirect.github.com/pnpm/pnpm/issues/13019).
- Fixed `pnpm self-update` failing to link native platform binaries
stored in sibling global virtual store slots.
###
[`v11.13.0`](https://redirect.github.com/pnpm/pnpm/releases/tag/v11.13.0):
pnpm 11.13
[Compare
Source](https://redirect.github.com/pnpm/pnpm/compare/v11.12.0...v11.13.0)
#### Minor Changes
- Added `versioning.epics` to `pnpm-workspace.yaml`. An epic ties a
group of member packages to a lead package, constraining every member's
major version to a band derived from the lead's major: while the lead is
on major `M`, members live in `M*100 … M*100+99`. Members move
independently inside the band (patch, minor, and a `major` intent that
stays in-band); a bump that would carry a member past the band ceiling
is rejected until the lead advances its own major. When a release plan
takes the lead to a new stable major, every member re-bases to the band
floor in the same plan. Membership is matched with pnpm's package
selectors — name globs, `./`-prefixed directory globs, and `!`-prefixed
negations.
- Added the `team` command for managing organization teams and team
memberships on the registry, with create, destroy, add, rm, and ls
subcommands and support for --otp, --parseable, and --json flags.
- Added native workspace release management
[#​12952](https://redirect.github.com/pnpm/pnpm/issues/12952): the
new `pnpm change` command records change intents as
changesets-compatible `.changeset/*.md` files (`pnpm change status`
shows the pending release plan), and the bare `pnpm version -r` consumes
them — bumping versions across the workspace with dependent propagation
through `workspace:` ranges, fixed groups, a `maxBump` cap, `--filter`
narrowing, and `--dry-run` — writing changelogs, and recording consumed
intents in a committed ledger that keeps cherry-picks and merge-backs
between release branches safe. Packages can be moved onto per-package
release lanes with the new `pnpm lane <name> --filter <pkg>` command and
back with `pnpm lane main --filter <pkg>` (`pnpm lane` shows the
membership), releasing `X.Y.Z-lane.N` prereleases from the same runs
that release stable versions of the packages on the main lane.
Configuration lives under the new `versioning` key of
`pnpm-workspace.yaml` (`fixed`, `ignore`, `maxBump`, `lanes`,
`changelog`). When two workspace projects publish the same name, intent
files, `versioning.lanes`, and `versioning.fixed`/`ignore` may reference
a project by its workspace-relative directory path (e.g.
`"./pnpm/npm/pnpm"`) — the one additive extension to the changesets
format, applied automatically by `pnpm change`.
Release changelogs default to `registry` storage
(`versioning.changelog.storage`): no `CHANGELOG.md` is committed. Each
release's section is composed at publish time and packed into the
published tarball on top of the previously published version's
changelog, and the consumed change intents are garbage-collected by a
later `pnpm version -r` only once the registry confirms the version is
published with its section. Set `versioning.changelog.storage:
repository` to keep committed `CHANGELOG.md` files instead.
- Added a new override selector form with an empty range — `"pkg@":
"<version>"` — called a convergence override. It rewrites a dependency
edge only when its exact version satisfies the edge's declared range, so
compatible consumers converge on one version while incompatible
consumers keep their own resolution — now and for any dependent added in
the future
[#​12794](https://redirect.github.com/pnpm/pnpm/issues/12794).
```yaml
overrides:
"form-data@": 4.0.6
```
The value must be an exact version. When a full resolution detects that
every declared range also admits a newer version, pnpm warns that the
override is stale and names the version to converge on. Previously an
empty range in an override selector was undocumented and behaved like a
bare (unscoped) override.
#### Patch Changes
- A `tokenHelper` set in the global pnpm `auth.ini` is no longer
rejected as project-level configuration. The guard that blocks
`tokenHelper` from a project `.npmrc` only treated `~/.npmrc` as a
trusted source, so a helper written to `auth.ini` (for example by `pnpm
config set`) failed on every command and could not even be removed with
`pnpm config delete`. A `tokenHelper` in a workspace or project `.npmrc`
is still rejected.
- `pnpm cache delete` now removes a package's metadata from every
metadata cache directory (`metadata`, `metadata-full`, and
`metadata-full-filtered`), instead of only the one the current
resolution mode reads. Previously a package cached under a different
mode (e.g. `metadata-full-filtered`) was left behind. Closes
[#​12753](https://redirect.github.com/pnpm/pnpm/issues/12753).
- Fixed an injected workspace dependency (`injectWorkspacePackages:
true`) incorrectly staying as `file:` instead of deduping back to
`link:` when an unrelated, ordinary shared dependency resolved to a
peer-suffixed variant for the target project's own copy but not for the
injected occurrence. See
[#​10433](https://redirect.github.com/pnpm/pnpm/issues/10433).
- `pnpm deploy` now supports workspaces that use catalogs.
- Fixed `pnpm deploy` with a shared lockfile so local `file:` tarball
dependencies keep their package name in the generated deploy lockfile.
This prevents warm-store deploys from failing with
`ERR_PNPM_UNEXPECTED_PKG_CONTENT_IN_STORE` when the tarball filename
includes the version.
- Options that follow `create`, `exec`, or `test` appearing as a
subcommand of another command are now parsed instead of being silently
treated as positional parameters. For example, `pnpm team create
@​org:team --registry <url>` previously ignored the `--registry`
option and sent the request to the default registry.
- `pnpm add -g`, `pnpm update -g`, `pnpm setup`, and the self-updater no
longer fail with `ERR_PNPM_MISSING_TIME` when `trustPolicy:
no-downgrade` or `resolutionMode: time-based` is set in the global
config
[#​12883](https://redirect.github.com/pnpm/pnpm/issues/12883). The
decision to fetch full registry metadata now lives in one place, and the
`no-downgrade` trust policy always requests full metadata (matching the
self-updater), since the trust evidence it checks is missing from
abbreviated metadata even on registries that include the `time` field.
- `pnpm list` and `pnpm why` no longer crash with `EMFILE: too many open
files` when a project has a large number of unsaved dependencies
(packages present in `node_modules` but not in the lockfile). The reads
of those packages are now concurrency-limited.
- The published `pnpm` package no longer declares `dependencies` or
`devDependencies`. Because the CLI bundles its runtime dependencies into
`dist/node_modules`, those fields are dropped when packing, so `npm
install` of the tarball no longer tries to resolve internal-only
packages such as `@pnpm/test-ipc-server`. Closes
[#​12955](https://redirect.github.com/pnpm/pnpm/issues/12955).
- Fixed `pnpm publish --otp` and `pnpm publish --batch --otp` to send
the configured OTP to the registry.
- `pnpm publish` again sends the package's README to the registry as
metadata, so registries can render it on the package page. The readme is
always included in the published metadata (matching the npm CLI), while
the `embed-readme` setting continues to control only whether the readme
is written into the `package.json` inside the tarball. This restores the
behavior that was lost when publishing became fully native. Closes
[#​12966](https://redirect.github.com/pnpm/pnpm/issues/12966).
- Fixed the dependency status check wrongly reporting "up to date" when
a `package.json`, `.pnpmfile.cjs`, or patch file was edited in the same
second as the previous install, on filesystems that record mtimes at
whole-second resolution (for example ext4 with 128-byte inodes). The
optimistic repeat-install fast path and `verify-deps-before-run`
compared mtimes strictly, so a same-second edit whose mtime rounded down
looked unchanged and re-resolution was skipped. Such a file's whole
second is now treated as possibly-modified, falling through to the
content check; behavior on sub-second filesystems is unchanged.
- Retry package metadata requests when a registry or proxy returns `304
Not Modified` to an unconditional request, preventing false
`ERR_PNPM_CACHE_MISSING_AFTER_304` failures
[pnpm/pnpm#12882](https://redirect.github.com/pnpm/pnpm/issues/12882).
If the retry also returns `304`, report
`ERR_PNPM_META_NOT_MODIFIED_WITHOUT_CACHE` instead.
- Fixed `pnpm update` removing transitive lockfile entries when
`dedupePeerDependents` is disabled and the selected package is absent
[pnpm/pnpm#12456](https://redirect.github.com/pnpm/pnpm/issues/12456).
- Limit modern deploy lockfiles and localized virtual stores to
dependencies reachable from the selected dependency groups.
- A `tokenHelper` command is now given a 60-second time limit. A helper
that hangs (deadlock, stuck I/O) is killed and reported as an error
instead of leaving the command waiting forever.
- Fixed orphaned child processes on Windows when pnpm exits on an error
while commands spawned by `pnpm exec` or `pnpm dlx` are still running
(for example, when one project's command fails during `pnpm --recursive
exec`). The PIDs of these commands are now recorded when they are
spawned and their whole process trees are terminated with `taskkill` on
an error exit. Previously the cleanup relied on enumerating the system
process list, which is so slow on Windows that the enumeration hit its
timeout and the cleanup was silently skipped
[#​12406](https://redirect.github.com/pnpm/pnpm/issues/12406).
- `pnpm pack` now respects workspace-root `.npmignore` and `.gitignore`
files when packing workspace packages.
<!-- sponsors -->
#### Platinum Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/openai_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/openai_light.svg" />
<img src="https://pnpm.io/img/users/openai_dark.svg" width="160"
alt="OpenAI" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
#### Gold Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/sanity.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/sanity_light.svg" />
<img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity"
/>
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/discord.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/discord_light.svg" />
<img src="https://pnpm.io/img/users/discord.svg" width="220"
alt="Discord" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/serpapi_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/serpapi_light.svg" />
<img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160"
alt="SerpApi" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/coderabbit.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/coderabbit_light.svg" />
<img src="https://pnpm.io/img/users/coderabbit.svg" width="220"
alt="CodeRabbit" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/stackblitz.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/stackblitz_light.svg" />
<img src="https://pnpm.io/img/users/stackblitz.svg" width="190"
alt="Stackblitz" />
</picture>
</a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/workleap.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/workleap_light.svg" />
<img src="https://pnpm.io/img/users/workleap.svg" width="190"
alt="Workleap" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://nx.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/nx.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/nx_light.svg" />
<img src="https://pnpm.io/img/users/nx.svg" width="50" alt="Nx" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
<!-- sponsors end -->
###
[`v11.12.0`](https://redirect.github.com/pnpm/pnpm/releases/tag/v11.12.0):
pnpm 11.12
[Compare
Source](https://redirect.github.com/pnpm/pnpm/compare/v11.11.0...v11.12.0)
#### Minor Changes
- [`a897ef7`](https://redirect.github.com/pnpm/pnpm/commit/a897ef7):
Custom fetchers exported from a pnpmfile can now delegate by returning a
`{ delegate: <resolution> }` envelope: pnpm rewrites the package's
resolution to the delegated shape and runs the built-in fetcher on it.
This is the portable delegation form that also works in pacquet, where
`cafs` and `fetchers` cannot be passed to the hook. Related to
[pnpm/pnpm#11685](https://redirect.github.com/pnpm/pnpm/issues/11685).
#### Patch Changes
- [`2b02764`](https://redirect.github.com/pnpm/pnpm/commit/2b02764): The
changed-packages filter (`--filter "...[<since>]"`) no longer allows an
option-like `<since>` value (such as `--output=<path>`) to be
interpreted as a git option — git now rejects it as a bad revision. The
repository root is also resolved to the nearest `.git` entry, so the
filter works in a git worktree checked out inside another repository's
tree.
- [`43711ce`](https://redirect.github.com/pnpm/pnpm/commit/43711ce):
`pnpm outdated` no longer checks the registry for dependencies that are
resolved from local `link:`, `file:`, or `workspace:` references in the
lockfile
[#​12827](https://redirect.github.com/pnpm/pnpm/issues/12827).
- [`3c6718b`](https://redirect.github.com/pnpm/pnpm/commit/3c6718b):
Fixed a deadlock in peer dependency resolution: `pnpm install` hung
forever when a peer dependency cycle spanned a project's own
dependencies and auto-installed peer providers, for example when
installing `electron-builder@26.15.3`
[#​12921](https://redirect.github.com/pnpm/pnpm/issues/12921).
- [`252f15e`](https://redirect.github.com/pnpm/pnpm/commit/252f15e):
Fixed peer dependency auto-install picking a version the peer range
rejects. In a workspace with several projects, a package declaring a
peer dependency with a semver range (for example `^1.0.0`) could get the
highest version found anywhere in the workspace (for example a `2.0.0`
resolved for another project) instead of a version that satisfies the
range. Peers are now deduplicated onto the highest preferred version
that satisfies the declared range, and when none does, the range is
resolved from the registry.
Also fixed re-resolving with an existing lockfile hoisting a different
peer version than a fresh install of the same manifest: root
dependencies reused from the lockfile were invisible to peer hoisting,
so a peer that a root dependency provides could be bound to another
version.
- [`a38adda`](https://redirect.github.com/pnpm/pnpm/commit/a38adda):
`pnpm self-update <version>` now installs the requested pnpm version
when it matches the currently running version but is missing from the
global self-update directory.
- [`6a85968`](https://redirect.github.com/pnpm/pnpm/commit/6a85968):
`pnpm stage list` now stops paginating after a fail-safe cap of 1000
pages, so a misbehaving registry cannot keep the command looping
forever.
- [`eee7c9a`](https://redirect.github.com/pnpm/pnpm/commit/eee7c9a):
`verify-deps-before-run` no longer spawns a `pnpm install` when pnpm is
executed in a directory that has no `package.json`. A mistyped command
run outside a project (for example `pnpm witch 10 login`) used to crash
with a confusing error from the spawned install; now it fails with the
regular "no package.json found" error.
<!-- sponsors -->
#### Platinum Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/openai_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/openai_light.svg" />
<img src="https://pnpm.io/img/users/openai_dark.svg" width="160"
alt="OpenAI" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
#### Gold Sponsors
<table>
<tbody>
<tr>
<td align="center" valign="middle">
<a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/sanity.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/sanity_light.svg" />
<img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity"
/>
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/discord.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/discord_light.svg" />
<img src="https://pnpm.io/img/users/discord.svg" width="220"
alt="Discord" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer"><img
src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/serpapi_dark.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/serpapi_light.svg" />
<img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160"
alt="SerpApi" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/coderabbit.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/coderabbit_light.svg" />
<img src="https://pnpm.io/img/users/coderabbit.svg" width="220"
alt="CodeRabbit" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a
href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/stackblitz.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/stackblitz_light.svg" />
<img src="https://pnpm.io/img/users/stackblitz.svg" width="190"
alt="Stackblitz" />
</picture>
</a>
</td>
</tr>
<tr>
<td align="center" valign="middle">
<a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/workleap.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/workleap_light.svg" />
<img src="https://pnpm.io/img/users/workleap.svg" width="190"
alt="Workleap" />
</picture>
</a>
</td>
<td align="center" valign="middle">
<a href="https://nx.dev/?utm_source=pnpm&utm_medium=release_notes"
target="_blank" rel="noopener noreferrer">
<picture>
<source media="(prefers-color-scheme: light)"
srcset="https://pnpm.io/img/users/nx.svg" />
<source media="(prefers-color-scheme: dark)"
srcset="https://pnpm.io/img/users/nx_light.svg" />
<img src="https://pnpm.io/img/users/nx.svg" width="50" alt="Nx" />
</picture>
</a>
</td>
</tr>
</tbody>
</table>
<!-- sponsors end -->
###
[`v11.11.0`](https://redirect.github.com/pnpm/pnpm/blob/HEAD/pnpm11/pnpm/CHANGELOG.md#11110)
[Compare
Source](https://redirect.github.com/pnpm/pnpm/compare/v11.10.0...v11.11.0)
##### Minor Changes
- [`508b8c2`](https://redirect.github.com/pnpm/pnpm/commit
> ✂ **Note**
>
> PR body was truncated to here.
</details>
---
### Configuration
📅 **Schedule**: (in timezone Asia/Shanghai)
- Branch creation
- "before 10am on the first day of the month"
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/oxc-project/oxc-node).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=-->
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>1 parent 2fe7bc9 commit a1cdf18
2 files changed
Lines changed: 125 additions & 121 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
24 | | - | |
| 24 | + | |
25 | 25 | | |
0 commit comments