Skip to content

fix: update auto merge on patch or minor - #280

Merged
notaphplover merged 1 commit into
masterfrom
renovate/auto-merge-on-patch-or-minor
Sep 29, 2026
Merged

notaphplover merged 1 commit into
masterfrom
renovate/auto-merge-on-patch-or-minor

Conversation

@inversify-app

@inversify-app inversify-app Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@apollo/subgraph ^2.15.0 → ^2.15.1 age confidence
@changesets/cli (source) 3.0.2 → 3.0.3 age confidence
@commitlint/cli (source) 21.2.2 → 21.2.3 age confidence
@commitlint/config-conventional (source) 21.2.2 → 21.2.3 age confidence
@commitlint/prompt-cli (source) 21.2.2 → 21.2.3 age confidence
@graphql-codegen/cli (source) ^7.4.0 → ^7.4.3 age confidence
@inversifyjs/foundation-vitest-config 0.2.2 → 0.2.3 age confidence
@inversifyjs/http-core (source) ^5.6.0 → ^5.6.1 age confidence
@inversifyjs/http-express (source) 5.6.0 → 5.6.1 age confidence
@inversifyjs/http-fastify (source) 5.6.0 → 5.6.1 age confidence
@types/node (source) 24.13.3 → 24.13.6 age confidence
eslint (source) 10.10.0 → 10.11.0 age confidence
fastify (source) 5.12.3 → 5.12.5 age confidence
graphql-ws (source) 6.2.1 → 6.3.0 age confidence
knip (source) 6.34.0 → 6.38.0 age confidence
lint-staged 17.5.0 → 17.5.1 age confidence
pnpm (source) 12.3.4 → 12.6.0 age confidence
pnpm (source) 12.3.4 → 12.6.0 age confidence
prettier (source) 3.9.6 → 3.9.9 age confidence
prettier (source) ^3.9.6 → ^3.9.9 age confidence

Release Notes

apollographql/subgraph-js (@​apollo/subgraph)

v2.15.1

Compare Source

Patch Changes
  • #​17 de906c3 Thanks @​marklai1998! - Restore Node.js 22 support. engines.node was set to >=24.0.0 during the graphql-js rewrite without a documented Node 24 runtime requirement, which silently dropped the current Node 22 LTS. CI now tests Node 22 alongside 24 and latest.
changesets/changesets (@​changesets/cli)

v3.0.3

Compare Source

Patch Changes
conventional-changelog/commitlint (@​commitlint/cli)

v21.2.3

Compare Source

Bug Fixes
  • lint: trim trailing whitespace off the message handed to ignore matchers (#​4960) (a6f279b)
conventional-changelog/commitlint (@​commitlint/config-conventional)

v21.2.3

Compare Source

Bug Fixes
  • rules: report the case that matched in case rule failure messages (#​4962) (9f5f7bc)
conventional-changelog/commitlint (@​commitlint/prompt-cli)

v21.2.3

Compare Source

Note: Version bump only for package @​commitlint/prompt-cli

dotansimha/graphql-code-generator (@​graphql-codegen/cli)

v7.4.3

Compare Source

Patch Changes

v7.4.2

Compare Source

Patch Changes
  • #​10956
    cec9c1c
    Thanks @​eddeee888! - Fix dynamically-loaded plugins/presets in ESM
    builds. Previously, ESM used the bare module specifier without resolving it relative to the
    consuming project first, so a plugin only loaded if it happened to be reachable from the CLI
    package's own node_modules. Resolving it the same way the CJS build already does
    (relativeRequire.resolve(mod)) fixes that, but the resolved absolute path also has to be
    converted to a file:// URL (pathToFileURL(...).href) before being passed to import() —
    otherwise, on Windows, the loader misparses a raw path like C:\... as a c: protocol scheme and
    throws ERR_UNSUPPORTED_ESM_URL_SCHEME.

  • #​10966
    3029b60
    Thanks @​eddeee888! - Fix lifecycle hook scripts (e.g.
    hooks: { afterAllFileWrite: ['prettier --write'] } }) failing on Windows when the file paths
    passed to them contain a backslash or other POSIX shell-special character. Hook arguments were
    always quoted using POSIX single-quoting, but child_process.exec() runs through cmd.exe on
    Windows by default, which doesn't strip single quotes — so the hook script received the literal
    quote characters as part of its argument and failed to find the file. Arguments are now quoted
    per-platform: POSIX quoting stays unchanged elsewhere, and Windows arguments are wrapped in double
    quotes only when they actually need it, matching cmd.exe's own convention.

  • #​10959
    7dffaae
    Thanks @​eddeee888! - Fix the CLI reporting success (exit code 0)
    when a generates output's preset can't be resolved. The error was shown in the terminal but
    never counted toward the run's failure state, so allowPartialOutputs: false (the default) never
    took effect for this case.

v7.4.1

Compare Source

Patch Changes
  • #​10935
    fb1a7c4
    Thanks @​eddeee888! - dependencies updates:

  • #​10942
    57c3e7b
    Thanks @​eddeee888! - dependencies updates:

  • #​10942
    57c3e7b
    Thanks @​eddeee888! - Bump @graphql-tools/merge from ^9.0.6 to
    ^9.2.4.

  • #​10935
    fb1a7c4
    Thanks @​eddeee888! - Fix a Windows-specific import() failure on
    absolute paths when loading a schema/document from a .js/.cjs/.mjs file (via
    @graphql-tools/code-file-loader), and when loading modules passed to that loader's own require
    option. Node's dynamic import() rejects raw absolute Windows paths (the drive letter is parsed
    as a URL scheme). Fixed by bumping @graphql-tools/code-file-loader to 8.1.39, which contains
    the upstream fix
    (ardatan/graphql-tools#8421).

  • #​10936
    9521c0c
    Thanks @​eddeee888! - Fix watch mode's generated ignore glob
    patterns using the platform path separator (\ on Windows), which @parcel/watcher never
    matched, so generated output files were watched (and could re-trigger builds) instead of being
    ignored. Ignore patterns are now always forward-slash, as @parcel/watcher expects.

    Also fixes the test suite's TempDir.clean() helper on Windows, where rimraf.sync() rejected
    its own glob-style cleanup pattern as containing illegal path characters; now passes
    { glob: true }. This is a test-only change (tests/utils.ts is not part of the published
    package) included here since it was needed to get the suite green on Windows alongside the
    watch-mode fix.

inversify/monorepo (@​inversifyjs/foundation-vitest-config)

v0.2.3

Compare Source

Patch Changes
  • Updated config with clearMocks value to false
eslint/eslint (eslint)

v10.11.0

Compare Source

Features
  • d136fa4 feat: object-shorthand handle quoted properties for ignoreConstructors (#​21271) (Pavel)
  • 397b3b8 feat: report unsafe labeled continue in no-unsafe-finally rule (#​21316) (electrohyun)
  • d3dd47f feat: only exempt new-cap built-ins that reference the global (#​21290) (sethamus)
Bug Fixes
  • 22b09f5 fix: ignore __proto__ properties in prefer-object-spread (#​21311) (xbinaryx)
  • b684bb1 fix: make TimePass.parse optional in types and docs (#​21313) (ntnyq)
  • 26d11bc fix: don't report __proto__ properties in object-shorthand (#​21310) (xbinaryx)
Documentation
  • 9ecfdc5 docs: note that --cache can serve stale results for cross-file rules (#​21312) (bytedoe)
  • 6c789ff docs: Update README (GitHub Actions Bot)
  • 5997825 docs: clarify preserve-caught-error known limitation (#​21294) (Akinyemi Toluwalase)
Chores
  • 520dd77 perf: Implement fast paths in critical areas (#​21210) (Nicholas C. Zakas)
  • 92086c8 test: update EMFILE error generation for Node.js 26.9.0 compatibility (#​21330) (Francesco Trotta)
  • 9ac7eb6 chore: update github/codeql-action action to v4.38.0 (#​21331) (renovate[bot])
  • 24310e3 chore: update ecosystem plugins (#​21324) (ESLint Bot)
  • 45ad79e ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (#​21318) (dependabot[bot])
  • ac74e37 chore: Add AGENTS.md with AI disclosure requirements (#​21221) (Nicholas C. Zakas)
  • c832660 chore: Upgrade Stylelint to the latest version in docs (#​21245) (Jung Hyeon Jun)
  • f9f88fc chore: update ecosystem plugins (#​21308) (ESLint Bot)
  • fc81076 ci: add more types integration tests (#​20395) (Nitin Kumar)
fastify/fastify (fastify)

v5.12.5

Compare Source

⚠️ Security release
What's Changed

Full Changelog: fastify/fastify@v5.12.4...v5.12.5

v5.12.4

Compare Source

Fixed the fastify.js version mismatch.

Full Changelog: fastify/fastify@v5.12.2...v5.12.4

enisdenjo/graphql-ws (graphql-ws)

v6.3.0

Compare Source

Minor Changes
  • #​691 b5f53cd Thanks @​niukanen1! - Add onPing and onPong server callbacks to ServerOptions, similar to onConnect and onDisconnect. The callbacks receive the connection Context as the first argument and the ping/pong payload as the second, allowing apps to log or react to subprotocol-level pings with access to connection state. The automatic pong reply is preserved when using the server-level onPing callback; the low-level websocket onPing listener still disables the automatic reply for full manual control.
Patch Changes

v6.2.2

Compare Source

Patch Changes
  • #​690 1029314 Thanks @​Haasini-kudala! - Support crossws 0.4 by selecting the GraphQL WebSocket subprotocol during the upgrade handshake. Preserve automatic protocol negotiation in the legacy crossws 0.3 Node and uWebSockets adapters.

  • #​686 536960e Thanks @​cpruijsen! - Fix the CrossWS adapter ignoring socket closes issued from server.opened

    makeHooks only registered the peer in the clients map after server.opened returned, while send/close no-op'd unless the peer was already in that map. A protocol-mismatch close (and any other close from inside opened) was therefore dropped, the WebSocket stayed open, and no ConnectionAck was ever sent because the message handler was never installed.

webpro-nl/knip (knip)

v6.38.0: Release 6.38.0

Compare Source

v6.37.0: Release 6.37.0

Compare Source

  • fix(graphql-codegen): mark near-operation-file outputs as entries, not the documents directory (#​2048) (06a68fc) - thanks @​RobHannay!
  • fix: enable JSX in the config loader (#​1959) (5b21dc9) - thanks @​addielaruee!
  • Match binaries only to their actual dependency providers (c5bdb69)
  • Preserve executable references across package manager commands (54af171)
  • Correct binary provider metadata in Relay fixtures (e67dfcb)
  • Separate shell binary expectations from reporting exemptions (resolve #​2022) (c1d7d75)
  • Respect npx no-install flags before the executable (4237010)
  • Update dependencies (038ea17)
  • Remove npm auth check now that's in release-it (4aaf77c)
  • Fix --format name resolution in the ESLint plugin (#​2046) (1269e98) - thanks @​bytedoe!

v6.36.0: Release 6.36.0

Compare Source

v6.35.1: Release 6.35.1

Compare Source

v6.35.0: Release 6.35.0

Compare Source

lint-staged/lint-staged (lint-staged)

v17.5.1

Compare Source

Patch Changes
  • #​1852 bfcca94 - Fix TypeScript issue TS1254 from defineConfig() by changing the signature from const to a function:

    A 'const' initializer in an ambient context must be a string or numeric literal or literal enum reference.

pnpm/pnpm (pnpm)

v12.6.0: pnpm 12.6

Compare Source

pnpm 12.6.0 ships with automatic dependency deduplication, relocatable node_modules, package.yaml manifest editing, and --save-types support.

Minor Changes
  • autoDedupe deduplicates compatible dependency versions during installation #​7258. Enable it in pnpm-workspace.yaml or use pnpm install --auto-dedupe or pnpm add --auto-dedupe. Frozen installs leave the lockfile unchanged.

  • pnpm install, pnpm run, and pnpm exec on macOS and Linux now reuse a node_modules directory and bin shims that moved or were copied together with their project #​6937. The first command after the move checks the tree and records its new location, so project commands in node_modules/.bin keep working.

  • pnpm add --save-types saves available @types/* packages in devDependencies alongside registry dependencies #​3868. Packages that declare bundled TypeScript types are skipped. Set saveTypes: true in pnpm-workspace.yaml to enable this by default.

  • package.yaml manifests can now be updated by pnpm add, pnpm update, pnpm remove, pnpm pkg, pnpm link, pnpm set-script, and pnpm version #​2008. Existing comments and key order are preserved.

  • Catalog entries can now use the file: and link: protocols #​8642. A relative path or bare path in an entry, such as ./tarballs/foo.tgz, is measured from the directory holding pnpm-workspace.yaml.

  • pnpm tasks status lists running and waiting tasks in each concurrency group, and waiting tasks now take available slots in arrival order with higher priority tasks going first #​15208. If workspaces use different limits for the same group, a later task can take a free slot that earlier tasks cannot use. A package script named tasks takes precedence; use pnpm pm tasks status when that script exists.

  • pnpm cache prune deletes registry metadata cache directories that this version of pnpm can no longer read #​15046. pnpm cache prune --dry-run lists what it would delete without removing anything.

  • macosBackup.excludeModulesDir and macosBackup.excludeStoreDir on macOS can now exclude newly created modules, virtual-store, and package-store directories from Time Machine #​6440. Set either to true in global configuration or using the PNPM_CONFIG_MACOS_BACKUP_EXCLUDE_MODULES_DIR and PNPM_CONFIG_MACOS_BACKUP_EXCLUDE_STORE_DIR environment variables.

  • pnpm add --tilde is now an alias for --save-prefix=~ #​12863. The Yarn -T shorthand is not supported.

  • progress setting and --no-progress option now turn off dependency and download progress lines #​14065. Warnings, lifecycle output, and the dependency summary are still printed.

Patch Changes
Security
  • POSIX bin shims now take cygpath and wslpath from the system default path on Cygwin, MSYS2, and WSL2 so a dependency cannot redirect another package's shim #​14866.

  • pnpm install warnings no longer carry the text of a package's deprecation notice, naming only the deprecated package and version #​15099. A deprecation warning names the newest non-deprecated version when one exists, and control characters and line separators are stripped from package identifiers and warnings.

  • pnpm install and other commands that report configuration warnings now warn when environment variables in project .npmrc credentials are ignored #​15051.

Installing packages
  • pnpm install --frozen-lockfile now succeeds when an optional dependency was unresolvable and skipped by the install that wrote the lockfile #​3960.

  • pnpm install --frozen-lockfile no longer installs dependencies of projects removed from pnpm-workspace.yaml #​15248. Missing local tarballs used only by those projects no longer fail the install.

  • pnpm ci now empties node_modules before installing in a project that declares a clean script #​15276.

  • pnpm install --force now re-imports every package into the virtual store #​15030 and removes obsolete dependency links inside virtual-store packages when their dependencies change #​15039.

  • preinstall script for the root project now runs before dependencies are resolved and linked #​3760.

  • pnpm install now runs pnpm:devPreinstall when the root project uses package.yaml #​15168.

  • pnpm install now enforces the root project's engines.node range when engineStrict is enabled #​3016.

  • pnpm install now uses the running Node.js when devEngines.runtime declares a range without onFail: download #​15230.

  • pnpm install no longer hangs when a git dependency is fetched over SSH and ssh prompts for a passphrase or host key confirmation, running ssh in batch mode instead #​2227.

  • pnpm install now installs git-hosted dependencies without preparing them when their builds are explicitly denied by allowBuilds #​10522.

  • pnpm install now reuses an in-flight tarball download when another resolution of the same archive still needs its package.json #​15037.

  • pnpm install --prod no longer downloads registry packages that only a devDependency reaches #​881.

  • pnpm install --no-runtime --frozen-lockfile with nodeLinker: hoisted no longer fails on repeated runs with a broken lockfile #​15212.

Resolving and linking dependencies
  • pnpm install and pnpm update now resolve a dependency range to the newest matching version that is not deprecated #​15128.

  • pnpm add <pkg> without a version now uses the catalog entry when the workspace already catalogs that package #​14865.

  • pnpm install now links workspace dependencies declared with plain version ranges when excludeLinksFromLockfile and linkWorkspacePackages are enabled #​15133.

  • pnpm install now resolves local tarball dependencies whose absolute file: paths contain .. consistently and skips reinstallation on repeat installs #​15190.

  • pnpm install now installs dependencies when a custom resolver returns a local or git-hosted tarball without a manifest #​15016.

  • pnpm.overrides entries written as a bare path, such as

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@changeset-bot

changeset-bot Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 077428d

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 32fbecd9-2037-481b-9bdd-ab6360a8ac75

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@inversify-app
inversify-app Bot force-pushed the renovate/auto-merge-on-patch-or-minor branch from 66a2c0a to c3fe69a Compare September 21, 2026 02:15
@inversify-app
inversify-app Bot force-pushed the renovate/auto-merge-on-patch-or-minor branch from c3fe69a to 077428d Compare September 28, 2026 02:28
@notaphplover
notaphplover merged commit b6d3f77 into master Sep 29, 2026
7 checks passed
@notaphplover
notaphplover deleted the renovate/auto-merge-on-patch-or-minor branch September 29, 2026 05:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant