fix: update auto merge on patch or minor - #280
Conversation
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
66a2c0a to
c3fe69a
Compare
c3fe69a to
077428d
Compare
This PR contains the following updates:
^2.15.0→^2.15.13.0.2→3.0.321.2.2→21.2.321.2.2→21.2.321.2.2→21.2.3^7.4.0→^7.4.30.2.2→0.2.3^5.6.0→^5.6.15.6.0→5.6.15.6.0→5.6.124.13.3→24.13.610.10.0→10.11.05.12.3→5.12.56.2.1→6.3.06.34.0→6.38.017.5.0→17.5.112.3.4→12.6.012.3.4→12.6.03.9.6→3.9.9^3.9.6→^3.9.9Release Notes
apollographql/subgraph-js (@apollo/subgraph)
v2.15.1Compare Source
Patch Changes
de906c3Thanks @marklai1998! - Restore Node.js 22 support.engines.nodewas set to>=24.0.0during the graphql-js rewrite without a documented Node 24 runtime requirement, which silently dropped the current Node 22 LTS. CI now tests Node 22 alongside 24 and latest.changesets/changesets (@changesets/cli)
v3.0.3Compare Source
Patch Changes
#2297
3f163daThanks @Andarist! - Fixed semver ranges (such as>=1.0.0 <2.0.0) getting cut off (>=2.0.0) when updating internal dependencies.#2276
ca9d110Thanks @Andarist! - Fixed pnpm 10 compatibility with npm 12 when reading registry information, packing, and publishing packages.Updated dependencies [
3f163da,bfe9050,e522996]:conventional-changelog/commitlint (@commitlint/cli)
v21.2.3Compare Source
Bug Fixes
conventional-changelog/commitlint (@commitlint/config-conventional)
v21.2.3Compare Source
Bug Fixes
conventional-changelog/commitlint (@commitlint/prompt-cli)
v21.2.3Compare Source
Note: Version bump only for package @commitlint/prompt-cli
dotansimha/graphql-code-generator (@graphql-codegen/cli)
v7.4.3Compare Source
Patch Changes
8512e51Thanks @eddeee888! - Add missing --check in CLI --help config
v7.4.2Compare Source
Patch Changes
#10956
cec9c1cThanks @eddeee888! - Fix dynamically-loaded plugins/presets in ESM
builds. Previously, ESM used the bare module specifier without resolving it relative to the
consuming project first, so a plugin only loaded if it happened to be reachable from the CLI
package's own
node_modules. Resolving it the same way the CJS build already does(
relativeRequire.resolve(mod)) fixes that, but the resolved absolute path also has to beconverted to a
file://URL (pathToFileURL(...).href) before being passed toimport()—otherwise, on Windows, the loader misparses a raw path like
C:\...as ac:protocol scheme andthrows
ERR_UNSUPPORTED_ESM_URL_SCHEME.#10966
3029b60Thanks @eddeee888! - Fix lifecycle hook scripts (e.g.
hooks: { afterAllFileWrite: ['prettier --write'] } }) failing on Windows when the file pathspassed to them contain a backslash or other POSIX shell-special character. Hook arguments were
always quoted using POSIX single-quoting, but
child_process.exec()runs throughcmd.exeonWindows by default, which doesn't strip single quotes — so the hook script received the literal
quote characters as part of its argument and failed to find the file. Arguments are now quoted
per-platform: POSIX quoting stays unchanged elsewhere, and Windows arguments are wrapped in double
quotes only when they actually need it, matching
cmd.exe's own convention.#10959
7dffaaeThanks @eddeee888! - Fix the CLI reporting success (exit code
0)when a
generatesoutput'spresetcan't be resolved. The error was shown in the terminal butnever counted toward the run's failure state, so
allowPartialOutputs: false(the default) nevertook effect for this case.
v7.4.1Compare Source
Patch Changes
#10935
fb1a7c4Thanks @eddeee888! - dependencies updates:
@graphql-tools/code-file-loader@^8.1.39↗︎(from
^8.1.28, independencies)#10942
57c3e7bThanks @eddeee888! - dependencies updates:
@graphql-tools/merge@^9.2.4↗︎(from
^9.0.6, independencies)#10942
57c3e7bThanks @eddeee888! - Bump
@graphql-tools/mergefrom^9.0.6to^9.2.4.#10935
fb1a7c4Thanks @eddeee888! - Fix a Windows-specific
import()failure onabsolute paths when loading a schema/document from a
.js/.cjs/.mjsfile (via@graphql-tools/code-file-loader), and when loading modules passed to that loader's ownrequireoption. Node's dynamic
import()rejects raw absolute Windows paths (the drive letter is parsedas a URL scheme). Fixed by bumping
@graphql-tools/code-file-loaderto8.1.39, which containsthe upstream fix
(ardatan/graphql-tools#8421).
#10936
9521c0cThanks @eddeee888! - Fix watch mode's generated
ignoreglobpatterns using the platform path separator (
\on Windows), which@parcel/watchernevermatched, so generated output files were watched (and could re-trigger builds) instead of being
ignored. Ignore patterns are now always forward-slash, as
@parcel/watcherexpects.Also fixes the test suite's
TempDir.clean()helper on Windows, whererimraf.sync()rejectedits own glob-style cleanup pattern as containing illegal path characters; now passes
{ glob: true }. This is a test-only change (tests/utils.tsis not part of the publishedpackage) included here since it was needed to get the suite green on Windows alongside the
watch-mode fix.
inversify/monorepo (@inversifyjs/foundation-vitest-config)
v0.2.3Compare Source
Patch Changes
clearMocksvalue tofalseeslint/eslint (eslint)
v10.11.0Compare Source
Features
d136fa4feat: object-shorthand handle quoted properties forignoreConstructors(#21271) (Pavel)397b3b8feat: report unsafe labeledcontinueinno-unsafe-finallyrule (#21316) (electrohyun)d3dd47ffeat: only exemptnew-capbuilt-ins that reference the global (#21290) (sethamus)Bug Fixes
22b09f5fix: ignore__proto__properties inprefer-object-spread(#21311) (xbinaryx)b684bb1fix: make TimePass.parse optional in types and docs (#21313) (ntnyq)26d11bcfix: don't report__proto__properties inobject-shorthand(#21310) (xbinaryx)Documentation
9ecfdc5docs: note that --cache can serve stale results for cross-file rules (#21312) (bytedoe)6c789ffdocs: Update README (GitHub Actions Bot)5997825docs: clarify preserve-caught-error known limitation (#21294) (Akinyemi Toluwalase)Chores
520dd77perf: Implement fast paths in critical areas (#21210) (Nicholas C. Zakas)92086c8test: updateEMFILEerror generation for Node.js 26.9.0 compatibility (#21330) (Francesco Trotta)9ac7eb6chore: update github/codeql-action action to v4.38.0 (#21331) (renovate[bot])24310e3chore: update ecosystem plugins (#21324) (ESLint Bot)45ad79eci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (#21318) (dependabot[bot])ac74e37chore: Add AGENTS.md with AI disclosure requirements (#21221) (Nicholas C. Zakas)c832660chore: Upgrade Stylelint to the latest version in docs (#21245) (Jung Hyeon Jun)f9f88fcchore: update ecosystem plugins (#21308) (ESLint Bot)fc81076ci: add more types integration tests (#20395) (Nitin Kumar)fastify/fastify (fastify)
v5.12.5Compare Source
What's Changed
Full Changelog: fastify/fastify@v5.12.4...v5.12.5
v5.12.4Compare Source
Fixed the
fastify.jsversion mismatch.Full Changelog: fastify/fastify@v5.12.2...v5.12.4
enisdenjo/graphql-ws (graphql-ws)
v6.3.0Compare Source
Minor Changes
b5f53cdThanks @niukanen1! - AddonPingandonPongserver callbacks toServerOptions, similar toonConnectandonDisconnect. The callbacks receive the connectionContextas the first argument and the ping/pongpayloadas the second, allowing apps to log or react to subprotocol-level pings with access to connection state. The automatic pong reply is preserved when using the server-levelonPingcallback; the low-level websocketonPinglistener still disables the automatic reply for full manual control.Patch Changes
#693
c41433eThanks @smnbbrv! - fix the client leaking memory per operation on long-living connections#695
93c8ebfThanks @zerolxy612! - Allow operation IDs that match properties inherited fromObject.prototype.v6.2.2Compare Source
Patch Changes
#690
1029314Thanks @Haasini-kudala! - Support crossws 0.4 by selecting the GraphQL WebSocket subprotocol during the upgrade handshake. Preserve automatic protocol negotiation in the legacy crossws 0.3 Node and uWebSockets adapters.#686
536960eThanks @cpruijsen! - Fix the CrossWS adapter ignoring socket closes issued fromserver.openedmakeHooksonly registered the peer in the clients map afterserver.openedreturned, whilesend/closeno-op'd unless the peer was already in that map. A protocol-mismatch close (and any other close from insideopened) was therefore dropped, the WebSocket stayed open, and noConnectionAckwas ever sent because the message handler was never installed.webpro-nl/knip (knip)
v6.38.0: Release 6.38.0Compare Source
0c33410)617f70d)260dbb9) - thanks @matchai!argsexample to that doc page (50b271b)e49d3db) - thanks @changbaebang!import-x/*settings in ESLint plugin (#2050) (1a34cf8) - thanks @bytedoe!9b5c5f6) - thanks @giaBaoJS!a149a98) - thanks @matthewnitschke-wk!8b0c850) - thanks @vdavid!8a8805e) - thanks @devYRPauli!584e53f)34dbccf) - thanks @gioboa!11e9450)7b58251)25a380c)v6.37.0: Release 6.37.0Compare Source
06a68fc) - thanks @RobHannay!5b21dc9) - thanks @addielaruee!c5bdb69)54af171)e67dfcb)c1d7d75)4237010)038ea17)4aaf77c)1269e98) - thanks @bytedoe!v6.36.0: Release 6.36.0Compare Source
b5ac0cf) - thanks @igas!23419b4)3c2c1a5) - thanks @gioboa!parserOptions.parserhandling in ESLint plugin (#2028) (c79463c) - thanks @bytedoe!68bbe51) - thanks @thanadolps!30ff756) - thanks @gioboa!adfaf4f) - thanks @gioboa!a05e155)1c26560)d911c18)c1f18d5) - thanks @kenfdev!66e966b)e4fbf46) - thanks @Joehoel!c8df8a2) - thanks @giaBaoJS!import/resolversetting in ESLint plugin (#2041) (a80d386) - thanks @bytedoe!4c67685) - thanks @shoutoutuoadi325!ce387b0) - thanks @giaBaoJS!532dab5) - thanks @anandghegde!84a4943) - thanks @CruseCtrl!3f756a7)43b3f9b)f1e97b9)0188e7d)extendsfiles in eslintrc configs (#2044) (62b5bf5) - thanks @bytedoe!a85eb4e) - thanks @bytedoe!882ba3a) - thanks @gioboa!v6.35.1: Release 6.35.1Compare Source
37b2642) - thanks @WooWan!0d9cf34)2659063)7be11aa)v6.35.0: Release 6.35.0Compare Source
c6497a1) - thanks @gioboa!9ce68ed) - thanks @gioboa!2e7d498) - thanks @devYRPauli!a21f972) - thanks @gioboa!3178940) - thanks @s-h-a-d-o-w!aaab35a) - thanks @gioboa!6c27aab) - thanks @gioboa!a092e40) - thanks @gioboa!pnpm.overridesis read from the root manifest only (f69a7f6)3662c95)90b384d) - thanks @renovate[bot]!16d03f7) - thanks @bytedoe!a4c7a93)cwdif its missing at therootlevel (#2020) (f66c9f1) - thanks @JayaKrishnaNamburu!75d5628) - thanks @gioboa!cyclesissue type/reporter (resolve #2021) (f1e690b)e2bd3fc)1cc979b)db6d891)4afbbcf)lint-staged/lint-staged (lint-staged)
v17.5.1Compare Source
Patch Changes
#1852
bfcca94- Fix TypeScript issueTS1254fromdefineConfig()by changing the signature fromconstto afunction:pnpm/pnpm (pnpm)
v12.6.0: pnpm 12.6Compare Source
pnpm 12.6.0 ships with automatic dependency deduplication, relocatable node_modules, package.yaml manifest editing, and --save-types support.
Minor Changes
autoDedupededuplicates compatible dependency versions during installation #7258. Enable it inpnpm-workspace.yamlor usepnpm install --auto-dedupeorpnpm add --auto-dedupe. Frozen installs leave the lockfile unchanged.pnpm install,pnpm run, andpnpm execon macOS and Linux now reuse anode_modulesdirectory and bin shims that moved or were copied together with their project #6937. The first command after the move checks the tree and records its new location, so project commands innode_modules/.binkeep working.pnpm add --save-typessaves available@types/*packages indevDependenciesalongside registry dependencies #3868. Packages that declare bundled TypeScript types are skipped. SetsaveTypes: trueinpnpm-workspace.yamlto enable this by default.package.yamlmanifests can now be updated bypnpm add,pnpm update,pnpm remove,pnpm pkg,pnpm link,pnpm set-script, andpnpm version#2008. Existing comments and key order are preserved.Catalog entries can now use the
file:andlink:protocols #8642. A relative path or bare path in an entry, such as./tarballs/foo.tgz, is measured from the directory holdingpnpm-workspace.yaml.pnpm tasks statuslists running and waiting tasks in each concurrency group, and waiting tasks now take available slots in arrival order with higherprioritytasks going first #15208. If workspaces use different limits for the same group, a later task can take a free slot that earlier tasks cannot use. A package script namedtaskstakes precedence; usepnpm pm tasks statuswhen that script exists.pnpm cache prunedeletes registry metadata cache directories that this version of pnpm can no longer read #15046.pnpm cache prune --dry-runlists what it would delete without removing anything.macosBackup.excludeModulesDirandmacosBackup.excludeStoreDiron macOS can now exclude newly created modules, virtual-store, and package-store directories from Time Machine #6440. Set either totruein global configuration or using thePNPM_CONFIG_MACOS_BACKUP_EXCLUDE_MODULES_DIRandPNPM_CONFIG_MACOS_BACKUP_EXCLUDE_STORE_DIRenvironment variables.pnpm add --tildeis now an alias for--save-prefix=~#12863. The Yarn-Tshorthand is not supported.progresssetting and--no-progressoption now turn off dependency and download progress lines #14065. Warnings, lifecycle output, and the dependency summary are still printed.Patch Changes
Security
POSIX bin shims now take
cygpathandwslpathfrom the system default path on Cygwin, MSYS2, and WSL2 so a dependency cannot redirect another package's shim #14866.pnpm installwarnings no longer carry the text of a package's deprecation notice, naming only the deprecated package and version #15099. A deprecation warning names the newest non-deprecated version when one exists, and control characters and line separators are stripped from package identifiers and warnings.pnpm installand other commands that report configuration warnings now warn when environment variables in project.npmrccredentials are ignored #15051.Installing packages
pnpm install --frozen-lockfilenow succeeds when an optional dependency was unresolvable and skipped by the install that wrote the lockfile #3960.pnpm install --frozen-lockfileno longer installs dependencies of projects removed frompnpm-workspace.yaml#15248. Missing local tarballs used only by those projects no longer fail the install.pnpm cinow emptiesnode_modulesbefore installing in a project that declares acleanscript #15276.pnpm install --forcenow re-imports every package into the virtual store #15030 and removes obsolete dependency links inside virtual-store packages when their dependencies change #15039.preinstallscript for the root project now runs before dependencies are resolved and linked #3760.pnpm installnow runspnpm:devPreinstallwhen the root project usespackage.yaml#15168.pnpm installnow enforces the root project'sengines.noderange whenengineStrictis enabled #3016.pnpm installnow uses the running Node.js whendevEngines.runtimedeclares a range withoutonFail: download#15230.pnpm installno longer hangs when a git dependency is fetched over SSH and ssh prompts for a passphrase or host key confirmation, running ssh in batch mode instead #2227.pnpm installnow installs git-hosted dependencies without preparing them when their builds are explicitly denied byallowBuilds#10522.pnpm installnow reuses an in-flight tarball download when another resolution of the same archive still needs itspackage.json#15037.pnpm install --prodno longer downloads registry packages that only a devDependency reaches #881.pnpm install --no-runtime --frozen-lockfilewithnodeLinker: hoistedno longer fails on repeated runs with a broken lockfile #15212.Resolving and linking dependencies
pnpm installandpnpm updatenow resolve a dependency range to the newest matching version that is not deprecated #15128.pnpm add <pkg>without a version now uses the catalog entry when the workspace already catalogs that package #14865.pnpm installnow links workspace dependencies declared with plain version ranges whenexcludeLinksFromLockfileandlinkWorkspacePackagesare enabled #15133.pnpm installnow resolves local tarball dependencies whose absolutefile:paths contain..consistently and skips reinstallation on repeat installs #15190.pnpm installnow installs dependencies when a custom resolver returns a local or git-hosted tarball without a manifest #15016.pnpm.overridesentries written as a bare path, such asConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.