Conversation
|
93f7efc to
b920e60
Compare
b920e60 to
9af3fbc
Compare
9af3fbc to
ca23315
Compare
package.json
Outdated
| "packageManager": "pnpm@10.28.2", | ||
| "engines": { | ||
| "pnpm": "10.28.2", | ||
| "pnpm": "10.30.0", |
There was a problem hiding this comment.
Bug: The PR description claims to update several dependencies, but these changes are missing from package.json. The packageManager version is also not updated, creating an inconsistency.
Severity: MEDIUM
Suggested Fix
Ensure the dependency versions in package.json match the versions specified in the PR description. Update @base-ui/react, dotenv, react-resizable-panels, and undici. Also, update the packageManager field to pnpm@10.30.0 to match the engines.pnpm version. Finally, run pnpm install to regenerate the pnpm-lock.yaml file.
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: package.json#L143
Potential issue: The pull request description indicates updates for four dependencies
(`@base-ui/react`, `dotenv`, `react-resizable-panels`, `undici`), but these version
changes are not reflected in the `package.json` file. The application will continue to
use the old, un-updated versions of these packages. Additionally, there is a mismatch
between the `engines.pnpm` version, which was updated to `10.30.0`, and the
`packageManager` field, which remains at `10.28.2`. This inconsistency could lead to
issues for developers. The `pnpm-lock.yaml` file also remains unchanged, confirming the
dependencies were not updated.
b219d1b to
5cb6a9e
Compare
| datasource | package | from | to | | ---------- | ------- | ------- | ------- | | npm | pnpm | 10.28.2 | 10.30.2 |
5cb6a9e to
867b93b
Compare
This PR contains the following updates:
10.28.2→10.30.210.30.3Release Notes
pnpm/pnpm (pnpm)
v10.30.2Compare Source
v10.30.1: pnpm 10.30.1Compare Source
Patch Changes
/-/npm/v1/security/audits/quickendpoint as the primary audit endpoint, falling back to/-/npm/v1/security/auditswhen it fails #10649.Platinum Sponsors
Gold Sponsors
v10.30.0: pnpm 10.30Compare Source
Minor Changes
pnpm whynow shows a reverse dependency tree. The searched package appears at the root with its dependents as branches, walking back to workspace roots. This replaces the previous forward-tree output which was noisy and hard to read for deeply nested dependencies.Patch Changes
pnpm whydependency pruning to prefer correctness over memory consumption. Reverted PR: #7122.pnpm whyandpnpm listperformance in workspaces with many importers by sharing the dependency graph and materialization cache across all importers instead of rebuilding them independently for each one #10596.Platinum Sponsors
Gold Sponsors
v10.29.3Compare Source
v10.29.2Compare Source
v10.29.1: pnpm 10.29.1Compare Source
Minor Changes
pnpm dlx/pnpxcommand now supports thecatalog:protocol. Example:pnpm dlx shx@catalog:.auditLevelin thepnpm-workspace.yamlfile #10540.workspace:protocol without version specifier. It is now treated asworkspace:*and resolves to the concrete version during publish #10436.Patch Changes
Fixed
pnpm list --jsonreturning incorrect paths when using global virtual store #10187.Fix
pnpm store pathandpnpm store statususing workspace root for path resolution whenstoreDiris relative #10290.Fixed
pnpm run -rfailing with "No projects matched the filters" when an emptypnpm-workspace.yamlexists #10497.Fixed a bug where
catalogMode: strictwould write the literal string"catalog:"topnpm-workspace.yamlinstead of the resolved version specifier when re-adding an existing catalog dependency #10176.Fixed the documentation URL shown in
pnpm completion --helpto point to the correct page at https://pnpm.io/completion #10281.Skip local
file:protocol dependencies duringpnpm fetch. This fixes an issue wherepnpm fetchwould fail in Docker builds when local directory dependencies were not available #10460.Fixed
pnpm audit --jsonto respect the--audit-levelsetting for both exit code and output filtering #10540.update tar to version 7.5.7 to fix security issue
Updating the version of dependency tar to 7.5.7 because the previous one have a security vulnerability reported here: CVE-2026-24842
Fix
pnpm audit --fixreplacing reference overrides (e.g.$foo) with concrete versions #10325.Fix
shamefullyHoistset viaupdateConfigin.pnpmfile.cjsnot being converted topublicHoistPattern#10271.pnpm helpshould correctly report if the currently running pnpm CLI is bundled with Node.js #10561.Add a warning when the current directory contains the PATH delimiter character. On macOS, folder names containing forward slashes (/) appear as colons (:) at the Unix layer. Since colons are PATH separators in POSIX systems, this breaks PATH injection for
node_modules/.bin, causing binaries to not be found when running commands likepnpm exec#10457.Platinum Sponsors
Gold Sponsors
Configuration
📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) in timezone America/New_York, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.