Repository navigation
fix(deps): update all non-major dependencies - #795
Merged
Merged
Conversation
|
| esac | ||
|
|
||
| FROM docker.io/library/buildpack-deps:26.04 | ||
| FROM docker.io/library/buildpack-deps:26.10 |
There was a problem hiding this comment.
Sandbox Dockerfile fails CI check The Dockerfile now uses
buildpack-deps:26.10, but its generator still renders 26.04. CI compares the committed file with the generated output byte-for-byte, so the image-contract test will fail. Update the generator alongside this change.
Prompt To Fix With AI
This is a comment left during a code review.
Path: docker/Dockerfile.alien-sandbox-gcp
Line: 19
Comment:
**Sandbox Dockerfile fails CI check** The Dockerfile now uses `buildpack-deps:26.10`, but its generator still renders `26.04`. CI compares the committed file with the generated output byte-for-byte, so the image-contract test will fail. Update the generator alongside this change.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.
lilienblum
added a commit
that referenced
this pull request
Sep 30, 2026
Pull request #795 moved `packageManager` to `pnpm@10.34.6` while the workflows still install `10.34.5`. GitHub merged it about twenty seconds after it opened, and the test jobs then failed in `pnpm/action-setup`. This reverts that commit. Renovate no longer asks GitHub to auto-merge when the pull request opens. It merges on a later run, after the checks are green. `pnpm` updates are disabled because this token cannot update the version pinned in the workflow.
lilienblum
added a commit
that referenced
this pull request
Sep 30, 2026
Reverts the Renovate session's merged changes from #784, #792, #795, and #796 while preserving unrelated commits. Merged current main to resolve the conflict with #780. Its sandbox Dockerfile ignorePaths are retained in the restored renovate.json, so the unrelated sandbox toolchain exclusions survive the rollback. Removes the self-hosted runner and its repair scripts and restores the previous Renovate configuration and repair workflow. Hosted Renovate remains disabled with `enabled: false`, and the restored repair job is paused with an explicit false condition. Keeps the SDK lockfile aligned with its unchanged manifest instead of restoring the pre-session TypeScript mismatch. Regenerated it with `npm install --package-lock-only --ignore-scripts --offline --no-audit --no-fund`; it matches the valid lockfile on main exactly. Validation: - Independently replayed all four reverse patches and compared the full repository tree. Only the automation pause, retained valid SDK lockfile, and preserved sandbox exclusions differ from that inverse. The complete diff against current main contains only the eight rollback files. - SDK `npm ci --ignore-scripts --offline --no-audit --no-fund` and TypeScript build passed. The clean install and TypeScript build passed again after merging main with Node 24.21.0 and a 12 GiB heap. - Workflow syntax validated with actionlint, supplying the existing Depot runner labels and ignoring the deliberate constant-false pause warning. `git diff --check` and the commit hooks passed. All six original review threads have documented dispositions: the SDK lockfile was regenerated, and the repaired workflow plus hosted bot remain disabled. The privileged repair trust boundary must be reviewed before any future re-enablement. GitHub CI and automated reviews must run against the new head. This PR has not been merged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.1122.0→3.1143.02.14.0→2.16.03.9.0→3.10.524.13.6→24.19.01.11.0→1.12.01.11.0→1.12.01.124.0→1.129.01.5.1→1.6.01.15.0→1.18.01.6.2→1.8.13.10.0→3.10.14.6.6→4.6.726.04→26.102.4.2→2.6.017.10.0→17.12.02.14.1→2.14.22.14.1→2.14.23.12.2→3.13.02.4.1→2.5.03.6.3→3.6.95.4.3→5.4.47.9.0→7.25.010.34.5→10.34.61.0.0→1.1.02.0.20→2.0.212.10.12→2.11.58.67.0→8.71.01.26.0→1.26.11.26.0→1.26.14.5.2→4.6.54.5.2→4.6.5Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
aws/aws-sdk-js-v3 (@aws-sdk/client-ssm)
v3.1143.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1142.0Compare Source
Features
v3.1141.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1140.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1139.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1138.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1137.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1136.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1135.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1134.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1133.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1132.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1131.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1130.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1129.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1128.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1127.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1126.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1125.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1124.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
v3.1123.0Compare Source
Note: Version bump only for package @aws-sdk/client-ssm
bufbuild/protobuf-es (@bufbuild/protobuf)
v2.16.0Compare Source
What's Changed
New Contributors
Full Changelog: bufbuild/protobuf-es@v2.15.0...v2.16.0
v2.15.0Compare Source
What's Changed
map_importsto point imports at packages by @anuraaga in #1528Full Changelog: bufbuild/protobuf-es@v2.14.1...v2.15.0
v2.14.1Compare Source
What's Changed
This release deprecates
configureTextEncoding()from@bufbuild/protobuf/wire. If you run@bufbuild/protobufin an environment that does not provide the Text Encoding API, please migrate to a polyfill that installsTextEncoder(with the methodsencodeand optionallyencodeInto) andTextDecoder(with thefatal: trueconstructor argument and thedecodemethod) onglobalThisinstead. Please see #1517 for the rationale.Full Changelog: bufbuild/protobuf-es@v2.14.0...v2.14.1
napi-rs/napi-rs (@napi-rs/cli)
v3.10.5Compare Source
v3.10.4Compare Source
v3.10.3Compare Source
v3.10.2Compare Source
v3.10.1Compare Source
v3.10.0Compare Source
v3.9.1Compare Source
Patch over 3.9.0.
Fixes
WASI threads builds on current toolchains (#3492)
wasm32-wasip1-threadswas failing in two ways: wasi-sdk 34 changed the futex ABI, and Rust nightly started linkingcrt1-reactor.oitself (duplicate_initialize). The CLI now picks the matching emnapi archive; the build crate stops double-linking_initialize.WASI on Android / Termux (#3485)
Generated Node loaders preopened
/, which Termux cannot open (UVWASI_EACCES). Android now preopens the current working directory. Other platforms are unchanged.Generated files share one format (#3501)
JSON / TOML / YAML,
.d.ts, and JS / WASI loaders now use one house style (indent, trailing newline, quotes). Regenerating bindings may produce noisy diffs with no behavior change.Deps
js-yaml4 → 5 (#3344) — YAML dump formatting can change; loaded values should not.Same-day packages
@napi-rs/triples@napi-rs/wasm-runtimeelastio/bon (bon)
v3.10.1Compare Source
Changed
r#prefix from raw identifiers inderive(Debug)(#402). Thanks @MaxFreedomPollard for the contribution!clap-rs/clap (clap)
v4.6.7Compare Source
Features
#[command(defer = <bool>)]attribute to opt-in to lazy initialisation of subcommandsjedisct1/rust-ed25519-compact (ed25519-compact)
v2.6.0Compare Source
v2.5.0Compare Source
sindresorhus/globals (globals)
v17.12.0Compare Source
50a2119__webpack_layer__global (#351)779a11av17.11.0Compare Source
react-nativeglobals (#337)61eafbfindexmap-rs/indexmap (indexmap)
v2.14.2Compare Source
const CAPcould shadow the same name in the caller's namespace.
constinitialization of emptyindexmap_with_default!andindexset_with_default!. The hasher may also be omitted if it's inferrable.Byron/open-rs (open)
v5.4.4Compare Source
Bug Fixes
open Windows paths without wildcard expansion
Opening a child of a bracket-named directory fails because Start-Process
resolves parent directories as PowerShell wildcard patterns. The isolated
Windows regression test reproduced WildcardPatternException for a copied
executable under "【Tiny Asa】 [77P7V-712MB]\child" before this change.
Use Test-Path and Invoke-Item with LiteralPath for existing items, retaining
Start-Process for URLs and application names. These cmdlets also work under
PowerShell Constrained Language Mode. Share the embedded script between
Windows and WSL, keep targets in environment data, and stop on launch errors
to report a nonzero exit status. Preserve the security boundary established
in
fd29861: cmd /c start remains opt-in through the insecure feature. Nopreviously removed launcher options are restored.
The integration test launches only a copy of its own test binary, which
records its executable path and exits. It checks absolute and relative paths
with invalid and valid bracket patterns, Unicode, backticks, quotes, shell
metacharacters, and leading dashes in normal and constrained PowerShell
sessions, plus failure for a missing executable. It requires neither Explorer
nor registered document or URL handlers. Adjust the existing fallback
assertion to also allow the opt-in cmd launcher after Explorer with all
features enabled.
Validated locally on Windows with PowerShell 5.1.26100.33438 and rustc 1.97.1:
cargo test and cargo test --all-features each passed all 19 tests, including
the behavioral regression. git diff --check passed, and cargo
package --list includes the embedded script. Test-Path returned false without
errors for representative https, mailto, and file URLs. Actual GUI folder,
document, URL handling and WSL interop were not exercised locally.
Commit Statistics
Commit Details
view details
ad95c40)45317f8)openai/openai-node (openai)
v7.25.0Compare Source
Features
v7.24.0Compare Source
Features
Bug Fixes
Chores
Documentation
v7.23.0Compare Source
Features
Chores
v7.22.0Compare Source
Features
v7.21.0Compare Source
Features
Bug Fixes
Chores
v7.20.0Compare Source
Features
Bug Fixes
v7.19.0Compare Source
Features
Chores
v7.18.0Compare Source
Features
Bug Fixes
Chores
v7.17.0Compare Source
Features
Bug Fixes
Chores
Documentation
v7.16.0Compare Source
Features
Bug Fixes
Chores
v7.15.0Compare Source
Features
v7.14.0Compare Source
Features
Bug Fixes
v7.13.0Compare Source
Features
v7.12.1Compare Source
Includes the GPT Image 2.5 support from 7.12.0, which was not published to npm.
Features
Bug Fixes
v7.10.0Compare Source
Features
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.