Skip to content

fix(deps): update all non-major dependencies - #795

Merged
alongubkin merged 1 commit into
mainfrom
renovate/alien-370-all-minor-patch
Sep 30, 2026
Merged

alongubkin merged 1 commit into
mainfrom
renovate/alien-370-all-minor-patch

Conversation

@alongubkin

Copy link
Copy Markdown
Member

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@aws-sdk/client-ssm (source) 3.1122.0 → 3.1143.0 age confidence devDependencies minor
@bufbuild/protobuf (source) 2.14.0 → 2.16.0 age confidence dependencies minor
@napi-rs/cli (source) 3.9.0 → 3.10.5 age confidence devDependencies minor
@types/node (source) 24.13.6 → 24.19.0 age confidence devDependencies minor
aws-config 1.11.0 → 1.12.0 age confidence dependencies minor
aws-config 1.11.0 → 1.12.0 age confidence workspace.dependencies minor
aws-sdk-cloudformation 1.124.0 → 1.129.0 age confidence dependencies minor
aws-sigv4 1.5.1 → 1.6.0 age confidence workspace.dependencies minor
aws-smithy-runtime-api 1.15.0 → 1.18.0 age confidence workspace.dependencies minor
aws-smithy-types 1.6.2 → 1.8.1 age confidence workspace.dependencies minor
bon (source) 3.10.0 → 3.10.1 age confidence workspace.dependencies patch
clap 4.6.6 → 4.6.7 age confidence workspace.dependencies patch
docker.io/library/buildpack-deps (source) 26.04 → 26.10 age confidence final minor
ed25519-compact 2.4.2 → 2.6.0 age confidence workspace.dependencies minor
globals 17.10.0 → 17.12.0 age confidence devDependencies minor
indexmap 2.14.1 → 2.14.2 age confidence dev-dependencies patch
indexmap 2.14.1 → 2.14.2 age confidence workspace.dependencies patch
napi 3.12.2 → 3.13.0 age confidence workspace.dependencies minor
napi-build 2.4.1 → 2.5.0 age confidence workspace.dependencies minor
napi-derive 3.6.3 → 3.6.9 age confidence workspace.dependencies patch
open 5.4.3 → 5.4.4 age confidence dependencies patch
openai 7.9.0 → 7.25.0 age confidence devDependencies minor
pnpm (source) 10.34.5 → 10.34.6 age confidence packageManager patch
sec 1.0.0 → 1.1.0 age confidence workspace.dependencies minor
thiserror 2.0.20 → 2.0.21 age confidence workspace.dependencies patch
turbo (source) 2.10.12 → 2.11.5 age confidence devDependencies minor
typescript-eslint (source) 8.67.0 → 8.71.0 age confidence devDependencies minor
uuid 1.26.0 → 1.26.1 age confidence dependencies patch
uuid 1.26.0 → 1.26.1 age confidence workspace.dependencies patch
zod (source) 4.5.2 → 4.6.5 age confidence dependencies minor
zod (source) 4.5.2 → 4.6.5 age confidence devDependencies minor

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

aws/aws-sdk-js-v3 (@​aws-sdk/client-ssm)

v3.1143.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1142.0

Compare Source

Features
  • client-ssm: Add support for sharing SSM documents with organizations and OUs using RAM. (4affe98)

v3.1141.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1140.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1139.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1138.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1137.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1136.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1135.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1134.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1133.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1132.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1131.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1130.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1129.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1128.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1127.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1126.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1125.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1124.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

v3.1123.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-ssm

bufbuild/protobuf-es (@​bufbuild/protobuf)

v2.16.0

Compare Source

What's Changed

New Contributors

Full Changelog: bufbuild/protobuf-es@v2.15.0...v2.16.0

v2.15.0

Compare Source

What's Changed

Full Changelog: bufbuild/protobuf-es@v2.14.1...v2.15.0

v2.14.1

Compare Source

What's Changed

This release deprecates configureTextEncoding() from @bufbuild/protobuf/wire. If you run @bufbuild/protobuf in an environment that does not provide the Text Encoding API, please migrate to a polyfill that installs TextEncoder (with the methods encode and optionally encodeInto) and TextDecoder (with the fatal: true constructor argument and the decode method) on globalThis instead. Please see #​1517 for the rationale.

Full Changelog: bufbuild/protobuf-es@v2.14.0...v2.14.1

napi-rs/napi-rs (@​napi-rs/cli)

v3.10.5

Compare Source

v3.10.4

Compare Source

v3.10.3

Compare Source

v3.10.2

Compare Source

v3.10.1

Compare Source

v3.10.0

Compare Source

v3.9.1

Compare Source

Patch over 3.9.0.

Fixes
  • WASI threads builds on current toolchains (#​3492)
    wasm32-wasip1-threads was failing in two ways: wasi-sdk 34 changed the futex ABI, and Rust nightly started linking crt1-reactor.o itself (duplicate _initialize). The CLI now picks the matching emnapi archive; the build crate stops double-linking _initialize.

  • WASI on Android / Termux (#​3485)
    Generated Node loaders preopened /, which Termux cannot open (UVWASI_EACCES). Android now preopens the current working directory. Other platforms are unchanged.

  • Generated files share one format (#​3501)
    JSON / TOML / YAML, .d.ts, and JS / WASI loaders now use one house style (indent, trailing newline, quotes). Regenerating bindings may produce noisy diffs with no behavior change.

Deps
  • js-yaml 4 → 5 (#​3344) — YAML dump formatting can change; loaded values should not.
Same-day packages
Package Version
@napi-rs/triples 2.1.23
@napi-rs/wasm-runtime 1.2.4
elastio/bon (bon)

v3.10.1

Compare Source

Changed
clap-rs/clap (clap)

v4.6.7

Compare Source

Features
  • (derive) Add #[command(defer = <bool>)] attribute to opt-in to lazy initialisation of subcommands
jedisct1/rust-ed25519-compact (ed25519-compact)

v2.6.0

Compare Source

v2.5.0

Compare Source

sindresorhus/globals (globals)

v17.12.0

Compare Source


v17.11.0

Compare Source


indexmap-rs/indexmap (indexmap)

v2.14.2

Compare Source

  • Fix item hygiene in map and set macros. Previously, an internal const CAP
    could shadow the same name in the caller's namespace.
  • Allow const initialization of empty indexmap_with_default! and
    indexset_with_default!. The hasher may also be omitted if it's inferrable.
Byron/open-rs (open)

v5.4.4

Compare Source

Bug Fixes
  • open Windows paths without wildcard expansion

    Opening a child of a bracket-named directory fails because Start-Process
    resolves parent directories as PowerShell wildcard patterns. The isolated
    Windows regression test reproduced WildcardPatternException for a copied
    executable under "【Tiny Asa】 [77P7V-712MB]\child" before this change.

    Use Test-Path and Invoke-Item with LiteralPath for existing items, retaining
    Start-Process for URLs and application names. These cmdlets also work under
    PowerShell Constrained Language Mode. Share the embedded script between
    Windows and WSL, keep targets in environment data, and stop on launch errors
    to report a nonzero exit status. Preserve the security boundary established
    in fd29861: cmd /c start remains opt-in through the insecure feature. No
    previously removed launcher options are restored.

    The integration test launches only a copy of its own test binary, which
    records its executable path and exits. It checks absolute and relative paths
    with invalid and valid bracket patterns, Unicode, backticks, quotes, shell
    metacharacters, and leading dashes in normal and constrained PowerShell
    sessions, plus failure for a missing executable. It requires neither Explorer
    nor registered document or URL handlers. Adjust the existing fallback
    assertion to also allow the opt-in cmd launcher after Explorer with all
    features enabled.

    Validated locally on Windows with PowerShell 5.1.26100.33438 and rustc 1.97.1:
    cargo test and cargo test --all-features each passed all 19 tests, including
    the behavioral regression. git diff --check passed, and cargo
    package --list includes the embedded script. Test-Path returned false without
    errors for representative https, mailto, and file URLs. Actual GUI folder,
    document, URL handling and WSL interop were not exercised locally.

Commit Statistics
  • 2 commits contributed to the release.
  • 8 days passed between releases.
  • 1 commit was understood as conventional.
  • 1 unique issue was worked on: #​132
Commit Details
view details
  • #​132
    • Open Windows paths without wildcard expansion (ad95c40)
  • Uncategorized
openai/openai-node (openai)

v7.25.0

Compare Source

Features

v7.24.0

Compare Source

Features
Bug Fixes
Chores
Documentation

v7.23.0

Compare Source

Features
Chores

v7.22.0

Compare Source

Features

v7.21.0

Compare Source

Features
Bug Fixes
  • api: preserve model choices and improve request handling (#​2787) (a4a4396)
Chores

v7.20.0

Compare Source

Features
Bug Fixes

v7.19.0

Compare Source

Features
Chores

v7.18.0

Compare Source

Features
Bug Fixes
  • api: validate WebSocket results and preserve header defaults (#​2763) (a7e830b)
Chores

v7.17.0

Compare Source

Features
Bug Fixes
Chores
  • update lint tooling and tailor anti-slop for the SDK (#​2753) (21a03c2)
Documentation
  • examples: preserve split UTF-8 in raw stream consumer (#​2714) (f44152a)

v7.16.0

Compare Source

Features
Bug Fixes
Chores

v7.15.0

Compare Source

Features

v7.14.0

Compare Source

Features
Bug Fixes
  • deps-dev: bump joi from 18.2.3 to 18.2.5 in /ecosystem-tests/vercel-edge (#​2702) (029b805)
  • deps: bump next from 15.5.23 to 15.5.25 in /ecosystem-tests/vercel-edge (#​2703) (e9446db)
  • deps: bump sharp from 0.35.3 to 0.35.4 in /ecosystem-tests/vercel-edge (#​2704) (ca95705)
  • deps: update remaining tooling and fixture patches (#​2712) (bcaabee)

v7.13.0

Compare Source

Features

v7.12.1

Compare Source

Includes the GPT Image 2.5 support from 7.12.0, which was not published to npm.

Features
Bug Fixes
  • ci: run Cloudflare example regressions before release (#​2706) (c5cc31c)

v7.10.0

Compare Source

Features

✂ Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@alongubkin
alongubkin enabled auto-merge (squash) September 30, 2026 06:22
@alongubkin
alongubkin merged commit d941adc into main Sep 30, 2026
25 of 26 checks passed
@alongubkin
alongubkin deleted the renovate/alien-370-all-minor-patch branch September 30, 2026 06:22
@greptile-apps

greptile-apps Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

[High risk] Updates dependencies across the entire codebase.

The PR is not ready to merge because the GCP sandbox Dockerfile change fails the CI image-contract test.

Fix All in CodexFindings

  1. P1 Sandbox Dockerfile fails CI check ▶
Fix with agent prompt
### Issue 1
docker/Dockerfile.alien-sandbox-gcp:19
The Dockerfile now uses `buildpack-deps:26.10`, but its generator still renders `26.04`. CI compares the committed file with the generated output byte-for-byte, so the image-contract test will fail. Update the generator alongside this change.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

This PR updates Rust and JavaScript dependencies, their lockfiles, the pnpm version, and the GCP sandbox base image.

  • The sandbox Dockerfile version bump is out of sync with its generator and fails the CI image-contract test.

Reviews (1) · Last reviewed commit: "fix(deps): update all non-major dependen..."

esac

FROM docker.io/library/buildpack-deps:26.04
FROM docker.io/library/buildpack-deps:26.10

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Sandbox Dockerfile fails CI check The Dockerfile now uses buildpack-deps:26.10, but its generator still renders 26.04. CI compares the committed file with the generated output byte-for-byte, so the image-contract test will fail. Update the generator alongside this change.

Prompt To Fix With AI
This is a comment left during a code review.
Path: docker/Dockerfile.alien-sandbox-gcp
Line: 19

Comment:
**Sandbox Dockerfile fails CI check** The Dockerfile now uses `buildpack-deps:26.10`, but its generator still renders `26.04`. CI compares the committed file with the generated output byte-for-byte, so the image-contract test will fail. Update the generator alongside this change.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Codex

lilienblum added a commit that referenced this pull request Sep 30, 2026
Pull request #795 moved `packageManager` to `pnpm@10.34.6` while the workflows still install `10.34.5`. GitHub merged it about twenty seconds after it opened, and the test jobs then failed in `pnpm/action-setup`.

This reverts that commit. Renovate no longer asks GitHub to auto-merge when the pull request opens. It merges on a later run, after the checks are green. `pnpm` updates are disabled because this token cannot update the version pinned in the workflow.
lilienblum added a commit that referenced this pull request Sep 30, 2026
Reverts the Renovate session's merged changes from #784, #792, #795, and
#796 while preserving unrelated commits.

Merged current main to resolve the conflict with #780. Its sandbox
Dockerfile ignorePaths are retained in the restored renovate.json, so
the unrelated sandbox toolchain exclusions survive the rollback.

Removes the self-hosted runner and its repair scripts and restores the
previous Renovate configuration and repair workflow. Hosted Renovate
remains disabled with `enabled: false`, and the restored repair job is
paused with an explicit false condition.

Keeps the SDK lockfile aligned with its unchanged manifest instead of
restoring the pre-session TypeScript mismatch. Regenerated it with `npm
install --package-lock-only --ignore-scripts --offline --no-audit
--no-fund`; it matches the valid lockfile on main exactly.

Validation:
- Independently replayed all four reverse patches and compared the full
repository tree. Only the automation pause, retained valid SDK lockfile,
and preserved sandbox exclusions differ from that inverse. The complete
diff against current main contains only the eight rollback files.
- SDK `npm ci --ignore-scripts --offline --no-audit --no-fund` and
TypeScript build passed. The clean install and TypeScript build passed
again after merging main with Node 24.21.0 and a 12 GiB heap.
- Workflow syntax validated with actionlint, supplying the existing
Depot runner labels and ignoring the deliberate constant-false pause
warning. `git diff --check` and the commit hooks passed.

All six original review threads have documented dispositions: the SDK
lockfile was regenerated, and the repaired workflow plus hosted bot
remain disabled. The privileged repair trust boundary must be reviewed
before any future re-enablement. GitHub CI and automated reviews must
run against the new head. This PR has not been merged.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant