feat(deps): update all non-major dependencies #205

Merged
ryangr0 merged 3 commits from renovate/all-non-major into development 2026-10-04 08:41:04 +00:00
Member

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@fission-ai/openspec 1.13.2 → 1.14.0 age adoption passing confidence
npm:@fission-ai/openspec 1.13.2 → 1.14.0 age adoption passing confidence
pnpm (source) 12.8.1 → 12.8.2 age adoption passing confidence

📦 Grouped update: confirm the group is operationally coherent before merging.

Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge.

Released is the upstream publish time. — means the datasource reports no release timestamp. Docker Hub is the only Docker registry that reports one, so this preset treats every other Docker registry (ghcr.io, quay.io, Harbor and its proxies, dhi.io) as timestamp-optional: minimumReleaseAge cannot hold those updates back and they are eligible as soon as checks pass. For any other datasource, a missing timestamp holds the update for as long as a soak applies. A real date means the soak is enforced: add this update type's minimumReleaseAge to Released to get the eligibility moment.


Release Notes

Fission-AI/OpenSpec (@​fission-ai/openspec)

v1.14.0

Compare Source

Minor Changes
  • #​883 c879d13 Thanks @​Code-Studio-Team! - Add Code Studio as an init and update target, with project skills and .prompt.md commands under .codestudio/.

  • #​1672 297092c Thanks @​DarkskyX15! - - DeepSeek Harness — openspec init --tools dsh (command-line id dsh) installs the OpenSpec workflow skills into .dsh/skills/ for DeepSeek Harness. It is skills-only (no command adapter or command files): dsh discovers the generated SKILL.md files as its highest-priority project root and surfaces them through its skill catalog, skill tool, and /openspec-* user invocations.

  • #​1961 3c3e6e3 Thanks @​fresh-fx59! - Add GigaCode as a supported --tools target, with skills in .gigacode/skills/openspec-*/SKILL.md and Markdown commands in .gigacode/commands/opsx-<id>.md.

  • #​1211 3de7c72 Thanks @​hu-qi! - Add AtomCode support through openspec init --tools atomcode, with project skills in .atomcode/skills/ and /opsx-<id> commands in .atomcode/commands/. Generated commands declare args: optional and receive $ARGUMENTS when the workflow reads invocation input, and args: none when it does not, so AtomCode runs them straight from the slash menu. Follows the selected workflow profile and delivery mode.

  • #​1082 a7f08b8 Thanks @​Storm-Chaser! - ### New Features

    • GSD support: Install OpenSpec workflows as project skills with openspec init --tools gsd.
  • #​420 070de01 Thanks @​jeanduplessis! - ### New Features

    • Amp support: select amp during init to install OpenSpec workflows as project skills under .agents/skills/.
  • #​2001 56528ea Thanks @​clay-good! - ### New Features

    • Version reports — Run openspec version to inspect the installed version and install type, or add --check and --json for structured update information that tools can consume.
  • #​1352 d1642cb Thanks @​redknox! - Add EasyCode support to init and update, with project-local skills and TOML commands invoked as /opsx:<id>.

  • #​399 ded99e2 Thanks @​ZEDce! - Add openspec list --archived and --all to browse archived changes, including JSON output and sorting. Show archived changes separately in the openspec view dashboard.

  • #​848 5a360c2 Thanks @​Columpio! - ### New Features

    • Veai support: select veai during init to install OpenSpec workflows as project skills under .veai/skills/.
  • #​1439 f197804 Thanks @​jmuchovej! - Expose OpenSpec as a reusable Nix overlay through overlays.default.

  • #​1349 e232080 Thanks @​0x6d6e647a! - Add Grok Build as a skills-only tool. Run openspec init --tools grok to install skills in .grok/skills, then invoke them with /openspec-propose and other skill names. Existing Grok installations are refreshed by openspec update.

  • #​1738 781c7f9 Thanks @​clay-good! - Add Warp support through project-local skills. Select warp during init to install OpenSpec workflows in .warp/skills, invoke them with /openspec-*, and refresh them with openspec update. Skills remain available in every delivery mode.

  • #​807 c21d897 Thanks @​Million-mo! - ### New Features

    • Dashboard workflow status: openspec view now shows each active change's schema and which artifacts are done, ready, blocked, or skipped. Task progress remains visible if a workflow cannot be loaded. Thanks to @​Million-mo for the original contribution in #​807.
Patch Changes
  • #​1977 7728194 Thanks @​clay-good! - The openspec-archive-change skill no longer tells the agent to run the openspec-sync-specs skill when that skill is not installed. It merges the delta specs into the main specs itself instead, as the /opsx:archive command already did (#​1975).

  • #​1722 817cdb6 Thanks @​caseyg! - ### Bug Fixes

    • IBM Bob now appears by its full product name in the tool picker and success messages. Existing bob selections, configuration, skills, and slash-command paths continue to work unchanged.
  • #​1999 bda8556 Thanks @​clay-good! - Guide users through an AI-assisted migration from legacy project.md to config.yaml.

  • #​1997 e70dcc7 Thanks @​clay-good! - Guide proposal authors toward durable, behavior-based capability names.

  • #​2018 81c2f9f Thanks @​clay-good! - ### Bug Fixes

    • Apply edits the right task — openspec instructions apply --json now gives each task its sourcePath and line. The apply workflow checks the checkbox at that location before marking the task done and rechecks progress afterward, so agents update the exact task, even when tasks span several files.
    • Archive stops on a failed spec sync — When the spec sync inside /opsx:archive reports a blocking condition, such as a capability retirement it could not complete, the archive now stops and leaves the change in place instead of archiving it with the main specs unchanged. The same applies to bulk archive.
    • Aligned openspec view progress bars — Active change names up to 48 characters now line up their progress bars instead of pushing each bar out of line.
  • #​1969 9557b43 Thanks @​flcrom! - ### Bug Fixes

    • Let store-only repositories run openspec init at the repo root to install integrations without changing the external-store config or creating local planning directories.
  • #​2004 d4e1c77 Thanks @​clay-good! - Warn that files listed for legacy cleanup are deleted entirely and ask users to back up custom content first. The openspec/AGENTS.md check detects the file by existence alone.

  • #​1995 baad449 Thanks @​clay-good! - Guide agents to keep project documentation and codebase facts out of config.yaml context.

  • #​1978 1872982 Thanks @​clay-good! - The specs instruction now tells agents the 500-character requirement length that openspec validate flags as an informational hint, and how to stay under it when writing new requirements without splitting existing ones. The validator's too-long message now explains how to split a requirement too.

  • #​1972 d28fb49 Thanks @​ryandemelo! - show --json now includes each requirement's and scenario's name, matching the header names archive uses, so JSON readers can cite a requirement without parsing the markdown again (#​1971).

  • #​2014 cf2859a Thanks @​clay-good! - Fix status --json for store-backed changes: actionContext.allowedEditRoots now lists the project on the current path that declares the store alongside the store, so apply no longer stops on a store-only edit scope. When no project on the current path declares the store, the constraint tells the agent to ask which repository to edit instead of naming the store.

  • #​1984 42671df Thanks @​Yi-111-a! - Name the offending index when a rules: list is not an array of strings

    A rule item containing an unquoted ": " is valid-looking YAML but parses as a
    mapping, so the artifact's whole rule set is dropped with only a stderr warning
    naming the artifact. The warning now also names the index and the shape YAML
    produced there, plus the quoting fix, so the bad item can be found without
    bisecting the list by hand.

  • #​1925 88692b3 Thanks @​kevin9327! - ### Bug Fixes

    • Change metadata — Warn when .openspec.yaml contains unrecognized keys such as skip_design. Those keys were stripped with no signal, so status still demanded the design artifact and validate --strict exited 0. status, validate, and archive now name the ignored keys; validate --strict fails.
  • #​2016 cd4f9e4 Thanks @​huiq777! - Make openspec completion uninstall zsh hand .zshrc back exactly as completion install zsh found it. Uninstall stripped every blank line at the top of the file, so a .zshrc that started with blank lines lost them after an install/uninstall round trip, even when the OpenSpec block had been moved further down. Uninstall now drops only the separator line install added, and only when the block sits at the top of the file, matching the bash installer.

pnpm/pnpm (pnpm)

v12.8.2: pnpm 12.8.2

Compare Source

pnpm 12.8.2 fixes a startup crash on Linux ppc64le and UnknownIssuer errors on systems without CA certificates. pnpm run no longer installs before every script on CI when autoDedupe is enabled, and resolution and hoisted installs on macOS are faster.

Patch Changes
Platforms and environments
  • Fixed pnpm crashing on startup on Linux ppc64le #​16380.

  • Fixed installs failing with UnknownIssuer on Linux systems without CA certificates, such as node:24-slim, when NODE_EXTRA_CA_CERTS is set. The extra certificates now extend the bundled CA roots #​16365.

  • pnpm now creates its store operation locks and other per-user lock files in $XDG_RUNTIME_DIR when it points to a directory only the user can write to. Otherwise, pnpm still uses /tmp on Linux and macOS. Sandboxes that block writes to /tmp can point XDG_RUNTIME_DIR at a writable directory #​16390.

  • POSIX bin shims and the pnpm, pn, pnpx, and pnx launchers now run inside a Nix build, where the system default path holds none of the utilities they call. Installing again replaces the shims already in node_modules #​16377.

  • In a project that pins another pnpm version, pnpm now passes a command with an option it does not know to the pinned version. Before, pnpm rejected the option before switching, so pnpm install --auto-dedupe failed with "Unknown option" even though the pinned pnpm supports it #​16353.

Installing and resolving dependencies
  • pnpm install --frozen-lockfile now fails when Cargo.lock does not satisfy a dependency requirement in Cargo.toml. The error names the crate and the version the lockfile holds #​16355.

  • pnpm install returns "Already up to date" again in a workspace with injected workspace dependencies and a shared lockfile. Since 12.7.0 every repeat install in such a workspace ran the full install and copied the injected projects again.

  • With injectWorkspacePackages: true, a fresh pnpm install now records a workspace dependency as link: when its injected copy differs from the project only by an optional peer that peer-dependent dedupe merges. It was recorded as a peer-suffixed file: copy #​16354.

  • pnpm dedupe --check now passes right after pnpm dedupe when deduplication merges variants of a package that differ only in their peers. A lockfile key whose peer suffix named a merged variant now names the variant that replaced it #​16356.

  • When minimumReleaseAge hides the version that latest points to, pnpm now falls back to a prerelease of the same major before a stable version of an older major. A stable version of the same major is still preferred. Before, while a new 1.0.0 was too new, latest fell back to an old 0.0.1 even though 1.0.0-beta.4 had been latest until then #​16388.

  • Git-hosted dependencies now respect pmOnFail. If it is set to anything other than download, a git-hosted dependency that pins a pnpm version is prepared by the running pnpm, and pnpm does not download the pinned version #​16376.

  • pnpmfile hooks such as readPackage now run once for a dependency that several packages request at the same time. They could run twice for it before.

  • childConcurrency now defaults to 5, the documented value. It used to be capped at 4 and to follow the host's CPU count.

Running scripts
  • pnpm run and pnpm exec no longer install dependencies before every script on CI when autoDedupe is enabled. pnpm install --frozen-lockfile now keeps the deduplication record left by an earlier install #​16374.

  • On macOS and Linux, lifecycle scripts and pnpm run now always get PATH from the PATH variable. When the environment also held a Path variable, a script sometimes got Path's value, and failed with node: not found #​16308.

  • pnpm run now exits after a SIGTERM in a container where pnpm is PID 1 and the script runs pnpm again, as "start": "pnpm serve" does. Since 12.6.0 it kept waiting after the script had shut down, until the container runtime killed it.

Other commands and settings
  • pnpm config get globalShims, pnpm shim list, and global installs no longer read globalShims from a project's pnpm-workspace.yaml. Only the global config file, the pnpm home's own pnpm-workspace.yaml, and PNPM_CONFIG_GLOBAL_SHIMS set it, so a repository cannot choose which globally installed packages get project-aware shims.

  • pnpm config set --location=project refuses a machine-level setting such as stateDir or scope with ERR_PNPM_CONFIG_SET_NOT_A_PROJECT_SETTING, which names where the setting belongs. pnpm config delete still clears such a key from a project's pnpm-workspace.yaml.

  • pnpm deploy no longer fails with ERR_PNPM_DEPLOY_AMBIGUOUS_PEER in a workspace with injectWorkspacePackages: true when a workspace package lists its peer dependency as a dev dependency too #​16375.

  • pnpm deploy no longer copies the workspace root's packageManager and devEngines.packageManager fields into the deployed package.json #​16403.

  • pnpm publish now includes bare README files and README files with Markdown extensions such as readme.markdown in registry metadata #​12704.

  • pnpm store prune now removes the packages that only expired pnpm dlx cache entries used. They were left in the store until the next pnpm store prune #​16383.

Performance
  • Sped up dependency resolution in large workspaces, and when many dependencies request different ranges of the same package. Resolution also uses less memory.

  • Sped up pnpm install with nodeLinker: hoisted on macOS when the lockfile is re-resolved, such as with autoDedupe enabled #​16397.

  • Sped up extracting package tarballs.

  • pnpm install without --frozen-lockfile is faster on some machines in projects with a pnpm-workspace.yaml. Those installs linked with one worker thread per core, half of what a frozen install uses.

  • On Windows, warm pnpm install --frozen-lockfile runs are 4-5% faster on 4- and 8-core machines. pnpm now links with one worker thread per core on Windows, between 4 and 16. This changes frozen installs and installs in projects without a pnpm-workspace.yaml on machines with 3 to 15 cores.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Adoption](https://docs.renovatebot.com/merge-confidence/) | [Passing](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---|---|---| | [@fission-ai/openspec](https://github.com/Fission-AI/OpenSpec) | [`1.13.2` → `1.14.0`](https://renovatebot.com/diffs/npm/@fission-ai%2fopenspec/1.13.2/1.14.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@fission-ai%2fopenspec/1.14.0?slim=true) | ![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/@fission-ai%2fopenspec/1.14.0?slim=true) | ![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/@fission-ai%2fopenspec/1.13.2/1.14.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@fission-ai%2fopenspec/1.13.2/1.14.0?slim=true) | | [npm:@fission-ai/openspec](https://github.com/Fission-AI/OpenSpec) | `1.13.2` → `1.14.0` | ![age](https://developer.mend.io/api/mc/badges/age/npm/@fission-ai%2fopenspec/1.14.0?slim=true) | ![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/@fission-ai%2fopenspec/1.14.0?slim=true) | ![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/@fission-ai%2fopenspec/1.13.2/1.14.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@fission-ai%2fopenspec/1.13.2/1.14.0?slim=true) | | [pnpm](https://github.com/pnpm/pnpm/tree/main/pnpm) ([source](https://github.com/pnpm/pnpm/tree/HEAD/pnpm/npm/pnpm)) | [`12.8.1` → `12.8.2`](https://renovatebot.com/diffs/npm/pnpm/12.8.1/12.8.2) | ![age](https://developer.mend.io/api/mc/badges/age/npm/pnpm/12.8.2?slim=true) | ![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/pnpm/12.8.2?slim=true) | ![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/pnpm/12.8.1/12.8.2?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/pnpm/12.8.1/12.8.2?slim=true) | 📦 **Grouped update**: confirm the group is operationally coherent before merging. Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge. `Released` is the upstream publish time. `—` means the datasource reports no release timestamp. Docker Hub is the only Docker registry that reports one, so this preset treats every other Docker registry (ghcr.io, quay.io, Harbor and its proxies, dhi.io) as `timestamp-optional`: `minimumReleaseAge` cannot hold those updates back and they are eligible as soon as checks pass. For any other datasource, a missing timestamp holds the update for as long as a soak applies. A real date means the soak is enforced: add this update type's `minimumReleaseAge` to `Released` to get the eligibility moment. --- ### Release Notes <details> <summary>Fission-AI/OpenSpec (@&#8203;fission-ai/openspec)</summary> ### [`v1.14.0`](https://github.com/Fission-AI/OpenSpec/blob/HEAD/CHANGELOG.md#1140) [Compare Source](https://github.com/Fission-AI/OpenSpec/compare/@fission-ai/openspec@1.13.2...@fission-ai/openspec@1.14.0) ##### Minor Changes - [#&#8203;883](https://github.com/Fission-AI/OpenSpec/pull/883) [`c879d13`](https://github.com/Fission-AI/OpenSpec/commit/c879d13d5f5d045c532a08523316d2d74f2db99a) Thanks [@&#8203;Code-Studio-Team](https://github.com/Code-Studio-Team)! - Add Code Studio as an `init` and `update` target, with project skills and `.prompt.md` commands under `.codestudio/`. - [#&#8203;1672](https://github.com/Fission-AI/OpenSpec/pull/1672) [`297092c`](https://github.com/Fission-AI/OpenSpec/commit/297092cb25d9831a408d2ce9bfd55daec1431b74) Thanks [@&#8203;DarkskyX15](https://github.com/DarkskyX15)! - - **DeepSeek Harness** — `openspec init --tools dsh` (command-line id `dsh`) installs the OpenSpec workflow skills into `.dsh/skills/` for DeepSeek Harness. It is skills-only (no command adapter or command files): dsh discovers the generated `SKILL.md` files as its highest-priority project root and surfaces them through its skill catalog, `skill` tool, and `/openspec-*` user invocations. - [#&#8203;1961](https://github.com/Fission-AI/OpenSpec/pull/1961) [`3c3e6e3`](https://github.com/Fission-AI/OpenSpec/commit/3c3e6e3d423625ffe554ff050c09bb530f17dc5e) Thanks [@&#8203;fresh-fx59](https://github.com/fresh-fx59)! - Add GigaCode as a supported `--tools` target, with skills in `.gigacode/skills/openspec-*/SKILL.md` and Markdown commands in `.gigacode/commands/opsx-<id>.md`. - [#&#8203;1211](https://github.com/Fission-AI/OpenSpec/pull/1211) [`3de7c72`](https://github.com/Fission-AI/OpenSpec/commit/3de7c72c267c40ff89809d2ae08b7bf6ac6faf8c) Thanks [@&#8203;hu-qi](https://github.com/hu-qi)! - Add AtomCode support through `openspec init --tools atomcode`, with project skills in `.atomcode/skills/` and `/opsx-<id>` commands in `.atomcode/commands/`. Generated commands declare `args: optional` and receive `$ARGUMENTS` when the workflow reads invocation input, and `args: none` when it does not, so AtomCode runs them straight from the slash menu. Follows the selected workflow profile and delivery mode. - [#&#8203;1082](https://github.com/Fission-AI/OpenSpec/pull/1082) [`a7f08b8`](https://github.com/Fission-AI/OpenSpec/commit/a7f08b8a462db5eeddae4e0b03f427987e3806a2) Thanks [@&#8203;Storm-Chaser](https://github.com/Storm-Chaser)! - ### New Features - **GSD support**: Install OpenSpec workflows as project skills with `openspec init --tools gsd`. - [#&#8203;420](https://github.com/Fission-AI/OpenSpec/pull/420) [`070de01`](https://github.com/Fission-AI/OpenSpec/commit/070de01dfac4ea343747fbd37b9bb9e77acdf7d0) Thanks [@&#8203;jeanduplessis](https://github.com/jeanduplessis)! - ### New Features - **Amp support**: select `amp` during init to install OpenSpec workflows as project skills under `.agents/skills/`. - [#&#8203;2001](https://github.com/Fission-AI/OpenSpec/pull/2001) [`56528ea`](https://github.com/Fission-AI/OpenSpec/commit/56528ea454a926159d05eb7c9ec1b687d7544b56) Thanks [@&#8203;clay-good](https://github.com/clay-good)! - ### New Features - **Version reports** — Run `openspec version` to inspect the installed version and install type, or add `--check` and `--json` for structured update information that tools can consume. - [#&#8203;1352](https://github.com/Fission-AI/OpenSpec/pull/1352) [`d1642cb`](https://github.com/Fission-AI/OpenSpec/commit/d1642cb58cb4ce2cda0a140cf2322aded53f4e46) Thanks [@&#8203;redknox](https://github.com/redknox)! - Add EasyCode support to init and update, with project-local skills and TOML commands invoked as `/opsx:<id>`. - [#&#8203;399](https://github.com/Fission-AI/OpenSpec/pull/399) [`ded99e2`](https://github.com/Fission-AI/OpenSpec/commit/ded99e27de71c32647ae7fc2f51112219420b5d5) Thanks [@&#8203;ZEDce](https://github.com/ZEDce)! - Add `openspec list --archived` and `--all` to browse archived changes, including JSON output and sorting. Show archived changes separately in the `openspec view` dashboard. - [#&#8203;848](https://github.com/Fission-AI/OpenSpec/pull/848) [`5a360c2`](https://github.com/Fission-AI/OpenSpec/commit/5a360c2088ad3094a092c34993eab97b43c25124) Thanks [@&#8203;Columpio](https://github.com/Columpio)! - ### New Features - **Veai support**: select `veai` during init to install OpenSpec workflows as project skills under `.veai/skills/`. - [#&#8203;1439](https://github.com/Fission-AI/OpenSpec/pull/1439) [`f197804`](https://github.com/Fission-AI/OpenSpec/commit/f197804a38057eee2272952b74d89884a9d3b7a4) Thanks [@&#8203;jmuchovej](https://github.com/jmuchovej)! - Expose OpenSpec as a reusable Nix overlay through `overlays.default`. - [#&#8203;1349](https://github.com/Fission-AI/OpenSpec/pull/1349) [`e232080`](https://github.com/Fission-AI/OpenSpec/commit/e232080d0943bd535388bdc2304b3301f1496226) Thanks [@&#8203;0x6d6e647a](https://github.com/0x6d6e647a)! - Add Grok Build as a skills-only tool. Run `openspec init --tools grok` to install skills in `.grok/skills`, then invoke them with `/openspec-propose` and other skill names. Existing Grok installations are refreshed by `openspec update`. - [#&#8203;1738](https://github.com/Fission-AI/OpenSpec/pull/1738) [`781c7f9`](https://github.com/Fission-AI/OpenSpec/commit/781c7f9447b4eeb6fdc69fa745ff46f6168f3edf) Thanks [@&#8203;clay-good](https://github.com/clay-good)! - Add Warp support through project-local skills. Select `warp` during init to install OpenSpec workflows in `.warp/skills`, invoke them with `/openspec-*`, and refresh them with `openspec update`. Skills remain available in every delivery mode. - [#&#8203;807](https://github.com/Fission-AI/OpenSpec/pull/807) [`c21d897`](https://github.com/Fission-AI/OpenSpec/commit/c21d897261b5daf0c61c49ccd0862288d4664db4) Thanks [@&#8203;Million-mo](https://github.com/Million-mo)! - ### New Features - **Dashboard workflow status**: `openspec view` now shows each active change's schema and which artifacts are done, ready, blocked, or skipped. Task progress remains visible if a workflow cannot be loaded. Thanks to [@&#8203;Million-mo](https://github.com/Million-mo) for the original contribution in [#&#8203;807](https://github.com/Fission-AI/OpenSpec/issues/807). ##### Patch Changes - [#&#8203;1977](https://github.com/Fission-AI/OpenSpec/pull/1977) [`7728194`](https://github.com/Fission-AI/OpenSpec/commit/772819417a2aa8a90cd50743139f402261628d21) Thanks [@&#8203;clay-good](https://github.com/clay-good)! - The `openspec-archive-change` skill no longer tells the agent to run the `openspec-sync-specs` skill when that skill is not installed. It merges the delta specs into the main specs itself instead, as the `/opsx:archive` command already did ([#&#8203;1975](https://github.com/Fission-AI/OpenSpec/issues/1975)). - [#&#8203;1722](https://github.com/Fission-AI/OpenSpec/pull/1722) [`817cdb6`](https://github.com/Fission-AI/OpenSpec/commit/817cdb64be744d4ee65d1a9922b23edc0c4699b8) Thanks [@&#8203;caseyg](https://github.com/caseyg)! - ### Bug Fixes - IBM Bob now appears by its full product name in the tool picker and success messages. Existing `bob` selections, configuration, skills, and slash-command paths continue to work unchanged. - [#&#8203;1999](https://github.com/Fission-AI/OpenSpec/pull/1999) [`bda8556`](https://github.com/Fission-AI/OpenSpec/commit/bda85565ef974d07c1c202c0ac4b2613241dd184) Thanks [@&#8203;clay-good](https://github.com/clay-good)! - Guide users through an AI-assisted migration from legacy `project.md` to `config.yaml`. - [#&#8203;1997](https://github.com/Fission-AI/OpenSpec/pull/1997) [`e70dcc7`](https://github.com/Fission-AI/OpenSpec/commit/e70dcc7c82a3b100145795d32ea9930dca7b4073) Thanks [@&#8203;clay-good](https://github.com/clay-good)! - Guide proposal authors toward durable, behavior-based capability names. - [#&#8203;2018](https://github.com/Fission-AI/OpenSpec/pull/2018) [`81c2f9f`](https://github.com/Fission-AI/OpenSpec/commit/81c2f9fce30d103bd22377042af1d428453b0bbc) Thanks [@&#8203;clay-good](https://github.com/clay-good)! - ### Bug Fixes - **Apply edits the right task** — `openspec instructions apply --json` now gives each task its `sourcePath` and `line`. The apply workflow checks the checkbox at that location before marking the task done and rechecks progress afterward, so agents update the exact task, even when tasks span several files. - **Archive stops on a failed spec sync** — When the spec sync inside `/opsx:archive` reports a blocking condition, such as a capability retirement it could not complete, the archive now stops and leaves the change in place instead of archiving it with the main specs unchanged. The same applies to bulk archive. - **Aligned `openspec view` progress bars** — Active change names up to 48 characters now line up their progress bars instead of pushing each bar out of line. - [#&#8203;1969](https://github.com/Fission-AI/OpenSpec/pull/1969) [`9557b43`](https://github.com/Fission-AI/OpenSpec/commit/9557b43aaff05af8bd9862c4755f7ac7b7f43cf1) Thanks [@&#8203;flcrom](https://github.com/flcrom)! - ### Bug Fixes - Let store-only repositories run `openspec init` at the repo root to install integrations without changing the external-store config or creating local planning directories. - [#&#8203;2004](https://github.com/Fission-AI/OpenSpec/pull/2004) [`d4e1c77`](https://github.com/Fission-AI/OpenSpec/commit/d4e1c77ebae0bd96a7c649fa35edef997989450a) Thanks [@&#8203;clay-good](https://github.com/clay-good)! - Warn that files listed for legacy cleanup are deleted entirely and ask users to back up custom content first. The `openspec/AGENTS.md` check detects the file by existence alone. - [#&#8203;1995](https://github.com/Fission-AI/OpenSpec/pull/1995) [`baad449`](https://github.com/Fission-AI/OpenSpec/commit/baad4494b48f1497ec2f73a457210c5567176942) Thanks [@&#8203;clay-good](https://github.com/clay-good)! - Guide agents to keep project documentation and codebase facts out of `config.yaml` context. - [#&#8203;1978](https://github.com/Fission-AI/OpenSpec/pull/1978) [`1872982`](https://github.com/Fission-AI/OpenSpec/commit/187298289dc5a7a63df87425151981586cbe5d7e) Thanks [@&#8203;clay-good](https://github.com/clay-good)! - The specs instruction now tells agents the 500-character requirement length that `openspec validate` flags as an informational hint, and how to stay under it when writing new requirements without splitting existing ones. The validator's too-long message now explains how to split a requirement too. - [#&#8203;1972](https://github.com/Fission-AI/OpenSpec/pull/1972) [`d28fb49`](https://github.com/Fission-AI/OpenSpec/commit/d28fb49c1ca901fe19fa443a56ede37ff8b8c61a) Thanks [@&#8203;ryandemelo](https://github.com/ryandemelo)! - `show --json` now includes each requirement's and scenario's `name`, matching the header names archive uses, so JSON readers can cite a requirement without parsing the markdown again ([#&#8203;1971](https://github.com/Fission-AI/OpenSpec/issues/1971)). - [#&#8203;2014](https://github.com/Fission-AI/OpenSpec/pull/2014) [`cf2859a`](https://github.com/Fission-AI/OpenSpec/commit/cf2859a52089dd6dd37f9b3388db90c2ca3f06e7) Thanks [@&#8203;clay-good](https://github.com/clay-good)! - Fix `status --json` for store-backed changes: `actionContext.allowedEditRoots` now lists the project on the current path that declares the store alongside the store, so apply no longer stops on a store-only edit scope. When no project on the current path declares the store, the constraint tells the agent to ask which repository to edit instead of naming the store. - [#&#8203;1984](https://github.com/Fission-AI/OpenSpec/pull/1984) [`42671df`](https://github.com/Fission-AI/OpenSpec/commit/42671df890fab730058fee108a2090e7c1e491b9) Thanks [@&#8203;Yi-111-a](https://github.com/Yi-111-a)! - Name the offending index when a `rules:` list is not an array of strings A rule item containing an unquoted `": "` is valid-looking YAML but parses as a mapping, so the artifact's whole rule set is dropped with only a stderr warning naming the artifact. The warning now also names the index and the shape YAML produced there, plus the quoting fix, so the bad item can be found without bisecting the list by hand. - [#&#8203;1925](https://github.com/Fission-AI/OpenSpec/pull/1925) [`88692b3`](https://github.com/Fission-AI/OpenSpec/commit/88692b3bb42262d30172819936847ed10f42a98f) Thanks [@&#8203;kevin9327](https://github.com/kevin9327)! - ### Bug Fixes - **Change metadata** — Warn when `.openspec.yaml` contains unrecognized keys such as `skip_design`. Those keys were stripped with no signal, so `status` still demanded the design artifact and `validate --strict` exited 0. `status`, `validate`, and `archive` now name the ignored keys; `validate --strict` fails. - [#&#8203;2016](https://github.com/Fission-AI/OpenSpec/pull/2016) [`cd4f9e4`](https://github.com/Fission-AI/OpenSpec/commit/cd4f9e4a5f99e7b48f2c452ef0fa3769db4dde4a) Thanks [@&#8203;huiq777](https://github.com/huiq777)! - Make `openspec completion uninstall zsh` hand `.zshrc` back exactly as `completion install zsh` found it. Uninstall stripped every blank line at the top of the file, so a `.zshrc` that started with blank lines lost them after an install/uninstall round trip, even when the OpenSpec block had been moved further down. Uninstall now drops only the separator line install added, and only when the block sits at the top of the file, matching the bash installer. </details> <details> <summary>pnpm/pnpm (pnpm)</summary> ### [`v12.8.2`](https://github.com/pnpm/pnpm/releases/tag/v12.8.2): pnpm 12.8.2 [Compare Source](https://github.com/pnpm/pnpm/compare/v12.8.1...v12.8.2) pnpm 12.8.2 fixes a startup crash on Linux ppc64le and `UnknownIssuer` errors on systems without CA certificates. `pnpm run` no longer installs before every script on CI when `autoDedupe` is enabled, and resolution and hoisted installs on macOS are faster. ##### Patch Changes ##### Platforms and environments - Fixed pnpm crashing on startup on Linux ppc64le [#&#8203;16380](https://github.com/pnpm/pnpm/issues/16380). - Fixed installs failing with `UnknownIssuer` on Linux systems without CA certificates, such as `node:24-slim`, when `NODE_EXTRA_CA_CERTS` is set. The extra certificates now extend the bundled CA roots [#&#8203;16365](https://github.com/pnpm/pnpm/issues/16365). - pnpm now creates its store operation locks and other per-user lock files in `$XDG_RUNTIME_DIR` when it points to a directory only the user can write to. Otherwise, pnpm still uses `/tmp` on Linux and macOS. Sandboxes that block writes to `/tmp` can point `XDG_RUNTIME_DIR` at a writable directory [#&#8203;16390](https://github.com/pnpm/pnpm/issues/16390). - POSIX bin shims and the `pnpm`, `pn`, `pnpx`, and `pnx` launchers now run inside a Nix build, where the system default path holds none of the utilities they call. Installing again replaces the shims already in `node_modules` [#&#8203;16377](https://github.com/pnpm/pnpm/issues/16377). - In a project that pins another pnpm version, pnpm now passes a command with an option it does not know to the pinned version. Before, pnpm rejected the option before switching, so `pnpm install --auto-dedupe` failed with "Unknown option" even though the pinned pnpm supports it [#&#8203;16353](https://github.com/pnpm/pnpm/issues/16353). ##### Installing and resolving dependencies - `pnpm install --frozen-lockfile` now fails when `Cargo.lock` does not satisfy a dependency requirement in `Cargo.toml`. The error names the crate and the version the lockfile holds [#&#8203;16355](https://github.com/pnpm/pnpm/issues/16355). - `pnpm install` returns "Already up to date" again in a workspace with injected workspace dependencies and a shared lockfile. Since 12.7.0 every repeat install in such a workspace ran the full install and copied the injected projects again. - With `injectWorkspacePackages: true`, a fresh `pnpm install` now records a workspace dependency as `link:` when its injected copy differs from the project only by an optional peer that peer-dependent dedupe merges. It was recorded as a peer-suffixed `file:` copy [#&#8203;16354](https://github.com/pnpm/pnpm/issues/16354). - `pnpm dedupe --check` now passes right after `pnpm dedupe` when deduplication merges variants of a package that differ only in their peers. A lockfile key whose peer suffix named a merged variant now names the variant that replaced it [#&#8203;16356](https://github.com/pnpm/pnpm/issues/16356). - When `minimumReleaseAge` hides the version that `latest` points to, pnpm now falls back to a prerelease of the same major before a stable version of an older major. A stable version of the same major is still preferred. Before, while a new `1.0.0` was too new, `latest` fell back to an old `0.0.1` even though `1.0.0-beta.4` had been `latest` until then [#&#8203;16388](https://github.com/pnpm/pnpm/issues/16388). - Git-hosted dependencies now respect `pmOnFail`. If it is set to anything other than `download`, a git-hosted dependency that pins a pnpm version is prepared by the running pnpm, and pnpm does not download the pinned version [#&#8203;16376](https://github.com/pnpm/pnpm/issues/16376). - pnpmfile hooks such as `readPackage` now run once for a dependency that several packages request at the same time. They could run twice for it before. - `childConcurrency` now defaults to 5, the documented value. It used to be capped at 4 and to follow the host's CPU count. ##### Running scripts - `pnpm run` and `pnpm exec` no longer install dependencies before every script on CI when `autoDedupe` is enabled. `pnpm install --frozen-lockfile` now keeps the deduplication record left by an earlier install [#&#8203;16374](https://github.com/pnpm/pnpm/issues/16374). - On macOS and Linux, lifecycle scripts and `pnpm run` now always get `PATH` from the `PATH` variable. When the environment also held a `Path` variable, a script sometimes got `Path`'s value, and failed with `node: not found` [#&#8203;16308](https://github.com/pnpm/pnpm/issues/16308). - `pnpm run` now exits after a `SIGTERM` in a container where pnpm is PID 1 and the script runs pnpm again, as `"start": "pnpm serve"` does. Since 12.6.0 it kept waiting after the script had shut down, until the container runtime killed it. ##### Other commands and settings - `pnpm config get globalShims`, `pnpm shim list`, and global installs no longer read `globalShims` from a project's `pnpm-workspace.yaml`. Only the global config file, the pnpm home's own `pnpm-workspace.yaml`, and `PNPM_CONFIG_GLOBAL_SHIMS` set it, so a repository cannot choose which globally installed packages get project-aware shims. - `pnpm config set --location=project` refuses a machine-level setting such as `stateDir` or `scope` with `ERR_PNPM_CONFIG_SET_NOT_A_PROJECT_SETTING`, which names where the setting belongs. `pnpm config delete` still clears such a key from a project's `pnpm-workspace.yaml`. - `pnpm deploy` no longer fails with `ERR_PNPM_DEPLOY_AMBIGUOUS_PEER` in a workspace with `injectWorkspacePackages: true` when a workspace package lists its peer dependency as a dev dependency too [#&#8203;16375](https://github.com/pnpm/pnpm/issues/16375). - `pnpm deploy` no longer copies the workspace root's `packageManager` and `devEngines.packageManager` fields into the deployed `package.json` [#&#8203;16403](https://github.com/pnpm/pnpm/issues/16403). - `pnpm publish` now includes bare `README` files and README files with Markdown extensions such as `readme.markdown` in registry metadata [#&#8203;12704](https://github.com/pnpm/pnpm/issues/12704). - `pnpm store prune` now removes the packages that only expired `pnpm dlx` cache entries used. They were left in the store until the next `pnpm store prune` [#&#8203;16383](https://github.com/pnpm/pnpm/discussions/16383). ##### Performance - Sped up dependency resolution in large workspaces, and when many dependencies request different ranges of the same package. Resolution also uses less memory. - Sped up `pnpm install` with `nodeLinker: hoisted` on macOS when the lockfile is re-resolved, such as with `autoDedupe` enabled [#&#8203;16397](https://github.com/pnpm/pnpm/issues/16397). - Sped up extracting package tarballs. - `pnpm install` without `--frozen-lockfile` is faster on some machines in projects with a `pnpm-workspace.yaml`. Those installs linked with one worker thread per core, half of what a frozen install uses. - On Windows, warm `pnpm install --frozen-lockfile` runs are 4-5% faster on 4- and 8-core machines. pnpm now links with one worker thread per core on Windows, between 4 and 16. This changes frozen installs and installs in projects without a `pnpm-workspace.yaml` on machines with 3 to 15 cores. <!-- sponsors --> #### Platinum Sponsors <table> <tbody> <tr> <td align="center" valign="middle"> <a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a> </td> <td align="center" valign="middle"> <a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/openai_dark.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/openai_light.svg" /> <img src="https://pnpm.io/img/users/openai_dark.svg" width="160" alt="OpenAI" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://notion.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/notion.svg" width="80" alt="Notion"></a> </td> </tr> <tr> <td align="center" valign="middle"> <a href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/coderabbit.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/coderabbit_light.svg" /> <img src="https://pnpm.io/img/users/coderabbit.svg" width="220" alt="CodeRabbit" /> </picture> </a> </td> </tr> </tbody> </table> #### Gold Sponsors <table> <tbody> <tr> <td align="center" valign="middle"> <a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/sanity.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/sanity_light.svg" /> <img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/discord.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/discord_light.svg" /> <img src="https://pnpm.io/img/users/discord.svg" width="220" alt="Discord" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a> </td> </tr> <tr> <td align="center" valign="middle"> <a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/serpapi_dark.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/serpapi_light.svg" /> <img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160" alt="SerpApi" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/stackblitz.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/stackblitz_light.svg" /> <img src="https://pnpm.io/img/users/stackblitz.svg" width="190" alt="Stackblitz" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/workleap.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/workleap_light.svg" /> <img src="https://pnpm.io/img/users/workleap.svg" width="190" alt="Workleap" /> </picture> </a> </td> </tr> <tr> <td align="center" valign="middle"> <a href="https://nx.dev/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/nx.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/nx_light.svg" /> <img src="https://pnpm.io/img/users/nx.svg" width="50" alt="Nx" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://latitude.so/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/latitude.svg" width="160" alt="Latitude"></a> </td> </tr> </tbody> </table> <!-- sponsors end --> </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Amsterdam) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzEuMyIsInVwZGF0ZWRJblZlciI6IjQzLjI3MS4zIiwidGFyZ2V0QnJhbmNoIjoiZGV2ZWxvcG1lbnQiLCJsYWJlbHMiOlsiYXV0b21lcmdlIiwiZGVwZW5kZW5jaWVzIiwicmVub3ZhdGUiLCJ0eXBlL21pbm9yIiwidHlwZS9wYXRjaCJdfQ==-->
fix(deps): update pnpm ( 12.8.1 ➔ 12.8.2 )
Some checks failed
renovate/stability-days Updates have met minimum release age requirement
[Workflow] On Pull Request / checks (pull_request) Failing after 41s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 16s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
a78bd86037
renovate force-pushed renovate/all-non-major from a78bd86037
Some checks failed
renovate/stability-days Updates have met minimum release age requirement
[Workflow] On Pull Request / checks (pull_request) Failing after 41s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 16s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
to 1f4738a377
Some checks failed
renovate/stability-days Updates have met minimum release age requirement
renovate/artifacts Artifact file update failure
[Workflow] On Pull Request / checks (pull_request) Failing after 47s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 44s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
2026-10-03 23:01:45 +00:00
Compare
renovate changed title from fix(deps): update pnpm ( 12.8.1 ➔ 12.8.2 ) to feat(deps): update all non-major dependencies 2026-10-03 23:02:24 +00:00
Author
Member

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: mise.lock

[WARN] migrate: mise version 2026.9.17 is required, but you are using 2026.7.7
Run `mise self-update` to update mise
mise ERROR mise version 2026.9.17 is required, but you are using 2026.7.7
Run `mise self-update` to update mise
mise ERROR Version: 2026.7.7 linux-x64 (2026-07-15)
mise ERROR Run with --verbose or MISE_VERBOSE=1 for more information

Command failed: mise lock npm:@fission-ai/openspec
[WARN] migrate: mise version 2026.9.17 is required, but you are using 2026.7.7
Run `mise self-update` to update mise
mise ERROR mise version 2026.9.17 is required, but you are using 2026.7.7
Run `mise self-update` to update mise
mise ERROR Version: 2026.7.7 linux-x64 (2026-07-15)
mise ERROR Run with --verbose or MISE_VERBOSE=1 for more information

### ⚠️ Artifact update problem Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is. ♻ Renovate will retry this branch, including artifacts, only when one of the following happens: - any of the package files in this branch needs updating, or - the branch becomes conflicted, or - you click the rebase/retry checkbox if found above, or - you rename this PR's title to start with "rebase!" to trigger it manually The artifact failure details are included below: ##### File name: mise.lock ``` [WARN] migrate: mise version 2026.9.17 is required, but you are using 2026.7.7 Run `mise self-update` to update mise mise ERROR mise version 2026.9.17 is required, but you are using 2026.7.7 Run `mise self-update` to update mise mise ERROR Version: 2026.7.7 linux-x64 (2026-07-15) mise ERROR Run with --verbose or MISE_VERBOSE=1 for more information Command failed: mise lock npm:@fission-ai/openspec [WARN] migrate: mise version 2026.9.17 is required, but you are using 2026.7.7 Run `mise self-update` to update mise mise ERROR mise version 2026.9.17 is required, but you are using 2026.7.7 Run `mise self-update` to update mise mise ERROR Version: 2026.7.7 linux-x64 (2026-07-15) mise ERROR Run with --verbose or MISE_VERBOSE=1 for more information ```
renovate force-pushed renovate/all-non-major from 1f4738a377
Some checks failed
renovate/stability-days Updates have met minimum release age requirement
renovate/artifacts Artifact file update failure
[Workflow] On Pull Request / checks (pull_request) Failing after 47s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 44s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
to dbf40833cd
Some checks failed
renovate/stability-days Updates have met minimum release age requirement
renovate/artifacts Artifact file update failure
[Workflow] On Pull Request / checks (pull_request) Failing after 40s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 22s
[Workflow] On Pull Request / ploeg-pin (pull_request) Successful in 27s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
2026-10-04 01:01:05 +00:00
Compare
build: lock openspec 1.14.0 in the root mise.lock
Some checks failed
[Workflow] On Pull Request / ploeg-pin (pull_request) Successful in 27s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 15s
[Workflow] On Pull Request / checks (pull_request) Failing after 1m49s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
3c77f568d3
Renovate raised openspec in mise.toml but could not relock: its runner
has mise 2026.7.7, below this repository's min_version 2026.9.17, so
`mise lock` refused and CI's `mise install --locked` failed. Renovate's
npm manager also rewrote the generated 1.13.2 lock directory under
.mise/locks as if it were a package. mise 2026.9.18 relocked openspec
and pruned that stale directory; a cold `mise install --locked` passes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Author
Member

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

### Edited/Blocked Notification Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. ⚠️ **Warning**: custom changes will be lost.
build(site): lock pnpm 12.8.2 in the site's pnpm-lock.yaml
All checks were successful
[Workflow] On Pull Request / checks (pull_request) Successful in 10m1s
[Workflow] On Pull Request / ploeg-pin (pull_request) Successful in 48s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 23s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
c707135ef1
pnpm 12 records the packageManager version in pnpm-lock.yaml. Renovate
raised packageManager to 12.8.2 without relocking, so CI's
`pnpm install --frozen-lockfile` refused the outdated lockfile.
`pnpm install --lockfile-only` with pnpm 12.8.2 changes only pnpm's own
entries.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ryangr0 merged commit 1f27158eff into development 2026-10-04 08:41:04 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/unfold!205
No description provided.