feat(deps): update all non-major dependencies #205
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "renovate/all-non-major"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
1.13.2→1.14.01.13.2→1.14.012.8.1→12.8.2📦 Grouped update: confirm the group is operationally coherent before merging.
Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge.
Releasedis the upstream publish time.—means the datasource reports no release timestamp. Docker Hub is the only Docker registry that reports one, so this preset treats every other Docker registry (ghcr.io, quay.io, Harbor and its proxies, dhi.io) astimestamp-optional:minimumReleaseAgecannot hold those updates back and they are eligible as soon as checks pass. For any other datasource, a missing timestamp holds the update for as long as a soak applies. A real date means the soak is enforced: add this update type'sminimumReleaseAgetoReleasedto get the eligibility moment.Release Notes
Fission-AI/OpenSpec (@fission-ai/openspec)
v1.14.0Compare Source
Minor Changes
#883
c879d13Thanks @Code-Studio-Team! - Add Code Studio as aninitandupdatetarget, with project skills and.prompt.mdcommands under.codestudio/.#1672
297092cThanks @DarkskyX15! - - DeepSeek Harness —openspec init --tools dsh(command-line iddsh) installs the OpenSpec workflow skills into.dsh/skills/for DeepSeek Harness. It is skills-only (no command adapter or command files): dsh discovers the generatedSKILL.mdfiles as its highest-priority project root and surfaces them through its skill catalog,skilltool, and/openspec-*user invocations.#1961
3c3e6e3Thanks @fresh-fx59! - Add GigaCode as a supported--toolstarget, with skills in.gigacode/skills/openspec-*/SKILL.mdand Markdown commands in.gigacode/commands/opsx-<id>.md.#1211
3de7c72Thanks @hu-qi! - Add AtomCode support throughopenspec init --tools atomcode, with project skills in.atomcode/skills/and/opsx-<id>commands in.atomcode/commands/. Generated commands declareargs: optionaland receive$ARGUMENTSwhen the workflow reads invocation input, andargs: nonewhen it does not, so AtomCode runs them straight from the slash menu. Follows the selected workflow profile and delivery mode.#1082
a7f08b8Thanks @Storm-Chaser! - ### New Featuresopenspec init --tools gsd.#420
070de01Thanks @jeanduplessis! - ### New Featuresampduring init to install OpenSpec workflows as project skills under.agents/skills/.#2001
56528eaThanks @clay-good! - ### New Featuresopenspec versionto inspect the installed version and install type, or add--checkand--jsonfor structured update information that tools can consume.#1352
d1642cbThanks @redknox! - Add EasyCode support to init and update, with project-local skills and TOML commands invoked as/opsx:<id>.#399
ded99e2Thanks @ZEDce! - Addopenspec list --archivedand--allto browse archived changes, including JSON output and sorting. Show archived changes separately in theopenspec viewdashboard.#848
5a360c2Thanks @Columpio! - ### New Featuresveaiduring init to install OpenSpec workflows as project skills under.veai/skills/.#1439
f197804Thanks @jmuchovej! - Expose OpenSpec as a reusable Nix overlay throughoverlays.default.#1349
e232080Thanks @0x6d6e647a! - Add Grok Build as a skills-only tool. Runopenspec init --tools grokto install skills in.grok/skills, then invoke them with/openspec-proposeand other skill names. Existing Grok installations are refreshed byopenspec update.#1738
781c7f9Thanks @clay-good! - Add Warp support through project-local skills. Selectwarpduring init to install OpenSpec workflows in.warp/skills, invoke them with/openspec-*, and refresh them withopenspec update. Skills remain available in every delivery mode.#807
c21d897Thanks @Million-mo! - ### New Featuresopenspec viewnow shows each active change's schema and which artifacts are done, ready, blocked, or skipped. Task progress remains visible if a workflow cannot be loaded. Thanks to @Million-mo for the original contribution in #807.Patch Changes
#1977
7728194Thanks @clay-good! - Theopenspec-archive-changeskill no longer tells the agent to run theopenspec-sync-specsskill when that skill is not installed. It merges the delta specs into the main specs itself instead, as the/opsx:archivecommand already did (#1975).#1722
817cdb6Thanks @caseyg! - ### Bug Fixesbobselections, configuration, skills, and slash-command paths continue to work unchanged.#1999
bda8556Thanks @clay-good! - Guide users through an AI-assisted migration from legacyproject.mdtoconfig.yaml.#1997
e70dcc7Thanks @clay-good! - Guide proposal authors toward durable, behavior-based capability names.#2018
81c2f9fThanks @clay-good! - ### Bug Fixesopenspec instructions apply --jsonnow gives each task itssourcePathandline. The apply workflow checks the checkbox at that location before marking the task done and rechecks progress afterward, so agents update the exact task, even when tasks span several files./opsx:archivereports a blocking condition, such as a capability retirement it could not complete, the archive now stops and leaves the change in place instead of archiving it with the main specs unchanged. The same applies to bulk archive.openspec viewprogress bars — Active change names up to 48 characters now line up their progress bars instead of pushing each bar out of line.#1969
9557b43Thanks @flcrom! - ### Bug Fixesopenspec initat the repo root to install integrations without changing the external-store config or creating local planning directories.#2004
d4e1c77Thanks @clay-good! - Warn that files listed for legacy cleanup are deleted entirely and ask users to back up custom content first. Theopenspec/AGENTS.mdcheck detects the file by existence alone.#1995
baad449Thanks @clay-good! - Guide agents to keep project documentation and codebase facts out ofconfig.yamlcontext.#1978
1872982Thanks @clay-good! - The specs instruction now tells agents the 500-character requirement length thatopenspec validateflags as an informational hint, and how to stay under it when writing new requirements without splitting existing ones. The validator's too-long message now explains how to split a requirement too.#1972
d28fb49Thanks @ryandemelo! -show --jsonnow includes each requirement's and scenario'sname, matching the header names archive uses, so JSON readers can cite a requirement without parsing the markdown again (#1971).#2014
cf2859aThanks @clay-good! - Fixstatus --jsonfor store-backed changes:actionContext.allowedEditRootsnow lists the project on the current path that declares the store alongside the store, so apply no longer stops on a store-only edit scope. When no project on the current path declares the store, the constraint tells the agent to ask which repository to edit instead of naming the store.#1984
42671dfThanks @Yi-111-a! - Name the offending index when arules:list is not an array of stringsA rule item containing an unquoted
": "is valid-looking YAML but parses as amapping, so the artifact's whole rule set is dropped with only a stderr warning
naming the artifact. The warning now also names the index and the shape YAML
produced there, plus the quoting fix, so the bad item can be found without
bisecting the list by hand.
#1925
88692b3Thanks @kevin9327! - ### Bug Fixes.openspec.yamlcontains unrecognized keys such asskip_design. Those keys were stripped with no signal, sostatusstill demanded the design artifact andvalidate --strictexited 0.status,validate, andarchivenow name the ignored keys;validate --strictfails.#2016
cd4f9e4Thanks @huiq777! - Makeopenspec completion uninstall zshhand.zshrcback exactly ascompletion install zshfound it. Uninstall stripped every blank line at the top of the file, so a.zshrcthat started with blank lines lost them after an install/uninstall round trip, even when the OpenSpec block had been moved further down. Uninstall now drops only the separator line install added, and only when the block sits at the top of the file, matching the bash installer.pnpm/pnpm (pnpm)
v12.8.2: pnpm 12.8.2Compare Source
pnpm 12.8.2 fixes a startup crash on Linux ppc64le and
UnknownIssuererrors on systems without CA certificates.pnpm runno longer installs before every script on CI whenautoDedupeis enabled, and resolution and hoisted installs on macOS are faster.Patch Changes
Platforms and environments
Fixed pnpm crashing on startup on Linux ppc64le #16380.
Fixed installs failing with
UnknownIssueron Linux systems without CA certificates, such asnode:24-slim, whenNODE_EXTRA_CA_CERTSis set. The extra certificates now extend the bundled CA roots #16365.pnpm now creates its store operation locks and other per-user lock files in
$XDG_RUNTIME_DIRwhen it points to a directory only the user can write to. Otherwise, pnpm still uses/tmpon Linux and macOS. Sandboxes that block writes to/tmpcan pointXDG_RUNTIME_DIRat a writable directory #16390.POSIX bin shims and the
pnpm,pn,pnpx, andpnxlaunchers now run inside a Nix build, where the system default path holds none of the utilities they call. Installing again replaces the shims already innode_modules#16377.In a project that pins another pnpm version, pnpm now passes a command with an option it does not know to the pinned version. Before, pnpm rejected the option before switching, so
pnpm install --auto-dedupefailed with "Unknown option" even though the pinned pnpm supports it #16353.Installing and resolving dependencies
pnpm install --frozen-lockfilenow fails whenCargo.lockdoes not satisfy a dependency requirement inCargo.toml. The error names the crate and the version the lockfile holds #16355.pnpm installreturns "Already up to date" again in a workspace with injected workspace dependencies and a shared lockfile. Since 12.7.0 every repeat install in such a workspace ran the full install and copied the injected projects again.With
injectWorkspacePackages: true, a freshpnpm installnow records a workspace dependency aslink:when its injected copy differs from the project only by an optional peer that peer-dependent dedupe merges. It was recorded as a peer-suffixedfile:copy #16354.pnpm dedupe --checknow passes right afterpnpm dedupewhen deduplication merges variants of a package that differ only in their peers. A lockfile key whose peer suffix named a merged variant now names the variant that replaced it #16356.When
minimumReleaseAgehides the version thatlatestpoints to, pnpm now falls back to a prerelease of the same major before a stable version of an older major. A stable version of the same major is still preferred. Before, while a new1.0.0was too new,latestfell back to an old0.0.1even though1.0.0-beta.4had beenlatestuntil then #16388.Git-hosted dependencies now respect
pmOnFail. If it is set to anything other thandownload, a git-hosted dependency that pins a pnpm version is prepared by the running pnpm, and pnpm does not download the pinned version #16376.pnpmfile hooks such as
readPackagenow run once for a dependency that several packages request at the same time. They could run twice for it before.childConcurrencynow defaults to 5, the documented value. It used to be capped at 4 and to follow the host's CPU count.Running scripts
pnpm runandpnpm execno longer install dependencies before every script on CI whenautoDedupeis enabled.pnpm install --frozen-lockfilenow keeps the deduplication record left by an earlier install #16374.On macOS and Linux, lifecycle scripts and
pnpm runnow always getPATHfrom thePATHvariable. When the environment also held aPathvariable, a script sometimes gotPath's value, and failed withnode: not found#16308.pnpm runnow exits after aSIGTERMin a container where pnpm is PID 1 and the script runs pnpm again, as"start": "pnpm serve"does. Since 12.6.0 it kept waiting after the script had shut down, until the container runtime killed it.Other commands and settings
pnpm config get globalShims,pnpm shim list, and global installs no longer readglobalShimsfrom a project'spnpm-workspace.yaml. Only the global config file, the pnpm home's ownpnpm-workspace.yaml, andPNPM_CONFIG_GLOBAL_SHIMSset it, so a repository cannot choose which globally installed packages get project-aware shims.pnpm config set --location=projectrefuses a machine-level setting such asstateDirorscopewithERR_PNPM_CONFIG_SET_NOT_A_PROJECT_SETTING, which names where the setting belongs.pnpm config deletestill clears such a key from a project'spnpm-workspace.yaml.pnpm deployno longer fails withERR_PNPM_DEPLOY_AMBIGUOUS_PEERin a workspace withinjectWorkspacePackages: truewhen a workspace package lists its peer dependency as a dev dependency too #16375.pnpm deployno longer copies the workspace root'spackageManageranddevEngines.packageManagerfields into the deployedpackage.json#16403.pnpm publishnow includes bareREADMEfiles and README files with Markdown extensions such asreadme.markdownin registry metadata #12704.pnpm store prunenow removes the packages that only expiredpnpm dlxcache entries used. They were left in the store until the nextpnpm store prune#16383.Performance
Sped up dependency resolution in large workspaces, and when many dependencies request different ranges of the same package. Resolution also uses less memory.
Sped up
pnpm installwithnodeLinker: hoistedon macOS when the lockfile is re-resolved, such as withautoDedupeenabled #16397.Sped up extracting package tarballs.
pnpm installwithout--frozen-lockfileis faster on some machines in projects with apnpm-workspace.yaml. Those installs linked with one worker thread per core, half of what a frozen install uses.On Windows, warm
pnpm install --frozen-lockfileruns are 4-5% faster on 4- and 8-core machines. pnpm now links with one worker thread per core on Windows, between 4 and 16. This changes frozen installs and installs in projects without apnpm-workspace.yamlon machines with 3 to 15 cores.Platinum Sponsors
Gold Sponsors
Configuration
📅 Schedule: (in timezone Europe/Amsterdam)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.
a78bd860371f4738a377fix(deps): update pnpm ( 12.8.1 ➔ 12.8.2 )to feat(deps): update all non-major dependencies⚠️ Artifact update problem
Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.
♻ Renovate will retry this branch, including artifacts, only when one of the following happens:
The artifact failure details are included below:
File name: mise.lock
1f4738a377dbf40833cdEdited/Blocked Notification
Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.
You can manually request rebase by checking the rebase/retry box above.
⚠️ Warning: custom changes will be lost.