dynamodb-parallel-scan
dynamodb-parallel-scan copied to clipboard
chore(deps): update pnpm to v10.20.0
This PR contains the following updates:
| Package | Change | Age | Confidence |
|---|---|---|---|
| pnpm (source) | 10.15.0 -> 10.20.0 |
Release Notes
pnpm/pnpm (pnpm)
v10.20.0
Minor Changes
- Support
--alloption inpnpm --helpto list all commands #8628.
Patch Changes
- When the
latestversion doesn't satisfy the maturity requirement configured byminimumReleaseAge, pick the highest version that is mature enough, even if it has a different major version #10100. createcommand should not verify patch info.- Set
managePackageManagerVersionstofalse, when switching to a different version of pnpm CLI, in order to avoid subsequent switches #10063.
v10.19.0
Minor Changes
-
You can now allow specific versions of dependencies to run postinstall scripts.
onlyBuiltDependenciesnow accepts package names with lists of trusted versions. For example:onlyBuiltDependencies: - [email protected] || 21.6.5 - [email protected]Related PR: #10104.
-
Added support for exact versions in
minimumReleaseAgeExclude#9985.You can now list one or more specific versions that pnpm should allow to install, even if those versions don’t satisfy the maturity requirement set by
minimumReleaseAge. For example:minimumReleaseAge: 1440 minimumReleaseAgeExclude: - [email protected] - [email protected] || 5.102.1
v10.18.3
Patch Changes
- Fix a bug where pnpm would infinitely recurse when using
verifyDepsBeforeInstall: installand pre/post install scripts that called other pnpm scripts #10060. - Fixed scoped registry keys (e.g.,
@scope:registry) being parsed as property paths inpnpm config getwhen--location=projectis used #9362. - Remove pnpm-specific CLI options before passing to npm publish to prevent "Unknown cli config" warnings #9646.
- Fixed EISDIR error when bin field points to a directory #9441.
- Preserve version and hasBin for variations packages #10022.
- Fixed
pnpm config set --location=projectincorrectly handling keys with slashes (auth tokens, registry settings) #9884. - When both
pnpm-workspace.yamland.npmrcexist,pnpm config set --location=projectnow writes topnpm-workspace.yaml(matching read priority) #10072. - Prevent a table width error in
pnpm outdated --long#10040. - Sync bin links after injected dependencies are updated by build scripts. This ensures that binaries created during build processes are properly linked and accessible to consuming projects #10057.
v10.18.2
Patch Changes
pnpm outdated --longshould work #10040.- Replace ndjson with split2. Reduce the bundle size of pnpm CLI #10054.
pnpm dlxshould request the full metadata of packages, whenminimumReleaseAgeis set #9963.- pnpm version switching should work when the pnpm home directory is in a symlinked directory #9715.
- Fix
EPIPEerrors when piping output to other commands #10027.
v10.18.1
Patch Changes
- Don't print a warning, when
--lockfile-onlyis used #8320. pnpm setupcreates a command shim to the pnpm executable. This is needed to be able to runpnpm self-updateon Windows #5700.- When using pnpm catalogs and running a normal
pnpm install, pnpm produced false positive warnings for "skip adding to the default catalog because it already exists". This warning now only prints when usingpnpm add --save-catalogas originally intended.
v10.18.0
Minor Changes
-
Added network performance monitoring to pnpm by implementing warnings for slow network requests, including both metadata fetches and tarball downloads.
Added configuration options for warning thresholds:
fetchWarnTimeoutMsandfetchMinSpeedKiBps. Warning messages are displayed when requests exceed time thresholds or fall below speed minimumsRelated PR: #10025.
Patch Changes
- Retry filesystem operations on EAGAIN errors #9959.
- Outdated command respects
minimumReleaseAgeconfiguration #10030. - Correctly apply the
cleanupUnusedCatalogsconfiguration when removing dependent packages. - Don't fail with a meaningless error when
scriptShellis set tofalse#8748. pnpm dlxshould not fail whenminimumReleaseAgeis set #10037.
v10.17.1
Patch Changes
- When a version specifier cannot be resolved because the versions don't satisfy the
minimumReleaseAgesetting, print this information out in the error message #9974. - Fix
state.jsoncreation path when executingpnpm patchin a workspace project #9733. - When
minimumReleaseAgeis set and thelatesttag is not mature enough, prefer a non-deprecated version as the newlatest#9987.
v10.17.0
Minor Changes
-
The
minimumReleaseAgeExcludesetting now supports patterns. For instance:minimumReleaseAge: 1440 minimumReleaseAgeExclude: - "@​eslint/*"Related PR: #9984.
Patch Changes
- Don't ignore the
minimumReleaseAgecheck, when the package is requested by exact version and the packument is loaded from cache #9978. - When
minimumReleaseAgeis set and the active version under a dist-tag is not mature enough, do not downgrade to a prerelease version in case the original version wasn't a prerelease one #9979.
v10.16.1
Patch Changes
- The full metadata cache should be stored not at the same location as the abbreviated metadata. This fixes a bug where pnpm was loading the abbreviated metadata from cache and couldn't find the "time" field as a result #9963.
- Forcibly disable ANSI color codes when generating patch diff #9914.
v10.16.0
Minor Changes
-
There have been several incidents recently where popular packages were successfully attacked. To reduce the risk of installing a compromised version, we are introducing a new setting that delays the installation of newly released dependencies. In most cases, such attacks are discovered quickly and the malicious versions are removed from the registry within an hour.
The new setting is called
minimumReleaseAge. It specifies the number of minutes that must pass after a version is published before pnpm will install it. For example, settingminimumReleaseAge: 1440ensures that only packages released at least one day ago can be installed.If you set
minimumReleaseAgebut need to disable this restriction for certain dependencies, you can list them under theminimumReleaseAgeExcludesetting. For instance, with the following configuration pnpm will always install the latest version of webpack, regardless of its release time:minimumReleaseAgeExclude: - webpackRelated issue: #9921.
-
Added support for
finders#9946.In the past,
pnpm listandpnpm whycould only search for dependencies by name (and optionally version). For example:pnpm why minimistprints the chain of dependencies to any installed instance of
minimist:verdaccio 5.20.1 ├─┬ handlebars 4.7.7 │ └── minimist 1.2.8 └─┬ mv 2.1.1 └─┬ mkdirp 0.5.6 └── minimist 1.2.8What if we want to search by other properties of a dependency, not just its name? For instance, find all packages that have
react@17in their peer dependencies?This is now possible with "finder functions". Finder functions can be declared in
.pnpmfile.cjsand invoked with the--find-by=<function name>flag when runningpnpm listorpnpm why.Let's say we want to find any dependencies that have React 17 in peer dependencies. We can add this finder to our
.pnpmfile.cjs:module.exports = { finders: { react17: (ctx) => { return ctx.readManifest().peerDependencies?.react === "^17.0.0"; }, }, };Now we can use this finder function by running:
pnpm why --find-by=react17pnpm will find all dependencies that have this React in peer dependencies and print their exact locations in the dependency graph.
@​apollo/client 4.0.4 ├── @​graphql-typed-document-node/core 3.2.0 └── graphql-tag 2.12.6It is also possible to print out some additional information in the output by returning a string from the finder. For example, with the following finder:
module.exports = { finders: { react17: (ctx) => { const manifest = ctx.readManifest(); if (manifest.peerDependencies?.react === "^17.0.0") { return `license: ${manifest.license}`; } return false; }, }, };Every matched package will also print out the license from its
package.json:@​apollo/client 4.0.4 ├── @​graphql-typed-document-node/core 3.2.0 │ license: MIT └── graphql-tag 2.12.6 license: MIT
Patch Changes
- Fix deprecation warning printed when executing pnpm with Node.js 24 #9529.
- Throw an error if
nodeVersionis not set to an exact semver version #9934. pnpm publishshould be able to publish a.tar.gzfile #9927.- Canceling a running process with Ctrl-C should make
pnpm runreturn a non-zero exit code #9626.
v10.15.1
Patch Changes
- Fix
.pnp.cjscrash when importing subpath #9904. - When resolving peer dependencies, pnpm looks whether the peer dependency is present in the root workspace project's dependencies. This change makes it so that the peer dependency is correctly resolved even from aliased npm-hosted dependencies or other types of dependencies #9913.
Configuration
📅 Schedule: Branch creation - At 06:00 PM through 11:59 PM and 12:00 AM through 09:59 AM ( * 18-23,0-9 * * * ) in timezone Europe/Kiev, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
- [ ] If you want to rebase/retry this PR, check this box
This PR was generated by Mend Renovate. View the repository job log.