Skip to content

fix(deps): pin dependencies - autoclosed #1896

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jun 18, 2025

This PR contains the following updates:

Package Type Update Change
@babel/parser (source) dependencies pin ^7.27.4 -> 7.27.5
@babel/traverse (source) dependencies pin ^7.27.4 -> 7.27.4
@npmcli/agent pnpm.overrides pin ^3.0.0 -> 3.0.0
@npmcli/agent overrides pin ^3.0.0 -> 3.0.0
@npmcli/arborist (source) dependencies pin ^9.1.2 -> 9.1.2
@npmcli/fs pnpm.overrides pin ^4.0.0 -> 4.0.0
@npmcli/fs overrides pin ^4.0.0 -> 4.0.0
abbrev pnpm.overrides pin ^3.0.1 -> 3.0.1
abbrev overrides pin ^3.0.1 -> 3.0.1
actions/checkout action pinDigest -> 11bd719
actions/setup-go action pinDigest -> d35c59a
actions/setup-java action pinDigest -> c5195ef
actions/setup-node action pinDigest -> 49933ea
actions/setup-python action pinDigest -> a26af69
actions/upload-artifact action pinDigest -> ea165f8
ajv (source) dependencies pin ^8.17.1 -> 8.17.1
ajv-formats dependencies pin ^3.0.1 -> 3.0.1
android-actions/setup-android action pinDigest -> 9fc6c4e
babel-plugin-istanbul pnpm.overrides pin ^7.0.0 -> 7.0.0
babel-plugin-istanbul overrides pin ^7.0.0 -> 7.0.0
body-parser optionalDependencies pin ^2.2.0 -> 2.2.0
cacache pnpm.overrides pin ^19.0.1 -> 19.0.1
cacache overrides pin ^19.0.1 -> 19.0.1
cachix/cachix-action action pinDigest -> 18cf96c
cachix/install-nix-action action pinDigest -> 8887e59
camelcase pnpm.overrides pin ^6.3.0 -> 6.3.0
camelcase overrides pin ^6.3.0 -> 6.3.0
cheerio (source) dependencies pin ^1.1.0 -> 1.1.0
chownr pnpm.overrides pin ^3.0.0 -> 3.0.0
chownr overrides pin ^3.0.0 -> 3.0.0
cloudposse/github-action-matrix-outputs-write action pinDigest -> ed06cf3
compression optionalDependencies pin ^1.7.5 -> 1.8.0
connect optionalDependencies pin ^3.7.0 -> 3.7.0
coursier/cache-action action pinDigest -> 4e26158
coursier/setup-action action pinDigest -> 039f736
debug pnpm.overrides pin ^4.4.1 -> 4.4.1
debug overrides pin ^4.4.1 -> 4.4.1
docker/build-push-action action pinDigest -> 2634353
docker/login-action action pinDigest -> 74a5d14
docker/metadata-action action pinDigest -> 902fa8e
docker/setup-buildx-action action pinDigest -> e468171
docker/setup-qemu-action action pinDigest -> 2910929
escape-string-regexp pnpm.overrides pin ^4.0.0 -> 4.0.0
escape-string-regexp overrides pin ^4.0.0 -> 4.0.0
github/codeql-action action pinDigest -> ce28f5b
glob pnpm.overrides pin ^11.0.3 -> 11.0.3
glob overrides pin ^11.0.3 -> 11.0.3
glob dependencies pin ^11.0.3 -> 11.0.3
global-agent dependencies pin ^3.0.0 -> 3.0.0
go uses-with pin 1.23 -> 1.23.10
got dependencies pin ^14.4.7 -> 14.4.7
iconv-lite dependencies pin ^0.6.3 -> 0.6.3
ini pnpm.overrides pin ^5.0.0 -> 5.0.0
ini overrides pin ^5.0.0 -> 5.0.0
int128/docker-manifest-create-action action pinDigest -> 736aaa0
is-stream pnpm.overrides pin ^4.0.1 -> 4.0.1
is-stream overrides pin ^4.0.1 -> 4.0.1
isexe pnpm.overrides pin ^3.1.1 -> 3.1.1
isexe overrides pin ^3.1.1 -> 3.1.1
istanbul-lib-instrument (source) pnpm.overrides pin ^6.0.3 -> 6.0.3
istanbul-lib-instrument (source) overrides pin ^6.0.3 -> 6.0.3
jest (source) devDependencies pin ^30.0.0 -> 30.0.0
json-parse-even-better-errors pnpm.overrides pin ^4.0.0 -> 4.0.0
json-parse-even-better-errors overrides pin ^4.0.0 -> 4.0.0
jsonata (source) optionalDependencies pin ^2.0.6 -> 2.0.6
jwa pnpm.overrides pin ^2.0.1 -> 2.0.1
jwa overrides pin ^2.0.1 -> 2.0.1
jws dependencies pin ^4.0.0 -> 4.0.0
lru-cache pnpm.overrides pin ^11.1.0 -> 11.1.0
lru-cache overrides pin ^11.1.0 -> 11.1.0
minimatch pnpm.overrides pin ^10.0.3 -> 10.0.3
minimatch overrides pin ^10.0.3 -> 10.0.3
minizlib pnpm.overrides pin ^3.0.2 -> 3.0.2
minizlib overrides pin ^3.0.2 -> 3.0.2
mkdirp pnpm.overrides pin ^3.0.1 -> 3.0.1
mkdirp overrides pin ^3.0.1 -> 3.0.1
ms pnpm.overrides pin ^2.1.3 -> 2.1.3
ms overrides pin ^2.1.3 -> 2.1.3
negotiator pnpm.overrides pin ^0.6.4 -> 0.6.4
negotiator overrides pin ^0.6.4 -> 0.6.4
node (source) pin 24 -> 24.2.0
node uses-with pin 24.x -> 24.2.0
node-gyp pnpm.overrides pin ^10.2.0 -> 10.3.1
node-gyp overrides pin ^10.2.0 -> 10.3.1
node-stream-zip dependencies pin ^1.15.0 -> 1.15.0
nopt pnpm.overrides pin ^8.1.0 -> 8.1.0
nopt overrides pin ^8.1.0 -> 8.1.0
on-finished pnpm.overrides pin ^2.4.1 -> 2.4.1
on-finished overrides pin ^2.4.1 -> 2.4.1
oras-project/setup-oras action pinDigest -> 8d34698
oven-sh/setup-bun action pinDigest -> f4d14e0
pacote pnpm.overrides pin ^20.0.0 -> 20.0.0
pacote overrides pin ^20.0.0 -> 20.0.0
pnpm/action-setup action pinDigest -> a7487c7
prebuild pnpm.overrides pin ^13.0.0 -> 13.0.1
prebuild overrides pin ^13.0.0 -> 13.0.1
prettify-xml dependencies pin ^1.2.0 -> 1.2.0
proc-log pnpm.overrides pin ^5.0.0 -> 5.0.0
proc-log overrides pin ^5.0.0 -> 5.0.0
properties-reader dependencies pin ^2.3.0 -> 2.3.0
python uses-with pin 3.12 -> 3.12.11
python uses-with pin 3.11 -> 3.11.13
sbt/setup-sbt action pinDigest -> 6c68d2f
semver pnpm.overrides pin ^7.7.2 -> 7.7.2
semver overrides pin ^7.7.2 -> 7.7.2
semver dependencies pin ^7.7.2 -> 7.7.2
sequelize (source) optionalDependencies pin ^6.37.7 -> 6.37.7
signal-exit pnpm.overrides pin ^4.1.0 -> 4.1.0
signal-exit overrides pin ^4.1.0 -> 4.1.0
softprops/action-gh-release action pinDigest -> 72f2c25
sprintf-js pnpm.overrides pin ^1.1.3 -> 1.1.3
sprintf-js overrides pin ^1.1.3 -> 1.1.3
sqlite3 optionalDependencies pin ^6.0.6 -> 6.0.6
ssri pnpm.overrides pin ^12.0.0 -> 12.0.0
ssri overrides pin ^12.0.0 -> 12.0.0
ssri dependencies pin ^12.0.0 -> 12.0.0
statuses pnpm.overrides pin ^2.0.1 -> 2.0.2
statuses overrides pin ^2.0.1 -> 2.0.2
strip-json-comments pnpm.overrides pin ^3.1.1 -> 3.1.1
strip-json-comments overrides pin ^3.1.1 -> 3.1.1
supports-color pnpm.overrides pin ^8.1.1 -> 8.1.1
supports-color overrides pin ^8.1.1 -> 8.1.1
table dependencies pin ^6.9.0 -> 6.9.0
tar pnpm.overrides pin ^7.4.3 -> 7.4.3
tar overrides pin ^7.4.3 -> 7.4.3
tar dependencies pin ^7.4.3 -> 7.4.3
tar-fs pnpm.overrides pin ^3.0.9 -> 3.0.10
type-fest pnpm.overrides pin ^4.41.0 -> 4.41.0
type-fest overrides pin ^4.41.0 -> 4.41.0
typescript (source) devDependencies pin ^5.8.3 -> 5.8.3
unique-filename (source) pnpm.overrides pin ^4.0.0 -> 4.0.0
unique-filename (source) overrides pin ^4.0.0 -> 4.0.0
unique-slug pnpm.overrides pin ^5.0.0 -> 5.0.0
unique-slug overrides pin ^5.0.0 -> 5.0.0
uuid pnpm.overrides pin ^11.1.0 -> 11.1.0
uuid overrides pin ^11.1.0 -> 11.1.0
uuid dependencies pin ^11.1.0 -> 11.1.0
validate-iri dependencies pin ^1.0.1 -> 1.0.1
which pnpm.overrides pin ^5.0.0 -> 5.0.0
which overrides pin ^5.0.0 -> 5.0.0
write-file-atomic pnpm.overrides pin ^6.0.0 -> 6.0.0
write-file-atomic overrides pin ^6.0.0 -> 6.0.0
xml-js dependencies pin ^1.6.11 -> 1.6.11
yallist pnpm.overrides pin ^5.0.0 -> 5.0.0
yallist overrides pin ^5.0.0 -> 5.0.0
yaml (source) dependencies pin ^2.8.0 -> 2.8.0
yargs (source) pnpm.overrides pin ^17.7.2 -> 17.7.2
yargs (source) overrides pin ^17.7.2 -> 17.7.2
yargs (source) dependencies pin ^17.7.2 -> 17.7.2
yoctocolors dependencies pin ^2.1.1 -> 2.1.1

Add the preset :preserveSemverRanges to your config if you don't want to pin your dependencies.


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, on day 1 of the month ( * 0-3 1 * * ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from prabhu as a code owner June 18, 2025 14:36
@renovate renovate bot added the dependency Dependency updates label Jun 18, 2025
@setchy
Copy link
Member

setchy commented Jun 18, 2025

We'll need to shape a few renovate package rules that will need to be created to make PRs like this happy

@renovate renovate bot force-pushed the renovate/pin-dependencies branch from 5fff51a to b4823ea Compare June 18, 2025 15:05
@renovate renovate bot changed the title fix(deps): pin dependencies fix(deps): pin dependencies - autoclosed Jun 18, 2025
@renovate renovate bot closed this Jun 18, 2025
@renovate renovate bot deleted the renovate/pin-dependencies branch June 18, 2025 15:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependency Dependency updates
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant