Skip to content

chore(deps): update github-actions (major) - #113

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-github-actions
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-github-actions

Conversation

@renovate

@renovate renovate Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Pending Age Confidence
actions/checkout action major v5v7 age confidence
actions/setup-node action major v6v7 age confidence
marocchino/sticky-pull-request-comment action major v2v3.0.5 age confidence
pnpm (source) uses-with major 10.33.412.4.1 12.4.2 age confidence
pnpm/action-setup action major v2v6 age confidence
pnpm/action-setup action major v4v6 age confidence

Release Notes

actions/checkout (actions/checkout)

v7.0.1

Compare Source

v7.0.0

Compare Source

v6.1.0

Compare Source

v6.0.3

Compare Source

v6.0.2

Compare Source

v6.0.1

Compare Source

v6.0.0

Compare Source

v5.1.0

Compare Source

v5.0.1

Compare Source

actions/setup-node (actions/setup-node)

v7.0.0

Compare Source

What's Changed
Enhancements:
Bug fixes:
Documentation updates:
Dependency update:
New Contributors

Full Changelog: actions/setup-node@v6...v7.0.0

v6.5.0

Compare Source

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

v6.4.0

Compare Source

What's Changed

Dependency updates:

New Contributors

Full Changelog: actions/setup-node@v6...v6.4.0

v6.3.0

Compare Source

What's Changed

Enhancements:

When using node-version-file: package.json, setup-node now prefers devEngines.runtime over engines.node.

Dependency updates:
Bug fixes:

New Contributors

Full Changelog: actions/setup-node@v6...v6.3.0

v6.2.0

Compare Source

What's Changed

Documentation
Dependency updates:

New Contributors

Full Changelog: actions/setup-node@v6...v6.2.0

v6.1.0

Compare Source

What's Changed

Enhancement:
Dependency updates:
Documentation update:

Full Changelog: actions/setup-node@v6...v6.1.0

marocchino/sticky-pull-request-comment (marocchino/sticky-pull-request-comment)

v3.0.5

Compare Source

v3.0.4

Compare Source

What's Changed

Full Changelog: marocchino/sticky-pull-request-comment@v3.0.3...v3.0.4

v3.0.3

Compare Source

What's Changed
New Contributors

Full Changelog: marocchino/sticky-pull-request-comment@v3.0.2...v3.0.3

v3.0.2

Compare Source

What's Changed

Full Changelog: marocchino/sticky-pull-request-comment@v3.0.1...v3.0.2

v3.0.1

Compare Source

What's Changed
  • Update deps
  • Change build system from ncc to rollup
  • Use pull_request trigger in github action

Full Changelog: marocchino/sticky-pull-request-comment@v3.0.0...v3.0.1

v3.0.0

Compare Source

What's Changed
  • Update node to 24
  • Update deps
New Contributors

Full Changelog: marocchino/sticky-pull-request-comment@v2.9.4...v3.0.0

v2.9.4

Compare Source

What's Changed

Full Changelog: marocchino/sticky-pull-request-comment@v2.9.3...v2.9.4

v2.9.3

Compare Source

What's Changed
  • Update deps (including security issues)
  • Test with vitest instead of jest
  • Use biome

Full Changelog: marocchino/sticky-pull-request-comment@v2.9.2...v2.9.3

v2.9.2

Compare Source

What's Changed

Full Changelog: marocchino/sticky-pull-request-comment@v2.9.1...v2.9.2

v2.9.1

Compare Source

What's Changed
New Contributors

Full Changelog: marocchino/sticky-pull-request-comment@v2.9.0...v2.9.1

v2.9.0

Compare Source

  • Update deps
  • Use node 20

v2.8.0

Compare Source

  • Add skip_unchanged input
  • Update deps

v2.7.0

Compare Source

Update deps.
Add two output.

  • previous_comment_id: "ID of previous comment, if found"
  • created_comment_id: "ID of newly created comment, if any"

v2.6.2

Compare Source

Reverted changes in version 2.6. As a result, the base_url has been removed.

v2.6.1

Compare Source

Change base_url default to ${{ env.GITHUB_API_URL }}

v2.6.0

Compare Source

v2.5.0

Compare Source

  • Update deps
  • Add only_update option.
  • Add owner option.

v2.4.0

Compare Source

  • Update deps
  • Add only_create option.

v2.3.1

Compare Source

  • Update deps
  • Change ignore empty default from true to false (This change will fix bug delete or hide comment not works)

v2.3.0

Compare Source

  • Support glob path
  • Add follow_symbolic_links for path
  • Add ignore_empty for skip empty body
  • Update README for new output syntax

v2.2.1: Update deps

Compare Source

  • Use node 16
  • Update npm deps

v2.2.0

Compare Source

Add hide, hide_details, hide_and_recreate, hide_classsify options

v2.1.1

Compare Source

v2.1.0: Set GitHub token by default

Compare Source

Features

Bug fix

  • Fix unexpected delete fail #​226
  • Convert buffer to string when file read #​202
  • Fix boolean handling #​215
pnpm/pnpm (pnpm)

v12.4.1: pnpm 12.4.1

Compare Source

pnpm 12.4.1 fixes installs that failed on filesystems refusing hard links or clones, on Android, and under nodeLinker: hoisted. Repeat installs are faster.

Patch Changes

Installing packages
  • pnpm install no longer fails with Operation not permitted when the filesystem refuses a hard link or a copy-on-write clone #​14722. Under packageImportMethod: auto and clone-or-copy, pnpm copies the file instead. EdenFS checkouts, which have no hard links, and rootless containers, which refuse the clone syscall, both hit this. An explicit packageImportMethod: hardlink or clone still reports the error.

    pnpm also copies a package file whose store entry has reached the filesystem's limit on names for one file, 1024 on NTFS and 65000 on ext4. Such a file failed the install under packageImportMethod: hardlink, and under auto it stopped pnpm hard linking for the rest of the install.

  • pnpm install no longer writes a package file through a symlink left at the path it is importing to. Copying such a file overwrote whatever the link pointed at, and created that file when the link pointed nowhere. An executable package file also made the link's target executable.

  • Fixed pnpm install and pnpm dlx on Android. Registry requests crashed because pnpm found no system CA certificates, so pnpm uses bundled ones there #​14777. Imports also failed with "Permission denied" on filesystems that deny hard links and reflinks, and now fall back to copying #​14780.

  • pnpm install no longer fails with "Invalid cross-device link" while preserving a package's nested node_modules directory during a Docker build #​14758.

  • pnpm install no longer fails on a package tarball that carries a file at the archive root, such as the ._* entries macOS tar adds #​14701. The file is installed at the root of the package.

    A file: tarball packed without the usual package/ directory is now recorded under the name and version from its own package.json. It was recorded under the alias the dependency was given, at version 0.0.0.

  • Under nodeLinker: hoisted, pnpm install no longer re-imports packages that are already in place. A repeat install replaced the whole node_modules tree and reported Packages: +N. A package is still imported when its directory is missing, when its package.json no longer carries the installed version, when it is a file: dependency, and when it is patched. Lifecycle scripts no longer run again for a package left in place, and pnpm rebuild and a change to allowBuilds still reach it.

  • pnpm install now runs a dependency's build scripts again when its side-effects cache entry has no files to restore #​14717. Such builds were skipped and nothing was put in their place, so a script whose whole effect lands outside its own package directory, such as a git hook installer, never took effect. pnpm no longer publishes empty artifacts to the shared side-effects cache either.

Resolving and linking dependencies
  • pnpm install, pnpm add, and pnpm dedupe now apply ignoredOptionalDependencies #​14729. Matching optional dependencies are left out of the lockfile and are not installed. pnpm 12 installed them whenever it resolved dependencies from scratch.

  • pnpm install no longer links a transitive dependency to a workspace package when linkWorkspacePackages is true and the dependency is declared with a plain version range #​14781. Enabling preferWorkspacePackages does not change this. Set linkWorkspacePackages: deep to link them.

  • pnpm install no longer leaves dangling dependency links in workspace packages located above the workspace root #​14726.

  • pnpm install and pnpm add no longer leave a dangling symlink in node_modules when a project starts depending directly on a package that the lockfile holds only as a transitive dependency with resolved peer dependencies #​14714.

  • pnpm dedupe now keeps a compatible auto-installed peer when another workspace project depends on a newer major #​14697. Repeated runs alternated between compatible and incompatible peer versions.

  • pnpm peers check no longer reports a peer dependency declared as workspace:^, workspace:~, or a bare workspace: as unmet #​14770. pnpm reported these as unmet whatever version the linked workspace project supplied.

Performance
  • Sped up repeat installs #​14540. pnpm checks the store's files only for the packages it links into node_modules, instead of every package in the lockfile. Creating the command shims in node_modules/.bin makes about 1,500 fewer filesystem calls in a 76 project workspace. Installs that use the global virtual store read their slot paths from the cache directory instead of deriving them every time. Verifying a large lockfile also allocates less memory.

  • Sped up pnpm install in Cargo workspaces with many member crates. Repeated installs reuse verified Cargo checksum metadata.

  • Installing several packages from the same Git repository and commit now downloads the source once per install #​14725. Each package still runs its prepare scripts in its own copy of the checkout.

Running scripts and tasks
  • pnpm now passes Ctrl+C on to the script or command it started and waits for it to shut down #​14723. pnpm exited first, so a script that was still writing landed on the shell prompt.

  • pnpm run "/pattern/" --no-bail now lets every matched script finish after one of them fails #​14718. The command exits with ERR_PNPM_RUN_FAILED, and its message lists the scripts that failed in the order they were selected.

  • pnpm pipeline no longer fails on a project that tracks a symlink, such as a CLAUDE.md pointing at AGENTS.md #​14692. Changing a symlinked input's target invalidates that task's cache, and pnpm pipeline --no-cache no longer hashes task inputs.

Commands
  • pnpm add -g, pnpm update -g, and pnpm remove -g no longer change global bins or install directories after reading only part of an installed package group #​13796. If any declared package manifest is missing, malformed, or unreadable, pnpm now fails before it activates or removes anything and leaves the existing global installation intact.

  • pnpm dedupe now processes every workspace project by default, including workspaces that keep a separate lockfile per project #​14732. Workspace filters select which projects it processes, and --fail-if-no-match exits with an error when no project matches.

  • pnpm update <name>@<version> now keeps the range operator the manifest declares #​14745. Running pnpm update react@19.3.0 on "react": "^19.2.8" writes "react": "^19.3.0". A jsr: entry keeps its jsr: prefix, and a plain pnpm update now moves a jsr: range the way it moves an npm range.

  • pnpm --filter directory selectors now support ? wildcards and character classes such as [ab]. A * or ? wildcard no longer selects a directory whose name starts with a dot, as on pnpm 11.

  • pnpm deploy --legacy now prefers the dependency versions pinned in the source workspace lockfile when they still satisfy the deployed project's range #​13857.

  • pnpm sbom now leaves out a package's author field when the manifest author name is empty or contains only whitespace #​14685. In a filtered or split workspace run, only a project with no author field inherits the workspace root's author.

    pnpm sbom --sbom-format spdx now writes creationInfo.created with whole seconds, such as 2026-09-08T10:38:21Z #​14684. The fractional seconds it carried were rejected by strict SPDX consumers.

Configuration
  • The updateConfig pnpmfile hook now receives the resolved configuration, including settings that came from .npmrc, the command line, or a default #​14676. Scoped registries are reported under registriesByScope, and a hook may rewrite that map to change where packages are fetched from. Registry credentials are reported under configByUri, as pnpm 11 reports them. An unset setting is left out rather than reported as null.

  • pnpm audit --fix and the minimumReleaseAgeStrict approval prompt now keep the comments in minimumReleaseAgeExclude when they append an entry to it in pnpm-workspace.yaml. The rest of the list is left as written, and the trustPolicyExcludePrune and minimumReleaseAgeExcludePrune cleanups keep the comments of the entries they retain.

    pnpm install and pnpm dedupe now run those cleanups too #​14759. Only pnpm add, pnpm update, and pnpm remove pruned the entries that the freshly written lockfile no longer resolves.

  • pnpm config set --global node-download-mirrors no longer rejects the key #​13611. The global config file already accepted nodeDownloadMirrors, but the command refused to write it.

  • NO_PROXY entries that start with a dot, such as .npmjs.org, now bypass the proxy for the domain and its subdomains #​14686.

  • pnpm no longer creates a project pnpm-lock.yaml when devEngines.packageManager.onFail is download and lockfile writing is off through lockfile: false or --no-lockfile #​14728. pnpm still switches to the pinned version.

  • pnpm now writes node_modules/.package-map.json only when nodeExperimentalPackageMap is enabled. Nothing reads the file without that setting, and an install that stops writing the map removes the one a previous install left.

Windows
  • pnpm pipeline no longer fails with intermittent access denied errors when concurrent tasks save their cache entries on Windows.

  • Windows filesystem operations now retry permission errors for up to one second #​14682. A permanent permission error delayed the failure by a minute. Sharing and lock violations keep their one minute retry budget.

Messages and output
  • pnpm now warns when the root package.json declares a non-empty workspaces array and the project has no pnpm-workspace.yaml #​2255. Such an install linked no project and said nothing about why.

  • ERR_PNPM_PACKAGE_MANAGER_REMOVE_MODULES_DIR now names the file or directory in node_modules that pnpm could not clean up. It reported only the underlying OS error, such as "Access is denied (os error 5)".

  • pnpm --help no longer describes pnpm as experimental.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.4.0: pnpm 12.4

Compare Source

Minor Changes
  • pnpm can now manage npm, Python, and Cargo dependencies in the same workspace. Enable python.enabled or cargo.enabled in pnpm-workspace.yaml, then use pnpm install to install them together.

    • Add Python packages with pnpm add pypi:<package>. pnpm uses pyproject.toml, pylock.toml, and a managed .venv. Frozen and offline installs are supported, and pnpm run and pnpm exec make the environment's executables available #​14566.
    • Add Rust crates with pnpm add crate:<package>. pnpm supports crates.io and custom sparse registries configured with cargo.indexUrl. Registry authentication supports pnpm credentials and, for crates.io, CARGO_REGISTRY_TOKEN or $CARGO_HOME/credentials.toml.

    Both ecosystems support faster dependency resolution through pnprServer, with local resolution as a fallback when the server does not support it.

  • Added pnpm pipeline [name] to install frozen dependencies and run workspace tasks declared in pipelines. It selects affected projects, runs their task graph, and continues running tasks after a task fails.

    Tasks support inputs, outputs, env, and cache settings. Cached results restore task outputs and replay logs. Cargo tasks can reuse local build state between worktrees with tasks.<name>.cargoTargetDir. Set includeWorkspaceRoot: true to include root tasks.

    Use pnpm pipeline --dry-run to preview the task graph without installing configuration dependencies or running workspace hooks.

  • Added support for Android on arm64 and x64, FreeBSD on x64, and Linux on ppc64le, s390x, and RISC-V (riscv64 with glibc) #​14431, #​14597, #​7582.

  • Added trustPolicyExcludePrune to automatically remove unused versions and packages from trustPolicyExclude when running pnpm add, pnpm update, or pnpm remove. It is disabled by default. Package name patterns such as @scope/* are kept, and cleanup is skipped when sharedWorkspaceLockfile is false.

  • Added pnpm change check for CI validation of package versions against the versioning.epics bands and versioning.fixed groups in pnpm-workspace.yaml. It reports all violations, including packages that are not part of the current release.

Patch Changes
  • Registry metadata is now kept separate for registries with different URL paths or schemes. This prevents installs from using another registry's package versions or tarball URLs, and keeps metadata fetched over HTTP from being reused for HTTPS #​13558.

    The first install after upgrading refetches registry metadata. The package store is unchanged. pnpm cache view now shows full registry URLs. Scripts that parse the directory names from pnpm cache list-registries or pnpm cache list need updating.

  • Patches that add build scripts or a binding.gyp now trigger a build, subject to build approval. Unapproved builds appear under "Ignored build scripts" #​14648.

  • Build scripts can now be rejected before installing a package with pnpm add --allow-build=!<pkg>, including global installs. pnpm approve-builds <pkg> and pnpm approve-builds !<pkg> also save decisions when no packages are awaiting approval. They warn if the named package is not awaiting approval #​14067.

  • A registry configured in .npmrc now takes precedence over registry settings saved by pnpm login in the global config.yaml. This fixes installs using the wrong registry after login #​14614.

  • Large downloads over slow connections no longer time out while data is still arriving. fetch-timeout now limits how long a request can go without making progress #​14604.

  • Sped up i

Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "after 2am and before 3am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/major-github-actions branch 4 times, most recently from 41c60df to 49aa220 Compare August 6, 2026 18:06
@renovate
renovate Bot force-pushed the renovate/major-github-actions branch 2 times, most recently from c27f8af to 9bd694c Compare August 18, 2026 17:41
@renovate
renovate Bot force-pushed the renovate/major-github-actions branch 3 times, most recently from b9b0e87 to 6944f59 Compare September 1, 2026 18:36
@renovate
renovate Bot force-pushed the renovate/major-github-actions branch 7 times, most recently from 62017e2 to 739751c Compare September 11, 2026 17:03
@renovate
renovate Bot force-pushed the renovate/major-github-actions branch from 739751c to 0fc8bc2 Compare September 13, 2026 17:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants