Skip to content

chore(deps): lock file maintenance - #403

Open
ferrlabs-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/lock-file-maintenance
Open

ferrlabs-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/lock-file-maintenance

Conversation

@ferrlabs-renovate

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

Warning

Some dependencies could not be looked up. Check the warning logs for more information.

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 6am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lock file maintenance only, no package.json/Cargo.toml range changes.

Cargo.lock: cc 1.4.6→1.4.7, find-msvc-tools 0.1.12→0.1.13 (both build-script helpers), hyper-rustls 0.27.9→0.27.10 (patch within the same minor). No breaking changes in any of these.

pnpm-lock.yaml: all diffs are patch/minor bumps in docs-site build tooling (rollup, vite/unplugin/unimport chain, browserslist data, marked-mangle, type-fest, etc.), nothing touching runtime/server code. No major version jumps.

Uneventful bump, nothing blocking.

CI was still mid-run at review time (several jobs in_progress, none failed) plus Renovate's own stability-days pending status, which just reflects the minimum-release-age policy rather than a check failure.

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewing at c5534df: the branch was regenerated and the resolutions are materially different from 5ec7e9ac, which I approved. My earlier note that there were "no major version jumps" no longer describes this diff, so here is the current state.

Cargo.lock — cc 1.4.6→1.5.1 (minor, not the 1.4.7 patch from last time), find-msvc-tools 0.1.12→0.1.14, hyper-rustls 0.27.9→0.27.10, plus new this round: hyper-util 0.1.20→0.1.21 (switches to the already-present base64 0.23.1 and gains httparse), wasm-bindgen/web-sys/js-sys 0.2.129/0.3.106, zerocopy 0.8.59, smallvec 1.16.2. I parsed the lock and every dependency reference resolves to a package entry, with no new duplicate-version crates beyond the ones already on main. cargo test --locked gates this.

pnpm-lock.yaml — bigger than last time: Angular 22.1.x→22.2.0 across the stack, Analog 2.7.2→2.7.4, Babel 8.0.x patches. @angular/build 22.2.0 changed its own dependency set, which is what produced the two surprising parts of this diff:

  • A cluster of transitive majors under beasties 0.4.3→0.5.4: htmlparser2 10→12, css-select 6→7, css-what 7→8, domutils 3→4, domhandler 5→6, dom-serializer 2→3, domelementtype 2→3, nth-check 2→3, boolbase 1→2. All build-time critical-CSS inlining, nothing reaching the Rust server. The highest new engines floor in the added set is node >=20.19.0, well under the '24' CI uses and the >=22.0.0 in engines.
  • sass-embedded 1.104.1 plus 19 platform binary packages are newly in the tree (with sync-child-process, sync-message-port, varint, @bufbuild/protobuf). Not an anomaly: @angular/build 22.2.0 lists sass-embedded as a direct dependency, and vite declares it as an optional peer. It is still a chunk of new native install surface arriving under a "lock file maintenance" title, so worth knowing it is there.

I checked the site importer block against site/package.json and there is no specifier drift, package and snapshot entries are balanced at 726 each, and the esbuild: '>=0.28.1' override is still satisfied by 0.28.2. pnpm install --frozen-lockfile would fail otherwise, and Check Site runs that plus typecheck and build.

Nit, and explicitly unverified: I could not reach crates.io from the runner (403), so I could not check whether cc 1.5.0 raised its MSRV. The workspace declares rust-version = "1.88" but rust-toolchain.toml pins 1.98 and there is no MSRV job, so a build-dependency raising its floor past 1.88 would not be caught here. That gap predates this PR; I mention it only because a minor cc bump is the usual way it bites.

Nothing blocking. Security scanners (osv-scanner, snyk, gitleaks, zizmor) are green; Check Site, Check, and the git-lfs matrix were still running when I looked, and they are what actually exercise the majors above.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/lock-file-maintenance branch from c5534df to 6da9129 Compare September 26, 2026 22:12

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed at 6da9129; the branch was regenerated since c5534df. Only what changed:

Cargo.lock is byte-identical to the revision I reviewed last time, so nothing new on the Rust side.

pnpm-lock.yaml, diffed against c5534df rather than against main, is a 198-line delta:

  • Rebase onto current main pulled in pnpm 12.5.1→12.6.0 (the 46 @pnpm/exe.* entries). That bump lives in main's package.json, not in this PR; lock specifier, resolution and packageManager all read 12.6.0, so no drift.
  • Analog 2.7.4→2.7.5 across the five @analogjs/* packages, inside the ^2.6.1 range in site/package.json.
  • Patches: bare-fs 4.8.2, baseline-browser-mapping 2.11.26, bundle-name 4.1.1, electron-to-chromium 1.5.439.

Everything else in the pnpm diff (Angular 22.2.0, the beasties transitive majors, the sass-embedded binaries) is unchanged from what I described last round.

Closing the MSRV nit I left unverified last time: the sparse index was reachable this run. cc 1.5.1 declares rust-version = 1.65.0, same as the 1.4.6 it replaces, so the minor bump did not raise the floor. Across the whole Rust delta the highest new MSRV is hyper-util 0.1.21 at 1.85 (up from 1.64), with wasm-bindgen/js-sys/web-sys/wasm-bindgen-futures at 1.81 (up from 1.77). All under the workspace's declared rust-version = "1.88", so the missing-MSRV-job gap I flagged does not bite here. None of the new versions are yanked.

CI is green this time, including Check (cargo test --locked) and Check Site (pnpm install --frozen-lockfile plus typecheck and build), which is what actually exercises the majors. Only git-lfs bundled on windows-latest was still running.

Nothing blocking.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/lock-file-maintenance branch from 6da9129 to d1cf5fa Compare September 27, 2026 12:10

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed at d1cf5fa; regenerated since 6da9129. Only what changed.

Cargo.lock is byte-identical to 6da9129, so nothing new on the Rust side.

pnpm-lock.yaml, diffed against 6da9129 rather than against main, is a 26-line delta, and almost all of it is one thing: the @ferrlabs/* packages moved off GitHub Packages. That migration landed in main (ef3c4fac reduced .npmrc to @ferrlabs:registry=https://registry.npmjs.org, dropped registry-url/scope/NODE_AUTH_TOKEN from the Check Site job, and replaced the BuildKit-secret install in site/Dockerfile with a plain one). This PR is where the lock catches up:

  • @ferrlabs/ui-foundation stays at 5.4.0 but its integrity changes and the tarball: https://npm.pkg.github.com/download/... field disappears; @ferrlabs/ui-ng goes 1.35.1→1.37.1, likewise without a tarball override. A same-version integrity change looks alarming in a lock diff and is worth naming explicitly: it is the registry switch, not a republish, since GitHub Packages serves its own re-packed tarballs. I checked both hashes against registry.npmjs.org and they match exactly (sha512-M9G1OZ/… for ui-foundation@5.4.0, sha512-3MwGTCf… for ui-ng@1.37.1). Practical consequence: the bytes being installed now are not the bytes CI installed before, and Check Site is green on them.
  • Zero npm.pkg.github.com references remain anywhere in the lock, so nothing will try to authenticate against GitHub Packages now that the token is gone from CI and the Dockerfile.
  • The ^5.1.0→^5.4.0 and ^1.23.0→^1.37.1 specifier bumps come from main's site/package.json, not from this PR. All 28 entries in the site importer match site/package.json with no drift.
  • ui-ng 1.37.1 declares a new optional peer on @ferrlabs/ui-foundation ^5.0.0, resolved to 5.4.0 in the snapshot.
  • One unrelated patch: pretty-bytes 7.1.3→7.2.0, transitive under nitro.

Structural sanity: package and snapshot entries balance at 726 each in the main document and 15 each in the leading packageManagerDependencies document (that two-document layout is pnpm 12's own format, not corruption), and every snapshot base name resolves to a package entry.

Nit, cross-repo and out of scope here: the public @ferrlabs scope was created today, holds exactly one version of each package, and has no npm provenance attestations. What protects this repo is the lock pinning the integrity hashes, which is pinning rather than verification. Publishing from FerrLabs/UI with --provenance would make the origin checkable; the fix belongs in that repo, not this PR.

CI is fully green, including Check, Check Site, and the whole git-lfs matrix. Nothing blocking.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/lock-file-maintenance branch from d1cf5fa to 9c233b2 Compare September 27, 2026 18:13
@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/lock-file-maintenance branch from 9c233b2 to a2bca18 Compare October 1, 2026 02:08

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed at a2bca18. This is a rebase of d1cf5fa, and I compared each revision against its own merge base.

  • Cargo.lock: the PR's added and removed lines are identical to d1cf5fa. Only the surrounding context moved.
  • pnpm-lock.yaml: the PR adds and removes the same packages as before. Everything else that looks new came from main: pnpm 12.7.0 (#471), @ferrlabs/ui-ng 1.40.0, vite 8.3.1, browserslist 4.29.3, @bufbuild/protobuf 2.16.0, plus a few patch bumps.
  • One shape change that is this PR's own: ajv-formats@3.0.1 no longer lists ajv as an optional peer and instead resolves it as a plain dependency on ajv@8.20.0. The integrity hash is unchanged. It looks like pnpm 12.7 writing the lock differently and should not change what gets installed. Check Site (--frozen-lockfile) will confirm that.
  • No npm.pkg.github.com references remain.

Nothing blocking. Check, Check Site and the git-lfs matrix were still running when I looked.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants