chore(deps): lock file maintenance - #403
ferrlabs-renovate[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Lock file maintenance only, no package.json/Cargo.toml range changes.
Cargo.lock: cc 1.4.6→1.4.7, find-msvc-tools 0.1.12→0.1.13 (both build-script helpers), hyper-rustls 0.27.9→0.27.10 (patch within the same minor). No breaking changes in any of these.
pnpm-lock.yaml: all diffs are patch/minor bumps in docs-site build tooling (rollup, vite/unplugin/unimport chain, browserslist data, marked-mangle, type-fest, etc.), nothing touching runtime/server code. No major version jumps.
Uneventful bump, nothing blocking.
CI was still mid-run at review time (several jobs in_progress, none failed) plus Renovate's own stability-days pending status, which just reflects the minimum-release-age policy rather than a check failure.
5ec7e9a to
b3fdc75
Compare
b3fdc75 to
c5534df
Compare
There was a problem hiding this comment.
Re-reviewing at c5534df: the branch was regenerated and the resolutions are materially different from 5ec7e9ac, which I approved. My earlier note that there were "no major version jumps" no longer describes this diff, so here is the current state.
Cargo.lock — cc 1.4.6→1.5.1 (minor, not the 1.4.7 patch from last time), find-msvc-tools 0.1.12→0.1.14, hyper-rustls 0.27.9→0.27.10, plus new this round: hyper-util 0.1.20→0.1.21 (switches to the already-present base64 0.23.1 and gains httparse), wasm-bindgen/web-sys/js-sys 0.2.129/0.3.106, zerocopy 0.8.59, smallvec 1.16.2. I parsed the lock and every dependency reference resolves to a package entry, with no new duplicate-version crates beyond the ones already on main. cargo test --locked gates this.
pnpm-lock.yaml — bigger than last time: Angular 22.1.x→22.2.0 across the stack, Analog 2.7.2→2.7.4, Babel 8.0.x patches. @angular/build 22.2.0 changed its own dependency set, which is what produced the two surprising parts of this diff:
- A cluster of transitive majors under
beasties0.4.3→0.5.4:htmlparser210→12,css-select6→7,css-what7→8,domutils3→4,domhandler5→6,dom-serializer2→3,domelementtype2→3,nth-check2→3,boolbase1→2. All build-time critical-CSS inlining, nothing reaching the Rust server. The highest new engines floor in the added set is node >=20.19.0, well under the'24'CI uses and the>=22.0.0inengines. sass-embedded1.104.1 plus 19 platform binary packages are newly in the tree (withsync-child-process,sync-message-port,varint,@bufbuild/protobuf). Not an anomaly:@angular/build22.2.0 listssass-embeddedas a direct dependency, and vite declares it as an optional peer. It is still a chunk of new native install surface arriving under a "lock file maintenance" title, so worth knowing it is there.
I checked the site importer block against site/package.json and there is no specifier drift, package and snapshot entries are balanced at 726 each, and the esbuild: '>=0.28.1' override is still satisfied by 0.28.2. pnpm install --frozen-lockfile would fail otherwise, and Check Site runs that plus typecheck and build.
Nit, and explicitly unverified: I could not reach crates.io from the runner (403), so I could not check whether cc 1.5.0 raised its MSRV. The workspace declares rust-version = "1.88" but rust-toolchain.toml pins 1.98 and there is no MSRV job, so a build-dependency raising its floor past 1.88 would not be caught here. That gap predates this PR; I mention it only because a minor cc bump is the usual way it bites.
Nothing blocking. Security scanners (osv-scanner, snyk, gitleaks, zizmor) are green; Check Site, Check, and the git-lfs matrix were still running when I looked, and they are what actually exercise the majors above.
c5534df to
6da9129
Compare
There was a problem hiding this comment.
Re-reviewed at 6da9129; the branch was regenerated since c5534df. Only what changed:
Cargo.lock is byte-identical to the revision I reviewed last time, so nothing new on the Rust side.
pnpm-lock.yaml, diffed against c5534df rather than against main, is a 198-line delta:
- Rebase onto current
mainpulled inpnpm12.5.1→12.6.0 (the 46@pnpm/exe.*entries). That bump lives inmain'spackage.json, not in this PR; lock specifier, resolution andpackageManagerall read 12.6.0, so no drift. - Analog 2.7.4→2.7.5 across the five
@analogjs/*packages, inside the^2.6.1range insite/package.json. - Patches:
bare-fs4.8.2,baseline-browser-mapping2.11.26,bundle-name4.1.1,electron-to-chromium1.5.439.
Everything else in the pnpm diff (Angular 22.2.0, the beasties transitive majors, the sass-embedded binaries) is unchanged from what I described last round.
Closing the MSRV nit I left unverified last time: the sparse index was reachable this run. cc 1.5.1 declares rust-version = 1.65.0, same as the 1.4.6 it replaces, so the minor bump did not raise the floor. Across the whole Rust delta the highest new MSRV is hyper-util 0.1.21 at 1.85 (up from 1.64), with wasm-bindgen/js-sys/web-sys/wasm-bindgen-futures at 1.81 (up from 1.77). All under the workspace's declared rust-version = "1.88", so the missing-MSRV-job gap I flagged does not bite here. None of the new versions are yanked.
CI is green this time, including Check (cargo test --locked) and Check Site (pnpm install --frozen-lockfile plus typecheck and build), which is what actually exercises the majors. Only git-lfs bundled on windows-latest was still running.
Nothing blocking.
6da9129 to
d1cf5fa
Compare
There was a problem hiding this comment.
Re-reviewed at d1cf5fa; regenerated since 6da9129. Only what changed.
Cargo.lock is byte-identical to 6da9129, so nothing new on the Rust side.
pnpm-lock.yaml, diffed against 6da9129 rather than against main, is a 26-line delta, and almost all of it is one thing: the @ferrlabs/* packages moved off GitHub Packages. That migration landed in main (ef3c4fac reduced .npmrc to @ferrlabs:registry=https://registry.npmjs.org, dropped registry-url/scope/NODE_AUTH_TOKEN from the Check Site job, and replaced the BuildKit-secret install in site/Dockerfile with a plain one). This PR is where the lock catches up:
@ferrlabs/ui-foundationstays at 5.4.0 but its integrity changes and thetarball: https://npm.pkg.github.com/download/...field disappears;@ferrlabs/ui-nggoes 1.35.1→1.37.1, likewise without a tarball override. A same-version integrity change looks alarming in a lock diff and is worth naming explicitly: it is the registry switch, not a republish, since GitHub Packages serves its own re-packed tarballs. I checked both hashes against registry.npmjs.org and they match exactly (sha512-M9G1OZ/…for ui-foundation@5.4.0,sha512-3MwGTCf…for ui-ng@1.37.1). Practical consequence: the bytes being installed now are not the bytes CI installed before, andCheck Siteis green on them.- Zero
npm.pkg.github.comreferences remain anywhere in the lock, so nothing will try to authenticate against GitHub Packages now that the token is gone from CI and the Dockerfile. - The
^5.1.0→^5.4.0and^1.23.0→^1.37.1specifier bumps come frommain'ssite/package.json, not from this PR. All 28 entries in thesiteimporter matchsite/package.jsonwith no drift. - ui-ng 1.37.1 declares a new optional peer on
@ferrlabs/ui-foundation^5.0.0, resolved to 5.4.0 in the snapshot. - One unrelated patch:
pretty-bytes7.1.3→7.2.0, transitive under nitro.
Structural sanity: package and snapshot entries balance at 726 each in the main document and 15 each in the leading packageManagerDependencies document (that two-document layout is pnpm 12's own format, not corruption), and every snapshot base name resolves to a package entry.
Nit, cross-repo and out of scope here: the public @ferrlabs scope was created today, holds exactly one version of each package, and has no npm provenance attestations. What protects this repo is the lock pinning the integrity hashes, which is pinning rather than verification. Publishing from FerrLabs/UI with --provenance would make the origin checkable; the fix belongs in that repo, not this PR.
CI is fully green, including Check, Check Site, and the whole git-lfs matrix. Nothing blocking.
d1cf5fa to
9c233b2
Compare
9c233b2 to
a2bca18
Compare
There was a problem hiding this comment.
Re-reviewed at a2bca18. This is a rebase of d1cf5fa, and I compared each revision against its own merge base.
- Cargo.lock: the PR's added and removed lines are identical to
d1cf5fa. Only the surrounding context moved. - pnpm-lock.yaml: the PR adds and removes the same packages as before. Everything else that looks new came from
main: pnpm 12.7.0 (#471),@ferrlabs/ui-ng1.40.0, vite 8.3.1, browserslist 4.29.3,@bufbuild/protobuf2.16.0, plus a few patch bumps. - One shape change that is this PR's own:
ajv-formats@3.0.1no longer listsajvas an optional peer and instead resolves it as a plain dependency onajv@8.20.0. The integrity hash is unchanged. It looks like pnpm 12.7 writing the lock differently and should not change what gets installed.Check Site(--frozen-lockfile) will confirm that. - No
npm.pkg.github.comreferences remain.
Nothing blocking. Check, Check Site and the git-lfs matrix were still running when I looked.
This PR contains the following updates:
Warning
Some dependencies could not be looked up. Check the warning logs for more information.
🔧 This Pull Request updates lock files to use the latest dependency versions.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.