Skip to content

Build(deps): Bump @pnpm/deps.graph-sequencer from 1100.0.1 to 1101.0.0 - #2288

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/pnpm/deps.graph-sequencer-1101.0.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/pnpm/deps.graph-sequencer-1101.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @pnpm/deps.graph-sequencer from 1100.0.1 to 1101.0.0.

Release notes

Sourced from @​pnpm/deps.graph-sequencer's releases.

pnpm 12 Alpha 19

Minor Changes

  • Added a new setting, update.githubActionsServer, for specifying the base URL of the GitHub server that hosts the repositories of the GitHub Actions referenced by the workflow files (for example, a GitHub Enterprise Server). When the setting is not defined, the URL is read from the GITHUB_SERVER_URL environment variable, falling back to https://github.com. The URL must use the https:// or http:// protocol #13220.

    pnpm outdated and pnpm update no longer fail when the refs of a GitHub Action's repository cannot be read (for example, when the action's repository is private or hosted on a different GitHub server). Such actions are now skipped with a warning.

    Setting update.githubActions to false now makes pnpm outdated and the interactive pnpm update skip GitHub Actions dependencies.

  • Added the pnpm unpublish command: remove a package from the registry entirely (requires --force), or remove the versions matching <package>@<range>, re-pointing dist-tags that referenced them and deleting the orphaned tarballs. Supports --registry and --otp.

Patch Changes

  • The token poll for web-based authentication no longer reads the body of non-OK or still-pending (HTTP 202) responses, and caps the token response body it does read at 64 KiB, so a malicious or compromised registry cannot exhaust memory through the poll pnpm/pnpm#12721.

  • pnpm install --no-runtime now works without --frozen-lockfile: on a fresh install, runtime dependencies are resolved and recorded in the lockfile, but their archives are not downloaded and their bins are not linked.

  • pnpm outdated now aligns its table borders when the output is colorized. The color escape codes in the Package and Latest cells were being counted as visible characters, so the columns and box-drawing borders drifted out of alignment on a terminal.

  • pnpm pack and pnpm publish no longer let workspace-root .gitignore / .npmignore rules exclude files matched by the package manifest's files allowlist. Workspace packages whose build output is gitignored at the workspace root (for example a compiled lib/ directory listed in files) were published with almost all payload files missing #13164.

  • Fixed pnpm update --latest failing with ERR_PNPM_PACKAGE_MANAGER_UPDATE_RESOLVE_LATEST when a dependency uses the workspace: (or link: / file:) protocol. Such a dependency links a local package that may not be published, so there is no registry "latest" to resolve — it is now skipped and preserved verbatim, matching the TypeScript CLI. Previously only workspace:<path> specifiers were skipped, so workspace:* / workspace:^1.0.0 deps pointing at unpublished packages made --latest try to fetch them from the registry and 404.

  • pnpm view now accepts the --registry option, matching the TypeScript CLI. Previously the flag was rejected as an unknown argument.

  • When the authentication URL cannot be rendered as a QR code (for example when it exceeds the maximum QR data capacity), web-based login now displays the URL alone with a warning instead of aborting authentication pnpm/pnpm#12721.

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 6, 2026
@changeset-bot

changeset-bot Bot commented Sep 6, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: d782a7c

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@netlify

netlify Bot commented Sep 6, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for changesets ready!

Name Link
🔨 Latest commit d782a7c
🔍 Latest deploy log https://app.netlify.com/projects/changesets/deploys/6aa7a8c822ac980008adead4
😎 Deploy Preview https://deploy-preview-2288--changesets.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@socket-security

socket-security Bot commented Sep 6, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​pnpm/​deps.graph-sequencer@​1100.0.1 ⏵ 1101.0.010010078 +285 -3100

View full report

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/pnpm/deps.graph-sequencer-1101.0.0 branch from a5de249 to 3e43e63 Compare September 14, 2026 07:10
Bumps [@pnpm/deps.graph-sequencer](https://github.com/pnpm/pnpm) from 1100.0.1 to 1101.0.0.
- [Release notes](https://github.com/pnpm/pnpm/releases)
- [Commits](https://github.com/pnpm/pnpm/commits)

---
updated-dependencies:
- dependency-name: "@pnpm/deps.graph-sequencer"
  dependency-version: 1101.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/pnpm/deps.graph-sequencer-1101.0.0 branch from 3e43e63 to d782a7c Compare September 14, 2026 07:56

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants