Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update dependency @pnpm/lockfile-file to v4 #22

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Apr 26, 2021

WhiteSource Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@pnpm/lockfile-file ^3.0.17 -> ^4.0.0 age adoption passing confidence

Release Notes

pnpm/pnpm

v4.0.1

Compare Source

Bug Fixes

v4.0.0

Breaking Changes
  • Node.js 10 or newer is required (it will probably work with Node.js 8 as well but we don't test it anymore)
  • new node_modules structure.
    • all the hard linked dependencies are inside node_modules/.pnpm (#​1636, @​zkochan)
    • all the hoisted dependencies are symlinked into node_modules/.pnpm/node_modules. So application code has no access to the hoisted packages but dependencies have. (#​1998, @​zkochan)
    • the current lockfile is moved from node_modules/.pnpm-lock.yaml to node_modules/.pnpm/lock.yaml (#​2018, @​zkochan)
  • shamefully-flatten renamed to shamefully-hoist. (@​zkochan)
  • hoist-pattern is * by default. All packages are hoisted but application code has access only to listed dependencies. So the buggy ecosystem packages will work but pnpm will prevent users from requiring packages that are not declared in package.json. (@​zkochan)
  • all globally installed packages are always hoisted. (@​zkochan)
  • pnpm add fails if no packages are specified (5f73a7c, @​zkochan)
  • pnpm install installs all dependencies of all workspace packages when executed inside a workspace (5f73a7c, @​zkochan)
  • independent-leaves is only allowed with hoisting turned off (f3d5037, @​zkochan)
  • pnpm outdated does not print details by default. To should details, use the --long flag (#​2017, @​aparajita)
  • the root package.json is always included in the workspace (#​2021, @​ExE-Boss)
  • the CLI fails with unknown/incompatible options (#​1645, @​zkochan)
    • fails because of unknown option: pnpm install --foo
    • fails because of incompatible option: pnpm remove foo --save-exact
    • removed legacy --*-shrinkwrap option aliases from the CLI.
  • the default resolution-strategy is fewer-dependencies instead of fast (#​2042, @​zkochan)
  • changes in the way packages are imported from the store (#​2043, @​zkochan):
    • package-import-method does not support reflink anymore. Use clone instead, which is a cross-platform alternative.
    • by default, pnpm will clone packages on systems that support it. If cloning is not supported, pnpm will link packages from the store. If hard links are also not supported, pnpm will copy the packages.
  • new pattern matcher (#​2048, @​zkochan)
    The new pattern matcher only supports * (so you can do eslint-* or *-plugin-*). The * now also matches scopes, so *plugin matches both @eslint/plugin and eslint-plugin.
Features
  • new config settings:
    • hoist: true by default. When false, pnpm will not hoist any dependencies in node_modules, preventing dependencies inside node_modules from accessing unlisted dependencies. (#​2004, @​zkochan)
    • hoist-pattern: * by default. All packages matching this pattern will be hoisted. For example, you can choose to hoist only eslint packages: hoist-pattern=eslint-*. By default, all packages are hoisted. (#​1997, #​1998, @​zkochan)
    • shamefully-hoist: same as shamefully-flatten in previous versions of pnpm. The project's code has access to hoisted dependencies. (#​2006, @​zkochan)
  • pnpm outdated:
  • nicer output of the --help commands (#​2013, @​zkochan)
    image
  • new command: pnpm why <package> (#​2015, @​ExE-Boss)

Configuration

📅 Schedule: At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box.

This PR has been generated by WhiteSource Renovate. View repository job log here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant