Skip to content

build(deps): bump pnpm/action-setup from 5 to 6 - #10241

Open
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/github_actions/dev/pnpm/action-setup-6
Open

build(deps): bump pnpm/action-setup from 5 to 6#10241
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/github_actions/dev/pnpm/action-setup-6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 20, 2026

Copy link
Copy Markdown
Contributor

Bumps pnpm/action-setup from 5 to 6.

Release notes

Sourced from pnpm/action-setup's releases.

v6.0.0

Added support for pnpm v11.

Commits
  • 91ab88e fix: bin_dest output points to self-updated pnpm, not bootstrap (#249)
  • e578e19 fix: update pnpm to 11.0.4
  • 8912a91 fix: append (not prepend) action node dir to PATH for npm bootstrap (#241)
  • 26f6d4f fix: use npm co-located with the action node binary (#239)
  • 903f9c1 fix: update pnpm to 11.0.0-rc.5
  • bdf0af2 test: add strict version-match jobs to reproduce #225 / #227
  • 71c9247 fix: pnpm self-update binary shadowed by bootstrap on PATH (#230)
  • 078e9d4 fix: update pnpm to 11.0.0-rc.2
  • 08c4be7 docs(README): update action-setup version
  • 5798914 chore: update .gitignore
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added ci CI/CD and GitHub Actions dependencies Pull requests that update a dependency file security Security update This issue is for an update or upgrade. labels Apr 20, 2026
@dependabot
dependabot Bot requested a review from h0lybyte as a code owner April 20, 2026 06:06
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ci CI/CD and GitHub Actions labels Apr 20, 2026
@github-actions

github-actions Bot commented Apr 20, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 4 package(s) with unknown licenses.
See the Details below.

License Issues

.github/workflows/ci-mc-gradle-cache.yml

PackageVersionLicenseIssue Type
pnpm/action-setup6.*.*NullUnknown License

.github/workflows/python-test-package.yml

PackageVersionLicenseIssue Type
pnpm/action-setup6.*.*NullUnknown License

.github/workflows/utils-nx-kbve-shell.yml

PackageVersionLicenseIssue Type
pnpm/action-setup6.*.*NullUnknown License

.github/workflows/utils-update-version-toml.yml

PackageVersionLicenseIssue Type
pnpm/action-setup6.*.*NullUnknown License

OpenSSF Scorecard

PackageVersionScoreDetails
actions/pnpm/action-setup 6.*.* 🟢 5.5
Details
CheckScoreReason
Code-Review🟢 4Found 12/30 approved changesets -- score normalized to 4
Maintained🟢 1022 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Pinned-Dependencies🟢 10all dependencies are pinned
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Security-Policy⚠️ 0security policy file not detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
actions/pnpm/action-setup 6.*.* 🟢 5.5
Details
CheckScoreReason
Code-Review🟢 4Found 12/30 approved changesets -- score normalized to 4
Maintained🟢 1022 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Pinned-Dependencies🟢 10all dependencies are pinned
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Security-Policy⚠️ 0security policy file not detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
actions/pnpm/action-setup 6.*.* 🟢 5.5
Details
CheckScoreReason
Code-Review🟢 4Found 12/30 approved changesets -- score normalized to 4
Maintained🟢 1022 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Pinned-Dependencies🟢 10all dependencies are pinned
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Security-Policy⚠️ 0security policy file not detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
actions/pnpm/action-setup 6.*.* 🟢 5.5
Details
CheckScoreReason
Code-Review🟢 4Found 12/30 approved changesets -- score normalized to 4
Maintained🟢 1022 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Pinned-Dependencies🟢 10all dependencies are pinned
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Security-Policy⚠️ 0security policy file not detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • .github/workflows/ci-mc-gradle-cache.yml
  • .github/workflows/python-test-package.yml
  • .github/workflows/utils-nx-kbve-shell.yml
  • .github/workflows/utils-update-version-toml.yml

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/dev/pnpm/action-setup-6 branch from db15157 to 9896db1 Compare April 25, 2026 00:21
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/dev/pnpm/action-setup-6 branch 2 times, most recently from d20d68f to 728a1ff Compare May 8, 2026 03:04
Bumps [pnpm/action-setup](https://github.com/pnpm/action-setup) from 5 to 6.
- [Release notes](https://github.com/pnpm/action-setup/releases)
- [Commits](pnpm/action-setup@v5...v6)

---
updated-dependencies:
- dependency-name: pnpm/action-setup
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump pnpm/action-setup from 5 to 6 build(deps): bump pnpm/action-setup from 5 to 6 May 11, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/dev/pnpm/action-setup-6 branch from 728a1ff to 4b1f981 Compare May 11, 2026 07:52
h0lybyte added a commit that referenced this pull request Aug 2, 2026
…ive-webgpu (#15161)

Consolidates dependabot PRs #14719, #14720, #14722, #14723, #14725.

- prost/prost-build 0.13 -> 0.14 in uniti; aligns with every other crate in
  the workspace, which was already on 0.14. Regenerates the checked-in
  proto modules (additive Eq/Hash derives only).
- syn 3.0.2 -> 3.0.3 (Cargo.lock).
- @nxlv/python 22.2.1 -> 22.2.2.
- postcss-merge-rules ^7.0.8 -> ^8.0.1.
- react-native-webgpu 0.5.15 -> 0.6.3, bumped in both the root manifest and
  apps/kbve/kbve-react-native so the app does not resolve a second copy.
  Peer ranges are unchanged and Canvas/useCanvasRef/useDevice still export
  from the package root.

Not included: expo-dev-client 57 (#14728) requires Expo SDK 57 while the
workspace is on Expo 56, and pnpm/action-setup v6 (#10241) which is stale
and only covers part of the workflows still on v5/v4.
h0lybyte added a commit that referenced this pull request Aug 2, 2026
…pace alignment (#15174)

* ci: bump pnpm/action-setup to v6 across all workflows

Supersedes the stale dependabot PR #10241, which covered 20 workflows and left
the rest on v5 and ci-unity.yml on v4. This takes all 29 call sites in 24
workflows at once so there is no v4/v5/v6 split to reason about later.

v6 exists to add pnpm v11 support, and the workspace is on pnpm 11.15.0. Every
call site pins that version explicitly, so v5 was not visibly broken, but
staying on a major that predates the pnpm version we actually run is not worth
the ambiguity.

The action's input surface is unchanged between v5 and v6 - same version, dest,
run_install, cache, cache_dependency_path, package_json_file and standalone
inputs, same node24 runtime - so no call site needed edits beyond the ref.

All 62 workflow files still parse as YAML.

* build(deps): align what can be aligned in the standalone Tauri workspaces

chuck-launcher, deathslayer-launcher and desktop-kbve/src-tauri each declare
their own [workspace], so cargo cannot bind them to the root
[workspace.dependencies] added in #15165. They have to be tracked by hand.

Aligned to the root pins:
- dirs 5 -> 6 in both launchers. Only dirs::data_local_dir() is used and it is
  unchanged. This also drops the old dirs-sys 0.4 subtree (redox_users plus a
  full windows-sys/windows-targets set), so the launcher lock gets smaller.
- tokio 1 -> 1.49 and thiserror 2 -> 2.0.12, floor raises only.

reqwest is deliberately NOT bumped to 0.13 here, unlike the main workspace.

0.13's rustls feature pulls the aws-lc-rs provider, and these three are separate
workspaces with their own lockfiles - so there is no shared-tree to deduplicate
and the only benefit would be cosmetic. The cost is real: building the bumped
version pulled aws-lc-rs, aws-lc-sys and cmake into the launcher lock, which
none of them needed before. ci-tauri-builder.yml runs on macos-latest,
windows-latest and a Linux runner with no cmake or NASM setup step, and
aws-lc-sys wants both on Windows. Trading a working desktop release pipeline for
version-string tidiness is not worth it.

Left as-is for the same reason: desktop-kbve keeps reqwest's default features
(native-tls), so it was never on the rustls path the main workspace uses.

Verified with cargo check --all-targets in each of the three workspaces
separately, 0 errors. deathslayer-launcher needs its icons/ generated to build
at all - only README.md is tracked there, so tauri::generate_context! fails on
unmodified dev too; checked with the icon set temporarily stubbed in.

Unrelated observation while here: deathslayer-launcher's Cargo.lock is untracked
while chuck-launcher's and desktop-kbve's are committed. Not changed here.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci CI/CD and GitHub Actions dependencies Pull requests that update a dependency file security Security update This issue is for an update or upgrade.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants