fix(deps): update dependency pacote to v21 #105
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Note
Mend has cancelled the proposed renaming of the Renovate GitHub app being renamed to
mend[bot]
.This notice will be removed on 2025-10-07.
This PR contains the following updates:
^12.0.0
->^21.0.0
Release Notes
npm/pacote (pacote)
v21.0.3
Compare Source
Dependencies
eed1bd5
#431@npmcli/git@7.0.0
(#431)v21.0.2
Compare Source
Dependencies
32cb6d1
#429npm-pick-manifest@11.0.1
(#429)v21.0.1
Compare Source
Dependencies
aae7798
#428@npmcli/run-script@10.0.0
1b233e3
#428@npmcli/package-json@7.0.0
d4b97ec
#428sigstore@4.0.0
cf27487
#428npm-registry-fetch@19.0.0
3e89235
#428npm-packlist@10.0.1
d46fc27
#428npm-package-arg@13.0.0
2a6a9f0
#428hosted-git-info@9.0.0
bbb72cf
#428cacache@20.0.0
8a642c0
#426tar@7.4.3
(#426)Chores
f81d8ed
#417 bump @npmcli/arborist from 8.0.0 to 9.0.0 (#417) (@dependabot[bot])0310b7b
#422 tests should not inherit --ignore-scripts flag from `npm run t… (#422) (@owlstronaut)v21.0.0
Compare Source
bun.lockb
files are now included in the strict ignore list during packingBug Fixes
844dc08
update node engines to ^20.17.0 || >=22.9.0 (#414) (@wraithgar)Dependencies
2cb6fa7
#415npm-packlist@10.0.0
(#415)47b928c
#412 replace node builtin rmSync with rimraf (#412) (@mbtools)Chores
b6f35a2
#402 bump @npmcli/arborist from 7.5.4 to 8.0.0 (#402) (@dependabot[bot])1ef54ba
#408 support tests on win32 (#408) (@mbtools)555b000
#401 bump @npmcli/template-oss from 4.23.3 to 4.23.4 (#401) (@dependabot[bot], @npm-cli-bot)v20.0.0
Compare Source
Dependencies
aae7798
#428@npmcli/run-script@10.0.0
1b233e3
#428@npmcli/package-json@7.0.0
d4b97ec
#428sigstore@4.0.0
cf27487
#428npm-registry-fetch@19.0.0
3e89235
#428npm-packlist@10.0.1
d46fc27
#428npm-package-arg@13.0.0
2a6a9f0
#428hosted-git-info@9.0.0
bbb72cf
#428cacache@20.0.0
8a642c0
#426tar@7.4.3
(#426)Chores
f81d8ed
#417 bump @npmcli/arborist from 8.0.0 to 9.0.0 (#417) (@dependabot[bot])0310b7b
#422 tests should not inherit --ignore-scripts flag from `npm run t… (#422) (@owlstronaut)v19.0.1
Compare Source
Bug Fixes
cbf94e8
#389 prepare script respects scriptshell config (#389) (@milaninfy)2b2948f
#403 log tarball retrieval from cache (#403) (@mbtools, @wraithgar)Dependencies
a9fc4d1
#405 bump sigstore from 2.2.0 to 3.0.0 (#405) (@bdehamer)v19.0.0
Compare Source
Dependencies
aae7798
#428@npmcli/run-script@10.0.0
1b233e3
#428@npmcli/package-json@7.0.0
d4b97ec
#428sigstore@4.0.0
cf27487
#428npm-registry-fetch@19.0.0
3e89235
#428npm-packlist@10.0.1
d46fc27
#428npm-package-arg@13.0.0
2a6a9f0
#428hosted-git-info@9.0.0
bbb72cf
#428cacache@20.0.0
8a642c0
#426tar@7.4.3
(#426)Chores
f81d8ed
#417 bump @npmcli/arborist from 8.0.0 to 9.0.0 (#417) (@dependabot[bot])0310b7b
#422 tests should not inherit --ignore-scripts flag from `npm run t… (#422) (@owlstronaut)v18.0.6
Compare Source
Bug Fixes
79441a5
#371 clean up requires (#371) (@wraithgar)b19aacb
#369 isolate full and corgi packuments in packumentCache (#369) (@wraithgar)v18.0.5
Compare Source
Bug Fixes
5e75582
#368 dont set _contentLength if not in headers (#368) (@lukekarrys)1b6950b
#365 move bin to its own directory (@lukekarrys)1b6950b
#365 refactor: symbol cleanup (#365) (@lukekarrys)v18.0.4
Compare Source
pacote
now supports node^18.17.0 || >=20.5.0
Bug Fixes
03b31ca
#392 align to npm 10 node engine range (@reggi)Dependencies
f055f71
#395 bump npm-pick-manifest from 9.1.0 to 10.0.0 (#395) (@dependabot[bot])932b9ab
#396 bump @npmcli/package-json from 5.2.1 to 6.0.0 (#396) (@dependabot[bot])a1621f9
#397 bump npm-registry-fetch from 17.1.0 to 18.0.0 (#397) (@dependabot[bot])c776199
#398 bump cacache from 18.0.4 to 19.0.0 (#398) (@dependabot[bot])6d59022
#399 bump @npmcli/git from 5.0.8 to 6.0.0 (#399)21ea2d4
#400 bump @npmcli/run-script from 8.1.0 to 9.0.0 (#400)eddbc01
#392ssri@12.0.0
6c672e9
#392proc-log@5.0.0
03ba2a2
#392npm-packlist@9.0.0
2710286
#392npm-package-arg@12.0.0
aa0bd4a
#392@npmcli/promise-spawn@8.0.0
df23343
#392@npmcli/installed-package-contents@3.0.0
Chores
e4ed5cd
#392 bump hosted-git-info ^7.0.0 to ^8.0.0 (@reggi)2871f56
#392 run template-oss-apply (@reggi)39643f1
#382 bump @npmcli/eslint-config from 4.0.5 to 5.0.0 (@dependabot[bot])7e33c82
#383 postinstall for dependabot template-oss PR (@hashtagchris)e4e07bf
#383 bump @npmcli/template-oss from 4.23.1 to 4.23.3 (@dependabot[bot])v18.0.3
Compare Source
Dependencies
5ecce7a
#360npm-registry-fetch@17.0.0
(#360)v18.0.2
Compare Source
Bug Fixes
116b277
#358 don't strip underscore attributes in .manifest() (#358) (@wraithgar)v18.0.1
Compare Source
Bug Fixes
b547e0d
#356 use @npmcli/package-json (#356) (@lukekarrys)v18.0.0
Compare Source
pacote
now supports node^18.17.0 || >=20.5.0
Bug Fixes
03b31ca
#392 align to npm 10 node engine range (@reggi)Dependencies
f055f71
#395 bump npm-pick-manifest from 9.1.0 to 10.0.0 (#395) (@dependabot[bot])932b9ab
#396 bump @npmcli/package-json from 5.2.1 to 6.0.0 (#396) (@dependabot[bot])a1621f9
#397 bump npm-registry-fetch from 17.1.0 to 18.0.0 (#397) (@dependabot[bot])c776199
#398 bump cacache from 18.0.4 to 19.0.0 (#398) (@dependabot[bot])6d59022
#399 bump @npmcli/git from 5.0.8 to 6.0.0 (#399)21ea2d4
#400 bump @npmcli/run-script from 8.1.0 to 9.0.0 (#400)eddbc01
#392ssri@12.0.0
6c672e9
#392proc-log@5.0.0
03ba2a2
#392npm-packlist@9.0.0
2710286
#392npm-package-arg@12.0.0
aa0bd4a
#392@npmcli/promise-spawn@8.0.0
df23343
#392@npmcli/installed-package-contents@3.0.0
Chores
e4ed5cd
#392 bump hosted-git-info ^7.0.0 to ^8.0.0 (@reggi)2871f56
#392 run template-oss-apply (@reggi)39643f1
#382 bump @npmcli/eslint-config from 4.0.5 to 5.0.0 (@dependabot[bot])7e33c82
#383 postinstall for dependabot template-oss PR (@hashtagchris)e4e07bf
#383 bump @npmcli/template-oss from 4.23.1 to 4.23.3 (@dependabot[bot])v17.0.7
Compare Source
Dependencies
e07c3e5
#350proc-log@4.0.0
(#350)v17.0.6
Compare Source
Dependencies
0a5920f
#343 bump sigstore from 2.0.0 to 2.2.0 (#343) (@bdehamer)Chores
6fd23ad
#342 postinstall for dependabot template-oss PR (@lukekarrys)c3b398a
#342 bump @npmcli/template-oss from 4.21.1 to 4.21.3 (@dependabot[bot])4557919
#337 postinstall for dependabot template-oss PR (@lukekarrys)c7e293c
#337 bump @npmcli/template-oss from 4.19.0 to 4.21.1 (@dependabot[bot])v17.0.5
Compare Source
Bug Fixes
0c96b9e
#338 bug to support rotated keys in signature/attestation audit (#338) (@feelepxyz)v17.0.4
Compare Source
Dependencies
ba8f790
#309 bump @npmcli/promise-spawn from 6.0.2 to 7.0.02c0d3ae
#308 bump @npmcli/run-script from 6.0.2 to 7.0.0v17.0.3
Compare Source
Dependencies
ace7c28
#305 bump npm-packlist from 7.0.4 to 8.0.0v17.0.2
Compare Source
Dependencies
c3b892d
#303 bump sigstore from 1.3.0 to 2.0.0v17.0.1
Compare Source
Dependencies
6ddae13
#302 bump npm-registry-fetch from 15.0.0 to 16.0.042bf787
#300 bump npm-pick-manifest from 8.0.2 to 9.0.0v17.0.0
Compare Source
Dependencies
5ecce7a
#360npm-registry-fetch@17.0.0
(#360)v16.0.0
Compare Source
Dependencies
6ddae13
#302 bump npm-registry-fetch from 15.0.0 to 16.0.042bf787
#300 bump npm-pick-manifest from 8.0.2 to 9.0.0v15.2.0
Compare Source
Features
3307ad9
#278 configurable TUF cache dir (#278) (@bdehamer)v15.1.3
Compare Source
Dependencies
c99db13
#271 bump minipass from 4.2.7 to 5.0.0 (#271)v15.1.2
Compare Source
Documentation
43363dd
#266 update dist details (#266) (@wraithgar)Dependencies
d5cb3df
#276sigstore@1.3.0
(#276)c231986
#267 sigstore@^1.1.0v15.1.1
Compare Source
Bug Fixes
8f4e39c
#261 always ignore ownership from tar headers (#261) (@nlf)v15.1.0
Compare Source
Features
2916b72
#259 verifyAttestations to registry.manifest (@feelepxyz, @bdehamer)Dependencies
f0bd19b
add sigstore 1.0.0v15.0.8
Compare Source
Dependencies
40aa6fe
#253 bump fs-minipass from 2.1.0 to 3.0.0v15.0.7
Compare Source
Dependencies
a734d61
#250 bump minipass from 3.3.6 to 4.0.0v15.0.6
Compare Source
Dependencies
dbbda43
#246@npmcli/run-script@6.0.0
v15.0.5
Compare Source
Dependencies
63797a8
#244 bump @npmcli/promise-spawn from 5.0.0 to 6.0.1 (#244)v15.0.4
Compare Source
Dependencies
854fad1
#239 bump @npmcli/promise-spawn from 4.0.0 to 5.0.0 (#239)v15.0.3
Compare Source
Dependencies
2a95ddb
#235 bump @npmcli/installed-package-contents (#235)v15.0.2
Compare Source
Bug Fixes
95f9cd5
handle new npm-package-arg semantics (@wraithgar)Dependencies
2ed4d22
npm-package-arg@10.0.0
v15.0.1
Compare Source
Dependencies
74821c2
#229 bump @npmcli/run-script from 4.2.1 to 5.0.0 (#229)a9844d0
#226 bump @npmcli/promise-spawn from 3.0.0 to 4.0.0 (#226)1058177
#227 bump read-package-json from 5.0.2 to 6.0.00f5ef8a
#228 bump @npmcli/installed-package-contents from 1.0.7 to 2.0.07e3b4b5
#220 bump ssri from 9.0.1 to 10.0.04e7536d
#222 bump @npmcli/git from 3.0.2 to 4.0.03bc7550
#223 bump npm-pick-manifest from 7.0.2 to 8.0.041fab27
#224 bump proc-log from 2.0.1 to 3.0.04abf24a
#218 bump npm-registry-fetch from 13.3.1 to 14.0.0 (#218)v15.0.0
Compare Source
Dependencies
6ddae13
#302 bump npm-registry-fetch from 15.0.0 to 16.0.042bf787
#300 bump npm-pick-manifest from 8.0.2 to 9.0.0v14.0.0
Compare Source
Dependencies
74821c2
#229 bump @npmcli/run-script from 4.2.1 to 5.0.0 (#229)a9844d0
#226 bump @npmcli/promise-spawn from 3.0.0 to 4.0.0 (#226)1058177
#227 bump read-package-json from 5.0.2 to 6.0.00f5ef8a
#228 bump @npmcli/installed-package-contents from 1.0.7 to 2.0.07e3b4b5
#220 bump ssri from 9.0.1 to 10.0.04e7536d
#222 bump @npmcli/git from 3.0.2 to 4.0.03bc7550
#223 bump npm-pick-manifest from 7.0.2 to 8.0.041fab27
#224 bump proc-log from 2.0.1 to 3.0.04abf24a
#218 bump npm-registry-fetch from 13.3.1 to 14.0.0 (#218)v13.6.2
Compare Source
Bug Fixes
v13.6.1
Compare Source
Dependencies
v13.6.0
Compare Source
Features
Bug Fixes
Documentation
v13.5.0
Compare Source
Features
13.4.1 (2022-05-19)
Bug Fixes
v13.4.1
Compare Source
Features
13.4.1 (2022-05-19)
Bug Fixes
v13.4.0
Compare Source
Features
13.4.1 (2022-05-19)
Bug Fixes
v13.3.0
Compare Source
Features
v13.2.0
Compare Source
Features
13.1.1 (2022-04-06)
Dependencies
v13.1.1
Compare Source
Features
13.1.1 (2022-04-06)
Dependencies
v13.1.0
Compare Source
Features
13.1.1 (2022-04-06)
Dependencies
v13.0.6
Compare Source
Features
13.0.6 (2022-04-05)
Bug Fixes
Dependencies
13.0.5 (2022-03-15)
Dependencies
13.0.4 (2022-03-14)
Dependencies
13.0.3 (2022-02-23)
Bug Fixes
Dependencies
13.0.2 (2022-02-16)
Bug Fixes
Dependencies
13.0.1 (2022-02-16)
Bug Fixes
Dependencies
v13.0.5
Compare Source
Features
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.