Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Oct 1, 2025

This PR contains the following updates:

Package Type Update Change Age Confidence
actions/checkout action major v4 -> v5 age confidence
actions/setup-node action major v4.4.0 -> v6.0.0 age confidence
sponsorkit devDependencies major ^16.4.2 -> ^17.0.0 age confidence
yarn (source) packageManager minor 4.9.2 -> 4.10.3 age confidence

Release Notes

actions/checkout (actions/checkout)

v5

Compare Source

actions/setup-node (actions/setup-node)

v6.0.0

Compare Source

What's Changed

Breaking Changes

Dependency Upgrades

Full Changelog: actions/setup-node@v5...v6.0.0

v5.0.0

Compare Source

What's Changed
Breaking Changes

This update, introduces automatic caching when a valid packageManager field is present in your package.json. This aims to improve workflow performance and make dependency management more seamless.
To disable this automatic caching, set package-manager-cache: false

steps:
- uses: actions/checkout@v5
- uses: actions/setup-node@v5
  with:
    package-manager-cache: false

Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. See Release Notes

Dependency Upgrades
New Contributors

Full Changelog: actions/setup-node@v4...v5.0.0

antfu-collective/sponsorkit (sponsorkit)

v17.0.0

Compare Source

   🚨 Breaking Changes
   🐞 Bug Fixes
    View changes on GitHub

v16.5.0

Compare Source

   🐞 Bug Fixes
    View changes on GitHub
yarnpkg/berry (yarn)

v4.10.3

Compare Source

v4.10.2

Compare Source

v4.10.1

Compare Source

v4.10.0

Compare Source

v4.9.4

Compare Source

v4.9.3

Compare Source


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, on day 1 of the month ( * 0-3 1 * * ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Copy link

changeset-bot bot commented Oct 1, 2025

⚠️ No Changeset found

Latest commit: 3cd5810

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

Copy link

coderabbitai bot commented Oct 1, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Comment @coderabbitai help to get the list of available commands and usage tips.

Copy link

socket-security bot commented Oct 1, 2025

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​img/​sharp-linux-ppc64@​0.34.41001004788100
Updated@​img/​sharp-darwin-arm64@​0.33.5 ⏵ 0.34.41001004788100
Updated@​img/​sharp-darwin-x64@​0.33.5 ⏵ 0.34.41001004788100
Updated@​img/​sharp-linux-arm@​0.33.5 ⏵ 0.34.41001004788100
Updated@​img/​sharp-linux-arm64@​0.33.5 ⏵ 0.34.41001004788100
Updated@​img/​sharp-linux-s390x@​0.33.5 ⏵ 0.34.41001004788100
Updated@​img/​sharp-linux-x64@​0.33.5 ⏵ 0.34.41001004788100
Updated@​img/​sharp-linuxmusl-arm64@​0.33.5 ⏵ 0.34.41001004788100
Updated@​img/​sharp-linuxmusl-x64@​0.33.5 ⏵ 0.34.41001004788100
Updatedansis@​3.17.0 ⏵ 4.2.01001005594100
Added@​img/​colour@​1.0.01001007684100
Updatedsponsorkit@​16.4.2 ⏵ 17.0.076 -810010091 +4100
Added@​img/​sharp-libvips-linux-ppc64@​1.2.3100100788970
Updated@​img/​sharp-libvips-darwin-arm64@​1.0.4 ⏵ 1.2.3100100788970
Updated@​img/​sharp-libvips-darwin-x64@​1.0.4 ⏵ 1.2.3100100788970
Updated@​img/​sharp-libvips-linux-arm@​1.0.5 ⏵ 1.2.3100100788970
Updated@​img/​sharp-libvips-linux-arm64@​1.0.4 ⏵ 1.2.3100100788970
Updated@​img/​sharp-libvips-linux-s390x@​1.0.4 ⏵ 1.2.3100100788970
Updated@​img/​sharp-libvips-linux-x64@​1.0.4 ⏵ 1.2.3100100788970
Updated@​img/​sharp-libvips-linuxmusl-arm64@​1.0.4 ⏵ 1.2.3100100788970
Updated@​img/​sharp-libvips-linuxmusl-x64@​1.0.4 ⏵ 1.2.3100100788970
Updated@​quansync/​fs@​0.1.3 ⏵ 0.1.5100 +110080 +281 -5100
Added@​img/​sharp-win32-arm64@​0.34.4100100828670
Updated@​img/​sharp-win32-ia32@​0.33.5 ⏵ 0.34.4100100828870
Updated@​img/​sharp-win32-x64@​0.33.5 ⏵ 0.34.4100100828870
Updated@​img/​sharp-wasm32@​0.33.5 ⏵ 0.34.4100100858870
Updatedunconfig@​7.3.2 ⏵ 7.3.3100 +110095 +185 -2100
Updatedquansync@​0.2.10 ⏵ 0.2.11100 +1100100 +187100
Updatedsharp@​0.33.5 ⏵ 0.34.492100100 +188100
Updateddetect-libc@​2.0.4 ⏵ 2.1.2100 +1100100 +189100
Updatedjiti@​2.4.2 ⏵ 2.6.199 +110010089100
Updatedsemver@​7.7.2 ⏵ 7.7.3100 +1100100 +190100
Updateddotenv@​16.5.0 ⏵ 17.2.310010010093100

View full report

Copy link

@ellipsis-dev ellipsis-dev bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Important

Looks good to me! 👍

Reviewed everything up to 1f6f1b1 in 1 minute and 15 seconds. Click for details.
  • Reviewed 41 lines of code in 3 files
  • Skipped 2 files when reviewing.
  • Skipped posting 5 draft comments. View those below.
  • Modify your settings and rules to customize what types of comments Ellipsis leaves. And don't forget to react with 👍 or 👎 to teach Ellipsis.
1. .github/workflows/scheduler.yml:20
  • Draft comment:
    Updated actions/checkout to v5. Ensure that your runner environment meets any new requirements (e.g. recent runner versions).
  • Reason this comment was not posted:
    Confidence changes required: 0% <= threshold 50% None
2. .github/workflows/scheduler.yml:23
  • Draft comment:
    Updated actions/setup-node to v5.0.0. Verify that 'cache: yarn' works as expected with the new automatic caching behavior, and confirm the runner version is at least v2.327.1.
  • Reason this comment was not posted:
    Confidence changes required: 33% <= threshold 50% None
3. .yarnrc.yml:5
  • Draft comment:
    Yarn version updated to 4.10.3. Confirm that this new version is compatible with existing tooling and project setups.
  • Reason this comment was not posted:
    Confidence changes required: 0% <= threshold 50% None
4. package.json:7
  • Draft comment:
    Upgraded sponsorkit to ^17.0.0. Check the release notes for breaking changes (like the renaming fix) that might affect build outputs or integrations.
  • Reason this comment was not posted:
    Confidence changes required: 33% <= threshold 50% None
5. package.json:9
  • Draft comment:
    Updated the packageManager field to '[email protected]' to remain consistent with the .yarnrc.yml configuration.
  • Reason this comment was not posted:
    Confidence changes required: 0% <= threshold 50% None

Workflow ID: wflow_GKmE6gMNy7RwLADv

You can customize Ellipsis by changing your verbosity settings, reacting with 👍 or 👎, replying to comments, or adding code review rules.

@renovate renovate bot force-pushed the renovate/all branch 2 times, most recently from 492643e to 21030e0 Compare October 14, 2025 05:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants