Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build(deps): bump PNPM from 8.3.1 to 8.6.4 #7330

Merged
merged 1 commit into from Jun 26, 2023

Conversation

yeikel
Copy link
Contributor

@yeikel yeikel commented May 16, 2023

@yeikel yeikel requested a review from a team as a code owner May 16, 2023 20:11
@jeffwidman
Copy link
Member

As always, thank you for these!

FYI that internally we have a deploy freeze for the next few days.

Once that ends, we'd prefer to avoid a big-bang release, so while we'll be merging docs changes and minor tweaks here and there, we're going to delay merging anything that bumps versions...

That way when the freeze lifts we can have a smaller safer deploy, get a healthy baseline of metrics, then iteratively start merging the slightly riskier bumps and watching them in production.

Copy link
Member

@jurre jurre left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We'll need to hold off merging this for a bit more, but going to approve so we know that it's good to go once we're ready

@deivid-rodriguez deivid-rodriguez changed the title build(deps): bump PNPM from 8.3.1 to 8.5.1 build(deps): bump PNPM from 8.3.1 to 8.6.3 Jun 22, 2023
@deivid-rodriguez deivid-rodriguez changed the title build(deps): bump PNPM from 8.3.1 to 8.6.3 build(deps): bump PNPM from 8.3.1 to 8.5.1 Jun 22, 2023
@deivid-rodriguez deivid-rodriguez changed the title build(deps): bump PNPM from 8.3.1 to 8.5.1 build(deps): bump PNPM from 8.3.1 to 8.6.3 Jun 22, 2023
@deivid-rodriguez
Copy link
Contributor

I edited this PR to bump PNPM all the way to 8.6.3.

The upgrade also fixes an issue specific to lockfiles generated with either PNPM 8.6.0 and 8.6.1. Those versions generated a lockfile format (lockfileVersion: '6.1') that previous PNPM versions cannot handle.

This will need some updates to smoke tests.

@deivid-rodriguez
Copy link
Contributor

Smoke tests failure should get fixed by dependabot/smoke-tests#82.

@deivid-rodriguez
Copy link
Contributor

@jurre You had already approved this but I added a few more changes on top of it, so I'll wait for a second review if that's ok 🙏.

@deivid-rodriguez
Copy link
Contributor

This PR fixes this error by the way!

@yeikel yeikel changed the title build(deps): bump PNPM from 8.3.1 to 8.6.3 build(deps): bump PNPM from 8.3.1 to 8.6.4 Jun 26, 2023
@yeikel yeikel force-pushed the patch-5 branch 3 times, most recently from 05b036f to 94d061c Compare June 26, 2023 03:08
@yeikel
Copy link
Contributor Author

yeikel commented Jun 26, 2023

@deivid-rodriguez 8.6.4 was released a couple of hours ago and I just updated this PR

@deivid-rodriguez
Copy link
Contributor

Thank you! By the way this is the upstream issue for the problem with the 6.1 format (now reverted as of 8.6.4).

Copy link
Contributor

@brrygrdn brrygrdn left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚀

Co-authored-by:  David Rodríguez <deivid.rodriguez@riseup.net>
@deivid-rodriguez
Copy link
Contributor

deivid-rodriguez commented Jun 26, 2023

Thank you @yeikel, @jurre and @brrygrdn!

@deivid-rodriguez deivid-rodriguez merged commit b70130d into dependabot:main Jun 26, 2023
83 checks passed
@yeikel yeikel deleted the patch-5 branch June 26, 2023 20:04
brettfo pushed a commit to brettfo/dependabot-core that referenced this pull request Oct 11, 2023
…abot#7330)

Co-authored-by: David Rodríguez <deivid.rodriguez@riseup.net>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

5 participants