Skip to content

build: update all non-major dependencies#3545

Merged
alan-agius4 merged 1 commit intoangular:mainfrom
angular-robot:ng-renovate/all-non-major-dependencies
Mar 16, 2026
Merged

build: update all non-major dependencies#3545
alan-agius4 merged 1 commit intoangular:mainfrom
angular-robot:ng-renovate/all-non-major-dependencies

Conversation

@angular-robot
Copy link
Copy Markdown
Contributor

@angular-robot angular-robot commented Mar 16, 2026

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@google/genai 1.44.01.45.0 age adoption passing confidence
firebase-tools 15.9.115.10.0 age adoption passing confidence
puppeteer (source) 24.39.024.39.1 age adoption passing confidence
puppeteer-core (source) 24.39.024.39.1 age adoption passing confidence
renovate (source) 43.62.043.76.0 age adoption passing confidence
rollup-plugin-dts 6.3.06.4.0 age adoption passing confidence
undici (source) 7.22.07.24.3 age adoption passing confidence

Release Notes

googleapis/js-genai (@​google/genai)

v1.45.0

Compare Source

Features
  • Add inference_generation_config to EvaluationConfig for Tuning (b4ac722)
  • enable language code for audio transcription config in Live API for Vertex AI (67f39ec)
firebase/firebase-tools (firebase-tools)

v15.10.0

Compare Source

  • Add support for VPC direct connect in GCF 2nd gen (#​10033)
  • Added --only flag for emulators:export (#​4033)
  • Added support for custom PostgreSQL schema names in Data Connect. (#​9271)
  • When SSR web app features are detected in the firebase init hosting flow, offer to switch to App Hosting (#​9887)
  • Removed the experimental web frameworks prompt from firebase init hosting (#​9843)
  • Added studio:export command to export Firebase Studio projects to Antigravity.
puppeteer/puppeteer (puppeteer)

v24.39.1

Compare Source

♻️ Chores
  • puppeteer: Synchronize puppeteer versions
Dependencies
  • The following workspace dependencies were updated
    • dependencies
      • puppeteer-core bumped from 24.39.0 to 24.39.1
🛠️ Fixes
renovatebot/renovate (renovate)

v43.76.0

Compare Source

Features
  • pip_requirements: detect requirements files with underscores (#​41911) (484c2ec)

v43.75.0

Compare Source

Features
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.25.0 (main) (#​41927) (425ca26)

v43.74.0

Compare Source

Features
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.24.0 (main) (#​41926) (4847242)
Miscellaneous Chores

v43.73.2

Compare Source

Bug Fixes

v43.73.1

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.23.1 (main) (#​41920) (dd1a102)
Miscellaneous Chores

v43.73.0

Compare Source

Features
  • config-migration: preserve comments when migrating renovate.json (#​38646) (e8a5c70)

v43.72.0

Compare Source

Features
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.23.0 (main) (#​41915) (8be386e)
Miscellaneous Chores

v43.71.0

Compare Source

Features
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.22.0 (main) (#​41909) (5906313)

v43.70.0

Compare Source

Features
Bug Fixes
Miscellaneous Chores
  • deps: update containerbase/internal-tools action to v4.4.1 (main) (#​41907) (ba21ce6)

v43.69.0

Compare Source

Features

v43.66.5

Compare Source

Bug Fixes
Miscellaneous Chores
  • deps: update containerbase/internal-tools action to v4.2.3 (main) (#​41880) (5be6098)
  • deps: update pnpm/action-setup action to v4.4.0 (main) (#​41888) (447ec1a)

v43.66.4

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.21.10 (main) (#​41871) (3145b2d)
Miscellaneous Chores

v43.66.3

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.21.9 (main) (#​41869) (4473d6c)

v43.66.2

Compare Source

Miscellaneous Chores
Build System

v43.66.1

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.21.8 (main) (#​41865) (7465ff1)
Miscellaneous Chores

v43.66.0

Compare Source

Features
  • git-refs: use dereferenced commit hash for annotated tags (#​41560) (74233b1)

v43.65.0

Compare Source

Features
Miscellaneous Chores

v43.64.6

Compare Source

Bug Fixes
  • datasource/rpm: accept repomd.xml without xml declaration (#​41850) (9175699)
Miscellaneous Chores

v43.64.5

Compare Source

Bug Fixes
  • correctly initialise logger for renovate-config-validator (#​41844) (31562cb)
Documentation
Miscellaneous Chores

v43.64.4

Compare Source

Bug Fixes
  • mise: use semver-partial versioning for short java versions (#​41179) (5429e7c)
Documentation

v43.64.3

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.21.7 (main) (#​41832) (ab1afc4)
Miscellaneous Chores

v43.64.2

Compare Source

Build System

v43.64.1

Compare Source

Bug Fixes
Miscellaneous Chores
  • deps: update actions/download-artifact action to v8.0.1 (main) (#​41823) (fc12b55)
  • deps: update containerbase/internal-tools action to v4.1.23 (main) (#​41824) (d997f77)

v43.64.0

Compare Source

Features
Miscellaneous Chores

v43.63.0

Compare Source

Features
  • gradle: add support for short dependency notation in version catalogs (#​41797) (c06b551)
  • presets/replacement: Add @base-ui-components/react => @base-ui/react rename (#​41787) (9df72b1)
Documentation
Miscellaneous Chores
Swatinem/rollup-plugin-dts (rollup-plugin-dts)

v6.4.0

Compare Source

Features:

  • Implement proper SourceMap support with goto-definition granularity
  • Support dotted namespace syntax

Fixes:

  • Better naming for declare module paths
  • Add compatibility with TS6

Thank you:

Features, fixes and improvements in this release have been contributed by:

nodejs/undici (undici)

v7.24.3

Compare Source

What's Changed
  • fix(h2): TypeError: Cannot read properties of null (reading 'push') i… by @​hxinhan in #​4881

Full Changelog: nodejs/undici@v7.24.2...v7.24.3

v7.24.2

Compare Source

What's Changed

Full Changelog: nodejs/undici@v7.24.1...v7.24.2

v7.24.1

Compare Source

What's Changed

Full Changelog: nodejs/undici@v7.24.0...v7.24.1

v7.24.0

Compare Source

Undici v7.24.0 Security Release Notes

This release addresses multiple security vulnerabilities in Undici.

Upgrade guidance

All users on v7 should upgrade to v7.24.0 or later.

Fixed advisories
Affected and patched ranges
References

v7.23.0

Compare Source

What's Changed
New Contributors

Full Changelog: nodejs/undici@v7.22.0...v7.23.0


  • If you want to rebase/retry this PR, check this box

@angular-robot angular-robot added action: merge The PR is ready for merge by the caretaker area: build & ci Related the build and CI infrastructure of the project target: automation This PR is targeted to only merge into the branch defined in Github [bot use only] labels Mar 16, 2026
Copy link
Copy Markdown

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates several non-major dependencies. The update to undici is particularly important as it includes security fixes. I've added a few comments regarding inconsistent dependency versioning practices (mixing pinned versions with ranges) which could be improved for better build predictability and maintainability. Otherwise, the dependency updates themselves look good and are ready to be merged.

"firebase-admin": "13.7.0",
"firebase-functions": "7.1.1",
"firebase-tools": "15.9.1"
"firebase-tools": "15.10.0"
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

While updating firebase-tools to a pinned version, I noticed that @apollo/server and @as-integrations/express4 use version ranges. For consistency and more predictable builds, consider pinning all dependencies to specific versions.

"memfs": "^4.14.0",
"rollup": "^4.59.0",
"rollup-plugin-dts": "6.3.0",
"rollup-plugin-dts": "6.4.0",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

For consistency with this newly pinned version and other dependencies in this file, consider also pinning the rollup dependency on the line above. Using a mix of pinned versions and version ranges (^) can make dependency management less predictable.

"micromatch": "^4.0.8",
"typed-graphqlify": "3.1.6",
"undici": "7.22.0",
"undici": "7.24.3",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

I notice that most dependencies in this file are pinned to specific versions, but @google/genai uses a version range (^1.43.0). For consistency, you might want to pin it to a specific version as well. This would make dependency resolution more predictable.

"@actions/core": "3.0.0",
"@google-cloud/spanner": "8.0.0",
"@google/genai": "1.44.0",
"@google/genai": "1.45.0",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

This file has a mix of pinned dependencies and dependencies with version ranges (e.g., zod: ^4.3.6). For more predictable dependency resolution, it would be beneficial to consistently pin all dependencies to specific versions.

"@bazel/bazelisk": "1.28.1",
"@bazel/buildifier": "8.2.1",
"firebase-tools": "15.9.1",
"firebase-tools": "15.10.0",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

This file contains a mix of pinned versions and version ranges (e.g., tslib: ^2.5.2). To ensure more predictable builds, it's a good practice to pin all dependencies to specific versions.

See associated pull request for more information.
@angular-robot angular-robot force-pushed the ng-renovate/all-non-major-dependencies branch from 0640013 to e620716 Compare March 16, 2026 08:50
@alan-agius4 alan-agius4 merged commit a2bf852 into angular:main Mar 16, 2026
13 checks passed
@alan-agius4
Copy link
Copy Markdown
Contributor

This PR was merged into the repository. The changes were merged into the following branches:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action: merge The PR is ready for merge by the caretaker area: build & ci Related the build and CI infrastructure of the project target: automation This PR is targeted to only merge into the branch defined in Github [bot use only]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants