Skip to content

chore(deps): update dependency @nubjs/nub to v0.9.5 - #117

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/nubjs-nub-0.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/nubjs-nub-0.x

Conversation

@renovate

@renovate renovate Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@nubjs/nub (source) 0.9.3 → 0.9.5 age confidence

Release Notes

nubjs/nub (@​nubjs/nub)

v0.9.5: Nub 0.9.5

Compare Source

The release archives carry the nubx and nubr aliases, the GitHub Actions move into this repository with a new npm-ci step, and the package manager gets a run of install fixes.

Package manager

Area What changed Links
Hoisted layout Under node-linker=hoisted, a package could be hoisted to where it shadowed a dependency its parent resolves further up, so send loaded ms 2.0.0 where it resolves 2.1.3. The placement walk now records the names each package resolves through an ancestor and never hoists over them. The isolated layout is unaffected. #​965, 2c2bcc0571
Failed builds Several failed dependency builds were reported as one, and the install exited 1. Every required failure is now reported in build order, and the process exits with the first failing script's code, as under nub run, npm, and pnpm. Fixes #​670. #​955, fdd8a7d485
tsconfig.json An extends that points through a package exports subpath pattern, such as astro/tsconfigs/strict, resolves as it does under tsc. A lifecycle script can generate the extends target, so a SvelteKit prepare script that writes .svelte-kit/tsconfig.json no longer fails under the node shim before the file exists. Fixes #​804. #​957, 1b917f61b1
Tarball dependencies The manifest scan of a git, file, or URL tarball stopped after 64 MiB of entries, so a URL-pinned next failed with unexpected EOF during skip. The cap now matches the store's 1 GiB extraction cap. #​959, a550619d2f
nub update -i An exact pin such as "chalk": "4.1.0" gets an in-range column computed as if the spec were ^4.1.0, and the pick is written back in the pin's own style (4.1.0, =4.1.0, npm:chalk@4.1.0). A mixed run such as nub update chalk@latest semver now rewrites the range floor of semver the way a solo nub update semver does. Fixes #​952. #​958, 733d0e8cd2
Node versions An alias pin (lts/*, lts/<codename>, node, latest) in .nvmrc provisioned through nub node install and then failed nub node which and nub run offline. The offline discovery path now resolves an alias against the release index the last provisioning run cached. #​966, 18cad48f58
Routed installs Under nub pm shim, the lifecycle scripts of a routed npm install or npm ci run under the node on PATH. The install consults no Node pin and provisions nothing, as under npm. #​967, 44e3df1633
Binaries A project's own bin entries no longer overwrite a dependency's entry of the same name in node_modules/.bin, so a prepare script that runs the rollup devDependency runs the dependency and not the project's unbuilt output. #​967, 44e3df1633

GitHub Actions

The setup-node and install actions now live in this repository and are consumed as nubjs/nub/setup-node@v0 and nubjs/nub/install@v0, ported from nubjs/action. The floating v0 tag moves to each stable release. (#​961, dc3e38b738)

A third action, nubjs/nub/npm-ci@v0, replaces a run: npm ci line for a project with a package-lock.json. It installs exactly what the lockfile records, hoisted as npm lays it out, runs every lifecycle script under the job's node, and fails if the lockfile changed, if the lockfile is missing, or if package.json disagrees with it. The args input takes the flags of npm ci, and a flag the engine does not honor fails the action rather than running npm. (#​967, 44e3df1633)

  - uses: actions/setup-node@v4
    with:
      node-version: 22
      cache: npm
- - run: npm ci
+ - uses: nubjs/nub/npm-ci@v0
+   with:
+     lockfile: package-lock.json
  - run: npm test

The GitHub Action page documents all three.

Release archives

Every release archive now carries the nubx and nubr aliases, so a plain extraction is a complete install. The Unix tarballs carry bin/nubx and bin/nubr as relative symlinks to bin/nub, and the Windows zips carry bin/nubx.exe and bin/nubr.exe, small stubs that run the sibling nub.exe under their own name.

The install scripts and nub upgrade keep their alias step as a fallback for an archive from before this release. (#​956, 5f4503439c)

Canary channel

[!NOTE]
The nightly canary no longer publishes to npm. It ships only as the rolling canary release on GitHub. An npm install of @nubjs/nub@canary receives no new nightlies. Install the canary with curl -fsSL https://nubjs.com/install.sh | bash -s canary, switch an existing install with nub upgrade --canary, and return with nub upgrade --stable. (#​973, 3452fb4f42)

Release pipeline

  • Every npm publish in a release is now npm stage publish. The trusted publishers of the @nubjs packages are stage-only, so CI can fill the staged queue and nothing else. A maintainer approves the staged versions with 2FA, and the workflow polls the registry before it promotes the draft GitHub Release to stable. (#​973, 3452fb4f42)
  • A stable release starts from a workflow_dispatch on main. The run reads the version from npm/nub/package.json and creates the v<version> tag itself after the gates pass; the push: tags trigger is gone. (#​975, 97b9414a34)
  • The public launcher-fetch smoke runs after the release is promoted, not while it is a draft (fe9c5310c5).
  • The staging script resolves each package directory before it reads the package's package.json (5727154ead).

Documentation

The Threadpool page now says what keeps the demoted worker threads off other work: a nice value ranks a thread only against the tasks in its own cgroup, and the cgroup's CPU weight is what bounds the pool against a neighbouring container or service. The page also notes that the pool size is how many tasks run at once, which is what bounds memory for a task such as a large image resize. (#​945, b1bf6b0199)

Testing & internals

  • The compiled-executable corpus runs each of its 14 packages cold and warm with the source and node_modules hidden, requires a successful plain-Node control, compares complete stdout, and exercises SQLite persistence and real Express requests. It runs in Linux CI. (#​954, 0532dfb268)
  • The scripts/check-lockfiles.sh script verifies every tracked Cargo.lock and reports a cold crate cache as unverified rather than stale. It runs in make verify and the pre-push hook. (#​945, b1bf6b0199)
  • The framework matrix gains a next-gvs arm that runs Next.js on the shared store through the turbopackAdditionalRoots option (3d01ab99b5).
  • The cold-start research note records that the generator fix is per process, not per isolate, with a four-way re-measurement (49d4f7cd0a).

What's Changed

Full Changelog: nubjs/nub@v0.9.3...v0.9.5


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant