chore(deps): update dependency @nubjs/nub to v0.8.2 - #75
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/nubjs-nub-0.x
branch
from
August 29, 2026 05:13
61b914b to
d5f331f
Compare
renovate
Bot
force-pushed
the
renovate/nubjs-nub-0.x
branch
from
August 31, 2026 20:03
d5f331f to
8157976
Compare
renovate
Bot
force-pushed
the
renovate/nubjs-nub-0.x
branch
3 times, most recently
from
September 1, 2026 07:40
d99e9a1 to
3f2573d
Compare
renovate
Bot
force-pushed
the
renovate/nubjs-nub-0.x
branch
from
September 2, 2026 18:02
3f2573d to
9338b8f
Compare
Contributor
Author
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
Member
|
@renovate rebase |
1 similar comment
Member
|
@renovate rebase |
Resolve lockfile conflict: regenerate pnpm-lock.yaml with @nubjs/nub 0.8.2
Resolve lockfile conflict: regenerate pnpm-lock.yaml with @nubjs/nub 0.8.2
lzm0x219
force-pushed
the
renovate/nubjs-nub-0.x
branch
from
September 2, 2026 18:37
cc3088b to
5208e91
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.6.0→0.8.2Release Notes
nubjs/nub (@nubjs/nub)
v0.8.2: Nub 0.8.2Compare Source
Nub's TypeScript loader is now available as a standalone package for plain Node, alongside fixes across install, resolution, configuration, runtime compatibility, and
nub compile.Standalone loader
The package arms the shared resolve and transpile hooks and nothing else. Every preload form Node accepts works:
It also works anywhere a preload can be set rather than passed, such as
NODE_OPTIONS="--import @nubjs/loader" vitest.The native transform rides eight
@nubjs/loader-<platform>packages asoptionalDependencies, covering macOS, Linux (glibc and musl), and Windows on x64 and arm64. Documentation is at nubjs.com/docs/loader. (#810)Install and update
trustPolicy=no-downgradenow backtracks to an older version in the same range that still carries its trust evidence, instead of aborting the install. This matches how the age gate already resolved the same situation.outdated,updateconfigconfig list --allor written byconfig set. Setting one previously added a key to your.npmrcthat changed nothing.Runtime
--experimental-webstorageis passed on the command line instead of throughNODE_OPTIONS. That variable is inherited by every descendant process, and the flag does not exist before Node 22.4, so any child running an older Node aborted at startup with exit 9. This was reachable in practice: a host on the Node 22.4–24 band running Electron 34 or earlier, which embeds Node 20.18.1, hit it. (#812)Compile
nub compilefinds the strip tool on Windows. The probe tested for a bare filename, so it never matchedllvm-strip.exeand every compile on a Windows host silently took the unstripped path — anote:on stderr and an artifact roughly 4 MB larger than it should be. The probe is now PATHEXT-aware. (#827)Testing and internals
Cross-runtime compatibility results now run
node:testfiles underbun test, matching how Deno is already measured, and the published numbers are updated accordingly (#820). The age-gate warning for registries that publish no dates gained end-to-end coverage (#813). Host build tooling gained a compile-slot cap (#808) and a self-pruning target directory collector (a247a22). None of these changes affect the released binary.What's Changed
Full Changelog: nubjs/nub@v0.8.1...v0.8.2
v0.8.1: Nub 0.8.1Compare Source
Nub 0.8.1 is a patch release: a lockfile fix for pnpm 12, a round of Node-version and loader compatibility fixes in the runtime, and global-install repairs in the package manager.
Package manager
peerDependenciesMetarecords onlyoptional: trueentries, matching pnpm; pnpm 12 reads the result under--frozen-lockfile.bun.lockno longer outrankspackage-lock.jsonand gets serialized back out as it.nub install -g <pkg>produces a runnable command, andnub remove -gunlinks the bins it created instead of leaving dangling entries in the global bin directory. Fixes #642.nub outdatedminimumReleaseAgewindow is applied without remark, asinstallandupdateapply it; the per-cell marker and the footer naming the held version are gone.Runtime
module.registerHooksreached the 23.x line at 23.5.0, and those releases threw at startup under the fast tier.nub compilerefuses an external-shim build targeting that band for the same reason.--enable-source-mapsis withheld on every Node 26.x below 26.8, the band affected by nodejs/node#63169.require("node:test"),node:sqlite,node:seaandnode:test/reporterswork again on Node 22.15.0–22.17.1, 23.5.0–23.11.1 and 24.0.0–24.3.0, where a registered resolve hook dropped thenode:scheme (fixed upstream in 22.18, 24.4 and 25+).file:URL passes through the load hook untouched, so a custom-protocol ESM loader behaves as it does on plain Node.--env-filevalues are no longer$VAR-expanded, matching Node. A value holding a literal$arrives intact..env.schemadiscovery walks from the project root up to the workspace root, so a schema at an enclosing package or at a directory without a manifest is found.file:URL as itssourceURL, so editor and DevTools breakpoints match the same script identity as undernode.URL.revokeObjectURL()with no argument throwsERR_MISSING_ARGS, as Node does.Documentation and site
--env-fileand.env.schemabehavior; the Varlock page's monorepo callout is updated. (#809)abe3a6a)c93d676)?section=share links route to an on-demand variant. (dbb4ae1)985d122)Testing & internals
nub.lock, and CI bootstraps withnub. (#807)runtime/builds into an isolated target directory. (#801)d50b1c2)5992582,ec69670)374c253)What's Changed
Full Changelog: nubjs/nub@v0.8.0...v0.8.1
v0.8.0: Nub 0.8.0Compare Source
Nub 0.8.0 reworks environment-file configuration, ships a round of package-manager correctness fixes, and adds garbage collection for the package store.
Breaking changes
File paths in
envFilego in an array."envFile": ".env"is now an error naming[".env"]; a string value is reserved for mode names, and"varlock"is the only one. This makesenvFileconsistent with the other list-valued config fields. (#735)A declared
envFilenow displaces a.env.schemahand-over, at every scope. A.env.schemafile decides the environment only when noenvFileis declared. Previously the two together were a hard error, andenvFile: falsein a schema project loaded the schema anyway. Now declared intent wins:envFile: false(or--no-env-file) loads nothing, anenvFilelist loads those files, andenvFile: "varlock"keeps the hand-over explicitly. This applies to a global-scopeenvFiletoo, so a machine-wideenvFile: falseempties a schema project unless the project declares"varlock". (#735, #774)An unreadable
tsconfig.jsonnow refuses the run. A project tsconfig whoseextendstarget is missing previously ran under options its author never wrote —extendsis wherestrict,target, and path aliases usually live. Nub now stops with the read error, astscdoes (TS5083). Fix the config, or run with--node. A dependency's own unreadable tsconfig is still salvaged rather than fatal. (#778, #768)Another package manager's config no longer directs the
node_moduleslayout. The layout is configured innub.jsonc(install.linker,install.publicHoist) under every project identity. The last two branded exceptions are gone: pnpm 11'spnpm-workspace.yamllayout keys are no longer read, and npm'sinstall-strategy=nestedno longer aborts the install. (#698)Version-gated feature flags moved out of
NODE_OPTIONS.NODE_OPTIONSis inherited by the whole process subtree, and flags matched to the host Node aborted any descendant on an older Node — Electron apps exited at startup. Feature flags now ride argv instead. Cost: a tool that spawns Node by absolute path (bypassing the shim) loses the version-gated features, though it keeps the preload and source-map remapping. (#777)Package manager
optionalDependenciesentry skips the package with a warning instead of failing the install, matching npm and pnpm.nub store prunenow garbage-collects the global virtual store and extracted-tree tiers, not just the content store. Installs register the project with the store; a project whose last install predates 0.8.0 registers on its next install.nub outdatedminimumReleaseAgenow applies to both reported columns, so the report no longer offers upgradesnub updatewould decline. A held version is marked with the time it becomes installable, and a project whose only pending upgrade is held exits 0.store-diroverride now moves every store tier together, so phantom-dependency protection keeps working and the machine's default store stays untouched..binwrappersnodenpm package) no longer produces a wrapper that resolves to itself —nub install nodeused to hang.nub updateresolves in the workspace-root frame.nub config initwritesnub.jsoncat the workspace root.1.0.0no longer beats2.0.0on lexicographic accident.NUB_CACHE_DIRmoves the engine cache, andnub config get/listreport values set through the environment.XDG_DATA_HOMEon a fresh install; an existing~/.nubinstall keeps its path.Runtime
import deferNODE_OPTIONSis seen by the CommonJS-sync guard.fetchcache@nubjs/typescovers the six polyfilled proposals anes2024lib can't reach.nub.exereserves an 8 MB main-thread stack, matchingnode.exe.CLI
pmandnodecommand groups. (#739)nub run, and--colortakes effect. (#744)What's Changed
nub.exeon Windows by @pullfrog[bot] in #701import deferon Node 26.4+ by @colinhacks in #770New Contributors
Full Changelog: nubjs/nub@v0.7.5...v0.8.0
v0.7.5Compare Source
A memory-retention release, plus two fixes to
nub upgrade.Memory retention
Seven unbounded-retention defects, each reproduced with a fixture against a plain Node control before and after the fix. (#702)
nub run -rsupervisornub run -r dev— grew the supervisor 1:1 with child output.URL.createObjectURLBlobsetImmediatethe process exited before running, so a user whose runs are all synchronous never swept. It is now scheduled only when a sweep is due, and ref'd.Upgrade
Fixes in #705.
installed v0.7.4 to \\?\C:\Users\you\.nub. The install itself was always correct. Paths are now spelled for display at the print sites, while the path used for the file swap keeps theMAX_PATHexemption a deep install directory depends on. (#704)nub upgradewith nothing newer to install downloaded and swapped in the release it was already running. It now reportsalready on the latest releaseand stops. An explicit--versionstill reinstalls, which is what repairs a damaged install, and--stablefrom a canary build still downloads, because that is a channel switch. (#664)--yesflag advertised a confirmation prompt that has never existed. Its help text now says what it does.Docs
The reference pages were rewritten for density — the config reference, the FAQ, and the install, runtime, runner and deployment sections — and two rotted links were fixed.
What's Changed
Full Changelog: nubjs/nub@v0.7.4...v0.7.5
v0.7.4Compare Source
Nub 0.7.4 adds guided config setup and makes missing-package errors authoritative during installs.
Configuration
nub config initcreates a commented, behavior-neutralnub.jsoncat the project root.nub config init --globalcreates the user config instead, and both forms refuse to replace an existing file.The config command now uses project scope by default,
--globalfor user scope, andnub global configas the prefix form. The former--locationoption has been removed. Protected npm credentials continue to default to the user.npmrc;--localselects a project credential explicitly. (#694)Package installation
Missing registry packages now fail with
ERR_NUB_PACKAGE_NOT_FOUNDbefore similarity or package-age warnings run. Public unscoped typos can include a non-interactive suggestion; scoped package names no longer suggest unrelated basenames from another namespace. (#693)Documentation and site
5b690fb9888c8aa825d7555b6294What's Changed
Full Changelog: nubjs/nub@v0.7.3...v0.7.4
v0.7.3Compare Source
A Windows fix for
nub run, native TypeScript transform configuration, and import-text on the Node 24 LTS backport.Windows
nub runexecutes script bodies through a bundled busyboxsh, which the binary resolves relative to itself. 0.7.0 began hardlinkingnub.exeinto npm's global bin directory for a faster dispatch path, which moved the binary away from that shell — so the first call after an install worked and every later one failed. The launcher now carries the shell into anub-sh/subdirectory beside the relocated binary, and the resolution accepts that layout. It goes in a subdirectory rather than beside the executable because that directory is onPATH, where a barebusybox.exewould shadow a busybox the user installed themselves. (#699, #687)Configuration
Project
nub.jsoncgains six native TypeScript transform fields —jsx,jsxFactory,jsxFragmentFactory,jsxImportSource,decorators, andemitDecoratorMetadata. (#697)Runtime
--experimental-import-textis injected on the 24.19.0 LTS backport band as well as 26.5+, so a Node that knows the flag no longer falls through to the default loader and fails withERR_UNKNOWN_FILE_EXTENSION439853bcustomConditionsfromtsconfig.jsonare applied as Node export conditions005e8e4dfe9b73.env.schemaownership is decided by loader resolution, and a missing schema is a refusal rather than a degrade7dfeb95Types
@nubjs/typessplits its shared declarations intocommon.d.tsand routes pre-6.0 compilers through a dedicated entry, so proposal declarations coexist with the official ones as they land. The fixture matrix runs under TypeScript 5.9, 6.0 and 7.0. (e29dc5c)Testing & internals
nub.jsoncsettingnodeCompat: truewas removed; it disabled augmentation for every in-tree test and took the whole test matrix red (#696, #695).v0.7config-schema snapshot was refreshed againstlatest.jsonafter the transform fields landed, restoring the release verification gate (f58f09f).ddcf309,f1b2542,1eb177c).What's Changed
--experimental-import-texton the 24.19.0 backport band by @pullfrog[bot] in #689Full Changelog: nubjs/nub@v0.7.2...v0.7.3
v0.7.2Compare Source
Supply-chain and workspace resolution fixes, plus per-invocation platform selection for cross-platform installs.
Release-age gate
Running a tool without naming a version resolves the
latesttag, which narrowed to that one version — so aminimumReleaseAgewindow covering it left nothing to fall back to andnubx <tool>failed outright. A blockedlatestnow resolves to the newest release that clears the window (#682, #681).The fallback stops at whatever the publisher currently tags
latest, so a higher version they published and then untagged is never selected, and alatestpointing at a prerelease is refused rather than falling back onto a stable release from an older line. The same narrowing also affected the non-strict mode in the opposite direction — the blocked release was the only candidate, so it was re-selected and the window had no effect. It is now enforced there too.Installs
--os,--cpuand--libcselect optional dependencies for a target other than the host, per invocation (#683)af33650workspace:<path>tail naming a member directory resolves to that member instead of being read as a version range and sent to the registry (#674)ab7350eadac3afab7350eDiagnostics
The refusal to accept a
nodeOptionsentry now namesNODE_OPTIONSas the constraint doing the refusing (#684,c178118).Documentation
The package-manager page's layout section is reworked to state the policy as neutral-surface-first, with a dead npmrc example corrected and a duplicated build-approval enumeration removed.
What's Changed
Full Changelog: <https://github.com/nubjs/nub/compare/v
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.