Skip to content

chore(deps): update dependency @nubjs/nub to v0.8.2 - #75

Merged
lzm0x219 merged 7 commits into
mainfrom
renovate/nubjs-nub-0.x
Sep 2, 2026
Merged

lzm0x219 merged 7 commits into
mainfrom
renovate/nubjs-nub-0.x

Conversation

@renovate

@renovate renovate Bot commented Aug 16, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@nubjs/nub (source) 0.6.0 → 0.8.2 age confidence

Release Notes

nubjs/nub (@​nubjs/nub)

v0.8.2: Nub 0.8.2

Compare Source

Nub's TypeScript loader is now available as a standalone package for plain Node, alongside fixes across install, resolution, configuration, runtime compatibility, and nub compile.

[!IMPORTANT]
The loader ships as its own package. @nubjs/loader runs TypeScript, JSX, tsconfig paths, and data-format imports under stock node, with no Nub binary involved. Install it as a dev dependency and register it the way tsx and ts-node are registered. Source that runs under it also runs unchanged under those, so adopting it is reversible.

Standalone loader

npm install --save-dev @nubjs/loader
node --import @nubjs/loader app.ts

The package arms the shared resolve and transpile hooks and nothing else. Every preload form Node accepts works:

node --import @nubjs/loader app.ts        # ESM hooks + CommonJS require() augmentation
node --require @nubjs/loader app.ts       # CommonJS delivery (Node 20.19+)
node --import @nubjs/loader/esm app.ts    # ESM hooks only

It also works anywhere a preload can be set rather than passed, such as NODE_OPTIONS="--import @nubjs/loader" vitest.

The native transform rides eight @nubjs/loader-<platform> packages as optionalDependencies, covering macOS, Linux (glibc and musl), and Windows on x64 and arm64. Documentation is at nubjs.com/docs/loader. (#​810)

Install and update

Area What changed PR
Resolver A version refused by trustPolicy=no-downgrade now backtracks to an older version in the same range that still carries its trust evidence, instead of aborting the install. This matches how the age gate already resolved the same situation. #​819
outdated, update Neither command reports or offers a version below the one already installed. A blocked latest tag widened the scan downward, so an older release could be advertised as the upgrade target while the exit code stayed at 1 with nothing installable. #​823
config Engine settings that Nub never reads are no longer listed by config list --all or written by config set. Setting one previously added a key to your .npmrc that changed nothing. #​811

Runtime

--experimental-webstorage is passed on the command line instead of through NODE_OPTIONS. That variable is inherited by every descendant process, and the flag does not exist before Node 22.4, so any child running an older Node aborted at startup with exit 9. This was reachable in practice: a host on the Node 22.4–24 band running Electron 34 or earlier, which embeds Node 20.18.1, hit it. (#​812)

Compile

nub compile finds the strip tool on Windows. The probe tested for a bare filename, so it never matched llvm-strip.exe and every compile on a Windows host silently took the unstripped path — a note: on stderr and an artifact roughly 4 MB larger than it should be. The probe is now PATHEXT-aware. (#​827)

Testing and internals

Cross-runtime compatibility results now run node:test files under bun test, matching how Deno is already measured, and the published numbers are updated accordingly (#​820). The age-gate warning for registries that publish no dates gained end-to-end coverage (#​813). Host build tooling gained a compile-slot cap (#​808) and a self-pruning target directory collector (a247a22). None of these changes affect the released binary.


What's Changed

Full Changelog: nubjs/nub@v0.8.1...v0.8.2

v0.8.1: Nub 0.8.1

Compare Source

Nub 0.8.1 is a patch release: a lockfile fix for pnpm 12, a round of Node-version and loader compatibility fixes in the runtime, and global-install repairs in the package manager.

[!NOTE]
pnpm 12 rejects a lockfile written by Nub 0.8.0 or earlier when a peer is declared optional: false (vitest declares vite that way). Nub wrote the entry as an empty mapping under peerDependenciesMeta; pnpm 12's reader fails on it with ERR_PNPM_BROKEN_LOCKFILE, where pnpm 10 accepted it. Nub now omits those entries, as pnpm does. (#​814)

Package manager

Area What changed PR
Lockfiles peerDependenciesMeta records only optional: true entries, matching pnpm; pnpm 12 reads the result under --frozen-lockfile. #​814
Lockfiles A lockfile read resolves against the declared package manager, not filename precedence. In a project declaring npm, a stray bun.lock no longer outranks package-lock.json and gets serialized back out as it. #​781
Global installs nub install -g <pkg> produces a runnable command, and nub remove -g unlinks the bins it created instead of leaving dangling entries in the global bin directory. Fixes #​642. #​773
nub outdated The minimumReleaseAge window is applied without remark, as install and update apply it; the per-cell marker and the footer naming the held version are gone. #​779

Runtime

Area What changed PR
Node versions Node 23.0–23.4 route to the compat tier: module.registerHooks reached the 23.x line at 23.5.0, and those releases threw at startup under the fast tier. nub compile refuses an external-shim build targeting that band for the same reason. #​802
Node versions --enable-source-maps is withheld on every Node 26.x below 26.8, the band affected by nodejs/node#63169. #​784
Builtins CommonJS require("node:test"), node:sqlite, node:sea and node:test/reporters work again on Node 22.15.0–22.17.1, 23.5.0–23.11.1 and 24.0.0–24.3.0, where a registered resolve hook dropped the node: scheme (fixed upstream in 22.18, 24.4 and 25+). #​803
Loaders A non-file: URL passes through the load hook untouched, so a custom-protocol ESM loader behaves as it does on plain Node. #​788
Environment files --env-file values are no longer $VAR-expanded, matching Node. A value holding a literal $ arrives intact. #​789
Environment files .env.schema discovery walks from the project root up to the workspace root, so a schema at an enclosing package or at a directory without a manifest is found. #​809
Test runner Node's default test-file coverage exclusion stays in effect when Nub adds its own exclusion for the preloaded runtime. #​798, #​815
Debugging A transpiled TypeScript file reports a file: URL as its sourceURL, so editor and DevTools breakpoints match the same script identity as under node. #​800
REPL A module-resolution error in the REPL keeps its named stack frames. #​797
Blob URLs URL.revokeObjectURL() with no argument throws ERR_MISSING_ARGS, as Node does. #​799

Documentation and site

  • The environment-file docs describe the current --env-file and .env.schema behavior; the Varlock page's monorepo callout is updated. (#​809)
  • The FAQ lists only the WinterTC gap global the preload defines. (abe3a6a)
  • The Node-compat corpus is refreshed to Node 26.7.0 and scored under named lenses; the compat benchmark on the site carries the remeasured figures. (#​785, c93d676)
  • The docs pages prerender again; ?section= share links route to an on-demand variant. (dbb4ae1)
  • The 0.8.0 blog post's eject callout describes the collective fallback tree. (985d122)

Testing & internals

  • The repository root is a nub-identity project on nub.lock, and CI bootstraps with nub. (#​807)
  • A worktree that edits only runtime/ builds into an isolated target directory. (#​801)
  • The public wiki drops research docs written as internal investigations and gains a public-content lint. (d50b1c2)
  • The download-stats pipeline reads the daily snapshot ledger. (5992582, ec69670)
  • A failing nubjs.com production deploy is tracked like a red trunk. (374c253)

What's Changed

Full Changelog: nubjs/nub@v0.8.0...v0.8.1

v0.8.0: Nub 0.8.0

Compare Source

Nub 0.8.0 reworks environment-file configuration, ships a round of package-manager correctness fixes, and adds garbage collection for the package store.

[!IMPORTANT]
Two changes are worth knowing before upgrading:

  • File paths in envFile now go in an array — "envFile": [".env"]. A bare string path is an error that names the fix. (#​735)
  • The first install after upgrading relinks each warm tree once, because hidden-hoist link ordering changed. (#​775)

Breaking changes

File paths in envFile go in an array. "envFile": ".env" is now an error naming [".env"]; a string value is reserved for mode names, and "varlock" is the only one. This makes envFile consistent with the other list-valued config fields. (#​735)

A declared envFile now displaces a .env.schema hand-over, at every scope. A .env.schema file decides the environment only when no envFile is declared. Previously the two together were a hard error, and envFile: false in a schema project loaded the schema anyway. Now declared intent wins: envFile: false (or --no-env-file) loads nothing, an envFile list loads those files, and envFile: "varlock" keeps the hand-over explicitly. This applies to a global-scope envFile too, so a machine-wide envFile: false empties a schema project unless the project declares "varlock". (#​735, #​774)

An unreadable tsconfig.json now refuses the run. A project tsconfig whose extends target is missing previously ran under options its author never wrote — extends is where strict, target, and path aliases usually live. Nub now stops with the read error, as tsc does (TS5083). Fix the config, or run with --node. A dependency's own unreadable tsconfig is still salvaged rather than fatal. (#​778, #​768)

Another package manager's config no longer directs the node_modules layout. The layout is configured in nub.jsonc (install.linker, install.publicHoist) under every project identity. The last two branded exceptions are gone: pnpm 11's pnpm-workspace.yaml layout keys are no longer read, and npm's install-strategy=nested no longer aborts the install. (#​698)

Version-gated feature flags moved out of NODE_OPTIONS. NODE_OPTIONS is inherited by the whole process subtree, and flags matched to the host Node aborted any descendant on an older Node — Electron apps exited at startup. Feature flags now ride argv instead. Cost: a tool that spawns Node by absolute path (bypassing the shim) loses the version-gated features, though it keeps the preload and source-map remapping. (#​777)

Package manager

Area What changed PR
Optional dependencies A build failure in an optionalDependencies entry skips the package with a warning instead of failing the install, matching npm and pnpm. #​737
Store maintenance nub store prune now garbage-collects the global virtual store and extracted-tree tiers, not just the content store. Installs register the project with the store; a project whose last install predates 0.8.0 registers on its next install. #​720
nub outdated minimumReleaseAge now applies to both reported columns, so the report no longer offers upgrades nub update would decline. A held version is marked with the time it becomes installable, and a project whose only pending upgrade is held exits 0. #​743
Release-age policy A frozen install revalidates the release policy only when the age gate actually moved. #​710
Relocated stores A store-dir override now moves every store tier together, so phantom-dependency protection keeps working and the machine's default store stays untouched. #​644
.bin wrappers A package whose bin shares its interpreter's name (for example the node npm package) no longer produces a wrapper that resolves to itself — nub install node used to hang. #​741
Workspaces Workspace aliases and relative-path workspace specs resolve. #​717
Workspaces A member-scoped nub update resolves in the workspace-root frame. #​754
Workspaces The disk-materialize eject applies in workspace projects too. #​736
Workspaces nub config init writes nub.jsonc at the workspace root. #​714
Lockfiles An empty importer reads as drift, not as a specifier-less lockfile format. #​763
Linker Hidden-hoist names are claimed shallowest-first, matching pnpm's depth ordering — 1.0.0 no longer beats 2.0.0 on lexicographic accident. #​775
Resolution Peer-context convergence is sized by graph. #​716
Registry A stalled packument fetch is bounded and surfaced instead of hanging the install. #​723
Configuration NUB_CACHE_DIR moves the engine cache, and nub config get/list report values set through the environment. #​740
Configuration A settings default with a namespace resolves against the active embedder. #​780
Fresh installs The shim directories honor XDG_DATA_HOME on a fresh install; an existing ~/.nub install keeps its path. #​752
Source builds A source build (Homebrew and friends) now fails loudly when a build prerequisite is missing instead of shipping a quietly degraded binary. #​761

Runtime

Area What changed PR
import defer Deferred module evaluation is enabled on Node 26.4+, where Node wires the defer phase through. #​770
Loaders A user loader delivered through NODE_OPTIONS is seen by the CommonJS-sync guard. #​742
fetch cache Cache-evict builtins load synchronously, closing a startup race. #​707
Types @nubjs/types covers the six polyfilled proposals an es2024 lib can't reach. #​734
Windows nub.exe reserves an 8 MB main-thread stack, matching node.exe. #​701

CLI

  • A help flag after the verb works in the pm and node command groups. (#​739)
  • Ctrl-C signals every concurrent child of nub run, and --color takes effect. (#​744)

What's Changed

New Contributors

Full Changelog: nubjs/nub@v0.7.5...v0.8.0

v0.7.5

Compare Source

A memory-retention release, plus two fixes to nub upgrade.

Memory retention

Seven unbounded-retention defects, each reproduced with a fixture against a plain Node control before and after the fix. (#​702)

Area What changed Measured
nub run -r supervisor Streaming mode no longer retains every prefixed output line for the child's whole life. A script that never exits — nub run -r dev — grew the supervisor 1:1 with child output. 45 → 325 MB over 50 s, now flat at 15 MB
Aggregate output Flushes past 8 MiB instead of buffering the entire run. A non-TTY stdout selects this path, so CI and piped runs were affected too. 250 MB climbing → flat 29 MB, output still in order
URL.createObjectURL Captures one compact Buffer when the Blob is built, capped at 4 MiB, and decodes only when a Worker asks for the source. 20k object URLs: +43.1 → +5.6 MB (plain Node: +1.1)
Blob A Blob no longer pins whatever its construction parts referenced. 2000 Blobs holding 64 KB between them: 504 → 4 MB external
Transpile-cache sweep Was armed on an unref'd setImmediate the process exited before running, so a user whose runs are all synchronous never swept. It is now scheduled only when a sweep is due, and ref'd. —

Upgrade

Fixes in #​705.

  • On Windows the command reported its install path in the extended-length form — installed v0.7.4 to \\?\C:\Users\you\.nub. The install itself was always correct. Paths are now spelled for display at the print sites, while the path used for the file swap keeps the MAX_PATH exemption a deep install directory depends on. (#​704)
  • A nub upgrade with nothing newer to install downloaded and swapped in the release it was already running. It now reports already on the latest release and stops. An explicit --version still reinstalls, which is what repairs a damaged install, and --stable from a canary build still downloads, because that is a channel switch. (#​664)
  • The upgrade line now names the version being left as well as the one arriving.
  • The --yes flag advertised a confirmation prompt that has never existed. Its help text now says what it does.

Docs

The reference pages were rewritten for density — the config reference, the FAQ, and the install, runtime, runner and deployment sections — and two rotted links were fixed.


What's Changed

  • fix: bound unbounded retention in the run supervisor, blob URLs, and the caches by @​colinhacks in #​702
  • fix(upgrade): strip the Windows verbatim path prefix, and skip a no-op upgrade by @​colinhacks in #​705

Full Changelog: nubjs/nub@v0.7.4...v0.7.5

v0.7.4

Compare Source

Nub 0.7.4 adds guided config setup and makes missing-package errors authoritative during installs.

Configuration

nub config init creates a commented, behavior-neutral nub.jsonc at the project root. nub config init --global creates the user config instead, and both forms refuse to replace an existing file.

The config command now uses project scope by default, --global for user scope, and nub global config as the prefix form. The former --location option has been removed. Protected npm credentials continue to default to the user .npmrc; --local selects a project credential explicitly. (#​694)

Package installation

Missing registry packages now fail with ERR_NUB_PACKAGE_NOT_FOUND before similarity or package-age warnings run. Public unscoped typos can include a non-interactive suggestion; scoped package names no longer suggest unrelated basenames from another namespace. (#​693)

Documentation and site

Area What changed Commit
Release archive Added the Nub 0.7.3 release post 5b690fb
Blog structure Reorganized the Nub 0.7.0 post and extracted the reusable Nub introduction 9888c8a
Table of contents Kept identifiers together when sidebar entries wrap a825d75
Config copy Tightened the config docs and Nub introduction 55b6294

What's Changed

Full Changelog: nubjs/nub@v0.7.3...v0.7.4

v0.7.3

Compare Source

A Windows fix for nub run, native TypeScript transform configuration, and import-text on the Node 24 LTS backport.

[!IMPORTANT]
Windows npm installs could not run scripts. On 0.7.0–0.7.2, nub run failed on Windows with "bundled POSIX shell (busybox.exe) was not found" from the second invocation onward. Upgrading fixes it; there is nothing to clean up by hand.

Windows

nub run executes script bodies through a bundled busybox sh, which the binary resolves relative to itself. 0.7.0 began hardlinking nub.exe into npm's global bin directory for a faster dispatch path, which moved the binary away from that shell — so the first call after an install worked and every later one failed. The launcher now carries the shell into a nub-sh/ subdirectory beside the relocated binary, and the resolution accepts that layout. It goes in a subdirectory rather than beside the executable because that directory is on PATH, where a bare busybox.exe would shadow a busybox the user installed themselves. (#​699, #​687)

Configuration

Project nub.jsonc gains six native TypeScript transform fields — jsx, jsxFactory, jsxFragmentFactory, jsxImportSource, decorators, and emitDecoratorMetadata. (#​697)

Runtime

Area What changed Commit
import-text --experimental-import-text is injected on the 24.19.0 LTS backport band as well as 26.5+, so a Node that knows the flag no longer falls through to the default loader and fails with ERR_UNKNOWN_FILE_EXTENSION 439853b
TypeScript customConditions from tsconfig.json are applied as Node export conditions 005e8e4
Environment An explicit env file is refused when Varlock owns the environment, rather than being silently layered dfe9b73
Environment .env.schema ownership is decided by loader resolution, and a missing schema is a refusal rather than a degrade 7dfeb95

Types

@nubjs/types splits its shared declarations into common.d.ts and routes pre-6.0 compilers through a dedicated entry, so proposal declarations coexist with the official ones as they land. The fixture matrix runs under TypeScript 5.9, 6.0 and 7.0. (e29dc5c)

Testing & internals

  • The Windows busybox probe runs its whole case matrix against both shell layouts, plus a negative control that fails when no shell is present (#​699).
  • A stray root nub.jsonc setting nodeCompat: true was removed; it disabled augmentation for every in-tree test and took the whole test matrix red (#​696, #​695).
  • The v0.7 config-schema snapshot was refreshed against latest.json after the transform fields landed, restoring the release verification gate (f58f09f).
  • Documentation for the runtime API augmentations, Varlock, and the configuration reference (ddcf309, f1b2542, 1eb177c).

What's Changed

Full Changelog: nubjs/nub@v0.7.2...v0.7.3

v0.7.2

Compare Source

Supply-chain and workspace resolution fixes, plus per-invocation platform selection for cross-platform installs.

Release-age gate

Running a tool without naming a version resolves the latest tag, which narrowed to that one version — so a minimumReleaseAge window covering it left nothing to fall back to and nubx <tool> failed outright. A blocked latest now resolves to the newest release that clears the window (#​682, #​681).

$ nubx some-tool
+ some-tool@2.3.0  latest 2.4.0

warn: the latest some-tool release (2.4.0) is younger than minimumReleaseAge; using 2.3.0 instead
help: to take the newest release anyway: `--minimum-release-age=0`, or `--minimum-release-age-exclude=some-tool`

The fallback stops at whatever the publisher currently tags latest, so a higher version they published and then untagged is never selected, and a latest pointing at a prerelease is refused rather than falling back onto a stable release from an older line. The same narrowing also affected the non-strict mode in the opposite direction — the blocked release was the only candidate, so it was re-selected and the window had no effect. It is now enforced there too.

Installs

Area What changed Commit
Platform selection --os, --cpu and --libc select optional dependencies for a target other than the host, per invocation (#​683) af33650
Workspace protocol A workspace:<path> tail naming a member directory resolves to that member instead of being read as a version range and sent to the registry (#​674) ab7350e
Prewarm The prewarm graph is host-filtered under the isolated layout, matching the linked tree (#​679) adac3af
Patch application A failing hunk reports its number and line, counted from 1, with what was searched for and that the patch needs regenerating (#​674) ab7350e

Diagnostics

The refusal to accept a nodeOptions entry now names NODE_OPTIONS as the constraint doing the refusing (#​684, c178118).

Documentation

The package-manager page's layout section is reworked to state the policy as neutral-surface-first, with a dead npmrc example corrected and a duplicated build-approval enumeration removed.


What's Changed

  • fix: name NODE_OPTIONS as the constraint refusing a nodeOptions entry by @​colinhacks in #​684
  • fix(install): host-filter the prewarm graph under the isolated layout too by @​colinhacks in #​679
  • feat(install): --os / --cpu / --libc for per-invocation platform selection by @​colinhacks in #​683
  • fix(aube): resolve workspace: specifiers, and say where a patch hunk failed by @​colinhacks in #​674
  • fix(resolver): fall back to the newest mature release when the age gate blocks latest by @​colinhacks in #​682

Full Changelog: <https://github.com/nubjs/nub/compare/v

✂ Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/nubjs-nub-0.x branch from 61b914b to d5f331f Compare August 29, 2026 05:13
@renovate renovate Bot changed the title chore(deps): update dependency @nubjs/nub to v0.7.5 chore(deps): update dependency @nubjs/nub to v0.8.0 Aug 29, 2026
@renovate
renovate Bot force-pushed the renovate/nubjs-nub-0.x branch from d5f331f to 8157976 Compare August 31, 2026 20:03
@renovate renovate Bot changed the title chore(deps): update dependency @nubjs/nub to v0.8.0 chore(deps): update dependency @nubjs/nub to v0.8.1 Aug 31, 2026
@renovate
renovate Bot force-pushed the renovate/nubjs-nub-0.x branch 3 times, most recently from d99e9a1 to 3f2573d Compare September 1, 2026 07:40
@renovate renovate Bot changed the title chore(deps): update dependency @nubjs/nub to v0.8.1 chore(deps): update dependency @nubjs/nub to v0.8.2 Sep 1, 2026
@renovate
renovate Bot force-pushed the renovate/nubjs-nub-0.x branch from 3f2573d to 9338b8f Compare September 2, 2026 18:02
@renovate

renovate Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@lzm0x219

lzm0x219 commented Sep 2, 2026

Copy link
Copy Markdown
Member

@renovate rebase

1 similar comment
@lzm0x219

lzm0x219 commented Sep 2, 2026

Copy link
Copy Markdown
Member

@renovate rebase

Resolve lockfile conflict: regenerate pnpm-lock.yaml with @nubjs/nub 0.8.2
Resolve lockfile conflict: regenerate pnpm-lock.yaml with @nubjs/nub 0.8.2
@lzm0x219
lzm0x219 force-pushed the renovate/nubjs-nub-0.x branch from cc3088b to 5208e91 Compare September 2, 2026 18:37
@lzm0x219
lzm0x219 merged commit e1fc427 into main Sep 2, 2026
4 checks passed
@lzm0x219
lzm0x219 deleted the renovate/nubjs-nub-0.x branch September 2, 2026 18:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant