Skip to content

Conversation

@zowe-robot
Copy link
Contributor

@zowe-robot zowe-robot commented Nov 21, 2025

Note: This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@reduxjs/toolkit (source) 2.10.1 -> 2.11.0 age confidence devDependencies minor
@types/node (source) 20.19.24 -> 20.19.25 age confidence devDependencies patch
@types/react (source) 18.3.26 -> 18.3.27 age confidence dependencies patch
@typescript-eslint/eslint-plugin (source) 8.46.3 -> 8.47.0 age confidence devDependencies minor
@typescript-eslint/parser (source) 8.46.3 -> 8.47.0 age confidence devDependencies minor
@zowe/cli (source) 8.28.0 -> 8.29.5 age confidence devDependencies minor
@zowe/cli-test-utils (source) 8.28.0 -> 8.29.4 age confidence devDependencies minor
@zowe/imperative (source) 8.28.0 -> 8.29.4 age confidence peerDependencies minor
@zowe/imperative (source) 8.28.0 -> 8.29.4 age confidence devDependencies minor
caniuse-lite 1.0.30001754 -> 1.0.30001757 age confidence devDependencies patch
got 14.6.2 -> 14.6.5 age confidence overrides patch
js-yaml 4.1.0 -> 4.1.1 age confidence dependencies patch
node (source) =20.19.5 -> =20.19.6 age confidence engines patch
nodemon (source) 3.1.10 -> 3.1.11 age confidence devDependencies patch
react-hook-form (source) 7.66.0 -> 7.66.1 age confidence dependencies patch
react-router (source) 7.9.5 -> 7.9.6 age confidence dependencies patch
rimraf 6.1.0 -> 6.1.2 age confidence devDependencies patch
sass 1.93.3 -> 1.94.2 age confidence dependencies minor
start-server-and-test 2.1.2 -> 2.1.3 age confidence devDependencies patch
ch.qos.logback:logback-classic (source, changelog) 1.5.20 -> 1.5.21 age confidence dependencies patch
io.micronaut:micronaut-core-bom (source) 4.10.8 -> 4.10.9 age confidence dependencies patch
io.micronaut:micronaut-http-client (source) 4.10.8 -> 4.10.9 age confidence dependencies patch
com.google.cloud.tools:jib-gradle-plugin 3.4.5 -> 3.5.1 age confidence dependencies minor
io.swagger.parser.v3:swagger-parser-v3 2.1.35 -> 2.1.36 age confidence dependencies patch
io.swagger.core.v3:swagger-models 2.2.40 -> 2.2.41 age confidence dependencies patch
io.swagger.core.v3:swagger-jaxrs2 2.2.40 -> 2.2.41 age confidence dependencies patch
io.swagger.core.v3:swagger-core 2.2.40 -> 2.2.41 age confidence dependencies patch
io.projectreactor:reactor-test 3.7.12 -> 3.8.0 age confidence dependencies minor
io.projectreactor:reactor-core 3.7.12 -> 3.8.0 age confidence dependencies minor
org.openapitools.openapidiff:openapi-diff-core 2.1.5 -> 2.1.6 age confidence dependencies patch
io.projectreactor.netty:reactor-netty-http 1.2.11 -> 1.3.0 age confidence dependencies minor
org.eclipse.jetty.websocket:jetty-websocket-jetty-common (source) 12.1.3 -> 12.1.4 age confidence dependencies patch
org.eclipse.jetty.websocket:jetty-websocket-jetty-client (source) 12.1.3 -> 12.1.4 age confidence dependencies patch
org.eclipse.jetty.websocket:jetty-websocket-jetty-api (source) 12.1.3 -> 12.1.4 age confidence dependencies patch
org.eclipse.jetty:jetty-util (source) 12.1.3 -> 12.1.4 age confidence dependencies patch
org.eclipse.jetty:jetty-io (source) 12.1.3 -> 12.1.4 age confidence dependencies patch
org.eclipse.jetty:jetty-http (source) 12.1.3 -> 12.1.4 age confidence dependencies patch
org.eclipse.jetty:jetty-client (source) 12.1.3 -> 12.1.4 age confidence dependencies patch
io.opentelemetry.instrumentation:opentelemetry-spring-boot-starter 2.21.0 -> 2.22.0 age confidence dependencies minor
com.gorylenko.gradle-git-properties 2.5.2 -> 2.5.4 age confidence plugin patch
com.gorylenko.gradle-git-properties:gradle-git-properties 2.5.2 -> 2.5.4 age confidence dependencies patch
com.google.errorprone:error_prone_annotations (source) 2.43.0 -> 2.45.0 age confidence dependencies minor
commons-io:commons-io (source) 2.20.0 -> 2.21.0 age confidence dependencies minor
org.apache.commons:commons-lang3 (source) 3.19.0 -> 3.20.0 age confidence dependencies minor
org.checkerframework:checker-qual (source) 3.52.0 -> 3.52.1 age confidence dependencies patch
org.bouncycastle:bcpkix-jdk18on (source) 1.82 -> 1.83 age confidence dependencies minor
org.bouncycastle:bcprov-jdk18on (source) 1.82 -> 1.83 age confidence dependencies minor
com.amazonaws:aws-java-sdk-bom (source) 1.12.793 -> 1.12.794 age confidence dependencies patch
org.springframework.modulith:spring-modulith-starter-test (source) 1.4.4 -> 1.4.5 age confidence dependencies patch
org.springframework.modulith:spring-modulith-starter-core (source) 1.4.4 -> 1.4.5 age confidence dependencies patch
org.springframework.modulith:spring-modulith-bom (source) 1.4.4 -> 1.4.5 age confidence dependencies patch
org.springframework:spring-test 6.2.12 -> 6.2.14 age confidence dependencies patch
org.springframework:spring-beans 6.2.12 -> 6.2.14 age confidence dependencies patch
org.springframework:spring-context-support 6.2.12 -> 6.2.14 age confidence dependencies patch
org.springframework:spring-webmvc 6.2.12 -> 6.2.14 age confidence dependencies patch
org.springframework:spring-tx 6.2.12 -> 6.2.14 age confidence dependencies patch
org.springframework:spring-web 6.2.12 -> 6.2.14 age confidence dependencies patch
org.springframework:spring-framework-bom 6.2.12 -> 6.2.14 age confidence dependencies patch
org.springframework:spring-webflux 6.2.12 -> 6.2.14 age confidence dependencies patch
org.springframework:spring-context 6.2.12 -> 6.2.14 age confidence dependencies patch
org.springframework.boot:spring-boot-starter-graphql (source) 3.5.7 -> 3.5.8 age confidence dependencies patch
org.springframework.boot:spring-boot-gradle-plugin (source) 3.5.7 -> 3.5.8 age confidence dependencies patch
org.springframework.boot:spring-boot-starter-oauth2-client (source) 3.5.7 -> 3.5.8 age confidence dependencies patch
org.springframework.boot:spring-boot-starter-webflux (source) 3.5.7 -> 3.5.8 age confidence dependencies patch
org.springframework.boot:spring-boot-starter-cache (source) 3.5.7 -> 3.5.8 age confidence dependencies patch
org.springframework.boot:spring-boot-starter-thymeleaf (source) 3.5.7 -> 3.5.8 age confidence dependencies patch
org.springframework.boot:spring-boot-starter-aop (source) 3.5.7 -> 3.5.8 age confidence dependencies patch
org.springframework.boot:spring-boot-starter-test (source) 3.5.7 -> 3.5.8 age confidence dependencies patch
org.springframework.boot:spring-boot-starter-websocket (source) 3.5.7 -> 3.5.8 age confidence dependencies patch
org.springframework.boot:spring-boot-starter-web (source) 3.5.7 -> 3.5.8 age confidence dependencies patch
org.springframework.boot:spring-boot-starter-validation (source) 3.5.7 -> 3.5.8 age confidence dependencies patch
org.springframework.boot:spring-boot-starter-security (source) 3.5.7 -> 3.5.8 age confidence dependencies patch
org.springframework.boot:spring-boot-starter-actuator (source) 3.5.7 -> 3.5.8 age confidence dependencies patch
org.springframework.boot:spring-boot-starter (source) 3.5.7 -> 3.5.8 age confidence dependencies patch
org.springframework.boot:spring-boot-dependencies (source) 3.5.7 -> 3.5.8 age confidence dependencies patch
org.springframework.boot:spring-boot-configuration-processor (source) 3.5.7 -> 3.5.8 age confidence dependencies patch

Release Notes

reduxjs/redux-toolkit (@​reduxjs/toolkit)

v2.11.0

Compare Source

This feature release upgrades our Immer dependency to v11 to pick up the additional recent performance optimizations, adds a new refetchCachedPages option to allow only fetching the first cached page, and fixes an issue with regex ignore paths in the immutability middleware.

Changelog

Immer v11 Performance Improvements

As described in the release notes for v2.10.0, we recently put significant effort into profiling Immer, and contributed several PRs that aimed to optimize its update performance.

v2.10.0 updated to use Immer 10.2.0, which added the first smaller set of perf updates. That included a new Immer option to disable "strict iteration" to speed up iterating copied objects, and we specifically applied that change in RTK under the assumption that standard plain JS objects as Redux state shouldn't have unusual keys anyway. Overall, this appears to boost Immer update perf by ~+20% over v10.1 depending on update scenario.

Immer v11.0.0 was just released and contains the second perf PR, a major internal architectural rewrite to change the update finalization implementation from a recursive tree traversal to a set of targeted updates based on accessed and updated fields. Based on the benchmarks in the PR, this adds another ~+5% perf boost over the improvements in v10.2, again with variations depending on update scenario. In practice, the actual improvement may be better than that - the benchmarks list includes some array update cases which actually got a bit slower (and thus drag down the overall average), and a majority of update scenarios show anywhere from +25% to +60% faster than Immer v10.1!

As a practical example, we have an RTK Query stress test benchmark where we mount 1000 components with query hooks at once, unmount, then remount them. We ran the same benchmark steps for RTK 2.9 and Immer 10.1, and then RTK 2.10+ and Immer 11. The overall scripting time dropped by about 30% (3330ms -> 2350ms), and the amount of time spent in Immer methods and the RTK reducers dropped significantly:

image

Based on this, it appears to be a major improvement overall.

As with the instructions in v2.10.0: if by some chance your Redux app state relies on non-string keys, you can still manually call setUseStrictIteration(true) in your app code to retain compatibility there, but we don't expect that standard Redux apps will have to worry about that.

There are still two outstanding Immer perf PRs that may offer further improvements: one that adds an optional plugin to override array methods to avoid proxy creation overhead, and another experimental tweak to shallow copying that may be better with larger object sizes.

New refetchCachedPages Option

RTK Query's infinite query API was directly based on React Query's approach, including the pages cache structure and refetching behavior. By default, that means that when you trigger a refetch, both R-Q and RTKQ will try to sequentially refetch all pages currently in that cache entry. So, if there were 5 pages cached for an entry, they will try to fetch pages 0...4, in turn.

Some users have asked for the ability to only refetch the first page. This can be accomplished somewhat manually by directly updating the cache entry to eliminate the old pages and then triggering a refetch, but that's admittedly not very ergonomic.

We've merged a contributed PR that adds a new refetchCachedPages flag. This can be defined as part of infinite query endpoints, passed as an option to infinite query hooks, or passed as an option in initiate() calls or hook refetch() methods. If set to refetchCachedPages: false, it will only refetch the first page in the cache and not the remaining pages, thus shrinking the cache from N pages to 1 page.

Other Fixes

We merged a fix to the immutability dev middleware where it was treating ignoredPath regexes as strings and not actually testing them correctly.

What's Changed

Full Changelog: reduxjs/redux-toolkit@v2.10.1...v2.11.0

typescript-eslint/typescript-eslint (@​typescript-eslint/eslint-plugin)

v8.47.0

Compare Source

🚀 Features
  • eslint-plugin: [no-unused-private-class-members] new extension rule (#​10913)
❤️ Thank You

You can read about our versioning strategy and releases on our website.

v8.46.4

Compare Source

🩹 Fixes
  • parser: error when both projectService and project are set (#​11333)
  • eslint-plugin: handle override modifier in promise-function-async fixer (#​11730)
  • eslint-plugin: [no-deprecated] fix double-report on computed literal identifiers (#​11006, #​10958)
❤️ Thank You

You can read about our versioning strategy and releases on our website.

typescript-eslint/typescript-eslint (@​typescript-eslint/parser)

v8.47.0

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

You can read about our versioning strategy and releases on our website.

v8.46.4

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

You can read about our versioning strategy and releases on our website.

zowe/zowe-cli (@​zowe/cli)

v8.29.5

Compare Source

Zowe CLI

  • BugFix: Updated glob dependency to resolve technical currency. #​2644

v8.29.4

Compare Source

Zowe CLI
  • BugFix: Updated js-yaml dependency to resolve technical currency.

v8.29.2

Compare Source

v8.29.1

Compare Source

Zowe CLI
  • BugFix: Added support for --overwrite option to all Download methods. The default behavior is no longer to always overwrite existing files. #​2620
z/OS Files SDK
  • BugFix: Fixed all the Download methods to now use the overwrite option. The default is no longer always overwriting existing files. Added new interfaces IDownloadAmResult and IDownloadAmResponse to provide detailed results when downloading all members of a PDS. #​2620
browserslist/caniuse-lite (caniuse-lite)

v1.0.30001757

Compare Source

v1.0.30001756

Compare Source

v1.0.30001755

Compare Source

sindresorhus/got (got)

v14.6.5

Compare Source

  • Fix TypeScript type inference for got.extend() with responseType option f7ab6e9

v14.6.4

Compare Source

  • Fix dnsLookup option type to accept Node.js dns.lookup 47c3155

v14.6.3

Compare Source


nodeca/js-yaml (js-yaml)

v4.1.1

Compare Source

Security
  • Fix prototype pollution issue in yaml merge (<<) operator.
nodejs/node (node)

v20.19.6: 2025-11-25, Version 20.19.6 'Iron' (LTS), @​marco-ippolito

Compare Source

Notable Changes
Commits

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@zowe-robot zowe-robot added the dependencies Pull requests that update a dependency file label Nov 21, 2025
@zowe-robot zowe-robot force-pushed the renovate/v3.x.x-all-minor-patch branch 3 times, most recently from 6d1a1ba to dc2624a Compare November 26, 2025 00:37
@zowe-robot
Copy link
Contributor Author

zowe-robot commented Nov 26, 2025

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: api-catalog-ui/frontend/package-lock.json
npm warn deprecated [email protected]: It is not compatible with newer versions of GA starting with v4, as long as you are using GAv3 it should be ok, but the package is not longer being maintained
npm warn deprecated [email protected]: [email protected]
npm warn deprecated [email protected]: Use your platform's native performance.now() and performance.timeOrigin.
npm warn deprecated [email protected]: Please see https://github.com/lydell/urix#deprecated
npm warn deprecated [email protected]: Modern JS already guarantees Array#sort() is a stable sort, so this library is deprecated. See the compatibility table on MDN: https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Array/sort#browser_compatibility
npm warn deprecated [email protected]: See https://github.com/lydell/source-map-url#deprecated
npm warn deprecated [email protected]: Please use @jridgewell/sourcemap-codec instead
npm warn deprecated [email protected]: See https://github.com/lydell/source-map-resolve#deprecated
npm warn deprecated [email protected]: This package has been deprecated and is no longer maintained. Please use @rollup/plugin-terser
npm warn deprecated [email protected]: some dependency vulnerabilities fixed, support for node < 10 dropped, and newer ECMAScript syntax/features added
npm warn deprecated [email protected]: This SVGO version is no longer supported. Upgrade to v2.x.x.
npm warn deprecated [email protected]: https://github.com/lydell/resolve-url#deprecated
npm warn deprecated [email protected]: You or someone you depend on is using Q, the JavaScript Promise library that gave JavaScript developers strong feelings about promises. They can almost certainly migrate to the native JavaScript promise now. Thank you literally everyone for joining me in this bet against the odds. Be excellent to each other.
npm warn deprecated
npm warn deprecated (For a CapTP with native promises, see @endo/eventual-send and @endo/captp)
npm warn deprecated [email protected]: This package is broken and no longer maintained. 'mkdirp' itself supports promises now, please switch to that.
npm warn deprecated [email protected]: Use your platform's native DOMException instead
npm warn deprecated [email protected]: This package is deprecated. Use require('node:util').isDeepStrictEqual instead.
npm warn deprecated [email protected]: This module is not supported, and leaks memory. Do not use it. Check out lru-cache if you want a good and tested way to coalesce async requests by a key value, which is much more comprehensive and powerful.
npm warn deprecated [email protected]: this library is no longer supported
npm warn deprecated [email protected]: Glob versions prior to v9 are no longer supported
npm warn deprecated [email protected]: Use your platform's native DOMException instead
npm warn deprecated [email protected]: Use your platform's native atob() and btoa() methods instead
npm warn deprecated @humanwhocodes/[email protected]: Use @eslint/object-schema instead
npm warn deprecated @humanwhocodes/[email protected]: Use @eslint/config-array instead
npm warn deprecated @babel/[email protected]: This proposal has been merged to the ECMAScript standard and thus this plugin is no longer maintained. Please use @babel/plugin-transform-private-methods instead.
npm warn deprecated @babel/[email protected]: This proposal has been merged to the ECMAScript standard and thus this plugin is no longer maintained. Please use @babel/plugin-transform-class-properties instead.
npm warn deprecated @babel/[email protected]: This proposal has been merged to the ECMAScript standard and thus this plugin is no longer maintained. Please use @babel/plugin-transform-numeric-separator instead.
npm warn deprecated @babel/[email protected]: This proposal has been merged to the ECMAScript standard and thus this plugin is no longer maintained. Please use @babel/plugin-transform-nullish-coalescing-operator instead.
npm warn deprecated @babel/[email protected]: This proposal has been merged to the ECMAScript standard and thus this plugin is no longer maintained. Please use @babel/plugin-transform-private-property-in-object instead.
npm warn deprecated @babel/[email protected]: This proposal has been merged to the ECMAScript standard and thus this plugin is no longer maintained. Please use @babel/plugin-transform-optional-chaining instead.
npm warn deprecated [email protected]: Rimraf versions prior to v4 are no longer supported
npm warn deprecated [email protected]: Rimraf versions prior to v4 are no longer supported
npm warn deprecated [email protected]: Rimraf versions prior to v4 are no longer supported
npm warn deprecated @material-ui/[email protected]: Material UI v4 doesn't receive active development since September 2021. See the guide https://mui.com/material-ui/migration/migration-v4/ to upgrade to v5.
npm warn deprecated [email protected]: This package is deprecated. Use require('node:util').isDeepStrictEqual instead.
npm warn deprecated [email protected]: This version is no longer supported. Please see https://eslint.org/version-support for other options.
npm warn deprecated @material-ui/[email protected]: Material UI v4 doesn't receive active development since September 2021. See the guide https://mui.com/material-ui/migration/migration-v4/ to upgrade to v5.
npm error code E404
npm error 404 Not Found - GET https://zowe.jfrog.io/artifactory/api/npm/npm-org/caniuse-lite/-/caniuse-lite-1.0.30001757.tgz
npm error 404
npm error 404  'caniuse-lite@https://zowe.jfrog.io/artifactory/api/npm/npm-org/caniuse-lite/-/caniuse-lite-1.0.30001757.tgz' is not in this registry.
npm error 404
npm error 404 Note that you can also install from a
npm error 404 tarball, folder, http url, or git url.
npm error A complete log of this run can be found in: /tmp/renovate/cache/others/npm/_logs/2025-12-03T00_34_59_378Z-debug-0.log

@balhar-jakub balhar-jakub moved this from Blocked to In Progress in API Mediation Layer Backlog Management Nov 26, 2025
@zowe-robot zowe-robot force-pushed the renovate/v3.x.x-all-minor-patch branch 3 times, most recently from 9707b5a to ef9ea2f Compare December 1, 2025 00:44
@zowe-robot zowe-robot force-pushed the renovate/v3.x.x-all-minor-patch branch from ef9ea2f to 191a688 Compare December 3, 2025 00:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file size/M

Projects

Status: In Progress

Development

Successfully merging this pull request may close these issues.

3 participants