Skip to content

chore(deps): update dependency rolldown to v1.1.2#1345

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/rolldown-1.x
Closed

chore(deps): update dependency rolldown to v1.1.2#1345
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/rolldown-1.x

Conversation

@renovate

@renovate renovate Bot commented Jun 22, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
rolldown (source) 1.0.01.1.2 age confidence

Release Notes

rolldown/rolldown (rolldown)

v1.1.2

Compare Source

🚀 Features
🐛 Bug Fixes
🚜 Refactor
📚 Documentation
⚡ Performance
🧪 Testing
⚙️ Miscellaneous Tasks
❤️ New Contributors

v1.1.1

Compare Source

🚀 Features
🐛 Bug Fixes
🚜 Refactor
📚 Documentation
⚡ Performance
🧪 Testing
⚙️ Miscellaneous Tasks
❤️ New Contributors

v1.1.0

Compare Source

🚀 Features
🐛 Bug Fixes
🚜 Refactor
📚 Documentation
⚡ Performance
🧪 Testing
⚙️ Miscellaneous Tasks
❤️ New Contributors

v1.0.3

Compare Source

🚀 Features
🐛 Bug Fixes
🚜 Refactor
📚 Documentation
⚡ Performance
  • generate: thread ast_table by value into codegen consumer (#​9555) by @​Boshen
  • finalizers: replace _reExport construction with a direct call to avoid calling clone_in (#​9501) by @​Dunqing
  • reorder hot-path boolean checks to short-circuit on cheap predicates first (#​9523) by @​Boshen
🧪 Testing
⚙️ Miscellaneous Tasks
❤️ New Contributors

v1.0.2

Compare Source

🚀 Features
🐛 Bug Fixes
🚜 Refactor
📚 Documentation
⚡ Performance
🧪 Testing
⚙️ Miscellaneous Tasks

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 5am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate using a curated preset maintained by Sanity. View repository job log here


Note

Medium Risk
Rolldown is the bundler behind Vite for CLI/studio builds; a 1.0→1.1.x bump can change bundle output or dev behavior even though the diff is dependency-only.

Overview
Bumps the pinned rolldown version from 1.0.0 to 1.1.2 everywhere the monorepo forces a single version: root pnpm.overrides, matching overrides in @sanity/cli, @sanity/cli-build, @sanity/cli-core, and @sanity/cli-test, plus the global override in pnpm-lock.yaml.

The lockfile refresh pulls in rolldown 1.1.2 platform bindings, updates related transitive bits (e.g. @oxc-project/types 0.137.0, newer @emnapi/* / @napi-rs/wasm-runtime for the wasm binding), and drops the standalone @rolldown/pluginutils@1.0.0 entry in favor of 1.0.1 as bundled with the new rolldown release. Anything that resolves rolldown through Vite, @rolldown/plugin-babel, or rolldown-plugin-dts now builds against 1.1.2 with no other source changes in this PR.

Reviewed by Cursor Bugbot for commit e356e5d. Bugbot is set up for automated code reviews on this repo. Configure here.

@renovate renovate Bot requested a review from a team as a code owner June 22, 2026 11:33
@renovate renovate Bot enabled auto-merge (squash) June 22, 2026 11:33
@github-actions

github-actions Bot commented Jun 22, 2026

Copy link
Copy Markdown
Contributor

Bundle Stats — Calculating bundle sizes for @sanity/cli, @sanity/cli-core, create-sanity...

@socket-security

socket-security Bot commented Jun 22, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @emnapi/runtime is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@rolldown/plugin-babel@0.2.3npm/vitest@4.1.8npm/vite@8.0.16npm/@sanity/pkg-utils@10.5.8npm/@emnapi/runtime@1.11.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@emnapi/runtime@1.11.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate Bot force-pushed the renovate/rolldown-1.x branch 3 times, most recently from 985348d to 5cc61c2 Compare June 22, 2026 15:41
@renovate renovate Bot force-pushed the renovate/rolldown-1.x branch from 5cc61c2 to e356e5d Compare June 22, 2026 17:19
@stipsan stipsan closed this Jun 22, 2026
auto-merge was automatically disabled June 22, 2026 17:20

Pull request was closed

@renovate

renovate Bot commented Jun 22, 2026

Copy link
Copy Markdown
Contributor Author

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update (1.1.2). You will get a PR once a newer version is released. To ignore this dependency forever, add it to the ignoreDeps array of your Renovate config.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

@renovate renovate Bot deleted the renovate/rolldown-1.x branch June 22, 2026 17:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant