Skip to content

build(deps-dev): bump @microsoft/rush from 5.179.0 to 5.180.0 in the dev group - #343

Merged
nev21 merged 3 commits into
mainfrom
dependabot/npm_and_yarn/dev-228cc92cf3
Oct 9, 2026
Merged

nev21 merged 3 commits into
mainfrom
dependabot/npm_and_yarn/dev-228cc92cf3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the dev group with 1 update: @microsoft/rush.

Updates @microsoft/rush from 5.179.0 to 5.180.0

Changelog

Sourced from @​microsoft/rush's changelog.

5.180.0

Tue, 29 Sep 2026 13:39:28 GMT

Minor changes

  • Allow hosts to discard unstarted graph iterations without executing scripts or closing retained runners, preserving completed results for safe replanning.
  • Publish validated opt-in daemon configuration and environment overrides. Watch and warm-set settings remain explicitly documented integration seams.
  • Expose a bounded native phased-command engine factory that reuses Rush command parsing and the all-project operation graph pipeline without CLI process-state mutation, with explicit lifetime cleanup and native lock ownership.
  • Expose native Rushx parsing and request-local lifecycle execution with owned asynchronous spawning, isolated dotenv preparation, native diagnostics and injected-dependency synchronization.
  • Add false-default persistent daemon Node runners selected by explicit per-operation daemonIpc descriptors, including the SDK declaration proxy. Preserve raw custom arguments, canonical hashes, native/rebuild/NoOp/shard behavior, and bounded implementation-tree reloads. Keep watch-only IPC unchanged and decode IPC stdout/stderr incrementally.
  • Expose stable workspace/runtime input fingerprints and safe borrowing of an already-held native preparation lock for generation-scoped engine reload.

Patches

  • Document the experimental reporter opt-in, rollback, output contracts, compatibility boundary, and reproducible demo.
  • Add repository configuration for opting into and configuring the experimental Rush reporter.
  • Add pre-major frontend reporter controls with legacy command compatibility, selected-engine gating, and deterministic reporter finalization.
  • Expose an optional scoped reporter producer API to Rush actions and plugins while preserving legacy terminal output.
  • Emit shadow Rush lifecycle, phase-aware operation, diagnostic, telemetry, and command-result events without changing legacy terminal output.
  • Complete shadow reporter parity coverage for event identity, telemetry privacy, exit status, repeated operation phases, and unchanged legacy output.
  • Emit feature-flagged phase-aware operation registration, status, raw output, stream-close, and completion events while preserving the legacy StreamCollator output path.
  • Add the opt-in direct build reporter demo path with reporter-owned output, a complete full-detail log, and an immediate legacy rollback.
  • Add a bounded nonce-protected install-run-rush handoff, replay it before version selection, and bridge cross-version reporter compatibility.
  • Relay compatible Heft child events through the selected Rush reporter with ordered raw fallback and problem matcher diagnostics.
  • Preserve immutable errors, diagnose pre-execution parser failures once, and register shadow operations after final watch iteration configuration.
  • Connect real watch cancellation to the persistent shadow exit-status observer without changing legacy process status, and verify raw stdout/stderr chunk parity.
  • Document daemon.watch as persistent host observation of warm projects, defaulting to root/config guards only without enabling automatic builds.
  • Preserve the inherited Windows Path when preparing native daemon operation environments.
  • Exclude volatile per-shell, terminal, session and daemon-routing environment variables (such as PWD, OLDPWD, SHLVL, TERM and WSL_INTEROP) from workspace input environment fingerprints, via the new workspaceFingerprintIgnoredEnvironmentVariables and getWorkspaceFingerprintEnvironmentEntries APIs.
  • Fix a build cache poisoning race: skip writing a build cache entry when an operation's tracked input files changed while it was executing.
  • Fix pnpm registry credentials being dropped by POSIX shells when provideNpmrcCredentialsViaEnvironment is enabled.
  • Allow operations to write build cache entries when their dependencies were not re-run because a previous iteration of a long-lived graph (such as the Rush daemon) produced a trusted result at the same state hash. Dependencies skipped by the user (e.g. --only) still block cache writes.
  • Document that the daemon warmSetMaxProjects limit only counts projects holding warm resources (active runners or file watchers).
  • Exclude --verbose, --parallelism and --timeline from the daemon engine parameter identity and expose them as per-request settings, so these flags no longer force the Rush daemon to reload its warm operation graph.
  • Preserve the original native Rushx registration path unless an explicit invocation namespace is supplied, and release fixture-owned native parser locks after frontend tests.
  • Preserve the active repository mutex and its Windows interrupted-owner marker when purging temporary files.
  • Preserve unexpected aggregate cleanup errors in per-operation runner lifetime handling so dependents do not execute after a failed cleanup notification.
  • Use LockFile's backing-file path contract to preserve active repository locks and their recovery companions during purge.
  • Consume reporter verbose and repository opt-in value controls only when command ownership is known, preserving native aliases and declared custom parameters.
  • Preserve custom bootstrap controls and legacy environment overrides, keep direct command output within reporter-owned destinations, and suppress duplicate watch presentation.
  • Recognize frontend-owned reporter environment controls when native engines or rushx execute without frontend environment scrubbing.
  • Preserve custom reporter controls during emergency legacy rollback and honor reserved stdout/stderr output destinations.
  • Report early initialization failures and defer successful reporter completion until telemetry finalization preserves the command's native outcome.
  • Fail corrupted negotiated Heft reporter streams while preserving genuine raw fallback, and validate the demo's intentional Windows fallback.
  • Correct local reporter demo examples to select the built Rush engine instead of an older repository-pinned version, and explain restoration of normal version selection.
  • Preserve legacy flags after valueless reporter rollback controls and default an unqualified primary file reporter to debug detail.
  • Preserve machine-readable stdout ownership for additional reporter outputs during engine compatibility handoff.
  • Resolve the command working directory to its physical path so watch input snapshots work with Windows short names and directory aliases. Preserve real watch cancellation and watcher cleanup coverage for both legacy and shadow reporting.
  • Resolve Windows lifecycle shells consistently from the request environment, retain asynchronous child ownership through named options, and isolate concurrent Git-selector configuration.
  • Preserve both resolved reporter-control stripping lists when bootstrap compatibility falls back to legacy output.

... (truncated)

Commits

Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
@microsoft/rush [>= 5.144.a, < 5.145]

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dev group with 1 update: [@microsoft/rush](https://github.com/microsoft/rushstack/tree/HEAD/apps/rush).


Updates `@microsoft/rush` from 5.179.0 to 5.180.0
- [Changelog](https://github.com/microsoft/rushstack/blob/main/apps/rush/CHANGELOG.md)
- [Commits](https://github.com/microsoft/rushstack/commits/HEAD/apps/rush)

---
updated-dependencies:
- dependency-name: "@microsoft/rush"
  dependency-version: 5.180.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 8, 2026
@dependabot
dependabot Bot requested review from a team as code owners October 8, 2026 20:35
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 8, 2026
@codecov

codecov Bot commented Oct 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 95.30%. Comparing base (25dae02) to head (52010e3).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #343   +/-   ##
=======================================
  Coverage   95.30%   95.30%           
=======================================
  Files         137      137           
  Lines        6388     6388           
  Branches     1679     1640   -39     
=======================================
  Hits         6088     6088           
  Misses        300      300           
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@nevware21-bot nevware21-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved by nevware21-bot

@nev21
nev21 merged commit 7d2a583 into main Oct 9, 2026
10 checks passed
@nev21
nev21 deleted the dependabot/npm_and_yarn/dev-228cc92cf3 branch October 9, 2026 01:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants