Skip to content

Bump @microsoft/rush from 5.179.0 to 5.180.0 - #235

Open
dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/npm_and_yarn/microsoft/rush-5.180.0
Open

dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/npm_and_yarn/microsoft/rush-5.180.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps @microsoft/rush from 5.179.0 to 5.180.0.

Changelog

Sourced from @​microsoft/rush's changelog.

5.180.0

Tue, 29 Sep 2026 13:39:28 GMT

Minor changes

  • Allow hosts to discard unstarted graph iterations without executing scripts or closing retained runners, preserving completed results for safe replanning.
  • Publish validated opt-in daemon configuration and environment overrides. Watch and warm-set settings remain explicitly documented integration seams.
  • Expose a bounded native phased-command engine factory that reuses Rush command parsing and the all-project operation graph pipeline without CLI process-state mutation, with explicit lifetime cleanup and native lock ownership.
  • Expose native Rushx parsing and request-local lifecycle execution with owned asynchronous spawning, isolated dotenv preparation, native diagnostics and injected-dependency synchronization.
  • Add false-default persistent daemon Node runners selected by explicit per-operation daemonIpc descriptors, including the SDK declaration proxy. Preserve raw custom arguments, canonical hashes, native/rebuild/NoOp/shard behavior, and bounded implementation-tree reloads. Keep watch-only IPC unchanged and decode IPC stdout/stderr incrementally.
  • Expose stable workspace/runtime input fingerprints and safe borrowing of an already-held native preparation lock for generation-scoped engine reload.

Patches

  • Document the experimental reporter opt-in, rollback, output contracts, compatibility boundary, and reproducible demo.
  • Add repository configuration for opting into and configuring the experimental Rush reporter.
  • Add pre-major frontend reporter controls with legacy command compatibility, selected-engine gating, and deterministic reporter finalization.
  • Expose an optional scoped reporter producer API to Rush actions and plugins while preserving legacy terminal output.
  • Emit shadow Rush lifecycle, phase-aware operation, diagnostic, telemetry, and command-result events without changing legacy terminal output.
  • Complete shadow reporter parity coverage for event identity, telemetry privacy, exit status, repeated operation phases, and unchanged legacy output.
  • Emit feature-flagged phase-aware operation registration, status, raw output, stream-close, and completion events while preserving the legacy StreamCollator output path.
  • Add the opt-in direct build reporter demo path with reporter-owned output, a complete full-detail log, and an immediate legacy rollback.
  • Add a bounded nonce-protected install-run-rush handoff, replay it before version selection, and bridge cross-version reporter compatibility.
  • Relay compatible Heft child events through the selected Rush reporter with ordered raw fallback and problem matcher diagnostics.
  • Preserve immutable errors, diagnose pre-execution parser failures once, and register shadow operations after final watch iteration configuration.
  • Connect real watch cancellation to the persistent shadow exit-status observer without changing legacy process status, and verify raw stdout/stderr chunk parity.
  • Document daemon.watch as persistent host observation of warm projects, defaulting to root/config guards only without enabling automatic builds.
  • Preserve the inherited Windows Path when preparing native daemon operation environments.
  • Exclude volatile per-shell, terminal, session and daemon-routing environment variables (such as PWD, OLDPWD, SHLVL, TERM and WSL_INTEROP) from workspace input environment fingerprints, via the new workspaceFingerprintIgnoredEnvironmentVariables and getWorkspaceFingerprintEnvironmentEntries APIs.
  • Fix a build cache poisoning race: skip writing a build cache entry when an operation's tracked input files changed while it was executing.
  • Fix pnpm registry credentials being dropped by POSIX shells when provideNpmrcCredentialsViaEnvironment is enabled.
  • Allow operations to write build cache entries when their dependencies were not re-run because a previous iteration of a long-lived graph (such as the Rush daemon) produced a trusted result at the same state hash. Dependencies skipped by the user (e.g. --only) still block cache writes.
  • Document that the daemon warmSetMaxProjects limit only counts projects holding warm resources (active runners or file watchers).
  • Exclude --verbose, --parallelism and --timeline from the daemon engine parameter identity and expose them as per-request settings, so these flags no longer force the Rush daemon to reload its warm operation graph.
  • Preserve the original native Rushx registration path unless an explicit invocation namespace is supplied, and release fixture-owned native parser locks after frontend tests.
  • Preserve the active repository mutex and its Windows interrupted-owner marker when purging temporary files.
  • Preserve unexpected aggregate cleanup errors in per-operation runner lifetime handling so dependents do not execute after a failed cleanup notification.
  • Use LockFile's backing-file path contract to preserve active repository locks and their recovery companions during purge.
  • Consume reporter verbose and repository opt-in value controls only when command ownership is known, preserving native aliases and declared custom parameters.
  • Preserve custom bootstrap controls and legacy environment overrides, keep direct command output within reporter-owned destinations, and suppress duplicate watch presentation.
  • Recognize frontend-owned reporter environment controls when native engines or rushx execute without frontend environment scrubbing.
  • Preserve custom reporter controls during emergency legacy rollback and honor reserved stdout/stderr output destinations.
  • Report early initialization failures and defer successful reporter completion until telemetry finalization preserves the command's native outcome.
  • Fail corrupted negotiated Heft reporter streams while preserving genuine raw fallback, and validate the demo's intentional Windows fallback.
  • Correct local reporter demo examples to select the built Rush engine instead of an older repository-pinned version, and explain restoration of normal version selection.
  • Preserve legacy flags after valueless reporter rollback controls and default an unqualified primary file reporter to debug detail.
  • Preserve machine-readable stdout ownership for additional reporter outputs during engine compatibility handoff.
  • Resolve the command working directory to its physical path so watch input snapshots work with Windows short names and directory aliases. Preserve real watch cancellation and watcher cleanup coverage for both legacy and shadow reporting.
  • Resolve Windows lifecycle shells consistently from the request environment, retain asynchronous child ownership through named options, and isolate concurrent Git-selector configuration.
  • Preserve both resolved reporter-control stripping lists when bootstrap compatibility falls back to legacy output.

... (truncated)

Commits

Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
@microsoft/rush [>= 5.144.a, < 5.145]

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@microsoft/rush](https://github.com/microsoft/rushstack/tree/HEAD/apps/rush) from 5.179.0 to 5.180.0.
- [Changelog](https://github.com/microsoft/rushstack/blob/main/apps/rush/CHANGELOG.md)
- [Commits](https://github.com/microsoft/rushstack/commits/HEAD/apps/rush)

---
updated-dependencies:
- dependency-name: "@microsoft/rush"
  dependency-version: 5.180.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 5, 2026
@dependabot
dependabot Bot requested review from a team as code owners October 5, 2026 20:25
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 5, 2026

@nevware21-bot nevware21-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved by nevware21-bot

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant