fix(deps): update all dependencies - #20
Conversation
61f06bc to
4c58bf8
Compare
52aba09 to
16d549f
Compare
f240877 to
3c2e51f
Compare
9456c54 to
0ff8d9f
Compare
6ff8486 to
4c77644
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughBump CI action versions, pin pnpm to 11.1.2 in root and app, and update Changesets plus many app dependencies/devDependencies (Effect stack, TypeScript tooling, linting, testing, and build tools). ChangesToolchain and dependency upgrades
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related issues
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🐇 I nudged a YAML line, made pnpm climb to eleven, Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/actions/setup/action.yml:
- Line 13: The workflow currently uses a mutable tag "pnpm/action-setup@v6";
replace that with an immutable full commit SHA (40-hex) for pnpm/action-setup to
pin the action (e.g., "pnpm/action-setup@<full-commit-sha>"). Locate the "uses:
pnpm/action-setup@v6" entry in the action.yml and update it to the exact commit
SHA from the pnpm/action-setup repository, verify the SHA is full-length (40
characters) and that the workflow still runs correctly after the change.
In @.github/workflows/checking-dependencies.yml:
- Line 15: Replace the mutable tag reference "uses: pnpm/action-setup@v6" with
an immutable pin to the full commit SHA for the pnpm/action-setup action (e.g.,
"uses: pnpm/action-setup@<full-commit-sha>"); locate the occurrences of
"pnpm/action-setup@v6" in the workflow and update them to the corresponding
release commit SHA from the action's repository, then verify the workflow runs
successfully.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 4cd2e52a-a23f-4849-8bc7-20b25e799703
⛔ Files ignored due to path filters (1)
pnpm-lock.yamlis excluded by!**/pnpm-lock.yaml
📒 Files selected for processing (5)
.github/actions/setup/action.yml.github/workflows/checking-dependencies.yml.github/workflows/snapshot.ymlpackage.jsonpackages/app/package.json
| steps: | ||
| - name: Install pnpm | ||
| uses: pnpm/action-setup@v3 | ||
| uses: pnpm/action-setup@v6 |
There was a problem hiding this comment.
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
# Verify mutable action refs under .github (tag-based refs like `@v1/`@v6).
# Expected: no matches after SHA pinning.
rg -n --iglob '*.yml' --iglob '*.yaml' 'uses:\s*[^@[:space:]]+@v[0-9]+(\.[0-9]+){0,2}\b' .githubRepository: ProverCoderAI/openapi-effect
Length of output: 1009
Pin pnpm/action-setup to an immutable commit SHA.
Line 13 uses a mutable tag (@v6). Please pin to a full-length commit SHA to reduce supply-chain risk and avoid policy breaks in hardened org settings.
🔒 Suggested change
- uses: pnpm/action-setup@v6
+ uses: pnpm/action-setup@<full-length-commit-sha> # v6.xReference: https://docs.github.com/actions/security-guides/security-hardening-for-github-actions
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/actions/setup/action.yml at line 13, The workflow currently uses a
mutable tag "pnpm/action-setup@v6"; replace that with an immutable full commit
SHA (40-hex) for pnpm/action-setup to pin the action (e.g.,
"pnpm/action-setup@<full-commit-sha>"). Locate the "uses: pnpm/action-setup@v6"
entry in the action.yml and update it to the exact commit SHA from the
pnpm/action-setup repository, verify the SHA is full-length (40 characters) and
that the workflow still runs correctly after the change.
| steps: | ||
| - uses: actions/checkout@v6 | ||
| - uses: pnpm/action-setup@v4 | ||
| - uses: pnpm/action-setup@v6 |
There was a problem hiding this comment.
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
# Verify mutable action refs under .github (tag-based refs like `@v1/`@v6).
# Expected: no matches after SHA pinning.
rg -n --iglob '*.yml' --iglob '*.yaml' 'uses:\s*[^@[:space:]]+@v[0-9]+(\.[0-9]+){0,2}\b' .githubRepository: ProverCoderAI/openapi-effect
Length of output: 1009
Pin pnpm/action-setup to a commit SHA instead of a mutable tag.
Line 15 uses @v6, which is a mutable tag reference. Per GitHub's security hardening guidelines, action references should be pinned to full commit SHAs to ensure immutability and prevent unintended updates from tag rewrites.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/checking-dependencies.yml at line 15, Replace the mutable
tag reference "uses: pnpm/action-setup@v6" with an immutable pin to the full
commit SHA for the pnpm/action-setup action (e.g., "uses:
pnpm/action-setup@<full-commit-sha>"); locate the occurrences of
"pnpm/action-setup@v6" in the workflow and update them to the corresponding
release commit SHA from the action's repository, then verify the workflow runs
successfully.
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@package.json`:
- Line 6: The package.json currently sets "packageManager": "pnpm@11.1.2" but
pnpm v11 requires config and environment changes; run the recommended codemod
(pnpx codemod run pnpm-v10-to-v11) and then: move any settings under the
package.json "pnpm" field into pnpm-workspace.yaml, strip .npmrc to only
auth/registry entries, update .nvmrc and CI to Node.js 22+ to match pnpm v11,
rename any environment variables from npm_config_* to pnpm_config_ and manually
review remaining envs, and rename or invoke scripts named
clean/setup/deploy/rebuild using pnpm pm to avoid shadowing built-ins.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 78ded05a-1811-4eac-8349-84f29cb8618e
⛔ Files ignored due to path filters (1)
pnpm-lock.yamlis excluded by!**/pnpm-lock.yaml
📒 Files selected for processing (5)
.github/actions/setup/action.yml.github/workflows/checking-dependencies.yml.github/workflows/snapshot.ymlpackage.jsonpackages/app/package.json
🚧 Files skipped from review as they are similar to previous changes (4)
- .github/actions/setup/action.yml
- .github/workflows/checking-dependencies.yml
- .github/workflows/snapshot.yml
- packages/app/package.json
| "private": true, | ||
| "description": "Monorepo workspace for effect-template", | ||
| "packageManager": "pnpm@10.30.1", | ||
| "packageManager": "pnpm@11.1.2", |
There was a problem hiding this comment.
🧩 Analysis chain
🌐 Web query:
pnpm 11 breaking changes and migration guide
💡 Result:
pnpm 11 is a major release that introduces significant breaking changes, security-first defaults, and architectural improvements [1]. The official migration guide is available at https://pnpm.io/11.x/migration [2]. Key Breaking Changes and Migration Steps Configuration Changes pnpm 11 significantly changes how configuration is handled [3][1]: - Configuration is no longer read from the pnpm field in package.json; move these settings to pnpm-workspace.yaml [3][2]. -.npmrc files are now restricted to auth and registry settings only [3][1]. All other settings (e.g., hoist-pattern, node-linker) must be moved to pnpm-workspace.yaml using camelCase keys [3][2]. - npm_config_* environment variables are no longer supported; rename them to pnpm_config_* [3][1]. - pnpm no longer reads npm's global config at $PREFIX/etc/npmrc [1]. Dependency and Script Management - Build-dependency settings (onlyBuiltDependencies, neverBuiltDependencies, etc.) are consolidated into a single allowBuilds map in pnpm-workspace.yaml [3][1]. - Package manager strictness settings are collapsed into a single pmOnFail setting [3][2]. - Script names now shadow built-in commands [3]. If you have scripts named clean, setup, deploy, or rebuild, pnpm will execute your script instead of the built-in command; use pnpm pm to access the built-in version [3]. - pnpm install -g (with no arguments) is no longer supported; use pnpm add -g instead [3][1]. Environment and Infrastructure - Node.js 18, 19, 20, and 21 are no longer supported; Node.js 22+ is required [1]. - pnpm is now distributed as pure ESM [1]. - Global installs are now isolated using a global-virtual-store, preventing interference between global packages [1]. Security and New Features - Minimum Release Age: By default, pnpm 11 blocks the installation of package versions published within the last 24 hours to mitigate supply chain attacks [4][5][6]. - Exotic Subdependencies: pnpm 11 blocks dependencies resolved from non-standard sources (e.g., Git repositories or direct tarball URLs) by default [4][6]. - Native Publish: The npm CLI fallback for publishing has been removed in favor of a native implementation [1]. - Store Index: The store index has been migrated from a JSON-per-package format to a single SQLite database for improved performance [1][5]. Migration Tooling The pnpm team provides a codemod to automate many of these changes [2]. You can run it in your project directory: pnpx codemod run pnpm-v10-to-v11 [2] For changes that cannot be automated, such as environment variable updates, manual review is required [3][2].
Citations:
- 1: https://pnpm.io/blog/releases/11.0
- 2: https://pnpm.io/11.x/migration
- 3: https://pnpm.io/migration
- 4: https://gbhackers.com/pnpm-11-enables-default-release-age-guard/
- 5: https://cyberpress.org/pnpm-blocks-supply-attacks/
- 6: https://undercodenews.com/pnpm-11-reinvents-javascript-security-a-new-era-for-dependency-protection/
🌐 Web query:
pnpm 11.1.2 release notes and security advisories
💡 Result:
As of May 17, 2026, pnpm version 11.1.2 is the latest release [1]. Release Notes for pnpm 11.1.2 Specific release notes for version 11.1.2 were not explicitly detailed in the provided search results, as it is a very recent patch release [1]. However, it follows the major 11.1.0 and 11.1.1 releases, which introduced several significant features and fixes [2][3][4]: - New Commands: Added pnpm audit signatures (to verify ECDSA registry signatures), pnpm bugs (to open package bug trackers), and pnpm owner (to manage package owners) [3][4]. - Named Registries: Added support for installing packages from arbitrary named registries, including a built-in gh: prefix for the GitHub Packages npm registry [3][4]. - CI Improvements: Introduced the --no-runtime flag (config: runtime=false) to skip installing runtime entries (e.g., Node.js) in CI environments [3][4]. - Fixes: Version 11.1.1 included fixes for installability validation in workspace projects, resolved issues with pnpm add for named registries, and updated @zkochan/cmd-shim to improve compatibility with Git Bash on Windows [2]. Security Advisories There are no specific security advisories listed for version 11.1.2. Users should monitor the official pnpm GitHub Security Advisories page for any future disclosures [5]. Recent security-related updates in the pnpm 11 series include: - Minimum Release Age: pnpm 11 introduced a default Minimum Release Age of 24 hours (1440 minutes), which prevents the installation of newly published package versions to mitigate supply chain attacks [6][7][8]. - Enhanced Auditing: pnpm audit now queries the registry's bulk security advisories endpoint and filters by GitHub Advisory ID (GHSA) rather than CVE identifiers [9]. - Security Hardening: pnpm 11 requires Node.js 22+ and is distributed as pure ESM [10][11]. It also includes improved control over lifecycle scripts via the allowBuilds model [7][8]. For the most up-to-date information, always check the official pnpm releases page on GitHub and the security advisories section [12][5].
Citations:
- 1: https://www.npmjs.com/package/pnpm?activeTab=versions
- 2: https://github.com/pnpm/pnpm/releases/tag/v11.1.1
- 3: https://pnpm.io/blog/releases/11.1
- 4: https://newreleases.io/project/npm/pnpm/release/11.1.0
- 5: https://github.com/pnpm/pnpm/security/advisories
- 6: https://gbhackers.com/pnpm-11-enables-default-release-age-guard/
- 7: https://undercodenews.com/pnpm-11-reinvents-javascript-security-a-new-era-for-dependency-protection/
- 8: https://pnpm.io/supply-chain-security
- 9: https://pnpm.io/cli/audit
- 10: https://github.com/pnpm/pnpm/releases/tag/v11.0.0
- 11: https://pnpm.io/blog/releases/11.0
- 12: https://github.com/pnpm/pnpm/releases
Review pnpm 11 migration requirements before merging.
This major version upgrade introduces breaking changes that require configuration updates and environment adjustments:
- Configuration files: Settings in
package.json'spnpmfield must move topnpm-workspace.yaml. Update.npmrcto contain only auth and registry settings. - Node.js requirement: pnpm 11 requires Node.js 22+. Verify your project's
.nvmrcand CI configuration specify a compatible version. - Environment variables: Any
npm_config_*variables must be renamed topnpm_config_*. - Script behavior: Scripts named
clean,setup,deploy, orrebuildnow shadow built-in commands; usepnpm pmto access built-in versions.
Run the migration codemod to automate configuration changes:
pnpx codemod run pnpm-v10-to-v11
Refer to https://pnpm.io/11.x/migration for the complete migration guide. Manual review is needed for environment variable updates that the codemod cannot automate.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@package.json` at line 6, The package.json currently sets "packageManager":
"pnpm@11.1.2" but pnpm v11 requires config and environment changes; run the
recommended codemod (pnpx codemod run pnpm-v10-to-v11) and then: move any
settings under the package.json "pnpm" field into pnpm-workspace.yaml, strip
.npmrc to only auth/registry entries, update .nvmrc and CI to Node.js 22+ to
match pnpm v11, rename any environment variables from npm_config_* to
pnpm_config_ and manually review remaining envs, and rename or invoke scripts
named clean/setup/deploy/rebuild using pnpm pm to avoid shadowing built-ins.
|
Надо смержить сюда main ветку и исправить все ошибки в CI/CD что бы код был с актуальными библиотеками |
|
🤖 AI Work Session Started Starting automated work session at 2026-06-19T19:17:51.406Z The PR has been converted to draft mode while work is in progress. This comment marks the beginning of an AI work session. Please wait for the session to finish, and provide your feedback. |
|
Update: the CI/CD fix is implemented and verified, but I cannot push it directly to this PR head branch. Blocker:
Prepared fix:
What the fix covers:
Verification:
Needed human action: either grant/push access to |
🤖 Solution Draft LogThis log file contains the complete execution trace of the AI solution draft process. 💰 Cost estimation:
📊 Context and tokens usage:
Total: (508.9K + 13.1M cached) input tokens, 68.4K output tokens, $21.304392 cost 🤖 Models used:
📎 Log file uploaded as Repository (75696KB)Now working session is ended, feel free to review and add any feedback on the solution draft. |
🔄 Auto-restart triggered (iteration 1)Reason: CI failures detected Starting new session to address the issues. Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations. |
|
Rechecked the failing CI/CD status in this restart session. Findings:
Verification repeated locally with Node
Fork CI also has successful runs for Remaining blocker is repository permissions, not code: |
🔄 Auto-restart-until-mergeable Log (iteration 1)This log file contains the complete execution trace of the AI solution draft process. 💰 Cost estimation:
🤖 Models used:
📎 Log file uploaded as Repository (96784KB)Now working session is ended, feel free to review and add any feedback on the solution draft. |
🔄 Auto-restart triggered (iteration 2)Reason: CI failures detected Starting new session to address the issues. Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations. |
|
Rechecked and updated the prepared fix in this restart session. Current prepared commit:
Root causes confirmed from upstream CI logs for old SHA
Verification on current SHA
Remaining blocker is repository permission, not code. Needed maintainer action: push/cherry-pick |
🔄 Auto-restart-until-mergeable Log (iteration 2)This log file contains the complete execution trace of the AI solution draft process. 💰 Cost estimation:
🤖 Models used:
📎 Log file uploaded as Repository (2 chunks) (116514KB)Now working session is ended, feel free to review and add any feedback on the solution draft. |
🔄 Auto-restart triggered (iteration 3)Reason: CI failures detected Starting new session to address the issues. Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations. |
|
Restart iteration 3 rechecked the prepared CI fix. Current verified head:
Fresh upstream CI logs downloaded in this session confirm old-head root causes:
Verification repeated on
Push blocker remains external: Needed maintainer action: push or cherry-pick |
🔄 Auto-restart-until-mergeable Log (iteration 3)This log file contains the complete execution trace of the AI solution draft process. 💰 Cost estimation:
🤖 Models used:
📎 Log file uploaded as Repository (2 chunks) (139990KB)Now working session is ended, feel free to review and add any feedback on the solution draft. |
🔄 Auto-restart triggered (iteration 4)Reason: CI failures detected Starting new session to address the issues. Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations. |
|
Restart iteration 4 rechecked the CI/CD fix. Current verified head:
Fresh upstream logs downloaded in this session confirm the old-head failures:
Verification repeated locally on
Push status:
Needed maintainer action: push or cherry-pick |
🔄 Auto-restart-until-mergeable Log (iteration 4)This log file contains the complete execution trace of the AI solution draft process. 💰 Cost estimation:
🤖 Models used:
📎 Log file uploaded as Repository (2 chunks) (154923KB)Now working session is ended, feel free to review and add any feedback on the solution draft. |
🔄 Auto-restart triggered (iteration 5)Reason: CI failures detected Starting new session to address the issues. Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations. |
|
Restart iteration 5 rechecked the CI/CD failures and the prepared fix. Current verified fix:
Fresh upstream CI status:
Root causes confirmed from downloaded upstream logs:
Verification repeated locally on
Fork CI on
Push status:
Needed maintainer action: push or cherry-pick |
🔄 Auto-restart-until-mergeable Log (iteration 5)This log file contains the complete execution trace of the AI solution draft process. 💰 Cost estimation:
🤖 Models used:
📎 Log file uploaded as Repository (2 chunks) (177139KB)Now working session is ended, feel free to review and add any feedback on the solution draft. |
|
|
🤖 AI Work Session Completed Work session ended at 2026-06-19T20:58:19.771Z The PR will be converted back to ready for review. This comment marks the end of an AI work session. New comments after this time will be considered as feedback. |
This PR contains the following updates:
^2.4.4→^2.5.13^0.5.2→^1.0.1^2.29.8→^3.0.2^4.6.0→^4.8.02.0.2→2.1.13.3.3→3.3.7^24.10.13→^24.13.4^8.56.0→^8.70.0^8.56.0→^8.70.0^4.0.18→^5.0.0^1.6.9→^1.6.27v6→v7v6→v7v6→v7^3.19.18→^3.22.2^10.0.1→^10.10.0^4.4.4→^4.4.5^12.1.1→^14.0.0^4.0.0→^4.2.0^63.0.0→^74.0.0^17.3.0→^17.12.0^4.0.8→^5.2.024.13.1→24.21.010.30.1→12.4.1v4→v6v3→v6^5.9.3→^7.0.2^8.56.0→^8.70.0^7.3.1→^8.3.0^4.0.18→^5.0.0cc @skulidropek
Release Notes
biomejs/biome (@biomejs/biome)
v2.5.13Compare Source
Patch Changes
#11379
07a0073Thanks @Netail! - Added the nursery ruleuseLayeredStyles, which enforces that style rules are defined within a cascade layer and import rules to import its styles into a cascade layer.#11667
e997900Thanks @devtechedge! - Added the nursery ruleuseBetterDomTraversing, which prefers.firstChild,.firstElementChild,.closest(), and merged.querySelector()calls over positional DOM traversal.#11620
20e513aThanks @jakeleventhal! - Fixed #11610, #11611, #11612, #11615, and #11616: Biome no longer fully infers an imported generic declaration just to apply its type arguments, restoring type-aware lint performance for large libraries such as Zod. This improvesuseRegexpExec,noFloatingPromises,noMisusedPromises,useNullishCoalescing, andnoUnsafePlusOperands.#11657
e322040Thanks @ematipico! - Fixed #7495:noUselessConstructornow ignores TypeScript constructors that forward at least one argument tosuper, preserving constructors that narrow the subclass's accepted parameter types. The exemption also applies when the parent and child signatures are identical; JavaScript and zero-argument forwarding behavior are unchanged.#11670
4969ee1Thanks @ematipico! - Fixed #7076:useAriaPropsForRoleanduseFocusableInteractiveno longer report non-focusable elements withrole="separator". A separator with an explicittabIndexortabindexstill requiresaria-valuenow.#11627
23aad6dThanks @ematipico! - Fixed #6571 so Grit plugins can capture and inspect multiple named import specifiers.#11631
00dbd3aThanks @ematipico! - Reduced unnecessary type inference when type-aware lint rules inspect members of namespace imports from libraries such as Zod. Fixed type inference so blanket re-exports do not expose default exports.#11628
a2f8ff7Thanks @dyc3! - Added the nursery rulenoXorAsExponentiation, which reports the bitwise XOR operator^between two decimal integer literals, where the exponentiation operator**was likely intended.#11670
4969ee1Thanks @ematipico! - Fixed #7192:noUnusedPrivateClassMembersnow considers compound assignments such as??=to read and use private class members.#11676
840a52aThanks @dyc3! - Fixed #11672 and #11671 by disabling the experimental capitalized-call and effect-dependency checks inuseReactCompiler, matching their exclusion from upstream's recommended lint preset. Valid calls such asIntl.NumberFormat()and captures of variables declared inside effects no longer produce these diagnostics.#11660
49485edThanks @ematipico! - Fixed #11653: Astro template suppression comments ({/* biome-ignore lint: reason */}) now suppress matching HTML lint diagnostics on the following line when full HTML support is enabled.#11664
9a73b9cThanks @dyc3! - Improved the performance ofuseRegexpExec.#11661
5341b3fThanks @ematipico! - Fixed #7479.noUnusedVariablesnow treats Unicode escapes in identifiers as the same binding as their decoded spelling.#11630
62e1fc5Thanks @dyc3! - Fixed the HTML formatter inserting whitespace between adjacent Svelte expressions when their combined length exceeds the line width.#11658
ed4bfa4Thanks @fredrikblau! - Fixed #11644:useHeadingContentno longer reports headings that render their text with a directive:set:htmlandset:textin Astro files,v-htmlandv-textin Vue files.#11613
47d7383Thanks @ematipico! - Improved the performance of Biome Formatter up to ~50% in some cases.#11655
fd8fc74Thanks @ematipico! - Fixed #6974, wherenoUnusedPrivateClassMembersincorrectly reported TypeScript private constructor properties read through object destructuring fromthisas unused.#11618
21a10cfThanks @siketyan! - Fixed #11605: Type inference now infers the type of an unannotated callback parameter from the signature of the function the callback is passed to, and honours explicit type arguments on call expressions. This improves type-aware analysis fornoBaseToString,noFloatingPromises,noMisleadingReturnType,noMisusedPromises,noUnnecessaryConditions,noUnsafePlusOperands,noUselessTypeConversion,useArrayFind,useArraySortCompare,useAwaitThenable,useDisposables,useExhaustiveSwitchCases,useIncludes,useNullishCoalescing,useRegexpExec, anduseStringStartsEndsWith. For example,noFloatingPromisescan now detect Promises reached through such parameters:#11698
b019982Thanks @denbezrukov! - Fixed parsing of unquoted CSS URLs beginning with@or!, such asurl(@/assets/icon.svg)andurl(!font.woff2). Preserved escaped and non-ASCII whitespace in raw URLs during formatting.#11622
c23e4c7Thanks @Netail! - Added the nursery rulenoUnsafeIframeSandbox, which reportsiframeelements whosesandboxattribute combinesallow-scriptsandallow-same-origin, since that combination lets the embedded document remove its own sandboxing.#11606
de0528fThanks @dyc3! - Added the recommendednoSvelteAtHtmlTagsnursery rule, which reports Svelte{@html}tags that render unescaped HTML.#11670
4969ee1Thanks @ematipico! - Fixed #6782: GritQL plugins now match captured JSX component names against code snippets such asReact.Fragment.#11687
09d97d9Thanks @hori-design! - Fixed #11678:useReactCompilerno longer panics on files that contain non-ASCII characters. This bumps the React Compiler version.#11595
a64d757Thanks @dyc3! - Added the nursery Vue-domain ruleuseVueBaseImportrule, which enforces importing Vue APIs fromvueinstead of internal@vue/*packages.#11675
353cbaeThanks @dyc3! - FixeduseReactCompilersilently producing no diagnostics in WebAssembly builds, including the playground.#11625
ea20e5aThanks @denbezrukov! - Improved linting performance for large CSS and JSON files.#11670
4969ee1Thanks @ematipico! - Fixed #7527: suppression actions for diagnostics emitted on comments are now inserted before the diagnostic comment. In particular, suppressingnoTsIgnorenow places thebiome-ignorecomment before@ts-ignore.#11655
fd8fc74Thanks @ematipico! - Fixed #8629, wherenoUnusedPrivateClassMembersincorrectly reported used private TypeScript method overload signatures as unused.#11669
579f401Thanks @denbezrukov! - Improved the performance ofnoExcessiveLinesPerFilewhenskipBlankLinesisfalse.v2.5.12Compare Source
Patch Changes
#11440
b88f1eaThanks @Princesseuh! - Fixed Astro attribute expressions rejecting TypeScript and JSX syntax that is accepted in text expressions.#11440
b88f1eaThanks @Princesseuh! - Fixed Astro attribute names being split on:and.inside an expression, such as{x && <button x-on:keyup.enter={go} client:load.foo />}.#11440
b88f1eaThanks @Princesseuh! - Fixed a bare>in the children of an Astro expression being treated as markup, such as{x && <div>a > b</div>}.#11440
b88f1eaThanks @Princesseuh! - Fixed HTML comments inside an Astro expression failing to parse. They are now read as trivia, wherever they appear among the children.#11440
b88f1eaThanks @Princesseuh! - Fixedis:rawchildren inside an Astro expression being read as JSX, such as{x && <div is:raw>{not js} < & text</div>}.#11440
b88f1eaThanks @Princesseuh! - Fixed an apostrophe or quote in the text of a JSX element inside an Astro expression ending the expression early, such as{items.map((i) => <li>it's {i}</li>)}.#11440
b88f1eaThanks @Princesseuh! - Fixed the children of a<script>or<style>inside an Astro expression being read as JSX. Their contents are text, so braces and comparisons no longer have to be escaped.#11440
b88f1eaThanks @Princesseuh! - Added support for template literal attribute values inside an Astro expression, such as{x && <C data-x=`t${x}` />}.#11440
b88f1eaThanks @Princesseuh! - Fixed unquoted attribute values being rejected inside an Astro expression, such as{x && <a class=foo maxlength=255 href=/about>go</a>}.#11440
b88f1eaThanks @Princesseuh! - Fixed a template literal nested inside${}breaking the rest of an Astro file, such asconst href = `/blog${page === 0 ? '' : `/${page + 1}`}`;.#11440
b88f1eaThanks @Princesseuh! - Fixed a quote inside a regex character class breaking the rest of an Astro file, such asconst unsafe = /[/"]/;.#11508
54f3a2eThanks @dyc3! - Added the nursery ruleuseFlatMathMinMax. BecauseMath.min()andMath.max()accept any number of arguments, the rule reports unnecessary nested calls to the same method:The fix flattens this expression to
Math.max(a, b, c).#11585
c5c8315Thanks @Netail! - Fixed #11475:noUnresolvedImportsno longer reports Bun runtime built-in modules (bun,bun:bundle,bun:ffi,bun:jsc,bun:sqlite,bun:test).#11368
52a57b3Thanks @Austin1serb! - Fixed #6830: Biome now reports a diagnostic for excessively deep syntax instead of overflowing the native stack while releasing the parsed tree.#11596
1fc42edThanks @dyc3! - Added the nursery rulenoThisOutsideOfClass. The rule reportsthisoutside class members and TypeScript functions with an explicitthisparameter.#11555
2516335Thanks @dyc3! - Fixed #11529, wherenoFloatingPromisesmissed unhandled Promise chains when the imported function's module belonged to an import cycle. Cyclic modules now preserve types for exports that do not participate in recursive type dependencies.#11518
0fee70cThanks @HarperZ9! - Fixed #11500: the formatter now prints thedeclaremodifier before accessibility modifiers on class properties.private declare readonly name: stringis now formatted asdeclare private readonly name: string, matching Prettier and TypeScript's canonical modifier order.#11580
1277af2Thanks @ematipico! - Fixed #5091: Biome no longer moves comments next to the<of a generic, which causes invalid TypeScript syntax:#11577
42995d2Thanks @ematipico! - Fixed #4592. Biome no longer crashes while parsing malformeddeleteexpressions.#11590
67963b4Thanks @ematipico! - Fixed #6427 so Grit plugins can usefunction = ...as a node argument.#11600
a689cb5Thanks @ematipico! - Fixed #6644:noUnusedVariablesnow recognizes all interface declarations in a TypeScript declaration-merging group when the interface is referenced.The following snippet no longer triggers the rule.
#11591
d4a0716Thanks @ematipico! - Fixed #6615.noDuplicatePropertiesno longer reports declarations nested in block at-rules as duplicates of declarations in their parent block.#11492
f2a07aaThanks @santichausis! - Fixed #11454:noMisplacedAssertionnow recognises@fast-check/vitest'stest.prop(...)(and.concurrent.prop,.skip.prop, etc.) as a test function, the same way it already recognisestest.each. The JS formatter picks up the same recognition, so a curriedtest.prop(...)(...)call is now formatted with the regular breakable argument layout used fortest.each/test.for, instead of the single-line-hugging layout used for plainit/testcalls.For example, Biome no longer reports the assertion below as misplaced:
#11589
65742b3Thanks @ematipico! - Fixed #4928:noUnusedVariablesno longer reports a value declaration as unused when its merged namespace is referenced.#11559
472dbc2Thanks @levrik! - Fixed a false positive innoVueDuplicateKeyswhere a<script setup>variable initialized frompropswas reported as a duplicate of the prop it derives from. Biome now exempts any variable whose initializer referencesprops, instead of only recognizingdefineProps()andtoRefs(props).For example, Biome no longer reports
foobelow as a duplicate key:#11594
6586cebThanks @ematipico! - Fixed #6640. Biome no longer crashes when linting malformedfor...ofstatements.#11571
85b197dThanks @ematipico! - Fixed #10838:useSortedAttributesno longer corrupts JSX attributes when nested JSX elements also require sorting.#11533
97e76c0Thanks @ematipico! - Fixed #11520, where the Biome scanner would start analysing dependencies multiple times, leading to long and unresponsive sessions.#11564
18a0e1fThanks @Netail! - Fixed the diagnostic range ofnoInferrableTypesso it now highlights only the type instead of including the leading:colon, spaces and comments.#11540
124fdaaThanks @ematipico! - Fixed#11537:noShorthandPropertyOverridesnow compares declarations only within the same block. The rule no longer reports@supportsfeature queries and correctly checks nested,@keyframes, and@pageblocks.#11532
7ceb0eeThanks @dyc3! - Fixed #11528:noFloatingPromisesno longer reports statement-levelawaitexpressions that handle Promise values, including overloaded calls returning Promise aliases. Awaited values that resolve to arrays of Promises remain reported because their element Promises are not handled byawait.#11474
3c6412eThanks @dyc3! - Fixed #10241. Biome no longer reports unsupported text expression diagnostics for double-curly text in vanilla HTML, and the formatter preserves adjacent curly-brace text.#11593
6c7fd27Thanks @dyc3! - Added the nursery rulenoVueDeprecatedScopedSlots. It reports deprecated$scopedSlotsreferences in Vue templates and component objects, and offers an unsafe replacement with$slots. For example, Biome now reportsthis.$scopedSlots.defaultinside a Vue component.#11440
b88f1eaThanks @Princesseuh! - Fixed the formatter crashing on an Astro or Svelte expression spanning several lines in a file with CRLF line endings, such as<p>{a +\r\n b}</p>.#11581
f4e5ebbThanks @dyc3! - Added the nursery ruleuseModernMathApis. The rule reports legacy mathematical patterns that have direct modernMathequivalents.#11597
a20f44aThanks @Netail! - Added the nursery rulenoBunModules, which forbids the use of Bun builtin modules (e.g.bun:sqlite,bun:ffi).#11545
7d54688Thanks @dyc3! - Fixed #11542: Biome now reports HTML comments between Svelte tag attributes as parse errors.#11582
b6611ddThanks @ematipico! - Fixed #3862. Biome now parses legacy Internet Explorerfilterand-ms-filtervalues such asprogid:DXImageTransform...andalpha(opacity=40).#11575
65da251Thanks @dyc3! - Improved the Tailwind parser's ability to recover from parsing failures. Whitespace now always allows the parser to recover and start parsing a new class.#11576
0f78499Thanks @ematipico! - Fixed #3515 and #10395, where Biome could corrupt Unicode characters while writing source received through standard input to standard output. Characters such as⚠and✔are now preserved.#11539
0fca643Thanks @ematipico! - Fixed #11512, wherestyle/noDescendingSpecificitymissed lower-specificity selectors after a later higher-specificity selector with the same tail selector.#11544
040f867Thanks @dyc3! - Fixed #11541: formatting a Svelte render tag followed by an HTML comment no longer duplicates the comment.<div> {@render children?.()} <!-- comment --> - <!-- comment --> </div>#11565
ee69e0eThanks @ematipico! - Fixed #11525. Now the configuration schema correctly provides auto-completion for linter domains.#11583
b19390cThanks @dyc3! - Fixed #11352:useExplicitLengthCheckno longer reportslength-like properties used as value-producing||fallbacks or optional chains, and it no longer offers fixes for value-producing&&checks or unsafe negations.#11562
753e955Thanks @ematipico! - Fixed an issue where the Biome Language Server would start with logging level set to debug. This would cause logs to grow exponentially in long sessions.#11217
7d3ee9cThanks @dyc3! - Fixed handling ofbiome-ignore formatsuppression comments on TypeScript declared class properties with string literal names.#11497
f5d7896Thanks @dyc3! - Added thenoInvalidFileInputAcceptnursery rule. The rule reports invalid literalacceptvalues on file inputs in JSX and HTML, and normalizes common mistakes.#11345
ac58958Thanks @jakeleventhal! - Improved type inference performance by avoiding resolution of unused members in object arguments.#11554
2d55931Thanks @Netail! - Added the new nursery ruleuseReactNamingConvention, which enforces naming conventions for React values assigned fromcreateContext,useId, anduseRef. A value fromcreateContextmust be a PascalCase component name ending withContext, a value fromuseIdmust be namedidor end withId, and a value fromuseRefmust be namedrefor end withRef.#11491
1d6210bThanks @dyc3! - Added the nursery rulenoUnmodifiedLoopCondition, which reports variables in loop conditions that are never modified in the loop.v2.5.11Compare Source
Patch Changes
#11499
9743d0cThanks @scs0209! - Fixed #11496:useValidAnchornow treats Astro JSX shorthand attributes like<a {href}>as a validhref.#11437
88f805eThanks @Princesseuh! - Fixed [#9944](https://redirect.github.com/biomConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.