fix(deps): update all dependencies - #20
Conversation
61f06bc to
4c58bf8
Compare
52aba09 to
16d549f
Compare
f240877 to
3c2e51f
Compare
9456c54 to
0ff8d9f
Compare
6ff8486 to
4c77644
Compare
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughBump CI action versions, pin pnpm to 11.1.2 in root and app, and update Changesets plus many app dependencies/devDependencies (Effect stack, TypeScript tooling, linting, testing, and build tools). ChangesToolchain and dependency upgrades
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related issues
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/actions/setup/action.yml:
- Line 13: The workflow currently uses a mutable tag "pnpm/action-setup@v6";
replace that with an immutable full commit SHA (40-hex) for pnpm/action-setup to
pin the action (e.g., "pnpm/action-setup@<full-commit-sha>"). Locate the "uses:
pnpm/action-setup@v6" entry in the action.yml and update it to the exact commit
SHA from the pnpm/action-setup repository, verify the SHA is full-length (40
characters) and that the workflow still runs correctly after the change.
In @.github/workflows/checking-dependencies.yml:
- Line 15: Replace the mutable tag reference "uses: pnpm/action-setup@v6" with
an immutable pin to the full commit SHA for the pnpm/action-setup action (e.g.,
"uses: pnpm/action-setup@<full-commit-sha>"); locate the occurrences of
"pnpm/action-setup@v6" in the workflow and update them to the corresponding
release commit SHA from the action's repository, then verify the workflow runs
successfully.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 4cd2e52a-a23f-4849-8bc7-20b25e799703
⛔ Files ignored due to path filters (1)
pnpm-lock.yamlis excluded by!**/pnpm-lock.yaml
📒 Files selected for processing (5)
.github/actions/setup/action.yml.github/workflows/checking-dependencies.yml.github/workflows/snapshot.ymlpackage.jsonpackages/app/package.json
| steps: | ||
| - name: Install pnpm | ||
| uses: pnpm/action-setup@v3 | ||
| uses: pnpm/action-setup@v6 |
There was a problem hiding this comment.
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
# Verify mutable action refs under .github (tag-based refs like `@v1/`@v6).
# Expected: no matches after SHA pinning.
rg -n --iglob '*.yml' --iglob '*.yaml' 'uses:\s*[^@[:space:]]+@v[0-9]+(\.[0-9]+){0,2}\b' .githubRepository: ProverCoderAI/openapi-effect
Length of output: 1009
Pin pnpm/action-setup to an immutable commit SHA.
Line 13 uses a mutable tag (@v6). Please pin to a full-length commit SHA to reduce supply-chain risk and avoid policy breaks in hardened org settings.
🔒 Suggested change
- uses: pnpm/action-setup@v6
+ uses: pnpm/action-setup@<full-length-commit-sha> # v6.xReference: https://docs.github.com/actions/security-guides/security-hardening-for-github-actions
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/actions/setup/action.yml at line 13, The workflow currently uses a
mutable tag "pnpm/action-setup@v6"; replace that with an immutable full commit
SHA (40-hex) for pnpm/action-setup to pin the action (e.g.,
"pnpm/action-setup@<full-commit-sha>"). Locate the "uses: pnpm/action-setup@v6"
entry in the action.yml and update it to the exact commit SHA from the
pnpm/action-setup repository, verify the SHA is full-length (40 characters) and
that the workflow still runs correctly after the change.
| steps: | ||
| - uses: actions/checkout@v6 | ||
| - uses: pnpm/action-setup@v4 | ||
| - uses: pnpm/action-setup@v6 |
There was a problem hiding this comment.
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
# Verify mutable action refs under .github (tag-based refs like `@v1/`@v6).
# Expected: no matches after SHA pinning.
rg -n --iglob '*.yml' --iglob '*.yaml' 'uses:\s*[^@[:space:]]+@v[0-9]+(\.[0-9]+){0,2}\b' .githubRepository: ProverCoderAI/openapi-effect
Length of output: 1009
Pin pnpm/action-setup to a commit SHA instead of a mutable tag.
Line 15 uses @v6, which is a mutable tag reference. Per GitHub's security hardening guidelines, action references should be pinned to full commit SHAs to ensure immutability and prevent unintended updates from tag rewrites.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/checking-dependencies.yml at line 15, Replace the mutable
tag reference "uses: pnpm/action-setup@v6" with an immutable pin to the full
commit SHA for the pnpm/action-setup action (e.g., "uses:
pnpm/action-setup@<full-commit-sha>"); locate the occurrences of
"pnpm/action-setup@v6" in the workflow and update them to the corresponding
release commit SHA from the action's repository, then verify the workflow runs
successfully.
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@package.json`:
- Line 6: The package.json currently sets "packageManager": "pnpm@11.1.2" but
pnpm v11 requires config and environment changes; run the recommended codemod
(pnpx codemod run pnpm-v10-to-v11) and then: move any settings under the
package.json "pnpm" field into pnpm-workspace.yaml, strip .npmrc to only
auth/registry entries, update .nvmrc and CI to Node.js 22+ to match pnpm v11,
rename any environment variables from npm_config_* to pnpm_config_ and manually
review remaining envs, and rename or invoke scripts named
clean/setup/deploy/rebuild using pnpm pm to avoid shadowing built-ins.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 78ded05a-1811-4eac-8349-84f29cb8618e
⛔ Files ignored due to path filters (1)
pnpm-lock.yamlis excluded by!**/pnpm-lock.yaml
📒 Files selected for processing (5)
.github/actions/setup/action.yml.github/workflows/checking-dependencies.yml.github/workflows/snapshot.ymlpackage.jsonpackages/app/package.json
🚧 Files skipped from review as they are similar to previous changes (4)
- .github/actions/setup/action.yml
- .github/workflows/checking-dependencies.yml
- .github/workflows/snapshot.yml
- packages/app/package.json
| "private": true, | ||
| "description": "Monorepo workspace for effect-template", | ||
| "packageManager": "pnpm@10.30.1", | ||
| "packageManager": "pnpm@11.1.2", |
There was a problem hiding this comment.
🧩 Analysis chain
🌐 Web query:
pnpm 11 breaking changes and migration guide
💡 Result:
pnpm 11 is a major release that introduces significant breaking changes, security-first defaults, and architectural improvements [1]. The official migration guide is available at https://pnpm.io/11.x/migration [2]. Key Breaking Changes and Migration Steps Configuration Changes pnpm 11 significantly changes how configuration is handled [3][1]: - Configuration is no longer read from the pnpm field in package.json; move these settings to pnpm-workspace.yaml [3][2]. -.npmrc files are now restricted to auth and registry settings only [3][1]. All other settings (e.g., hoist-pattern, node-linker) must be moved to pnpm-workspace.yaml using camelCase keys [3][2]. - npm_config_* environment variables are no longer supported; rename them to pnpm_config_* [3][1]. - pnpm no longer reads npm's global config at $PREFIX/etc/npmrc [1]. Dependency and Script Management - Build-dependency settings (onlyBuiltDependencies, neverBuiltDependencies, etc.) are consolidated into a single allowBuilds map in pnpm-workspace.yaml [3][1]. - Package manager strictness settings are collapsed into a single pmOnFail setting [3][2]. - Script names now shadow built-in commands [3]. If you have scripts named clean, setup, deploy, or rebuild, pnpm will execute your script instead of the built-in command; use pnpm pm to access the built-in version [3]. - pnpm install -g (with no arguments) is no longer supported; use pnpm add -g instead [3][1]. Environment and Infrastructure - Node.js 18, 19, 20, and 21 are no longer supported; Node.js 22+ is required [1]. - pnpm is now distributed as pure ESM [1]. - Global installs are now isolated using a global-virtual-store, preventing interference between global packages [1]. Security and New Features - Minimum Release Age: By default, pnpm 11 blocks the installation of package versions published within the last 24 hours to mitigate supply chain attacks [4][5][6]. - Exotic Subdependencies: pnpm 11 blocks dependencies resolved from non-standard sources (e.g., Git repositories or direct tarball URLs) by default [4][6]. - Native Publish: The npm CLI fallback for publishing has been removed in favor of a native implementation [1]. - Store Index: The store index has been migrated from a JSON-per-package format to a single SQLite database for improved performance [1][5]. Migration Tooling The pnpm team provides a codemod to automate many of these changes [2]. You can run it in your project directory: pnpx codemod run pnpm-v10-to-v11 [2] For changes that cannot be automated, such as environment variable updates, manual review is required [3][2].
Citations:
- 1: https://pnpm.io/blog/releases/11.0
- 2: https://pnpm.io/11.x/migration
- 3: https://pnpm.io/migration
- 4: https://gbhackers.com/pnpm-11-enables-default-release-age-guard/
- 5: https://cyberpress.org/pnpm-blocks-supply-attacks/
- 6: https://undercodenews.com/pnpm-11-reinvents-javascript-security-a-new-era-for-dependency-protection/
🌐 Web query:
pnpm 11.1.2 release notes and security advisories
💡 Result:
As of May 17, 2026, pnpm version 11.1.2 is the latest release [1]. Release Notes for pnpm 11.1.2 Specific release notes for version 11.1.2 were not explicitly detailed in the provided search results, as it is a very recent patch release [1]. However, it follows the major 11.1.0 and 11.1.1 releases, which introduced several significant features and fixes [2][3][4]: - New Commands: Added pnpm audit signatures (to verify ECDSA registry signatures), pnpm bugs (to open package bug trackers), and pnpm owner (to manage package owners) [3][4]. - Named Registries: Added support for installing packages from arbitrary named registries, including a built-in gh: prefix for the GitHub Packages npm registry [3][4]. - CI Improvements: Introduced the --no-runtime flag (config: runtime=false) to skip installing runtime entries (e.g., Node.js) in CI environments [3][4]. - Fixes: Version 11.1.1 included fixes for installability validation in workspace projects, resolved issues with pnpm add for named registries, and updated @zkochan/cmd-shim to improve compatibility with Git Bash on Windows [2]. Security Advisories There are no specific security advisories listed for version 11.1.2. Users should monitor the official pnpm GitHub Security Advisories page for any future disclosures [5]. Recent security-related updates in the pnpm 11 series include: - Minimum Release Age: pnpm 11 introduced a default Minimum Release Age of 24 hours (1440 minutes), which prevents the installation of newly published package versions to mitigate supply chain attacks [6][7][8]. - Enhanced Auditing: pnpm audit now queries the registry's bulk security advisories endpoint and filters by GitHub Advisory ID (GHSA) rather than CVE identifiers [9]. - Security Hardening: pnpm 11 requires Node.js 22+ and is distributed as pure ESM [10][11]. It also includes improved control over lifecycle scripts via the allowBuilds model [7][8]. For the most up-to-date information, always check the official pnpm releases page on GitHub and the security advisories section [12][5].
Citations:
- 1: https://www.npmjs.com/package/pnpm?activeTab=versions
- 2: https://github.com/pnpm/pnpm/releases/tag/v11.1.1
- 3: https://pnpm.io/blog/releases/11.1
- 4: https://newreleases.io/project/npm/pnpm/release/11.1.0
- 5: https://github.com/pnpm/pnpm/security/advisories
- 6: https://gbhackers.com/pnpm-11-enables-default-release-age-guard/
- 7: https://undercodenews.com/pnpm-11-reinvents-javascript-security-a-new-era-for-dependency-protection/
- 8: https://pnpm.io/supply-chain-security
- 9: https://pnpm.io/cli/audit
- 10: https://github.com/pnpm/pnpm/releases/tag/v11.0.0
- 11: https://pnpm.io/blog/releases/11.0
- 12: https://github.com/pnpm/pnpm/releases
Review pnpm 11 migration requirements before merging.
This major version upgrade introduces breaking changes that require configuration updates and environment adjustments:
- Configuration files: Settings in
package.json'spnpmfield must move topnpm-workspace.yaml. Update.npmrcto contain only auth and registry settings. - Node.js requirement: pnpm 11 requires Node.js 22+. Verify your project's
.nvmrcand CI configuration specify a compatible version. - Environment variables: Any
npm_config_*variables must be renamed topnpm_config_*. - Script behavior: Scripts named
clean,setup,deploy, orrebuildnow shadow built-in commands; usepnpm pmto access built-in versions.
Run the migration codemod to automate configuration changes:
pnpx codemod run pnpm-v10-to-v11
Refer to https://pnpm.io/11.x/migration for the complete migration guide. Manual review is needed for environment variable updates that the codemod cannot automate.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@package.json` at line 6, The package.json currently sets "packageManager":
"pnpm@11.1.2" but pnpm v11 requires config and environment changes; run the
recommended codemod (pnpx codemod run pnpm-v10-to-v11) and then: move any
settings under the package.json "pnpm" field into pnpm-workspace.yaml, strip
.npmrc to only auth/registry entries, update .nvmrc and CI to Node.js 22+ to
match pnpm v11, rename any environment variables from npm_config_* to
pnpm_config_ and manually review remaining envs, and rename or invoke scripts
named clean/setup/deploy/rebuild using pnpm pm to avoid shadowing built-ins.
|
Надо смержить сюда main ветку и исправить все ошибки в CI/CD что бы код был с актуальными библиотеками |
|
🤖 AI Work Session Started Starting automated work session at 2026-06-19T19:17:51.406Z The PR has been converted to draft mode while work is in progress. This comment marks the beginning of an AI work session. Please wait for the session to finish, and provide your feedback. |
|
Update: the CI/CD fix is implemented and verified, but I cannot push it directly to this PR head branch. Blocker:
Prepared fix:
What the fix covers:
Verification:
Needed human action: either grant/push access to |
🤖 Solution Draft LogThis log file contains the complete execution trace of the AI solution draft process. 💰 Cost estimation:
📊 Context and tokens usage:
Total: (508.9K + 13.1M cached) input tokens, 68.4K output tokens, $21.304392 cost 🤖 Models used:
📎 Log file uploaded as Repository (75696KB)Now working session is ended, feel free to review and add any feedback on the solution draft. |
🔄 Auto-restart triggered (iteration 1)Reason: CI failures detected Starting new session to address the issues. Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations. |
|
Rechecked the failing CI/CD status in this restart session. Findings:
Verification repeated locally with Node
Fork CI also has successful runs for Remaining blocker is repository permissions, not code: |
🔄 Auto-restart-until-mergeable Log (iteration 1)This log file contains the complete execution trace of the AI solution draft process. 💰 Cost estimation:
🤖 Models used:
📎 Log file uploaded as Repository (96784KB)Now working session is ended, feel free to review and add any feedback on the solution draft. |
🔄 Auto-restart triggered (iteration 2)Reason: CI failures detected Starting new session to address the issues. Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations. |
|
Rechecked and updated the prepared fix in this restart session. Current prepared commit:
Root causes confirmed from upstream CI logs for old SHA
Verification on current SHA
Remaining blocker is repository permission, not code. Needed maintainer action: push/cherry-pick |
🔄 Auto-restart-until-mergeable Log (iteration 2)This log file contains the complete execution trace of the AI solution draft process. 💰 Cost estimation:
🤖 Models used:
📎 Log file uploaded as Repository (2 chunks) (116514KB)Now working session is ended, feel free to review and add any feedback on the solution draft. |
🔄 Auto-restart triggered (iteration 3)Reason: CI failures detected Starting new session to address the issues. Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations. |
|
Restart iteration 3 rechecked the prepared CI fix. Current verified head:
Fresh upstream CI logs downloaded in this session confirm old-head root causes:
Verification repeated on
Push blocker remains external: Needed maintainer action: push or cherry-pick |
🔄 Auto-restart-until-mergeable Log (iteration 3)This log file contains the complete execution trace of the AI solution draft process. 💰 Cost estimation:
🤖 Models used:
📎 Log file uploaded as Repository (2 chunks) (139990KB)Now working session is ended, feel free to review and add any feedback on the solution draft. |
🔄 Auto-restart triggered (iteration 4)Reason: CI failures detected Starting new session to address the issues. Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations. |
|
Restart iteration 4 rechecked the CI/CD fix. Current verified head:
Fresh upstream logs downloaded in this session confirm the old-head failures:
Verification repeated locally on
Push status:
Needed maintainer action: push or cherry-pick |
🔄 Auto-restart-until-mergeable Log (iteration 4)This log file contains the complete execution trace of the AI solution draft process. 💰 Cost estimation:
🤖 Models used:
📎 Log file uploaded as Repository (2 chunks) (154923KB)Now working session is ended, feel free to review and add any feedback on the solution draft. |
🔄 Auto-restart triggered (iteration 5)Reason: CI failures detected Starting new session to address the issues. Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations. |
|
Restart iteration 5 rechecked the CI/CD failures and the prepared fix. Current verified fix:
Fresh upstream CI status:
Root causes confirmed from downloaded upstream logs:
Verification repeated locally on
Fork CI on
Push status:
Needed maintainer action: push or cherry-pick |
🔄 Auto-restart-until-mergeable Log (iteration 5)This log file contains the complete execution trace of the AI solution draft process. 💰 Cost estimation:
🤖 Models used:
📎 Log file uploaded as Repository (2 chunks) (177139KB)Now working session is ended, feel free to review and add any feedback on the solution draft. |
|
|
🤖 AI Work Session Completed Work session ended at 2026-06-19T20:58:19.771Z The PR will be converted back to ready for review. This comment marks the end of an AI work session. New comments after this time will be considered as feedback. |
This PR contains the following updates:
^2.4.4→^2.5.10^0.5.2→^1.0.0^2.29.8→^3.0.1^4.6.0→^4.7.22.0.2→2.1.03.3.3→3.3.6^24.10.13→^24.13.3^8.56.0→^8.67.0^8.56.0→^8.67.0^4.0.18→^4.1.11^1.6.9→^1.6.27v6→v7v6→v7v6→v7^3.19.18→^3.22.1^10.0.1→^10.9.0^4.4.4→^4.4.5^12.1.1→^14.0.0^4.0.0→^4.2.0^63.0.0→^73.0.0^17.3.0→^17.11.0^4.0.8→^5.0.1624.13.1→24.19.010.30.1→11.22.0v4→v6v3→v6^5.9.3→^7.0.2^8.56.0→^8.67.0^7.3.1→^8.2.2^4.0.18→^4.1.11cc @skulidropek
Release Notes
biomejs/biome (@biomejs/biome)
v2.5.10Compare Source
Patch Changes
#11403
8f7786fThanks @Princesseuh! - Fixed Astro rejecting JavaScript comments between attributes.#11403
8f7786fThanks @Princesseuh! - Fixed a bare<in Astro text being treated as the start of a tag, such as<p>5 < 6 and 7 > 6</p>. As in HTML, a<that cannot open a tag is text and needs no escaping.#11438
3133ffaThanks @Princesseuh! - Fixed #8294: an Astro expression holding only a comment is no longer reported as a parse error, which also stopped the whole file from being formatted.#11403
8f7786fThanks @Princesseuh! - Fixed #9165: an empty Astro expression such as<div>{}</div>no longer fails to parse. Astro renders{}as nothing.#11403
8f7786fThanks @Princesseuh! - Fixed Astro expressions containing a comment failing to parse.#11403
8f7786fThanks @Princesseuh! - Added support for Astro's fragment shorthand.#11403
8f7786fThanks @Princesseuh! - Fixed an Astro frontmatter block being cut short by a closing tag inside a string or comment.#11403
8f7786fThanks @Princesseuh! - Fixed---being read as an Astro frontmatter fence when markup precedes it. Astro only recognizes frontmatter at the very start of a file, so a file opening with a comment now has no frontmatter, and its---lines are content.<!-- c --> --- this is text, not frontmatter ---#11403
8f7786fThanks @Princesseuh! - Fixed an Astro frontmatter block ending early on a line that merely starts with a dash.#11403
8f7786fThanks @Princesseuh! - Fixed the children of an Astro element carryingis:rawbeing parsed as markup instead of raw text. This now also covers<script>and<style>, whose contents Astro emits verbatim rather than processing, so they are no longer linted as JavaScript or CSS.#11403
8f7786fThanks @Princesseuh! - Fixed Astro rejecting attribute names that start with a colon, such as:href.#11403
8f7786fThanks @Princesseuh! - Fixed the Astro parser failing to recover from a malformed closing tag such as<div></{<//, so that a later mistake is reported where it happens rather than cascading.#11403
8f7786fThanks @Princesseuh! - Fixed{inside an Astro<math>element opening an expression. MathML is foreign content where Astro parses no expressions, so LaTeX such asR^{2x}now survives as text.<svg>is unaffected.#11403
8f7786fThanks @Princesseuh! - Fixed{{at the start of an Astro expression being read as an interpolation. Astro has no{{ }}syntax, so{{ a: 1 }}and<Comp a={{ b: 1 }} />are object literals.#11403
8f7786fThanks @Princesseuh! - Fixed expressions inside an Astro<pre>or<textarea>being read as raw text. Astro parses both as ordinary elements, so their markup and interpolations are now parsed, and a variable used only inside one is no longer reported as unused.#11403
8f7786fThanks @Princesseuh! - Added support for template literal attribute values in Astro, such as<div class=`a ${b} c`>.#11403
8f7786fThanks @Princesseuh! - Fixed Astro rejecting HTML5 unquoted attribute values that contain`,=,'or", such as<a href=a=b>and<a href=a'b>.#11393
dec5a8fThanks @1678092075! - Fixed #11207:useStrictModeno longer reports Vue event handlers such as@click="count++".#11431
c065f99Thanks @levrik! - Fixed #11429: Variables and imports used by Vue same-name bindings such as:disabledorv-bind:disabledare no longer reported as unused.#11409
405dedbThanks @ematipico! - Fixed a memory leak in the LSP server where memory usage kept growing over long editor sessions.#11422
a51eff7Thanks @dyc3! - Fixed #11416: Biome no longer crashes when parsing incomplete{let}or{const}declarations in Svelte files.#11378
34b715cThanks @Netail! - Added extra rule sources from@eslint/css.biome migrate eslintdetects rules in your eslint configurations more reliably.#11403
8f7786fThanks @Princesseuh! - Fixed{#,{/,{:and{@being read as Svelte block openings in every HTML-like file. They are now Svelte-only, so in HTML, Vue and Angular files a sequence such as{#if x}is ordinary text instead of a parse error.#11443
8d45229Thanks @ematipico! - Fixed #11390:noFloatingPromisesno longer performs unnecessary type inference on call arguments when checking methods of non-generic class instances created withnew.#11425
9c2667bThanks @dyc3! - Fixed #6426: GritQL plugins now match and rewrite metavariables embedded in quoted strings.#11441
00317c3Thanks @dyc3! - Improved performance ofuseNamedCaptureGroup,noMisplacedAssertion,noSkippedTests,noExportsInTest,noDuplicateTestHooks,noIdenticalTestTitle,useTestHooksInOrder, anduseTestHooksOnTop.v2.5.9Compare Source
Patch Changes
#11321
41386f3Thanks @dyc3! - Fixed #11315: The CSS parser now recovers at declaration boundaries after bogus declarations, allowing subsequent valid declarations to be parsed.#11248
57b197eThanks @yanthomasdev! - Expanded the environment variable metadata used bybiome rageto includeBIOME_BINARY,BIOME_LOG_FILE, andRUST_BACKTRACEas well as reworded explanations for better readability.#11377
a8798eaThanks @Netail! - Added a new nursery ruleuseNamedLayerwhich disallows anonymous cascade layers.#11327
6771cf5Thanks @dyc3! - The HTML formatter now preserves meaningful blank lines in HTML, including spacing after elements with trailing spaces and blank lines between comment groups.<div> <!-- first group --> + <!-- second group --> </div>#10312
ba8aa18Thanks @dyc3! - Added the nursery ruleuseTailwindShorthandClasses, which suggests shorter Tailwind utility classes. For example, the rule suggests replacingw-4 h-4withsize-4.#11333
715e0cdThanks @kkkhs! - Fixed #11328:lint/nursery/useExpectnow recognizes Vitest Browser Modeexpect.element()calls as assertions.#11343
9b98211Thanks @johncarmack1984! - Fixed #11311: the CSS parser now accepts Tailwind container-query variant names in@variant, such as@xland@max-xl. These previously produced a parse error and anoUnknownAtRulesdiagnostic.#11220
3e8c488Thanks @santichausis! - Fixed #9541:noUndeclaredVariables,noUnusedImports, andnoUnusedVariablesnow correctly recognise exported variables and functions declared in one embedded<script>block as usable from a sibling<script>block, in Svelte's<script module>/<script>pair and Vue's non-setup<script>blocks.For example, Biome no longer reports
greetas undeclared in the following Svelte component:#11300
36430ebThanks @dyc3! - Fixed the HTML formatter's whitespace handling formarquee,noscript,video,audio, andobjectelements.#11299
6559e6cThanks @jp-knj! - Added the nursery ruleuseAstroClientOnlyDirectiveValue, which reports Astroclient:onlydirectives without an initializer.For example,
<Component client:only />triggers the rule.#11365
7529811Thanks @MHJahanbakhsh! - Fixed #11229: TheuseGenericFontNamesrule now treatsmathas a valid generic font family.#11346
674f5f4Thanks @Jayllyz! - Fixed #11335:noComponentHookFactoriesnow reports ause-prefixed variable only when a function is assigned to it directly.#11334
c87c46aThanks @zkasuran! - Fixed #11317:noSvgWithoutTitleno longer reports ansvgthat uses the boolean shorthandaria-hidden(equivalent toaria-hidden={true}in React).#11364
13853b1Thanks @ematipico! - Fixed a bug whereuseJsxKeyInIterableincorrectly flagged Astro files.#11321
41386f3Thanks @dyc3! - Fixed #11315: Invalid CSS declarations in HTMLstyleattributes now produce parser diagnostics instead of causing a panic.#11325
67c3bf0Thanks @dyc3! - Fixed HTML text wrapping to account for the width of an adjacent closing tag, avoiding lines that exceed the configured width when the final word and tag must move together.#11367
fe5b5d4Thanks @ematipico! - Fixed TypeScriptcompilerOptions.pathsresolution when mapping targets omit./. Biome now resolves these targets relative to their configured path base.#11316
17e48d6Thanks @wanxiankai! - Fixed #11289: the safe fix fornoExtraBooleanCastnow preserves parentheses around nested conditional expressions.#11254
d25d113Thanks @dyc3! - Fixed #11242: Biome no longer crashes with an access violation when analysing files on Windows ARM64.#11221
85aac73Thanks @freeatnet! - Added the nursery rulenoUnsafeTypeAssertion, which disallows TypeScript type assertions while allowing const assertions.#11314
7ffb677Thanks @ematipico! - Fixed #11310: Restored the performance ofnoMisusedPromisesandnoFloatingPromiseswhen analyzed expressions share deep imported type paths.#11356
6cd3263Thanks @johncarmack1984! - The Tailwind parser now understands modifiers on bare utilities (@container/sidebar,shadow/50).#11318
76059e9Thanks @johncarmack1984! - The Tailwind parser now understands container-query variants (@sm:,@max-lg:,@min-[400px]:) and child and descendant variants (*:,**:).#11357
faa2074Thanks @johncarmack1984! - The Tailwind parser now accepts the legacy leading!important marker (!flex,hover:!p-4).#11344
f34e15cThanks @johncarmack1984! - The Tailwind parser now understands combinator selectors in arbitrary variants (has-[>svg]:,has-[+p]:), modifiers on variants (group-hover/menu:,@sm/main:), and arbitrary container-query sizes (@[400px]:).#11324
2f5d452Thanks @dyc3! - Fixed HTML formatting that inserted rendered whitespace between an element and touching text when the line wrapped.#11312
e65f07eThanks @xosnos! - Added a new nursery ruleuseControlLabelfor both HTML and JSX, which reports interactive control elements (button,menuitem) without an accessible label.#11364
13853b1Thanks @ematipico! - Fixed SVG parsing for files with an XML declaration followed by aPUBLICdoctype, such as<?xml version="1.0"?><!DOCTYPE svg PUBLIC "a" "b">.#11301
610ee28Thanks @dyc3! - Fixed parent tag wrapping when an HTML element starts or ends with a block-like or hidden child such assource,track, orparam.v2.5.8Compare Source
Patch Changes
#10710
0a0fbc1Thanks @dyc3! - Added a new nursery ruleuseReactCompiler, which reports diagnostics from React Compiler lint mode.#11251
ea9dd8aThanks @dyc3! - Improved performance ofnoImportCycles.#11247
52b44d6Thanks @dyc3! - Added the nursery rulenoSvelteLegacyConst, which disallows legacy Svelte{@const}tags and recommends declaration tags with$derived().Invalid:
{#each boxes as box} {@const area = box.width * box.height} <p>{area}</p> {/each}Valid:
{#each boxes as box} {const area = $derived(box.width * box.height)} <p>{area}</p> {/each}#11252
d5f5704Thanks @Turtle-Hwan! - Fixed #11250:useAwaitno longer reports async functions that contain anawait usingdeclaration.#11143
6be7be1Thanks @vznh! - Fixed #11017:noUselessUndefinedno longer reportsreturn undefinedwhen the enclosing function has a return type annotation other thanundefinedorvoid.#11234
caefe39Thanks @subotac! - Fixed #11228: CSS block comments between a declaration colon and value now preserve their source indentation.:root { --font-stack: -/* comment */ + /* comment */ system-ui; }#11285
bca1f73Thanks @denbezrukov! - Fixed #11280: CSS formatting keeps comments inside functional pseudo-classes and pseudo-elements instead of moving them before the function name.#11080
af16a0bThanks @dyc3! - HTMLstyleattribute values are now parsed as CSS. All Biome CSS lint rules are applied to thestyleattributes.#11195
6a85588Thanks @dyc3! - Fixed Svelte files failing to parse when an expression begins with an object literal.Now the following snippet is correctly parsed:
#11173
481d008Thanks @Austin1serb! - Fixed #10242: JavaScript GritQL patterns with multiple metavariables now match snippets consistently in WebAssembly.#11187
23c0369Thanks @ematipico! - Added the nursery rulenoInvalidPropertyInitValue, which reports an@propertywhoseinitial-valuedoes not match itssyntaxdescriptor. For example, the following declaration triggers the rule becauseredis not a<length>:#11272
73896e6Thanks @ematipico! - Improved the diagnostic emitted bynoRootType.#11240
bd0b68dThanks @ematipico! - Fixed #11223: Improved theperformance of
noMisusedPromiseswhen analyzing async class methods that call other methods through
this.#11172
4a0bc5cThanks @saberoueslati! - Fixed #10806:noUselessFragmentsno longer causes Biome to panic when its unsafe fix removes a fragment used as a JSX attribute value.#11227
4d603b0Thanks @saberoueslati! - Fixed #11178:noUndeclaredVariablesno longer reports Vue's built-in instance properties, such as$slotsand$attrs, in template expressions or$eventin inline event-handler expressions. The instance properties are still reported inside<script setup>, where they are not defined.#11187
23c0369Thanks @ematipico! - Fixed CSS parsing of registered custom properties: Biome now correctly validates thesyntaxdescriptor of@propertyrules.v2.5.7Compare Source
Patch Changes
#10822
c171b3bThanks @pkallos! - Added the optionignoreIfStatementsto useNullishCoalescing. Biome now flagsifstatements that only assign to a nullish variable (such asif (!a) { a = b }) and can rewrite them to??=. When enabled, Biome ignores thoseifstatements.#11136
e63354cThanks @AkashNaickar! - Added a new nursery rulenoExtendNative, which reports extending the prototype of a built-in object.#10094
e007143Thanks @THEjacob1000! - Added the nursery rulenoTailwindArbitraryValue. Biome now reports Tailwind CSS arbitrary values such asw-[400px], including in HTML/JSX class attributes, configured utility functions, and tagged templates.#11184
135f476Thanks @subotac! - Fixed #11176:noUnknownPseudoClassnow recognizes Vue's:deep()pseudo-class inside.vuestyle blocks.#8239
a519f9dThanks @cormacrelf! - Fixed #8233, where Biome CLI instdin mode didn't work correctly when handling files in projects with nested
configurations. For example, with the following structure,
--stdin-file-path=subdirectory/...would not use the nested configuration insubdirectory/biome.json:biome format --write --stdin-file-path=subdirectory/lib.js < subdirectory/lib.jsNow, the nested configuration is correctly picked up and applied.
In addition, Biome now shows a warning if
--stdin-file-pathis provided butthat path is ignored and therefore not formatted or fixed.
#11138
8c2c6bdThanks @ematipico! - FixednoUnnecessaryConditions: Biome now chooses the same function overload as TypeScript when an argument is a callback, so conditions that were previously missed are reported.The following code is now invalid, because a parameter typed
() => voidaccepts anasynccallback andscheduletherefore returnsstring:The following code is also now invalid, because
map(() => 42)returns42:#11138
8c2c6bdThanks @ematipico! - Fixed #11087:noUnnecessaryConditionsno longer reports optional chains and nullish coalescing whose receiver can be nullish.For example, the optional chain and fallback in the following code are no longer reported:
#11118
9c16840Thanks @subotac! - Fixed #11098: The HTML formatter now preserves the configured trailing newline when a file ends with a comment.#11201
0e80610Thanks @Bishwas-py! - Fixed #11182: suppression comments fornoPositiveTabindexnow suppress the rule in HTML files when the attributes of the element span multiple lines.#11079
607afd2Thanks @dyc3! - The HTML formatter now lays out thesrcsetattribute of<img>and<source>as the list of candidates it is. Runs of whitespace between candidates collapse, and once the list no longer fits on one line each candidate goes on its own line with the descriptors aligned:#11156
fed72c7Thanks @saberoueslati! - Fixed #11129:noUnusedVariablesno longer reports Vue bindings as unused when they are assigned through automatically unwrapped template refs.#11124
d890b39Thanks @denbezrukov! - Fixed CSS formatting of line comments between a declaration colon and value to preserve their source indentation..test { background: - /////// foo - // bar + /////// foo + // bar radial-gradient(circle, #​000, transparent); }#11113
3d8ab73Thanks @denbezrukov! - Fixed CSS formatting of long block comments between comma-separated property values:.foo { box-shadow: - 1000px /* long long long long long long long long long long long long comment */ 1000px /* long long long long long long long long long comment */ 2px color(srgb 0.555555555 0.555555555 0.555555555), + 1000px + /* long long long long long long long long long long long long comment */ + 1000px /* long long long long long long long long long comment */ 2px + color(srgb 0.555555555 0.555555555 0.555555555), 1px 1px black; }#11127
da5c1a5Thanks @dyc3! - The HTML formatter now picks the quote character for an attribute byConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.