fix(deps): update all dependencies - #31
Conversation
6cba843 to
0f055c2
Compare
92bada8 to
71cb2e1
Compare
54d829d to
590142f
Compare
5daa077 to
79555ae
Compare
055e1ef to
d1673ca
Compare
c20c888 to
c23139a
Compare
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughBumps pnpm to 11.1.3 at root and app, upgrades Changesets and many app deps/devDeps, and updates GitHub Actions versions: ChangesDependency and Action Upgrades
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related issues
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/actions/setup/action.yml:
- Line 13: The action uses pnpm/action-setup@v6 but the custom action default
still sets node-version: 20.16.0 which is incompatible; update the default
node-version in action.yml to Node 24 (>=24.0.0, e.g., 24.15.0 to match
checking-dependencies.yml) so the action runs on the required runtime, and after
changing the default verify pnpm selection behavior (packageManager in
package.json / pnpm@11.1.2) because v6 has a bug that may ignore
packageManager—if necessary pin the pnpm version explicitly or add configuration
to enforce packageManager to ensure the expected pnpm version is used.
In @.github/workflows/checking-dependencies.yml:
- Line 15: The workflow uses pnpm/action-setup@v6 but package.json declares
packageManager: pnpm@11.1.2, causing a mismatch; either align the workflow or
package.json: update package.json's packageManager to "pnpm@11.1.1" to match the
action's default, or explicitly configure the action in
.github/workflows/checking-dependencies.yml (pnpm/action-setup) with a
compatible with.version value (e.g., 11.1.1) until 11.1.2 is released, or remove
the explicit version so the action auto-detects from package.json and surfaces
the proper error if the version is unavailable.
In `@package.json`:
- Line 6: Update package.json to remove deprecated pnpm v10 fields and adopt
pnpm v11 format: replace any ignoredBuiltDependencies and onlyBuiltDependencies
entries with the new allowBuilds configuration (mapping allowed package patterns
or booleans accordingly) and set the engines.node field to ">=22" (or "22.x" per
project policy) so Node.js requirement is explicit for pnpm 11; also keep
packageManager set to "pnpm@11.1.2" and run the pnpm v10→v11 codemod (pnpx
codemod run pnpm-v10-to-v11) to ensure any other migration changes are applied.
In `@packages/app/package.json`:
- Line 71: Add an "engines" entry to packages/app/package.json to require
Node.js >=20.19.0 so ESLint 10.3.0 runs correctly; locate the existing "eslint":
"^10.3.0" dependency in package.json and add an "engines" object with "node":
">=20.19.0" to enforce the minimum Node version for contributors and CI.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 99f915a6-56ca-42ec-8fc8-02ccf3d20151
⛔ Files ignored due to path filters (1)
pnpm-lock.yamlis excluded by!**/pnpm-lock.yaml
📒 Files selected for processing (5)
.github/actions/setup/action.yml.github/workflows/checking-dependencies.yml.github/workflows/snapshot.ymlpackage.jsonpackages/app/package.json
| steps: | ||
| - uses: actions/checkout@v6 | ||
| - uses: pnpm/action-setup@v4 | ||
| - uses: pnpm/action-setup@v6 |
There was a problem hiding this comment.
🧩 Analysis chain
🌐 Web query:
pnpm/action-setup v6 release notes
💡 Result:
pnpm/action-setup v6 release notes (from the repo’s official GitHub Releases pages) are available as a series of versioned release entries under the v6 tags. The most recent v6 entry visible in the official releases feed is v6.0.8 (published 2026-05-12), with the following changes: 1) v6.0.8 (2026-05-12) - docs(README): fix cache_dependency_path type (PR #257) [1] - fix: drop patchPnpmEnv so standalone+self-update works on Windows (PR #258) [1] - fix: update pnpm to 11.1.1 (PR #248) [1] 2) v6.0.4 (2026-04-30) - fix: use npm co-located with the action node binary (PR #239) [2] Additional v6 changes are also reflected in the v4...v6 comparison page (including updates to README/examples and caching-related input typing/behavior), which indicates that v6 introduces/updates inputs like cache_dependency_path handling. In that compare view, cache_dependency_path is described as accepting multiple paths delimited by newlines, and the example workflows are updated to use pnpm/action-setup@v6 instead of v4. [3] Notes / where to read the full set of v6 release notes: - Start at the official Releases index for pnpm/action-setup and select the v6.x.y tags. The Releases index is the source of truth for the complete v6 changelog history. [4] If you want, tell me the exact v6 range you care about (e.g., “v6.0.0 through v6.0.8” or “just v6.0.8”), and I’ll summarize only those entries.
Citations:
- 1: https://github.com/pnpm/action-setup/releases/tag/v6.0.8
- 2: https://github.com/pnpm/action-setup/releases/tag/v6.0.4
- 3: pnpm/action-setup@v4...v6
- 4: https://github.com/pnpm/action-setup/releases
🌐 Web query:
Node.js 24.15.0 release notes
💡 Result:
Node.js 24.15.0 (Krypton, LTS) release notes (published 2026-04-15) list these notable changes: - cli: add --max-heap-size option [1] - cli: add --require-module / --no-require-module [2] - crypto: add raw key formats support to the KeyObject APIs [1] - fs: add throwIfNoEntry option for fs.stat and fs.promises.stat [2] - http2: add http1Options for HTTP/1 fallback configuration [2] - module: mark require(esm) as stable [2] - module: mark module compile cache as stable [2] - net: add setTOS and getTOS to Socket [2] - sqlite: add limits property to DatabaseSync [2] - sqlite: mark as release candidate [2] - src: add C++ support for diagnostics channels [2] - stream: rename Duplex.toWeb type option to readableType [2] - test_runner: add exports option for module mocks [2] - test_runner: expose worker ID for concurrent test execution [2] - test_runner: show interrupted test on SIGINT [2] Primary sources for the above are the official Node.js blog release page and the Node.js v24 changelog section for 24.15.0 [1][2].
Citations:
- 1: https://nodejs.org/blog/release/v24.15.0
- 2: https://github.com/nodejs/node/blob/main/doc/changelogs/CHANGELOG_V24.md
🏁 Script executed:
#!/bin/bash
# Check all workflow files for consistency in action versions
rg -n "pnpm/action-setup@" --type yaml
rg -n "node-version:" --type yamlRepository: ProverCoderAI/effect-template
Length of output: 55
🏁 Script executed:
#!/bin/bash
# Check if the workflow file exists
ls -la .github/workflows/ 2>/dev/null || echo "Directory not found"
# If it exists, read the file
if [ -f ".github/workflows/checking-dependencies.yml" ]; then
echo "=== File found, reading contents ==="
cat -n ".github/workflows/checking-dependencies.yml"
else
echo "File not found"
fi
# Also check with fd for any workflow files
echo "=== Searching for workflow files ==="
fd -e yml -e yaml ".github/workflows/" 2>/dev/null || fd -e yml -e yamlRepository: ProverCoderAI/effect-template
Length of output: 1412
🏁 Script executed:
#!/bin/bash
# Check pnpm version in lock file
head -20 pnpm-lock.yaml | grep -i "version\|lockfileVersion"
# Also check package.json for pnpm version requirement if any
if [ -f "package.json" ]; then
grep -i "pnpm" package.json
fi
# Check if there's a .npmrc or similar config
if [ -f ".npmrc" ]; then
cat .npmrc
fiRepository: ProverCoderAI/effect-template
Length of output: 745
🌐 Web query:
pnpm 11.1.2 release date and availability
💡 Result:
No evidence found of a pnpm 11.1.2 release as of 2026-05-14. The latest releases are v11.1.1 (published around 2026-05-12 [1]) and v11.1.0 (published 2026-05-11 [2][3][4]). Official GitHub releases page lists recent tags up to May 12 but no 11.1.2 [3]. npm registry tracks these releases [4], and no sources mention 11.1.2. It is not yet released or available.[2][3][1]
Citations:
- 1: https://newreleases.io/project/github/pnpm/pnpm/release/v11.1.1
- 2: https://github.com/pnpm/pnpm/releases/tag/v11.1.0
- 3: https://github.com/pnpm/pnpm/releases
- 4: https://newreleases.io/project/npm/pnpm/release/11.1.0
🌐 Web query:
pnpm/action-setup configure pnpm version 11.1.2
💡 Result:
To configure pnpm/action-setup to install pnpm 11.1.2, use the action’s with.version input: steps: - uses: pnpm/action-setup@v6 with: version: 11.1.2 The version input is “Version of pnpm to install” and supports exact versions like 11.1.2 (or version ranges/tags). If you omit version, the action can use the packageManager field from your package.json instead.[1] You may optionally specify run_install if you also want the action to run pnpm install for you; otherwise run pnpm install in a later step.[1]
Citations:
Configure pnpm version in pnpm/action-setup to match project requirement.
The workflow uses pnpm/action-setup@v6 which installs pnpm 11.1.1 by default, but the project specifies packageManager: pnpm@11.1.2 in package.json. Since pnpm 11.1.2 does not yet exist, the pnpm install --frozen-lockfile step (line 21) will fail due to version mismatch. Either update package.json to use pnpm 11.1.1, or configure the action with with.version: 11.1.2 once that version is released. Alternatively, the action can auto-detect the version from package.json if no version input is specified (allowing proper error messaging when unavailable).
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/checking-dependencies.yml at line 15, The workflow uses
pnpm/action-setup@v6 but package.json declares packageManager: pnpm@11.1.2,
causing a mismatch; either align the workflow or package.json: update
package.json's packageManager to "pnpm@11.1.1" to match the action's default, or
explicitly configure the action in .github/workflows/checking-dependencies.yml
(pnpm/action-setup) with a compatible with.version value (e.g., 11.1.1) until
11.1.2 is released, or remove the explicit version so the action auto-detects
from package.json and surfaces the proper error if the version is unavailable.
| "private": true, | ||
| "description": "Monorepo workspace for effect-template", | ||
| "packageManager": "pnpm@10.29.3", | ||
| "packageManager": "pnpm@11.1.2", |
There was a problem hiding this comment.
🧩 Analysis chain
🌐 Web query:
pnpm 11 release notes breaking changes from pnpm 10
💡 Result:
pnpm 11 introduces several breaking changes from v10, primarily documented in the official migration guide [1] and v11.0.0 release notes [2][3]. Key breaking changes include: Node.js requirement: Now requires Node.js 22 or newer; support for v18-21 dropped. pnpm is pure ESM, and standalone exe needs glibc 2.27+ [3][2][4]. Configuration changes [1]: - No longer reads config from package.json#pnpm; move to pnpm-workspace.yaml. -.npmrc limited to auth/registry; other settings (hoist-pattern, node-linker, etc.) to pnpm-workspace.yaml (camelCase keys). - npm_config_* env vars ignored; use pnpm_config_*. - Deprecated build settings (onlyBuiltDependencies, etc.) removed; use allowBuilds [3][2]. - Package manager settings consolidated to pmOnFail: 'download'|'ignore'|'warn'|'error'. - Renames: allowNonAppliedPatches -> allowUnusedPatches; auditConfig.ignoreCves -> auditConfig.ignoreGhsas. Store upgraded to v11: SQLite index.db replaces JSON files; incompatible with v10 stores (clear or migrate) [3][2][5]. Global installs: Isolated in {pnpmHomeDir}/global/v11/{hash}/ with own package.json/node_modules/pnpm-lock.yaml. pnpm install -g (no args) removed; use pnpm add -g [3][2]. pnpm link changes: No global store resolution; only relative/absolute paths. --global removed (use pnpm add -g.); no-arg pnpm link removed [1][6]. Removed commands: pnpm server; npm passthrough (publish, login, etc.) now native, some like access, edit removed [3][2]. Lockfile: patchedDependencies simplified to selector -> hash; auto-migrated [5]. Script shadowing: Scripts named clean/setup/deploy/rebuild run script, not built-in; use pnpm pm [1]. Security defaults: minimumReleaseAge=1440 (1 day), blockExoticSubdeps=true, strictDepBuilds=true [3][2]. A codemod assists migration: pnpx codemod run pnpm-v10-to-v11 [1]. Full details: https://pnpm.io/migration [1], https://github.com/pnpm/pnpm/releases/tag/v11.0.0 [2], https://pnpm.io/blog/releases/11.0 [3].
Citations:
- 1: https://pnpm.io/migration
- 2: https://github.com/pnpm/pnpm/releases/tag/v11.0.0
- 3: https://pnpm.io/blog/releases/11.0
- 4: https://github.com/pnpm/pnpm/releases/tag/v11.0.0-rc.0
- 5: https://github.com/pnpm/pnpm/releases/tag/v11.0.0-alpha.14
- 6: https://github.com/pnpm/pnpm/releases/tag/v11.0.0-beta.3
🏁 Script executed:
#!/bin/bash
# Check if pnpm-lock.yaml has been updated alongside this change
git diff HEAD -- pnpm-lock.yaml | head -50Repository: ProverCoderAI/effect-template
Length of output: 55
🏁 Script executed:
#!/bin/bash
# Check if pnpm-lock.yaml exists and what version it specifies
if [ -f "pnpm-lock.yaml" ]; then
echo "=== pnpm-lock.yaml lockfileVersion ==="
head -20 pnpm-lock.yaml | rg "lockfileVersion|name|version"
else
echo "pnpm-lock.yaml not found"
fi
# Check if package.json has pnpm config that needs migration
echo -e "\n=== package.json pnpm config ==="
jq '.pnpm' package.json 2>/dev/null || echo "No pnpm config in package.json"
# Check Node.js version requirement
echo -e "\n=== Node.js engines requirement ==="
jq '.engines' package.json 2>/dev/null || echo "No engines field"Repository: ProverCoderAI/effect-template
Length of output: 586
🏁 Script executed:
#!/bin/bash
# Check git log to see if pnpm-lock.yaml was modified in this change
echo "=== Recent git changes to pnpm-lock.yaml ==="
git log --oneline -n 10 -- pnpm-lock.yaml 2>/dev/null || echo "No pnpm-lock.yaml history"
# Check if .npmrc or pnpm-workspace.yaml exists
echo -e "\n=== pnpm configuration files ==="
ls -la .npmrc pnpm-workspace.yaml .pnpmfile.cjs 2>/dev/null || echo "Checking config files..."
fd -e "npmrc|pnpmfile|workspace.yaml" .Repository: ProverCoderAI/effect-template
Length of output: 287
🏁 Script executed:
#!/bin/bash
# Check CI workflows for Node.js version
echo "=== CI/CD Node.js version requirement ==="
find .github -name "*.yml" -o -name "*.yaml" 2>/dev/null | head -5 | xargs grep -l "node-version\|node_version\|setup-node" 2>/dev/null | head -1 | xargs cat 2>/dev/null | grep -A 2 "node-version\|setup-node" || echo "Checking workflows..."Repository: ProverCoderAI/effect-template
Length of output: 370
Migrate deprecated pnpm configuration to pnpm 11 format.
The pnpm-lock.yaml has been regenerated to v9.0 (pnpm 11 format), but package.json still contains deprecated configuration that is no longer supported in pnpm 11:
ignoredBuiltDependenciesandonlyBuiltDependenciesmust be migrated to the newallowBuildsconfiguration- Node.js requirement must be explicitly set to 22+ in the
enginesfield (pnpm 11 no longer supports Node.js v18-21)
These deprecated options will cause failures when running pnpm commands. Use the pnpm v10→v11 migration codemod (pnpx codemod run pnpm-v10-to-v11) to complete the migration.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@package.json` at line 6, Update package.json to remove deprecated pnpm v10
fields and adopt pnpm v11 format: replace any ignoredBuiltDependencies and
onlyBuiltDependencies entries with the new allowBuilds configuration (mapping
allowed package patterns or booleans accordingly) and set the engines.node field
to ">=22" (or "22.x" per project policy) so Node.js requirement is explicit for
pnpm 11; also keep packageManager set to "pnpm@11.1.2" and run the pnpm v10→v11
codemod (pnpx codemod run pnpm-v10-to-v11) to ensure any other migration changes
are applied.
| "@typescript-eslint/parser": "^8.59.3", | ||
| "typescript-eslint": "^8.59.3", | ||
| "@vitest/coverage-v8": "^4.1.6", | ||
| "eslint": "^10.3.0", |
There was a problem hiding this comment.
🧩 Analysis chain
🌐 Web query:
ESLint 10.0 release notes breaking changes migration guide
💡 Result:
ESLint 10.0 release notes / breaking changes and the official migration guide are here: 1) Official migration guide (v9.x → v10.x) https://eslint.org/docs/latest/use/migrate-to-10.0.0 [1] 2) Official release notes for v10.0.0 https://eslint.org/blog/2026/02/eslint-v10.0.0-released/ [2] Key breaking changes called out in the migration guide (high-signal items) A) Node.js version support dropped ESLint v10.0.0 no longer supports Node.js versions < v20.19.0 (and also drops v21.x and v23.x); the migration guide says to upgrade to Node.js v20.19.0 or later [1][3]. B) “Old config format” no longer supported; flat config required The v10 migration guide states the legacy config system is removed (i.e., old eslintrc format is no longer supported) and points you to use flat config (eslint.config.) [1]. The migration guide summary also calls out removing the eslintrc format [1][3]. C) New configuration file lookup algorithm In ESLint v9 there was an alternate behavior guarded by a feature flag; in v10.0.0, the behavior is the default. The migration guide describes that config lookup now starts from the directory of each linted file and searches upward to the filesystem root (instead of starting from the current working directory) and that the v10_config_lookup_from_file flag was removed [1]. D) Removed feature for eslintrc config lookup behavior flag Attempting to use v10_config_lookup_from_file now results in an error (because the flag was removed) [1]. E) Rule/behavior & API breaking changes (examples listed in the migration guide) The migration guide lists multiple other breaking/API changes, including (among others) removal of the nodeType property in LintMessage objects [1], JSX references now being tracked [1], and changes around fixer APIs requiring string text arguments [1]. How to migrate (practical steps to follow) - Upgrade Node.js to a supported version (>= v20.19.0) before running ESLint 10 [1]. - Ensure you are using flat config (eslint.config.) and remove any legacy eslintrc configuration usage [1]. - If you previously relied on the v9 config lookup behavior / feature flag, update to the new lookup algorithm (start from each linted file’s directory) [1]. - Then run the official migration guide’s checklist/sections to address any remaining listed breaking changes in your specific setup [1].
Citations:
- 1: https://eslint.org/docs/latest/use/migrate-to-10.0.0
- 2: https://eslint.org/blog/2026/02/eslint-v10.0.0-released/
- 3: https://mintlify.com/eslint/eslint/guides/migrate-to-10
🏁 Script executed:
#!/bin/bash
# Check ESLint configuration files for compatibility
fd eslint.config -e js -e mjs -e cjs --exec cat {}Repository: ProverCoderAI/effect-template
Length of output: 55
🏁 Script executed:
#!/bin/bash
# Check for ESLint configuration files
echo "=== Searching for ESLint config files ==="
fd -e json -e js -e cjs -e mjs '(eslintrc|eslint\.config)' --base-directory .
# Check package.json for Node.js version and ESLint config location
echo -e "\n=== Checking packages/app/package.json ==="
head -80 packages/app/package.json | tail -20
# Check root package.json for Node.js engines
echo -e "\n=== Checking root package.json for engines ==="
rg '"engines"' -A 5 package.jsonRepository: ProverCoderAI/effect-template
Length of output: 1013
🏁 Script executed:
#!/bin/bash
# More comprehensive search for all ESLint-related configs
echo "=== Searching for all ESLint configs ==="
find . -type f \( -name ".eslintrc*" -o -name "eslint.config.*" \) 2>/dev/null
# Check for ESLint in workspace packages
echo -e "\n=== Checking eslint references in all package.json files ==="
find . -name "package.json" -type f -exec grep -l "eslint" {} \; 2>/dev/nullRepository: ProverCoderAI/effect-template
Length of output: 252
🏁 Script executed:
#!/bin/bash
# Check the ESLint flat config file
echo "=== Content of eslint.config.mts ==="
cat packages/app/eslint.config.mts
# Search for Node.js version constraints
echo -e "\n=== Searching for Node.js version constraints ==="
find . -type f \( -name ".nvmrc" -o -name ".tool-versions" -o -name "nvmrc" \) 2>/dev/null | head -10
# Check GitHub workflows for Node.js version
echo -e "\n=== Checking for Node.js version in CI/workflows ==="
fd "\.ya?ml$" .github/workflows 2>/dev/null | xargs grep -h "node-version" 2>/dev/null | head -10Repository: ProverCoderAI/effect-template
Length of output: 10380
🏁 Script executed:
#!/bin/bash
# Check if engines field exists in root and app package.json
echo "=== Checking engines field in package.json files ==="
rg '"engines"' -B 1 -A 3 . --type json
# Check for `@eslint/compat` usage in eslint.config.mts
echo -e "\n=== Checking `@eslint/compat` usage ==="
grep -n "@eslint/compat\|compat" packages/app/eslint.config.mts || echo "No `@eslint/compat` found in config"Repository: ProverCoderAI/effect-template
Length of output: 219
Add engines field to enforce Node.js >= v20.19.0 for ESLint 10.3.0 compatibility.
The repository has already properly migrated to ESLint's flat config format (eslint.config.mts) and uses @eslint/compat correctly for plugin compatibility. However, ESLint 10.3.0 requires Node.js >= v20.19.0, and this constraint should be explicitly documented in package.json via an engines field. Without it, developers using older Node.js versions may encounter runtime errors. Add to packages/app/package.json:
"engines": {
"node": ">=20.19.0"
}🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/app/package.json` at line 71, Add an "engines" entry to
packages/app/package.json to require Node.js >=20.19.0 so ESLint 10.3.0 runs
correctly; locate the existing "eslint": "^10.3.0" dependency in package.json
and add an "engines" object with "node": ">=20.19.0" to enforce the minimum Node
version for contributors and CI.
This PR contains the following updates:
^2.4.0→^2.5.12^0.5.2→^1.0.1^2.29.8→^3.0.2^0.73.2→^0.77.0^0.56.4→^0.60.2^0.58.0→^0.61.1^0.94.5→^0.97.1^0.104.1→^0.108.1^0.47.0→^0.51.0^0.47.0→^0.51.0^0.73.1→^0.76.2^0.49.0→^0.52.1^0.38.0→^0.41.0^0.27.0→^0.30.0^0.16.0→^0.19.1^4.6.0→^4.7.22.0.2→2.1.13.3.3→3.3.7^0.0.25→^0.0.26^24.10.13→^24.13.3^8.55.0→^8.69.0^8.55.0→^8.69.0^4.0.18→^5.0.0^1.6.9→^1.6.27v6→v7v6→v7v6→v7^3.19.17→^3.22.1^10.0.0→^10.10.0^4.4.4→^4.4.5^12.1.1→^14.0.0^3.0.7→^4.2.0^2.0.0→^3.0.0^63.0.0→^74.0.0^17.3.0→^17.12.0^4.0.8→^5.1.224.13.1→24.20.010.29.3→11.25.0v4→v6v3→v6^27.0.2→^28.0.0^5.9.3→^7.0.2^8.55.0→^8.69.0^7.3.1→^8.2.2^4.0.18→^5.0.0cc @skulidropek
Release Notes
biomejs/biome (@biomejs/biome)
v2.5.12Compare Source
Patch Changes
#11440
b88f1eaThanks @Princesseuh! - Fixed Astro attribute expressions rejecting TypeScript and JSX syntax that is accepted in text expressions.#11440
b88f1eaThanks @Princesseuh! - Fixed Astro attribute names being split on:and.inside an expression, such as{x && <button x-on:keyup.enter={go} client:load.foo />}.#11440
b88f1eaThanks @Princesseuh! - Fixed a bare>in the children of an Astro expression being treated as markup, such as{x && <div>a > b</div>}.#11440
b88f1eaThanks @Princesseuh! - Fixed HTML comments inside an Astro expression failing to parse. They are now read as trivia, wherever they appear among the children.#11440
b88f1eaThanks @Princesseuh! - Fixedis:rawchildren inside an Astro expression being read as JSX, such as{x && <div is:raw>{not js} < & text</div>}.#11440
b88f1eaThanks @Princesseuh! - Fixed an apostrophe or quote in the text of a JSX element inside an Astro expression ending the expression early, such as{items.map((i) => <li>it's {i}</li>)}.#11440
b88f1eaThanks @Princesseuh! - Fixed the children of a<script>or<style>inside an Astro expression being read as JSX. Their contents are text, so braces and comparisons no longer have to be escaped.#11440
b88f1eaThanks @Princesseuh! - Added support for template literal attribute values inside an Astro expression, such as{x && <C data-x=`t${x}` />}.#11440
b88f1eaThanks @Princesseuh! - Fixed unquoted attribute values being rejected inside an Astro expression, such as{x && <a class=foo maxlength=255 href=/about>go</a>}.#11440
b88f1eaThanks @Princesseuh! - Fixed a template literal nested inside${}breaking the rest of an Astro file, such asconst href = `/blog${page === 0 ? '' : `/${page + 1}`}`;.#11440
b88f1eaThanks @Princesseuh! - Fixed a quote inside a regex character class breaking the rest of an Astro file, such asconst unsafe = /[/"]/;.#11508
54f3a2eThanks @dyc3! - Added the nursery ruleuseFlatMathMinMax. BecauseMath.min()andMath.max()accept any number of arguments, the rule reports unnecessary nested calls to the same method:The fix flattens this expression to
Math.max(a, b, c).#11585
c5c8315Thanks @Netail! - Fixed #11475:noUnresolvedImportsno longer reports Bun runtime built-in modules (bun,bun:bundle,bun:ffi,bun:jsc,bun:sqlite,bun:test).#11368
52a57b3Thanks @Austin1serb! - Fixed #6830: Biome now reports a diagnostic for excessively deep syntax instead of overflowing the native stack while releasing the parsed tree.#11596
1fc42edThanks @dyc3! - Added the nursery rulenoThisOutsideOfClass. The rule reportsthisoutside class members and TypeScript functions with an explicitthisparameter.#11555
2516335Thanks @dyc3! - Fixed #11529, wherenoFloatingPromisesmissed unhandled Promise chains when the imported function's module belonged to an import cycle. Cyclic modules now preserve types for exports that do not participate in recursive type dependencies.#11518
0fee70cThanks @HarperZ9! - Fixed #11500: the formatter now prints thedeclaremodifier before accessibility modifiers on class properties.private declare readonly name: stringis now formatted asdeclare private readonly name: string, matching Prettier and TypeScript's canonical modifier order.#11580
1277af2Thanks @ematipico! - Fixed #5091: Biome no longer moves comments next to the<of a generic, which causes invalid TypeScript syntax:#11577
42995d2Thanks @ematipico! - Fixed #4592. Biome no longer crashes while parsing malformeddeleteexpressions.#11590
67963b4Thanks @ematipico! - Fixed #6427 so Grit plugins can usefunction = ...as a node argument.#11600
a689cb5Thanks @ematipico! - Fixed #6644:noUnusedVariablesnow recognizes all interface declarations in a TypeScript declaration-merging group when the interface is referenced.The following snippet no longer triggers the rule.
#11591
d4a0716Thanks @ematipico! - Fixed #6615.noDuplicatePropertiesno longer reports declarations nested in block at-rules as duplicates of declarations in their parent block.#11492
f2a07aaThanks @santichausis! - Fixed #11454:noMisplacedAssertionnow recognises@fast-check/vitest'stest.prop(...)(and.concurrent.prop,.skip.prop, etc.) as a test function, the same way it already recognisestest.each. The JS formatter picks up the same recognition, so a curriedtest.prop(...)(...)call is now formatted with the regular breakable argument layout used fortest.each/test.for, instead of the single-line-hugging layout used for plainit/testcalls.For example, Biome no longer reports the assertion below as misplaced:
#11589
65742b3Thanks @ematipico! - Fixed #4928:noUnusedVariablesno longer reports a value declaration as unused when its merged namespace is referenced.#11559
472dbc2Thanks @levrik! - Fixed a false positive innoVueDuplicateKeyswhere a<script setup>variable initialized frompropswas reported as a duplicate of the prop it derives from. Biome now exempts any variable whose initializer referencesprops, instead of only recognizingdefineProps()andtoRefs(props).For example, Biome no longer reports
foobelow as a duplicate key:#11594
6586cebThanks @ematipico! - Fixed #6640. Biome no longer crashes when linting malformedfor...ofstatements.#11571
85b197dThanks @ematipico! - Fixed #10838:useSortedAttributesno longer corrupts JSX attributes when nested JSX elements also require sorting.#11533
97e76c0Thanks @ematipico! - Fixed #11520, where the Biome scanner would start analysing dependencies multiple times, leading to long and unresponsive sessions.#11564
18a0e1fThanks @Netail! - Fixed the diagnostic range ofnoInferrableTypesso it now highlights only the type instead of including the leading:colon, spaces and comments.#11540
124fdaaThanks @ematipico! - Fixed#11537:noShorthandPropertyOverridesnow compares declarations only within the same block. The rule no longer reports@supportsfeature queries and correctly checks nested,@keyframes, and@pageblocks.#11532
7ceb0eeThanks @dyc3! - Fixed #11528:noFloatingPromisesno longer reports statement-levelawaitexpressions that handle Promise values, including overloaded calls returning Promise aliases. Awaited values that resolve to arrays of Promises remain reported because their element Promises are not handled byawait.#11474
3c6412eThanks @dyc3! - Fixed #10241. Biome no longer reports unsupported text expression diagnostics for double-curly text in vanilla HTML, and the formatter preserves adjacent curly-brace text.#11593
6c7fd27Thanks @dyc3! - Added the nursery rulenoVueDeprecatedScopedSlots. It reports deprecated$scopedSlotsreferences in Vue templates and component objects, and offers an unsafe replacement with$slots. For example, Biome now reportsthis.$scopedSlots.defaultinside a Vue component.#11440
b88f1eaThanks @Princesseuh! - Fixed the formatter crashing on an Astro or Svelte expression spanning several lines in a file with CRLF line endings, such as<p>{a +\r\n b}</p>.#11581
f4e5ebbThanks @dyc3! - Added the nursery ruleuseModernMathApis. The rule reports legacy mathematical patterns that have direct modernMathequivalents.#11597
a20f44aThanks @Netail! - Added the nursery rulenoBunModules, which forbids the use of Bun builtin modules (e.g.bun:sqlite,bun:ffi).#11545
7d54688Thanks @dyc3! - Fixed #11542: Biome now reports HTML comments between Svelte tag attributes as parse errors.#11582
b6611ddThanks @ematipico! - Fixed #3862. Biome now parses legacy Internet Explorerfilterand-ms-filtervalues such asprogid:DXImageTransform...andalpha(opacity=40).#11575
65da251Thanks @dyc3! - Improved the Tailwind parser's ability to recover from parsing failures. Whitespace now always allows the parser to recover and start parsing a new class.#11576
0f78499Thanks @ematipico! - Fixed #3515 and #10395, where Biome could corrupt Unicode characters while writing source received through standard input to standard output. Characters such as⚠and✔are now preserved.#11539
0fca643Thanks @ematipico! - Fixed #11512, wherestyle/noDescendingSpecificitymissed lower-specificity selectors after a later higher-specificity selector with the same tail selector.#11544
040f867Thanks @dyc3! - Fixed #11541: formatting a Svelte render tag followed by an HTML comment no longer duplicates the comment.<div> {@render children?.()} <!-- comment --> - <!-- comment --> </div>#11565
ee69e0eThanks @ematipico! - Fixed #11525. Now the configuration schema correctly provides auto-completion for linter domains.#11583
b19390cThanks @dyc3! - Fixed #11352:useExplicitLengthCheckno longer reportslength-like properties used as value-producing||fallbacks or optional chains, and it no longer offers fixes for value-producing&&checks or unsafe negations.#11562
753e955Thanks @ematipico! - Fixed an issue where the Biome Language Server would start with logging level set to debug. This would cause logs to grow exponentially in long sessions.#11217
7d3ee9cThanks @dyc3! - Fixed handling ofbiome-ignore formatsuppression comments on TypeScript declared class properties with string literal names.#11497
f5d7896Thanks @dyc3! - Added thenoInvalidFileInputAcceptnursery rule. The rule reports invalid literalacceptvalues on file inputs in JSX and HTML, and normalizes common mistakes.#11345
ac58958Thanks @jakeleventhal! - Improved type inference performance by avoiding resolution of unused members in object arguments.#11554
2d55931Thanks @Netail! - Added the new nursery ruleuseReactNamingConvention, which enforces naming conventions for React values assigned fromcreateContext,useId, anduseRef. A value fromcreateContextmust be a PascalCase component name ending withContext, a value fromuseIdmust be namedidor end withId, and a value fromuseRefmust be namedrefor end withRef.#11491
1d6210bThanks @dyc3! - Added the nursery rulenoUnmodifiedLoopCondition, which reports variables in loop conditions that are never modified in the loop.v2.5.11Compare Source
Patch Changes
#11499
9743d0cThanks @scs0209! - Fixed #11496:useValidAnchornow treats Astro JSX shorthand attributes like<a {href}>as a validhref.#11437
88f805eThanks @Princesseuh! - Fixed #9944: adjacent elements inside an Astro expression now parse as an implicit fragment instead of raising an error.#11437
88f805eThanks @Princesseuh! - Fixed Astro templates rejecting unclosed HTML void elements, such as{cond && <br>}.#11507
e2fc036Thanks @dyc3! - Fixed #11157:noUnusedVariablesno longer reports Vue<script setup>bindings used by CSSv-bind()as unused.#11398
afc4615Thanks @dyc3! - Fixed #11389: Files passed through--stdin-file-pathnow use full HTML support for Astro, Svelte, and Vue when it is enabled.#11526
372cd68Thanks @dyc3! - FixednoVueRefAsOperandto track Vue refs through declaration aliases andtoRefs()properties, and to recognizeuseTemplateRef()results. The rule no longer reports false positives such as plain ref transfers, plaintoRefs()property access,defineModel()modifiers, or the supported.effectmember as operands.The refactor enabling these fixes also improves the performance of the rule.
#11458
a7cd286Thanks @dyc3! - Fixed #11436: GritQL snippets such asexport { $specifiers } from $sourcenow match named re-exports with aliases, inlinetypemodifiers, and multiple specifiers.#11515
382b15dThanks @dyc3! - Fixed #11390, wherenoFloatingPromisesperformed expensive full type inference for calls to non-Promise methods declared on third-party TypeScript classes. The rule now classifies those calls using targeted type information.#11516
6f40e82Thanks @levrik! - FixednoVueRefAsOperandso it no longer reports a callback parameter (e.g. from.find(),.map()) as an unwrapped ref value just because it's nested inside aref(),computed(), or similar call.Previously,
itemhere was incorrectly treated as a ref value because the rule attributed it to the outercomputed()call.#11495
496268dThanks @Netail! - FixeduseGraphqlNamingConventionso it no longer reports GraphQL enum value definitions with comments & descriptions and now displays a more accurate diagnostic range.#11407
6ef52b0Thanks @1678092075! - Fixed #11214:noUnusedVariablesno longer reports type parameters declared by non-default function overload signatures that have an implementation.#11322
5c353e6Thanks @jp-knj! - Added a new nursery rulenoAstroSetHtmlDirective, which disallows Astro'sset:htmldirective because untrusted content can introduce cross-site scripting vulnerabilities.For example, the following snippet triggers the rule:
#11462
18883b7Thanks @dyc3! - Fixed #10776:useVueHyphenatedAttributesno longer reports lowercase attribute names containing punctuation, such aspt:header:data-test-idandsome_attr.#11476
3270ca4Thanks @dyc3! - Fixed #10330: Vue interpolation delimiters now stay attached to whitespace-sensitive element boundaries and adjacent inline siblings, wrapping their expression when needed to fit the configured line width. Interpolations followed by text now also converge after one formatting pass.#11191
3e5367fThanks @ematipico! - Added the nursery rulenoUndeclaredCustomProperties, which reports references to custom properties that are not defined in available CSS, static HTML-likestyleattributes, or JSX stringstyleattributes.For example, the following snippet triggers the rule:
#11435
7754894Thanks @levrik! - Fixed: Variables and imports used as custom Vue directives are no longer reported as unused.For example:
#11501
e6acdedThanks @aminya! - Improved the performance ofuseArraySortCompareby skipping type inference for calls to unrelated methods.#11467
66b282cThanks @dyc3! - Fixed #11464: Biome now parses parenthesized object literals returned from arrow functions when they contain a conditional expression and a nested arrow function.#11456
db9aa2aThanks @dyc3! - Fixed #10278: Marked the fix fornoThisInStaticas unsafe by default.#11502
652aedbThanks @levrik! -noGlobalAssignno longer reports assignments to a Vue<script setup>binding from a template expression, when the binding's name happens to match a built-in global (e.g.open,parent,top).For example, this no longer triggers a diagnostic:
v2.5.10Compare Source
Patch Changes
#11403
8f7786fThanks @Princesseuh! - Fixed Astro rejecting JavaScript comments between attributes.#11403
8f7786fThanks @Princesseuh! - Fixed a bare<in Astro text being treated as the start ofConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.