fix(deps): update all dependencies - #26
Conversation
f0eb932 to
80b71eb
Compare
2dc47fe to
3d206f6
Compare
b6e6440 to
330b63d
Compare
e4d4033 to
8d5e498
Compare
84fe11a to
476a35d
Compare
72fa092 to
ea422a2
Compare
1e1df26 to
0f03dfe
Compare
8bb39eb to
e83d3ca
Compare
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/eslint-template/package.json`:
- Around line 55-56: Update the peer dependency range for TypeScript in
package.json so it aligns with the official `@typescript-eslint/parser` support
matrix: change the "typescript" peer dependency value (in
packages/eslint-template/package.json) to ">=4.8.4, <6.1.0" so TypeScript 5.x is
allowed and 6.1.0+ is excluded.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 7c81982e-6e8b-4579-99d6-c29e8ff2024f
⛔ Files ignored due to path filters (1)
pnpm-lock.yamlis excluded by!**/pnpm-lock.yaml
📒 Files selected for processing (5)
.github/actions/setup/action.yml.github/workflows/checking-dependencies.ymlpackage.jsonpackages/app/package.jsonpackages/eslint-template/package.json
| "eslint": "^10.3.0", | ||
| "typescript": "^6.0.3" |
There was a problem hiding this comment.
🧩 Analysis chain
🌐 Web query:
What TypeScript versions are officially supported by @typescript-eslint/parser 8.59.3 (and the typescript-eslint 8.59.3 toolchain)?
💡 Result:
@typescript-eslint/parser 8.59.3 (and the typescript-eslint 8.59.3 toolchain) officially supports TypeScript in the version range >=4.8.4 and <6.1.0 (i.e., TypeScript 4.8.x through 6.0.x, but not 6.1+). [1][2][3] Notes: - typescript-eslint publishes the same version number across packages to coordinate releases, so the 8.59.3 toolchain refers to the 8.59.3 versions of related packages like the parser and typescript-estree. [4] - If you use a non-supported TypeScript version, the parser logs a warning (configurable via parserOptions). [3]
Citations:
- 1: https://npmx.dev/package/@typescript-eslint/parser/v/%5E8.59.0
- 2: https://typescript-eslint.io/users/dependency-versions/
- 3: https://github.com/typescript-eslint/typescript-eslint/blob/57f032c2e6a822c049177713778d0077ee138d9a/README.md
- 4: https://dev.to/jtorchia/typescript-70-beta-i-ran-it-against-my-real-codebase-heres-what-changed-and-what-didnt-1mba
Peer dependency range is incompatible with official TypeScript-ESLint support matrix.
Line 56 restricts peers to TypeScript 6.0.x, but @typescript-eslint/parser 8.59.3 officially supports TypeScript >=4.8.4 and <6.1.0. The current range excludes TypeScript 5.x (which is supported) and inadvertently allows 6.1.0+ (which is not supported). Use "typescript": ">=4.8.4, <6.1.0" to align with the official support matrix.
Suggested fix
- "typescript": "^6.0.3"
+ "typescript": ">=4.8.4, <6.1.0"📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| "eslint": "^10.3.0", | |
| "typescript": "^6.0.3" | |
| "eslint": "^10.3.0", | |
| "typescript": ">=4.8.4, <6.1.0" |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/eslint-template/package.json` around lines 55 - 56, Update the peer
dependency range for TypeScript in package.json so it aligns with the official
`@typescript-eslint/parser` support matrix: change the "typescript" peer
dependency value (in packages/eslint-template/package.json) to ">=4.8.4, <6.1.0"
so TypeScript 5.x is allowed and 6.1.0+ is excluded.
There was a problem hiding this comment.
Actionable comments posted: 1
♻️ Duplicate comments (1)
packages/eslint-template/package.json (1)
55-56:⚠️ Potential issue | 🟠 Major | ⚡ Quick winPeer dependency range is incompatible with official TypeScript-ESLint support matrix.
The typescript peer dependency "^6.0.3" excludes TypeScript 5.x (which is still officially supported by
@typescript-eslint/parser8.59.3) and allows TypeScript 6.1.0+ (which is not supported). This will prevent users on TypeScript 5.x from installing this package even though the underlying tooling supports it.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@packages/eslint-template/package.json` around lines 55 - 56, The peer dependency for TypeScript in package.json is too restrictive (currently "typescript": "^6.0.3"); update the peerDependencies entry for "typescript" to allow supported TS 5.x but exclude unsupported 6.1.0+ (for example change it to a range like ">=5 <6.1.0") so users on TypeScript 5.x can install while preventing incompatible 6.1+ versions; update the "typescript" peer dependency value accordingly in package.json.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/eslint-template/package.json`:
- Line 17: The package bump to ts-morph@28.0.0 and vite@8.0.13 can surface
TypeScript 6.0-related defaults that break ESLint rule behavior and SSR builds;
run full test builds and SSR (dev/prod) for packages/eslint-template and any
projects using vite.config.ts, verify ESLint rule outputs (rules that use
ts-morph/TypeScript APIs), and confirm the repo's TypeScript version
(tsconfig.json / devDependencies) is pinned or adjusted; if problems appear,
either pin ts-morph/vite or explicitly set TypeScript compiler options in
tsconfig.json (e.g., strict, module, target, moduleResolution, types) to
previous values, and update vite.config.ts to address any
rollupOptions/esbuildOptions compatibility issues per the Vite 8 migration
guide.
---
Duplicate comments:
In `@packages/eslint-template/package.json`:
- Around line 55-56: The peer dependency for TypeScript in package.json is too
restrictive (currently "typescript": "^6.0.3"); update the peerDependencies
entry for "typescript" to allow supported TS 5.x but exclude unsupported 6.1.0+
(for example change it to a range like ">=5 <6.1.0") so users on TypeScript 5.x
can install while preventing incompatible 6.1+ versions; update the "typescript"
peer dependency value accordingly in package.json.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 5479e2ca-56cc-425c-93e8-fc91f82246f2
⛔ Files ignored due to path filters (1)
pnpm-lock.yamlis excluded by!**/pnpm-lock.yaml
📒 Files selected for processing (5)
.github/actions/setup/action.yml.github/workflows/checking-dependencies.ymlpackage.jsonpackages/app/package.jsonpackages/eslint-template/package.json
✅ Files skipped from review due to trivial changes (3)
- .github/actions/setup/action.yml
- .github/workflows/checking-dependencies.yml
- package.json
🚧 Files skipped from review as they are similar to previous changes (1)
- packages/app/package.json
This PR contains the following updates:
^2.4.2→^2.5.6^0.5.2→^0.7.0^2.29.8→^2.31.1^0.73.2→^0.76.0^0.56.4→^0.60.0^0.58.0→^0.61.0^0.94.5→^0.97.0^0.104.1→^0.108.0^0.47.0→^0.50.0^0.47.0→^0.50.0^0.73.2→^0.76.0^0.49.0→^0.52.0^0.38.0→^0.41.0^0.27.0→^0.30.0^0.16.0→^0.19.0^4.6.0→^4.7.22.0.2→2.1.03.3.3→3.3.6^0.0.25→^0.0.26^25.3.0→^25.9.5^8.56.0→^8.65.0^8.56.0→^8.65.08.56.0→8.65.08.56.0→8.65.0^4.0.18→^4.1.10^1.6.9→^1.6.24v6→v7v6→v7^3.19.18→^3.22.0^10.0.0→^10.8.0^10.0.0→^10.8.0^3.1.0→^3.7.0^4.4.4→^4.4.5^7.3.1→^7.6.0^12.1.1→^14.0.0^4.0.0→^4.2.0^63.0.0→^72.0.0^17.3.0→^17.8.0^4.0.8→^5.0.1424.13.1→24.18.010.30.0→11.17.0v4→v6v3→v6^27.0.2→^28.0.0^5.9.3→^7.0.2^5.9.3→^7.0.2^8.56.0→^8.65.0^7.3.1→^8.1.5^4.0.18→^4.1.10cc @skulidropek
Release Notes
biomejs/biome (@biomejs/biome)
v2.5.6Compare Source
Patch Changes
#11035
0e4b03bThanks @ematipico! - Fixed a performance regression innoMisusedPromisesthat caused type inference to run repeatedly while linting a file.#11043
22ec076Thanks @denbezrukov! - Fixed CSS formatting for multiline function arguments preceded by comments:.example { value: outer( 1, /* comment */ nested( - first, - second - ) + first, + second + ) ); }#11007
c9acb25Thanks @BTF-Kabir-2020! - Fixed #9195:useHookAtTopLevelno longer reports hooks in namedforwardRefcomponents that receive arefparameter.#10152
50a9bd8Thanks @Zelys-DFKH! - Fixed #10131: Biome now correctly parses curried arrow functions in ternary consequents when the inner arrow's parameters use a destructuring pattern, e.g.cond ? (x) => ({ a, b }) => body : alt.#11105
8ffe2b9Thanks @dadavidtseng! - Fixed #11092: ThenoUselessTernaryquick fix now preserves operator spacing when simplifying or inverting boolean ternary expressions.#10533
5809875Thanks @Mokto! - Fixed #10515:biome check --writewas not idempotent on Svelte files — multi-line template literals in<script>blocks and block comments in<style>blocks gained an extra indent level on every run.#11040
0abb620Thanks @Mokto! - Fixed an issue where the HTML formatter would duplicate a comment placed directly before a Svelte{@​const ...}or{@​debug ...}block. The duplication compounded on every subsequent--write, causing the file to grow exponentially.#10858
6d18204Thanks @ruidosujeira! - Fixed #10839: Svelte{#each}array destructuring no longer includes spaces inside square brackets, and multiline bind function expressions now indent their getter, setter, and function body correctly.#11009
2c36626Thanks @ematipico! - Improved the accuracy of type-aware lint rules by resolving more inferred types. For example,noFloatingPromisesnow detects floating Promises returned by aliased callbacks and arrays of Promises created by async mapping callbacks.The following statements are now reported:
#10973
9cb044cThanks @ematipico! - Fixed false positives innoMisleadingReturnTypewhen generic-constraint, normalization, substitution, or structural return-type comparison cannot complete. The rule now suppresses diagnostics rather than suggesting a return type derived from partial information. For example, this unresolved return type is no longer reported:#11071
15047a2Thanks @dyc3! - The HTML parser now accepts mixed-casedoctypedeclarations.#11030
cc90e65Thanks @marschattha! - Therdjsonreporter now populates the severity field of each diagnostic (ERROR,WARNING, orINFO), so tools consuming Reviewdog Diagnostic Format output no longer need to assume a default severity.#11009
2c36626Thanks @ematipico! - Fixed a performance regression in type-aware JavaScript lint rules by inferring only requested types and memoizing export resolution.#11056
903b177Thanks @dyc3! - Added support for Svelte declaration tags usingletandconst. Biome can now parse, format, and lint bindings declared in these tags.#11045
89c27c6Thanks @ematipico! - Improved the performance of Biome formatter up to ~7% across the board.#9806
781d68dThanks @dyc3! - Added the nursery rulenoJsRestrictedProperties, which ports ESLint'sno-restricted-propertiesrule. Biome now flags restricted member access and object destructuring, andbiome migrate eslintpreserves the rule's options.v2.5.5Compare Source
Patch Changes
#10972
ab8c21bThanks @ematipico! - FixeduseExhaustiveSwitchCasesfor unions of bigint literals. The rule now reports missing bigint cases and compares bigint literals by value, including binary, octal, hexadecimal, and separator-containing spellings. For example, this switch now reports the missing2ncase:#10972
ab8c21bThanks @ematipico! - Fixed false positives innoBaseToStringanduseNullishCoalescingwhen member, stringification, or nullish inference cannot complete. These rules now suppress diagnostics instead of reporting from partial type information. For example, neither expression is reported when a recursive type cannot be fully resolved:#10977
0bf7486Thanks @ematipico! - Fixed #10922: the actionuseSortedAttributesno longer triggers for HTML instructions.#10957
cf263c4Thanks @dyc3! - FixednoThenPropertyfailing to detectObject.fromEntries,Object.defineProperty, andReflect.definePropertycalls with comments between their tokens.#10983
edc0ed7Thanks @ayaangazali! - Fixed #10980:useAriaPropsSupportedByRoleno longer reports false positives when the attribute that determines an element's implicit ARIA role is written as a shorthand attribute, such as<a {href} aria-label="...">in Astro and Svelte files.Shorthand attributes are now taken into account when computing the implicit role, so the anchor above correctly resolves to the
linkrole instead ofgeneric.#10889
89526e3Thanks @denbezrukov! - Fixed CSS formatter casing for syntax-owned names while preserving author-defined names, including scoped keyframes and container scroll-state queries.#10964
794ccd0Thanks @denbezrukov! - Fixed CSS formatting for comments between declaration values and!important.#10993
b7a9694Thanks @denbezrukov! - Fixed the CSS formatter to preserve comments on the correct side of selector combinators and before declaration blocks.It now also keeps selectors with escaped newlines in attribute values inline when they fit.
#10978
8ebafe1Thanks @ematipico! - Fixed #10870:noUnresolvedImportsno longer reports false positives such asimport type { NextRequest } from "next/server".#10901
68c10e6Thanks @Socialpranker! - Fixed #10622: the HTML/Vue parser no longer panics on the argument-lessv-bindshorthand (:="props").This syntax is valid Vue and equivalent to
v-bind="props", so the parser now accepts it (along with the longhandv-bind:="props") instead of crashing while building a diagnostic for a missing argument.#10936
7df46f5Thanks @ematipico! - Improved generic tuple inference foruseIncludes. The rule now recognizes specialised tuple element types returned through generic aliases.#10941
f787725Thanks @siketyan! - Fixed#10855: Biome now supports parsing and formatting CSS custom media queries declared with@custom-media.#10969
72d309bThanks @ematipico! - Fixed an issue where Biome logs became too verbose, dumping information not relevant to user's operations.e62f6b6Thanks @ematipico! - Fixed #10963: Biome no longer panics when a type-aware rule such asnoFloatingPromiseschecks a call to a function with multiple call signatures imported from another module.#10931
899c60dThanks @ematipico! - Fixedcheck --writecommand. Now the command reports code frame of the formatted code, if the formatter is enabled.#10904
ceee4f4Thanks @qzwxsaedc! - Fixed #10892:noUnnecessaryConditionsno longer reports a false positive when checking a member of a discriminated union that is accessed through a default type-only namespace import. The following code is no longer flagged:#10962
f0a67f2Thanks @ematipico! - Biome no longer removes embedded styles and scripts in HTML files.#11000
5039a1eThanks @ematipico! - Fixed a bug where closing one editor stopped a shared Biome daemon used by other editors. LSP proxy processes now exit when either the editor or daemon disconnects.#10957
cf263c4Thanks @dyc3! - Improved the performance of thenoThenPropertylint rule by about 50%.#10992
4bf9b21Thanks @ematipico! - FixednoMisusedPromises: The rule now reports Promise-returning callbacks where a synchronous callback is expected when calls use tuple spreads or tuple rest parameters, including generic and deeply nested tuples, and when constructor signatures come from interface or object types. Recursive or excessively nested tuple spreads use a conservative fallback so analysis terminates.For example, the following callback is now reported.
#10915
b3b12b3Thanks @Functionhx! - Added the rulenoNegationInEqualityCheck. The rule flags negated expressions on the left side of strict equality checks like!foo === bar— due to operator precedence this evaluates as(!foo) === barwhich is almost always a mistake forfoo !== bar.The rule provides an unsafe fix that flips the operator.
#10970
bd1038bThanks @ematipico! - Improved overload selection fornoMisusedPromises. Biome now handles overloaded calls, overloaded constructors, rest parameters, union arguments, and generic constraints without selecting an incompatible signature. For example,noMisusedPromisesnow reports the async callback passed to the synchronous overload:#10933
48a4abbThanks @ematipico! - FixeduseArrayFindto recognize bigint zero indexes.#10931
899c60dThanks @ematipico! - Fixed an orchestration issue that could lead to deadlocks when type-aware rules are enabled.#10969
72d309bThanks @ematipico! - Hardened the Biome Language Server by improving its synchronisation logic.#10972
ab8c21bThanks @ematipico! - Fixed false positives innoMisusedPromisesanduseAwaitThenablewhen Promise or thenable inference cannot complete. These rules now suppress diagnostics instead of treating incomplete type information as a definite result. For example,useAwaitThenableno longer reportsawait valuewhen the value's thenability is unknown:v2.5.4Compare Source
Patch Changes
#10665
55ff995Thanks @dyc3! - Improved the performance of the HTML parser slightly in our synthetic benchmarks.#10894
f4fb10eThanks @ematipico! - Fixed #6392: On-type formatting no longer moves comments before anifstatement into its body.#10939
f2799dbThanks @Netail! - Fixed #10930:noLabelWithoutControlnow correctly detects text interpolation in Astro, Svelte & Vue as valid accessible content.#10945
ae15d98Thanks @Netail! - Fixed #10942: Svelte directives don't throw an accidental debug log anymore.#10842
5e1abfeThanks @JamBalaya56562! - Fixed #9196:biome check --write --unsafeno longer hangs forever when applying thenoCommentTextcode fix.The rule's fix now wraps the comment in a real JSX expression container (
{/* comment */}) instead of re-inserting the braces as plain JSX text, so the fixed code is no longer reported again by the same rule.#10891
ecca79eThanks @ematipico! - Fixed#10885: prevented a module-inference regression introduced by a housekeeping change.#10886
60c8043Thanks @dyc3! - Fixed #10727: Biome now breaks the arguments of curriedtest.each,it.each,describe.each, andtest.forcalls when they exceed the configured line width.#10895
01a85f0Thanks @ematipico! - Biome will now remove stale Unix daemon sockets from older Biome versions when starting a newer daemon.v2.5.3Compare Source
Patch Changes
#10815
86613d5Thanks @WaterWhisperer! - Fixed a parser panic reported in #10708: Biome now recovers when unsupported CSS Modules@valuerules or scoped@keyframesnames end at EOF.#10534
da9b403Thanks @Mokto! - FixednoUnusedVariablesfalse positives in Svelte files: Svelte store subscriptions ($storereferences in templates now keep the underlyingstorebinding from being flagged), and$bindable()props that are only written to in the script block (write-only is intentional for bindable props) are no longer reported as unused.#10827
098ba41Thanks @Aqu1bp! - Fixed #10698: ThenoUnsafeOptionalChainingrule now reports unsafe optional chains wrapped in TypeScriptas,satisfies, type assertion, and instantiation expressions, such asnew (value?.constructor as Constructor)().#10773
3c6513dThanks @otkrickey! - Fixed #10772:useVueValidVOnno longer reports a missing handler for v-on directives using a verb modifier (.stop/.prevent) without an expression, e.g.<div @​click.stop></div>. The rule also accepts the arg-less object syntax<div v-on="$listeners"></div>instead of reporting a missing event name.#10721
d83c66bThanks @minseong0324! - Improved type-aware lint rule inference for built-in globals and indexed function calls. Biome now resolvesError(...),new Error(...), optionalError#stack, and calls through indexed function values such ashandlers[0]()more accurately.#10865
6450276Thanks @ematipico! - Fixed #10845. Biome Language Server no longer goes in deadlock when the scanner is enabled.#10853
93d8e53Thanks @Netail! - Fixed #10840: Astro shorthand attribute syntax is now correctly being parsed from embedded nodes.#10820
bba3092Thanks @JamBalaya56562! - Fixed #10619:noProcessEnvnow also reports computed (bracket) member access. Previously only dot access was checked, soprocess["env"]andenv["NODE_ENV"](whereenvis imported fromnode:process) were missed. Both static and computed accesses are now reported.#10835
3447b2fThanks @dyc3! - Fixed #10824:useDomQuerySelectornow supports anignoreoption for receiver identifiers that should not be reported.#10875
b12e486Thanks @dyc3! - Fixed #10795:--profile-rulesnow reports timings for each plugin separately asplugin/<pluginName>, matching the naming used by plugin suppressions, instead of aggregating all plugins under a singleplugin/pluginentry.#10877
d6bc447Thanks @ematipico! - Fixed biome-zed#164: Biome no longer inserts stray whitespace when format-on-type runs after closing delimiters such as),], and}.#10867
a21463eThanks @dyc3! - Fixed #10864: Biome no longer crashes when checking or linting HTML files with unquoted attribute values such as<textarea rows=4></textarea>.v2.5.2Compare Source
Patch Changes
#10595
f458028Thanks @pkallos! - Added the optionignoreBooleanCoercionto useNullishCoalescing. When enabled, Biome ignores||and||=used inside aBoolean()call, where coalescing on falsy values is intentional.#10798
4a32b63Thanks @pkallos! - Added the optionignorePrimitivesto useNullishCoalescing. When enabled, Biome ignores||,||=, and ternary expressions whose non-nullish operands are all primitives the option opts out of. Usetrueto ignore all primitives, or an object selectingstring,number,boolean, orbigint.#10545 [
f3d4c00](https://redirect.github.com/biomejs/biome/commit/f3d4c0082676c5188e9a6aa516318c7e3dConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.