fix(deps): update all dependencies - #26
Conversation
f0eb932 to
80b71eb
Compare
2dc47fe to
3d206f6
Compare
b6e6440 to
330b63d
Compare
e4d4033 to
8d5e498
Compare
84fe11a to
476a35d
Compare
72fa092 to
ea422a2
Compare
1e1df26 to
0f03dfe
Compare
8bb39eb to
e83d3ca
Compare
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/eslint-template/package.json`:
- Around line 55-56: Update the peer dependency range for TypeScript in
package.json so it aligns with the official `@typescript-eslint/parser` support
matrix: change the "typescript" peer dependency value (in
packages/eslint-template/package.json) to ">=4.8.4, <6.1.0" so TypeScript 5.x is
allowed and 6.1.0+ is excluded.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 7c81982e-6e8b-4579-99d6-c29e8ff2024f
⛔ Files ignored due to path filters (1)
pnpm-lock.yamlis excluded by!**/pnpm-lock.yaml
📒 Files selected for processing (5)
.github/actions/setup/action.yml.github/workflows/checking-dependencies.ymlpackage.jsonpackages/app/package.jsonpackages/eslint-template/package.json
| "eslint": "^10.3.0", | ||
| "typescript": "^6.0.3" |
There was a problem hiding this comment.
🧩 Analysis chain
🌐 Web query:
What TypeScript versions are officially supported by @typescript-eslint/parser 8.59.3 (and the typescript-eslint 8.59.3 toolchain)?
💡 Result:
@typescript-eslint/parser 8.59.3 (and the typescript-eslint 8.59.3 toolchain) officially supports TypeScript in the version range >=4.8.4 and <6.1.0 (i.e., TypeScript 4.8.x through 6.0.x, but not 6.1+). [1][2][3] Notes: - typescript-eslint publishes the same version number across packages to coordinate releases, so the 8.59.3 toolchain refers to the 8.59.3 versions of related packages like the parser and typescript-estree. [4] - If you use a non-supported TypeScript version, the parser logs a warning (configurable via parserOptions). [3]
Citations:
- 1: https://npmx.dev/package/@typescript-eslint/parser/v/%5E8.59.0
- 2: https://typescript-eslint.io/users/dependency-versions/
- 3: https://github.com/typescript-eslint/typescript-eslint/blob/57f032c2e6a822c049177713778d0077ee138d9a/README.md
- 4: https://dev.to/jtorchia/typescript-70-beta-i-ran-it-against-my-real-codebase-heres-what-changed-and-what-didnt-1mba
Peer dependency range is incompatible with official TypeScript-ESLint support matrix.
Line 56 restricts peers to TypeScript 6.0.x, but @typescript-eslint/parser 8.59.3 officially supports TypeScript >=4.8.4 and <6.1.0. The current range excludes TypeScript 5.x (which is supported) and inadvertently allows 6.1.0+ (which is not supported). Use "typescript": ">=4.8.4, <6.1.0" to align with the official support matrix.
Suggested fix
- "typescript": "^6.0.3"
+ "typescript": ">=4.8.4, <6.1.0"📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| "eslint": "^10.3.0", | |
| "typescript": "^6.0.3" | |
| "eslint": "^10.3.0", | |
| "typescript": ">=4.8.4, <6.1.0" |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/eslint-template/package.json` around lines 55 - 56, Update the peer
dependency range for TypeScript in package.json so it aligns with the official
`@typescript-eslint/parser` support matrix: change the "typescript" peer
dependency value (in packages/eslint-template/package.json) to ">=4.8.4, <6.1.0"
so TypeScript 5.x is allowed and 6.1.0+ is excluded.
There was a problem hiding this comment.
Actionable comments posted: 1
♻️ Duplicate comments (1)
packages/eslint-template/package.json (1)
55-56:⚠️ Potential issue | 🟠 Major | ⚡ Quick winPeer dependency range is incompatible with official TypeScript-ESLint support matrix.
The typescript peer dependency "^6.0.3" excludes TypeScript 5.x (which is still officially supported by
@typescript-eslint/parser8.59.3) and allows TypeScript 6.1.0+ (which is not supported). This will prevent users on TypeScript 5.x from installing this package even though the underlying tooling supports it.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@packages/eslint-template/package.json` around lines 55 - 56, The peer dependency for TypeScript in package.json is too restrictive (currently "typescript": "^6.0.3"); update the peerDependencies entry for "typescript" to allow supported TS 5.x but exclude unsupported 6.1.0+ (for example change it to a range like ">=5 <6.1.0") so users on TypeScript 5.x can install while preventing incompatible 6.1+ versions; update the "typescript" peer dependency value accordingly in package.json.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/eslint-template/package.json`:
- Line 17: The package bump to ts-morph@28.0.0 and vite@8.0.13 can surface
TypeScript 6.0-related defaults that break ESLint rule behavior and SSR builds;
run full test builds and SSR (dev/prod) for packages/eslint-template and any
projects using vite.config.ts, verify ESLint rule outputs (rules that use
ts-morph/TypeScript APIs), and confirm the repo's TypeScript version
(tsconfig.json / devDependencies) is pinned or adjusted; if problems appear,
either pin ts-morph/vite or explicitly set TypeScript compiler options in
tsconfig.json (e.g., strict, module, target, moduleResolution, types) to
previous values, and update vite.config.ts to address any
rollupOptions/esbuildOptions compatibility issues per the Vite 8 migration
guide.
---
Duplicate comments:
In `@packages/eslint-template/package.json`:
- Around line 55-56: The peer dependency for TypeScript in package.json is too
restrictive (currently "typescript": "^6.0.3"); update the peerDependencies
entry for "typescript" to allow supported TS 5.x but exclude unsupported 6.1.0+
(for example change it to a range like ">=5 <6.1.0") so users on TypeScript 5.x
can install while preventing incompatible 6.1+ versions; update the "typescript"
peer dependency value accordingly in package.json.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 5479e2ca-56cc-425c-93e8-fc91f82246f2
⛔ Files ignored due to path filters (1)
pnpm-lock.yamlis excluded by!**/pnpm-lock.yaml
📒 Files selected for processing (5)
.github/actions/setup/action.yml.github/workflows/checking-dependencies.ymlpackage.jsonpackages/app/package.jsonpackages/eslint-template/package.json
✅ Files skipped from review due to trivial changes (3)
- .github/actions/setup/action.yml
- .github/workflows/checking-dependencies.yml
- package.json
🚧 Files skipped from review as they are similar to previous changes (1)
- packages/app/package.json
This PR contains the following updates:
^2.4.2→^2.5.11^0.5.2→^1.0.0^2.29.8→^3.0.1^0.73.2→^0.77.0^0.56.4→^0.60.2^0.58.0→^0.61.1^0.94.5→^0.97.1^0.104.1→^0.108.1^0.47.0→^0.51.0^0.47.0→^0.51.0^0.73.2→^0.76.2^0.49.0→^0.52.1^0.38.0→^0.41.0^0.27.0→^0.30.0^0.16.0→^0.19.1^4.6.0→^4.7.22.0.2→2.1.03.3.3→3.3.6^0.0.25→^0.0.26^25.3.0→^25.9.5^8.56.0→^8.68.0^8.56.0→^8.68.08.56.0→8.68.08.56.0→8.68.0^4.0.18→^4.1.11^1.6.9→^1.6.27v6→v7v6→v7^3.19.18→^3.22.1^10.0.0→^10.9.1^10.0.0→^10.9.1^3.1.0→^3.7.1^4.4.4→^4.4.5^7.3.1→^7.6.2^12.1.1→^14.0.0^4.0.0→^4.2.0^63.0.0→^74.0.0^17.3.0→^17.11.0^4.0.8→^5.0.1624.13.1→24.20.010.30.0→11.24.0v4→v6v3→v6^27.0.2→^28.0.0^5.9.3→^7.0.2^5.9.3→^7.0.2^8.56.0→^8.68.0^7.3.1→^8.2.2^4.0.18→^4.1.11cc @skulidropek
Release Notes
biomejs/biome (@biomejs/biome)
v2.5.11Compare Source
Patch Changes
#11499
9743d0cThanks @scs0209! - Fixed #11496:useValidAnchornow treats Astro JSX shorthand attributes like<a {href}>as a validhref.#11437
88f805eThanks @Princesseuh! - Fixed #9944: adjacent elements inside an Astro expression now parse as an implicit fragment instead of raising an error.#11437
88f805eThanks @Princesseuh! - Fixed Astro templates rejecting unclosed HTML void elements, such as{cond && <br>}.#11507
e2fc036Thanks @dyc3! - Fixed #11157:noUnusedVariablesno longer reports Vue<script setup>bindings used by CSSv-bind()as unused.#11398
afc4615Thanks @dyc3! - Fixed #11389: Files passed through--stdin-file-pathnow use full HTML support for Astro, Svelte, and Vue when it is enabled.#11526
372cd68Thanks @dyc3! - FixednoVueRefAsOperandto track Vue refs through declaration aliases andtoRefs()properties, and to recognizeuseTemplateRef()results. The rule no longer reports false positives such as plain ref transfers, plaintoRefs()property access,defineModel()modifiers, or the supported.effectmember as operands.The refactor enabling these fixes also improves the performance of the rule.
#11458
a7cd286Thanks @dyc3! - Fixed #11436: GritQL snippets such asexport { $specifiers } from $sourcenow match named re-exports with aliases, inlinetypemodifiers, and multiple specifiers.#11515
382b15dThanks @dyc3! - Fixed #11390, wherenoFloatingPromisesperformed expensive full type inference for calls to non-Promise methods declared on third-party TypeScript classes. The rule now classifies those calls using targeted type information.#11516
6f40e82Thanks @levrik! - FixednoVueRefAsOperandso it no longer reports a callback parameter (e.g. from.find(),.map()) as an unwrapped ref value just because it's nested inside aref(),computed(), or similar call.Previously,
itemhere was incorrectly treated as a ref value because the rule attributed it to the outercomputed()call.#11495
496268dThanks @Netail! - FixeduseGraphqlNamingConventionso it no longer reports GraphQL enum value definitions with comments & descriptions and now displays a more accurate diagnostic range.#11407
6ef52b0Thanks @1678092075! - Fixed #11214:noUnusedVariablesno longer reports type parameters declared by non-default function overload signatures that have an implementation.#11322
5c353e6Thanks @jp-knj! - Added a new nursery rulenoAstroSetHtmlDirective, which disallows Astro'sset:htmldirective because untrusted content can introduce cross-site scripting vulnerabilities.For example, the following snippet triggers the rule:
#11462
18883b7Thanks @dyc3! - Fixed #10776:useVueHyphenatedAttributesno longer reports lowercase attribute names containing punctuation, such aspt:header:data-test-idandsome_attr.#11476
3270ca4Thanks @dyc3! - Fixed #10330: Vue interpolation delimiters now stay attached to whitespace-sensitive element boundaries and adjacent inline siblings, wrapping their expression when needed to fit the configured line width. Interpolations followed by text now also converge after one formatting pass.#11191
3e5367fThanks @ematipico! - Added the nursery rulenoUndeclaredCustomProperties, which reports references to custom properties that are not defined in available CSS, static HTML-likestyleattributes, or JSX stringstyleattributes.For example, the following snippet triggers the rule:
#11435
7754894Thanks @levrik! - Fixed: Variables and imports used as custom Vue directives are no longer reported as unused.For example:
#11501
e6acdedThanks @aminya! - Improved the performance ofuseArraySortCompareby skipping type inference for calls to unrelated methods.#11467
66b282cThanks @dyc3! - Fixed #11464: Biome now parses parenthesized object literals returned from arrow functions when they contain a conditional expression and a nested arrow function.#11456
db9aa2aThanks @dyc3! - Fixed #10278: Marked the fix fornoThisInStaticas unsafe by default.#11502
652aedbThanks @levrik! -noGlobalAssignno longer reports assignments to a Vue<script setup>binding from a template expression, when the binding's name happens to match a built-in global (e.g.open,parent,top).For example, this no longer triggers a diagnostic:
v2.5.10Compare Source
Patch Changes
#11403
8f7786fThanks @Princesseuh! - Fixed Astro rejecting JavaScript comments between attributes.#11403
8f7786fThanks @Princesseuh! - Fixed a bare<in Astro text being treated as the start of a tag, such as<p>5 < 6 and 7 > 6</p>. As in HTML, a<that cannot open a tag is text and needs no escaping.#11438
3133ffaThanks @Princesseuh! - Fixed #8294: an Astro expression holding only a comment is no longer reported as a parse error, which also stopped the whole file from being formatted.#11403
8f7786fThanks @Princesseuh! - Fixed #9165: an empty Astro expression such as<div>{}</div>no longer fails to parse. Astro renders{}as nothing.#11403
8f7786fThanks @Princesseuh! - Fixed Astro expressions containing a comment failing to parse.#11403
8f7786fThanks @Princesseuh! - Added support for Astro's fragment shorthand.#11403
8f7786fThanks @Princesseuh! - Fixed an Astro frontmatter block being cut short by a closing tag inside a string or comment.#11403
8f7786fThanks @Princesseuh! - Fixed---being read as an Astro frontmatter fence when markup precedes it. Astro only recognizes frontmatter at the very start of a file, so a file opening with a comment now has no frontmatter, and its---lines are content.<!-- c --> --- this is text, not frontmatter ---#11403
8f7786fThanks @Princesseuh! - Fixed an Astro frontmatter block ending early on a line that merely starts with a dash.#11403
8f7786fThanks @Princesseuh! - Fixed the children of an Astro element carryingis:rawbeing parsed as markup instead of raw text. This now also covers<script>and<style>, whose contents Astro emits verbatim rather than processing, so they are no longer linted as JavaScript or CSS.#11403
8f7786fThanks @Princesseuh! - Fixed Astro rejecting attribute names that start with a colon, such as:href.#11403
8f7786fThanks @Princesseuh! - Fixed the Astro parser failing to recover from a malformed closing tag such as<div></{<//, so that a later mistake is reported where it happens rather than cascading.#11403
8f7786fThanks @Princesseuh! - Fixed{inside an Astro<math>element opening an expression. MathML is foreign content where Astro parses no expressions, so LaTeX such asR^{2x}now survives as text.<svg>is unaffected.#11403
8f7786fThanks @Princesseuh! - Fixed{{at the start of an Astro expression being read as an interpolation. Astro has no{{ }}syntax, so{{ a: 1 }}and<Comp a={{ b: 1 }} />are object literals.#11403
8f7786fThanks @Princesseuh! - Fixed expressions inside an Astro<pre>or<textarea>being read as raw text. Astro parses both as ordinary elements, so their markup and interpolations are now parsed, and a variable used only inside one is no longer reported as unused.#11403
8f7786fThanks @Princesseuh! - Added support for template literal attribute values in Astro, such as<div class=`a ${b} c`>.#11403
8f7786fThanks @Princesseuh! - Fixed Astro rejecting HTML5 unquoted attribute values that contain`,=,'or", such as<a href=a=b>and<a href=a'b>.#11393
dec5a8fThanks @1678092075! - Fixed #11207:useStrictModeno longer reports Vue event handlers such as@click="count++".#11431
c065f99Thanks @levrik! - Fixed #11429: Variables and imports used by Vue same-name bindings such as:disabledorv-bind:disabledare no longer reported as unused.#11409
405dedbThanks @ematipico! - Fixed a memory leak in the LSP server where memory usage kept growing over long editor sessions.#11422
a51eff7Thanks @dyc3! - Fixed #11416: Biome no longer crashes when parsing incomplete{let}or{const}declarations in Svelte files.#11378
34b715cThanks @Netail! - Added extra rule sources from@eslint/css.biome migrate eslintdetects rules in your eslint configurations more reliably.#11403
8f7786fThanks @Princesseuh! - Fixed{#,{/,{:and{@being read as Svelte block openings in every HTML-like file. They are now Svelte-only, so in HTML, Vue and Angular files a sequence such as{#if x}is ordinary text instead of a parse error.#11443
8d45229Thanks @ematipico! - Fixed #11390:noFloatingPromisesno longer performs unnecessary type inference on call arguments when checking methods of non-generic class instances created withnew.#11425
9c2667bThanks @dyc3! - Fixed #6426: GritQL plugins now match and rewrite metavariables embedded in quoted strings.#11441
00317c3Thanks @dyc3! - Improved performance ofuseNamedCaptureGroup,noMisplacedAssertion,noSkippedTests,noExportsInTest,noDuplicateTestHooks,noIdenticalTestTitle,useTestHooksInOrder, anduseTestHooksOnTop.v2.5.9Compare Source
Patch Changes
#11321
41386f3Thanks @dyc3! - Fixed #11315: The CSS parser now recovers at declaration boundaries after bogus declarations, allowing subsequent valid declarations to be parsed.#11248
57b197eThanks @yanthomasdev! - Expanded the environment variable metadata used bybiome rageto includeBIOME_BINARY,BIOME_LOG_FILE, andRUST_BACKTRACEas well as reworded explanations for better readability.#11377
a8798eaThanks @Netail! - Added a new nursery ruleuseNamedLayerwhich disallows anonymous cascade layers.#11327
6771cf5Thanks @dyc3! - The HTML formatter now preserves meaningful blank lines in HTML, including spacing after elements with trailing spaces and blank lines between comment groups.<div> <!-- first group --> + <!-- second group --> </div>#10312
ba8aa18Thanks @dyc3! - Added the nursery ruleuseTailwindShorthandClasses, which suggests shorter Tailwind utility classes. For example, the rule suggests replacingw-4 h-4withsize-4.#11333
715e0cdThanks @kkkhs! - Fixed #11328:lint/nursery/useExpectnow recognizes Vitest Browser Modeexpect.element()calls as assertions.#11343
9b98211Thanks @johncarmack1984! - Fixed #11311: the CSS parser now accepts Tailwind container-query variant names in@variant, such as@xland@max-xl. These previously produced a parse error and anoUnknownAtRulesdiagnostic.#11220
3e8c488Thanks @santichausis! - Fixed #9541:noUndeclaredVariables,noUnusedImports, andnoUnusedVariablesnow correctly recognise exported variables and functions declared in one embedded<script>block as usable from a sibling<script>block, in Svelte's<script module>/<script>pair and Vue's non-setup<script>blocks.For example, Biome no longer reports
greetas undeclared in the following Svelte component:#11300
36430ebThanks @dyc3! - Fixed the HTML formatter's whitespace handling formarquee,noscript,video,audio, andobjectelements.#11299
6559e6cThanks @jp-knj! - Added the nursery ruleuseAstroClientOnlyDirectiveValue, which reports Astroclient:onlydirectives without an initializer.For example,
<Component client:only />triggers the rule.#11365
7529811Thanks @MHJahanbakhsh! - Fixed #11229: TheuseGenericFontNamesrule now treatsmathas a valid generic font family.#11346
674f5f4Thanks @Jayllyz! - Fixed #11335:noComponentHookFactoriesnow reports ause-prefixed variable only when a function is assigned to it directly.#11334
c87c46aThanks @zkasuran! - Fixed #11317:noSvgWithoutTitleno longer reports ansvgthat uses the boolean shorthandaria-hidden(equivalent toaria-hidden={true}in React).#11364
13853b1Thanks @ematipico! - Fixed a bug whereuseJsxKeyInIterableincorrectly flagged Astro files.#11321
41386f3Thanks @dyc3! - Fixed #11315: Invalid CSS declarations in HTMLstyleattributes now produce parser diagnostics instead of causing a panic.#11325
67c3bf0Thanks @dyc3! - Fixed HTML text wrapping to account for the width of an adjacent closing tag, avoiding lines that exceed the configured width when the final word and tag must move together.#11367
fe5b5d4Thanks @ematipico! - Fixed TypeScriptcompilerOptions.pathsresolution when mapping targets omit./. Biome now resolves these targets relative to their configured path base.#11316
17e48d6Thanks @wanxiankai! - Fixed #11289: the safe fix fornoExtraBooleanCastnow preserves parentheses around nested conditional expressions.#11254
d25d113Thanks @dyc3! - Fixed #11242: Biome no longer crashes with an access violation when analysing files on Windows ARM64.#11221
85aac73Thanks @freeatnet! - Added the nursery rulenoUnsafeTypeAssertion, which disallows TypeScript type assertions while allowing const assertions.#11314
7ffb677Thanks @ematipico! - Fixed #11310: Restored the performance ofnoMisusedPromisesandnoFloatingPromiseswhen analyzed expressions share deep imported type paths.#11356
6cd3263Thanks @johncarmack1984! - The Tailwind parser now understands modifiers on bare utilities (@container/sidebar,shadow/50).#11318
76059e9Thanks @johncarmack1984! - The Tailwind parser now understands container-query variants (@sm:,@max-lg:,@min-[400px]:) and child and descendant variants (*:,**:).#11357 [
faa2074](https://redirect.github.com/biomejs/biome/commit/faa2074Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.