Skip to content

chore(deps): update npm dependencies (non-major) - #533

Open
derodero24 wants to merge 1 commit into
developfrom
renovate/npm-dependencies-(non-major)
Open

derodero24 wants to merge 1 commit into
developfrom
renovate/npm-dependencies-(non-major)

Conversation

@derodero24

@derodero24 derodero24 commented Sep 20, 2026 •

Copy link
Copy Markdown
Owner

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@biomejs/biome (source) 2.5.13 → 2.5.15 age confidence
@changesets/cli (source) 3.0.2 → 3.0.3 age confidence
@commitlint/cli (source) 21.2.2 → 21.2.3 age confidence
@commitlint/config-conventional (source) 21.2.2 → 21.2.3 age confidence
@types/node (source) 24.13.4 → 24.19.0 age confidence
fastify (source) 5.12.3 → 5.12.5 age confidence
hono (source) 4.13.7 → 4.13.12 age confidence
lefthook 2.1.12 → 2.1.16 age confidence
pnpm (source) 12.4.1 → 12.8.2 age confidence
publint (source) 0.3.24 → 0.3.25 age confidence
vite (source) 8.3.0 → 8.3.2 age confidence
vite (source) 8.3.1 → 8.3.2 age confidence

Release Notes

biomejs/biome (@​biomejs/biome)

v2.5.15

Compare Source

Patch Changes
  • #​10634 b436ba0 Thanks @​subaru-hello! - Added the new nursery rule noReactObjectTypeAsDefaultProp, which disallows array, object, and function values as default props in React components.

    For example, the following snippet triggers the rule.

    function Component({ items = [] }) {
      return items;
    }
  • #​11956 faa8b37 Thanks @​dyc3! - Added the nursery rule noSvelteExportLet, which disallows declaring Svelte component props with the legacy export let syntax. Use the $props() rune instead.

    <script>
      export let name;
    </script>
  • #​10816 1b9479e Thanks @​Th3S4mur41! - Added a new nursery rule useLogicalProperties that enforces the use of logical properties in CSS, promoting better internationalization and accessibility practices. The rule supports a direction option with "ltr" as the default and "rtl" as the alternative.
    This is a first rule covering parts of #​9034

    {
      "linter": {
        "rules": {
          "nursery": {
            "useLogicalProperties": {
              "level": "warn",
              "options": {
                "direction": "rtl"
              }
            }
          }
        }
      }
    }
  • #​11960 1fdb5c2 Thanks @​dyc3! - Added the nursery rule useSvelteKitRuneImports, which reports imports from the deprecated $app/stores module and suggests $app/state instead.

    import { page } from "$app/stores";
  • #​11723 3b429d1 Thanks @​m1handr! - Fixed #​11656: noAstroSetHtmlDirective now correctly reports set:html directives inside Astro template expressions.

  • #​12023 874d5ae Thanks @​codspeed! - Improved the performance of the HTML formatter up to 4x.

  • #​11761 a3462fe Thanks @​saberoueslati! - Fixed #​11351: useSimplifiedLogicExpression no longer reports boolean literals on the right side of || and && outside boolean contexts, because removing them can change the result of the expression. For example, y = x || false is no longer reported, while if (x || false) still is.

  • #​11732 ff4c4dd Thanks @​dyc3! - Added the nursery rule noMeaninglessVoidOperator, which reports unnecessary uses of void, such as void log() when log returns void. The rule allows discarded call results, thenables, void 0, and calls returning never.

  • #​11975 40dd3fb Thanks @​ematipico! - Fixed the indentation of multiline Astro expressions, in templates and attribute values, when running biome check --write. Biome now formats Astro expressions with biome format too, and places them at the column of the surrounding markup.

     <div>
     	{items.map((item) => (
    -	<span>{item}</span>
    -))}
    +		<span>{item}</span>
    +	))}
     </div>
  • #​12016 09d4000 Thanks @​codspeed! - Improved the performance of indexing and analysis of big files up to 2x. The improvements are mostly visible in projects that make use of project and types lint rules.

  • #​11750 089bde0 Thanks @​dyc3! - Added the nursery rule useStrictBooleanExpressions, which reports ambiguous truthiness checks such as if (value) when value has type number | undefined. Non-nullable strings and numbers and nullable objects are allowed; the rule has no options.

  • #​11494 ad5b362 Thanks @​jp-knj! - Added the nursery rule noAstroConflictingSetDirectives, which reports Astro elements with multiple content sources, such as set:html, set:text, and child content.

    For example, <div set:html={html}>content</div> triggers the rule.

  • #​11878 84d1b3b Thanks @​dyc3! - Fixed #​11748: useExhaustiveSwitchCases now reports missing cases for values created with the mapping overload of Array.from, including arrays imported from another module.

  • #​11802 7d1f37e Thanks @​dyc3! - Tailwind classes will now be detected in Svelte, Vue, and Astro class attribute expressions that don't use a class merging function.

  • #​11910 9e50ea2 Thanks @​ematipico! - Fixed #​11504, a regression where Biome would silently ignore errors in the configuration file. Now errors are correctly retained and checked before executing any command.

  • #​11921 d568632 Thanks @​hirehamir! - Fixed #​10846: when plugins fail to load, Biome now prints each failing plugin's path on its own line, instead of concatenating bare messages like Cannot read file.Cannot read file..

  • #​11930 82ea5a6 Thanks @​dyc3! - Fixed #​11927: The HTML formatter no longer duplicates comments around Svelte blocks. This affected a comment after a block such as {#if} or {#each} at the end of an element, and a comment on the same line as the last element inside a block, before {:else}, {/if}, or a similar tag.

  • #​11931 0cc46d8 Thanks @​dyc3! - Fixed the indentation of comments at the end of a Svelte block's contents. A comment before {:else}, {:then}, {/if}, or a similar tag is now indented with the block's contents instead of with the tag.

     {#if condition}
     	<span>Text</span>
    -<!-- comment -->
    +	<!-- comment -->
     {/if}
  • #​12031 ef0edd4 Thanks @​dyc3! - Fixed #​12027: Biome's test rules no longer mistake regular method calls named test, it, or describe for tests. For example, useValidTestTitle used to report the following regular expression check as a test with an invalid title:

    const isComment = /^\s*#/.test(line);
  • #​11959 8477e61 Thanks @​dyc3! - Fixed #​11950: noUnusedVariables now reports arrow functions with expression bodies that only reference themselves, such as let h = () => h();.

  • #​11915 3260602 Thanks @​ematipico! - Fixed #​11841, where suppression comments had no effect on some parts of HTML-ish files and on snippets embedded in JavaScript files.

    Now the following suppression works as expected:

    <!-- biome-ignore lint/correctness/noUndeclaredVariables: intentionally external -->
    <div :title="missingValue"></div>
  • #​11952 b51040e Thanks @​dyc3! - Fixed #​11951: the GritQL formatter no longer inserts a space after a within pattern without an until clause.

    -$arg <: within `bar($_)` ,
    +$arg <: within `bar($_)`,
  • #​11794 429cf95 Thanks @​dyc3! - Added the nursery rule noTailwindRawColors for JavaScript and HTML. It disallows Tailwind palette colors such as bg-pink-500 and text-white, encouraging design system color utilities such as bg-primary.

  • #​11837 f5e249b Thanks @​dyc3! - Fixed #​11836: biome check --write no longer adds invalid parentheses around Svelte {@const} declarations when experimental HTML support and formatting are enabled.

  • #​11978 8be0b9e Thanks @​dyc3! - Fixed #​11817: Biome no longer crashes when its output is piped to a program that exits early, such as head. Output to the closed pipe is now discarded and Biome exits normally.

  • #​11868 3841c26 Thanks @​ematipico! - Fixed #​8986: Biome's language server now scopes all watched-file patterns to each workspace folder, falling back to the deprecated rootUri when no workspace folders are provided. Clients without relative-pattern support receive compatible absolute glob patterns.

  • #​11928 0015681 Thanks @​dyc3! - Restricted access to the Unix daemon socket to the user running Biome. The socket now lives in a biome-daemon directory inside Biome's cache directory that only this user can access, and the socket itself has mode 0600.

  • #​11835 589ca1a Thanks @​dyc3! - Updated useReactCompiler: Biome now reports React Compiler diagnostics regardless of the React version declared in package.json.

  • #​11907 b7d9037 Thanks @​posido! - Fixed withastro/compiler-rs#194: the HTML parser no longer treats a regex literal that starts with > as the end of a self-closing tag. Astro frontmatter such as const escaped = s.replace(/>/g, "&gt;"); no longer swallows the closing --- fence, and the same regex inside a template expression no longer runs past its closing }. A regex literal after a keyword such as return, as in return />'/.test(s), is now recognized too.

  • #​12021 59cc595 Thanks @​dyc3! - Type inference performance has been significantly improved. Some popular libraries like Zod, Valibot, Arktype, Effect, Kysely, and Drizzle have gained a ~2-240x speedup in our benchmarks. This improvement affects all rules that use type information.

  • #​12044 c73fb91 Thanks @​dyc3! - Fixed #​12042: the HTML formatter no longer removes the space between text and an inline element on the next line when it joins the lines.

    - <p>a <em>b</em> c<u>d</u></p>
    + <p>a <em>b</em> c <u>d</u></p>
  • #​11965 f90bf38 Thanks @​ematipico! - Fixed module resolution in long-running workspaces so imports reflect package manifest and TypeScript path-mapping changes without requiring the importing file to be edited.

  • #​11860 0884e29 Thanks @​dyc3! - Removed the attributes and functions options from the nursery rule noTailwindArbitraryValue. The rule now uses the same Tailwind detection as useTailwindShorthandClasses.

  • #​11969 865cd30 Thanks @​AlbinoGeek! - Fixed #​11962: noUnknownTypeSelector no longer reports view transition names inside view transition pseudo-elements, such as page in ::view-transition-group(page).

  • #​11914 06ff47b Thanks @​dyc3! - Fixed #​11897: the safe fix for noUselessStringConcat now escapes embedded double quotes when combining literals, preserving valid JavaScript and existing escape sequences.

  • #​11997 af7825f Thanks @​github-actions! - The noRestrictedDependencies rule has been updated with new module replacement data, it should now detect for more relevant replacements.

  • #​11827 31bb662 Thanks @​dfedoryshchev! - Fixed #​11566: useNamingConvention no longer reports a namespace declared inside declare global or inside an external module declaration. Both positions are documented as always ignored, and the rule offered a safe fix, so biome check --write renamed the declaration:

    export {}
    declare global {
        // no longer renamed to `Jsx`
        namespace JSX {}
    }
  • #​11814 23ba25f Thanks @​siketyan! - Fixed type inference through generic type aliases that instantiate another generic type with a nested generic argument, such as type Nested<T> = Box<Wrapper<T>>. Type-aware rules now resolve members of such types:

    declare const nested: Nested<number>;
    // noUnnecessaryConditions now reports that `??` is unnecessary.
    const inner = nested.value.inner ?? 1;
  • #​11908 dd5a5ce Thanks @​siketyan! - Fixed #​11880: Biome no longer misparses a << expression followed by a later >>> as TypeScript type arguments. For example, const mask = 1 << bits followed by const m = mask >>> 0 on the next line now parses correctly.

  • #​11882 28c817d Thanks @​mikehasa! - Fixed a bug in noOctalEscape where the safe fix could silently change a string's value. A legacy octal escape is at most two digits when the leading digit is 4-7, so "\751" is "\75" + "1" (i.e. "=1") but was rewritten to the single character ǩ; it is now rewritten to "\x3d1".

  • #​11861 81b0adb Thanks @​Netail! - Added the new nursery rule noSelfImport, which forbids a module from importing itself.

    // foo.js
    import foo from "./foo.js";
  • #​12041 5e14509 Thanks @​ematipico! - Fixed a stack overflow in type-aware lint rules, such as noMisusedPromises and noFloatingPromises, when generic types in files that import each other reference one another in their type parameters.

    // entity.ts
    import type { Repository } from "./repository";
    export interface Entity<R extends Repository<any> = Repository<any>> {}
    
    // repository.ts
    import type { Entity } from "./entity";
    export interface Repository<E extends Entity<any> = Entity<any>> {}
  • #​11838 9bbff0c Thanks @​dyc3! - Added the nursery rule usePromiseRejectErrors, which requires Error objects as Promise rejection reasons.

    Promise.reject("Request failed");
    new Promise((resolve, reject) => reject(42));
  • #​11917 717db8c Thanks @​dyc3! - Added the nursery rule noMisplacedListElements for HTML and JSX, which requires <li> elements with an HTML element parent to be children of <ul>, <ol>, or <menu>. For example, <div><li>Item</li></div> is invalid.

  • #​11919 8d0b990 Thanks @​dyc3! - Fixed #​11899: disabling a domain no longer disables rules that also belong to another enabled domain. For example, with "domains": { "react": "all", "next": "none" }, useExhaustiveDependencies and useHookAtTopLevel are now enabled.
    Rules enabled explicitly in the configuration also stay enabled when one of their domains is set to "none".

  • #​11814 23ba25f Thanks @​siketyan! - Fixed #​11810 and #​11813: type-aware rules such as noUnnecessaryConditions and noFloatingPromises no longer take several seconds when a member is accessed on a recursive generic type alias, such as react-hook-form's FieldPathValue or zustand's Mutate.

  • #​11983 cc39794 Thanks @​AlbinoGeek! - Fixed #​11939: the fix of useRegexLiterals no longer escapes a slash that is already escaped. new RegExp("\\/") is now fixed to /\// instead of the invalid /\\//.

  • #​11869 3a21c80 Thanks @​ematipico! - Fixed #9105: vcs.useIgnoreFile now evaluates parent directory patterns when matching child paths, preserving re-included directories such as !/src while ignoring their excluded siblings.

  • #​11875 2cdd220 Thanks @​dyc3! - Fixed #​11867: noUndeclaredVariables incorrectly reported Vue slot props declared with v-slot or its # shorthand, including destructured props.

  • #​12021 59cc595 Thanks @​dyc3! - Type inference accuracy has been improved significantly. More global types, like Array, Map, Set, etc., are now fully defined. This should decrease false positives on all typed rules, since less types will be unknown.

  • #​11929 aef690d Thanks @​Th3S4mur41! - Fixed noUnknownProperty to recognize the frame-sizing CSS property.

  • #​12022 6233eb2 Thanks @​dyc3! - Fixed #​12020: the HTML parser now reports an error for a mismatched closing tag like the </span> in <p>two</span></p>. Previously, it accepted </span> as the end of <p> because span contains the letter p, and the formatter deleted everything after it. HTML tag names are matched case-insensitively, so <DIV></div> is no longer reported as mismatched.

    A closing tag with no opening tag at the top level of a file, like the second </p> in <p>a</p></p><p>b</p>, is now also reported as an error, instead of the formatter deleting it and everything after it.

  • #​12037 48cdbb8 Thanks @​ff1451! - Fixed #​11898: noUselessReturn no longer offers a safe fix for a return; that is the body of an unbraced if, else, or label, because removing it produced invalid code. The safe fix now also keeps comments placed before or after the removed return;.

    function foo() {
      // Still reported, but the return is no longer removed
      if (aborted) return;
    }
  • #​12030 4ff83dd Thanks @​ematipico! - Fixed #​9155: Biome no longer reports a parse error for typed slot props in Vue files, such as v-slot="{ value }: { value: ValueType }". Types used in slot props annotations are now correctly detected as used by noUnusedVariables.

  • #​11955 088164f Thanks @​dyc3! - Fixed #​11946: noUnreachable and useGetterReturn now recognize while and do...while loops with truthy literal conditions as infinite unless control flow exits the loop.

  • #​11958 6964bfc Thanks @​erenbati! - Fixed #​11924: noFocusedTests no longer reports chained method calls such as builder.image(url).fit("max") as focused tests.

  • #​11908 dd5a5ce Thanks @​siketyan! - Fixed parsing of left shifts between TypeScript instantiation expressions. Biome now parses f<T> << f<T> as a left shift of two instantiation expressions, matching TypeScript, instead of reporting a parse error.

  • #​11877 5a53b2c Thanks @​dyc3! - Fixed #​11278: noUnnecessaryConditions no longer incorrectly reports optional chaining on RegExp.exec() results, including patterns created with new RegExp(). Biome now infers the nullable RegExpExecArray | null return type, preserving necessary checks such as new RegExp(pattern).exec(input)?.[1].

  • #​11906 b87822d Thanks @​dyc3! - Fixed #​11900: useForOf no longer reports loops that update their index inside the body, including i += 1 and argv[++i].

  • #​11834 f89dd4f Thanks @​dyc3! - Fixed incorrect type inference when generic parameters are reused across inherited types or swapped in recursive types.

v2.5.14

Compare Source

Patch Changes
  • #​9022 0d49e24 Thanks @​dyc3! - Added the nursery rule noReturnInFinally. This rule disallows return statements in Promise.prototype.finally() callbacks, including inside nested blocks and conditional branches. Returns in nested functions are ignored by the rule.

    // Invalid: return in finally callback
    Promise.resolve(1).finally(() => { return 2 })
    
    // Valid: no return in finally callback
    Promise.resolve(1).finally(() => { console.log(2) })

    Returning a value from a Promise.prototype.finally() callback does not replace the original promise's fulfillment value, which can be confusing. Returned promises and thenables are awaited, and their rejection rejects the resulting promise.

  • #​11754 71eaa0d Thanks @​griff-rees! - Added the nursery rule noSvelteAtDebugTags, which disallows Svelte's {@debug} tag.

    <!-- Invalid: leftover debugging tag -->
    {@debug user}

    The {@debug} tag is a debugging aid and should be removed once you no longer need it, as it should not remain in production code. The rule provides a safe fix that removes the tag.

  • #​11725 5eb5f09 Thanks @​m1handr! - Added the nursery rule useValidTestTitle, which enforces valid titles for unit test cases and suites.

  • #​11735 9bd70c7 Thanks @​ematipico! - Fixed #​8471: source.fixAll.biome ignored formatter.formatWithErrors. It now applies safe fixes without formatting files that have parse errors when the option is disabled.

  • #​11715 f05a3c3 Thanks @​ematipico! - Fixed #​7771: Grit plugins that use sequential no longer panic when Biome processes files.

  • #​11766 c2542c6 Thanks @​dyc3! - Fixed validation of readonly and accessor modifiers: combining them in either order now reports that they cannot be used together.

  • #​11461 22e9966 Thanks @​FoundDream! - Fixed #​11423: Multiline template interpolations now preserve the indentation of their closing brace when the source indentation is not a multiple of tabWidth.

     const value = `
          ${
            condition
              ? "yes"
              : "no"
    -}
    +     }
     `;
  • #​11766 c2542c6 Thanks @​dyc3! - Fixed #​11763: TypeScript class members using override accessor, such as override accessor value = 1, now parse correctly. The reversed order, accessor override, now reports that override must precede accessor.

  • #​11790 17d0ff0 Thanks @​ematipico! - Fixed #​10248: noUselessFragments now allows fragments with props in Astro files, such as <Fragment slot="name">{text}</Fragment> inside template expressions.

  • #​11777 7ee3a6c Thanks @​ematipico! - Fixed #​7573: added the requireExplicitCase option to useExhaustiveSwitchCases. When set to true, the rule reports missing cases even when the switch has a default clause, so you can keep a runtime fallback while checking that every value in the union has its own case. The option defaults to false.

  • #​11751 d37f24b Thanks @​ematipico! - Fixed #​8347: the fix from useConsistentArrowReturn now parenthesizes returned expressions that begin with object literals before removing the arrow function body braces, preventing invalid output for expressions such as object property access.

  • #​11784 46e8912 Thanks @​dyc3! - Fixed #​11782: noUndeclaredCustomProperties could hang while checking stylesheets imported by JavaScript modules with many shared dependencies.

  • #​11731 1534885 Thanks @​ematipico! - Fixed #​7984: The fix from useSimplifiedLogicExpression now preserves line breaks in multiline conditions with line comments, preventing the right-hand side condition from being commented out.

  • #​11735 9bd70c7 Thanks @​ematipico! - Fixed #​7304: the HTML formatter now preserves authored segment breaks between CJK characters, and next to CJK punctuation, instead of replacing them with spaces.

     <div lang="zh-Hant-TW">
    -  這個段落是那麼長, 在一行寫不行。
    +  這個段落是那麼長,
    +  在一行寫不行。
     </div>
  • #​11749 ff992a1 Thanks @​ematipico! - Fixed #​11747: formatting and checking large parenthesized object expressions no longer exhibit quadratic slowdowns.

  • #​11736 1dd1fc4 Thanks @​dyc3! - Fixed #​8177: code actions no longer modify the wrong part of Vue, Svelte, or Astro files when experimental full HTML support is disabled.

  • #​11743 3835945 Thanks @​santichausis! - Fixed #​10247: biome check --write/biome lint --write now correctly writes fixes for code inside an HTML attribute expression (for example a Svelte onclick={...} handler, or a mustache expression like {count}), instead of silently reporting the diagnostic as fixable and applying nothing.

    For example, running biome lint --write --unsafe for useBlockStatements (an unsafe fix) on this Svelte component used to leave the file unchanged:

    <button onclick={() => { if (open) close(); }}>Close</button>
  • #​11740 8ea8b4a Thanks @​dyc3! - Fixed #​11453: useConsistentTestIt now updates imports alongside calls, preserving the original export through an alias. The rule ignores locally declared functions and withholds fixes when the preferred name would conflict with another binding or global reference.

  • #​11355 27177ca Thanks @​dyc3! - Fixed the HTML formatter incorrectly applying native HTML element formatting to PascalCase component names such as <Ul> and <Body> in Vue, Svelte, and Astro files.

    -<Body>
    -  <div>content</div>
    -</Body>
    +<Body><div>content</div></Body>
  • #​11355 27177ca Thanks @​dyc3! - Fixed the HTML formatter incorrectly applying SVG block formatting to unknown elements whose names matched SVG element names.

    -<foreignobject>
    -  <div>content</div>
    -</foreignobject>
    +<foreignobject><div>content</div></foreignobject>
  • #​11741 fc69047 Thanks @​dyc3! - Fixed #​8893: useImportExtensions no longer suggests adding .ts to .jsx imports when a colocated .d.ts file provides type declarations.

  • #​11642 c87341c Thanks @​dyc3! - Added the nursery rule useConsistentFunctionStyle, which requires a consistent style for defining functions.

    By default, the rule reports the following declaration because it requires a function expression assigned to a variable:

    function greet() {
        return "Hello";
    }
  • #​11770 ddfd622 Thanks @​dyc3! - Fixed #​8980: suppression comments targeting the entire assist category are now respected, including biome-ignore-all assist when running check.

  • #​11792 7a4b895 Thanks @​dyc3! - Fixed dashed utility base names in the Tailwind parser, including border-bs, font-features, and scrollbar-thumb. Classes such as min-inline-[12rem] now preserve the complete base name and parse the arbitrary value separately.

  • #​11739 1fc17e3 Thanks @​Netail! - The rule useIncludes now also reports lastIndexOf() comparisons and some() calls with a strict-equality callback.

    arr.lastIndexOf(x) !== -1
    
    arr.some(item => item === x)
  • #​11735 9bd70c7 Thanks @​ematipico! - Fixed #​6888. GritQL plugins can now use contains on import-clause metavariables such as $clause in import $clause from "module" patterns.

  • #​11790 17d0ff0 Thanks @​ematipico! - Fixed #​11786: useAnchorContent now reports anchors without accessible content in HTML, Astro, Vue, and Svelte even when they have an aria-label, aria-labelledby, or title attribute, matching JSX behavior.

  • #​11651 a9c4aa0 Thanks @​saberoueslati! - Added the new nursery rule noVueUndeclaredDirectives, which reports custom Vue directives that are not declared by a <script setup> binding, the component's directives option, or the rule's globals option. Closes #​11478.

    <template>
      <!-- v-highlight is not declared anywhere -->
      <div v-highlight></div>
    </template>

    Aliased named imports in single-file components are now tracked under their local name, so noUndeclaredVariables recognizes vHighlight in import { highlight as vHighlight } from "./directives".

  • #​11715 f05a3c3 Thanks @​ematipico! - Fixed #​7795. The noJsxLiterals rule now ignores surrounding whitespace when matching literals against allowedStrings.

  • #​11780 99c7049 Thanks @​ematipico! - Fixed false positives in useExhaustiveSwitchCases when numeric cases use different spellings of the same value. For example, case 0x1 now covers the numeric literal type 1.

  • #​11720 c7c4e2b Thanks @​ematipico! - Fixed #​7880: noUselessStringConcat no longer reports literal concatenations split across multiple lines when a numeric literal ends the chain.

  • #​11355 27177ca Thanks @​dyc3! - Improved performance of the HTML formatter for documents that contain many HTML-native or SVG-native tags.

  • #​11720 c7c4e2b Thanks @​ematipico! - Fixed #​7949: useReadonlyClassProperties now reports static class properties that are never reassigned.

  • #​11751 d37f24b Thanks [@​ematipico](https://redirec

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@coderabbitai

coderabbitai Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 696a3ad6-9896-41eb-aa6e-4db1b65474dd

📥 Commits

Reviewing files that changed from the base of the PR and between 1b3d82d and a777f11.

⛔ Files ignored due to path filters (2)
  • playground/pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • package.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

package.jsonのpackageManager指定をpnpm@12.4.1からpnpm@12.6.0に更新しました。

Changes

パッケージマネージャー指定

Layer / File(s) Summary
pnpmバージョン指定の更新
package.json
packageManagerのバージョン指定をpnpm@12.6.0に変更しました。

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to a777f

No concrete merge-blocking risk is established by the available evidence.

Architecture Summary

Architecture risk: 🔵 Low · up to a777f

The change affects 1 system.

Changed systems: package.json

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — package.json (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in package.json: packageManagerのバージョン指定をpnpm@12.4.1からpnpm@12.6.0に変更しました。
🚥 Pre-merge checks | ✅ 4 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Description check ⚠️ Warning 説明には依存関係の更新情報がありますが、テンプレートの「Related issue」「Breaking changes / Deprecations」「Checklist」が不足しています。また、説明内の更新内容が変更概要と一致していません。 実際の変更内容に合わせて説明を修正してください。「Summary」「Related issue」「Breaking changes / Deprecations」(該当しない場合はN/A)を記載し、Checklistの各項目の実施状況を示してください。記載するパッケージ名とバージョンを実際の変更に一致させてください。
Description check ⚠️ Warning 説明には依存関係の更新情報がありますが、テンプレートの「Related issue」「Breaking changes / Deprecations」「Checklist」が不足しています。また、説明内の更新内容が変更概要と一致していません。 実際の変更内容に合わせて説明を修正してください。「Summary」「Related issue」「Breaking changes / Deprecations」(該当しない場合はN/A)を記載し、Checklistの各項目の実施状況を示してください。記載するパッケージ名とバージョンを実際の変更に一致させてください。
✅ Passed checks (4 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed タイトルは依存関係の更新を示しており、変更内容に関連しています。ただし、更新対象を特定していません。
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

うさぎが跳ねて、版を見つめる
pnpmの数字が新しくなる
package.jsonに小さく記す
にんじん片手に更新を祝う
月明かりの下、耳を揺らす

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

WASM Binary Size

File Size
comprs.wasm32-wasi.debug.wasm 2258 KB

@derodero24
derodero24 force-pushed the renovate/npm-dependencies-(non-major) branch from f452593 to a777f11 Compare September 27, 2026 21:44
@github-actions

Copy link
Copy Markdown
Contributor

WASM Binary Size

File Size
comprs.wasm32-wasi.debug.wasm 2258 KB

derodero24 added a commit that referenced this pull request Oct 3, 2026
* ci: run the full native matrix for napi-rs toolchain changes

The changes job runs every build target, and with them the release
packaging dry run over all eight platform packages, only when a pull
request touches crates/, npm/, scripts/, the Cargo files or the
workflows. @napi-rs/cli drives every native build and the packaging,
but its updates land in package.json and pnpm-lock.yaml, so they were
built for Linux alone. Renovate's open PR #533 moves the CLI from 3.9.1
to 3.10.5 in the lockfile only; the 3.9.1 update itself broke the first
two 2.0.2 publish attempts (#526, #529).

Also run the full matrix when a changed line in package.json,
pnpm-lock.yaml or pnpm-workspace.yaml names napi as a word: the
@napi-rs packages, including those the CLI pulls in, and the napi
scripts. Treating those files as native outright would send every npm
update, the weekly Renovate group included, through eight builds and
the macOS and Windows test legs, although nothing in them reaches a
binary. The narrower check can miss a toolchain change that names no
napi package, such as a transitive dependency of the CLI moving on its
own, or an edit to the targets in the napi field, which comes with its
npm/ package anyway. develop runs the full matrix after every merge,
so such a change cannot reach a release untested.

The diff is captured before grep -q reads it. Piped straight in, grep
stops at the first match and, under pipefail, the git diff it cuts off
would turn a match into a miss on a large lockfile diff.

Refs #575

* ci(renovate): pin the napi-rs toolchain and hold flate2

Renovate treated the packages that build and package comprs like any
other dependency. @napi-rs/cli sat behind a ^3.7.1 range in the
automerged non-major npm group, so a new CLI arrived as a lockfile-only
change and merged once CI passed; 3.9.1 came that way and broke the
first two 2.0.2 publish attempts (#526, #529). Now that the napi crates
are no longer held (#518), their minor and patch updates would be
automerged with the other crates as well. The cargo automerge rule also
overrode the deliberate flate2 =1.1.9 pin (#509): open PR #534 rewrites
it to =1.1.10, and only a test that happens to catch another behaviour
change in 1.1.10 keeps it from merging.

- Group @napi-rs/* and the napi, napi-derive and napi-build crates as
  "napi-rs toolchain", majors included, and never automerge it. The
  rule follows the generic ones because later rules win.
- Pin @napi-rs/cli to the locked 3.9.1 and keep the @napi-rs packages
  pinned, so a toolchain update shows in the reviewed package.json
  diff. The crates keep their major-version requirements; pinning
  them would turn "3" into "=3.13.0".
- Allow flate2 only up to 1.1.9 until #509 is resolved.
- Refresh the lock files once a month, without automerge. The workflow
  runs Renovate weekly, so the schedule covers the first seven days of
  the month; the built-in monthly schedule, before 4am on the 1st,
  would never coincide with a run. Cargo.lock gets its own PR through
  the rust-dependencies group. A refresh has no release timestamp to
  age, so it opts out of the minimum release age, which would keep
  its stability check pending for good.
- Hold GitHub Actions updates, digests included, for 3 days instead of
  0 (#385): retargeted tags are how the tj-actions/changed-files
  compromise reached even SHA-pinned workflows, as ordinary digest
  updates. Renovate ages a digest update by the release its tag
  resolves to, but the update carries no timestamp of its own, and
  with the default timestamp-required behaviour its branch would never
  pass the stability check or automerge. timestamp-optional keeps the
  3-day hold at lookup time and lets the branch merge afterwards.

renovate-config-validator 44.115.13, the Renovate release that last
ran on this repository, accepts the config. A local lookup with it
puts @napi-rs/cli 3.10.5 and napi 3.14.0, napi-derive 3.6.10 and
napi-build 2.6.0 in the napi-rs toolchain branch and no longer
proposes flate2 1.1.10, which the current config offers for both
Cargo.toml and the fuzz crate.

Closes #575

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRi2Qu5rPjQSDBcR8xmkSS
@derodero24
derodero24 force-pushed the renovate/npm-dependencies-(non-major) branch from a777f11 to 5f0fb8a Compare October 4, 2026 22:07
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

WASM binary size

browser/comprs-wasm_bg.wasm Bytes Budget
Raw 1,871,242 1,925,000
gzip (level 9) 794,041 815,000
brotli (quality 11) 547,277 -

Within budget.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants