fix(deps): update all non-major dependencies #117
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^2.1.3
->^2.2.0
2.1.3
->2.2.0
^4.20250807.0
->^4.20250821.0
^1.11.2
->^1.11.3
^2.5.1
->^2.6.0
^0.38.18
->^0.38.21
10.14.0
->10.15.0
^4.28.1
->^4.32.0
Release Notes
biomejs/biome (@biomejs/biome)
v2.2.0
Compare Source
Minor Changes
#5506
1f8755b
Thanks @sakai-ast! - ThenoRestrictedImports
rule has been enhanced with a newpatterns
option. This option allows for more flexible and powerful import restrictions using gitignore-style patterns.You can now define patterns to restrict entire groups of modules. For example, you can disallow imports from any path under
import-foo/
except forimport-foo/baz
.Invalid examples
Valid examples
Additionally, the
patterns
option introducesimportNamePattern
to restrict specific import names using regular expressions.The following example restricts the import names that match
x
,y
orz
letters from modules underimport-foo/
.Invalid examples
Valid examples
Furthermore, you can use the
invertImportNamePattern
boolean option to reverse this logic. When set to true, only the import names that match theimportNamePattern
will be allowed. The following configuration only allows the import names that matchx
,y
orz
letters from modules underimport-foo/
.Invalid examples
Valid examples
#6506
90c5d6b
Thanks @nazarhussain! - Allow customization of the sort order for different sorting actions. These actions now support a sort option:assist/source/useSortedKeys
now has asortOrder
optionassist/source/useSortedAttributes
now has asortOrder
optionassist/source/organizeImports
now has anidentifierOrder
optionFor each of these options, the supported values are the same:
natural
. Compares two strings using a natural ASCII order. Uppercase letters come first (e.g.A < a < B < b
) and number are compared in a human way (e.g.9
<10
). This is the default value.lexicographic
. Strings are ordered lexicographically by their byte values. This orders Unicode code points based on their positions in the code charts. This is not necessarily the same as “alphabetical” order, which varies by language and locale.#7159
df3afdf
Thanks @ematipico! - Added the new ruleuseBiomeIgnoreFolder
. Since v2.2, Biome correctly prevents the indexing and crawling of folders.However, the correct pattern has changed. This rule attempts to detect incorrect usage, and promote the new pattern:
#6989
85b1128
Thanks @arendjr! - Fixed minor inconsistencies in howfiles.includes
was being handled.Previously, Biome sometimes failed to properly ignore the contents of a folder if you didn't specify the
/**
at the end of a glob pattern. This was unfortunate, because it meant we still had to traverse the folder and then apply the glob to every entry inside it.This is no longer an issue and we now recommend to ignore folders without using the
/**
suffix.#7118
a78e878
Thanks @avshalomt2! - Added support for.graphqls
files. Biome can now format and lint GraphQL files that have the extension.graphqls
#6159
f02a296
Thanks @bavalpey! - Added a new option to Biome's JavaScript formatter,javascript.formatter.operatorLinebreak
, to configure whether long lines should be broken before or after binary operators.For example, the following configuration:
Will cause this JavaScript file:
to be formatted like this:
#7137
a653a0f
Thanks @ematipico! - Promoted multiple lint rules from nursery to stable groups and renamed several rules for consistency.Promoted rules
The following rules have been promoted from nursery to stable groups:
CSS
noImportantStyles
to thecomplexity
group.noUnknownAtRules
to thesuspicious
group.GraphQL
useGraphqlNamedOperations
to thecorrectness
group.useGraphqlNamingConvention
to thestyle
group.JavaScript/TypeScript
noExcessiveLinesPerFunction
to thecomplexity
group.noImplicitCoercions
to thecomplexity
group.useIndexOf
to thecomplexity
group.noGlobalDirnameFilename
to thecorrectness
group.noNestedComponentDefinitions
to thecorrectness
group.noProcessGlobal
to thecorrectness
group.noReactPropAssignments
to thecorrectness
group.noRestrictedElements
to thecorrectness
group.noSolidDestructuredProps
to thecorrectness
group.useJsonImportAttributes
to thecorrectness
group.useParseIntRadix
to thecorrectness
group.useSingleJsDocAsterisk
to thecorrectness
group.useUniqueElementIds
to thecorrectness
group.noAwaitInLoops
to theperformance
group.noUnwantedPolyfillio
to theperformance
group.useGoogleFontPreconnect
to theperformance
group.useSolidForComponent
to theperformance
group.noMagicNumbers
to thestyle
group.useConsistentObjectDefinitions
to thestyle
group.useExportsLast
to thestyle
group.useGroupedAccessorPairs
to thestyle
group.useNumericSeparators
to thestyle
group.useObjectSpread
to thestyle
group.useReadonlyClassProperties
to thestyle
group.useSymbolDescription
to thestyle
group.useUnifiedTypeSignatures
to thestyle
group.noBitwiseOperators
to thesuspicious
group.noConstantBinaryExpressions
to thesuspicious
group.noTsIgnore
to thesuspicious
group.noUnassignedVariables
to thesuspicious
group.noUselessRegexBackrefs
to thesuspicious
group.noUselessStringEscapes
to thesuspicious
group.useConsistentIterableCallbackReturnValues
to thesuspicious
group.useStaticResponseMethods
to thesuspicious
group.Renamed rules
The following rules have been renamed during promotion. The migration tool will automatically update your configuration:
noAwaitInLoop
tonoAwaitInLoops
.noConstantBinaryExpression
tonoConstantBinaryExpressions
.noDestructuredProps
tonoSolidDestructuredProps
.noImplicitCoercion
tonoImplicitCoercions
.noReactPropAssign
tonoReactPropAssignments
.noUnknownAtRule
tonoUnknownAtRules
.noUselessBackrefInRegex
tonoUselessRegexBackrefs
.useAdjacentGetterSetter
touseGroupedAccessorPairs
.useConsistentObjectDefinition
touseConsistentObjectDefinitions
.useConsistentResponse
touseStaticResponseMethods
.useForComponent
touseSolidForComponent
.useJsonImportAttribute
touseJsonImportAttributes
.useNamedOperation
touseGraphqlNamedOperations
.useNamingConvention
touseGraphqlNamingConvention
.useUnifiedTypeSignature
touseUnifiedTypeSignatures
.Configuration files using the old rule names will need to be updated. Use the migration tool to automatically update your configuration:
#7159
df3afdf
Thanks @ematipico! - Added the new rulenoBiomeFirstException
. This rule prevents the incorrect usage of patterns insidefiles.includes
.This rule catches if the first element of the array contains
!
. This mistake will cause Biome to analyze no files:#6923
0589f08
Thanks @ptkagori! - Added Qwik Domain to BiomeThis release introduces Qwik domain support in Biome, enabling Qwik developers to use Biome as a linter and formatter for their projects.
useJsxKeyInIterable
noReactSpecificProps
#6989
85b1128
Thanks @arendjr! - Fixed #6965: Implemented smarter scanner for project rules.Previously, if project rules were enabled, Biome's scanner would scan all dependencies regardless of whether they were used by/reachable from source files or not. While this worked for a first version, it was far from optimal.
The new scanner first scans everything listed under the
files.includes
setting, and then descends into the dependencies that were discovered there, including transitive dependencies. This has three main advantages:vcs.useIgnoreFile
is enabled,.gitignore
gets respected as well. Assuming you have folders such asbuild/
ordist/
configured there, those will be automatically ignored by the scanner.The change in the scanner also has a more nuanced impact: Previously, if you used
files.includes
to ignore a file in an included folder, the scanner would still index this file. Now the file is fully ignored, unless you import it.As a user you should notice better scanner performance (if you have project rules enabled), and hopefully you need to worry less about configuring
files.experimentalScannerIgnores
. Eventually our goal is still to deprecate that setting, so if you're using it today, we encourage you to see which ignores are still necessary there, and whether you can achieve the same effect by ignoring paths usingfiles.includes
instead.None of these changes affect the scanner if no project rules are enabled.
#6731
d6a05b5
Thanks @ematipico! - The--reporter=summary
has been greatly enhanced. It now shows the list of files that contains violations, the files shown are clickable and can be opened from the editor.Below an example of the new version:
#6896
527db7f
Thanks @ematipico! - Added new functions to the@biomejs/wasm-*
packages:fileExists
: returns whether the input file exists in the workspace.isPathIgnored
: returns whether the input path is ignored.updateModuleGraph
: updates the internal module graph of the input path.getModuleGraph
: it returns a serialized version of the internal module graph.scanProject
: scans the files and directories in the project to build the internal module graph.#6398
d1a315d
Thanks @josh-! - Added support for tracking stable results in user-provided React hooks that return objects touseExhaustiveDependencies
to compliment existing support for array return values. For example:This will allow the following to be validated:
#7201
2afaa49
Thanks @Conaclos! - Implemented #7174.useConst
no longer reports variables that are read before being written.Previously,
useConst
reported uninitialised variables that were read in an inner function before being written, as shown in the following example:This can produce false positives in the case where
f
is called beforev
has been written, as in the following code:Although this is an expected behavior of the original implementation, we consider it problematic since the rule’s fix is marked as safe.
To avoid false positives like this, the rule now ignores the previous examples.
However, this has the disadvantage of resulting in false negatives, such as not reporting the first example.
Patch Changes
#7156
137d111
Thanks @ematipico! - Fixed #7152. Now the rulenoDuplicateFontNames
correctly detects font names with spaces e.g.Liberation Mono
. The diagnostic of the rule now points to the first instances of the repeated font.The following example doesn't trigger the rule anymore:
#6907
7331bb9
Thanks @ematipico! - Added a new experimental option that allows parsing of.html
files that contain interpolation syntax.#7124
3f436b8
Thanks @Jayllyz! - Added the ruleuseMaxParams
.This rule enforces a maximum number of parameters for functions to improve code readability and maintainability. Functions with many parameters are difficult to read, understand, and maintain because they require memorizing parameter order and types.
#7161
1a14a59
Thanks @ematipico! - Fixed #7160. Now Biome correctly computes ignored files when usingformatter.includes
,linter.includes
andassist.includes
inside nested configurations that use"extends": "//"
.#7081
a081bbe
Thanks @Jayllyz! - Added the rulenoNextAsyncClientComponent
.This rule prevents the use of async functions for client components in Next.js applications. Client components marked with "use client" directive should not be async as this can cause hydration mismatches, break component rendering lifecycle, and lead to unexpected behavior with React's concurrent features.
#7171
5241690
Thanks @siketyan! - Fixed #7162: ThenoUndeclaredDependencies
rule now considers a type-only import as a dev dependency.For example, the following code is no longer reported:
package.json
:foo.ts
:Note that you still need to declare the package in the
devDependencies
section inpackage.json
.v2.1.4
Compare Source
Patch Changes
#7121
b9642ab
Thanks @arendjr! - Fixed #7111: Imported symbols using aliases are now correctly recognised.#7103
80515ec
Thanks @omasakun! - Fixed #6933 and #6994.When the values of private member assignment expressions, increment expressions, etc. are used, those private members are no longer marked as unused.
#6887
0cc38f5
Thanks @ptkagori! - Added thenoQwikUseVisibleTask
rule to Qwik.This rule is intended for use in Qwik applications to warn about the use of
useVisibleTask$()
functions which require careful consideration before use.Invalid:
Valid:
#7084
50ca155
Thanks @ematipico! - Added the new nursery rulenoUnnecessararyConditions
, which detects whenever some conditions don'tchange during the life cycle of the program, and truthy or false, hence deemed redundant.
For example, the following snippets will trigger the rule:
#6887
0cc38f5
Thanks @ptkagori! - Added theuseImageSize
rule to Biome.The
useImageSize
rule enforces the use of width and height attributes on<img>
elements for performance reasons. This rule is intended to prevent layout shifts and improve Core Web Vitals by ensuring images have explicit dimensions.Invalid:
Valid:
#6887
0cc38f5
Thanks @ptkagori! - Added theuseAnchorHref
rule to Biome.The
useAnchorHref
rule enforces the presence of anhref
attribute on<a>
elements in JSX. This rule is intended to ensure that anchor elements are always valid and accessible.Invalid:
Valid:
#7100
29fcb05
Thanks @Jayllyz! - Added the rulenoNonNullAssertedOptionalChain
.This rule prevents the use of non-null assertions (
!
) immediately after optional chaining expressions (?.
). Optional chaining is designed to safely handle nullable values by returningundefined
when the chain encountersnull
orundefined
. Using a non-null assertion defeats this purpose and can lead to runtime errors.#7129
9f4538a
Thanks @drwpow! - Removed option, combobox, listbox roles from useSemanticElements suggestions#7106
236deaa
Thanks @arendjr! - Fixed #6985: Inference of return types no longer mistakenly picks up return types of nested functions.#7102
d3118c6
Thanks @omasakun! - Fixed #7101:noUnusedPrivateClassMembers
now handles members declared as part of constructor arguments:private
modifier and makes it a plain method argument.noUnusedFunctionParameter
.#7104
5395297
Thanks @harxki! - Reverting to prevent regressions around ref handling#7143
1a6933a
Thanks @siketyan! - Fixed #6799: ThenoImportCycles
rule now ignores type-only imports if the newignoreTypes
option is enabled (enabled by default).#7099
6cc84cb
Thanks @arendjr! - Fixed #7062: Biome now correctly considers extended configs when determining the mode for the scanner.#6887
0cc38f5
Thanks @ptkagori! - Added theuseQwikClasslist
rule to Biome.This rule is intended for use in Qwik applications to encourage the use of the built-in
class
prop (which accepts a string, object, or array) instead of theclassnames
utility library.Invalid:
Valid:
#7019
57c15e6
Thanks @fireairforce! - Added support in the JS parser forimport source
(a stage3 proposal). The syntax looks like:#7053
655049e
Thanks @jakeleventhal! - Added theuseConsistentTypeDefinitions
rule.This rule enforces consistent usage of either
interface
ortype
for object type definitions in TypeScript.The rule accepts an option to specify the preferred style:
interface
(default): Prefer usinginterface
for object type definitionstype
: Prefer usingtype
for object type definitionsExamples:
The rule will automatically fix simple cases where conversion is straightforward.
cloudflare/workerd (@cloudflare/workers-types)
v4.20250821.0
Compare Source
v4.20250820.0
Compare Source
v4.20250819.0
Compare Source
v4.20250816.0
Compare Source
v4.20250813.0
Compare Source
v4.20250812.0
Compare Source
v4.20250810.0
Compare Source
v4.20250809.0
Compare Source
discordjs/discord.js (@discordjs/builders)
v1.11.3
Compare Source
Bug Fixes
discordjs/discord-api-types (discord-api-types)
v0.38.21
Compare Source
Features
PinMessages
(#1340) (b05df17)v0.38.20
Compare Source
v0.38.19
Compare Source
Features
pnpm/pnpm (pnpm)
v10.15.0
Compare Source
Minor Changes
cleanupUnusedCatalogs
configuration. When set totrue
, pnpm will remove unused catalog entries during installation #9793.@*/pnpm-plugin-*
#9780.pnpm config get
now prints an INI string for an object value #9797.pnpm config get
now accepts property paths (e.g.pnpm config get catalog.react
,pnpm config get .catalog.react
,pnpm config get 'packageExtensions["@​babel/parser"].peerDependencies["@​babel/types"]'
), andpnpm config set
now accepts dot-leading or subscripted keys (e.g.pnpm config set .ignoreScripts true
).pnpm config get --json
now prints a JSON serialization of config value, andpnpm config set --json
now parses the input value as JSON.Patch Changes
pnpm create
command, must verify whether the node version is supported even if a cache already exists #9775.*/*
to theAccept
header to avoid getting a 406 error on AWS CodeArtifact #9862.pnpm dlx pkg --help
doesn't pass--help
topkg
#9823.cloudflare/workers-sdk (wrangler)
v4.32.0
Compare Source
Minor Changes
#10354
da40571
Thanks @edmundhung! - Enable cross-process communication forwrangler dev
with multiple config filesWorkers running in separate
wrangler dev
sessions can now communicate with each other regardless of whether you are running with single or multiple config files.Check out the Developing with multiple Workers guide to learn more about the different approaches and when to use each one.
#10012
4728c68
Thanks @penalosa! - Support unsafe dynamic worker loading bindingsPatch Changes
#10245
d304055
Thanks @edmundhung! - Migrate wrangler dev to use Miniflare dev registry implementationUpdated
wrangler dev
to use a shared dev registry implementation that now powers both the Cloudflare Vite plugin and Wrangler. This internal refactoring has no user-facing changes but consolidates registry logic for better consistency across tools.#10407
f534c0d
Thanks @emily-shen! - defaultcontainers.rollout_active_grace_period
to 0#10425
0a96e69
Thanks @dario-piotrowicz! - Fix debugging logs not including headers for CF API requests and responsesFix the fact that
wrangler
, when run with theWRANGLER_LOG=DEBUG
andWRANGLER_LOG_SANITIZE=false
environment variables, displays{}
instead of the actual headers for requests and responses for CF API fetches#10337
f9f7519
Thanks @emily-shen! - containers:rollout_step_percentage
now also accepts an array of numbers. Previously it accepted a single number, and each rollout step would target the same percentage of instances. Now users can customise percentages for each step.rollout_step_percentage
also now defaults to[10,100]
(previously25
), which should make rollouts progress slightly faster.You can also use
wrangler deploy --containers-rollout=immediate
to override rollout settings in Wrangler configuration and update all instances in one step. Note this doesn't overriderollout_active_grace_period
if configured.Updated dependencies [
4728c68
]:v4.31.0
Compare Source
Minor Changes
#10314
9b09751
Thanks @dario-piotrowicz! - Show possible local vs. dashboard diff information on deploysWhen re-deploying a Worker using
wrangler deploy
, if the configuration has been modified in the Cloudflare dashboard, the local configuration will overwrite the remote one. This can lead to unexpected results for users. To address this, currentlywrangler deploy
warns users about potential configuration overrides (without presenting them) and prompts them to confirm whether they want to proceed.The changes here improve the above flow in the following way:
wrangler deploy
now displays a git-like diff showing the differences between the dashboard and local configurations. This allows users to review and understand the impact of their changes before confirming the deployment.#10334
cadf19a
Thanks @jonesphillip! - Added queues subscription command to Wrangler including create, update, delete, get, listPatch Changes
#10374
20520fa
Thanks @edmundhung! - Simplify debug package resolution with nodejs_compatA patched version of
debug
was previously introduced that resolved the package to a custom implementation. However, this caused issues due to CJS/ESM interop problems. We now resolve thedebug
package to use the Node.js implementation instead.#10249
875197a
Thanks @penalosa! - Support JSRPC for remote bindings. This unlocks:Updated dependencies [
565c3a3
,ddadb93
,20520fa
,875197a
]:v4.30.0
Compare Source
Minor Changes
76a6701
Thanks @garvit-gupta! - feat: Add Wrangler command for Vectorize list-vectors operationPatch Changes
#10217
979984b
Thanks @veggiedefender! - Increase the maxBuffer size for capnp uploads[#10356](https://redirect.github.com/cloudflare/workers-sd
Configuration
📅 Schedule: Branch creation - "before 9am on monday" in timezone Europe/Gibraltar, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.