chore(deps): update devdependencies (major) - #428
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
3 times, most recently
from
July 10, 2025 16:47
baf6177 to
c6f4687
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
3 times, most recently
from
July 25, 2025 23:10
0d472cc to
b7a264c
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
from
July 29, 2025 20:31
b7a264c to
2a5f91e
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
5 times, most recently
from
August 12, 2025 02:51
875e206 to
ce3769a
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
2 times, most recently
from
August 19, 2025 10:35
781b29f to
0979286
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
5 times, most recently
from
August 27, 2025 15:56
b48cc3a to
ed834e7
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
2 times, most recently
from
September 6, 2025 22:54
c9fd260 to
b984190
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
2 times, most recently
from
September 10, 2025 13:29
ce4fc79 to
0fc5e29
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
3 times, most recently
from
September 22, 2025 06:11
617f9d5 to
d5af895
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
2 times, most recently
from
September 29, 2025 01:32
389dee2 to
b942834
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
8 times, most recently
from
October 29, 2025 07:58
7f47b7e to
0b27ccf
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
7 times, most recently
from
November 5, 2025 17:53
39ed51f to
6f72944
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
6 times, most recently
from
November 12, 2025 02:52
689c0a7 to
6ea173d
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
4 times, most recently
from
November 20, 2025 09:14
ab8d7f2 to
2a07453
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
2 times, most recently
from
November 27, 2025 15:38
dc2ac94 to
98d1fa6
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
2 times, most recently
from
December 2, 2025 20:49
ee8f02a to
179ddd6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^4.0.2→^6.0.0^1.11.1→^3.0.0^1.1.1→^3.0.02.2.3→4.0.1^1.1.3→^3.0.0^2.0.2→^4.0.0^7.26.9→^8.0.0^7.27.1→^8.0.0^1.9.4→^2.0.0^25.0.0→^28.0.0^13.0.0→^15.0.0^16.0.0→^18.0.0^14.0.0→^17.0.0^1000.0.7→^1100.0.0^29.5.14→^30.0.0^22.13.8→^26.0.0^1.0.1→^2.0.07.0.3→10.1.0^9.0.0→^10.0.0^1.22.1→^2.0.0^29.7.0→^30.0.0^19.3.1→^23.0.0^8.0.4→^9.0.0^6.1.4→^7.0.0^5.8.2→^7.0.0^7.3.1→^8.0.0Release Notes
actions/toolkit (@actions/cache)
v6.2.0cache read denied:prefix on cache download failures (both the v2 twirp path and the v1_apis/artifactcachepath) and surface it as acore.warning(without failing the run).ACTIONS_CACHE_MODEenvironment variable: skip restore when the effective cache-mode does not permit reads (none,write-only) and skip save when it does not permit writes (none,read), logging a single non-fatalcore.infoline. WhenACTIONS_CACHE_MODEis unset or unrecognized, behavior is unchanged.v6.1.0cache write denied:prefix on cache reservation failures and surface it as acore.warning(without failing the run).v6.0.1@actions/coreto^3.0.1@actions/http-clientto^4.0.1@actions/ioto^3.0.2@azure/core-rest-pipelineto^1.23.0@azure/storage-blobto^12.31.0semverto^7.7.4v6.0.0import()instead ofrequire()v5.0.5@actions/globto0.5.1v5.0.4@actions/http-clientto3.0.2v5.0.3Prevent retries for rate limited cache operations 2243.
v5.0.1@azure/storage-blobfrom^12.13.0to^12.29.1#2213@azure/core-rest-pipelineinstead of deprecated@azure/core-http, which eliminates the transitive dependency onnode-fetch@2→whatwg-url@5→tr46@0.0.3that used the deprecated punycode modulev5.0.0@azure/ms-rest-jsdependency #2197TransferProgressEventtype is now imported from@azure/core-rest-pipelineinstead of@azure/ms-rest-js@actions/corefrom^1.11.1to^2.0.0#2198@actions/execfrom^1.0.1to^2.0.0#2198@actions/globfrom^0.1.0to^0.5.0#2198@actions/http-clientfrom^2.1.1to^3.0.0#2198@actions/iofrom^1.0.1to^2.0.0#2198node-fetchoverride to resolve audit vulnerabilities #2110actions/toolkit (@actions/core)
v3.0.1undicifrom6.23.0to6.24.1#2348v3.0.0import()instead ofrequire()v2.0.3@actions/http-clientto3.0.2v2.0.1v2.0.0actions/toolkit (@actions/exec)
v3.0.0import()instead ofrequire()v2.0.0actions/toolkit (@actions/http-client)
v4.0.1undicifrom6.23.0to6.24.0#2347v4.0.0import()instead ofrequire()v3.0.2undicifrom5.28.5to6.23.0v3.0.1v3.0.0actions/toolkit (@actions/io)
v3.0.2v3.0.1@actions/io/lib/io-utilv3.0.0import()instead ofrequire()v2.0.0actions/toolkit (@actions/tool-cache)
v4.0.0import()instead ofrequire()3.0.1
@actions/http-clientto3.0.23.0.0
@actions/core@actions/exec@actions/http-client@actions/io2.0.2
@actions/coreto v1.11.1 #1872uuidpackage #1824, #18422.0.1
@actions/http-client#10872.0.0
@actions/http-clientheadersparameter in the exported functiondownloadToolhas been narrowed from{ [header: string]: any }to{ [header: string]: number | string | string[] | undefined; }(that is,http.OutgoingHttpHeaders).This is strictly a compile-time change for TypeScript consumers. Previous attempts to use a header value of a type other than those now accepted would have resulted in an error at run time.
1.7.2
lockfileVersiontov2inpackage-lock.json#10251.7.1
1.7.0
isExplicitVersionandevaluateVersionsfunctions1.6.1
1.6.0
1.3.5
1.3.4
Here is the security issue that was fixed in the http-client 1.0.8 release
1.3.3
1.3.2
1.3.1
1.3.0
1.2.0
extractTaron Windows1.1.2
extractTar1.0.0
v3.0.1@actions/http-clientto3.0.2v3.0.0@actions/core@actions/exec@actions/http-client@actions/iobabel/babel (@babel/core)
v8.0.1Compare Source
💥 Breaking Change
babel-core,babel-plugin-transform-object-rest-spread,babel-plugin-transform-runtime,babel-preset-env,babel-standalonepreset-env'suseBuiltIns(@nicolo-ribaudo)v8.0.0Compare Source
👓 Spec Compliance
babel-core💥 Breaking Change
babel-cli,babel-node,babel-plugin-proposal-decorators,babel-plugin-transform-classes,babel-plugin-transform-function-name,babel-plugin-transform-modules-commonjs,babel-plugin-transform-object-rest-spread,babel-plugin-transform-parameters,babel-plugin-transform-react-constant-elements,babel-plugin-transform-regenerator,babel-preset-env,babel-registermodules: auto(@nicolo-ribaudo)babel-plugin-transform-runtime,babel-runtime-corejs3,babel-runtime@babe/runtime-corejs3(@liuxingbaoyu)babel-parserlocations: "packed"(@liuxingbaoyu)🐛 Bug Fix
babel-generatorbabel-plugin-transform-modules-systemjs📝 Documentation
🏠 Internal
🏃♀️ Performance
babel-corebiomejs/biome (@biomejs/biome)
v2.5.7Compare Source
Patch Changes
#10822
c171b3bThanks @pkallos! - Added the optionignoreIfStatementsto useNullishCoalescing. Biome now flagsifstatements that only assign to a nullish variable (such asif (!a) { a = b }) and can rewrite them to??=. When enabled, Biome ignores thoseifstatements.#11136
e63354cThanks @AkashNaickar! - Added a new nursery rulenoExtendNative, which reports extending the prototype of a built-in object.#10094
e007143Thanks @THEjacob1000! - Added the nursery rulenoTailwindArbitraryValue. Biome now reports Tailwind CSS arbitrary values such asw-[400px], including in HTML/JSX class attributes, configured utility functions, and tagged templates.#11184
135f476Thanks @subotac! - Fixed #11176:noUnknownPseudoClassnow recognizes Vue's:deep()pseudo-class inside.vuestyle blocks.#8239
a519f9dThanks @cormacrelf! - Fixed #8233, where Biome CLI instdin mode didn't work correctly when handling files in projects with nested
configurations. For example, with the following structure,
--stdin-file-path=subdirectory/...would not use the nested configuration insubdirectory/biome.json:biome format --write --stdin-file-path=subdirectory/lib.js < subdirectory/lib.jsNow, the nested configuration is correctly picked up and applied.
In addition, Biome now shows a warning if
--stdin-file-pathis provided butthat path is ignored and therefore not formatted or fixed.
#11138
8c2c6bdThanks @ematipico! - FixednoUnnecessaryConditions: Biome now chooses the same function overload as TypeScript when an argument is a callback, so conditions that were previously missed are reported.The following code is now invalid, because a parameter typed
() => voidaccepts anasynccallback andscheduletherefore returnsstring:The following code is also now invalid, because
map(() => 42)returns42:#11138
8c2c6bdThanks @ematipico! - Fixed #11087:noUnnecessaryConditionsno longer reports optional chains and nullish coalescing whose receiver can be nullish.For example, the optional chain and fallback in the following code are no longer reported:
#11118
9c16840Thanks @subotac! - Fixed #11098: The HTML formatter now preserves the configured trailing newline when a file ends with a comment.#11201
0e80610Thanks @Bishwas-py! - Fixed #11182: suppression comments fornoPositiveTabindexnow suppress the rule in HTML files when the attributes of the element span multiple lines.#11079
607afd2Thanks @dyc3! - The HTML formatter now lays out thesrcsetattribute of<img>and<source>as the list of candidates it is. Runs of whitespace between candidates collapse, and once the list no longer fits on one line each candidate goes on its own line with the descriptors aligned:#11156
fed72c7Thanks @saberoueslati! - Fixed #11129:noUnusedVariablesno longer reports Vue bindings as unused when they are assigned through automatically unwrapped template refs.#11124
d890b39Thanks @denbezrukov! - Fixed CSS formatting of line comments between a declaration colon and value to preserve their source indentation..test { background: - /////// foo - // bar + /////// foo + // bar radial-gradient(circle, #​000, transparent); }#11113
3d8ab73Thanks @denbezrukov! - Fixed CSS formatting of long block comments between comma-separated property values:.foo { box-shadow: - 1000px /* long long long long long long long long long long long long comment */ 1000px /* long long long long long long long long long comment */ 2px color(srgb 0.555555555 0.555555555 0.555555555), + 1000px + /* long long long long long long long long long long long long comment */ + 1000px /* long long long long long long long long long comment */ 2px + color(srgb 0.555555555 0.555555555 0.555555555), 1px 1px black; }#11127
da5c1a5Thanks @dyc3! - The HTML formatter now picks the quote character for an attribute by counting the quotes in the value rather than looking only for a double quote.'and"count as the characters they stand for, and only the character that ends up as the delimiter stays escaped:Entities that are not quotes, such as
&or&[#​39](https://redirect.github.com/biomejs/biome/issues/39);, are left exactly as written.#11193
77035bbThanks @dyc3! - Fixed the HTML formatter collapsing the blank line between an element and the text that follows it. A blank line before text is now kept, the way one before another element already was:<div>foo</div> - text#11106
ad80f57Thanks @dyc3! - The HTML formatter now writes the HTML5 doctype in lowercase, matching Prettier:This only applies to a plain
.htmlfile whose doctype stands alone. A doctype that names a DTD keeps the case it was written with, since the rest of the declaration is not lowercased either:<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">A
.vue,.svelte, or.astrofile keeps whatever the author wrote.#11188
60679dbThanks @dyc3! - Fixed the HTML formatter printing a comment twice when it ended the line of the last element in a document:#11077
4dcd0d9Thanks @dyc3! - Fixed a bug where the HTML formatter collapsed the whitespace inside<textarea>,<xmp>and<plaintext>, changing what the page renders.Biome now prints the content of these elements exactly as it appears in the source, matching the existing behavior for
<pre>.#11194
abfbb11Thanks @dyc3! - Fixed the HTML formatter refusing to format a Svelte file containing an array pattern that skips a position:{#each animals as [, value]} <p>{value}</p> {/each}#10094
e007143Thanks @THEjacob1000! - FixeduseSortedClassesto correctly detect unsorted classes in static member expression tagged templates (e.g.tw.div\...``). Previously, these were silently skipped due to surrounding whitespace trivia not being stripped from the tag name.#11078
10da30eThanks @dyc3! - Fixed Vue single-file components failing to parse when they contain a custom block such as<i18n>or<docs>, or a<template>written in another language. Their content is no longer read as HTML, so a block may hold whatever its own tooling expects:Previously both blocks produced a parse error and the whole file was left unformatted. Biome now prints their content unchanged while still formatting the opening tag.
#11231
4afd901Thanks @ematipico! - Improved the performance of the following lint rules:noArguments.noGlobalAssign.noUndeclaredVariables.noRestrictedGlobals.noInvalidUseBeforeDeclaration.noShadow.noRedeclare.#11134
2fa0a62Thanks @yanthomasdev! - Clarified the warning emitted when using the experimentaljsonandjson-prettyreporters.#11198
ed88b13Thanks @saberoueslati! - Fixed #11171: variables referenced only inside a Svelte attachment ({@attach ...}) are no longer reported as unused bynoUnusedVariablesandnoUnusedImports.#11155
6ee17eaThanks @dyc3! - Improved performance when printing diagnostics to the console.#11160
217f8adThanks @dyc3! - Improved the performance ofnoFloatingPromisesby skipping type inference for assignment statements, which are always considered handled.#11159
26c23d9Thanks @saberoueslati! - Fixed #11144:noFloatingPromisesno longer reports already-awaited optional Promise values.#11138
8c2c6bdThanks @ematipico! - Fixed #11121:noUnnecessaryConditionsno longer reports conditions based on an inapplicable function overload.For example, the condition in the following code is no longer reported because
query({})selects the overload that returnsboolean:#11152
c4fc6a9Thanks @dyc3! - Improved the performance of collecting rule timings with--profile-rulesin heavily multithreaded environments.#11128
4d3ff76Thanks @ematipico! - Fixed #7635:noDeprecatedImportsnow detects deprecated ambient declarations that are exported separately.#11117
01f7ef5Thanks @subotac! - Fixed #11014:noDeleteno longer reportsprocess.env["FOO"]style property deletions.#11168
9847e68Thanks @saberoueslati! - Added the nursery rulenoNonScalableViewport, which reports viewport metadata that disables user scaling withuser-scalable=no.For example:
#11154
a1d6b1fThanks @dyc3! - Improved the performance ofnoImportCyclesby skipping graph traversals for imports that cannot be part of a cycle.#11175
d96d6ddThanks @ematipico! - Fixed CSS parsing of registered custom properties: Biome now correctly validates thesyntaxdescriptor of@propertyrules.v2.5.6Compare Source
Patch Changes
#11035
0e4b03bThanks @ematipico! - Fixed a performance regression innoMisusedPromisesthat caused type inference to run repeatedly while linting a file.#11043
22ec076Thanks @denbezrukov! - Fixed CSS formatting for multiline function arguments preceded by comments:.example { value: outer( 1, /* comment */ nested( - first, - second - ) + first, + second + ) ); }#11007
c9acb25Thanks @BTF-Kabir-2020! - Fixed #9195:useHookAtTopLevelno longer reports hooks in namedforwardRefcomponents that receive arefparameter.#10152
50a9bd8Thanks @Zelys-DFKH! - Fixed #10131: Biome now correctly parses curried arrow functions in ternary consequents when the inner arrow's parameters use a destructuring pattern, e.g.cond ? (x) => ({ a, b }) => body : alt.#11105
8ffe2b9Thanks @dadavidtseng! - Fixed #11092: ThenoUselessTernaryquick fix now preserves operator spacing when simplifying or inverting boolean ternary expressions.#10533
5809875Thanks @Mokto! - Fixed #10515:biome check --writewas not idempotent on Svelte files — multi-line template literals in<script>blocks and block comments in<style>blocks gained an extra indent level on every run.#11040
0abb620Thanks @Mokto! - Fixed an issue where the HTML formatter would duplicate a comment placed directly before a Svelte{@const ...}or{@debug ...}block. The duplication compounded on every subsequent--write, causing the file to grow exponentially.#10858
6d18204Thanks @ruidosujeira! - Fixed #10839: Svelte{#each}array destructuring no longer includes spaces inside square brackets, and multiline bind function expressions now indent their getter, setter, and function body correctly.#11009
2c36626Thanks @ematipico! - Improved the accuracy of type-aware lint rules by resolving more inferred types. For example,noFloatingPromisesnow detects floating Promises returned by aliased callbacks and arrays of Promises created by async mapping callbacks.The following statements are now reported:
#10973
9cb044cThanks @ematipico! - Fixed false positives innoMisleadingReturnTypewhen generic-constraint, normalization, substitution, or structural return-type comparison cannot complete. The rule now suppresses diagnostics rather than suggesting a return type derived from partial information. For example, this unresolved return type is no longer reported:#11071
15047a2Thanks @dyc3! - The HTML parser now accepts mixed-casedoctypedeclarations.#11030
cc90e65Thanks @marschattha! - Therdjsonreporter now populates the severity field of each diagnostic (ERROR,WARNING, orINFO), so tools consuming Reviewdog Diagnostic Format output no longer need to assume a default severity.#11009
2c36626Thanks @ematipico! - Fixed a performance regression in type-aware JavaScript lint rules by inferring only requested types and memoizing export resolution.#11056
903b177Thanks @dyc3! - Added support for Svelte declaration tags usingletandconst. Biome can now parse, format, and lint bindings declared in these tags.#11045
89c27c6Thanks @ematipico! - Improved the performance of Biome formatter up to ~7% across the board.#9806
781d68dThanks @dyc3! - Added the nursery rulenoJsRestrictedProperties, which ports ESLint'sno-restricted-propertiesrule. Biome now flags restricted member access and object destructuring, andbiome migrate eslintpreserves the rule's options.v2.5.5Compare Source
Patch Changes
#10972
ab8c21bThanks @ematipico! - FixeduseExhaustiveSwitchCasesfor unions of bigint literals. The rule now reports missing bigint cases and compares bigint literals by value, including binary, octal, hexadecimal, and separator-containing spellings. For example, this switch now reports the missing2ncase:#10972
ab8c21bThanks @ematipico! - Fixed false positives innoBaseToStringanduseNullishCoalescingwhen member, stringification, or nullish inference cannot complete. These rules now suppress diagnostics instead of reporting from partial type information. For example, neither expression is reported when a recursive type cannot be fully resolved:#10977
0bf7486Thanks @ematipico! - Fixed #10922: the actionuseSortedAttributesno longer triggers for HTML instructions.#10957
cf263c4Thanks @dyc3! - Fixed [Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.