Skip to content

chore(deps): update linters#2346

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/linters
Open

chore(deps): update linters#2346
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/linters

Conversation

@renovate

@renovate renovate Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Update Change Pending Age Confidence
aqua:jonwiggins/xmloxide patch 0.4.30.4.4 age confidence
biome patch 2.5.32.5.5 age confidence
npm:renovate (source) minor 43.257.443.279.1 43.281.1 (+8) age confidence
ruff minor 0.15.210.16.0 age confidence
rumdl patch v0.2.31v0.2.43 age confidence
zizmor minor 1.26.11.28.0 age confidence

Release Notes

jonwiggins/xmloxide (aqua:jonwiggins/xmloxide)

v0.4.4

Compare Source

Security
  • Fix stack exhaustion when parsing deeply-nested DTD content models
    (CVE-2026-61727 / GHSA-7jmw-29gc-ffx4, thanks @​williamareynolds). The DTD
    parser recursed without a depth bound when parsing an <!ELEMENT> content
    model, so a small untrusted document with many nested ( in a content model
    could overflow the stack and abort the process — an uncatchable denial of
    service (CWE-674). This is reachable on the default parse path because the
    internal DTD subset is parsed during ordinary parsing, and the existing
    ParseOptions::max_depth did not cover it (it bounds element nesting, not the
    DTD content-model grammar). The content-model recursion is now bounded at 256
    levels and returns a normal ParseError past the limit; well-formed DTDs are
    unaffected.
biomejs/biome (biome)

v2.5.5: Biome CLI v2.5.5

Compare Source

2.5.5

Patch Changes
  • #​10972 ab8c21b Thanks @​ematipico! - Fixed useExhaustiveSwitchCases for unions of bigint literals. The rule now reports missing bigint cases and compares bigint literals by value, including binary, octal, hexadecimal, and separator-containing spellings. For example, this switch now reports the missing 2n case:

    declare const value: 1n | 2n;
    switch (value) {
      case 1n:
        break;
    }
  • #​10972 ab8c21b Thanks @​ematipico! - Fixed false positives in noBaseToString and useNullishCoalescing when member, stringification, or nullish inference cannot complete. These rules now suppress diagnostics instead of reporting from partial type information. For example, neither expression is reported when a recursive type cannot be fully resolved:

    type Recursive = Recursive;
    declare const value: Recursive;
    
    String(value);
    value || "fallback";
  • #​10977 0bf7486 Thanks @​ematipico! - Fixed #​10922: the action useSortedAttributes no longer triggers for HTML instructions.

  • #​10957 cf263c4 Thanks @​dyc3! - Fixed noThenProperty failing to detect Object.fromEntries, Object.defineProperty, and Reflect.defineProperty calls with comments between their tokens.

  • #​10983 edc0ed7 Thanks @​ayaangazali! - Fixed #​10980: useAriaPropsSupportedByRole no longer reports false positives when the attribute that determines an element's implicit ARIA role is written as a shorthand attribute, such as <a {href} aria-label="..."> in Astro and Svelte files.

    Shorthand attributes are now taken into account when computing the implicit role, so the anchor above correctly resolves to the link role instead of generic.

  • #​10889 89526e3 Thanks @​denbezrukov! - Fixed CSS formatter casing for syntax-owned names while preserving author-defined names, including scoped keyframes and container scroll-state queries.

    - A:HOVER { COLOR: INITIAL; }
    + A:hover { color: initial; }
    - @&#8203;KEYFRAMES :GLOBAL KeepFrames { FROM { COLOR: RED; } }
    + @&#8203;keyframes :GLOBAL KeepFrames { from { color: RED; } }
    - @&#8203;CONTAINER scroll-state((SCROLLED: TOP) AND (STUCK)) { A:HOVER { COLOR: RED; } }
    + @&#8203;container scroll-state((SCROLLED: TOP) AND (STUCK)) { A:hover { color: RED; } }
  • #​10964 794ccd0 Thanks @​denbezrukov! - Fixed CSS formatting for comments between declaration values and !important.

    -a { color: /* before */ /* after */ red !important; }
    +a { color: /* before */ red /* after */ !important; }
  • #​10993 b7a9694 Thanks @​denbezrukov! - Fixed the CSS formatter to preserve comments on the correct side of selector combinators and before declaration blocks.

    -.before > /* comment */ .after {}
    +.before /* comment */ > .after {}

    It now also keeps selectors with escaped newlines in attribute values inline when they fit.

    -div
    -  span[foo="bar\
    +div span[foo="bar\
     value"] {}
  • #​10978 8ebafe1 Thanks @​ematipico! - Fixed #​10870: noUnresolvedImports no longer reports false positives such as import type { NextRequest } from "next/server".

  • #​10901 68c10e6 Thanks @​Socialpranker! - Fixed #​10622: the HTML/Vue parser no longer panics on the argument-less v-bind shorthand (:="props").

    This syntax is valid Vue and equivalent to v-bind="props", so the parser now accepts it (along with the longhand v-bind:="props") instead of crashing while building a diagnostic for a missing argument.

  • #​10936 7df46f5 Thanks @​ematipico! - Improved generic tuple inference for useIncludes. The rule now recognizes specialised tuple element types returned through generic aliases.

  • #​10941 f787725 Thanks @​siketyan! - Fixed #10855: Biome now supports parsing and formatting CSS custom media queries declared with @custom-media.

  • #​10969 72d309b Thanks @​ematipico! - Fixed an issue where Biome logs became too verbose, dumping information not relevant to user's operations.

  • e62f6b6 Thanks @​ematipico! - Fixed #​10963: Biome no longer panics when a type-aware rule such as noFloatingPromises checks a call to a function with multiple call signatures imported from another module.

  • #​10931 899c60d Thanks @​ematipico! - Fixed check --write command. Now the command reports code frame of the formatted code, if the formatter is enabled.

  • #​10904 ceee4f4 Thanks @​qzwxsaedc! - Fixed #​10892: noUnnecessaryConditions no longer reports a false positive when checking a member of a discriminated union that is accessed through a default type-only namespace import. The following code is no longer flagged:

    import type Types from "./types";
    
    declare function parse(): Types.Result<string>;
    const result = parse();
    if (!result.success) {
    }
  • #​10962 f0a67f2 Thanks @​ematipico! - Biome no longer removes embedded styles and scripts in HTML files.

  • #​11000 5039a1e Thanks @​ematipico! - Fixed a bug where closing one editor stopped a shared Biome daemon used by other editors. LSP proxy processes now exit when either the editor or daemon disconnects.

  • #​10957 cf263c4 Thanks @​dyc3! - Improved the performance of the noThenProperty lint rule by about 50%.

  • #​10992 4bf9b21 Thanks @​ematipico! - Fixed noMisusedPromises: The rule now reports Promise-returning callbacks where a synchronous callback is expected when calls use tuple spreads or tuple rest parameters, including generic and deeply nested tuples, and when constructor signatures come from interface or object types. Recursive or excessively nested tuple spreads use a conservative fallback so analysis terminates.

    For example, the following callback is now reported.

    declare function consume(...args: [number, () => void]): void;
    const prefix: [number] = [1];
    
    consume(...prefix, async () => {});
  • #​10915 b3b12b3 Thanks @​Functionhx! - Added the rule noNegationInEqualityCheck. The rule flags negated expressions on the left side of strict equality checks like !foo === bar — due to operator precedence this evaluates as (!foo) === bar which is almost always a mistake for foo !== bar.

    The rule provides an unsafe fix that flips the operator.

    // Invalid
    !foo === bar;
    !foo !== bar;
    
    // Valid
    foo !== bar;
    foo === bar;
  • #​10970 bd1038b Thanks @​ematipico! - Improved overload selection for noMisusedPromises. Biome now handles overloaded calls, overloaded constructors, rest parameters, union arguments, and generic constraints without selecting an incompatible signature. For example, noMisusedPromises now reports the async callback passed to the synchronous overload:

    declare function consume(kind: "async", callback: () => Promise<void>): void;
    declare function consume(kind: "sync", callback: () => void): void;
    consume("sync", async () => {});
  • #​10933 48a4abb Thanks @​ematipico! - Fixed useArrayFind to recognize bigint zero indexes.

  • #​10931 899c60d Thanks @​ematipico! - Fixed an orchestration issue that could lead to deadlocks when type-aware rules are enabled.

  • #​10969 72d309b Thanks @​ematipico! - Hardened the Biome Language Server by improving its synchronisation logic.

  • #​10972 ab8c21b Thanks @​ematipico! - Fixed false positives in noMisusedPromises and useAwaitThenable when Promise or thenable inference cannot complete. These rules now suppress diagnostics instead of treating incomplete type information as a definite result. For example, useAwaitThenable no longer reports await value when the value's thenability is unknown:

    declare const value: unknown;
    
    async function consume() {
      await value;
    }

What's Changed

New Contributors

Full Changelog: https://github.com/biomejs/biome/compare/@biomejs/biome@2.5.4...@​biomejs/biome@2.5.5

v2.5.4: Biome CLI v2.5.4

Compare Source

2.5.4

Patch Changes
  • #​10665 55ff995 Thanks @​dyc3! - Improved the performance of the HTML parser slightly in our synthetic benchmarks.

  • #​10894 f4fb10e Thanks @​ematipico! - Fixed #​6392: On-type formatting no longer moves comments before an if statement into its body.

  • #​10939 f2799db Thanks @​Netail! - Fixed #​10930: noLabelWithoutControl now correctly detects text interpolation in Astro, Svelte & Vue as valid accessible content.

  • #​10945 ae15d98 Thanks @​Netail! - Fixed #​10942: Svelte directives don't throw an accidental debug log anymore.

  • #​10842 5e1abfe Thanks @​JamBalaya56562! - Fixed #​9196: biome check --write --unsafe no longer hangs forever when applying the noCommentText code fix.

    The rule's fix now wraps the comment in a real JSX expression container ({/* comment */}) instead of re-inserting the braces as plain JSX text, so the fixed code is no longer reported again by the same rule.

  • #​10891 ecca79e Thanks @​ematipico! - Fixed #10885: prevented a module-inference regression introduced by a housekeeping change.

  • #​10886 60c8043 Thanks @​dyc3! - Fixed #​10727: Biome now breaks the arguments of curried test.each, it.each, describe.each, and test.for calls when they exceed the configured line width.

    - test.each([[1, 2]])("a description that is long enough to push the hugged opening line beyond the print width", (a, b) => {
    -   expect(a).toBe(b);
    - });
    + test.each([[1, 2]])(
    +   "a description that is long enough to push the hugged opening line beyond the print width",
    +   (a, b) => {
    +     expect(a).toBe(b);
    +   },
    + );
  • #​10895 01a85f0 Thanks @​ematipico! - Biome will now remove stale Unix daemon sockets from older Biome versions when starting a newer daemon.

What's Changed

Full Changelog: https://github.com/biomejs/biome/compare/@biomejs/biome@2.5.3...@​biomejs/biome@2.5.4

renovatebot/renovate (npm:renovate)

v43.279.1

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.77.2 (main) (#​44816) (ee7285a)
Miscellaneous Chores

v43.279.0

Compare Source

Features
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.77.0 (main) (#​44802) (609a1be)
Documentation
Miscellaneous Chores
Code Refactoring
Tests

v43.278.5

Compare Source

Bug Fixes
Miscellaneous Chores

v43.278.4

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.76.12 (main) (#​44790) (5a400e2)
Miscellaneous Chores
Tests

v43.278.3

Compare Source

Miscellaneous Chores
  • deps: update dependency vitest-mock-extended to v5 (main) (#​44786) (d6f2426)
Build System

v43.278.2

Compare Source

Bug Fixes

v43.278.1

Compare Source

Build System

v43.278.0

Compare Source

Features

v43.277.1

Compare Source

Bug Fixes
  • presets/monorepo: update react and react-native source URLs to react/react org (#​44780) (61e4c9c)
Documentation

v43.277.0

Compare Source

Features
Bug Fixes

v43.276.0

Compare Source

Features
Bug Fixes
Miscellaneous Chores

v43.275.2

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.76.11 (main) (#​44775) (381a5b4)
Miscellaneous Chores

v43.275.1

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.76.10 (main) (#​44771) (5586073)
Miscellaneous Chores

v43.275.0

Compare Source

Features

v43.274.0

Compare Source

Features
Miscellaneous Chores
  • deps: update github/codeql-action action to v4.37.2 (main) (#​44760) (2f7284f)
Code Refactoring

v43.273.0

Compare Source

Features
  • platform: get all branch update dates in a more performant manner (#​44582) (f932d52)
Code Refactoring
  • config/global: improve type restrictions for GlobalConfig.OPTIONS (#​44636) (d16dc9a)

v43.272.9

Compare Source

Bug Fixes
  • manager/dockerfile: handle single-quoted empty ARG default value (#​44522) (1f5f6da)

v43.272.8

Compare Source

Bug Fixes
  • git-submodule: handle ./ relative paths in URL resolution (#​44742) (bad5e22)

v43.272.7

Compare Source

Bug Fixes
  • gomod: pseudo-version digest updates produce no change when module is absent from go proxy (#​44477) (e5ace74)

v43.272.6

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.76.8 (main) (#​44747) (a00c621)
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.76.9 (main) (#​44748) (d2aa7e3)
Miscellaneous Chores
Tests

v43.272.5

Compare Source

Bug Fixes
  • deps: update ghcr.io/renovatebot/base-image docker tag to v13.76.7 (main) (#​44743) (1e7391f)
Miscellaneous Chores
Code Refactoring
Tests
  • linters: add linting rule to enforce v8 ignore reason declaration (#​44726) (91e068f)
Continuous Integration

v43.272.4

Compare Source

Documentation
Tests
Build System

v43.272.3

Compare Source

Bug Fixes

v43.272.2

Compare Source

Bug Fixes
  • platform/azure: evaluate policies before attempting to merge PR (#​44631) (7ac677d)
Code Refactoring

[`v43

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 4am on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from fstab as a code owner July 27, 2026 00:41
@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Jul 27, 2026
@renovate
renovate Bot enabled auto-merge (squash) July 27, 2026 00:41
@github-actions

Copy link
Copy Markdown
Contributor

Benchmark results

Benchmark run finished with conclusion skipped for b9ce3dd36492712f4a45e396c5e268dfb49416ec.

Benchmark summary artifact was not found; see the workflow run for details.

@renovate
renovate Bot force-pushed the renovate/linters branch from b9ce3dd to 44af042 Compare July 27, 2026 06:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants