chore(deps): update linters#2346
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
requested review from
dhoard,
jaydeluca and
zeitlinger
as code owners
July 27, 2026 00:41
Contributor
Benchmark resultsBenchmark run finished with conclusion
Benchmark summary artifact was not found; see the workflow run for details. |
renovate
Bot
force-pushed
the
renovate/linters
branch
from
July 27, 2026 06:38
b9ce3dd to
44af042
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.4.3→0.4.42.5.3→2.5.543.257.4→43.279.143.281.1(+8)0.15.21→0.16.0v0.2.31→v0.2.431.26.1→1.28.0Release Notes
jonwiggins/xmloxide (aqua:jonwiggins/xmloxide)
v0.4.4Compare Source
Security
(CVE-2026-61727 / GHSA-7jmw-29gc-ffx4, thanks @williamareynolds). The DTD
parser recursed without a depth bound when parsing an
<!ELEMENT>contentmodel, so a small untrusted document with many nested
(in a content modelcould overflow the stack and abort the process — an uncatchable denial of
service (CWE-674). This is reachable on the default parse path because the
internal DTD subset is parsed during ordinary parsing, and the existing
ParseOptions::max_depthdid not cover it (it bounds element nesting, not theDTD content-model grammar). The content-model recursion is now bounded at 256
levels and returns a normal
ParseErrorpast the limit; well-formed DTDs areunaffected.
biomejs/biome (biome)
v2.5.5: Biome CLI v2.5.5Compare Source
2.5.5
Patch Changes
#10972
ab8c21bThanks @ematipico! - FixeduseExhaustiveSwitchCasesfor unions of bigint literals. The rule now reports missing bigint cases and compares bigint literals by value, including binary, octal, hexadecimal, and separator-containing spellings. For example, this switch now reports the missing2ncase:#10972
ab8c21bThanks @ematipico! - Fixed false positives innoBaseToStringanduseNullishCoalescingwhen member, stringification, or nullish inference cannot complete. These rules now suppress diagnostics instead of reporting from partial type information. For example, neither expression is reported when a recursive type cannot be fully resolved:#10977
0bf7486Thanks @ematipico! - Fixed #10922: the actionuseSortedAttributesno longer triggers for HTML instructions.#10957
cf263c4Thanks @dyc3! - FixednoThenPropertyfailing to detectObject.fromEntries,Object.defineProperty, andReflect.definePropertycalls with comments between their tokens.#10983
edc0ed7Thanks @ayaangazali! - Fixed #10980:useAriaPropsSupportedByRoleno longer reports false positives when the attribute that determines an element's implicit ARIA role is written as a shorthand attribute, such as<a {href} aria-label="...">in Astro and Svelte files.Shorthand attributes are now taken into account when computing the implicit role, so the anchor above correctly resolves to the
linkrole instead ofgeneric.#10889
89526e3Thanks @denbezrukov! - Fixed CSS formatter casing for syntax-owned names while preserving author-defined names, including scoped keyframes and container scroll-state queries.#10964
794ccd0Thanks @denbezrukov! - Fixed CSS formatting for comments between declaration values and!important.#10993
b7a9694Thanks @denbezrukov! - Fixed the CSS formatter to preserve comments on the correct side of selector combinators and before declaration blocks.It now also keeps selectors with escaped newlines in attribute values inline when they fit.
#10978
8ebafe1Thanks @ematipico! - Fixed #10870:noUnresolvedImportsno longer reports false positives such asimport type { NextRequest } from "next/server".#10901
68c10e6Thanks @Socialpranker! - Fixed #10622: the HTML/Vue parser no longer panics on the argument-lessv-bindshorthand (:="props").This syntax is valid Vue and equivalent to
v-bind="props", so the parser now accepts it (along with the longhandv-bind:="props") instead of crashing while building a diagnostic for a missing argument.#10936
7df46f5Thanks @ematipico! - Improved generic tuple inference foruseIncludes. The rule now recognizes specialised tuple element types returned through generic aliases.#10941
f787725Thanks @siketyan! - Fixed#10855: Biome now supports parsing and formatting CSS custom media queries declared with@custom-media.#10969
72d309bThanks @ematipico! - Fixed an issue where Biome logs became too verbose, dumping information not relevant to user's operations.e62f6b6Thanks @ematipico! - Fixed #10963: Biome no longer panics when a type-aware rule such asnoFloatingPromiseschecks a call to a function with multiple call signatures imported from another module.#10931
899c60dThanks @ematipico! - Fixedcheck --writecommand. Now the command reports code frame of the formatted code, if the formatter is enabled.#10904
ceee4f4Thanks @qzwxsaedc! - Fixed #10892:noUnnecessaryConditionsno longer reports a false positive when checking a member of a discriminated union that is accessed through a default type-only namespace import. The following code is no longer flagged:#10962
f0a67f2Thanks @ematipico! - Biome no longer removes embedded styles and scripts in HTML files.#11000
5039a1eThanks @ematipico! - Fixed a bug where closing one editor stopped a shared Biome daemon used by other editors. LSP proxy processes now exit when either the editor or daemon disconnects.#10957
cf263c4Thanks @dyc3! - Improved the performance of thenoThenPropertylint rule by about 50%.#10992
4bf9b21Thanks @ematipico! - FixednoMisusedPromises: The rule now reports Promise-returning callbacks where a synchronous callback is expected when calls use tuple spreads or tuple rest parameters, including generic and deeply nested tuples, and when constructor signatures come from interface or object types. Recursive or excessively nested tuple spreads use a conservative fallback so analysis terminates.For example, the following callback is now reported.
#10915
b3b12b3Thanks @Functionhx! - Added the rulenoNegationInEqualityCheck. The rule flags negated expressions on the left side of strict equality checks like!foo === bar— due to operator precedence this evaluates as(!foo) === barwhich is almost always a mistake forfoo !== bar.The rule provides an unsafe fix that flips the operator.
#10970
bd1038bThanks @ematipico! - Improved overload selection fornoMisusedPromises. Biome now handles overloaded calls, overloaded constructors, rest parameters, union arguments, and generic constraints without selecting an incompatible signature. For example,noMisusedPromisesnow reports the async callback passed to the synchronous overload:#10933
48a4abbThanks @ematipico! - FixeduseArrayFindto recognize bigint zero indexes.#10931
899c60dThanks @ematipico! - Fixed an orchestration issue that could lead to deadlocks when type-aware rules are enabled.#10969
72d309bThanks @ematipico! - Hardened the Biome Language Server by improving its synchronisation logic.#10972
ab8c21bThanks @ematipico! - Fixed false positives innoMisusedPromisesanduseAwaitThenablewhen Promise or thenable inference cannot complete. These rules now suppress diagnostics instead of treating incomplete type information as a definite result. For example,useAwaitThenableno longer reportsawait valuewhen the value's thenability is unknown:What's Changed
process_filecall stateless by @ematipico in #10931:="props"in HTML/Vue by @Socialpranker in #10901Text, preferTokenTextby @dyc3 in #10967exportsis missing by @ematipico in #10978New Contributors
Full Changelog: https://github.com/biomejs/biome/compare/@biomejs/biome@2.5.4...@biomejs/biome@2.5.5
v2.5.4: Biome CLI v2.5.4Compare Source
2.5.4
Patch Changes
#10665
55ff995Thanks @dyc3! - Improved the performance of the HTML parser slightly in our synthetic benchmarks.#10894
f4fb10eThanks @ematipico! - Fixed #6392: On-type formatting no longer moves comments before anifstatement into its body.#10939
f2799dbThanks @Netail! - Fixed #10930:noLabelWithoutControlnow correctly detects text interpolation in Astro, Svelte & Vue as valid accessible content.#10945
ae15d98Thanks @Netail! - Fixed #10942: Svelte directives don't throw an accidental debug log anymore.#10842
5e1abfeThanks @JamBalaya56562! - Fixed #9196:biome check --write --unsafeno longer hangs forever when applying thenoCommentTextcode fix.The rule's fix now wraps the comment in a real JSX expression container (
{/* comment */}) instead of re-inserting the braces as plain JSX text, so the fixed code is no longer reported again by the same rule.#10891
ecca79eThanks @ematipico! - Fixed#10885: prevented a module-inference regression introduced by a housekeeping change.#10886
60c8043Thanks @dyc3! - Fixed #10727: Biome now breaks the arguments of curriedtest.each,it.each,describe.each, andtest.forcalls when they exceed the configured line width.#10895
01a85f0Thanks @ematipico! - Biome will now remove stale Unix daemon sockets from older Biome versions when starting a newer daemon.What's Changed
Full Changelog: https://github.com/biomejs/biome/compare/@biomejs/biome@2.5.3...@biomejs/biome@2.5.4
renovatebot/renovate (npm:renovate)
v43.279.1Compare Source
Bug Fixes
Miscellaneous Chores
v43.279.0Compare Source
Features
Documentation
Miscellaneous Chores
Code Refactoring
Tests
v43.278.5Compare Source
Bug Fixes
Miscellaneous Chores
v43.278.4Compare Source
Bug Fixes
Miscellaneous Chores
Tests
trust level(#44244) (a72dc7e)v43.278.3Compare Source
Miscellaneous Chores
Build System
v43.278.2Compare Source
Bug Fixes
v43.278.1Compare Source
Build System
v43.278.0Compare Source
Features
v43.277.1Compare Source
Bug Fixes
Documentation
v43.277.0Compare Source
Features
Bug Fixes
v43.276.0Compare Source
Features
sigstore/cosign-installerversion input (#44766) (f01f1b5)Bug Fixes
resolutions'depName# (#44776) (476d10a), closes #44768Miscellaneous Chores
v43.275.2Compare Source
Bug Fixes
Miscellaneous Chores
v43.275.1Compare Source
Bug Fixes
Miscellaneous Chores
v43.275.0Compare Source
Features
v43.274.0Compare Source
Features
Miscellaneous Chores
Code Refactoring
v43.273.0Compare Source
Features
Code Refactoring
GlobalConfig.OPTIONS(#44636) (d16dc9a)v43.272.9Compare Source
Bug Fixes
v43.272.8Compare Source
Bug Fixes
v43.272.7Compare Source
Bug Fixes
v43.272.6Compare Source
Bug Fixes
Miscellaneous Chores
Tests
recommendedwithpreset(#44735) (73d21dd)v43.272.5Compare Source
Bug Fixes
Miscellaneous Chores
Code Refactoring
node/no-syncand migrate to async calls (#44693) (2dbfd85)Tests
Continuous Integration
v43.272.4Compare Source
Documentation
Tests
as LongCommitShain test files (#44681) (1e03699)Build System
v43.272.3Compare Source
Bug Fixes
globalandinheritedJSON schemas (#44674) (29ca969)v43.272.2Compare Source
Bug Fixes
Code Refactoring
localDirisn't aglobalOnlyoption (#44635) (0e6429b)[`v43
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.