build(deps-dev): bump all - #1272
Conversation
|
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
🚮 Removed packages: npm/cspell@8.8.3, npm/cssnano@7.0.1, npm/dprint@0.46.1, npm/editorconfig-checker@5.1.5, npm/prettier@3.3.0 |
|
👍 Dependency issues cleared. Learn more about Socket for GitHub ↗︎ This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. Ignoring: Next stepsTake a deeper look at the dependencyTake a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev. Remove the packageIf you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency. Mark a package as acceptable riskTo ignore an alert, reply with a comment starting with |
15b1a09 to
dd49c12
Compare
|
@SocketSecurity ignore npm/@biomejs/biome@1.8.1 npm/@biomejs/biome@1.7.3 npm/dprint@0.46.1 |
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
dd49c12 to
bb1d2d1
Compare
PR URL: #1272 Reviewed-by: Derek Lewis <dereknongeneric@open.inf.is> Reviewed-by: OpenINF-bot <openinfbot@open.inf.is> --------- Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-Authored-By: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates:
1.7.3->1.8.10.62.0->0.64.0v4.1.6->v4.1.78.8.3->8.8.47.0.1->7.0.20.46.1->0.46.25.1.5->5.1.8v3.25.7->v3.25.109.1.4->9.3.09.1.4->9.3.03.3.0->3.3.2cffeb57->550dfda3.3.2->3.3.3v1.178.0->v1.180.0Release Notes
biomejs/biome (@biomejs/biome)
v1.8.1Compare Source
Analyzer
CLI
Bug fixes
--stagedor--changedoptions. Contributed by @unvalleyConfiguration
Bug fixes
indentWidth. Contributed by @ematipicoEditors
Formatter
Bug fixes
JavaScript APIs
Linter
Bug fixes
The
noEmptyBlockcss lint rule now treats empty blocks containing comments as valid ones. Contributed by @Sec-antuseLiteralKeys no longer reports quoted member names (#3085).
Previously useLiteralKeys reported quoted member names that can be unquoted.
For example, the rule suggested the following fix:
This conflicted with the option quoteProperties of our formatter.
The rule now ignores quoted member names.
Contributed by @Conaclos
noEmptyInterface now ignores empty interfaces in ambient modules (#3110). Contributed by @Conaclos
noUnusedVariables and noUnusedFunctionParameters no longer report the parameters of a constructor type (#3135).
Previously,
argwas reported as unused in a constructor type like:Contributed by @Conaclos
noStringCaseMismatch now ignores escape sequences (#3134).
The following code is no longer reported by the rule:
Contributed by @Conaclos
Parser
New features
Bug fixes
v1.8.0Compare Source
Analyzer
New features
used for the lint rule
useExhaustiveDependencies, which is now able tosuppress specific dependencies. Fixes #2509. Contributed by @arendjr
Enhancements
Astroobject is always a global when processing.astrofiles. Contributed by @minht11.vuefiles. (#2771) Contributed by @dyc3CLI
New features
New
cleancommand. Use this new command to clean after thebiome-logsdirectory, and remove all the log files.Add two new options
--onlyand--skipto the commandbiome lint(#58).The
--onlyoption allows you to run a given rule or rule group,For example, the following command runs only the
style/useNamingConventionandstyle/noInferrableTypesrules.If the rule is disabled in the configuration, then its severity level is set to
errorfor a recommended rule orwarnotherwise.Passing a group does not change the severity level of the rules in the group.
All the disabled rules in the group will remain disabled.
To ensure that the group is run, the
recommendedfield of the group is enabled.The
nurserygroup cannot be passed, as no rules are enabled by default in the nursery group.The
--skipoption allows you to skip the execution of a given group or a given rule.For example, the following command skips the
stylegroup and thesuspicious/noExplicitAnyrule.You can also use
--onlyand--skiptogether.--skipoevrrides--only.The following command executes only the rules from the
stylegroup, but thestyle/useNamingConventionrule.These options are compatible with other options such as
--write(previously--apply), and--reporter.Contributed by @Conaclos
Add new command
biome clean. Use this command to purge all the logs emitted by the Biome daemon. This command is really useful, because the Biome daemon tendslog many files and contents during its lifecycle. This means that if your editor is open for hours (or even days), the
biome-logsfolder could become quite heavy. Contributed by @ematipicoAdd support for formatting and linting CSS files from the CLI. These operations are opt-in for the time being.
If you don't have a configuration file, you can enable these features with
--css-formatter-enabledand--css-linter-enabled:Contributed by @ematipico
Add new CLI options to control the CSS formatting. Check the CLI reference page for more details. Contributed by @ematipico
Add new options
--write,--fix(alias of--write) and--unsafeto the commandbiome lintandbiome check.Add a new option
--fix(alias of--write) to the commandbiome formatandbiome migrate.The
biome <lint|check> --<write|fix>has the same behavior asbiome <lint|check> --apply.The
biome <lint|check> --<write|fix> --unsafehas the same behavior asbiome <lint|check> --apply-unsafe.The
biome format --fixhas the same behavior asbiome format --write.The
biome migrate --fixhas the same behavior asbiome migrate --write.This change allows these commands to write modifications in the same options.
With this change, the
--applyand--apply-unsafeoptions are deprecated.Contributed by @unvalley
Enhancements
Biome now executes commands (lint, format, check and ci) on the working directory by default. #2266 Contributed by @unvalley
biome migrate eslintnow tries to convert ESLint ignore patterns into Biome ignore patterns.ESLint uses gitignore patterns.
Biome now tries to convert these patterns into Biome ignore patterns.
For example, the gitignore pattern
/srcis a relative path to the file in which it appears.Biome now recognizes this and translates this pattern to
./src.Contributed by @Conaclos
biome migrate eslintnow supports theeslintIgnorefield inpackage.json.ESLint allows the use of
package.jsonas an ESLint configuration file.ESLint supports two fields:
eslintConfigandeslintIgnore.Biome only supported the former. It now supports both.
Contributed by @Conaclos
biome migrate eslintnow propagates NodeJS errors to the user.This will help users to identify why Biome is unable to load some ESLint configurations.
Contributed by @Conaclos
Add a new
--reportercalledsummary. This reporter will print diagnostics in a different way, based on the tools (formatter, linter, etc.) that are executed.Import sorting and formatter shows the name of the files that require formatting. Instead, the linter will group the number of rules triggered and the number of errors/warnings:
Contributed by @ematipico
biome cinow enforces printing the output using colours. If you were previously using--colors=force, you can remove it because it's automatically set. Contributed by @ematipicoAdd a new
--reportercalledgithub. This reporter will print diagnostics using GitHub workflow commands:Contributed by @ematipico
Add a new
--reportercalledjunit. This reporter will print diagnostics using GitHub workflow commands:Contributed by @ematipico
Bug fixes
biome initwould createbiome.jsoneven ifbiome.jsoncalready exists. Contributed by @minht11Configuration
New features
Add an rule option
fixto override the code fix kind of a rule (#2882).A rule can provide a safe or an unsafe code action.
You can now tune the kind of code actions thanks to the
fixoption.This rule option takes a value among:
none: the rule no longer emits code actions.safe: the rule emits safe code action.unsafe: the rule emits unsafe code action.The following configuration disables the code actions of
noUnusedVariables, makes the emitted code actions ofstyle/useConstandstyle/useTemplateunsafe and safe respectively.{ "linter": { "rules": { "correctness": { "noUnusedVariables": { "level": "error", "fix": "none" }, "style": { "useConst": { "level": "warn", "fix": "unsafe" }, "useTemplate": { "level": "warn", "fix": "safe" } } } } } }Contributed by @Conaclos
Add option
javascript.linter.enabledto control the linter for JavaScript (and its super languages) files. Contributed by @ematipicoAdd option
json.linter.enabledto control the linter for JSON (and its super languages) files. Contributed by @ematipicoAdd option
css.linter.enabledto control the linter for CSS (and its super languages) files. Contributed by @ematipicoAdd option
css.formatter, to control the formatter options for CSS (and its super languages) files. Contributed by @ematipicoYou can now change the severity of lint rules down to
"info". The"info"severity doesn't emit error codes, and it isn't affected by other options like--error-on-warnings:{ "linter": { "rules": { "suspicious": { "noDebugger": "info" } } } }Contributed by @ematipico
Enhancements
javascript.formatter.trailingCommaoption is deprecated and renamed tojavascript.formatter.trailingCommas. The corresponding CLI option--trailing-commais also deprecated and renamed to--trailing-commas. Details can be checked in #2492. Contributed by @Sec-antBug fixes
override that did not specify the formatter section #2924. Contributed by @dyc3
biome.json. Contributed by @dyc3Editors
New features
Enhancements
Formatting and linting is disabled until the configuration file is fixed. Contributed by @ematipico
Bug fixes
Formatter
Bug fixes
Linter
Promoted rules
New rules are incubated in the nursery group. Once stable, we promote them to a stable group. The following rules are promoted:
New features
Add nursery/useDateNow. Contributed by @minht11
Add nursery/useErrorMessage. Contributed by @minht11
Add nursery/useThrowOnlyError. Contributed by @minht11
Add nursery/useImportExtensions. Contributed by @minht11
useNamingConvention now supports an option to enforce custom conventions (#1900).
For example, you can enforce the use of a prefix for private class members:
{ "linter": { "rules": { "style": { "useNamingConvention": { "level": "error", "options": { "conventions": [ { "selector": { "kind": "classMember", "modifiers": ["private"] }, "match": "_(.*)", "formats": ["camelCase"] } ] } } } } } }Please, find more details in the rule documentation.
Contributed by @Conaclos
Add nursery/useNumberToFixedDigitsArgument.
Contributed by @minht11
Add nursery/useThrowNewError.
Contributed by @minht11
Add nursery/useTopLevelRegex, which enforces defining regular expressions at the top level of a module. #2148 Contributed by @dyc3.
Add nursery/noCssEmptyBlock. #2513 Contributed by @togami2864
Add nursery/noDuplicateAtImportRules. #2658 Contributed by @DerTimonius
Add nursery/noDuplicateFontNames. #2308 Contributed by @togami2864
Add nursery/noDuplicateSelectorsKeyframeBlock. #2534 Contributed by @isnakode
Add nursery/noImportantInKeyframe. #2542 Contributed by @isnakode
Add nursery/noInvalidPositionAtImportRule. #2717 Contributed by @t-shiratori
Add nursery/noUnknownFunction. #2570 Contributed by @neokidev
Add nursery/noUnknownMediaFeatureName. #2751 Contributed by @Kazuhiro-Mimaki
Add nursery/noUnknownProperty. #2755 Contributed by @chansuke
Add nursery/noUnknownSelectorPseudoElement. #2655 Contributed by @keita-hino
Add nursery/noUnknownUnit. #2535 Contributed by @neokidev
Add nursery/noUnmatchableAnbSelector. #2706 Contributed by @togami2864
Add nursery/useGenericFontNames. #2573 Contributed by @togami2864
Add nursery/noYodaExpression. Contributed by @michellocana
Add nursery/noUnusedFunctionParameters Contributed by @printfn
Enhancements
Add a code action for noConfusingVoidType and improve the diagnostics.
The rule now suggests using
undefinedinstead ofvoidin confusing places.The diagnosis is also clearer.
Contributed by @Conaclos
Improve code action for nursery/noUselessUndefinedInitialization to handle comments.
The rule now places inline comments after the declaration statement, instead of removing them.
The code action is now safe to apply.
Contributed by @lutaok
Make useExhaustiveDependencies report duplicate dependencies. Contributed by @tunamaguro
Rename
noEvolvingAnyintonoEvolvingTypes(#48). Contributed by @ConaclosBug fixes
noUndeclaredVariables and noUnusedImports now correctly handle import namespaces (#2796).
Previously, Biome bound unqualified type to import namespaces.
Import namespaces can only be used as qualified names in a type (ambient) context.
Contributed by @Conaclos
noUndeclaredVariables now correctly handle ambient computed member names (#2975).
A constant can be imported as a type and used in a computed member name of a member signature.
Previously, Biome was unable to bind the value imported as a type to the computed member name.
Contributed by @Conaclos
noUndeclaredVariables now ignores
thisin JSX components (#2636).The rule no longer reports
thisas undeclared in following code.Contributed by @printfn and @Conaclos
useJsxKeyInIterablenow handles more cases involving fragments. See the snippets below. Contributed by @dyc3noExcessiveNestedTestSuitesno longer erroneously alerts ondescribecalls that are not invoking the globaldescribefunction. #2599 Contributed by @dyc3noEmptyBlockStatementsno longer reports empty constructors using typescript parameter properties. #3005 Contributed by @dyc3noEmptyBlockStatementsno longer reports empty private or protected constructors. Contributed by @dyc3noExportsInTest rule no longer treats files with in-source testing as test files https://github.com/biomejs/biome/issues/2859. Contributed by @ah-yu
useSortedClasses now keeps leading and trailing spaces when applying the code action inside template literals:
noUndeclaredDependencies is correctly triggered when running
biome ci. Contributed by @ematipiconoUnusedVariables no longer panics when a certain combination of characters is typed. Contributed by @ematipico
noUndeclaredVariables no logger alerts on
argumentsobject in a function scope. Contributed by @ah-yuParser
Enhancements
lang="tsx"is now supported in Vue Single File Components. #2765 Contributed by @dyc3Bug fixes
The
constmodifier for type parameters is now accepted for TypeScriptnewsignatures (#2825).The following code is now correctly parsed:
Contributed by @Conaclos
Some invalid TypeScript syntax caused the Biome parser to crash.
The following invalid syntax no longer causes the Biome parser to crash:
Contributed by @Conaclos
devcontainers/cli (@devcontainers/cli)
v0.64.0Compare Source
v0.63.0Compare Source
devcontainer up. (https://github.com/devcontainers/cli/pull/836)actions/checkout (actions/checkout)
v4.1.7Compare Source
streetsidesoftware/cspell (cspell)
v8.8.4Compare Source
cssnano/cssnano (cssnano)
v7.0.2: v7.0.2Compare Source
Bug Fixes
dprint/dprint (dprint)
v0.46.2Compare Source
Changes
Install
Run
dprint upgradeor see https://dprint.dev/install/Checksums
editorconfig-checker/editorconfig-checker.javascript (editorconfig-checker)
v5.1.8Compare Source
Reverts
v5.1.6 release didn't work because of an issue with the
@vercel/ncccompiler: https://github.com/vercel/ncc/issues/1193, for now we revert the changes, so basically v5.1.8 is the same as v5.1.5.Sorry for the troubles, we also improved our CI, so we should be able to detect this kind of issues in the future.
v5.1.7Compare Source
Reverts
v5.1.6Compare Source
Bug Fixes
github/codeql-action (github/codeql-action)
v3.25.10Compare Source
v3.25.9Compare Source
v3.25.8Compare Source
pnpm/pnpm (pnpm)
v9.3.0Compare Source
Minor Changes
peers-suffix-max-lengthsetting #8177.Patch Changes
reporter-hide-prefixtotrueby default forpnpm exec. In order to show prefix, the user now has to explicitly setreporter-hide-prefix=false#8174.Platinum Sponsors
Gold Sponsors
Our Silver Sponsors
v9.2.0[
Configuration
📅 Schedule: Branch creation - "before 4am on Monday" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate. View repository job log here.