chore(deps): update devdependencies (major) - #485
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
15 times, most recently
from
September 12, 2026 03:09
9c90a2e to
ea96bf1
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
10 times, most recently
from
September 19, 2026 01:48
d78fc22 to
25648e2
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
3 times, most recently
from
September 23, 2026 03:58
bda9bde to
c6387c4
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
6 times, most recently
from
September 29, 2026 15:46
adfda01 to
f3906dd
Compare
renovate
Bot
force-pushed
the
renovate/major-devdependencies
branch
from
September 30, 2026 20:19
f3906dd to
a25782e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^4.0.2→^6.0.0^1.11.1→^3.0.0^1.1.1→^3.0.02.2.3→4.0.1^1.1.3→^3.0.0^2.0.2→^4.0.0^7.26.9→^8.0.0^7.27.1→^8.0.0^1.9.4→^2.0.0^25.0.0→^29.0.0^13.0.0→^16.0.0^16.0.0→^18.0.0^14.0.0→^18.0.0^1000.0.7→^1100.0.0^29.5.14→^30.0.0^22.13.8→^26.0.0^1.0.1→^2.0.07.0.3→10.1.0^9.0.0→^10.0.0^1.22.1→^2.0.0^29.7.0→^30.0.0^19.3.1→^23.0.0^8.0.4→^9.0.0^6.1.4→^7.0.0^5.8.2→^7.0.0^7.3.1→^8.0.0Release Notes
actions/toolkit (@actions/cache)
v6.3.0v6.2.0cache read denied:prefix on cache download failures (both the v2 twirp path and the v1_apis/artifactcachepath) and surface it as acore.warning(without failing the run).ACTIONS_CACHE_MODEenvironment variable: skip restore when the effective cache-mode does not permit reads (none,write-only) and skip save when it does not permit writes (none,read), logging a single non-fatalcore.infoline. WhenACTIONS_CACHE_MODEis unset or unrecognized, behavior is unchanged.v6.1.0cache write denied:prefix on cache reservation failures and surface it as acore.warning(without failing the run).v6.0.1@actions/coreto^3.0.1@actions/http-clientto^4.0.1@actions/ioto^3.0.2@azure/core-rest-pipelineto^1.23.0@azure/storage-blobto^12.31.0semverto^7.7.4v6.0.0import()instead ofrequire()v5.3.0cache.tar#2497.v5.2.0cache read denied:prefix on cache download failures (both the v2 twirp path and the v1_apis/artifactcachepath) and surface it as acore.warning(without failing the run).ACTIONS_CACHE_MODEenvironment variable: skip restore when the effective cache-mode does not permit reads (none,write-only) and skip save when it does not permit writes (none,read), logging a single non-fatalcore.infoline. WhenACTIONS_CACHE_MODEis unset or unrecognized, behavior is unchanged.v5.1.0cache write denied:prefix on cache reservation failures and surface it as acore.warning(without failing the run).v5.0.5@actions/globto0.5.1v5.0.4@actions/http-clientto3.0.2v5.0.3Prevent retries for rate limited cache operations 2243.
v5.0.1@azure/storage-blobfrom^12.13.0to^12.29.1#2213@azure/core-rest-pipelineinstead of deprecated@azure/core-http, which eliminates the transitive dependency onnode-fetch@2→whatwg-url@5→tr46@0.0.3that used the deprecated punycode modulev5.0.0@azure/ms-rest-jsdependency #2197TransferProgressEventtype is now imported from@azure/core-rest-pipelineinstead of@azure/ms-rest-js@actions/corefrom^1.11.1to^2.0.0#2198@actions/execfrom^1.0.1to^2.0.0#2198@actions/globfrom^0.1.0to^0.5.0#2198@actions/http-clientfrom^2.1.1to^3.0.0#2198@actions/iofrom^1.0.1to^2.0.0#2198node-fetchoverride to resolve audit vulnerabilities #2110actions/toolkit (@actions/core)
v3.0.1undicifrom6.23.0to6.24.1#2348v3.0.0import()instead ofrequire()v2.0.3@actions/http-clientto3.0.2v2.0.1v2.0.0actions/toolkit (@actions/exec)
v3.0.0import()instead ofrequire()v2.0.0actions/toolkit (@actions/http-client)
v4.0.1undicifrom6.23.0to6.24.0#2347v4.0.0import()instead ofrequire()v3.0.2undicifrom5.28.5to6.23.0v3.0.1v3.0.0actions/toolkit (@actions/io)
v3.0.2v3.0.1@actions/io/lib/io-utilv3.0.0import()instead ofrequire()v2.0.0actions/toolkit (@actions/tool-cache)
v4.0.0import()instead ofrequire()3.0.1
@actions/http-clientto3.0.23.0.0
@actions/core@actions/exec@actions/http-client@actions/io2.0.2
@actions/coreto v1.11.1 #1872uuidpackage #1824, #18422.0.1
@actions/http-client#10872.0.0
@actions/http-clientheadersparameter in the exported functiondownloadToolhas been narrowed from{ [header: string]: any }to{ [header: string]: number | string | string[] | undefined; }(that is,http.OutgoingHttpHeaders).This is strictly a compile-time change for TypeScript consumers. Previous attempts to use a header value of a type other than those now accepted would have resulted in an error at run time.
1.7.2
lockfileVersiontov2inpackage-lock.json#10251.7.1
1.7.0
isExplicitVersionandevaluateVersionsfunctions1.6.1
1.6.0
1.3.5
1.3.4
Here is the security issue that was fixed in the http-client 1.0.8 release
1.3.3
1.3.2
1.3.1
1.3.0
1.2.0
extractTaron Windows1.1.2
extractTar1.0.0
v3.0.1@actions/http-clientto3.0.2v3.0.0@actions/core@actions/exec@actions/http-client@actions/iobabel/babel (@babel/core)
v8.0.6Compare Source
👓 Spec Compliance
babel-helper-validator-identifier,babel-parser🐛 Bug Fix
babel-parserbabel-helper-string-parser,babel-parser🏠 Internal
babel-code-frame,babel-core,babel-generator,babel-helper-create-class-features-plugin,babel-helper-module-transforms,babel-parser,babel-plugin-bugfix-safari-rest-destructuring-rhs-array,babel-plugin-proposal-destructuring-private,babel-plugin-proposal-discard-binding,babel-plugin-transform-regenerator,babel-plugin-transform-typescript,babel-preset-env,babel-traverse,babel-typesbabel-parserbabel-corebabel-build-external-helpers,babel-cli,babel-code-frame,babel-core,babel-generator,babel-helper-compilation-targets,babel-helper-create-class-features-plugin,babel-helper-globals,babel-helper-string-parser,babel-helper-transform-fixture-test-runner,babel-helper-validator-identifier,babel-node,babel-parser,babel-plugin-transform-async-generator-functions,babel-plugin-transform-runtime,babel-register,babel-runtime-corejs3,babel-traverse🏃♀️ Performance
babel-helper-compilation-targets,babel-helper-transform-fixture-test-runnerlru-cachewithflru(@nicolo-ribaudo)v8.0.5Compare Source
👓 Spec Compliance
babel-parser🐛 Bug Fix
babel-parserbabel-plugin-transform-destructuringbabel-plugin-transform-typescriptenuminto anamespace(@nicolo-ribaudo)babel-nodebabel-plugin-bugfix-safari-rest-destructuring-rhs-arraybabel-traversegetAll{Prev,Next}Siblings(@JLHwung)babel-plugin-transform-block-scopingbabel-generatorbabel-registerbabel-cli,babel-helper-transform-fixture-test-runner,babel-registerbabel-standalone@babel/standalone(@liuxingbaoyu)📝 Documentation
🏠 Internal
babel-cli,babel-core,babel-helper-compilation-targets,babel-helper-create-class-features-plugin,babel-helper-create-regexp-features-plugin,babel-helper-fixtures,babel-preset-envsemverwithverkit(@sxzz)babel-nodebabel-types🏃♀️ Performance
babel-parser@babel/parser(@liuxingbaoyu)v8.0.1Compare Source
💥 Breaking Change
babel-core,babel-plugin-transform-object-rest-spread,babel-plugin-transform-runtime,babel-preset-env,babel-standalonepreset-env'suseBuiltIns(@nicolo-ribaudo)v8.0.0Compare Source
👓 Spec Compliance
babel-core💥 Breaking Change
babel-cli,babel-node,babel-plugin-proposal-decorators,babel-plugin-transform-classes,babel-plugin-transform-function-name,babel-plugin-transform-modules-commonjs,babel-plugin-transform-object-rest-spread,babel-plugin-transform-parameters,babel-plugin-transform-react-constant-elements,babel-plugin-transform-regenerator,babel-preset-env,babel-registermodules: auto(@nicolo-ribaudo)babel-plugin-transform-runtime,babel-runtime-corejs3,babel-runtime@babe/runtime-corejs3(@liuxingbaoyu)babel-parserlocations: "packed"(@liuxingbaoyu)🐛 Bug Fix
babel-generatorbabel-plugin-transform-modules-systemjs📝 Documentation
🏠 Internal
🏃♀️ Performance
babel-corebiomejs/biome (@biomejs/biome)
v2.5.15Compare Source
Patch Changes
#10634
b436ba0Thanks @subaru-hello! - Added the new nursery rulenoReactObjectTypeAsDefaultProp, which disallows array, object, and function values as default props in React components.For example, the following snippet triggers the rule.
#11956
faa8b37Thanks @dyc3! - Added the nursery rulenoSvelteExportLet, which disallows declaring Svelte component props with the legacyexport letsyntax. Use the$props()rune instead.#10816
1b9479eThanks @Th3S4mur41! - Added a new nursery ruleuseLogicalPropertiesthat enforces the use of logical properties in CSS, promoting better internationalization and accessibility practices. The rule supports adirectionoption with"ltr"as the default and"rtl"as the alternative.This is a first rule covering parts of #9034
{ "linter": { "rules": { "nursery": { "useLogicalProperties": { "level": "warn", "options": { "direction": "rtl" } } } } } }#11960
1fdb5c2Thanks @dyc3! - Added the nursery ruleuseSvelteKitRuneImports, which reports imports from the deprecated$app/storesmodule and suggests$app/stateinstead.#11723
3b429d1Thanks @m1handr! - Fixed #11656:noAstroSetHtmlDirectivenow correctly reportsset:htmldirectives inside Astro template expressions.#12023
874d5aeThanks @codspeed! - Improved the performance of the HTML formatter up to 4x.#11761
a3462feThanks @saberoueslati! - Fixed #11351:useSimplifiedLogicExpressionno longer reports boolean literals on the right side of||and&&outside boolean contexts, because removing them can change the result of the expression. For example,y = x || falseis no longer reported, whileif (x || false)still is.#11732
ff4c4ddThanks @dyc3! - Added the nursery rulenoMeaninglessVoidOperator, which reports unnecessary uses ofvoid, such asvoid log()whenlogreturnsvoid. The rule allows discarded call results, thenables,void 0, and calls returningnever.#11975
40dd3fbThanks @ematipico! - Fixed the indentation of multiline Astro expressions, in templates and attribute values, when runningbiome check --write. Biome now formats Astro expressions withbiome formattoo, and places them at the column of the surrounding markup.<div> {items.map((item) => ( - <span>{item}</span> -))} + <span>{item}</span> + ))} </div>#12016
09d4000Thanks @codspeed! - Improved the performance of indexing and analysis of big files up to 2x. The improvements are mostly visible in projects that make use of project and types lint rules.#11750
089bde0Thanks @dyc3! - Added the nursery ruleuseStrictBooleanExpressions, which reports ambiguous truthiness checks such asif (value)whenvaluehas typenumber | undefined. Non-nullable strings and numbers and nullable objects are allowed; the rule has no options.#11494
ad5b362Thanks @jp-knj! - Added the nursery rulenoAstroConflictingSetDirectives, which reports Astro elements with multiple content sources, such asset:html,set:text, and child content.For example,
<div set:html={html}>content</div>triggers the rule.#11878
84d1b3bThanks @dyc3! - Fixed #11748:useExhaustiveSwitchCasesnow reports missing cases for values created with the mapping overload ofArray.from, including arrays imported from another module.#11802
7d1f37eThanks @dyc3! - Tailwind classes will now be detected in Svelte, Vue, and Astro class attribute expressions that don't use a class merging function.#11910
9e50ea2Thanks @ematipico! - Fixed #11504, a regression where Biome would silently ignore errors in the configuration file. Now errors are correctly retained and checked before executing any command.#11921
d568632Thanks @hirehamir! - Fixed #10846: when plugins fail to load, Biome now prints each failing plugin's path on its own line, instead of concatenating bare messages likeCannot read file.Cannot read file..#11930
82ea5a6Thanks @dyc3! - Fixed #11927: The HTML formatter no longer duplicates comments around Svelte blocks. This affected a comment after a block such as{#if}or{#each}at the end of an element, and a comment on the same line as the last element inside a block, before{:else},{/if}, or a similar tag.#11931
0cc46d8Thanks @dyc3! - Fixed the indentation of comments at the end of a Svelte block's contents. A comment before{:else},{:then},{/if}, or a similar tag is now indented with the block's contents instead of with the tag.{#if condition} <span>Text</span> -<!-- comment --> + <!-- comment --> {/if}#12031
ef0edd4Thanks @dyc3! - Fixed #12027: Biome's test rules no longer mistake regular method calls namedtest,it, ordescribefor tests. For example,useValidTestTitleused to report the following regular expression check as a test with an invalid title:#11959
8477e61Thanks @dyc3! - Fixed #11950:noUnusedVariablesnow reports arrow functions with expression bodies that only reference themselves, such aslet h = () => h();.#11915
3260602Thanks @ematipico! - Fixed #11841, where suppression comments had no effect on some parts of HTML-ish files and on snippets embedded in JavaScript files.Now the following suppression works as expected:
#11952
b51040eThanks @dyc3! - Fixed #11951: the GritQL formatter no longer inserts a space after awithinpattern without anuntilclause.#11794
429cf95Thanks @dyc3! - Added the nursery rulenoTailwindRawColorsfor JavaScript and HTML. It disallows Tailwind palette colors such asbg-pink-500andtext-white, encouraging design system color utilities such asbg-primary.#11837
f5e249bThanks @dyc3! - Fixed #11836:biome check --writeno longer adds invalid parentheses around Svelte{@const}declarations when experimental HTML support and formatting are enabled.#11978
8be0b9eThanks @dyc3! - Fixed #11817: Biome no longer crashes when its output is piped to a program that exits early, such ashead. Output to the closed pipe is now discarded and Biome exits normally.#11868
3841c26Thanks @ematipico! - Fixed #8986: Biome's language server now scopes all watched-file patterns to each workspace folder, falling back to the deprecatedrootUriwhen no workspace folders are provided. Clients without relative-pattern support receive compatible absolute glob patterns.#11928
0015681Thanks @dyc3! - Restricted access to the Unix daemon socket to the user running Biome. The socket now lives in abiome-daemondirectory inside Biome's cache directory that only this user can access, and the socket itself has mode0600.#11835
589ca1aThanks @dyc3! - UpdateduseReactCompiler: Biome now reports React Compiler diagnostics regardless of the React version declared inpackage.json.#11907
b7d9037Thanks @posido! - Fixed withastro/compiler-rs#194: the HTML parser no longer treats a regex literal that starts with>as the end of a self-closing tag. Astro frontmatter such asconst escaped = s.replace(/>/g, ">");no longer swallows the closing---fence, and the same regex inside a template expression no longer runs past its closing}. A regex literal after a keyword such asreturn, as inreturn />'/.test(s), is now recognized too.#12021
59cc595Thanks @dyc3! - Type inference performance has been significantly improved. Some popular libraries like Zod, Valibot, Arktype, Effect, Kysely, and Drizzle have gained a ~2-240x speedup in our benchmarks. This improvement affects all rules that use type information.#12044
c73fb91Thanks @dyc3! - Fixed #12042: the HTML formatter no longer removes the space between text and an inline element on the next line when it joins the lines.#11965
f90bf38Thanks @ematipico! - Fixed module resolution in long-running workspaces so imports reflect package manifest and TypeScript path-mapping changes without requiring the importing file to be edited.#11860
0884e29Thanks @dyc3! - Removed theattributesandfunctionsoptions from the nursery rulenoTailwindArbitraryValue. The rule now uses the same Tailwind detection asuseTailwindShorthandClasses.#11969
865cd30Thanks @AlbinoGeek! - Fixed #11962:noUnknownTypeSelectorno longer reports view transition names inside view transition pseudo-elements, such aspagein::view-transition-group(page).#11914
06ff47bThanks @dyc3! - Fixed #11897: the safe fix fornoUselessStringConcatnow escapes embedded double quotes when combining literals, preserving valid JavaScript and existing escape sequences.#11997
af7825fThanks @github-actions! - The noRestrictedDependencies rule has been updated with new module replacement data, it should now detect for more relevant replacements.#11827
31bb662Thanks @dfedoryshchev! - Fixed #11566:useNamingConventionno longer reports anamespacedeclared insidedeclare globalor inside an external module declaration. Both positions are documented as always ignored, and the rule offered a safe fix, sobiome check --writerenamed the declaration:#11814
23ba25fThanks @siketyan! - Fixed type inference through generic type aliases that instantiate another generic type with a nested generic argument, such astype Nested<T> = Box<Wrapper<T>>. Type-aware rules now resolve members of such types:Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.