Skip to content

chore(deps): update devdependencies (major) - #485

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/major-devdependencies
Open

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/major-devdependencies

Conversation

@renovate

@renovate renovate Bot commented Sep 5, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@actions/cache (source) ^4.0.2 → ^6.0.0 age confidence
@actions/core (source) ^1.11.1 → ^3.0.0 age confidence
@actions/exec (source) ^1.1.1 → ^3.0.0 age confidence
@actions/http-client (source) 2.2.3 → 4.0.1 age confidence
@actions/io (source) ^1.1.3 → ^3.0.0 age confidence
@actions/tool-cache (source) ^2.0.2 → ^4.0.0 age confidence
@babel/core (source) ^7.26.9 → ^8.0.0 age confidence
@babel/preset-typescript (source) ^7.27.1 → ^8.0.0 age confidence
@biomejs/biome (source) ^1.9.4 → ^2.0.0 age confidence
@octokit/openapi-types (source) ^25.0.0 → ^29.0.0 age confidence
@octokit/plugin-paginate-rest ^13.0.0 → ^16.0.0 age confidence
@octokit/plugin-rest-endpoint-methods ^16.0.0 → ^18.0.0 age confidence
@octokit/types ^14.0.0 → ^18.0.0 age confidence
@pnpm/patching.apply-patch (source) ^1000.0.7 → ^1100.0.0 age confidence
@types/jest (source) ^29.5.14 → ^30.0.0 age confidence
@types/node (source) ^22.13.8 → ^26.0.0 age confidence
admina ^1.0.1 → ^2.0.0 age confidence
cross-env 7.0.3 → 10.1.0 age confidence
cspell (source) ^9.0.0 → ^10.0.0 age confidence
eslint-config-atomic ^1.22.1 → ^2.0.0 age confidence
jest (source) ^29.7.0 → ^30.0.0 age confidence
npm-check-updates ^19.3.1 → ^23.0.0 age confidence
npm-run-all2 ^8.0.4 → ^9.0.0 age confidence
p-timeout ^6.1.4 → ^7.0.0 age confidence
typescript (source) ^5.8.2 → ^7.0.0 age confidence
vite (source) ^7.3.1 → ^8.0.0 age confidence

Release Notes

actions/toolkit (@​actions/cache)

v6.3.0

  • Isolate Windows BSD tar read scratch files per operation and make cleanup best-effort, preventing concurrent cache restores from racing over shared temporary archives (#​2497).
  • Update compatible runtime and development dependencies, refresh transitive dependencies, and resolve npm audit findings.

v6.2.0

  • Handle cache read error due to read-only token: detect the cache read denied: prefix on cache download failures (both the v2 twirp path and the v1 _apis/artifactcache path) and surface it as a core.warning (without failing the run).
  • Honor the ACTIONS_CACHE_MODE environment variable: skip restore when the effective cache-mode does not permit reads (none, write-only) and skip save when it does not permit writes (none, read), logging a single non-fatal core.info line. When ACTIONS_CACHE_MODE is unset or unrecognized, behavior is unchanged.

v6.1.0

  • Handle cache write error due to read-only token: detect the cache write denied: prefix on cache reservation failures and surface it as a core.warning (without failing the run).

v6.0.1

  • Bump dependency versions (#​2393):
    • @actions/core to ^3.0.1
    • @actions/http-client to ^4.0.1
    • @actions/io to ^3.0.2
    • @azure/core-rest-pipeline to ^1.23.0
    • @azure/storage-blob to ^12.31.0
    • semver to ^7.7.4

v6.0.0

  • Breaking change: Package is now ESM-only
    • CommonJS consumers must use dynamic import() instead of require()

v5.3.0

  • Isolate Windows BSD tar scratch files for concurrent cache list and extract operations, preventing calls from sharing cache.tar #​2497.
  • Update compatible runtime and development dependencies and resolve npm audit findings.

v5.2.0

  • Handle cache read error due to read-only token: detect the cache read denied: prefix on cache download failures (both the v2 twirp path and the v1 _apis/artifactcache path) and surface it as a core.warning (without failing the run).
  • Honor the ACTIONS_CACHE_MODE environment variable: skip restore when the effective cache-mode does not permit reads (none, write-only) and skip save when it does not permit writes (none, read), logging a single non-fatal core.info line. When ACTIONS_CACHE_MODE is unset or unrecognized, behavior is unchanged.

v5.1.0

  • Handle cache write error due to read-only token: detect the cache write denied: prefix on cache reservation failures and surface it as a core.warning (without failing the run).

v5.0.5

  • Bump @actions/glob to 0.5.1

v5.0.4

  • Bump @actions/http-client to 3.0.2

v5.0.3

Prevent retries for rate limited cache operations 2243.

v5.0.1

  • Fix Node.js 24 punycode deprecation warning by updating @azure/storage-blob from ^12.13.0 to ^12.29.1 #​2213
  • Newer storage-blob uses @azure/core-rest-pipeline instead of deprecated @azure/core-http, which eliminates the transitive dependency on node-fetch@2 → whatwg-url@5 → tr46@0.0.3 that used the deprecated punycode module

v5.0.0

  • Remove @azure/ms-rest-js dependency #​2197
    • The TransferProgressEvent type is now imported from @azure/core-rest-pipeline instead of @azure/ms-rest-js
  • Bump @actions/core from ^1.11.1 to ^2.0.0 #​2198
  • Bump @actions/exec from ^1.0.1 to ^2.0.0 #​2198
  • Bump @actions/glob from ^0.1.0 to ^0.5.0 #​2198
  • Bump @actions/http-client from ^2.1.1 to ^3.0.0 #​2198
  • Bump @actions/io from ^1.0.1 to ^2.0.0 #​2198
  • Add support for Node.js 24 #​2110
  • Add node-fetch override to resolve audit vulnerabilities #​2110
actions/toolkit (@​actions/core)

v3.0.1

  • Bump undici from 6.23.0 to 6.24.1 #​2348

v3.0.0

  • Breaking change: Package is now ESM-only
    • CommonJS consumers must use dynamic import() instead of require()

v2.0.3

  • Bump @actions/http-client to 3.0.2

v2.0.1

v2.0.0

actions/toolkit (@​actions/exec)

v3.0.0

  • Breaking change: Package is now ESM-only
    • CommonJS consumers must use dynamic import() instead of require()

v2.0.0

actions/toolkit (@​actions/http-client)

v4.0.1

  • Bump undici from 6.23.0 to 6.24.0 #​2347

v4.0.0

  • Breaking change: Package is now ESM-only
    • CommonJS consumers must use dynamic import() instead of require()

v3.0.2

  • Bump undici from 5.28.5 to 6.23.0

v3.0.1

  • Add support for ACTIONS_ORCHESTRATION_ID in user-agent and default user-agent #​2229

v3.0.0

actions/toolkit (@​actions/io)

v3.0.2

  • Fix: update lock file version

v3.0.1

  • Fix: export @actions/io/lib/io-util

v3.0.0

  • Breaking change: Package is now ESM-only
    • CommonJS consumers must use dynamic import() instead of require()

v2.0.0

  • Add support for Node 24 #​2110
  • Ensures consistent behavior for paths on Node 24 with Windows
actions/toolkit (@​actions/tool-cache)

v4.0.0

  • Breaking change: Package is now ESM-only
    • CommonJS consumers must use dynamic import() instead of require()
3.0.1
  • Bump @actions/http-client to 3.0.2
3.0.0
  • Update to v2.0.1 of @actions/core
  • Update to v2.0.0 of @actions/exec
  • Update to v3.0.1 of @actions/http-client
  • Update to v2.0.0 of @actions/io
2.0.2
2.0.1
  • Update to v2.0.1 of @actions/http-client #​1087
2.0.0
  • Update to v2.0.0 of @actions/http-client
  • The type of the headers parameter in the exported function downloadTool has been narrowed from { [header: string]: any } to { [header: string]: number | string | string[] | undefined; } (that is, http.OutgoingHttpHeaders).
    This is strictly a compile-time change for TypeScript consumers. Previous attempts to use a header value of a type other than those now accepted would have resulted in an error at run time.
1.7.2
  • Update lockfileVersion to v2 in package-lock.json #​1025
1.7.1
1.7.0
1.6.1
1.6.0
1.3.5
1.3.4

Here is the security issue that was fixed in the http-client 1.0.8 release

1.3.3
1.3.2
1.3.1
1.3.0
1.2.0
1.1.2
1.0.0
  • Initial release

v3.0.1

  • Bump @actions/http-client to 3.0.2

v3.0.0

  • Update to v2.0.1 of @actions/core
  • Update to v2.0.0 of @actions/exec
  • Update to v3.0.1 of @actions/http-client
  • Update to v2.0.0 of @actions/io
babel/babel (@​babel/core)

v8.0.6

Compare Source

👓 Spec Compliance
  • babel-helper-validator-identifier, babel-parser
🐛 Bug Fix
  • babel-parser
  • babel-helper-string-parser, babel-parser
🏠 Internal
  • babel-code-frame, babel-core, babel-generator, babel-helper-create-class-features-plugin, babel-helper-module-transforms, babel-parser, babel-plugin-bugfix-safari-rest-destructuring-rhs-array, babel-plugin-proposal-destructuring-private, babel-plugin-proposal-discard-binding, babel-plugin-transform-regenerator, babel-plugin-transform-typescript, babel-preset-env, babel-traverse, babel-types
  • babel-parser
  • babel-core
  • babel-build-external-helpers, babel-cli, babel-code-frame, babel-core, babel-generator, babel-helper-compilation-targets, babel-helper-create-class-features-plugin, babel-helper-globals, babel-helper-string-parser, babel-helper-transform-fixture-test-runner, babel-helper-validator-identifier, babel-node, babel-parser, babel-plugin-transform-async-generator-functions, babel-plugin-transform-runtime, babel-register, babel-runtime-corejs3, babel-traverse
🏃‍♀️ Performance
  • babel-helper-compilation-targets, babel-helper-transform-fixture-test-runner

v8.0.5

Compare Source

👓 Spec Compliance
🐛 Bug Fix
📝 Documentation
🏠 Internal
  • babel-cli, babel-core, babel-helper-compilation-targets, babel-helper-create-class-features-plugin, babel-helper-create-regexp-features-plugin, babel-helper-fixtures, babel-preset-env
  • babel-node
  • babel-types
🏃‍♀️ Performance

v8.0.1

Compare Source

💥 Breaking Change
  • babel-core, babel-plugin-transform-object-rest-spread, babel-plugin-transform-runtime, babel-preset-env, babel-standalone

v8.0.0

Compare Source

👓 Spec Compliance
💥 Breaking Change
  • babel-cli, babel-node, babel-plugin-proposal-decorators, babel-plugin-transform-classes, babel-plugin-transform-function-name, babel-plugin-transform-modules-commonjs, babel-plugin-transform-object-rest-spread, babel-plugin-transform-parameters, babel-plugin-transform-react-constant-elements, babel-plugin-transform-regenerator, babel-preset-env, babel-register
  • babel-plugin-transform-runtime, babel-runtime-corejs3, babel-runtime
  • babel-parser
🐛 Bug Fix
  • babel-generator
  • babel-plugin-transform-modules-systemjs
📝 Documentation
🏠 Internal
🏃‍♀️ Performance
biomejs/biome (@​biomejs/biome)

v2.5.15

Compare Source

Patch Changes
  • #​10634 b436ba0 Thanks @​subaru-hello! - Added the new nursery rule noReactObjectTypeAsDefaultProp, which disallows array, object, and function values as default props in React components.

    For example, the following snippet triggers the rule.

    function Component({ items = [] }) {
      return items;
    }
  • #​11956 faa8b37 Thanks @​dyc3! - Added the nursery rule noSvelteExportLet, which disallows declaring Svelte component props with the legacy export let syntax. Use the $props() rune instead.

    <script>
      export let name;
    </script>
  • #​10816 1b9479e Thanks @​Th3S4mur41! - Added a new nursery rule useLogicalProperties that enforces the use of logical properties in CSS, promoting better internationalization and accessibility practices. The rule supports a direction option with "ltr" as the default and "rtl" as the alternative.
    This is a first rule covering parts of #​9034

    {
      "linter": {
        "rules": {
          "nursery": {
            "useLogicalProperties": {
              "level": "warn",
              "options": {
                "direction": "rtl"
              }
            }
          }
        }
      }
    }
  • #​11960 1fdb5c2 Thanks @​dyc3! - Added the nursery rule useSvelteKitRuneImports, which reports imports from the deprecated $app/stores module and suggests $app/state instead.

    import { page } from "$app/stores";
  • #​11723 3b429d1 Thanks @​m1handr! - Fixed #​11656: noAstroSetHtmlDirective now correctly reports set:html directives inside Astro template expressions.

  • #​12023 874d5ae Thanks @​codspeed! - Improved the performance of the HTML formatter up to 4x.

  • #​11761 a3462fe Thanks @​saberoueslati! - Fixed #​11351: useSimplifiedLogicExpression no longer reports boolean literals on the right side of || and && outside boolean contexts, because removing them can change the result of the expression. For example, y = x || false is no longer reported, while if (x || false) still is.

  • #​11732 ff4c4dd Thanks @​dyc3! - Added the nursery rule noMeaninglessVoidOperator, which reports unnecessary uses of void, such as void log() when log returns void. The rule allows discarded call results, thenables, void 0, and calls returning never.

  • #​11975 40dd3fb Thanks @​ematipico! - Fixed the indentation of multiline Astro expressions, in templates and attribute values, when running biome check --write. Biome now formats Astro expressions with biome format too, and places them at the column of the surrounding markup.

     <div>
     	{items.map((item) => (
    -	<span>{item}</span>
    -))}
    +		<span>{item}</span>
    +	))}
     </div>
  • #​12016 09d4000 Thanks @​codspeed! - Improved the performance of indexing and analysis of big files up to 2x. The improvements are mostly visible in projects that make use of project and types lint rules.

  • #​11750 089bde0 Thanks @​dyc3! - Added the nursery rule useStrictBooleanExpressions, which reports ambiguous truthiness checks such as if (value) when value has type number | undefined. Non-nullable strings and numbers and nullable objects are allowed; the rule has no options.

  • #​11494 ad5b362 Thanks @​jp-knj! - Added the nursery rule noAstroConflictingSetDirectives, which reports Astro elements with multiple content sources, such as set:html, set:text, and child content.

    For example, <div set:html={html}>content</div> triggers the rule.

  • #​11878 84d1b3b Thanks @​dyc3! - Fixed #​11748: useExhaustiveSwitchCases now reports missing cases for values created with the mapping overload of Array.from, including arrays imported from another module.

  • #​11802 7d1f37e Thanks @​dyc3! - Tailwind classes will now be detected in Svelte, Vue, and Astro class attribute expressions that don't use a class merging function.

  • #​11910 9e50ea2 Thanks @​ematipico! - Fixed #​11504, a regression where Biome would silently ignore errors in the configuration file. Now errors are correctly retained and checked before executing any command.

  • #​11921 d568632 Thanks @​hirehamir! - Fixed #​10846: when plugins fail to load, Biome now prints each failing plugin's path on its own line, instead of concatenating bare messages like Cannot read file.Cannot read file..

  • #​11930 82ea5a6 Thanks @​dyc3! - Fixed #​11927: The HTML formatter no longer duplicates comments around Svelte blocks. This affected a comment after a block such as {#if} or {#each} at the end of an element, and a comment on the same line as the last element inside a block, before {:else}, {/if}, or a similar tag.

  • #​11931 0cc46d8 Thanks @​dyc3! - Fixed the indentation of comments at the end of a Svelte block's contents. A comment before {:else}, {:then}, {/if}, or a similar tag is now indented with the block's contents instead of with the tag.

     {#if condition}
     	<span>Text</span>
    -<!-- comment -->
    +	<!-- comment -->
     {/if}
  • #​12031 ef0edd4 Thanks @​dyc3! - Fixed #​12027: Biome's test rules no longer mistake regular method calls named test, it, or describe for tests. For example, useValidTestTitle used to report the following regular expression check as a test with an invalid title:

    const isComment = /^\s*#/.test(line);
  • #​11959 8477e61 Thanks @​dyc3! - Fixed #​11950: noUnusedVariables now reports arrow functions with expression bodies that only reference themselves, such as let h = () => h();.

  • #​11915 3260602 Thanks @​ematipico! - Fixed #​11841, where suppression comments had no effect on some parts of HTML-ish files and on snippets embedded in JavaScript files.

    Now the following suppression works as expected:

    <!-- biome-ignore lint/correctness/noUndeclaredVariables: intentionally external -->
    <div :title="missingValue"></div>
  • #​11952 b51040e Thanks @​dyc3! - Fixed #​11951: the GritQL formatter no longer inserts a space after a within pattern without an until clause.

    -$arg <: within `bar($_)` ,
    +$arg <: within `bar($_)`,
  • #​11794 429cf95 Thanks @​dyc3! - Added the nursery rule noTailwindRawColors for JavaScript and HTML. It disallows Tailwind palette colors such as bg-pink-500 and text-white, encouraging design system color utilities such as bg-primary.

  • #​11837 f5e249b Thanks @​dyc3! - Fixed #​11836: biome check --write no longer adds invalid parentheses around Svelte {@const} declarations when experimental HTML support and formatting are enabled.

  • #​11978 8be0b9e Thanks @​dyc3! - Fixed #​11817: Biome no longer crashes when its output is piped to a program that exits early, such as head. Output to the closed pipe is now discarded and Biome exits normally.

  • #​11868 3841c26 Thanks @​ematipico! - Fixed #​8986: Biome's language server now scopes all watched-file patterns to each workspace folder, falling back to the deprecated rootUri when no workspace folders are provided. Clients without relative-pattern support receive compatible absolute glob patterns.

  • #​11928 0015681 Thanks @​dyc3! - Restricted access to the Unix daemon socket to the user running Biome. The socket now lives in a biome-daemon directory inside Biome's cache directory that only this user can access, and the socket itself has mode 0600.

  • #​11835 589ca1a Thanks @​dyc3! - Updated useReactCompiler: Biome now reports React Compiler diagnostics regardless of the React version declared in package.json.

  • #​11907 b7d9037 Thanks @​posido! - Fixed withastro/compiler-rs#194: the HTML parser no longer treats a regex literal that starts with > as the end of a self-closing tag. Astro frontmatter such as const escaped = s.replace(/>/g, "&gt;"); no longer swallows the closing --- fence, and the same regex inside a template expression no longer runs past its closing }. A regex literal after a keyword such as return, as in return />'/.test(s), is now recognized too.

  • #​12021 59cc595 Thanks @​dyc3! - Type inference performance has been significantly improved. Some popular libraries like Zod, Valibot, Arktype, Effect, Kysely, and Drizzle have gained a ~2-240x speedup in our benchmarks. This improvement affects all rules that use type information.

  • #​12044 c73fb91 Thanks @​dyc3! - Fixed #​12042: the HTML formatter no longer removes the space between text and an inline element on the next line when it joins the lines.

    - <p>a <em>b</em> c<u>d</u></p>
    + <p>a <em>b</em> c <u>d</u></p>
  • #​11965 f90bf38 Thanks @​ematipico! - Fixed module resolution in long-running workspaces so imports reflect package manifest and TypeScript path-mapping changes without requiring the importing file to be edited.

  • #​11860 0884e29 Thanks @​dyc3! - Removed the attributes and functions options from the nursery rule noTailwindArbitraryValue. The rule now uses the same Tailwind detection as useTailwindShorthandClasses.

  • #​11969 865cd30 Thanks @​AlbinoGeek! - Fixed #​11962: noUnknownTypeSelector no longer reports view transition names inside view transition pseudo-elements, such as page in ::view-transition-group(page).

  • #​11914 06ff47b Thanks @​dyc3! - Fixed #​11897: the safe fix for noUselessStringConcat now escapes embedded double quotes when combining literals, preserving valid JavaScript and existing escape sequences.

  • #​11997 af7825f Thanks @​github-actions! - The noRestrictedDependencies rule has been updated with new module replacement data, it should now detect for more relevant replacements.

  • #​11827 31bb662 Thanks @​dfedoryshchev! - Fixed #​11566: useNamingConvention no longer reports a namespace declared inside declare global or inside an external module declaration. Both positions are documented as always ignored, and the rule offered a safe fix, so biome check --write renamed the declaration:

    export {}
    declare global {
        // no longer renamed to `Jsx`
        namespace JSX {}
    }
  • #​11814 23ba25f Thanks @​siketyan! - Fixed type inference through generic type aliases that instantiate another generic type with a nested generic argument, such as type Nested<T> = Box<Wrapper<T>>. Type-aware rules now resolve members of such types:

    declare const nested: Nested<number>;
    // noUnnecessaryCo

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "every weekend"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Sep 5, 2026
@renovate
renovate Bot enabled auto-merge (squash) September 5, 2026 06:14
@renovate
renovate Bot force-pushed the renovate/major-devdependencies branch 15 times, most recently from 9c90a2e to ea96bf1 Compare September 12, 2026 03:09
@renovate
renovate Bot force-pushed the renovate/major-devdependencies branch 10 times, most recently from d78fc22 to 25648e2 Compare September 19, 2026 01:48
@renovate
renovate Bot force-pushed the renovate/major-devdependencies branch 3 times, most recently from bda9bde to c6387c4 Compare September 23, 2026 03:58
@renovate
renovate Bot force-pushed the renovate/major-devdependencies branch 6 times, most recently from adfda01 to f3906dd Compare September 29, 2026 15:46
@renovate
renovate Bot force-pushed the renovate/major-devdependencies branch from f3906dd to a25782e Compare September 30, 2026 20:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants