chore(deps): update all dependencies - #523
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
Contributor
Author
|
renovate
Bot
force-pushed
the
renovate/all
branch
from
August 3, 2026 14:50
29793c6 to
4925881
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.70.0→0.70.12.5.4→2.5.52.5.62.5.4→2.5.52.5.6^22.20.0→^26.0.0^22.20.0→^26.0.0^22.20.1→^26.0.0^3.1.4→^4.0.04.1.2^29.1.1→^30.0.030.0.1^0.55.1→^0.56.026.5.0→26.6.026.2.0→26.5.1v6.0.9→v6.0.10^3.0.2→^4.0.019.2.7→19.2.819.2.7→19.2.80.35.0→0.35.3^6.0.3→^7.0.0Release Notes
Azure/typespec-azure (@azure-tools/typespec-autorest)
v0.70.1Bug Fixes
service.yamlversions when updating an existing manifest. Versions the emitter no longer produces are now kept when they are not TypeSpec-generated (for example legacy swagger-only versions migrated fromreadme.md), while stalesource: typespecversions the emitter no longer produces are still removed. This makes re-running the emitter idempotent for manifests that carry historical versions.biomejs/biome (@biomejs/biome)
v2.5.5Compare Source
Patch Changes
#10972
ab8c21bThanks @ematipico! - FixeduseExhaustiveSwitchCasesfor unions of bigint literals. The rule now reports missing bigint cases and compares bigint literals by value, including binary, octal, hexadecimal, and separator-containing spellings. For example, this switch now reports the missing2ncase:#10972
ab8c21bThanks @ematipico! - Fixed false positives innoBaseToStringanduseNullishCoalescingwhen member, stringification, or nullish inference cannot complete. These rules now suppress diagnostics instead of reporting from partial type information. For example, neither expression is reported when a recursive type cannot be fully resolved:#10977
0bf7486Thanks @ematipico! - Fixed #10922: the actionuseSortedAttributesno longer triggers for HTML instructions.#10957
cf263c4Thanks @dyc3! - FixednoThenPropertyfailing to detectObject.fromEntries,Object.defineProperty, andReflect.definePropertycalls with comments between their tokens.#10983
edc0ed7Thanks @ayaangazali! - Fixed #10980:useAriaPropsSupportedByRoleno longer reports false positives when the attribute that determines an element's implicit ARIA role is written as a shorthand attribute, such as<a {href} aria-label="...">in Astro and Svelte files.Shorthand attributes are now taken into account when computing the implicit role, so the anchor above correctly resolves to the
linkrole instead ofgeneric.#10889
89526e3Thanks @denbezrukov! - Fixed CSS formatter casing for syntax-owned names while preserving author-defined names, including scoped keyframes and container scroll-state queries.#10964
794ccd0Thanks @denbezrukov! - Fixed CSS formatting for comments between declaration values and!important.#10993
b7a9694Thanks @denbezrukov! - Fixed the CSS formatter to preserve comments on the correct side of selector combinators and before declaration blocks.It now also keeps selectors with escaped newlines in attribute values inline when they fit.
#10978
8ebafe1Thanks @ematipico! - Fixed #10870:noUnresolvedImportsno longer reports false positives such asimport type { NextRequest } from "next/server".#10901
68c10e6Thanks @Socialpranker! - Fixed #10622: the HTML/Vue parser no longer panics on the argument-lessv-bindshorthand (:="props").This syntax is valid Vue and equivalent to
v-bind="props", so the parser now accepts it (along with the longhandv-bind:="props") instead of crashing while building a diagnostic for a missing argument.#10936
7df46f5Thanks @ematipico! - Improved generic tuple inference foruseIncludes. The rule now recognizes specialised tuple element types returned through generic aliases.#10941
f787725Thanks @siketyan! - Fixed#10855: Biome now supports parsing and formatting CSS custom media queries declared with@custom-media.#10969
72d309bThanks @ematipico! - Fixed an issue where Biome logs became too verbose, dumping information not relevant to user's operations.e62f6b6Thanks @ematipico! - Fixed #10963: Biome no longer panics when a type-aware rule such asnoFloatingPromiseschecks a call to a function with multiple call signatures imported from another module.#10931
899c60dThanks @ematipico! - Fixedcheck --writecommand. Now the command reports code frame of the formatted code, if the formatter is enabled.#10904
ceee4f4Thanks @qzwxsaedc! - Fixed #10892:noUnnecessaryConditionsno longer reports a false positive when checking a member of a discriminated union that is accessed through a default type-only namespace import. The following code is no longer flagged:#10962
f0a67f2Thanks @ematipico! - Biome no longer removes embedded styles and scripts in HTML files.#11000
5039a1eThanks @ematipico! - Fixed a bug where closing one editor stopped a shared Biome daemon used by other editors. LSP proxy processes now exit when either the editor or daemon disconnects.#10957
cf263c4Thanks @dyc3! - Improved the performance of thenoThenPropertylint rule by about 50%.#10992
4bf9b21Thanks @ematipico! - FixednoMisusedPromises: The rule now reports Promise-returning callbacks where a synchronous callback is expected when calls use tuple spreads or tuple rest parameters, including generic and deeply nested tuples, and when constructor signatures come from interface or object types. Recursive or excessively nested tuple spreads use a conservative fallback so analysis terminates.For example, the following callback is now reported.
#10915
b3b12b3Thanks @Functionhx! - Added the rulenoNegationInEqualityCheck. The rule flags negated expressions on the left side of strict equality checks like!foo === bar— due to operator precedence this evaluates as(!foo) === barwhich is almost always a mistake forfoo !== bar.The rule provides an unsafe fix that flips the operator.
#10970
bd1038bThanks @ematipico! - Improved overload selection fornoMisusedPromises. Biome now handles overloaded calls, overloaded constructors, rest parameters, union arguments, and generic constraints without selecting an incompatible signature. For example,noMisusedPromisesnow reports the async callback passed to the synchronous overload:#10933
48a4abbThanks @ematipico! - FixeduseArrayFindto recognize bigint zero indexes.#10931
899c60dThanks @ematipico! - Fixed an orchestration issue that could lead to deadlocks when type-aware rules are enabled.#10969
72d309bThanks @ematipico! - Hardened the Biome Language Server by improving its synchronisation logic.#10972
ab8c21bThanks @ematipico! - Fixed false positives innoMisusedPromisesanduseAwaitThenablewhen Promise or thenable inference cannot complete. These rules now suppress diagnostics instead of treating incomplete type information as a definite result. For example,useAwaitThenableno longer reportsawait valuewhen the value's thenability is unknown:biomejs/biome (@biomejs/wasm-nodejs)
v2.5.5Compare Source
fastify/fast-uri (fast-uri@^3)
v4.1.1Compare Source
Fix for GHSA-v2hh-gcrm-f6hx
Full Changelog: fastify/fast-uri@v4.1.0...v4.1.1
v4.1.0Compare Source
v4.0.1Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fast-uri@v4.0.0...v4.0.1
v4.0.0Compare Source
What's Changed
Full Changelog: fastify/fast-uri@v3.1.2...v4.0.0
jsdom/jsdom (jsdom)
v30.0.0Compare Source
microsoft/monaco-editor (monaco-editor)
v0.56.0Compare Source
Breaking Changes
monaco-editorentry point continues to load all features and languages. Custom bundles can now importmonaco-editor/editorand opt into:monaco-editor/features/register.all, or individual features withmonaco-editor/features/<feature>/register;monaco-editor/languages/definitions/register.all, or individual definitions withmonaco-editor/languages/definitions/<language>/register;monaco-editor/languages/features/register.all, or their individualregisterentry points.IOverlayWidgetPosition.stackOridinalproperty tostackOrdinal.IMirrorModelandIWorkerContextworker API types.New Features and APIs
editor.doubleClickSelectsBlock.editor.find.closeOnResultandeditor.inlayHints.showLongLineWarning.offWhenInlineCompletionstoQuickSuggestionsValue.ICodeEditor.revealAllCursors,ICodeEditor.getWidthOfLine, andICodeEditor.renderAsync.advanced-externalandadvanced-wasmdiff algorithms.Fixes
0.56.0-dev-20260625.nodejs/node (node)
v26.6.0Compare Source
actions/node-versions (node)
v26.5.1: 26.5.1Compare Source
Node.js 26.5.1
pnpm/action-setup (pnpm/action-setup)
v6.0.10Compare Source
stream-utils/raw-body (raw-body)
v4.0.0Compare Source
Remove support for Node <22 - by @bjohansebas in #156
Node.js versions prior to 22 are no longer supported. This allows the package to migrate to ESM and rely on
require(esm), which does not work correctly on earlier versions.Migrate to TypeScript and publish as ESM-only - by @bjohansebas in #157
CommonJS consumers can keep loading the package through
require(esm).Use native
TextDecoderinstead oficonv-lite- by @bjohansebas in #143Supported encodings are now those of the WHATWG Encoding Standard; encodings outside the standard (e.g. UTF-32) now throw a 415 error.
utf-16no longer detects a big-endian BOM and always decodes as little-endian; useutf-16befor big-endian content.Remove streams1 support - by @bjohansebas in #144 and #161
Node streams that emit string chunks now error with a 500
stream.encoding.setthrough the callback (previously they were decoded silently, or crashed the process when no encoding was set), matching the web stream path. Streams are expected to implement the readable stream interface (unpipe,pause).Validate the
limitoption - by @bjohansebas in #162A
limitthat does not parse to a byte count (e.g.'banana',NaN) now throws aTypeErrorinstead of silently reading with no limit at all.limit: nullremains the explicit way to disable the limit.🚀 Improvements
Support reading WHATWG
ReadableStream(web streams) through the newgetRawBodyWebexport - by @bjohansebas in #148, #160 and #175fetchRequest/Responsebodies,Blob.stream(),TransformStreamreadables, andReadable.toWeb()bridges can be read withgetRawBodyWeb, which takes the same options asgetRawBody;getRawBodyitself keeps accepting only node streams. Streams already locked, read, or cancelled error with a 500stream.not.readable; client aborts are mapped to the same 400request.abortederror as node streams, with the original error incause; string chunks are accepted without an encoding (UTF-8Buffer), but error with a 500stream.encoding.setwhen combined with one, since the stream is already decoded; non-byte chunks (e.g.ArrayBuffer) error with aTypeError. On error the reader lock is released, but the stream is not cancelled; disposing it is up to the caller.Add a custom
decoderoption - by @bjohansebas in #145A function compatible with
iconv-lite'sgetDecodercan be plugged in to decode encodings outside the WHATWG Encoding Standard.Use native
stream.unpipe()and remove theunpipedependency - by @Phillip9587 in #93Remove the check for a global
Promisewhen no callback is provided - by @bjohansebas in #146Add a benchmark suite - by @bjohansebas in #163
npm run benchcompares the node and web stream paths with realistic request bodies.Fail as soon as a stream exceeds its declared
length- by @bjohansebas in #172A body that sends more bytes than its declared
lengthnow errors with a 400request.size.invalidas soon as the excess arrives, rather than buffering the rest first. This bounds memory tolengtheven when nolimitis set. When both are set, alengthoverrun is reported before thelimit's 413.🐞 Bug fixes
Fix a
lengththat does not parse to a number failing every request - by @bjohansebas in #172Values like
''passed the numeric pre-check but parsed toNaN, so the size check could never match and every request errored with a 400request.size.invalid. They are now treated as no expected length, like any other unparseable value.Fix node streams destroyed without an error never settling - by @bjohansebas in #158
They now error through the callback / reject the promise with the same 400
request.abortederror as the web path, instead of never invoking the callback or settling the promise.Fix process crash when a custom
decoderthrows while reading node streams - by @bjohansebas in #157react/react (react)
v19.2.8Compare Source
react/react (react-dom)
v19.2.8Compare Source
lovell/sharp (sharp)
v0.35.3Compare Source
Tighten verification of
textdimensions, TIFF tile dimensions andextendvalues.Improve code bundler support by resolving path to libvips binary.
Increase default concurrency when use of
MALLOC_ARENA_MAXis detected.Emit warning about binaries provided by Electron for use on Linux.
Add
hasAlphaproperty to outputinfo.#4500
TypeScript: Return more precise
Buffer<ArrayBuffer>fromtoBuffer.#4520
@Andarist
Bound
clahewidth and height to avoid signed overflow.#4551
@metsw24-max
Bound
trimmargin to avoid signed overflow.#4552
@metsw24-max
Reject infinite values when validating numbers.
#4553
@metsw24-max
Bound extract region to libvips coordinate limit.
#4555
@metsw24-max
Verify background colour values are numbers.
#4556
@metsw24-max
Bound create and raw input dimensions to coordinate limit.
#4558
@metsw24-max
Tighten recomb and affine matrix verification.
#4560
@chatman-media
Verify cache memory limit to avoid overflow.
#4561
@metsw24-max
v0.35.2Compare Source
v0.35.1Compare Source
TypeScript: Ensure type definitions are published for both ESM and CJS.
#4537
WebAssembly: Ensure wrapper file is published.
#4538
microsoft/TypeScript (typescript)
v7.0.2Compare Source
Configuration
📅 Schedule: (UTC)
* 0-3 1 * *)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.