Skip to content

fix(deps): update all dependencies - #28

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Mar 27, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@biomejs/biome (source) ^2.4.9 → ^2.5.15 age confidence devDependencies minor
@changesets/changelog-github (source) ^0.6.0 → ^1.0.1 age confidence devDependencies major
@changesets/cli (source) ^2.30.0 → ^3.0.3 age confidence devDependencies major
@effect/cli (source) ^0.75.0 → ^0.77.2 age confidence dependencies minor
@effect/cluster (source) ^0.58.0 → ^0.60.2 age confidence dependencies minor
@effect/experimental (source) ^0.60.0 → ^0.61.1 age confidence dependencies minor
@effect/platform (source) ^0.96.0 → ^0.97.2 age confidence dependencies minor
@effect/platform-node (source) ^0.106.0 → ^4.0.1 age confidence dependencies major
@effect/printer (source) ^0.49.0 → ^0.51.0 age confidence dependencies minor
@effect/printer-ansi (source) ^0.49.0 → ^0.51.0 age confidence dependencies minor
@effect/rpc (source) ^0.75.0 → ^0.76.2 age confidence dependencies minor
@effect/sql (source) ^0.51.0 → ^0.52.1 age confidence dependencies minor
@effect/typeclass (source) ^0.40.0 → ^0.41.0 age confidence dependencies minor
@effect/vitest (source) ^0.29.0 → ^4.0.1 age confidence devDependencies major
@effect/workflow (source) ^0.18.0 → ^0.19.1 age confidence dependencies minor
@eslint-community/eslint-plugin-eslint-comments ^4.7.1 → ^4.8.1 age confidence devDependencies minor
@eslint/compat (source) 2.0.3 → 2.1.1 age confidence devDependencies minor
@eslint/eslintrc 3.3.5 → 3.3.7 age confidence devDependencies patch
@types/node (source) ^25.5.0 → ^25.9.9 age confidence devDependencies minor
@typescript-eslint/eslint-plugin (source) ^8.57.2 → ^8.71.1 age confidence devDependencies minor
@typescript-eslint/parser (source) ^8.57.2 → ^8.71.1 age confidence devDependencies minor
@typescript-eslint/rule-tester (source) 8.57.2 → 8.71.1 age confidence devDependencies minor
@typescript-eslint/utils (source) 8.57.2 → 8.71.1 age confidence dependencies minor
@vitest/coverage-v8 (source) ^4.1.2 → ^5.0.3 age confidence devDependencies major
@vitest/eslint-plugin ^1.6.13 → ^1.6.27 age confidence devDependencies patch
actions/checkout v6 → v7 age confidence action major
actions/setup-node v6 → v7 age confidence action major
biome (source) ^2.4.9 → ^2.5.15 age confidence devDependencies minor
effect (source) ^3.21.0 → ^4.0.1 age confidence dependencies major
eslint (source) ^10.1.0 → ^10.12.0 age confidence devDependencies minor
eslint-doc-generator ^3.3.2 → ^3.7.1 age confidence devDependencies minor
eslint-import-resolver-typescript ^4.4.4 → ^4.4.5 age confidence devDependencies patch
eslint-plugin-eslint-plugin ^7.3.2 → ^7.6.2 age confidence devDependencies minor
eslint-plugin-simple-import-sort ^12.1.1 → ^14.0.0 age confidence devDependencies major
eslint-plugin-sonarjs (source) ^4.0.2 → ^4.2.2 age confidence devDependencies minor
eslint-plugin-unicorn ^63.0.0 → ^77.0.0 age confidence devDependencies major
globals ^17.4.0 → ^17.13.0 age confidence devDependencies minor
jscpd (source) ^4.0.8 → ^5.4.0 age confidence devDependencies major
node 24.14.1 → 24.21.0 age confidence uses-with minor
npm (source) ^11.12.1 → ^12.2.0 age confidence devDependencies major
pnpm (source) 10.33.0 → 12.9.1 age confidence packageManager major
pnpm/action-setup v5 → v6 age confidence action major
ts-morph ^27.0.2 → ^28.0.0 age confidence devDependencies major
typescript (source) >=4.8.4 <7.0.0 → >=4.8.4 <8.0.0 age confidence peerDependencies major
typescript (source) ^6.0.2 → ^7.0.2 age confidence devDependencies major
typescript-eslint (source) ^8.57.2 → ^8.71.1 age confidence devDependencies minor
vite (source) ^8.0.3 → ^8.3.2 age confidence devDependencies minor
vitest (source) ^4.1.2 → ^5.0.3 age confidence devDependencies major

cc @skulidropek


Release Notes

biomejs/biome (@​biomejs/biome)

v2.5.15

Compare Source

Patch Changes
  • #​10634 b436ba0 Thanks @​subaru-hello! - Added the new nursery rule noReactObjectTypeAsDefaultProp, which disallows array, object, and function values as default props in React components.

    For example, the following snippet triggers the rule.

    function Component({ items = [] }) {
      return items;
    }
  • #​11956 faa8b37 Thanks @​dyc3! - Added the nursery rule noSvelteExportLet, which disallows declaring Svelte component props with the legacy export let syntax. Use the $props() rune instead.

    <script>
      export let name;
    </script>
  • #​10816 1b9479e Thanks @​Th3S4mur41! - Added a new nursery rule useLogicalProperties that enforces the use of logical properties in CSS, promoting better internationalization and accessibility practices. The rule supports a direction option with "ltr" as the default and "rtl" as the alternative.
    This is a first rule covering parts of #​9034

    {
      "linter": {
        "rules": {
          "nursery": {
            "useLogicalProperties": {
              "level": "warn",
              "options": {
                "direction": "rtl"
              }
            }
          }
        }
      }
    }
  • #​11960 1fdb5c2 Thanks @​dyc3! - Added the nursery rule useSvelteKitRuneImports, which reports imports from the deprecated $app/stores module and suggests $app/state instead.

    import { page } from "$app/stores";
  • #​11723 3b429d1 Thanks @​m1handr! - Fixed #​11656: noAstroSetHtmlDirective now correctly reports set:html directives inside Astro template expressions.

  • #​12023 874d5ae Thanks @​codspeed! - Improved the performance of the HTML formatter up to 4x.

  • #​11761 a3462fe Thanks @​saberoueslati! - Fixed #​11351: useSimplifiedLogicExpression no longer reports boolean literals on the right side of || and && outside boolean contexts, because removing them can change the result of the expression. For example, y = x || false is no longer reported, while if (x || false) still is.

  • #​11732 ff4c4dd Thanks @​dyc3! - Added the nursery rule noMeaninglessVoidOperator, which reports unnecessary uses of void, such as void log() when log returns void. The rule allows discarded call results, thenables, void 0, and calls returning never.

  • #​11975 40dd3fb Thanks @​ematipico! - Fixed the indentation of multiline Astro expressions, in templates and attribute values, when running biome check --write. Biome now formats Astro expressions with biome format too, and places them at the column of the surrounding markup.

     <div>
     	{items.map((item) => (
    -	<span>{item}</span>
    -))}
    +		<span>{item}</span>
    +	))}
     </div>
  • #​12016 09d4000 Thanks @​codspeed! - Improved the performance of indexing and analysis of big files up to 2x. The improvements are mostly visible in projects that make use of project and types lint rules.

  • #​11750 089bde0 Thanks @​dyc3! - Added the nursery rule useStrictBooleanExpressions, which reports ambiguous truthiness checks such as if (value) when value has type number | undefined. Non-nullable strings and numbers and nullable objects are allowed; the rule has no options.

  • #​11494 ad5b362 Thanks @​jp-knj! - Added the nursery rule noAstroConflictingSetDirectives, which reports Astro elements with multiple content sources, such as set:html, set:text, and child content.

    For example, <div set:html={html}>content</div> triggers the rule.

  • #​11878 84d1b3b Thanks @​dyc3! - Fixed #​11748: useExhaustiveSwitchCases now reports missing cases for values created with the mapping overload of Array.from, including arrays imported from another module.

  • #​11802 7d1f37e Thanks @​dyc3! - Tailwind classes will now be detected in Svelte, Vue, and Astro class attribute expressions that don't use a class merging function.

  • #​11910 9e50ea2 Thanks @​ematipico! - Fixed #​11504, a regression where Biome would silently ignore errors in the configuration file. Now errors are correctly retained and checked before executing any command.

  • #​11921 d568632 Thanks @​hirehamir! - Fixed #​10846: when plugins fail to load, Biome now prints each failing plugin's path on its own line, instead of concatenating bare messages like Cannot read file.Cannot read file..

  • #​11930 82ea5a6 Thanks @​dyc3! - Fixed #​11927: The HTML formatter no longer duplicates comments around Svelte blocks. This affected a comment after a block such as {#if} or {#each} at the end of an element, and a comment on the same line as the last element inside a block, before {:else}, {/if}, or a similar tag.

  • #​11931 0cc46d8 Thanks @​dyc3! - Fixed the indentation of comments at the end of a Svelte block's contents. A comment before {:else}, {:then}, {/if}, or a similar tag is now indented with the block's contents instead of with the tag.

     {#if condition}
     	<span>Text</span>
    -<!-- comment -->
    +	<!-- comment -->
     {/if}
  • #​12031 ef0edd4 Thanks @​dyc3! - Fixed #​12027: Biome's test rules no longer mistake regular method calls named test, it, or describe for tests. For example, useValidTestTitle used to report the following regular expression check as a test with an invalid title:

    const isComment = /^\s*#/.test(line);
  • #​11959 8477e61 Thanks @​dyc3! - Fixed #​11950: noUnusedVariables now reports arrow functions with expression bodies that only reference themselves, such as let h = () => h();.

  • #​11915 3260602 Thanks @​ematipico! - Fixed #​11841, where suppression comments had no effect on some parts of HTML-ish files and on snippets embedded in JavaScript files.

    Now the following suppression works as expected:

    <!-- biome-ignore lint/correctness/noUndeclaredVariables: intentionally external -->
    <div :title="missingValue"></div>
  • #​11952 b51040e Thanks @​dyc3! - Fixed #​11951: the GritQL formatter no longer inserts a space after a within pattern without an until clause.

    -$arg <: within `bar($_)` ,
    +$arg <: within `bar($_)`,
  • #​11794 429cf95 Thanks @​dyc3! - Added the nursery rule noTailwindRawColors for JavaScript and HTML. It disallows Tailwind palette colors such as bg-pink-500 and text-white, encouraging design system color utilities such as bg-primary.

  • #​11837 f5e249b Thanks @​dyc3! - Fixed #​11836: biome check --write no longer adds invalid parentheses around Svelte {@const} declarations when experimental HTML support and formatting are enabled.

  • #​11978 8be0b9e Thanks @​dyc3! - Fixed #​11817: Biome no longer crashes when its output is piped to a program that exits early, such as head. Output to the closed pipe is now discarded and Biome exits normally.

  • #​11868 3841c26 Thanks @​ematipico! - Fixed #​8986: Biome's language server now scopes all watched-file patterns to each workspace folder, falling back to the deprecated rootUri when no workspace folders are provided. Clients without relative-pattern support receive compatible absolute glob patterns.

  • #​11928 0015681 Thanks @​dyc3! - Restricted access to the Unix daemon socket to the user running Biome. The socket now lives in a biome-daemon directory inside Biome's cache directory that only this user can access, and the socket itself has mode 0600.

  • #​11835 589ca1a Thanks @​dyc3! - Updated useReactCompiler: Biome now reports React Compiler diagnostics regardless of the React version declared in package.json.

  • #​11907 b7d9037 Thanks @​posido! - Fixed withastro/compiler-rs#194: the HTML parser no longer treats a regex literal that starts with > as the end of a self-closing tag. Astro frontmatter such as const escaped = s.replace(/>/g, "&gt;"); no longer swallows the closing --- fence, and the same regex inside a template expression no longer runs past its closing }. A regex literal after a keyword such as return, as in return />'/.test(s), is now recognized too.

  • #​12021 59cc595 Thanks @​dyc3! - Type inference performance has been significantly improved. Some popular libraries like Zod, Valibot, Arktype, Effect, Kysely, and Drizzle have gained a ~2-240x speedup in our benchmarks. This improvement affects all rules that use type information.

  • #​12044 c73fb91 Thanks @​dyc3! - Fixed #​12042: the HTML formatter no longer removes the space between text and an inline element on the next line when it joins the lines.

    - <p>a <em>b</em> c<u>d</u></p>
    + <p>a <em>b</em> c <u>d</u></p>
  • #​11965 f90bf38 Thanks @​ematipico! - Fixed module resolution in long-running workspaces so imports reflect package manifest and TypeScript path-mapping changes without requiring the importing file to be edited.

  • #​11860 0884e29 Thanks @​dyc3! - Removed the attributes and functions options from the nursery rule noTailwindArbitraryValue. The rule now uses the same Tailwind detection as useTailwindShorthandClasses.

  • #​11969 865cd30 Thanks @​AlbinoGeek! - Fixed #​11962: noUnknownTypeSelector no longer reports view transition names inside view transition pseudo-elements, such as page in ::view-transition-group(page).

  • #​11914 06ff47b Thanks @​dyc3! - Fixed #​11897: the safe fix for noUselessStringConcat now escapes embedded double quotes when combining literals, preserving valid JavaScript and existing escape sequences.

  • #​11997 af7825f Thanks @​github-actions! - The noRestrictedDependencies rule has been updated with new module replacement data, it should now detect for more relevant replacements.

  • #​11827 31bb662 Thanks @​dfedoryshchev! - Fixed #​11566: useNamingConvention no longer reports a namespace declared inside declare global or inside an external module declaration. Both positions are documented as always ignored, and the rule offered a safe fix, so biome check --write renamed the declaration:

    export {}
    declare global {
        // no longer renamed to `Jsx`
        namespace JSX {}
    }
  • #​11814 23ba25f Thanks @​siketyan! - Fixed type inference through generic type aliases that instantiate another generic type with a nested generic argument, such as type Nested<T> = Box<Wrapper<T>>. Type-aware rules now resolve members of such types:

    declare const nested: Nested<number>;
    // noUnnecessaryConditions now reports that `??` is unnecessary.
    const inner = nested.value.inner ?? 1;
  • #​11908 dd5a5ce Thanks @​siketyan! - Fixed #​11880: Biome no longer misparses a << expression followed by a later >>> as TypeScript type arguments. For example, const mask = 1 << bits followed by const m = mask >>> 0 on the next line now parses correctly.

  • #​11882 28c817d Thanks @​mikehasa! - Fixed a bug in noOctalEscape where the safe fix could silently change a string's value. A legacy octal escape is at most two digits when the leading digit is 4-7, so "\751" is "\75" + "1" (i.e. "=1") but was rewritten to the single character ǩ; it is now rewritten to "\x3d1".

  • #​11861 81b0adb Thanks @​Netail! - Added the new nursery rule noSelfImport, which forbids a module from importing itself.

    // foo.js
    import foo from "./foo.js";
  • #​12041 5e14509 Thanks @​ematipico! - Fixed a stack overflow in type-aware lint rules, such as noMisusedPromises and noFloatingPromises, when generic types in files that import each other reference one another in their type parameters.

    // entity.ts
    import type { Repository } from "./repository";
    export interface Entity<R extends Repository<any> = Repository<any>> {}
    
    // repository.ts
    import type { Entity } from "./entity";
    export interface Repository<E extends Entity<any> = Entity<any>> {}
  • #​11838 9bbff0c Thanks @​dyc3! - Added the nursery rule usePromiseRejectErrors, which requires Error objects as Promise rejection reasons.

    Promise.reject("Request failed");
    new Promise((resolve, reject) => reject(42));
  • #​11917 717db8c Thanks @​dyc3! - Added the nursery rule noMisplacedListElements for HTML and JSX, which requires <li> elements with an HTML element parent to be children of <ul>, <ol>, or <menu>. For example, <div><li>Item</li></div> is invalid.

  • #​11919 8d0b990 Thanks @​dyc3! - Fixed #​11899: disabling a domain no longer disables rules that also belong to another enabled domain. For example, with "domains": { "react": "all", "next": "none" }, useExhaustiveDependencies and useHookAtTopLevel are now enabled.
    Rules enabled explicitly in the configuration also stay enabled when one of their domains is set to "none".

  • #​11814 23ba25f Thanks @​siketyan! - Fixed #​11810 and #​11813: type-aware rules such as noUnnecessaryConditions and noFloatingPromises no longer take several seconds when a member is accessed on a recursive generic type alias, such as react-hook-form's FieldPathValue or zustand's Mutate.

  • #​11983 cc39794 Thanks @​AlbinoGeek! - Fixed #​11939: the fix of useRegexLiterals no longer escapes a slash that is already escaped. new RegExp("\\/") is now fixed to /\// instead of the invalid /\\//.

  • #​11869 3a21c80 Thanks @​ematipico! - Fixed #9105: vcs.useIgnoreFile now evaluates parent directory patterns when matching child paths, preserving re-included directories such as !/src while ignoring their excluded siblings.

  • #​11875 2cdd220 Thanks @​dyc3! - Fixed #​11867: noUndeclaredVariables incorrectly reported Vue slot props declared with v-slot or its # shorthand, including destructured props.

  • #​12021 59cc595 Thanks @​dyc3! - Type inference accuracy has been improved significantly. More global types, like Array, Map, Set, etc., are now fully defined. This should decrease false positives on all typed rules, since less types will be unknown.

  • #​11929 aef690d Thanks @​Th3S4mur41! - Fixed noUnknownProperty to recognize the frame-sizing CSS property.

  • #​12022 6233eb2 Thanks @​dyc3! - Fixed #​12020: the HTML parser now reports an error for a mismatched closing tag like the </span> in <p>two</span></p>. Previously, it accepted </span> as the end of <p> because span contains the letter p, and the formatter deleted everything after it. HTML tag names are matched case-insensitively, so <DIV></div> is no longer reported as mismatched.

    A closing tag with no opening tag at the top level of a file, like the second </p> in <p>a</p></p><p>b</p>, is now also reported as an error, instead of the formatter deleting it and everything after it.

  • #​12037 48cdbb8 Thanks @​ff1451! - Fixed #​11898: noUselessReturn no longer offers a safe fix for a return; that is the body of an unbraced if, else, or label, because removing it produced invalid code. The safe fix now also keeps comments placed before or after the removed return;.

    function foo() {
      // Still reported, but the return is no longer removed
      if (aborted) return;
    }
  • #​12030 4ff83dd Thanks @​ematipico! - Fixed #​9155: Biome no longer reports a parse error for typed slot props in Vue files, such as v-slot="{ value }: { value: ValueType }". Types used in slot props annotations are now correctly detected as used by noUnusedVariables.

  • #​11955 088164f Thanks @​dyc3! - Fixed #​11946: noUnreachable and useGetterReturn now recognize while and do...while loops with truthy literal conditions as infinite unless control flow exits the loop.

  • #​11958 6964bfc Thanks @​erenbati! - Fixed #​11924: noFocusedTests no longer reports chained method calls such as builder.image(url).fit("max") as focused tests.

  • #​11908 dd5a5ce Thanks @​siketyan! - Fixed parsing of left shifts between TypeScript instantiation expressions. Biome now parses f<T> << f<T> as a left shift of two instantiation expressions, matching TypeScript, instead of reporting a parse error.

  • #​11877 5a53b2c Thanks @​dyc3! - Fixed #​11278: noUnnecessaryConditions no longer incorrectly reports optional chaining on RegExp.exec() results, including patterns created with new RegExp(). Biome now infers the nullable RegExpExecArray | null return type, preserving necessary checks such as new RegExp(pattern).exec(input)?.[1].

  • #​11906 b87822d Thanks @​dyc3! - Fixed #​11900: useForOf no longer reports loops that update their index inside the body, including i += 1 and argv[++i].

  • #​11834 f89dd4f Thanks @​dyc3! - Fixed incorrect type inference when generic parameters are reused across inherited types or swapped in recursive types.

v2.5.14

Compare Source

Patch Changes
  • #​9022 0d49e24 Thanks @​dyc3! - Added the nursery rule noReturnInFinally. This rule disallows return statements in Promise.prototype.finally() callbacks, including inside nested blocks and conditional branches. Returns in nested functions are ignored by the rule.

    // Invalid: return in finally callback
    Promise.resolve(1).finally(() => { return 2 })
    
    // Valid: no return in finally callback
    Promise.resolve(1).finally(() => { console.log(2) })

    Returning a value from a Promise.prototype.finally() callback does not replace the original promise's fulfillment value, which can be confusing. Returned promises and thenables are awaited, and their rejection rejects the resulting promise.

  • #​11754 71eaa0d Thanks @​griff-rees! - Added the nursery rule noSvelteAtDebugTags, which disallows Svelte's {@debug} tag.

    <!-- Invalid: leftover debugging tag -->
    {@debug user}

    The {@debug} tag is a debugging aid and should be removed once you no longer need it, as it should not remain in production code. The rule provides a safe fix

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from skulidropek March 27, 2026 21:46
@renovate renovate Bot changed the title chore(deps): update dependency eslint-plugin-unicorn to v64 fix(deps): update all dependencies Mar 30, 2026
@renovate
renovate Bot force-pushed the renovate/all branch 9 times, most recently from e5e89f4 to 96d426f Compare April 7, 2026 16:34
@renovate
renovate Bot force-pushed the renovate/all branch 12 times, most recently from 651f6b4 to 573619b Compare April 13, 2026 17:43
@renovate
renovate Bot force-pushed the renovate/all branch 5 times, most recently from 4059187 to e18b80b Compare April 17, 2026 22:09
@renovate
renovate Bot force-pushed the renovate/all branch 15 times, most recently from ed8aaaf to 195b515 Compare May 11, 2026 18:02
@renovate
renovate Bot force-pushed the renovate/all branch 3 times, most recently from 0af92ca to 5784ad7 Compare May 14, 2026 12:27
@coderabbitai

coderabbitai Bot commented May 14, 2026 •

Copy link
Copy Markdown

Review Change Stack

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: b8110c34-ecc0-4239-bdc5-a3711257d9c0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Upgrade CI and workspace toolchain: pnpm/action-setup → v6, Node runtime bumped in dependency workflow, workspace packageManager → pnpm@11.1.2, and multiple runtime/dev dependency version bumps across app and template packages.

Changes

Dependency and Toolchain Upgrade

Layer / File(s) Summary
GitHub Actions versions
.github/actions/setup/action.yml, .github/workflows/checking-dependencies.yml
Updated pnpm/action-setup from @v5 to @v6 and bumped Node.js runtime to 24.15.0 in the dependency check workflow.
Workspace pnpm version alignment
package.json, packages/app/package.json
Updated packageManager from pnpm@10.33.0 to pnpm@11.1.2 across root and packages/app; root devDependencies also bumped.
Application package dependencies
packages/app/package.json
Bumped Effect ecosystem (@effect/*, effect) and numerous devDependencies (Biome, ESLint, @typescript-eslint, Vitest, Vite, tooling).
Template package dependencies
packages/eslint-template/package.json
Updated runtime (@effect/platform, @typescript-eslint/utils, effect) and broad devDependencies (Biome, Changesets, @typescript-eslint, Vitest, ESLint plugins, ts-morph, TypeScript, Vite).

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related issues

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly summarizes the primary change: broad dependency and tooling updates across the repository.
Description check ✅ Passed The description directly explains the dependency, package manager, and GitHub Actions updates in the changeset.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch renovate/all

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

🐰 I hopped through package trees tonight,
> nudged pnpm and actions to shine bright,
> lint and tests got spruced and primed,
> CI woke up on bumped Node time,
> carrot-toast for every updated line.

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
package.json (1)

51-53: ⚠️ Potential issue | 🔴 Critical | ⚡ Quick win

Remove or update the patch version in patchedDependencies to match the installed version.

The patchedDependencies entry references @typescript-eslint/eslint-plugin@8.57.2, but the installed version is 8.59.3 (as shown in the lockfile and package.json). This version mismatch prevents the patch from being applied. Since 8.59.3 was released after the patch was created and the underlying optional chaining fix was already included in an earlier release, the patch is likely obsolete. Either update the key to @typescript-eslint/eslint-plugin@8.59.3 if the patch is still needed, or remove it if the issue is already resolved in 8.59.3.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@package.json` around lines 51 - 53, The patchedDependencies entry for
"@typescript-eslint/eslint-plugin@8.57.2" in package.json doesn't match the
installed version (8.59.3) so the patch won't apply; open package.json, locate
the "patchedDependencies" object and either (a) update the key to
"@typescript-eslint/eslint-plugin@8.59.3" if the patch is still required and
ensure the corresponding patch file exists, or (b) remove the
"@typescript-eslint/eslint-plugin@..." entry entirely if the upstream release
already contains the fix (preferred if the optional chaining issue is resolved).
♻️ Duplicate comments (1)
packages/app/package.json (1)

55-86: ⚠️ Potential issue | 🟠 Major

Same major version bumps as eslint-template package.

This package includes the same major version bumps flagged in packages/eslint-template/package.json:

  • ts-morph 27 → 28 (line 80)
  • eslint-plugin-simple-import-sort 12 → 13 (line 73)
  • eslint-plugin-unicorn 63 → 64 (line 76)

Please ensure the verification for those breaking changes applies to this package as well.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/app/package.json` around lines 55 - 86, The same major-version
upgrades flagged for the eslint-template package also affect this package:
update verification for the dependencies ts-morph,
eslint-plugin-simple-import-sort, and eslint-plugin-unicorn in packages/app by
running the identical compatibility checks you ran for eslint-template (exercise
unit tests, linting, build, and any dedicated migration/compat scripts) and
address any API or config changes uncovered; ensure package lock/lockfile is
updated and any fixes or code changes required for the ts-morph 27→28,
eslint-plugin-simple-import-sort 12→13, and eslint-plugin-unicorn 63→64 upgrades
are applied here as well.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@package.json`:
- Line 6: The package.json currently pins "packageManager": "pnpm@11.1.2" but
the repo must be migrated to pnpm v11 config changes: run the pnpm v10→v11
codemod to move settings from the "pnpm" field in package.json and any .npmrc
entries into a new pnpm-workspace.yaml (use camelCase keys), replace any
npm_config_* env usages with pnpm_config_*, stop using pnpm link --global (use
pnpm add -g), convert build-related settings (neverBuiltDependencies,
ignoreDepScripts, etc.) into the allowBuilds map, verify Node engine
compatibility (v18–v21 removed, ensure pure ESM readiness), and confirm global
install path expectations (pnpmHomeDir/global/v11/{hash}); update packageManager
value only after these migrations and verify CI/environment variables and
workspace config are correct.

In `@packages/eslint-template/package.json`:
- Line 33: The package.json now pins "eslint-plugin-simple-import-sort" to
^13.0.0 which enforces deterministic ordering when the same module is imported
multiple times with different styles; search the codebase for modules imported
more than once using different styles (namespace imports like import * as X,
default imports like import X, and named imports like import {a}) and
consolidate them into a single consistent import per source (e.g., combine
default and named into one line or convert namespace to named/default as
appropriate) so autofix no longer changes ordering unexpectedly; update any
files referencing the same source in multiple import statements (look for
occurrences of the module names flagged by the linter) to use a single unified
import form.

---

Outside diff comments:
In `@package.json`:
- Around line 51-53: The patchedDependencies entry for
"@typescript-eslint/eslint-plugin@8.57.2" in package.json doesn't match the
installed version (8.59.3) so the patch won't apply; open package.json, locate
the "patchedDependencies" object and either (a) update the key to
"@typescript-eslint/eslint-plugin@8.59.3" if the patch is still required and
ensure the corresponding patch file exists, or (b) remove the
"@typescript-eslint/eslint-plugin@..." entry entirely if the upstream release
already contains the fix (preferred if the optional chaining issue is resolved).

---

Duplicate comments:
In `@packages/app/package.json`:
- Around line 55-86: The same major-version upgrades flagged for the
eslint-template package also affect this package: update verification for the
dependencies ts-morph, eslint-plugin-simple-import-sort, and
eslint-plugin-unicorn in packages/app by running the identical compatibility
checks you ran for eslint-template (exercise unit tests, linting, build, and any
dedicated migration/compat scripts) and address any API or config changes
uncovered; ensure package lock/lockfile is updated and any fixes or code changes
required for the ts-morph 27→28, eslint-plugin-simple-import-sort 12→13, and
eslint-plugin-unicorn 63→64 upgrades are applied here as well.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: db3c2e88-f3f6-4ca6-8964-0ab35e5ab234

📥 Commits

Reviewing files that changed from the base of the PR and between e03feb6 and 5784ad7.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • .github/actions/setup/action.yml
  • .github/workflows/checking-dependencies.yml
  • package.json
  • packages/app/package.json
  • packages/eslint-template/package.json

Comment thread package.json Outdated
"private": true,
"description": "Monorepo workspace for effect-template",
"packageManager": "pnpm@10.33.0",
"packageManager": "pnpm@11.1.2",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | 🏗️ Heavy lift

🧩 Analysis chain

🌐 Web query:

What are the breaking changes in pnpm 11 compared to pnpm 10?

💡 Result:

The breaking changes in pnpm 11 compared to pnpm 10, as detailed in the official migration guide and release notes, are primarily around configuration handling, command behaviors, and removed features. Here's a complete list: Configuration changes [1][2][3]: - pnpm no longer reads settings from the pnpm field in package.json; move them to pnpm-workspace.yaml [1][2][3]. - .npmrc now only reads auth and registry settings; all other settings (e.g., hoist-pattern, node-linker, save-exact) must be moved to pnpm-workspace.yaml using camelCase keys [1][2][3]. - npm_config_* environment variables are no longer read; use pnpm_config_* instead [1][2][3]. - pnpm no longer reads npm's global config at $PREFIX/etc/npmrc [3]. - Package manager strictness settings (managePackageManagerVersions, packageManagerStrict, packageManagerStrictVersion) collapsed into pmOnFail: download | ignore | warn | error [1]. - allowNonAppliedPatches renamed to allowUnusedPatches; auditConfig.ignoreCves to auditConfig.ignoreGhsas (requires manual CVE to GHSA conversion) [1][2]. Command and behavior changes [1][2][3]: - pnpm link no longer resolves from global store; use relative/absolute paths (e.g., pnpm link ./foo). Removed --global flag (use pnpm add -g .) and pnpm link with no args [1][3]. - pnpm install -g (no args) unsupported; use pnpm add -g <pkg> [1]. - pnpm server command removed [1][2]. - Script names like clean, setup, deploy, rebuild now shadow built-in commands; use pnpm pm <command> to force built-ins [1]. - Removed npm CLI fallback: commands like access, bugs, docs, edit, home, issues, owner, ping, prefix, profile, pkg, search, set-script, team, token, unstar, whoami, xmas (and aliases) now throw errors; many reimplemented natively [2][3]. - Global installs (pnpm add -g) now use isolated directories in {pnpmHomeDir}/global/v11/{hash}/ to prevent interference [3]. - Globally installed binaries now in bin/ subdirectory of PNPM_HOME [3]. Removed/deprecated features [2][3]: - Deprecated build dependency settings removed: onlyBuiltDependencies, onlyBuiltDependenciesFile, neverBuiltDependencies, ignoredBuiltDependencies, ignoreDepScripts. Use allowBuilds map instead [2][3]. - Removed support for useNodeVersion, Env.nodeVersion, pnpmfile [2]. Other [1][2][3]: - Bumps packageManager in package.json to pnpm v11 version [1]. - Default changes: optimisticRepeatInstall: true, verifyDepsBeforeRun: install, minimumReleaseAge: 1440 (1 day), minimumReleaseAgeStrict: false [2]. - Drops Node.js 18-21 support; now pure ESM; standalone exe requires glibc 2.27+ [3]. A codemod is available to automate many config migrations [4]. pnpm prints a pointer to the migration guide on pnpm self-update from v10 [1].

Citations:


Review pnpm 11 migration guide and update configuration accordingly.

pnpm 11 introduces breaking changes requiring configuration updates:

  • Settings in the pnpm field in package.json and .npmrc must migrate to pnpm-workspace.yaml with camelCase keys
  • npm_config_* environment variables replaced with pnpm_config_*
  • pnpm link --global removed; use pnpm add -g <pkg> instead
  • Build dependency settings (neverBuiltDependencies, ignoreDepScripts, etc.) replaced with allowBuilds map
  • Node.js 18-21 support dropped; now pure ESM
  • Global installs now use isolated directories at {pnpmHomeDir}/global/v11/{hash}/

Use the pnpm codemod to automate most config migrations, then verify all settings are correctly moved to pnpm-workspace.yaml.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@package.json` at line 6, The package.json currently pins "packageManager":
"pnpm@11.1.2" but the repo must be migrated to pnpm v11 config changes: run the
pnpm v10→v11 codemod to move settings from the "pnpm" field in package.json and
any .npmrc entries into a new pnpm-workspace.yaml (use camelCase keys), replace
any npm_config_* env usages with pnpm_config_*, stop using pnpm link --global
(use pnpm add -g), convert build-related settings (neverBuiltDependencies,
ignoreDepScripts, etc.) into the allowBuilds map, verify Node engine
compatibility (v18–v21 removed, ensure pure ESM readiness), and confirm global
install path expectations (pnpmHomeDir/global/v11/{hash}); update packageManager
value only after these migrations and verify CI/environment variables and
workspace config are correct.

Comment thread packages/eslint-template/package.json Outdated
@renovate
renovate Bot force-pushed the renovate/all branch 4 times, most recently from 2a1dd99 to 845acb7 Compare May 16, 2026 05:28

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

♻️ Duplicate comments (1)
package.json (1)

6-6: ⚠️ Potential issue | 🟠 Major | 🏗️ Heavy lift

pnpm v11 bump needs config migration validation before merge.

Line 6 upgrades to pnpm@11.1.2, but this file still contains legacy pnpm config keys (Lines 42 and 46) that may no longer behave as intended under v11. Please validate and migrate config to the v11-supported shape before releasing.

#!/bin/bash
set -euo pipefail

echo "1) Locate workspace-level pnpm config files"
fd -HI '^pnpm-workspace\.yaml$' .
fd -HI '^\.npmrc$' .

echo
echo "2) Find deprecated/legacy pnpm keys and any new allowBuilds usage"
rg -n --hidden --glob '!.git' '"(ignoredBuiltDependencies|onlyBuiltDependencies|neverBuiltDependencies|ignoreDepScripts|allowBuilds)"'

echo
echo "3) Find packageManager pin and pnpm config blocks"
rg -n --hidden --glob '!.git' '"packageManager"\s*:|^\s*"pnpm"\s*:'

echo
echo "4) Check env var usage needing pnpm v11 migration"
rg -n --hidden --glob '!.git' '\bnpm_config_[A-Za-z0-9_]+\b|\bpnpm_config_[A-Za-z0-9_]+\b'

echo
echo "5) Check for removed global-link patterns"
rg -n --hidden --glob '!.git' 'pnpm\s+link(\s+--global|\s+-g|\s*$)'
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@package.json` at line 6, The packageManager bump to "pnpm@11.1.2" requires
validating and migrating legacy pnpm config keys (e.g.,
ignoredBuiltDependencies, onlyBuiltDependencies, neverBuiltDependencies,
ignoreDepScripts, allowBuilds) before merge; inspect and update workspace-level
pnpm config (pnpm-workspace.yaml) and project .npmrc entries to the
v11-supported shape, replace/deprecate old env var usages
(npm_config_*/pnpm_config_*), remove any deprecated global link patterns (pnpm
link --global/-g), and ensure the packageManager pin remains correct; run the
provided shell checks (search for pnpm-workspace.yaml, .npmrc, the legacy keys,
packageManager/pnpm blocks, and env var patterns) and apply migrations so the
repo config matches pnpm v11 expectations.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Duplicate comments:
In `@package.json`:
- Line 6: The packageManager bump to "pnpm@11.1.2" requires validating and
migrating legacy pnpm config keys (e.g., ignoredBuiltDependencies,
onlyBuiltDependencies, neverBuiltDependencies, ignoreDepScripts, allowBuilds)
before merge; inspect and update workspace-level pnpm config
(pnpm-workspace.yaml) and project .npmrc entries to the v11-supported shape,
replace/deprecate old env var usages (npm_config_*/pnpm_config_*), remove any
deprecated global link patterns (pnpm link --global/-g), and ensure the
packageManager pin remains correct; run the provided shell checks (search for
pnpm-workspace.yaml, .npmrc, the legacy keys, packageManager/pnpm blocks, and
env var patterns) and apply migrations so the repo config matches pnpm v11
expectations.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e766f135-c608-4b3a-b538-99c7494d15cb

📥 Commits

Reviewing files that changed from the base of the PR and between 2a1dd99 and 845acb7.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • .github/actions/setup/action.yml
  • .github/workflows/checking-dependencies.yml
  • package.json
  • packages/app/package.json
  • packages/eslint-template/package.json
✅ Files skipped from review due to trivial changes (3)
  • .github/workflows/checking-dependencies.yml
  • .github/actions/setup/action.yml
  • packages/eslint-template/package.json
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/app/package.json

@renovate
renovate Bot force-pushed the renovate/all branch 4 times, most recently from 980a33b to bed89b0 Compare May 20, 2026 05:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant