chore(deps): update dependency @biomejs/biome to v2.4.11 - #15
Closed
renovate[bot] wants to merge 337 commits into
Closed
renovate[bot] wants to merge 337 commits into
renovate[bot] wants to merge 337 commits into
Conversation
renovate
Bot
force-pushed
the
renovate/biomejs-biome-2.x
branch
4 times, most recently
from
January 13, 2026 22:45
f345133 to
9e60956
Compare
renovate
Bot
force-pushed
the
renovate/biomejs-biome-2.x
branch
9 times, most recently
from
January 23, 2026 04:09
ef3bf0c to
0056a35
Compare
renovate
Bot
force-pushed
the
renovate/biomejs-biome-2.x
branch
from
January 24, 2026 11:42
0056a35 to
1159fe6
Compare
renovate
Bot
force-pushed
the
renovate/biomejs-biome-2.x
branch
5 times, most recently
from
January 28, 2026 04:10
a5244fb to
d8af0f9
Compare
renovate
Bot
force-pushed
the
renovate/biomejs-biome-2.x
branch
from
February 4, 2026 04:03
d8af0f9 to
53404ea
Compare
renovate
Bot
force-pushed
the
renovate/biomejs-biome-2.x
branch
2 times, most recently
from
February 6, 2026 11:27
6fae266 to
3dd8bf0
Compare
renovate
Bot
force-pushed
the
renovate/biomejs-biome-2.x
branch
from
February 6, 2026 19:59
3dd8bf0 to
ba6fee6
Compare
Add three workflow templates for internal dogfood launch: - Deploy Notification: event trigger on deploy.succeeded → Slack - New User Onboarding: event trigger on member.added → welcome email - Daily Audit Digest: cron → query Chronicle → email summary
renovate
Bot
force-pushed
the
renovate/biomejs-biome-2.x
branch
from
February 7, 2026 07:36
ba6fee6 to
0e079b4
Compare
These files were referenced by committed code but never tracked, breaking Docker/CI builds that clone from git.
The DSL executor traverses workflows via edges, not step next fields. Event workflow seeds had empty edges arrays with next fields on steps, so the executor only ran the trigger step and stopped. Generate edges from next/trueBranch/falseBranch during seeding.
Code sandbox only exposes an input object, not trigger/steps/process.env globals. Add explicit inputs mappings to resolve trigger data, step results, and env vars into the input object for each code step.
Use `hasBilling = !!BILLING_BASE_URL` instead of the boolean `SELF_HOSTED` env var. Remove redundant `isSelfHosted` guard from warden client (existing `authzEnabled` check already handles this).
Publish workflow superseded by Fractal/Kiln pipeline. Add console.warn for optional env vars per Omni startup convention.
The sandbox blocks process globals and the deployed container's template
resolver doesn't support {{ trigger.data.* }}. Use
{{ steps['trigger'].output.event.data.* }} to access trigger data via
the trigger step's output, then pass through check-suppression for
downstream steps.
Register fractal.build.failed, fractal.deploy.succeeded, and fractal.service.crashed event schemas. Add seed script for the fractal-email-send workflow and routing rule.
Add fractal email notification workflow to the eventWorkflows seed array so it is automatically registered on every vortex-api boot. Resolves workspace owners via Gatekeeper, checks suppression, renders templates via fractal-app, and sends individually via Resend.
Add --frozen-lockfile to bun install, pin base image tags, add missing EXPOSE directives, and standardize .dockerignore entries.
GATEKEEPER_ -> AUTH_, AETHER_ -> BILLING_. Core infra env vars should describe their use case, not their internal product name.
…e and quote events Route mantle.invoice.* and mantle.quote.* events to MyFi's /api/webhooks/mantle endpoint for automated accounting
The platform has grown beyond 16 internal subscriptions, hitting the previous default
Reads all user-organization memberships from the local DB (synced from Gatekeeper) and writes the corresponding authorization tuples to the Warden PDP. Supports --dry-run and --delete-orphans flags, following the same pattern as Runa's reconciliation scripts. Usage: bun authz:reconcile
Add three REST endpoints for external systems (e.g. Hatchet cron) to check and repair user-organization membership tuple drift between the DB and Warden PDP: - GET /api/v1/authz/tuples (expected tuples from DB) - GET /api/v1/authz/drift (diff expected vs PDP) - POST /api/v1/authz/reconcile (write missing, optionally delete orphans)
The API was blindly setting status='running' after dispatchWorkflow returned, but the worker can complete the run before the dispatch call returns (races of 100ms or less for simple workflows). This overwrote completed/failed terminal states back to running, leaving runs stuck forever in the UI. Add WHERE status='pending' guard so the update only fires if the worker hasn't already transitioned the state.
…er seats - Security: drizzle-orm 0.45.1 to 0.45.2 (SQL injection fix) - Deps: graphql 16.13.2, @sentry/bun 10.48.0, @hatchet-dev/typescript-sdk 1.21.0, graphql-yoga 5.21.0, @tanstack/query-core 5.97.0, @temporalio/client 1.16.0 - Auth: propagate idpUserId from Gatekeeper API keys so Warden checks run for API key holders (not just session users) - Billing: hard-enforce MAX_USERS entitlement in IDP webhook handler (was warn-only, now rejects when seat limit exceeded) - Tests: add regression tests for API key authZ propagation and seat enforcement - Chore: add packageManager field, rename WARDEN_SYNC to AUTHZ_SYNC in locks, fix graphql type dedup in schema generation script
Add Warden authorization checks to 18 read endpoints and billing usage metering (recordUsage) to 20 mutation endpoints. Upgrade dependencies (graphile to stable 1.0.0). Align with Omni template conventions (package.json metadata, changeset config, husky). Note: tsc --noEmit has pre-existing PostGraphile v5 type errors from the graphile RC to stable upgrade that need separate resolution.
Add type annotations for graphile 1.0.0 stable API changes: - Cast fieldArgs.getRaw() returns (AnyInputStep to Step<any>) - Annotate Drizzle where callback parameters - Bridge GraphQLSchema type between graphql and graphql-yoga
…illing exports Close the authorization gap for event subscriptions by adding a GraphQL plugin that enforces admin+ role and max_subscriptions plan limits on create/update/delete mutations. Also export checkUsage from the billing module for worker-side pre-execution limit checks.
Add AUTHZ_API_URL and AUTHZ_SERVICE_KEY to all env config mocks so the warden/client.ts re-export does not fail when Bun runs multiple test files in the same process. Expand the wardenSyncPoller mock to preserve checkPermission behavior and prevent it from stubbing out the authorize wrapper tests. Add env config mock to execution.test.ts to prevent the real assertEnv from throwing.
…upgrade deps Add execution limit check to function invocation to prevent billing bypass. Add Warden authorize to DLQ list/stats endpoints. Add CLA workflow, changeset tooling, and source-code validation tests for enforcement coverage.
The dep upgrade resolved grafast ^1.0.0-rc.8 to stable 1.0.0, which has breaking changes in the planning lifecycle (currentLayerPlan). Pin to exact 1.0.0-rc.8 until PostGraphile v5 reaches stable.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.4.8→2.4.112.4.8→2.4.11Release Notes
biomejs/biome (@biomejs/biome)
v2.4.11Compare Source
Patch Changes
#9350
4af4a3aThanks @dyc3! - Added the new nursery rule useConsistentTestIt in thetestdomain. The rule enforces consistent use of eitheritortestfor test functions in Jest/Vitest suites, with separate control for top-level tests and tests insidedescribeblocks.Invalid:
#9429
a2f3f7eThanks @ematipico! - Added the new nursery lint ruleuseExplicitReturnType. It reports TypeScript functions and methods that omit an explicit return type.#9828
9e40844Thanks @ematipico! - Fixed #9484: the formatter no longer panics when formatting files that containgraphqltagged template literals combined with parenthesized expressions.#9886
e7c681eThanks @ematipico! - Fixed an issue where, occasionally, some bindings and references were not properly tracked, causing false positives fromnoUnusedVariablesandnoUndeclaredVariablesin Svelte, Vue, and Astro files.#9760
5b16d18Thanks @myx0m0p! - Fixed #4093: thenoDeleterule no longer triggers fordelete process.env.FOO, sincedeleteis the documented way to remove environment variables in Node.js.#9799
2af8efdThanks @minseong0324! - Added the rulenoMisleadingReturnType. The rule detects when a function's return type annotation is wider than what the implementation actually returns.#9880
7f67749Thanks @dyc3! - Improved the diagnostics foruseFindto better explain the problem, why it matters, and how to fix it.#9755
bff7bdbThanks @ematipico! - Improved performance of fix-all operations (--write). Biome is now smarter when it runs lint rules and assist actions. First, it runs only rules that have code fixes, and then runs the rest of the rules.#8651
aafca2dThanks @siketyan! - Add a new lint ruleuseDisposablesfor JavaScript, which detects disposable objects assigned to variables withoutusingorawait usingsyntax. Disposable objects that implement theDisposableorAsyncDisposableinterface are intended to be disposed of after use. Not disposing them can lead to resource or memory leaks, depending on the implementation.Invalid:
Valid:
#9788
53b8e57Thanks @MeGaNeKoS! - Fixed #7760: Added support for CSS scroll-driven animationtimeline-range-namekeyframe selectors (cover,contain,entry,exit,entry-crossing,exit-crossing). Biome no longer reports parse errors on keyframes likeentry 0% { ... }orexit 100% { ... }.#9728
5085424Thanks @mkosei! - Fixed #9696: Astro frontmatter now correctly parses regular expression literals like/\d{4}/.#9261
16b6c49Thanks @ematipico! - Fixed #8409: CSS formatter now correctly places comments after the colon in property declarations.Previously, comments that appeared after the colon in CSS property values were incorrectly moved before the property name:
[lang]:lang(ja) { - /* system-ui,*/ font-family: + font-family: /* system-ui,*/ Hiragino Sans, sans-serif; }#9441
957ea4cThanks @soconnor-seeq! - Fixed #1630: LSP project selection now prefers the most specific project root in nested workspaces.#9878
de6210fThanks @ematipico! - Fixed #9118:noUnusedImportsno longer reports false positives for default imports used inside Svelte, Vue and Astro components.#9879
ce7e2b7Thanks @dyc3! - Fixed a parser diagnostic's message when vue syntax is disabled so that it no longer references the non-existanthtml.parser.vueoption. This option will become available in 2.5.#9880
7f67749Thanks @dyc3! - Improved the diagnostics foruseRegexpExecto better explain the problem, why it matters, and how to fix it.#9846
b7134d9Thanks @ematipico! - Fixed #9140: Biome now parses Astro's attribute shorthand inside.astrofiles. The following snippet no longer reports a parse error:#9790
67df09dThanks @dyc3! - Fixed #9781: Trailing comments after a top-levelbiome-ignore-all formatsuppression are now preserved instead of being dropped. This applies to JavaScript, CSS, HTML, JSONC, GraphQL, and Grit files.#9745
d87073eThanks @ematipico! - Fixed #9741: the LSP server now correctly returns theorganizeImportscode action when the client requests it viasource.organizeImports.biomein theonlyfilter. Previously, editors withcodeAction/resolvesupport (e.g. Zed) received an empty response because the action was serialized with the wrong kind (source.biome.organizeImportsinstead ofsource.organizeImports.biome).#9880
7f67749Thanks @dyc3! - Improved the diagnostics foruseArraySometo better explain the problem, why it matters, and how to fix it.#9795
1d09f0fThanks @dyc3! - RelaxeduseExplicitTypefor trivially inferrable types.Type annotations can now be omitted when types are trivially inferrable from:
const sum = 1 + 1)const isEqual = 'a' === 'b',const isTest = process.env.NODE_ENV === 'test')const and = true && false)const date = new Date())const arr = [1, 2, 3])const val = true ? 'yes' : 'no')const num = Math.random())const fn = (max = MAX_ATTEMPTS) => ...)Comparison expressions always return
boolean, so any operands are now allowed(including property access like
process.env.NODE_ENV).Parameters with default values no longer require type annotations, as TypeScript
can infer the type from the default value (even when referencing variables).
Also removed the redundant
anytype validation from this rule. Theanytypeis now only validated by the dedicated
noExplicitAnyrule, following theSingle Responsibility Principle.
#9809
e8cad58Thanks @Netail! - Added the new nursery ruleuseQwikLoaderLocation, which enforces that Qwik loader functions are declared in the correct location.#9877
fc9d715Thanks @ematipico! - Fixed #9136 and #9653:noUndeclaredVariablesandnoUnusedVariablesno longer report false positives on several Svelte template constructs that declare or reference bindings in the host grammar:{#snippet name(params)}— the snippet name and its parameters (including object, array, rest, and nested destructuring) are now tracked.{@​render name(args)}— the snippet name used at the render site is now resolved against the snippet declaration.{#each items as item, index (key)}— theitembinding (plain identifier or destructured), the optionalindex, and the optionalkeyexpression are now tracked.{@​const name = value}— the declared name is now tracked as a binding and the initializer is analyzed for undeclared references.{@​debug a, b, c}— each debugged identifier is now analyzed and reported if undeclared.<img {src} />— the curly-shorthand attribute is now analyzed as an expression, so undeclared references inside it are reported.For example, the following template no longer triggers either rule:
#9869
78bce77Thanks @Netail! - UpdatednoDuplicateFieldDefinitionNamesto also flag duplicate fields within type extensions, interface extensions & input extensions.#9739
0bc2198Thanks @dyc3! - Fixed Grit queries that use native Biome AST node names with the native field names that are in our.ungramgrammar files. Queries such asJsConditionalExpression(consequent = $cons, alternate = $alt)now compile successfully inbiome searchand grit plugins.#9811
2dddca3Thanks @dyc3! - UpdatednoImpliedEvalto flagnew Function()usages, as its a form of indirecteval, and to includeno-new-funcas a rule source.#9870
ccf9770Thanks @Netail! - Marked eslint-qwik-plugin'sunused-serveras redundant since it was covered bynoUnusedVariables.#9701
1417c3bThanks @dyc3! - Added the new nursery rulenoUselessTypeConversion, which reports redundant primitive conversion patterns such asString(value)whenvalueis already a string.#9248
49f00a3Thanks @pkallos! -useNullishCoalescingnow also detects ternary expressions that check fornullorundefinedand suggests rewriting them with??. A newignoreTernaryTestsoption allows disabling this behavior.#9863
6a44619Thanks @ematipico! - Fixed #9690:biome check --writeis now idempotent on HTML files that contain embedded<style>or<script>blocks. Previously, each run reported "Fixed 1 file" even when the file content did not actually change, because the embedded language formatter's output was not re-indented to match the surrounding HTML block.v2.4.10Compare Source
Patch Changes
#8838
f3a6a6bThanks @baeseokjae! - Added new lint nursery rulenoImpliedEval.The rule detects implied
eval()usage through functions likesetTimeout,setInterval, andsetImmediatewhen called with string arguments.#9320
93c3b6cThanks @taberoajorge! - Fixed #7664:noUnusedVariablesno longer reports false positives for TypeScript namespace declarations that participate in declaration merging with an exported or used value declaration (const,function, orclass) of the same name. The reverse direction is also handled: a value declaration merged with an exported namespace is no longer flagged.#9630
1dd4a56Thanks @raashish1601! - Fixed #9629:noNegationElsenow keeps ternary branch comments attached to the correct branch when applying its fixer.#9216
04243b0Thanks @FrederickStempfle! - Fixed #9061:noProcessEnvnow also detectsprocess.envwhenprocessis imported from the"process"or"node:process"modules.Previously, only the global
processobject was flagged:#9692
61b7ec5Thanks @mkosei! - Fixed Svelte#eachdestructuring parsing and formatting for nested patterns such as[key, { a, b }].#9627
06a0f35Thanks @ematipico! - Fixed #191: Improved the performance of how the Biome Language Server pulls code actions and diagnostics.Before, code actions were pulled and computed all at once in one request. This approach couldn't work in big files, and caused Biome to stale and have CPU usage spikes up to 100%.
Now, code actions are pulled and computed lazily, and Biome won't choke anymore in big files.
#9643
5bfee36Thanks @dyc3! - Fixed #9347:useVueValidVBindno longer reports valid object bindings likev-bind="props".#9627
06a0f35Thanks @ematipico! - Fixed assist diagnostics being invisible when using--diagnostic-level=error. Enforced assist violations (e.g.useSortedKeys) were filtered out before being promoted to errors, causingbiome checkto incorrectly return success.#9695
9856a87Thanks @dyc3! - Added the new nursery rulenoUnsafePlusOperands, which reports+and+=operations that use object-like,symbol,unknown, orneveroperands, or that mixnumberwithbigint.#9627
06a0f35Thanks @ematipico! - Fixed duplicate parse errors incheckandcioutput. When a file had syntax errors, the same parse error was printed twice and the error count was inflated.#9627
06a0f35Thanks @ematipico! - Improved the performance of the commandslintandcheckwhen they are called with--write.#9627
06a0f35Thanks @ematipico! - Fixed--diagnostic-levelnot fully filtering diagnostics. Setting--diagnostic-level=errornow correctly excludes warnings and infos from both the output and the summary counts.#9623
13b3261Thanks @ematipico! - Fixed #9258:--skipno longer causessuppressions/unusedwarnings for suppression comments targeting skipped rules or domains.#9631
599dd04Thanks @raashish1601! - Fixed #9625:experimentalEmbeddedSnippetsEnabledno longer crashes when a file mixes formatable CSS-in-JS templates with tagged templates that the embedded formatter can't currently delegate, such as a styled-components interpolation returning `css```.v2.4.9Compare Source
Patch Changes
#9315
085d324Thanks @ematipico! - Added a new nursery CSS rulenoDuplicateSelectors, that disallows duplicate selector lists within the same at-rule context.For example, the following snippet triggers the rule because the second selector and the first selector are the same:
#9567
b7ab931Thanks @ematipico! - Fixed #7211:useOptionalChainnow detects negated logical OR chains. The following code is now considered invalid:#8670
607ebf9Thanks @tt-a1i! - Fixed #8345:useAdjacentOverloadSignaturesno longer reports false positives for static and instance methods with the same name. Static methods and instance methods are now treated as separate overload groups.#9476
97b80a8Thanks @masterkain! - Fixed#9475: Fixed a panic when Biome analyzed ambient TypeScript modules containing class constructor, getter, or setter signatures that reference local type aliases. Biome now handles these declarations without crashing during semantic analysis.#9553
0cd5298Thanks @dyc3! - Fixed a bug where enabling the rules of a whole group, would enable rules that belonged to a domain under the same group.For example,
linter.rules.correctness = "error"no longer enables React- or Qwik-specific correctness rules unlesslinter.domains.react,linter.domains.qwik, or an explicit rule config also enables them, or their relative dependencies are installed.#9586
4cafb71Thanks @dyc3! - Fixed #8828: Grit patterns usingexport { $foo } from $sourcenow match named re-exports in JavaScript and TypeScript files.#9550
d4e3d6eThanks @dyc3! - Fixed #9548: Biome now parses conditional expressions whose consequent is an arrow function returning a parenthesized object expression.#8696
a7c19ccThanks @Faizanq! - Fixed #8685 wherenoUselessLoneBlockStatementswould remove empty blocks containing comments. The rule now preserves these blocks since comments may contain important information like TODOs or commented-out code.#9557
6671ac5Thanks @datalek! - Fixed #9557: Biome's LSP server no longer crashes on startup when used with editors that don't sendworkspaceFoldersduring initialization. This affected any LSP client that only sendsrootUri, which is valid per the LSP specification.#9455
1710cf1Thanks @omar-y-abdi! - Fixed #9174:useExpectnow correctly rejects asymmetric matchers in Vitest or Jest likeexpect.stringContaining(),expect.objectContaining(), and utilities likeexpect.extend()that are not valid assertions. Previously these constructs caused false negatives, allowing tests without real assertions to pass the lint rule.#9584
956e367Thanks @ematipico! - Fixed a bug where Vue directive attribute values likev-bind:class="{'dynamic': true}"were incorrectly parsed as JavaScript statements instead of expressions. Object literals inside directive values like:class,v-if, andv-htmlare now correctly parsed as expressions, preventing spurious parse errors.#9474
e168494Thanks @ematipico! - Added the new nursery rulenoUntrustedLicenses. This rule disallows dependencies that ship with invalid licenses or licenses that don't meet the criteria of your project/organisation.The rule has the following options:
allow: a list of licenses that can be allowed. Useful to bypass possible invalid licenses from downstream dependencies.deny: a list of licenses that should trigger the rule. Useful to deny licenses that don't fit your project/organisation.When both
denyandalloware provided,denytakes precedence.requireOsiApproved: whether the licenses need to be approved by the Open Source Initiative.requireFsfLibre: whether the licenses need to be approved by the Free Software Foundation.#9544
723798bThanks @ViniciusDev26! - Added an unsafe fix touseConsistentMethodSignaturesthat automatically converts between method-style and property-style signatures.#9555
8a3647bThanks @ematipico! - Fixed#188: the Biome Language Server no longer panics when open files change abruptly, such as during git branch checkouts.#9605
f65c637Thanks @ematipico! - Fixed #9589. Now Biome correctly parses object expressions inside props and directives. The following code doesn't emit errors anymore:#9565
ccb249eThanks @eyupcanakman! - Fixed #9505:noUselessStringConcatno longer reports tagged template literals as useless string concatenations. Tagged templates invoke a function and can return non-string values, so combining them with+is not equivalent to a single template literal.#9534
4d050dfThanks @Netail! - Added the nursery rulenoInlineStyles. The rule disallows the use of inlinestyleattributes in HTML and thestyleprop in JSX, includingReact.createElementcalls. Inline styles make code harder to maintain and can interfere with Content Security Policy.#9611
cddaa44Thanks @gaauwe! - Fixed a regression where Biome LSP could misread editor settings sent throughworkspace/didChangeConfigurationwhen the payload was wrapped in a top-levelbiomekey. This causedrequireConfigurationand related settings to be ignored in some editors.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.