chore(deps): update linters - #2375
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
requested review from
dhoard,
fstab,
jaydeluca and
zeitlinger
as code owners
August 10, 2026 01:40
Contributor
Benchmark resultsBenchmark run finished with conclusion
Benchmark summary artifact was not found; see the workflow run for details. |
renovate
Bot
force-pushed
the
renovate/linters
branch
7 times, most recently
from
August 12, 2026 00:40
f99a3b6 to
5503307
Compare
renovate
Bot
force-pushed
the
renovate/linters
branch
from
August 12, 2026 09:37
5503307 to
c2b5224
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.4.4→0.5.02.5.5→2.5.83.8.0→3.11.11.35.0→1.36.143.279.1→44.16.044.26.0(+23)0.16.0→0.16.2v0.2.43→v0.2.541.48.0→1.49.01.28.0→1.29.0Release Notes
jonwiggins/xmloxide (aqua:jonwiggins/xmloxide)
v0.5.0Compare Source
Changed
Node-sets (
XPathValue::NodeSet) now holdXPathNodeentries — either atree node or an attribute identified by owner element and index — instead
of bare
NodeIds. This fixes a family of wrong-answer bugs rooted in theold one-value-per-element override map:
//a/@x != //a/@ycomparisons nolonger clobber each other's values,
@*yields one node per attribute(previously only the first per element),
count((//a)[1]/@href)returns anumber instead of a type error,
name()/local-name()/namespace-uri()work on attribute nodes,
@attr/..navigates to the owner element,predicates evaluate with the attribute as context node, and namespace
declarations (
xmlns,xmlns:*) are no longer visible as attributes perthe XPath 1.0 data model. Mixed node-sets (
//a | //a/@x) sort indocument order with attributes directly after their owner element.
Breaking: code matching
XPathValue::NodeSetmust handleXPathNode; use.anchor()for the owning tree node or.as_tree_node()to filter attributes out. The single-match collapse(attribute paths returning
XPathValue::String) is gone — convert withstring()where a string is wanted.xmllint --xpathprints attributeresults as
name="value"lines, matching libxml2. The C API keepsxmloxide_xpath_nodeset_item()(returns the owner element id forattributes) and adds
xmloxide_xpath_nodeset_item_is_attribute(),..._attr_name(), and..._attr_value().//a/b[1]now selects the firstbof everya(previously the firstof the merged set), and
position()/last()in step predicates arerelative to each context node's own node-set, matching libxml2. The
parenthesized form
(//a/b)[1]keeps global-position semantics.context="//@id") now firewith the attribute itself as the context node —
.is the attributevalue and
<value-of select="."/>reads it, per ISO Schematron.Previously such rules either never fired (single match) or misfired
against the owner element.
Security
WFC: No Recursion walks in the DTD validator re-visited entities once per
path, so a 474-byte document with chained entity declarations took 8+
seconds to parse and a 694-byte one about 22 hours. The walks (including
parameter entities and ATTLIST-default validation) now memoize entities
proven acyclic, making the check linear in the size of the DTD. Cycle
detection is unaffected.
is parsed by nested sub-parsers, which now inherit the outer parser's
nesting depth so total element depth stays bounded by
ParseOptions::max_depthinstead ofmax_depthper expansion level.Fixed
(#43, thanks @hey-jj).
EntityRefnodes now carry their parsed expansionas children: character references in declarations are expanded when
replacement text is built (§4.5), nested entity references are included,
and markup-bearing entities produce real element children instead of
escaped text — while serialization still emits
&name;, keepinground-trips lossless. Replacement text must match the content production
(§4.3.2); unbalanced or split tags are rejected. Entity expansion is
subject to the expansion counter, a nesting-depth cap, and the 5x
amplification guard, matching libxml2. DTD content-model validation sees
through entity references (§4.4.3), so entity-supplied elements are
validated too.
!=uses its own existential semantics for node-sets per XPath1.0 §3.4 (#44, thanks @hey-jj).
!=was evaluated asnot(=), invertingempty-node-set comparisons and breaking multi-node sets (both
=and!=can hold at once). Node-set vs boolean keeps boolean-conversion semantics;
scalar comparisons are unchanged. An absent attribute step now also yields
an empty node-set (false under both
=and!=) instead of anempty-string sentinel.
thanks @ancientcatz).
(//a)[1]/@hrefparsed to the same AST as(//a)[@href], so the trailing path acted as a predicate andstring((//a)[1]/@href)returned the anchor text. A newExpr::FilterPathAST variant evaluates the continuation steps againstthe filter's node-set. Breaking: downstream exhaustive matches on
xpath::ast::Exprmust handle the new variant.biomejs/biome (biome)
v2.5.8: Biome CLI v2.5.8Compare Source
2.5.8
Patch Changes
#10710
0a0fbc1Thanks @dyc3! - Added a new nursery ruleuseReactCompiler, which reports diagnostics from React Compiler lint mode.#11251
ea9dd8aThanks @dyc3! - Improved performance ofnoImportCycles.#11247
52b44d6Thanks @dyc3! - Added the nursery rulenoSvelteLegacyConst, which disallows legacy Svelte{@const}tags and recommends declaration tags with$derived().Invalid:
{#each boxes as box} {@const area = box.width * box.height} <p>{area}</p> {/each}Valid:
{#each boxes as box} {const area = $derived(box.width * box.height)} <p>{area}</p> {/each}#11252
d5f5704Thanks @Turtle-Hwan! - Fixed #11250:useAwaitno longer reports async functions that contain anawait usingdeclaration.#11143
6be7be1Thanks @vznh! - Fixed #11017:noUselessUndefinedno longer reportsreturn undefinedwhen the enclosing function has a return type annotation other thanundefinedorvoid.#11234
caefe39Thanks @subotac! - Fixed #11228: CSS block comments between a declaration colon and value now preserve their source indentation.:root { --font-stack: -/* comment */ + /* comment */ system-ui; }#11285
bca1f73Thanks @denbezrukov! - Fixed #11280: CSS formatting keeps comments inside functional pseudo-classes and pseudo-elements instead of moving them before the function name.#11080
af16a0bThanks @dyc3! - HTMLstyleattribute values are now parsed as CSS. All Biome CSS lint rules are applied to thestyleattributes.#11195
6a85588Thanks @dyc3! - Fixed Svelte files failing to parse when an expression begins with an object literal.Now the following snippet is correctly parsed:
#11173
481d008Thanks @Austin1serb! - Fixed #10242: JavaScript GritQL patterns with multiple metavariables now match snippets consistently in WebAssembly.#11187
23c0369Thanks @ematipico! - Added the nursery rulenoInvalidPropertyInitValue, which reports an@propertywhoseinitial-valuedoes not match itssyntaxdescriptor. For example, the following declaration triggers the rule becauseredis not a<length>:#11272
73896e6Thanks @ematipico! - Improved the diagnostic emitted bynoRootType.#11240
bd0b68dThanks @ematipico! - Fixed #11223: Improved theperformance of
noMisusedPromiseswhen analyzing async class methods that call other methods through
this.#11172
4a0bc5cThanks @saberoueslati! - Fixed #10806:noUselessFragmentsno longer causes Biome to panic when its unsafe fix removes a fragment used as a JSX attribute value.#11227
4d603b0Thanks @saberoueslati! - Fixed #11178:noUndeclaredVariablesno longer reports Vue's built-in instance properties, such as$slotsand$attrs, in template expressions or$eventin inline event-handler expressions. The instance properties are still reported inside<script setup>, where they are not defined.#11187
23c0369Thanks @ematipico! - Fixed CSS parsing of registered custom properties: Biome now correctly validates thesyntaxdescriptor of@propertyrules.What's Changed
useReactCompilerby @dyc3 in #10710noSvelteLegacyConstby @dyc3 in #11247{{as an interpolation in Svelte by @dyc3 in #11195New Contributors
Full Changelog: https://github.com/biomejs/biome/compare/@biomejs/biome@2.5.7...@biomejs/biome@2.5.8
v2.5.7: Biome CLI v2.5.7Compare Source
2.5.7
Patch Changes
#10822
c171b3bThanks @pkallos! - Added the optionignoreIfStatementsto useNullishCoalescing. Biome now flagsifstatements that only assign to a nullish variable (such asif (!a) { a = b }) and can rewrite them to??=. When enabled, Biome ignores thoseifstatements.#11136
e63354cThanks @AkashNaickar! - Added a new nursery rulenoExtendNative, which reports extending the prototype of a built-in object.#10094
e007143Thanks @THEjacob1000! - Added the nursery rulenoTailwindArbitraryValue. Biome now reports Tailwind CSS arbitrary values such asw-[400px], including in HTML/JSX class attributes, configured utility functions, and tagged templates.#11184
135f476Thanks @subotac! - Fixed #11176:noUnknownPseudoClassnow recognizes Vue's:deep()pseudo-class inside.vuestyle blocks.#8239
a519f9dThanks @cormacrelf! - Fixed #8233, where Biome CLI instdin mode didn't work correctly when handling files in projects with nested
configurations. For example, with the following structure,
--stdin-file-path=subdirectory/...would not use the nested configuration insubdirectory/biome.json:biome format --write --stdin-file-path=subdirectory/lib.js < subdirectory/lib.jsNow, the nested configuration is correctly picked up and applied.
In addition, Biome now shows a warning if
--stdin-file-pathis provided butthat path is ignored and therefore not formatted or fixed.
#11138
8c2c6bdThanks @ematipico! - FixednoUnnecessaryConditions: Biome now chooses the same function overload as TypeScript when an argument is a callback, so conditions that were previously missed are reported.The following code is now invalid, because a parameter typed
() => voidaccepts anasynccallback andscheduletherefore returnsstring:The following code is also now invalid, because
map(() => 42)returns42:#11138
8c2c6bdThanks @ematipico! - Fixed #11087:noUnnecessaryConditionsno longer reports optional chains and nullish coalescing whose receiver can be nullish.For example, the optional chain and fallback in the following code are no longer reported:
#11118
9c16840Thanks @subotac! - Fixed #11098: The HTML formatter now preserves the configured trailing newline when a file ends with a comment.#11201
0e80610Thanks @Bishwas-py! - Fixed #11182: suppression comments fornoPositiveTabindexnow suppress the rule in HTML files when the attributes of the element span multiple lines.#11079
607afd2Thanks @dyc3! - The HTML formatter now lays out thesrcsetattribute of<img>and<source>as the list of candidates it is. Runs of whitespace between candidates collapse, and once the list no longer fits on one line each candidate goes on its own line with the descriptors aligned:#11156
fed72c7Thanks @saberoueslati! - Fixed #11129:noUnusedVariablesno longer reports Vue bindings as unused when they are assigned through automatically unwrapped template refs.#11124
d890b39Thanks @denbezrukov! - Fixed CSS formatting of line comments between a declaration colon and value to preserve their source indentation..test { background: - /////// foo - // bar + /////// foo + // bar radial-gradient(circle, #​000, transparent); }#11113
3d8ab73Thanks @denbezrukov! - Fixed CSS formatting of long block comments between comma-separated property values:.foo { box-shadow: - 1000px /* long long long long long long long long long long long long comment */ 1000px /* long long long long long long long long long comment */ 2px color(srgb 0.555555555 0.555555555 0.555555555), + 1000px + /* long long long long long long long long long long long long comment */ + 1000px /* long long long long long long long long long comment */ 2px + color(srgb 0.555555555 0.555555555 0.555555555), 1px 1px black; }#11127
da5c1a5Thanks @dyc3! - The HTML formatter now picks the quote character for an attribute by counting the quotes in the value rather than looking only for a double quote.'and"count as the characters they stand for, and only the character that ends up as the delimiter stays escaped:Entities that are not quotes, such as
&or&[#​39](https://redirect.github.com/biomejs/biome/issues/39);, are left exactly as written.#11193
77035bbThanks @dyc3! - Fixed the HTML formatter collapsing the blank line between an element and the text that follows it. A blank line before text is now kept, the way one before another element already was:<div>foo</div> - text#11106
ad80f57Thanks @dyc3! - The HTML formatter now writes the HTML5 doctype in lowercase, matching Prettier:This only applies to a plain
.htmlfile whose doctype stands alone. A doctype that names a DTD keeps the case it was written with, since the rest of the declaration is not lowercased either:<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">A
.vue,.svelte, or.astrofile keeps whatever the author wrote.#11188
60679dbThanks @dyc3! - Fixed the HTML formatter printing a comment twice when it ended the line of the last element in a document:#11077
4dcd0d9Thanks @dyc3! - Fixed a bug where the HTML formatter collapsed the whitespace inside<textarea>,<xmp>and<plaintext>, changing what the page renders.Biome now prints the content of these elements exactly as it appears in the source, matching the existing behavior for
<pre>.#11194
abfbb11Thanks @dyc3! - Fixed the HTML formatter refusing to format a Svelte file containing an array pattern that skips a position:{#each animals as [, value]} <p>{value}</p> {/each}#10094
e007143Thanks @THEjacob1000! - FixeduseSortedClassesto correctly detect unsorted classes in static member expression tagged templates (e.g.tw.div\...``). Previously, these were silently skipped due to surrounding whitespace trivia not being stripped from the tag name.#11078
10da30eThanks @dyc3! - Fixed Vue single-file components failing to parse when they contain a custom block such as<i18n>or<docs>, or a<template>written in another language. Their content is no longer read as HTML, so a block may hold whatever its own tooling expects:Previously both blocks produced a parse error and the whole file was left unformatted. Biome now prints their content unchanged while still formatting the opening tag.
#11231
4afd901Thanks @ematipico! - Improved the performance of the following lint rules:noArguments.noGlobalAssign.noUndeclaredVariables.noRestrictedGlobals.noInvalidUseBeforeDeclaration.noShadow.noRedeclare.#11134
2fa0a62Thanks @yanthomasdev! - Clarified the warning emitted when using the experimentaljsonandjson-prettyreporters.#11198
ed88b13Thanks @saberoueslati! - Fixed #11171: variables referenced only inside a Svelte attachment ({@attach ...}) are no longer reported as unused bynoUnusedVariablesandnoUnusedImports.#11155
6ee17eaThanks @dyc3! - Improved performance when printing diagnostics to the console.#11160
217f8adThanks @dyc3! - Improved the performance ofnoFloatingPromisesby skipping type inference for assignment statements, which are always considered handled.#11159
26c23d9Thanks @saberoueslati! - Fixed #11144:noFloatingPromisesno longer reports already-awaited optional Promise values.#11138
8c2c6bdThanks @ematipico! - Fixed #11121:noUnnecessaryConditionsno longer reports conditions based on an inapplicable function overload.For example, the condition in the following code is no longer reported because
query({})selects the overload that returnsboolean:#11152
c4fc6a9Thanks @dyc3! - Improved the performance of collecting rule timings with--profile-rulesin heavily multithreaded environments.#11128
4d3ff76Thanks @ematipico! - Fixed #7635:noDeprecatedImportsnow detects deprecated ambient declarations that are exported separately.#11117
01f7ef5Thanks @subotac! - Fixed #11014:noDeleteno longer reportsprocess.env["FOO"]style property deletions.#11168
9847e68Thanks @saberoueslati! - Added the nursery rulenoNonScalableViewport, which reports viewport metadata that disables user scaling withuser-scalable=no.For example:
#11154
a1d6b1fThanks @dyc3! - Improved the performance ofnoImportCyclesby skipping graph traversals for imports that cannot be part of a cycle.#11175
d96d6ddThanks @ematipico! - Fixed CSS parsing of registered custom properties: Biome now correctly validates thesyntaxdescriptor of@propertyrules.What's Changed
#and alias name lexing by @dyc3 in #11061--stdin-file-pathwith nested configuration by @cormacrelf in #8239html_embedsfeature for tests by @dyc3 in #11216New Contributors
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.