Skip to content

fix(deps): update all dependencies - #28

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all
Open

fix(deps): update all dependencies#28
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Mar 27, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@biomejs/biome (source) ^2.4.9^2.5.6 age confidence devDependencies minor
@changesets/changelog-github (source) ^0.6.0^0.7.0 age confidence devDependencies minor
@changesets/cli (source) ^2.30.0^2.31.1 age confidence devDependencies minor
@effect/cli (source) ^0.75.0^0.77.0 age confidence dependencies minor
@effect/cluster (source) ^0.58.0^0.60.2 age confidence dependencies minor
@effect/experimental (source) ^0.60.0^0.61.1 age confidence dependencies minor
@effect/platform (source) ^0.96.0^0.97.1 age confidence dependencies minor
@effect/platform-node (source) ^0.106.0^0.108.1 age confidence dependencies minor
@effect/printer (source) ^0.49.0^0.51.0 age confidence dependencies minor
@effect/printer-ansi (source) ^0.49.0^0.51.0 age confidence dependencies minor
@effect/rpc (source) ^0.75.0^0.76.2 age confidence dependencies minor
@effect/sql (source) ^0.51.0^0.52.1 age confidence dependencies minor
@effect/typeclass (source) ^0.40.0^0.41.0 age confidence dependencies minor
@effect/vitest (source) ^0.29.0^0.30.0 age confidence devDependencies minor
@effect/workflow (source) ^0.18.0^0.19.1 age confidence dependencies minor
@eslint-community/eslint-plugin-eslint-comments ^4.7.1^4.7.2 age confidence devDependencies patch
@eslint/compat (source) 2.0.32.1.0 age confidence devDependencies minor
@eslint/eslintrc 3.3.53.3.6 age confidence devDependencies patch
@types/node (source) ^25.5.0^25.9.5 age confidence devDependencies minor
@typescript-eslint/eslint-plugin (source) ^8.57.2^8.65.0 age confidence devDependencies minor
@typescript-eslint/parser (source) ^8.57.2^8.65.0 age confidence devDependencies minor
@typescript-eslint/rule-tester (source) 8.57.28.65.0 age confidence devDependencies minor
@typescript-eslint/utils (source) 8.57.28.65.0 age confidence dependencies minor
@vitest/coverage-v8 (source) ^4.1.2^4.1.10 age confidence devDependencies patch
@vitest/eslint-plugin ^1.6.13^1.6.24 age confidence devDependencies patch
actions/checkout v6v7 age confidence action major
actions/setup-node v6v7 age confidence action major
biome (source) ^2.4.9^2.5.6 age confidence devDependencies minor
effect (source) ^3.21.0^3.22.1 age confidence dependencies minor
eslint (source) ^10.1.0^10.8.0 age confidence devDependencies minor
eslint-doc-generator ^3.3.2^3.7.0 age confidence devDependencies minor
eslint-import-resolver-typescript ^4.4.4^4.4.5 age confidence devDependencies patch
eslint-plugin-eslint-plugin ^7.3.2^7.6.0 age confidence devDependencies minor
eslint-plugin-simple-import-sort ^12.1.1^14.0.0 age confidence devDependencies major
eslint-plugin-sonarjs (source) ^4.0.2^4.2.0 age confidence devDependencies minor
eslint-plugin-unicorn ^63.0.0^72.0.0 age confidence devDependencies major
globals ^17.4.0^17.8.0 age confidence devDependencies minor
jscpd (source) ^4.0.8^5.0.14 age confidence devDependencies major
node 24.14.124.18.1 age confidence uses-with minor
npm (source) ^11.12.1^12.0.2 age confidence devDependencies major
pnpm (source) 10.33.011.18.0 age confidence packageManager major
pnpm/action-setup v5v6 age confidence action major
ts-morph ^27.0.2^28.0.0 age confidence devDependencies major
typescript (source) >=4.8.4 <7.0.0>=4.8.4 <8.0.0 age confidence peerDependencies major
typescript (source) ^6.0.2^7.0.2 age confidence devDependencies major
typescript-eslint (source) ^8.57.2^8.65.0 age confidence devDependencies minor
vite (source) ^8.0.3^8.2.0 age confidence devDependencies minor
vitest (source) ^4.1.2^4.1.10 age confidence devDependencies patch

cc @skulidropek


Release Notes

biomejs/biome (@​biomejs/biome)

v2.5.6

Compare Source

Patch Changes
  • #​11035 0e4b03b Thanks @​ematipico! - Fixed a performance regression in noMisusedPromises that caused type inference to run repeatedly while linting a file.

  • #​11043 22ec076 Thanks @​denbezrukov! - Fixed CSS formatting for multiline function arguments preceded by comments:

     .example {
       value: outer(
         1,
         /* comment */
         nested(
    -      first,
    -      second
    -    )
    +        first,
    +        second
    +      )
       );
     }
  • #​11007 c9acb25 Thanks @​BTF-Kabir-2020! - Fixed #​9195: useHookAtTopLevel no longer reports hooks in named forwardRef components that receive a ref parameter.

  • #​10152 50a9bd8 Thanks @​Zelys-DFKH! - Fixed #​10131: Biome now correctly parses curried arrow functions in ternary consequents when the inner arrow's parameters use a destructuring pattern, e.g. cond ? (x) => ({ a, b }) => body : alt.

  • #​11105 8ffe2b9 Thanks @​dadavidtseng! - Fixed #​11092: The noUselessTernary quick fix now preserves operator spacing when simplifying or inverting boolean ternary expressions.

  • #​10533 5809875 Thanks @​Mokto! - Fixed #​10515: biome check --write was not idempotent on Svelte files — multi-line template literals in <script> blocks and block comments in <style> blocks gained an extra indent level on every run.

  • #​11040 0abb620 Thanks @​Mokto! - Fixed an issue where the HTML formatter would duplicate a comment placed directly before a Svelte {@&#8203;const ...} or {@&#8203;debug ...} block. The duplication compounded on every subsequent --write, causing the file to grow exponentially.

  • #​10858 6d18204 Thanks @​ruidosujeira! - Fixed #​10839: Svelte {#each} array destructuring no longer includes spaces inside square brackets, and multiline bind function expressions now indent their getter, setter, and function body correctly.

  • #​11009 2c36626 Thanks @​ematipico! - Improved the accuracy of type-aware lint rules by resolving more inferred types. For example, noFloatingPromises now detects floating Promises returned by aliased callbacks and arrays of Promises created by async mapping callbacks.

    The following statements are now reported:

    type AsyncCallback = () => Promise<void>;
    declare const callback: AsyncCallback;
    callback();
    
    [1, 2, 3].map(async (value) => value);
  • #​10973 9cb044c Thanks @​ematipico! - Fixed false positives in noMisleadingReturnType when generic-constraint, normalization, substitution, or structural return-type comparison cannot complete. The rule now suppresses diagnostics rather than suggesting a return type derived from partial information. For example, this unresolved return type is no longer reported:

    function unresolvedReturnType(): MissingType {
      return "value" as const;
    }
  • #​11071 15047a2 Thanks @​dyc3! - The HTML parser now accepts mixed-case doctype declarations.

  • #​11030 cc90e65 Thanks @​marschattha! - The rdjson reporter now populates the severity field of each diagnostic (ERROR, WARNING, or INFO), so tools consuming Reviewdog Diagnostic Format output no longer need to assume a default severity.

  • #​11009 2c36626 Thanks @​ematipico! - Fixed a performance regression in type-aware JavaScript lint rules by inferring only requested types and memoizing export resolution.

  • #​11056 903b177 Thanks @​dyc3! - Added support for Svelte declaration tags using let and const. Biome can now parse, format, and lint bindings declared in these tags.

  • #​11045 89c27c6 Thanks @​ematipico! - Improved the performance of Biome formatter up to ~7% across the board.

  • #​9806 781d68d Thanks @​dyc3! - Added the nursery rule noJsRestrictedProperties, which ports ESLint's no-restricted-properties rule. Biome now flags restricted member access and object destructuring, and biome migrate eslint preserves the rule's options.

v2.5.5

Compare Source

Patch Changes
  • #​10972 ab8c21b Thanks @​ematipico! - Fixed useExhaustiveSwitchCases for unions of bigint literals. The rule now reports missing bigint cases and compares bigint literals by value, including binary, octal, hexadecimal, and separator-containing spellings. For example, this switch now reports the missing 2n case:

    declare const value: 1n | 2n;
    switch (value) {
      case 1n:
        break;
    }
  • #​10972 ab8c21b Thanks @​ematipico! - Fixed false positives in noBaseToString and useNullishCoalescing when member, stringification, or nullish inference cannot complete. These rules now suppress diagnostics instead of reporting from partial type information. For example, neither expression is reported when a recursive type cannot be fully resolved:

    type Recursive = Recursive;
    declare const value: Recursive;
    
    String(value);
    value || "fallback";
  • #​10977 0bf7486 Thanks @​ematipico! - Fixed #​10922: the action useSortedAttributes no longer triggers for HTML instructions.

  • #​10957 cf263c4 Thanks @​dyc3! - Fixed noThenProperty failing to detect Object.fromEntries, Object.defineProperty, and Reflect.defineProperty calls with comments between their tokens.

  • #​10983 edc0ed7 Thanks @​ayaangazali! - Fixed #​10980: useAriaPropsSupportedByRole no longer reports false positives when the attribute that determines an element's implicit ARIA role is written as a shorthand attribute, such as <a {href} aria-label="..."> in Astro and Svelte files.

    Shorthand attributes are now taken into account when computing the implicit role, so the anchor above correctly resolves to the link role instead of generic.

  • #​10889 89526e3 Thanks @​denbezrukov! - Fixed CSS formatter casing for syntax-owned names while preserving author-defined names, including scoped keyframes and container scroll-state queries.

    - A:HOVER { COLOR: INITIAL; }
    + A:hover { color: initial; }
    - @&#8203;KEYFRAMES :GLOBAL KeepFrames { FROM { COLOR: RED; } }
    + @&#8203;keyframes :GLOBAL KeepFrames { from { color: RED; } }
    - @&#8203;CONTAINER scroll-state((SCROLLED: TOP) AND (STUCK)) { A:HOVER { COLOR: RED; } }
    + @&#8203;container scroll-state((SCROLLED: TOP) AND (STUCK)) { A:hover { color: RED; } }
  • #​10964 794ccd0 Thanks @​denbezrukov! - Fixed CSS formatting for comments between declaration values and !important.

    -a { color: /* before */ /* after */ red !important; }
    +a { color: /* before */ red /* after */ !important; }
  • #​10993 b7a9694 Thanks @​denbezrukov! - Fixed the CSS formatter to preserve comments on the correct side of selector combinators and before declaration blocks.

    -.before > /* comment */ .after {}
    +.before /* comment */ > .after {}

    It now also keeps selectors with escaped newlines in attribute values inline when they fit.

    -div
    -  span[foo="bar\
    +div span[foo="bar\
     value"] {}
  • #​10978 8ebafe1 Thanks @​ematipico! - Fixed #​10870: noUnresolvedImports no longer reports false positives such as import type { NextRequest } from "next/server".

  • #​10901 68c10e6 Thanks @​Socialpranker! - Fixed #​10622: the HTML/Vue parser no longer panics on the argument-less v-bind shorthand (:="props").

    This syntax is valid Vue and equivalent to v-bind="props", so the parser now accepts it (along with the longhand v-bind:="props") instead of crashing while building a diagnostic for a missing argument.

  • #​10936 7df46f5 Thanks @​ematipico! - Improved generic tuple inference for useIncludes. The rule now recognizes specialised tuple element types returned through generic aliases.

  • #​10941 f787725 Thanks @​siketyan! - Fixed #10855: Biome now supports parsing and formatting CSS custom media queries declared with @custom-media.

  • #​10969 72d309b Thanks @​ematipico! - Fixed an issue where Biome logs became too verbose, dumping information not relevant to user's operations.

  • e62f6b6 Thanks @​ematipico! - Fixed #​10963: Biome no longer panics when a type-aware rule such as noFloatingPromises checks a call to a function with multiple call signatures imported from another module.

  • #​10931 899c60d Thanks @​ematipico! - Fixed check --write command. Now the command reports code frame of the formatted code, if the formatter is enabled.

  • #​10904 ceee4f4 Thanks @​qzwxsaedc! - Fixed #​10892: noUnnecessaryConditions no longer reports a false positive when checking a member of a discriminated union that is accessed through a default type-only namespace import. The following code is no longer flagged:

    import type Types from "./types";
    
    declare function parse(): Types.Result<string>;
    const result = parse();
    if (!result.success) {
    }
  • #​10962 f0a67f2 Thanks @​ematipico! - Biome no longer removes embedded styles and scripts in HTML files.

  • #​11000 5039a1e Thanks @​ematipico! - Fixed a bug where closing one editor stopped a shared Biome daemon used by other editors. LSP proxy processes now exit when either the editor or daemon disconnects.

  • #​10957 cf263c4 Thanks @​dyc3! - Improved the performance of the noThenProperty lint rule by about 50%.

  • #​10992 4bf9b21 Thanks @​ematipico! - Fixed noMisusedPromises: The rule now reports Promise-returning callbacks where a synchronous callback is expected when calls use tuple spreads or tuple rest parameters, including generic and deeply nested tuples, and when constructor signatures come from interface or object types. Recursive or excessively nested tuple spreads use a conservative fallback so analysis terminates.

    For example, the following callback is now reported.

    declare function consume(...args: [number, () => void]): void;
    const prefix: [number] = [1];
    
    consume(...prefix, async () => {});
  • #​10915 b3b12b3 Thanks @​Functionhx! - Added the rule noNegationInEqualityCheck. The rule flags negated expressions on the left side of strict equality checks like !foo === bar — due to operator precedence this evaluates as (!foo) === bar which is almost always a mistake for foo !== bar.

    The rule provides an unsafe fix that flips the operator.

    // Invalid
    !foo === bar;
    !foo !== bar;
    
    // Valid
    foo !== bar;
    foo === bar;
  • #​10970 bd1038b Thanks @​ematipico! - Improved overload selection for noMisusedPromises. Biome now handles overloaded calls, overloaded constructors, rest parameters, union arguments, and generic constraints without selecting an incompatible signature. For example, noMisusedPromises now reports the async callback passed to the synchronous overload:

    declare function consume(kind: "async", callback: () => Promise<void>): void;
    declare function consume(kind: "sync", callback: () => void): void;
    consume("sync", async () => {});
  • #​10933 48a4abb Thanks @​ematipico! - Fixed useArrayFind to recognize bigint zero indexes.

  • #​10931 899c60d Thanks @​ematipico! - Fixed an orchestration issue that could lead to deadlocks when type-aware rules are enabled.

  • #​10969 72d309b Thanks @​ematipico! - Hardened the Biome Language Server by improving its synchronisation logic.

  • #​10972 ab8c21b Thanks @​ematipico! - Fixed false positives in noMisusedPromises and useAwaitThenable when Promise or thenable inference cannot complete. These rules now suppress diagnostics instead of treating incomplete type information as a definite result. For example, useAwaitThenable no longer reports await value when the value's thenability is unknown:

    declare const value: unknown;
    
    async function consume() {
      await value;
    }

v2.5.4

Compare Source

Patch Changes
  • #​10665 55ff995 Thanks @​dyc3! - Improved the performance of the HTML parser slightly in our synthetic benchmarks.

  • #​10894 f4fb10e Thanks @​ematipico! - Fixed #​6392: On-type formatting no longer moves comments before an if statement into its body.

  • #​10939 f2799db Thanks @​Netail! - Fixed #​10930: noLabelWithoutControl now correctly detects text interpolation in Astro, Svelte & Vue as valid accessible content.

  • #​10945 ae15d98 Thanks @​Netail! - Fixed #​10942: Svelte directives don't throw an accidental debug log anymore.

  • #​10842 5e1abfe Thanks @​JamBalaya56562! - Fixed #​9196: biome check --write --unsafe no longer hangs forever when applying the noCommentText code fix.

    The rule's fix now wraps the comment in a real JSX expression container ({/* comment */}) instead of re-inserting the braces as plain JSX text, so the fixed code is no longer reported again by the same rule.

  • #​10891 ecca79e Thanks @​ematipico! - Fixed #10885: prevented a module-inference regression introduced by a housekeeping change.

  • #​10886 60c8043 Thanks @​dyc3! - Fixed #​10727: Biome now breaks the arguments of curried test.each, it.each, describe.each, and test.for calls when they exceed the configured line width.

    - test.each([[1, 2]])("a description that is long enough to push the hugged opening line beyond the print width", (a, b) => {
    -   expect(a).toBe(b);
    - });
    + test.each([[1, 2]])(
    +   "a description that is long enough to push the hugged opening line beyond the print width",
    +   (a, b) => {
    +     expect(a).toBe(b);
    +   },
    + );
  • #​10895 01a85f0 Thanks @​ematipico! - Biome will now remove stale Unix daemon sockets from older Biome versions when starting a newer daemon.

v2.5.3

Compare Source

Patch Changes
  • #​10815 86613d5 Thanks @​WaterWhisperer! - Fixed a parser panic reported in #​10708: Biome now recovers when unsupported CSS Modules @value rules or scoped @keyframes names end at EOF.

  • #​10534 da9b403 Thanks @​Mokto! - Fixed noUnusedVariables false positives in Svelte files: Svelte store subscriptions ($store references in templates now keep the underlying store binding from being flagged), and $bindable() props that are only written to in the script block (write-only is intentional for bindable props) are no longer reported as unused.

  • #​10827 098ba41 Thanks @​Aqu1bp! - Fixed #​10698: The noUnsafeOptionalChaining rule now reports unsafe optional chains wrapped in TypeScript as, satisfies, type assertion, and instantiation expressions, such as new (value?.constructor as Constructor)().

  • #​10773 3c6513d Thanks @​otkrickey! - Fixed #​10772: useVueValidVOn no longer reports a missing handler for v-on directives using a verb modifier (.stop / .prevent) without an expression, e.g. <div @&#8203;click.stop></div>. The rule also accepts the arg-less object syntax <div v-on="$listeners"></div> instead of reporting a missing event name.

  • #​10721 d83c66b Thanks @​minseong0324! - Improved type-aware lint rule inference for built-in globals and indexed function calls. Biome now resolves Error(...), new Error(...), optional Error#stack, and calls through indexed function values such as handlers[0]() more accurately.

  • #​10865 6450276 Thanks @​ematipico! - Fixed #​10845. Biome Language Server no longer goes in deadlock when the scanner is enabled.

  • #​10853 93d8e53 Thanks @​Netail! - Fixed #​10840: Astro shorthand attribute syntax is now correctly being parsed from embedded nodes.

  • #​10820 bba3092 Thanks @​JamBalaya56562! - Fixed #​10619: noProcessEnv now also reports computed (bracket) member access. Previously only dot access was checked, so process["env"] and env["NODE_ENV"] (where env is imported from node:process) were missed. Both static and computed accesses are now reported.

  • #​10835 3447b2f Thanks @​dyc3! - Fixed #​10824: useDomQuerySelector now supports an ignore option for receiver identifiers that should not be reported.

  • #​10875 b12e486 Thanks @​dyc3! - Fixed #​10795: --profile-rules now reports timings for each plugin separately as plugin/<pluginName>, matching the naming used by plugin suppressions, instead of aggregating all plugins under a single plugin/plugin entry.

  • #​10877 d6bc447 Thanks @​ematipico! - Fixed biome-zed#164: Biome no longer inserts stray whitespace when format-on-type runs after closing delimiters such as ), ], and }.

  • #​10867 a21463e Thanks @​dyc3! - Fixed #​10864: Biome no longer crashes when checking or linting HTML files with unquoted attribute values such as <textarea rows=4></textarea>.

v2.5.2

Compare Source

Patch Changes
  • #​10595 f458028 Thanks @​pkallos! - Added the option ignoreBooleanCoercion to useNullishCoalescing. When enabled, Biome ignores || and ||= used inside a Boolean() call, where coalescing on falsy values is intentional.

  • #​10798 4a32b63 Thanks @​pkallos! - Added the option ignorePrimitives to useNullishCoalescing. When enabled, Biome ignores ||, ||=, and ternary expressions whose non-nullish operands are all primitives the option opts out of. Use true to ignore all primitives, or an object selecting string, number, boolean, or bigint.

  • #​10545 f3d4c00 Thanks @​Mokto! - Added the new nursery rule noSvelteUnnecessaryStateWrap, which reports unnecessary $state() wrapping of classes from svelte/reactivity that are already reactive.

    <script>
    import { SvelteMap } from "svelte/reactivi
    

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from skulidropek March 27, 2026 21:46
@renovate renovate Bot changed the title chore(deps): update dependency eslint-plugin-unicorn to v64 fix(deps): update all dependencies Mar 30, 2026
@renovate
renovate Bot force-pushed the renovate/all branch 9 times, most recently from e5e89f4 to 96d426f Compare April 7, 2026 16:34
@renovate
renovate Bot force-pushed the renovate/all branch 12 times, most recently from 651f6b4 to 573619b Compare April 13, 2026 17:43
@renovate
renovate Bot force-pushed the renovate/all branch 5 times, most recently from 4059187 to e18b80b Compare April 17, 2026 22:09
@renovate
renovate Bot force-pushed the renovate/all branch 15 times, most recently from ed8aaaf to 195b515 Compare May 11, 2026 18:02
@renovate
renovate Bot force-pushed the renovate/all branch 3 times, most recently from 0af92ca to 5784ad7 Compare May 14, 2026 12:27
@coderabbitai

coderabbitai Bot commented May 14, 2026

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Upgrade CI and workspace toolchain: pnpm/action-setup → v6, Node runtime bumped in dependency workflow, workspace packageManager → pnpm@11.1.2, and multiple runtime/dev dependency version bumps across app and template packages.

Changes

Dependency and Toolchain Upgrade

Layer / File(s) Summary
GitHub Actions versions
.github/actions/setup/action.yml, .github/workflows/checking-dependencies.yml
Updated pnpm/action-setup from @v5 to @v6 and bumped Node.js runtime to 24.15.0 in the dependency check workflow.
Workspace pnpm version alignment
package.json, packages/app/package.json
Updated packageManager from pnpm@10.33.0 to pnpm@11.1.2 across root and packages/app; root devDependencies also bumped.
Application package dependencies
packages/app/package.json
Bumped Effect ecosystem (@effect/*, effect) and numerous devDependencies (Biome, ESLint, @typescript-eslint, Vitest, Vite, tooling).
Template package dependencies
packages/eslint-template/package.json
Updated runtime (@effect/platform, @typescript-eslint/utils, effect) and broad devDependencies (Biome, Changesets, @typescript-eslint, Vitest, ESLint plugins, ts-morph, TypeScript, Vite).

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related issues

Poem

🐰 I hopped through package trees tonight,

nudged pnpm and actions to shine bright,
lint and tests got spruced and primed,
CI woke up on bumped Node time,
carrot-toast for every updated line.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies the pull request as a broad dependency update, which matches the main changes.
Description check ✅ Passed The description is directly related to the dependency, package manager, and GitHub Actions updates in the pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch renovate/all

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
package.json (1)

51-53: ⚠️ Potential issue | 🔴 Critical | ⚡ Quick win

Remove or update the patch version in patchedDependencies to match the installed version.

The patchedDependencies entry references @typescript-eslint/eslint-plugin@8.57.2, but the installed version is 8.59.3 (as shown in the lockfile and package.json). This version mismatch prevents the patch from being applied. Since 8.59.3 was released after the patch was created and the underlying optional chaining fix was already included in an earlier release, the patch is likely obsolete. Either update the key to @typescript-eslint/eslint-plugin@8.59.3 if the patch is still needed, or remove it if the issue is already resolved in 8.59.3.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@package.json` around lines 51 - 53, The patchedDependencies entry for
"@typescript-eslint/eslint-plugin@8.57.2" in package.json doesn't match the
installed version (8.59.3) so the patch won't apply; open package.json, locate
the "patchedDependencies" object and either (a) update the key to
"@typescript-eslint/eslint-plugin@8.59.3" if the patch is still required and
ensure the corresponding patch file exists, or (b) remove the
"@typescript-eslint/eslint-plugin@..." entry entirely if the upstream release
already contains the fix (preferred if the optional chaining issue is resolved).
♻️ Duplicate comments (1)
packages/app/package.json (1)

55-86: ⚠️ Potential issue | 🟠 Major

Same major version bumps as eslint-template package.

This package includes the same major version bumps flagged in packages/eslint-template/package.json:

  • ts-morph 27 → 28 (line 80)
  • eslint-plugin-simple-import-sort 12 → 13 (line 73)
  • eslint-plugin-unicorn 63 → 64 (line 76)

Please ensure the verification for those breaking changes applies to this package as well.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/app/package.json` around lines 55 - 86, The same major-version
upgrades flagged for the eslint-template package also affect this package:
update verification for the dependencies ts-morph,
eslint-plugin-simple-import-sort, and eslint-plugin-unicorn in packages/app by
running the identical compatibility checks you ran for eslint-template (exercise
unit tests, linting, build, and any dedicated migration/compat scripts) and
address any API or config changes uncovered; ensure package lock/lockfile is
updated and any fixes or code changes required for the ts-morph 27→28,
eslint-plugin-simple-import-sort 12→13, and eslint-plugin-unicorn 63→64 upgrades
are applied here as well.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@package.json`:
- Line 6: The package.json currently pins "packageManager": "pnpm@11.1.2" but
the repo must be migrated to pnpm v11 config changes: run the pnpm v10→v11
codemod to move settings from the "pnpm" field in package.json and any .npmrc
entries into a new pnpm-workspace.yaml (use camelCase keys), replace any
npm_config_* env usages with pnpm_config_*, stop using pnpm link --global (use
pnpm add -g), convert build-related settings (neverBuiltDependencies,
ignoreDepScripts, etc.) into the allowBuilds map, verify Node engine
compatibility (v18–v21 removed, ensure pure ESM readiness), and confirm global
install path expectations (pnpmHomeDir/global/v11/{hash}); update packageManager
value only after these migrations and verify CI/environment variables and
workspace config are correct.

In `@packages/eslint-template/package.json`:
- Line 33: The package.json now pins "eslint-plugin-simple-import-sort" to
^13.0.0 which enforces deterministic ordering when the same module is imported
multiple times with different styles; search the codebase for modules imported
more than once using different styles (namespace imports like import * as X,
default imports like import X, and named imports like import {a}) and
consolidate them into a single consistent import per source (e.g., combine
default and named into one line or convert namespace to named/default as
appropriate) so autofix no longer changes ordering unexpectedly; update any
files referencing the same source in multiple import statements (look for
occurrences of the module names flagged by the linter) to use a single unified
import form.

---

Outside diff comments:
In `@package.json`:
- Around line 51-53: The patchedDependencies entry for
"@typescript-eslint/eslint-plugin@8.57.2" in package.json doesn't match the
installed version (8.59.3) so the patch won't apply; open package.json, locate
the "patchedDependencies" object and either (a) update the key to
"@typescript-eslint/eslint-plugin@8.59.3" if the patch is still required and
ensure the corresponding patch file exists, or (b) remove the
"@typescript-eslint/eslint-plugin@..." entry entirely if the upstream release
already contains the fix (preferred if the optional chaining issue is resolved).

---

Duplicate comments:
In `@packages/app/package.json`:
- Around line 55-86: The same major-version upgrades flagged for the
eslint-template package also affect this package: update verification for the
dependencies ts-morph, eslint-plugin-simple-import-sort, and
eslint-plugin-unicorn in packages/app by running the identical compatibility
checks you ran for eslint-template (exercise unit tests, linting, build, and any
dedicated migration/compat scripts) and address any API or config changes
uncovered; ensure package lock/lockfile is updated and any fixes or code changes
required for the ts-morph 27→28, eslint-plugin-simple-import-sort 12→13, and
eslint-plugin-unicorn 63→64 upgrades are applied here as well.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: db3c2e88-f3f6-4ca6-8964-0ab35e5ab234

📥 Commits

Reviewing files that changed from the base of the PR and between e03feb6 and 5784ad7.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • .github/actions/setup/action.yml
  • .github/workflows/checking-dependencies.yml
  • package.json
  • packages/app/package.json
  • packages/eslint-template/package.json

Comment thread package.json Outdated
"private": true,
"description": "Monorepo workspace for effect-template",
"packageManager": "pnpm@10.33.0",
"packageManager": "pnpm@11.1.2",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | 🏗️ Heavy lift

🧩 Analysis chain

🌐 Web query:

What are the breaking changes in pnpm 11 compared to pnpm 10?

💡 Result:

The breaking changes in pnpm 11 compared to pnpm 10, as detailed in the official migration guide and release notes, are primarily around configuration handling, command behaviors, and removed features. Here's a complete list: Configuration changes [1][2][3]: - pnpm no longer reads settings from the pnpm field in package.json; move them to pnpm-workspace.yaml [1][2][3]. - .npmrc now only reads auth and registry settings; all other settings (e.g., hoist-pattern, node-linker, save-exact) must be moved to pnpm-workspace.yaml using camelCase keys [1][2][3]. - npm_config_* environment variables are no longer read; use pnpm_config_* instead [1][2][3]. - pnpm no longer reads npm's global config at $PREFIX/etc/npmrc [3]. - Package manager strictness settings (managePackageManagerVersions, packageManagerStrict, packageManagerStrictVersion) collapsed into pmOnFail: download | ignore | warn | error [1]. - allowNonAppliedPatches renamed to allowUnusedPatches; auditConfig.ignoreCves to auditConfig.ignoreGhsas (requires manual CVE to GHSA conversion) [1][2]. Command and behavior changes [1][2][3]: - pnpm link no longer resolves from global store; use relative/absolute paths (e.g., pnpm link ./foo). Removed --global flag (use pnpm add -g .) and pnpm link with no args [1][3]. - pnpm install -g (no args) unsupported; use pnpm add -g <pkg> [1]. - pnpm server command removed [1][2]. - Script names like clean, setup, deploy, rebuild now shadow built-in commands; use pnpm pm <command> to force built-ins [1]. - Removed npm CLI fallback: commands like access, bugs, docs, edit, home, issues, owner, ping, prefix, profile, pkg, search, set-script, team, token, unstar, whoami, xmas (and aliases) now throw errors; many reimplemented natively [2][3]. - Global installs (pnpm add -g) now use isolated directories in {pnpmHomeDir}/global/v11/{hash}/ to prevent interference [3]. - Globally installed binaries now in bin/ subdirectory of PNPM_HOME [3]. Removed/deprecated features [2][3]: - Deprecated build dependency settings removed: onlyBuiltDependencies, onlyBuiltDependenciesFile, neverBuiltDependencies, ignoredBuiltDependencies, ignoreDepScripts. Use allowBuilds map instead [2][3]. - Removed support for useNodeVersion, Env.nodeVersion, pnpmfile [2]. Other [1][2][3]: - Bumps packageManager in package.json to pnpm v11 version [1]. - Default changes: optimisticRepeatInstall: true, verifyDepsBeforeRun: install, minimumReleaseAge: 1440 (1 day), minimumReleaseAgeStrict: false [2]. - Drops Node.js 18-21 support; now pure ESM; standalone exe requires glibc 2.27+ [3]. A codemod is available to automate many config migrations [4]. pnpm prints a pointer to the migration guide on pnpm self-update from v10 [1].

Citations:


Review pnpm 11 migration guide and update configuration accordingly.

pnpm 11 introduces breaking changes requiring configuration updates:

  • Settings in the pnpm field in package.json and .npmrc must migrate to pnpm-workspace.yaml with camelCase keys
  • npm_config_* environment variables replaced with pnpm_config_*
  • pnpm link --global removed; use pnpm add -g <pkg> instead
  • Build dependency settings (neverBuiltDependencies, ignoreDepScripts, etc.) replaced with allowBuilds map
  • Node.js 18-21 support dropped; now pure ESM
  • Global installs now use isolated directories at {pnpmHomeDir}/global/v11/{hash}/

Use the pnpm codemod to automate most config migrations, then verify all settings are correctly moved to pnpm-workspace.yaml.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@package.json` at line 6, The package.json currently pins "packageManager":
"pnpm@11.1.2" but the repo must be migrated to pnpm v11 config changes: run the
pnpm v10→v11 codemod to move settings from the "pnpm" field in package.json and
any .npmrc entries into a new pnpm-workspace.yaml (use camelCase keys), replace
any npm_config_* env usages with pnpm_config_*, stop using pnpm link --global
(use pnpm add -g), convert build-related settings (neverBuiltDependencies,
ignoreDepScripts, etc.) into the allowBuilds map, verify Node engine
compatibility (v18–v21 removed, ensure pure ESM readiness), and confirm global
install path expectations (pnpmHomeDir/global/v11/{hash}); update packageManager
value only after these migrations and verify CI/environment variables and
workspace config are correct.

Comment thread packages/eslint-template/package.json Outdated
@renovate
renovate Bot force-pushed the renovate/all branch 4 times, most recently from 2a1dd99 to 845acb7 Compare May 16, 2026 05:28

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

♻️ Duplicate comments (1)
package.json (1)

6-6: ⚠️ Potential issue | 🟠 Major | 🏗️ Heavy lift

pnpm v11 bump needs config migration validation before merge.

Line 6 upgrades to pnpm@11.1.2, but this file still contains legacy pnpm config keys (Lines 42 and 46) that may no longer behave as intended under v11. Please validate and migrate config to the v11-supported shape before releasing.

#!/bin/bash
set -euo pipefail

echo "1) Locate workspace-level pnpm config files"
fd -HI '^pnpm-workspace\.yaml$' .
fd -HI '^\.npmrc$' .

echo
echo "2) Find deprecated/legacy pnpm keys and any new allowBuilds usage"
rg -n --hidden --glob '!.git' '"(ignoredBuiltDependencies|onlyBuiltDependencies|neverBuiltDependencies|ignoreDepScripts|allowBuilds)"'

echo
echo "3) Find packageManager pin and pnpm config blocks"
rg -n --hidden --glob '!.git' '"packageManager"\s*:|^\s*"pnpm"\s*:'

echo
echo "4) Check env var usage needing pnpm v11 migration"
rg -n --hidden --glob '!.git' '\bnpm_config_[A-Za-z0-9_]+\b|\bpnpm_config_[A-Za-z0-9_]+\b'

echo
echo "5) Check for removed global-link patterns"
rg -n --hidden --glob '!.git' 'pnpm\s+link(\s+--global|\s+-g|\s*$)'
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@package.json` at line 6, The packageManager bump to "pnpm@11.1.2" requires
validating and migrating legacy pnpm config keys (e.g.,
ignoredBuiltDependencies, onlyBuiltDependencies, neverBuiltDependencies,
ignoreDepScripts, allowBuilds) before merge; inspect and update workspace-level
pnpm config (pnpm-workspace.yaml) and project .npmrc entries to the
v11-supported shape, replace/deprecate old env var usages
(npm_config_*/pnpm_config_*), remove any deprecated global link patterns (pnpm
link --global/-g), and ensure the packageManager pin remains correct; run the
provided shell checks (search for pnpm-workspace.yaml, .npmrc, the legacy keys,
packageManager/pnpm blocks, and env var patterns) and apply migrations so the
repo config matches pnpm v11 expectations.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Duplicate comments:
In `@package.json`:
- Line 6: The packageManager bump to "pnpm@11.1.2" requires validating and
migrating legacy pnpm config keys (e.g., ignoredBuiltDependencies,
onlyBuiltDependencies, neverBuiltDependencies, ignoreDepScripts, allowBuilds)
before merge; inspect and update workspace-level pnpm config
(pnpm-workspace.yaml) and project .npmrc entries to the v11-supported shape,
replace/deprecate old env var usages (npm_config_*/pnpm_config_*), remove any
deprecated global link patterns (pnpm link --global/-g), and ensure the
packageManager pin remains correct; run the provided shell checks (search for
pnpm-workspace.yaml, .npmrc, the legacy keys, packageManager/pnpm blocks, and
env var patterns) and apply migrations so the repo config matches pnpm v11
expectations.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e766f135-c608-4b3a-b538-99c7494d15cb

📥 Commits

Reviewing files that changed from the base of the PR and between 2a1dd99 and 845acb7.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • .github/actions/setup/action.yml
  • .github/workflows/checking-dependencies.yml
  • package.json
  • packages/app/package.json
  • packages/eslint-template/package.json
✅ Files skipped from review due to trivial changes (3)
  • .github/workflows/checking-dependencies.yml
  • .github/actions/setup/action.yml
  • packages/eslint-template/package.json
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/app/package.json

@renovate
renovate Bot force-pushed the renovate/all branch 4 times, most recently from 980a33b to bed89b0 Compare May 20, 2026 05:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant