chore(deps): update all dependencies - #523
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
Contributor
Author
|
renovate
Bot
force-pushed
the
renovate/all
branch
5 times, most recently
from
August 5, 2026 18:12
eba9297 to
12c7a42
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
August 6, 2026 02:48
12c7a42 to
98451b1
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.70.0→0.70.12.5.4→2.5.62.5.72.5.4→2.5.62.5.7^22.20.0→^26.0.0^22.20.0→^26.0.0^22.20.1→^26.0.0^3.1.4→^4.0.04.1.2^29.1.1→^30.0.0^0.55.1→^0.56.026.5.0→26.7.026.2.0→26.7.011.17.0+sha512.cca3cea332ad254bb84145f966d19f4879615210346fc92c79a047f23a0d7b3cca3c3792f0076ba1f1831d277efbcf0a9119b31a9a60eca7fb3d6231f331ef72→11.18.011.20.0(+1)v6.0.9→v6.0.10^3.0.2→^4.0.019.2.7→19.2.819.2.7→19.2.80.35.0→0.35.3^6.0.3→^7.0.0Release Notes
Azure/typespec-azure (@azure-tools/typespec-autorest)
v0.70.1Bug Fixes
service.yamlversions when updating an existing manifest. Versions the emitter no longer produces are now kept when they are not TypeSpec-generated (for example legacy swagger-only versions migrated fromreadme.md), while stalesource: typespecversions the emitter no longer produces are still removed. This makes re-running the emitter idempotent for manifests that carry historical versions.biomejs/biome (@biomejs/biome)
v2.5.6Compare Source
Patch Changes
#11035
0e4b03bThanks @ematipico! - Fixed a performance regression innoMisusedPromisesthat caused type inference to run repeatedly while linting a file.#11043
22ec076Thanks @denbezrukov! - Fixed CSS formatting for multiline function arguments preceded by comments:.example { value: outer( 1, /* comment */ nested( - first, - second - ) + first, + second + ) ); }#11007
c9acb25Thanks @BTF-Kabir-2020! - Fixed #9195:useHookAtTopLevelno longer reports hooks in namedforwardRefcomponents that receive arefparameter.#10152
50a9bd8Thanks @Zelys-DFKH! - Fixed #10131: Biome now correctly parses curried arrow functions in ternary consequents when the inner arrow's parameters use a destructuring pattern, e.g.cond ? (x) => ({ a, b }) => body : alt.#11105
8ffe2b9Thanks @dadavidtseng! - Fixed #11092: ThenoUselessTernaryquick fix now preserves operator spacing when simplifying or inverting boolean ternary expressions.#10533
5809875Thanks @Mokto! - Fixed #10515:biome check --writewas not idempotent on Svelte files — multi-line template literals in<script>blocks and block comments in<style>blocks gained an extra indent level on every run.#11040
0abb620Thanks @Mokto! - Fixed an issue where the HTML formatter would duplicate a comment placed directly before a Svelte{@const ...}or{@debug ...}block. The duplication compounded on every subsequent--write, causing the file to grow exponentially.#10858
6d18204Thanks @ruidosujeira! - Fixed #10839: Svelte{#each}array destructuring no longer includes spaces inside square brackets, and multiline bind function expressions now indent their getter, setter, and function body correctly.#11009
2c36626Thanks @ematipico! - Improved the accuracy of type-aware lint rules by resolving more inferred types. For example,noFloatingPromisesnow detects floating Promises returned by aliased callbacks and arrays of Promises created by async mapping callbacks.The following statements are now reported:
#10973
9cb044cThanks @ematipico! - Fixed false positives innoMisleadingReturnTypewhen generic-constraint, normalization, substitution, or structural return-type comparison cannot complete. The rule now suppresses diagnostics rather than suggesting a return type derived from partial information. For example, this unresolved return type is no longer reported:#11071
15047a2Thanks @dyc3! - The HTML parser now accepts mixed-casedoctypedeclarations.#11030
cc90e65Thanks @marschattha! - Therdjsonreporter now populates the severity field of each diagnostic (ERROR,WARNING, orINFO), so tools consuming Reviewdog Diagnostic Format output no longer need to assume a default severity.#11009
2c36626Thanks @ematipico! - Fixed a performance regression in type-aware JavaScript lint rules by inferring only requested types and memoizing export resolution.#11056
903b177Thanks @dyc3! - Added support for Svelte declaration tags usingletandconst. Biome can now parse, format, and lint bindings declared in these tags.#11045
89c27c6Thanks @ematipico! - Improved the performance of Biome formatter up to ~7% across the board.#9806
781d68dThanks @dyc3! - Added the nursery rulenoJsRestrictedProperties, which ports ESLint'sno-restricted-propertiesrule. Biome now flags restricted member access and object destructuring, andbiome migrate eslintpreserves the rule's options.v2.5.5Compare Source
Patch Changes
#10972
ab8c21bThanks @ematipico! - FixeduseExhaustiveSwitchCasesfor unions of bigint literals. The rule now reports missing bigint cases and compares bigint literals by value, including binary, octal, hexadecimal, and separator-containing spellings. For example, this switch now reports the missing2ncase:#10972
ab8c21bThanks @ematipico! - Fixed false positives innoBaseToStringanduseNullishCoalescingwhen member, stringification, or nullish inference cannot complete. These rules now suppress diagnostics instead of reporting from partial type information. For example, neither expression is reported when a recursive type cannot be fully resolved:#10977
0bf7486Thanks @ematipico! - Fixed #10922: the actionuseSortedAttributesno longer triggers for HTML instructions.#10957
cf263c4Thanks @dyc3! - FixednoThenPropertyfailing to detectObject.fromEntries,Object.defineProperty, andReflect.definePropertycalls with comments between their tokens.#10983
edc0ed7Thanks @ayaangazali! - Fixed #10980:useAriaPropsSupportedByRoleno longer reports false positives when the attribute that determines an element's implicit ARIA role is written as a shorthand attribute, such as<a {href} aria-label="...">in Astro and Svelte files.Shorthand attributes are now taken into account when computing the implicit role, so the anchor above correctly resolves to the
linkrole instead ofgeneric.#10889
89526e3Thanks @denbezrukov! - Fixed CSS formatter casing for syntax-owned names while preserving author-defined names, including scoped keyframes and container scroll-state queries.#10964
794ccd0Thanks @denbezrukov! - Fixed CSS formatting for comments between declaration values and!important.#10993
b7a9694Thanks @denbezrukov! - Fixed the CSS formatter to preserve comments on the correct side of selector combinators and before declaration blocks.It now also keeps selectors with escaped newlines in attribute values inline when they fit.
#10978
8ebafe1Thanks @ematipico! - Fixed #10870:noUnresolvedImportsno longer reports false positives such asimport type { NextRequest } from "next/server".#10901
68c10e6Thanks @Socialpranker! - Fixed #10622: the HTML/Vue parser no longer panics on the argument-lessv-bindshorthand (:="props").This syntax is valid Vue and equivalent to
v-bind="props", so the parser now accepts it (along with the longhandv-bind:="props") instead of crashing while building a diagnostic for a missing argument.#10936
7df46f5Thanks @ematipico! - Improved generic tuple inference foruseIncludes. The rule now recognizes specialised tuple element types returned through generic aliases.#10941
f787725Thanks @siketyan! - Fixed#10855: Biome now supports parsing and formatting CSS custom media queries declared with@custom-media.#10969
72d309bThanks @ematipico! - Fixed an issue where Biome logs became too verbose, dumping information not relevant to user's operations.e62f6b6Thanks @ematipico! - Fixed #10963: Biome no longer panics when a type-aware rule such asnoFloatingPromiseschecks a call to a function with multiple call signatures imported from another module.#10931
899c60dThanks @ematipico! - Fixedcheck --writecommand. Now the command reports code frame of the formatted code, if the formatter is enabled.#10904
ceee4f4Thanks @qzwxsaedc! - Fixed #10892:noUnnecessaryConditionsno longer reports a false positive when checking a member of a discriminated union that is accessed through a default type-only namespace import. The following code is no longer flagged:#10962
f0a67f2Thanks @ematipico! - Biome no longer removes embedded styles and scripts in HTML files.#11000
5039a1eThanks @ematipico! - Fixed a bug where closing one editor stopped a shared Biome daemon used by other editors. LSP proxy processes now exit when either the editor or daemon disconnects.#10957
cf263c4Thanks @dyc3! - Improved the performance of thenoThenPropertylint rule by about 50%.#10992
4bf9b21Thanks @ematipico! - FixednoMisusedPromises: The rule now reports Promise-returning callbacks where a synchronous callback is expected when calls use tuple spreads or tuple rest parameters, including generic and deeply nested tuples, and when constructor signatures come from interface or object types. Recursive or excessively nested tuple spreads use a conservative fallback so analysis terminates.For example, the following callback is now reported.
#10915
b3b12b3Thanks @Functionhx! - Added the rulenoNegationInEqualityCheck. The rule flags negated expressions on the left side of strict equality checks like!foo === bar— due to operator precedence this evaluates as(!foo) === barwhich is almost always a mistake forfoo !== bar.The rule provides an unsafe fix that flips the operator.
#10970
bd1038bThanks @ematipico! - Improved overload selection fornoMisusedPromises. Biome now handles overloaded calls, overloaded constructors, rest parameters, union arguments, and generic constraints without selecting an incompatible signature. For example,noMisusedPromisesnow reports the async callback passed to the synchronous overload:#10933
48a4abbThanks @ematipico! - FixeduseArrayFindto recognize bigint zero indexes.#10931
899c60dThanks @ematipico! - Fixed an orchestration issue that could lead to deadlocks when type-aware rules are enabled.#10969
72d309bThanks @ematipico! - Hardened the Biome Language Server by improving its synchronisation logic.#10972
ab8c21bThanks @ematipico! - Fixed false positives innoMisusedPromisesanduseAwaitThenablewhen Promise or thenable inference cannot complete. These rules now suppress diagnostics instead of treating incomplete type information as a definite result. For example,useAwaitThenableno longer reportsawait valuewhen the value's thenability is unknown:biomejs/biome (@biomejs/wasm-nodejs)
v2.5.6Compare Source
v2.5.5Compare Source
fastify/fast-uri (fast-uri@^3)
v4.1.1Compare Source
Fix for GHSA-v2hh-gcrm-f6hx
Full Changelog: fastify/fast-uri@v4.1.0...v4.1.1
v4.1.0Compare Source
v4.0.1Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fast-uri@v4.0.0...v4.0.1
v4.0.0Compare Source
What's Changed
Full Changelog: fastify/fast-uri@v3.1.2...v4.0.0
jsdom/jsdom (jsdom)
v30.0.1Compare Source
v30.0.0Compare Source
microsoft/monaco-editor (monaco-editor)
v0.56.0Compare Source
Breaking Changes
monaco-editorentry point continues to load all features and languages. Custom bundles can now importmonaco-editor/editorand opt into:monaco-editor/features/register.all, or individual features withmonaco-editor/features/<feature>/register;monaco-editor/languages/definitions/register.all, or individual definitions withmonaco-editor/languages/definitions/<language>/register;monaco-editor/languages/features/register.all, or their individualregisterentry points.IOverlayWidgetPosition.stackOridinalproperty tostackOrdinal.IMirrorModelandIWorkerContextworker API types.New Features and APIs
editor.doubleClickSelectsBlock.editor.find.closeOnResultandeditor.inlayHints.showLongLineWarning.offWhenInlineCompletionstoQuickSuggestionsValue.ICodeEditor.revealAllCursors,ICodeEditor.getWidthOfLine, andICodeEditor.renderAsync.advanced-externalandadvanced-wasmdiff algorithms.Fixes
0.56.0-dev-20260625.nodejs/node (node)
v26.7.0: 2026-08-05, Version 26.7.0 (Current), @aduh95Compare Source
Notable Changes
58717685a1] - (SEMVER-MINOR) crypto: support loading private keys through STORE loaders (Filip Skokan) #6394944b940ee8c] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746c1e4f7365e] - (SEMVER-MINOR) lib: add perfetto support (Chengzhong Wu) #6456511c2f9c642] - (SEMVER-MINOR) module: implementSymbol.disposeinModuleHooks(Remco Haszing) #63928a646319f61] - (SEMVER-MINOR) test_runner: add support for--test-coverage-include-all(avivkeller) #64830Commits
a2d3f891d3] - async_hooks: use validateBoolean for trackPromises (Soul Lee) #64731d7266cdd99] - benchmark: fix calibrate-n option handling (Luan Muniz) #641462e64293e3f] - buffer: use Clamp conversion in Blob slice (Donghoon Kang) #647395fda0958bd] - buffer: validate copyArrayBuffer offsets against buffer length (Ilia Alshanetsky) #639045298db40f9] - build: run perfetto build and test on GHA (Chengzhong Wu) #64721e3eac7cef9] - build: fix v8_use_perfetto source scraping (Chengzhong Wu) #64721ab5f076d7f] - build: bump rustc requirement to >=1.86 (Renegade334) #64543df608e061f] - (SEMVER-MINOR) build: perfetto-sdk (Chengzhong Wu) #6456574928adc46] - build,tools: fix shared library cross-compile (Kirill Saied) #6396358717685a1] - (SEMVER-MINOR) crypto: support loading private keys through STORE loaders (Filip Skokan) #6394958d13b6f3d] - crypto: preserve OpenSSL errors from KDF failures (Filip Skokan) #64776478a719cb5] - crypto: fix Argon2 bypassing FIPS mode (Filip Skokan) #6477644b940ee8c] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746fde85237c7] - crypto: clarify missing cipher error (Filip Skokan) #64852c604d8846d] - crypto: reuse X509 issuer result (Filip Skokan) #64852c68c7d0112] - crypto: validate key generation options (Filip Skokan) #64852c36bb1d017] - crypto: fix Argon2 validation errors (Filip Skokan) #64852f61408bb27] - crypto: handle XOF output allocation failure (Filip Skokan) #648512b4053d046] - crypto: initialize KeyObjectData mutex eagerly (Filip Skokan) #648514b7b2adf44] - crypto: handle DH operation failures (Filip Skokan) #6485112170c3753] - crypto: use user-facing error for output encoding changes (Archkon) #64692474f06d550] - debugger: preserve overlapping CDP request state (Trivikram Kamat) #64467718cbe9497] - deps: upgrade npm to 11.19.0 (npm team) #64883657c6154b3] - deps: update ngtcp2 to 1.25.0 (Node.js GitHub Bot) #6494475a1fbeff9] - deps: update nghttp3 to 1.18.0 (Node.js GitHub Bot) #6494307d7cb7cd8] - deps: update minimatch to 10.2.6 (Node.js GitHub Bot) #64945f7d56359f1] - deps: update simdjson to 4.6.6 (Node.js GitHub Bot) #649428b06457cfb] - deps: update acorn to 8.18.0 (Node.js GitHub Bot) #649415919d01525] - deps: update googletest to1b6f64d(Node.js GitHub Bot) #649404a87ad6cff] - deps: update nghttp2 to 1.70.0 (Node.js GitHub Bot) #64939c96d76a7c8] - deps: update zlib to 1.3.2.1-motley-42c2f19 (Node.js GitHub Bot) #647442b59984c0f] - deps: V8: backport5177b10(avivkeller) #64631b839af91da] - deps: update ada to 4.0.0 (Node.js GitHub Bot) #6479070dedef942] - deps: update sqlite to 3.53.4 (Node.js GitHub Bot) #647457bc4c171f5] - deps: update Rust crates for V8 14.6.202.34-node.26 (Renegade334) #64543308c6b2ac3] - deps: V8: backport7d9b7e0(Manish Goregaokar) #645438eeae28e88] - deps: V8: backportc4d06ba(liujiahui) #63731bbd6fc58c4] - diagnostics_channel: grow native channel storage (Stephen Belanger) #64497ce8b292955] - doc: fix grammar and punctuation in dgram documentation (Kamal Rawal) #649571a413a60cf] - doc: fix grammar and editorial issues in addons documentation (Kamal Rawal) #6495263fbd59e64] - doc: formalize fn/name as part of TestOptions API (Christopher Hiller) #64946b263b0bca1] - doc: remove references toca/crlas per-context QuicSession options (René) #64769f37de14b27] - doc: fix typo in maintaining-dependencies.md (greenhead) #6489616cb77cdc8] - doc: add RafaelGSS as last security release stewards (Rafael Gonzaga) #64843335c28cd17] - doc: fix typos in documentation (greenhead) #64900d4bed8ca39] - doc: fix missing references in doc type map (Tim Perry) #64872e71d09d5f1] - doc: improve TestContext hook descriptions (Kamal Rawal) #648997089bd9ae4] - doc: add missing float32/float64 FFI type names (Soul Lee) #648748d3ae0830e] - doc: document stream.isDestroyed() (YspritanHyzygy) #64789a757e62af7] - doc: add contributing detail for git Signed-off-by trailer (Mike McCready) #648623e840f43ed] - doc: mark config-file as release candidate (Marco Ippolito) #6451670cd5df810] - doc: fix duplicated word in test snapshot docs (Kamal Rawal) #64837d5f36c7adc] - doc: remove obsolete cctest node.gyp instructions (Soul Lee) #64814a0bf29ea09] - doc: report proper return type on url.format (Brian Muenzenmeyer) #64806e655e42085] - doc: use ffi.suffix for library paths in examples (Junsoo Ha) #64805e0f0830dbc] - doc: document --permission-audit audit mode behavior (Adrián Estrada) #64791efbede6de0] - doc: clarify tlsSocket.authorized on resumption (soreavis) #64584db95655c4a] - doc: stabilize --disable-warning (Jean Michelet) #64742a8367200be] - doc: add MDN links for explicit resource management in fs (lluisemper) #595571c09165c2e] - doc: mention constructor check in deepStrictEqual (Sumit Kumar Das) #6201029709324e0] - doc: update technical priorities (Jacob Smith) #64505522a28e648] - doc: deprecation add more codemod (Augustin Mauroy) #63175c40aaa6539] - doc: run license-builder (Node.js GitHub Bot) #63918428e9bc50f] - ffi: fix crash in refCallback and unrefCallback (TrivikramConfiguration
📅 Schedule: (UTC)
* 0-3 1 * *)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.