Skip to content

Update frontend dependencies (dev) - #427

Open
renovate[bot] wants to merge 1 commit into
devfrom
renovate/dev-frontend-dependencies
Open

Update frontend dependencies (dev)#427
renovate[bot] wants to merge 1 commit into
devfrom
renovate/dev-frontend-dependencies

Conversation

@renovate

@renovate renovate Bot commented Jul 8, 2026

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
@biomejs/biome (source) 2.5.02.5.12 age confidence devDependencies patch 2.5.13
@eslint/compat (source) ^1.4.11.4.1 age confidence devDependencies pin
@eslint/eslintrc ^3.3.53.3.5 age confidence devDependencies pin
@eslint/js (source) ^9.39.49.39.4 age confidence devDependencies pin
@floating-ui/react (source) 0.27.190.27.20 age confidence dependencies patch
@inlang/paraglide-js (source) 2.20.12.25.0 age confidence devDependencies minor 2.25.1
@inlang/paraglide-js (source) 2.20.12.25.0 age confidence dependencies minor 2.25.1
@playwright/test (source) 1.61.01.62.1 age confidence dependencies minor 1.63.0
@prettier/plugin-oxc (source) ^0.0.40.0.4 age confidence devDependencies pin
@tanstack/devtools-vite (source) ^0.8.00.8.0 age confidence devDependencies pin
@tanstack/react-devtools (source) ^0.10.70.10.7 age confidence devDependencies pin
@tanstack/react-form (source) 1.33.01.33.5 age confidence dependencies patch
@tanstack/react-query (source) 5.101.05.102.8 age confidence dependencies minor
@tanstack/react-query-devtools (source) ^5.101.05.101.0 age confidence devDependencies pin
@tanstack/react-router (source) 1.170.161.170.32 age confidence dependencies patch 1.170.35 (+2)
@tanstack/react-router-devtools (source) ^1.167.01.167.0 age confidence devDependencies pin
@tanstack/react-virtual (source) 3.14.33.14.10 age confidence dependencies patch 3.14.11
@tanstack/router-plugin (source) ^1.168.181.168.18 age confidence devDependencies pin
@testing-library/jest-dom ^6.9.16.9.1 age confidence devDependencies pin
@testing-library/react ^16.3.216.3.2 age confidence devDependencies pin
@testing-library/user-event ^14.6.114.6.1 age confidence devDependencies pin
@types/byte-size (source) ^8.1.28.1.2 age confidence devDependencies pin
@types/humanize-duration (source) ^3.27.43.27.4 age confidence devDependencies pin
@types/lodash (source) 4.17.244.17.25 age confidence dependencies patch
@types/lodash-es (source) ^4.17.124.17.12 age confidence devDependencies pin
@types/node (source) ^26.0.026.0.0 age confidence devDependencies pin
@types/node (source) ^22.19.2122.19.21 age confidence devDependencies pin
@types/pg (source) 8.20.08.23.1 age confidence dependencies minor
@types/qs (source) ^6.15.16.15.1 age confidence devDependencies pin
@types/react (source) ^19.2.1719.2.17 age confidence devDependencies pin
@types/react-dom (source) ^19.2.319.2.3 age confidence devDependencies pin
@​types/totp-generator ^0.0.80.0.8 age confidence devDependencies pin
@typescript-eslint/eslint-plugin (source) ^8.61.08.61.0 age confidence devDependencies pin
@typescript-eslint/parser (source) ^8.61.08.61.0 age confidence devDependencies pin
@vitejs/plugin-react (source) ^6.0.26.0.2 age confidence devDependencies pin
@vitest/ui (source) 4.1.94.1.11 age confidence devDependencies patch
autoprefixer ^10.5.010.5.0 age confidence devDependencies pin
axios (source) 1.18.01.20.0 age confidence dependencies minor
dayjs (source) 1.11.211.11.23 age confidence dependencies patch
eslint (source) ^9.39.49.39.4 age confidence devDependencies pin
eslint-config-prettier ^10.1.810.1.8 age confidence devDependencies pin
eslint-plugin-import ^2.32.02.32.0 age confidence devDependencies pin
eslint-plugin-prettier ^5.5.65.5.6 age confidence devDependencies pin
eslint-plugin-simple-import-sort ^12.1.112.1.1 age confidence devDependencies pin
globals ^17.6.017.6.0 age confidence devDependencies pin
humanize-duration 3.33.23.34.1 age confidence dependencies minor
ipaddr.js 2.4.02.5.0 age confidence dependencies minor
isbot (source) 5.1.425.2.2 age confidence pnpm-workspace.overrides minor
jsdom ^29.1.129.1.1 age confidence devDependencies pin
motion 12.40.012.43.0 age confidence dependencies minor
pg (source) 8.21.08.23.0 age confidence dependencies minor
playwright (source) 1.61.01.62.1 age confidence dependencies minor 1.63.0
prettier (source) ^3.8.43.8.4 age confidence devDependencies pin
react (source) 19.2.719.2.8 age confidence dependencies patch 19.3.0
react-dom (source) 19.2.719.2.8 age confidence dependencies patch 19.3.0
react-intersection-observer 10.0.310.1.0 age confidence dependencies minor
recharts 3.8.13.10.1 age confidence dependencies minor
sass ^1.101.01.101.0 age confidence devDependencies pin
stylelint (source) ^17.13.017.13.0 age confidence devDependencies pin
stylelint-config-standard-scss ^17.0.017.0.0 age confidence devDependencies pin
stylelint-scss ^7.2.07.2.0 age confidence devDependencies pin
typescript (source) ~6.0.36.0.3 age confidence devDependencies pin
vite (source) ^8.0.168.0.16 age confidence devDependencies pin
vite-plugin-image-optimizer ^2.0.32.0.3 age confidence devDependencies pin
zod (source) 4.4.34.5.4 age confidence dependencies minor 4.6.2 (+2)
zustand 5.0.145.0.15 age confidence dependencies patch

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

⚠️ Renovate's pin functionality does not currently wire in the release age for a package, so the Minimum Release Age checks can apply. You will need to manually validate the Minimum Release Age for these package(s).


Release Notes

biomejs/biome (@​biomejs/biome)

v2.5.12

Compare Source

Patch Changes
  • #​11440 b88f1ea Thanks @​Princesseuh! - Fixed Astro attribute expressions rejecting TypeScript and JSX syntax that is accepted in text expressions.

    <Component icon={<Icon />} count={total as number} onSelect={(e: Event) => e} />
  • #​11440 b88f1ea Thanks @​Princesseuh! - Fixed Astro attribute names being split on : and . inside an expression, such as {x && <button x-on:keyup.enter={go} client:load.foo />}.

  • #​11440 b88f1ea Thanks @​Princesseuh! - Fixed a bare > in the children of an Astro expression being treated as markup, such as {x && <div>a > b</div>}.

  • #​11440 b88f1ea Thanks @​Princesseuh! - Fixed HTML comments inside an Astro expression failing to parse. They are now read as trivia, wherever they appear among the children.

    {x && <div><!-- first -->text<!-- last --></div>}
    {cond && <a></a><!-- c --><b></b>}
  • #​11440 b88f1ea Thanks @​Princesseuh! - Fixed is:raw children inside an Astro expression being read as JSX, such as {x && <div is:raw>{not js} < & text</div>}.

  • #​11440 b88f1ea Thanks @​Princesseuh! - Fixed an apostrophe or quote in the text of a JSX element inside an Astro expression ending the expression early, such as {items.map((i) => <li>it's {i}</li>)}.

  • #​11440 b88f1ea Thanks @​Princesseuh! - Fixed the children of a <script> or <style> inside an Astro expression being read as JSX. Their contents are text, so braces and comparisons no longer have to be escaped.

    {cond && <style>a { color: red }</style>}
    {cond && <script>let x = {a: 1};</script>}
  • #​11440 b88f1ea Thanks @​Princesseuh! - Added support for template literal attribute values inside an Astro expression, such as {x && <C data-x=`t${x}` />}.

  • #​11440 b88f1ea Thanks @​Princesseuh! - Fixed unquoted attribute values being rejected inside an Astro expression, such as {x && <a class=foo maxlength=255 href=/about>go</a>}.

  • #​11440 b88f1ea Thanks @​Princesseuh! - Fixed a template literal nested inside ${} breaking the rest of an Astro file, such as const href = `/blog${page === 0 ? '' : `/${page + 1}`}`;.

  • #​11440 b88f1ea Thanks @​Princesseuh! - Fixed a quote inside a regex character class breaking the rest of an Astro file, such as const unsafe = /[/"]/;.

  • #​11508 54f3a2e Thanks @​dyc3! - Added the nursery rule useFlatMathMinMax. Because Math.min() and Math.max() accept any number of arguments, the rule reports unnecessary nested calls to the same method:

    Math.max(Math.max(a, b), c);

    The fix flattens this expression to Math.max(a, b, c).

  • #​11585 c5c8315 Thanks @​Netail! - Fixed #​11475: noUnresolvedImports no longer reports Bun runtime built-in modules (bun, bun:bundle, bun:ffi, bun:jsc, bun:sqlite, bun:test).

  • #​11368 52a57b3 Thanks @​Austin1serb! - Fixed #​6830: Biome now reports a diagnostic for excessively deep syntax instead of overflowing the native stack while releasing the parsed tree.

  • #​11596 1fc42ed Thanks @​dyc3! - Added the nursery rule noThisOutsideOfClass. The rule reports this outside class members and TypeScript functions with an explicit this parameter.

    function Person(name) {
        this.name = name;
    }
  • #​11555 2516335 Thanks @​dyc3! - Fixed #​11529, where noFloatingPromises missed unhandled Promise chains when the imported function's module belonged to an import cycle. Cyclic modules now preserve types for exports that do not participate in recursive type dependencies.

  • #​11518 0fee70c Thanks @​HarperZ9! - Fixed #​11500: the formatter now prints the declare modifier before accessibility modifiers on class properties. private declare readonly name: string is now formatted as declare private readonly name: string, matching Prettier and TypeScript's canonical modifier order.

  • #​11580 1277af2 Thanks @​ematipico! - Fixed #​5091: Biome no longer moves comments next to the < of a generic, which causes invalid TypeScript syntax:

    - Generic<// a comment
    + Generic<
    +   // a comment
  • #​11577 42995d2 Thanks @​ematipico! - Fixed #​4592. Biome no longer crashes while parsing malformed delete expressions.

  • #​11590 67963b4 Thanks @​ematipico! - Fixed #​6427 so Grit plugins can use function = ... as a node argument.

  • #​11600 a689cb5 Thanks @​ematipico! - Fixed #​6644: noUnusedVariables now recognizes all interface declarations in a TypeScript declaration-merging group when the interface is referenced.

    The following snippet no longer triggers the rule.

    interface Things {
        foo: string;
    }
    
    interface Things {
        bar: string;
    }
    
    export type Key = keyof Things;
    
    interface Things {
        baz: string;
    }
  • #​11591 d4a0716 Thanks @​ematipico! - Fixed #​6615. noDuplicateProperties no longer reports declarations nested in block at-rules as duplicates of declarations in their parent block.

  • #​11492 f2a07aa Thanks @​santichausis! - Fixed #​11454: noMisplacedAssertion now recognises @fast-check/vitest's test.prop(...) (and .concurrent.prop, .skip.prop, etc.) as a test function, the same way it already recognises test.each. The JS formatter picks up the same recognition, so a curried test.prop(...)(...) call is now formatted with the regular breakable argument layout used for test.each/test.for, instead of the single-line-hugging layout used for plain it/test calls.

    For example, Biome no longer reports the assertion below as misplaced:

    import { fc, test } from "@fast-check/vitest";
    
    test.prop([fc.string()])("round-trips", (s) => {
      expect(s).toBe(s);
    });
  • #​11589 65742b3 Thanks @​ematipico! - Fixed #​4928: noUnusedVariables no longer reports a value declaration as unused when its merged namespace is referenced.

  • #​11559 472dbc2 Thanks @​levrik! - Fixed a false positive in noVueDuplicateKeys where a <script setup> variable initialized from props was reported as a duplicate of the prop it derives from. Biome now exempts any variable whose initializer references props, instead of only recognizing defineProps() and toRefs(props).

    For example, Biome no longer reports foo below as a duplicate key:

    <script setup>
    import { toRef } from 'vue';
    const props = defineProps(['foo']);
    const foo = toRef(props, 'foo');
    </script>
  • #​11594 6586ceb Thanks @​ematipico! - Fixed #​6640. Biome no longer crashes when linting malformed for...of statements.

  • #​11571 85b197d Thanks @​ematipico! - Fixed #​10838: useSortedAttributes no longer corrupts JSX attributes when nested JSX elements also require sorting.

  • #​11533 97e76c0 Thanks @​ematipico! - Fixed #​11520, where the Biome scanner would start analysing dependencies multiple times, leading to long and unresponsive sessions.

  • #​11564 18a0e1f Thanks @​Netail! - Fixed the diagnostic range of noInferrableTypes so it now highlights only the type instead of including the leading : colon, spaces and comments.

  • #​11540 124fdaa Thanks @​ematipico! - Fixed #11537: noShorthandPropertyOverrides now compares declarations only within the same block. The rule no longer reports @supports feature queries and correctly checks nested, @keyframes, and @page blocks.

  • #​11532 7ceb0ee Thanks @​dyc3! - Fixed #​11528: noFloatingPromises no longer reports statement-level await expressions that handle Promise values, including overloaded calls returning Promise aliases. Awaited values that resolve to arrays of Promises remain reported because their element Promises are not handled by await.

  • #​11474 3c6412e Thanks @​dyc3! - Fixed #​10241. Biome no longer reports unsupported text expression diagnostics for double-curly text in vanilla HTML, and the formatter preserves adjacent curly-brace text.

  • #​11593 6c7fd27 Thanks @​dyc3! - Added the nursery rule noVueDeprecatedScopedSlots. It reports deprecated $scopedSlots references in Vue templates and component objects, and offers an unsafe replacement with $slots. For example, Biome now reports this.$scopedSlots.default inside a Vue component.

  • #​11440 b88f1ea Thanks @​Princesseuh! - Fixed the formatter crashing on an Astro or Svelte expression spanning several lines in a file with CRLF line endings, such as <p>{a +\r\n b}</p>.

  • #​11581 f4e5ebb Thanks @​dyc3! - Added the nursery rule useModernMathApis. The rule reports legacy mathematical patterns that have direct modern Math equivalents.

    Math.sqrt(a * a + b * b);
  • #​11597 a20f44a Thanks @​Netail! - Added the nursery rule noBunModules, which forbids the use of Bun builtin modules (e.g. bun:sqlite, bun:ffi).

  • #​11545 7d54688 Thanks @​dyc3! - Fixed #​11542: Biome now reports HTML comments between Svelte tag attributes as parse errors.

  • #​11582 b6611dd Thanks @​ematipico! - Fixed #​3862. Biome now parses legacy Internet Explorer filter and -ms-filter values such as progid:DXImageTransform... and alpha(opacity=40).

  • #​11575 65da251 Thanks @​dyc3! - Improved the Tailwind parser's ability to recover from parsing failures. Whitespace now always allows the parser to recover and start parsing a new class.

  • #​11576 0f78499 Thanks @​ematipico! - Fixed #​3515 and #​10395, where Biome could corrupt Unicode characters while writing source received through standard input to standard output. Characters such as and are now preserved.

  • #​11539 0fca643 Thanks @​ematipico! - Fixed #​11512, where style/noDescendingSpecificity missed lower-specificity selectors after a later higher-specificity selector with the same tail selector.

  • #​11544 040f867 Thanks @​dyc3! - Fixed #​11541: formatting a Svelte render tag followed by an HTML comment no longer duplicates the comment.

     <div>
       {@render children?.()}
       <!-- comment -->
    -  <!-- comment -->
     </div>
  • #​11565 ee69e0e Thanks @​ematipico! - Fixed #​11525. Now the configuration schema correctly provides auto-completion for linter domains.

  • #​11583 b19390c Thanks @​dyc3! - Fixed #​11352: useExplicitLengthCheck no longer reports length-like properties used as value-producing || fallbacks or optional chains, and it no longer offers fixes for value-producing && checks or unsafe negations.

  • #​11562 753e955 Thanks @​ematipico! - Fixed an issue where the Biome Language Server would start with logging level set to debug. This would cause logs to grow exponentially in long sessions.

  • #​11217 7d3ee9c Thanks @​dyc3! - Fixed handling of biome-ignore format suppression comments on TypeScript declared class properties with string literal names.

    class A {
    	declare /* biome-ignore format: exercise suppression checking */ 'a-b': 0;
    }
  • #​11497 f5d7896 Thanks @​dyc3! - Added the noInvalidFileInputAccept nursery rule. The rule reports invalid literal accept values on file inputs in JSX and HTML, and normalizes common mistakes.

    <input type="file" accept="image/jpg" />
  • #​11345 ac58958 Thanks @​jakeleventhal! - Improved type inference performance by avoiding resolution of unused members in object arguments.

  • #​11554 2d55931 Thanks @​Netail! - Added the new nursery rule useReactNamingConvention, which enforces naming conventions for React values assigned from createContext, useId, and useRef. A value from createContext must be a PascalCase component name ending with Context, a value from useId must be named id or end with Id, and a value from useRef must be named ref or end with Ref.

  • #​11491 1d6210b Thanks @​dyc3! - Added the nursery rule noUnmodifiedLoopCondition, which reports variables in loop conditions that are never modified in the loop.

    let node = getNode();
    while (node) {
        process(node);
    }

v2.5.11

Compare Source

Patch Changes

Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Europe/Warsaw)

  • Branch creation
    • Only on Sunday and Saturday (* * * * 0,6)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/dev-frontend-dependencies branch from cfc7c06 to f6fed3a Compare July 8, 2026 12:55
@renovate
renovate Bot force-pushed the renovate/dev-frontend-dependencies branch 2 times, most recently from a92b856 to c3cf976 Compare July 18, 2026 12:18
@renovate
renovate Bot force-pushed the renovate/dev-frontend-dependencies branch 2 times, most recently from c58b8da to f682af3 Compare July 30, 2026 00:15
@renovate
renovate Bot force-pushed the renovate/dev-frontend-dependencies branch 3 times, most recently from 3484428 to d7f615f Compare August 7, 2026 03:52
@renovate
renovate Bot force-pushed the renovate/dev-frontend-dependencies branch 2 times, most recently from 8ac0797 to 86bd53d Compare August 9, 2026 15:02
@renovate
renovate Bot force-pushed the renovate/dev-frontend-dependencies branch 2 times, most recently from b03cbcc to c32b3e2 Compare August 21, 2026 23:58
@renovate
renovate Bot force-pushed the renovate/dev-frontend-dependencies branch 3 times, most recently from cc96246 to 43a251d Compare September 3, 2026 11:37
@renovate
renovate Bot force-pushed the renovate/dev-frontend-dependencies branch from 43a251d to 4033e53 Compare September 6, 2026 03:52
@renovate

renovate Bot commented Sep 6, 2026

Copy link
Copy Markdown
Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: web/pnpm-lock.yaml
Error: ERR_PNPM_STRICT_MIN_RELEASE_AGE_REQUIRES_SAVE

  × updating dependencies
  ╰─▶ minimumReleaseAgeStrict cannot be combined with --no-save: approval
      would require writing to minimumReleaseAgeExclude in pnpm-
      workspace.yaml, which --no-save prevents.
  help: Drop --no-save so the exclude list can be persisted, or set
        minimumReleaseAgeStrict: false.


@renovate
renovate Bot force-pushed the renovate/dev-frontend-dependencies branch from 4033e53 to e84a02d Compare September 10, 2026 23:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants