Skip to content

fix(deps): update all dependencies - #31

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Feb 19, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@biomejs/biome (source) ^2.4.0 → ^2.5.15 age confidence devDependencies minor
@changesets/changelog-github (source) ^0.5.2 → ^1.0.1 age confidence devDependencies major
@changesets/cli (source) ^2.29.8 → ^3.0.3 age confidence devDependencies major
@effect/cli (source) ^0.73.2 → ^0.77.2 age confidence dependencies minor
@effect/cluster (source) ^0.56.4 → ^0.60.2 age confidence dependencies minor
@effect/experimental (source) ^0.58.0 → ^0.61.1 age confidence dependencies minor
@effect/platform (source) ^0.94.5 → ^0.97.2 age confidence dependencies minor
@effect/platform-node (source) ^0.104.1 → ^4.0.2 age confidence dependencies major
@effect/printer (source) ^0.47.0 → ^0.51.0 age confidence dependencies minor
@effect/printer-ansi (source) ^0.47.0 → ^0.51.0 age confidence dependencies minor
@effect/rpc (source) ^0.73.1 → ^0.76.2 age confidence dependencies minor
@effect/sql (source) ^0.49.0 → ^0.52.1 age confidence dependencies minor
@effect/typeclass (source) ^0.38.0 → ^0.41.0 age confidence dependencies minor
@effect/vitest (source) ^0.27.0 → ^4.0.2 age confidence devDependencies major
@effect/workflow (source) ^0.16.0 → ^0.19.1 age confidence dependencies minor
@eslint-community/eslint-plugin-eslint-comments ^4.6.0 → ^4.8.1 age confidence devDependencies minor
@eslint/compat (source) 2.0.2 → 2.1.1 age confidence devDependencies minor
@eslint/eslintrc 3.3.3 → 3.3.7 age confidence devDependencies patch
@​prover-coder-ai/eslint-plugin-suggest-members ^0.0.25 → ^0.0.26 age confidence devDependencies patch
@types/node (source) ^24.10.13 → ^24.19.1 age confidence devDependencies minor
@typescript-eslint/eslint-plugin (source) ^8.55.0 → ^8.71.1 age confidence devDependencies minor
@typescript-eslint/parser (source) ^8.55.0 → ^8.71.1 age confidence devDependencies minor
@vitest/coverage-v8 (source) ^4.0.18 → ^5.0.3 age confidence devDependencies major
@vitest/eslint-plugin ^1.6.9 → ^1.6.27 age confidence devDependencies patch
actions/checkout v6 → v7 age confidence action major
actions/setup-node v6 → v7 age confidence action major
actions/upload-artifact v6 → v7 age confidence action major
effect (source) ^3.19.17 → ^4.0.2 age confidence dependencies major
eslint (source) ^10.0.0 → ^10.12.0 age confidence devDependencies minor
eslint-import-resolver-typescript ^4.4.4 → ^4.4.5 age confidence devDependencies patch
eslint-plugin-simple-import-sort ^12.1.1 → ^14.0.0 age confidence devDependencies major
eslint-plugin-sonarjs (source) ^3.0.7 → ^4.2.2 age confidence devDependencies major
eslint-plugin-sort-destructure-keys ^2.0.0 → ^3.0.0 age confidence devDependencies major
eslint-plugin-unicorn ^63.0.0 → ^77.0.0 age confidence devDependencies major
globals ^17.3.0 → ^17.13.0 age confidence devDependencies minor
jscpd (source) ^4.0.8 → ^5.4.0 age confidence devDependencies major
node 24.13.1 → 24.21.0 age confidence uses-with minor
pnpm (source) 10.29.3 → 12.10.1 age confidence packageManager major
pnpm/action-setup v4 → v6 age confidence action major
pnpm/action-setup v3 → v6 age confidence action major
ts-morph ^27.0.2 → ^28.0.0 age confidence dependencies major
typescript (source) ^5.9.3 → ^7.0.2 age confidence devDependencies major
typescript-eslint (source) ^8.55.0 → ^8.71.1 age confidence devDependencies minor
vite (source) ^7.3.1 → ^8.3.3 age confidence devDependencies major
vitest (source) ^4.0.18 → ^5.0.3 age confidence devDependencies major

cc @skulidropek


Release Notes

biomejs/biome (@​biomejs/biome)

v2.5.15

Compare Source

Patch Changes
  • #​10634 b436ba0 Thanks @​subaru-hello! - Added the new nursery rule noReactObjectTypeAsDefaultProp, which disallows array, object, and function values as default props in React components.

    For example, the following snippet triggers the rule.

    function Component({ items = [] }) {
      return items;
    }
  • #​11956 faa8b37 Thanks @​dyc3! - Added the nursery rule noSvelteExportLet, which disallows declaring Svelte component props with the legacy export let syntax. Use the $props() rune instead.

    <script>
      export let name;
    </script>
  • #​10816 1b9479e Thanks @​Th3S4mur41! - Added a new nursery rule useLogicalProperties that enforces the use of logical properties in CSS, promoting better internationalization and accessibility practices. The rule supports a direction option with "ltr" as the default and "rtl" as the alternative.
    This is a first rule covering parts of #​9034

    {
      "linter": {
        "rules": {
          "nursery": {
            "useLogicalProperties": {
              "level": "warn",
              "options": {
                "direction": "rtl"
              }
            }
          }
        }
      }
    }
  • #​11960 1fdb5c2 Thanks @​dyc3! - Added the nursery rule useSvelteKitRuneImports, which reports imports from the deprecated $app/stores module and suggests $app/state instead.

    import { page } from "$app/stores";
  • #​11723 3b429d1 Thanks @​m1handr! - Fixed #​11656: noAstroSetHtmlDirective now correctly reports set:html directives inside Astro template expressions.

  • #​12023 874d5ae Thanks @​codspeed! - Improved the performance of the HTML formatter up to 4x.

  • #​11761 a3462fe Thanks @​saberoueslati! - Fixed #​11351: useSimplifiedLogicExpression no longer reports boolean literals on the right side of || and && outside boolean contexts, because removing them can change the result of the expression. For example, y = x || false is no longer reported, while if (x || false) still is.

  • #​11732 ff4c4dd Thanks @​dyc3! - Added the nursery rule noMeaninglessVoidOperator, which reports unnecessary uses of void, such as void log() when log returns void. The rule allows discarded call results, thenables, void 0, and calls returning never.

  • #​11975 40dd3fb Thanks @​ematipico! - Fixed the indentation of multiline Astro expressions, in templates and attribute values, when running biome check --write. Biome now formats Astro expressions with biome format too, and places them at the column of the surrounding markup.

     <div>
     	{items.map((item) => (
    -	<span>{item}</span>
    -))}
    +		<span>{item}</span>
    +	))}
     </div>
  • #​12016 09d4000 Thanks @​codspeed! - Improved the performance of indexing and analysis of big files up to 2x. The improvements are mostly visible in projects that make use of project and types lint rules.

  • #​11750 089bde0 Thanks @​dyc3! - Added the nursery rule useStrictBooleanExpressions, which reports ambiguous truthiness checks such as if (value) when value has type number | undefined. Non-nullable strings and numbers and nullable objects are allowed; the rule has no options.

  • #​11494 ad5b362 Thanks @​jp-knj! - Added the nursery rule noAstroConflictingSetDirectives, which reports Astro elements with multiple content sources, such as set:html, set:text, and child content.

    For example, <div set:html={html}>content</div> triggers the rule.

  • #​11878 84d1b3b Thanks @​dyc3! - Fixed #​11748: useExhaustiveSwitchCases now reports missing cases for values created with the mapping overload of Array.from, including arrays imported from another module.

  • #​11802 7d1f37e Thanks @​dyc3! - Tailwind classes will now be detected in Svelte, Vue, and Astro class attribute expressions that don't use a class merging function.

  • #​11910 9e50ea2 Thanks @​ematipico! - Fixed #​11504, a regression where Biome would silently ignore errors in the configuration file. Now errors are correctly retained and checked before executing any command.

  • #​11921 d568632 Thanks @​hirehamir! - Fixed #​10846: when plugins fail to load, Biome now prints each failing plugin's path on its own line, instead of concatenating bare messages like Cannot read file.Cannot read file..

  • #​11930 82ea5a6 Thanks @​dyc3! - Fixed #​11927: The HTML formatter no longer duplicates comments around Svelte blocks. This affected a comment after a block such as {#if} or {#each} at the end of an element, and a comment on the same line as the last element inside a block, before {:else}, {/if}, or a similar tag.

  • #​11931 0cc46d8 Thanks @​dyc3! - Fixed the indentation of comments at the end of a Svelte block's contents. A comment before {:else}, {:then}, {/if}, or a similar tag is now indented with the block's contents instead of with the tag.

     {#if condition}
     	<span>Text</span>
    -<!-- comment -->
    +	<!-- comment -->
     {/if}
  • #​12031 ef0edd4 Thanks @​dyc3! - Fixed #​12027: Biome's test rules no longer mistake regular method calls named test, it, or describe for tests. For example, useValidTestTitle used to report the following regular expression check as a test with an invalid title:

    const isComment = /^\s*#/.test(line);
  • #​11959 8477e61 Thanks @​dyc3! - Fixed #​11950: noUnusedVariables now reports arrow functions with expression bodies that only reference themselves, such as let h = () => h();.

  • #​11915 3260602 Thanks @​ematipico! - Fixed #​11841, where suppression comments had no effect on some parts of HTML-ish files and on snippets embedded in JavaScript files.

    Now the following suppression works as expected:

    <!-- biome-ignore lint/correctness/noUndeclaredVariables: intentionally external -->
    <div :title="missingValue"></div>
  • #​11952 b51040e Thanks @​dyc3! - Fixed #​11951: the GritQL formatter no longer inserts a space after a within pattern without an until clause.

    -$arg <: within `bar($_)` ,
    +$arg <: within `bar($_)`,
  • #​11794 429cf95 Thanks @​dyc3! - Added the nursery rule noTailwindRawColors for JavaScript and HTML. It disallows Tailwind palette colors such as bg-pink-500 and text-white, encouraging design system color utilities such as bg-primary.

  • #​11837 f5e249b Thanks @​dyc3! - Fixed #​11836: biome check --write no longer adds invalid parentheses around Svelte {@const} declarations when experimental HTML support and formatting are enabled.

  • #​11978 8be0b9e Thanks @​dyc3! - Fixed #​11817: Biome no longer crashes when its output is piped to a program that exits early, such as head. Output to the closed pipe is now discarded and Biome exits normally.

  • #​11868 3841c26 Thanks @​ematipico! - Fixed #​8986: Biome's language server now scopes all watched-file patterns to each workspace folder, falling back to the deprecated rootUri when no workspace folders are provided. Clients without relative-pattern support receive compatible absolute glob patterns.

  • #​11928 0015681 Thanks @​dyc3! - Restricted access to the Unix daemon socket to the user running Biome. The socket now lives in a biome-daemon directory inside Biome's cache directory that only this user can access, and the socket itself has mode 0600.

  • #​11835 589ca1a Thanks @​dyc3! - Updated useReactCompiler: Biome now reports React Compiler diagnostics regardless of the React version declared in package.json.

  • #​11907 b7d9037 Thanks @​posido! - Fixed withastro/compiler-rs#194: the HTML parser no longer treats a regex literal that starts with > as the end of a self-closing tag. Astro frontmatter such as const escaped = s.replace(/>/g, "&gt;"); no longer swallows the closing --- fence, and the same regex inside a template expression no longer runs past its closing }. A regex literal after a keyword such as return, as in return />'/.test(s), is now recognized too.

  • #​12021 59cc595 Thanks @​dyc3! - Type inference performance has been significantly improved. Some popular libraries like Zod, Valibot, Arktype, Effect, Kysely, and Drizzle have gained a ~2-240x speedup in our benchmarks. This improvement affects all rules that use type information.

  • #​12044 c73fb91 Thanks @​dyc3! - Fixed #​12042: the HTML formatter no longer removes the space between text and an inline element on the next line when it joins the lines.

    - <p>a <em>b</em> c<u>d</u></p>
    + <p>a <em>b</em> c <u>d</u></p>
  • #​11965 f90bf38 Thanks @​ematipico! - Fixed module resolution in long-running workspaces so imports reflect package manifest and TypeScript path-mapping changes without requiring the importing file to be edited.

  • #​11860 0884e29 Thanks @​dyc3! - Removed the attributes and functions options from the nursery rule noTailwindArbitraryValue. The rule now uses the same Tailwind detection as useTailwindShorthandClasses.

  • #​11969 865cd30 Thanks @​AlbinoGeek! - Fixed #​11962: noUnknownTypeSelector no longer reports view transition names inside view transition pseudo-elements, such as page in ::view-transition-group(page).

  • #​11914 06ff47b Thanks @​dyc3! - Fixed #​11897: the safe fix for noUselessStringConcat now escapes embedded double quotes when combining literals, preserving valid JavaScript and existing escape sequences.

  • #​11997 af7825f Thanks @​github-actions! - The noRestrictedDependencies rule has been updated with new module replacement data, it should now detect for more relevant replacements.

  • #​11827 31bb662 Thanks @​dfedoryshchev! - Fixed #​11566: useNamingConvention no longer reports a namespace declared inside declare global or inside an external module declaration. Both positions are documented as always ignored, and the rule offered a safe fix, so biome check --write renamed the declaration:

    export {}
    declare global {
        // no longer renamed to `Jsx`
        namespace JSX {}
    }
  • #​11814 23ba25f Thanks @​siketyan! - Fixed type inference through generic type aliases that instantiate another generic type with a nested generic argument, such as type Nested<T> = Box<Wrapper<T>>. Type-aware rules now resolve members of such types:

    declare const nested: Nested<number>;
    // noUnnecessaryConditions now reports that `??` is unnecessary.
    const inner = nested.value.inner ?? 1;
  • #​11908 dd5a5ce Thanks @​siketyan! - Fixed #​11880: Biome no longer misparses a << expression followed by a later >>> as TypeScript type arguments. For example, const mask = 1 << bits followed by const m = mask >>> 0 on the next line now parses correctly.

  • #​11882 28c817d Thanks @​mikehasa! - Fixed a bug in noOctalEscape where the safe fix could silently change a string's value. A legacy octal escape is at most two digits when the leading digit is 4-7, so "\751" is "\75" + "1" (i.e. "=1") but was rewritten to the single character ǩ; it is now rewritten to "\x3d1".

  • #​11861 81b0adb Thanks @​Netail! - Added the new nursery rule noSelfImport, which forbids a module from importing itself.

    // foo.js
    import foo from "./foo.js";
  • #​12041 5e14509 Thanks @​ematipico! - Fixed a stack overflow in type-aware lint rules, such as noMisusedPromises and noFloatingPromises, when generic types in files that import each other reference one another in their type parameters.

    // entity.ts
    import type { Repository } from "./repository";
    export interface Entity<R extends Repository<any> = Repository<any>> {}
    
    // repository.ts
    import type { Entity } from "./entity";
    export interface Repository<E extends Entity<any> = Entity<any>> {}
  • #​11838 9bbff0c Thanks @​dyc3! - Added the nursery rule usePromiseRejectErrors, which requires Error objects as Promise rejection reasons.

    Promise.reject("Request failed");
    new Promise((resolve, reject) => reject(42));
  • #​11917 717db8c Thanks @​dyc3! - Added the nursery rule noMisplacedListElements for HTML and JSX, which requires <li> elements with an HTML element parent to be children of <ul>, <ol>, or <menu>. For example, <div><li>Item</li></div> is invalid.

  • #​11919 8d0b990 Thanks @​dyc3! - Fixed #​11899: disabling a domain no longer disables rules that also belong to another enabled domain. For example, with "domains": { "react": "all", "next": "none" }, useExhaustiveDependencies and useHookAtTopLevel are now enabled.
    Rules enabled explicitly in the configuration also stay enabled when one of their domains is set to "none".

  • #​11814 23ba25f Thanks @​siketyan! - Fixed #​11810 and #​11813: type-aware rules such as noUnnecessaryConditions and noFloatingPromises no longer take several seconds when a member is accessed on a recursive generic type alias, such as react-hook-form's FieldPathValue or zustand's Mutate.

  • #​11983 cc39794 Thanks @​AlbinoGeek! - Fixed #​11939: the fix of useRegexLiterals no longer escapes a slash that is already escaped. new RegExp("\\/") is now fixed to /\// instead of the invalid /\\//.

  • #​11869 3a21c80 Thanks @​ematipico! - Fixed #9105: vcs.useIgnoreFile now evaluates parent directory patterns when matching child paths, preserving re-included directories such as !/src while ignoring their excluded siblings.

  • #​11875 2cdd220 Thanks @​dyc3! - Fixed #​11867: noUndeclaredVariables incorrectly reported Vue slot props declared with v-slot or its # shorthand, including destructured props.

  • #​12021 59cc595 Thanks @​dyc3! - Type inference accuracy has been improved significantly. More global types, like Array, Map, Set, etc., are now fully defined. This should decrease false positives on all typed rules, since less types will be unknown.

  • #​11929 aef690d Thanks @​Th3S4mur41! - Fixed noUnknownProperty to recognize the frame-sizing CSS property.

  • #​12022 6233eb2 Thanks @​dyc3! - Fixed #​12020: the HTML parser now reports an error for a mismatched closing tag like the </span> in <p>two</span></p>. Previously, it accepted </span> as the end of <p> because span contains the letter p, and the formatter deleted everything after it. HTML tag names are matched case-insensitively, so <DIV></div> is no longer reported as mismatched.

    A closing tag with no opening tag at the top level of a file, like the second </p> in <p>a</p></p><p>b</p>, is now also reported as an error, instead of the formatter deleting it and everything after it.

  • #​12037 48cdbb8 Thanks @​ff1451! - Fixed #​11898: noUselessReturn no longer offers a safe fix for a return; that is the body of an unbraced if, else, or label, because removing it produced invalid code. The safe fix now also keeps comments placed before or after the removed return;.

    function foo() {
      // Still reported, but the return is no longer removed
      if (aborted) return;
    }
  • #​12030 4ff83dd Thanks @​ematipico! - Fixed #​9155: Biome no longer reports a parse error for typed slot props in Vue files, such as v-slot="{ value }: { value: ValueType }". Types used in slot props annotations are now correctly detected as used by noUnusedVariables.

  • #​11955 088164f Thanks @​dyc3! - Fixed #​11946: noUnreachable and useGetterReturn now recognize while and do...while loops with truthy literal conditions as infinite unless control flow exits the loop.

  • #​11958 6964bfc Thanks @​erenbati! - Fixed #​11924: noFocusedTests no longer reports chained method calls such as builder.image(url).fit("max") as focused tests.

  • #​11908 dd5a5ce Thanks @​siketyan! - Fixed parsing of left shifts between TypeScript instantiation expressions. Biome now parses f<T> << f<T> as a left shift of two instantiation expressions, matching TypeScript, instead of reporting a parse error.

  • #​11877 5a53b2c Thanks @​dyc3! - Fixed #​11278: noUnnecessaryConditions no longer incorrectly reports optional chaining on RegExp.exec() results, including patterns created with new RegExp(). Biome now infers the nullable RegExpExecArray | null return type, preserving necessary checks such as new RegExp(pattern).exec(input)?.[1].

  • #​11906 b87822d Thanks @​dyc3! - Fixed #​11900: useForOf no longer reports loops that update their index inside the body, including i += 1 and argv[++i].

  • #​11834 f89dd4f Thanks @​dyc3! - Fixed incorrect type inference when generic parameters are reused across inherited types or swapped in recursive types.

v2.5.14

Compare Source

Patch Changes
  • #​9022 0d49e24 Thanks @​dyc3! - Added the nursery rule noReturnInFinally. This rule disallows return statements in Promise.prototype.finally() callbacks, including inside nested blocks and conditional branches. Returns in nested functions are ignored by the rule.

    // Invalid: return in finally callback
    Promise.resolve(1).finally(() => { return 2 })
      // Valid: no return in finally callback
    Promise.resolve(1).finally(() => { console.log(2) })

    Returning a value from a Promise.prototype.finally() callback does not replace the original promise's fulfillment value, which can be confusing. Returned promises and thenables are awaited, and their rejection rejects the resulting promise.

  • #​11754 71eaa0d Thanks @​griff-rees! - Added the nursery rule noSvelteAtDebugTags, which disallows Svelte's {@debug} tag.

    <!-- Invalid: leftover debugging tag -->
    {@debug user}

    The {@debug} tag is a debugging aid and should be removed once you no longer need it, as it should not remain in production code. The rule provides a safe fix that removes the tag.

  • #​11725 5eb5f09 Thanks @​m1handr! - Added the nursery rule useValidTestTitle, which enforces valid titles for unit test cases and suites.

  • #​11735 9bd70c7 Thanks @​ematipico! - Fixed #​8471: source.fixAll.biome ignored formatter.formatWithErrors. It now applies safe fixes without formatting files that have parse errors when the option is disabled.

  • #​11715 f05a3c3 Thanks @​ematipico! - Fixed #​7771: Grit plugins that use sequential no longer panic when Biome processes files.

  • #​11766 c2542c6 Thanks @​dyc3! - Fixed validation of readonly and `a

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from skulidropek February 19, 2026 08:15
@renovate
renovate Bot force-pushed the renovate/all branch 12 times, most recently from 6cba843 to 0f055c2 Compare February 26, 2026 20:40
@renovate
renovate Bot force-pushed the renovate/all branch 9 times, most recently from 92bada8 to 71cb2e1 Compare March 7, 2026 01:14
@renovate
renovate Bot force-pushed the renovate/all branch 7 times, most recently from 54d829d to 590142f Compare March 13, 2026 18:50
@renovate
renovate Bot force-pushed the renovate/all branch 7 times, most recently from 5daa077 to 79555ae Compare March 31, 2026 20:40
@renovate
renovate Bot force-pushed the renovate/all branch 14 times, most recently from 055e1ef to d1673ca Compare April 10, 2026 12:43
@renovate
renovate Bot force-pushed the renovate/all branch 6 times, most recently from c20c888 to c23139a Compare April 16, 2026 12:07
@coderabbitai

coderabbitai Bot commented May 14, 2026 •

Copy link
Copy Markdown

Review Change Stack

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 3c9eab7e-346a-4f48-857a-57dca5080df7

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Bumps pnpm to 11.1.3 at root and app, upgrades Changesets and many app deps/devDeps, and updates GitHub Actions versions: pnpm/action-setup → v6, Node runtime → 24.15.0, and actions/upload-artifact → v7.

Changes

Dependency and Action Upgrades

Layer / File(s) Summary
Root package manager and Changesets tooling
package.json
Root package.json updated to packageManager: "pnpm@11.1.3" and Changesets devDependencies (@changesets/changelog-github, @changesets/cli) bumped.
App package manager and dependency upgrades
packages/app/package.json
packages/app packageManager set to pnpm@11.1.3; multiple runtime dependencies and devDependencies (including @effect/*, effect, ts-morph, tooling, TypeScript, Vite/Vitest, linters) have version bumps.
GitHub Actions and workflow configuration
.github/actions/setup/action.yml, .github/workflows/checking-dependencies.yml, .github/workflows/snapshot.yml
Composite action/workflows updated: pnpm/action-setup bumped to v6, actions/setup-node node-version changed to 24.15.0, and actions/upload-artifact bumped to v7.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related issues

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies the pull request as a dependency update, which matches the primary changes across packages, tooling, and CI actions.
Description check ✅ Passed The description directly documents the Renovate-generated dependency, package manager, CI action, and runtime version updates.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch renovate/all

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

🐰 A patch of pins and versions new,
I nibbled bumps and pushed them through.
Workflows hum and artifacts sing,
PNPM hops to a brighter spring.
— Rabbit with a CI carrot 🥕

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/actions/setup/action.yml:
- Line 13: The action uses pnpm/action-setup@v6 but the custom action default
still sets node-version: 20.16.0 which is incompatible; update the default
node-version in action.yml to Node 24 (>=24.0.0, e.g., 24.15.0 to match
checking-dependencies.yml) so the action runs on the required runtime, and after
changing the default verify pnpm selection behavior (packageManager in
package.json / pnpm@11.1.2) because v6 has a bug that may ignore
packageManager—if necessary pin the pnpm version explicitly or add configuration
to enforce packageManager to ensure the expected pnpm version is used.

In @.github/workflows/checking-dependencies.yml:
- Line 15: The workflow uses pnpm/action-setup@v6 but package.json declares
packageManager: pnpm@11.1.2, causing a mismatch; either align the workflow or
package.json: update package.json's packageManager to "pnpm@11.1.1" to match the
action's default, or explicitly configure the action in
.github/workflows/checking-dependencies.yml (pnpm/action-setup) with a
compatible with.version value (e.g., 11.1.1) until 11.1.2 is released, or remove
the explicit version so the action auto-detects from package.json and surfaces
the proper error if the version is unavailable.

In `@package.json`:
- Line 6: Update package.json to remove deprecated pnpm v10 fields and adopt
pnpm v11 format: replace any ignoredBuiltDependencies and onlyBuiltDependencies
entries with the new allowBuilds configuration (mapping allowed package patterns
or booleans accordingly) and set the engines.node field to ">=22" (or "22.x" per
project policy) so Node.js requirement is explicit for pnpm 11; also keep
packageManager set to "pnpm@11.1.2" and run the pnpm v10→v11 codemod (pnpx
codemod run pnpm-v10-to-v11) to ensure any other migration changes are applied.

In `@packages/app/package.json`:
- Line 71: Add an "engines" entry to packages/app/package.json to require
Node.js >=20.19.0 so ESLint 10.3.0 runs correctly; locate the existing "eslint":
"^10.3.0" dependency in package.json and add an "engines" object with "node":
">=20.19.0" to enforce the minimum Node version for contributors and CI.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 99f915a6-56ca-42ec-8fc8-02ccf3d20151

📥 Commits

Reviewing files that changed from the base of the PR and between 2b21043 and f9810e9.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • .github/actions/setup/action.yml
  • .github/workflows/checking-dependencies.yml
  • .github/workflows/snapshot.yml
  • package.json
  • packages/app/package.json

Comment thread .github/actions/setup/action.yml
steps:
- uses: actions/checkout@v6
- uses: pnpm/action-setup@v4
- uses: pnpm/action-setup@v6

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🌐 Web query:

pnpm/action-setup v6 release notes

💡 Result:

pnpm/action-setup v6 release notes (from the repo’s official GitHub Releases pages) are available as a series of versioned release entries under the v6 tags. The most recent v6 entry visible in the official releases feed is v6.0.8 (published 2026-05-12), with the following changes: 1) v6.0.8 (2026-05-12) - docs(README): fix cache_dependency_path type (PR #257) [1] - fix: drop patchPnpmEnv so standalone+self-update works on Windows (PR #258) [1] - fix: update pnpm to 11.1.1 (PR #248) [1] 2) v6.0.4 (2026-04-30) - fix: use npm co-located with the action node binary (PR #239) [2] Additional v6 changes are also reflected in the v4...v6 comparison page (including updates to README/examples and caching-related input typing/behavior), which indicates that v6 introduces/updates inputs like cache_dependency_path handling. In that compare view, cache_dependency_path is described as accepting multiple paths delimited by newlines, and the example workflows are updated to use pnpm/action-setup@v6 instead of v4. [3] Notes / where to read the full set of v6 release notes: - Start at the official Releases index for pnpm/action-setup and select the v6.x.y tags. The Releases index is the source of truth for the complete v6 changelog history. [4] If you want, tell me the exact v6 range you care about (e.g., “v6.0.0 through v6.0.8” or “just v6.0.8”), and I’ll summarize only those entries.

Citations:


🌐 Web query:

Node.js 24.15.0 release notes

💡 Result:

Node.js 24.15.0 (Krypton, LTS) release notes (published 2026-04-15) list these notable changes: - cli: add --max-heap-size option [1] - cli: add --require-module / --no-require-module [2] - crypto: add raw key formats support to the KeyObject APIs [1] - fs: add throwIfNoEntry option for fs.stat and fs.promises.stat [2] - http2: add http1Options for HTTP/1 fallback configuration [2] - module: mark require(esm) as stable [2] - module: mark module compile cache as stable [2] - net: add setTOS and getTOS to Socket [2] - sqlite: add limits property to DatabaseSync [2] - sqlite: mark as release candidate [2] - src: add C++ support for diagnostics channels [2] - stream: rename Duplex.toWeb type option to readableType [2] - test_runner: add exports option for module mocks [2] - test_runner: expose worker ID for concurrent test execution [2] - test_runner: show interrupted test on SIGINT [2] Primary sources for the above are the official Node.js blog release page and the Node.js v24 changelog section for 24.15.0 [1][2].

Citations:


🏁 Script executed:

#!/bin/bash
# Check all workflow files for consistency in action versions
rg -n "pnpm/action-setup@" --type yaml
rg -n "node-version:" --type yaml

Repository: ProverCoderAI/effect-template

Length of output: 55


🏁 Script executed:

#!/bin/bash
# Check if the workflow file exists
ls -la .github/workflows/ 2>/dev/null || echo "Directory not found"

# If it exists, read the file
if [ -f ".github/workflows/checking-dependencies.yml" ]; then
  echo "=== File found, reading contents ==="
  cat -n ".github/workflows/checking-dependencies.yml"
else
  echo "File not found"
fi

# Also check with fd for any workflow files
echo "=== Searching for workflow files ==="
fd -e yml -e yaml ".github/workflows/" 2>/dev/null || fd -e yml -e yaml

Repository: ProverCoderAI/effect-template

Length of output: 1412


🏁 Script executed:

#!/bin/bash
# Check pnpm version in lock file
head -20 pnpm-lock.yaml | grep -i "version\|lockfileVersion"

# Also check package.json for pnpm version requirement if any
if [ -f "package.json" ]; then
  grep -i "pnpm" package.json
fi

# Check if there's a .npmrc or similar config
if [ -f ".npmrc" ]; then
  cat .npmrc
fi

Repository: ProverCoderAI/effect-template

Length of output: 745


🌐 Web query:

pnpm 11.1.2 release date and availability

💡 Result:

No evidence found of a pnpm 11.1.2 release as of 2026-05-14. The latest releases are v11.1.1 (published around 2026-05-12 [1]) and v11.1.0 (published 2026-05-11 [2][3][4]). Official GitHub releases page lists recent tags up to May 12 but no 11.1.2 [3]. npm registry tracks these releases [4], and no sources mention 11.1.2. It is not yet released or available.[2][3][1]

Citations:


🌐 Web query:

pnpm/action-setup configure pnpm version 11.1.2

💡 Result:

To configure pnpm/action-setup to install pnpm 11.1.2, use the action’s with.version input: steps: - uses: pnpm/action-setup@v6 with: version: 11.1.2 The version input is “Version of pnpm to install” and supports exact versions like 11.1.2 (or version ranges/tags). If you omit version, the action can use the packageManager field from your package.json instead.[1] You may optionally specify run_install if you also want the action to run pnpm install for you; otherwise run pnpm install in a later step.[1]

Citations:


Configure pnpm version in pnpm/action-setup to match project requirement.

The workflow uses pnpm/action-setup@v6 which installs pnpm 11.1.1 by default, but the project specifies packageManager: pnpm@11.1.2 in package.json. Since pnpm 11.1.2 does not yet exist, the pnpm install --frozen-lockfile step (line 21) will fail due to version mismatch. Either update package.json to use pnpm 11.1.1, or configure the action with with.version: 11.1.2 once that version is released. Alternatively, the action can auto-detect the version from package.json if no version input is specified (allowing proper error messaging when unavailable).

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/checking-dependencies.yml at line 15, The workflow uses
pnpm/action-setup@v6 but package.json declares packageManager: pnpm@11.1.2,
causing a mismatch; either align the workflow or package.json: update
package.json's packageManager to "pnpm@11.1.1" to match the action's default, or
explicitly configure the action in .github/workflows/checking-dependencies.yml
(pnpm/action-setup) with a compatible with.version value (e.g., 11.1.1) until
11.1.2 is released, or remove the explicit version so the action auto-detects
from package.json and surfaces the proper error if the version is unavailable.

Comment thread package.json Outdated
"private": true,
"description": "Monorepo workspace for effect-template",
"packageManager": "pnpm@10.29.3",
"packageManager": "pnpm@11.1.2",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical | 🏗️ Heavy lift

🧩 Analysis chain

🌐 Web query:

pnpm 11 release notes breaking changes from pnpm 10

💡 Result:

pnpm 11 introduces several breaking changes from v10, primarily documented in the official migration guide [1] and v11.0.0 release notes [2][3]. Key breaking changes include: Node.js requirement: Now requires Node.js 22 or newer; support for v18-21 dropped. pnpm is pure ESM, and standalone exe needs glibc 2.27+ [3][2][4]. Configuration changes [1]: - No longer reads config from package.json#pnpm; move to pnpm-workspace.yaml. -.npmrc limited to auth/registry; other settings (hoist-pattern, node-linker, etc.) to pnpm-workspace.yaml (camelCase keys). - npm_config_* env vars ignored; use pnpm_config_*. - Deprecated build settings (onlyBuiltDependencies, etc.) removed; use allowBuilds [3][2]. - Package manager settings consolidated to pmOnFail: 'download'|'ignore'|'warn'|'error'. - Renames: allowNonAppliedPatches -> allowUnusedPatches; auditConfig.ignoreCves -> auditConfig.ignoreGhsas. Store upgraded to v11: SQLite index.db replaces JSON files; incompatible with v10 stores (clear or migrate) [3][2][5]. Global installs: Isolated in {pnpmHomeDir}/global/v11/{hash}/ with own package.json/node_modules/pnpm-lock.yaml. pnpm install -g (no args) removed; use pnpm add -g [3][2]. pnpm link changes: No global store resolution; only relative/absolute paths. --global removed (use pnpm add -g.); no-arg pnpm link removed [1][6]. Removed commands: pnpm server; npm passthrough (publish, login, etc.) now native, some like access, edit removed [3][2]. Lockfile: patchedDependencies simplified to selector -> hash; auto-migrated [5]. Script shadowing: Scripts named clean/setup/deploy/rebuild run script, not built-in; use pnpm pm [1]. Security defaults: minimumReleaseAge=1440 (1 day), blockExoticSubdeps=true, strictDepBuilds=true [3][2]. A codemod assists migration: pnpx codemod run pnpm-v10-to-v11 [1]. Full details: https://pnpm.io/migration [1], https://github.com/pnpm/pnpm/releases/tag/v11.0.0 [2], https://pnpm.io/blog/releases/11.0 [3].

Citations:


🏁 Script executed:

#!/bin/bash
# Check if pnpm-lock.yaml has been updated alongside this change
git diff HEAD -- pnpm-lock.yaml | head -50

Repository: ProverCoderAI/effect-template

Length of output: 55


🏁 Script executed:

#!/bin/bash
# Check if pnpm-lock.yaml exists and what version it specifies
if [ -f "pnpm-lock.yaml" ]; then
  echo "=== pnpm-lock.yaml lockfileVersion ==="
  head -20 pnpm-lock.yaml | rg "lockfileVersion|name|version"
else
  echo "pnpm-lock.yaml not found"
fi

# Check if package.json has pnpm config that needs migration
echo -e "\n=== package.json pnpm config ==="
jq '.pnpm' package.json 2>/dev/null || echo "No pnpm config in package.json"

# Check Node.js version requirement
echo -e "\n=== Node.js engines requirement ==="
jq '.engines' package.json 2>/dev/null || echo "No engines field"

Repository: ProverCoderAI/effect-template

Length of output: 586


🏁 Script executed:

#!/bin/bash
# Check git log to see if pnpm-lock.yaml was modified in this change
echo "=== Recent git changes to pnpm-lock.yaml ==="
git log --oneline -n 10 -- pnpm-lock.yaml 2>/dev/null || echo "No pnpm-lock.yaml history"

# Check if .npmrc or pnpm-workspace.yaml exists
echo -e "\n=== pnpm configuration files ==="
ls -la .npmrc pnpm-workspace.yaml .pnpmfile.cjs 2>/dev/null || echo "Checking config files..."
fd -e "npmrc|pnpmfile|workspace.yaml" .

Repository: ProverCoderAI/effect-template

Length of output: 287


🏁 Script executed:

#!/bin/bash
# Check CI workflows for Node.js version
echo "=== CI/CD Node.js version requirement ==="
find .github -name "*.yml" -o -name "*.yaml" 2>/dev/null | head -5 | xargs grep -l "node-version\|node_version\|setup-node" 2>/dev/null | head -1 | xargs cat 2>/dev/null | grep -A 2 "node-version\|setup-node" || echo "Checking workflows..."

Repository: ProverCoderAI/effect-template

Length of output: 370


Migrate deprecated pnpm configuration to pnpm 11 format.

The pnpm-lock.yaml has been regenerated to v9.0 (pnpm 11 format), but package.json still contains deprecated configuration that is no longer supported in pnpm 11:

  • ignoredBuiltDependencies and onlyBuiltDependencies must be migrated to the new allowBuilds configuration
  • Node.js requirement must be explicitly set to 22+ in the engines field (pnpm 11 no longer supports Node.js v18-21)

These deprecated options will cause failures when running pnpm commands. Use the pnpm v10→v11 migration codemod (pnpx codemod run pnpm-v10-to-v11) to complete the migration.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@package.json` at line 6, Update package.json to remove deprecated pnpm v10
fields and adopt pnpm v11 format: replace any ignoredBuiltDependencies and
onlyBuiltDependencies entries with the new allowBuilds configuration (mapping
allowed package patterns or booleans accordingly) and set the engines.node field
to ">=22" (or "22.x" per project policy) so Node.js requirement is explicit for
pnpm 11; also keep packageManager set to "pnpm@11.1.2" and run the pnpm v10→v11
codemod (pnpx codemod run pnpm-v10-to-v11) to ensure any other migration changes
are applied.

Comment thread packages/app/package.json Outdated
"@typescript-eslint/parser": "^8.59.3",
"typescript-eslint": "^8.59.3",
"@vitest/coverage-v8": "^4.1.6",
"eslint": "^10.3.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🌐 Web query:

ESLint 10.0 release notes breaking changes migration guide

💡 Result:

ESLint 10.0 release notes / breaking changes and the official migration guide are here: 1) Official migration guide (v9.x → v10.x) https://eslint.org/docs/latest/use/migrate-to-10.0.0 [1] 2) Official release notes for v10.0.0 https://eslint.org/blog/2026/02/eslint-v10.0.0-released/ [2] Key breaking changes called out in the migration guide (high-signal items) A) Node.js version support dropped ESLint v10.0.0 no longer supports Node.js versions < v20.19.0 (and also drops v21.x and v23.x); the migration guide says to upgrade to Node.js v20.19.0 or later [1][3]. B) “Old config format” no longer supported; flat config required The v10 migration guide states the legacy config system is removed (i.e., old eslintrc format is no longer supported) and points you to use flat config (eslint.config.) [1]. The migration guide summary also calls out removing the eslintrc format [1][3]. C) New configuration file lookup algorithm In ESLint v9 there was an alternate behavior guarded by a feature flag; in v10.0.0, the behavior is the default. The migration guide describes that config lookup now starts from the directory of each linted file and searches upward to the filesystem root (instead of starting from the current working directory) and that the v10_config_lookup_from_file flag was removed [1]. D) Removed feature for eslintrc config lookup behavior flag Attempting to use v10_config_lookup_from_file now results in an error (because the flag was removed) [1]. E) Rule/behavior & API breaking changes (examples listed in the migration guide) The migration guide lists multiple other breaking/API changes, including (among others) removal of the nodeType property in LintMessage objects [1], JSX references now being tracked [1], and changes around fixer APIs requiring string text arguments [1]. How to migrate (practical steps to follow) - Upgrade Node.js to a supported version (>= v20.19.0) before running ESLint 10 [1]. - Ensure you are using flat config (eslint.config.) and remove any legacy eslintrc configuration usage [1]. - If you previously relied on the v9 config lookup behavior / feature flag, update to the new lookup algorithm (start from each linted file’s directory) [1]. - Then run the official migration guide’s checklist/sections to address any remaining listed breaking changes in your specific setup [1].

Citations:


🏁 Script executed:

#!/bin/bash
# Check ESLint configuration files for compatibility
fd eslint.config -e js -e mjs -e cjs --exec cat {}

Repository: ProverCoderAI/effect-template

Length of output: 55


🏁 Script executed:

#!/bin/bash
# Check for ESLint configuration files
echo "=== Searching for ESLint config files ==="
fd -e json -e js -e cjs -e mjs '(eslintrc|eslint\.config)' --base-directory .

# Check package.json for Node.js version and ESLint config location
echo -e "\n=== Checking packages/app/package.json ==="
head -80 packages/app/package.json | tail -20

# Check root package.json for Node.js engines
echo -e "\n=== Checking root package.json for engines ==="
rg '"engines"' -A 5 package.json

Repository: ProverCoderAI/effect-template

Length of output: 1013


🏁 Script executed:

#!/bin/bash
# More comprehensive search for all ESLint-related configs
echo "=== Searching for all ESLint configs ==="
find . -type f \( -name ".eslintrc*" -o -name "eslint.config.*" \) 2>/dev/null

# Check for ESLint in workspace packages
echo -e "\n=== Checking eslint references in all package.json files ==="
find . -name "package.json" -type f -exec grep -l "eslint" {} \; 2>/dev/null

Repository: ProverCoderAI/effect-template

Length of output: 252


🏁 Script executed:

#!/bin/bash
# Check the ESLint flat config file
echo "=== Content of eslint.config.mts ==="
cat packages/app/eslint.config.mts

# Search for Node.js version constraints
echo -e "\n=== Searching for Node.js version constraints ==="
find . -type f \( -name ".nvmrc" -o -name ".tool-versions" -o -name "nvmrc" \) 2>/dev/null | head -10

# Check GitHub workflows for Node.js version
echo -e "\n=== Checking for Node.js version in CI/workflows ==="
fd "\.ya?ml$" .github/workflows 2>/dev/null | xargs grep -h "node-version" 2>/dev/null | head -10

Repository: ProverCoderAI/effect-template

Length of output: 10380


🏁 Script executed:

#!/bin/bash
# Check if engines field exists in root and app package.json
echo "=== Checking engines field in package.json files ==="
rg '"engines"' -B 1 -A 3 . --type json

# Check for `@eslint/compat` usage in eslint.config.mts
echo -e "\n=== Checking `@eslint/compat` usage ==="
grep -n "@eslint/compat\|compat" packages/app/eslint.config.mts || echo "No `@eslint/compat` found in config"

Repository: ProverCoderAI/effect-template

Length of output: 219


Add engines field to enforce Node.js >= v20.19.0 for ESLint 10.3.0 compatibility.

The repository has already properly migrated to ESLint's flat config format (eslint.config.mts) and uses @eslint/compat correctly for plugin compatibility. However, ESLint 10.3.0 requires Node.js >= v20.19.0, and this constraint should be explicitly documented in package.json via an engines field. Without it, developers using older Node.js versions may encounter runtime errors. Add to packages/app/package.json:

"engines": {
  "node": ">=20.19.0"
}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/app/package.json` at line 71, Add an "engines" entry to
packages/app/package.json to require Node.js >=20.19.0 so ESLint 10.3.0 runs
correctly; locate the existing "eslint": "^10.3.0" dependency in package.json
and add an "engines" object with "node": ">=20.19.0" to enforce the minimum Node
version for contributors and CI.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant