Skip to content

fix(deps): update all dependencies - #20

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Feb 21, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@biomejs/biome (source) ^2.4.4 → ^2.5.15 age confidence devDependencies minor
@changesets/changelog-github (source) ^0.5.2 → ^1.0.1 age confidence devDependencies major
@changesets/cli (source) ^2.29.8 → ^3.0.3 age confidence devDependencies major
@eslint-community/eslint-plugin-eslint-comments ^4.6.0 → ^4.8.1 age confidence devDependencies minor
@eslint/compat (source) 2.0.2 → 2.1.1 age confidence devDependencies minor
@eslint/eslintrc 3.3.3 → 3.3.7 age confidence devDependencies patch
@types/node (source) ^24.10.13 → ^24.19.1 age confidence devDependencies minor
@typescript-eslint/eslint-plugin (source) ^8.56.0 → ^8.71.1 age confidence devDependencies minor
@typescript-eslint/parser (source) ^8.56.0 → ^8.71.1 age confidence devDependencies minor
@vitest/coverage-v8 (source) ^4.0.18 → ^5.0.3 age confidence devDependencies major
@vitest/eslint-plugin ^1.6.9 → ^1.6.27 age confidence devDependencies patch
actions/checkout v6 → v7 age confidence action major
actions/setup-node v6 → v7 age confidence action major
actions/upload-artifact v6 → v7 age confidence action major
effect (source) ^3.19.18 → ^4.0.1 age confidence dependencies major
eslint (source) ^10.0.1 → ^10.12.0 age confidence devDependencies minor
eslint-import-resolver-typescript ^4.4.4 → ^4.4.5 age confidence devDependencies patch
eslint-plugin-simple-import-sort ^12.1.1 → ^14.0.0 age confidence devDependencies major
eslint-plugin-sonarjs (source) ^4.0.0 → ^4.2.2 age confidence devDependencies minor
eslint-plugin-unicorn ^63.0.0 → ^77.0.0 age confidence devDependencies major
globals ^17.3.0 → ^17.13.0 age confidence devDependencies minor
jscpd (source) ^4.0.8 → ^5.4.0 age confidence devDependencies major
node 24.13.1 → 24.21.0 age confidence uses-with minor
pnpm (source) 10.30.1 → 12.9.1 age confidence packageManager major
pnpm/action-setup v4 → v6 age confidence action major
pnpm/action-setup v3 → v6 age confidence action major
typescript (source) ^5.9.3 → ^7.0.2 age confidence devDependencies major
typescript-eslint (source) ^8.56.0 → ^8.71.1 age confidence devDependencies minor
vite (source) ^7.3.1 → ^8.3.3 age confidence devDependencies major
vitest (source) ^4.0.18 → ^5.0.3 age confidence devDependencies major

cc @skulidropek


Release Notes

biomejs/biome (@​biomejs/biome)

v2.5.15

Compare Source

Patch Changes
  • #​10634 b436ba0 Thanks @​subaru-hello! - Added the new nursery rule noReactObjectTypeAsDefaultProp, which disallows array, object, and function values as default props in React components.

    For example, the following snippet triggers the rule.

    function Component({ items = [] }) {
      return items;
    }
  • #​11956 faa8b37 Thanks @​dyc3! - Added the nursery rule noSvelteExportLet, which disallows declaring Svelte component props with the legacy export let syntax. Use the $props() rune instead.

    <script>
      export let name;
    </script>
  • #​10816 1b9479e Thanks @​Th3S4mur41! - Added a new nursery rule useLogicalProperties that enforces the use of logical properties in CSS, promoting better internationalization and accessibility practices. The rule supports a direction option with "ltr" as the default and "rtl" as the alternative.
    This is a first rule covering parts of #​9034

    {
      "linter": {
        "rules": {
          "nursery": {
            "useLogicalProperties": {
              "level": "warn",
              "options": {
                "direction": "rtl"
              }
            }
          }
        }
      }
    }
  • #​11960 1fdb5c2 Thanks @​dyc3! - Added the nursery rule useSvelteKitRuneImports, which reports imports from the deprecated $app/stores module and suggests $app/state instead.

    import { page } from "$app/stores";
  • #​11723 3b429d1 Thanks @​m1handr! - Fixed #​11656: noAstroSetHtmlDirective now correctly reports set:html directives inside Astro template expressions.

  • #​12023 874d5ae Thanks @​codspeed! - Improved the performance of the HTML formatter up to 4x.

  • #​11761 a3462fe Thanks @​saberoueslati! - Fixed #​11351: useSimplifiedLogicExpression no longer reports boolean literals on the right side of || and && outside boolean contexts, because removing them can change the result of the expression. For example, y = x || false is no longer reported, while if (x || false) still is.

  • #​11732 ff4c4dd Thanks @​dyc3! - Added the nursery rule noMeaninglessVoidOperator, which reports unnecessary uses of void, such as void log() when log returns void. The rule allows discarded call results, thenables, void 0, and calls returning never.

  • #​11975 40dd3fb Thanks @​ematipico! - Fixed the indentation of multiline Astro expressions, in templates and attribute values, when running biome check --write. Biome now formats Astro expressions with biome format too, and places them at the column of the surrounding markup.

     <div>
     	{items.map((item) => (
    -	<span>{item}</span>
    -))}
    +		<span>{item}</span>
    +	))}
     </div>
  • #​12016 09d4000 Thanks @​codspeed! - Improved the performance of indexing and analysis of big files up to 2x. The improvements are mostly visible in projects that make use of project and types lint rules.

  • #​11750 089bde0 Thanks @​dyc3! - Added the nursery rule useStrictBooleanExpressions, which reports ambiguous truthiness checks such as if (value) when value has type number | undefined. Non-nullable strings and numbers and nullable objects are allowed; the rule has no options.

  • #​11494 ad5b362 Thanks @​jp-knj! - Added the nursery rule noAstroConflictingSetDirectives, which reports Astro elements with multiple content sources, such as set:html, set:text, and child content.

    For example, <div set:html={html}>content</div> triggers the rule.

  • #​11878 84d1b3b Thanks @​dyc3! - Fixed #​11748: useExhaustiveSwitchCases now reports missing cases for values created with the mapping overload of Array.from, including arrays imported from another module.

  • #​11802 7d1f37e Thanks @​dyc3! - Tailwind classes will now be detected in Svelte, Vue, and Astro class attribute expressions that don't use a class merging function.

  • #​11910 9e50ea2 Thanks @​ematipico! - Fixed #​11504, a regression where Biome would silently ignore errors in the configuration file. Now errors are correctly retained and checked before executing any command.

  • #​11921 d568632 Thanks @​hirehamir! - Fixed #​10846: when plugins fail to load, Biome now prints each failing plugin's path on its own line, instead of concatenating bare messages like Cannot read file.Cannot read file..

  • #​11930 82ea5a6 Thanks @​dyc3! - Fixed #​11927: The HTML formatter no longer duplicates comments around Svelte blocks. This affected a comment after a block such as {#if} or {#each} at the end of an element, and a comment on the same line as the last element inside a block, before {:else}, {/if}, or a similar tag.

  • #​11931 0cc46d8 Thanks @​dyc3! - Fixed the indentation of comments at the end of a Svelte block's contents. A comment before {:else}, {:then}, {/if}, or a similar tag is now indented with the block's contents instead of with the tag.

     {#if condition}
     	<span>Text</span>
    -<!-- comment -->
    +	<!-- comment -->
     {/if}
  • #​12031 ef0edd4 Thanks @​dyc3! - Fixed #​12027: Biome's test rules no longer mistake regular method calls named test, it, or describe for tests. For example, useValidTestTitle used to report the following regular expression check as a test with an invalid title:

    const isComment = /^\s*#/.test(line);
  • #​11959 8477e61 Thanks @​dyc3! - Fixed #​11950: noUnusedVariables now reports arrow functions with expression bodies that only reference themselves, such as let h = () => h();.

  • #​11915 3260602 Thanks @​ematipico! - Fixed #​11841, where suppression comments had no effect on some parts of HTML-ish files and on snippets embedded in JavaScript files.

    Now the following suppression works as expected:

    <!-- biome-ignore lint/correctness/noUndeclaredVariables: intentionally external -->
    <div :title="missingValue"></div>
  • #​11952 b51040e Thanks @​dyc3! - Fixed #​11951: the GritQL formatter no longer inserts a space after a within pattern without an until clause.

    -$arg <: within `bar($_)` ,
    +$arg <: within `bar($_)`,
  • #​11794 429cf95 Thanks @​dyc3! - Added the nursery rule noTailwindRawColors for JavaScript and HTML. It disallows Tailwind palette colors such as bg-pink-500 and text-white, encouraging design system color utilities such as bg-primary.

  • #​11837 f5e249b Thanks @​dyc3! - Fixed #​11836: biome check --write no longer adds invalid parentheses around Svelte {@const} declarations when experimental HTML support and formatting are enabled.

  • #​11978 8be0b9e Thanks @​dyc3! - Fixed #​11817: Biome no longer crashes when its output is piped to a program that exits early, such as head. Output to the closed pipe is now discarded and Biome exits normally.

  • #​11868 3841c26 Thanks @​ematipico! - Fixed #​8986: Biome's language server now scopes all watched-file patterns to each workspace folder, falling back to the deprecated rootUri when no workspace folders are provided. Clients without relative-pattern support receive compatible absolute glob patterns.

  • #​11928 0015681 Thanks @​dyc3! - Restricted access to the Unix daemon socket to the user running Biome. The socket now lives in a biome-daemon directory inside Biome's cache directory that only this user can access, and the socket itself has mode 0600.

  • #​11835 589ca1a Thanks @​dyc3! - Updated useReactCompiler: Biome now reports React Compiler diagnostics regardless of the React version declared in package.json.

  • #​11907 b7d9037 Thanks @​posido! - Fixed withastro/compiler-rs#194: the HTML parser no longer treats a regex literal that starts with > as the end of a self-closing tag. Astro frontmatter such as const escaped = s.replace(/>/g, "&gt;"); no longer swallows the closing --- fence, and the same regex inside a template expression no longer runs past its closing }. A regex literal after a keyword such as return, as in return />'/.test(s), is now recognized too.

  • #​12021 59cc595 Thanks @​dyc3! - Type inference performance has been significantly improved. Some popular libraries like Zod, Valibot, Arktype, Effect, Kysely, and Drizzle have gained a ~2-240x speedup in our benchmarks. This improvement affects all rules that use type information.

  • #​12044 c73fb91 Thanks @​dyc3! - Fixed #​12042: the HTML formatter no longer removes the space between text and an inline element on the next line when it joins the lines.

    - <p>a <em>b</em> c<u>d</u></p>
    + <p>a <em>b</em> c <u>d</u></p>
  • #​11965 f90bf38 Thanks @​ematipico! - Fixed module resolution in long-running workspaces so imports reflect package manifest and TypeScript path-mapping changes without requiring the importing file to be edited.

  • #​11860 0884e29 Thanks @​dyc3! - Removed the attributes and functions options from the nursery rule noTailwindArbitraryValue. The rule now uses the same Tailwind detection as useTailwindShorthandClasses.

  • #​11969 865cd30 Thanks @​AlbinoGeek! - Fixed #​11962: noUnknownTypeSelector no longer reports view transition names inside view transition pseudo-elements, such as page in ::view-transition-group(page).

  • #​11914 06ff47b Thanks @​dyc3! - Fixed #​11897: the safe fix for noUselessStringConcat now escapes embedded double quotes when combining literals, preserving valid JavaScript and existing escape sequences.

  • #​11997 af7825f Thanks @​github-actions! - The noRestrictedDependencies rule has been updated with new module replacement data, it should now detect for more relevant replacements.

  • #​11827 31bb662 Thanks @​dfedoryshchev! - Fixed #​11566: useNamingConvention no longer reports a namespace declared inside declare global or inside an external module declaration. Both positions are documented as always ignored, and the rule offered a safe fix, so biome check --write renamed the declaration:

    export {}
    declare global {
        // no longer renamed to `Jsx`
        namespace JSX {}
    }
  • #​11814 23ba25f Thanks @​siketyan! - Fixed type inference through generic type aliases that instantiate another generic type with a nested generic argument, such as type Nested<T> = Box<Wrapper<T>>. Type-aware rules now resolve members of such types:

    declare const nested: Nested<number>;
    // noUnnecessaryConditions now reports that `??` is unnecessary.
    const inner = nested.value.inner ?? 1;
  • #​11908 dd5a5ce Thanks @​siketyan! - Fixed #​11880: Biome no longer misparses a << expression followed by a later >>> as TypeScript type arguments. For example, const mask = 1 << bits followed by const m = mask >>> 0 on the next line now parses correctly.

  • #​11882 28c817d Thanks @​mikehasa! - Fixed a bug in noOctalEscape where the safe fix could silently change a string's value. A legacy octal escape is at most two digits when the leading digit is 4-7, so "\751" is "\75" + "1" (i.e. "=1") but was rewritten to the single character ǩ; it is now rewritten to "\x3d1".

  • #​11861 81b0adb Thanks @​Netail! - Added the new nursery rule noSelfImport, which forbids a module from importing itself.

    // foo.js
    import foo from "./foo.js";
  • #​12041 5e14509 Thanks @​ematipico! - Fixed a stack overflow in type-aware lint rules, such as noMisusedPromises and noFloatingPromises, when generic types in files that import each other reference one another in their type parameters.

    // entity.ts
    import type { Repository } from "./repository";
    export interface Entity<R extends Repository<any> = Repository<any>> {}
    
    // repository.ts
    import type { Entity } from "./entity";
    export interface Repository<E extends Entity<any> = Entity<any>> {}
  • #​11838 9bbff0c Thanks @​dyc3! - Added the nursery rule usePromiseRejectErrors, which requires Error objects as Promise rejection reasons.

    Promise.reject("Request failed");
    new Promise((resolve, reject) => reject(42));
  • #​11917 717db8c Thanks @​dyc3! - Added the nursery rule noMisplacedListElements for HTML and JSX, which requires <li> elements with an HTML element parent to be children of <ul>, <ol>, or <menu>. For example, <div><li>Item</li></div> is invalid.

  • #​11919 8d0b990 Thanks @​dyc3! - Fixed #​11899: disabling a domain no longer disables rules that also belong to another enabled domain. For example, with "domains": { "react": "all", "next": "none" }, useExhaustiveDependencies and useHookAtTopLevel are now enabled.
    Rules enabled explicitly in the configuration also stay enabled when one of their domains is set to "none".

  • #​11814 23ba25f Thanks @​siketyan! - Fixed #​11810 and #​11813: type-aware rules such as noUnnecessaryConditions and noFloatingPromises no longer take several seconds when a member is accessed on a recursive generic type alias, such as react-hook-form's FieldPathValue or zustand's Mutate.

  • #​11983 cc39794 Thanks @​AlbinoGeek! - Fixed #​11939: the fix of useRegexLiterals no longer escapes a slash that is already escaped. new RegExp("\\/") is now fixed to /\// instead of the invalid /\\//.

  • #​11869 3a21c80 Thanks @​ematipico! - Fixed #9105: vcs.useIgnoreFile now evaluates parent directory patterns when matching child paths, preserving re-included directories such as !/src while ignoring their excluded siblings.

  • #​11875 2cdd220 Thanks @​dyc3! - Fixed #​11867: noUndeclaredVariables incorrectly reported Vue slot props declared with v-slot or its # shorthand, including destructured props.

  • #​12021 59cc595 Thanks @​dyc3! - Type inference accuracy has been improved significantly. More global types, like Array, Map, Set, etc., are now fully defined. This should decrease false positives on all typed rules, since less types will be unknown.

  • #​11929 aef690d Thanks @​Th3S4mur41! - Fixed noUnknownProperty to recognize the frame-sizing CSS property.

  • #​12022 6233eb2 Thanks @​dyc3! - Fixed #​12020: the HTML parser now reports an error for a mismatched closing tag like the </span> in <p>two</span></p>. Previously, it accepted </span> as the end of <p> because span contains the letter p, and the formatter deleted everything after it. HTML tag names are matched case-insensitively, so <DIV></div> is no longer reported as mismatched.

    A closing tag with no opening tag at the top level of a file, like the second </p> in <p>a</p></p><p>b</p>, is now also reported as an error, instead of the formatter deleting it and everything after it.

  • #​12037 48cdbb8 Thanks @​ff1451! - Fixed #​11898: noUselessReturn no longer offers a safe fix for a return; that is the body of an unbraced if, else, or label, because removing it produced invalid code. The safe fix now also keeps comments placed before or after the removed return;.

    function foo() {
      // Still reported, but the return is no longer removed
      if (aborted) return;
    }
  • #​12030 4ff83dd Thanks @​ematipico! - Fixed #​9155: Biome no longer reports a parse error for typed slot props in Vue files, such as v-slot="{ value }: { value: ValueType }". Types used in slot props annotations are now correctly detected as used by noUnusedVariables.

  • #​11955 088164f Thanks @​dyc3! - Fixed #​11946: noUnreachable and useGetterReturn now recognize while and do...while loops with truthy literal conditions as infinite unless control flow exits the loop.

  • #​11958 6964bfc Thanks @​erenbati! - Fixed #​11924: noFocusedTests no longer reports chained method calls such as builder.image(url).fit("max") as focused tests.

  • #​11908 dd5a5ce Thanks @​siketyan! - Fixed parsing of left shifts between TypeScript instantiation expressions. Biome now parses f<T> << f<T> as a left shift of two instantiation expressions, matching TypeScript, instead of reporting a parse error.

  • #​11877 5a53b2c Thanks @​dyc3! - Fixed #​11278: noUnnecessaryConditions no longer incorrectly reports optional chaining on RegExp.exec() results, including patterns created with new RegExp(). Biome now infers the nullable RegExpExecArray | null return type, preserving necessary checks such as new RegExp(pattern).exec(input)?.[1].

  • #​11906 b87822d Thanks @​dyc3! - Fixed #​11900: useForOf no longer reports loops that update their index inside the body, including i += 1 and argv[++i].

  • #​11834 f89dd4f Thanks @​dyc3! - Fixed incorrect type inference when generic parameters are reused across inherited types or swapped in recursive types.

v2.5.14

Compare Source

Patch Changes
  • #​9022 0d49e24 Thanks @​dyc3! - Added the nursery rule noReturnInFinally. This rule disallows return statements in Promise.prototype.finally() callbacks, including inside nested blocks and conditional branches. Returns in nested functions are ignored by the rule.

    // Invalid: return in finally callback
    Promise.resolve(1).finally(() => { return 2 })
    
    // Valid: no return in finally callback
    Promise.resolve(1).finally(() => { console.log(2) })

    Returning a value from a Promise.prototype.finally() callback does not replace the original promise's fulfillment value, which can be confusing. Returned promises and thenables are awaited, and their rejection rejects the resulting promise.

  • #​11754 71eaa0d Thanks @​griff-rees! - Added the nursery rule noSvelteAtDebugTags, which disallows Svelte's {@debug} tag.

    <!-- Invalid: leftover debugging tag -->
    {@debug user}

    The {@debug} tag is a debugging aid and should be removed once you no longer need it, as it should not remain in production code. The rule provides a safe fix that removes the tag.

  • #​11725 5eb5f09 Thanks @​m1handr! - Added the nursery rule useValidTestTitle, which enforces valid titles for unit test cases and suites.

  • #​11735 9bd70c7 Thanks @​ematipico! - Fixed #​8471: source.fixAll.biome ignored formatter.formatWithErrors. It now applies safe fixes without formatting files that have parse errors when the option is disabled.

  • #​11715 f05a3c3 Thanks @​ematipico! - Fixed #​7771: Grit plugins that use sequential no longer panic when Biome processes files.

  • #​11766 c2542c6 Thanks @​dyc3! - Fixed validation of readonly and accessor modifiers: combining them in either order now reports that they cannot be used together.

  • #​11461 22e9966 Thanks @​FoundDream! - Fixed #​11423: Multiline template interpolations now preserve the indentation of their closing brace when the source indentation is not a multiple of tabWidth.

     const value = `
          ${
            condition
              ? "yes"
              : "no"
    -}
    +     }
     `;
  • #​11766 c2542c6 Thanks @​dyc3! - Fixed #​11763: TypeScript class members using override accessor, such as override accessor value = 1, now parse correctly. The reversed order, accessor override, now reports that override must precede accessor.

  • #​11790 17d0ff0 Thanks @​ematipico! - Fixed #​10248: noUselessFragments now allows fragments with props in Astro files, such as <Fragment slot="name">{text}</Fragment> inside template expressions.

  • #​11777 7ee3a6c Thanks @​ematipico! - Fixed #​7573: added the requireExplicitCase option to useExhaustiveSwitchCases. When set to true, the rule reports missing cases even when the switch has a default clause, so you can keep a runtime fallback while checking that every value in the union has its own case. The option defaults to false.

  • #​11751 d37f24b Thanks @​ematipico! - Fixed #​8347: the fix from useConsistentArrowReturn now parenthesizes returned expressions that begin with object literals before removing the arrow function body braces, preventing invalid output for expressions such as object property access.

  • #​11784 46e8912 Thanks @​dyc3! - Fixed #​11782: noUndeclaredCustomProperties could hang while checking stylesheets imported by JavaScript modules with many shared dependencies.

  • #​11731 1534885 Thanks @​ematipico! - Fixed #​7984: The fix from useSimplifiedLogicExpression now preserves line breaks in multiline conditions with line comments, preventing the right-hand side condition from being commented out.

  • #​11735 9bd70c7 Thanks @​ematipico! - Fixed #​7304: the HTML formatter now preserves authored segment breaks between CJK characters, and next to CJK punctuation, instead of replacing them with spaces.

     <div lang="zh-Hant-TW">
    -  這個段落是那麼長, 在一行寫不行。
    +  這個段落是那麼長,
    +  在一行寫不行。
     </div>
  • #​11749 ff992a1 Thanks @​ematipico! - Fixed #​11747: formatting and checking large parenthesized object expressions no longer exhibit quadratic slowdowns.

  • #​11736 1dd1fc4 Thanks @​dyc3! - Fixed #​8177: code actions no longer modify the wrong part of Vue, Svelte, or Astro files when experimental full HTML support is disabled.

  • #​11743 3835945 Thanks @​santichausis! - Fixed #​10247: biome check --write/biome lint --write now correctly writes fixes for code inside an HTML attribute expression (for example a Svelte onclick={...} handler, or a mustache expression like {count}), instead of silently reporting the diagnostic as fixable and applying nothing.

    For example, running biome lint --write --unsafe for useBlockStatements (an unsafe fix) on this Svelte component used to leave the file unchanged:

    <button onclick={() => { if (open) close(); }}>Close</button>
  • #​11740 8ea8b4a Thanks @​dyc3! - Fixed #​11453: [`

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from skulidropek February 21, 2026 13:44
@renovate renovate Bot changed the title fix(deps): update dependency effect to ^3.19.19 fix(deps): update all dependencies Feb 23, 2026
@renovate
renovate Bot force-pushed the renovate/all branch 9 times, most recently from 52aba09 to 16d549f Compare March 2, 2026 17:40
@renovate
renovate Bot force-pushed the renovate/all branch 10 times, most recently from f240877 to 3c2e51f Compare March 9, 2026 23:06
@renovate
renovate Bot force-pushed the renovate/all branch 7 times, most recently from 9456c54 to 0ff8d9f Compare March 17, 2026 14:38
@renovate
renovate Bot force-pushed the renovate/all branch 5 times, most recently from 6ff8486 to 4c77644 Compare April 24, 2026 02:39
@coderabbitai

coderabbitai Bot commented May 14, 2026 •

Copy link
Copy Markdown

Review Change Stack

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 354cab28-33a0-46fc-88c4-732b12380281

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Bump CI action versions, pin pnpm to 11.1.2 in root and app, and update Changesets plus many app dependencies/devDependencies (Effect stack, TypeScript tooling, linting, testing, and build tools).

Changes

Toolchain and dependency upgrades

Layer / File(s) Summary
GitHub Actions versions
.github/actions/setup/action.yml, .github/workflows/checking-dependencies.yml, .github/workflows/snapshot.yml
pnpm action bumped to @v6 in composite and workflow; actions/setup-node Node input updated to 24.15.0; artifact upload action bumped to actions/upload-artifact@v7.
pnpm version pins
package.json, packages/app/package.json
Workspace and app packageManager updated from pnpm@10.30.1 to pnpm@11.1.2.
Dependency and toolchain upgrades
package.json, packages/app/package.json
Root Changesets packages (@changesets/changelog-github, @changesets/cli) bumped; app package dependencies and devDependencies refreshed (Effect packages, ts-morph, Biome/ESLint, TypeScript tooling, Vitest/Vite, etc.).

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related issues

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description check ✅ Passed The description clearly documents the Renovate dependency, package manager, and GitHub Actions updates in the changeset.
Title check ✅ Passed The title accurately identifies the pull request as a broad dependency update, including packages, tooling, and GitHub Actions.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch renovate/all

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

🐇 I nudged a YAML line, made pnpm climb to eleven,
Actions hum a newer tune, workflows light as heaven.
Packages refreshed, linters wake and play,
Tests tiptoe cleaner paths, building through the day.
✨

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/actions/setup/action.yml:
- Line 13: The workflow currently uses a mutable tag "pnpm/action-setup@v6";
replace that with an immutable full commit SHA (40-hex) for pnpm/action-setup to
pin the action (e.g., "pnpm/action-setup@<full-commit-sha>"). Locate the "uses:
pnpm/action-setup@v6" entry in the action.yml and update it to the exact commit
SHA from the pnpm/action-setup repository, verify the SHA is full-length (40
characters) and that the workflow still runs correctly after the change.

In @.github/workflows/checking-dependencies.yml:
- Line 15: Replace the mutable tag reference "uses: pnpm/action-setup@v6" with
an immutable pin to the full commit SHA for the pnpm/action-setup action (e.g.,
"uses: pnpm/action-setup@<full-commit-sha>"); locate the occurrences of
"pnpm/action-setup@v6" in the workflow and update them to the corresponding
release commit SHA from the action's repository, then verify the workflow runs
successfully.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 4cd2e52a-a23f-4849-8bc7-20b25e799703

📥 Commits

Reviewing files that changed from the base of the PR and between 6b3e168 and 373422e.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • .github/actions/setup/action.yml
  • .github/workflows/checking-dependencies.yml
  • .github/workflows/snapshot.yml
  • package.json
  • packages/app/package.json

steps:
- name: Install pnpm
uses: pnpm/action-setup@v3
uses: pnpm/action-setup@v6

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Verify mutable action refs under .github (tag-based refs like `@v1/`@v6).
# Expected: no matches after SHA pinning.
rg -n --iglob '*.yml' --iglob '*.yaml' 'uses:\s*[^@[:space:]]+@v[0-9]+(\.[0-9]+){0,2}\b' .github

Repository: ProverCoderAI/openapi-effect

Length of output: 1009


Pin pnpm/action-setup to an immutable commit SHA.

Line 13 uses a mutable tag (@v6). Please pin to a full-length commit SHA to reduce supply-chain risk and avoid policy breaks in hardened org settings.

🔒 Suggested change
-      uses: pnpm/action-setup@v6
+      uses: pnpm/action-setup@<full-length-commit-sha> # v6.x

Reference: https://docs.github.com/actions/security-guides/security-hardening-for-github-actions

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/actions/setup/action.yml at line 13, The workflow currently uses a
mutable tag "pnpm/action-setup@v6"; replace that with an immutable full commit
SHA (40-hex) for pnpm/action-setup to pin the action (e.g.,
"pnpm/action-setup@<full-commit-sha>"). Locate the "uses: pnpm/action-setup@v6"
entry in the action.yml and update it to the exact commit SHA from the
pnpm/action-setup repository, verify the SHA is full-length (40 characters) and
that the workflow still runs correctly after the change.

steps:
- uses: actions/checkout@v6
- uses: pnpm/action-setup@v4
- uses: pnpm/action-setup@v6

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Verify mutable action refs under .github (tag-based refs like `@v1/`@v6).
# Expected: no matches after SHA pinning.
rg -n --iglob '*.yml' --iglob '*.yaml' 'uses:\s*[^@[:space:]]+@v[0-9]+(\.[0-9]+){0,2}\b' .github

Repository: ProverCoderAI/openapi-effect

Length of output: 1009


Pin pnpm/action-setup to a commit SHA instead of a mutable tag.

Line 15 uses @v6, which is a mutable tag reference. Per GitHub's security hardening guidelines, action references should be pinned to full commit SHAs to ensure immutability and prevent unintended updates from tag rewrites.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/checking-dependencies.yml at line 15, Replace the mutable
tag reference "uses: pnpm/action-setup@v6" with an immutable pin to the full
commit SHA for the pnpm/action-setup action (e.g., "uses:
pnpm/action-setup@<full-commit-sha>"); locate the occurrences of
"pnpm/action-setup@v6" in the workflow and update them to the corresponding
release commit SHA from the action's repository, then verify the workflow runs
successfully.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@package.json`:
- Line 6: The package.json currently sets "packageManager": "pnpm@11.1.2" but
pnpm v11 requires config and environment changes; run the recommended codemod
(pnpx codemod run pnpm-v10-to-v11) and then: move any settings under the
package.json "pnpm" field into pnpm-workspace.yaml, strip .npmrc to only
auth/registry entries, update .nvmrc and CI to Node.js 22+ to match pnpm v11,
rename any environment variables from npm_config_* to pnpm_config_ and manually
review remaining envs, and rename or invoke scripts named
clean/setup/deploy/rebuild using pnpm pm to avoid shadowing built-ins.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 78ded05a-1811-4eac-8349-84f29cb8618e

📥 Commits

Reviewing files that changed from the base of the PR and between 6898c52 and 57c74f4.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • .github/actions/setup/action.yml
  • .github/workflows/checking-dependencies.yml
  • .github/workflows/snapshot.yml
  • package.json
  • packages/app/package.json
🚧 Files skipped from review as they are similar to previous changes (4)
  • .github/actions/setup/action.yml
  • .github/workflows/checking-dependencies.yml
  • .github/workflows/snapshot.yml
  • packages/app/package.json

Comment thread package.json Outdated
"private": true,
"description": "Monorepo workspace for effect-template",
"packageManager": "pnpm@10.30.1",
"packageManager": "pnpm@11.1.2",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

🧩 Analysis chain

🌐 Web query:

pnpm 11 breaking changes and migration guide

💡 Result:

pnpm 11 is a major release that introduces significant breaking changes, security-first defaults, and architectural improvements [1]. The official migration guide is available at https://pnpm.io/11.x/migration [2]. Key Breaking Changes and Migration Steps Configuration Changes pnpm 11 significantly changes how configuration is handled [3][1]: - Configuration is no longer read from the pnpm field in package.json; move these settings to pnpm-workspace.yaml [3][2]. -.npmrc files are now restricted to auth and registry settings only [3][1]. All other settings (e.g., hoist-pattern, node-linker) must be moved to pnpm-workspace.yaml using camelCase keys [3][2]. - npm_config_* environment variables are no longer supported; rename them to pnpm_config_* [3][1]. - pnpm no longer reads npm's global config at $PREFIX/etc/npmrc [1]. Dependency and Script Management - Build-dependency settings (onlyBuiltDependencies, neverBuiltDependencies, etc.) are consolidated into a single allowBuilds map in pnpm-workspace.yaml [3][1]. - Package manager strictness settings are collapsed into a single pmOnFail setting [3][2]. - Script names now shadow built-in commands [3]. If you have scripts named clean, setup, deploy, or rebuild, pnpm will execute your script instead of the built-in command; use pnpm pm to access the built-in version [3]. - pnpm install -g (with no arguments) is no longer supported; use pnpm add -g instead [3][1]. Environment and Infrastructure - Node.js 18, 19, 20, and 21 are no longer supported; Node.js 22+ is required [1]. - pnpm is now distributed as pure ESM [1]. - Global installs are now isolated using a global-virtual-store, preventing interference between global packages [1]. Security and New Features - Minimum Release Age: By default, pnpm 11 blocks the installation of package versions published within the last 24 hours to mitigate supply chain attacks [4][5][6]. - Exotic Subdependencies: pnpm 11 blocks dependencies resolved from non-standard sources (e.g., Git repositories or direct tarball URLs) by default [4][6]. - Native Publish: The npm CLI fallback for publishing has been removed in favor of a native implementation [1]. - Store Index: The store index has been migrated from a JSON-per-package format to a single SQLite database for improved performance [1][5]. Migration Tooling The pnpm team provides a codemod to automate many of these changes [2]. You can run it in your project directory: pnpx codemod run pnpm-v10-to-v11 [2] For changes that cannot be automated, such as environment variable updates, manual review is required [3][2].

Citations:


🌐 Web query:

pnpm 11.1.2 release notes and security advisories

💡 Result:

As of May 17, 2026, pnpm version 11.1.2 is the latest release [1]. Release Notes for pnpm 11.1.2 Specific release notes for version 11.1.2 were not explicitly detailed in the provided search results, as it is a very recent patch release [1]. However, it follows the major 11.1.0 and 11.1.1 releases, which introduced several significant features and fixes [2][3][4]: - New Commands: Added pnpm audit signatures (to verify ECDSA registry signatures), pnpm bugs (to open package bug trackers), and pnpm owner (to manage package owners) [3][4]. - Named Registries: Added support for installing packages from arbitrary named registries, including a built-in gh: prefix for the GitHub Packages npm registry [3][4]. - CI Improvements: Introduced the --no-runtime flag (config: runtime=false) to skip installing runtime entries (e.g., Node.js) in CI environments [3][4]. - Fixes: Version 11.1.1 included fixes for installability validation in workspace projects, resolved issues with pnpm add for named registries, and updated @zkochan/cmd-shim to improve compatibility with Git Bash on Windows [2]. Security Advisories There are no specific security advisories listed for version 11.1.2. Users should monitor the official pnpm GitHub Security Advisories page for any future disclosures [5]. Recent security-related updates in the pnpm 11 series include: - Minimum Release Age: pnpm 11 introduced a default Minimum Release Age of 24 hours (1440 minutes), which prevents the installation of newly published package versions to mitigate supply chain attacks [6][7][8]. - Enhanced Auditing: pnpm audit now queries the registry's bulk security advisories endpoint and filters by GitHub Advisory ID (GHSA) rather than CVE identifiers [9]. - Security Hardening: pnpm 11 requires Node.js 22+ and is distributed as pure ESM [10][11]. It also includes improved control over lifecycle scripts via the allowBuilds model [7][8]. For the most up-to-date information, always check the official pnpm releases page on GitHub and the security advisories section [12][5].

Citations:


Review pnpm 11 migration requirements before merging.

This major version upgrade introduces breaking changes that require configuration updates and environment adjustments:

  • Configuration files: Settings in package.json's pnpm field must move to pnpm-workspace.yaml. Update .npmrc to contain only auth and registry settings.
  • Node.js requirement: pnpm 11 requires Node.js 22+. Verify your project's .nvmrc and CI configuration specify a compatible version.
  • Environment variables: Any npm_config_* variables must be renamed to pnpm_config_*.
  • Script behavior: Scripts named clean, setup, deploy, or rebuild now shadow built-in commands; use pnpm pm to access built-in versions.

Run the migration codemod to automate configuration changes:

pnpx codemod run pnpm-v10-to-v11

Refer to https://pnpm.io/11.x/migration for the complete migration guide. Manual review is needed for environment variable updates that the codemod cannot automate.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@package.json` at line 6, The package.json currently sets "packageManager":
"pnpm@11.1.2" but pnpm v11 requires config and environment changes; run the
recommended codemod (pnpx codemod run pnpm-v10-to-v11) and then: move any
settings under the package.json "pnpm" field into pnpm-workspace.yaml, strip
.npmrc to only auth/registry entries, update .nvmrc and CI to Node.js 22+ to
match pnpm v11, rename any environment variables from npm_config_* to
pnpm_config_ and manually review remaining envs, and rename or invoke scripts
named clean/setup/deploy/rebuild using pnpm pm to avoid shadowing built-ins.

@skulidropek

Copy link
Copy Markdown
Member

Надо смержить сюда main ветку и исправить все ошибки в CI/CD что бы код был с актуальными библиотеками

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🤖 AI Work Session Started

Starting automated work session at 2026-06-19T19:17:51.406Z

The PR has been converted to draft mode while work is in progress.

This comment marks the beginning of an AI work session. Please wait for the session to finish, and provide your feedback.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

Update: the CI/CD fix is implemented and verified, but I cannot push it directly to this PR head branch.

Blocker:

  • PR fix(deps): update all dependencies #20 head is ProverCoderAI/openapi-effect:renovate/all.
  • Current GitHub credentials are konard and git push upstream renovate/all fails with 403 Permission to ProverCoderAI/openapi-effect.git denied to konard.

Prepared fix:

  • Commit: b16eac4b7948745fcd49d07e270b92f77b0ccb7d (fix(ci): adapt renovate update to pnpm 11)
  • Branch with the commit: konard/ProverCoderAI-openapi-effect:renovate/all

What the fix covers:

  • merged main into renovate/all locally;
  • moved pnpm 11 config from package.json#pnpm into pnpm-workspace.yaml and kept release-age policy with exact excludes;
  • pinned pnpm/action-setup to full SHA 0ebf47130e4866e96fce0953f49152a61190b271 (v6.0.9);
  • updated CI Node runtime to 24.17.0 so pnpm 11 can load node:sqlite;
  • fixed TypeScript 6/lint fallout while preserving legacy public aliases;
  • added consumer compile proof for the legacy serializer aliases.

Verification:

Needed human action: either grant/push access to ProverCoderAI/openapi-effect:renovate/all, or cherry-pick b16eac4b7948745fcd49d07e270b92f77b0ccb7d from the fork branch into the PR head branch.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🤖 Solution Draft Log

This log file contains the complete execution trace of the AI solution draft process.

💰 Cost estimation:

  • Model: GPT-5.5
  • Provider: OpenAI
  • Public pricing estimate: $21.304392

📊 Context and tokens usage:

  • 508.9K / 200K (254%) input tokens, 68.4K / 128K (53%) output tokens

Total: (508.9K + 13.1M cached) input tokens, 68.4K output tokens, $21.304392 cost

🤖 Models used:

  • Tool: OpenAI Codex
  • Requested: gpt-5.5
  • Thinking level: max (~31999 tokens)
  • Model: GPT-5.5 (gpt-5.5)

📎 Log file uploaded as Repository (75696KB)


Now working session is ended, feel free to review and add any feedback on the solution draft.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart triggered (iteration 1)

Reason: CI failures detected

Starting new session to address the issues.


Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

Rechecked the failing CI/CD status in this restart session.

Findings:

  • Latest upstream PR runs are still for old SHA 48c4a8472fb0d70d3d48c14f5963a2d421a90ec7 from 2026-06-19T13:11:52Z.
  • Logs saved locally during investigation show the failures are from pnpm 11 running on Node 20.16.0 / 22.12.0 and from pnpm 11 ignoring package.json#pnpm, causing minimumReleaseAge violations.
  • The prepared fix commit is still b16eac4b7948745fcd49d07e270b92f77b0ccb7d on konard/ProverCoderAI-openapi-effect:renovate/all.

Verification repeated locally with Node 24.17.0 and pnpm 11.8.0:

  • pnpm install --frozen-lockfile
  • pnpm check
  • pnpm build
  • pnpm lint:effect
  • pnpm lint
  • pnpm test
  • pnpm --filter @prover-coder-ai/openapi-effect test:consumer
  • pnpm dlx @prover-coder-ai/dist-deps-prune scan --package ./packages/app/package.json --prune-dev true --silent
  • snapshot fallback artifact check via npm pack

Fork CI also has successful runs for b16eac4: Check 27845776274, Checking Dependencies 27845776279.

Remaining blocker is repository permissions, not code: git push upstream renovate/all still fails with 403 Permission to ProverCoderAI/openapi-effect.git denied to konard. Please either grant push access to ProverCoderAI/openapi-effect:renovate/all or cherry-pick/push b16eac4b7948745fcd49d07e270b92f77b0ccb7d from the fork branch into the upstream PR head branch.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart-until-mergeable Log (iteration 1)

This log file contains the complete execution trace of the AI solution draft process.

💰 Cost estimation:

  • Model: GPT-5.5
  • Provider: OpenAI
  • Public pricing estimate: $4.197492
  • Token usage: 93,621 input, 17,194 output, 5,819 reasoning, 2,487,552 cache read

🤖 Models used:

  • Tool: OpenAI Codex
  • Requested: gpt-5.5
  • Model: GPT-5.5 (gpt-5.5)

📎 Log file uploaded as Repository (96784KB)


Now working session is ended, feel free to review and add any feedback on the solution draft.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart triggered (iteration 2)

Reason: CI failures detected

Starting new session to address the issues.


Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations.

@konard

konard commented Jun 19, 2026 •

Copy link
Copy Markdown
Contributor

Rechecked and updated the prepared fix in this restart session.

Current prepared commit:

  • b52bed11666e71930f1d563062826936f36fd5f3 on konard/ProverCoderAI-openapi-effect:renovate/all
  • This includes the earlier CI/pnpm 11 fix plus a small follow-up commit fix(app): satisfy strict type lint example so lint:types also passes.

Root causes confirmed from upstream CI logs for old SHA 48c4a8472fb0d70d3d48c14f5963a2d421a90ec7:

  • Check/Snapshot: pnpm 11 ran under an old Node runtime and failed on node:sqlite / Node >= 22.13 requirement.
  • dist-deps-prune: pnpm 11 minimum release age policy rejected fresh lockfile entries.

Verification on current SHA b52bed1:

  • Local with Node 24.17.0 and pnpm 11.8.0: pnpm install --frozen-lockfile, pnpm check, pnpm build, pnpm lint, pnpm lint:effect, pnpm test, pnpm lint:tests, pnpm --filter @prover-coder-ai/openapi-effect lint:types, pnpm --filter @prover-coder-ai/openapi-effect test:consumer, pnpm dlx @prover-coder-ai/dist-deps-prune scan --package ./packages/app/package.json --prune-dev true --silent, and package pack check all passed.
  • Fork CI Check passed: https://github.com/konard/ProverCoderAI-openapi-effect/actions/runs/27846721442
  • Fork CI Checking Dependencies passed: https://github.com/konard/ProverCoderAI-openapi-effect/actions/runs/27846721454
  • Fork Snapshot is skipped by the workflow owner guard (github.repository_owner == 'ProverCoderAI'); the equivalent local pnpm build plus fallback npm pack artifact path passed.

Remaining blocker is repository permission, not code. git push upstream renovate/all still fails with:

remote: Permission to ProverCoderAI/openapi-effect.git denied to konard.
fatal: unable to access 'https://github.com/ProverCoderAI/openapi-effect.git/': The requested URL returned error: 403

Needed maintainer action: push/cherry-pick b52bed11666e71930f1d563062826936f36fd5f3 from the fork branch into ProverCoderAI/openapi-effect:renovate/all. Until that happens, PR #20 remains on the old upstream head SHA 48c4a8472fb0d70d3d48c14f5963a2d421a90ec7 and will keep showing stale failing checks.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart-until-mergeable Log (iteration 2)

This log file contains the complete execution trace of the AI solution draft process.

💰 Cost estimation:

  • Model: GPT-5.5
  • Provider: OpenAI
  • Public pricing estimate: $4.788024
  • Token usage: 95,677 input, 18,030 output, 5,431 reasoning, 3,019,904 cache read

🤖 Models used:

  • Tool: OpenAI Codex
  • Requested: gpt-5.5
  • Model: GPT-5.5 (gpt-5.5)

📎 Log file uploaded as Repository (2 chunks) (116514KB)


Now working session is ended, feel free to review and add any feedback on the solution draft.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart triggered (iteration 3)

Reason: CI failures detected

Starting new session to address the issues.


Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations.

@konard

konard commented Jun 19, 2026 •

Copy link
Copy Markdown
Contributor

Restart iteration 3 rechecked the prepared CI fix.

Current verified head:

  • b52bed11666e71930f1d563062826936f36fd5f3 on konard/ProverCoderAI-openapi-effect:renovate/all
  • Local branch includes upstream/main via merge commit f43684a.
  • PR fix(deps): update all dependencies #20 still points to ProverCoderAI/openapi-effect:renovate/all@48c4a8472fb0d70d3d48c14f5963a2d421a90ec7, so its failing checks are stale for the old head.

Fresh upstream CI logs downloaded in this session confirm old-head root causes:

  • Check: pnpm 11 under Node 20.16.0 fails on node:sqlite / Node >= 22.13 requirement.
  • Snapshot: pnpm 11 under Node 22.12.0 fails the Node >= 22.13 requirement.
  • Checking Dependencies: pnpm 11 ignores package.json#pnpm and then fails minimumReleaseAge for the refreshed lockfile entries.

Verification repeated on b52bed1 with Node 24.17.0 and pnpm 11.8.0:

  • pnpm install --frozen-lockfile
  • pnpm check
  • pnpm build
  • pnpm lint
  • pnpm lint:effect
  • pnpm test
  • pnpm lint:tests
  • pnpm --filter @prover-coder-ai/openapi-effect lint:types
  • pnpm --filter @prover-coder-ai/openapi-effect test:consumer
  • pnpm dlx @prover-coder-ai/dist-deps-prune scan --package ./packages/app/package.json --prune-dev true --silent
  • snapshot fallback npm pack artifact path

Push blocker remains external:
git push upstream HEAD:renovate/all fails with 403 Permission to ProverCoderAI/openapi-effect.git denied to konard.

Needed maintainer action: push or cherry-pick b52bed11666e71930f1d563062826936f36fd5f3 from the fork branch into ProverCoderAI/openapi-effect:renovate/all.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart-until-mergeable Log (iteration 3)

This log file contains the complete execution trace of the AI solution draft process.

💰 Cost estimation:

  • Model: GPT-5.5
  • Provider: OpenAI
  • Public pricing estimate: $4.433867
  • Token usage: 92,361 input, 16,725 output, 5,362 reasoning, 2,757,632 cache read

🤖 Models used:

  • Tool: OpenAI Codex
  • Requested: gpt-5.5
  • Model: GPT-5.5 (gpt-5.5)

📎 Log file uploaded as Repository (2 chunks) (139990KB)


Now working session is ended, feel free to review and add any feedback on the solution draft.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart triggered (iteration 4)

Reason: CI failures detected

Starting new session to address the issues.


Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

Restart iteration 4 rechecked the CI/CD fix.

Current verified head:

  • b52bed11666e71930f1d563062826936f36fd5f3 on konard/ProverCoderAI-openapi-effect:renovate/all
  • upstream/main is merged into this branch.
  • PR fix(deps): update all dependencies #20 upstream head is still ProverCoderAI/openapi-effect:renovate/all@48c4a8472fb0d70d3d48c14f5963a2d421a90ec7, so the visible failing checks are still for the old head.

Fresh upstream logs downloaded in this session confirm the old-head failures:

  • Check: pnpm 11 runs under Node 20.16.0 and fails on node:sqlite / Node >= 22.13.
  • Snapshot: pnpm 11 runs under Node 22.12.0 and fails the Node >= 22.13 requirement.
  • Checking Dependencies: pnpm 11 rejects fresh lockfile entries through minimumReleaseAge.

Verification repeated locally on b52bed1 with Node 24.17.0 and pnpm 11.8.0:

  • pnpm install --frozen-lockfile
  • pnpm check
  • pnpm build
  • pnpm lint
  • pnpm lint:effect
  • pnpm test
  • pnpm lint:tests
  • pnpm --filter @prover-coder-ai/openapi-effect lint:types
  • pnpm --filter @prover-coder-ai/openapi-effect test:consumer
  • pnpm dlx @prover-coder-ai/dist-deps-prune scan --package ./packages/app/package.json --prune-dev true --silent
  • snapshot fallback artifact check via npm pack

Push status:

  • git push origin HEAD:renovate/all: up to date.
  • git push upstream HEAD:renovate/all: blocked with 403 Permission to ProverCoderAI/openapi-effect.git denied to konard.

Needed maintainer action: push or cherry-pick b52bed11666e71930f1d563062826936f36fd5f3 from konard/ProverCoderAI-openapi-effect:renovate/all into ProverCoderAI/openapi-effect:renovate/all. Until then PR #20 cannot receive fresh CI for the verified fix.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart-until-mergeable Log (iteration 4)

This log file contains the complete execution trace of the AI solution draft process.

💰 Cost estimation:

  • Model: GPT-5.5
  • Provider: OpenAI
  • Public pricing estimate: $4.654120
  • Token usage: 127,152 input, 17,640 output, 5,582 reasoning, 2,588,800 cache read

🤖 Models used:

  • Tool: OpenAI Codex
  • Requested: gpt-5.5
  • Model: GPT-5.5 (gpt-5.5)

📎 Log file uploaded as Repository (2 chunks) (154923KB)


Now working session is ended, feel free to review and add any feedback on the solution draft.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart triggered (iteration 5)

Reason: CI failures detected

Starting new session to address the issues.


Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

Restart iteration 5 rechecked the CI/CD failures and the prepared fix.

Current verified fix:

  • b52bed11666e71930f1d563062826936f36fd5f3 on konard/ProverCoderAI-openapi-effect:renovate/all
  • This branch includes upstream/main and has origin/renovate/all up to date.

Fresh upstream CI status:

  • PR fix(deps): update all dependencies #20 still points to ProverCoderAI/openapi-effect:renovate/all@48c4a8472fb0d70d3d48c14f5963a2d421a90ec7.
  • Latest upstream runs are still from 2026-06-19T13:11:52Z for that old SHA:
    • Check 27827776411: failure
    • Checking Dependencies 27827776440: failure
    • Snapshot 27827776423: failure

Root causes confirmed from downloaded upstream logs:

  • Check jobs (Build, Types, Lint, Lint Effect-TS, Test) fail before project code because pnpm 11 runs under Node 20.16.0 and errors with No such built-in module: node:sqlite / Node >= 22.13 requirement.
  • Snapshot fails for the same pnpm 11 runtime requirement under Node 22.12.0.
  • dist-deps-prune fails with ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION for effect@3.21.4, eslint-plugin-sonarjs@4.1.0, and eslint-plugin-unicorn@68.0.0.

Verification repeated locally on b52bed1 with Node 24.17.0 and pnpm 11.8.0:

  • pnpm install --frozen-lockfile
  • pnpm check
  • pnpm build
  • pnpm lint
  • pnpm lint:effect
  • pnpm test
  • pnpm lint:tests
  • pnpm --filter @prover-coder-ai/openapi-effect lint:types
  • pnpm --filter @prover-coder-ai/openapi-effect test:consumer
  • pnpm dlx @prover-coder-ai/dist-deps-prune scan --package ./packages/app/package.json --prune-dev true --silent
  • snapshot fallback artifact path via npm pack

Fork CI on b52bed1:

Push status:

  • git push origin HEAD:renovate/all: up to date.
  • git push upstream HEAD:renovate/all: blocked with 403 Permission to ProverCoderAI/openapi-effect.git denied to konard.

Needed maintainer action: push or cherry-pick b52bed11666e71930f1d563062826936f36fd5f3 from konard/ProverCoderAI-openapi-effect:renovate/all into ProverCoderAI/openapi-effect:renovate/all. Until that upstream PR head moves off 48c4a84, the visible PR checks remain stale failures for the old commit.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart-until-mergeable Log (iteration 5)

This log file contains the complete execution trace of the AI solution draft process.

💰 Cost estimation:

  • Model: GPT-5.5
  • Provider: OpenAI
  • Public pricing estimate: $4.888533
  • Token usage: 166,658 input, 16,101 output, 4,054 reasoning, 2,497,408 cache read

🤖 Models used:

  • Tool: OpenAI Codex
  • Requested: gpt-5.5
  • Model: GPT-5.5 (gpt-5.5)

📎 Log file uploaded as Repository (2 chunks) (177139KB)


Now working session is ended, feel free to review and add any feedback on the solution draft.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

⚠️ Auto-restart limit reached

Hive Mind stopped auto-restart-until-mergeable after 5 restart iterations.

Configured limit: 5
Remaining reason: CI failures detected

No further AI sessions will be started automatically for this run. Please review the remaining blockers manually or rerun with a higher --auto-restart-max-iterations value.


Auto-restart-until-mergeable stopped by the safety limit.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🤖 AI Work Session Completed

Work session ended at 2026-06-19T20:58:19.771Z

The PR will be converted back to ready for review.

This comment marks the end of an AI work session. New comments after this time will be considered as feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants