⬆️ Upgrade Biome to the latest version - #1861

Merged
alejsdev merged 14 commits into
masterfrom
upgrade-biome
Sep 9, 2025
Merged

⬆️ Upgrade Biome to the latest version#1861
alejsdev merged 14 commits into
masterfrom
upgrade-biome

Conversation

@alejsdev

@alejsdevalejsdev commented Sep 8, 2025

Copy link
Copy Markdown
Member

⬆️ Upgrade Biome to the latest version

Also included fix proposed in #1833 (to exclude dist and src/client)

Closes#1858

@alejsdev
alejsdev marked this pull request as ready for review September 8, 2025 15:36
@alejsdevalejsdev changed the title ⬆️ Upgrade Biome⬆️ Upgrade Biome to the latest versionSep 8, 2025
@alejsdevalejsdev mentioned this pull request Sep 8, 2025
@alexrockhill

alexrockhill commented Sep 8, 2025

Copy link
Copy Markdown
Contributor
$ npm install
added 101 packages, removed 21 packages, changed 66 packages, and audited 424 packages in 2s
72 packages are looking for funding
run `npm fund` for details
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
full-stack-fastapi-template/frontend$ npm audit
# npm audit report
is-arrayish *
Severity: critical
Malware in is-arrayish - https://github.com/advisories/GHSA-hfm8-9jrf-7g9w
fix available via `npm audit fix --force`
Will install @emotion/react@11.7.1, which is a breaking change
node_modules/is-arrayish
error-ex >=1.3.0
Depends on vulnerable versions of is-arrayish
node_modules/error-ex
parse-json 3.0.0 - 7.1.1
Depends on vulnerable versions of error-ex
node_modules/parse-json
cosmiconfig >=3.0.1
Depends on vulnerable versions of parse-json
node_modules/cosmiconfig
babel-plugin-macros >=2.0.0
Depends on vulnerable versions of cosmiconfig
node_modules/babel-plugin-macros
@emotion/babel-plugin *
Depends on vulnerable versions of babel-plugin-macros
node_modules/@emotion/babel-plugin
@emotion/react >=11.8.0
Depends on vulnerable versions of @emotion/babel-plugin
node_modules/@emotion/react
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force

FYI

"@emotion/react": "<11.8.0",

fixes it in the package.json

@alejsdev

Copy link
Copy Markdown
MemberAuthor
$ npm install
added 101 packages, removed 21 packages, changed 66 packages, and audited 424 packages in 2s
72 packages are looking for funding
run `npm fund` for details
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
full-stack-fastapi-template/frontend$ npm audit
# npm audit report
is-arrayish *
Severity: critical
Malware in is-arrayish - https://github.com/advisories/GHSA-hfm8-9jrf-7g9w
fix available via `npm audit fix --force`
Will install @emotion/react@11.7.1, which is a breaking change
node_modules/is-arrayish
error-ex >=1.3.0
Depends on vulnerable versions of is-arrayish
node_modules/error-ex
parse-json 3.0.0 - 7.1.1
Depends on vulnerable versions of error-ex
node_modules/parse-json
cosmiconfig >=3.0.1
Depends on vulnerable versions of parse-json
node_modules/cosmiconfig
babel-plugin-macros >=2.0.0
Depends on vulnerable versions of cosmiconfig
node_modules/babel-plugin-macros
@emotion/babel-plugin *
Depends on vulnerable versions of babel-plugin-macros
node_modules/@emotion/babel-plugin
@emotion/react >=11.8.0
Depends on vulnerable versions of @emotion/babel-plugin
node_modules/@emotion/react
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force

FYI

"@emotion/react": "<11.8.0",

fixes it in the package.json

I cannot replicate it. Have you pulled the latest changes from master? Several upgrades were made recently.
In this branch with the latest changes, I found 0 vulnerabilities.

@alexrockhill

Copy link
Copy Markdown
Contributor

I'm not able to replicate now either, maybe it's yanked already, it was posted 3 hours ago

Comment threadfrontend/biome.json Outdated
Comment threadfrontend/biome.json Outdated
Comment threadfrontend/biome.json Outdated
Comment threadscripts/generate-client.sh Outdated
Comment threadfrontend/src/client/core/request.ts
@alejsdev
alejsdev merged commit f813161 into masterSep 9, 2025
17 checks passed
@alejsdev
alejsdev deleted the upgrade-biome branch September 9, 2025 12:45
jpizquierdo pushed a commit to jpizquierdo/full-stack-fastapi-template that referenced this pull request Sep 24, 2025
rajdavee pushed a commit to OrganyzAI/python-backend that referenced this pull request Dec 30, 2025
azzi2023 pushed a commit to azzi2023/organyz-python-backend that referenced this pull request Jan 9, 2026
BraidaFac pushed a commit to BraidaFac/insurance-broker-api that referenced this pull request Apr 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@alejsdev@alexrockhill@YuriiMotov@tiangolo
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

⬆️ Upgrade Biome to the latest version - #1861

Merged
alejsdev merged 14 commits into
masterfrom
upgrade-biome
Sep 9, 2025
Merged

⬆️ Upgrade Biome to the latest version#1861
alejsdev merged 14 commits into
masterfrom
upgrade-biome

Conversation

@alejsdev

@alejsdevalejsdev commented Sep 8, 2025

Copy link
Copy Markdown
Member

⬆️ Upgrade Biome to the latest version

Also included fix proposed in #1833 (to exclude dist and src/client)

Closes#1858

@alejsdev
alejsdev marked this pull request as ready for review September 8, 2025 15:36
@alejsdevalejsdev changed the title ⬆️ Upgrade Biome⬆️ Upgrade Biome to the latest versionSep 8, 2025
@alejsdevalejsdev mentioned this pull request Sep 8, 2025
@alexrockhill

alexrockhill commented Sep 8, 2025

Copy link
Copy Markdown
Contributor
$ npm install
added 101 packages, removed 21 packages, changed 66 packages, and audited 424 packages in 2s
72 packages are looking for funding
run `npm fund` for details
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
full-stack-fastapi-template/frontend$ npm audit
# npm audit report
is-arrayish *
Severity: critical
Malware in is-arrayish - https://github.com/advisories/GHSA-hfm8-9jrf-7g9w
fix available via `npm audit fix --force`
Will install @emotion/react@11.7.1, which is a breaking change
node_modules/is-arrayish
error-ex >=1.3.0
Depends on vulnerable versions of is-arrayish
node_modules/error-ex
parse-json 3.0.0 - 7.1.1
Depends on vulnerable versions of error-ex
node_modules/parse-json
cosmiconfig >=3.0.1
Depends on vulnerable versions of parse-json
node_modules/cosmiconfig
babel-plugin-macros >=2.0.0
Depends on vulnerable versions of cosmiconfig
node_modules/babel-plugin-macros
@emotion/babel-plugin *
Depends on vulnerable versions of babel-plugin-macros
node_modules/@emotion/babel-plugin
@emotion/react >=11.8.0
Depends on vulnerable versions of @emotion/babel-plugin
node_modules/@emotion/react
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force

FYI

"@emotion/react": "<11.8.0",

fixes it in the package.json

@alejsdev

Copy link
Copy Markdown
MemberAuthor
$ npm install
added 101 packages, removed 21 packages, changed 66 packages, and audited 424 packages in 2s
72 packages are looking for funding
run `npm fund` for details
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
full-stack-fastapi-template/frontend$ npm audit
# npm audit report
is-arrayish *
Severity: critical
Malware in is-arrayish - https://github.com/advisories/GHSA-hfm8-9jrf-7g9w
fix available via `npm audit fix --force`
Will install @emotion/react@11.7.1, which is a breaking change
node_modules/is-arrayish
error-ex >=1.3.0
Depends on vulnerable versions of is-arrayish
node_modules/error-ex
parse-json 3.0.0 - 7.1.1
Depends on vulnerable versions of error-ex
node_modules/parse-json
cosmiconfig >=3.0.1
Depends on vulnerable versions of parse-json
node_modules/cosmiconfig
babel-plugin-macros >=2.0.0
Depends on vulnerable versions of cosmiconfig
node_modules/babel-plugin-macros
@emotion/babel-plugin *
Depends on vulnerable versions of babel-plugin-macros
node_modules/@emotion/babel-plugin
@emotion/react >=11.8.0
Depends on vulnerable versions of @emotion/babel-plugin
node_modules/@emotion/react
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force

FYI

"@emotion/react": "<11.8.0",

fixes it in the package.json

I cannot replicate it. Have you pulled the latest changes from master? Several upgrades were made recently.
In this branch with the latest changes, I found 0 vulnerabilities.

@alexrockhill

Copy link
Copy Markdown
Contributor

I'm not able to replicate now either, maybe it's yanked already, it was posted 3 hours ago

Comment threadfrontend/biome.json Outdated
Comment threadfrontend/biome.json Outdated
Comment threadfrontend/biome.json Outdated
Comment threadscripts/generate-client.sh Outdated
Comment threadfrontend/src/client/core/request.ts
@alejsdev
alejsdev merged commit f813161 into masterSep 9, 2025
17 checks passed
@alejsdev
alejsdev deleted the upgrade-biome branch September 9, 2025 12:45
jpizquierdo pushed a commit to jpizquierdo/full-stack-fastapi-template that referenced this pull request Sep 24, 2025
rajdavee pushed a commit to OrganyzAI/python-backend that referenced this pull request Dec 30, 2025
azzi2023 pushed a commit to azzi2023/organyz-python-backend that referenced this pull request Jan 9, 2026
BraidaFac pushed a commit to BraidaFac/insurance-broker-api that referenced this pull request Apr 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@alejsdev@alexrockhill@YuriiMotov@tiangolo
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

⬆️ Upgrade Biome to the latest version - #1861

Merged
alejsdev merged 14 commits into
masterfrom
upgrade-biome
Sep 9, 2025
Merged

⬆️ Upgrade Biome to the latest version#1861
alejsdev merged 14 commits into
masterfrom
upgrade-biome

Conversation

@alejsdev

@alejsdevalejsdev commented Sep 8, 2025

Copy link
Copy Markdown
Member

⬆️ Upgrade Biome to the latest version

Also included fix proposed in #1833 (to exclude dist and src/client)

Closes#1858

@alejsdev
alejsdev marked this pull request as ready for review September 8, 2025 15:36
@alejsdevalejsdev changed the title ⬆️ Upgrade Biome⬆️ Upgrade Biome to the latest versionSep 8, 2025
@alejsdevalejsdev mentioned this pull request Sep 8, 2025
@alexrockhill

alexrockhill commented Sep 8, 2025

Copy link
Copy Markdown
Contributor
$ npm install
added 101 packages, removed 21 packages, changed 66 packages, and audited 424 packages in 2s
72 packages are looking for funding
run `npm fund` for details
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
full-stack-fastapi-template/frontend$ npm audit
# npm audit report
is-arrayish *
Severity: critical
Malware in is-arrayish - https://github.com/advisories/GHSA-hfm8-9jrf-7g9w
fix available via `npm audit fix --force`
Will install @emotion/react@11.7.1, which is a breaking change
node_modules/is-arrayish
error-ex >=1.3.0
Depends on vulnerable versions of is-arrayish
node_modules/error-ex
parse-json 3.0.0 - 7.1.1
Depends on vulnerable versions of error-ex
node_modules/parse-json
cosmiconfig >=3.0.1
Depends on vulnerable versions of parse-json
node_modules/cosmiconfig
babel-plugin-macros >=2.0.0
Depends on vulnerable versions of cosmiconfig
node_modules/babel-plugin-macros
@emotion/babel-plugin *
Depends on vulnerable versions of babel-plugin-macros
node_modules/@emotion/babel-plugin
@emotion/react >=11.8.0
Depends on vulnerable versions of @emotion/babel-plugin
node_modules/@emotion/react
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force

FYI

"@emotion/react": "<11.8.0",

fixes it in the package.json

@alejsdev

Copy link
Copy Markdown
MemberAuthor
$ npm install
added 101 packages, removed 21 packages, changed 66 packages, and audited 424 packages in 2s
72 packages are looking for funding
run `npm fund` for details
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
full-stack-fastapi-template/frontend$ npm audit
# npm audit report
is-arrayish *
Severity: critical
Malware in is-arrayish - https://github.com/advisories/GHSA-hfm8-9jrf-7g9w
fix available via `npm audit fix --force`
Will install @emotion/react@11.7.1, which is a breaking change
node_modules/is-arrayish
error-ex >=1.3.0
Depends on vulnerable versions of is-arrayish
node_modules/error-ex
parse-json 3.0.0 - 7.1.1
Depends on vulnerable versions of error-ex
node_modules/parse-json
cosmiconfig >=3.0.1
Depends on vulnerable versions of parse-json
node_modules/cosmiconfig
babel-plugin-macros >=2.0.0
Depends on vulnerable versions of cosmiconfig
node_modules/babel-plugin-macros
@emotion/babel-plugin *
Depends on vulnerable versions of babel-plugin-macros
node_modules/@emotion/babel-plugin
@emotion/react >=11.8.0
Depends on vulnerable versions of @emotion/babel-plugin
node_modules/@emotion/react
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force

FYI

"@emotion/react": "<11.8.0",

fixes it in the package.json

I cannot replicate it. Have you pulled the latest changes from master? Several upgrades were made recently.
In this branch with the latest changes, I found 0 vulnerabilities.

@alexrockhill

Copy link
Copy Markdown
Contributor

I'm not able to replicate now either, maybe it's yanked already, it was posted 3 hours ago

Comment threadfrontend/biome.json Outdated
Comment threadfrontend/biome.json Outdated
Comment threadfrontend/biome.json Outdated
Comment threadscripts/generate-client.sh Outdated
Comment threadfrontend/src/client/core/request.ts
@alejsdev
alejsdev merged commit f813161 into masterSep 9, 2025
17 checks passed
@alejsdev
alejsdev deleted the upgrade-biome branch September 9, 2025 12:45
jpizquierdo pushed a commit to jpizquierdo/full-stack-fastapi-template that referenced this pull request Sep 24, 2025
rajdavee pushed a commit to OrganyzAI/python-backend that referenced this pull request Dec 30, 2025
azzi2023 pushed a commit to azzi2023/organyz-python-backend that referenced this pull request Jan 9, 2026
BraidaFac pushed a commit to BraidaFac/insurance-broker-api that referenced this pull request Apr 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@alejsdev@alexrockhill@YuriiMotov@tiangolo
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

⬆️ Upgrade Biome to the latest version - #1861

Merged
alejsdev merged 14 commits into
masterfrom
upgrade-biome
Sep 9, 2025
Merged

⬆️ Upgrade Biome to the latest version#1861
alejsdev merged 14 commits into
masterfrom
upgrade-biome

Conversation

@alejsdev

@alejsdevalejsdev commented Sep 8, 2025

Copy link
Copy Markdown
Member

⬆️ Upgrade Biome to the latest version

Also included fix proposed in #1833 (to exclude dist and src/client)

Closes#1858

@alejsdev
alejsdev marked this pull request as ready for review September 8, 2025 15:36
@alejsdevalejsdev changed the title ⬆️ Upgrade Biome⬆️ Upgrade Biome to the latest versionSep 8, 2025
@alejsdevalejsdev mentioned this pull request Sep 8, 2025
@alexrockhill

alexrockhill commented Sep 8, 2025

Copy link
Copy Markdown
Contributor
$ npm install
added 101 packages, removed 21 packages, changed 66 packages, and audited 424 packages in 2s
72 packages are looking for funding
run `npm fund` for details
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
full-stack-fastapi-template/frontend$ npm audit
# npm audit report
is-arrayish *
Severity: critical
Malware in is-arrayish - https://github.com/advisories/GHSA-hfm8-9jrf-7g9w
fix available via `npm audit fix --force`
Will install @emotion/react@11.7.1, which is a breaking change
node_modules/is-arrayish
error-ex >=1.3.0
Depends on vulnerable versions of is-arrayish
node_modules/error-ex
parse-json 3.0.0 - 7.1.1
Depends on vulnerable versions of error-ex
node_modules/parse-json
cosmiconfig >=3.0.1
Depends on vulnerable versions of parse-json
node_modules/cosmiconfig
babel-plugin-macros >=2.0.0
Depends on vulnerable versions of cosmiconfig
node_modules/babel-plugin-macros
@emotion/babel-plugin *
Depends on vulnerable versions of babel-plugin-macros
node_modules/@emotion/babel-plugin
@emotion/react >=11.8.0
Depends on vulnerable versions of @emotion/babel-plugin
node_modules/@emotion/react
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force

FYI

"@emotion/react": "<11.8.0",

fixes it in the package.json

@alejsdev

Copy link
Copy Markdown
MemberAuthor
$ npm install
added 101 packages, removed 21 packages, changed 66 packages, and audited 424 packages in 2s
72 packages are looking for funding
run `npm fund` for details
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
full-stack-fastapi-template/frontend$ npm audit
# npm audit report
is-arrayish *
Severity: critical
Malware in is-arrayish - https://github.com/advisories/GHSA-hfm8-9jrf-7g9w
fix available via `npm audit fix --force`
Will install @emotion/react@11.7.1, which is a breaking change
node_modules/is-arrayish
error-ex >=1.3.0
Depends on vulnerable versions of is-arrayish
node_modules/error-ex
parse-json 3.0.0 - 7.1.1
Depends on vulnerable versions of error-ex
node_modules/parse-json
cosmiconfig >=3.0.1
Depends on vulnerable versions of parse-json
node_modules/cosmiconfig
babel-plugin-macros >=2.0.0
Depends on vulnerable versions of cosmiconfig
node_modules/babel-plugin-macros
@emotion/babel-plugin *
Depends on vulnerable versions of babel-plugin-macros
node_modules/@emotion/babel-plugin
@emotion/react >=11.8.0
Depends on vulnerable versions of @emotion/babel-plugin
node_modules/@emotion/react
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force

FYI

"@emotion/react": "<11.8.0",

fixes it in the package.json

I cannot replicate it. Have you pulled the latest changes from master? Several upgrades were made recently.
In this branch with the latest changes, I found 0 vulnerabilities.

@alexrockhill

Copy link
Copy Markdown
Contributor

I'm not able to replicate now either, maybe it's yanked already, it was posted 3 hours ago

Comment threadfrontend/biome.json Outdated
Comment threadfrontend/biome.json Outdated
Comment threadfrontend/biome.json Outdated
Comment threadscripts/generate-client.sh Outdated
Comment threadfrontend/src/client/core/request.ts
@alejsdev
alejsdev merged commit f813161 into masterSep 9, 2025
17 checks passed
@alejsdev
alejsdev deleted the upgrade-biome branch September 9, 2025 12:45
jpizquierdo pushed a commit to jpizquierdo/full-stack-fastapi-template that referenced this pull request Sep 24, 2025
rajdavee pushed a commit to OrganyzAI/python-backend that referenced this pull request Dec 30, 2025
azzi2023 pushed a commit to azzi2023/organyz-python-backend that referenced this pull request Jan 9, 2026
BraidaFac pushed a commit to BraidaFac/insurance-broker-api that referenced this pull request Apr 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@alejsdev@alexrockhill@YuriiMotov@tiangolo
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

⬆️ Upgrade Biome to the latest version - #1861

Merged
alejsdev merged 14 commits into
masterfrom
upgrade-biome
Sep 9, 2025
Merged

⬆️ Upgrade Biome to the latest version#1861
alejsdev merged 14 commits into
masterfrom
upgrade-biome

Conversation

@alejsdev

@alejsdevalejsdev commented Sep 8, 2025

Copy link
Copy Markdown
Member

⬆️ Upgrade Biome to the latest version

Also included fix proposed in #1833 (to exclude dist and src/client)

Closes#1858

@alejsdev
alejsdev marked this pull request as ready for review September 8, 2025 15:36
@alejsdevalejsdev changed the title ⬆️ Upgrade Biome⬆️ Upgrade Biome to the latest versionSep 8, 2025
@alejsdevalejsdev mentioned this pull request Sep 8, 2025
@alexrockhill

alexrockhill commented Sep 8, 2025

Copy link
Copy Markdown
Contributor
$ npm install
added 101 packages, removed 21 packages, changed 66 packages, and audited 424 packages in 2s
72 packages are looking for funding
run `npm fund` for details
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
full-stack-fastapi-template/frontend$ npm audit
# npm audit report
is-arrayish *
Severity: critical
Malware in is-arrayish - https://github.com/advisories/GHSA-hfm8-9jrf-7g9w
fix available via `npm audit fix --force`
Will install @emotion/react@11.7.1, which is a breaking change
node_modules/is-arrayish
error-ex >=1.3.0
Depends on vulnerable versions of is-arrayish
node_modules/error-ex
parse-json 3.0.0 - 7.1.1
Depends on vulnerable versions of error-ex
node_modules/parse-json
cosmiconfig >=3.0.1
Depends on vulnerable versions of parse-json
node_modules/cosmiconfig
babel-plugin-macros >=2.0.0
Depends on vulnerable versions of cosmiconfig
node_modules/babel-plugin-macros
@emotion/babel-plugin *
Depends on vulnerable versions of babel-plugin-macros
node_modules/@emotion/babel-plugin
@emotion/react >=11.8.0
Depends on vulnerable versions of @emotion/babel-plugin
node_modules/@emotion/react
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force

FYI

"@emotion/react": "<11.8.0",

fixes it in the package.json

@alejsdev

Copy link
Copy Markdown
MemberAuthor
$ npm install
added 101 packages, removed 21 packages, changed 66 packages, and audited 424 packages in 2s
72 packages are looking for funding
run `npm fund` for details
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
full-stack-fastapi-template/frontend$ npm audit
# npm audit report
is-arrayish *
Severity: critical
Malware in is-arrayish - https://github.com/advisories/GHSA-hfm8-9jrf-7g9w
fix available via `npm audit fix --force`
Will install @emotion/react@11.7.1, which is a breaking change
node_modules/is-arrayish
error-ex >=1.3.0
Depends on vulnerable versions of is-arrayish
node_modules/error-ex
parse-json 3.0.0 - 7.1.1
Depends on vulnerable versions of error-ex
node_modules/parse-json
cosmiconfig >=3.0.1
Depends on vulnerable versions of parse-json
node_modules/cosmiconfig
babel-plugin-macros >=2.0.0
Depends on vulnerable versions of cosmiconfig
node_modules/babel-plugin-macros
@emotion/babel-plugin *
Depends on vulnerable versions of babel-plugin-macros
node_modules/@emotion/babel-plugin
@emotion/react >=11.8.0
Depends on vulnerable versions of @emotion/babel-plugin
node_modules/@emotion/react
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force

FYI

"@emotion/react": "<11.8.0",

fixes it in the package.json

I cannot replicate it. Have you pulled the latest changes from master? Several upgrades were made recently.
In this branch with the latest changes, I found 0 vulnerabilities.

@alexrockhill

Copy link
Copy Markdown
Contributor

I'm not able to replicate now either, maybe it's yanked already, it was posted 3 hours ago

Comment threadfrontend/biome.json Outdated
Comment threadfrontend/biome.json Outdated
Comment threadfrontend/biome.json Outdated
Comment threadscripts/generate-client.sh Outdated
Comment threadfrontend/src/client/core/request.ts
@alejsdev
alejsdev merged commit f813161 into masterSep 9, 2025
17 checks passed
@alejsdev
alejsdev deleted the upgrade-biome branch September 9, 2025 12:45
jpizquierdo pushed a commit to jpizquierdo/full-stack-fastapi-template that referenced this pull request Sep 24, 2025
rajdavee pushed a commit to OrganyzAI/python-backend that referenced this pull request Dec 30, 2025
azzi2023 pushed a commit to azzi2023/organyz-python-backend that referenced this pull request Jan 9, 2026
BraidaFac pushed a commit to BraidaFac/insurance-broker-api that referenced this pull request Apr 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@alejsdev@alexrockhill@YuriiMotov@tiangolo
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

⬆️ Upgrade Biome to the latest version - #1861

Merged
alejsdev merged 14 commits into
masterfrom
upgrade-biome
Sep 9, 2025
Merged

⬆️ Upgrade Biome to the latest version#1861
alejsdev merged 14 commits into
masterfrom
upgrade-biome

Conversation

@alejsdev

@alejsdevalejsdev commented Sep 8, 2025

Copy link
Copy Markdown
Member

⬆️ Upgrade Biome to the latest version

Also included fix proposed in #1833 (to exclude dist and src/client)

Closes#1858

@alejsdev
alejsdev marked this pull request as ready for review September 8, 2025 15:36
@alejsdevalejsdev changed the title ⬆️ Upgrade Biome⬆️ Upgrade Biome to the latest versionSep 8, 2025
@alejsdevalejsdev mentioned this pull request Sep 8, 2025
@alexrockhill

alexrockhill commented Sep 8, 2025

Copy link
Copy Markdown
Contributor
$ npm install
added 101 packages, removed 21 packages, changed 66 packages, and audited 424 packages in 2s
72 packages are looking for funding
run `npm fund` for details
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
full-stack-fastapi-template/frontend$ npm audit
# npm audit report
is-arrayish *
Severity: critical
Malware in is-arrayish - https://github.com/advisories/GHSA-hfm8-9jrf-7g9w
fix available via `npm audit fix --force`
Will install @emotion/react@11.7.1, which is a breaking change
node_modules/is-arrayish
error-ex >=1.3.0
Depends on vulnerable versions of is-arrayish
node_modules/error-ex
parse-json 3.0.0 - 7.1.1
Depends on vulnerable versions of error-ex
node_modules/parse-json
cosmiconfig >=3.0.1
Depends on vulnerable versions of parse-json
node_modules/cosmiconfig
babel-plugin-macros >=2.0.0
Depends on vulnerable versions of cosmiconfig
node_modules/babel-plugin-macros
@emotion/babel-plugin *
Depends on vulnerable versions of babel-plugin-macros
node_modules/@emotion/babel-plugin
@emotion/react >=11.8.0
Depends on vulnerable versions of @emotion/babel-plugin
node_modules/@emotion/react
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force

FYI

"@emotion/react": "<11.8.0",

fixes it in the package.json

@alejsdev

Copy link
Copy Markdown
MemberAuthor
$ npm install
added 101 packages, removed 21 packages, changed 66 packages, and audited 424 packages in 2s
72 packages are looking for funding
run `npm fund` for details
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
full-stack-fastapi-template/frontend$ npm audit
# npm audit report
is-arrayish *
Severity: critical
Malware in is-arrayish - https://github.com/advisories/GHSA-hfm8-9jrf-7g9w
fix available via `npm audit fix --force`
Will install @emotion/react@11.7.1, which is a breaking change
node_modules/is-arrayish
error-ex >=1.3.0
Depends on vulnerable versions of is-arrayish
node_modules/error-ex
parse-json 3.0.0 - 7.1.1
Depends on vulnerable versions of error-ex
node_modules/parse-json
cosmiconfig >=3.0.1
Depends on vulnerable versions of parse-json
node_modules/cosmiconfig
babel-plugin-macros >=2.0.0
Depends on vulnerable versions of cosmiconfig
node_modules/babel-plugin-macros
@emotion/babel-plugin *
Depends on vulnerable versions of babel-plugin-macros
node_modules/@emotion/babel-plugin
@emotion/react >=11.8.0
Depends on vulnerable versions of @emotion/babel-plugin
node_modules/@emotion/react
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force

FYI

"@emotion/react": "<11.8.0",

fixes it in the package.json

I cannot replicate it. Have you pulled the latest changes from master? Several upgrades were made recently.
In this branch with the latest changes, I found 0 vulnerabilities.

@alexrockhill

Copy link
Copy Markdown
Contributor

I'm not able to replicate now either, maybe it's yanked already, it was posted 3 hours ago

Comment threadfrontend/biome.json Outdated
Comment threadfrontend/biome.json Outdated
Comment threadfrontend/biome.json Outdated
Comment threadscripts/generate-client.sh Outdated
Comment threadfrontend/src/client/core/request.ts
@alejsdev
alejsdev merged commit f813161 into masterSep 9, 2025
17 checks passed
@alejsdev
alejsdev deleted the upgrade-biome branch September 9, 2025 12:45
jpizquierdo pushed a commit to jpizquierdo/full-stack-fastapi-template that referenced this pull request Sep 24, 2025
rajdavee pushed a commit to OrganyzAI/python-backend that referenced this pull request Dec 30, 2025
azzi2023 pushed a commit to azzi2023/organyz-python-backend that referenced this pull request Jan 9, 2026
BraidaFac pushed a commit to BraidaFac/insurance-broker-api that referenced this pull request Apr 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@alejsdev@alexrockhill@YuriiMotov@tiangolo
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

⬆️ Upgrade Biome to the latest version - #1861

Merged
alejsdev merged 14 commits into
masterfrom
upgrade-biome
Sep 9, 2025
Merged

⬆️ Upgrade Biome to the latest version#1861
alejsdev merged 14 commits into
masterfrom
upgrade-biome

Conversation

@alejsdev

@alejsdevalejsdev commented Sep 8, 2025

Copy link
Copy Markdown
Member

⬆️ Upgrade Biome to the latest version

Also included fix proposed in #1833 (to exclude dist and src/client)

Closes#1858

@alejsdev
alejsdev marked this pull request as ready for review September 8, 2025 15:36
@alejsdevalejsdev changed the title ⬆️ Upgrade Biome⬆️ Upgrade Biome to the latest versionSep 8, 2025
@alejsdevalejsdev mentioned this pull request Sep 8, 2025
@alexrockhill

alexrockhill commented Sep 8, 2025

Copy link
Copy Markdown
Contributor
$ npm install
added 101 packages, removed 21 packages, changed 66 packages, and audited 424 packages in 2s
72 packages are looking for funding
run `npm fund` for details
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
full-stack-fastapi-template/frontend$ npm audit
# npm audit report
is-arrayish *
Severity: critical
Malware in is-arrayish - https://github.com/advisories/GHSA-hfm8-9jrf-7g9w
fix available via `npm audit fix --force`
Will install @emotion/react@11.7.1, which is a breaking change
node_modules/is-arrayish
error-ex >=1.3.0
Depends on vulnerable versions of is-arrayish
node_modules/error-ex
parse-json 3.0.0 - 7.1.1
Depends on vulnerable versions of error-ex
node_modules/parse-json
cosmiconfig >=3.0.1
Depends on vulnerable versions of parse-json
node_modules/cosmiconfig
babel-plugin-macros >=2.0.0
Depends on vulnerable versions of cosmiconfig
node_modules/babel-plugin-macros
@emotion/babel-plugin *
Depends on vulnerable versions of babel-plugin-macros
node_modules/@emotion/babel-plugin
@emotion/react >=11.8.0
Depends on vulnerable versions of @emotion/babel-plugin
node_modules/@emotion/react
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force

FYI

"@emotion/react": "<11.8.0",

fixes it in the package.json

@alejsdev

Copy link
Copy Markdown
MemberAuthor
$ npm install
added 101 packages, removed 21 packages, changed 66 packages, and audited 424 packages in 2s
72 packages are looking for funding
run `npm fund` for details
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
full-stack-fastapi-template/frontend$ npm audit
# npm audit report
is-arrayish *
Severity: critical
Malware in is-arrayish - https://github.com/advisories/GHSA-hfm8-9jrf-7g9w
fix available via `npm audit fix --force`
Will install @emotion/react@11.7.1, which is a breaking change
node_modules/is-arrayish
error-ex >=1.3.0
Depends on vulnerable versions of is-arrayish
node_modules/error-ex
parse-json 3.0.0 - 7.1.1
Depends on vulnerable versions of error-ex
node_modules/parse-json
cosmiconfig >=3.0.1
Depends on vulnerable versions of parse-json
node_modules/cosmiconfig
babel-plugin-macros >=2.0.0
Depends on vulnerable versions of cosmiconfig
node_modules/babel-plugin-macros
@emotion/babel-plugin *
Depends on vulnerable versions of babel-plugin-macros
node_modules/@emotion/babel-plugin
@emotion/react >=11.8.0
Depends on vulnerable versions of @emotion/babel-plugin
node_modules/@emotion/react
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force

FYI

"@emotion/react": "<11.8.0",

fixes it in the package.json

I cannot replicate it. Have you pulled the latest changes from master? Several upgrades were made recently.
In this branch with the latest changes, I found 0 vulnerabilities.

@alexrockhill

Copy link
Copy Markdown
Contributor

I'm not able to replicate now either, maybe it's yanked already, it was posted 3 hours ago

Comment threadfrontend/biome.json Outdated
Comment threadfrontend/biome.json Outdated
Comment threadfrontend/biome.json Outdated
Comment threadscripts/generate-client.sh Outdated
Comment threadfrontend/src/client/core/request.ts
@alejsdev
alejsdev merged commit f813161 into masterSep 9, 2025
17 checks passed
@alejsdev
alejsdev deleted the upgrade-biome branch September 9, 2025 12:45
jpizquierdo pushed a commit to jpizquierdo/full-stack-fastapi-template that referenced this pull request Sep 24, 2025
rajdavee pushed a commit to OrganyzAI/python-backend that referenced this pull request Dec 30, 2025
azzi2023 pushed a commit to azzi2023/organyz-python-backend that referenced this pull request Jan 9, 2026
BraidaFac pushed a commit to BraidaFac/insurance-broker-api that referenced this pull request Apr 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@alejsdev@alexrockhill@YuriiMotov@tiangolo
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

⬆️ Upgrade Biome to the latest version - #1861

Merged
alejsdev merged 14 commits into
masterfrom
upgrade-biome
Sep 9, 2025
Merged

⬆️ Upgrade Biome to the latest version#1861
alejsdev merged 14 commits into
masterfrom
upgrade-biome

Conversation

@alejsdev

@alejsdevalejsdev commented Sep 8, 2025

Copy link
Copy Markdown
Member

⬆️ Upgrade Biome to the latest version

Also included fix proposed in #1833 (to exclude dist and src/client)

Closes#1858

@alejsdev
alejsdev marked this pull request as ready for review September 8, 2025 15:36
@alejsdevalejsdev changed the title ⬆️ Upgrade Biome⬆️ Upgrade Biome to the latest versionSep 8, 2025
@alejsdevalejsdev mentioned this pull request Sep 8, 2025
@alexrockhill

alexrockhill commented Sep 8, 2025

Copy link
Copy Markdown
Contributor
$ npm install
added 101 packages, removed 21 packages, changed 66 packages, and audited 424 packages in 2s
72 packages are looking for funding
run `npm fund` for details
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
full-stack-fastapi-template/frontend$ npm audit
# npm audit report
is-arrayish *
Severity: critical
Malware in is-arrayish - https://github.com/advisories/GHSA-hfm8-9jrf-7g9w
fix available via `npm audit fix --force`
Will install @emotion/react@11.7.1, which is a breaking change
node_modules/is-arrayish
error-ex >=1.3.0
Depends on vulnerable versions of is-arrayish
node_modules/error-ex
parse-json 3.0.0 - 7.1.1
Depends on vulnerable versions of error-ex
node_modules/parse-json
cosmiconfig >=3.0.1
Depends on vulnerable versions of parse-json
node_modules/cosmiconfig
babel-plugin-macros >=2.0.0
Depends on vulnerable versions of cosmiconfig
node_modules/babel-plugin-macros
@emotion/babel-plugin *
Depends on vulnerable versions of babel-plugin-macros
node_modules/@emotion/babel-plugin
@emotion/react >=11.8.0
Depends on vulnerable versions of @emotion/babel-plugin
node_modules/@emotion/react
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force

FYI

"@emotion/react": "<11.8.0",

fixes it in the package.json

@alejsdev

Copy link
Copy Markdown
MemberAuthor
$ npm install
added 101 packages, removed 21 packages, changed 66 packages, and audited 424 packages in 2s
72 packages are looking for funding
run `npm fund` for details
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
full-stack-fastapi-template/frontend$ npm audit
# npm audit report
is-arrayish *
Severity: critical
Malware in is-arrayish - https://github.com/advisories/GHSA-hfm8-9jrf-7g9w
fix available via `npm audit fix --force`
Will install @emotion/react@11.7.1, which is a breaking change
node_modules/is-arrayish
error-ex >=1.3.0
Depends on vulnerable versions of is-arrayish
node_modules/error-ex
parse-json 3.0.0 - 7.1.1
Depends on vulnerable versions of error-ex
node_modules/parse-json
cosmiconfig >=3.0.1
Depends on vulnerable versions of parse-json
node_modules/cosmiconfig
babel-plugin-macros >=2.0.0
Depends on vulnerable versions of cosmiconfig
node_modules/babel-plugin-macros
@emotion/babel-plugin *
Depends on vulnerable versions of babel-plugin-macros
node_modules/@emotion/babel-plugin
@emotion/react >=11.8.0
Depends on vulnerable versions of @emotion/babel-plugin
node_modules/@emotion/react
7 critical severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force

FYI

"@emotion/react": "<11.8.0",

fixes it in the package.json

I cannot replicate it. Have you pulled the latest changes from master? Several upgrades were made recently.
In this branch with the latest changes, I found 0 vulnerabilities.

@alexrockhill

Copy link
Copy Markdown
Contributor

I'm not able to replicate now either, maybe it's yanked already, it was posted 3 hours ago

Comment threadfrontend/biome.json Outdated
Comment threadfrontend/biome.json Outdated
Comment threadfrontend/biome.json Outdated
Comment threadscripts/generate-client.sh Outdated
Comment threadfrontend/src/client/core/request.ts
@alejsdev
alejsdev merged commit f813161 into masterSep 9, 2025
17 checks passed
@alejsdev
alejsdev deleted the upgrade-biome branch September 9, 2025 12:45
jpizquierdo pushed a commit to jpizquierdo/full-stack-fastapi-template that referenced this pull request Sep 24, 2025
rajdavee pushed a commit to OrganyzAI/python-backend that referenced this pull request Dec 30, 2025
azzi2023 pushed a commit to azzi2023/organyz-python-backend that referenced this pull request Jan 9, 2026
BraidaFac pushed a commit to BraidaFac/insurance-broker-api that referenced this pull request Apr 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@alejsdev@alexrockhill@YuriiMotov@tiangolo