Skip to content

chore(deps): update linters - #2375

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/linters
Open

chore(deps): update linters#2375
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/linters

Conversation

@renovate

@renovaterenovateBot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

PackageTypeUpdateChangePendingAgeConfidence
aqua:jonwiggins/xmloxidetoolsminor0.4.40.5.0ageconfidence
biometoolspatch2.5.52.5.7ageconfidence
editorconfig-checkertoolsminor3.8.03.11.1ageconfidence
google-java-formattoolsminor1.35.01.36.1ageconfidence
npm:renovate (source)toolsmajor43.279.144.14.544.17.5 (+14)ageconfidence
rufftoolspatch0.16.00.16.2ageconfidence
rumdltoolspatchv0.2.43v0.2.53ageconfidence
typostoolsminor1.48.01.49.0ageconfidence
zizmortoolsminor1.28.01.29.0ageconfidence

Release Notes

jonwiggins/xmloxide (aqua:jonwiggins/xmloxide)

v0.5.0

Compare Source

Changed
  • XPath attribute results are first-class attribute nodes (#​47).
    Node-sets (XPathValue::NodeSet) now hold XPathNode entries — either a
    tree node or an attribute identified by owner element and index — instead
    of bare NodeIds. This fixes a family of wrong-answer bugs rooted in the
    old one-value-per-element override map: //a/@x != //a/@y comparisons no
    longer clobber each other's values, @* yields one node per attribute
    (previously only the first per element), count((//a)[1]/@href) returns a
    number instead of a type error, name()/local-name()/namespace-uri()
    work on attribute nodes, @attr/.. navigates to the owner element,
    predicates evaluate with the attribute as context node, and namespace
    declarations (xmlns, xmlns:*) are no longer visible as attributes per
    the XPath 1.0 data model. Mixed node-sets (//a | //a/@x) sort in
    document order with attributes directly after their owner element.
    Breaking: code matching XPathValue::NodeSet must handle
    XPathNode; use .anchor() for the owning tree node or
    .as_tree_node() to filter attributes out. The single-match collapse
    (attribute paths returning XPathValue::String) is gone — convert with
    string() where a string is wanted. xmllint --xpath prints attribute
    results as name="value" lines, matching libxml2. The C API keeps
    xmloxide_xpath_nodeset_item() (returns the owner element id for
    attributes) and adds xmloxide_xpath_nodeset_item_is_attribute(),
    ..._attr_name(), and ..._attr_value().
  • XPath step predicates apply per context node per XPath 1.0 §2.4:
    //a/b[1] now selects the first b of everya (previously the first
    of the merged set), and position()/last() in step predicates are
    relative to each context node's own node-set, matching libxml2. The
    parenthesized form (//a/b)[1] keeps global-position semantics.
  • Schematron rules with attribute contexts (context="//@id") now fire
    with the attribute itself as the context node — . is the attribute
    value and <value-of select="."/> reads it, per ISO Schematron.
    Previously such rules either never fired (single match) or misfired
    against the owner element.
Security
  • Fix exponential-time entity recursion check (#​42, thanks @​hey-jj). The
    WFC: No Recursion walks in the DTD validator re-visited entities once per
    path, so a 474-byte document with chained entity declarations took 8+
    seconds to parse and a 694-byte one about 22 hours. The walks (including
    parameter entities and ATTLIST-default validation) now memoize entities
    proven acyclic, making the check linear in the size of the DTD. Cycle
    detection is unaffected.
  • Bound element nesting across entity expansions. Entity replacement text
    is parsed by nested sub-parsers, which now inherit the outer parser's
    nesting depth so total element depth stays bounded by
    ParseOptions::max_depth instead of max_depth per expansion level.
Fixed
  • General entity replacement text is parsed as content per XML 1.0 §4.4
    (#​43, thanks @​hey-jj). EntityRef nodes now carry their parsed expansion
    as children: character references in declarations are expanded when
    replacement text is built (§4.5), nested entity references are included,
    and markup-bearing entities produce real element children instead of
    escaped text — while serialization still emits &name;, keeping
    round-trips lossless. Replacement text must match the content production
    (§4.3.2); unbalanced or split tags are rejected. Entity expansion is
    subject to the expansion counter, a nesting-depth cap, and the 5x
    amplification guard, matching libxml2. DTD content-model validation sees
    through entity references (§4.4.3), so entity-supplied elements are
    validated too.
  • XPath != uses its own existential semantics for node-sets per XPath
    1.0 §3.4 (#​44, thanks @​hey-jj). != was evaluated as not(=), inverting
    empty-node-set comparisons and breaking multi-node sets (both = and !=
    can hold at once). Node-set vs boolean keeps boolean-conversion semantics;
    scalar comparisons are unchanged. An absent attribute step now also yields
    an empty node-set (false under both = and !=) instead of an
    empty-string sentinel.
  • XPath filter-path continuations navigate instead of filtering (#​20,
    thanks @​ancientcatz). (//a)[1]/@href parsed to the same AST as
    (//a)[@href], so the trailing path acted as a predicate and
    string((//a)[1]/@href) returned the anchor text. A new
    Expr::FilterPath AST variant evaluates the continuation steps against
    the filter's node-set. Breaking: downstream exhaustive matches on
    xpath::ast::Expr must handle the new variant.
biomejs/biome (biome)

v2.5.7: Biome CLI v2.5.7

Compare Source

2.5.7

Patch Changes
  • #​10822c171b3b Thanks @​pkallos! - Added the option ignoreIfStatements to useNullishCoalescing. Biome now flags if statements that only assign to a nullish variable (such as if (!a) { a = b }) and can rewrite them to ??=. When enabled, Biome ignores those if statements.

  • #​11136e63354c Thanks @​AkashNaickar! - Added a new nursery rule noExtendNative, which reports extending the prototype of a built-in object.

  • #​10094e007143 Thanks @​THEjacob1000! - Added the nursery rule noTailwindArbitraryValue. Biome now reports Tailwind CSS arbitrary values such as w-[400px], including in HTML/JSX class attributes, configured utility functions, and tagged templates.

  • #​11184135f476 Thanks @​subotac! - Fixed #​11176: noUnknownPseudoClass now recognizes Vue's :deep() pseudo-class inside .vue style blocks.

  • #​8239a519f9d Thanks @​cormacrelf! - Fixed #​8233, where Biome CLI in
    stdin mode didn't work correctly when handling files in projects with nested
    configurations. For example, with the following structure,
    --stdin-file-path=subdirectory/... would not use the nested configuration in
    subdirectory/biome.json:

    ├── biome.json
    └── subdirectory
    ├── biome.json
    └── lib.js
    
    biome format --write --stdin-file-path=subdirectory/lib.js < subdirectory/lib.js

    Now, the nested configuration is correctly picked up and applied.

    In addition, Biome now shows a warning if --stdin-file-path is provided but
    that path is ignored and therefore not formatted or fixed.

  • #​111388c2c6bd Thanks @​ematipico! - Fixed noUnnecessaryConditions: Biome now chooses the same function overload as TypeScript when an argument is a callback, so conditions that were previously missed are reported.

    The following code is now invalid, because a parameter typed () => void accepts an async callback and schedule therefore returns string:

    declarefunctionschedule(handler: ()=>void): string;declarefunctionschedule(handler: ()=>Promise<void>): string|undefined;schedule(async()=>{})??"fallback";

    The following code is also now invalid, because map(() => 42) returns 42:

    typeMapper<T>=()=>T;declarefunctionmap<T>(mapper: Mapper<T>): T;map(()=>42)||flag;
  • #​111388c2c6bd Thanks @​ematipico! - Fixed #​11087: noUnnecessaryConditions no longer reports optional chains and nullish coalescing whose receiver can be nullish.

    For example, the optional chain and fallback in the following code are no longer reported:

    declareconstusage: {range: {startDate: string}}|null;conststartDate=usage?.range.startDate??"N/A";
  • #​111189c16840 Thanks @​subotac! - Fixed #​11098: The HTML formatter now preserves the configured trailing newline when a file ends with a comment.

    -<!-- trailing comment -->
    \ No newline at end of file
    +<!-- trailing comment -->
  • #​112010e80610 Thanks @​Bishwas-py! - Fixed #​11182: suppression comments for noPositiveTabindex now suppress the rule in HTML files when the attributes of the element span multiple lines.

  • #​11079607afd2 Thanks @​dyc3! - The HTML formatter now lays out the srcset attribute of <img> and <source> as the list of candidates it is. Runs of whitespace between candidates collapse, and once the list no longer fits on one line each candidate goes on its own line with the descriptors aligned:

    - <img srcset="/visual@0.5.png 400w, /visual.png 805w, /visual@2x.png 1610w, /visual@3x.png 2415w" />+ <img+ srcset="+ /visual@0.5.png 400w,+ /visual.png 805w,+ /visual@2x.png 1610w,+ /visual@3x.png 2415w+ "+ />
  • #​11156fed72c7 Thanks @​saberoueslati! - Fixed #​11129: noUnusedVariables no longer reports Vue bindings as unused when they are assigned through automatically unwrapped template refs.

  • #​11124d890b39 Thanks @​denbezrukov! - Fixed CSS formatting of line comments between a declaration colon and value to preserve their source indentation.

     .test {
    background:
    - /////// foo- // bar+ /////// foo+ // bar
    radial-gradient(circle, #&#8203;000, transparent);
    }
  • #​111133d8ab73 Thanks @​denbezrukov! - Fixed CSS formatting of long block comments between comma-separated property values:

     .foo {
    box-shadow:
    - 1000px /* long long long long long long long long long long long long comment */ 1000px /* long long long long long long long long long comment */ 2px color(srgb 0.555555555 0.555555555 0.555555555),+ 1000px+ /* long long long long long long long long long long long long comment */+ 1000px /* long long long long long long long long long comment */ 2px+ color(srgb 0.555555555 0.555555555 0.555555555),
    1px 1px black;
    }
  • #​11127da5c1a5 Thanks @​dyc3! - The HTML formatter now picks the quote character for an attribute by counting the quotes in the value rather than looking only for a double quote. &apos; and &quot; count as the characters they stand for, and only the character that ends up as the delimiter stays escaped:

    - <div title='123 &apos;&quot; 456'></div>+ <div title="123 '&quot; 456"></div>

    Entities that are not quotes, such as &amp; or &[#&#8203;39](https://redirect.github.com/biomejs/biome/issues/39);, are left exactly as written.

  • #​1119377035bb Thanks @​dyc3! - Fixed the HTML formatter collapsing the blank line between an element and the text that follows it. A blank line before text is now kept, the way one before another element already was:

     <div>foo</div>
    -
    text
  • #​11106ad80f57 Thanks @​dyc3! - The HTML formatter now writes the HTML5 doctype in lowercase, matching Prettier:

    - <!DOCTYPE html>+ <!doctype html>

    This only applies to a plain .html file whose doctype stands alone. A doctype that names a DTD keeps the case it was written with, since the rest of the declaration is not lowercased either:

    <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

    A .vue, .svelte, or .astro file keeps whatever the author wrote.

  • #​1118860679db Thanks @​dyc3! - Fixed the HTML formatter printing a comment twice when it ended the line of the last element in a document:

    - text<!-- a --><!-- a -->+ text<!-- a -->
  • #​110774dcd0d9 Thanks @​dyc3! - Fixed a bug where the HTML formatter collapsed the whitespace inside <textarea>, <xmp> and <plaintext>, changing what the page renders.

    - <textarea>- line one- line two </textarea>+ <textarea>line one line two</textarea>

    Biome now prints the content of these elements exactly as it appears in the source, matching the existing behavior for <pre>.

  • #​11194abfbb11 Thanks @​dyc3! - Fixed the HTML formatter refusing to format a Svelte file containing an array pattern that skips a position:

    {#eachanimalsas [, value]}
    <p>{value}</p>
    {/each}
  • #​10094e007143 Thanks @​THEjacob1000! - Fixed useSortedClasses to correctly detect unsorted classes in static member expression tagged templates (e.g. tw.div\...``). Previously, these were silently skipped due to surrounding whitespace trivia not being stripped from the tag name.

  • #​1107810da30e Thanks @​dyc3! - Fixed Vue single-file components failing to parse when they contain a custom block such as <i18n> or <docs>, or a <template> written in another language. Their content is no longer read as HTML, so a block may hold whatever its own tooling expects:

    <docs>
    This block is prose, and it may mention a `<my-component>` without closing it.
    </docs>
    <template lang="pug">
    .test#foo
    </template>

    Previously both blocks produced a parse error and the whole file was left unformatted. Biome now prints their content unchanged while still formatting the opening tag.

  • #​112314afd901 Thanks @​ematipico! - Improved the performance of the following lint rules:

  • #​111342fa0a62 Thanks @​yanthomasdev! - Clarified the warning emitted when using the experimental json and json-pretty reporters.

  • #​11198ed88b13 Thanks @​saberoueslati! - Fixed #​11171: variables referenced only inside a Svelte attachment ({@attach ...}) are no longer reported as unused by noUnusedVariables and noUnusedImports.

  • #​111556ee17ea Thanks @​dyc3! - Improved performance when printing diagnostics to the console.

  • #​11160217f8ad Thanks @​dyc3! - Improved the performance of noFloatingPromises by skipping type inference for assignment statements, which are always considered handled.

  • #​1115926c23d9 Thanks @​saberoueslati! - Fixed #​11144: noFloatingPromises no longer reports already-awaited optional Promise values.

  • #​111388c2c6bd Thanks @​ematipico! - Fixed #​11121: noUnnecessaryConditions no longer reports conditions based on an inapplicable function overload.

    For example, the condition in the following code is no longer reported because query({}) selects the overload that returns boolean:

    declarefunctionquery(options: {initial: string}): {isPending: false};declarefunctionquery(options: {initial?: string}): {isPending: boolean};const{ isPending }=query({});isPending||fallback;
  • #​11152c4fc6a9 Thanks @​dyc3! - Improved the performance of collecting rule timings with --profile-rules in heavily multithreaded environments.

  • #​111284d3ff76 Thanks @​ematipico! - Fixed #​7635: noDeprecatedImports now detects deprecated ambient declarations that are exported separately.

  • #​1111701f7ef5 Thanks @​subotac! - Fixed #​11014: noDelete no longer reports process.env["FOO"] style property deletions.

  • #​111689847e68 Thanks @​saberoueslati! - Added the nursery rule noNonScalableViewport, which reports viewport metadata that disables user scaling with user-scalable=no.

    For example:

    <metaname="viewport" content="width=device-width, user-scalable=no" />
  • #​11154a1d6b1f Thanks @​dyc3! - Improved the performance of noImportCycles by skipping graph traversals for imports that cannot be part of a cycle.

  • #​11175d96d6dd Thanks @​ematipico! - Fixed CSS parsing of registered custom properties: Biome now correctly validates the syntax descriptor of @property rules.

What's Changed

New Contributors

Full Changelog: https://github.com/biomejs/biome/compare/@biomejs/biome@2.5.6...@​biomejs/biome@2.5.7

v2.5.6: Biome CLI v2.5.6

Compare Source

2.5.6

Patch Changes
  • #​110350e4b03b Thanks @​ematipico! - Fixed a performance regression in noMisusedPromises that caused type inference to run repeatedly while linting a file.

  • #​1104322ec076 Thanks @​denbezrukov! - Fixed CSS formatting for multiline function arguments preceded by comments:

     .example {
    value: outer(
    1,
    /* comment */
    nested(
    - first,- second- )+ first,+ second+ )
    );
    }
  • #​11007c9acb25 Thanks @​BTF-Kabir-2020! - Fixed #​9195: useHookAtTopLevel no longer reports hooks in named forwardRef components that receive a ref parameter.

  • #​1015250a9bd8 Thanks @​Zelys-DFKH! - Fixed #​10131: Biome now correctly parses curried arrow functions in ternary consequents when the inner arrow's parameters use a destructuring pattern, e.g. cond ? (x) => ({ a, b }) => body : alt.

  • #​111058ffe2b9 Thanks @​dadavidtseng! - Fixed #​11092: The noUselessTernary quick fix now preserves operator spacing when simplifying or inverting boolean ternary expressions.

  • #​105335809875 Thanks @​Mokto! - Fixed #​10515: biome check --write was not idempotent on Svelte files — multi-line template literals in <script> blocks and block comments in <style> blocks gained an extra indent level on every run.

  • #​110400abb620 Thanks @​Mokto! - Fixed an issue where the HTML formatter would duplicate a comment placed directly before a Svelte {@const ...} or {@debug ...} block. The duplication compounded on every subsequent --write, causing the file to grow exponentially.

  • #​108586d18204 Thanks @​ruidosujeira! - Fixed #​10839: Svelte {#each} array destructuring no longer includes spaces inside square brackets, and multiline bind function expressions now indent their getter, setter, and function body correctly.

  • #​110092c36626 Thanks @​ematipico! - Improved the accuracy of type-aware lint rules by resolving more inferred types. For example, noFloatingPromises now detects floating Promises returned by aliased callbacks and arrays of Promises created by async mapping callbacks.

    The following statements are now reported:

    typeAsyncCallback=()=>Promise<void>;declareconstcallback: AsyncCallback;callback();[1,2,3].map(async(value)=>value);
  • #​109739cb044c Thanks @​ematipico! - Fixed false positives in noMisleadingReturnType when generic-constraint, normalization, substitution, or structural return-type comparison cannot complete. The rule now suppresses diagnostics rather than suggesting a return type derived from partial information. For example, this unresolved return type is no longer reported:

    functionunresolvedReturnType(): MissingType{return"value"asconst;}
  • #​1107115047a2 Thanks @​dyc3! - The HTML parser now accepts mixed-case doctype declarations.

  • #​11030cc90e65 Thanks @​marschattha! - The rdjson reporter now populates the severity field of each diagnostic (ERROR, WARNING, or INFO), so tools consuming Reviewdog Diagnostic Format output no longer need to assume a default severity.

  • #​110092c36626 Thanks @​ematipico! - Fixed a performance regression in type-aware JavaScript lint rules by inferring only requested types and memoizing export resolution.

  • #​11056903b177 Thanks @​dyc3! - Added support for Svelte declaration tags using let and const. Biome can now parse, format, and lint bindings declared in these tags.

  • #​1104589c27c6 Thanks @​ematipico! - Improved the performance of Biome formatter up to ~7% across the board.

  • #​9806781d68d Thanks @​dyc3! - Added the nursery rule noJsRestrictedProperties, which ports ESLint's no-restricted-properties rule. Biome now flags restricted member access and object destructuring, and biome migrate eslint preserves the rule's options.

What's Changed

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 4am on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovaterenovateBot added the dependencies Pull requests that update a dependency file label Aug 10, 2026
@renovate
renovateBot enabled auto-merge (squash) August 10, 2026 01:40
@github-actions

Copy link
Copy Markdown
Contributor

Benchmark results

Benchmark run finished with conclusion skipped for dffdb244f4e5f356f1ad69ff063a9b1f7122cd06.

Benchmark summary artifact was not found; see the workflow run for details.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants