Skip to content

build(deps-dev): bump @biomejs/biome from 2.5.6 to 2.5.14 - #36

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/biomejs/biome-2.5.14
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/biomejs/biome-2.5.14

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 26, 2026

Copy link
Copy Markdown
Contributor

Bumps @biomejs/biome from 2.5.6 to 2.5.14.

Release notes

Sourced from @​biomejs/biome's releases.

Biome CLI v2.5.14

2.5.14

Patch Changes

  • #9022 0d49e24 Thanks @​dyc3! - Added the nursery rule noReturnInFinally. This rule disallows return statements in Promise.prototype.finally() callbacks, including inside nested blocks and conditional branches. Returns in nested functions are ignored by the rule.

    // Invalid: return in finally callback
    Promise.resolve(1).finally(() => { return 2 })
    // Valid: no return in finally callback
    Promise.resolve(1).finally(() => { console.log(2) })

    Returning a value from a Promise.prototype.finally() callback does not replace the original promise's fulfillment value, which can be confusing. Returned promises and thenables are awaited, and their rejection rejects the resulting promise.

  • #11754 71eaa0d Thanks @​griff-rees! - Added the nursery rule noSvelteAtDebugTags, which disallows Svelte's {@debug} tag.

    <!-- Invalid: leftover debugging tag -->
    {@debug user}

    The {@debug} tag is a debugging aid and should be removed once you no longer need it, as it should not remain in production code. The rule provides a safe fix that removes the tag.

  • #11725 5eb5f09 Thanks @​m1handr! - Added the nursery rule useValidTestTitle, which enforces valid titles for unit test cases and suites.

  • #11735 9bd70c7 Thanks @​ematipico! - Fixed #8471: source.fixAll.biome ignored formatter.formatWithErrors. It now applies safe fixes without formatting files that have parse errors when the option is disabled.

  • #11715 f05a3c3 Thanks @​ematipico! - Fixed #7771: Grit plugins that use sequential no longer panic when Biome processes files.

  • #11766 c2542c6 Thanks @​dyc3! - Fixed validation of readonly and accessor modifiers: combining them in either order now reports that they cannot be used together.

  • #11461 22e9966 Thanks @​FoundDream! - Fixed #11423: Multiline template interpolations now preserve the indentation of their closing brace when the source indentation is not a multiple of tabWidth.

     const value = `
          ${
            condition
              ? "yes"
              : "no"
    -}
    +     }
     `;
  • #11766 c2542c6 Thanks @​dyc3! - Fixed #11763: TypeScript class members using override accessor, such as override accessor value = 1, now parse correctly. The reversed order, accessor override, now reports that override must precede accessor.

... (truncated)

Changelog

Sourced from @​biomejs/biome's changelog.

2.5.14

Patch Changes

  • #9022 0d49e24 Thanks @​dyc3! - Added the nursery rule noReturnInFinally. This rule disallows return statements in Promise.prototype.finally() callbacks, including inside nested blocks and conditional branches. Returns in nested functions are ignored by the rule.

    // Invalid: return in finally callback
    Promise.resolve(1).finally(() => { return 2 })
    // Valid: no return in finally callback
    Promise.resolve(1).finally(() => { console.log(2) })

    Returning a value from a Promise.prototype.finally() callback does not replace the original promise's fulfillment value, which can be confusing. Returned promises and thenables are awaited, and their rejection rejects the resulting promise.

  • #11754 71eaa0d Thanks @​griff-rees! - Added the nursery rule noSvelteAtDebugTags, which disallows Svelte's {@debug} tag.

    <!-- Invalid: leftover debugging tag -->
    {@debug user}

    The {@debug} tag is a debugging aid and should be removed once you no longer need it, as it should not remain in production code. The rule provides a safe fix that removes the tag.

  • #11725 5eb5f09 Thanks @​m1handr! - Added the nursery rule useValidTestTitle, which enforces valid titles for unit test cases and suites.

  • #11735 9bd70c7 Thanks @​ematipico! - Fixed #8471: source.fixAll.biome ignored formatter.formatWithErrors. It now applies safe fixes without formatting files that have parse errors when the option is disabled.

  • #11715 f05a3c3 Thanks @​ematipico! - Fixed #7771: Grit plugins that use sequential no longer panic when Biome processes files.

  • #11766 c2542c6 Thanks @​dyc3! - Fixed validation of readonly and accessor modifiers: combining them in either order now reports that they cannot be used together.

  • #11461 22e9966 Thanks @​FoundDream! - Fixed #11423: Multiline template interpolations now preserve the indentation of their closing brace when the source indentation is not a multiple of tabWidth.

     const value = `
          ${
            condition
              ? "yes"
              : "no"
    -}
    +     }
     `;
  • #11766 c2542c6 Thanks @​dyc3! - Fixed #11763: TypeScript class members using override accessor, such as override accessor value = 1, now parse correctly. The reversed order, accessor override, now reports that override must precede accessor.

  • #11790 17d0ff0 Thanks @​ematipico! - Fixed #10248: noUselessFragments now allows fragments with props in Astro files, such as <Fragment slot="name">{text}</Fragment> inside template expressions.

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) from 2.5.6 to 2.5.14.
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.14/packages/@biomejs/biome)

---
updated-dependencies:
- dependency-name: "@biomejs/biome"
  dependency-version: 2.5.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 26, 2026
@github-actions

Copy link
Copy Markdown

Super-linter summary

Language Validation result
BIOME_FORMAT Fail ❌
BIOME_LINT Pass ✅
CHECKOV Pass ✅
GITHUB_ACTIONS Fail ❌
GITHUB_ACTIONS_ZIZMOR Fail ❌
GITLEAKS Pass ✅
GIT_MERGE_CONFLICT_MARKERS Pass ✅
JAVASCRIPT_ES Pass ✅
JAVASCRIPT_PRETTIER Pass ✅
JSCPD Pass ✅
JSON Pass ✅
JSON_PRETTIER Pass ✅
MARKDOWN Pass ✅
MARKDOWN_PRETTIER Pass ✅
NATURAL_LANGUAGE Pass ✅
PRE_COMMIT Pass ✅
SPELL_CODESPELL Pass ✅
TRIVY Pass ✅
YAML Pass ✅
YAML_PRETTIER Pass ✅

Super-linter detected linting errors

For more information, see the GitHub Actions workflow run

Powered by Super-linter

BIOME_FORMAT
Checked 2 files in 4ms. No fixes applied.
Found 2 errors.package.json format ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

  × Formatter would have printed the following content:

    1 1 │   {
    2   │ - ··"scripts":·{
    3   │ - ····"lint":·"npx·@biomejs/biome·lint·&&·actionlint·&&·zizmor·./.github"
    4   │ - ··},
    5   │ - ··"devDependencies":·{
    6   │ - ····"@biomejs/biome":·"2.5.14"
    7   │ - ··}
      2 │ + → "scripts":·{
      3 │ + → → "lint":·"npx·@biomejs/biome·lint·&&·actionlint·&&·zizmor·./.github"
      4 │ + → },
      5 │ + → "devDependencies":·{
      6 │ + → → "@biomejs/biome":·"2.5.14"
      7 │ + → }
    8 8 │   }
    9 9 │


scripts/static-utils.js format ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

  × Formatter would have printed the following content:

    13 13 │    */
    14 14 │   function parse({ core }, state = {}) {
    15    │ - ··const·fs·=·require("fs");
    16    │ - ··let·config·=·{};
    17    │ - ··try·{
    18    │ - ····config·=·JSON.parse(fs.readFileSync("./static.json",·"utf8"));
    19    │ - ··}·catch·(e)·{
    20    │ - ····core.setFailed(`Unable·to·parse·static.json:·${e.message}`);
    21    │ - ··}
    22    │ - ··//·Merge·GitHub·Action·state·with·the·parsed·static.json
    23    │ - ··config·=·{
    24    │ - ····...config,
    25    │ - ····_static:·{
    26    │ - ······host:·{
    27    │ - ········...state.host,
    28    │ - ······},
    29    │ - ······...config._static,
    30    │ - ····},
    31    │ - ··};
       15 │ + → const·fs·=·require("fs");
       16 │ + → let·config·=·{};
       17 │ + → try·{
       18 │ + → → config·=·JSON.parse(fs.readFileSync("./static.json",·"utf8"));
       19 │ + → }·catch·(e)·{
       20 │ + → → core.setFailed(`Unable·to·parse·static.json:·${e.message}`);
       21 │ + → }
       22 │ + → //·Merge·GitHub·Action·state·with·the·parsed·static.json
       23 │ + → config·=·{
       24 │ + → → ...config,
       25 │ + → → _static:·{
       26 │ + → → → host:·{
       27 │ + → → → → ...state.host,
       28 │ + → → → },
       29 │ + → → → ...config._static,
       30 │ + → → },
       31 │ + → };
    32 32 │
    33    │ - ··try·{
    34    │ - ····validate(config);
    35    │ - ··}·catch·(e)·{
    36    │ - ····core.setFailed(`Invalid·static.json:·${e.message}`);
    37    │ - ··}
    38    │ - ··return·config;
       33 │ + → try·{
       34 │ + → → validate(config);
       35 │ + → }·catch·(e)·{
       36 │ + → → core.setFailed(`Invalid·static.json:·${e.message}`);
       37 │ + → }
       38 │ + → return·config;
    39 39 │   }
    40 40 │
    ····· │
    43 43 │    */
    44 44 │   function validate(config) {
    45    │ - ··if·(!config)·{
    46    │ - ····throw·new·Error("No·configuration·provided.");
    47    │ - ··}
    48    │ - ··if·(!("_static"·in·config)·||·!config._static)·{
    49    │ - ····throw·new·Error("`_static`·member·not·found·in·configuration.");
    50    │ - ··}
    51    │ - ··if·(!config._static?.generator)·{
    52    │ - ····throw·new·Error("A·`generator`·is·required·in·a·`_static`·configuration.");
    53    │ - ··}
    54    │ - ··if·(config._static?.ecosystem·&&·config._static?.ecosystem·!==·"npm")·{
    55    │ - ····throw·new·Error(
    56    │ - ······"Unknown·ecosystem·provided.·`npm`·is·currently·the·only·official·supported·ecosystem.",
    57    │ - ····);
    58    │ - ··}
    59    │ - ··return·true;
       45 │ + → if·(!config)·{
       46 │ + → → throw·new·Error("No·configuration·provided.");
       47 │ + → }
       48 │ + → if·(!("_static"·in·config)·||·!config._static)·{
       49 │ + → → throw·new·Error("`_static`·member·not·found·in·configuration.");
       50 │ + → }
       51 │ + → if·(!config._static?.generator)·{
       52 │ + → → throw·new·Error("A·`generator`·is·required·in·a·`_static`·configuration.");
       53 │ + → }
       54 │ + → if·(config._static?.ecosystem·&&·config._static?.ecosystem·!==·"npm")·{
       55 │ + → → throw·new·Error(
       56 │ + → → → "Unknown·ecosystem·provided.·`npm`·is·currently·the·only·official·supported·ecosystem.",
       57 │ + → → );
       58 │ + → }
       59 │ + → return·true;
    60 60 │   }
    61 61 │
    62 62 │   module.exports = {
    63    │ - ··parse,
    64    │ - ··validate,
       63 │ + → parse,
       64 │ + → validate,
    65 65 │   };
    66 66 │


format ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

  × Some errors were emitted while running checks.

GITHUB_ACTIONS
.github/workflows/static.yml:140:9: shellcheck reported issue in this script: SC2086:info:1:36: Double quote to prevent globbing and word splitting [shellcheck]
    |
140 |         run: |
    |         ^~~~
.github/workflows/static.yml:146:9: shellcheck reported issue in this script: SC2086:info:2:12: Double quote to prevent globbing and word splitting [shellcheck]
    |
146 |         run: |
    |         ^~~~
GITHUB_ACTIONS_ZIZMOR
�[1m�[33mwarning[ref-version-mismatch]�[0m�[1m: action's hash pin has mismatched or missing version comment�[0m
   �[1m�[94m--> �[0m/github/workspace/.github/workflows/static.yml:193:79
    �[1m�[94m|�[0m
�[1m�[94m193�[0m �[1m�[94m|�[0m         uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5
    �[1m�[94m|�[0m         �[1m�[94m-------------------------------------------------------------------�[0m   �[1m�[33m^^�[0m �[1m�[33mpoints to commit 368f82528645�[0m
    �[1m�[94m|�[0m         �[1m�[94m|�[0m
    �[1m�[94m|�[0m         �[1m�[94mis pointed to by tag v3.0.2-node.24�[0m
    �[1m�[94m|�[0m
    �[1m�[94m= �[0m�[1mnote�[0m: audit confidence → High
    �[1m�[94m= �[0m�[1mnote�[0m: this finding has an auto-fix
    �[1m�[94m= �[0m�[1mhelp�[0m: audit documentation → �[32mhttps://docs.zizmor.sh/audits/#ref-version-mismatch�[39m

�[32m7�[39m findings (�[1m�[93m6�[39m suppressed, �[91m1�[39m unsafe fixes�[0m): �[35m0�[39m informational, �[36m0�[39m low, �[33m1�[39m medium, �[31m0�[39m high�[32m INFO�[0m �[2mzizmor�[0m�[2m:�[0m 🌈 zizmor v1.25.2
�[32m INFO�[0m �[1maudit�[0m�[2m:�[0m �[2mzizmor�[0m�[2m:�[0m 🌈 completed /github/workspace/.github/dependabot.yml
�[32m INFO�[0m �[1maudit�[0m�[2m:�[0m �[2mzizmor�[0m�[2m:�[0m 🌈 completed /github/workspace/.github/workflows/lint.yml
�[32m INFO�[0m �[1maudit�[0m�[2m:�[0m �[2mzizmor�[0m�[2m:�[0m 🌈 completed /github/workspace/.github/workflows/static.yml

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants