[Snyk] Upgrade @biomejs/biome from 1.8.3 to 2.2.2 #389
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade @biomejs/biome from 1.8.3 to 2.2.2.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 37 versions ahead of your current version.
The recommended version was released 23 days ago.
Release notes
Package name: @biomejs/biome
2.2.2
Patch Changes
#7266
b270bb5
Thanks @ ematipico! - Fixed an issue where Biome got stuck when analyzing some files. This is usually caused by a bug in the inference engine. Now Biome has some guards in place in case the number of types grows too much, and if that happens, a diagnostic is emitted and the inference is halted.#7281
6436180
Thanks @ ematipico! - Fixed an issue where the functionscanProject
wouldn't work as expected.#7285
1511d0c
Thanks @ rriski! - Partially fixed #6782: JSX node kinds are now supported in GritQL AST nodes.#7249
dff85c0
Thanks @ ematipico! - Fixed #748, where Biome Language Server didn't show the unsafe fixes when requesting the quick fixes. Now all LSP editors will show also opt-in, unsafe fixes.#7266
b270bb5
Thanks @ ematipico! - Fixed #7020: Resolved an issue with analysing types of static member expressions involving unions. If the object type was a union that referenced nested unions, it would trigger an infinite loop as it tried to keep expanding nested unions, and the set of types would grow indefinitely.#7209
679b70e
Thanks @ patrickshipe! - Resolved an overcorrection inuseImportExtensions
when importing explicit index files.Imports that explicitly reference an index file are now preserved and no longer rewritten to nested index paths.
Example
+ import "./sub/index/index.js";
// After
- import "./sub/index";
+ import "./sub/index.js";
#7270
953f9c6
Thanks @ arendjr! - Fixed #6172: Resolved an issue with inferring types for rest parameters. This issue caused rest-parameter types to be incorrect, and in some cases caused extreme performance regressions in files that contained many methods with rest-parameter definitions.#7234
b7aa111
Thanks @ JeetuSuthar! - Fixed #7233: The useIndexOf rule now correctly suggests using indexOf() instead of findIndex().The diagnostic message was incorrectly recommending Array#findIndex() over Array#indexOf(), when it should recommend the opposite for simple equality checks.
#7283
0b07f45
Thanks @ ematipico! - Fixed #7236. Now Biome correctly migrates JSONC configuration files when they are passed using--config-path
.#7239
1d643d8
Thanks @ minht11! - Fixed an issue where Svelte globals ($state and so on) were not properly recognized inside.svelte.test.ts/js
and.svelte.spec.ts/js
files.#7264
62fdbc8
Thanks @ ematipico! - Fixed a regression where when using--log-kind-pretty
wasn't working anymore as expected.#7244
660031b
Thanks @ JeetuSuthar! - Fixed #7225: ThenoExtraBooleanCast
rule now preserves parentheses when removingBoolean
calls inside negations.#7298
46a8e93
Thanks @ unvalley! - Fixed #6695:useNamingConvention
now correctly reports TypeScript parameter properties with modifiers.Previously, constructor parameter properties with modifiers like
private
orreadonly
were not checked against naming conventions. These properties are now treated consistently with regular class properties.What's Changed
divan
for module graph benchmarks by @ arendjr in #7231useImportExtensions
handling of index files by @ patrickshipe in #7209scanProject
being stuck by @ ematipico in #7281New Contributors
Full Changelog: https://github.com/biomejs/biome/compare/@ biomejs/[email protected]...@ biomejs/[email protected]
2.2.0
Minor Changes
#5506
1f8755b
Thanks @ sakai-ast! - ThenoRestrictedImports
rule has been enhanced with a newpatterns
option. This option allows for more flexible and powerful import restrictions using gitignore-style patterns.You can now define patterns to restrict entire groups of modules. For example, you can disallow imports from any path under
import-foo/
except forimport-foo/baz
.Invalid examples
Valid examples
Additionally, the
patterns
option introducesimportNamePattern
to restrict specific import names using regular expressions.The following example restricts the import names that match
x
,y
orz
letters from modules underimport-foo/
.Invalid examples
Valid examples
Furthermore, you can use the
invertImportNamePattern
boolean option to reverse this logic. When set to true, only the import names that match theimportNamePattern
will be allowed. The following configuration only allows the import names that matchx
,y
orz
letters from modules underimport-foo/
.Invalid examples
Valid examples
#6506
90c5d6b
Thanks @ nazarhussain! - Allow customization of the sort order for different sorting actions. These actions now support a sort option:assist/source/useSortedKeys
now has asortOrder
optionassist/source/useSortedAttributes
now has asortOrder
optionassist/source/organizeImports
now has anidentifierOrder
optionFor each of these options, the supported values are the same:
natural
. Compares two strings using a natural ASCII order. Uppercase letters come first (e.g.A < a < B < b
) and number are compared in a human way (e.g.9
<10
). This is the default value.lexicographic
. Strings are ordered lexicographically by their byte values. This orders Unicode code points based on their positions in the code charts. This is not necessarily the same as “alphabetical” order, which varies by language and locale.#7159
df3afdf
Thanks @ ematipico! - Added the new ruleuseBiomeIgnoreFolder
. Since v2.2, Biome correctly prevents the indexing and crawling of folders.However, the correct pattern has changed. This rule attempts to detect incorrect usage, and promote the new pattern:
#6989
85b1128
Thanks @ arendjr! - Fixed minor inconsistencies in howfiles.includes
was being handled.Previously, Biome sometimes failed to properly ignore the contents of a folder if you didn't specify the
/**
at the end of a glob pattern. This was unfortunate, because it meant we still had to traverse the folder and then apply the glob to every entry inside it.This is no longer an issue and we now recommend to ignore folders without using the
/**
suffix.#7118
a78e878
Thanks @ avshalomt2! - Added support for.graphqls
files. Biome can now format and lint GraphQL files that have the extension.graphqls
#6159
f02a296
Thanks @ bavalpey! - Added a new option to Biome's JavaScript formatter,javascript.formatter.operatorLinebreak
, to configure whether long lines should be broken before or after binary operators.For example, the following configuration:
Will cause this JavaScript file:
if (
VERY_LONG_CONDITION_1234123412341234123412341234 &&
VERY_LONG_CONDITION_1234123412341234123412341234 &&
VERY_LONG_CONDITION_1234123412341234123412341234 &&
VERY_LONG_CONDITION_1234123412341234123412341234
) {
console.log("DONE");
}
to be formatted like this:
#7137
a653a0f
Thanks @ ematipico! - Promoted multiple lint rules from nursery to stable groups and renamed several rules for consistency.Promoted rules
The following rules have been promoted from nursery to stable groups:
CSS
noImportantStyles
to thecomplexity
group.noUnknownAtRules
to thesuspicious
group.GraphQL
useGraphqlNamedOperations
to thecorrectness
group.useGraphqlNamingConvention
to thestyle
group.JavaScript/TypeScript
noExcessiveLinesPerFunction
to thecomplexity
group.noImplicitCoercions
to thecomplexity
group.useIndexOf
to thecomplexity
group.noGlobalDirnameFilename
to thecorrectness
group.noNestedComponentDefinitions
to thecorrectness
group.noProcessGlobal
to thecorrectness
group.noReactPropAssignments
to thecorrectness
group.noRestrictedElements
to thecorrectness
group.noSolidDestructuredProps
to thecorrectness
group.useJsonImportAttributes
to thecorrectness
group.useParseIntRadix
to thecorrectness
group.useSingleJsDocAsterisk
to thecorrectness
group.useUniqueElementIds
to thecorrectness
group.noAwaitInLoops
to theperformance
group.noUnwantedPolyfillio
to theperformance
group.useGoogleFontPreconnect
to theperformance
group.useSolidForComponent
to theperformance
group.noMagicNumbers
to thestyle
group.useConsistentObjectDefinitions
to thestyle
group.useExportsLast
to thestyle
group.useGroupedAccessorPairs
to thestyle
group.useNumericSeparators
to thestyle
group.useObjectSpread
to thestyle
group.useReadonlyClassProperties
to thestyle
group.useSymbolDescription
to thestyle
group.useUnifiedTypeSignatures
to thestyle
group.noBitwiseOperators
to thesuspicious
group.noConstantBinaryExpressions
to thesuspicious
group.noTsIgnore
to thesuspicious
group.noUnassignedVariables
to thesuspicious
group.noUselessRegexBackrefs
to thesuspicious
group.noUselessStringEscapes
to thesuspicious
group.useConsistentIterableCallbackReturnValues
to thesuspicious
group.useStaticResponseMethods
to thesuspicious
group.Renamed rules
The following rules have been renamed during promotion. The migration tool will automatically update your configuration:
noAwaitInLoop
tonoAwaitInLoops
.noConstantBinaryExpression
tonoConstantBinaryExpressions
.noDestructuredProps
tonoSolidDestructuredProps
.noImplicitCoercion
tonoImplicitCoercions
.noReactPropAssign
tonoReactPropAssignments
.noUnknownAtRule
tonoUnknownAtRules
.noUselessBackrefInRegex
tonoUselessRegexBackrefs
.useAdjacentGetterSetter
touseGroupedAccessorPairs
.useConsistentObjectDefinition
touseConsistentObjectDefinitions
.useConsistentResponse
touseStaticResponseMethods
.useForComponent
touseSolidForComponent
.useJsonImportAttribute
touseJsonImportAttributes
.useNamedOperation
touseGraphqlNamedOperations
.useNamingConvention
touseGraphqlNamingConvention
.useUnifiedTypeSignature
touseUnifiedTypeSignatures
.Configuration files using the old rule names will need to be updated. Use the migration tool to automatically update your configuration:
#7159
df3afdf
Thanks @ ematipico! - Added the new rulenoBiomeFirstException
. This rule prevents the incorrect usage of patterns insidefiles.includes
.This rule catches if the first element of the array contains
!
. This mistake will cause Biome to analyze no files:#6923
0589f08
Thanks @ ptkagori! - Added Qwik Domain to BiomeThis release introduces Qwik domain support in Biome, enabling Qwik developers to use Biome as a linter and formatter for their projects.
useJsxKeyInIterable
noReactSpecificProps
#6989
85b1128
Thanks @ arendjr! - Fixed #6965: Implemented smarter scanner for project rules.Previously, if project rules were enabled, Biome's scanner would scan all dependencies regardless of whether they were used by/reachable from source files or not. While this worked for a first version, it was far from optimal.
The new scanner first scans everything listed under the
files.includes
setting, and then descends into the dependencies that were discovered there, including transitive dependencies. This has three main advantages:vcs.useIgnoreFile
is enabled,.gitignore
gets respected as well. Assuming you have folders such asbuild/
ordist/
configured there, those will be automatically ignored by the scanner.The change in the scanner also has a more nuanced impact: Previously, if you used
files.includes
to ignore a file in an included folder, the scanner would still index this file. Now the file is fully ignored, unless you import it.As a user you should notice better scanner performance (if you have project rules enabled), and hopefully you need to worry less about configuring
files.experimentalScannerIgnores
. Eventually our goal is still to deprecate that setting, so if you're using it today, we encourage you to see which ignores are still necessary there, and whether you can achieve the same effect by ignoring paths usingfiles.includes
instead.None of these changes affect the scanner if no project rules are enabled.
#6731
d6a05b5
Thanks @ ematipico! - The--reporter=summary
has been greatly enhanced. It now shows the list of files that contains violations, the files shown are clickable and can be opened from the editor.Below an example of the new version: