Skip to content

chore(deps): update all non-major dependencies#290

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/all-minor-patch
Open

chore(deps): update all non-major dependencies#290
renovate[bot] wants to merge 1 commit intomainfrom
renovate/all-minor-patch

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Dec 15, 2025

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@babel/core (source) ^7.28.4^7.29.0 age confidence dependencies patch
@babel/generator (source) ^7.28.3^7.29.1 age confidence dependencies patch
@babel/parser (source) ^7.28.4^7.29.0 age confidence dependencies patch
@babel/traverse (source) ^7.28.4^7.29.0 age confidence dependencies patch
@babel/types (source) ^7.28.4^7.29.0 age confidence dependencies patch
@biomejs/biome (source) 2.2.42.4.6 age confidence devDependencies minor
@changesets/cli (source) ^2.29.7^2.30.0 age confidence devDependencies patch
@cloudflare/vite-plugin (source) ^1.13.8^1.28.0 age confidence dependencies minor
@preact/preset-vite ^2.10.2^2.10.3 age confidence devDependencies patch
@solid-primitives/event-listener (source) ^2.4.3^2.4.5 age confidence dependencies patch
@solid-primitives/keyboard (source) ^1.3.3^1.3.5 age confidence dependencies patch
@solid-primitives/resize-observer (source) ^2.1.3^2.1.5 age confidence dependencies patch
@solidjs/start (source) ^1.2.0^1.3.2 age confidence dependencies minor
@tailwindcss/vite (source) ^4.0.6^4.2.1 age confidence dependencies patch
@tanstack/eslint-config (source) 0.3.20.4.0 age confidence devDependencies minor
@tanstack/react-form (source) ^1.23.7^1.28.5 age confidence dependencies patch
@tanstack/react-form-devtools (source) ^0.1.7^0.2.18 age confidence devDependencies minor
@tanstack/react-query (source) ^5.90.1^5.90.21 age confidence dependencies patch
@tanstack/react-query-devtools (source) ^5.90.1^5.91.3 age confidence dependencies patch
@tanstack/react-router (source) ^1.132.0^1.166.7 age confidence dependencies minor
@tanstack/react-router-devtools (source) ^1.132.0^1.166.7 age confidence dependencies minor
@tanstack/react-router-ssr-query (source) ^1.131.7^1.166.7 age confidence dependencies minor
@tanstack/react-start (source) ^1.132.0^1.166.8 age confidence dependencies patch
@tanstack/react-store (source) ^0.9.0^0.9.2 age confidence dependencies patch
@tanstack/router-plugin (source) ^1.132.0^1.166.7 age confidence dependencies minor
@tanstack/solid-query (source) ^5.90.1^5.90.26 age confidence dependencies patch
@tanstack/solid-query-devtools (source) ^5.90.1^5.91.3 age confidence dependencies patch
@tanstack/solid-router (source) ^1.131.50^1.166.7 age confidence dependencies minor
@tanstack/solid-router-devtools (source) ^1.131.50^1.166.7 age confidence dependencies minor
@tanstack/store (source) ^0.9.0^0.9.2 age confidence dependencies patch
@tanstack/typedoc-config (source) 0.2.10.3.3 age confidence devDependencies minor
@tanstack/vite-config (source) 0.2.10.5.0 age confidence devDependencies minor
@tanstack/vue-query (source) ^5.90.5^5.92.9 age confidence dependencies patch
@tanstack/vue-query-devtools (source) ^6.1.0^6.1.5 age confidence dependencies patch
@testing-library/dom ^10.4.0^10.4.1 age confidence devDependencies patch
@testing-library/jest-dom ^6.8.0^6.9.1 age confidence devDependencies patch
@testing-library/react ^16.2.0^16.3.2 age confidence devDependencies patch
@types/react (source) ^19.2.0^19.2.14 age confidence devDependencies patch
@types/react-dom (source) ^19.2.0^19.2.3 age confidence devDependencies patch
@vitejs/plugin-react (source) ^5.0.4^5.2.0 age confidence devDependencies minor
@vitejs/plugin-vue (source) ^6.0.1^6.0.5 age confidence devDependencies patch
actions/checkout v6.0.1v6.0.2 age confidence action patch
changesets/action v1.5.3v1.7.0 age confidence action minor
dayjs (source) ^1.11.19^1.11.20 age confidence dependencies patch
drizzle-kit (source) ^0.31.4^0.31.9 age confidence devDependencies patch
drizzle-orm (source) ^0.44.5^0.45.1 age confidence devDependencies minor
eslint (source) ^9.36.0^9.39.4 age confidence devDependencies patch
eslint-plugin-unused-imports ^4.2.0^4.4.1 age confidence devDependencies patch
eslint-plugin-vue (source) ^10.5.1^10.8.0 age confidence devDependencies patch
goober ^2.1.16^2.1.18 age confidence dependencies patch
jsdom ^27.0.0^27.4.0 age confidence devDependencies patch
knip (source) ^5.64.0^5.86.0 age confidence devDependencies minor
launch-editor ^2.11.1^2.13.1 age confidence dependencies patch
lucide-react (source) ^0.561.0^0.577.0 age confidence dependencies minor
markdown-link-extractor ^4.0.2^4.0.3 age confidence devDependencies patch
nx (source) 22.1.322.5.4 age confidence devDependencies minor
pg (source) ^8.16.3^8.20.0 age confidence devDependencies minor
pnpm (source) 10.24.010.32.1 age confidence packageManager minor
preact (source) ^10.28.0^10.29.0 age confidence devDependencies minor
preact (source) ^10.28.0^10.29.0 age confidence dependencies minor
prettier-plugin-svelte ^3.4.1^3.5.1 age confidence devDependencies patch
publint (source) ^0.3.13^0.3.18 age confidence devDependencies patch
react (source) ^19.2.0^19.2.4 age confidence devDependencies patch
react (source) ^19.2.0^19.2.4 age confidence dependencies patch
react-dom (source) ^19.2.0^19.2.4 age confidence dependencies patch
sherif ^1.7.0^1.10.0 age confidence devDependencies patch
solid-js (source) ^1.9.9^1.9.11 age confidence devDependencies patch
solid-js (source) ^1.9.9^1.9.11 age confidence dependencies patch
solid-js (source) ^1.9.9^1.9.11 age confidence dependencies patch
sonda (source) 0.9.00.11.1 age confidence devDependencies minor
streamdown (source) ^1.6.5^1.6.11 age confidence dependencies patch
tailwind-merge ^3.0.2^3.5.0 age confidence dependencies patch
tailwindcss (source) ^4.0.6^4.2.1 age confidence dependencies patch
tsup (source) ^8.5.0^8.5.1 age confidence devDependencies patch
tw-animate-css ^1.3.6^1.4.0 age confidence dependencies patch
typescript (source) ~5.9.2~5.9.3 age confidence devDependencies patch
vinxi (source) ^0.5.8^0.5.11 age confidence dependencies patch
vite (source) ^7.1.7^7.3.1 age confidence devDependencies patch
vite-plugin-mkcert ^1.17.8^1.17.10 age confidence devDependencies patch
vite-plugin-solid ^2.11.8^2.11.10 age confidence devDependencies patch
vite-tsconfig-paths ^6.0.2^6.1.1 age confidence dependencies patch
vue (source) ^3.5.22^3.5.30 age confidence devDependencies patch
vue (source) ^3.5.22^3.5.30 age confidence dependencies patch
wrangler (source) ^4.40.3^4.73.0 age confidence devDependencies minor
ws ^8.18.3^8.19.0 age confidence dependencies patch
zod (source) ^4.3.5^4.3.6 age confidence dependencies patch
zustand ^5.0.8^5.0.11 age confidence dependencies patch

Release Notes

biomejs/biome (@​biomejs/biome)

v2.4.6

Compare Source

Patch Changes

v2.4.5

Compare Source

Patch Changes
  • #​9185 e43e730 Thanks @​dyc3! - Added the nursery rule useVueScopedStyles for Vue SFCs. This rule enforces that <style> blocks have the scoped attribute (or module for CSS Modules), preventing style leakage and conflicts between components.

  • #​9184 49c8fde Thanks @​chocky335! - Improved plugin performance by batching all plugins into a single syntax visitor with a kind-to-plugin lookup map, reducing per-node dispatch overhead from O(N) to O(1) where N is the number of plugins.

  • #​9283 071c700 Thanks @​dyc3! - Fixed noUndeclaredVariables erroneously flagging functions and variables defined in the <script setup> section of Vue SFCs.

  • #​9221 4612133 Thanks @​ematipico! - Fixed an issue where the JSON reporter didn't contain the duration of the command.

  • #​9294 1805c8f Thanks @​Netail! - Extra rule source reference. biome migrate eslint should do a bit better detecting rules in your eslint configurations.

  • #​9178 101b3bb Thanks @​Bertie690! - Fixed #​9172 and #​9168:
    Biome now considers more constructs as valid test assertions.

    Previously, assert, expectTypeOf and assertType
    were not recognized as valid assertions by Biome's linting rules, producing false positives in lint/nursery/useExpect and other similar rules.

    Now, these rules will no longer produce errors in test cases that used these constructs instead of expect:

    import { expectTypeOf, assert, assertType } from "vitest";
    
    const myStr = "Hello from vitest!";
    it("should be a string", () => {
      expectTypeOf(myStr).toBeString();
    });
    test("should still be a string", () => {
      assertType<string>(myStr);
    });
    it.todo("should still still be a string", () => {
      assert(typeof myStr === "string");
    });
  • #​9173 32dad2d Thanks @​dyc3! - Added parsing support for Svelte's new comments-in-tags feature.

    The HTML parser will now accept JS style comments in tags in Svelte files.

    <button
      // single-line comment
      onclick={doTheThing}
    >click me</button>
    
    <div
      /* block comment */
      class="foo"
    >text</div>
  • #​8952 1d2ca15 Thanks @​pkallos! - Added the nursery rule useNullishCoalescing. This rule suggests using the nullish coalescing operator (??) instead of logical OR (||) when the left operand may be nullish. This prevents bugs where falsy values like 0, '', or false are incorrectly treated as missing. Addresses #​8043

    // Invalid
    declare const x: string | null;
    const value = x || "default";
    
    // Valid
    const value = x ?? "default";
  • #​9243 1992a85 Thanks @​Netail! - Fixed #​7813: improved the diagnostic of the rule useExhaustiveDependencies. The diagnostic now shows the name of the variable to add to the dependency array.

  • #​9063 3d0648f Thanks @​taga3s! - Added the nursery rule noVueRefAsOperand. This rule disallows cases where a ref is used as an operand.

    The following code is now flagged:

    import { ref } from "vue";
    
    const count = ref(0);
    count++; // Should be: count.value++
    import { ref } from "vue";
    
    const ok = ref(false);
    if (ok) {
      // Should be: if (ok.value)
      //
    }
  • #​9273 f239e20 Thanks @​denbezrukov! - Fixed #​9253: parsing of @container scroll-state(...) queries.

    @&#8203;container scroll-state(scrolled: bottom) {
    }
    @&#8203;container scroll-state(stuck) {
    }
    @&#8203;container scroll-state(not (stuck)) {
    }
    @&#8203;container scroll-state((stuck) and (scrolled: bottom)) {
    }
    @&#8203;container scroll-state((stuck) or (snapped: x)) {
    }
    @&#8203;container main-layout scroll-state(not ((stuck) and (scrolled: bottom))) {
    }
  • #​9259 96939c0 Thanks @​ematipico! - Fixed CSS formatter incorrectly collapsing selectors when a BOM (Byte Order Mark) character is present at the start of the file. The formatter now correctly preserves line breaks between comments and selectors in BOM-prefixed CSS files, matching Prettier's behavior.

  • #​9251 59e33fb Thanks @​ematipico! - Fixed #​9249: The CSS formatter no longer incorrectly breaks ratio values (like 1 / -1) across lines when followed by comments.

  • #​9284 ec3a17f Thanks @​denbezrukov! - Fixed #​9253: removed false-positive diagnostics for valid @container/@supports general-enclosed queries.

    @&#8203;container scroll-state(scrolled: bottom) {
    }
    @&#8203;supports foo(bar: baz) {
    }
  • #​9215 b2619a1 Thanks @​FrederickStempfle! - Fixed #​9189: biome ci in GitHub Actions now correctly disables colors so that ::error/::warning workflow commands are not wrapped in ANSI escape codes.

  • #​9256 65ae4c1 Thanks @​ematipico! - Fixed JSON reporter escaping of special characters in diagnostic messages. The JSON reporter now properly escapes double quotes, backslashes, and control characters in error messages and advice text, preventing invalid JSON output when diagnostics contain these characters.

  • #​9223 5b9da81 Thanks @​ematipico! - Fixed an issue where the JSON reporter didn't write output to a file when --reporter-file was specified. The output is now correctly written to the specified file instead of always going to stdout.

  • #​9154 c487e54 Thanks @​abossenbroek! - Fixed #​9115: The noPlaywrightMissingAwait rule no longer produces false positives on jest-dom matchers like toBeVisible, toBeChecked, toHaveAttribute, etc. For matchers shared between Playwright and jest-dom, the rule now checks whether expect()'s argument is a Playwright locator or page object before flagging. Added semantic variable resolution so that extracted Playwright locators (e.g. const loc = page.locator('.item'); expect(loc).toBeVisible()) are still correctly flagged.

  • #​9269 33e5cdf Thanks @​dyc3! - Fixed a false positive where noUndeclaredVariables reported bindings from Vue <script setup> as undeclared when used in <template>.

    This change ensures embedded bindings collected from script snippets (like imports and defineModel results) are respected by the rule.

  • #​9267 2c2e060 Thanks @​ematipico! - Fixed #​9143 and #​8849: The noUnresolvedImports rule no longer reports false positives for several common patterns:

    • node:fs, node:path, node:url, and other Node.js built-in modules with the node: prefix are now accepted.
    • Packages that declare their TypeScript entry point via "typings" (instead of "types") in package.json now resolve correctly.
    • Named imports from aliased re-export chains (e.g. export { x as y } from "...") are now resolved correctly through the alias.
    • Namespace re-exports (e.g. export * as Ns from "...") are now recognized as own exports of the barrel module.
  • #​9254 f7bf12b Thanks @​ematipico! - Fixed #​8842: The CSS formatter now correctly formats @container scroll-state() without adding an unwanted space between the function name and opening parenthesis.

  • #​9211 2d0b8e6 Thanks @​ematipico! - Fixed #​7905. Improved the accuracy of type-aware lint rules when analyzing re-exported functions and values.

    Previously, when a binding was imported from another module, its type was not correctly inferred during the type analysis phase. This caused type-aware lint rules to fail to detect issues when working with re-exported imports.

    The following rules now correctly handle re-exported imports:

    Example of now-working detection:

    // getValue.ts
    export async function getValue(): Promise<number> {
      return 42;
    }
    
    // reexport.ts
    export { getValue } from "./getValue";
    
    // index.ts
    import { getValue } from "./reexport";
    
    // Previously: no diagnostic (type was unknown)
    // Now: correctly detects that getValue() returns a Promise
    await getValue(); // Valid - properly awaited
    getValue(); // Diagnostic - floating promise

Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Summary by CodeRabbit

  • Chores
    • Updated package dependencies and development tools across all packages and examples to the latest compatible versions.
    • Updated GitHub Actions workflows to use latest versions of build and automation tools.
    • Updated package manager version for project consistency.

@changeset-bot
Copy link

changeset-bot bot commented Dec 15, 2025

⚠️ No Changeset found

Latest commit: b24a560

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@nx-cloud
Copy link

nx-cloud bot commented Dec 15, 2025

🤖 Nx Cloud AI Fix Eligible

An automatically generated fix could have helped fix failing tasks for this run, but Self-healing CI is disabled for this workspace. Visit workspace settings to enable it and get automatic fixes in future runs.

To disable these notifications, a workspace admin can disable them in workspace settings.


View your CI Pipeline Execution ↗ for commit b24a560

Command Status Duration Result
nx affected --targets=test:eslint,test:sherif,t... ❌ Failed 1m 49s View ↗
nx run-many --targets=build --exclude=examples/** ✅ Succeeded 28s View ↗

☁️ Nx Cloud last updated this comment at 2026-03-13 11:04:30 UTC

@pkg-pr-new
Copy link

pkg-pr-new bot commented Dec 15, 2025

More templates

@tanstack/devtools

npm i https://pkg.pr.new/@tanstack/devtools@290

@tanstack/devtools-client

npm i https://pkg.pr.new/@tanstack/devtools-client@290

@tanstack/devtools-ui

npm i https://pkg.pr.new/@tanstack/devtools-ui@290

@tanstack/devtools-utils

npm i https://pkg.pr.new/@tanstack/devtools-utils@290

@tanstack/devtools-vite

npm i https://pkg.pr.new/@tanstack/devtools-vite@290

@tanstack/devtools-event-bus

npm i https://pkg.pr.new/@tanstack/devtools-event-bus@290

@tanstack/devtools-event-client

npm i https://pkg.pr.new/@tanstack/devtools-event-client@290

@tanstack/preact-devtools

npm i https://pkg.pr.new/@tanstack/preact-devtools@290

@tanstack/react-devtools

npm i https://pkg.pr.new/@tanstack/react-devtools@290

@tanstack/solid-devtools

npm i https://pkg.pr.new/@tanstack/solid-devtools@290

@tanstack/vue-devtools

npm i https://pkg.pr.new/@tanstack/vue-devtools@290

commit: 0552f14

@renovate renovate bot force-pushed the renovate/all-minor-patch branch 26 times, most recently from 8f5167e to 09c56be Compare December 20, 2025 17:05
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 26 times, most recently from e861232 to 4b90eb1 Compare December 30, 2025 21:54
@coderabbitai
Copy link

coderabbitai bot commented Mar 13, 2026

📝 Walkthrough

Walkthrough

This pull request updates GitHub Actions workflow versions and bumps dependency/devDependency versions across the root, packages, and example projects; no source code logic or API signatures were changed.

Changes

Cohort / File(s) Summary
GitHub Actions Workflows
.github/workflows/autofix.yml, .github/workflows/pr.yml, .github/workflows/release.yml
Updated actions/checkout from v6.0.1v6.0.2; release.yml also updated changesets action from v1.5.3v1.7.0 and adjusted the Run Changesets step configuration.
Root workspace
package.json
Updated packageManager to pnpm@10.32.1; bumped many devDependencies (@changesets/cli, @tanstack/* tooling, eslint, nx, typescript, vite, and others).
Core devtools packages
packages/devtools/package.json, packages/devtools-ui/package.json, packages/devtools-utils/package.json, packages/devtools-vite/package.json, packages/event-bus/package.json
Version bumps for framework/runtime deps and dev tooling (solid-js, goober, dayjs, ws, tsup, vite-plugin-solid, Babel libs, launch-editor).
Framework-specific devtools
packages/preact-devtools/package.json, packages/react-devtools/package.json, packages/solid-devtools/package.json, packages/vue-devtools/package.json
Updated framework/runtime and devDependency versions (preact, react, solid-js, vue, types, and plugin versions).
Examples — React
examples/react/basic/package.json, examples/react/bundling-repro/package.json, examples/react/custom-devtools/package.json, examples/react/drizzle/package.json, examples/react/https/package.json, examples/react/start/package.json, examples/react/time-travel/package.json
Broad dependency and devDependency upgrades across TanStack packages, React, React DOM, typings, Vite and related tooling; large but consistent version bumps.
Examples — Solid / Preact / Vue
examples/solid/basic/package.json, examples/solid/devtools-ui/package.json, examples/solid/start/package.json, examples/preact/basic/package.json, examples/preact/custom-devtools/package.json, examples/vue/basic/package.json
Updated framework dependencies and dev tooling (solid-js, @solidjs/start, preact, vite, vite-plugin-solid, @vitejs/plugin-vue, @tanstack/vue-query).

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Poem

🐰 I hopped through package lists with a cheerful tune,
Bumping versions beneath the silver moon,
Workflows refreshed and examples all new,
A tiny rabbit's tidy update — fresh as dew! ✨

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title 'chore(deps): update all non-major dependencies' accurately and concisely describes the main objective of the PR, matching the raw summary showing extensive dependency updates across the project.
Description check ✅ Passed The PR description largely completes the required template with a detailed changelog table and release notes, though the body was truncated by the platform and some sections lack full detail.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch renovate/all-minor-patch
📝 Coding Plan
  • Generate coding plan for human review comments

Comment @coderabbitai help to get the list of available commands and usage tips.

Copy link

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
examples/react/bundling-repro/package.json (1)

18-26: Consider pinning @tanstack/ai-* packages to specific versions.

Using "latest" for these AI packages means builds are non-reproducible and could break unexpectedly when new versions are published. While acceptable for a repro/debugging example, consider pinning to specific versions if this example is used for CI or regression testing.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@examples/react/bundling-repro/package.json` around lines 18 - 26, The
package.json currently pins multiple `@tanstack/ai` packages to "latest" which
makes builds unreproducible; replace the "latest" specifiers for "@tanstack/ai",
"@tanstack/ai-anthropic", "@tanstack/ai-client", "@tanstack/ai-gemini",
"@tanstack/ai-ollama", "@tanstack/ai-openai", "@tanstack/ai-react",
"@tanstack/react-ai-devtools", and "@tanstack/react-devtools" with concrete
version numbers (choose a specific semver like "^X.Y.Z" or an exact "X.Y.Z") to
lock dependencies for CI/regression tests and update the lockfile accordingly.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Nitpick comments:
In `@examples/react/bundling-repro/package.json`:
- Around line 18-26: The package.json currently pins multiple `@tanstack/ai`
packages to "latest" which makes builds unreproducible; replace the "latest"
specifiers for "@tanstack/ai", "@tanstack/ai-anthropic", "@tanstack/ai-client",
"@tanstack/ai-gemini", "@tanstack/ai-ollama", "@tanstack/ai-openai",
"@tanstack/ai-react", "@tanstack/react-ai-devtools", and
"@tanstack/react-devtools" with concrete version numbers (choose a specific
semver like "^X.Y.Z" or an exact "X.Y.Z") to lock dependencies for CI/regression
tests and update the lockfile accordingly.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: de66d22c-d3cb-4f54-a7b2-387035694052

📥 Commits

Reviewing files that changed from the base of the PR and between a120650 and 11e75ba.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (26)
  • .github/workflows/autofix.yml
  • .github/workflows/pr.yml
  • .github/workflows/release.yml
  • examples/preact/basic/package.json
  • examples/preact/custom-devtools/package.json
  • examples/react/basic/package.json
  • examples/react/bundling-repro/package.json
  • examples/react/custom-devtools/package.json
  • examples/react/drizzle/package.json
  • examples/react/https/package.json
  • examples/react/start/package.json
  • examples/react/time-travel/package.json
  • examples/solid/basic/package.json
  • examples/solid/devtools-ui/package.json
  • examples/solid/start/package.json
  • examples/vue/basic/package.json
  • package.json
  • packages/devtools-ui/package.json
  • packages/devtools-utils/package.json
  • packages/devtools-vite/package.json
  • packages/devtools/package.json
  • packages/event-bus/package.json
  • packages/preact-devtools/package.json
  • packages/react-devtools/package.json
  • packages/solid-devtools/package.json
  • packages/vue-devtools/package.json

Copy link

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/release.yml:
- Line 26: Replace mutable action references like uses: actions/checkout@v6.0.2
with the immutable commit SHA form (e.g., uses:
actions/checkout@<FULL_COMMIT_SHA>) while preserving the human-friendly tag as a
trailing comment (e.g., # v6.0.2) to maintain readability; update the checkout
usages in the release workflow (the uses: actions/checkout entries) and apply
the same SHA-pinning pattern to the checkout actions referenced in pr.yml (the
uses: actions/checkout entries on the other specified lines).

In `@package.json`:
- Around line 62-65: The `@tanstack` package upgrades introduce breaking changes:
update our build/docs configs accordingly by (1) in typedoc-related code/configs
(search for any Typedoc config files or usages that expect lower-cased output)
remove or adjust any post-processing that lower-cases Typedoc output and ensure
templates/consumers accept the new casing produced by `@tanstack/typedoc-config`
v0.3.3, and (2) in vite.config.ts (look for references to viteConfig or imports
from `@tanstack/vite-config`) migrate the old viteConfig usage to the new shape:
upgrade to Vite 8+ if not already and replace viteConfig options with
rolldownOptions and use the new native resolve.tsconfigPaths behavior (update
imports, option names, and any tsconfig path resolution code). Make these
changes where viteConfig and Typedoc config objects are defined so the project
builds and docs generate correctly with the new `@tanstack` versions.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 3e3729bd-9872-4d23-b9a5-164d848e5c26

📥 Commits

Reviewing files that changed from the base of the PR and between 11e75ba and b24a560.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (26)
  • .github/workflows/autofix.yml
  • .github/workflows/pr.yml
  • .github/workflows/release.yml
  • examples/preact/basic/package.json
  • examples/preact/custom-devtools/package.json
  • examples/react/basic/package.json
  • examples/react/bundling-repro/package.json
  • examples/react/custom-devtools/package.json
  • examples/react/drizzle/package.json
  • examples/react/https/package.json
  • examples/react/start/package.json
  • examples/react/time-travel/package.json
  • examples/solid/basic/package.json
  • examples/solid/devtools-ui/package.json
  • examples/solid/start/package.json
  • examples/vue/basic/package.json
  • package.json
  • packages/devtools-ui/package.json
  • packages/devtools-utils/package.json
  • packages/devtools-vite/package.json
  • packages/devtools/package.json
  • packages/event-bus/package.json
  • packages/preact-devtools/package.json
  • packages/react-devtools/package.json
  • packages/solid-devtools/package.json
  • packages/vue-devtools/package.json
🚧 Files skipped from review as they are similar to previous changes (17)
  • examples/react/time-travel/package.json
  • packages/preact-devtools/package.json
  • packages/devtools/package.json
  • packages/devtools-ui/package.json
  • packages/devtools-utils/package.json
  • packages/react-devtools/package.json
  • examples/solid/devtools-ui/package.json
  • packages/solid-devtools/package.json
  • .github/workflows/autofix.yml
  • examples/solid/basic/package.json
  • packages/vue-devtools/package.json
  • examples/react/basic/package.json
  • examples/vue/basic/package.json
  • examples/preact/basic/package.json
  • packages/devtools-vite/package.json
  • examples/preact/custom-devtools/package.json
  • examples/react/start/package.json

steps:
- name: Checkout
uses: actions/checkout@v6.0.1
uses: actions/checkout@v6.0.2
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "Unpinned GitHub Actions references in workflows:"
rg -nP '^\s*uses:\s*[^@]+@(?![0-9a-f]{40}\b)\S+' .github/workflows

echo
echo "Resolve immutable SHAs for tags touched in this PR:"
for item in "actions/checkout v6.0.2" "changesets/action v1.7.0"; do
  repo=$(awk '{print $1}' <<<"$item")
  tag=$(awk '{print $2}' <<<"$item")
  sha=$(git ls-remote --refs --tags "https://github.com/${repo}.git" \
        "refs/tags/${tag}" "refs/tags/${tag}^{}" | awk 'END{print $1}')
  printf "%s@%s -> %s\n" "$repo" "$tag" "$sha"
done

Repository: TanStack/devtools

Length of output: 1721


Pin GitHub Actions to immutable commit SHAs.

Lines 26 and 34 use mutable version tags. Pinning to full commit SHAs improves CI integrity and provenance; keep the tag as a trailing comment for readability. Apply the same pattern to all checkout actions in .github/workflows/pr.yml (lines 26, 42, and 56).

Suggested changes
-        uses: actions/checkout@v6.0.2
+        uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
...
-        uses: changesets/action@v1.7.0
+        uses: changesets/action@e87c8ed249971350e47fab7515075f44eb134e5b # v1.7.0
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
uses: actions/checkout@v6.0.2
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/release.yml at line 26, Replace mutable action references
like uses: actions/checkout@v6.0.2 with the immutable commit SHA form (e.g.,
uses: actions/checkout@<FULL_COMMIT_SHA>) while preserving the human-friendly
tag as a trailing comment (e.g., # v6.0.2) to maintain readability; update the
checkout usages in the release workflow (the uses: actions/checkout entries) and
apply the same SHA-pinning pattern to the checkout actions referenced in pr.yml
(the uses: actions/checkout entries on the other specified lines).

Comment on lines +62 to +65
"@tanstack/eslint-config": "0.4.0",
"@tanstack/intent": "^0.0.14",
"@tanstack/typedoc-config": "0.2.1",
"@tanstack/vite-config": "0.2.1",
"@testing-library/jest-dom": "^6.8.0",
"@tanstack/typedoc-config": "0.3.3",
"@tanstack/vite-config": "0.5.0",
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

🧩 Analysis chain

🌐 Web query:

`What are the breaking changes (if any) between:

  1. @tanstack/eslint-config 0.3.2 -> 0.4.0
  2. @tanstack/typedoc-config 0.2.1 -> 0.3.3
  3. @tanstack/vite-config 0.2.1 -> 0.5.0
    Please cite official release notes/changelogs.`

💡 Result:

1) @tanstack/eslint-config 0.3.2 → 0.4.0

  • No explicit BREAKING change is called out in the release notes; the only noted change is: “update to @eslint/js v10”. [1]
  • However, the official docs for this config state you must have ESLint v9+ installed, which may be a practical breaking requirement if you were on ESLint 8. [2]

2) @tanstack/typedoc-config 0.2.1 → 0.3.3

  • Breaking change introduced in 0.3.0: upgrade to TypeDoc v0.28, and “typedoc output is no longer lower-cased” (marked BREAKING in the release notes). [3]
  • 0.3.3 is a patch release (“migrate to tsdown”) and does not list breaking changes. [4]

3) @tanstack/vite-config 0.2.1 → 0.5.0

  • 0.3.0: update to Vite v7 (major Vite bump; not labeled breaking in the release note, but it is a major underlying dependency change). [5]
  • 0.4.0: “support for bundling dependencies” (not labeled breaking). [6]
  • Breaking change in 0.5.0: “Bump to Vite 8 with Rolldown. Drops Vite 6/7 support. Switches to rolldownOptions and native resolve.tsconfigPaths.” [7]

Sources (official release notes/docs): GitHub Releases for TanStack/config and TanStack Config docs. [1][2][3][4][5][6][7]


Address breaking changes in upgraded @tanstack config packages before merge.

Lines 62–65 upgrade three @tanstack config packages with 0.x minor bumps that introduce breaking changes:

  • @tanstack/typedoc-config (0.2.1 → 0.3.3): Breaking change in 0.3.0 — "typedoc output is no longer lower-cased" (output format changed).
  • @tanstack/vite-config (0.2.1 → 0.5.0): Breaking change in 0.5.0 — drops support for Vite 6/7, requires Vite 8+, and switches configuration from viteConfig to rolldownOptions with native resolve.tsconfigPaths.

These upgrades require corresponding changes to the codebase configuration (especially vite.config.ts). Verify and apply necessary config adjustments before merging.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@package.json` around lines 62 - 65, The `@tanstack` package upgrades introduce
breaking changes: update our build/docs configs accordingly by (1) in
typedoc-related code/configs (search for any Typedoc config files or usages that
expect lower-cased output) remove or adjust any post-processing that lower-cases
Typedoc output and ensure templates/consumers accept the new casing produced by
`@tanstack/typedoc-config` v0.3.3, and (2) in vite.config.ts (look for references
to viteConfig or imports from `@tanstack/vite-config`) migrate the old viteConfig
usage to the new shape: upgrade to Vite 8+ if not already and replace viteConfig
options with rolldownOptions and use the new native resolve.tsconfigPaths
behavior (update imports, option names, and any tsconfig path resolution code).
Make these changes where viteConfig and Typedoc config objects are defined so
the project builds and docs generate correctly with the new `@tanstack` versions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants