Skip to content

fix(deps): update all dependencies - #20

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all
Open

fix(deps): update all dependencies#20
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Feb 21, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@biomejs/biome (source) ^2.4.4^2.5.7 age confidence devDependencies minor
@changesets/changelog-github (source) ^0.5.2^0.7.0 age confidence devDependencies minor
@changesets/cli (source) ^2.29.8^2.31.1 age confidence devDependencies minor
@eslint-community/eslint-plugin-eslint-comments ^4.6.0^4.7.2 age confidence devDependencies minor
@eslint/compat (source) 2.0.22.1.0 age confidence devDependencies minor
@eslint/eslintrc 3.3.33.3.6 age confidence devDependencies patch
@types/node (source) ^24.10.13^24.13.3 age confidence devDependencies minor
@typescript-eslint/eslint-plugin (source) ^8.56.0^8.66.0 age confidence devDependencies minor
@typescript-eslint/parser (source) ^8.56.0^8.66.0 age confidence devDependencies minor
@vitest/coverage-v8 (source) ^4.0.18^4.1.10 age confidence devDependencies minor
@vitest/eslint-plugin ^1.6.9^1.6.26 age confidence devDependencies patch
actions/checkout v6v7 age confidence action major
actions/setup-node v6v7 age confidence action major
actions/upload-artifact v6v7 age confidence action major
effect (source) ^3.19.18^3.22.1 age confidence dependencies minor
eslint (source) ^10.0.1^10.8.0 age confidence devDependencies minor
eslint-import-resolver-typescript ^4.4.4^4.4.5 age confidence devDependencies patch
eslint-plugin-simple-import-sort ^12.1.1^14.0.0 age confidence devDependencies major
eslint-plugin-sonarjs (source) ^4.0.0^4.2.0 age confidence devDependencies minor
eslint-plugin-unicorn ^63.0.0^73.0.0 age confidence devDependencies major
globals ^17.3.0^17.9.0 age confidence devDependencies minor
jscpd (source) ^4.0.8^5.0.14 age confidence devDependencies major
node 24.13.124.19.0 age confidence uses-with minor
pnpm (source) 10.30.111.20.0 age confidence packageManager major
pnpm/action-setup v4v6 age confidence action major
pnpm/action-setup v3v6 age confidence action major
typescript (source) ^5.9.3^7.0.2 age confidence devDependencies major
typescript-eslint (source) ^8.56.0^8.66.0 age confidence devDependencies minor
vite (source) ^7.3.1^8.2.0 age confidence devDependencies major
vitest (source) ^4.0.18^4.1.10 age confidence devDependencies minor

cc @skulidropek


Release Notes

biomejs/biome (@​biomejs/biome)

v2.5.7

Compare Source

Patch Changes
  • #​10822 c171b3b Thanks @​pkallos! - Added the option ignoreIfStatements to useNullishCoalescing. Biome now flags if statements that only assign to a nullish variable (such as if (!a) { a = b }) and can rewrite them to ??=. When enabled, Biome ignores those if statements.

  • #​11136 e63354c Thanks @​AkashNaickar! - Added a new nursery rule noExtendNative, which reports extending the prototype of a built-in object.

  • #​10094 e007143 Thanks @​THEjacob1000! - Added the nursery rule noTailwindArbitraryValue. Biome now reports Tailwind CSS arbitrary values such as w-[400px], including in HTML/JSX class attributes, configured utility functions, and tagged templates.

  • #​11184 135f476 Thanks @​subotac! - Fixed #​11176: noUnknownPseudoClass now recognizes Vue's :deep() pseudo-class inside .vue style blocks.

  • #​8239 a519f9d Thanks @​cormacrelf! - Fixed #​8233, where Biome CLI in
    stdin mode didn't work correctly when handling files in projects with nested
    configurations. For example, with the following structure,
    --stdin-file-path=subdirectory/... would not use the nested configuration in
    subdirectory/biome.json:

    ├── biome.json
    └── subdirectory
        ├── biome.json
        └── lib.js
    
    biome format --write --stdin-file-path=subdirectory/lib.js < subdirectory/lib.js

    Now, the nested configuration is correctly picked up and applied.

    In addition, Biome now shows a warning if --stdin-file-path is provided but
    that path is ignored and therefore not formatted or fixed.

  • #​11138 8c2c6bd Thanks @​ematipico! - Fixed noUnnecessaryConditions: Biome now chooses the same function overload as TypeScript when an argument is a callback, so conditions that were previously missed are reported.

    The following code is now invalid, because a parameter typed () => void accepts an async callback and schedule therefore returns string:

    declare function schedule(handler: () => void): string;
    declare function schedule(handler: () => Promise<void>): string | undefined;
    
    schedule(async () => {}) ?? "fallback";

    The following code is also now invalid, because map(() => 42) returns 42:

    type Mapper<T> = () => T;
    declare function map<T>(mapper: Mapper<T>): T;
    
    map(() => 42) || flag;
  • #​11138 8c2c6bd Thanks @​ematipico! - Fixed #​11087: noUnnecessaryConditions no longer reports optional chains and nullish coalescing whose receiver can be nullish.

    For example, the optional chain and fallback in the following code are no longer reported:

    declare const usage: { range: { startDate: string } } | null;
    const startDate = usage?.range.startDate ?? "N/A";
  • #​11118 9c16840 Thanks @​subotac! - Fixed #​11098: The HTML formatter now preserves the configured trailing newline when a file ends with a comment.

    -<!-- trailing comment -->
    \ No newline at end of file
    +<!-- trailing comment -->
  • #​11201 0e80610 Thanks @​Bishwas-py! - Fixed #​11182: suppression comments for noPositiveTabindex now suppress the rule in HTML files when the attributes of the element span multiple lines.

  • #​11079 607afd2 Thanks @​dyc3! - The HTML formatter now lays out the srcset attribute of <img> and <source> as the list of candidates it is. Runs of whitespace between candidates collapse, and once the list no longer fits on one line each candidate goes on its own line with the descriptors aligned:

    - <img srcset="/visual@0.5.png  400w, /visual.png 805w, /visual@2x.png 1610w, /visual@3x.png 2415w" />
    + <img
    +   srcset="
    +     /visual@0.5.png  400w,
    +     /visual.png      805w,
    +     /visual@2x.png  1610w,
    +     /visual@3x.png  2415w
    +   "
    + />
  • #​11156 fed72c7 Thanks @​saberoueslati! - Fixed #​11129: noUnusedVariables no longer reports Vue bindings as unused when they are assigned through automatically unwrapped template refs.

  • #​11124 d890b39 Thanks @​denbezrukov! - Fixed CSS formatting of line comments between a declaration colon and value to preserve their source indentation.

     .test {
       background:
    -  /////// foo
    -  // bar
    +        /////// foo
    +        // bar
         radial-gradient(circle, #&#8203;000, transparent);
     }
  • #​11113 3d8ab73 Thanks @​denbezrukov! - Fixed CSS formatting of long block comments between comma-separated property values:

     .foo {
       box-shadow:
    -    1000px /* long long long long long long long long long long long long comment */ 1000px /* long long long long long long long long long comment */ 2px color(srgb 0.555555555 0.555555555 0.555555555),
    +    1000px
    +      /* long long long long long long long long long long long long comment */
    +      1000px /* long long long long long long long long long comment */ 2px
    +      color(srgb 0.555555555 0.555555555 0.555555555),
         1px 1px black;
     }
  • #​11127 da5c1a5 Thanks @​dyc3! - The HTML formatter now picks the quote character for an attribute by counting the quotes in the value rather than looking only for a double quote. &apos; and &quot; count as the characters they stand for, and only the character that ends up as the delimiter stays escaped:

    - <div title='123 &apos;&quot; 456'></div>
    + <div title="123 '&quot; 456"></div>

    Entities that are not quotes, such as &amp; or &[#&#8203;39](https://redirect.github.com/biomejs/biome/issues/39);, are left exactly as written.

  • #​11193 77035bb Thanks @​dyc3! - Fixed the HTML formatter collapsing the blank line between an element and the text that follows it. A blank line before text is now kept, the way one before another element already was:

      <div>foo</div>
    -
      text
  • #​11106 ad80f57 Thanks @​dyc3! - The HTML formatter now writes the HTML5 doctype in lowercase, matching Prettier:

    - <!DOCTYPE html>
    + <!doctype html>

    This only applies to a plain .html file whose doctype stands alone. A doctype that names a DTD keeps the case it was written with, since the rest of the declaration is not lowercased either:

    <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

    A .vue, .svelte, or .astro file keeps whatever the author wrote.

  • #​11188 60679db Thanks @​dyc3! - Fixed the HTML formatter printing a comment twice when it ended the line of the last element in a document:

    - text<!-- a --><!-- a -->
    + text<!-- a -->
  • #​11077 4dcd0d9 Thanks @​dyc3! - Fixed a bug where the HTML formatter collapsed the whitespace inside <textarea>, <xmp> and <plaintext>, changing what the page renders.

    - <textarea>
    -  line one
    - line two </textarea>
    + <textarea>line one line two</textarea>

    Biome now prints the content of these elements exactly as it appears in the source, matching the existing behavior for <pre>.

  • #​11194 abfbb11 Thanks @​dyc3! - Fixed the HTML formatter refusing to format a Svelte file containing an array pattern that skips a position:

    {#each animals as [, value]}
    	<p>{value}</p>
    {/each}
  • #​10094 e007143 Thanks @​THEjacob1000! - Fixed useSortedClasses to correctly detect unsorted classes in static member expression tagged templates (e.g. tw.div\...``). Previously, these were silently skipped due to surrounding whitespace trivia not being stripped from the tag name.

  • #​11078 10da30e Thanks @​dyc3! - Fixed Vue single-file components failing to parse when they contain a custom block such as <i18n> or <docs>, or a <template> written in another language. Their content is no longer read as HTML, so a block may hold whatever its own tooling expects:

    <docs>
    This block is prose, and it may mention a `<my-component>` without closing it.
    </docs>
    
    <template lang="pug">
      .test
        #foo
    </template>

    Previously both blocks produced a parse error and the whole file was left unformatted. Biome now prints their content unchanged while still formatting the opening tag.

  • #​11231 4afd901 Thanks @​ematipico! - Improved the performance of the following lint rules:

  • #​11134 2fa0a62 Thanks @​yanthomasdev! - Clarified the warning emitted when using the experimental json and json-pretty reporters.

  • #​11198 ed88b13 Thanks @​saberoueslati! - Fixed #​11171: variables referenced only inside a Svelte attachment ({@attach ...}) are no longer reported as unused by noUnusedVariables and noUnusedImports.

  • #​11155 6ee17ea Thanks @​dyc3! - Improved performance when printing diagnostics to the console.

  • #​11160 217f8ad Thanks @​dyc3! - Improved the performance of noFloatingPromises by skipping type inference for assignment statements, which are always considered handled.

  • #​11159 26c23d9 Thanks @​saberoueslati! - Fixed #​11144: noFloatingPromises no longer reports already-awaited optional Promise values.

  • #​11138 8c2c6bd Thanks @​ematipico! - Fixed #​11121: noUnnecessaryConditions no longer reports conditions based on an inapplicable function overload.

    For example, the condition in the following code is no longer reported because query({}) selects the overload that returns boolean:

    declare function query(options: { initial: string }): { isPending: false };
    declare function query(options: { initial?: string }): { isPending: boolean };
    
    const { isPending } = query({});
    isPending || fallback;
  • #​11152 c4fc6a9 Thanks @​dyc3! - Improved the performance of collecting rule timings with --profile-rules in heavily multithreaded environments.

  • #​11128 4d3ff76 Thanks @​ematipico! - Fixed #​7635: noDeprecatedImports now detects deprecated ambient declarations that are exported separately.

  • #​11117 01f7ef5 Thanks @​subotac! - Fixed #​11014: noDelete no longer reports process.env["FOO"] style property deletions.

  • #​11168 9847e68 Thanks @​saberoueslati! - Added the nursery rule noNonScalableViewport, which reports viewport metadata that disables user scaling with user-scalable=no.

    For example:

    <meta name="viewport" content="width=device-width, user-scalable=no" />
  • #​11154 a1d6b1f Thanks @​dyc3! - Improved the performance of noImportCycles by skipping graph traversals for imports that cannot be part of a cycle.

  • #​11175 d96d6dd Thanks @​ematipico! - Fixed CSS parsing of registered custom properties: Biome now correctly validates the syntax descriptor of @property rules.

v2.5.6

Compare Source

Patch Changes
  • #​11035 0e4b03b Thanks @​ematipico! - Fixed a performance regression in noMisusedPromises that caused type inference to run repeatedly while linting a file.

  • #​11043 22ec076 Thanks @​denbezrukov! - Fixed CSS formatting for multiline function arguments preceded by comments:

     .example {
       value: outer(
         1,
         /* comment */
         nested(
    -      first,
    -      second
    -    )
    +        first,
    +        second
    +      )
       );
     }
  • #​11007 c9acb25 Thanks @​BTF-Kabir-2020! - Fixed #​9195: useHookAtTopLevel no longer reports hooks in named forwardRef components that receive a ref parameter.

  • #​10152 50a9bd8 Thanks @​Zelys-DFKH! - Fixed #​10131: Biome now correctly parses curried arrow functions in ternary consequents when the inner arrow's parameters use a destructuring pattern, e.g. cond ? (x) => ({ a, b }) => body : alt.

  • #​11105 8ffe2b9 Thanks @​dadavidtseng! - Fixed #​11092: The noUselessTernary quick fix now preserves operator spacing when simplifying or inverting boolean ternary expressions.

  • #​10533 5809875 Thanks @​Mokto! - Fixed #​10515: biome check --write was not idempotent on Svelte files — multi-line template literals in <script> blocks and block comments in <style> blocks gained an extra indent level on every run.

  • #​11040 0abb620 Thanks @​Mokto! - Fixed an issue where the HTML formatter would duplicate a comment placed directly before a Svelte {@const ...} or {@debug ...} block. The duplication compounded on every subsequent --write, causing the file to grow exponentially.

  • #​10858 6d18204 Thanks @​ruidosujeira! - Fixed #​10839: Svelte {#each} array destructuring no longer includes spaces inside square brackets, and multiline bind function expressions now indent their getter, setter, and function body correctly.

  • #​11009 2c36626 Thanks @​ematipico! - Improved the accuracy of type-aware lint rules by resolving more inferred types. For example, noFloatingPromises now detects floating Promises returned by aliased callbacks and arrays of Promises created by async mapping callbacks.

    The following statements are now reported:

    type AsyncCallback = () => Promise<void>;
    declare const callback: AsyncCallback;
    callback();
    
    [1, 2, 3].map(async (value) => value);
  • #​10973 9cb044c Thanks @​ematipico! - Fixed false positives in noMisleadingReturnType when generic-constraint, normalization, substitution, or structural return-type comparison cannot complete. The rule now suppresses diagnostics rather than suggesting a return type derived from partial information. For example, this unresolved return type is no longer reported:

    function unresolvedReturnType(): MissingType {
      return "value" as const;
    }
  • #​11071 15047a2 Thanks @​dyc3! - The HTML parser now accepts mixed-case doctype declarations.

  • #​11030 cc90e65 Thanks @​marschattha! - The rdjson reporter now populates the severity field of each diagnostic (ERROR, WARNING, or INFO), so tools consuming Reviewdog Diagnostic Format output no longer need to assume a default severity.

  • #​11009 2c36626 Thanks @​ematipico! - Fixed a performance regression in type-aware JavaScript lint rules by inferring only requested types and memoizing export resolution.

  • #​11056 903b177 Thanks @​dyc3! - Added support for Svelte declaration tags using let and const. Biome can now parse, format, and lint bindings declared in these tags.

  • #​11045 89c27c6 Thanks @​ematipico! - Improved the performance of Biome formatter up to ~7% across the board.

  • #​9806 781d68d Thanks @​dyc3! - Added the nursery rule noJsRestrictedProperties, which ports ESLint's no-restricted-properties rule. Biome now flags restricted member access and object destructuring, and biome migrate eslint preserves the rule's options.

v2.5.5

Compare Source

Patch Changes
  • #​10972 ab8c21b Thanks @​ematipico! - Fixed useExhaustiveSwitchCases for unions of bigint literals. The rule now reports missing bigint cases and compares bigint literals by value, including binary, octal, hexadecimal, and separator-containing spellings. For example, this switch now reports the missing 2n case:

    declare const value: 1n | 2n;
    switch (value) {
      case 1n:
        break;
    }
  • #​10972 ab8c21b Thanks @​ematipico! - Fixed false positives in noBaseToString and useNullishCoalescing when member, stringification, or nullish inference cannot complete. These rules now suppress diagnostics instead of reporting from partial type information. For example, neither expression is reported when a recursive type cannot be fully resolved:

    type Recursive = Recursive;
    declare const value: Recursive;
    
    String(value);
    value || "fallback";
  • #​10977 0bf7486 Thanks @​ematipico! - Fixed #​10922: the action useSortedAttributes no longer triggers for HTML instructions.

  • #​10957 cf263c4 Thanks @​dyc3! - Fixed noThenProperty failing to detect Object.fromEntries, Object.defineProperty, and Reflect.defineProperty calls with comments between their tokens.

  • #​10983 edc0ed7 Thanks @​ayaangazali! - Fixed #​10980: useAriaPropsSupportedByRole no longer reports false positives when the attribute that determines an element's implicit ARIA role is written as a shorthand attribute, such as <a {href} aria-label="..."> in Astro and Svelte files.

    Shorthand attributes are now taken into account when computing the implicit role, so the anchor above correctly resolves to the link role instead of generic.

  • #​10889 89526e3 Thanks @​denbezrukov! - Fixed CSS formatter casing for syntax-owned names while preserving author-defined names, including scoped keyframes and container scroll-state queries.

    - A:HOVER { COLOR: INITIAL; }
    + A:hover { color: initial; }
    - @KEYFRAMES :GLOBAL KeepFrames { FROM { COLOR: RED; } }
    + @keyframes :GLOBAL KeepFrames { from { color: RED; } }
    - @CONTAINER scroll-state((SCROLLED: TOP) AND (STUCK)) { A:HOVER { COLOR: RED; } }
    + @container scroll-state((SCROLLED: TOP) AND (STUCK)) { A:hover { color: RED; } }
  • #​10964 794ccd0 Thanks @​denbezrukov! - Fixed CSS formatting for comments between declaration values and !important.

    -a { color: /* before */ /* after */ red !important; }
    +a { color: /* before */ red /* after */ !important; }
  • #​10993 b7a9694 Thanks @​denbezrukov! - Fixed the CSS formatter to preserve comments on the correct side of selector combinators and before declaration blocks.

    -.before > /* comment */ .after {}
    +.before /* comment */ > .after {}

    It now also keeps selectors with escaped newlines in attribute values inline when they fit.

    -div
    -  span[foo="bar\
    +div span[foo="bar\
     value"] {}
  • #​10978 8ebafe1 Thanks @​ematipico! - Fixed #​10870: noUnresolvedImports no longer reports false positives such as import type { NextRequest } from "next/server".

  • #​10901 68c10e6 Thanks @​Socialpranker! - Fixed #​10622: the HTML/Vue parser no longer panics on the argument-less v-bind shorthand (:="props").

    This syntax is valid Vue and equivalent to v-bind="props", so the parser now accepts it (along with the longhand v-bind:="props") instead of crashing while building a diagnostic for a missing argument.

  • #​10936 7df46f5 Thanks @​ematipico! - Improved generic tuple inference for useIncludes. The rule now recognizes specialised tuple element types returned through generic aliases.

  • #​10941 f787725 Thanks @​siketyan! - Fixed #10855: Biome now supports parsing and formatting CSS custom media queries declared with @custom-media.

  • #​10969 72d309b Thanks @​ematipico! - Fixed an issue where Biome logs became too verbose, dumping information not relevant to user's operations.

  • e62f6b6 Thanks @​ematipico! - Fixed #​10963: Biome no longer panics when a type-aware rule such as noFloatingPromises checks a call to a function with multiple call signatures imported from another module.

  • #​10931 899c60d Thanks @​ematipico! - Fixed check --write command. Now the command reports code frame of the formatted code, if the formatter is enabled.

  • #​10904 ceee4f4 Thanks @​qzwxsaedc! - Fixed #​10892: noUnnecessaryConditions no longer reports a false positive when checking a member of a discriminated union that is accessed through a default type-only namespace import. The following code is no longer flagged:

    import type Types from "./types";
    
    declare function parse(): Types.Result<string>;
    const result = parse();
    if (!result.success) {
    }
  • #​10962 f0a67f2 Thanks @​ematipico! - Biome no longer removes embedded styles and scripts in HTML files.

  • #​11000 5039a1e Thanks @​ematipico! - Fixed a bug where closing one editor stopped a shared Biome daemon used by other editors. LSP proxy processes now exit when either the editor or daemon disconnects.

  • #​10957 cf263c4 Thanks @​dyc3! - Improved the performance of the noThenProperty lint rule by about 50%.

  • #​10992 4bf9b21 Thanks @​ematipico! - Fixed noMisusedPromises: The rule now reports Promise-returning callbacks where a synchronous callback is expected when calls use tuple spreads or tuple rest parameters, including generic and deeply nested tuples, and when constructor signatures come from interface or object types. Recursive or excessively nested tuple spreads use a conservative fallback so analysis terminates.

    For example, the following callback is now reported.

    declare function consume(...args: [number, () => void]): void;
    const prefix: [number] = [1];
    
    consume(...prefix, async () => {});
  • #​10915 b3b12b3 Thanks @​Functionhx! - Added the rule noNegationInEqualityCheck. The rule flags negated expressions on the left side of strict equality checks like !foo === bar — due to operator precedence this evaluates as (!foo) === bar which is almost always a mistake for foo !== bar.

    The rule provides an unsafe fix that flips the operator.

    // Invalid
    !foo === bar;
    !foo !== bar;
    
    // Valid
    foo !== bar;
    foo === bar;
  • #​10970 bd1038b Thanks @​ematipico! - Improved overload selection for noMisusedPromises. Biome now handles overloaded calls, overloaded constructors, rest parameters, union arguments, and generic constraints without selecting an incompatible signature. For example, noMisusedPromises now reports the async callback passed to the synchronous overload:

    declare function consume(kind: "async", callback: () => Promise<void>): void;
    declare function consume(kind: "sync", callback: () => void): void;
    consume("sync", async () => {});
  • #​10933 48a4abb Thanks @​ematipico! - Fixed useArrayFind to recognize bigint zero indexes.

  • #​10931 899c60d Thanks @​ematipico! - Fixed an orchestration issue that could lead to deadlocks when type-aware rules are enabled.

  • #​10969 72d309b Thanks @​ematipico! - Hardened the Biome Language Server by improving its synchronisation logic.

  • #​10972 ab8c21b Thanks @​ematipico! - Fixed false positives in noMisusedPromises and useAwaitThenable when Promise or thenable inference cannot complete. These rules now suppress diagnostics instead of treating incomplete type information as a definite result. For example, useAwaitThenable no longer reports await value when the value's thenability is unknown:

    declare const value: unknown;
    
    async function consume() {
      await value;
    }

v2.5.4

Compare Source

Patch Changes

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from skulidropek February 21, 2026 13:44
@renovate renovate Bot changed the title fix(deps): update dependency effect to ^3.19.19 fix(deps): update all dependencies Feb 23, 2026
@renovate
renovate Bot force-pushed the renovate/all branch 9 times, most recently from 52aba09 to 16d549f Compare March 2, 2026 17:40
@renovate
renovate Bot force-pushed the renovate/all branch 10 times, most recently from f240877 to 3c2e51f Compare March 9, 2026 23:06
@renovate
renovate Bot force-pushed the renovate/all branch 7 times, most recently from 9456c54 to 0ff8d9f Compare March 17, 2026 14:38
@renovate
renovate Bot force-pushed the renovate/all branch 5 times, most recently from 6ff8486 to 4c77644 Compare April 24, 2026 02:39
@coderabbitai

coderabbitai Bot commented May 14, 2026

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Bump CI action versions, pin pnpm to 11.1.2 in root and app, and update Changesets plus many app dependencies/devDependencies (Effect stack, TypeScript tooling, linting, testing, and build tools).

Changes

Toolchain and dependency upgrades

Layer / File(s) Summary
GitHub Actions versions
.github/actions/setup/action.yml, .github/workflows/checking-dependencies.yml, .github/workflows/snapshot.yml
pnpm action bumped to @v6 in composite and workflow; actions/setup-node Node input updated to 24.15.0; artifact upload action bumped to actions/upload-artifact@v7.
pnpm version pins
package.json, packages/app/package.json
Workspace and app packageManager updated from pnpm@10.30.1 to pnpm@11.1.2.
Dependency and toolchain upgrades
package.json, packages/app/package.json
Root Changesets packages (@changesets/changelog-github, @changesets/cli) bumped; app package dependencies and devDependencies refreshed (Effect packages, ts-morph, Biome/ESLint, TypeScript tooling, Vitest/Vite, etc.).

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related issues

Poem

🐇 I nudged a YAML line, made pnpm climb to eleven,
Actions hum a newer tune, workflows light as heaven.
Packages refreshed, linters wake and play,
Tests tiptoe cleaner paths, building through the day.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly summarizes the primary dependency and toolchain updates in the pull request.
Description check ✅ Passed The description directly documents the dependency, package manager, and GitHub Actions updates in the changeset.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch renovate/all

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/actions/setup/action.yml:
- Line 13: The workflow currently uses a mutable tag "pnpm/action-setup@v6";
replace that with an immutable full commit SHA (40-hex) for pnpm/action-setup to
pin the action (e.g., "pnpm/action-setup@<full-commit-sha>"). Locate the "uses:
pnpm/action-setup@v6" entry in the action.yml and update it to the exact commit
SHA from the pnpm/action-setup repository, verify the SHA is full-length (40
characters) and that the workflow still runs correctly after the change.

In @.github/workflows/checking-dependencies.yml:
- Line 15: Replace the mutable tag reference "uses: pnpm/action-setup@v6" with
an immutable pin to the full commit SHA for the pnpm/action-setup action (e.g.,
"uses: pnpm/action-setup@<full-commit-sha>"); locate the occurrences of
"pnpm/action-setup@v6" in the workflow and update them to the corresponding
release commit SHA from the action's repository, then verify the workflow runs
successfully.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 4cd2e52a-a23f-4849-8bc7-20b25e799703

📥 Commits

Reviewing files that changed from the base of the PR and between 6b3e168 and 373422e.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • .github/actions/setup/action.yml
  • .github/workflows/checking-dependencies.yml
  • .github/workflows/snapshot.yml
  • package.json
  • packages/app/package.json

steps:
- name: Install pnpm
uses: pnpm/action-setup@v3
uses: pnpm/action-setup@v6

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Verify mutable action refs under .github (tag-based refs like `@v1/`@v6).
# Expected: no matches after SHA pinning.
rg -n --iglob '*.yml' --iglob '*.yaml' 'uses:\s*[^@[:space:]]+@v[0-9]+(\.[0-9]+){0,2}\b' .github

Repository: ProverCoderAI/openapi-effect

Length of output: 1009


Pin pnpm/action-setup to an immutable commit SHA.

Line 13 uses a mutable tag (@v6). Please pin to a full-length commit SHA to reduce supply-chain risk and avoid policy breaks in hardened org settings.

🔒 Suggested change
-      uses: pnpm/action-setup@v6
+      uses: pnpm/action-setup@<full-length-commit-sha> # v6.x

Reference: https://docs.github.com/actions/security-guides/security-hardening-for-github-actions

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/actions/setup/action.yml at line 13, The workflow currently uses a
mutable tag "pnpm/action-setup@v6"; replace that with an immutable full commit
SHA (40-hex) for pnpm/action-setup to pin the action (e.g.,
"pnpm/action-setup@<full-commit-sha>"). Locate the "uses: pnpm/action-setup@v6"
entry in the action.yml and update it to the exact commit SHA from the
pnpm/action-setup repository, verify the SHA is full-length (40 characters) and
that the workflow still runs correctly after the change.

steps:
- uses: actions/checkout@v6
- uses: pnpm/action-setup@v4
- uses: pnpm/action-setup@v6

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Verify mutable action refs under .github (tag-based refs like `@v1/`@v6).
# Expected: no matches after SHA pinning.
rg -n --iglob '*.yml' --iglob '*.yaml' 'uses:\s*[^@[:space:]]+@v[0-9]+(\.[0-9]+){0,2}\b' .github

Repository: ProverCoderAI/openapi-effect

Length of output: 1009


Pin pnpm/action-setup to a commit SHA instead of a mutable tag.

Line 15 uses @v6, which is a mutable tag reference. Per GitHub's security hardening guidelines, action references should be pinned to full commit SHAs to ensure immutability and prevent unintended updates from tag rewrites.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/checking-dependencies.yml at line 15, Replace the mutable
tag reference "uses: pnpm/action-setup@v6" with an immutable pin to the full
commit SHA for the pnpm/action-setup action (e.g., "uses:
pnpm/action-setup@<full-commit-sha>"); locate the occurrences of
"pnpm/action-setup@v6" in the workflow and update them to the corresponding
release commit SHA from the action's repository, then verify the workflow runs
successfully.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@package.json`:
- Line 6: The package.json currently sets "packageManager": "pnpm@11.1.2" but
pnpm v11 requires config and environment changes; run the recommended codemod
(pnpx codemod run pnpm-v10-to-v11) and then: move any settings under the
package.json "pnpm" field into pnpm-workspace.yaml, strip .npmrc to only
auth/registry entries, update .nvmrc and CI to Node.js 22+ to match pnpm v11,
rename any environment variables from npm_config_* to pnpm_config_ and manually
review remaining envs, and rename or invoke scripts named
clean/setup/deploy/rebuild using pnpm pm to avoid shadowing built-ins.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 78ded05a-1811-4eac-8349-84f29cb8618e

📥 Commits

Reviewing files that changed from the base of the PR and between 6898c52 and 57c74f4.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • .github/actions/setup/action.yml
  • .github/workflows/checking-dependencies.yml
  • .github/workflows/snapshot.yml
  • package.json
  • packages/app/package.json
🚧 Files skipped from review as they are similar to previous changes (4)
  • .github/actions/setup/action.yml
  • .github/workflows/checking-dependencies.yml
  • .github/workflows/snapshot.yml
  • packages/app/package.json

Comment thread package.json Outdated
"private": true,
"description": "Monorepo workspace for effect-template",
"packageManager": "pnpm@10.30.1",
"packageManager": "pnpm@11.1.2",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

🧩 Analysis chain

🌐 Web query:

pnpm 11 breaking changes and migration guide

💡 Result:

pnpm 11 is a major release that introduces significant breaking changes, security-first defaults, and architectural improvements [1]. The official migration guide is available at https://pnpm.io/11.x/migration [2]. Key Breaking Changes and Migration Steps Configuration Changes pnpm 11 significantly changes how configuration is handled [3][1]: - Configuration is no longer read from the pnpm field in package.json; move these settings to pnpm-workspace.yaml [3][2]. -.npmrc files are now restricted to auth and registry settings only [3][1]. All other settings (e.g., hoist-pattern, node-linker) must be moved to pnpm-workspace.yaml using camelCase keys [3][2]. - npm_config_* environment variables are no longer supported; rename them to pnpm_config_* [3][1]. - pnpm no longer reads npm's global config at $PREFIX/etc/npmrc [1]. Dependency and Script Management - Build-dependency settings (onlyBuiltDependencies, neverBuiltDependencies, etc.) are consolidated into a single allowBuilds map in pnpm-workspace.yaml [3][1]. - Package manager strictness settings are collapsed into a single pmOnFail setting [3][2]. - Script names now shadow built-in commands [3]. If you have scripts named clean, setup, deploy, or rebuild, pnpm will execute your script instead of the built-in command; use pnpm pm to access the built-in version [3]. - pnpm install -g (with no arguments) is no longer supported; use pnpm add -g instead [3][1]. Environment and Infrastructure - Node.js 18, 19, 20, and 21 are no longer supported; Node.js 22+ is required [1]. - pnpm is now distributed as pure ESM [1]. - Global installs are now isolated using a global-virtual-store, preventing interference between global packages [1]. Security and New Features - Minimum Release Age: By default, pnpm 11 blocks the installation of package versions published within the last 24 hours to mitigate supply chain attacks [4][5][6]. - Exotic Subdependencies: pnpm 11 blocks dependencies resolved from non-standard sources (e.g., Git repositories or direct tarball URLs) by default [4][6]. - Native Publish: The npm CLI fallback for publishing has been removed in favor of a native implementation [1]. - Store Index: The store index has been migrated from a JSON-per-package format to a single SQLite database for improved performance [1][5]. Migration Tooling The pnpm team provides a codemod to automate many of these changes [2]. You can run it in your project directory: pnpx codemod run pnpm-v10-to-v11 [2] For changes that cannot be automated, such as environment variable updates, manual review is required [3][2].

Citations:


🌐 Web query:

pnpm 11.1.2 release notes and security advisories

💡 Result:

As of May 17, 2026, pnpm version 11.1.2 is the latest release [1]. Release Notes for pnpm 11.1.2 Specific release notes for version 11.1.2 were not explicitly detailed in the provided search results, as it is a very recent patch release [1]. However, it follows the major 11.1.0 and 11.1.1 releases, which introduced several significant features and fixes [2][3][4]: - New Commands: Added pnpm audit signatures (to verify ECDSA registry signatures), pnpm bugs (to open package bug trackers), and pnpm owner (to manage package owners) [3][4]. - Named Registries: Added support for installing packages from arbitrary named registries, including a built-in gh: prefix for the GitHub Packages npm registry [3][4]. - CI Improvements: Introduced the --no-runtime flag (config: runtime=false) to skip installing runtime entries (e.g., Node.js) in CI environments [3][4]. - Fixes: Version 11.1.1 included fixes for installability validation in workspace projects, resolved issues with pnpm add for named registries, and updated @zkochan/cmd-shim to improve compatibility with Git Bash on Windows [2]. Security Advisories There are no specific security advisories listed for version 11.1.2. Users should monitor the official pnpm GitHub Security Advisories page for any future disclosures [5]. Recent security-related updates in the pnpm 11 series include: - Minimum Release Age: pnpm 11 introduced a default Minimum Release Age of 24 hours (1440 minutes), which prevents the installation of newly published package versions to mitigate supply chain attacks [6][7][8]. - Enhanced Auditing: pnpm audit now queries the registry's bulk security advisories endpoint and filters by GitHub Advisory ID (GHSA) rather than CVE identifiers [9]. - Security Hardening: pnpm 11 requires Node.js 22+ and is distributed as pure ESM [10][11]. It also includes improved control over lifecycle scripts via the allowBuilds model [7][8]. For the most up-to-date information, always check the official pnpm releases page on GitHub and the security advisories section [12][5].

Citations:


Review pnpm 11 migration requirements before merging.

This major version upgrade introduces breaking changes that require configuration updates and environment adjustments:

  • Configuration files: Settings in package.json's pnpm field must move to pnpm-workspace.yaml. Update .npmrc to contain only auth and registry settings.
  • Node.js requirement: pnpm 11 requires Node.js 22+. Verify your project's .nvmrc and CI configuration specify a compatible version.
  • Environment variables: Any npm_config_* variables must be renamed to pnpm_config_*.
  • Script behavior: Scripts named clean, setup, deploy, or rebuild now shadow built-in commands; use pnpm pm to access built-in versions.

Run the migration codemod to automate configuration changes:

pnpx codemod run pnpm-v10-to-v11

Refer to https://pnpm.io/11.x/migration for the complete migration guide. Manual review is needed for environment variable updates that the codemod cannot automate.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@package.json` at line 6, The package.json currently sets "packageManager":
"pnpm@11.1.2" but pnpm v11 requires config and environment changes; run the
recommended codemod (pnpx codemod run pnpm-v10-to-v11) and then: move any
settings under the package.json "pnpm" field into pnpm-workspace.yaml, strip
.npmrc to only auth/registry entries, update .nvmrc and CI to Node.js 22+ to
match pnpm v11, rename any environment variables from npm_config_* to
pnpm_config_ and manually review remaining envs, and rename or invoke scripts
named clean/setup/deploy/rebuild using pnpm pm to avoid shadowing built-ins.

@skulidropek

Copy link
Copy Markdown
Member

Надо смержить сюда main ветку и исправить все ошибки в CI/CD что бы код был с актуальными библиотеками

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🤖 AI Work Session Started

Starting automated work session at 2026-06-19T19:17:51.406Z

The PR has been converted to draft mode while work is in progress.

This comment marks the beginning of an AI work session. Please wait for the session to finish, and provide your feedback.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

Update: the CI/CD fix is implemented and verified, but I cannot push it directly to this PR head branch.

Blocker:

  • PR fix(deps): update all dependencies #20 head is ProverCoderAI/openapi-effect:renovate/all.
  • Current GitHub credentials are konard and git push upstream renovate/all fails with 403 Permission to ProverCoderAI/openapi-effect.git denied to konard.

Prepared fix:

  • Commit: b16eac4b7948745fcd49d07e270b92f77b0ccb7d (fix(ci): adapt renovate update to pnpm 11)
  • Branch with the commit: konard/ProverCoderAI-openapi-effect:renovate/all

What the fix covers:

  • merged main into renovate/all locally;
  • moved pnpm 11 config from package.json#pnpm into pnpm-workspace.yaml and kept release-age policy with exact excludes;
  • pinned pnpm/action-setup to full SHA 0ebf47130e4866e96fce0953f49152a61190b271 (v6.0.9);
  • updated CI Node runtime to 24.17.0 so pnpm 11 can load node:sqlite;
  • fixed TypeScript 6/lint fallout while preserving legacy public aliases;
  • added consumer compile proof for the legacy serializer aliases.

Verification:

Needed human action: either grant/push access to ProverCoderAI/openapi-effect:renovate/all, or cherry-pick b16eac4b7948745fcd49d07e270b92f77b0ccb7d from the fork branch into the PR head branch.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🤖 Solution Draft Log

This log file contains the complete execution trace of the AI solution draft process.

💰 Cost estimation:

  • Model: GPT-5.5
  • Provider: OpenAI
  • Public pricing estimate: $21.304392

📊 Context and tokens usage:

  • 508.9K / 200K (254%) input tokens, 68.4K / 128K (53%) output tokens

Total: (508.9K + 13.1M cached) input tokens, 68.4K output tokens, $21.304392 cost

🤖 Models used:

  • Tool: OpenAI Codex
  • Requested: gpt-5.5
  • Thinking level: max (~31999 tokens)
  • Model: GPT-5.5 (gpt-5.5)

📎 Log file uploaded as Repository (75696KB)


Now working session is ended, feel free to review and add any feedback on the solution draft.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart triggered (iteration 1)

Reason: CI failures detected

Starting new session to address the issues.


Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

Rechecked the failing CI/CD status in this restart session.

Findings:

  • Latest upstream PR runs are still for old SHA 48c4a8472fb0d70d3d48c14f5963a2d421a90ec7 from 2026-06-19T13:11:52Z.
  • Logs saved locally during investigation show the failures are from pnpm 11 running on Node 20.16.0 / 22.12.0 and from pnpm 11 ignoring package.json#pnpm, causing minimumReleaseAge violations.
  • The prepared fix commit is still b16eac4b7948745fcd49d07e270b92f77b0ccb7d on konard/ProverCoderAI-openapi-effect:renovate/all.

Verification repeated locally with Node 24.17.0 and pnpm 11.8.0:

  • pnpm install --frozen-lockfile
  • pnpm check
  • pnpm build
  • pnpm lint:effect
  • pnpm lint
  • pnpm test
  • pnpm --filter @prover-coder-ai/openapi-effect test:consumer
  • pnpm dlx @prover-coder-ai/dist-deps-prune scan --package ./packages/app/package.json --prune-dev true --silent
  • snapshot fallback artifact check via npm pack

Fork CI also has successful runs for b16eac4: Check 27845776274, Checking Dependencies 27845776279.

Remaining blocker is repository permissions, not code: git push upstream renovate/all still fails with 403 Permission to ProverCoderAI/openapi-effect.git denied to konard. Please either grant push access to ProverCoderAI/openapi-effect:renovate/all or cherry-pick/push b16eac4b7948745fcd49d07e270b92f77b0ccb7d from the fork branch into the upstream PR head branch.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart-until-mergeable Log (iteration 1)

This log file contains the complete execution trace of the AI solution draft process.

💰 Cost estimation:

  • Model: GPT-5.5
  • Provider: OpenAI
  • Public pricing estimate: $4.197492
  • Token usage: 93,621 input, 17,194 output, 5,819 reasoning, 2,487,552 cache read

🤖 Models used:

  • Tool: OpenAI Codex
  • Requested: gpt-5.5
  • Model: GPT-5.5 (gpt-5.5)

📎 Log file uploaded as Repository (96784KB)


Now working session is ended, feel free to review and add any feedback on the solution draft.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart triggered (iteration 2)

Reason: CI failures detected

Starting new session to address the issues.


Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

Rechecked and updated the prepared fix in this restart session.

Current prepared commit:

  • b52bed11666e71930f1d563062826936f36fd5f3 on konard/ProverCoderAI-openapi-effect:renovate/all
  • This includes the earlier CI/pnpm 11 fix plus a small follow-up commit fix(app): satisfy strict type lint example so lint:types also passes.

Root causes confirmed from upstream CI logs for old SHA 48c4a8472fb0d70d3d48c14f5963a2d421a90ec7:

  • Check/Snapshot: pnpm 11 ran under an old Node runtime and failed on node:sqlite / Node >= 22.13 requirement.
  • dist-deps-prune: pnpm 11 minimum release age policy rejected fresh lockfile entries.

Verification on current SHA b52bed1:

  • Local with Node 24.17.0 and pnpm 11.8.0: pnpm install --frozen-lockfile, pnpm check, pnpm build, pnpm lint, pnpm lint:effect, pnpm test, pnpm lint:tests, pnpm --filter @prover-coder-ai/openapi-effect lint:types, pnpm --filter @prover-coder-ai/openapi-effect test:consumer, pnpm dlx @prover-coder-ai/dist-deps-prune scan --package ./packages/app/package.json --prune-dev true --silent, and package pack check all passed.
  • Fork CI Check passed: https://github.com/konard/ProverCoderAI-openapi-effect/actions/runs/27846721442
  • Fork CI Checking Dependencies passed: https://github.com/konard/ProverCoderAI-openapi-effect/actions/runs/27846721454
  • Fork Snapshot is skipped by the workflow owner guard (github.repository_owner == 'ProverCoderAI'); the equivalent local pnpm build plus fallback npm pack artifact path passed.

Remaining blocker is repository permission, not code. git push upstream renovate/all still fails with:

remote: Permission to ProverCoderAI/openapi-effect.git denied to konard.
fatal: unable to access 'https://github.com/ProverCoderAI/openapi-effect.git/': The requested URL returned error: 403

Needed maintainer action: push/cherry-pick b52bed11666e71930f1d563062826936f36fd5f3 from the fork branch into ProverCoderAI/openapi-effect:renovate/all. Until that happens, PR #20 remains on the old upstream head SHA 48c4a8472fb0d70d3d48c14f5963a2d421a90ec7 and will keep showing stale failing checks.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart-until-mergeable Log (iteration 2)

This log file contains the complete execution trace of the AI solution draft process.

💰 Cost estimation:

  • Model: GPT-5.5
  • Provider: OpenAI
  • Public pricing estimate: $4.788024
  • Token usage: 95,677 input, 18,030 output, 5,431 reasoning, 3,019,904 cache read

🤖 Models used:

  • Tool: OpenAI Codex
  • Requested: gpt-5.5
  • Model: GPT-5.5 (gpt-5.5)

📎 Log file uploaded as Repository (2 chunks) (116514KB)


Now working session is ended, feel free to review and add any feedback on the solution draft.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart triggered (iteration 3)

Reason: CI failures detected

Starting new session to address the issues.


Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

Restart iteration 3 rechecked the prepared CI fix.

Current verified head:

  • b52bed11666e71930f1d563062826936f36fd5f3 on konard/ProverCoderAI-openapi-effect:renovate/all
  • Local branch includes upstream/main via merge commit f43684a.
  • PR fix(deps): update all dependencies #20 still points to ProverCoderAI/openapi-effect:renovate/all@48c4a8472fb0d70d3d48c14f5963a2d421a90ec7, so its failing checks are stale for the old head.

Fresh upstream CI logs downloaded in this session confirm old-head root causes:

  • Check: pnpm 11 under Node 20.16.0 fails on node:sqlite / Node >= 22.13 requirement.
  • Snapshot: pnpm 11 under Node 22.12.0 fails the Node >= 22.13 requirement.
  • Checking Dependencies: pnpm 11 ignores package.json#pnpm and then fails minimumReleaseAge for the refreshed lockfile entries.

Verification repeated on b52bed1 with Node 24.17.0 and pnpm 11.8.0:

  • pnpm install --frozen-lockfile
  • pnpm check
  • pnpm build
  • pnpm lint
  • pnpm lint:effect
  • pnpm test
  • pnpm lint:tests
  • pnpm --filter @prover-coder-ai/openapi-effect lint:types
  • pnpm --filter @prover-coder-ai/openapi-effect test:consumer
  • pnpm dlx @prover-coder-ai/dist-deps-prune scan --package ./packages/app/package.json --prune-dev true --silent
  • snapshot fallback npm pack artifact path

Push blocker remains external:
git push upstream HEAD:renovate/all fails with 403 Permission to ProverCoderAI/openapi-effect.git denied to konard.

Needed maintainer action: push or cherry-pick b52bed11666e71930f1d563062826936f36fd5f3 from the fork branch into ProverCoderAI/openapi-effect:renovate/all.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart-until-mergeable Log (iteration 3)

This log file contains the complete execution trace of the AI solution draft process.

💰 Cost estimation:

  • Model: GPT-5.5
  • Provider: OpenAI
  • Public pricing estimate: $4.433867
  • Token usage: 92,361 input, 16,725 output, 5,362 reasoning, 2,757,632 cache read

🤖 Models used:

  • Tool: OpenAI Codex
  • Requested: gpt-5.5
  • Model: GPT-5.5 (gpt-5.5)

📎 Log file uploaded as Repository (2 chunks) (139990KB)


Now working session is ended, feel free to review and add any feedback on the solution draft.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart triggered (iteration 4)

Reason: CI failures detected

Starting new session to address the issues.


Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

Restart iteration 4 rechecked the CI/CD fix.

Current verified head:

  • b52bed11666e71930f1d563062826936f36fd5f3 on konard/ProverCoderAI-openapi-effect:renovate/all
  • upstream/main is merged into this branch.
  • PR fix(deps): update all dependencies #20 upstream head is still ProverCoderAI/openapi-effect:renovate/all@48c4a8472fb0d70d3d48c14f5963a2d421a90ec7, so the visible failing checks are still for the old head.

Fresh upstream logs downloaded in this session confirm the old-head failures:

  • Check: pnpm 11 runs under Node 20.16.0 and fails on node:sqlite / Node >= 22.13.
  • Snapshot: pnpm 11 runs under Node 22.12.0 and fails the Node >= 22.13 requirement.
  • Checking Dependencies: pnpm 11 rejects fresh lockfile entries through minimumReleaseAge.

Verification repeated locally on b52bed1 with Node 24.17.0 and pnpm 11.8.0:

  • pnpm install --frozen-lockfile
  • pnpm check
  • pnpm build
  • pnpm lint
  • pnpm lint:effect
  • pnpm test
  • pnpm lint:tests
  • pnpm --filter @prover-coder-ai/openapi-effect lint:types
  • pnpm --filter @prover-coder-ai/openapi-effect test:consumer
  • pnpm dlx @prover-coder-ai/dist-deps-prune scan --package ./packages/app/package.json --prune-dev true --silent
  • snapshot fallback artifact check via npm pack

Push status:

  • git push origin HEAD:renovate/all: up to date.
  • git push upstream HEAD:renovate/all: blocked with 403 Permission to ProverCoderAI/openapi-effect.git denied to konard.

Needed maintainer action: push or cherry-pick b52bed11666e71930f1d563062826936f36fd5f3 from konard/ProverCoderAI-openapi-effect:renovate/all into ProverCoderAI/openapi-effect:renovate/all. Until then PR #20 cannot receive fresh CI for the verified fix.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart-until-mergeable Log (iteration 4)

This log file contains the complete execution trace of the AI solution draft process.

💰 Cost estimation:

  • Model: GPT-5.5
  • Provider: OpenAI
  • Public pricing estimate: $4.654120
  • Token usage: 127,152 input, 17,640 output, 5,582 reasoning, 2,588,800 cache read

🤖 Models used:

  • Tool: OpenAI Codex
  • Requested: gpt-5.5
  • Model: GPT-5.5 (gpt-5.5)

📎 Log file uploaded as Repository (2 chunks) (154923KB)


Now working session is ended, feel free to review and add any feedback on the solution draft.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart triggered (iteration 5)

Reason: CI failures detected

Starting new session to address the issues.


Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

Restart iteration 5 rechecked the CI/CD failures and the prepared fix.

Current verified fix:

  • b52bed11666e71930f1d563062826936f36fd5f3 on konard/ProverCoderAI-openapi-effect:renovate/all
  • This branch includes upstream/main and has origin/renovate/all up to date.

Fresh upstream CI status:

  • PR fix(deps): update all dependencies #20 still points to ProverCoderAI/openapi-effect:renovate/all@48c4a8472fb0d70d3d48c14f5963a2d421a90ec7.
  • Latest upstream runs are still from 2026-06-19T13:11:52Z for that old SHA:
    • Check 27827776411: failure
    • Checking Dependencies 27827776440: failure
    • Snapshot 27827776423: failure

Root causes confirmed from downloaded upstream logs:

  • Check jobs (Build, Types, Lint, Lint Effect-TS, Test) fail before project code because pnpm 11 runs under Node 20.16.0 and errors with No such built-in module: node:sqlite / Node >= 22.13 requirement.
  • Snapshot fails for the same pnpm 11 runtime requirement under Node 22.12.0.
  • dist-deps-prune fails with ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION for effect@3.21.4, eslint-plugin-sonarjs@4.1.0, and eslint-plugin-unicorn@68.0.0.

Verification repeated locally on b52bed1 with Node 24.17.0 and pnpm 11.8.0:

  • pnpm install --frozen-lockfile
  • pnpm check
  • pnpm build
  • pnpm lint
  • pnpm lint:effect
  • pnpm test
  • pnpm lint:tests
  • pnpm --filter @prover-coder-ai/openapi-effect lint:types
  • pnpm --filter @prover-coder-ai/openapi-effect test:consumer
  • pnpm dlx @prover-coder-ai/dist-deps-prune scan --package ./packages/app/package.json --prune-dev true --silent
  • snapshot fallback artifact path via npm pack

Fork CI on b52bed1:

Push status:

  • git push origin HEAD:renovate/all: up to date.
  • git push upstream HEAD:renovate/all: blocked with 403 Permission to ProverCoderAI/openapi-effect.git denied to konard.

Needed maintainer action: push or cherry-pick b52bed11666e71930f1d563062826936f36fd5f3 from konard/ProverCoderAI-openapi-effect:renovate/all into ProverCoderAI/openapi-effect:renovate/all. Until that upstream PR head moves off 48c4a84, the visible PR checks remain stale failures for the old commit.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🔄 Auto-restart-until-mergeable Log (iteration 5)

This log file contains the complete execution trace of the AI solution draft process.

💰 Cost estimation:

  • Model: GPT-5.5
  • Provider: OpenAI
  • Public pricing estimate: $4.888533
  • Token usage: 166,658 input, 16,101 output, 4,054 reasoning, 2,497,408 cache read

🤖 Models used:

  • Tool: OpenAI Codex
  • Requested: gpt-5.5
  • Model: GPT-5.5 (gpt-5.5)

📎 Log file uploaded as Repository (2 chunks) (177139KB)


Now working session is ended, feel free to review and add any feedback on the solution draft.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

⚠️ Auto-restart limit reached

Hive Mind stopped auto-restart-until-mergeable after 5 restart iterations.

Configured limit: 5
Remaining reason: CI failures detected

No further AI sessions will be started automatically for this run. Please review the remaining blockers manually or rerun with a higher --auto-restart-max-iterations value.


Auto-restart-until-mergeable stopped by the safety limit.

@konard

konard commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

🤖 AI Work Session Completed

Work session ended at 2026-06-19T20:58:19.771Z

The PR will be converted back to ready for review.

This comment marks the end of an AI work session. New comments after this time will be considered as feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants