chore(deps-dev): bump the dev-dependencies group across 1 directory with 7 updates - #988
dependabot[bot] wants to merge 1 commit into
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
freshtonic
left a comment
There was a problem hiding this comment.
Requesting changes. The bumps themselves are fine, but the PR is not mergeable as-is: Biome 2.5.13 formats two files differently from 2.5.9, and Lint (Biome) fails with exactly those two errors.
The blocker
packages/stack-prisma/test/operation-types.types.test-d.ts: the closing>of severalM3<…>generics now joins the previous line (five sites, lines 109–126).packages/stack/__tests__/operation-failure-diagnostics.test.ts: the same shape at line 82.
Reproduced locally:
pnpm dlx @biomejs/biome@2.5.13 check . --diagnostic-level=error
Dependabot will not fix this itself. Someone needs to push one commit onto this branch:
pnpm install --frozen-lockfile && pnpm run code:fix
It touches only those two files. Bumping Biome on main first has the same problem there, so the reformat has to ride with the bump.
Two more things 2.5.13 changes that CI does not gate on, worth the same commit
e2e/wasm/supabase-declared.test.ts:84: thebiome-ignore lint/suspicious/noExplicitAnycomment no longer reachesconst qb: anyon line 86, because adeno-lint-ignoreline sits between them. 2.5.13 reports the suppression as unused and theanyas unsuppressed (both warnings today). Move thebiome-ignoredirectly above line 86.lint/suspicious/useIterableCallbackReturnnow fires, at error level under our config, on aforEachcallback whose arrow body returns a call's value (for examplexs.forEach((x) => walk(x))). Nothing on main trips it. New code will, so expect it on rebases.
What I checked on the bumps
@supabase/postgrest-js/@supabase/supabase-js2.112.3 → 2.116.0 (devDependencies, pinned exactly): the only postgrest-js change in the range is a newgetOpenApiSpec(); the rest is auth, storage and realtime. The liveSupabase v3 integrationjob passed on this PR, which is the check that matters for the PostgREST wire behaviour the adapter depends on.@clerk/backend3.16.7 → 3.17.2 is not verified by this PR's CI. It is only exercised by the Drizzle identity (lock-context) suites, and those fail on every Dependabot PR withmissing CLERK_MACHINE_TOKEN: the two Clerk tokens are Actions secrets but not Dependabot secrets (details in my review on #986). Add them to Dependabot secrets and rebase, and those cells will both go green and actually test this bump.fast-check4.9 → 4.10,turbo2.10.10 → 2.10.12,yaml2.9.0 → 2.9.1: unit, property and e2e jobs green.- Lockfile-only otherwise. No
onlyBuiltDependencieschange; frozen-lockfile install, OSV scan and the supply-chain e2e passed.
ba8083e to
e2e40b4
Compare
freshtonic
left a comment
There was a problem hiding this comment.
Approving. Dependabot recreated the branch at e2e40b4b, and the blocker from my last review is gone: Lint (Biome) passes on this head with Biome 2.5.14, so no reformat commit is needed. ci-required is green.
What changed in this version of the PR
@biomejs/biome^2.5.9 → ^2.5.14 (root andprotect-ffi). Lint passes.turbo2.10.10 → 2.11.3 (a minor bump now, not a patch). Unit, e2e, bench and the Turborepo-driven test jobs all pass.@supabase/postgrest-js/@supabase/supabase-js→ 2.117.1 (pinned exactly instackandstack-supabase). The liveSupabase v3 integrationjob passes. That job is the one that tests the PostgREST behaviour the adapter depends on.fast-check→ ^4.10.2 andyaml→ ^2.9.1. The property and e2e jobs pass.- Changes are limited to devDependencies and the lockfile.
onlyBuiltDependenciesdoes not change. The frozen-lockfile install, the OSV scan and the supply-chain e2e pass. A changeset is not necessary for a dev-only bump.
Still not verified: @clerk/backend 3.16.7 → 3.19.0
Both Drizzle v3 integration cells (postgres and supabase) are still red. Those cells are the only CI that runs the Clerk code. I could not read the job logs from this reviewer session, so I have not confirmed the cause on this run. The annotations show only pnpm run test:integration exited (1). On the earlier version of this PR, the cause was missing CLERK_MACHINE_TOKEN: the Clerk tokens are Actions secrets, but they are not Dependabot secrets (see #986). Before you merge, make sure the failure is still that cause and not a regression from 3.19.0. If you add the tokens to Dependabot secrets and rebase, those cells will test this bump.
93b723d to
a463903
Compare
…ith 7 updates Bumps the dev-dependencies group with 7 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) | `2.5.9` | `2.5.14` | | [turbo](https://github.com/vercel/turborepo) | `2.10.10` | `2.11.4` | | [@clerk/backend](https://github.com/clerk/javascript/tree/HEAD/packages/backend) | `3.16.7` | `3.20.1` | | [@supabase/postgrest-js](https://github.com/supabase/supabase-js/tree/HEAD/packages/core/postgrest-js) | `2.112.3` | `2.117.2` | | [@supabase/supabase-js](https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js) | `2.112.3` | `2.117.2` | | [fast-check](https://github.com/dubzzz/fast-check/tree/HEAD/packages/fast-check) | `4.9.0` | `4.10.2` | | [yaml](https://github.com/eemeli/yaml) | `2.9.0` | `2.9.1` | Updates `@biomejs/biome` from 2.5.9 to 2.5.14 - [Release notes](https://github.com/biomejs/biome/releases) - [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md) - [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.14/packages/@biomejs/biome) Updates `turbo` from 2.10.10 to 2.11.4 - [Release notes](https://github.com/vercel/turborepo/releases) - [Changelog](https://github.com/vercel/turborepo/blob/main/RELEASE.md) - [Commits](vercel/turborepo@v2.10.10...v2.11.4) Updates `@clerk/backend` from 3.16.7 to 3.20.1 - [Release notes](https://github.com/clerk/javascript/releases) - [Changelog](https://github.com/clerk/javascript/blob/main/packages/backend/CHANGELOG.md) - [Commits](https://github.com/clerk/javascript/commits/@clerk/backend@3.20.1/packages/backend) Updates `@supabase/postgrest-js` from 2.112.3 to 2.117.2 - [Release notes](https://github.com/supabase/supabase-js/releases) - [Changelog](https://github.com/supabase/supabase-js/blob/master/packages/core/postgrest-js/CHANGELOG.md) - [Commits](https://github.com/supabase/supabase-js/commits/v2.117.2/packages/core/postgrest-js) Updates `@supabase/supabase-js` from 2.112.3 to 2.117.2 - [Release notes](https://github.com/supabase/supabase-js/releases) - [Changelog](https://github.com/supabase/supabase-js/blob/master/packages/core/supabase-js/CHANGELOG.md) - [Commits](https://github.com/supabase/supabase-js/commits/v2.117.2/packages/core/supabase-js) Updates `fast-check` from 4.9.0 to 4.10.2 - [Release notes](https://github.com/dubzzz/fast-check/releases) - [Changelog](https://github.com/dubzzz/fast-check/blob/main/packages/fast-check/CHANGELOG.md) - [Commits](https://github.com/dubzzz/fast-check/commits/v4.10.2/packages/fast-check) Updates `yaml` from 2.9.0 to 2.9.1 - [Release notes](https://github.com/eemeli/yaml/releases) - [Commits](eemeli/yaml@v2.9.0...v2.9.1) --- updated-dependencies: - dependency-name: "@biomejs/biome" dependency-version: 2.5.13 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: "@clerk/backend" dependency-version: 3.17.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: "@supabase/postgrest-js" dependency-version: 2.116.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: "@supabase/supabase-js" dependency-version: 2.116.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: fast-check dependency-version: 4.10.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: turbo dependency-version: 2.10.12 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: yaml dependency-version: 2.9.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
a463903 to
e32c83a
Compare
Bumps the dev-dependencies group with 7 updates in the / directory:
2.5.92.5.142.10.102.11.43.16.73.20.12.112.32.117.22.112.32.117.24.9.04.10.22.9.02.9.1Updates
@biomejs/biomefrom 2.5.9 to 2.5.14Release notes
Sourced from @biomejs/biome's releases.
... (truncated)
Changelog
Sourced from @biomejs/biome's changelog.
... (truncated)
Commits
af4365dci: release (#11711)7ee3a6cfix(useExhaustiveSwitchCases): add optionrequireExplicitCase(#11777)02ea438feat(json_analyze): implement noJsonUnsafeValues (#9758)64fd314feat(json_analyze): implement useConsistentObjectKeys (#9797)a9c4aa0feat(html): detect undeclared custom Vue directives (#11651)1fc17e3feat: expand useIncludes (#11739)71eaa0dfeat(lint/html/svelte): add noSvelteAtDebugTags (#11754)9bd70c7fix: various bug fixes (#11735)c7c4e2bfix(analyzer): various bugs (#11720)5eb5f09feat(biome_js_analyze): implement useValidTestTitle rule (#9176) (#11725)Updates
turbofrom 2.10.10 to 2.11.4Release notes
Sourced from turbo's releases.
... (truncated)
Commits
40c2847publish 2.11.4 to registryf74650cfix: Put version inturbo queryJSON output instead of a separate banner (#...4d72915test: Move Cargo and Go discovery cases into contracts (#14227)8a9a10atest: Move Cargo prune layout checks into in-process plan contracts (#14226)4b72ac9refactor: Group Run state into execution and services contexts (#14225)58a4889refactor: Make repository context inputs injectable (#14224)813bed0fix: Share concurrent remote-cache token recovery (#14223)7353b16fix: Coordinate artifact requests after rate limiting (#14221)ec329a0test: Move affected run planning into RunBuilder contracts (#14212)935c9eatest: Move config precedence cases into funnel contracts (#14217)Updates
@clerk/backendfrom 3.16.7 to 3.20.1Release notes
Sourced from @clerk/backend's releases.
Changelog
Sourced from @clerk/backend's changelog.
... (truncated)
Commits
750e7fcci(repo): Version packages (#9931)8bca915ci(repo): Version packages (#9893)9d78a1ffix(e2e): filter OAuth cleanup by test run (#9904)cc6f11afix(shared): Reword error messaging when missing or invalid keys (#9848)0a15af9ci(repo): Version packages (#9782)917453afix(backend)!: require matching OAuth token audiences (#9724)40f40f2fix(shared): type JWT aud as string or string array (#9585)3d6ed25docs(backend): clarify domain API documentation (#9741)ee1f90aci(repo): Version packages (#9768)0cf3565ci(repo): Version packages (#9703)Updates
@supabase/postgrest-jsfrom 2.112.3 to 2.117.2Release notes
Sourced from @supabase/postgrest-js's releases.
... (truncated)
Changelog
Sourced from @supabase/postgrest-js's changelog.
Commits
6d21e3ffix(postgrest): avoid instantiation depth errors for large relationship union...54c225dchore(release): version 2.117.1 changelogs (#2700)f34d428chore(release): version 2.117.0 changelogs (#2697)84af33fchore(release): version 2.116.0 changelogs (#2679)dbe7679chore(release): version 2.115.0 changelogs (#2664)92fb8bafeat(postgrest): add getOpenApiSpec() (#2651)aef432bchore(release): version 2.114.0 changelogs (#2653)67b07b0chore(release): version 2.113.0 changelogs (#2650)062ae5echore(release): version 2.112.4 changelogs (#2628)c7397c1chore(supabase): bump supabase cli to 2.113.0 (#2606)Updates
@supabase/supabase-jsfrom 2.112.3 to 2.117.2Release notes
Sourced from @supabase/supabase-js's releases.
... (truncated)
Changelog
Sourced from @supabase/supabase-js's changelog.
... (truncated)
Commits
54c225dchore(release): version 2.117.1 changelogs (#2700)739b351fix(auth): return stored session when a refresh loses to another tab (#2698)f34d428chore(release): version 2.117.0 changelogs (#2697)cc45ccffeat(auth): enable passkey API by default and deprecate experimental passkey ...c511286docs(realtime): document relationship ofaccessToken()and heartbeat (#2680)84af33fchore(release): version 2.116.0 changelogs (#2679)5aedaabfeat(auth): add MFA recovery codes API (#2676)e4f675afix(supabase): warn when schema is passed outside db options (#2663)dbe7679chore(release): version 2.115.0 changelogs (#2664)3eb6193docs(supabase): clarify db.schema needs the second generic (#2662)Updates
fast-checkfrom 4.9.0 to 4.10.2Release notes
Sourced from fast-check's releases.
... (truncated)
Changelog
Sourced from fast-check's changelog.
... (truncated)
Commits
c77afa8v4.10.21e80f3av4.10.22df3265🐛 PlugininterruptAfterTimeLimitcrashes (#7333)e93c6a8🔖 Update CHANGELOG.md for fast-check@4.10.1 (#7294)15744d0🐛 Capture timers forinterruptAfterTimeLimitplugin (#7293)fb2ea50🐛 Capture timer globals fortimeoutplugin (#7292)4fba17d🔖 Update CHANGELOG.md for fast-check@4.10.0,@fast-check/jest@2.3.0,@fast-ch...a433d8b⬆️ Update dependency@types/nodeto ^24.13.4 (#7263)