Skip to content

dependabot:(deps): bump the npm-all-updates group across 1 directory with 15 updates#18

Closed
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/npm-all-updates-7d0b739a06
Closed

dependabot:(deps): bump the npm-all-updates group across 1 directory with 15 updates#18
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/npm-all-updates-7d0b739a06

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 22, 2026

Bumps the npm-all-updates group with 15 updates in the / directory:

Package From To
@ai-sdk/provider-utils 4.0.15 4.0.23
@opentelemetry/auto-instrumentations-node 0.52.1 0.73.0
@opentelemetry/exporter-trace-otlp-http 0.56.0 0.215.0
@opentelemetry/resources 1.30.1 2.7.0
@opentelemetry/sdk-node 0.56.0 0.215.0
@ai-sdk/openai-compatible 2.0.30 2.0.41
@biomejs/biome 2.4.4 2.4.12
@changesets/cli 2.29.8 2.31.0
@rollup/rollup-darwin-arm64 4.60.1 4.60.2
@vitest/coverage-v8 4.1.4 4.1.5
ai 6.0.97 6.0.168
typescript 5.9.3 6.0.3
ultracite 7.2.3 7.6.0
vite 7.3.2 8.0.9
vitest 4.1.4 4.1.5

Updates @ai-sdk/provider-utils from 4.0.15 to 4.0.23

Commits
  • c3a057d Version Packages (#14153)
  • 6247886 Backport: chore(provider-utils,google): fix grammar errors in error and warni...
  • 674da61 Version Packages (#14129)
  • 5f439a1 Backport: feat (provider/gateway): add hipaaCompliant provider option (#14128)
  • ee90415 Version Packages (#14114)
  • f20ba77 Backport: feat(@​ai-sdk/google): preserve per-modality token details in usage ...
  • c9ae9d5 Version Packages (#14094)
  • 0f2b2f1 Backport: fix(provider/google): fix Gemini service tier enum after upstream u...
  • ffd431a Backport: chore(provider/gateway): update gateway model settings files v6 (#1...
  • 5151a8c Version Packages (#14087)
  • Additional commits viewable in compare view

Updates @opentelemetry/auto-instrumentations-node from 0.52.1 to 0.73.0

Release notes

Sourced from @​opentelemetry/auto-instrumentations-node's releases.

auto-instrumentations-node: v0.73.0

0.73.0 (2026-04-17)

Features

  • deps: update deps matching '@opentelemetry/*' (#3479) (8891261)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-amqplib bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-aws-lambda bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-aws-sdk bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-bunyan bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-cassandra-driver bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-connect bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-cucumber bumped from ^0.30.0 to ^0.31.0
      • @​opentelemetry/instrumentation-dataloader bumped from ^0.31.0 to ^0.32.0
      • @​opentelemetry/instrumentation-dns bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-express bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.33.0 to ^0.34.0
      • @​opentelemetry/instrumentation-generic-pool bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-graphql bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-hapi bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-ioredis bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-kafkajs bumped from ^0.23.0 to ^0.24.0
      • @​opentelemetry/instrumentation-knex bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-koa bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-lru-memoizer bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-memcached bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-mongodb bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-mongoose bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-mysql bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-mysql2 bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-nestjs-core bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-net bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-openai bumped from ^0.12.0 to ^0.13.0
      • @​opentelemetry/instrumentation-oracledb bumped from ^0.39.0 to ^0.40.0
      • @​opentelemetry/instrumentation-pg bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-pino bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-redis bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-restify bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-router bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-runtime-node bumped from ^0.27.0 to ^0.28.0
      • @​opentelemetry/instrumentation-socket.io bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-tedious bumped from ^0.33.0 to ^0.34.0
      • @​opentelemetry/instrumentation-undici bumped from ^0.24.0 to ^0.25.0

... (truncated)

Changelog

Sourced from @​opentelemetry/auto-instrumentations-node's changelog.

0.73.0 (2026-04-17)

Features

  • deps: update deps matching '@opentelemetry/*' (#3479) (8891261)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-amqplib bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-aws-lambda bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-aws-sdk bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-bunyan bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-cassandra-driver bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-connect bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-cucumber bumped from ^0.30.0 to ^0.31.0
      • @​opentelemetry/instrumentation-dataloader bumped from ^0.31.0 to ^0.32.0
      • @​opentelemetry/instrumentation-dns bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-express bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.33.0 to ^0.34.0
      • @​opentelemetry/instrumentation-generic-pool bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-graphql bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-hapi bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-ioredis bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-kafkajs bumped from ^0.23.0 to ^0.24.0
      • @​opentelemetry/instrumentation-knex bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-koa bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-lru-memoizer bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-memcached bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-mongodb bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-mongoose bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-mysql bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-mysql2 bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-nestjs-core bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-net bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-openai bumped from ^0.12.0 to ^0.13.0
      • @​opentelemetry/instrumentation-oracledb bumped from ^0.39.0 to ^0.40.0
      • @​opentelemetry/instrumentation-pg bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-pino bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-redis bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-restify bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-router bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-runtime-node bumped from ^0.27.0 to ^0.28.0
      • @​opentelemetry/instrumentation-socket.io bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-tedious bumped from ^0.33.0 to ^0.34.0
      • @​opentelemetry/instrumentation-undici bumped from ^0.24.0 to ^0.25.0
      • @​opentelemetry/instrumentation-winston bumped from ^0.58.0 to ^0.59.0

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​opentelemetry/auto-instrumentations-node since your current version.


Updates @opentelemetry/exporter-trace-otlp-http from 0.56.0 to 0.215.0

Release notes

Sourced from @​opentelemetry/exporter-trace-otlp-http's releases.

experimental/v0.215.0

0.215.0

💥 Breaking Changes

  • feat(sdk-logs)!: add required forceFlush() to LogRecordExporter interface #6356 @​pichlermarc
    • (user-facing): LogRecordExporter interface now requires a forceFlush() method to be implemented. Custom exporters will need to implement this method to continue working with the Logs SDK.
  • feat(api-logs, sdk-logs)!: add Logger#enabled() #6371 @​david-luna

🚀 Features

🐛 Bug Fixes

  • fix(instrumentation-fetch): preserve init overrides when input is a Request object #6421 @​akandic47
  • fix(otlp-exporter-base): limit Node.js HTTP transport response body to 4 MiB #6552 @​kartikgola
  • fix(instrumentation-fetch): avoid unwrapping fetch API when disabling #6575 @​david-luna
  • fix(web-common): add check for possible unsafe json parse #6589 @​maryliag
  • fix(otlp-transformer): add check for possible unsafe json parse #6588 @​maryliag

experimental/v0.214.0

0.214.0

💥 Breaking Changes

  • feat(configuration)!: rename OTEL_EXPERIMENTAL_CONFIG_FILE to OTEL_CONFIG_FILE #6486 @​maryliag
  • refactor!(otlp-grpc-exporter-base): remove headers from gRPC exporter config type, passing headers now results in a compile-time error instead of being silently ignored #6487

🚀 Features

🐛 Bug Fixes

  • fix(opentelemetry-instrumentation): access require via globalThis to avoid webpack analysis #6481 @​overbalance
  • fix(sdk-logs): fix inflated droppedAttributesCount when updating existing attribute keys #6479 @​overbalance
  • fix(instrumentation-fetch): do not modify the returned type of fetch #6521 @​dyladan
  • fix(opentelemetry-sdk-node): add missing @opentelemetry/otlp-exporter-base dependency #6520 @​gotgenes

🏠 Internal

... (truncated)

Commits
  • a0476ee chore: prepare next release (#6603)
  • 6bc69c7 fix(instr-fetch): avoid unwrap fetch API (#6575)
  • 840f3d4 chore: re-arrange misplaced changelog entries (#6604)
  • 2da8d39 feat(configuration): refactoring config loader to print warning message for b...
  • 401af13 fix(deps): update dependency protobufjs to v8 (#6602)
  • 36e2a9a fix(opentelemetry-core): add extra checks on internal merge function for safe...
  • 8ee2a8b fix(web-common): add check for possible unsafe json parse (#6589)
  • f40fd24 fix(otlp-transformer): add check for possible unsafe json parse (#6588)
  • 394eeb0 chore: update changelog script (#6586)
  • 36ce569 feat(sdk-metrics): adds the cardinalitySelector argument to PeriodicExporting...
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​opentelemetry/exporter-trace-otlp-http since your current version.


Updates @opentelemetry/resources from 1.30.1 to 2.7.0

Release notes

Sourced from @​opentelemetry/resources's releases.

v2.7.0

2.7.0

🚀 Features

  • feat(sdk-logs): implement log creation metrics #6433 @​anuraaga
  • feat(sdk-metrics): add the cardinalitySelector argument to PeriodicExportingMetricReaders #6460 @​starzlocker
  • feat(opentelemetry-core): add extra checks on internal merge function for safety #6587 @​maryliag

🐛 Bug Fixes

  • fix(opentelemetry-resources): do not discard OTEL_RESOURCE_ATTRIBUTES when it contains empty kv pairs

🏠 Internal

v2.6.1

2.6.1

🐛 Bug Fixes

  • fix(opentelemetry-instrumentation): improve _warnOnPreloadedModules function not to show warning logs when the module is not marked as loaded #6095 @​rlj1202
  • fix(sdk-trace-base): derive internal SpanOptions from API type to prevent drift #6478 @​overbalance
  • fix(span): enforce attributePerEventCountLimit, attributePerLinkCountLimit, linkCountLimit, and attributeValueLengthLimit for event/link attributes #6479 @​overbalance

🏠 Internal

v2.6.0

2.6.0

💥 Breaking Changes

  • fix(resources): update OTEL_RESOURCE_ATTRIBUTESopen-telemetry/opentelemetry-specification#4856#6261 @​jacksonweber
    • Important: This fix is included in the "breaking changes" section because it can be breaking for some edge case usage of OTEL_RESOURCE_ATTRIBUTES:
      • export OTEL_RESOURCE_ATTRIBUTES=foo=bar,spam will now be fully ignored, because the spam entry is invalid (missing =). Per spec, any parsing error results in ignoring the entire environment variable.
      • export OTEL_RESOURCE_ATTRIBUTES='wat=" spaces "' will now result in {"wat": "\" spaces \""} with the double-quotes included in the value. Before this change the implementation included brittle double-quoting to allow leading and trailing whitespace in the value. To support leading or trailing whitespace now, you must percent-encode the whitespace. Internal whitespace still works without encoding, e.g. export OTEL_RESOURCE_ATTRIBUTES='green=eggs and ham'.

🚀 Features

... (truncated)

Changelog

Sourced from @​opentelemetry/resources's changelog.

2.7.0

🚀 Features

  • feat(sdk-logs): implement log creation metrics #6433 @​anuraaga
  • feat(sdk-metrics): add the cardinalitySelector argument to PeriodicExportingMetricReaders #6460 @​starzlocker
  • feat(opentelemetry-core): add extra checks on internal merge function for safety #6587 @​maryliag

🐛 Bug Fixes

  • fix(opentelemetry-resources): do not discard OTEL_RESOURCE_ATTRIBUTES when it contains empty kv pairs

🏠 Internal

2.6.1

🐛 Bug Fixes

  • fix(opentelemetry-instrumentation): improve _warnOnPreloadedModules function not to show warning logs when the module is not marked as loaded #6095 @​rlj1202
  • fix(sdk-trace-base): derive internal SpanOptions from API type to prevent drift #6478 @​overbalance
  • fix(span): enforce attributePerEventCountLimit, attributePerLinkCountLimit, linkCountLimit, and attributeValueLengthLimit for event/link attributes #6479 @​overbalance
  • fix(context-zone): guard onCancelTask against terminal-state tasks to prevent infinite loop with rc-align (Ant Design) in React 16 dev mode #6512 @​Renegade2345

🏠 Internal

2.6.0

💥 Breaking Changes

  • fix(resources): update OTEL_RESOURCE_ATTRIBUTESopen-telemetry/opentelemetry-specification#4856#6261 @​jacksonweber
    • Important: This fix is included in the "breaking changes" section because it can be breaking for some edge case usage of OTEL_RESOURCE_ATTRIBUTES:
      • export OTEL_RESOURCE_ATTRIBUTES=foo=bar,spam will now be fully ignored, because the spam entry is invalid (missing =). Per spec, any parsing error results in ignoring the entire environment variable.
      • export OTEL_RESOURCE_ATTRIBUTES='wat=" spaces "' will now result in {"wat": "\" spaces \""} with the double-quotes included in the value. Before this change the implementation included brittle double-quoting to allow leading and trailing whitespace in the value. To support leading or trailing whitespace now, you must percent-encode the whitespace. Internal whitespace still works without encoding, e.g. export OTEL_RESOURCE_ATTRIBUTES='green=eggs and ham'.

🚀 Features

🐛 Bug Fixes

... (truncated)

Commits
  • a0476ee chore: prepare next release (#6603)
  • 6bc69c7 fix(instr-fetch): avoid unwrap fetch API (#6575)
  • 840f3d4 chore: re-arrange misplaced changelog entries (#6604)
  • 2da8d39 feat(configuration): refactoring config loader to print warning message for b...
  • 401af13 fix(deps): update dependency protobufjs to v8 (#6602)
  • 36e2a9a fix(opentelemetry-core): add extra checks on internal merge function for safe...
  • 8ee2a8b fix(web-common): add check for possible unsafe json parse (#6589)
  • f40fd24 fix(otlp-transformer): add check for possible unsafe json parse (#6588)
  • 394eeb0 chore: update changelog script (#6586)
  • 36ce569 feat(sdk-metrics): adds the cardinalitySelector argument to PeriodicExporting...
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​opentelemetry/resources since your current version.


Updates @opentelemetry/sdk-node from 0.56.0 to 0.215.0

Release notes

Sourced from @​opentelemetry/sdk-node's releases.

experimental/v0.215.0

0.215.0

💥 Breaking Changes

  • feat(sdk-logs)!: add required forceFlush() to LogRecordExporter interface #6356 @​pichlermarc
    • (user-facing): LogRecordExporter interface now requires a forceFlush() method to be implemented. Custom exporters will need to implement this method to continue working with the Logs SDK.
  • feat(api-logs, sdk-logs)!: add Logger#enabled() #6371 @​david-luna

🚀 Features

🐛 Bug Fixes

  • fix(instrumentation-fetch): preserve init overrides when input is a Request object #6421 @​akandic47
  • fix(otlp-exporter-base): limit Node.js HTTP transport response body to 4 MiB #6552 @​kartikgola
  • fix(instrumentation-fetch): avoid unwrapping fetch API when disabling #6575 @​david-luna
  • fix(web-common): add check for possible unsafe json parse #6589 @​maryliag
  • fix(otlp-transformer): add check for possible unsafe json parse #6588 @​maryliag

experimental/v0.214.0

0.214.0

💥 Breaking Changes

  • feat(configuration)!: rename OTEL_EXPERIMENTAL_CONFIG_FILE to OTEL_CONFIG_FILE #6486 @​maryliag
  • refactor!(otlp-grpc-exporter-base): remove headers from gRPC exporter config type, passing headers now results in a compile-time error instead of being silently ignored #6487

🚀 Features

🐛 Bug Fixes

  • fix(opentelemetry-instrumentation): access require via globalThis to avoid webpack analysis #6481 @​overbalance
  • fix(sdk-logs): fix inflated droppedAttributesCount when updating existing attribute keys #6479 @​overbalance
  • fix(instrumentation-fetch): do not modify the returned type of fetch #6521 @​dyladan
  • fix(opentelemetry-sdk-node): add missing @opentelemetry/otlp-exporter-base dependency #6520 @​gotgenes

🏠 Internal

... (truncated)

Commits
  • a0476ee chore: prepare next release (#6603)
  • 6bc69c7 fix(instr-fetch): avoid unwrap fetch API (#6575)
  • 840f3d4 chore: re-arrange misplaced changelog entries (#6604)
  • 2da8d39 feat(configuration): refactoring config loader to print warning message for b...
  • 401af13 fix(deps): update dependency protobufjs to v8 (#6602)
  • 36e2a9a fix(opentelemetry-core): add extra checks on internal merge function for safe...
  • 8ee2a8b fix(web-common): add check for possible unsafe json parse (#6589)
  • f40fd24 fix(otlp-transformer): add check for possible unsafe json parse (#6588)
  • 394eeb0 chore: update changelog script (#6586)
  • 36ce569 feat(sdk-metrics): adds the cardinalitySelector argument to PeriodicExporting...
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​opentelemetry/sdk-node since your current version.


Updates @ai-sdk/openai-compatible from 2.0.30 to 2.0.41

Commits

Updates @biomejs/biome from 2.4.4 to 2.4.12

Release notes

Sourced from @​biomejs/biome's releases.

Biome CLI v2.4.12

2.4.12

Patch Changes

  • #9376 9701a33 Thanks @​dyc3! - Added the nursery/noIdenticalTestTitle lint rule. This rule disallows using the same title for two describe blocks or two test cases at the same nesting level.

    describe("foo", () => {});
    describe("foo", () => {
      // invalid: same title as previous describe block
      test("baz", () => {});
      test("baz", () => {}); // invalid: same title as previous test case
    });
  • #9889 7ae83f2 Thanks @​dyc3! - Improved the diagnostics for useForOf to better explain the problem, why it matters, and how to fix it.

  • #9916 27dd7b1 Thanks @​Jayllyz! - Added a new nursery rule noComponentHookFactories, that disallows defining React components or custom hooks inside other functions.

    For example, the following snippets trigger the rule:

    function createComponent(label) {
      function MyComponent() {
        return <div>{label}</div>;
      }
      return MyComponent;
    }
    function Parent() {
      function Child() {
        return <div />;
      }
      return <Child />;
    }
  • #9980 098f1ff Thanks @​ematipico! - Fixed #9941: Biome now emits a warning diagnostic when a file exceed the files.maxSize limit.

  • #9942 9956f1d Thanks @​dyc3! - Fixed #9918: useConsistentTestIt no longer panics when applying fixes to chained calls such as test.for([])("x", () => {});.

  • #9891 4d9ac51 Thanks @​dyc3! - Improved the noGlobalObjectCalls diagnostic to better explain why calling global objects like Math or JSON is invalid and how to fix it.

  • #9902 3f4d103 Thanks @​ematipico! - Fixed #9901: the command lint --write is now idempotent when it's run against HTML-ish files that contains scripts and styles.

  • #9891 4d9ac51 Thanks @​dyc3! - Improved the noMultiStr diagnostic to explain why escaped multiline strings are discouraged and what to use instead.

... (truncated)

Changelog

Sourced from @​biomejs/biome's changelog.

2.4.12

Patch Changes

  • #9376 9701a33 Thanks @​dyc3! - Added the nursery/noIdenticalTestTitle lint rule. This rule disallows using the same title for two describe blocks or two test cases at the same nesting level.

    describe("foo", () => {});
    describe("foo", () => {
      // invalid: same title as previous describe block
      test("baz", () => {});
      test("baz", () => {}); // invalid: same title as previous test case
    });
  • #9889 7ae83f2 Thanks @​dyc3! - Improved the diagnostics for useForOf to better explain the problem, why it matters, and how to fix it.

  • #9916 27dd7b1 Thanks @​Jayllyz! - Added a new nursery rule noComponentHookFactories, that disallows defining React components or custom hooks inside other functions.

    For example, the following snippets trigger the rule:

    function createComponent(label) {
      function MyComponent() {
        return <div>{label}</div>;
      }
      return MyComponent;
    }
    function Parent() {
      function Child() {
        return <div />;
      }
      return <Child />;
    }
  • #9980 098f1ff Thanks @​ematipico! - Fixed #9941: Biome now emits a warning diagnostic when a file exceed the files.maxSize limit.

  • #9942 9956f1d Thanks @​dyc3! - Fixed #9918: useConsistentTestIt no longer panics when applying fixes to chained calls such as test.for([])("x", () => {});.

  • #9891 4d9ac51 Thanks @​dyc3! - Improved the noGlobalObjectCalls diagnostic to better explain why calling global objects like Math or JSON is invalid and how to fix it.

  • #9902 3f4d103 Thanks @​ematipico! - Fixed #9901: the command lint --write is now idempotent when it's run against HTML-ish files that contains scripts and styles.

  • #9891 4d9ac51 Thanks @​dyc3! - Improved the noMultiStr diagnostic to explain why escaped multiline strings are discouraged and what to use instead.

  • #9966 322675e Thanks @​siketyan! - Fixed #9113: Biome now parses and formats @media and other conditional blocks correctly inside embedded CSS snippets.

... (truncated)

Commits

…with 15 updates

Bumps the npm-all-updates group with 15 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@ai-sdk/provider-utils](https://github.com/vercel/ai) | `4.0.15` | `4.0.23` |
| [@opentelemetry/auto-instrumentations-node](https://github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/auto-instrumentations-node) | `0.52.1` | `0.73.0` |
| [@opentelemetry/exporter-trace-otlp-http](https://github.com/open-telemetry/opentelemetry-js) | `0.56.0` | `0.215.0` |
| [@opentelemetry/resources](https://github.com/open-telemetry/opentelemetry-js) | `1.30.1` | `2.7.0` |
| [@opentelemetry/sdk-node](https://github.com/open-telemetry/opentelemetry-js) | `0.56.0` | `0.215.0` |
| [@ai-sdk/openai-compatible](https://github.com/vercel/ai) | `2.0.30` | `2.0.41` |
| [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) | `2.4.4` | `2.4.12` |
| [@changesets/cli](https://github.com/changesets/changesets) | `2.29.8` | `2.31.0` |
| [@rollup/rollup-darwin-arm64](https://github.com/rollup/rollup) | `4.60.1` | `4.60.2` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `4.1.4` | `4.1.5` |
| [ai](https://github.com/vercel/ai) | `6.0.97` | `6.0.168` |
| [typescript](https://github.com/microsoft/TypeScript) | `5.9.3` | `6.0.3` |
| [ultracite](https://github.com/haydenbleasel/ultracite) | `7.2.3` | `7.6.0` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `7.3.2` | `8.0.9` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.4` | `4.1.5` |



Updates `@ai-sdk/provider-utils` from 4.0.15 to 4.0.23
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/compare/@ai-sdk/provider-utils@4.0.15...@ai-sdk/provider-utils@4.0.23)

Updates `@opentelemetry/auto-instrumentations-node` from 0.52.1 to 0.73.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js-contrib/blob/main/packages/auto-instrumentations-node/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-js-contrib/commits/auto-instrumentations-node-v0.73.0/packages/auto-instrumentations-node)

Updates `@opentelemetry/exporter-trace-otlp-http` from 0.56.0 to 0.215.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.56.0...experimental/v0.215.0)

Updates `@opentelemetry/resources` from 1.30.1 to 2.7.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@v1.30.1...v2.7.0)

Updates `@opentelemetry/sdk-node` from 0.56.0 to 0.215.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.56.0...experimental/v0.215.0)

Updates `@ai-sdk/openai-compatible` from 2.0.30 to 2.0.41
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/compare/@ai-sdk/openai-compatible@2.0.30...@ai-sdk/openai-compatible@2.0.41)

Updates `@biomejs/biome` from 2.4.4 to 2.4.12
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.4.12/packages/@biomejs/biome)

Updates `@changesets/cli` from 2.29.8 to 2.31.0
- [Release notes](https://github.com/changesets/changesets/releases)
- [Commits](https://github.com/changesets/changesets/commits/@changesets/cli@2.31.0)

Updates `@rollup/rollup-darwin-arm64` from 4.60.1 to 4.60.2
- [Release notes](https://github.com/rollup/rollup/releases)
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md)
- [Commits](rollup/rollup@v4.60.1...v4.60.2)

Updates `@vitest/coverage-v8` from 4.1.4 to 4.1.5
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.5/packages/coverage-v8)

Updates `ai` from 6.0.97 to 6.0.168
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/compare/ai@6.0.97...ai@6.0.168)

Updates `typescript` from 5.9.3 to 6.0.3
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v5.9.3...v6.0.3)

Updates `ultracite` from 7.2.3 to 7.6.0
- [Release notes](https://github.com/haydenbleasel/ultracite/releases)
- [Commits](https://github.com/haydenbleasel/ultracite/compare/ultracite@7.2.3...ultracite@7.6.0)

Updates `vite` from 7.3.2 to 8.0.9
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.0.9/packages/vite)

Updates `vitest` from 4.1.4 to 4.1.5
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.5/packages/vitest)

---
updated-dependencies:
- dependency-name: "@ai-sdk/provider-utils"
  dependency-version: 4.0.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-all-updates
- dependency-name: "@opentelemetry/auto-instrumentations-node"
  dependency-version: 0.73.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-all-updates
- dependency-name: "@opentelemetry/exporter-trace-otlp-http"
  dependency-version: 0.215.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-all-updates
- dependency-name: "@opentelemetry/resources"
  dependency-version: 2.7.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: npm-all-updates
- dependency-name: "@opentelemetry/sdk-node"
  dependency-version: 0.215.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-all-updates
- dependency-name: "@ai-sdk/openai-compatible"
  dependency-version: 2.0.41
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-all-updates
- dependency-name: "@biomejs/biome"
  dependency-version: 2.4.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-all-updates
- dependency-name: "@changesets/cli"
  dependency-version: 2.31.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-all-updates
- dependency-name: "@rollup/rollup-darwin-arm64"
  dependency-version: 4.60.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-all-updates
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 4.1.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-all-updates
- dependency-name: ai
  dependency-version: 6.0.168
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-all-updates
- dependency-name: typescript
  dependency-version: 6.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-all-updates
- dependency-name: ultracite
  dependency-version: 7.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-all-updates
- dependency-name: vite
  dependency-version: 8.0.9
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-all-updates
- dependency-name: vitest
  dependency-version: 4.1.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-all-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 22, 2026

Labels

The following labels could not be found: automated, dependencies, npm. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 30, 2026

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Apr 30, 2026
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/npm-all-updates-7d0b739a06 branch April 30, 2026 00:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants