Skip to content

chore(deps): update dependency ultracite to v7.10.6 - #190

Merged
happy-haki merged 1 commit into
mainfrom
renovate/ultracite-7.x
Aug 22, 2026
Merged

chore(deps): update dependency ultracite to v7.10.6#190
happy-haki merged 1 commit into
mainfrom
renovate/ultracite-7.x

Conversation

@renovate

@renovate renovate Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
ultracite (source) 7.9.47.10.6 age confidence

Release Notes

haydenbleasel/ultracite (ultracite)

v7.10.6

Compare Source

Patch Changes
  • 972b946: Update the oxlint presets for oxlint 1.79: replace the removed react/react-compiler rule with the 22 new React Compiler rules in the react preset, add jsdoc/no-blank-blocks and one-var to the core preset (mirrored in the ESLint presets), and require oxlint ^1.79.0
  • 2d5bbdb: Declare the jsPluginSettings named export in the ultracite/oxlint/js-plugins type declarations, so the documented (and ultracite init-generated) import jsPlugins, { jsPluginSettings } from "ultracite/oxlint/js-plugins" type-checks (#​773)
  • 56aef65: Refresh the toolchain versions that ultracite init installs into projects: @biomejs/biome 2.5.9, the ESLint plugin family (including eslint-plugin-cypress 7, eslint-plugin-jsdoc 64, eslint-plugin-solid 0.15, and eslint-plugin-unicorn 73 — the dynamic presets adopt their new rules automatically), and prettier-plugin-svelte 4.1.1 / prettier-plugin-tailwindcss 0.8.1

v7.10.5

Compare Source

Patch Changes
  • 8df6ad0: Offer the vendored anti-slop Oxlint preset during ultracite init — it now appears in the JS-plugins prompt when you pick Oxlint, and non-interactive setup accepts it via --js-plugins anti-slop. Selecting it adds ultracite/oxlint/anti-slop to the generated config's extends; since the preset is vendored inside Ultracite, nothing extra is installed.
  • cd229e9: Bump the oxlint-plugin-react-doctor pin from ^0.7.1 to ^0.9.12, so ultracite init installs the current plugin. All react-doctor rules enabled by the js-plugins presets still exist in 0.9.12, and the ported rules run in curated mode via the settings shipped alongside this release (#​771).
  • e1ac886: Pin React Doctor's ported rules to their framework-aware "curated" mode (#​771). react-doctor 0.9.x rewrote its ported oxc/react-refresh rules — notably only-export-components — with a stripped-down default mode: no framework detection, no route-file skipping, and allowConstantExport off, so Next.js route-segment exports like export const dynamic = "force-static" or metadata were flagged as non-component exports in every route file. The ESLint react preset now sets settings["react-doctor"].portedRuleMode: "curated", and generated oxlint configs apply a new jsPluginSettings export from ultracite/oxlint/js-plugins on the root config (oxlint does not merge settings from extended configs, so the setting cannot ride along inside the preset). If you extend the js-plugins preset manually, add settings: jsPluginSettings to your root oxlint config.
  • c27fe36: Generate oxlint configs that enable a subset of the JS plugins via a new selectJsPlugins export from ultracite/oxlint/js-plugins, instead of inlining the filtering logic into the generated file. The inlined block contained a typeof check that user-side lint presets flagged (anti-slop/no-runtime-typeof, #​770); the generated config is now a one-line extend, is emitted already formatted (including the previously missing blank line after imports), and re-running ultracite init migrates existing configs with the old inlined block automatically.
  • 0616523: Update the vendored anti-slop Oxlint plugin to upstream commit 446268e, picking up fixes to no-object-parameters and no-unknown-returns (respect lexical type binders in alias resolution) and a new allowInTypeGuards option on no-runtime-typeof. The ultracite/oxlint/anti-slop preset enables allowInTypeGuards, so typeof checks inside type predicate functions ((x): x is T) no longer need disable comments — predicates are the named-boundary pattern the rule pushes toward (dmmulroy/anti-slop#10).

v7.10.4

Compare Source

Patch Changes
  • 417a85a: Add an opt-in ultracite/oxlint/anti-slop preset that ships a vendored, self-contained build of the anti-slop Oxlint plugin — fifteen rules that reject low-evidence TypeScript and JavaScript patterns (unjustified type assertions, unknown leaking through signatures, Reflect-based access, module mocking, and more). Extend it alongside ultracite/oxlint/core; nothing extra to install. The preset also turns off two core rules that conflict with anti-slop's widening checks (typescript/consistent-indexed-object-style and unicorn/no-immediate-mutation) when extended after core.
  • 4d3fab8: Move suspicious/useArraySortCompare from the Biome core config to the opt-in type-aware config. The rule is in Biome's types domain — it type-infers the receiver of every method call before checking the method name, which made ultracite check up to ~260x slower on projects with expensive library types (zod, better-auth, Prisma). It now only runs when type-aware linting is explicitly enabled, alongside the other type/project-domain rules. Fixes #​768.

v7.10.3

Compare Source

Patch Changes
  • a1fa9c4: Replace the hand-rolled package exports map matching in the config-resolution doctor check with the resolve.exports library, which implements Node's full PACKAGE_TARGET_RESOLVE algorithm (wildcard patterns, key-order precedence, conditional exports, and array fallbacks). The manual node_modules walk is kept intentionally — it exists to avoid Bun's auto-install cache resolving specifiers the project's own node_modules can't.
  • 414ea80: Replace the hand-rolled monorepo workspace scan in framework detection with the find-workspaces library. Workspace declarations from package.json (array and yarn-classic object form) and pnpm-workspace.yaml — including negated globs — are now resolved by the library instead of manual pattern collection and globbing, and lerna/bolt monorepos are picked up as well.
  • a9a1989: Replace the hand-rolled upward directory walks in findNearestFile and detectLinter with the empathic library's find.any, which checks candidate names in order within each directory before moving to the parent — the same per-directory precedence the previous implementation enforced manually.
  • 27b2707: Use magicast to update ESM lint-staged config files during ultracite init. The config is now edited as an AST instead of being imported and re-serialized, so comments and function-valued entries elsewhere in the config survive the update, and the user's config code is no longer executed. If the Ultracite glob pattern is already owned by a non-array value, or the config isn't a mergeable object literal (e.g. defineConfig(...)), init warns and leaves the file untouched instead of rewriting it. CommonJS configs keep the previous behavior.
  • f2529b8: Rewrite the agent-fix progress renderer on top of log-update, cli-truncate, and string-width. log-update now owns the in-place block rewriting that was previously done with manual cursor-up/clear-line escape sequences, and line truncation is measured by display width instead of code units — so lint messages containing emoji or CJK text can no longer overflow the terminal row and corrupt the animated block.
  • 277b9d6: Replace the hand-rolled child-process handling in the agent fix runner with execa. The timeout → SIGTERM → grace period → SIGKILL escalation, stderr capture, and spawn-failure handling now use execa's timeout and forceKillAfterDelay options, which are battle-tested across platforms (including Windows kill semantics the manual implementation didn't cover). Behavior is unchanged: agent runs still time out after 5 minutes, escalate to SIGKILL after a 10-second grace period, and report a capped stderr tail.
  • 1614a80: Drop the direct cross-spawn dependency: all synchronous process spawning (linter runs, tool version checks, editor extension installs, skill installs) now goes through a small adapter over execa's sync API, which owns the Windows spawn semantics cross-spawn provided. The adapter preserves the spawnSync result shape (status/signal/error/stdout), always disables shell interpretation, and always decodes output as UTF-8. execa was already a dependency for the agent fix runner, so this consolidates on one process-spawning library.
  • ac114b4: Replace the glob dependency with fast-glob for the tsconfig.json scan during init. fast-glob was already in the dependency tree via find-workspaces, so this drops glob's transitive dependencies (minipass, path-scurry, etc.) from the install without changing behavior.

v7.10.2

Compare Source

Patch Changes
  • 1c48c68: Enable Tailwind CSS class sorting (sortTailwindcss) in the Oxfmt preset. Classes in class/className attributes and in clsx, cva, tw, twMerge, cn, twJoin, and tv calls are now sorted using the same algorithm as prettier-plugin-tailwindcss, matching the behavior of the Prettier preset (which always loads the Tailwind plugin) and the Biome preset's useSortedClasses rule. Projects without Tailwind installed are unaffected beyond class strings being sorted against the default theme, and oxfmt versions older than 0.35.0 ignore the option.
  • dc78be4: Stop sorting TanStack route option keys in route files. TanStack Router's route option types are order-sensitive (head/component infer loaderData from properties declared before them), so the Biome useSortedKeys source action rewrote createFileRoute literals into an order that breaks type inference (loaderData becomes never). The Biome TanStack preset now disables useSortedKeys for route files, and the oxlint TanStack preset disables sort-keys there so route files aren't caught between it and react-doctor/tanstack-start-route-property-order.

v7.10.1

Compare Source

Patch Changes
  • d018b7f: Fix several agent fix mode (fix --claude/--codex) issues: runs no longer abort with ENOBUFS when linter JSON output exceeds 1MB, user-supplied format/reporter flags can no longer override the JSON reporter and break parsing, a stuck agent process is force-killed 10 seconds after the timeout instead of hanging forever, and the progress renderer no longer garbles TTY output when file paths and rule names exceed the terminal width.
  • d018b7f: Fix Biome config migration leaving the legacy bare "extends": ["ultracite"] form in place, which breaks Biome's module resolution since the package has no root export. It's now mapped to ultracite/biome/core.
  • d018b7f: Fix ultracite doctor reporting spurious failures: config checks now walk up parent directories (matching check/fix and the linters themselves) so monorepo packages inheriting a root config pass, .oxlintrc.json is accepted as a valid oxlint config (with a migration suggestion), and Prettier/Stylelint configs declared via package.json keys are recognized.
  • d018b7f: Fix ultracite init corrupting existing Prettier/Stylelint/ESLint configs by writing an ESM module into JSON/YAML/TOML/CJS config files (e.g. .prettierrc, eslint.config.cjs). Updates now write the default .mjs config instead and remove the incompatible file so it can't shadow the new one.
  • d018b7f: Fix ultracite check/fix misrouting space-separated flag values (e.g. --max-warnings 10) into the file list, which scrambled the underlying linter invocation and made formatters fail on bogus targets. Positional files listed before a -- separator are also kept as lint targets instead of being reclassified as passthrough, which could silently widen formatter runs to the whole project.
  • d018b7f: Fix Lefthook and pre-commit YAML updates silently doing nothing on common config shapes: the Lefthook job is now inserted correctly when jobs: isn't the first key under pre-commit: (and no longer matches a jobs: key in a different hook), repos: [] in .pre-commit-config.yaml is handled, and shapes that can't be safely edited produce a warning instead of writing the file back unchanged.
  • d018b7f: Fix the Husky integration overwriting an existing .husky/pre-commit hook: ultracite init ran husky init, which unconditionally replaces the hook with npm test. It now runs plain husky to set up the hooks infrastructure without touching the hook file.
  • d018b7f: Fix ultracite init destroying user files it couldn't parse or merge: unparseable tsconfig.json files are no longer replaced with a minimal config, unparseable .vscode/.zed settings are no longer overwritten wholesale, and lint-staged configs with function-valued entries are left untouched — all now warn and skip instead.
  • d018b7f: Fix re-running ultracite init on an oxlint setup silently enabling the full js-plugins preset — the previously selected JS plugins are now preserved when no new selection is made. Init also no longer flips an explicit "type": "commonjs" in package.json to "module"; it warns instead.
  • d018b7f: Fix switching linters removing storybook from the project's dependencies. It was swept into the removal set as a peer of eslint-plugin-storybook, but it's a user-facing tool a project may use independently of linting.
  • d018b7f: Fix Stylelint target generation dropping directories with a dot in their name (e.g. app.web) and producing non-matching globs from Windows-style backslash paths. Framework detection also handles negated workspace patterns (!packages/legacy) again.
  • d018b7f: Fix the CLI becoming a silent no-op (exiting 0 without linting anything) when a generic TEST environment variable is set, as is common in CI matrices. The internal test guard now uses ULTRACITE_TEST.
  • 36c7b80: Move @​typescript-eslint/utils from dependencies to devDependencies. It was accidentally shipped as a runtime dependency in 7.9.0, pulling eslint and the typescript-eslint packages into every consumer's install (including oxlint-only setups) via npm's automatic peer dependency installation. Nothing in the published package imports it — it only exists to support the workspace-internal rule-parity script.

v7.10.0

Compare Source

Minor Changes
  • cd0a36c: Add --claude and --codex flags to ultracite fix. After the normal autofix pass, remaining diagnostics are handed to the Claude Code or Codex CLI non-interactively, one agent run per affected file, with a live per-issue spinner that flips to ✓/✗ once the fix is verified by a re-lint. Fixes that don't survive verification are retried (up to 3 attempts per file) with the fresh diagnostics and feedback that the previous approach failed. Works with all three linter modes (Oxlint, Biome, ESLint); exits non-zero if any issues remain, matching the plain fix contract.

  • e089510: Scope React Doctor's framework-specific rules to per-framework add-on presets (#​752)

    The ultracite/oxlint/js-plugins preset no longer enables React Doctor's nextjs-* and TanStack (query-*, tanstack-start-*) rules for every consumer. Rules like nextjs-no-img-element and tanstack-start-no-anchor-element fire on plain <img>/<a> JSX and recommend framework replacements, which falsely errored in Vite + React and other non-Next/non-TanStack projects.

    Those rules now live in two new add-on presets:

    • ultracite/oxlint/next/js-plugins
    • ultracite/oxlint/tanstack/js-plugins

    ultracite init wires the matching add-on automatically when you select the framework together with oxlint-plugin-react-doctor. If you manage oxlint.config.ts by hand and use Next.js or TanStack, add the matching add-on preset to extends alongside js-plugins to keep those rules — or re-run npx ultracite init.

    Also fixes re-running init on a config that already extends js-plugins producing a duplicate import jsPlugins declaration.

Patch Changes
  • 3320cd8: Update Biome to 2.5.6. No stable (non-nursery) rules were added, removed, or promoted between 2.5.3 and 2.5.6, so the preset configs are unchanged.

  • 477cd6e: Update ESLint to 10.8.0 and all ESLint plugins to their latest versions. Highlights:

    • eslint-plugin-react-doctor 0.9.3: the react preset expands from 149 to 417 rules, adopting the upstream recommended set (react-router, three.js/r3f, ink, motion, remotion, zustand/valtio/mobx, and more) while excluding rules that duplicate already-enabled react, react-hooks, and jsx-a11y rules. The next preset gains nextjs-async-dynamic-api-not-awaited and nextjs-metadata-url-consistency; the tanstack preset gains tanstack-start-missing-scripts, query-floating-mutate-async, and query-no-mutation-in-effect-as-read.
    • eslint-plugin-unicorn 72: adds no-missing-local-resource, no-multiple-promise-resolver-calls, no-shorthand-property-overrides, no-transition-all, no-unnecessary-string-trim, no-useless-re-export, prefer-then-catch, and require-frontmatter-fields. CSS-only rules are excluded from the preset since they fail config validation for JS files.
    • eslint-plugin-sonarjs 4.2: adds 11 rules including no-fixed-wait-in-tests, parameterized-tests, assertions-in-test-cases, prefer-native-lodash-alternative, and explicit-test-skip.
    • typescript-eslint 8.65: @typescript-eslint/no-loop-func and @typescript-eslint/no-restricted-imports were deprecated upstream in favor of the base rules, which now apply to TypeScript files.
    • eslint-plugin-astro 3: removes astro/no-omitted-end-tags and astro/valid-compile.
    • eslint-plugin-svelte 3.22: adds no-bind-value-on-checkable-inputs and no-conflicting-module-names; no-restricted-html-elements is now off because its schema requires a user-supplied element list.
    • @angular-eslint/eslint-plugin 22.1: adds inject-at-top and prefer-service-decorator.
  • b81578b: Fix the useSortedPackageJson action not being executed by turning on assist actions for package.json-like files.

  • 9ec454a: Update oxlint to 1.76.0 and oxfmt to 0.61.0. New stable rules added to the presets: oxc/bad-match-all-arg, id-denylist, node/exports-style (core), react/function-component-definition with arrow-function components (react), and vitest/padding-around-test-blocks (vitest). node/no-top-level-await is off — top-level await is idiomatic in ESM, Astro frontmatter, and build scripts — and the ESLint preset's n/no-top-level-await is now off to match. No rules were removed or promoted out of nursery.

  • ba61c02: Fix generated oxlint.config.ts accessing plugin.name on ExternalPluginEntry without narrowing the string form, which caused a TypeScript error in projects that type-check the config (#​753)


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 4am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@netlify

netlify Bot commented Aug 5, 2026

Copy link
Copy Markdown

Deploy Preview for semantic-template failed. Why did it fail? →

Name Link
🔨 Latest commit 1ea1cca
🔍 Latest deploy log https://app.netlify.com/projects/semantic-template/deploys/6a879d91f8e6b00008ea5fa6

@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch from 9606cfb to 6d193d9 Compare August 5, 2026 05:39
@renovate renovate Bot changed the title chore(deps): update dependency ultracite to v7.10.0 chore(deps): update dependency ultracite to v7.10.1 Aug 5, 2026
@renovate renovate Bot changed the title chore(deps): update dependency ultracite to v7.10.1 chore(deps): update dependency ultracite to v7.10.2 Aug 8, 2026
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch from 6d193d9 to c2476b8 Compare August 8, 2026 22:01
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch from c2476b8 to 0c49827 Compare August 12, 2026 00:34
@renovate renovate Bot changed the title chore(deps): update dependency ultracite to v7.10.2 chore(deps): update dependency ultracite to v7.10.3 Aug 12, 2026
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch from 0c49827 to d6756e7 Compare August 12, 2026 09:41
@happy-haki

Copy link
Copy Markdown
Contributor

Daily maintainer check (2026-08-14): holding — Netlify deploy-preview failed (log). Additionally, ultracite@7.10.3 was published 2026-08-12 (2 days old) which is a minor version with significant linter/tooling changes; 7-day hold applies per policy.

@happy-haki happy-haki mentioned this pull request Aug 14, 2026
6 tasks
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch 2 times, most recently from c05e13d to 331c14f Compare August 14, 2026 09:13
@renovate renovate Bot changed the title chore(deps): update dependency ultracite to v7.10.3 chore(deps): update dependency ultracite to v7.10.4 Aug 14, 2026
@happy-haki

Copy link
Copy Markdown
Contributor

📅 Daily maintainer check (2026-08-15)

Status: 7-DAY HOLD + BLOCKED

  • ultracite 7.9.4→7.10.4 is a minor version jump with substantive lint config changes (new anti-slop preset, rule reclassifications)
  • npm publish age: ~1 day (published 2026-08-14) — well within 7-day hold
  • Netlify deploy-preview: FAILED — also blocks merge
  • This does NOT qualify for low-risk exception (minor version, runtime lint behavior changes)

Eligible for review after: 2026-08-21 (7-day hold) AND Netlify failures resolved

Next review: 2026-08-16

@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch 2 times, most recently from 9dc9831 to 0700eae Compare August 15, 2026 08:35
@renovate renovate Bot changed the title chore(deps): update dependency ultracite to v7.10.4 chore(deps): update dependency ultracite to v7.10.5 Aug 15, 2026
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch 4 times, most recently from 8833393 to bd76d1c Compare August 20, 2026 09:55
@renovate renovate Bot changed the title chore(deps): update dependency ultracite to v7.10.5 chore(deps): update dependency ultracite to v7.10.6 Aug 20, 2026
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch from bd76d1c to 1ea1cca Compare August 21, 2026 00:36
@happy-haki
happy-haki merged commit 1cf4075 into main Aug 22, 2026
1 of 5 checks passed
@renovate
renovate Bot deleted the renovate/ultracite-7.x branch August 22, 2026 00:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant