Skip to content

chore(deps): update dependency ultracite to v7#23

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/ultracite-7.x
Open

chore(deps): update dependency ultracite to v7#23
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/ultracite-7.x

Conversation

@renovate

@renovate renovate Bot commented Jan 1, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
ultracite (source) 5.0.327.9.4 age confidence

Release Notes

haydenbleasel/ultracite (ultracite)

v7.9.4

Compare Source

Patch Changes
  • f480c12: Upgrade Biome to 2.5.3 to fix the LSP scanner deadlock (#​10845) where editors get stuck on "Biome is scanning the project".
  • 1d70c40: Fail fast with an actionable message when Biome can't resolve ultracite/biome/core. Biome resolves that config out of the project's node_modules, so it errors with an opaque "module not found" whenever Ultracite isn't installed there — a state npx ultracite check / bunx ultracite check hide, because they run the CLI from a temp cache regardless. check and fix now detect it before invoking Biome and say what's actually wrong, and doctor verifies that Ultracite resolves rather than just appearing in package.json (#​750).
  • 38d10bc: Move Biome's noUnknownAttribute rule out of the core preset and into the react preset. The rule only recognises React's JSX attribute names, so projects using Solid, Svelte, Vue, or Qwik were incorrectly flagged for framework-standard attributes such as class.
  • cf723bd: Add interactive and non-interactive selection for optional Oxlint JS plugins during init.

v7.9.3

Compare Source

Patch Changes
  • dc6d760: Disable the n/no-unpublished-import rule in the ESLint core config. This rule flags imports of packages that aren't listed as published dependencies, but it produces a lot of false positives in practice, so it's now turned off.
  • 15ecfba: Fix ultracite init --linter eslint installing an unusable toolchain. The generated ESLint config imports eslint-plugin-storybook unconditionally (which requires the storybook peer) and the generated Stylelint config extends stylelint-config-standard / stylelint-config-idiomatic-order / stylelint-prettier, but none of those packages were installed — so a fresh ESLint setup failed to load with "Cannot find package 'storybook'" or "Could not find stylelint-config-standard". These four packages are now installed with the ESLint linter.
  • 2f73a41: Upgrade to oxlint 1.73.0 and oxfmt 0.58.0, and enable the new lint rules they introduce: no-unreachable-loop, unicorn/explicit-timer-delay, and unicorn/no-confusing-array-with.
  • 83b2783: Add an [astro] formatter mapping (astro-build.astro-vscode) to the oxlint VS Code editor settings generated by ultracite init, since oxfmt doesn't format .astro files.
  • d186c53: Move every JS-plugin-based rule set out of the Oxlint core and framework presets and into a single opt-in ultracite/oxlint/js-plugins preset. This covers eslint-plugin-github and eslint-plugin-sonarjs (previously in core) as well as oxlint-plugin-react-doctor (previously bundled into the react, next, and tanstack presets). The core, react, next, and tanstack presets now run entirely on Oxlint's native Rust rules, so new setups no longer install those dependencies and no longer pay the slower JS-plugin lint pass. To keep the extra ESLint-parity and React Doctor rules, install eslint-plugin-github, eslint-plugin-sonarjs, and oxlint-plugin-react-doctor and extend ultracite/oxlint/js-plugins alongside core (and your framework preset).
  • 057753e: Add performance benchmarks for ultracite check / ultracite fix across all three providers (oxlint, biome, eslint). A new CI job builds the PR and its base branch on the same runner, benchmarks them interleaved, and fails on a statistically significant regression (median ratio > 1.25x with Mann-Whitney U p < 0.05) so config changes can't silently slow the linters down again.

v7.9.2

Compare Source

Patch Changes
  • c335a1f: Add **/node_modules and **/.git to the shared ignore patterns. oxlint only skips node_modules when a .gitignore lists it, so in projects without one, ultracite fix would lint and autofix files inside node_modules — corrupting installed packages (e.g. rewriting var enum wrappers in typescript/lib/typescript.js to self-referencing const, causing "Cannot access 'Comparison' before initialization" when oxlint loads eslint-plugin-sonarjs). Fixes #​737.

v7.9.1

Compare Source

Patch Changes
  • ecd10cc: Disable sonarjs/no-implicit-dependencies and github/no-implicit-buggy-globals in the oxlint and ESLint presets. Both produce false positives through oxlint's JS plugin bridge: no-implicit-dependencies has no dependency-manifest resolution so it flags builtin (bun:test) and workspace imports as missing dependencies, and no-implicit-buggy-globals misreads module-scoped declarations such as Astro frontmatter as implicit globals.

  • c76f59d: Disable sonarjs/file-name-differ-from-class in the oxlint and ESLint presets. It fires on any file whose name differs from an exported class, which is noise for the many config and module files that export objects rather than classes.

  • 29e30ce: Fold the github and sonarjs rules into the oxlint core preset. The standalone ultracite/oxlint/github and ultracite/oxlint/sonarjs presets are removed — ultracite ships framework presets, not individual plugins. Their rules now live in ultracite/oxlint/core, so every oxlint setup gets eslint-plugin-github and eslint-plugin-sonarjs through oxlint's JS plugin bridge, matching how the ESLint preset already bundles them into core.

    This is a breaking change to generated configs: ultracite/oxlint/github and ultracite/oxlint/sonarjs no longer exist. Re-run ultracite init to regenerate oxlint.config.ts.

    Also fixed: nine sonarjs rules (async-test-assertions, hooks-before-test-cases, no-duplicate-test-title, no-empty-test-title, no-floating-point-equality, no-forced-browser-interaction, no-trivial-assertions, prefer-specific-assertions, super-linear-regex) that exist in eslint-plugin-sonarjs but that oxlint's JS plugin bridge does not register. Naming them made oxlint hard-fail config parsing, which broke ultracite fix/check for oxlint projects using the sonarjs preset. They are omitted from oxlint core (still enabled in the ESLint preset), and a test now runs oxlint against core to catch this class of regression.

    The React Doctor, github, and sonarjs plugins are installed into your project's devDependencies at init (as the ESLint plugins already were), rather than bundled as dependencies of ultracite — oxlint resolves JS plugin specifiers from the project root, so they must be installed there directly.

  • 8a4291f: Upgrade to Oxlint 1.72.0 and Oxfmt 0.57.0. Oxfmt 0.57 adds native CSS and GraphQL formatters. The five new non-nursery Oxlint rules from the 1.71/1.72 releases are already covered by the presets (node/no-sync, node/no-mixed-requires, unicorn/prefer-number-coercion, unicorn/max-nested-calls, vue/no-async-in-computed-properties). The markdown ::: container-directive fence patch (which keeps proseWrap: "never" from folding fences into prose) was regenerated against the 0.57 bundle.

v7.9.0

Compare Source

Minor Changes
  • aea7fc0: Update Biome to 2.5.2 and enable the newly-stabilized rules. This adds coverage for the rules promoted out of nursery in Biome 2.5.0, including noShadow, noUnnecessaryConditions, noUnusedInstantiation (formerly noFloatingClasses), useArrayFind, useDestructuring, useGlobalThis, useErrorCause, noNestedPromises, GraphQL validation rules, and the recommended Vue/Next.js domain rules.
  • 2687cf9: Align the ESLint and Biome presets with the oxlint preset, which is now the benchmark for rule decisions across linters. ESLint: rules that oxlint deliberately disables are now off (no-console, no-continue, id-length, new-cap, max-depth, no-implicit-coercion, no-underscore-dangle, init-declarations, n/no-sync, promise/always-return, promise/catch-or-return, import-x/no-commonjs, import-x/no-dynamic-require, import-x/no-nodejs-modules, import-x/unambiguous, import-x/no-anonymous-default-export, @typescript-eslint/explicit-member-accessibility, @typescript-eslint/explicit-module-boundary-types, @typescript-eslint/no-require-imports, and the unicorn rules explicit-length-check, max-nested-calls, no-process-exit, prefer-global-this, prefer-string-raw, prefer-top-level-await); consistent-type-definitions now enforces interface instead of type, matching oxlint and Biome; no-void allows statement position to coexist with no-floating-promises; import-x/no-named-as-default is enabled; and curly and no-unexpected-multiline are re-enabled past eslint-config-prettier. Biome: noAwaitInLoops and noIncrementDecrement are now errors and the useSortedKeys assist is on (matching no-await-in-loop, no-plusplus, and sort-keys in the other presets), while useGlobalThis is off (matching unicorn/prefer-global-this).
  • 73c1993: Require ESLint 10 for ESLint setups. The plugin suite upgrade (notably eslint-plugin-unicorn 70 and eslint-plugin-astro 2) requires ESLint 10, but ultracite init still installed eslint@^9.0.0, which crashed at config load time. Init now installs eslint@^10.0.0 and @eslint/js@^10.0.0, and the presets are fixed for ESLint 10 compatibility: settings.react.version is pinned to 19.0.0 instead of "detect" (detection uses an API removed in ESLint 10), react/jsx-filename-extension and react/forward-ref-uses-ref are disabled (their implementations use removed APIs; the former is already off in the oxlint preset and the latter is covered by react-doctor/no-react19-deprecated-apis), the react config re-applies eslint-config-prettier so JSX formatting rules stay off (several crash under ESLint 10), and import-x/no-unused-modules is disabled (it is a warning-emitting no-op under ESLint 10). Note that some plugins (eslint-plugin-github, eslint-plugin-react, eslint-plugin-jsx-a11y, eslint-plugin-solid, @tanstack/eslint-plugin-start) have not yet updated their declared peer ranges to include ESLint 10 even though they work at runtime, so strict package managers may report peer dependency warnings.
  • 4cfdf3d: Add eslint-plugin-jsdoc to the ESLint preset. The oxlint preset already enforces a set of jsdoc rules, but the ESLint preset had no jsdoc coverage at all. The plugin is now installed by ultracite init for ESLint setups and enables the same rule selection the oxlint preset enforces (check-access, check-property-names, check-tag-names, empty-tags, implements-on-classes, no-defaults, and the require-* description/name/type rules), keeping the two presets in lockstep.
  • 0b8fc12: Upgrade the ESLint plugin suite and enable the new rules that ship with it. Notable bumps: eslint-plugin-unicorn 64 → 70 (adds a large batch of new correctness and quality rules), eslint-plugin-astro 1 → 2 (adds no-omitted-end-tags, now requires ESLint 10), eslint-plugin-sonarjs 4.0 → 4.1 (adds test-assertion and ReDoS rules like super-linear-regex), eslint-plugin-svelte 3.19 → 3.20 (adds no-at-const-tags), plus @typescript-eslint, eslint-plugin-import-x, eslint-plugin-n, @vitest/eslint-plugin, and others. Two Unicorn rules that were renamed are re-mapped in the config (prefer-dom-node-datasetdom-node-dataset, prevent-abbreviationsname-replacements). Two new Unicorn rules are disabled: prefer-temporal (since Temporal still lacks broad runtime support) and no-asterisk-prefix-in-documentation-comments (it fights the conventional JSDoc comment style).
  • 4440393: Bring the oxlint preset closer to ESLint parity with two new presets that run ESLint plugins through oxlint's JS plugin support: ultracite/oxlint/github (eslint-plugin-github) and ultracite/oxlint/sonarjs (eslint-plugin-sonarjs, 187 rules — type-aware rules are excluded since the JS plugin bridge provides no type information, and no-reference-error is off because the bridge provides no globals). ultracite init now adds both presets to generated oxlint configs and installs the two plugins; existing configs are untouched until the next init, and either preset can be dropped from extends to opt out (the plugins add roughly 1–3s to a lint run for the JS runtime bridge). Rule decisions mirror the oxlint benchmark in both directions: the ESLint preset now disables sonarjs/file-header (it errored on every file), sonarjs/arrow-function-convention (fights the formatter), sonarjs/cyclomatic-complexity, sonarjs/max-lines, sonarjs/max-lines-per-function, sonarjs/nested-control-flow (duplicates of core rules the preset disables), sonarjs/shorthand-property-grouping (conflicts with sort-keys), and github/no-dataset (conflicts with unicorn/prefer-dom-node-dataset), and sets sonarjs/cognitive-complexity to 20 to match Biome's noExcessiveCognitiveComplexity. Switching linters with init no longer removes dependencies that the newly selected linter still needs.
  • f7025b1: Extend cross-linter parity to the framework presets and add an automated parity check. The oxlint react preset now explicitly lists all 102 non-nursery react/react-perf/jsx-a11y rules (previously only ~20 were configured, so most a11y and correctness rules silently never ran) and the next preset lists all 21 nextjs rules, with decisions matching the ESLint presets. The revived exhaustiveness test (the oxlint --rules markdown output it parsed is empty as of oxlint 1.72, so it was passing vacuously) also caught five newly stabilized rules which are now enabled: getter-return, no-unreachable, oxc/branches-sharing-code, unicorn/prefer-export-from, and unicorn/prefer-single-call. ESLint preset fixes that fell out of the audit: no-loss-of-precision and no-duplicate-imports are re-enabled for TypeScript files (their @typescript-eslint twins were removed in v8, leaving TS uncovered), no-duplicate-imports gets allowSeparateTypeImports to match oxlint, the react/vue configs now only re-apply the react/-vue/-prefixed entries of eslint-config-prettier so they can't clobber unrelated rules, the svelte preset keeps the formatting rules disabled that eslint-plugin-svelte's own prettier preset lists, and astro/semi is off (Prettier owns formatting). A new compare-rule-parity script runs as part of validate:configs: it resolves the effective ESLint rule sets with ESLint's own config resolution, normalizes names to oxlint's, and fails on any divergence not recorded in an explicit allowlist — currently just two entries (sonarjs/no-reference-error, unicorn/number-literal-case), both with documented reasons.
  • 223233f: Add React Doctor rules to the ESLint and Oxlint React, Next.js, and TanStack presets. This enables React Doctor's own rules — the "You Might Not Need an Effect" family (no-fetch-in-effect, no-derived-state, no-mirror-prop-effect, etc.) plus its render-performance, hydration, server-component, security, and framework-specific rules — via eslint-plugin-react-doctor and the oxlint-plugin-react-doctor JS plugin. Rules that React Doctor ports from eslint-plugin-react, eslint-plugin-react-hooks, and eslint-plugin-jsx-a11y are intentionally left off to avoid duplicate diagnostics with the plugins Ultracite already ships.
Patch Changes
  • d247ff2: Migrate stale linter and formatter configuration when switching toolchains during init. Running ultracite init now removes config files and dependencies for unselected Biome, ESLint/Prettier/Stylelint, or Oxlint/Oxfmt setups before writing the selected toolchain config.
  • e24068b: Sort package.json keys when using Biome

v7.8.4

Compare Source

Patch Changes
  • e4ddd22: Ignore .yarn directories by default
  • a1d5c06: Configure Oxfmt to never wrap prose (proseWrap: "never")
  • df709a4: Ignore .wrangler and .wrangler-dry-run output directories by default

v7.8.3

Compare Source

Patch Changes
  • c863d09: Fix automatic editor extension installation during ultracite init.

    The whole command line (e.g. code --install-extension) was passed to
    spawnSync as the executable name, which always failed with ENOENT and
    silently fell back to the "install manually" message. The command is now split
    into the binary and its arguments, so the linter extension actually installs
    for VS Code-based editors.

  • 6888129: Enable the eslint/no-await-in-loop rule as an error in the core Oxlint
    preset.

    Awaiting inside a loop forces each iteration to run sequentially, which can
    lead to serious performance issues when the asynchronous operations could
    otherwise run concurrently. Promoting this rule to an error encourages
    collecting promises and resolving them together (e.g. with Promise.all)
    instead of blocking on each one in turn.

  • 62a9b5c: Fix the generated Husky pre-commit hook's error handling and section
    replacement.

    The standalone hook script set set -e and then tried to capture the
    formatter's exit code, re-stage files, and print a failure message — but a
    non-zero formatter exit terminated the script immediately, so none of that
    ever ran. The script now captures the exit code with || FORMAT_EXIT_CODE=$?
    so files are re-staged and failures are reported with the right exit code.

    Re-running ultracite init also deleted everything from the # ultracite
    marker to the end of the hook, including commands the user added after the
    ultracite section. The section is now terminated with an explicit
    # ultracite end marker and updates replace only the section between the
    markers (legacy sections without an end marker are detected by their closing
    echo line).

  • 6608ceb: Make the lint-staged integration idempotent and respect dedicated config
    files.

    package.json was always treated as the lint-staged config because the file
    exists in every project, so ultracite init wrote the lint-staged config into
    package.json even when a dedicated .lintstagedrc.* or
    lint-staged.config.* file was present — leaving two conflicting configs.
    package.json now only counts when it actually has a lint-staged key;
    otherwise the dedicated config file is updated (or .lintstagedrc.json is
    created).

    Re-running ultracite init also appended another npx ultracite fix entry on
    every run because the merge concatenates arrays. Updates are now skipped when
    the existing config already references ultracite.

  • 4e847f7: Insert -- before script arguments in npm hook commands.

    The post-edit hook command generated for npm projects was
    npm run fix --skip=correctness/noUnusedImports, where npm consumes the
    --skip flag itself instead of forwarding it to the script — so agent hooks
    ran a plain ultracite fix, including the unused-import removal the flag
    exists to prevent mid-edit. The generated command is now
    npm run fix -- --skip=correctness/noUnusedImports, matching the documented
    form.

  • ecb0d5b: Scope the Stylelint step of ultracite check and ultracite fix (ESLint mode)
    to style files.

    Stylelint was previously given the same targets as ESLint and Prettier (or .
    when no files were passed), so it tried to parse .ts/.json files as CSS and
    failed with CssSyntaxError. Style files now pass through unchanged, directory
    targets become **/*.{css,scss,sass,less} globs, other files are dropped, and
    the step is skipped entirely when no style targets remain.
    --allow-empty-input is passed so projects without CSS still succeed.

  • 61ea0a1: Fix the project-path write guard's error message and ordering.

    The "Refusing to write through directory outside project" error interpolated
    the node:path module instead of the offending file path, printing
    [object Object]. It now reports the actual path.

    writeProjectFile also created directories (mkdir -p) before running the
    path-escape check, so directories could be created outside the project before
    the guard threw. Validation now happens first; the parent-directory check
    resolves the nearest existing ancestor so writes into not-yet-created nested
    directories still work.

v7.8.2

Compare Source

Patch Changes
  • 30971a8: Enable newly available Oxlint and Stylelint rules in the shared configs.

    For Oxlint, the core preset now enables eslint/prefer-named-capture-group,
    jsdoc/require-yields-description, node/callback-return,
    typescript/method-signature-style, and unicorn/import-style.

    The Vue preset now enables vue/component-definition-name-casing,
    vue/no-computed-properties-in-data, vue/no-deprecated-props-default-this,
    vue/no-expose-after-await, vue/no-reserved-component-names,
    vue/no-shared-component-data, vue/no-watch-after-await,
    vue/require-prop-type-constructor, vue/require-render-return,
    vue/require-slots-as-functions, vue/return-in-emits-validator,
    vue/valid-define-options, and vue/valid-next-tick.

    The Stylelint preset now enables display-notation with the short option.

v7.8.1

Compare Source

Patch Changes
  • 8335be7: Build the CLI with bun build and a tsgo type-check gate instead of tsup.
  • f747449: Fix the Oxlint TanStack preset so route files under routes/ and app/routes/ are exempt from unicorn/filename-case, matching the documented 7.8.0 behavior.
  • 092597e: Fix generated oxlint.config.ts to be pre-formatted according to oxfmt rules, so ultracite check passes immediately after ultracite init without requiring a separate format step.
  • 81da6e8: Generate agent and editor hook commands through nypm's package-manager script helper.
  • 81da6e8: Keep hyphen-prefixed file operands from being forwarded to linters as options.

v7.8.0

Compare Source

Minor Changes
  • 4e2fea0: Add a dedicated tanstack framework preset for Biome, ESLint, and Oxlint. The ESLint preset layers @tanstack/eslint-plugin-query, @tanstack/eslint-plugin-router, and @tanstack/eslint-plugin-start, while the Biome and Oxlint presets relax file-naming conventions for routes/ directories and the generated routeTree.gen.ts. Framework detection now maps @tanstack/react-query, @tanstack/react-router, and @tanstack/react-start to the new tanstack preset.

    Two behavior changes for existing consumers: TanStack Query rules now live in the tanstack preset instead of react, so projects that relied on Query rules must opt into tanstack; and TanStack Router projects now resolve to the tanstack preset rather than remix.

Patch Changes
  • 51a2af0: Recognize .biome.json and .biome.jsonc as valid Biome config files across the CLI. detectLinter, the doctor command, and the Biome config resolver now match the dot-prefixed names alongside biome.json/biome.jsonc, following Biome's documented configuration file resolution order. Closes #​700.

  • 14b557c: Harden the generated standalone Husky hook by using git add -- "$file" when restaging formatted files. This prevents option-shaped filenames from being interpreted as Git options during the hook.

  • baa3dd0: Add ignorePatterns to the generated oxlint config at the root level so they are actually applied. Oxlint does not merge ignorePatterns through extends (see oxc-project/oxc#10223), so patterns set in the core preset were silently ignored. The generated config now sets ignorePatterns: core.ignorePatterns at the top level, reusing the patterns from the imported core preset.

  • bd27fd4: Add newly supported Oxlint rules from the latest release to the core, React, and Vitest presets:

    • Core: id-match, no-implicit-globals, no-implied-eval, prefer-arrow-callback, prefer-regex-literals, import/newline-after-import, jsdoc/require-throws-description, jsdoc/require-throws-type, and jsdoc/require-yields-type
    • React: jsx-a11y/control-has-associated-label, jsx-a11y/no-interactive-element-to-noninteractive-role, jsx-a11y/no-noninteractive-element-interactions, jsx-a11y/no-noninteractive-element-to-interactive-role, react/no-object-type-as-default-prop, and react/no-unstable-nested-components
    • Vitest: vitest/padding-around-after-all-blocks
  • 14b557c: Reject symlinked generated config targets before writing project files. CLI config writers now route through a shared project-file write guard that checks for symlinks and project-root escapes before mutating files.

  • 14b557c: Validate package-manager names before generating agent and editor hook commands. Hook configuration now only uses supported package-manager prefixes, preventing unsafe values from being persisted into later-executed hook commands.

  • 14b557c: Reject unsupported package-manager names during ultracite init. Explicit --pm values and detected packageManager metadata are now runtime-validated against the supported package managers before dependency installation, preventing malicious project metadata from selecting an arbitrary executable.

v7.7.0

Compare Source

Minor Changes
  • 24b0d27: Wire up the nestjs ESLint preset to actually enforce rules. Previously the preset exported an empty const config = [], meaning users who imported ultracite/eslint/nestjs got nothing. It now layers @darraghor/eslint-plugin-nestjs-typed (22 rules covering NestJS conventions, dependency injection correctness, and class-validator/Swagger usage) using the same dynamic-enable pattern as the other framework presets.

    Consumers who already had the empty preset in their config may see new violations on first run.

Patch Changes
  • 161418a: Add missing Biome stable rules to the core config:

    • suspicious/noDuplicateDependencies"error" — flags a dependency listed multiple times in the same group, or across dependencies and devDependencies, in package.json.
    • suspicious/useDeprecatedDate"off" — GraphQL-only convention requiring a deletionDate argument on @deprecated; too opinionated for the default preset.
  • 9a2b548: Pin @angular-eslint/eslint-plugin to ^21.3.1 in packages/cli/package.json. Previously declared as "latest", which defeats lockfile reproducibility and means each bun install could pull a newer version than what was tested at publish time. The current resolved version (21.3.1) is unchanged.

  • 44f6d7f: Align ESLint presets with the oxlint configs (the maintained source of truth). Mostly tightens ESLint where oxlint was stricter; a few documented behavioural exceptions oxlint carries (rule conflicts, bun:test compat) are mirrored back.

    coreeslint.mjs now enforces complexity, no-unused-private-class-members, sort-keys, sort-vars, and full prefer-destructuring (object + array). typescript.mjs now enforces no-confusing-void-expression, no-misused-promises, prefer-readonly, strict-boolean-expressions, and sets return-await: ["error", "always"]. import.mjs now sets consistent-type-specifier-style: ["error", "prefer-top-level"].

    next — added next-env.d.ts override that disables import-x/no-unassigned-import on the generated file.

    remix — added routeTree.gen.ts override that disables unicorn/filename-case and unicorn/no-abusive-eslint-disable on the generated file.

    react — disabled react/jsx-boolean-value, react/no-unknown-property, and react/only-export-components to match oxlint.

    jest — broadened test globs to **/*.{test,spec}.{ts,tsx,js,jsx} + **/__tests__/**/*.{ts,tsx,js,jsx} (previously missed *.spec.* and __tests__/). Disabled no-empty-function and promise/prefer-await-to-then in test scope. Disabled jest/require-hook, jest/no-conditional-in-test, jest/no-hooks, jest/prefer-expect-assertions to mirror oxlint's bun:test/mocking accommodations.

    vitest — same test-glob broadening; same no-empty-function / promise/prefer-await-to-then test-scope disables. Removed the prefer-importing-vitest-globals and prefer-to-have-been-called-times disables (oxlint enforces these). Added prefer-lowercase-title: off and valid-title: off to resolve the documented conflict with prefer-describe-function-title (#​665).

  • 63f6a18: Drop the redundant react-hooks/exhaustive-deps: "error" override in config/eslint/react/rules/react-hooks.mjs. The dynamic-enable pattern already sets every non-deprecated react-hooks/* rule to "error", so the override was dead code. No behavior change.

  • 5a0ce67: Refresh the misleading header comment in config/eslint/core/rules/eslint-typescript.mjs. The disables for the formatting rules (brace-style, comma-dangle, indent, etc.) used to defer to @typescript-eslint's typed equivalents, but those rules were removed in v8. They're now disabled because Prettier/Oxfmt owns formatting. Updated the comment to reflect the actual rationale.

  • d681f70: Clean up config/eslint/core/rules/typescript.mjs: remove 22 stale overrides that referenced rules no longer present in @typescript-eslint/eslint-plugin v8.

    Most were formatting rules moved out to @stylistic (block-spacing, brace-style, comma-dangle, comma-spacing, func-call-spacing, indent, key-spacing, keyword-spacing, lines-around-comment, lines-between-class-members, member-delimiter-style, no-extra-parens, object-curly-spacing, padding-line-between-statements, quotes, semi, space-before-blocks, space-before-function-paren, space-infix-ops, type-annotation-spacing). The remaining two (no-type-alias, sort-type-union-intersection-members) were removed/deprecated upstream. All were dead no-ops — no behavior change.

v7.6.5

Compare Source

Patch Changes
  • 3e08c25: Fix ultracite init failing with npm error No workspaces found! in npm monorepos. When isMonorepo() was true, nypm was passed workspace: true, which translates to --workspaces for npm — that installs in every workspace package and errors when patterns match nothing. We now skip the workspace flag for npm (the default root install is what we want) while preserving the flag for pnpm (--workspace-root) and yarn classic (-W). Applies to ultracite, husky, lefthook, and lint-staged installs.

v7.6.4

Compare Source

Patch Changes
  • aba89bb: Add new oxlint 1.63.0 rules:

    • eslint/logical-assignment-operators"error" — prefer ||=, &&=, ??= over their longhand equivalents; aligns with the modern-JS baseline.
    • eslint/require-unicode-regexp"error" — require the u (or v) flag on regex literals for correct Unicode handling.
    • eslint/no-restricted-properties"off" — purely a project-specific allowlist; no useful default to enforce.
    • unicorn/no-negated-condition"error" — newly split from the eslint version; the unicorn variant additionally covers ternary expressions and complements the existing eslint/no-negated-condition.
    • jsx-a11y/interactive-supports-focus"error" — interactive elements (click handlers, role="button", etc.) must be keyboard-focusable; matches the rest of the a11y baseline.
    • vue/return-in-computed-property"error" — computed properties must return a value; missing return silently breaks reactivity.
    • vue/no-deprecated-model-definition"error" — flags Vue 2 model: { ... } usage; Vue 3 is the supported target.
    • vitest/prefer-mock-return-shorthand"error", vitest/no-unneeded-async-expect-function"error", vitest/prefer-to-have-been-called-times"error", vitest/prefer-snapshot-hint"error" — newly split out from the jest plugin; mirrors the existing jest config which has all four enabled.
    • vitest/require-hook"off" — newly split out from jest; disabled to mirror jest config (bun:test mock.module() must be called at top level).
  • 522155e: Set typescript/return-await to ["error", "always"] to resolve a circular conflict between eslint/require-await, typescript/promise-function-async, and typescript/return-await on Promise-returning functions outside try/catch. With the default in-try-catch mode, autofixers chase each other: promise-function-async adds async, require-await then demands an await, and return-await removes any return await outside a try/catch — leaving no resolvable state. The "always" mode keeps return await everywhere, breaking the cycle while preserving consistent stack traces.

v7.6.3

Compare Source

Patch Changes
  • f584d93: Disable unicorn/number-literal-case due to oxc-project/oxc#21949.

  • ef5c3ae: Fix ultracite check and ultracite fix short-circuiting after the formatter step. Previously, when the formatter (oxfmt or Prettier) exited non-zero, the linter (oxlint, ESLint, Stylelint) was never invoked, hiding lint errors until formatting was clean. The commands now run every step, accumulate failures, and exit with the first failing tool's status. Fixes #​690.

  • 3ecb159: Fix the generated oxfmt.config.ts template, which used extends: [ultracite] — a key oxfmt does not recognize, so the preset was silently dropped and built-in options like sortImports never took effect. The template now spreads the preset (...ultracite) so its options are actually applied. Fixes #​689.

  • 5a18ec8: Add new oxlint 1.61.0 and 1.62.0 rules:

    • eslint/func-name-matching"error" — function names should match the variable they're assigned to; matches the project's strict baseline.
    • eslint/no-underscore-dangle"off" — common patterns like _id (Mongo) and _internal make this rule too noisy in practice.
    • typescript/explicit-member-accessibility"off" — forcing public/private on every class member is verbose and not idiomatic in modern TS.
    • jest/prefer-expect-assertions"off" and vitest/prefer-expect-assertions"off" — requiring expect.assertions(n) in every test is too strict for general use; not all tests need explicit assertion counts.
    • vitest/max-expects"error" and vitest/max-nested-describe"error" — newly split out from the jest plugin; mirrors the existing jest config which has both enabled.
    • vitest/no-conditional-in-test"off" — newly split out from jest; disabled to mirror jest config (mock factories use conditionals for path-based routing).
    • vitest/no-hooks"off" — newly split out from jest; disabled to mirror jest config (bun:test uses beforeEach for mock.restore()).
    • react/forbid-component-props"off" — parity with the ESLint config, which already disables this rule.

v7.6.2

Compare Source

Patch Changes
  • 5be860c: Automatically detect frameworks during the init process.
  • 10d9e95: Support -v as a short alias for --version on the CLI (previously only -V worked).
  • 8ff1b96: Fix update command not migrating legacy ultracite/<name> extends entries to ultracite/biome/<name> (e.g. ultracite/core, ultracite/react, ultracite/type-aware, etc.).
  • 5e055ce: Ignore Cloudflare Workers' generated worker-configuration.d.ts (produced by wrangler types), matching the existing handling of next-env.d.ts.
  • 9cc7416: Add a universal editor target that creates .vscode/settings.json for every VS Code-based editor (VS Code, Cursor, Windsurf, CodeBuddy, Antigravity, IBM Bob, Kiro, Trae, Void) with a single selection. The init prompt now offers a "Universal" option, and --editors universal works as an alias on the CLI.

v7.6.1

Compare Source

Patch Changes
  • 2fbded9: Disable the typescript/prefer-readonly-parameter-types Oxlint rule. While the rule is useful for user-authored types, it fires on virtually every parameter that touches a third-party type (Express Request/Response, React events, Node Buffer, ORM models, DOM APIs) because those types aren't deeply readonly internally — leaving users with unfixable violations. Matches the existing ESLint config, which already has this rule off.
  • 617affd: Fix dist/, .next/, **/*.gen.*, and other strong-negation (!!) ignore globs being dropped when a consumer's biome.jsonc extends ultracite/biome/core and also defines its own files.includes. The globs moved into config/shared/ignores.jsonc in 7.5.9 were transitively extended through biome/core, and Biome's extend merge doesn't carry files.includes through a two-level chain when the middle config lacks its own entry. The patterns are now inlined directly in biome/core's files.includes (still generated from config/shared/ignores.mjs), matching the pre-7.5.9 behavior.
  • d681e08: Remove the nonexistent import-x/enforce-node-protocol-usage rule from the ESLint core config, which caused ESLint 9 to throw Could not find "enforce-node-protocol-usage" in plugin "import-x". Node protocol enforcement is already covered by unicorn/prefer-node-protocol.

v7.6.0

Compare Source

Minor Changes
Patch Changes
  • a684c4a: Fix Tanstack Query ESLint plugin import
  • 4983eaa: Skip the init skill-install prompt when the Ultracite skill is already installed in the current project or globally.

v7.5.9

Compare Source

Patch Changes
  • 77e9b41: Aggregate all ignore patterns
  • 73fc21c: Code reliability improvements
  • 63f7426: Migrate remaining json parsing to jsonc-parser
  • aa199d1: fix conflicting prefer-describe-function-title / valid-title rules in vitest
  • 402908e: Replace custom yaml parser with dependency
  • 3dbfe5c: Validate framework name to prevent injection
  • a2cdc0f: Warn if the file looks like it has ultracite config but we couldn't parse it
  • 95718bb: Use cross-spawn for cross-platform spawn compatibility
  • d09174b: Ignore .open-next in the Biome and ESLint core presets.
  • 71aeca4: Remove remaining execSync calls
  • e81a604: Add zod for safer json parsing

v7.5.8

Compare Source

Patch Changes
  • c35a1b3: Performance improvements - doctor
  • 56e4c00: Remove process.exit() - swap with typed Error
  • d35d03c: Performance optimizations - mkdir(), readFile()
  • ee224a6: Use Commander.js args properly
  • a2b7a46: Rework doctor command
  • cf4a044: Fix angular eslint plugin typo
  • 25eb24f: Optimize dev dep install
  • b46537a: Performance optimizations - exists()

v7.5.7

Compare Source

Patch Changes
  • a63d9c5: Fix cross-config leaking rules
  • d18d0e7: Configure Prettier with frameworks context
  • 1d6de0d: Add declaration files for ultracite/oxlint/* and ultracite/oxfmt so TypeScript config imports resolve without ts(7016) errors.
  • 1073f34: Ensure init'ed JSON files have newlines

v7.5.6

Compare Source

Patch Changes
  • acf4a97: Update oxlint jest rules
  • 6905932: Fix vitest/no-importing-vitest-globals conflict
  • 4e4dc03: Update oxlint vitest rules
  • 6a583d1: Fix oxfmt setup config

v7.5.5

Compare Source

Patch Changes
  • 5437f81: Attempt to fix oxlint/oxfmt AGAIN

v7.5.4

Compare Source

Patch Changes
  • 66999e0: Fix oxlint and oxfmt yet again

v7.5.3

Compare Source

Patch Changes
  • 97c3938: Fix oxlint and oxfmt import paths

v7.5.2

Compare Source

Patch Changes
  • 22df7a5: Fix oxlint import issues

v7.5.1

Compare Source

Patch Changes
  • e96c55a: Switch oxlint.config.ts to js imports

v7.5.0

Compare Source

Minor Changes
  • 7861cf7: Migrate oxlint and oxfmt configurations from JSON to TypeScript using defineConfig. The CLI now generates oxlint.config.ts and oxfmt.config.ts instead of .oxlintrc.json and .oxfmtrc.jsonc, and all internal framework presets have been converted to TypeScript.
Patch Changes
  • fdb1493: Exclude package manager lock files (bun.lock, bun.lockb, package-lock.json, yarn.lock, pnpm-lock.yaml) from Biome linting and formatting

v7.4.4

Compare Source

Patch Changes
  • e9db6f1: Add IBM Bob agent, editor, and logo
  • 5341bcc: Disable vitest/prefer-strict-boolean-matchers to resolve conflict with prefer-to-be-truthy and prefer-to-be-falsy

v7.4.3

Compare Source

Patch Changes
  • 42b3552: Update the bundled VS Code settings to use js/ts.tsdk.path and js/ts.tsdk.promptToUseWorkspaceVersion instead of the deprecated typescript.tsdk setting.
  • a0a03c6: Allow utf-8 values in the unicorn/text-encoding-identifier-case rule across the bundled ESLint and Oxlint configs.

v7.4.2

Compare Source

Patch Changes
  • 94e770e: Remove non-existent oxlint rules (import/no-unresolved, vitest/no-done-callback) for compatibility with oxlint 1.58.0+

v7.4.0

Compare Source

Minor Changes
  • c189cf1: Add support for new agent integrations including Zencoder, Ona, OpenClaw, Continue, Snowflake Cortex, Deepagents, Qoder, Kimi CLI, Kode, MCPJam, Mux, Pi, Neovate, Pochi, and AdaL, plus add CodeBuddy as a supported editor.
Patch Changes
  • 04d8455: Add no-void rule with allowAsStatement to complement no-floating-promises
  • e38d579: Fix DEP0190 deprecation warnings in check, fix, and doctor by routing CLI subprocesses through a shared cross-spawn runner with shell: false, while preserving Windows command resolution and direct file-path argument passing.
  • 98cb8c2: Pin ESLint initialization to a peer-compatible dependency set so ultracite init no longer installs an incompatible eslint@latest with eslint-plugin-github
  • fd7d05f: Disable conflicting vitest/prefer-called-times oxlint rule to resolve conflict with vitest/prefer-called-once
  • [581ea40](https://redirect.github.com/hayden

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@coderabbitai

coderabbitai Bot commented Jan 1, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • 🔍 Trigger a full review

Comment @coderabbitai help to get the list of available commands and usage tips.

@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch 5 times, most recently from f65d2fe to 7a1ea43 Compare January 8, 2026 15:50
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch from 7a1ea43 to 854c2a3 Compare January 10, 2026 07:45
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch from 854c2a3 to a94b1aa Compare January 21, 2026 07:43
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch 5 times, most recently from a79dccc to 7b093af Compare February 4, 2026 12:16
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch 2 times, most recently from 3ec91f3 to bcdb951 Compare February 13, 2026 23:55
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch 4 times, most recently from 02b40bc to e9a422b Compare February 19, 2026 07:47
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch from e9a422b to bfda886 Compare March 1, 2026 08:07
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch 2 times, most recently from 8bdf913 to a40721a Compare March 14, 2026 21:47
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch from a40721a to 7c310be Compare March 31, 2026 10:13
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch 2 times, most recently from 1c54c27 to 50796e5 Compare April 19, 2026 04:16
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch 2 times, most recently from 6502c2d to de0c874 Compare May 6, 2026 02:47
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch 3 times, most recently from 29c4c9a to ee2bc20 Compare May 11, 2026 19:50
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch 2 times, most recently from 9022ae7 to e537638 Compare May 28, 2026 03:47
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch from e537638 to df4a994 Compare June 4, 2026 03:34
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch from df4a994 to d03330c Compare June 12, 2026 23:55
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch 2 times, most recently from 55da23e to 9c61d16 Compare July 8, 2026 08:07
@renovate
renovate Bot force-pushed the renovate/ultracite-7.x branch from 9c61d16 to ccb5619 Compare July 17, 2026 04:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants