chore(deps): update dependency ultracite to v7.9.4#120
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
from
April 11, 2026 08:46
945d1b5 to
e197cf6
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
from
April 11, 2026 17:34
e197cf6 to
df60c64
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
from
April 11, 2026 21:02
df60c64 to
66fd065
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
from
April 12, 2026 01:04
66fd065 to
1841698
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
2 times, most recently
from
April 15, 2026 10:23
e7c4cd6 to
75324e0
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
from
April 16, 2026 15:40
75324e0 to
145efa4
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
2 times, most recently
from
April 26, 2026 05:26
97532a5 to
0882344
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
from
April 29, 2026 18:12
0882344 to
87e186c
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
2 times, most recently
from
May 8, 2026 05:44
1ec2d2c to
04e1d84
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
from
May 8, 2026 16:58
04e1d84 to
7dde70e
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
from
May 11, 2026 00:47
7dde70e to
04235b7
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
2 times, most recently
from
May 18, 2026 17:42
1d11a82 to
e1c9ba7
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
from
May 26, 2026 11:01
e1c9ba7 to
74e06b2
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
from
May 31, 2026 09:45
74e06b2 to
e5736f2
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
from
June 1, 2026 19:51
e5736f2 to
0a3ac31
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
2 times, most recently
from
June 10, 2026 06:16
5394f1a to
ad3d9ef
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
from
July 2, 2026 18:58
ad3d9ef to
57b27ac
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
from
July 5, 2026 10:36
57b27ac to
1cd4521
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
from
July 6, 2026 09:14
1cd4521 to
7bd5257
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
from
July 8, 2026 05:39
7bd5257 to
c98afc0
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
2 times, most recently
from
July 14, 2026 03:12
ead42f6 to
0d81b39
Compare
renovate
Bot
force-pushed
the
renovate/ultracite-7.x
branch
from
July 16, 2026 21:09
0d81b39 to
a2135df
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
7.4.3→7.9.4Release Notes
haydenbleasel/ultracite (ultracite)
v7.9.4Compare Source
Patch Changes
f480c12: Upgrade Biome to 2.5.3 to fix the LSP scanner deadlock (#10845) where editors get stuck on "Biome is scanning the project".1d70c40: Fail fast with an actionable message when Biome can't resolveultracite/biome/core. Biome resolves that config out of the project'snode_modules, so it errors with an opaque "module not found" whenever Ultracite isn't installed there — a statenpx ultracite check/bunx ultracite checkhide, because they run the CLI from a temp cache regardless.checkandfixnow detect it before invoking Biome and say what's actually wrong, anddoctorverifies that Ultracite resolves rather than just appearing inpackage.json(#750).38d10bc: Move Biome'snoUnknownAttributerule out of the core preset and into thereactpreset. The rule only recognises React's JSX attribute names, so projects using Solid, Svelte, Vue, or Qwik were incorrectly flagged for framework-standard attributes such asclass.cf723bd: Add interactive and non-interactive selection for optional Oxlint JS plugins during init.v7.9.3Compare Source
Patch Changes
dc6d760: Disable then/no-unpublished-importrule in the ESLint core config. This rule flags imports of packages that aren't listed as published dependencies, but it produces a lot of false positives in practice, so it's now turned off.15ecfba: Fixultracite init --linter eslintinstalling an unusable toolchain. The generated ESLint config importseslint-plugin-storybookunconditionally (which requires thestorybookpeer) and the generated Stylelint config extendsstylelint-config-standard/stylelint-config-idiomatic-order/stylelint-prettier, but none of those packages were installed — so a fresh ESLint setup failed to load with "Cannot find package 'storybook'" or "Could not find stylelint-config-standard". These four packages are now installed with the ESLint linter.2f73a41: Upgrade to oxlint 1.73.0 and oxfmt 0.58.0, and enable the new lint rules they introduce:no-unreachable-loop,unicorn/explicit-timer-delay, andunicorn/no-confusing-array-with.83b2783: Add an[astro]formatter mapping (astro-build.astro-vscode) to the oxlint VS Code editor settings generated byultracite init, since oxfmt doesn't format.astrofiles.d186c53: Move every JS-plugin-based rule set out of the Oxlint core and framework presets and into a single opt-inultracite/oxlint/js-pluginspreset. This coverseslint-plugin-githubandeslint-plugin-sonarjs(previously in core) as well asoxlint-plugin-react-doctor(previously bundled into thereact,next, andtanstackpresets). The core,react,next, andtanstackpresets now run entirely on Oxlint's native Rust rules, so new setups no longer install those dependencies and no longer pay the slower JS-plugin lint pass. To keep the extra ESLint-parity and React Doctor rules, installeslint-plugin-github,eslint-plugin-sonarjs, andoxlint-plugin-react-doctorand extendultracite/oxlint/js-pluginsalongsidecore(and your framework preset).057753e: Add performance benchmarks forultracite check/ultracite fixacross all three providers (oxlint, biome, eslint). A new CI job builds the PR and its base branch on the same runner, benchmarks them interleaved, and fails on a statistically significant regression (median ratio > 1.25x with Mann-Whitney U p < 0.05) so config changes can't silently slow the linters down again.v7.9.2Compare Source
Patch Changes
c335a1f: Add**/node_modulesand**/.gitto the shared ignore patterns. oxlint only skipsnode_moduleswhen a.gitignorelists it, so in projects without one,ultracite fixwould lint and autofix files insidenode_modules— corrupting installed packages (e.g. rewritingvarenum wrappers intypescript/lib/typescript.jsto self-referencingconst, causing "Cannot access 'Comparison' before initialization" when oxlint loads eslint-plugin-sonarjs). Fixes #737.v7.9.1Compare Source
Patch Changes
ecd10cc: Disablesonarjs/no-implicit-dependenciesandgithub/no-implicit-buggy-globalsin the oxlint and ESLint presets. Both produce false positives through oxlint's JS plugin bridge:no-implicit-dependencieshas no dependency-manifest resolution so it flags builtin (bun:test) and workspace imports as missing dependencies, andno-implicit-buggy-globalsmisreads module-scoped declarations such as Astro frontmatter as implicit globals.c76f59d: Disablesonarjs/file-name-differ-from-classin the oxlint and ESLint presets. It fires on any file whose name differs from an exported class, which is noise for the many config and module files that export objects rather than classes.29e30ce: Fold the github and sonarjs rules into the oxlint core preset. The standaloneultracite/oxlint/githubandultracite/oxlint/sonarjspresets are removed — ultracite ships framework presets, not individual plugins. Their rules now live inultracite/oxlint/core, so every oxlint setup gets eslint-plugin-github and eslint-plugin-sonarjs through oxlint's JS plugin bridge, matching how the ESLint preset already bundles them into core.This is a breaking change to generated configs:
ultracite/oxlint/githubandultracite/oxlint/sonarjsno longer exist. Re-runultracite initto regenerateoxlint.config.ts.Also fixed: nine sonarjs rules (
async-test-assertions,hooks-before-test-cases,no-duplicate-test-title,no-empty-test-title,no-floating-point-equality,no-forced-browser-interaction,no-trivial-assertions,prefer-specific-assertions,super-linear-regex) that exist in eslint-plugin-sonarjs but that oxlint's JS plugin bridge does not register. Naming them made oxlint hard-fail config parsing, which brokeultracite fix/checkfor oxlint projects using the sonarjs preset. They are omitted from oxlint core (still enabled in the ESLint preset), and a test now runs oxlint against core to catch this class of regression.The React Doctor, github, and sonarjs plugins are installed into your project's devDependencies at init (as the ESLint plugins already were), rather than bundled as dependencies of ultracite — oxlint resolves JS plugin specifiers from the project root, so they must be installed there directly.
8a4291f: Upgrade to Oxlint 1.72.0 and Oxfmt 0.57.0. Oxfmt 0.57 adds native CSS and GraphQL formatters. The five new non-nursery Oxlint rules from the 1.71/1.72 releases are already covered by the presets (node/no-sync,node/no-mixed-requires,unicorn/prefer-number-coercion,unicorn/max-nested-calls,vue/no-async-in-computed-properties). The markdown:::container-directive fence patch (which keepsproseWrap: "never"from folding fences into prose) was regenerated against the 0.57 bundle.v7.9.0Compare Source
Minor Changes
aea7fc0: Update Biome to 2.5.2 and enable the newly-stabilized rules. This adds coverage for the rules promoted out of nursery in Biome 2.5.0, includingnoShadow,noUnnecessaryConditions,noUnusedInstantiation(formerlynoFloatingClasses),useArrayFind,useDestructuring,useGlobalThis,useErrorCause,noNestedPromises, GraphQL validation rules, and the recommended Vue/Next.js domain rules.2687cf9: Align the ESLint and Biome presets with the oxlint preset, which is now the benchmark for rule decisions across linters. ESLint: rules that oxlint deliberately disables are now off (no-console,no-continue,id-length,new-cap,max-depth,no-implicit-coercion,no-underscore-dangle,init-declarations,n/no-sync,promise/always-return,promise/catch-or-return,import-x/no-commonjs,import-x/no-dynamic-require,import-x/no-nodejs-modules,import-x/unambiguous,import-x/no-anonymous-default-export,@typescript-eslint/explicit-member-accessibility,@typescript-eslint/explicit-module-boundary-types,@typescript-eslint/no-require-imports, and theunicornrulesexplicit-length-check,max-nested-calls,no-process-exit,prefer-global-this,prefer-string-raw,prefer-top-level-await);consistent-type-definitionsnow enforcesinterfaceinstead oftype, matching oxlint and Biome;no-voidallows statement position to coexist withno-floating-promises;import-x/no-named-as-defaultis enabled; andcurlyandno-unexpected-multilineare re-enabled pasteslint-config-prettier. Biome:noAwaitInLoopsandnoIncrementDecrementare now errors and theuseSortedKeysassist is on (matchingno-await-in-loop,no-plusplus, andsort-keysin the other presets), whileuseGlobalThisis off (matchingunicorn/prefer-global-this).73c1993: Require ESLint 10 for ESLint setups. The plugin suite upgrade (notablyeslint-plugin-unicorn70 andeslint-plugin-astro2) requires ESLint 10, butultracite initstill installedeslint@^9.0.0, which crashed at config load time. Init now installseslint@^10.0.0and@eslint/js@^10.0.0, and the presets are fixed for ESLint 10 compatibility:settings.react.versionis pinned to19.0.0instead of"detect"(detection uses an API removed in ESLint 10),react/jsx-filename-extensionandreact/forward-ref-uses-refare disabled (their implementations use removed APIs; the former is already off in the oxlint preset and the latter is covered byreact-doctor/no-react19-deprecated-apis), the react config re-applieseslint-config-prettierso JSX formatting rules stay off (several crash under ESLint 10), andimport-x/no-unused-modulesis disabled (it is a warning-emitting no-op under ESLint 10). Note that some plugins (eslint-plugin-github,eslint-plugin-react,eslint-plugin-jsx-a11y,eslint-plugin-solid,@tanstack/eslint-plugin-start) have not yet updated their declared peer ranges to include ESLint 10 even though they work at runtime, so strict package managers may report peer dependency warnings.4cfdf3d: Addeslint-plugin-jsdocto the ESLint preset. The oxlint preset already enforces a set of jsdoc rules, but the ESLint preset had no jsdoc coverage at all. The plugin is now installed byultracite initfor ESLint setups and enables the same rule selection the oxlint preset enforces (check-access,check-property-names,check-tag-names,empty-tags,implements-on-classes,no-defaults, and therequire-*description/name/type rules), keeping the two presets in lockstep.0b8fc12: Upgrade the ESLint plugin suite and enable the new rules that ship with it. Notable bumps:eslint-plugin-unicorn64 → 70 (adds a large batch of new correctness and quality rules),eslint-plugin-astro1 → 2 (addsno-omitted-end-tags, now requires ESLint 10),eslint-plugin-sonarjs4.0 → 4.1 (adds test-assertion and ReDoS rules likesuper-linear-regex),eslint-plugin-svelte3.19 → 3.20 (addsno-at-const-tags), plus@typescript-eslint,eslint-plugin-import-x,eslint-plugin-n,@vitest/eslint-plugin, and others. Two Unicorn rules that were renamed are re-mapped in the config (prefer-dom-node-dataset→dom-node-dataset,prevent-abbreviations→name-replacements). Two new Unicorn rules are disabled:prefer-temporal(sinceTemporalstill lacks broad runtime support) andno-asterisk-prefix-in-documentation-comments(it fights the conventional JSDoc comment style).4440393: Bring the oxlint preset closer to ESLint parity with two new presets that run ESLint plugins through oxlint's JS plugin support:ultracite/oxlint/github(eslint-plugin-github) andultracite/oxlint/sonarjs(eslint-plugin-sonarjs, 187 rules — type-aware rules are excluded since the JS plugin bridge provides no type information, andno-reference-erroris off because the bridge provides no globals).ultracite initnow adds both presets to generated oxlint configs and installs the two plugins; existing configs are untouched until the nextinit, and either preset can be dropped fromextendsto opt out (the plugins add roughly 1–3s to a lint run for the JS runtime bridge). Rule decisions mirror the oxlint benchmark in both directions: the ESLint preset now disablessonarjs/file-header(it errored on every file),sonarjs/arrow-function-convention(fights the formatter),sonarjs/cyclomatic-complexity,sonarjs/max-lines,sonarjs/max-lines-per-function,sonarjs/nested-control-flow(duplicates of core rules the preset disables),sonarjs/shorthand-property-grouping(conflicts withsort-keys), andgithub/no-dataset(conflicts withunicorn/prefer-dom-node-dataset), and setssonarjs/cognitive-complexityto 20 to match Biome'snoExcessiveCognitiveComplexity. Switching linters withinitno longer removes dependencies that the newly selected linter still needs.f7025b1: Extend cross-linter parity to the framework presets and add an automated parity check. The oxlint react preset now explicitly lists all 102 non-nursery react/react-perf/jsx-a11y rules (previously only ~20 were configured, so most a11y and correctness rules silently never ran) and the next preset lists all 21 nextjs rules, with decisions matching the ESLint presets. The revived exhaustiveness test (theoxlint --rulesmarkdown output it parsed is empty as of oxlint 1.72, so it was passing vacuously) also caught five newly stabilized rules which are now enabled:getter-return,no-unreachable,oxc/branches-sharing-code,unicorn/prefer-export-from, andunicorn/prefer-single-call. ESLint preset fixes that fell out of the audit:no-loss-of-precisionandno-duplicate-importsare re-enabled for TypeScript files (their@typescript-eslinttwins were removed in v8, leaving TS uncovered),no-duplicate-importsgetsallowSeparateTypeImportsto match oxlint, the react/vue configs now only re-apply thereact/-vue/-prefixed entries ofeslint-config-prettierso they can't clobber unrelated rules, the svelte preset keeps the formatting rules disabled thateslint-plugin-svelte's own prettier preset lists, andastro/semiis off (Prettier owns formatting). A newcompare-rule-parityscript runs as part ofvalidate:configs: it resolves the effective ESLint rule sets with ESLint's own config resolution, normalizes names to oxlint's, and fails on any divergence not recorded in an explicit allowlist — currently just two entries (sonarjs/no-reference-error,unicorn/number-literal-case), both with documented reasons.223233f: Add React Doctor rules to the ESLint and Oxlint React, Next.js, and TanStack presets. This enables React Doctor's own rules — the "You Might Not Need an Effect" family (no-fetch-in-effect,no-derived-state,no-mirror-prop-effect, etc.) plus its render-performance, hydration, server-component, security, and framework-specific rules — viaeslint-plugin-react-doctorand theoxlint-plugin-react-doctorJS plugin. Rules that React Doctor ports fromeslint-plugin-react,eslint-plugin-react-hooks, andeslint-plugin-jsx-a11yare intentionally left off to avoid duplicate diagnostics with the plugins Ultracite already ships.Patch Changes
d247ff2: Migrate stale linter and formatter configuration when switching toolchains during init. Runningultracite initnow removes config files and dependencies for unselected Biome, ESLint/Prettier/Stylelint, or Oxlint/Oxfmt setups before writing the selected toolchain config.e24068b: Sortpackage.jsonkeys when using Biomev7.8.4Compare Source
Patch Changes
e4ddd22: Ignore.yarndirectories by defaulta1d5c06: Configure Oxfmt to never wrap prose (proseWrap: "never")df709a4: Ignore.wranglerand.wrangler-dry-runoutput directories by defaultv7.8.3Compare Source
Patch Changes
c863d09: Fix automatic editor extension installation duringultracite init.The whole command line (e.g.
code --install-extension) was passed tospawnSyncas the executable name, which always failed withENOENTandsilently fell back to the "install manually" message. The command is now split
into the binary and its arguments, so the linter extension actually installs
for VS Code-based editors.
6888129: Enable theeslint/no-await-in-looprule as an error in the core Oxlintpreset.
Awaiting inside a loop forces each iteration to run sequentially, which can
lead to serious performance issues when the asynchronous operations could
otherwise run concurrently. Promoting this rule to an error encourages
collecting promises and resolving them together (e.g. with
Promise.all)instead of blocking on each one in turn.
62a9b5c: Fix the generated Husky pre-commit hook's error handling and sectionreplacement.
The standalone hook script set
set -eand then tried to capture theformatter's exit code, re-stage files, and print a failure message — but a
non-zero formatter exit terminated the script immediately, so none of that
ever ran. The script now captures the exit code with
|| FORMAT_EXIT_CODE=$?so files are re-staged and failures are reported with the right exit code.
Re-running
ultracite initalso deleted everything from the# ultracitemarker to the end of the hook, including commands the user added after the
ultracite section. The section is now terminated with an explicit
# ultracite endmarker and updates replace only the section between themarkers (legacy sections without an end marker are detected by their closing
echo line).
6608ceb: Make the lint-staged integration idempotent and respect dedicated configfiles.
package.jsonwas always treated as the lint-staged config because the fileexists in every project, so
ultracite initwrote the lint-staged config intopackage.jsoneven when a dedicated.lintstagedrc.*orlint-staged.config.*file was present — leaving two conflicting configs.package.jsonnow only counts when it actually has alint-stagedkey;otherwise the dedicated config file is updated (or
.lintstagedrc.jsoniscreated).
Re-running
ultracite initalso appended anothernpx ultracite fixentry onevery run because the merge concatenates arrays. Updates are now skipped when
the existing config already references ultracite.
4e847f7: Insert--before script arguments in npm hook commands.The post-edit hook command generated for npm projects was
npm run fix --skip=correctness/noUnusedImports, where npm consumes the--skipflag itself instead of forwarding it to the script — so agent hooksran a plain
ultracite fix, including the unused-import removal the flagexists to prevent mid-edit. The generated command is now
npm run fix -- --skip=correctness/noUnusedImports, matching the documentedform.
ecb0d5b: Scope the Stylelint step ofultracite checkandultracite fix(ESLint mode)to style files.
Stylelint was previously given the same targets as ESLint and Prettier (or
.when no files were passed), so it tried to parse
.ts/.jsonfiles as CSS andfailed with
CssSyntaxError. Style files now pass through unchanged, directorytargets become
**/*.{css,scss,sass,less}globs, other files are dropped, andthe step is skipped entirely when no style targets remain.
--allow-empty-inputis passed so projects without CSS still succeed.61ea0a1: Fix the project-path write guard's error message and ordering.The "Refusing to write through directory outside project" error interpolated
the
node:pathmodule instead of the offending file path, printing[object Object]. It now reports the actual path.writeProjectFilealso created directories (mkdir -p) before running thepath-escape check, so directories could be created outside the project before
the guard threw. Validation now happens first; the parent-directory check
resolves the nearest existing ancestor so writes into not-yet-created nested
directories still work.
v7.8.2Compare Source
Patch Changes
30971a8: Enable newly available Oxlint and Stylelint rules in the shared configs.For Oxlint, the core preset now enables
eslint/prefer-named-capture-group,jsdoc/require-yields-description,node/callback-return,typescript/method-signature-style, andunicorn/import-style.The Vue preset now enables
vue/component-definition-name-casing,vue/no-computed-properties-in-data,vue/no-deprecated-props-default-this,vue/no-expose-after-await,vue/no-reserved-component-names,vue/no-shared-component-data,vue/no-watch-after-await,vue/require-prop-type-constructor,vue/require-render-return,vue/require-slots-as-functions,vue/return-in-emits-validator,vue/valid-define-options, andvue/valid-next-tick.The Stylelint preset now enables
display-notationwith theshortoption.v7.8.1Compare Source
Patch Changes
8335be7: Build the CLI withbun buildand atsgotype-check gate instead of tsup.f747449: Fix the Oxlint TanStack preset so route files underroutes/andapp/routes/are exempt fromunicorn/filename-case, matching the documented 7.8.0 behavior.092597e: Fix generatedoxlint.config.tsto be pre-formatted according to oxfmt rules, soultracite checkpasses immediately afterultracite initwithout requiring a separate format step.81da6e8: Generate agent and editor hook commands through nypm's package-manager script helper.81da6e8: Keep hyphen-prefixed file operands from being forwarded to linters as options.v7.8.0Compare Source
Minor Changes
4e2fea0: Add a dedicatedtanstackframework preset for Biome, ESLint, and Oxlint. The ESLint preset layers@tanstack/eslint-plugin-query,@tanstack/eslint-plugin-router, and@tanstack/eslint-plugin-start, while the Biome and Oxlint presets relax file-naming conventions forroutes/directories and the generatedrouteTree.gen.ts. Framework detection now maps@tanstack/react-query,@tanstack/react-router, and@tanstack/react-startto the newtanstackpreset.Two behavior changes for existing consumers: TanStack Query rules now live in the
tanstackpreset instead ofreact, so projects that relied on Query rules must opt intotanstack; and TanStack Router projects now resolve to thetanstackpreset rather thanremix.Patch Changes
51a2af0: Recognize.biome.jsonand.biome.jsoncas valid Biome config files across the CLI.detectLinter, thedoctorcommand, and the Biome config resolver now match the dot-prefixed names alongsidebiome.json/biome.jsonc, following Biome's documented configuration file resolution order. Closes #700.14b557c: Harden the generated standalone Husky hook by usinggit add -- "$file"when restaging formatted files. This prevents option-shaped filenames from being interpreted as Git options during the hook.baa3dd0: AddignorePatternsto the generated oxlint config at the root level so they are actually applied. Oxlint does not mergeignorePatternsthroughextends(see oxc-project/oxc#10223), so patterns set in the core preset were silently ignored. The generated config now setsignorePatterns: core.ignorePatternsat the top level, reusing the patterns from the imported core preset.bd27fd4: Add newly supported Oxlint rules from the latest release to the core, React, and Vitest presets:id-match,no-implicit-globals,no-implied-eval,prefer-arrow-callback,prefer-regex-literals,import/newline-after-import,jsdoc/require-throws-description,jsdoc/require-throws-type, andjsdoc/require-yields-typejsx-a11y/control-has-associated-label,jsx-a11y/no-interactive-element-to-noninteractive-role,jsx-a11y/no-noninteractive-element-interactions,jsx-a11y/no-noninteractive-element-to-interactive-role,react/no-object-type-as-default-prop, andreact/no-unstable-nested-componentsvitest/padding-around-after-all-blocks14b557c: Reject symlinked generated config targets before writing project files. CLI config writers now route through a shared project-file write guard that checks for symlinks and project-root escapes before mutating files.14b557c: Validate package-manager names before generating agent and editor hook commands. Hook configuration now only uses supported package-manager prefixes, preventing unsafe values from being persisted into later-executed hook commands.14b557c: Reject unsupported package-manager names duringultracite init. Explicit--pmvalues and detectedpackageManagermetadata are now runtime-validated against the supported package managers before dependency installation, preventing malicious project metadata from selecting an arbitrary executable.v7.7.0Compare Source
Minor Changes
24b0d27: Wire up thenestjsESLint preset to actually enforce rules. Previously the preset exported an emptyconst config = [], meaning users who importedultracite/eslint/nestjsgot nothing. It now layers@darraghor/eslint-plugin-nestjs-typed(22 rules covering NestJS conventions, dependency injection correctness, and class-validator/Swagger usage) using the same dynamic-enable pattern as the other framework presets.Consumers who already had the empty preset in their config may see new violations on first run.
Patch Changes
161418a: Add missing Biome stable rules to the core config:suspicious/noDuplicateDependencies→"error"— flags a dependency listed multiple times in the same group, or acrossdependenciesanddevDependencies, inpackage.json.suspicious/useDeprecatedDate→"off"— GraphQL-only convention requiring adeletionDateargument on@deprecated; too opinionated for the default preset.9a2b548: Pin@angular-eslint/eslint-pluginto^21.3.1inpackages/cli/package.json. Previously declared as"latest", which defeats lockfile reproducibility and means eachbun installcould pull a newer version than what was tested at publish time. The current resolved version (21.3.1) is unchanged.44f6d7f: Align ESLint presets with the oxlint configs (the maintained source of truth). Mostly tightens ESLint where oxlint was stricter; a few documented behavioural exceptions oxlint carries (rule conflicts, bun:test compat) are mirrored back.core —
eslint.mjsnow enforcescomplexity,no-unused-private-class-members,sort-keys,sort-vars, and fullprefer-destructuring(object + array).typescript.mjsnow enforcesno-confusing-void-expression,no-misused-promises,prefer-readonly,strict-boolean-expressions, and setsreturn-await: ["error", "always"].import.mjsnow setsconsistent-type-specifier-style: ["error", "prefer-top-level"].next — added
next-env.d.tsoverride that disablesimport-x/no-unassigned-importon the generated file.remix — added
routeTree.gen.tsoverride that disablesunicorn/filename-caseandunicorn/no-abusive-eslint-disableon the generated file.react — disabled
react/jsx-boolean-value,react/no-unknown-property, andreact/only-export-componentsto match oxlint.jest — broadened test globs to
**/*.{test,spec}.{ts,tsx,js,jsx}+**/__tests__/**/*.{ts,tsx,js,jsx}(previously missed*.spec.*and__tests__/). Disabledno-empty-functionandpromise/prefer-await-to-thenin test scope. Disabledjest/require-hook,jest/no-conditional-in-test,jest/no-hooks,jest/prefer-expect-assertionsto mirror oxlint's bun:test/mocking accommodations.vitest — same test-glob broadening; same
no-empty-function/promise/prefer-await-to-thentest-scope disables. Removed theprefer-importing-vitest-globalsandprefer-to-have-been-called-timesdisables (oxlint enforces these). Addedprefer-lowercase-title: offandvalid-title: offto resolve the documented conflict withprefer-describe-function-title(#665).63f6a18: Drop the redundantreact-hooks/exhaustive-deps: "error"override inconfig/eslint/react/rules/react-hooks.mjs. The dynamic-enable pattern already sets every non-deprecatedreact-hooks/*rule to"error", so the override was dead code. No behavior change.5a0ce67: Refresh the misleading header comment inconfig/eslint/core/rules/eslint-typescript.mjs. The disables for the formatting rules (brace-style,comma-dangle,indent, etc.) used to defer to@typescript-eslint's typed equivalents, but those rules were removed in v8. They're now disabled because Prettier/Oxfmt owns formatting. Updated the comment to reflect the actual rationale.d681f70: Clean upconfig/eslint/core/rules/typescript.mjs: remove 22 stale overrides that referenced rules no longer present in@typescript-eslint/eslint-pluginv8.Most were formatting rules moved out to
@stylistic(block-spacing,brace-style,comma-dangle,comma-spacing,func-call-spacing,indent,key-spacing,keyword-spacing,lines-around-comment,lines-between-class-members,member-delimiter-style,no-extra-parens,object-curly-spacing,padding-line-between-statements,quotes,semi,space-before-blocks,space-before-function-paren,space-infix-ops,type-annotation-spacing). The remaining two (no-type-alias,sort-type-union-intersection-members) were removed/deprecated upstream. All were dead no-ops — no behavior change.v7.6.5Compare Source
Patch Changes
3e08c25: Fixultracite initfailing withnpm error No workspaces found!in npm monorepos. WhenisMonorepo()was true, nypm was passedworkspace: true, which translates to--workspacesfor npm — that installs in every workspace package and errors when patterns match nothing. We now skip the workspace flag for npm (the default root install is what we want) while preserving the flag for pnpm (--workspace-root) and yarn classic (-W). Applies to ultracite, husky, lefthook, and lint-staged installs.v7.6.4Compare Source
Patch Changes
aba89bb: Add new oxlint 1.63.0 rules:eslint/logical-assignment-operators→"error"— prefer||=,&&=,??=over their longhand equivalents; aligns with the modern-JS baseline.eslint/require-unicode-regexp→"error"— require theu(orv) flag on regex literals for correct Unicode handling.eslint/no-restricted-properties→"off"— purely a project-specific allowlist; no useful default to enforce.unicorn/no-negated-condition→"error"— newly split from the eslint version; the unicorn variant additionally covers ternary expressions and complements the existingeslint/no-negated-condition.jsx-a11y/interactive-supports-focus→"error"— interactive elements (click handlers,role="button", etc.) must be keyboard-focusable; matches the rest of the a11y baseline.vue/return-in-computed-property→"error"— computed properties must return a value; missingreturnsilently breaks reactivity.vue/no-deprecated-model-definition→"error"— flags Vue 2model: { ... }usage; Vue 3 is the supported target.vitest/prefer-mock-return-shorthand→"error",vitest/no-unneeded-async-expect-function→"error",vitest/prefer-to-have-been-called-times→"error",vitest/prefer-snapshot-hint→"error"— newly split out from the jest plugin; mirrors the existing jest config which has all four enabled.vitest/require-hook→"off"— newly split out from jest; disabled to mirror jest config (bun:testmock.module()must be called at top level).522155e: Settypescript/return-awaitto["error", "always"]to resolve a circular conflict betweeneslint/require-await,typescript/promise-function-async, andtypescript/return-awaiton Promise-returning functions outside try/catch. With the defaultin-try-catchmode, autofixers chase each other:promise-function-asyncaddsasync,require-awaitthen demands anawait, andreturn-awaitremoves anyreturn awaitoutside a try/catch — leaving no resolvable state. The"always"mode keepsreturn awaiteverywhere, breaking the cycle while preserving consistent stack traces.v7.6.3Compare Source
Patch Changes
f584d93: Disableunicorn/number-literal-casedue to oxc-project/oxc#21949.ef5c3ae: Fixultracite checkandultracite fixshort-circuiting after the formatter step. Previously, when the formatter (oxfmt or Prettier) exited non-zero, the linter (oxlint, ESLint, Stylelint) was never invoked, hiding lint errors until formatting was clean. The commands now run every step, accumulate failures, and exit with the first failing tool's status. Fixes #690.3ecb159: Fix the generatedoxfmt.config.tstemplate, which usedextends: [ultracite]— a key oxfmt does not recognize, so the preset was silently dropped and built-in options likesortImportsnever took effect. The template now spreads the preset (...ultracite) so its options are actually applied. Fixes #689.5a18ec8: Add new oxlint 1.61.0 and 1.62.0 rules:eslint/func-name-matching→"error"— function names should match the variable they're assigned to; matches the project's strict baseline.eslint/no-underscore-dangle→"off"— common patterns like_id(Mongo) and_internalmake this rule too noisy in practice.typescript/explicit-member-accessibility→"off"— forcingpublic/privateon every class member is verbose and not idiomatic in modern TS.jest/prefer-expect-assertions→"off"andvitest/prefer-expect-assertions→"off"— requiringexpect.assertions(n)in every test is too strict for general use; not all tests need explicit assertion counts.vitest/max-expects→"error"andvitest/max-nested-describe→"error"— newly split out from the jest plugin; mirrors the existing jest config which has both enabled.vitest/no-conditional-in-test→"off"— newly split out from jest; disabled to mirror jest config (mock factories use conditionals for path-based routing).vitest/no-hooks→"off"— newly split out from jest; disabled to mirror jest config (bun:test usesbeforeEachformock.restore()).react/forbid-component-props→"off"— parity with the ESLint config, which already disables this rule.v7.6.2Compare Source
Patch Changes
5be860c: Automatically detect frameworks during theinitprocess.10d9e95: Support-vas a short alias for--versionon the CLI (previously only-Vworked).8ff1b96: Fixupdatecommand not migrating legacyultracite/<name>extends entries toultracite/biome/<name>(e.g.ultracite/core,ultracite/react,ultracite/type-aware, etc.).5e055ce: Ignore Cloudflare Workers' generatedworker-configuration.d.ts(produced bywrangler types), matching the existing handling ofnext-env.d.ts.9cc7416: Add auniversaleditor target that creates.vscode/settings.jsonfor every VS Code-based editor (VS Code, Cursor, Windsurf, CodeBuddy, Antigravity, IBM Bob, Kiro, Trae, Void) with a single selection. Theinitprompt now offers a "Universal" option, and--editors universalworks as an alias on the CLI.v7.6.1Compare Source
Patch Changes
2fbded9: Disable thetypescript/prefer-readonly-parameter-typesOxlint rule. While the rule is useful for user-authored types, it fires on virtually every parameter that touches a third-party type (ExpressRequest/Response, React events, NodeBuffer, ORM models, DOM APIs) because those types aren't deeply readonly internally — leaving users with unfixable violations. Matches the existing ESLint config, which already has this rule off.617affd: Fixdist/,.next/,**/*.gen.*, and other strong-negation (!!) ignore globs being dropped when a consumer'sbiome.jsoncextendsultracite/biome/coreand also defines its ownfiles.includes. The globs moved intoconfig/shared/ignores.jsoncin 7.5.9 were transitively extended throughbiome/core, and Biome's extend merge doesn't carryfiles.includesthrough a two-level chain when the middle config lacks its own entry. The patterns are now inlined directly inbiome/core'sfiles.includes(still generated fromconfig/shared/ignores.mjs), matching the pre-7.5.9 behavior.d681e08: Remove the nonexistentimport-x/enforce-node-protocol-usagerule from the ESLint core config, which caused ESLint 9 to throwCould not find "enforce-node-protocol-usage" in plugin "import-x". Node protocol enforcement is already covered byunicorn/prefer-node-protocol.v7.6.0Compare Source
Minor Changes
67227c9: Add new Biome rulesf506624: Add new oxlint 1.160.0 rulesPatch Changes
a684c4a: Fix Tanstack Query ESLint plugin import4983eaa: Skip the init skill-install prompt when the Ultracite skill is already installed in the current project or globally.v7.5.9Compare Source
Patch Changes
77e9b41: Aggregate all ignore patterns73fc21c: Code reliability improvements63f7426: Migrate remaining json parsing to jsonc-parseraa199d1: fix conflicting prefer-describe-function-title / valid-title rules in vitest402908e: Replace custom yaml parser with dependency3dbfe5c: Validate framework name to prevent injectiona2cdc0f: Warn if the file looks like it has ultracite config but we couldn't parse it95718bb: Use cross-spawn for cross-platform spawn compatibilityd09174b: Ignore.open-nextin the Biome and ESLint core presets.71aeca4: Remove remaining execSync callse81a604: Add zod for safer json parsingv7.5.8Compare Source
Patch Changes
c35a1b3: Performance improvements - doctor56e4c00: Remove process.exit() - swap with typed Errord35d03c: Performance optimizations - mkdir(), readFile()ee224a6: Use Commander.js args properlya2b7a46: Rework doctor commandcf4a044: Fix angular eslint plugin typo25eb24f: Optimize dev dep installb46537a: Performance optimizations - exists()v7.5.7Compare Source
Patch Changes
a63d9c5: Fix cross-config leaking rulesd18d0e7: Configure Prettier with frameworks context1d6de0d: Add declaration files forultracite/oxlint/*andultracite/oxfmtso TypeScript config imports resolve withoutts(7016)errors.1073f34: Ensure init'ed JSON files have newlinesv7.5.6Compare Source
Patch Changes
acf4a97: Update oxlint jest rules6905932: Fix vitest/no-importing-vitest-globals conflict4e4dc03: Update oxlint vitest rules6a583d1: Fix oxfmt setup configv7.5.5Compare Source
Patch Changes
5437f81: Attempt to fix oxlint/oxfmt AGAINv7.5.4Compare Source
Patch Changes
66999e0: Fix oxlint and oxfmt yet againv7.5.3Compare Source
Patch Changes
97c3938: Fix oxlint and oxfmt import pathsv7.5.2Compare Source
Patch Changes
22df7a5: Fix oxlint import issuesv7.5.1Compare Source
Patch Changes
e96c55a: Switch oxlint.config.ts to js importsv7.5.0Compare Source
Minor Changes
7861cf7: Migrate oxlint and oxfmt configurations from JSON to TypeScript usingdefineConfig. The CLI now generatesoxlint.config.tsandoxfmt.config.tsinstead of.oxlintrc.jsonand.oxfmtrc.jsonc, and all internal framework presets have been converted to TypeScript.Patch Changes
fdb1493: Exclude package manager lock files (bun.lock, bun.lockb, package-lock.json, yarn.lock, pnpm-lock.yaml) from Biome linting and formattingv7.4.4Compare Source
Patch Changes
e9db6f1: Add IBM Bob agent, editor, and logo5341bcc: Disable vitest/prefer-strict-boolean-matchers to resolve conflict with prefer-to-be-truthy and prefer-to-be-falsyConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.