refactor(lint): make frontend/package.json the only Biome version - #88
Merged
Merged
Conversation
Biome ran through the remote biomejs/pre-commit hook, which fetches its own hermetic copy and never looks at frontend/node_modules. That copy needed its own version, so one fact — which Biome this repo uses — was declared five times: the npm pin, the lockfile, the hook rev, the hook's additional_dependencies, and biome.json's $schema URL. Drift between them failed silently, the gate quietly enforcing the older ruleset; that is how the repo once ran 2.2.4 against a declared 2.5.11 (issue #81). scripts/check_biome_pins.py turned that silence into a loud failure, but it made every Biome bump a two-PR affair: Dependabot can only reach two of the five pins, so its PR failed CI by construction. Biome now runs as a repo: local hook invoking `npm run lint` — the same command a developer runs, and the pattern svelte-check already used. The version comes from node_modules, so package.json is the single source of truth and the guard has nothing left to check. Also moves file scoping out of the hook's regex into biome.json's files.includes, where it belongs. It had never been in biome.json at all, so `npm run lint` was unscoped: it swept frontend/.svelte-kit/ and emitted ~5600 diagnostics, making the documented lint command unusable. Both the hook and the npm script now check the same 26 files. Coverage is unchanged — verified the same file set before and after, and verified the hook still fails on an injected formatting violation.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Collapses five Biome version declarations into one, and deletes the guard that existed to police them.
The problem
Biome ran through the remote
biomejs/pre-commithook. Pre-commit fetches its own hermetic copy of a hook's tool and deliberately never looks atfrontend/node_modules— so that copy needed its own version number. Combined with the npm pin, the lockfile, andbiome.json's$schema, one fact was stated five times.Drift between them failed silently, the gate quietly enforcing whichever ruleset the hook's copy happened to be. That is how this repo once ran 2.2.4 against a declared 2.5.11, nine releases apart (#81).
scripts/check_biome_pins.pyturned that silence into a loud failure, which was the right immediate call. But it made every Biome bump a two-PR affair: Dependabot can only reach two of the five pins, so its PR failed CI by construction — most recently #85, which needed #86 to land first.The fix
Biome now runs as a
repo: localhook invokingnpm run lint— the same command a developer runs by hand, and the patternsvelte-checkalready used in this very file. The version comes fromnode_modules, sofrontend/package.jsonis the single source of truth and the guard has nothing left to check.frontend/package.jsonfrontend/package-lock.json.pre-commit-config.yamlrev.pre-commit-config.yamladditional_dependenciesbiome.json$schemaA future
@biomejs/biomebump from Dependabot now passes CI unaided.A bug found along the way
File scoping lived in the hook's
files:regex, and had never been inbiome.jsonat all. Sonpm run lint— the documented lint command — had no scoping whatsoever: it sweptfrontend/.svelte-kit/generated output and reported 1600 errors and 3996 warnings. CI never invokes that script, so nobody noticed.Scoping now lives in
biome.json'sfiles.includes, where it belongs. Both the hook and the npm script check the same 26 files, andnpm run lintis usable again.Verification
pre-commit run --all-files— 15/15 hooks pass (was 16; the guard is gone)package-lock.json, which Biome ignores internally either way.frontend/src/lib/types.ts, confirmedbiome checkfails on it, restored the file, confirmed it passes.npm run lint— 26 files, clean.Tradeoffs
frontend/node_modulesto exist. Already true forsvelte-check, already mandated by AGENTS.md, and CI runsnpm cibefore pre-commit.npm ciis reproducible, so this is a small, deliberate loss.AGENTS.mdis updated in the same PR per the rule added in #84 — the five-pin section is rewritten to describe the single source and the two things that follow from it.