Skip to content

build(deps-dev): bump eslint from 9.10.0 to 9.39.4 - #111

Closed
dependabot[bot] wants to merge 2 commits into
masterfrom
dependabot/npm_and_yarn/eslint-9.39.4
Closed

dependabot[bot] wants to merge 2 commits into
masterfrom
dependabot/npm_and_yarn/eslint-9.39.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 9, 2026 •

Copy link
Copy Markdown

Bumps eslint from 9.10.0 to 9.39.4.

Release notes

Sourced from eslint's releases.

v9.39.4

Bug Fixes

  • f18f6c8 fix: update dependency minimatch to ^3.1.5 (#20564) (Milos Djermanovic)
  • a3c868f fix: update dependency @​eslint/eslintrc to ^3.3.4 (#20554) (Milos Djermanovic)
  • 234d005 fix: minimatch security vulnerability patch for v9.x (#20549) (Andrej Beles)
  • b1b37ee fix: update ajv to 6.14.0 to address security vulnerabilities (#20538) (루밀LuMir)

Documentation

  • 4675152 docs: add deprecation notice partial (#20520) (Milos Djermanovic)

Chores

  • b8b4eb1 chore: update dependencies for ESLint v9.39.4 (#20596) (Francesco Trotta)
  • 71b2f6b chore: package.json update for @​eslint/js release (Jenkins)
  • 1d16c2f ci: pin Node.js 25.6.1 (#20563) (Milos Djermanovic)

v9.39.3

Bug Fixes

  • 791bf8d fix: restore TypeScript 4.0 compatibility in types (#20504) (sethamus)

Chores

  • 8594a43 chore: upgrade @​eslint/js@​9.39.3 (#20529) (Milos Djermanovic)
  • 9ceef92 chore: package.json update for @​eslint/js release (Jenkins)
  • af498c6 chore: ignore /docs/v9.x in link checker (#20453) (Milos Djermanovic)

v9.39.2

Bug Fixes

  • 5705833 fix: warn when eslint-env configuration comments are found (#20381) (sethamus)

Build Related

  • 506f154 build: add .scss files entry to knip (#20391) (Milos Djermanovic)

Chores

  • 7ca0af7 chore: upgrade to @eslint/js@9.39.2 (#20394) (Francesco Trotta)
  • c43ce24 chore: package.json update for @​eslint/js release (Jenkins)
  • 4c9858e ci: add v9.x-dev branch (#20382) (Milos Djermanovic)

v9.39.1

Bug Fixes

  • 650753e fix: Only pass node to JS lang visitor methods (#20283) (Nicholas C. Zakas)

Documentation

  • 51b51f4 docs: add a section on when to use extends vs cascading (#20268) (Tanuj Kanti)
  • b44d426 docs: Update README (GitHub Actions Bot)

Chores

  • 92db329 chore: update @eslint/js version to 9.39.1 (#20284) (Francesco Trotta)
  • c7ebefc chore: package.json update for @​eslint/js release (Jenkins)
  • 61778f6 chore: update eslint-config-eslint dependency @​eslint/js to ^9.39.0 (#20275) (renovate[bot])
  • d9ca2fc ci: Add rangeStrategy to eslint group in renovate config (#20266) (唯然)
  • 009e507 test: fix version tests for ESLint v10 (#20274) (Milos Djermanovic)

... (truncated)

Commits

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [eslint](https://github.com/eslint/eslint) from 9.10.0 to 9.39.4.
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v9.10.0...v9.39.4)

---
updated-dependencies:
- dependency-name: eslint
  dependency-version: 9.39.4
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies javascript Pull requests that update javascript code labels Apr 9, 2026

@Phani024 Phani024 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Apr 9, 2026

Copy link
Copy Markdown
Author

Looks like this PR is already up-to-date with master! If you'd still like to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@Phani024 Phani024 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github May 19, 2026

Copy link
Copy Markdown
Author

Looks like this PR is already up-to-date with master! If you'd still like to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@zeeshanamjad-eng

Copy link
Copy Markdown
Contributor

https://github.com/dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Jul 13, 2026

Copy link
Copy Markdown
Author

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates JavaScript/TypeScript linting toolchain dependencies in this repo by bumping eslint and typescript-eslint to newer versions, along with the resulting lockfile updates.

Changes:

  • Bump eslint from ^9.10.0 to ^9.39.4.
  • Bump typescript-eslint from ^8.5.0 to ^8.60.1.
  • Refresh package-lock.json to reflect updated transitive dependency graph.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
package.json Updates eslint and typescript-eslint devDependency versions.
package-lock.json Updates resolved versions/transitive dependencies corresponding to the new lint tooling versions.
Comments suppressed due to low confidence (1)

package.json:38

  • After bumping eslint/typescript-eslint, the repo's declared Node engine (>=20.0.0) is now looser than what the dependency tree requires. eslint@9.39.4 requires Node ^18.18.0 || ^20.9.0 || >=21.1.0, and @typescript-eslint/visitor-keys pulls eslint-visitor-keys@5.0.1 which requires Node ^20.19.0 || ^22.13.0 || >=24. This can break installs/linting for users on Node 20.0–20.18 even though package.json advertises support.
    "typescript-eslint": "^8.60.1"
  },
  "engines": {
    "node": ">=20.0.0"
  }

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@dependabot @github

dependabot Bot commented on behalf of github Jul 28, 2026

Copy link
Copy Markdown
Author

A newer version of eslint exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.

sachushaji added a commit that referenced this pull request Sep 3, 2026
Consolidates stale dependabot PRs #75, #101, #111, #116, #121, #145 and #151 into one bump: eslint ^9.39.4, typescript-eslint ^8.60.1, plus transitive updates (fast-uri, brace-expansion, qs, follow-redirects, diff, sha.js). Major bumps (hardhat 3, hardhat-toolbox 7) are intentionally excluded as breaking.

Ticket: SCAAS-11228
sachushaji added a commit that referenced this pull request Sep 3, 2026
Consolidates stale dependabot PRs #75, #101, #111, #116, #121, #145 and #151 into one bump. Major bumps (hardhat 3, hardhat-toolbox 7) are intentionally excluded as breaking.

Ticket: SCAAS-11228
sachushaji added a commit that referenced this pull request Sep 3, 2026
Consolidates stale dependabot PRs #75, #101, #111, #116, #121, #145 and #151 into one bump: eslint ^9.39.4, typescript-eslint ^8.60.1, engines.node >=20.19.0, plus transitive updates (fast-uri, brace-expansion, qs, follow-redirects, diff, sha.js). Major bumps (hardhat 3, hardhat-toolbox 7) are intentionally excluded as breaking. Rebased on master with axios 1.19.0.

Ticket: SCAAS-11228
sachushaji added a commit that referenced this pull request Sep 3, 2026
Consolidates stale dependabot PRs #75, #101, #111, #116, #121, #145 and #151 into one bump: eslint ^9.39.4, typescript-eslint ^8.60.1, engines.node >=20.19.0, plus transitive updates (fast-uri, brace-expansion, qs, follow-redirects, diff, sha.js). Major bumps (hardhat 3, hardhat-toolbox 7) are intentionally excluded as breaking. Rebased on master with axios 1.19.0.

Ticket: SCAAS-11228
Signed-off-by: Sachu Abraham <sachuabraham@bitgo.com>
sachushaji added a commit that referenced this pull request Sep 3, 2026
Consolidates stale dependabot PRs #75, #101, #111, #116, #121, #145 and #151 into one bump: eslint ^9.39.4, typescript-eslint ^8.60.1, engines.node >=20.19.0, plus transitive updates (fast-uri, brace-expansion, qs, follow-redirects, diff, sha.js). Major bumps (hardhat 3, hardhat-toolbox 7) are intentionally excluded as breaking. Rebased on master with axios 1.19.0.

Ticket: SCAAS-11228
Signed-off-by: Sachu Abraham <sachuabraham@bitgo.com>
Signed-off-by: Sachu Shaji Abraham <sachuabraham@bitgo.com>
@sachushaji

Copy link
Copy Markdown
Contributor

Superseded by merged PR #152, which consolidates the non-breaking dependency updates.

@sachushaji sachushaji closed this Sep 3, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/eslint-9.39.4 branch September 3, 2026 10:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants