build(deps-dev): bump eslint from 9.10.0 to 9.39.4 - #111
dependabot[bot] wants to merge 2 commits into
Conversation
Bumps [eslint](https://github.com/eslint/eslint) from 9.10.0 to 9.39.4. - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v9.10.0...v9.39.4) --- updated-dependencies: - dependency-name: eslint dependency-version: 9.39.4 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
|
Looks like this PR is already up-to-date with master! If you'd still like to recreate it from scratch, overwriting any edits, you can request |
|
Looks like this PR is already up-to-date with master! If you'd still like to recreate it from scratch, overwriting any edits, you can request |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
There was a problem hiding this comment.
Pull request overview
Updates JavaScript/TypeScript linting toolchain dependencies in this repo by bumping eslint and typescript-eslint to newer versions, along with the resulting lockfile updates.
Changes:
- Bump
eslintfrom^9.10.0to^9.39.4. - Bump
typescript-eslintfrom^8.5.0to^8.60.1. - Refresh
package-lock.jsonto reflect updated transitive dependency graph.
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| package.json | Updates eslint and typescript-eslint devDependency versions. |
| package-lock.json | Updates resolved versions/transitive dependencies corresponding to the new lint tooling versions. |
Comments suppressed due to low confidence (1)
package.json:38
- After bumping eslint/typescript-eslint, the repo's declared Node engine (>=20.0.0) is now looser than what the dependency tree requires. eslint@9.39.4 requires Node ^18.18.0 || ^20.9.0 || >=21.1.0, and
@typescript-eslint/visitor-keyspulls eslint-visitor-keys@5.0.1 which requires Node ^20.19.0 || ^22.13.0 || >=24. This can break installs/linting for users on Node 20.0–20.18 even though package.json advertises support.
"typescript-eslint": "^8.60.1"
},
"engines": {
"node": ">=20.0.0"
}
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
A newer version of eslint exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged. |
Consolidates stale dependabot PRs #75, #101, #111, #116, #121, #145 and #151 into one bump: eslint ^9.39.4, typescript-eslint ^8.60.1, plus transitive updates (fast-uri, brace-expansion, qs, follow-redirects, diff, sha.js). Major bumps (hardhat 3, hardhat-toolbox 7) are intentionally excluded as breaking. Ticket: SCAAS-11228
Consolidates stale dependabot PRs #75, #101, #111, #116, #121, #145 and #151 into one bump: eslint ^9.39.4, typescript-eslint ^8.60.1, engines.node >=20.19.0, plus transitive updates (fast-uri, brace-expansion, qs, follow-redirects, diff, sha.js). Major bumps (hardhat 3, hardhat-toolbox 7) are intentionally excluded as breaking. Rebased on master with axios 1.19.0. Ticket: SCAAS-11228
Consolidates stale dependabot PRs #75, #101, #111, #116, #121, #145 and #151 into one bump: eslint ^9.39.4, typescript-eslint ^8.60.1, engines.node >=20.19.0, plus transitive updates (fast-uri, brace-expansion, qs, follow-redirects, diff, sha.js). Major bumps (hardhat 3, hardhat-toolbox 7) are intentionally excluded as breaking. Rebased on master with axios 1.19.0. Ticket: SCAAS-11228 Signed-off-by: Sachu Abraham <sachuabraham@bitgo.com>
Consolidates stale dependabot PRs #75, #101, #111, #116, #121, #145 and #151 into one bump: eslint ^9.39.4, typescript-eslint ^8.60.1, engines.node >=20.19.0, plus transitive updates (fast-uri, brace-expansion, qs, follow-redirects, diff, sha.js). Major bumps (hardhat 3, hardhat-toolbox 7) are intentionally excluded as breaking. Rebased on master with axios 1.19.0. Ticket: SCAAS-11228 Signed-off-by: Sachu Abraham <sachuabraham@bitgo.com> Signed-off-by: Sachu Shaji Abraham <sachuabraham@bitgo.com>
|
Superseded by merged PR #152, which consolidates the non-breaking dependency updates. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps eslint from 9.10.0 to 9.39.4.
Release notes
Sourced from eslint's releases.
... (truncated)
Commits
f5770b09.39.4c30147aBuild: changelog update for 9.39.4b8b4eb1chore: update dependencies for ESLint v9.39.4 (#20596)71b2f6bchore: package.json update for@eslint/jsrelease4675152docs: add deprecation notice partial (#20520)f18f6c8fix: update dependency minimatch to ^3.1.5 (#20564)1d16c2fci: pin Node.js 25.6.1 (#20563)a3c868ffix: update dependency@eslint/eslintrcto ^3.3.4 (#20554)234d005fix: minimatch security vulnerability patch for v9.x (#20549)b1b37eefix: updateajvto6.14.0to address security vulnerabilities (#20538)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.