Skip to content

Override typescript-eslint to v8 to drop vulnerable braces chain - #1011

Merged
cclauss merged 1 commit into
mapbox:masterfrom
acalcutt:mapbox-fix-typescript-eslint-8
Oct 4, 2026
Merged

cclauss merged 1 commit into
mapbox:masterfrom
acalcutt:mapbox-fix-typescript-eslint-8

Conversation

@acalcutt

@acalcutt acalcutt commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Fixes the 13 high-severity npm audit findings from the braces chain (GHSA-vfj7-8cjw-p6xm). Dev dependencies only; nothing shipped to users changes.

@mapbox/eslint-config-mapbox (including the latest 5.1.0) still pulls in typescript-eslint 7, which depends on globby → fast-glob → micromatch → braces. braces has no patched release, and npm audit fix --force would downgrade eslint-config-mapbox to 3.0.0.

typescript-eslint 8 no longer depends on globby, so this adds overrides for @typescript-eslint/eslint-plugin, @typescript-eslint/parser (^8) and eslint-plugin-unused-imports (^4, which supports typescript-eslint 8). They can be removed once eslint-config-mapbox widens its peer ranges.

  • npm audit: 16 → 5 vulnerabilities (remaining: underscore via mock-aws-s3, uuid via nyc 17)
  • npm run lint passes, and the config still flags violations as before

@mapbox/eslint-config-mapbox (latest 5.1.0) still pulls in
typescript-eslint 7, which depends on globby -> fast-glob -> micromatch
-> braces. braces has no patched release for GHSA-vfj7-8cjw-p6xm, and
npm's suggested fix downgrades eslint-config-mapbox to 3.0.0.

typescript-eslint 8 no longer depends on globby, so override
@typescript-eslint/eslint-plugin, @typescript-eslint/parser and
eslint-plugin-unused-imports (v4 supports typescript-eslint 8) until
eslint-config-mapbox updates its peer ranges. Dev dependencies only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@acalcutt
acalcutt requested a review from a team as a code owner October 4, 2026 15:46
@cclauss
cclauss merged commit 30e4761 into mapbox:master Oct 4, 2026
30 checks passed
@cclauss

cclauss commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

Thanks for this, but I would like to update all the ESLint dependencies if you can help with that too.

@acalcutt

acalcutt commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

I can look at it. I have two more PRs with fixes I made in my fork to fix the vulnerabilities which i will try to submit first

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants