Override typescript-eslint to v8 to drop vulnerable braces chain - #1011
Merged
Merged
Conversation
@mapbox/eslint-config-mapbox (latest 5.1.0) still pulls in typescript-eslint 7, which depends on globby -> fast-glob -> micromatch -> braces. braces has no patched release for GHSA-vfj7-8cjw-p6xm, and npm's suggested fix downgrades eslint-config-mapbox to 3.0.0. typescript-eslint 8 no longer depends on globby, so override @typescript-eslint/eslint-plugin, @typescript-eslint/parser and eslint-plugin-unused-imports (v4 supports typescript-eslint 8) until eslint-config-mapbox updates its peer ranges. Dev dependencies only. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
cclauss
approved these changes
Oct 4, 2026
Collaborator
|
Thanks for this, but I would like to update all the ESLint dependencies if you can help with that too. |
Contributor
Author
|
I can look at it. I have two more PRs with fixes I made in my fork to fix the vulnerabilities which i will try to submit first |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the 13 high-severity
npm auditfindings from the braces chain (GHSA-vfj7-8cjw-p6xm). Dev dependencies only; nothing shipped to users changes.@mapbox/eslint-config-mapbox (including the latest 5.1.0) still pulls in typescript-eslint 7, which depends on globby → fast-glob → micromatch → braces. braces has no patched release, and
npm audit fix --forcewould downgrade eslint-config-mapbox to 3.0.0.typescript-eslint 8 no longer depends on globby, so this adds
overridesfor@typescript-eslint/eslint-plugin,@typescript-eslint/parser(^8) andeslint-plugin-unused-imports(^4, which supports typescript-eslint 8). They can be removed once eslint-config-mapbox widens its peer ranges.npm audit: 16 → 5 vulnerabilities (remaining: underscore via mock-aws-s3, uuid via nyc 17)npm run lintpasses, and the config still flags violations as before