Bump typescript-eslint from 8.65.0 to 8.67.0 - #285
Conversation
Bumps [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) from 8.65.0 to 8.67.0. - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.67.0/packages/typescript-eslint) --- updated-dependencies: - dependency-name: typescript-eslint dependency-version: 8.67.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
Strix is installed on this repository, but we couldn't run this PR security review because this workspace's trial has ended. Add a card to resume code reviews here. So far, Strix has reviewed 28 pull requests, surfaced 3 security issues (1 critical/high) and blocked 2 risky merges across this workspace. |
… CI installs Five npm dev-dependency upgrades, applied together and verified as ONE state: eslint 10.8.0 -> 10.8.1, globals 17.7 -> 17.11, happy-dom 20.8.9 -> 20.11.2, typescript-eslint 8.65 -> 8.67, vite 8.1.5 -> 8.2.1 (dependabot #278 #280 #283 #285 #287). Applied in one commit rather than merged one by one because all five rewrite package-lock.json and would have conflicted pairwise. DEPENDABOT COULD NOT SEE THE WHOLE PICTURE. The ROOT workspace declares vite, eslint and happy-dom too; dependabot only opened PRs against apps/web. So merging them as-is would have changed less than they claimed: * eslint would have stayed on the root's 10.8.0 - hoisted, so the apps/web bump was a NO-OP for linting, the very tool the bump exists to update; * vite would have been installed TWICE - root's exact 8.1.5 against web's exact 8.2.1, forcing a nested second copy. Both roots are aligned; all five now resolve to single hoisted copies at the intended versions, confirmed by reading node_modules rather than the manifest. There is also an `overrides` block pinning eslint repo-wide that dependabot never touches. The first edit landed on IT instead of the devDependency - the same key lives in both sections and a count-limited replace takes whichever comes first. npm rejected it loudly (EOVERRIDE), which is the good case. Both now read 10.8.1 and are asserted equal. toolchainDocs.test.ts then caught the third thing: docs/engineering/web-standards.md still said "eslint 10.8.0". A governed doc whose versions are asserted against the manifest - and whose own comment records that both versions there were wrong for weeks once before. THE SEVEN PYTHON PRs ARE NOT MERGED HERE, deliberately. CI installs from services/api/requirements.lock with --require-hashes, NOT requirements.txt, and those PRs only raise >= floors: * #289 manifold3d, #286 fastapi, #282 shapely, #284 bandit - the lock already pins versions satisfying the new floors; safe, purely making the declaration honest. * #277 numpy, #281 trimesh, #288 boto3 - raise the floor ABOVE what the lock pins (2.5.1, 4.12.2, 1.43.46). test_lock_satisfies_requirements.py guards exactly this and was mutation-tested by simulating #281. Merging without a lock regeneration reds main - and CI would still install the old versions, so a green run would prove nothing about trimesh 5. Web typecheck + lint clean, 1651/1651, build OK. Backend 608/608 (the one failure in the first run was test_changelog_current doing its job: version bumped before this entry existed). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
Superseded by 675c129 (v0.3.984), which applies this bump together with the other four npm dev-dependency upgrades in one verified state. Applied there rather than merged here for two reasons worth recording:
Verified on the upgraded toolchain: typecheck + lint clean, 1651/1651 web tests, build OK, backend 608/608. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps typescript-eslint from 8.65.0 to 8.67.0.
Release notes
Sourced from typescript-eslint's releases.
Changelog
Sourced from typescript-eslint's changelog.
Commits
20a261fchore(release): publish 8.67.0c245fbbfeat(typescript-eslint): export basic globs for using tseslint (#12105)3b155bbchore: use typescript 7 for typechecking (#12601)e51b11bchore(release): publish 8.66.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)