-
-
Couldn't load subscription status.
- Fork 0
[Snyk] Upgrade @typescript-eslint/parser from 5.9.0 to 5.62.0 #6
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -5,7 +5,7 @@ | |
| "main": "action.js", | ||
| "dependencies": { | ||
| "@typescript-eslint/eslint-plugin": "^5.9.0", | ||
| "@typescript-eslint/parser": "^5.9.0", | ||
| "@typescript-eslint/parser": "^5.62.0", | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🛑 Missing Lock File Update: This PR only updates package.json but doesn't include the corresponding pnpm-lock.yaml update. After making the dependency changes, you must run There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. The version jump from 5.9.0 to 5.62.0 spans over 50 minor releases and includes significant changes. While this addresses security vulnerabilities, it's worth noting that this large version jump may introduce breaking changes or behavioral differences in ESLint rules and parsing. Consider testing thoroughly with your existing TypeScript codebase. |
||
| "eslint": "^8.6.0", | ||
| "typescript": "^4.5.4" | ||
| }, | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Consider updating ESLint to a more recent version. ESLint 8.6.0 is quite old (from January 2022), and newer versions include important security fixes, performance improvements, and better TypeScript support. The latest ESLint 8.x versions are compatible with the updated TypeScript ESLint packages. |
||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This dependency update creates a version mismatch between
@typescript-eslint/parser(5.62.0) and@typescript-eslint/eslint-plugin(5.9.0). The TypeScript ESLint packages are designed to work together and should be kept at the same major.minor version to ensure compatibility and avoid potential parsing or rule conflicts.