Skip to content

deps: bump eslint from 9.39.2 to 10.0.2 - #54

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/eslint-10.0.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/eslint-10.0.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 2, 2026

Copy link
Copy Markdown
Contributor

Bumps eslint from 9.39.2 to 10.0.2.

Release notes

Sourced from eslint's releases.

v10.0.2

Bug Fixes

  • 2b72361 fix: update ajv to 6.14.0 to address security vulnerabilities (#20537) (루밀LuMir)

Documentation

  • 13eeedb docs: link rule type explanation to CLI option --fix-type (#20548) (Mike McCready)
  • 98cbf6b docs: update migration guide per Program range change (#20534) (Huáng Jùnliàng)
  • 61a2405 docs: add missing semicolon in vars-on-top rule example (#20533) (Abilash)

Chores

  • 951223b chore: update dependency @​eslint/eslintrc to ^3.3.4 (#20553) (renovate[bot])
  • 6aa1afe chore: update dependency eslint-plugin-jsdoc to ^62.7.0 (#20536) (Milos Djermanovic)

v10.0.1

Bug Fixes

  • c87d5bd fix: update eslint (#20531) (renovate[bot])
  • d841001 fix: update minimatch to 10.2.1 to address security vulnerabilities (#20519) (루밀LuMir)
  • 04c2147 fix: update error message for unused suppressions (#20496) (fnx)
  • 38b089c fix: update dependency @​eslint/config-array to ^0.23.1 (#20484) (renovate[bot])

Documentation

  • 5b3dbce docs: add AI acknowledgement section to templates (#20431) (루밀LuMir)
  • 6f23076 docs: toggle nav in no-JS mode (#20476) (Tanuj Kanti)
  • b69cfb3 docs: Update README (GitHub Actions Bot)

Chores

  • e5c281f chore: updates for v9.39.3 release (Jenkins)
  • 8c3832a chore: update @​typescript-eslint/parser to ^8.56.0 (#20514) (Milos Djermanovic)
  • 8330d23 test: add tests for config-api (#20493) (Milos Djermanovic)
  • 37d6e91 chore: remove eslint v10 prereleases from eslint-config-eslint deps (#20494) (Milos Djermanovic)
  • da7cd0e refactor: cleanup error message templates (#20479) (Francesco Trotta)
  • 84fb885 chore: package.json update for @​eslint/js release (Jenkins)
  • 1f66734 chore: add eslint to peerDependencies of @eslint/js (#20467) (Milos Djermanovic)

v10.0.0

Breaking Changes

  • f9e54f4 feat!: estimate rule-tester failure location (#20420) (ST-DDT)
  • a176319 feat!: replace chalk with styleText and add color to ResultsMeta (#20227) (루밀LuMir)
  • c7046e6 feat!: enable JSX reference tracking (#20152) (Pixel998)
  • fa31a60 feat!: add name to configs (#20015) (Kirk Waiblinger)
  • 3383e7e fix!: remove deprecated SourceCode methods (#20137) (Pixel998)
  • 501abd0 feat!: update dependency minimatch to v10 (#20246) (renovate[bot])
  • ca4d3b4 fix!: stricter rule tester assertions for valid test cases (#20125) (唯然)
  • 96512a6 fix!: Remove deprecated rule context methods (#20086) (Nicholas C. Zakas)
  • c69fdac feat!: remove eslintrc support (#20037) (Francesco Trotta)
  • 208b5cc feat!: Use ScopeManager#addGlobals() (#20132) (Milos Djermanovic)
  • a2ee188 fix!: add uniqueItems: true in no-invalid-regexp option (#20155) (Tanuj Kanti)
  • a89059d feat!: Program range span entire source text (#20133) (Pixel998)
  • 39a6424 fix!: assert 'text' is a string across all RuleFixer methods (#20082) (Pixel998)
  • f28fbf8 fix!: Deprecate "always" and "as-needed" options of the radix rule (#20223) (Milos Djermanovic)

... (truncated)

Commits
  • 55122d6 10.0.2
  • 80f1e29 Build: changelog update for 10.0.2
  • 951223b chore: update dependency @​eslint/eslintrc to ^3.3.4 (#20553)
  • 13eeedb docs: link rule type explanation to CLI option --fix-type (#20548)
  • 6aa1afe chore: update dependency eslint-plugin-jsdoc to ^62.7.0 (#20536)
  • 2b72361 fix: update ajv to 6.14.0 to address security vulnerabilities (#20537)
  • 98cbf6b docs: update migration guide per Program range change (#20534)
  • 61a2405 docs: add missing semicolon in vars-on-top rule example (#20533)
  • 0bd5497 10.0.1
  • ddb80ef Build: changelog update for 10.0.1
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [eslint](https://github.com/eslint/eslint) from 9.39.2 to 10.0.2.
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v9.39.2...v10.0.2)

---
updated-dependencies:
- dependency-name: eslint
  dependency-version: 10.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Mar 2, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@robotlearning123

Copy link
Copy Markdown
Member

Backlog-loop verification: checks/tests green except pre-existing base failures (delta: Repo-wide red gate (claude-review) at head vs base-equivalent PRs, plus local gate numbers, head SHA 49d1a2d (parent == origin/main == ce7da5b, so the base worktree is the exact parent; head is 0 behind / 1 ahead of main).

Gates (real counts, head vs base):

  • GitHub checks on head SHA 49d1a2d: 8 success / 1 failure (claude-review). Local reproduction of the same gates at head: npm ci exit 0 (311 packages); eslint v10.0.2 lint exit 0, 0 errors / 1 warning over 25 files; format:check exit 0; typecheck exit 0; tests 57 pass / 0 fail; build exit 0 (dist/index.js produced).
  • Base ref ce7da5b (eslint v9.39.2): npm ci exit 0 (326 packages); lint exit 0, 0 errors / 1 warning (same warning); format:check exit 0; typecheck exit 0; tests 57 pass / 0 fail; build exit 0.
  • Delta = 0 regressions: identical lint warning count, identical 57/57 test results, identical exit codes; the dependency-tree shrink 326 -> 311 packages is the expected eslintrc-tree removal in eslint 10.
  • npm audit: identical both refs, total 19 (0 critical / 10 high / 8 moderate / 1 low) — bump is not worse, also not a net reduction.
  • claude-review has no literal base-ref run by construction (workflow triggers on pull_request only, no push-to-main); base-equivalent = same workflow on other PRs against main, which fail identically (2026-09-23 runs 35806774022, 35807151350) => pre-existing, content-independent, PR not worse.

DEVIATIONS (conservative option taken, logged per instructions):

  1. claude-review could not be executed locally (GitHub-Actions-only action + CLAUDE_CODE_OAUTH_TOKEN secret); substituted with the base-equivalent evidence above instead of claiming a literal base-ref rerun.
  2. PR 54's own claude-review run log is expired (gh run view --log-failed returns HTTP 410), so the failure signature was read from a same-workflow run on 2026-09-23 (35806774022) that shows the identical error text.
  3. Node 20.x lane not reproducible locally (only Node v22.22.0 installed, no nvm node versions); the Node 20.x result rests on the CI check-run conclusion (success) on the exact head SHA, labeled as such rather than locally reproduced. Local runs cover the Node 22.x lane.
  4. No PR comment posted and no repo mutation performed: review-only verdict returned to orchestrator; main working tree confirmed clean at 8373df4 before and after.). Independent review: REQUEST_CHANGES.
    INDEPENDENT REVIEW OBTAINED (writer=devin/deepseek-branch, reviewer=grok, writer != reviewer). Grok 1.0.41 headless, exit 0, full output at /tmp/loop-pr54-grok-review.txt (1198 bytes); stderr /tmp/loop-pr54-grok-review.err (only "Memory flush started.").

PINNED REF REVIEWED: agent-next/agent-ready PR #54, head dependabot/npm_and_yarn/eslint-10.0.2 @ 49d1a2d, base main (merge-base ce7da5b). PR body = dependabot "Bumps eslint 9.39.2 -> 10.0.2"; diff = package.json + package-lock.json only (+73/-285, 2 files).

GROK VERDICT: REQUEST_CHANGES, one numbered finding:

  1. package.json:94 — eslint 10.0.2 drops Node <20.19, 21, 23 (package-lock.json:1960 "node": "^20.19.0 || ^22.13.0 || >=24"), but engines.node stays >=20.0.0 (lockfile root engines at package-lock.json:41). Gates that run eslint: package.json:40 check and package.json:42 prepublishOnly; no engine-strict setting. CI lint only passed on floating 20.x (.github/workflows/ci.yml:23); test matrix 20.x/22.x (:59); npm test (package.json:32) never runs eslint — so green CI does not cover 20.0-20.18, 21, 22.0-22.12, 23. Fix: raise engines.node to the eslint 10 floor and pin CI inside it, or keep eslint 9.

I VERIFIED EVERY GROK CITATION BY EXECUTION (all correct): package.json:94 "node": ">=20.0.0"; package-lock.json:1960 engines of node_modules/eslint@10.0.2 (version at :1919); package-lock.json:41 root engines; package.json:40 check script / :42 prepublishOnly; no .npmrc and no engine-strict key (checked); ci.yml:23 '20.x' and :59 ['20.x','22.x'].

EXECUTION CORROBORATION (my additions beyond the 3 prescribed steps, inside the /tmp worktree only): npm ci exit 0 (lockfile in sync, NPMCI_EXIT=0, log /tmp/loop-pr54-npmci.log); ./node_modules/.bin/eslint --version = v10.0.2; npm run check exit 0 — 0 errors, 1 warning at test/e2e/cli.e2e.test.ts:21 (FIXTURES_DIR unused, file NOT touched by this PR); npm test exit 0 — 57 pass / 0 fail / 0 skipped. PR CI (gh pr checks 54): Build, Check Repository, Lint & Format, Scan Agent Readiness, Test (Node 20.x), Test (Node 22.x), Type Check, Validate PR all PASS; only claude-review FAILS (known repo-wide, baseline-delta rule per repo notes).

SEVERITY HONESTY ADJUSTMENT (grok's framing is accurate but its blast radius is narrower than it implies): the bump is NOT CI-breaking — GH Actions '20.x' floats to >=20.19 and CI lint/test are green. The defect is an inaccurate declared support range: consumers on Node 20.0-20.18/21/23 get EBADENGINE (fatal only under engine-strict). It is also pre-existing in kind: git show origin/main:package.json gives engines ">=20.0.0" while eslint 9.39.2 required ^20.9.0+, so this PR narrows the true floor (20.19+) and drops 21/23 without updating the declaration — aggravated, not newly introduced.

ADDITIONAL OBSERVATION (mine, not grok's; NOT proven breaking): @eslint/js stays "^9.17.0" -> installed 9.39.2 (package-lock.json:580) while eslint core is 10.0.2; eslint 10's recommended configs ship as @eslint/js 10. Lint passes today (verified), so this is a version-consistency gap only. (unverified as to future breakage)

SCOPE CREEP: none authored — only the dependabot dependency edit plus its lockfile regeneration. The lockfile-side version: 0.1.0 -> 0.2.0 edits are dependabot's install fixing pre-existing drift (origin/main package.json:3 = 0.2.0 vs origin/main package-lock.json:3 = 0.1.0), a mechanical side effect, not human scope expansion.

TEST COVERAGE: devDependency-only change, no production code; repo has no test for its eslint config, and the repo's own gate (npm run check) plus 57 tests pass. Coverage adequate for this diff.

DEVIATIONS FROM PLAN: (1) The prescribed worktree /tmp/loop-wt-agent-next_agent-ready-pr54 did not exist; per the safety contract I created it in /tmp from the fetched clean origin ref (git fetch origin --prune then git worktree add --detach /tmp/loop-wt-agent-next_agent-ready-pr54 49d1a2dc...), leaving the main working tree untouched (it was clean: git status --porcelain empty). (2) The step-2 prompt's head placeholder "PR-head" was replaced by the real head branch + pinned SHA in the command as run. (3) Added the npm ci/check/test execution verification above; no PR comment posted, no approve, no merge, no branch/PR mutation of any kind.

RECEIPTS: /tmp/loop-pr54-grok-review.txt, /tmp/loop-pr54-grok-review.err, /tmp/loop-pr54-npmci.log; worktree /tmp/loop-wt-agent-next_agent-ready-pr54 (kept at this lane's prescribed path with node_modules installed for future rounds; no other lane's worktree touched).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant