deps: bump eslint from 9.39.2 to 10.0.2 - #54
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [eslint](https://github.com/eslint/eslint) from 9.39.2 to 10.0.2. - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v9.39.2...v10.0.2) --- updated-dependencies: - dependency-name: eslint dependency-version: 10.0.2 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Backlog-loop verification: checks/tests green except pre-existing base failures (delta: Repo-wide red gate (claude-review) at head vs base-equivalent PRs, plus local gate numbers, head SHA 49d1a2d (parent == origin/main == ce7da5b, so the base worktree is the exact parent; head is 0 behind / 1 ahead of main). Gates (real counts, head vs base):
DEVIATIONS (conservative option taken, logged per instructions):
PINNED REF REVIEWED: agent-next/agent-ready PR #54, head dependabot/npm_and_yarn/eslint-10.0.2 @ 49d1a2d, base main (merge-base ce7da5b). PR body = dependabot "Bumps eslint 9.39.2 -> 10.0.2"; diff = package.json + package-lock.json only (+73/-285, 2 files). GROK VERDICT: REQUEST_CHANGES, one numbered finding:
I VERIFIED EVERY GROK CITATION BY EXECUTION (all correct): package.json:94 EXECUTION CORROBORATION (my additions beyond the 3 prescribed steps, inside the /tmp worktree only): SEVERITY HONESTY ADJUSTMENT (grok's framing is accurate but its blast radius is narrower than it implies): the bump is NOT CI-breaking — GH Actions '20.x' floats to >=20.19 and CI lint/test are green. The defect is an inaccurate declared support range: consumers on Node 20.0-20.18/21/23 get EBADENGINE (fatal only under engine-strict). It is also pre-existing in kind: ADDITIONAL OBSERVATION (mine, not grok's; NOT proven breaking): @eslint/js stays "^9.17.0" -> installed 9.39.2 (package-lock.json:580) while eslint core is 10.0.2; eslint 10's recommended configs ship as @eslint/js 10. Lint passes today (verified), so this is a version-consistency gap only. (unverified as to future breakage) SCOPE CREEP: none authored — only the dependabot dependency edit plus its lockfile regeneration. The lockfile-side TEST COVERAGE: devDependency-only change, no production code; repo has no test for its eslint config, and the repo's own gate ( DEVIATIONS FROM PLAN: (1) The prescribed worktree /tmp/loop-wt-agent-next_agent-ready-pr54 did not exist; per the safety contract I created it in /tmp from the fetched clean origin ref ( RECEIPTS: /tmp/loop-pr54-grok-review.txt, /tmp/loop-pr54-grok-review.err, /tmp/loop-pr54-npmci.log; worktree /tmp/loop-wt-agent-next_agent-ready-pr54 (kept at this lane's prescribed path with node_modules installed for future rounds; no other lane's worktree touched). |
Bumps eslint from 9.39.2 to 10.0.2.
Release notes
Sourced from eslint's releases.
... (truncated)
Commits
55122d610.0.280f1e29Build: changelog update for 10.0.2951223bchore: update dependency@eslint/eslintrcto ^3.3.4 (#20553)13eeedbdocs: link rule type explanation to CLI option --fix-type (#20548)6aa1afechore: update dependency eslint-plugin-jsdoc to ^62.7.0 (#20536)2b72361fix: updateajvto6.14.0to address security vulnerabilities (#20537)98cbf6bdocs: update migration guide per Program range change (#20534)61a2405docs: add missing semicolon in vars-on-top rule example (#20533)0bd549710.0.1ddb80efBuild: changelog update for 10.0.1Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)