Skip to content

chore(deps-dev): bump @eslint/js from 9.39.5 to 10.0.1 in /web - #11

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/web/eslint/js-10.0.1
Open

chore(deps-dev): bump @eslint/js from 9.39.5 to 10.0.1 in /web#11
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/web/eslint/js-10.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 23, 2026

Copy link
Copy Markdown
Contributor

Bumps @eslint/js from 9.39.5 to 10.0.1.

Release notes

Sourced from @​eslint/js's releases.

v10.0.1

Bug Fixes

  • c87d5bd fix: update eslint (#20531) (renovate[bot])
  • d841001 fix: update minimatch to 10.2.1 to address security vulnerabilities (#20519) (루밀LuMir)
  • 04c2147 fix: update error message for unused suppressions (#20496) (fnx)
  • 38b089c fix: update dependency @​eslint/config-array to ^0.23.1 (#20484) (renovate[bot])

Documentation

  • 5b3dbce docs: add AI acknowledgement section to templates (#20431) (루밀LuMir)
  • 6f23076 docs: toggle nav in no-JS mode (#20476) (Tanuj Kanti)
  • b69cfb3 docs: Update README (GitHub Actions Bot)

Chores

  • e5c281f chore: updates for v9.39.3 release (Jenkins)
  • 8c3832a chore: update @​typescript-eslint/parser to ^8.56.0 (#20514) (Milos Djermanovic)
  • 8330d23 test: add tests for config-api (#20493) (Milos Djermanovic)
  • 37d6e91 chore: remove eslint v10 prereleases from eslint-config-eslint deps (#20494) (Milos Djermanovic)
  • da7cd0e refactor: cleanup error message templates (#20479) (Francesco Trotta)
  • 84fb885 chore: package.json update for @​eslint/js release (Jenkins)
  • 1f66734 chore: add eslint to peerDependencies of @eslint/js (#20467) (Milos Djermanovic)

v10.0.0

Breaking Changes

  • f9e54f4 feat!: estimate rule-tester failure location (#20420) (ST-DDT)
  • a176319 feat!: replace chalk with styleText and add color to ResultsMeta (#20227) (루밀LuMir)
  • c7046e6 feat!: enable JSX reference tracking (#20152) (Pixel998)
  • fa31a60 feat!: add name to configs (#20015) (Kirk Waiblinger)
  • 3383e7e fix!: remove deprecated SourceCode methods (#20137) (Pixel998)
  • 501abd0 feat!: update dependency minimatch to v10 (#20246) (renovate[bot])
  • ca4d3b4 fix!: stricter rule tester assertions for valid test cases (#20125) (唯然)
  • 96512a6 fix!: Remove deprecated rule context methods (#20086) (Nicholas C. Zakas)
  • c69fdac feat!: remove eslintrc support (#20037) (Francesco Trotta)
  • 208b5cc feat!: Use ScopeManager#addGlobals() (#20132) (Milos Djermanovic)
  • a2ee188 fix!: add uniqueItems: true in no-invalid-regexp option (#20155) (Tanuj Kanti)
  • a89059d feat!: Program range span entire source text (#20133) (Pixel998)
  • 39a6424 fix!: assert 'text' is a string across all RuleFixer methods (#20082) (Pixel998)
  • f28fbf8 fix!: Deprecate "always" and "as-needed" options of the radix rule (#20223) (Milos Djermanovic)
  • aa3fb2b fix!: tighten func-names schema (#20119) (Pixel998)
  • f6c0ed0 feat!: report eslint-env comments as errors (#20128) (Francesco Trotta)
  • 4bf739f fix!: remove deprecated LintMessage#nodeType and TestCaseError#type (#20096) (Pixel998)
  • 523c076 feat!: drop support for jiti < 2.2.0 (#20016) (michael faith)
  • 454a292 feat!: update eslint:recommended configuration (#20210) (Pixel998)
  • 4f880ee feat!: remove v10_* and inactive unstable_* flags (#20225) (sethamus)
  • f18115c feat!: no-shadow-restricted-names report globalThis by default (#20027) (sethamus)
  • c6358c3 feat!: Require Node.js ^20.19.0 || ^22.13.0 || >=24 (#20160) (Milos Djermanovic)

Features

  • bff9091 feat: handle Array.fromAsync in array-callback-return (#20457) (Francesco Trotta)
  • 290c594 feat: add self to no-implied-eval rule (#20468) (sethamus)
  • 43677de feat: fix handling of function and class expression names in no-shadow (#20432) (Milos Djermanovic)

... (truncated)

Commits
  • 84fb885 chore: package.json update for @​eslint/js release
  • 1f66734 chore: add eslint to peerDependencies of @eslint/js (#20467)
  • f3fbc2f chore: set @eslint/js version to 10.0.0 to skip releasing it (#20466)
  • b4b3127 chore: package.json update for @​eslint/js release
  • 0b14059 chore: package.json update for @​eslint/js release
  • fa31a60 feat!: add name to configs (#20015)
  • 1e2cad5 chore: package.json update for @​eslint/js release
  • 454a292 feat!: update eslint:recommended configuration (#20210)
  • c6358c3 feat!: Require Node.js ^20.19.0 || ^22.13.0 || >=24 (#20160)
  • See full diff in compare view

@dependabot @github

dependabot Bot commented on behalf of github Aug 23, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, javascript. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/web/eslint/js-10.0.1 branch from 32c3449 to 0c123f1 Compare August 24, 2026 08:25
@piotrlaczkowski
piotrlaczkowski force-pushed the main branch 2 times, most recently from a85446a to 1d710eb Compare August 24, 2026 09:52
piotrlaczkowski added a commit that referenced this pull request Aug 27, 2026
…#22)

* build(deps): React 19, Vite 8, Vitest 4, and the GitHub Actions majors

Closes the dependabot backlog in one sweep rather than 17 sequential
rebase-and-merge cycles: every one of those PRs touches package.json or
package-lock.json, so each merge conflicts the next and the queue can only
drain one CI round at a time.

── GitHub Actions (7 PRs) ────────────────────────────────────────────────────

checkout 4→7, setup-go 5→7, setup-node 4→7, setup-python 5→7, deploy-pages 4→5,
upload-pages-artifact 3→5, action-gh-release 2→3. Mechanical; the v4/v5 majors
were also emitting Node 20 deprecation warnings on every run.

── Web (7 of 10 PRs) ─────────────────────────────────────────────────────────

react + react-dom 18.3.1→19.2.8, @types/react 19, @dnd-kit/sortable 8→10
(with core →6.3.0 for its peer), vite 5→8, @vitejs/plugin-react 4→6,
vitest + @vitest/coverage-v8 2→4, globals 15→17, eslint-plugin-react-hooks 5→7,
typescript-eslint →8.68.0.

Three things had to change for these to work:

  • React 19 types. `useRef<T>(null)` now yields `RefObject<T | null>` rather
    than `RefObject<T>` — the honest type, since a ref genuinely is null until
    its element mounts. Fixed at the three declaration sites (useStickToBottom's
    return, Modal's initialFocusRef, HITLPopup's firstActionRef) rather than
    cast away at the ~10 use sites.

  • Vite 8 builds on rolldown, which accepts `manualChunks` only as a callback
    and fails the build outright on the object form. Same three vendor chunks
    (react / dnd / icons), matched on module id.

  • `__dirname` in the vite and vitest configs, which Vite 8's native config
    loader warns about. Now `import.meta.dirname`.

── The new React Compiler lint rules are OFF, deliberately ──────────────────

eslint-plugin-react-hooks v7 enables a family of rules derived from the React
Compiler. They flag 42 EXISTING patterns across Studio — not regressions, just
constructs the compiler cannot prove safe to memoize, setState-inside-an-effect
being most of them.

They are off rather than warnings because a warning nobody can act on 42 times
is noise that trains people to ignore the whole report. Adopting them is a real
refactor of state flow across the app and deserves its own review, not a
silent rewrite of every effect riding along in a version bump.

rules-of-hooks and exhaustive-deps — the two that caught real shipped bugs —
stay errors. The gate is not weakened by one rule: eslint still reports
0 errors and the same 50 pre-existing warnings it did before.

── Three PRs are NOT adoptable, and the blocker is upstream ─────────────────

  typescript 5.9.3 → 7.0.2 (#17)
    typescript-eslint caps TypeScript at <6.1.0 — including its own 8.68.1
    alphas. Taking TS 7 means deleting TypeScript linting from the project.

  eslint 9.39.5 → 10.8.1 (#19) and @eslint/js → 10.0.1 (#11)
    eslint-plugin-jsx-a11y's newest release (6.10.2) peers eslint ^3..^9 only.
    No ESLint 10 support has shipped.

Forcing either with --legacy-peer-deps produces a tree whose linting is
silently broken, which is worse than staying on the current major. They stay
open until the ecosystem catches up.

Verified: tsc clean, eslint 0 errors, 79/79 vitest, vite build green, Go build
+ lint at the zero baseline + full suite clean, and Studio exercised in a
browser under React 19 — SSE connected, all chunks and API calls 200, the
composition preview and phase rail rendering correctly.

* ci: run Node 22, which the new web toolchain requires

Vitest 4 pulls a jsdom whose undici calls `webidl.util.markAsUncloneable`,
added in Node 22.10. On CI's Node 20 that is a TypeError thrown while merely
IMPORTING jsdom, so every test file failed to start — 9 unhandled errors and
'no tests' rather than a test failure.

Two jobs disagreed about this and the disagreement hid it: Web Frontend Check
only runs tsc and the build, so it passed; Lint & Test and Pre-commit run
`make check`, which runs vitest, and both failed. A green check on the job
named after the frontend was reporting on half of it.

`engines: node >=22.10` in web/package.json makes the floor explicit, so a
mismatch fails at install time with a readable message instead of at test time
with a TypeError from inside a transitive dependency. Docs updated from the
stale 'Node 18+' to match.
@piotrlaczkowski

Copy link
Copy Markdown
Contributor

Blocked upstream — not mergeable today.

eslint-plugin-jsx-a11y has no ESLint 10 support; its newest release peers ESLint 9 at most:

$ npm view eslint-plugin-jsx-a11y version peerDependencies
6.10.2  { eslint: '^3 || ^4 || ^5 || ^6 || ^7 || ^8 || ^9' }

Forcing it with --legacy-peer-deps would leave the a11y rules silently not running, which is worse than staying on ESLint 9.

Leaving this open until jsx-a11y ships ESLint 10 support. Note that #13 (eslint-plugin-react-hooks 7) did land in #22 — it supports both majors.

Bumps [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js) from 9.39.5 to 10.0.1.
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](https://github.com/eslint/eslint/commits/v10.0.1/packages/js)

---
updated-dependencies:
- dependency-name: "@eslint/js"
  dependency-version: 10.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps-dev): bump @eslint/js from 9.39.5 to 10.0.1 in /web chore(deps-dev): bump @eslint/js from 9.39.5 to 10.0.1 in /web Aug 27, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/web/eslint/js-10.0.1 branch from 0c123f1 to 553a972 Compare August 27, 2026 17:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant