Skip to content

build(deps-dev): bump the npm-dependencies group across 1 directory with 10 updates - #106

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-dependencies-dd348e016a
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-dependencies-dd348e016a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm-dependencies group with 10 updates in the / directory:

Package From To
@commitlint/cli 21.2.2 21.2.3
@commitlint/config-conventional 21.2.2 21.2.3
@exadev/eslint-config 2.12.3 2.23.0
@types/node 26.4.1 26.6.3
eslint 10.9.1 10.11.0
lint-staged 17.4.1 17.6.0
prettier 3.9.6 3.9.9
turbo 2.10.12 2.11.5
typescript 6.0.3 7.0.2
typescript-eslint 8.69.0 8.70.1

Updates @commitlint/cli from 21.2.2 to 21.2.3

Release notes

Sourced from @​commitlint/cli's releases.

v21.2.3

21.2.3 (2026-09-19)

Bug Fixes

Refactor

Chore, ci, build, etc.

New Contributors

Full Changelog: conventional-changelog/commitlint@v21.2.2...v21.2.3

Changelog

Sourced from @​commitlint/cli's changelog.

21.2.3 (2026-09-19)

Bug Fixes

  • lint: trim trailing whitespace off the message handed to ignore matchers (#4960) (a6f279b)
Commits
  • 95d4056 v21.2.3
  • a6f279b fix(lint): trim trailing whitespace off the message handed to ignore matchers...
  • See full diff in compare view

Updates @commitlint/config-conventional from 21.2.2 to 21.2.3

Release notes

Sourced from @​commitlint/config-conventional's releases.

v21.2.3

21.2.3 (2026-09-19)

Bug Fixes

Refactor

Chore, ci, build, etc.

New Contributors

Full Changelog: conventional-changelog/commitlint@v21.2.2...v21.2.3

Changelog

Sourced from @​commitlint/config-conventional's changelog.

21.2.3 (2026-09-19)

Bug Fixes

  • rules: report the case that matched in case rule failure messages (#4962) (9f5f7bc)
Commits

Updates @exadev/eslint-config from 2.12.3 to 2.23.0

Release notes

Sourced from @​exadev/eslint-config's releases.

v2.23.0

2.23.0 (2026-09-28)

Bug Fixes

  • exempt a /*! license or banner block from both comment rules (7758fa8)
  • prefer-doc-comment: correct the PropertyDefinition null-guard comment (8b051f6)
  • prefer-doc-comment: cover a genuinely ambient function signature (b53de1d)
  • prefer-doc-comment: drop the redundant isLineRun guard in directiveIndex (9feebbb)
  • prefer-doc-comment: exempt overload implementation signatures (96d8edb)
  • prefer-doc-comment: judge the segment adjacent to the anchor, not the first directive (335f2be), closes #region
  • prefer-doc-comment: match ESLint's own directive rules exactly (2b76c29)
  • prefer-doc-comment: never merge a directive line into the fixed doc comment (e82af51)
  • prefer-doc-comment: never merge a directive line into the fixed doc comment (6f0373b)
  • prefer-doc-comment: preserve comment indentation and unwrap starred blocks (3cb5088)
  • prefer-doc-comment: read the CRLF terminator from real source, not a rewritten comment (1d03f9e)
  • prefer-doc-comment: recognise #region/#endregion editor folding markers (b620e04), closes region/#endregion #region #endregion
  • prefer-doc-comment: recognise a real @-prefixed TypeScript directive (bc6ad31)
  • prefer-doc-comment: recognise directives despite extra leading whitespace (f198f72)
  • prefer-doc-comment: recognise eslint-enable in the directive pattern (b6e9cae)
  • prefer-doc-comment: recognise node:coverage, cspell and biome-ignore directives (d2da2be)
  • prefer-doc-comment: recognise prettier-ignore and coverage-tool ignore directives (d43028b)
  • prefer-doc-comment: report a multi-declarator export exactly once (87c71e0)
  • prefer-doc-comment: require ordering and static-match for a method's own overload signature (cfa3fb0)
  • prefer-doc-comment: require the export wrapper to reach the public surface (df97ee9)
  • prefer-doc-comment: restrict the VariableDeclaration check to export const (0dd0e84)
  • prefer-doc-comment: stop absorbing a trailing comment into the next leading group (a081eae)
  • prefer-doc-comment: stop folding triple-slash directives into doc comments (1074346)
  • prefer-doc-comment: stop the fixer splicing real text into every line as indent (bf9185c)
  • prefer-doc-comment: take the fixer's line break from the source (a4e4bb9)
  • prefer-doc-comment: validate the unsafe-content gate against real TSDoc (cce1303)
  • prefer-doc-comment: withhold autofix for any TSDoc tag line, not just a blank line before one (b97fb2c)
  • prefer-doc-comment: withhold autofix when a line would collide with jsdoc/no-multi-asterisks (36561e9)
  • prefer-doc-comment: withhold autofix when a line would collide with jsdoc/tag-lines (0c86926)
  • release: arm the deploy-key push by persisting checkout credentials (456c22f)
  • satisfy prefer-doc-comment across the repo's own source (0c4a288)
  • stylistic-comments: exempt cspell:disable-line from line-comment-position (5983a46)
  • stylistic-comments: stop enabling multiline-comment-style (1b4e5bd)
  • stylistic-comments: stop forcing a blank line between consecutive imports and directives (674bfe6)
  • stylistic-comments: stop multiline-comment-style breaking triple-slash directives (0b7d45b), closes eslint-stylistic/eslint-stylistic#1285
  • stylistic-comments: stop spaced-comment breaking source-map and #region markers (a511051), closes #region region/#endregion

Features

  • add prefer-doc-comment rule (aa3d937)
  • deps: add @​stylistic/eslint-plugin (37e38de)
  • prefer-doc-comment: cover exported enums, namespaces, value consts, default expressions (3f658d5)
  • prefer-doc-comment: cover public abstract methods and function-valued class properties (349d96a)

... (truncated)

Changelog

Sourced from @​exadev/eslint-config's changelog.

2.23.0 (2026-09-28)

Bug Fixes

  • exempt a /*! license or banner block from both comment rules (7758fa8)
  • prefer-doc-comment: correct the PropertyDefinition null-guard comment (8b051f6)
  • prefer-doc-comment: cover a genuinely ambient function signature (b53de1d)
  • prefer-doc-comment: drop the redundant isLineRun guard in directiveIndex (9feebbb)
  • prefer-doc-comment: exempt overload implementation signatures (96d8edb)
  • prefer-doc-comment: judge the segment adjacent to the anchor, not the first directive (335f2be), closes #region
  • prefer-doc-comment: match ESLint's own directive rules exactly (2b76c29)
  • prefer-doc-comment: never merge a directive line into the fixed doc comment (e82af51)
  • prefer-doc-comment: never merge a directive line into the fixed doc comment (6f0373b)
  • prefer-doc-comment: preserve comment indentation and unwrap starred blocks (3cb5088)
  • prefer-doc-comment: read the CRLF terminator from real source, not a rewritten comment (1d03f9e)
  • prefer-doc-comment: recognise #region/#endregion editor folding markers (b620e04), closes region/#endregion #region #endregion
  • prefer-doc-comment: recognise a real @-prefixed TypeScript directive (bc6ad31)
  • prefer-doc-comment: recognise directives despite extra leading whitespace (f198f72)
  • prefer-doc-comment: recognise eslint-enable in the directive pattern (b6e9cae)
  • prefer-doc-comment: recognise node:coverage, cspell and biome-ignore directives (d2da2be)
  • prefer-doc-comment: recognise prettier-ignore and coverage-tool ignore directives (d43028b)
  • prefer-doc-comment: report a multi-declarator export exactly once (87c71e0)
  • prefer-doc-comment: require ordering and static-match for a method's own overload signature (cfa3fb0)
  • prefer-doc-comment: require the export wrapper to reach the public surface (df97ee9)
  • prefer-doc-comment: restrict the VariableDeclaration check to export const (0dd0e84)
  • prefer-doc-comment: stop absorbing a trailing comment into the next leading group (a081eae)
  • prefer-doc-comment: stop folding triple-slash directives into doc comments (1074346)
  • prefer-doc-comment: stop the fixer splicing real text into every line as indent (bf9185c)
  • prefer-doc-comment: take the fixer's line break from the source (a4e4bb9)
  • prefer-doc-comment: validate the unsafe-content gate against real TSDoc (cce1303)
  • prefer-doc-comment: withhold autofix for any TSDoc tag line, not just a blank line before one (b97fb2c)
  • prefer-doc-comment: withhold autofix when a line would collide with jsdoc/no-multi-asterisks (36561e9)
  • prefer-doc-comment: withhold autofix when a line would collide with jsdoc/tag-lines (0c86926)
  • release: arm the deploy-key push by persisting checkout credentials (456c22f)
  • satisfy prefer-doc-comment across the repo's own source (0c4a288)
  • stylistic-comments: exempt cspell:disable-line from line-comment-position (5983a46)
  • stylistic-comments: stop enabling multiline-comment-style (1b4e5bd)
  • stylistic-comments: stop forcing a blank line between consecutive imports and directives (674bfe6)
  • stylistic-comments: stop multiline-comment-style breaking triple-slash directives (0b7d45b), closes eslint-stylistic/eslint-stylistic#1285
  • stylistic-comments: stop spaced-comment breaking source-map and #region markers (a511051), closes #region region/#endregion

Features

  • add prefer-doc-comment rule (aa3d937)
  • deps: add @​stylistic/eslint-plugin (37e38de)
  • prefer-doc-comment: cover exported enums, namespaces, value consts, default expressions (3f658d5)
  • prefer-doc-comment: cover public abstract methods and function-valued class properties (349d96a)
  • prefer-doc-comment: report an exported function's own overload signature (cb4be1e)

... (truncated)

Commits
  • 9daf091 chore(release): 2.23.0 [skip ci]
  • 456c22f fix(release): arm the deploy-key push by persisting checkout credentials
  • 2581b55 docs(readme): cover a directive seated directly above the declaration
  • 5983a46 fix(stylistic-comments): exempt cspell:disable-line from line-comment-position
  • 6b39472 docs(readme): document the @​stylistic plugin registration migration
  • 3f658d5 feat(prefer-doc-comment): cover exported enums, namespaces, value consts, def...
  • a6609e6 docs(readme): describe prefer-doc-comment's generalised tag-line withholding
  • b97fb2c fix(prefer-doc-comment): withhold autofix for any TSDoc tag line, not just a ...
  • 0c86926 fix(prefer-doc-comment): withhold autofix when a line would collide with jsdo...
  • e01aa20 docs(readme): fix the dangling clause in the prefer-doc-comment row
  • Additional commits viewable in compare view

Updates @types/node from 26.4.1 to 26.6.3

Commits

Updates eslint from 10.9.1 to 10.11.0

Release notes

Sourced from eslint's releases.

v10.11.0

Features

  • d136fa4 feat: object-shorthand handle quoted properties for ignoreConstructors (#21271) (Pavel)
  • 397b3b8 feat: report unsafe labeled continue in no-unsafe-finally rule (#21316) (electrohyun)
  • d3dd47f feat: only exempt new-cap built-ins that reference the global (#21290) (sethamus)

Bug Fixes

  • 22b09f5 fix: ignore __proto__ properties in prefer-object-spread (#21311) (xbinaryx)
  • b684bb1 fix: make TimePass.parse optional in types and docs (#21313) (ntnyq)
  • 26d11bc fix: don't report __proto__ properties in object-shorthand (#21310) (xbinaryx)

Documentation

  • 9ecfdc5 docs: note that --cache can serve stale results for cross-file rules (#21312) (bytedoe)
  • 6c789ff docs: Update README (GitHub Actions Bot)
  • 5997825 docs: clarify preserve-caught-error known limitation (#21294) (Akinyemi Toluwalase)

Chores

  • 520dd77 perf: Implement fast paths in critical areas (#21210) (Nicholas C. Zakas)
  • 92086c8 test: update EMFILE error generation for Node.js 26.9.0 compatibility (#21330) (Francesco Trotta)
  • 9ac7eb6 chore: update github/codeql-action action to v4.38.0 (#21331) (renovate[bot])
  • 24310e3 chore: update ecosystem plugins (#21324) (ESLint Bot)
  • 45ad79e ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (#21318) (dependabot[bot])
  • ac74e37 chore: Add AGENTS.md with AI disclosure requirements (#21221) (Nicholas C. Zakas)
  • c832660 chore: Upgrade Stylelint to the latest version in docs (#21245) (Jung Hyeon Jun)
  • f9f88fc chore: update ecosystem plugins (#21308) (ESLint Bot)
  • fc81076 ci: add more types integration tests (#20395) (Nitin Kumar)

v10.10.0

Features

  • 264b434 feat: add d and v flags to no-unexpected-multiline (#21305) (Gihyeon Jeong / 정기현)
  • c6cc6c5 feat: check Object.prototype property names in new-cap (#21269) (crimsonjay0)
  • 5661fa6 feat: no-extra-bind false negatives with class fields and static blocks (#21260) (synthex-byte)

Bug Fixes

  • bb47dc6 fix: update dependency file-entry-cache to v11 (#20801) (Milos Djermanovic)
  • 427ac0a fix: use format strings in debug calls (#21247) (Francesco Trotta)
  • 9d81532 fix: support __proto__ in /* exported */ comments (#21261) (sethamus)
  • 87e0a08 fix: prefer-object-has-own autofix breaks when Object is shadowed (#21282) (김채영)
  • 8e2cb14 fix: new-cap false positive for UTC calls with properties: false (#21275) (Pixel)
  • 9f4a364 fix: Ignore static imports in no-unreachable (#21276) (Taha Kotil)

Documentation

  • 2417cad docs: Update README (GitHub Actions Bot)
  • 9cecb8a docs: document \c control letter escapes in no-control-regex (#21286) (한국)
  • 8724829 docs: update compat table links (#21263) (fnx)
  • 5634542 docs: Clarify eqeqeq suggestion behavior (#21256) (Müslüm Yılmaz)

Chores

  • b3d876b chore: disable npm audit in ecosystem tests (#21306) (Francesco Trotta)
  • 1696682 ci: restore EMFILE test on Node.js 26 (#21297) (Marry (Subin Yang))

... (truncated)

Commits
  • 3c0b7c6 10.11.0
  • 321f0a7 Build: changelog update for 10.11.0
  • 520dd77 perf: Implement fast paths in critical areas (#21210)
  • 9ecfdc5 docs: note that --cache can serve stale results for cross-file rules (#21312)
  • 92086c8 test: update EMFILE error generation for Node.js 26.9.0 compatibility (#21330)
  • 9ac7eb6 chore: update github/codeql-action action to v4.38.0 (#21331)
  • 22b09f5 fix: ignore __proto__ properties in prefer-object-spread (#21311)
  • 24310e3 chore: update ecosystem plugins (#21324)
  • d136fa4 feat: object-shorthand handle quoted properties for ignoreConstructors (#21...
  • 45ad79e ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (#21318)
  • Additional commits viewable in compare view

Updates lint-staged from 17.4.1 to 17.6.0

Release notes

Sourced from lint-staged's releases.

v17.6.0

Minor Changes

  • #1850 938d3f4 - Task functions like { title, task } can now use a logger function log() to emit output while the task runs. By default, the output will only be visible if the task fails, unless the --verbose option was used. Additionally, when the task rejects, the error will be shown in the output.

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*': {
    title: 'Fail if PDF files are committed',
    task: async (filepaths, { log }) => {
    const pdfFiles = filepaths.filter((f) => f.toLowerCase().endsWith('.pdf'))
    if (pdfFiles.length > 0) {
    log('PDF files should not be committed: %s', pdfFiles)
    throw new Error('Failed')
    }
    },
    },
    })

  • #1854 30562bc - lint-staged now stages changes to all tracked files modified by tasks, including files that weren’t originally staged or didn’t match the configured globs. This can happen when your task has side-effects, or it's a function that ignores the staged files like () => "prettier --write .".

    If you have unstaged changes in a file and the task also edits that file, your unstaged changes will be staged too. Use --hide-unstaged to hide your changes while tasks run.

Patch Changes

  • #1860 4296532 - The assignment of staged files to lint-staged configuration files (when using multiple, for example in a monorepo) has been rewritten to be more efficient. As a reminder, each staged file is assigned to exactly one configuration (the closest one), even if that config doesn't match the file in its globs.

  • #1861 c45f28a - Fix running parallel tasks for a single glob, when tasks are created by a function. Nesting one level of arrays inside an array of tasks will result in the inner tasks running in parallel. This behavior should now be consistent when creating tasks using functions. In the following example eslint and prettier will run in parallel (for all files, when any JS files are staged):

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*.js': () => [['eslint --max-warnings=0 .', 'prettier --list-different .']],
    })

  • #1859 f0ea69d - Various performance improvements from skipping redundant internal Git calls.

  • #1856 69d7d17 - Partially staged changes are hidden in a uniquely-named patch file to avoid multiple invocations of lint-staged overwriting it. This makes it safer to run lint-staged in multiple worktrees at the same time.

v17.5.1

Patch Changes

  • #1852 bfcca94 - Fix TypeScript issue TS1254 from defineConfig() by changing the signature from const to a function:

    A 'const' initializer in an ambient context must be a string or numeric literal or literal enum reference.

... (truncated)

Changelog

Sourced from lint-staged's changelog.

17.6.0

Minor Changes

  • #1850 938d3f4 - Task functions like { title, task } can now use a logger function log() to emit output while the task runs. By default, the output will only be visible if the task fails, unless the --verbose option was used. Additionally, when the task rejects, the error will be shown in the output.

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*': {
    title: 'Fail if PDF files are committed',
    task: async (filepaths, { log }) => {
    const pdfFiles = filepaths.filter((f) => f.toLowerCase().endsWith('.pdf'))
    if (pdfFiles.length > 0) {
    log('PDF files should not be committed: %s', pdfFiles)
    throw new Error('Failed')
    }
    },
    },
    })

  • #1854 30562bc - lint-staged now stages changes to all tracked files modified by tasks, including files that weren’t originally staged or didn’t match the configured globs. This can happen when your task has side-effects, or it's a function that ignores the staged files like () => "prettier --write .".

    If you have unstaged changes in a file and the task also edits that file, your unstaged changes will be staged too. Use --hide-unstaged to hide your changes while tasks run.

Patch Changes

  • #1860 4296532 - The assignment of staged files to lint-staged configuration files (when using multiple, for example in a monorepo) has been rewritten to be more efficient. As a reminder, each staged file is assigned to exactly one configuration (the closest one), even if that config doesn't match the file in its globs.

  • #1861 c45f28a - Fix running parallel tasks for a single glob, when tasks are created by a function. Nesting one level of arrays inside an array of tasks will result in the inner tasks running in parallel. This behavior should now be consistent when creating tasks using functions. In the following example eslint and prettier will run in parallel (for all files, when any JS files are staged):

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*.js': () => [['eslint --max-warnings=0 .', 'prettier --list-different .']],
    })

  • #1859 f0ea69d - Various performance improvements from skipping redundant internal Git calls.

  • #1856 69d7d17 - Partially staged changes are hidden in a uniquely-named patch file to avoid multiple invocations of lint-staged overwriting it. This makes it safer to run lint-staged in multiple worktrees at the same time.

17.5.1

Patch Changes

  • #1852 bfcca94 - Fix TypeScript issue TS1254 from defineConfig() by changing the signature from const to a function:

... (truncated)

Commits
  • 48f9f4e Merge pull request #1857 from lint-staged/changeset-release/main
  • 16b2e21 chore(changeset): release
  • 195f156 docs: improve changeset
  • 0ba6261 fix: create hidden directory only when required
  • 66ac2de docs: fixes to changesets
  • 80af8d7 Merge pull request #1863 from lint-staged/fix-issues
  • e433488 fix: handle task editing a symlinked file to a regular file, and --fail-on-ch...
  • e5019b3 fix: handle trailing newlines when detecting changed files
  • 74efec8 ci: run Cygwin and MSYS2 tests on Node.js 26
  • 655b7dc fix: use TypeScript types instead of JSDoc
  • Additional commits viewable in compare view

Updates prettier from 3.9.6 to 3.9.9

Release notes

Sourced from prettier's releases.

3.9.9

  • Markdown: Fix text with $ been incorrectly parsed as math syntax (#20140 by @​fisker)

🔗 Changelog

3.9.8

  • Markdown: Don't let Liquid objects interrupt paragraphs (#20087 by @​seiyab)

🔗 Changelog

3.9.7

  • Support Angular 22.2
  • Fix regressions in v3.9

🔗 Changelog

Changelog

Sourced from prettier's changelog.

3.9.9

diff

Markdown: Fix text with $ been incorrectly parsed as math syntax (#20140 by @​fisker)

<!-- Input -->
**Uses $FOO** from `a.sh` and `b.sh`, plus `$BAR` from `c.sh`, before anything else runs here.
<!-- Prettier 3.9.8 -->
Uses $FOO from a.sh and b.sh, plus $BARfromc.sh, before anything else runs here.
<!-- Prettier 3.9.9 -->
Uses $FOO from a.sh and b.sh, plus $BAR from c.sh, before anything else runs here.

3.9.8

diff

Markdown: Don't let Liquid objects interrupt paragraphs (#20087 by @​seiyab)

<!-- Input -->
If `module` is not a [`WebAssembly.Module`](https://github.com/prettier/prettier/blob/main/en-US/docs/WebAssembly/Reference/JavaScript_interface/Module) object instance, a
{{jsxref("TypeError")}} is thrown.
<!-- Prettier 3.9.7 -->
If module is not a WebAssembly.Module object instance, a
{{jsxref("TypeError")}} is thrown.
<!-- Prettier 3.9.8 -->
If module is not a WebAssembly.Module object instance, a
{{jsxref("TypeError")}} is thrown.

3.9.7

diff

Markdown: Prevent indentation drift in list-item code blocks (#19647, #19990 by @​Austin1serb, @​giaBaoJS)

<!-- Input -->
- [x] short first line.
</tr></table> 

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
Comment thread package.json
"typescript": "6.0.3",
"typescript-eslint": "8.69.0"
"turbo": "2.11.2",
"typescript": "7.0.2",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocker [policy] — this bump of typescript to 7.0.2 is incompatible with typescript-eslint@8.70.0 (bumped in the same PR, package.json:40), which peer-depends on typescript@">=4.8.4 <6.1.0" (see the unchanged peer-dependency entries throughout package-lock.json, e.g. under eslint-plugin-jsdoc/node_modules/@typescript-eslint/*). Because both typescript and typescript-eslint are direct root devDependencies, npm can't nest a second copy of typescript to satisfy the conflict the way it does for eslint-plugin-jsdoc's own nested @typescript-eslint/* copy.

This isn't theoretical — CI on this PR's head commit is actually failing on it: npm ci in the Commitlint, Typecheck, Lint and Format jobs all abort with

npm error code ERESOLVE
npm error While resolving: typescript-eslint@8.70.0
npm error Found: typescript@7.0.2
npm error Could not resolve dependency:
npm error peer typescript@">=4.8.4 <6.1.0" typescript-eslint@8.70.0

(e.g. https://github.com/ExaDev/claude-code-action/actions/runs/36439733683/job/108986797382). "Required Checks" is red as a result, so this PR cannot merge as-is.

The grouped Dependabot update shouldn't have bumped typescript past what typescript-eslint currently supports. Either drop the typescript bump from this PR (keep it at 6.0.3 until typescript-eslint adds 7.x support) or hold the whole group back until that support lands.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-dependencies-dd348e016a branch from 7ba4d14 to 2e20bcb Compare September 30, 2026 14:54
@github-actions
github-actions Bot dismissed their stale review September 30, 2026 14:59

Superseded by re-review on the latest commit.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-dependencies-dd348e016a branch from 2e20bcb to e27e2ce Compare October 1, 2026 14:59
@github-actions
github-actions Bot dismissed their stale review October 1, 2026 15:05

Superseded by re-review on the latest commit.

…ith 10 updates

Bumps the npm-dependencies group with 10 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@commitlint/cli](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/cli) | `21.2.2` | `21.2.3` |
| [@commitlint/config-conventional](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/config-conventional) | `21.2.2` | `21.2.3` |
| [@exadev/eslint-config](https://github.com/ExaDev/eslint-config) | `2.12.3` | `2.23.0` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.4.1` | `26.6.3` |
| [eslint](https://github.com/eslint/eslint) | `10.9.1` | `10.11.0` |
| [lint-staged](https://github.com/lint-staged/lint-staged) | `17.4.1` | `17.6.0` |
| [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.9` |
| [turbo](https://github.com/vercel/turborepo) | `2.10.12` | `2.11.5` |
| [typescript](https://github.com/microsoft/TypeScript) | `6.0.3` | `7.0.2` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.69.0` | `8.70.1` |



Updates `@commitlint/cli` from 21.2.2 to 21.2.3
- [Release notes](https://github.com/conventional-changelog/commitlint/releases)
- [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/cli/CHANGELOG.md)
- [Commits](https://github.com/conventional-changelog/commitlint/commits/v21.2.3/@commitlint/cli)

Updates `@commitlint/config-conventional` from 21.2.2 to 21.2.3
- [Release notes](https://github.com/conventional-changelog/commitlint/releases)
- [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/config-conventional/CHANGELOG.md)
- [Commits](https://github.com/conventional-changelog/commitlint/commits/v21.2.3/@commitlint/config-conventional)

Updates `@exadev/eslint-config` from 2.12.3 to 2.23.0
- [Release notes](https://github.com/ExaDev/eslint-config/releases)
- [Changelog](https://github.com/ExaDev/eslint-config/blob/main/CHANGELOG.md)
- [Commits](ExaDev/eslint-config@v2.12.3...v2.23.0)

Updates `@types/node` from 26.4.1 to 26.6.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `eslint` from 10.9.1 to 10.11.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.9.1...v10.11.0)

Updates `lint-staged` from 17.4.1 to 17.6.0
- [Release notes](https://github.com/lint-staged/lint-staged/releases)
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md)
- [Commits](lint-staged/lint-staged@v17.4.1...v17.6.0)

Updates `prettier` from 3.9.6 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.6...3.9.9)

Updates `turbo` from 2.10.12 to 2.11.5
- [Release notes](https://github.com/vercel/turborepo/releases)
- [Changelog](https://github.com/vercel/turborepo/blob/main/RELEASE.md)
- [Commits](vercel/turborepo@v2.10.12...v2.11.5)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v6.0.3...v7.0.2)

Updates `typescript-eslint` from 8.69.0 to 8.70.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/typescript-eslint)

---
updated-dependencies:
- dependency-name: "@commitlint/cli"
  dependency-version: 21.2.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-dependencies
- dependency-name: "@commitlint/config-conventional"
  dependency-version: 21.2.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-dependencies
- dependency-name: "@exadev/eslint-config"
  dependency-version: 2.20.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: "@types/node"
  dependency-version: 26.6.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: eslint
  dependency-version: 10.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: lint-staged
  dependency-version: 17.5.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: prettier
  dependency-version: 3.9.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-dependencies
- dependency-name: turbo
  dependency-version: 2.11.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: typescript-eslint
  dependency-version: 8.70.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-dependencies-dd348e016a branch from e27e2ce to 1335f39 Compare October 5, 2026 14:55
@github-actions
github-actions Bot dismissed their stale review October 5, 2026 14:59

Superseded by re-review on the latest commit.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-review of head commit 1335f39 (branch moved from e27e2ce, which I reviewed before). I cleared and dismissed the stale CHANGES_REQUESTED review from that commit before submitting this one.

Verdict: still blocked, same issue as before.

🔴 Blocker [policy] — the still-open thread on package.json:39 stands: this grouped update still bumps root typescript to 7.0.2 while a nested @typescript-eslint/utils@8.67.0 (pulled in transitively via @exadev/eslint-config, package-lock.json:928-951) still declares peerDependencies.typescript: ">=4.8.4 <6.1.0". I re-verified this is unchanged on the current commit rather than assuming the prior finding still holds: package.json:39-40 is unchanged (typescript: 7.0.2, typescript-eslint: 8.70.1), and the same incompatible >=4.8.4 <6.1.0 peer range is still present in multiple nested node_modules/**/@typescript-eslint/* entries in the current package-lock.json. CI on this exact commit is red as a direct result: Typecheck, Lint, Format and Commitlint all fail npm ci's ERESOLVE, and Required Checks is failing — this cannot merge as-is. I haven't duplicated the inline comment since the finding and its anchor are both unchanged; see that thread for the full detail.

The other nine updates in the group (@commitlint/*, @exadev/eslint-config itself, @types/node, eslint, lint-staged, prettier, turbo) remain ordinary patch/minor bumps with no new conflicts I could find — only the typescript bump is the blocker. As before: either drop typescript from this grouped update (hold at 6.0.3) or hold the whole group until the @typescript-eslint chain supports TypeScript 7.

Title and description are the standard Dependabot-generated format for a grouped update and accurately describe the change, so I left them untouched.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

🗜️ Headroom context compression

Metric Value
Requests proxied 29
Tokens saved 54025
Aggregate savings 1.9% of all tokens sent
Average per-request compression 2.5%

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants