Skip to content

chore(deps): update all dependencies - #112

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Pending OpenSSF
@eslint-react/eslint-plugin (source) devDependencies minor 5.20.8 → 5.24.2 5.24.8 (+5) OpenSSF Scorecard
@types/node (source) devDependencies patch 26.6.2 → 26.6.4 OpenSSF Scorecard
@types/vscode (source) devDependencies minor 1.138.0 → 1.140.0 OpenSSF Scorecard
@typescript-eslint/eslint-plugin (source) devDependencies minor 8.70.1 → 8.71.0 8.71.1 OpenSSF Scorecard
@typescript-eslint/parser (source) devDependencies minor 8.70.1 → 8.71.0 8.71.1 OpenSSF Scorecard
eslint (source) devDependencies minor 10.11.0 → 10.12.0 OpenSSF Scorecard
typescript (source) devDependencies major 6.0.3 → 7.0.2 OpenSSF Scorecard

Release Notes

Rel1cx/eslint-react (@​eslint-react/eslint-plugin)

v5.24.2

Compare Source

🏗️ Internal
  • @eslint-react/core, @eslint-react/var, the react-dom plugin, and the react-x plugin: replaced in operator checks with the hasProperty helper from @local/eff.
  • @eslint-react/shared: documented getNormalizedSettings.
  • JSDoc comments are now stripped from the tsdown build output, producing smaller published packages.

Full Changelog: Rel1cx/eslint-react@v5.24.1...v5.24.2

v5.24.1

Compare Source

🏗️ Internal
  • @eslint-react/shared: normalized settings are now cached via the memoize helper from @local/eff instead of a manual map lookup, and non-object react-x settings fall back to the defaults before normalization; added a settings normalization benchmark. (#​1992)
  • @local/eff: synced the vendored utilities with Effect v4. (#​1991)
  • Bumped eslint to 10.12.0.

Full Changelog: Rel1cx/eslint-react@v5.24.0...v5.24.1

v5.24.0

Compare Source

🐞 Fixes
  • react-x/set-state-in-effect: more value shapes are recognized as ref-derived setState arguments: interpolations in template literals (ex: setData(`${ref.current}`)), tagged templates (both the quasi and a ref-derived tag), object and array literals (ex: setData({ value: ref.current })), and spreads (ex: setData({ ...ref.current })) — previously these fell through to the default case and were reported. (#​1988)
📝 Documentation
  • Added eslint-config-xo-react to the website's community presets.
🏗️ Internal
  • @local/eff: added predicate combinators and type guards synced with effect, and migrated call sites across the workspace to them. (#​1989)
  • react-x/set-state-in-effect, react-x/set-state-in-render, and react-x/use-memo: reworked to the fact-based implementation pattern — fact collection (collect.ts), provenance resolution (origins.ts), and violation inference (effects.ts) are now separate modules, with lib.ts replaced by a pure-AST helpers.ts; set-state-in-effect again classifies a hook name configured as both additionalStateHooks and additionalEffectHooks as a state hook first. (#​1983, #​1985, #​1986)
  • react-x/use-state: aligned the nested-expression collectors' visitor keys to callee-first order, matching eslint-visitor-keys; no behavior change. (#​1988)
  • Migrated package unit tests to the shared @local/testkit helpers. (#​1987)
  • Renamed message ids to kebab-case across all plugins. (#​1984)
  • Bumped fumadocs-core and fumadocs-ui to 16.15.18, fumadocs-mdx to 15.4.6, lucide-react to 1.50.0, and @types/node to 26.6.4.

Full Changelog: Rel1cx/eslint-react@v5.23.5...v5.24.0

v5.23.5

Compare Source

🐞 Fixes
  • react-x/set-state-in-effect: the ref-derived value exemption now also covers setState calls reached indirectly through functions or hook callbacks invoked from the effect setup, not only setState written directly in the setup body. (#​1982)
  • react-x/set-state-in-effect: more ref read shapes are recognized as ref-derived values — <ref-named>.current anywhere in a member chain, locals derived from other ref-derived locals, and reads through a ref/xxxRef parameter. (#​1982)
  • react-web-api/no-leaked-event-listener: removeEventListener inside a function called from the effect cleanup now pairs with its addEventListener, fixing false positives for listeners removed on unmount; cleanup calls resolve to the actual functions, so same-named shadowed functions no longer pair by coincidence. (#​1982)
🏗️ Internal
  • Bumped effect to 4.0.0 and migrated the repo scripts to the v4 APIs. (#​1981)

Full Changelog: Rel1cx/eslint-react@v5.23.4...v5.23.5

v5.23.4

Compare Source

🐞 Fixes
  • Added the missing react-x/static-components rule to the disable-experimental preset. (#​1980)
  • Fixed type imports in react-x/exhaustive-deps and react-x/rules-of-hooks (RuleFeature is now imported from @eslint-react/eslint instead of @eslint-react/shared).
📝 Documentation
  • react-jsx/no-useless-fragment: clarified the scope of the allowExpressions option and unified experimental-rule callout wording across rule docs.
  • react-x: unified cross-rule references in rule docs to full rule names.
  • Removed low-relevance entries from the further reading sections of rule docs, and removed a redundant note about eslint being an optional peer dependency.
  • Fixed inaccuracies in internal documentation. (#​1980)
🏗️ Internal
  • Adopted ts-pattern for type checks in @eslint-react/core, @eslint-react/jsx, and the react-dom plugin, and declared the missing ts-pattern dependencies.
  • Added behavior boundary tests for react-jsx/no-useless-fragment.
  • Bumped fumadocs-core, fumadocs-ui, and lucide-react in the website.

Full Changelog: Rel1cx/eslint-react@v5.23.3...v5.23.4

v5.23.3

Compare Source

🐞 Fixes
  • react-x/immutability: reassigning a binding that resolves to component props or state (value = value + "!", count++, including destructuring and for...of rebinding forms) is now reported as a direct mutation, matching upstream react-hooks/immutability; rebinding iterator or shallow-copy bindings remains allowed. (#​1979)
  • react-x/set-state-in-effect: ref reads traced through intermediate local computations (ex: const dv = visible - prevVisible.current) are now recognized as ref-derived values, and a preceding early-return guard whose test is ref-derived (ex: if (dv === 0) return;) now exempts the setState calls that follow it — previously only setState nested directly inside a ref-gated if/conditional was exempted. Aligns with react-hooks 7.1.1. (#​1979)
📝 Documentation
  • react-x/no-unstable-context-value: documented the React 19 <Context> provider detection heuristic and its name-based limitations. (#​1979)
  • Updated the README badges to reference eslint-plugin-react-x.

Full Changelog: Rel1cx/eslint-react@v5.23.2...v5.23.3

v5.23.2

Compare Source

🏗️ Internal
  • Removed unused dependencies and fixed phantom dependencies across the workspace.
  • Bumped next to 16.3.7, fumadocs-core and fumadocs-ui to 16.15.16, and eslint-plugin-package-json to 1.10.1.

Full Changelog: Rel1cx/eslint-react@v5.23.1...v5.23.2

v5.23.1

Compare Source

🏗️ Internal
  • Re-verified and synchronized the IMPL-SPEC diff reports for the following react-x rules. (#​1977, #​1978)
    • react-x/error-boundaries
    • react-x/globals
    • react-x/immutability
    • react-x/purity
    • react-x/refs
    • react-x/set-state-in-effect
    • react-x/set-state-in-render
    • react-x/use-memo
  • Bumped typescript-eslint to 8.71.0, tsl-dx to 0.13.7, and pnpm to 12.8.1.
📝 Documentation
  • Added argo-cd, griffel, tanstack/table, and eslint-config-studio to the website's community lists.

Full Changelog: Rel1cx/eslint-react@v5.23.0...v5.23.1

v5.23.0

Compare Source

✨ New
  • react-x/static-components: dynamic creation-site tracing now follows both sides of logical expressions (ex: const C = DefaultComponent || (() => <div />)) and the last element of sequence expressions (ex: const C = (setup(), () => <div />)), in initializers and reassignments alike. (#​1975)
🐞 Fixes
  • react-x/static-components: parameters of nested non-component functions (ex: function render(Comp) { return <Comp /> }) are no longer mistaken for render-created components; definitions are judged by definition type instead of AST node type. (#​1975)
  • react-x/static-components: createdHere is now reported once per creation site instead of once per JSX usage; the default diagnostic remains per usage. (#​1975)
🏗️ Internal
  • react-x/static-components: restructured the rule to the fact-based implementation pattern — collect.ts (usage facts), origins.ts (creation-site resolution), and effects.ts (effect inference) are now separate modules, with reporting centralized in Program:exit; added 14 boundary test cases covering creation-site resolution, render boundaries, and per-usage reporting. (#​1975)
  • Renamed lib.ts to helpers.ts in the fact-based react-x rules (globals, immutability, refs). (#​1976)
  • Bumped @effect/language-service to 0.87.3 and oxlint to 1.86.0.

Full Changelog: Rel1cx/eslint-react@v5.22.1...v5.23.0

v5.22.1

Compare Source

🐞 Fixes
  • react-x/use-state: directly returning the useState result (ex: return React.useState()) is now allowed regardless of the rule's options, matching the exemption in the original react/hook-use-state rule. Covers explicit, implicit (arrow function), and type-asserted returns; lazy initialization checks still apply. (#​1974, closes #​1963)
📝 Documentation
  • Added a note about eslint being an optional peer dependency to the READMEs and the website's getting-started guides.
  • Simplified the @eslint-react/kit README to point to the full documentation.

Full Changelog: Rel1cx/eslint-react@v5.22.0...v5.22.1

v5.22.0

Compare Source

✨ New
  • react-dom/no-unknown-property: added React 19.3 properties to the known property allowlist. (#​1973)
    • closedby on dialog
    • onFullscreenChange, onFullscreenError (and their Capture variants), credentialless, and maskType — gated on React version >= 19.3.0
    • onLoad on body
    • onScrollEnd (and its Capture variant)
    • shadowrootmode, shadowrootclonable, shadowrootdelegatesfocus, and shadowrootserializable on template
🏗️ Internal
  • Bumped fumadocs-core and fumadocs-ui to 16.15.15.

Full Changelog: Rel1cx/eslint-react@v5.21.3...v5.22.0

v5.21.3

Compare Source

🐞 Fixes
  • react-x/purity: reverted the v5.21.2 exemption for impure calls in useRef initializer arguments (ex: useRef(document.createElement("div"))); such calls are reported again. (#​1972)

Full Changelog: Rel1cx/eslint-react@v5.21.2...v5.21.3

v5.21.2

Compare Source

🐞 Fixes
  • react-x/no-unnecessary-use-prefix: hooks that call other hooks only within nested callbacks, functions named exactly use, and hooks defined in test mock module registrations are no longer reported. (#​1971)
  • react-x/no-unused-class-component-members: methods invoked by host environments through refs (React Native's NativeMethods) are no longer reported as unused. (#​1971)
  • react-x/purity: async function components in modules without a use client directive and impure calls in useRef initializer arguments are no longer reported. (#​1971)
  • react-x/set-state-in-effect: local variables initialized from nested member expressions rooted at a ref are now recognized as ref-derived values and no longer reported. (#​1971)
🏗️ Internal
  • @eslint-react/ast: predefined and exported common node-type helpers in the Check namespace and migrated call sites to them.
📝 Documentation
  • Website rule docs no longer include the per-rule ## Versions section; a rule's changelog can be viewed directly via the Rule Changelog link under the ## Resources section of each rule doc.

Full Changelog: Rel1cx/eslint-react@v5.21.1...v5.21.2

v5.21.1

Compare Source

🐞 Fixes
  • Fixed missed reports where a timer, fetch controller, or observer created in one effect was treated as cleaned up because an unrelated cleanup in another effect referenced a different variable with the same name; identifier matching now resolves both sides to their variables by scope instead of comparing names only. (#​1969) Affected rules:
    • react-web-api/no-leaked-timeout
    • react-web-api/no-leaked-interval
    • react-web-api/no-leaked-fetch
    • react-web-api/no-leaked-resize-observer
    • react-web-api/no-leaked-intersection-observer
🏗️ Internal
  • Simplified the react-web-api leaked-resource rules by replacing manual function-context stack tracking with Traverse.findParent ancestor lookup, and added boundary tests covering deeply nested callbacks, cross-effect pairing, and wrapped or referenced setup callbacks. (#​1969) Affected rules:
    • react-web-api/no-leaked-timeout
    • react-web-api/no-leaked-interval
    • react-web-api/no-leaked-fetch
    • react-web-api/no-leaked-event-listener
    • react-web-api/no-leaked-resize-observer
    • react-web-api/no-leaked-intersection-observer
  • @eslint-react/var: isAssignmentTargetEqual no longer short-circuits same-name identifiers through structural equality; identifier pairs are compared with scope-aware value equality. (#​1969)
  • react-x/no-unused-class-component-members: removed the manual class and method context stacks; the enclosing class and method are now resolved at the hit point with Traverse.findParent ancestor lookup, and the per-class member definition/usage maps are initialized lazily. (#​1970)

Full Changelog: Rel1cx/eslint-react@v5.21.0...v5.21.1

v5.21.0

Compare Source

✨ New
  • The plugins can now be used with Oxlint without an eslint installation: eslint is now an optional peer dependency across all published packages, and the rule utilities no longer eagerly load the eslint package at import time. (#​1965)
🏗️ Internal
  • @eslint-react/core: removed the unused isAssignmentToThisState helper, and simplified the react-x class-component rules (no-access-state-in-setstate, no-class-component, no-direct-mutation-state, no-set-state-in-*) accordingly.
  • @eslint-react/eslint: added a local getConstrainedTypeAtLocation helper (adapted from @typescript-eslint/type-utils) so consumers don't need to load @typescript-eslint/type-utils, whose entry point eagerly loads the eslint package. (#​1965)
  • Bumped typescript-eslint to 8.70.1, fumadocs to 16.15.14, fumadocs-mdx to 15.4.5, vite to 8.3.1, and other dependencies.
New Contributors

Full Changelog: Rel1cx/eslint-react@v5.20.8...v5.21.0

typescript-eslint/typescript-eslint (@​typescript-eslint/eslint-plugin)

v8.71.0

Compare Source

🚀 Features
  • eslint-plugin: [no-unsafe-enum-assignment] add rule (#​12732)
🩹 Fixes
  • eslint-plugin: [no-misused-promises] handle a return outside of any function (#​12912)
  • eslint-plugin: [no-unnecessary-type-assertion] specialize generic assertion report message (#​12832)
  • eslint-plugin: [unbound-method] respect this: void on class properties (7fce9127d)
  • eslint-plugin: [switch-exhaustiveness-check] always sort literal cases in stable order (#​12885)
❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

typescript-eslint/typescript-eslint (@​typescript-eslint/parser)

v8.71.0

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

eslint/eslint (eslint)

v10.12.0

Compare Source

Features

  • 4618052 feat: handle astral letters in new-cap (#​21357) (sary)
  • 4ec5168 feat: allow SourceCode#getText() to accept tokens and comments (#​21340) (electrohyun)

Bug Fixes

  • bc51eee fix: prefer-arrow-callback false positive in conditional test (#​21373) (Daniel Pinto)
  • bbff86c fix: skip lines with multiple comments in max-lines-per-function (#​21332) (xbinaryx)
  • efc4d6b fix: astral letters in consistent-return, no-eval, no-invalid-this (#​21360) (lumir)
  • 93de066 fix: prefer-exponentiation-operator autofix for async function base (#​21322) (Vladimir Babin)
  • 02e34ff fix: add missing space after else in curly autofix (#​21355) (Pixel)
  • b14b8bc fix: correct id-length message for long private names (#​21348) (Pixel)
  • 69aac01 fix: support TSFunctionType in getFunctionHeadLoc (#​21335) (xbinaryx)
  • 686630e fix: no-loss-of-precision false positive with 0.e5 (#​21337) (sethamus)

Documentation

  • 67eb586 docs: Update README (GitHub Actions Bot)
  • 5370d7e docs: clarify one-var separateRequires matches any require() call (#​21192) (sethamus)
  • 8816c1d docs: Update README (GitHub Actions Bot)
  • 3d2e7ce docs: fix typo in no-unused-expressions documentation (#​21346) (bytedoe)

Chores

  • 152067f chore: update ecosystem plugins (#​21362) (ESLint Bot)
  • b56d58e chore: update github/codeql-action action to v4.38.2 (#​21376) (renovate[bot])
  • bfaea12 perf: cache normalized config globals per languageOptions (#​21364) (James Ross)
  • 322209e ci: avoid Nx cache in ecosystem tests and disable failing test (#​21369) (Francesco Trotta)
  • d166567 chore: update dependency prettier to v3.9.9 (#​21371) (renovate[bot])
  • 29585ce chore: update dependency eslint-plugin-expect-type to ^0.7.0 (#​21359) (renovate[bot])
  • 39d79ba chore: update github/codeql-action action to v4.38.1 (#​21354) (renovate[bot])
  • 182a6e9 chore: update dependency prettier to v3.9.8 (#​21352) (renovate[bot])
  • f995127 chore: remove CLAUDE.md in favor of AGENTS.md (#​21339) (Jarren)
  • b95fb6c chore: update dependency prettier to v3.9.7 (#​21347) (renovate[bot])
  • 3782dd4 chore: update ecosystem plugins (#​21342) (ESLint Bot)
microsoft/TypeScript (typescript)

v7.0.2: TypeScript 7.0.2

Compare Source

https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/

This tag was originally released at: https://github.com/microsoft/typescript-go/releases/tag/typescript%2Fv7.0.2


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate

renovate Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: package-lock.json
npm warn Unknown env config "store". This will error in a future major version of npm. See `npm help npmrc` for supported config options.
npm error code ERESOLVE
npm error ERESOLVE unable to resolve dependency tree
npm error
npm error While resolving: achievements@0.7.1
npm error Found: typescript@7.0.2
npm error node_modules/typescript
npm error   dev typescript@"7.0.2" from the root project
npm error
npm error Could not resolve dependency:
npm error peer typescript@">=4.8.4 <6.1.0" from @typescript-eslint/parser@8.71.0
npm error node_modules/@typescript-eslint/parser
npm error   dev @typescript-eslint/parser@"8.71.0" from the root project
npm error   peer @typescript-eslint/parser@"^8.71.0" from @typescript-eslint/eslint-plugin@8.71.0
npm error   node_modules/@typescript-eslint/eslint-plugin
npm error     dev @typescript-eslint/eslint-plugin@"8.71.0" from the root project
npm error
npm error Fix the upstream dependency conflict, or retry this command with --force or --legacy-peer-deps to accept an incorrect (and potentially broken) dependency resolution.
npm error
npm error
npm error For a full report see:
npm error /runner/cache/others/npm/_logs/2026-10-07T18_23_53_727Z-eresolve-report.txt
npm error A complete log of this run can be found in: /runner/cache/others/npm/_logs/2026-10-07T18_23_53_727Z-debug-0.log

@renovate renovate Bot changed the title chore(deps): update dependency typescript to v7 chore(deps): update all dependencies Sep 28, 2026
@renovate
renovate Bot force-pushed the renovate/all branch 11 times, most recently from 8cc9b6a to 0623875 Compare October 7, 2026 10:14
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant