π¨ [security] Update all of eslint 9.39.2 β 10.0.0 (major)#631
π¨ [security] Update all of eslint 9.39.2 β 10.0.0 (major)#631depfu[bot] wants to merge 1 commit into
Conversation
|
The files' contents are under analysis for test generation. |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Caution Review the following alerts detected in dependencies. According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.
|
guibranco
left a comment
There was a problem hiding this comment.
Automatically approved by gstraccini[bot]
|
@depfu merge |
ccbd609 to
da54889
Compare
|
@depfu recreate |
cd922fd to
b6351ad
Compare
|
Infisical secrets check: β No secrets leaked! π» Scan logs2026-03-03T18:13:42Z INF scanning for exposed secrets...
6:13PM INF 523 commits scanned.
2026-03-03T18:13:43Z INF scan completed in 358ms
2026-03-03T18:13:43Z INF no leaks found
|
|
Closed in favor of #660. |
π¨ Your current dependencies have known security vulnerabilities π¨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this upgrade. Please take a good look at what changed and the test results before merging this pull request.
What changed?
β³οΈ @βeslint/js (9.39.2 β 10.0.0) Β· Repo Β· Changelog
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
β³οΈ eslint (9.39.2 β 10.0.0) Β· Repo Β· Changelog
Release Notes
10.0.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
0.6.0 (from changelog)
0.5.1 (from changelog)
0.5.0 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 22 commits:
Mark version 8.16.0Mark acorn-walk 8.3.5Properly check for presence of node.attributes in walkersBump test262Bump Unicode 17, regenerate script valuesProperly throw an error, not a raw stringMore explicit error when walking a tree and a node type isn't registered.Rename eslint config file to suppress warningUpdate to ESLint 9Add Unicode v17 supportUse consistent semicolon-less style in readmesDocs: Announce both ESM and CommonJS imports are supported, change all examples to ESM importsClean up identifier char handling in keyword lookahead functionsIncrease accuracy of isAsyncFunction when followed by a backslashFix await using double lookahead edge caseMark acorn-loose 8.5.2Bump dependency on acorn in acorn-looseAdd support for sourceType: commonjs optionReject return statement in static block, even if allowReturnOutsideFunction is usedReject using declarations directly in for loop or switch scopes.Improve lookahead test for using syntaxMark acorn-loose 8.5.1Security Advisories π¨
π¨ ajv has ReDoS when using `$data` option
Commits
See the full diff on Github. The new version differs by 7 commits:
6.14.0add regExp option to address $data exploit via a regular expression (CVE-2025-69873) (#2590)docs: update v7 infoMerge pull request #1320 from philsturgeon/patch-1Add spectral, an AJV util from a sponsordocs: v7.0.0-beta.3update readme for v7Release Notes
9.1.1 (from changelog)
Does any of this look wrong? Please let us know.
Release Notes
11.1.1 (from changelog)
11.1.0 (from changelog)
11.0.0 (from changelog)
Does any of this look wrong? Please let us know.
Sorry, we couldn't find anything useful about this release.
π @βtypes/esrecurse (added, 4.3.1)
ποΈ @βeslint/eslintrc (removed)
ποΈ argparse (removed)
ποΈ callsites (removed)
ποΈ chalk (removed)
ποΈ color-convert (removed)
ποΈ color-name (removed)
ποΈ concat-map (removed)
ποΈ import-fresh (removed)
ποΈ js-yaml (removed)
ποΈ lodash.merge (removed)
ποΈ parent-module (removed)
ποΈ resolve-from (removed)
ποΈ strip-json-comments (removed)
ποΈ eslint-visitor-keys (removed)
ποΈ globals (removed)
ποΈ balanced-match (removed)
ποΈ brace-expansion (removed)
ποΈ minimatch (removed)
ποΈ ansi-styles (removed)
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands