π¨ [security] Update eslint 9.39.2 β 10.0.2 (major)#558
π¨ [security] Update eslint 9.39.2 β 10.0.2 (major)#558depfu[bot] wants to merge 1 commit intomainfrom
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Caution Review the following alerts detected in dependencies. According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.
|
|||||||||||||||||||||||||||||||||
|
|
Overall GradeΒ Β |
SecurityΒ Β ReliabilityΒ Β ComplexityΒ Β HygieneΒ Β |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| Test coverage | Feb 24, 2026 10:56p.m. | ReviewΒ β | |
| JavaScript | Feb 24, 2026 10:56p.m. | ReviewΒ β | |
| Secrets | Feb 24, 2026 10:56p.m. | ReviewΒ β |
guibranco
left a comment
There was a problem hiding this comment.
Automatically approved by gstraccini[bot]
|
@depfu merge |
π¨ Your current dependencies have known security vulnerabilities π¨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this upgrade. Please take a good look at what changed and the test results before merging this pull request.
What changed?
Release Notes
3.3.4 (from changelog)
3.3.3 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 6 commits:
9.39.3Build: changelog update for 9.39.3chore: upgrade @eslint/js@9.39.3 (#20529)chore: package.json update for @eslint/js releasefix: restore TypeScript 4.0 compatibility in types (#20504)chore: ignore `/docs/v9.x` in link checker (#20453)Commits
See the full diff on Github. The new version differs by 22 commits:
Mark version 8.16.0Mark acorn-walk 8.3.5Properly check for presence of node.attributes in walkersBump test262Bump Unicode 17, regenerate script valuesProperly throw an error, not a raw stringMore explicit error when walking a tree and a node type isn't registered.Rename eslint config file to suppress warningUpdate to ESLint 9Add Unicode v17 supportUse consistent semicolon-less style in readmesDocs: Announce both ESM and CommonJS imports are supported, change all examples to ESM importsClean up identifier char handling in keyword lookahead functionsIncrease accuracy of isAsyncFunction when followed by a backslashFix await using double lookahead edge caseMark acorn-loose 8.5.2Bump dependency on acorn in acorn-looseAdd support for sourceType: commonjs optionReject return statement in static block, even if allowReturnOutsideFunction is usedReject using declarations directly in for loop or switch scopes.Improve lookahead test for using syntaxMark acorn-loose 8.5.1Security Advisories π¨
π¨ ajv has ReDoS when using `$data` option
Commits
See the full diff on Github. The new version differs by 7 commits:
6.14.0add regExp option to address $data exploit via a regular expression (CVE-2025-69873) (#2590)docs: update v7 infoMerge pull request #1320 from philsturgeon/patch-1Add spectral, an AJV util from a sponsordocs: v7.0.0-beta.3update readme for v7Sorry, we couldn't find anything useful about this release.
π @βtypes/esrecurse (added, 4.3.1)
π brace-expansion (added, 5.0.3)
π minimatch (added, 10.2.2)
π minimatch (added, 3.1.3)
π @βeslint/config-array (added, 0.23.2)
π @βeslint/config-helpers (added, 0.5.2)
π @βeslint/object-schema (added, 3.0.2)
π @βeslint/plugin-kit (added, 0.6.0)
π @βtypescript-eslint/project-service (added, 8.56.1)
π @βtypescript-eslint/scope-manager (added, 8.56.1)
π @βtypescript-eslint/tsconfig-utils (added, 8.56.1)
π @βtypescript-eslint/types (added, 8.56.1)
π @βtypescript-eslint/typescript-estree (added, 8.56.1)
π @βtypescript-eslint/utils (added, 8.56.1)
π @βtypescript-eslint/visitor-keys (added, 8.56.1)
π eslint-visitor-keys (added, 5.0.1)
π balanced-match (added, 4.0.4)
π eslint (added, 9.39.3)
π eslint (added, 10.0.2)
π eslint-scope (added, 9.1.1)
π espree (added, 11.1.1)
ποΈ eslint (removed)
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands