Skip to content

meta: bump the lint group across 1 directory with 3 updates - #1129

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/lint-ae1162a5ec
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/lint-ae1162a5ec

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the lint group with 3 updates in the / directory: eslint-plugin-jsdoc, eslint-plugin-react-x and lint-staged.

Updates eslint-plugin-jsdoc from 64.3.1 to 64.5.4

Release notes

Sourced from eslint-plugin-jsdoc's releases.

v64.5.4

64.5.4 (2026-09-19)

Bug Fixes

  • no-unnecessary-type-assertion: only try typescript if the rule is enabled; fixes #1773 (3c1c209)

v64.5.3

64.5.3 (2026-09-18)

Bug Fixes

v64.5.2

64.5.2 (2026-09-16)

Bug Fixes

  • set optional typescript peer dep. to any to undo breaking change (f469cdf)

v64.5.1

64.5.1 (2026-09-16)

Bug Fixes

  • specify typescript as an optional peer dependency; fixes #1768 (d147779)

v64.5.0

64.5.0 (2026-09-15)

Features

  • ts-ban-ts-comments: add rule mirrorring typescript-eslint's ban-ts-comments rule (afff498)

v64.4.0

64.4.0 (2026-09-14)

Features

  • convert-to-jsdoc-comments, no-bad-blocks: add LibreJS tags (99d2abf)

v64.3.10

64.3.10 (2026-09-12)

... (truncated)

Commits
  • 3c1c209 fix(no-unnecessary-type-assertion): only try typescript if the rule is enab...
  • a142875 chore: update jsdoccomment, typescript-eslint/utils, comment-parser, devDeps
  • 2d85fed fix: for @​link targets, check properties within export class declarations; fi...
  • f1f318a chore: update ncurc format
  • f469cdf fix: set optional typescript peer dep. to any to undo breaking change
  • d147779 fix: specify typescript as an optional peer dependency; fixes #1768
  • afff498 feat(ts-ban-ts-comments): add rule mirrorring typescript-eslint's `ban-ts-c...
  • 99d2abf feat(convert-to-jsdoc-comments, no-bad-blocks): add LibreJS tags
  • 64a8dca fix(convert-to-jsdoc-comments): merge stacked line comments into a single J...
  • eade377 fix(no-undefined-types): recognize class members from the class's own JSDoc
  • Additional commits viewable in compare view

Updates eslint-plugin-react-x from 5.18.6 to 5.20.8

Release notes

Sourced from eslint-plugin-react-x's releases.

v5.20.8 (2026-09-24)

What's Changed

🐞 Fixes

  • @eslint-react/core: isJsxLike now recognizes JSX wrapped in TypeScript expressions (as, satisfies, type assertions, and non-null assertions) and await expressions.
  • @eslint-react/jsx: isFragmentElement now requires the configured jsxFragmentFactory, avoiding an implicit React fragment factory for custom JSX runtimes.

🏗️ Internal

  • @eslint-react/jsx: exported the AttributeValue type from the package entry point.
  • @eslint-react/var: renamed the AssignmentTarget type to EnclosingAssignmentTarget and inlined getRequireExpressionArguments into its sole consumer.

Full Changelog: Rel1cx/eslint-react@v5.20.6...v5.20.8

Attestation

https://github.com/Rel1cx/eslint-react/attestations/49643669

v5.20.6 (2026-09-23)

What's Changed

🐞 Fixes

  • react-x/globals: for...in/for...of loop targets without a declaration (e.g. for (globalValue of items)) are now collected as writes instead of being missed.
  • react-x/immutability: destructuring assignment targets (e.g. ({ a: props.x } = value)) and for...in/for...of loop targets without a declaration are now collected as mutations instead of being missed.
  • react-x/purity: builtin alias resolution now preserves the property path, so aliases of impure builtins (const random = Math.random; random(), const { now } = Date; now(), window.Math.random()) are now detected instead of being missed; unknown-global roots are not followed, preventing speculative reports.
  • react-x/refs: destructuring assignments, for-in/of loop targets, and delete operations on ref.current are now classified as writes instead of being misreported as reads.
  • react-x/refs: refs passed to constructor calls (new Widget(ref)) and tagged templates are now checked for render-time exposure, same as refs passed to plain functions.
  • react-x/refs: the mergeRefs exemption for passing refs now survives simple variable aliases (const combine = mergeRefs), resolved position-aware so reassigned aliases lose it again.
  • react-x/use-memo: reassignments of outer variables through destructuring patterns and for...in/for...of loop targets inside useMemo callbacks are now reported instead of being missed; property mutation targets remain exempt, matching the React Compiler's StoreContext semantics.

🏗️ Internal

  • @eslint-react/var: split resolve into a value-based resolve and a new origin-based resolveOrigin, and updated the consumers in react-web-api and react-x rules accordingly. (#1964)
  • Bumped fumadocs to 16.15.12, fumadocs-mdx to 15.4.3, tsl-dx to 0.13.6, eslint-plugin-de-morgan to 2.2.0, and eslint-plugin-regexp to 3.3.1.

Full Changelog: Rel1cx/eslint-react@v5.20.5...v5.20.6

Attestation

https://github.com/Rel1cx/eslint-react/attestations/49570738

v5.20.5 (2026-09-21)

What's Changed

... (truncated)

Changelog

Sourced from eslint-plugin-react-x's changelog.

v5.20.8 (2026-09-24)

🐞 Fixes

  • @eslint-react/core: isJsxLike now recognizes JSX wrapped in TypeScript expressions (as, satisfies, type assertions, and non-null assertions) and await expressions.
  • @eslint-react/jsx: isFragmentElement now requires the configured jsxFragmentFactory, avoiding an implicit React fragment factory for custom JSX runtimes.

🏗️ Internal

  • @eslint-react/jsx: exported the AttributeValue type from the package entry point.
  • @eslint-react/var: renamed the AssignmentTarget type to EnclosingAssignmentTarget and inlined getRequireExpressionArguments into its sole consumer.

Full Changelog: Rel1cx/eslint-react@v5.20.6...v5.20.8

v5.20.6 (2026-09-23)

🐞 Fixes

  • react-x/globals: for...in/for...of loop targets without a declaration (e.g. for (globalValue of items)) are now collected as writes instead of being missed.
  • react-x/immutability: destructuring assignment targets (e.g. ({ a: props.x } = value)) and for...in/for...of loop targets without a declaration are now collected as mutations instead of being missed.
  • react-x/purity: builtin alias resolution now preserves the property path, so aliases of impure builtins (const random = Math.random; random(), const { now } = Date; now(), window.Math.random()) are now detected instead of being missed; unknown-global roots are not followed, preventing speculative reports.
  • react-x/refs: destructuring assignments, for-in/of loop targets, and delete operations on ref.current are now classified as writes instead of being misreported as reads.
  • react-x/refs: refs passed to constructor calls (new Widget(ref)) and tagged templates are now checked for render-time exposure, same as refs passed to plain functions.
  • react-x/refs: the mergeRefs exemption for passing refs now survives simple variable aliases (const combine = mergeRefs), resolved position-aware so reassigned aliases lose it again.
  • react-x/use-memo: reassignments of outer variables through destructuring patterns and for...in/for...of loop targets inside useMemo callbacks are now reported instead of being missed; property mutation targets remain exempt, matching the React Compiler's StoreContext semantics.

🏗️ Internal

  • @eslint-react/var: split resolve into a value-based resolve and a new origin-based resolveOrigin, and updated the consumers in react-web-api and react-x rules accordingly. (#1964)
  • Bumped fumadocs to 16.15.12, fumadocs-mdx to 15.4.3, tsl-dx to 0.13.6, eslint-plugin-de-morgan to 2.2.0, and eslint-plugin-regexp to 3.3.1.

Full Changelog: Rel1cx/eslint-react@v5.20.5...v5.20.6

v5.20.5 (2026-09-21)

🐞 Fixes

  • react-web-api/no-leaked-fetch: fixed a false positive where an abort call nested in a callback within the cleanup function (e.g. setTimeout(() => ctrl.abort())) was not recognized, causing a spurious expectedAbortInCleanup report; the abort lookup now finds the nearest enclosing setup/cleanup function instead of requiring the innermost one. (#1962)

Full Changelog: Rel1cx/eslint-react@v5.20.4...v5.20.5

v5.20.4 (2026-09-21)

🐞 Fixes

  • react-web-api/no-leaked-event-listener: listeners that are only added inside the effect cleanup are now reported when the matching removeEventListener is in the setup (reversed setup/cleanup pairing), since a listener attached on unmount is never removed. (#1961)

🏗️ Internal

  • react-jsx and react-web-api rules: unified rule code style and variable naming across the plugins. (#1960, #1961)

... (truncated)

Commits
  • db7377e release: 5.20.8
  • 4d5c200 release: 5.20.7
  • 6ed4957 fix(react-x): comprehensive improvements to refs, purity, use-memo, i… (#1966)
  • 590bc2c chore(deps): update fumadocs to 16.15.12, tsl-dx to 0.13.6 and other deps
  • 878c65f refactor(var): split resolve into value-based resolve and origin-base… (#1964)
  • 22bf7c5 release: 5.20.5
  • 989b4a1 release: 5.20.4
  • 3a57ab3 release: 5.20.3
  • 4bba7bc refactor(ast): move getInnermostCall to its sole consumer in react-x
  • 8e5778e refactor(ast): replace getIdentifierAt with getMemberChain (#1959)
  • Additional commits viewable in compare view

Updates lint-staged from 17.4.1 to 17.5.1

Release notes

Sourced from lint-staged's releases.

v17.5.1

Patch Changes

  • #1852 bfcca94 - Fix TypeScript issue TS1254 from defineConfig() by changing the signature from const to a function:

    A 'const' initializer in an ambient context must be a string or numeric literal or literal enum reference.

v17.5.0

Minor Changes

  • #1847 f9063b7 - Lint-staged now refuses to run when files were staged with --intent-to-add, because Git stash doesn't support them. Previously this was an unhandled error.

Patch Changes

  • #1848 d718ccc - Lint-staged now handles color support better in non-TTY streams, and honors the FORCE_COLOR environment variable.

  • #1845 7e5ece8 - Update tinyexec@1.3.1 so that local binaries from node_modules/.bin are resolved starting from the directory of each lint-staged configuration file (in monorepo setups). This behavior was broken in lint-staged@16.3.0 where they were only resolved from the current working directory and up.

  • #1845 eb8a4e3 - Do not try to restore untracked files when using --hide-all and there is no initial commit yet.

Changelog

Sourced from lint-staged's changelog.

17.5.1

Patch Changes

  • #1852 bfcca94 - Fix TypeScript issue TS1254 from defineConfig() by changing the signature from const to a function:

    A 'const' initializer in an ambient context must be a string or numeric literal or literal enum reference.

17.5.0

Minor Changes

  • #1847 f9063b7 - Lint-staged now refuses to run when files were staged with --intent-to-add, because Git stash doesn't support them. Previously this was an unhandled error.

Patch Changes

  • #1848 d718ccc - Lint-staged now handles color support better in non-TTY streams, and honors the FORCE_COLOR environment variable.

  • #1845 7e5ece8 - Update tinyexec@1.3.1 so that local binaries from node_modules/.bin are resolved starting from the directory of each lint-staged configuration file (in monorepo setups). This behavior was broken in lint-staged@16.3.0 where they were only resolved from the current working directory and up.

  • #1845 eb8a4e3 - Do not try to restore untracked files when using --hide-all and there is no initial commit yet.

Commits
  • f8b1ab1 Merge pull request #1853 from lint-staged/changeset-release/main
  • 3b54961 chore(changeset): release
  • 09317ff Merge pull request #1852 from lint-staged/fix-ambient-declaration
  • bfcca94 fix: change defineConfig signature from const to a function
  • dcb59f6 Merge pull request #1846 from lint-staged/changeset-release/main
  • 9c8c6dc chore(changeset): release
  • 586466f Merge pull request #1849 from lint-staged/improve-intent-to-add
  • 45eda5f refactor: improve --intent-to-add detection
  • 26372e3 Merge pull request #1848 from lint-staged/fix-color-detection
  • d718ccc fix: honor FORCE_COLOR/NO_COLOR env variables in non-TTY streams
  • Additional commits viewable in compare view

@dependabot dependabot Bot added auto-merge Ready to automatically merge after being open for 48 hours dependencies [Dependabot Only] Pull requests that update a dependency file javascript [Dependabot Only] Pull requests that update Javascript code labels Oct 1, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 1, 2026 13:41
@dependabot dependabot Bot added dependencies [Dependabot Only] Pull requests that update a dependency file javascript [Dependabot Only] Pull requests that update Javascript code auto-merge Ready to automatically merge after being open for 48 hours labels Oct 1, 2026
@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
api-docs-tooling Ready Ready Preview Oct 3, 2026 2:09am UTC

Request Review

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Failed ❌

View logs ↗
ba8467a 2026-10-03T02:09:18.975Z View logs ↗
  • Build: Failed ❌

View logs ↗
84e88b8 2026-10-01T13:42:36.198Z View logs ↗

@codecov

codecov Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 92.64%. Comparing base (acc1e4a) to head (ba8467a).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #1129   +/-   ##
=======================================
  Coverage   92.64%   92.64%           
=======================================
  Files         244      244           
  Lines       23114    23114           
  Branches     2263     2263           
=======================================
  Hits        21413    21413           
  Misses       1692     1692           
  Partials        9        9           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

api-links Generator

Output: 1 file differs

apilinks.json
Expected values to be strictly deep-equal:
+ actual - expected
... Skipped lines

  {
    'Agent.defaultMaxSockets': 'https://github.com/{repository}/blob/HEAD/lib/_http_agent.js#L300',
    'Buffer.alloc': 'https://github.com/{repository}/blob/HEAD/lib/buffer.js#L454',
    'Buffer.allocUnsafe': 'https://github.com/{repository}/blob/HEAD/lib/buffer.js#L473',
    'Buffer.allocUnsafeSlow': 'https://github.com/{repository}/blob/HEAD/lib/buffer.js#L496',
...
    'agent.addRequest': 'https://github.com/{repository}/blob/HEAD/lib/_http_agent.js#L365',
+   'agent.createConnection': 'https://github.com/{repository}/blob/HEAD/lib/https.js#L354',
-   'agent.createConnection': 'https://github.com/{repository}/blob/HEAD/lib/_http_agent.js#L304',
    'agent.createSocket': 'https://github.com/{repository}/blob/HEAD/lib/_http_agent.js#L446',
    'agent.destroy': 'https://github.com/{repository}/blob/HEAD/lib/_http_agent.js#L679',
+   'agent.getName': 'https://github.com/{repository}/blob/HEAD/lib/https.js#L537',
+   'agent.keepSocketAlive': 'https://github.com/{repository}/blob/HEAD/lib/https.js#L506',
-   'agent.getName': 'https://github.com/{repository}/blob/HEAD/lib/_http_agent.js#L334',
-   'agent.keepSocketAlive': 'https://github.com/{repository}/blob/HEAD/lib/_http_agent.js#L635',
    'agent.removeSocket': 'https://github.com/{repository}/blob/HEAD/lib/_http_agent.js#L574',
    'agent.reuseSocket': 'https://github.com/{repository}/blob/HEAD/lib/_http_agent.js#L671',
    'assert.assert': 'https://github.com/{repository}/blob/HEAD/lib/assert.js#L185',
    'asyncResource.asyncId': 'https://github.com/{repository}/blob/HEAD/lib/async_hooks.js#L243',
    'asyncResource.bind': 'https://github.com/{repository}/blob/HEAD/lib/async_hooks.js#L275',
...
    'server.address': 'https://github.com/{repository}/blob/HEAD/lib/net.js#L2776',
+   'server.close': 'https://github.com/{repository}/blob/HEAD/lib/net.js#L2909',
+   'server.closeAllConnections': 'https://github.com/{repository}/blob/HEAD/lib/https.js#L125',
+   'server.closeIdleConnections': 'https://github.com/{repository}/blob/HEAD/lib/https.js#L127',
-   'server.close': 'https://github.com/{repository}/blob/HEAD/lib/_http_server.js#L697',
-   'server.closeAllConnections': 'https://github.com/{repository}/blob/HEAD/lib/_http_server.js#L707',
-   'server.closeIdleConnections': 'https://github.com/{repository}/blob/HEAD/lib/_http_server.js#L719',
    'server.getConnections': 'https://github.com/{repository}/blob/HEAD/lib/net.js#L2871',
    'server.listen': 'https://github.com/{repository}/blob/HEAD/lib/net.js#L2566',
    'server.ref': 'https://github.com/{repository}/blob/HEAD/lib/net.js#L3023',
+   'server.setTimeout': 'https://github.com/{repository}/blob/HEAD/lib/https.js#L129',
-   'server.setTimeout': 'https://github.com/{repository}/blob/HEAD/lib/_http_server.js#L735',
    'server.unref': 'https://github.com/{repository}/blob/HEAD/lib/net.js#L3032',
+   'server[SymbolAsyncDispose]': 'https://github.com/{repository}/blob/HEAD/lib/net.js#L2950',
-   'server[SymbolAsyncDispose]': 'https://github.com/{repository}/blob/HEAD/lib/_http_server.js#L703',
    'server[SymbolAsyncIterator]': 'https://github.com/{repository}/blob/HEAD/lib/net.js#L2957',
    'server[kDeserialize]': 'https://github.com/{repository}/blob/HEAD/lib/net.js#L2487',
    'server[kTransferList]': 'https://github.com/{repository}/blob/HEAD/lib/net.js#L2459',
    'server[kTransfer]': 'https://github.com/{repository}/blob/HEAD/lib/net.js#L2464',
+   'server[undefined]': 'https://github.com/{repository}/blob/HEAD/lib/net.js#L2987',
-   'server[undefined]': 'https://github.com/{repository}/blob/HEAD/lib/_http_server.js#L742',
    'serverresponse._finish': 'https://github.com/{repository}/blob/HEAD/lib/_http_server.js#L262',
    'serverresponse._implicitHeader': 'https://github.com/{repository}/blob/HEAD/lib/_http_server.js#L419',
    'serverresponse.assignSocket': 'https://github.com/{repository}/blob/HEAD/lib/_http_server.js#L312',
    'serverresponse.detachSocket': 'https://github.com/{repository}/blob/HEAD/lib/_http_server.js#L323',
    'serverresponse.statusCode': 'https://github.com/{repository}/blob/HEAD/lib/_http_server.js#L285',

Performance estimate (single CI run)

  • Generation time: 3.0% slower (1.35 s → 1.39 s)
  • Peak memory: 0.4% higher (426.75 MB → 428.51 MB)

json Generator

Performance estimate (single CI run)

  • Generation time: 32.0% slower (6.78 s → 8.95 s)
  • Peak memory: 7.5% lower (1.74 GB → 1.61 GB)

legacy-html Generator

Performance estimate (single CI run)

  • Generation time: 1.1% faster (43.60 s → 43.12 s)
  • Peak memory: 6.7% higher (2.29 GB → 2.44 GB)

legacy-json Generator

Performance estimate (single CI run)

  • Generation time: 1.3% faster (8.62 s → 8.51 s)
  • Peak memory: 13.1% lower (1.64 GB → 1.42 GB)

llms-txt Generator

Performance estimate (single CI run)

  • Generation time: 28.9% slower (7.13 s → 9.19 s)
  • Peak memory: 8.7% lower (1.53 GB → 1.39 GB)

orama-db Generator

Performance estimate (single CI run)

  • Generation time: 4.7% slower (8.10 s → 8.48 s)
  • Peak memory: 3.9% higher (1.53 GB → 1.59 GB)

web Generator

Performance estimate (single CI run)

  • Generation time: 41.3% faster (60.75 s → 35.68 s)
  • Peak memory: 26.4% higher (3.27 GB → 4.13 GB)

Bumps the lint group with 3 updates in the / directory: [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc), [eslint-plugin-react-x](https://github.com/Rel1cx/eslint-react/tree/HEAD/plugins/eslint-plugin-react-x) and [lint-staged](https://github.com/lint-staged/lint-staged).


Updates `eslint-plugin-jsdoc` from 64.3.1 to 64.5.4
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases)
- [Commits](gajus/eslint-plugin-jsdoc@v64.3.1...v64.5.4)

Updates `eslint-plugin-react-x` from 5.18.6 to 5.20.8
- [Release notes](https://github.com/Rel1cx/eslint-react/releases)
- [Changelog](https://github.com/Rel1cx/eslint-react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Rel1cx/eslint-react/commits/v5.20.8/plugins/eslint-plugin-react-x)

Updates `lint-staged` from 17.4.1 to 17.5.1
- [Release notes](https://github.com/lint-staged/lint-staged/releases)
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md)
- [Commits](lint-staged/lint-staged@v17.4.1...v17.5.1)

---
updated-dependencies:
- dependency-name: eslint-plugin-jsdoc
  dependency-version: 64.5.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: lint
- dependency-name: eslint-plugin-react-x
  dependency-version: 5.20.8
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: lint
- dependency-name: lint-staged
  dependency-version: 17.5.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: lint
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title meta: bump the lint group with 3 updates meta: bump the lint group across 1 directory with 3 updates Oct 3, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/lint-ae1162a5ec branch from 84e88b8 to ba8467a Compare October 3, 2026 02:08

This branch was successfully deployed

1 active deployment
Preview – api-docs-tooling — ba8467af Deployed Oct 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-merge Ready to automatically merge after being open for 48 hours dependencies [Dependabot Only] Pull requests that update a dependency file javascript [Dependabot Only] Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant