deps(ts): bump typescript-eslint from 8.61.1 to 8.66.0 in /frontend - #121
deps(ts): bump typescript-eslint from 8.61.1 to 8.66.0 in /frontend#121dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) from 8.61.1 to 8.66.0. - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.66.0/packages/typescript-eslint) --- updated-dependencies: - dependency-name: typescript-eslint dependency-version: 8.66.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
…v/brace-expansion/nanoid advisories (#127) Consolidates 8 of the 11 open Dependabot PRs into a single branch: - deps(rust): bytes 1.11.1 -> 1.12.1 (#124) - deps(rust): http-body-util 0.1.3 -> 0.1.4 (#122) - deps(rust): ruvector-sona 0.2.0 -> 0.2.1 (#120) - deps(ts): @hookform/resolvers 5.4.0 -> 5.7.1 (#125) - deps(ts): @playwright/test 1.62.0 -> 1.62.1 (#118) - deps(ts): @vitejs/plugin-react 6.0.2 -> 6.0.5 (#123) - deps(ts): typescript-eslint 8.60.0 -> 8.66.0 (#121) - deps(actions): taiki-e/install-action 2.85.4 -> 2.85.8 (#117) Deferred (left open, not applied): - #119 (@tanstack/react-table 8.21.3 -> 9.0.0): 8.21.3 is already the latest 8.x release, so this is a major-version rewrite, not a patch bump. - #116/#126 (candle-core/candle-transformers 0.10.2 -> 0.11.0): would create duplicate candle-core/candle-nn builds (0.10.2 pinned exactly by mistralrs, 0.11.0 for our direct use), which the existing Cargo.toml comment explicitly says the 0.10 pin exists to avoid. Blocked on a mistralrs release that supports candle 0.11. Security audit (cargo audit / pnpm audit / GitHub Dependabot alerts): - RUSTSEC-2026-0233/0234/0235 (rkyv 0.8.16 UAF + OOB reads via ruvector-core): fixed by bumping rkyv to 0.8.17 (in-range for ruvector-core's "0.8" req). - RUSTSEC-2026-0235 (rkyv 0.7.46 via rust_decimal's optional "rkyv" feature): documented in audit-ignore. Confirmed unreachable — nothing in the workspace enables rust_decimal's rkyv feature, and the edge persists even in a from-scratch `cargo generate-lockfile`, so the vulnerable path is never compiled. - GHSA-rgw5-rvv9-x895 (brace-expansion DoS, bypasses prior GHSA-jxxr-4gwj-5jf2 mitigation): pnpm override widened to >=4.0.0 <5.0.9 -> >=5.0.9. - GHSA-2v37-7h3g-55p8 (nanoid infinite loop on zero-size generator): pnpm override added, constrained to the 3.x line (postcss requires nanoid 3.x) since an unconstrained >=3.3.17 override resolves to a nanoid 6 major bump. - 0 open GitHub Dependabot alerts. Verification (all green): - cargo fmt --all -- --check - cargo clippy --workspace --all-targets -- -D warnings - cargo test --workspace (all crates, doctests included) - bash .github/scripts/cargo-audit.sh - pnpm install --frozen-lockfile - pnpm run lint / tsc --noEmit / prettier --check - pnpm run test -- --run - pnpm run build - pnpm audit
Bumps typescript-eslint from 8.61.1 to 8.66.0.
Release notes
Sourced from typescript-eslint's releases.
... (truncated)
Changelog
Sourced from typescript-eslint's changelog.
... (truncated)
Commits
e51b11bchore(release): publish 8.66.063ba81bchore(release): publish 8.65.0eaf4576feat: add warning when TS 7 is detected (#12529)0d06406chore: add attw validation to repo (#12437)c2386e4chore(deps): update dependency prettier to v3.9.5 (#12486)414d9abchore(release): publish 8.64.0290cf6cchore(release): publish 8.63.03ea32f4chore(release): publish 8.62.154e2857chore(release): publish 8.62.081e4c26feat: remove redundant package.json "files" (#12444)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)