Skip to content

chore(deps-dev): bump eslint-config-next from 16.3.3 to 16.3.4 - #36

Closed
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/dev/eslint-config-next-16.3.4
Closed

dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/dev/eslint-config-next-16.3.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor

Bumps eslint-config-next from 16.3.3 to 16.3.4.

Release notes

Sourced from eslint-config-next's releases.

v16.3.4

Follow-up release to v16.3.3 re-enabling AVIF Image Optimization (#97949).

The following bug fixes have been backported. It does not include all pending features/changes on canary.

  • testmode: Fix infinite recursion in testmode passthrough fetch (#97691)
  • Fix build error when aliasing typescript to @​typescript/typescript6 (#97997)
  • Fix unset crossOrigin in Turbopack manifests (#97930)

Credits

Huge thanks to @​eps1lon, @​mischnic, and @​timneutkens for helping!

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) from 16.3.3 to 16.3.4.
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.3.4/packages/eslint-config-next)

---
updated-dependencies:
- dependency-name: eslint-config-next
  dependency-version: 16.3.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 7, 2026
@dependabot
dependabot Bot requested a review from CountableNewt as a code owner September 7, 2026 19:58
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 7, 2026
CountableNewt pushed a commit that referenced this pull request Sep 25, 2026
## Problem and change

The September dependency PRs cannot merge because npm-based Dependabot updates omit `bun.lock`, the artifact scan depends on filesystem ordering, and new Automerge/Swift setup versions require compatibility fixes. This candidate combines all 18 valid updates, regenerates the Bun graph, and preserves the working Rust 1.98 toolchain.

- Web: Next 16.3.4, React 19.3.0, Starlight 0.42 with Astro >=7.2.10, Vitest 5, ESLint Next 16.3.4, Bun types 1.4.1, and React Testing Library 16.3.3.
- Rust: Automerge 0.12 in both lockfiles, Iroh 1.2, UUID 1.26.1, and Tower HTTP 0.7.1. Replace the deprecated string accessor with its equivalent current API.
- Native/CI: AGP 9.4.1, Kotlin 2.4.20, Compose BOM 2026.09.00, Swift HTTP Types 1.8, Java setup v6, and Swift setup v3 with official signing keys imported before signature verification.
- Reliability: deterministic artifact diagnostics with an order-independence regression test, explicit Node 24 for Vitest, Rust optional-feature Clippy/tests, and native Bun Dependabot support.

## Verification

The new artifact-order regression fails against the original implementation and passes with the fix. Frozen Bun installation, the repository policy test suite, and full `bun run verify` pass from a clean snapshot with the exact Development CI environment. This covers generated contracts, Railway validation, license/secret policies, 100% domain line/function coverage, static/privacy tests, typecheck, lint, all web builds, tests, and release-artifact origin checks. All 30 required CI checks passed on `3357275267ed1bfb06d17ebc60fa6681091b1949`: https://github.com/Stygian-Tech/atelier/actions/runs/36196572070. This includes optional-feature Rust Clippy/tests, coverage gates, Swift services, Android, Apple builds, every container, database isolation tests, and Development/Production web artifact checks. No check bypasses or reduced coverage gates.

React type packages are aligned to 19.3 across the web workspace to avoid incompatible duplicate type identities. An initial local Astro build failure was traced to unrelated ancestor-directory dependencies; the clean snapshot passes without an application workaround.

## Scope and closeout

Tracks ATE-21: https://linear.app/stygian-tech/issue/ATE-21/review-and-merge-september-dependabot-updates-into-dev

Consolidates #30, #31, #32, #35, #36, #37, #38, #41, #42, #43, #44, #46, #47, #48, #49, #50, and #51. Those PRs will be closed only after this candidate passes protected merge and their exact changes are verified in dev. #33 requests unavailable Rust 1.120.0 and will be closed with its rustup 404 evidence, retaining 1.98.

Targets dev only. No main promotion, Production provisioning, DNS changes, store uploads, or database migrations. Rollback is a normal revert of the merged dependency change. Vitest, Iroh, and Swift setup major/runtime transitions are covered by the expanded CI suite.
@CountableNewt

Copy link
Copy Markdown
Contributor

Completed in #45, merged to dev as 6f2b695. Verified this PR head (9f5f236) still matches the reviewed patch and every added dependency line is present in merged dev. All 30 required checks passed on the equivalent candidate tree (run 36196572070), with full local verification. Closing this superseded PR; tracked in ATE-21.

@dependabot @github

dependabot Bot commented on behalf of github Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/dev/eslint-config-next-16.3.4 branch September 25, 2026 22:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant