Skip to content

chore(deps-dev): bump the root-dev-dependencies group with 7 updates - #34

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/root-dev-dependencies-e3ceec9303
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/root-dev-dependencies-e3ceec9303

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps the root-dev-dependencies group with 7 updates:

Package From To
eslint 10.11.0 10.12.0
eslint-plugin-security 4.0.1 4.2.0
stylelint 17.15.0 17.16.0
typescript-eslint 8.70.1 8.71.0
supertest 7.3.0 7.3.1
msw 2.15.0 3.0.1
vite 8.3.1 8.3.2

Updates eslint from 10.11.0 to 10.12.0

Release notes

Sourced from eslint's releases.

v10.12.0

Features

  • 4618052 feat: handle astral letters in new-cap (#21357) (sary)
  • 4ec5168 feat: allow SourceCode#getText() to accept tokens and comments (#21340) (electrohyun)

Bug Fixes

  • bc51eee fix: prefer-arrow-callback false positive in conditional test (#21373) (Daniel Pinto)
  • bbff86c fix: skip lines with multiple comments in max-lines-per-function (#21332) (xbinaryx)
  • efc4d6b fix: astral letters in consistent-return, no-eval, no-invalid-this (#21360) (lumir)
  • 93de066 fix: prefer-exponentiation-operator autofix for async function base (#21322) (Vladimir Babin)
  • 02e34ff fix: add missing space after else in curly autofix (#21355) (Pixel)
  • b14b8bc fix: correct id-length message for long private names (#21348) (Pixel)
  • 69aac01 fix: support TSFunctionType in getFunctionHeadLoc (#21335) (xbinaryx)
  • 686630e fix: no-loss-of-precision false positive with 0.e5 (#21337) (sethamus)

Documentation

  • 67eb586 docs: Update README (GitHub Actions Bot)
  • 5370d7e docs: clarify one-var separateRequires matches any require() call (#21192) (sethamus)
  • 8816c1d docs: Update README (GitHub Actions Bot)
  • 3d2e7ce docs: fix typo in no-unused-expressions documentation (#21346) (bytedoe)

Chores

  • 152067f chore: update ecosystem plugins (#21362) (ESLint Bot)
  • b56d58e chore: update github/codeql-action action to v4.38.2 (#21376) (renovate[bot])
  • bfaea12 perf: cache normalized config globals per languageOptions (#21364) (James Ross)
  • 322209e ci: avoid Nx cache in ecosystem tests and disable failing test (#21369) (Francesco Trotta)
  • d166567 chore: update dependency prettier to v3.9.9 (#21371) (renovate[bot])
  • 29585ce chore: update dependency eslint-plugin-expect-type to ^0.7.0 (#21359) (renovate[bot])
  • 39d79ba chore: update github/codeql-action action to v4.38.1 (#21354) (renovate[bot])
  • 182a6e9 chore: update dependency prettier to v3.9.8 (#21352) (renovate[bot])
  • f995127 chore: remove CLAUDE.md in favor of AGENTS.md (#21339) (Jarren)
  • b95fb6c chore: update dependency prettier to v3.9.7 (#21347) (renovate[bot])
  • 3782dd4 chore: update ecosystem plugins (#21342) (ESLint Bot)
Commits
  • a438ec3 10.12.0
  • 32a73f1 Build: changelog update for 10.12.0
  • bc51eee fix: prefer-arrow-callback false positive in conditional test (#21373)
  • bbff86c fix: skip lines with multiple comments in max-lines-per-function (#21332)
  • 152067f chore: update ecosystem plugins (#21362)
  • b56d58e chore: update github/codeql-action action to v4.38.2 (#21376)
  • 67eb586 docs: Update README
  • bfaea12 perf: cache normalized config globals per languageOptions (#21364)
  • 322209e ci: avoid Nx cache in ecosystem tests and disable failing test (#21369)
  • d166567 chore: update dependency prettier to v3.9.9 (#21371)
  • Additional commits viewable in compare view

Updates eslint-plugin-security from 4.0.1 to 4.2.0

Release notes

Sourced from eslint-plugin-security's releases.

eslint-plugin-security: v4.2.0

4.2.0 (2026-10-01)

Features

eslint-plugin-security: v4.1.0

4.1.0 (2026-09-16)

Features

Bug Fixes

Changelog

Sourced from eslint-plugin-security's changelog.

4.2.0 (2026-10-01)

Features

4.1.0 (2026-09-16)

Features

Bug Fixes

Commits

Updates stylelint from 17.15.0 to 17.16.0

Release notes

Sourced from stylelint's releases.

17.16.0

It fixes 2 bugs in the layout-mappings rules. This will likely be the last 17.x release, as we prepare for 18.0.0.

  • Fixed: property-layout-mappings and unit-layout-mappings false negatives for uppercase property names and units (#9485) (@​giaBaoJS).
  • Fixed: value-keyword-layout-mappings false positives for caption-side (#9483) (@​giaBaoJS).
Changelog

Sourced from stylelint's changelog.

17.16.0 - 2026-10-01

It fixes 2 bugs in the layout-mappings rules. This will likely be the last 17.x release, as we prepare for 18.0.0.

  • Fixed: property-layout-mappings and unit-layout-mappings false negatives for uppercase property names and units (#9485) (@​giaBaoJS).
  • Fixed: value-keyword-layout-mappings false positives for caption-side (#9483) (@​giaBaoJS).
Commits
  • bc06c7c Release 17.16.0 (#9551)
  • f4fb76f Set target-branch to v18 in Dependabot config (#9488)
  • 2019478 Fix property-layout-mappings and unit-layout-mappings false negatives for...
  • e875710 Fix value-keyword-layout-mappings false positives for caption-side (#9483)
  • See full diff in compare view

Updates typescript-eslint from 8.70.1 to 8.71.0

Release notes

Sourced from typescript-eslint's releases.

v8.71.0

8.71.0 (2026-09-28)

🚀 Features

  • eslint-plugin: [no-unsafe-enum-assignment] add rule (#12732)

🩹 Fixes

  • eslint-plugin: [switch-exhaustiveness-check] always sort literal cases in stable order (#12885)
  • eslint-plugin: [unbound-method] respect this: void on class properties (7fce9127d)
  • eslint-plugin: [no-unnecessary-type-assertion] specialize generic assertion report message (#12832)
  • eslint-plugin: [no-misused-promises] handle a return outside of any function (#12912)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Changelog

Sourced from typescript-eslint's changelog.

8.71.0 (2026-09-28)

This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Commits

Updates supertest from 7.3.0 to 7.3.1

Release notes

Sourced from supertest's releases.

v7.3.1

  • Merge pull request #907 from JH8459/fix/ephemeral-loopback-bind 884cd26
  • fix: bind ephemeral server to the loopback address it connects to e74a1e0

forwardemail/supertest@v7.3.0...v7.3.1

Commits
  • 3634bdd 7.3.1
  • 884cd26 Merge pull request #907 from JH8459/fix/ephemeral-loopback-bind
  • e74a1e0 fix: bind ephemeral server to the loopback address it connects to
  • See full diff in compare view

Updates msw from 2.15.0 to 3.0.1

Release notes

Sourced from msw's releases.

v3.0.1 (2026-09-30)

Bug Fixes

  • treat CONNECT requests as the transport mechanism (#2796) (7cad86a03b0ddb2efdec96ce8a49b0ed07d9f4dc) @​kettanaito

v3.0.0 (2026-09-28)

⚠️ BREAKING CHANGES

  • MSW is now ESM-only (#2765).
  • Deprecate support for Node.js v18 and v20 (#2729). The minimal supported Node.js version is v22.
  • msw/native is removed in favor of @msw/react-native.
  • Require TypeScript 5.9 as the minimal version.
  • Deprecate support for TypeScript 5.1 and 5.2 (#2730)
  • worker.stop() returns a Promise (#2724). Awaiting it is relevant only for in-flight critical scenarios.
  • graphql is now exported as msw/graphql (#2691). GraphQL is now handled as a proper optional peer dependency.
  • Removes the handleRequest() utility. Please use the defineNetwork() API instead.
  • GraphQLLinkHandlers type has been renamed to GraphQLLink.
  • The file:// requests now throw in Node.js as they normally do (not supported by fetch).
  • The Content-Length request header is now removed by bypass().
  • HTTP-to-WebSocket upgrade requests performed via fetch() now throw in Node.js as they normally do (not supported by fetch).
  • Cookies are no longer managed in Node.js for better compatibilty. Instead, whatever is the default behavior of your environment that's the cookie behavior you get. This has no effect on the browser.
  • WebSocket connection life cycle event has been renamed to websocket:connection (#2783).
  • onUnhandledRequest option has been renamed to onUnhandledFrame.
  • The library no longer patches setTimeout to circumvent fake timers in test runners. You should advance the fake timers normally for delayed mocked responses to resolve.
  • The library no longer returns a mocked cookie string on request.headers.get('cookie') in the handlers. It returns null in all environments. Please use the cookies resolver argument to have cookie-based logic.

Features

  • Supports Node.js v24 and v26.
  • Supports TypeScript v6.0 and v7.0.
  • You can import individual utilities, like delay or passthrough, from the new msw/utils entrypoint for smaller footprint on your bundle.
  • Support GraphQL v17.0.
  • Support intercepting page navigations and form submissions (#2721).
  • Support GraphQL subscriptions (#285, #2763).
  • Migrate from path-to-regexp to @msw/url (#2678).
  • Remove the following dependencies:
    • graphql
    • path-to-regexp
    • picocolors
    • statuses
    • strict-event-emitter
  • Adds a Vite plugin for MSW (#2781).
  • Adds a websocket:error life cycle event to listen to WebSocket connection errors (#2784).
  • Support modifying the intercepted request headers in passthrough scenarios (#2786).
  • Support a new WebSocket Extension API that allows for better custom experiences (#2791).

... (truncated)

Commits

Updates vite from 8.3.1 to 8.3.2

Release notes

Sourced from vite's releases.

v8.3.2

Bug Fixes

  • build: preload CSS correctly when renderBuiltUrl returns URLs with queries (#23611) (64e0a21)
  • bundled-dev: serve lazy chunk sourcemaps (#23026) (eb7aa9a)
  • bundled-dev: serve the rolldown runtime from the installed rolldown (#23568) (bc598a6)
  • deps: update all non-major dependencies (#23601) (9944fa6)
  • deps: update rolldown-related dependencies (#23602) (88c1741)
  • html: resolve percent-encoded srcset urls (#23609) (53f1ce7)
  • limit size of object and array printing via forwardConsole (#23565) (e64a587)
  • merge build.rolldownOptions.output.minify correctly (#23536) (bba3bb8)
  • optimize-deps: avoid "unsupported" warnings for browser:false mappings (#23590) (5e4b9ca)
  • optimizer: preserve excluded optional peer require fallbacks (#23600) (a2bd6fa)
  • pass queries to renderBuiltUrl (#23586) (744269e)
  • server: handle file watcher errors without crashing (#23503) (6894f5c)
  • server: release previous environments after initialization (#23499) (5a3a010)
  • ssr: encode whitespace in module runner sourceURL (#23513) (bbc8812)
  • worker: align worker urls in client and server when using terser (#23614) (24bd331)

Performance Improvements

  • avoid encoding intermediate source maps (#23461) (89574f6)
  • build: avoid quadratic link scan in the preload helper (#23510) (cf5c028)
  • only register time middleware when debug logging is enabled (#23621) (94d0080)

Documentation

  • fix dead og-image PNG links in vite6/vite7 changelog entries (#23594) (1929b4c)

Miscellaneous Chores

Code Refactoring

Tests

  • bundled-dev: accept a rolldown dev runtime with no helper imports (#23606) (634745d)
Changelog

Sourced from vite's changelog.

8.3.2 (2026-10-01)

Bug Fixes

  • build: preload CSS correctly when renderBuiltUrl returns URLs with queries (#23611) (64e0a21)
  • bundled-dev: serve lazy chunk sourcemaps (#23026) (eb7aa9a)
  • bundled-dev: serve the rolldown runtime from the installed rolldown (#23568) (bc598a6)
  • deps: update all non-major dependencies (#23601) (9944fa6)
  • deps: update rolldown-related dependencies (#23602) (88c1741)
  • html: resolve percent-encoded srcset urls (#23609) (53f1ce7)
  • limit size of object and array printing via forwardConsole (#23565) (e64a587)
  • merge build.rolldownOptions.output.minify correctly (#23536) (bba3bb8)
  • optimize-deps: avoid "unsupported" warnings for browser:false mappings (#23590) (5e4b9ca)
  • optimizer: preserve excluded optional peer require fallbacks (#23600) (a2bd6fa)
  • pass queries to renderBuiltUrl (#23586) (744269e)
  • server: handle file watcher errors without crashing (#23503) (6894f5c)
  • server: release previous environments after initialization (#23499) (5a3a010)
  • ssr: encode whitespace in module runner sourceURL (#23513) (bbc8812)
  • worker: align worker urls in client and server when using terser (#23614) (24bd331)

Performance Improvements

  • avoid encoding intermediate source maps (#23461) (89574f6)
  • build: avoid quadratic link scan in the preload helper (#23510) (cf5c028)
  • only register time middleware when debug logging is enabled (#23621) (94d0080)

Documentation

  • fix dead og-image PNG links in vite6/vite7 changelog entries (#23594) (1929b4c)

Miscellaneous Chores

Code Refactoring

Tests

  • bundled-dev: accept a rolldown dev runtime with no helper imports (#23606) (634745d)
Commits
  • 1003321 release: v8.3.2 (#23623)
  • 24bd331 fix(worker): align worker urls in client and server when using terser (#23614)
  • 94d0080 perf: only register time middleware when debug logging is enabled (#23621)
  • 89574f6 perf: avoid encoding intermediate source maps (#23461)
  • 5a3a010 fix(server): release previous environments after initialization (#23499)
  • 1929b4c docs: fix dead og-image PNG links in vite6/vite7 changelog entries (#23594)
  • 6894f5c fix(server): handle file watcher errors without crashing (#23503)
  • cf5c028 perf(build): avoid quadratic link scan in the preload helper (#23510)
  • bba3bb8 fix: merge build.rolldownOptions.output.minify correctly (#23536)
  • 5e4b9ca fix(optimize-deps): avoid "unsupported" warnings for browser:false mappings (...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the root-dev-dependencies group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [eslint](https://github.com/eslint/eslint) | `10.11.0` | `10.12.0` |
| [eslint-plugin-security](https://github.com/eslint-community/eslint-plugin-security) | `4.0.1` | `4.2.0` |
| [stylelint](https://github.com/stylelint/stylelint) | `17.15.0` | `17.16.0` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.70.1` | `8.71.0` |
| [supertest](https://github.com/ladjs/supertest) | `7.3.0` | `7.3.1` |
| [msw](https://github.com/mswjs/msw) | `2.15.0` | `3.0.1` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.3.1` | `8.3.2` |


Updates `eslint` from 10.11.0 to 10.12.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.11.0...v10.12.0)

Updates `eslint-plugin-security` from 4.0.1 to 4.2.0
- [Release notes](https://github.com/eslint-community/eslint-plugin-security/releases)
- [Changelog](https://github.com/eslint-community/eslint-plugin-security/blob/main/CHANGELOG.md)
- [Commits](eslint-community/eslint-plugin-security@eslint-plugin-security-v4.0.1...eslint-plugin-security-v4.2.0)

Updates `stylelint` from 17.15.0 to 17.16.0
- [Release notes](https://github.com/stylelint/stylelint/releases)
- [Changelog](https://github.com/stylelint/stylelint/blob/main/CHANGELOG.md)
- [Commits](stylelint/stylelint@17.15.0...17.16.0)

Updates `typescript-eslint` from 8.70.1 to 8.71.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/typescript-eslint)

Updates `supertest` from 7.3.0 to 7.3.1
- [Release notes](https://github.com/ladjs/supertest/releases)
- [Commits](forwardemail/supertest@v7.3.0...v7.3.1)

Updates `msw` from 2.15.0 to 3.0.1
- [Release notes](https://github.com/mswjs/msw/releases)
- [Changelog](https://github.com/mswjs/msw/blob/main/CHANGELOG.md)
- [Commits](mswjs/msw@v2.15.0...v3.0.1)

Updates `vite` from 8.3.1 to 8.3.2
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.2/packages/vite)

---
updated-dependencies:
- dependency-name: eslint
  dependency-version: 10.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: root-dev-dependencies
- dependency-name: eslint-plugin-security
  dependency-version: 4.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: root-dev-dependencies
- dependency-name: stylelint
  dependency-version: 17.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: root-dev-dependencies
- dependency-name: typescript-eslint
  dependency-version: 8.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: root-dev-dependencies
- dependency-name: supertest
  dependency-version: 7.3.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: root-dev-dependencies
- dependency-name: msw
  dependency-version: 3.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: root-dev-dependencies
- dependency-name: vite
  dependency-version: 8.3.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: root-dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026
@dependabot
dependabot Bot requested a review from orbivort as a code owner October 5, 2026 23:38
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026
@orbivort orbivort closed this Oct 8, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/root-dev-dependencies-e3ceec9303 branch October 8, 2026 04:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant