Skip to content

chore(deps-dev): bump the development-dependencies group with 5 updates - #8262

Merged
dclstn merged 1 commit into
masterfrom
dependabot/npm_and_yarn/development-dependencies-0b33908d2a
Oct 6, 2026
Merged

dclstn merged 1 commit into
masterfrom
dependabot/npm_and_yarn/development-dependencies-0b33908d2a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor

Bumps the development-dependencies group with 5 updates:

Package From To
@eslint-react/eslint-plugin 5.21.1 5.23.5
eslint 10.11.0 10.12.0
globals 17.12.0 17.13.0
postcss-preset-env 11.5.4 11.6.0
vite 8.3.1 8.3.2

Updates @eslint-react/eslint-plugin from 5.21.1 to 5.23.5

Release notes

Sourced from @​eslint-react/eslint-plugin's releases.

v5.23.5 (2026-10-03)

What's Changed

🐞 Fixes

  • react-x/set-state-in-effect: the ref-derived value exemption now also covers setState calls reached indirectly through functions or hook callbacks invoked from the effect setup, not only setState written directly in the setup body. (#1982)
  • react-x/set-state-in-effect: more ref read shapes are recognized as ref-derived values — <ref-named>.current anywhere in a member chain, locals derived from other ref-derived locals, and reads through a ref/xxxRef parameter. (#1982)
  • react-web-api/no-leaked-event-listener: removeEventListener inside a function called from the effect cleanup now pairs with its addEventListener, fixing false positives for listeners removed on unmount; cleanup calls resolve to the actual functions, so same-named shadowed functions no longer pair by coincidence. (#1982)

🏗️ Internal

  • Bumped effect to 4.0.0 and migrated the repo scripts to the v4 APIs. (#1981)

Full Changelog: Rel1cx/eslint-react@v5.23.4...v5.23.5

Attestation

https://github.com/Rel1cx/eslint-react/attestations/52275386

v5.23.4 (2026-10-03)

What's Changed

🐞 Fixes

  • Added the missing react-x/static-components rule to the disable-experimental preset. (#1980)
  • Fixed type imports in react-x/exhaustive-deps and react-x/rules-of-hooks (RuleFeature is now imported from @eslint-react/eslint instead of @eslint-react/shared).

📝 Documentation

  • react-jsx/no-useless-fragment: clarified the scope of the allowExpressions option and unified experimental-rule callout wording across rule docs.
  • react-x: unified cross-rule references in rule docs to full rule names.
  • Removed low-relevance entries from the further reading sections of rule docs, and removed a redundant note about eslint being an optional peer dependency.
  • Fixed inaccuracies in internal documentation. (#1980)

🏗️ Internal

  • Adopted ts-pattern for type checks in @eslint-react/core, @eslint-react/jsx, and the react-dom plugin, and declared the missing ts-pattern dependencies.
  • Added behavior boundary tests for react-jsx/no-useless-fragment.
  • Bumped fumadocs-core, fumadocs-ui, and lucide-react in the website.

Full Changelog: Rel1cx/eslint-react@v5.23.3...v5.23.4

Attestation

https://github.com/Rel1cx/eslint-react/attestations/52237942

... (truncated)

Changelog

Sourced from @​eslint-react/eslint-plugin's changelog.

v5.23.5 (2026-10-03)

🐞 Fixes

  • react-x/set-state-in-effect: the ref-derived value exemption now also covers setState calls reached indirectly through functions or hook callbacks invoked from the effect setup, not only setState written directly in the setup body. (#1982)
  • react-x/set-state-in-effect: more ref read shapes are recognized as ref-derived values — <ref-named>.current anywhere in a member chain, locals derived from other ref-derived locals, and reads through a ref/xxxRef parameter. (#1982)
  • react-web-api/no-leaked-event-listener: removeEventListener inside a function called from the effect cleanup now pairs with its addEventListener, fixing false positives for listeners removed on unmount; cleanup calls resolve to the actual functions, so same-named shadowed functions no longer pair by coincidence. (#1982)

🏗️ Internal

  • Bumped effect to 4.0.0 and migrated the repo scripts to the v4 APIs. (#1981)

Full Changelog: Rel1cx/eslint-react@v5.23.4...v5.23.5

v5.23.4 (2026-10-03)

🐞 Fixes

  • Added the missing react-x/static-components rule to the disable-experimental preset. (#1980)
  • Fixed type imports in react-x/exhaustive-deps and react-x/rules-of-hooks (RuleFeature is now imported from @eslint-react/eslint instead of @eslint-react/shared).

📝 Documentation

  • react-jsx/no-useless-fragment: clarified the scope of the allowExpressions option and unified experimental-rule callout wording across rule docs.
  • react-x: unified cross-rule references in rule docs to full rule names.
  • Removed low-relevance entries from the further reading sections of rule docs, and removed a redundant note about eslint being an optional peer dependency.
  • Fixed inaccuracies in internal documentation. (#1980)

🏗️ Internal

  • Adopted ts-pattern for type checks in @eslint-react/core, @eslint-react/jsx, and the react-dom plugin, and declared the missing ts-pattern dependencies.
  • Added behavior boundary tests for react-jsx/no-useless-fragment.
  • Bumped fumadocs-core, fumadocs-ui, and lucide-react in the website.

Full Changelog: Rel1cx/eslint-react@v5.23.3...v5.23.4

v5.23.3 (2026-09-30)

🐞 Fixes

  • react-x/immutability: reassigning a binding that resolves to component props or state (value = value + "!", count++, including destructuring and for...of rebinding forms) is now reported as a direct mutation, matching upstream react-hooks/immutability; rebinding iterator or shallow-copy bindings remains allowed. (#1979)
  • react-x/set-state-in-effect: ref reads traced through intermediate local computations (ex: const dv = visible - prevVisible.current) are now recognized as ref-derived values, and a preceding early-return guard whose test is ref-derived (ex: if (dv === 0) return;) now exempts the setState calls that follow it — previously only setState nested directly inside a ref-gated if/conditional was exempted. Aligns with react-hooks 7.1.1. (#1979)

📝 Documentation

  • react-x/no-unstable-context-value: documented the React 19 <Context> provider detection heuristic and its name-based limitations. (#1979)
  • Updated the README badges to reference eslint-plugin-react-x.

Full Changelog: Rel1cx/eslint-react@v5.23.2...v5.23.3

... (truncated)

Commits
  • d13434b release: 5.23.5
  • 8db7dce release: 5.23.4
  • a6642d7 docs: remove redundant note about eslint as optional peer dependency
  • 4d35170 release: 5.23.3
  • 8b74307 docs: update README badges to reference eslint-plugin-react-x
  • b993085 release: 5.23.2
  • 0148902 chore: remove unused dependencies and fix phantom dependencies
  • 427feff release: 5.23.1
  • cdad818 release: 5.23.0
  • d0c3687 release: 5.22.1
  • Additional commits viewable in compare view

Updates eslint from 10.11.0 to 10.12.0

Release notes

Sourced from eslint's releases.

v10.12.0

Features

  • 4618052 feat: handle astral letters in new-cap (#21357) (sary)
  • 4ec5168 feat: allow SourceCode#getText() to accept tokens and comments (#21340) (electrohyun)

Bug Fixes

  • bc51eee fix: prefer-arrow-callback false positive in conditional test (#21373) (Daniel Pinto)
  • bbff86c fix: skip lines with multiple comments in max-lines-per-function (#21332) (xbinaryx)
  • efc4d6b fix: astral letters in consistent-return, no-eval, no-invalid-this (#21360) (lumir)
  • 93de066 fix: prefer-exponentiation-operator autofix for async function base (#21322) (Vladimir Babin)
  • 02e34ff fix: add missing space after else in curly autofix (#21355) (Pixel)
  • b14b8bc fix: correct id-length message for long private names (#21348) (Pixel)
  • 69aac01 fix: support TSFunctionType in getFunctionHeadLoc (#21335) (xbinaryx)
  • 686630e fix: no-loss-of-precision false positive with 0.e5 (#21337) (sethamus)

Documentation

  • 67eb586 docs: Update README (GitHub Actions Bot)
  • 5370d7e docs: clarify one-var separateRequires matches any require() call (#21192) (sethamus)
  • 8816c1d docs: Update README (GitHub Actions Bot)
  • 3d2e7ce docs: fix typo in no-unused-expressions documentation (#21346) (bytedoe)

Chores

  • 152067f chore: update ecosystem plugins (#21362) (ESLint Bot)
  • b56d58e chore: update github/codeql-action action to v4.38.2 (#21376) (renovate[bot])
  • bfaea12 perf: cache normalized config globals per languageOptions (#21364) (James Ross)
  • 322209e ci: avoid Nx cache in ecosystem tests and disable failing test (#21369) (Francesco Trotta)
  • d166567 chore: update dependency prettier to v3.9.9 (#21371) (renovate[bot])
  • 29585ce chore: update dependency eslint-plugin-expect-type to ^0.7.0 (#21359) (renovate[bot])
  • 39d79ba chore: update github/codeql-action action to v4.38.1 (#21354) (renovate[bot])
  • 182a6e9 chore: update dependency prettier to v3.9.8 (#21352) (renovate[bot])
  • f995127 chore: remove CLAUDE.md in favor of AGENTS.md (#21339) (Jarren)
  • b95fb6c chore: update dependency prettier to v3.9.7 (#21347) (renovate[bot])
  • 3782dd4 chore: update ecosystem plugins (#21342) (ESLint Bot)
Commits
  • a438ec3 10.12.0
  • 32a73f1 Build: changelog update for 10.12.0
  • bc51eee fix: prefer-arrow-callback false positive in conditional test (#21373)
  • bbff86c fix: skip lines with multiple comments in max-lines-per-function (#21332)
  • 152067f chore: update ecosystem plugins (#21362)
  • b56d58e chore: update github/codeql-action action to v4.38.2 (#21376)
  • 67eb586 docs: Update README
  • bfaea12 perf: cache normalized config globals per languageOptions (#21364)
  • 322209e ci: avoid Nx cache in ecosystem tests and disable failing test (#21369)
  • d166567 chore: update dependency prettier to v3.9.9 (#21371)
  • Additional commits viewable in compare view

Updates globals from 17.12.0 to 17.13.0

Release notes

Sourced from globals's releases.

v17.13.0

  • Update globals (2026-10-01) (#354) b007369

sindresorhus/globals@v17.12.0...v17.13.0

Commits

Updates postcss-preset-env from 11.5.4 to 11.6.0

Changelog

Sourced from postcss-preset-env's changelog.

11.6.0

October 2, 2026

11.5.5

October 1, 2026

Notable changes:

  • postcss-mixins now implements more of the current spec
  • many plugins now have bounds to prevent CPU starvation or OOM

All updates plugins:

Commits

Updates vite from 8.3.1 to 8.3.2

Release notes

Sourced from vite's releases.

v8.3.2

Bug Fixes

  • build: preload CSS correctly when renderBuiltUrl returns URLs with queries (#23611) (64e0a21)
  • bundled-dev: serve lazy chunk sourcemaps (#23026) (eb7aa9a)
  • bundled-dev: serve the rolldown runtime from the installed rolldown (#23568) (bc598a6)
  • deps: update all non-major dependencies (#23601) (9944fa6)
  • deps: update rolldown-related dependencies (#23602) (88c1741)
  • html: resolve percent-encoded srcset urls (#23609) (53f1ce7)
  • limit size of object and array printing via forwardConsole (#23565) (e64a587)
  • merge build.rolldownOptions.output.minify correctly (#23536) (bba3bb8)
  • optimize-deps: avoid "unsupported" warnings for browser:false mappings (#23590) (5e4b9ca)
  • optimizer: preserve excluded optional peer require fallbacks (#23600) (a2bd6fa)
  • pass queries to renderBuiltUrl (#23586) (744269e)
  • server: handle file watcher errors without crashing (#23503) (6894f5c)
  • server: release previous environments after initialization (#23499) (5a3a010)
  • ssr: encode whitespace in module runner sourceURL (#23513) (bbc8812)
  • worker: align worker urls in client and server when using terser (#23614) (24bd331)

Performance Improvements

  • avoid encoding intermediate source maps (#23461) (89574f6)
  • build: avoid quadratic link scan in the preload helper (#23510) (cf5c028)
  • only register time middleware when debug logging is enabled (#23621) (94d0080)

Documentation

  • fix dead og-image PNG links in vite6/vite7 changelog entries (#23594) (1929b4c)

Miscellaneous Chores

Code Refactoring

Tests

  • bundled-dev: accept a rolldown dev runtime with no helper imports (#23606) (634745d)
Changelog

Sourced from vite's changelog.

8.3.2 (2026-10-01)

Bug Fixes

  • build: preload CSS correctly when renderBuiltUrl returns URLs with queries (#23611) (64e0a21)
  • bundled-dev: serve lazy chunk sourcemaps (#23026) (eb7aa9a)
  • bundled-dev: serve the rolldown runtime from the installed rolldown (#23568) (bc598a6)
  • deps: update all non-major dependencies (#23601) (9944fa6)
  • deps: update rolldown-related dependencies (#23602) (88c1741)
  • html: resolve percent-encoded srcset urls (#23609) (53f1ce7)
  • limit size of object and array printing via forwardConsole (#23565) (e64a587)
  • merge build.rolldownOptions.output.minify correctly (#23536) (bba3bb8)
  • optimize-deps: avoid "unsupported" warnings for browser:false mappings (#23590) (5e4b9ca)
  • optimizer: preserve excluded optional peer require fallbacks (#23600) (a2bd6fa)
  • pass queries to renderBuiltUrl (#23586) (744269e)
  • server: handle file watcher errors without crashing (#23503) (6894f5c)
  • server: release previous environments after initialization (#23499) (5a3a010)
  • ssr: encode whitespace in module runner sourceURL (#23513) (bbc8812)
  • worker: align worker urls in client and server when using terser (#23614) (24bd331)

Performance Improvements

  • avoid encoding intermediate source maps (#23461) (89574f6)
  • build: avoid quadratic link scan in the preload helper (#23510) (cf5c028)
  • only register time middleware when debug logging is enabled (#23621) (94d0080)

Documentation

  • fix dead og-image PNG links in vite6/vite7 changelog entries (#23594) (1929b4c)

Miscellaneous Chores

Code Refactoring

Tests

  • bundled-dev: accept a rolldown dev runtime with no helper imports (#23606) (634745d)
Commits
  • 1003321 release: v8.3.2 (#23623)
  • 24bd331 fix(worker): align worker urls in client and server when using terser (#23614)
  • 94d0080 perf: only register time middleware when debug logging is enabled (#23621)
  • 89574f6 perf: avoid encoding intermediate source maps (#23461)
  • 5a3a010 fix(server): release previous environments after initialization (#23499)
  • 1929b4c docs: fix dead og-image PNG links in vite6/vite7 changelog entries (#23594)
  • 6894f5c fix(server): handle file watcher errors without crashing (#23503)
  • cf5c028 perf(build): avoid quadratic link scan in the preload helper (#23510)
  • bba3bb8 fix: merge build.rolldownOptions.output.minify correctly (#23536)
  • 5e4b9ca fix(optimize-deps): avoid "unsupported" warnings for browser:false mappings (...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the development-dependencies group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [@eslint-react/eslint-plugin](https://github.com/Rel1cx/eslint-react/tree/HEAD/plugins/eslint-plugin) | `5.21.1` | `5.23.5` |
| [eslint](https://github.com/eslint/eslint) | `10.11.0` | `10.12.0` |
| [globals](https://github.com/sindresorhus/globals) | `17.12.0` | `17.13.0` |
| [postcss-preset-env](https://github.com/csstools/postcss-plugins/tree/HEAD/plugin-packs/postcss-preset-env) | `11.5.4` | `11.6.0` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.3.1` | `8.3.2` |


Updates `@eslint-react/eslint-plugin` from 5.21.1 to 5.23.5
- [Release notes](https://github.com/Rel1cx/eslint-react/releases)
- [Changelog](https://github.com/Rel1cx/eslint-react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Rel1cx/eslint-react/commits/v5.23.5/plugins/eslint-plugin)

Updates `eslint` from 10.11.0 to 10.12.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.11.0...v10.12.0)

Updates `globals` from 17.12.0 to 17.13.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.12.0...v17.13.0)

Updates `postcss-preset-env` from 11.5.4 to 11.6.0
- [Changelog](https://github.com/csstools/postcss-plugins/blob/main/plugin-packs/postcss-preset-env/CHANGELOG.md)
- [Commits](https://github.com/csstools/postcss-plugins/commits/HEAD/plugin-packs/postcss-preset-env)

Updates `vite` from 8.3.1 to 8.3.2
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.2/packages/vite)

---
updated-dependencies:
- dependency-name: "@eslint-react/eslint-plugin"
  dependency-version: 5.23.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: eslint
  dependency-version: 10.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: globals
  dependency-version: 17.13.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: postcss-preset-env
  dependency-version: 11.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: vite
  dependency-version: 8.3.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026
@dclstn
dclstn merged commit 79e3afa into master Oct 6, 2026
1 check passed
@dclstn
dclstn deleted the dependabot/npm_and_yarn/development-dependencies-0b33908d2a branch October 6, 2026 15:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant