Skip to content

chore(deps): update eslint monorepo to v10 - #83

Merged
github-actions[bot] merged 1 commit into
mainfrom
renovate/major-eslint-monorepo
Oct 10, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
renovate/major-eslint-monorepo

Conversation

@renovate

@renovate renovate Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@eslint/js (source) ^9.39.5 → ^10.0.1 age confidence
eslint (source) ^9.0.0 → ^10.12.0 age confidence

Release Notes

eslint/eslint (@​eslint/js)

v10.0.1

Compare Source

Bug Fixes

Documentation

  • 5b3dbce docs: add AI acknowledgement section to templates (#​20431) (루밀LuMir)
  • 6f23076 docs: toggle nav in no-JS mode (#​20476) (Tanuj Kanti)
  • b69cfb3 docs: Update README (GitHub Actions Bot)

Chores

v10.0.0

Compare Source

Breaking Changes

  • f9e54f4 feat!: estimate rule-tester failure location (#​20420) (ST-DDT)
  • a176319 feat!: replace chalk with styleText and add color to ResultsMeta (#​20227) (루밀LuMir)
  • c7046e6 feat!: enable JSX reference tracking (#​20152) (Pixel998)
  • fa31a60 feat!: add name to configs (#​20015) (Kirk Waiblinger)
  • 3383e7e fix!: remove deprecated SourceCode methods (#​20137) (Pixel998)
  • 501abd0 feat!: update dependency minimatch to v10 (#​20246) (renovate[bot])
  • ca4d3b4 fix!: stricter rule tester assertions for valid test cases (#​20125) (唯然)
  • 96512a6 fix!: Remove deprecated rule context methods (#​20086) (Nicholas C. Zakas)
  • c69fdac feat!: remove eslintrc support (#​20037) (Francesco Trotta)
  • 208b5cc feat!: Use ScopeManager#addGlobals() (#​20132) (Milos Djermanovic)
  • a2ee188 fix!: add uniqueItems: true in no-invalid-regexp option (#​20155) (Tanuj Kanti)
  • a89059d feat!: Program range span entire source text (#​20133) (Pixel998)
  • 39a6424 fix!: assert 'text' is a string across all RuleFixer methods (#​20082) (Pixel998)
  • f28fbf8 fix!: Deprecate "always" and "as-needed" options of the radix rule (#​20223) (Milos Djermanovic)
  • aa3fb2b fix!: tighten func-names schema (#​20119) (Pixel998)
  • f6c0ed0 feat!: report eslint-env comments as errors (#​20128) (Francesco Trotta)
  • 4bf739f fix!: remove deprecated LintMessage#nodeType and TestCaseError#type (#​20096) (Pixel998)
  • 523c076 feat!: drop support for jiti < 2.2.0 (#​20016) (michael faith)
  • 454a292 feat!: update eslint:recommended configuration (#​20210) (Pixel998)
  • 4f880ee feat!: remove v10_* and inactive unstable_* flags (#​20225) (sethamus)
  • f18115c feat!: no-shadow-restricted-names report globalThis by default (#​20027) (sethamus)
  • c6358c3 feat!: Require Node.js ^20.19.0 || ^22.13.0 || >=24 (#​20160) (Milos Djermanovic)

Features

  • bff9091 feat: handle Array.fromAsync in array-callback-return (#​20457) (Francesco Trotta)
  • 290c594 feat: add self to no-implied-eval rule (#​20468) (sethamus)
  • 43677de feat: fix handling of function and class expression names in no-shadow (#​20432) (Milos Djermanovic)
  • f0cafe5 feat: rule tester add assertion option requireData (#​20409) (fnx)
  • f7ab693 feat: output RuleTester test case failure index (#​19976) (ST-DDT)
  • 7cbcbf9 feat: add countThis option to max-params (#​20236) (Gerkin)
  • f148a5e feat: add error assertion options (#​20247) (ST-DDT)
  • 09e6654 feat: update error loc of require-yield and no-useless-constructor (#​20267) (Tanuj Kanti)

Bug Fixes

  • 436b82f fix: update eslint (#​20473) (renovate[bot])
  • 1d29d22 fix: detect default this binding in Array.fromAsync callbacks (#​20456) (Francesco Trotta)
  • 727451e fix: fix regression of global mode report range in strict rule (#​20462) (ntnyq)
  • e80485f fix: remove fake FlatESLint and LegacyESLint exports (#​20460) (Francesco Trotta)
  • 9eeff3b fix: update esquery (#​20423) (cryptnix)
  • b34b938 fix: use Error.prepareStackTrace to estimate failing test location (#​20436) (Francesco Trotta)
  • 51aab53 fix: update eslint (#​20443) (renovate[bot])
  • 23490b2 fix: handle space before colon in RuleTester location estimation (#​20433) (Francesco Trotta)
  • f244dbf fix: use MessagePlaceholderData type from @eslint/core (#​20348) (루밀LuMir)
  • d186f8c fix: update eslint (#​20427) (renovate[bot])
  • 2332262 fix: error location should not modify error message in RuleTester (#​20421) (Milos Djermanovic)
  • ab99b21 fix: ensure filename is passed as third argument to verifyAndFix() (#​20405) (루밀LuMir)
  • 8a60f3b fix: remove ecmaVersion and sourceType from ParserOptions type (#​20415) (Pixel998)
  • eafd727 fix: remove TDZ scope type (#​20231) (jaymarvelz)
  • 39d1f51 fix: correct Scope typings (#​20404) (sethamus)
  • 2bd0f13 fix: update verify and verifyAndFix types (#​20384) (Francesco Trotta)
  • ba6ebfa fix: correct typings for loadESLint() and shouldUseFlatConfig() (#​20393) (루밀LuMir)
  • e7673ae fix: correct RuleTester typings (#​20105) (Pixel998)
  • 53e9522 fix: strict removed formatters check (#​20241) (ntnyq)
  • b017f09 fix: correct no-restricted-import messages (#​20374) (Francesco Trotta)

Documentation

  • e978dda docs: Update README (GitHub Actions Bot)
  • 4cecf83 docs: Update README (GitHub Actions Bot)
  • c79f0ab docs: Update README (GitHub Actions Bot)
  • 773c052 docs: Update README (GitHub Actions Bot)
  • f2962e4 docs: document meta.docs.frozen property (#​20475) (Pixel998)
  • 8e94f58 docs: fix broken anchor links from gerund heading updates (#​20449) (Copilot)
  • 1495654 docs: Update README (GitHub Actions Bot)
  • 0b8ed5c docs: document support for :is selector alias (#​20454) (sethamus)
  • 1c4b33f docs: Document policies about ESM-only dependencies (#​20448) (Milos Djermanovic)
  • 3e5d38c docs: add missing indentation space in rule example (#​20446) (fnx)
  • 63a0c7c docs: Update README (GitHub Actions Bot)
  • 65ed0c9 docs: Update README (GitHub Actions Bot)
  • b0e4717 docs: [no-await-in-loop] Expand inapplicability (#​20363) (Niklas Hambüchen)
  • fca421f docs: Update README (GitHub Actions Bot)
  • d925c54 docs: update config syntax in no-lone-blocks (#​20413) (Pixel998)
  • 7d5c95f docs: remove redundant sourceType: "module" from rule examples (#​20412) (Pixel998)
  • 02e7e71 docs: correct .mts glob pattern in files with extensions example (#​20403) (Ali Essalihi)
  • 264b981 docs: Update README (GitHub Actions Bot)
  • 5a4324f docs: clarify "local" option of no-unused-vars (#​20385) (Milos Djermanovic)
  • e593aa0 docs: improve clarity, grammar, and wording in documentation site README (#​20370) (Aditya)
  • 3f5062e docs: Add messages property to rule meta documentation (#​20361) (Sabya Sachi)
  • 9e5a5c2 docs: remove Examples headings from rule docs (#​20364) (Milos Djermanovic)
  • 194f488 docs: Update README (GitHub Actions Bot)
  • 0f5a94a docs: [class-methods-use-this] explain purpose of rule (#​20008) (Kirk Waiblinger)
  • df5566f docs: add Options section to all rule docs (#​20296) (sethamus)
  • adf7a2b docs: no-unsafe-finally note for generator functions (#​20330) (Tom Pereira)
  • ef7028c docs: Update README (GitHub Actions Bot)
  • fbae5d1 docs: consistently use "v10.0.0" in migration guide (#​20328) (Pixel998)
  • 778aa2d docs: ignoring default file patterns (#​20312) (Tanuj Kanti)
  • 4b5dbcd docs: reorder v10 migration guide (#​20315) (Milos Djermanovic)
  • 5d84a73 docs: Update README (GitHub Actions Bot)
  • 37c8863 docs: fix incorrect anchor link in v10 migration guide (#​20299) (Pixel998)
  • 077ff02 docs: add migrate-to-10.0.0 doc (#​20143) (唯然)
  • 3822e1b docs: Update README (GitHub Actions Bot)

Build Related

  • 9f08712 Build: changelog update for 10.0.0-rc.2 (Jenkins)
  • 1e2c449 Build: changelog update for 10.0.0-rc.1 (Jenkins)
  • c4c72a8 Build: changelog update for 10.0.0-rc.0 (Jenkins)
  • 7e4daf9 Build: changelog update for 10.0.0-beta.0 (Jenkins)
  • a126a2a build: add .scss files entry to knip (#​20389) (Francesco Trotta)
  • f5c0193 Build: changelog update for 10.0.0-alpha.1 (Jenkins)
  • 165326f Build: changelog update for 10.0.0-alpha.0 (Jenkins)

Chores


Configuration

📅 Schedule: (in timezone Europe/London)

  • Branch creation
    • Between 12:00 AM and 06:59 AM, only on Monday (* 0-6 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from rishitank as a code owner September 26, 2026 06:59
@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 78f93ebc-3306-49ce-9743-1d5afcefcf76

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions
github-actions Bot enabled auto-merge (squash) September 26, 2026 06:59
@renovate
renovate Bot force-pushed the renovate/major-eslint-monorepo branch 4 times, most recently from 5e5f262 to 97673ab Compare October 5, 2026 22:06
rishitank added a commit that referenced this pull request Oct 8, 2026
…; hold TypeScript 7

- simple-git ^3 -> ^4.0.2: GHSA-858h-whjf-mvg5, GHSA-g4wm-2vf7-vfgr,
  GHSA-x6jw-m9v5-85vh and @simple-git/argv-parser GHSA-v5rq-49vh-5v5c are
  fixed only in 4.x (Renovate #85 / Dependabot #91 show it is compatible).
- vitest and @vitest/coverage-v8 ^3 -> ^4.1.11 together: GHSA-82fw-gwwq-j7x9
  (vitest/@vitest/mocker) and tinypool GHSA-5gmw-xhrv-c9v3 /
  GHSA-85c8-ppgw-ccpr. coverage-v8 peers the exact vitest version, which is
  why #74 (vitest only) and #82 (coverage-v8 5 only) each fail npm ci.
- @eslint/js is imported by eslint.config.js but was never declared; it
  only resolved because eslint 9 depends on it. ESLint 10 no longer does
  (#83), so declare it explicitly.
- renovate.json: hold TypeScript 7 (typescript-eslint 8.x peers
  typescript <6.1.0, #84) and group vitest with @vitest/* so they can't
  split again.
- Lockfile refreshed on a runner by the one-shot deps-refresh-once workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi
github-actions Bot added a commit that referenced this pull request Oct 8, 2026
…simple-git 4 and vitest 4 (#94)

* ci: add shared security scan and actionlint workflows

- security.yml: osv-scanner and full-history gitleaks via
  rishitank/.github security.yml@v1 (ecosystem node). Runs alongside the
  existing CodeQL and npm audit jobs in ci.yml, which stay as they are.
- workflows-lint.yml: actionlint via the shared workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

* chore(renovate): extend the house preset instead of config:base

config:base is deprecated (renamed config:recommended), and
matchPackagePatterns is deprecated in favour of regex entries in
matchPackageNames. Switch the base to github>rishitank/.github:node
(which already includes config:recommended) and convert the patterns to
/regex/ matchPackageNames. Both custom packageRules are kept.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

* chore(deps): override tsup's esbuild; prepare an in-range lockfile refresh

- package.json: override tsup's esbuild to ^0.28.1. tsup 8.5.1 asks for
  ^0.27.0, and GHSA-g7r4-m6w7-qqqr affects esbuild >=0.27.3 <0.28.1, so no
  0.27.x fix exists. `npm run build` passes with 0.28.2.
- .github/workflows/deps-refresh-once.yml: one-shot runner job running
  `npm update` within the declared ranges. This clears hono, ip-address,
  js-yaml, minimatch, nanoid, path-to-regexp, picomatch, postcss,
  proxy-addr, qs, rollup, sharp, source-map-js and vite. Checked locally on
  the refreshed lock: typecheck, lint (same 22 warnings as before, 0
  errors), all 240 tests and the build pass. Deleted in the next commit.

Not fixable here without a major upgrade: simple-git 3 -> 4
(GHSA-858h-whjf-mvg5, GHSA-g4wm-2vf7-vfgr, GHSA-x6jw-m9v5-85vh; Renovate
#85/#91) and vitest/@vitest/coverage-v8 3 -> 4.1.11+ (GHSA-82fw-gwwq-j7x9,
plus tinypool through vitest; Renovate #74/#82).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

* chore(deps): refresh lockfile to pick up patched versions

Ran on a runner by the one-shot deps-refresh-once workflow: npm update --package-lock-only --ignore-scripts --no-audit --no-fund

* ci: remove the one-shot deps-refresh-once workflow

It refreshed package-lock.json in ed5ae35 (`npm update` within the
declared ranges, tsup's esbuild override applied). This commit is what
runs CI against the refreshed lockfile.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

* fix(deps): simple-git 4, vitest + coverage-v8 4.1, declare @eslint/js; hold TypeScript 7

- simple-git ^3 -> ^4.0.2: GHSA-858h-whjf-mvg5, GHSA-g4wm-2vf7-vfgr,
  GHSA-x6jw-m9v5-85vh and @simple-git/argv-parser GHSA-v5rq-49vh-5v5c are
  fixed only in 4.x (Renovate #85 / Dependabot #91 show it is compatible).
- vitest and @vitest/coverage-v8 ^3 -> ^4.1.11 together: GHSA-82fw-gwwq-j7x9
  (vitest/@vitest/mocker) and tinypool GHSA-5gmw-xhrv-c9v3 /
  GHSA-85c8-ppgw-ccpr. coverage-v8 peers the exact vitest version, which is
  why #74 (vitest only) and #82 (coverage-v8 5 only) each fail npm ci.
- @eslint/js is imported by eslint.config.js but was never declared; it
  only resolved because eslint 9 depends on it. ESLint 10 no longer does
  (#83), so declare it explicitly.
- renovate.json: hold TypeScript 7 (typescript-eslint 8.x peers
  typescript <6.1.0, #84) and group vitest with @vitest/* so they can't
  split again.
- Lockfile refreshed on a runner by the one-shot deps-refresh-once workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

* chore(deps): refresh lockfile to pick up patched versions

Ran on a runner by the one-shot deps-refresh-once workflow: npm install --package-lock-only --ignore-scripts --no-audit --no-fund

* ci: remove the one-shot deps-refresh-once workflow

Its job is done: a5e9414 committed the lockfile resolved on a runner.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@renovate
renovate Bot force-pushed the renovate/major-eslint-monorepo branch from 97673ab to 32f3b73 Compare October 8, 2026 23:16
@renovate renovate Bot added dependencies Pull requests that update a dependency file major-upgrade labels Oct 8, 2026
@renovate renovate Bot changed the title chore(deps): update dependency eslint to v10 chore(deps): update eslint monorepo to v10 Oct 8, 2026
@renovate
renovate Bot force-pushed the renovate/major-eslint-monorepo branch from 32f3b73 to eebead7 Compare October 8, 2026 23:19

@rishitank rishitank left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Self-review by Claude

Checked the ESLint 10 bump. The manifest and lockfile are consistent, and lint and CI are green. Nothing to fix.

@renovate
renovate Bot force-pushed the renovate/major-eslint-monorepo branch from eebead7 to e428d65 Compare October 9, 2026 01:45
@renovate
renovate Bot force-pushed the renovate/major-eslint-monorepo branch from e428d65 to 3ffbf71 Compare October 10, 2026 02:12
@github-actions
github-actions Bot merged commit 16cde2f into main Oct 10, 2026
14 checks passed
@renovate
renovate Bot deleted the renovate/major-eslint-monorepo branch October 10, 2026 02:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file major-upgrade

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant