Skip to content

fix(deps): update eslint (patch) - #1170

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/patch-eslint
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/patch-eslint

Conversation

@renovate

@renovate renovate Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
eslint (source) 10.8.0 → 10.8.1 age confidence
eslint (source) >=9.39.5 → >=10.0.3 age confidence
eslint-plugin-es-x 10.0.0 → 10.0.1 age confidence
eslint-plugin-jsonc (source) 3.4.1 → 3.4.2 age confidence
eslint-plugin-perfectionist (source) 5.10.0 → 5.10.1 age confidence
eslint-plugin-react-refresh 0.5.3 → 0.5.7 age confidence
eslint-plugin-react-you-might-not-need-an-effect 1.0.1 → 1.0.2 age confidence
eslint-plugin-sonarjs (source) 4.2.0 → 4.2.2 age confidence
eslint-plugin-sonarjs@<4.2.0 (source) >=4.2.0 → >=4.2.2 age confidence
eslint-plugin-storybook (source) 10.5.3 → 10.5.10 age confidence
eslint-plugin-tsdoc (source) 0.5.2 → 0.5.4 age confidence
eslint-plugin-zod (source) 4.9.0 → 4.9.1 age confidence

⚠️ Renovate does not enforce Minimum Release Age for bump, lockfileUpdate, or rollback updates, so these are raised without a Minimum Release Age check. You will need to manually validate the Minimum Release Age for these package(s).


Release Notes

eslint/eslint (eslint)

v10.8.1

Compare Source

Bug Fixes

  • 18eb0a7 fix: prevent ASI hazard in no-unused-labels autofix (#​21173) (dongkyu lee)
  • 151ba3f fix: false positives in getter-return and accessor-pairs (#​21163) (Grit)
  • 6898df9 fix: ignore meta-property names in id-denylist (#​21166) (Pixel)
  • 4d7db66 fix: ignore meta-property names in id-match (#​21167) (Pixel)
  • 677214e fix: handle ASI hazards in no-unused-vars removeVar suggestion (#​20935) (kuldeep kumar)

Documentation

  • 7d0cbf8 docs: Update README (GitHub Actions Bot)
  • 0a05812 docs: add missing backticks to no-duplicate-imports.js (#​21183) (Lee Daeun)
  • 678c90b docs: Update README (GitHub Actions Bot)
  • 8a10424 docs: Update README (GitHub Actions Bot)
  • 69bb948 docs: Update README (GitHub Actions Bot)

Chores

eslint-community/eslint-plugin-es-x (eslint-plugin-es-x)

v10.0.1

Compare Source

Patch Changes
  • fix: updates unicode resource (#​390)
ota-meshi/eslint-plugin-jsonc (eslint-plugin-jsonc)

v3.4.2

Compare Source

Patch Changes
azat-io/eslint-plugin-perfectionist (eslint-plugin-perfectionist)

v5.10.1

Compare Source

compare changes

🐞 Bug Fixes
  • Fix crash in typescript 7
    (fbbc372)
  • Fix complex comments cases not being auto-fixed correctly
    (7a35d8b)
  • Respect ignored callback dependencies in nested calls
    (c9a119e)
  • Take into account extended tsconfigs
    (93a267e)
❤️ Contributors
ArnaudBarre/eslint-plugin-react-refresh (eslint-plugin-react-refresh)

v0.5.7

Compare Source

Add allowCompoundComponents option (#​117)

Default: false (true in vite config)

Don't warn when components are exported as an object gathering them. Every member of the object must be a component, and a member holding an anonymous function requires a component name as key.

This should be enabled if the fast refresh implementation correctly handles this case. Vite supports it since @vitejs/plugin-react 4.7.0, @vitejs/plugin-react-swc 3.11.0.

{
  "react-refresh/only-export-components": [
    "error",
    { "allowCompoundComponents": true }
  ]
}

Enabling this option allows code such as the following:

const Root = () => <></>;
const Label = () => <></>;
export const Tag = { Root, Label };

v0.5.6

Compare Source

  • Support re-exporting namespace components (fixes #​116)

v0.5.5

Compare Source

  • Fix SCREAMING_SNAKE_CASE constant exported via export { Name } incorrectly treated as React component #​114 (fixes #​113)
  • Add contentType and size to allowExportNames in Next config #​115

v0.5.4

Compare Source

  • Add instant to allowExportNames in Next config #​112
nickjvandyke/eslint-plugin-react-you-might-not-need-an-effect (eslint-plugin-react-you-might-not-need-an-effect)

v1.0.2

Compare Source

Miscellaneous Chores
SonarSource/SonarJS (eslint-plugin-sonarjs)

v4.2.2

Compare Source

v4.2.1

Compare Source

storybookjs/storybook (eslint-plugin-storybook)

v10.5.10

Compare Source

v10.5.9

Compare Source

v10.5.8

Compare Source

v10.5.7

Compare Source

v10.5.6

Compare Source

v10.5.5

Compare Source

v10.5.4

Compare Source

microsoft/tsdoc (eslint-plugin-tsdoc)

v0.5.4

Tue, 29 Sep 2026 18:52:33 GMT

Version update only

v0.5.3

Wed, 16 Sep 2026 01:24:29 GMT

Patches
  • Declare eslint as an optional peer dependency so published typings resolve against the consumer's ESLint under non-hoisted installers.
marcalexiei/eslint-zod (eslint-plugin-zod)

v4.9.1

Compare Source

Patch Changes
  • #​376 b1f666a Thanks @​marcalexiei! - fix: consistent-import alias collision between two zod sources

    Every rewritten import group received the alias z, so a file importing from both zod and zod/v3 was fixed into two import * as z declarations.
    Each group now gets a distinct alias.

  • #​383 6b4122e Thanks @​marcalexiei! - fix: no-number-schema-with-safe, -finite and -step missed the deprecated method mid-chain

    All three required the deprecated call to be the last one in the chain, so z.number().safe().min(0) went unreported while z.number().safe() was flagged.
    -step additionally renamed the chain's outermost property, which would have rewritten .min() instead of .step().

  • #​379 dfa974b Thanks @​marcalexiei! - fix: no-conflicting-checks now recognises every deprecated chained string format

    .ipv4(), .guid(), .ksuid(), .uuidv4(), .xid() and others were missing
    from the rule's table, so conflicts involving them went unreported.

  • #​400 fb49a63 Thanks @​marcalexiei! - fix: no-conflicting-checks no longer flags a narrowed string format as impossible

    z.string().uuid().uuidv4() and z.string().guid().uuid() are refinements, not
    contradictions — the GUID/UUID family nests. Two different UUID versions still
    conflict.

    Also fixes no-number-schema-with-safe/-step/-finite matching the factory of
    an aliased import (import { number as safe }), and stops no-native-enum and
    prefer-string-schema-with-trim crashing on a computed factory.

  • #​376 b1f666a Thanks @​marcalexiei! - fix: no-any-schema crash on a computed factory call

    The rule threw on z['any']().
    It now reports the schema without a rename suggestion.

  • Updated dependencies [dfa974b, dfa974b, dfa974b, dfa974b, fb49a63, b1f666a, dfa974b, b1f666a, fb49a63, 4d8edae]:


Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • "after 1am and before 5am every weekend"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Signed-off-by: Renovate Bot <bot@renovateapp.com>
@renovate
renovate Bot requested a review from prisis as a code owner October 4, 2026 01:02
@renovate renovate Bot added the eslint label Oct 4, 2026
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Thank you for following the naming conventions! 🙏

@coderabbitai

coderabbitai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 31ce73ee-63a1-4d78-90ae-97bdbfa7253e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@socket-security

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants