Skip to content

chore(deps): bump the npm-dependencies group with 7 updates - #1105

Merged
CasLubbers merged 2 commits into
mainfrom
dependabot/npm_and_yarn/npm-dependencies-210f69506d
Oct 6, 2026
Merged

CasLubbers merged 2 commits into
mainfrom
dependabot/npm_and_yarn/npm-dependencies-210f69506d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-dependencies group with 7 updates:

Package From To
@typescript-eslint/eslint-plugin 8.70.1 8.71.0
@typescript-eslint/parser 8.70.1 8.71.0
cspell 10.3.4 10.3.6
dotenv 18.0.3 18.0.5
globals 17.12.0 17.13.0
lint-staged 17.5.1 17.6.0
tsc-alias 1.9.5 1.9.7

Updates @typescript-eslint/eslint-plugin from 8.70.1 to 8.71.0

Release notes

Sourced from @​typescript-eslint/eslint-plugin's releases.

v8.71.0

8.71.0 (2026-09-28)

🚀 Features

  • eslint-plugin: [no-unsafe-enum-assignment] add rule (#12732)

🩹 Fixes

  • eslint-plugin: [switch-exhaustiveness-check] always sort literal cases in stable order (#12885)
  • eslint-plugin: [unbound-method] respect this: void on class properties (7fce9127d)
  • eslint-plugin: [no-unnecessary-type-assertion] specialize generic assertion report message (#12832)
  • eslint-plugin: [no-misused-promises] handle a return outside of any function (#12912)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Changelog

Sourced from @​typescript-eslint/eslint-plugin's changelog.

8.71.0 (2026-09-28)

🚀 Features

  • eslint-plugin: [no-unsafe-enum-assignment] add rule (#12732)

🩹 Fixes

  • eslint-plugin: [no-misused-promises] handle a return outside of any function (#12912)
  • eslint-plugin: [no-unnecessary-type-assertion] specialize generic assertion report message (#12832)
  • eslint-plugin: [unbound-method] respect this: void on class properties (7fce9127d)
  • eslint-plugin: [switch-exhaustiveness-check] always sort literal cases in stable order (#12885)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Commits
  • 8695664 chore(release): publish 8.71.0
  • 99d759a feat(eslint-plugin): [no-unsafe-enum-assignment] add rule (#12732)
  • ae3ac15 docs(eslint-plugin): clarify checkTypePredicates assumptions (#12378)
  • 33824c1 fix(eslint-plugin): [no-misused-promises] handle a return outside of any func...
  • 7e25db3 fix(eslint-plugin): [no-unnecessary-type-assertion] specialize generic assert...
  • 8d7ab88 test: order union constituents stably in RuleTester tests
  • 7fce912 fix(eslint-plugin): [unbound-method] respect this: void on class properties
  • ce70016 fix(eslint-plugin): [switch-exhaustiveness-check] always sort literal cases i...
  • See full diff in compare view

Updates @typescript-eslint/parser from 8.70.1 to 8.71.0

Release notes

Sourced from @​typescript-eslint/parser's releases.

v8.71.0

8.71.0 (2026-09-28)

🚀 Features

  • eslint-plugin: [no-unsafe-enum-assignment] add rule (#12732)

🩹 Fixes

  • eslint-plugin: [switch-exhaustiveness-check] always sort literal cases in stable order (#12885)
  • eslint-plugin: [unbound-method] respect this: void on class properties (7fce9127d)
  • eslint-plugin: [no-unnecessary-type-assertion] specialize generic assertion report message (#12832)
  • eslint-plugin: [no-misused-promises] handle a return outside of any function (#12912)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Changelog

Sourced from @​typescript-eslint/parser's changelog.

8.71.0 (2026-09-28)

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Commits

Updates cspell from 10.3.4 to 10.3.6

Release notes

Sourced from cspell's releases.

v10.3.6

Fixes

fix: Report unknown CSpell directives again (#9319)

Summary

cspell lint reports unknown in-document directives again, such as cspell:bad-dir, when --validate-directives or validateDirectives: true in the config asks for them. Since 9.1.0 they were found but never shown or counted.

  • --validate-directives and --no-validate-directives override the config setting.
  • An unknown directive counts as an issue, so cspell lint exits with an error, as it did before 9.1.0.
  • The JSON reporter, @cspell/cspell-json-reporter, includes them in its output again.
  • The default reporter and the JSON reporter now ask to receive directive issues. Other reporters still only get them if they ask for them.
  • The command-line flag is now applied as a setting, like --report, so it controls what is shown as well as what is checked.

fix(cspell-io): Keep redirected requests under the private root (#9329)

Summary

createRedirectProvider in cspell-io now only serves requests that map to a location under its private root. A request that would resolve outside the private root is refused with VFSErrorUnsupportedRequest, the same error as a request outside the public root.

  • Refused: a path that starts with a separator (/, \, %2F, %5C) right after the public root.
  • Now served from inside the private root: file names that look like a URL scheme or a drive, such as a:b.txt or C|. They used to resolve to a different URL.

cspell itself does not use createRedirectProvider. This affects projects that use cspell-io directly.

  • The part of the URL after the public root is resolved as a relative path under the private root, and the result is checked to be under the private root: same protocol, same host, and the same path prefix.
  • Results coming back from the private file system are checked the same way before they are shown under the public root.
  • The change is in commit 25359026e1.

... (truncated)

Changelog

Sourced from cspell's changelog.

v10.3.6 (2026-09-29)

Fixes

fix: Report unknown CSpell directives again (#9319)

Summary

cspell lint reports unknown in-document directives again, such as cspell:bad-dir, when --validate-directives or validateDirectives: true in the config asks for them. Since 9.1.0 they were found but never shown or counted.

  • --validate-directives and --no-validate-directives override the config setting.
  • An unknown directive counts as an issue, so cspell lint exits with an error, as it did before 9.1.0.
  • The JSON reporter, @cspell/cspell-json-reporter, includes them in its output again.
  • The default reporter and the JSON reporter now ask to receive directive issues. Other reporters still only get them if they ask for them.
  • The command-line flag is now applied as a setting, like --report, so it controls what is shown as well as what is checked.

fix(cspell-io): Keep redirected requests under the private root (#9329)

Summary

createRedirectProvider in cspell-io now only serves requests that map to a location under its private root. A request that would resolve outside the private root is refused with VFSErrorUnsupportedRequest, the same error as a request outside the public root.

  • Refused: a path that starts with a separator (/, \, %2F, %5C) right after the public root.
  • Now served from inside the private root: file names that look like a URL scheme or a drive, such as a:b.txt or C|. They used to resolve to a different URL.

cspell itself does not use createRedirectProvider. This affects projects that use cspell-io directly.

  • The part of the URL after the public root is resolved as a relative path under the private root, and the result is checked to be under the private root: same protocol, same host, and the same path prefix.
  • Results coming back from the private file system are checked the same way before they are shown under the public root.
  • The change is in commit 25359026e1.

... (truncated)

Commits
  • 8559198 v10.3.6
  • 72e1be3 chore: Prepare Release v10.3.6 (auto-deploy) (#9305)
  • e230ca0 test: Give time-limited RPC and worker tests room on slow runners (#9330)
  • 8eae6b6 fix: Report unknown CSpell directives again (#9319)
  • a5f5111 fix: Don't reuse cached results made with different command-line options (#9318)
  • 2f897be fix: --show-perf-summary shows where all of the run's time goes (#9307)
  • fe37b7b chore: Label per package, and bugs links to its open issues (#9309)
  • f37a244 v10.3.5
  • b36374c chore: Prepare Release v10.3.5 (auto-deploy) (#9277)
  • 93e55c0 fix(cspell-lib): shouldCheckDocument honors the forceCheck option (#9303)
  • Additional commits viewable in compare view

Updates dotenv from 18.0.3 to 18.0.5

Changelog

Sourced from dotenv's changelog.

18.0.5 (2026-09-30)

Changed

  • Fix missing typescript module declaration (#1068)
  • Improve performance for large .env files (#1066)

18.0.4 (2026-09-25)

Changed

  • import dotenv/config should default quiet: true (#1063)
Commits

Updates globals from 17.12.0 to 17.13.0

Release notes

Sourced from globals's releases.

v17.13.0

  • Update globals (2026-10-01) (#354) b007369

sindresorhus/globals@v17.12.0...v17.13.0

Commits

Updates lint-staged from 17.5.1 to 17.6.0

Release notes

Sourced from lint-staged's releases.

v17.6.0

Minor Changes

  • #1850 938d3f4 - Task functions like { title, task } can now use a logger function log() to emit output while the task runs. By default, the output will only be visible if the task fails, unless the --verbose option was used. Additionally, when the task rejects, the error will be shown in the output.

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*': {
    title: 'Fail if PDF files are committed',
    task: async (filepaths, { log }) => {
    const pdfFiles = filepaths.filter((f) => f.toLowerCase().endsWith('.pdf'))
    if (pdfFiles.length > 0) {
    log('PDF files should not be committed: %s', pdfFiles)
    throw new Error('Failed')
    }
    },
    },
    })

  • #1854 30562bc - lint-staged now stages changes to all tracked files modified by tasks, including files that weren’t originally staged or didn’t match the configured globs. This can happen when your task has side-effects, or it's a function that ignores the staged files like () => "prettier --write .".

    If you have unstaged changes in a file and the task also edits that file, your unstaged changes will be staged too. Use --hide-unstaged to hide your changes while tasks run.

Patch Changes

  • #1860 4296532 - The assignment of staged files to lint-staged configuration files (when using multiple, for example in a monorepo) has been rewritten to be more efficient. As a reminder, each staged file is assigned to exactly one configuration (the closest one), even if that config doesn't match the file in its globs.

  • #1861 c45f28a - Fix running parallel tasks for a single glob, when tasks are created by a function. Nesting one level of arrays inside an array of tasks will result in the inner tasks running in parallel. This behavior should now be consistent when creating tasks using functions. In the following example eslint and prettier will run in parallel (for all files, when any JS files are staged):

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*.js': () => [['eslint --max-warnings=0 .', 'prettier --list-different .']],
    })

  • #1859 f0ea69d - Various performance improvements from skipping redundant internal Git calls.

  • #1856 69d7d17 - Partially staged changes are hidden in a uniquely-named patch file to avoid multiple invocations of lint-staged overwriting it. This makes it safer to run lint-staged in multiple worktrees at the same time.

Changelog

Sourced from lint-staged's changelog.

17.6.0

Minor Changes

  • #1850 938d3f4 - Task functions like { title, task } can now use a logger function log() to emit output while the task runs. By default, the output will only be visible if the task fails, unless the --verbose option was used. Additionally, when the task rejects, the error will be shown in the output.

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*': {
    title: 'Fail if PDF files are committed',
    task: async (filepaths, { log }) => {
    const pdfFiles = filepaths.filter((f) => f.toLowerCase().endsWith('.pdf'))
    if (pdfFiles.length > 0) {
    log('PDF files should not be committed: %s', pdfFiles)
    throw new Error('Failed')
    }
    },
    },
    })

  • #1854 30562bc - lint-staged now stages changes to all tracked files modified by tasks, including files that weren’t originally staged or didn’t match the configured globs. This can happen when your task has side-effects, or it's a function that ignores the staged files like () => "prettier --write .".

    If you have unstaged changes in a file and the task also edits that file, your unstaged changes will be staged too. Use --hide-unstaged to hide your changes while tasks run.

Patch Changes

  • #1860 4296532 - The assignment of staged files to lint-staged configuration files (when using multiple, for example in a monorepo) has been rewritten to be more efficient. As a reminder, each staged file is assigned to exactly one configuration (the closest one), even if that config doesn't match the file in its globs.

  • #1861 c45f28a - Fix running parallel tasks for a single glob, when tasks are created by a function. Nesting one level of arrays inside an array of tasks will result in the inner tasks running in parallel. This behavior should now be consistent when creating tasks using functions. In the following example eslint and prettier will run in parallel (for all files, when any JS files are staged):

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*.js': () => [['eslint --max-warnings=0 .', 'prettier --list-different .']],
    })

  • #1859 f0ea69d - Various performance improvements from skipping redundant internal Git calls.

  • #1856 69d7d17 - Partially staged changes are hidden in a uniquely-named patch file to avoid multiple invocations of lint-staged overwriting it. This makes it safer to run lint-staged in multiple worktrees at the same time.

Commits
  • 48f9f4e Merge pull request #1857 from lint-staged/changeset-release/main
  • 16b2e21 chore(changeset): release
  • 195f156 docs: improve changeset
  • 0ba6261 fix: create hidden directory only when required
  • 66ac2de docs: fixes to changesets
  • 80af8d7 Merge pull request #1863 from lint-staged/fix-issues
  • e433488 fix: handle task editing a symlinked file to a regular file, and --fail-on-ch...
  • e5019b3 fix: handle trailing newlines when detecting changed files
  • 74efec8 ci: run Cygwin and MSYS2 tests on Node.js 26
  • 655b7dc fix: use TypeScript types instead of JSDoc
  • Additional commits viewable in compare view

Updates tsc-alias from 1.9.5 to 1.9.7

Release notes

Sourced from tsc-alias's releases.

v1.9.7(2026-09-30

Fixes #196

Full Changelog: justkey007/tsc-alias@v1.9.7...v1.9.7

v1.9.6(2026-09-30)

What's Changed

Full Changelog: justkey007/tsc-alias@v1.9.5...v1.9.6

Commits
  • 1c87891 1.9.7
  • 119fadc Merge pull request #285 from justkey007/issue196-2
  • 1e754dc fix: correctly resolve aliases between declaration files when using build wit...
  • 6d32952 1.9.6
  • 528be88 Merge pull request #282 from justkey007/issue196
  • 7d01d4f fix: correctly resolve aliases between declaration files when using build wit...
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the npm-dependencies group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.70.1` | `8.71.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.70.1` | `8.71.0` |
| [cspell](https://github.com/streetsidesoftware/cspell/tree/HEAD/packages/cspell) | `10.3.4` | `10.3.6` |
| [dotenv](https://github.com/motdotla/dotenv) | `18.0.3` | `18.0.5` |
| [globals](https://github.com/sindresorhus/globals) | `17.12.0` | `17.13.0` |
| [lint-staged](https://github.com/lint-staged/lint-staged) | `17.5.1` | `17.6.0` |
| [tsc-alias](https://github.com/justkey007/tsc-alias) | `1.9.5` | `1.9.7` |


Updates `@typescript-eslint/eslint-plugin` from 8.70.1 to 8.71.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.70.1 to 8.71.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/parser)

Updates `cspell` from 10.3.4 to 10.3.6
- [Release notes](https://github.com/streetsidesoftware/cspell/releases)
- [Changelog](https://github.com/streetsidesoftware/cspell/blob/main/packages/cspell/CHANGELOG.md)
- [Commits](https://github.com/streetsidesoftware/cspell/commits/v10.3.6/packages/cspell)

Updates `dotenv` from 18.0.3 to 18.0.5
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v18.0.3...v18.0.5)

Updates `globals` from 17.12.0 to 17.13.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.12.0...v17.13.0)

Updates `lint-staged` from 17.5.1 to 17.6.0
- [Release notes](https://github.com/lint-staged/lint-staged/releases)
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md)
- [Commits](lint-staged/lint-staged@v17.5.1...v17.6.0)

Updates `tsc-alias` from 1.9.5 to 1.9.7
- [Release notes](https://github.com/justkey007/tsc-alias/releases)
- [Commits](justkey007/tsc-alias@v1.9.5...v1.9.7)

---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: cspell
  dependency-version: 10.3.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-dependencies
- dependency-name: dotenv
  dependency-version: 18.0.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-dependencies
- dependency-name: globals
  dependency-version: 17.13.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: lint-staged
  dependency-version: 17.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: tsc-alias
  dependency-version: 1.9.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependabot dependencies Pull requests that update a dependency file labels Oct 5, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file dependabot labels Oct 5, 2026
@CasLubbers
CasLubbers merged commit 4412415 into main Oct 6, 2026
8 checks passed
@CasLubbers
CasLubbers deleted the dependabot/npm_and_yarn/npm-dependencies-210f69506d branch October 6, 2026 05:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependabot dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants