Repository navigation
chore(deps-dev): bump @typescript-eslint/eslint-plugin from 8.58.2 to 8.71.0 - #1352
dependabot[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Routine Dependabot dev-dependency bump of @typescript-eslint/eslint-plugin from ^8.58.2/8.32.1 to ^8.70.1, limited to package.json and package-lock.json. This is a devDependency used only for linting (not shipped in app code), the version jump is a minor bump within the same major version (8.x) with no breaking changes noted in the changelog, and the lockfile is internally consistent with the package.json change. No functional/application code is touched, so no correctness, security, or infra concerns apply here.
Bumps [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) from 8.58.2 to 8.71.0. - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/eslint-plugin) --- updated-dependencies: - dependency-name: "@typescript-eslint/eslint-plugin" dependency-version: 8.70.1 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
2599a92 to
2435b72
Compare
There was a problem hiding this comment.
Routine dependabot dev-dependency bump of @typescript-eslint/eslint-plugin from 8.58.2 to 8.71.0, with package-lock.json updated accordingly. This is a devDependency used only for linting, scoped and consistent with the stated purpose of the MR, and lockfile changes are the expected downstream effect of the package.json bump — no action needed.
## High Level Overview of Change
Quarterly batch dependency upgrade (2026-Q4). This PR consolidates the
open Dependabot dependency PRs **and** applies any further upgrades
needed to resolve the open Semgrep (DGE) supply-chain tickets that a
package upgrade can fix.
- **21** Dependabot PRs applied (Upgraded); **9** skipped
(peer-dependency or Node-engine conflicts — see the table).
- **0** Semgrep tickets needed an upgrade: the 4 new **Critical** axios
tickets (DGE-8416–8419, `axios ≥ 1.20.0`) are already satisfied on
`main` by the Q3 batch (No-op), and none are left open.
- Twelve of the applied PRs are major bumps, eight of them production
dependencies: `express` 5, `dotenv` 18,
`i18next-browser-languagedetector` 8, `i18next-http-backend` 4,
`react-helmet-async` 3, `react-error-boundary` 6, `vite-plugin-svgr` 5,
`tldts` 7.
> **Express 4 → 5 needed a server fix that CI does not catch — please
review it specifically.** Under Express 5 the production server crashed
on startup (`PathError: Missing parameter name at index 1: *`), because
`path-to-regexp` 8 no longer accepts a bare `*` route. No Jest test
loads `server/`, so `lint:ci`, `build`, `build-ts` and `test:ci` all
passed regardless. Two lines in `server/index.js` were changed to the
Express 5 syntax, and the server was started and probed in both
production and development modes (see Test Plan).
### Context of Change
Quarterly batch of the Dependabot PRs opened on 2026-10-01, plus the
Semgrep tickets a package upgrade can fix. Direct dependency versions
were bumped in `package.json`; `package-lock.json` was updated in place
(never regenerated from scratch). No `overrides` or `resolutions` were
added and no parent range was widened.
### Type of Change
- [ ] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [x] Breaking change (fix or feature that would cause existing
functionality to not work as expected)
- [ ] Refactor (non-breaking change that only restructures code)
- [ ] Tests (You added tests for code that already exists, or your new
feature included in this PR)
- [ ] Documentation Updates
- [ ] Translation Updates
- [ ] Release
"Breaking change" is checked because production dependencies cross major
versions (most notably `express` 5). User-facing behavior is unchanged.
### Codebase Modernization
N/A — no file conversions.
- [ ] Updated files to React Hooks
- [ ] Updated files to TypeScript
## Before / After
**`server/index.js`** — Express 5 route syntax (details in
`code-changes.md`):
```js
// before (Express 4)
app.get('*', (_req, res) => { res.sendFile(path.join(__dirname, '/../build/index.html')) })
app.use('*', (req, res) => { /* 404 */ })
// after (Express 5)
app.get('/{*splat}', (_req, res) => { res.sendFile(path.join(__dirname, '/../build/index.html')) })
app.use((req, res) => { /* 404 */ })
```
`/{*splat}` keeps matching `/` itself, as `*` did; `app.use` with no
path already matches every request.
**Prettier 3.9 reformat** — six files re-wrapped by `npm run lint`
(`--fix`), cosmetic only: `BasicInfoCard.test.tsx`, `AMMPool/utils.ts`,
`ConfBalanceTooltipIcon.tsx`, `Notification/index.tsx`,
`TransactionActionIcon.tsx`, `registerServiceWorker.js`.
**Lockfile** — 86 packages changed version, 44 added, 46 removed; most
of the churn is Express 5's own dependency tree (`router`,
`path-to-regexp` 8, `serve-static` 2, …).
All Semgrep tickets closed in Q3 were re-verified against this lockfile
and remain satisfied (e.g. `path-to-regexp` is now 8.4.2 and
`serve-static` 2.2.1, both outside their advisories' affected ranges).
## Test Plan
Run locally on Node 22.14:
- `npm run lint:ci` — passes
- `npm run build` — passes
- `npm run build-ts` — passes
- `npm run test:ci` — 292/293 suites, 1688/1726 tests pass; coverage
thresholds met. The only failure,
`src/containers/shared/test/amendmentUtils.test.ts` (38 tests), calls
the live VHS dev API (`vhs.dev.ripplex.io/v1/network/amendments/info`),
which was returning **HTTP 503** during the run; it fails identically on
an untouched `main` checkout. It is unrelated to this batch and should
pass once the endpoint recovers (or be mocked in a follow-up).
- **Express 5 server smoke test** (not covered by CI), with `node
server`:
- `NODE_ENV=production`: `/` → 200 `index.html`; `/transactions/ABC123`
→ 200 `index.html` (SPA fallback); `/api/v1/healthz` → 200 `success`.
- `NODE_ENV=development`: `/` → 200 (static); `/transactions/ABC123` →
404 `{"error":"route not found"}`; `/api/v1/does-not-exist` → 404.
## Superseded Dependabot PRs
| PR | Package | From | Asked for | Resolved | Status |
MajorVersionUpgrade |
|----|---------|------|-----------|----------|--------|---------------------|
| #1375 | ts-jest | 29.4.9 | 29.4.14 | 29.4.14 | Upgraded | No |
| #1374 | dotenv | 17.4.2 | 18.0.5 | 18.0.6 | Upgraded | Yes
([v18](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)) |
| #1373 | @testing-library/react | 13.4.0 | 16.3.3 | 16.3.3 | Upgraded |
Yes
([v14](https://github.com/testing-library/react-testing-library/releases/tag/v14.0.0),
[v15](https://github.com/testing-library/react-testing-library/releases/tag/v15.0.0),
[v16](https://github.com/testing-library/react-testing-library/releases/tag/v16.0.0))
|
| #1372 | compression | 1.8.1 | 1.8.2 | 1.8.2 | Upgraded | No |
| #1371 | stylelint-scss | 7.0.0 | 7.3.0 | 7.3.0 | Upgraded | No |
| #1370 | @babel/preset-react | 7.28.5 | 8.0.1 | 7.28.5 | Skipped (peer
dep conflict: requires `@babel/core ^8`; installed 7.29.7) | Yes
([v8](https://github.com/babel/babel/releases/tag/v8.0.0)) |
| #1369 | express | 4.22.3 | 5.2.1 | 5.2.1 | Upgraded (with
`server/index.js` route fix) | Yes
([v5](https://github.com/expressjs/express/releases/tag/v5.0.0),
[migration guide](https://expressjs.com/en/guide/migrating-5.html)) |
| #1368 | lint-staged | 15.5.2 | 17.6.0 | 15.5.2 | Skipped (engine
conflict: requires Node ≥ 22.22.1; repo allows `>=22.0.0` with
`engine-strict=true`) | Yes
([v16](https://github.com/lint-staged/lint-staged/releases/tag/v16.0.0),
[v17](https://github.com/lint-staged/lint-staged/releases/tag/v17.0.0))
|
| #1367 | @types/node | 22.19.17 | 26.6.4 | 22.19.17 | Skipped (runtime
is Node 22; Node 26 types would allow APIs missing at runtime) | Yes
([types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/node))
|
| #1366 | jest-environment-jsdom | 30.3.0 | 30.5.2 | 30.5.2 | Upgraded |
No |
| #1365 | i18next-browser-languagedetector | 7.2.2 | 8.2.1 | 8.2.1 |
Upgraded | Yes
([v8](https://github.com/i18next/i18next-browser-languageDetector/blob/master/CHANGELOG.md))
|
| #1364 | eslint-plugin-prettier | 5.5.5 | 5.5.6 | 5.5.6 | Upgraded | No
|
| #1363 | i18next-http-backend | 3.0.6 | 4.0.2 | 4.0.2 | Upgraded | Yes
([v4](https://github.com/i18next/i18next-http-backend/blob/master/CHANGELOG.md))
|
| #1362 | @typescript-eslint/parser | 8.58.2 | 8.71.0 | 8.71.1 |
Upgraded | No |
| #1361 | react / @types/react | 18.3.1 / 18.3.28 | 19.3.0 / 19.3.0 |
18.3.1 / 18.3.28 | Skipped (peer dep conflict: `react-query@3.39.3`, the
last v3, requires `react ≤ 18`) | Yes
([v19](https://github.com/facebook/react/releases/tag/v19.0.0),
[types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/react))
|
| #1360 | react-helmet-async | 2.0.5 | 3.0.0 | 3.0.0 | Upgraded | Yes
([v3](https://github.com/staylor/react-helmet-async/releases/tag/v3.0.0))
|
| #1359 | react-error-boundary | 4.1.2 | 6.1.6 | 6.1.6 | Upgraded | Yes
([v5](https://github.com/bvaughn/react-error-boundary/releases/tag/5.0.0),
[v6](https://github.com/bvaughn/react-error-boundary/releases/tag/6.0.0))
|
| #1358 | react-error-overlay | 6.0.11 | 6.1.0 | 6.1.0 | Upgraded | No |
| #1357 | vite-plugin-environment | 1.1.3 | 1.1.4 | 1.1.3 | Skipped
(peer dep conflict: requires `vite >= 8`; installed 7.3.6) | No |
| #1356 | prettier | 3.6.2 | 3.9.9 | 3.9.9 | Upgraded | No |
| #1355 | xrpl | 4.6.0 | 5.3.0 | 5.3.0 | Upgraded | Yes
([v5](https://github.com/XRPLF/xrpl.js/releases/tag/xrpl%405.0.0)) |
| #1354 | react-router | 7.18.4 | 8.4.0 | 7.18.4 | Skipped (peer dep
conflict: requires `react ≥ 19.2.7`, blocked by #1361; also Node ≥
22.22) | Yes
([v8](https://github.com/remix-run/react-router/releases/tag/react-router%408.0.0))
|
| #1353 | vite-plugin-svgr | 4.5.0 | 5.2.0 | 5.2.0 | Upgraded | Yes
([v5](https://github.com/pd4d10/vite-plugin-svgr/releases/tag/v5.0.0)) |
| #1352 | @typescript-eslint/eslint-plugin | 8.58.2 | 8.71.0 | 8.71.1 |
Upgraded | No |
| #1351 | react-i18next | 15.4.1 | 17.0.15 | 15.4.1 | Skipped (peer dep
conflict: requires `i18next ≥ 26.2.0`; installed 23.16.8) | Yes
([CHANGELOG](https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md))
|
| #1350 | babel-jest | 29.7.0 | 30.5.2 | 30.5.2 | Upgraded | Yes
([v30](https://jestjs.io/blog/2025/06/04/jest-30)) |
| #1349 | tldts | 6.1.86 | 7.4.16 | 7.4.16 | Upgraded | Yes
([v7](https://github.com/remusao/tldts/releases/tag/v7.0.0)) |
| #1348 | eslint-import-resolver-typescript | 4.4.4 | 4.4.5 | 4.4.5 |
Upgraded | No |
| #1347 | @babel/preset-env | 7.29.2 | 8.0.6 | 7.29.2 | Skipped (peer
dep conflict: requires `@babel/core ^8`; installed 7.29.7) | Yes
([v8](https://github.com/babel/babel/releases/tag/v8.0.0)) |
| #1346 | eslint-plugin-react-hooks | 4.6.2 | 7.1.1 | 4.6.2 | Skipped
(peer dep conflict: `eslint-config-airbnb@19.0.4`, the latest, requires
`^4.3.0`) | Yes
([CHANGELOG](https://github.com/facebook/react/blob/main/packages/eslint-plugin-react-hooks/CHANGELOG.md))
|
## Semgrep tickets
Out of scope (not package-upgrade-fixable; not addressed here):
DGE-4837, DGE-4839, DGE-4840, DGE-7803, DGE-7812 (code findings);
DGE-7802, DGE-7804 (config findings); DGE-4831, DGE-4834, DGE-4843,
DGE-7794 (`ripple/explorer-deploy`).
| Ticket | Package | From | Asked for | Resolved | Status |
MajorVersionUpgrade |
|--------|---------|------|-----------|----------|--------|---------------------|
| [DGE-8416](https://ripplelabs.atlassian.net/browse/DGE-8416) | axios |
1.20.0 | ≥ 1.20.0 | 1.20.0 | No-op (already satisfied on main since the
Q3 batch) | No |
| [DGE-8417](https://ripplelabs.atlassian.net/browse/DGE-8417) | axios |
1.20.0 | ≥ 1.20.0 | 1.20.0 | No-op (already satisfied on main since the
Q3 batch) | No |
| [DGE-8418](https://ripplelabs.atlassian.net/browse/DGE-8418) | axios |
1.20.0 | ≥ 1.20.0 | 1.20.0 | No-op (already satisfied on main since the
Q3 batch) | No |
| [DGE-8419](https://ripplelabs.atlassian.net/browse/DGE-8419) | axios |
1.20.0 | ≥ 1.20.0 | 1.20.0 | No-op (already satisfied on main since the
Q3 batch) | No |
No ticket required an upgrade that a Dependabot PR did not already
propose.
## Closing instructions
After merging, run `/batch-deps-upgrade close` to close the superseded
PRs and the resolved Semgrep tickets. It will close these **Upgraded**
Dependabot PRs — #1375, #1374, #1373, #1372, #1371, #1369, #1366, #1365,
#1364, #1363, #1362, #1360, #1359, #1358, #1356, #1355, #1353, #1352,
#1350, #1349, #1348 — and these **No-op** tickets: DGE-8416, DGE-8417,
DGE-8418, DGE-8419.
The following PRs were **Skipped** and should remain open so Dependabot
keeps rebasing them: #1370 (@babel/preset-react), #1368 (lint-staged),
#1367 (@types/node), #1361 (react / @types/react), #1357
(vite-plugin-environment), #1354 (react-router), #1351 (react-i18next),
#1347 (@babel/preset-env), #1346 (eslint-plugin-react-hooks). No Semgrep
tickets stay open.
|
Looks like @typescript-eslint/eslint-plugin is up-to-date now, so this is no longer needed. |
|
Superseded by the 2026-Q4 batch dependency upgrade: #1377 |
Bumps @typescript-eslint/eslint-plugin from 8.58.2 to 8.71.0.
Release notes
Sourced from @typescript-eslint/eslint-plugin's releases.
... (truncated)
Changelog
Sourced from @typescript-eslint/eslint-plugin's changelog.
... (truncated)
Commits
8695664chore(release): publish 8.71.099d759afeat(eslint-plugin): [no-unsafe-enum-assignment] add rule (#12732)ae3ac15docs(eslint-plugin): clarify checkTypePredicates assumptions (#12378)33824c1fix(eslint-plugin): [no-misused-promises] handle a return outside of any func...7e25db3fix(eslint-plugin): [no-unnecessary-type-assertion] specialize generic assert...8d7ab88test: order union constituents stably in RuleTester tests7fce912fix(eslint-plugin): [unbound-method] respectthis: voidon class propertiesce70016fix(eslint-plugin): [switch-exhaustiveness-check] always sort literal cases i...23d38cechore(release): publish 8.70.19d82e4bchore: expand eslint-plugin rules test files glob (#12878)