build(deps-dev): bump the npm-dependencies group across 1 directory with 2 updates - #64
Conversation
…ith 2 updates Bumps the npm-dependencies group with 2 updates in the / directory: [eslint](https://github.com/eslint/eslint) and [typescript](https://github.com/microsoft/TypeScript). Updates `eslint` from 10.9.1 to 10.10.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.9.1...v10.10.0) Updates `typescript` from 6.0.3 to 7.0.2 - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](microsoft/TypeScript@v6.0.3...v7.0.2) --- updated-dependencies: - dependency-name: eslint dependency-version: 10.10.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
|
❌ Claude's run did not complete (outcome: failure). View job run |
There was a problem hiding this comment.
Verdict: changes requested — this PR breaks CI as-is.
This is a Dependabot dependency-group bump (eslint 10.9.1→10.10.0, typescript 6.0.3→7.0.2). The eslint bump is fine on its own, but bundling in the typescript major bump breaks the build: typescript-eslint is left at 8.69.0 in the same diff, whose own peer dependency (recorded in package-lock.json) requires typescript: >=4.8.4 <6.1.0 — well below 7.0.2.
This isn't a theoretical incompatibility. On this PR's own head commit, npm ci itself fails with ERESOLVE (While resolving: typescript-eslint@8.69.0 / Found: typescript@7.0.2), and as a direct result every check that depends on install succeeding — Lint, Typecheck, Format, Commitlint, and the aggregating Required Checks gate — is currently failure on this PR.
See the inline comment on package.json for the detail and the options I'd weigh (hold typescript back to typescript-eslint's supported range and take only the eslint bump, versus pairing this with a typescript-eslint upgrade that actually supports TS 7.x, if one exists — I couldn't confirm that in this session, so I'm flagging the conflict rather than prescribing which fix to take).
No @claude fix prompt included: resolving this is a dependency-compatibility decision (which package to hold back, or which paired version to take), not a drop-in code fix.
I didn't find anything to change in the PR title/description — Dependabot's own generated text is accurate for what's actually in the diff.
| "semantic-release": "25.0.9", | ||
| "turbo": "2.10.12", | ||
| "typescript": "6.0.3", | ||
| "typescript": "7.0.2", |
There was a problem hiding this comment.
🔴 Blocker [policy] — this bump breaks CI outright, confirmed on this PR's own head commit.
typescript-eslint stays at 8.69.0 in this same diff, and that version's own recorded peer dependency (visible in the package-lock.json diff, e.g. @typescript-eslint/typescript-estree, @typescript-eslint/eslint-plugin, @typescript-eslint/utils) is:
"peerDependencies": { "typescript": ">=4.8.4 <6.1.0" }
Bumping typescript here to 7.0.2 (a major version) falls well outside that range. This isn't theoretical — the PR's own check runs on this exact commit confirm it: Lint, Typecheck, Format, Commitlint, and Required Checks are all failure, and the Lint/Typecheck job logs both fail at npm ci with:
npm error code ERESOLVE
npm error ERESOLVE could not resolve
npm error
npm error While resolving: typescript-eslint@8.69.0
npm error Found: typescript@7.0.2
I could not verify whether a newer typescript-eslint release supports TypeScript 7.x (the lookup I tried to confirm this wasn't available to me in this session), so I'm not recommending a specific replacement version rather than guessing. Options as I see them: hold typescript back to the highest version typescript-eslint@8.69.0's peer range allows (<6.1.0) and take only the eslint 10.9.1→10.10.0 bump in this PR, or bump typescript-eslint to whatever version (if any) actually supports TS 7.x alongside this change. Either way, this combination can't merge as-is — every downstream check that depends on npm ci succeeding is currently red on this PR.
|
🗜️ Headroom context compression
|
Bumps the npm-dependencies group with 2 updates in the / directory: eslint and typescript.
Updates
eslintfrom 10.9.1 to 10.10.0Release notes
Sourced from eslint's releases.
Commits
3f20a5710.10.0f4e5284Build: changelog update for 10.10.0bb47dc6fix: update dependency file-entry-cache to v11 (#20801)427ac0afix: use format strings in debug calls (#21247)b3d876bchore: disable npm audit in ecosystem tests (#21306)9d81532fix: support__proto__in/* exported */comments (#21261)264b434feat: adddandvflags tono-unexpected-multiline(#21305)1696682ci: restore EMFILE test on Node.js 26 (#21297)2c7f5d6chore: update github/codeql-action action to v4.37.9 (#21296)87e0a08fix: prefer-object-has-own autofix breaks when Object is shadowed (#21282)Updates
typescriptfrom 6.0.3 to 7.0.2Release notes
Sourced from typescript's releases.
Commits
1e4744dMerge branch 'main' into ts7-releasea5a219cmicrosoft/typescript-go#4558ecfe30dUpdate status localization5de25b5Hide executable name in TypeScript statusd7ce74aShow bundled TypeScript version for packaged servers29be66aCorrect TS 7 release version to 7.0.2ed2bd1bMerge branch 'main' into ts7-release8873075Bump the github-actions group across 1 directory with 3 updates (microsoft/ty...9427131Set up stable / nightly extension split, other prep (microsoft/typescript-go#...d4eaca5microsoft/typescript-go#4549Maintainer changes
This version was pushed to npm by microsoft1es, a new releaser for typescript since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions