Skip to content

chore(deps-dev): bump the dev-dependencies group with 8 updates - #341

Closed
dependabot[bot] wants to merge 1 commit into
betafrom
dependabot/npm_and_yarn/beta/dev-dependencies-aea9fb632e
Closed

dependabot[bot] wants to merge 1 commit into
betafrom
dependabot/npm_and_yarn/beta/dev-dependencies-aea9fb632e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the dev-dependencies group with 8 updates:

Package From To
@types/node 26.6.2 26.6.4
@typescript-eslint/eslint-plugin 8.70.1 8.71.0
@typescript-eslint/parser 8.70.1 8.71.0
dotenv 18.0.4 18.0.5
globals 17.12.0 17.13.0
mocha 12.0.2 12.0.3
stylelint 17.15.0 17.16.0
typescript-eslint 8.70.1 8.71.0

Updates @types/node from 26.6.2 to 26.6.4

Commits

Updates @typescript-eslint/eslint-plugin from 8.70.1 to 8.71.0

Release notes

Sourced from @​typescript-eslint/eslint-plugin's releases.

v8.71.0

8.71.0 (2026-09-28)

🚀 Features

  • eslint-plugin: [no-unsafe-enum-assignment] add rule (#12732)

🩹 Fixes

  • eslint-plugin: [switch-exhaustiveness-check] always sort literal cases in stable order (#12885)
  • eslint-plugin: [unbound-method] respect this: void on class properties (7fce9127d)
  • eslint-plugin: [no-unnecessary-type-assertion] specialize generic assertion report message (#12832)
  • eslint-plugin: [no-misused-promises] handle a return outside of any function (#12912)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Changelog

Sourced from @​typescript-eslint/eslint-plugin's changelog.

8.71.0 (2026-09-28)

🚀 Features

  • eslint-plugin: [no-unsafe-enum-assignment] add rule (#12732)

🩹 Fixes

  • eslint-plugin: [no-misused-promises] handle a return outside of any function (#12912)
  • eslint-plugin: [no-unnecessary-type-assertion] specialize generic assertion report message (#12832)
  • eslint-plugin: [unbound-method] respect this: void on class properties (7fce9127d)
  • eslint-plugin: [switch-exhaustiveness-check] always sort literal cases in stable order (#12885)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Commits
  • 8695664 chore(release): publish 8.71.0
  • 99d759a feat(eslint-plugin): [no-unsafe-enum-assignment] add rule (#12732)
  • ae3ac15 docs(eslint-plugin): clarify checkTypePredicates assumptions (#12378)
  • 33824c1 fix(eslint-plugin): [no-misused-promises] handle a return outside of any func...
  • 7e25db3 fix(eslint-plugin): [no-unnecessary-type-assertion] specialize generic assert...
  • 8d7ab88 test: order union constituents stably in RuleTester tests
  • 7fce912 fix(eslint-plugin): [unbound-method] respect this: void on class properties
  • ce70016 fix(eslint-plugin): [switch-exhaustiveness-check] always sort literal cases i...
  • See full diff in compare view

Updates @typescript-eslint/parser from 8.70.1 to 8.71.0

Release notes

Sourced from @​typescript-eslint/parser's releases.

v8.71.0

8.71.0 (2026-09-28)

🚀 Features

  • eslint-plugin: [no-unsafe-enum-assignment] add rule (#12732)

🩹 Fixes

  • eslint-plugin: [switch-exhaustiveness-check] always sort literal cases in stable order (#12885)
  • eslint-plugin: [unbound-method] respect this: void on class properties (7fce9127d)
  • eslint-plugin: [no-unnecessary-type-assertion] specialize generic assertion report message (#12832)
  • eslint-plugin: [no-misused-promises] handle a return outside of any function (#12912)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Changelog

Sourced from @​typescript-eslint/parser's changelog.

8.71.0 (2026-09-28)

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Commits

Updates dotenv from 18.0.4 to 18.0.5

Changelog

Sourced from dotenv's changelog.

18.0.5 (2026-09-30)

Changed

  • Fix missing typescript module declaration (#1068)
  • Improve performance for large .env files (#1066)
Commits

Updates globals from 17.12.0 to 17.13.0

Release notes

Sourced from globals's releases.

v17.13.0

  • Update globals (2026-10-01) (#354) b007369

sindresorhus/globals@v17.12.0...v17.13.0

Commits

Updates mocha from 12.0.2 to 12.0.3

Release notes

Sourced from mocha's releases.

v12.0.3

12.0.3 (2026-10-01)

🩹 Fixes

  • keep watching when the last test file is removed (#6355) (921c161)
  • show require() error on unsupported directory import (#6354) (a68344f)
  • support --X one-char aliases (#6391) (1227939)

📚 Documentation

🧹 Chores

Changelog

Sourced from mocha's changelog.

12.0.3 (2026-10-01)

🩹 Fixes

  • keep watching when the last test file is removed (#6355) (921c161)
  • show require() error on unsupported directory import (#6354) (a68344f)
  • support --X one-char aliases (#6391) (1227939)

📚 Documentation

🧹 Chores

Commits

Updates stylelint from 17.15.0 to 17.16.0

Release notes

Sourced from stylelint's releases.

17.16.0

It fixes 2 bugs in the layout-mappings rules. This will likely be the last 17.x release, as we prepare for 18.0.0.

  • Fixed: property-layout-mappings and unit-layout-mappings false negatives for uppercase property names and units (#9485) (@​giaBaoJS).
  • Fixed: value-keyword-layout-mappings false positives for caption-side (#9483) (@​giaBaoJS).
Changelog

Sourced from stylelint's changelog.

17.16.0 - 2026-10-01

It fixes 2 bugs in the layout-mappings rules. This will likely be the last 17.x release, as we prepare for 18.0.0.

  • Fixed: property-layout-mappings and unit-layout-mappings false negatives for uppercase property names and units (#9485) (@​giaBaoJS).
  • Fixed: value-keyword-layout-mappings false positives for caption-side (#9483) (@​giaBaoJS).
Commits
  • bc06c7c Release 17.16.0 (#9551)
  • f4fb76f Set target-branch to v18 in Dependabot config (#9488)
  • 2019478 Fix property-layout-mappings and unit-layout-mappings false negatives for...
  • e875710 Fix value-keyword-layout-mappings false positives for caption-side (#9483)
  • See full diff in compare view

Updates typescript-eslint from 8.70.1 to 8.71.0

Release notes

Sourced from typescript-eslint's releases.

v8.71.0

8.71.0 (2026-09-28)

🚀 Features

  • eslint-plugin: [no-unsafe-enum-assignment] add rule (#12732)

🩹 Fixes

  • eslint-plugin: [switch-exhaustiveness-check] always sort literal cases in stable order (#12885)
  • eslint-plugin: [unbound-method] respect this: void on class properties (7fce9127d)
  • eslint-plugin: [no-unnecessary-type-assertion] specialize generic assertion report message (#12832)
  • eslint-plugin: [no-misused-promises] handle a return outside of any function (#12912)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Changelog

Sourced from typescript-eslint's changelog.

8.71.0 (2026-09-28)

This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dev-dependencies group with 8 updates:

| Package | From | To |
| --- | --- | --- |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.2` | `26.6.4` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.70.1` | `8.71.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.70.1` | `8.71.0` |
| [dotenv](https://github.com/motdotla/dotenv) | `18.0.4` | `18.0.5` |
| [globals](https://github.com/sindresorhus/globals) | `17.12.0` | `17.13.0` |
| [mocha](https://github.com/mochajs/mocha) | `12.0.2` | `12.0.3` |
| [stylelint](https://github.com/stylelint/stylelint) | `17.15.0` | `17.16.0` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.70.1` | `8.71.0` |


Updates `@types/node` from 26.6.2 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@typescript-eslint/eslint-plugin` from 8.70.1 to 8.71.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.70.1 to 8.71.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/parser)

Updates `dotenv` from 18.0.4 to 18.0.5
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v18.0.4...v18.0.5)

Updates `globals` from 17.12.0 to 17.13.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.12.0...v17.13.0)

Updates `mocha` from 12.0.2 to 12.0.3
- [Release notes](https://github.com/mochajs/mocha/releases)
- [Changelog](https://github.com/mochajs/mocha/blob/main/CHANGELOG.md)
- [Commits](mochajs/mocha@v12.0.2...v12.0.3)

Updates `stylelint` from 17.15.0 to 17.16.0
- [Release notes](https://github.com/stylelint/stylelint/releases)
- [Changelog](https://github.com/stylelint/stylelint/blob/main/CHANGELOG.md)
- [Commits](stylelint/stylelint@17.15.0...17.16.0)

Updates `typescript-eslint` from 8.70.1 to 8.71.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/typescript-eslint)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: dotenv
  dependency-version: 18.0.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: globals
  dependency-version: 17.13.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: mocha
  dependency-version: 12.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: stylelint
  dependency-version: 17.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: typescript-eslint
  dependency-version: 8.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🛡️ Security Hardening Pipeline Results

Branch: dependabot/npm_and_yarn/beta/dev-dependencies-aea9fb632e
Commit: c0fa4fb

Workflow Run: 540
Branch: dependabot/npm_and_yarn/beta/dev-dependencies-aea9fb632e
Commit: c0fa4fb

Scan Status

Scanner Status
bandit ⏭️ skipped
checkov ⏭️ skipped
clamav ⏭️ skipped
codeql ✅ PASS
container ⏭️ skipped
dependency-review ✅ PASS
gitleaks ✅ PASS
grype ⏭️ skipped
lint ⏭️ skipped
opengrep ⏭️ skipped
osv ✅ PASS
sbom ⏭️ skipped
supply-chain ⏭️ skipped
trivy-container ⏭️ skipped
trivy-iac ⏭️ skipped
zap ⏭️ skipped

✅ All enabled scanners completed successfully.

Summaries Collected: 4

Scanner Results

🔬 CodeQL SAST (Javascript)

Status: Completed

Findings Summary

Critical High Medium Low Total
0 0 0 0 0

No security findings detected for Javascript.

Artifacts: CodeQL Reports (Javascript)

🔗 Dependency Review

Status: ✅ No issues found

No vulnerable or license-violating dependencies detected in this PR.
📋 View full report

🔑 Gitleaks (Secrets)

No 🔑 Gitleaks (Secrets) findings summary was produced.

📦 OSV (Dependencies)

No 📦 OSV (Dependencies) findings summary was produced.


Generated by Argus


Generated by Argus

@dependabot @github

dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 6, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/beta/dev-dependencies-aea9fb632e branch October 6, 2026 14:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant