chore(deps-dev): bump the npm group with 3 updates - #62
Conversation
Bumps the npm group with 3 updates: [eslint](https://github.com/eslint/eslint), [globals](https://github.com/sindresorhus/globals) and [markdownlint-cli2](https://github.com/DavidAnson/markdownlint-cli2). Updates `eslint` from 10.7.0 to 10.8.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.7.0...v10.8.0) Updates `globals` from 17.7.0 to 17.8.0 - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](sindresorhus/globals@v17.7.0...v17.8.0) Updates `markdownlint-cli2` from 0.23.1 to 0.23.2 - [Changelog](https://github.com/DavidAnson/markdownlint-cli2/blob/main/CHANGELOG.md) - [Commits](DavidAnson/markdownlint-cli2@v0.23.1...v0.23.2) --- updated-dependencies: - dependency-name: eslint dependency-version: 10.8.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm - dependency-name: globals dependency-version: 17.8.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm - dependency-name: markdownlint-cli2 dependency-version: 0.23.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
CI diagnosis: not a real failure — supply-chain release-age policyAll 11 jobs fail in the install step, seconds in. Nothing in the code, lint, or tests is broken: Both were inside the 24h The bumps themselves are verified cleanChecked locally on a throwaway branch off current
Plan: wait it out rather than add exclusionsDeliberately not relaxing the policy — letting the packages mature is the point of the guard.
After ~05:30 UTC on 2026-07-28, comment Follow-up once this mergesmarkdownlint-cli2 0.23.2 bumps js-yaml to 5.2.2 itself, so the |
|
Re-running CI — the failures were pnpm's minimumReleaseAge policy blocking globals@17.8.0 and markdownlint-cli2@0.23.2 until they matured 24h past publish, not real breakage. Both are now past that window. |
Bumps the npm group with 3 updates: eslint, globals and markdownlint-cli2.
Updates
eslintfrom 10.7.0 to 10.8.0Release notes
Sourced from eslint's releases.
Commits
749dfed10.8.04bd0d75Build: changelog update for 10.8.04fbf46dtest: pinwebpackversion to 5.108.4 (#21137)6ddf858docs: fix broken Specify Parser Options anchor link (#21106)784dfbedocs: Clarifyno-eq-nulldescription (#21120)6b8d2f7fix: escape reserved characters in rule id inhtmlformatter (#21129)2d063e2chore: update HTTP URLs to HTTPS in JSDoc and comments (#21101)eccbe7btest: add error locations tono-class-assign(#21123)2fee9bbfeat: exportConfigObjectfromeslint/config(#21082)e7d1e43ci: bump actions/setup-go from 6 to 7 (#21118)Updates
globalsfrom 17.7.0 to 17.8.0Release notes
Sourced from globals's releases.
Commits
36c765917.8.07394811Update globals (2026-07-01) (#347)Updates
markdownlint-cli2from 0.23.1 to 0.23.2Changelog
Sourced from markdownlint-cli2's changelog.
Commits
b82a6c8Update to version 0.23.2.e4e659dAdd a stub for process.nextTick (using queueMicrotask) now that globby (indir...99760afBump globby from 16.2.1 to 16.2.23070236Address new ESLint warnings from previous commit.6e3cc93Bump eslint-plugin-unicorn from 71.1.0 to 72.0.04ba8177Add eslint-package-json/all to lint script, address new issues.9cb99b2Refactor eslint.config.mjs to use defineConfig, change eslint-plugin-n from "...37fb0ecAddress new ESLint warnings from previous commit.f7fea61Bump eslint-node-test from 0.2.0 to 0.3.085bb5e7Bump js-yaml from 5.2.1 to 5.2.2Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions