fix(deps): update patch - #799
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Contributor
Author
|
🦜 ChachalogNo changelog entries detected. Learn more about Chachalog. Create a new entry online or run |
commit: |
renovate
Bot
force-pushed
the
renovate/patch
branch
3 times, most recently
from
September 24, 2026 22:06
716de0a to
fdfc342
Compare
renovate
Bot
force-pushed
the
renovate/patch
branch
3 times, most recently
from
October 1, 2026 05:00
5f543dd to
fda1f44
Compare
renovate
Bot
force-pushed
the
renovate/patch
branch
3 times, most recently
from
October 5, 2026 13:16
e5c1259 to
6d470f5
Compare
renovate
Bot
force-pushed
the
renovate/patch
branch
from
October 5, 2026 20:45
6d470f5 to
c1f6205
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.19.1→5.23.58.5.0→8.6.022.20.3→22.20.57.3.3→7.4.06.0.0→6.0.217.12.0→17.13.01.4.1→1.4.23.9.7→3.9.90.3.24→0.3.2517.0.14→17.0.151.2.9→1.2.128.3.0→8.3.2Release Notes
Rel1cx/eslint-react (@eslint-react/eslint-plugin)
v5.23.5Compare Source
🐞 Fixes
react-x/set-state-in-effect: the ref-derived value exemption now also coverssetStatecalls reached indirectly through functions or hook callbacks invoked from the effect setup, not onlysetStatewritten directly in the setup body. (#1982)react-x/set-state-in-effect: more ref read shapes are recognized as ref-derived values —<ref-named>.currentanywhere in a member chain, locals derived from other ref-derived locals, and reads through aref/xxxRefparameter. (#1982)react-web-api/no-leaked-event-listener:removeEventListenerinside a function called from the effect cleanup now pairs with itsaddEventListener, fixing false positives for listeners removed on unmount; cleanup calls resolve to the actual functions, so same-named shadowed functions no longer pair by coincidence. (#1982)🏗️ Internal
effectto4.0.0and migrated the repo scripts to the v4 APIs. (#1981)Full Changelog: Rel1cx/eslint-react@v5.23.4...v5.23.5
v5.23.4Compare Source
🐞 Fixes
react-x/static-componentsrule to thedisable-experimentalpreset. (#1980)react-x/exhaustive-depsandreact-x/rules-of-hooks(RuleFeatureis now imported from@eslint-react/eslintinstead of@eslint-react/shared).📝 Documentation
react-jsx/no-useless-fragment: clarified the scope of theallowExpressionsoption and unified experimental-rule callout wording across rule docs.react-x: unified cross-rule references in rule docs to full rule names.eslintbeing an optional peer dependency.🏗️ Internal
ts-patternfor type checks in@eslint-react/core,@eslint-react/jsx, and thereact-domplugin, and declared the missingts-patterndependencies.react-jsx/no-useless-fragment.fumadocs-core,fumadocs-ui, andlucide-reactin the website.Full Changelog: Rel1cx/eslint-react@v5.23.3...v5.23.4
v5.23.3Compare Source
🐞 Fixes
react-x/immutability: reassigning a binding that resolves to component props or state (value = value + "!",count++, including destructuring andfor...ofrebinding forms) is now reported as a direct mutation, matching upstreamreact-hooks/immutability; rebinding iterator or shallow-copy bindings remains allowed. (#1979)react-x/set-state-in-effect: ref reads traced through intermediate local computations (ex:const dv = visible - prevVisible.current) are now recognized as ref-derived values, and a preceding early-return guard whose test is ref-derived (ex:if (dv === 0) return;) now exempts thesetStatecalls that follow it — previously onlysetStatenested directly inside a ref-gatedif/conditional was exempted. Aligns withreact-hooks7.1.1. (#1979)📝 Documentation
react-x/no-unstable-context-value: documented the React 19<Context>provider detection heuristic and its name-based limitations. (#1979)eslint-plugin-react-x.Full Changelog: Rel1cx/eslint-react@v5.23.2...v5.23.3
v5.23.2Compare Source
🏗️ Internal
nextto16.3.7,fumadocs-coreandfumadocs-uito16.15.16, andeslint-plugin-package-jsonto1.10.1.Full Changelog: Rel1cx/eslint-react@v5.23.1...v5.23.2
v5.23.1Compare Source
🏗️ Internal
react-xrules. (#1977, #1978)react-x/error-boundariesreact-x/globalsreact-x/immutabilityreact-x/purityreact-x/refsreact-x/set-state-in-effectreact-x/set-state-in-renderreact-x/use-memotypescript-eslintto8.71.0,tsl-dxto0.13.7, andpnpmto12.8.1.📝 Documentation
Full Changelog: Rel1cx/eslint-react@v5.23.0...v5.23.1
v5.23.0Compare Source
✨ New
react-x/static-components: dynamic creation-site tracing now follows both sides of logical expressions (ex:const C = DefaultComponent || (() => <div />)) and the last element of sequence expressions (ex:const C = (setup(), () => <div />)), in initializers and reassignments alike. (#1975)🐞 Fixes
react-x/static-components: parameters of nested non-component functions (ex:function render(Comp) { return <Comp /> }) are no longer mistaken for render-created components; definitions are judged by definition type instead of AST node type. (#1975)react-x/static-components:createdHereis now reported once per creation site instead of once per JSX usage; thedefaultdiagnostic remains per usage. (#1975)🏗️ Internal
react-x/static-components: restructured the rule to the fact-based implementation pattern —collect.ts(usage facts),origins.ts(creation-site resolution), andeffects.ts(effect inference) are now separate modules, with reporting centralized inProgram:exit; added 14 boundary test cases covering creation-site resolution, render boundaries, and per-usage reporting. (#1975)lib.tstohelpers.tsin the fact-basedreact-xrules (globals,immutability,refs). (#1976)@effect/language-serviceto0.87.3andoxlintto1.86.0.Full Changelog: Rel1cx/eslint-react@v5.22.1...v5.23.0
v5.22.1Compare Source
🐞 Fixes
react-x/use-state: directly returning theuseStateresult (ex:return React.useState()) is now allowed regardless of the rule's options, matching the exemption in the originalreact/hook-use-staterule. Covers explicit, implicit (arrow function), and type-asserted returns; lazy initialization checks still apply. (#1974, closes #1963)📝 Documentation
eslintbeing an optional peer dependency to the READMEs and the website's getting-started guides.@eslint-react/kitREADME to point to the full documentation.Full Changelog: Rel1cx/eslint-react@v5.22.0...v5.22.1
v5.22.0Compare Source
✨ New
react-dom/no-unknown-property: added React 19.3 properties to the known property allowlist. (#1973)closedbyondialogonFullscreenChange,onFullscreenError(and theirCapturevariants),credentialless, andmaskType— gated on React version>= 19.3.0onLoadonbodyonScrollEnd(and itsCapturevariant)shadowrootmode,shadowrootclonable,shadowrootdelegatesfocus, andshadowrootserializableontemplate🏗️ Internal
fumadocs-coreandfumadocs-uito16.15.15.Full Changelog: Rel1cx/eslint-react@v5.21.3...v5.22.0
v5.21.3Compare Source
🐞 Fixes
react-x/purity: reverted the v5.21.2 exemption for impure calls inuseRefinitializer arguments (ex:useRef(document.createElement("div"))); such calls are reported again. (#1972)Full Changelog: Rel1cx/eslint-react@v5.21.2...v5.21.3
v5.21.2Compare Source
🐞 Fixes
react-x/no-unnecessary-use-prefix: hooks that call other hooks only within nested callbacks, functions named exactlyuse, and hooks defined in test mock module registrations are no longer reported. (#1971)react-x/no-unused-class-component-members: methods invoked by host environments through refs (React Native'sNativeMethods) are no longer reported as unused. (#1971)react-x/purity: async function components in modules without ause clientdirective and impure calls inuseRefinitializer arguments are no longer reported. (#1971)react-x/set-state-in-effect: local variables initialized from nested member expressions rooted at a ref are now recognized as ref-derived values and no longer reported. (#1971)🏗️ Internal
@eslint-react/ast: predefined and exported common node-type helpers in theChecknamespace and migrated call sites to them.📝 Documentation
## Versionssection; a rule's changelog can be viewed directly via theRule Changeloglink under the## Resourcessection of each rule doc.Full Changelog: Rel1cx/eslint-react@v5.21.1...v5.21.2
v5.21.1Compare Source
🐞 Fixes
react-web-api/no-leaked-timeoutreact-web-api/no-leaked-intervalreact-web-api/no-leaked-fetchreact-web-api/no-leaked-resize-observerreact-web-api/no-leaked-intersection-observer🏗️ Internal
react-web-apileaked-resource rules by replacing manual function-context stack tracking withTraverse.findParentancestor lookup, and added boundary tests covering deeply nested callbacks, cross-effect pairing, and wrapped or referenced setup callbacks. (#1969) Affected rules:react-web-api/no-leaked-timeoutreact-web-api/no-leaked-intervalreact-web-api/no-leaked-fetchreact-web-api/no-leaked-event-listenerreact-web-api/no-leaked-resize-observerreact-web-api/no-leaked-intersection-observer@eslint-react/var:isAssignmentTargetEqualno longer short-circuits same-name identifiers through structural equality; identifier pairs are compared with scope-aware value equality. (#1969)react-x/no-unused-class-component-members: removed the manual class and method context stacks; the enclosing class and method are now resolved at the hit point withTraverse.findParentancestor lookup, and the per-class member definition/usage maps are initialized lazily. (#1970)Full Changelog: Rel1cx/eslint-react@v5.21.0...v5.21.1
v5.21.0Compare Source
✨ New
eslintinstallation:eslintis now an optional peer dependency across all published packages, and the rule utilities no longer eagerly load theeslintpackage at import time. (#1965)🏗️ Internal
@eslint-react/core: removed the unusedisAssignmentToThisStatehelper, and simplified thereact-xclass-component rules (no-access-state-in-setstate,no-class-component,no-direct-mutation-state,no-set-state-in-*) accordingly.@eslint-react/eslint: added a localgetConstrainedTypeAtLocationhelper (adapted from@typescript-eslint/type-utils) so consumers don't need to load@typescript-eslint/type-utils, whose entry point eagerly loads theeslintpackage. (#1965)typescript-eslintto8.70.1,fumadocsto16.15.14,fumadocs-mdxto15.4.5,viteto8.3.1, and other dependencies.New Contributors
Full Changelog: Rel1cx/eslint-react@v5.20.8...v5.21.0
v5.20.8🐞 Fixes
@eslint-react/core:isJsxLikenow recognizes JSX wrapped in TypeScript expressions (as,satisfies, type assertions, and non-null assertions) andawaitexpressions.@eslint-react/jsx:isFragmentElementnow requires the configuredjsxFragmentFactory, avoiding an implicit React fragment factory for custom JSX runtimes.🏗️ Internal
@eslint-react/jsx: exported theAttributeValuetype from the package entry point.@eslint-react/var: renamed theAssignmentTargettype toEnclosingAssignmentTargetand inlinedgetRequireExpressionArgumentsinto its sole consumer.Full Changelog: Rel1cx/eslint-react@v5.20.6...v5.20.8
v5.20.6Compare Source
🐞 Fixes
react-x/globals:for...in/for...ofloop targets without a declaration (e.g.for (globalValue of items)) are now collected as writes instead of being missed.react-x/immutability: destructuring assignment targets (e.g.({ a: props.x } = value)) andfor...in/for...ofloop targets without a declaration are now collected as mutations instead of being missed.react-x/purity: builtin alias resolution now preserves the property path, so aliases of impure builtins (const random = Math.random; random(),const { now } = Date; now(),window.Math.random()) are now detected instead of being missed; unknown-global roots are not followed, preventing speculative reports.react-x/refs: destructuring assignments, for-in/of loop targets, anddeleteoperations onref.currentare now classified as writes instead of being misreported as reads.react-x/refs: refs passed to constructor calls (new Widget(ref)) and tagged templates are now checked for render-time exposure, same as refs passed to plain functions.react-x/refs: themergeRefsexemption for passing refs now survives simple variable aliases (const combine = mergeRefs), resolved position-aware so reassigned aliases lose it again.react-x/use-memo: reassignments of outer variables through destructuring patterns andfor...in/for...ofloop targets insideuseMemocallbacks are now reported instead of being missed; property mutation targets remain exempt, matching the React Compiler'sStoreContextsemantics.🏗️ Internal
@eslint-react/var: splitresolveinto a value-basedresolveand a new origin-basedresolveOrigin, and updated the consumers inreact-web-apiandreact-xrules accordingly. (#1964)fumadocsto16.15.12,fumadocs-mdxto15.4.3,tsl-dxto0.13.6,eslint-plugin-de-morganto2.2.0, andeslint-plugin-regexpto3.3.1.Full Changelog: Rel1cx/eslint-react@v5.20.5...v5.20.6
v5.20.5Compare Source
🐞 Fixes
react-web-api/no-leaked-fetch: fixed a false positive where anabortcall nested in a callback within the cleanup function (e.g.setTimeout(() => ctrl.abort())) was not recognized, causing a spuriousexpectedAbortInCleanupreport; theabortlookup now finds the nearest enclosing setup/cleanup function instead of requiring the innermost one. (#1962)Full Changelog: Rel1cx/eslint-react@v5.20.4...v5.20.5
v5.20.4Compare Source
🐞 Fixes
react-web-api/no-leaked-event-listener: listeners that are only added inside the effect cleanup are now reported when the matchingremoveEventListeneris in the setup (reversed setup/cleanup pairing), since a listener attached on unmount is never removed. (#1961)🏗️ Internal
react-jsxandreact-web-apirules: unified rule code style and variable naming across the plugins. (#1960, #1961)Full Changelog: Rel1cx/eslint-react@v5.20.3...v5.20.4
v5.20.3Compare Source
🏗️ Internal
@eslint-react/ast: replacedgetIdentifierAtwith the newgetMemberChainhelper and movedgetInnermostCallto its sole consumer inreact-x/no-nested-component-definitions. (#1959)react-domrules: unified rule code style and variable naming across the plugin, and switchedno-find-dom-nodeto import-aware detection viacreateImportLookup. (#1958)Full Changelog: Rel1cx/eslint-react@v5.20.2...v5.20.3
v5.20.2Compare Source
🐞 Fixes
react-domrules: polymorphic components written as member expressions (e.g.<motion.div as="button">) were mistaken for host elements, so the polymorphic prop was ignored and these rules skipped them entirely; they are now resolved through the polymorphic prop and checked like the underlying DOM element. String values of the polymorphic prop are also normalized to lowercase, soas="BUTTON"is treated asbutton. Affected rules:react-dom/no-missing-button-typereact-dom/no-missing-iframe-sandboxreact-dom/no-unsafe-iframe-sandboxreact-dom/no-unsafe-target-blankreact-dom/no-void-elements-with-children🏗️ Internal
polymorphicPropNamesetting type is corrected fromstring | nulltostring— it could never benullat runtime — and the unreachablenullbranch in the JSX element resolver used by thereact-domrules is removed.Full Changelog: Rel1cx/eslint-react@v5.20.1...v5.20.2
v5.20.1Compare Source
🐞 Fixes
react-dom/no-flush-sync:flushSynccalls are now detected by trackingreact-domimports directly instead of matching by name, so aliased named imports (e.g.import { flushSync as fs } from "react-dom") and default/namespace member calls (e.g.ReactDOM.flushSync()) are reported, while local functions, object methods, and same-named APIs from other packages (e.g. pino'sdestination().flushSync()) are no longer misreported. (#1954, closes #1943)🏗️ Internal
react-dom/no-flush-syncandreact-dom/no-find-dom-node: API call checks now usecore.isAPICall;core.isJsxLikenow usesisCreateElementCall.eslintto10.11.0,eslint-plugin-jsdocto64.5.4,eslint-plugin-package-jsonto1.9.0,typedoc-plugin-markdownto4.13.1,@types/nodeto26.6.2,pnpmto12.5.1, and the dprint JSON plugin to0.24.0.New Contributors
Full Changelog: Rel1cx/eslint-react@v5.20.0...v5.20.1
v5.20.0Compare Source
✨ New
react-x/immutability: mutations onfor...ofiterator variables (e.g.for (const item of items) { item.done = true; }), including destructured iterator bindings, are now reported when the iterated collection resolves through its root identifier to a component's props, a state value, or a shallow copy of either, since the iterator variable is bound to each shared element of the original collection. Member-expression collections (for (const item of props.items)) are traced to their root;for...inloops and right sides without a root identifier are not traced. (#1953, closes #1764)🏗️ Internal
@types/nodeto26.6.1,tsl-dxto0.13.5,eslint-plugin-jsdocto64.5.2,lucide-reactto1.47.0, andpnpmto12.4.2.New Contributors
Full Changelog: Rel1cx/eslint-react@v5.19.1...v5.20.0
Jahia/jahia-cypress (@jahia/cypress)
v8.6.0Compare Source
Added
breakAclInheritanceandrestoreAclInheritancehelpers to stop or restore the inheritance of roles on a node.Added
createRoleanddeleteRoleto manage a role from a test through GraphQL, so each project no longer needs its own Groovy script.archfz/cypress-terminal-report (cypress-terminal-report)
v7.4.0Compare Source
sveltejs/devalue (devalue)
v6.0.2Compare Source
Patch Changes
12ad9d6: chore: remove dts-buddyv6.0.1Compare Source
Patch Changes
c13cf6a: fix: populateerror.pathfor values reached through a promise instringifyAsync6156b2e: perf:stringifyandunevalskip per-character escaping for strings with nothing to escapee7a9a73: fix: throwInvalid inputinstead of a rawTypeErrorfor malformed typed array and boxed primitive payloads6156b2e: perf: only format path when an error is raised6156b2e: perf: cache quoted property names9e44253: Fixunevalfor typed array views whose backing buffer ends with a partial elementsindresorhus/globals (globals)
v17.13.0Compare Source
b007369Rich-Harris/magic-string (magic-string)
v1.4.2Compare Source
Bug Fixes
Performance Improvements
prettier/prettier (prettier)
v3.9.9Compare Source
diff
Markdown: Fix text with
$been incorrectly parsed as math syntax (#20140 by @fisker)v3.9.8Compare Source
publint/publint (publint)
v0.3.25Compare Source
Patch Changes
#260
54aebea- FixFILE_INVALID_JSX_EXTENSIONnot detecting the.ctsxextension#265
78604f3- Skip file existence check forbrowserfield values that point at another packagei18next/react-i18next (react-i18next)
v17.0.15Compare Source
<wrap></wrap>), a component array (<0></0>), or indexed JSX children (<1></1>). This matches the existing behavior for two or more children and self-closing tags. React represents one JSX child as an element and multiple children as an array; the previous array-only check silently rendered the one-child case empty. Compatibility note: when that sole element contains an interpolation object, the restored raw children can expose an existing React rendering limitation as an error instead of silently rendering empty; the same shape already errors with two children. Fixes #1932.rolldown/rolldown (rolldown)
v1.2.12Compare Source
🚀 Features
inlineCommonChunkssupport (#10899) by @hyfdev🐛 Bug Fixes
import.meta.hot.acceptdeps with Vite (#10997) by @h-a-n-a🚜 Refactor
__internalForcePanic(#10989) by @IWANABETHATGUY📚 Documentation
⚡ Performance
🧪 Testing
⚙️ Miscellaneous Tasks
CLAUDE.md(#10925) by @iiio2❤️ New Contributors
v1.2.11Compare Source
🚀 Features
🐛 Bug Fixes
collapse_sourcemaps(#9486) by @eoin🚜 Refactor
📚 Documentation
❤️ New Contributors
v1.2.10Compare Source
🚀 Features
🐛 Bug Fixes
codeSplittingtiming rows (#10916) by @IWANABETHATGUYindicesoption (#10934) by @shulaoda🚜 Refactor
ResolvedIdin one place (#10921) by @IWANABETHATGUY📚 Documentation
⚡ Performance
sourcemapPathTransformcalls (#10763) by @IWANABETHATGUYsourcemapIgnoreListcalls (#10762) by @IWANABETHATGUY🧪 Testing
⚙️ Miscellaneous Tasks
ban-expect-assertionsJS lint with builtinno-restricted-properties(#10933) by @isker❤️ New Contributors
vitejs/vite (vite)
v8.3.2Compare Source
Bug Fixes
renderBuiltUrlreturns URLs with queries (#23611) (64e0a21)Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.