Skip to content

[Snyk] Upgrade eslint from 6.8.0 to 9.23.0 #244

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

nerdy-tech-com-gitub
Copy link
Owner

@nerdy-tech-com-gitub nerdy-tech-com-gitub commented Apr 20, 2025

Sweep Summary Sweep

Enhances ESM module resolution to support importing directories with trailing slashes by automatically looking for index files in those directories.

  • Modified lib/internal/modules/esm/resolve.js to handle URL specifiers with trailing slashes by checking if they point to directories and then looking for index files.
  • Added comprehensive test cases in test/es-module/test-esm-import-trailing-slash.js to verify the new trailing slash resolution behavior.
  • Updated existing import tests in test/es-module/test-esm-imports.js to include the new trailing slash functionality.

Ask Sweep AI questions about this PR

snyk-top-banner

Snyk has created this PR to upgrade eslint from 6.8.0 to 9.23.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


⚠️ Warning: This PR contains major version upgrade(s), and may be a breaking change.

  • The recommended version is 142 versions ahead of your current version.

  • The recommended version was released a month ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Prototype Pollution
SNYK-JS-AJV-584908
165 No Known Exploit
high severity Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
165 No Known Exploit
critical severity Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
165 Proof of Concept
high severity Excessive Platform Resource Consumption within a Loop
SNYK-JS-BRACES-6838727
165 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
165 Proof of Concept
high severity Denial of Service (DoS)
SNYK-JS-DECODEURICOMPONENT-3149970
165 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HAWK-2808852
165 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
165 Proof of Concept
high severity Prototype Pollution
SNYK-JS-UNSETVALUE-2400660
165 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
165 Proof of Concept
critical severity Authentication Bypass
SNYK-JS-HAWK-6969142
165 Proof of Concept
high severity Prototype Poisoning
SNYK-JS-QS-3153490
165 Proof of Concept
medium severity Insecure Randomness
npm:cryptiles:20180710
165 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-7925106
165 Proof of Concept
Release notes
Package name: eslint
  • 9.23.0 - 2025-03-21

    Features

    • 557a0d2 feat: support TypeScript syntax in no-useless-constructor (#19535) (Josh Goldberg ✨)
    • 8320241 feat: support TypeScript syntax in default-param-last (#19431) (Josh Goldberg ✨)
    • 833c4a3 feat: defineConfig() supports "flat/" config prefix (#19533) (Nicholas C. Zakas)
    • 4a0df16 feat: circular autofix/conflicting rules detection (#19514) (Milos Djermanovic)
    • be56a68 feat: support TypeScript syntax in class-methods-use-this (#19498) (Josh Goldberg ✨)

    Bug Fixes

    • 0e20aa7 fix: move deprecated RuleContext methods to subtype (#19531) (Francesco Trotta)
    • cc3bd00 fix: reporting variable used in catch block in no-useless-assignment (#19423) (Tanuj Kanti)
    • d46ff83 fix: no-dupe-keys false positive with proto setter (#19508) (Milos Djermanovic)
    • e732773 fix: navigation of search results on pressing Enter (#19502) (Tanuj Kanti)
    • f4e9c5f fix: allow RuleTester to test files inside node_modules/ (#19499) (fisker Cheung)

    Documentation

    • 5405939 docs: show red underlines in TypeScript examples in rules docs (#19547) (Milos Djermanovic)
    • 48b53d6 docs: replace var with const in examples (#19539) (Nitin Kumar)
    • c39d7db docs: Update README (GitHub Actions Bot)
    • a4f8760 docs: revert accidental changes (#19542) (Francesco Trotta)
    • 280128f docs: add copy button (#19512) (xbinaryx)
    • cd83eaa docs: replace var with const in examples (#19530) (Nitin Kumar)
    • 7ff0cde docs: Update README (GitHub Actions Bot)
    • 996cfb9 docs: migrate sass to module system (#19518) (xbinaryx)
    • 17cb958 docs: replace var with let and const in rule examples (#19515) (Tanuj Kanti)
    • 83e24f5 docs: Replace var with let or const (#19511) (Jenna Toff)
    • a59d0c0 docs: Update docs for defineConfig (#19505) (Nicholas C. Zakas)
    • fe92927 docs: require-unicode-regexp add note for i flag and \w (#19510) (Chaemin-Lim)

    Build Related

    • 2357edd build: exclude autogenerated files from Prettier formatting (#19548) (Francesco Trotta)

    Chores

    • 0ac8ea4 chore: update dependencies for v9.23.0 release (#19554) (Francesco Trotta)
    • 20591c4 chore: package.json update for @ eslint/js release (Jenkins)
    • 901344f chore: update dependency @ eslint/json to ^0.11.0 (#19552) (renovate[bot])
    • 5228383 chore: fix update-readme formatting (#19544) (Milos Djermanovic)
    • 5439525 chore: format JSON files in Trunk (#19541) (Francesco Trotta)
    • 75adc99 chore: enabled Prettier in Trunk (#19354) (Josh Goldberg ✨)
    • 2395168 chore: added .git-blame-ignore-revs for Prettier via trunk fmt (#19538) (Josh Goldberg ✨)
    • 129882d chore: formatted files with Prettier via trunk fmt (#19355) (Josh Goldberg ✨)
    • 1738dbc chore: temporarily disable prettier in trunk (#19537) (Josh Goldberg ✨)
    • dc854fd chore: update dependency shelljs to ^0.9.0 (#19524) (renovate[bot])
    • 5d57496 chore: fix some comments (#19525) (jimmycathy)
    • 9c5c6ee test: fix an assertion failure (#19500) (fisker Cheung)
    • 7a699a6 chore: remove formatting-related lint rules internally (#19473) (Josh Goldberg ✨)
    • c99db89 test: replace WebdriverIO with Cypress (#19465) (Pixel998)
  • 9.22.0 - 2025-03-07

    Features

    • 7ddb095 feat: Export defineConfig, globalIgnores (#19487) (Nicholas C. Zakas)

    Bug Fixes

    • 19c0127 fix: improve message for no-console suggestions (#19483) (Francesco Trotta)
    • 49e624f fix: improve error message for falsy parsed JS AST (#19458) (Josh Goldberg ✨)

    Documentation

    • 86c5f37 docs: Update README (GitHub Actions Bot)
    • fbdeff0 docs: Update README (GitHub Actions Bot)
    • c9e8510 docs: generate deprecation notice in TSDoc comments from rule metadata (#19461) (Francesco Trotta)
    • 2f386ad docs: replace var with const in rule examples (#19469) (Tanuj Kanti)
    • 0e688e3 docs: Update README (GitHub Actions Bot)
    • 06b596d docs: Restore the carrot to the position where the search input was lost (#19459) (Amaresh S M)

    Chores

    • 97f788b chore: upgrade @ eslint/js@9.22.0 (#19489) (Milos Djermanovic)
    • eed409a chore: package.json update for @ eslint/js release (Jenkins)
    • f9a56d3 chore: upgrade eslint-scope@8.3.0 (#19488) (Milos Djermanovic)
  • 9.21.0 - 2025-02-21

    Features

    • 418717f feat: introduce new deprecated types for rules (#19238) (fnx)
    • 5c5b802 feat: Add --ext CLI option (#19405) (Milos Djermanovic)

    Bug Fixes

    • db5340d fix: update missing plugin message template (#19445) (Milos Djermanovic)
    • d8ffdd4 fix: do not exit process on rule crash (#19436) (Francesco Trotta)

    Documentation

    • c5561ea docs: Update README (GitHub Actions Bot)
    • 80b0485 docs: replace var with let and const in rule example (#19434) (Tanuj Kanti)
    • f67d5e8 docs: Update README (GitHub Actions Bot)
    • 75afc61 docs: Update README (GitHub Actions Bot)
    • 0636cab docs: Update Eleventy from v2 to v3 (#19415) (Amaresh S M)
    • dd7d930 docs: Update README (GitHub Actions Bot)

    Chores

    • a8c9a9f chore: update @ eslint/eslintrc and @ eslint/js (#19453) (Francesco Trotta)
    • 265e0cf chore: package.json update for @ eslint/js release (Jenkins)
    • 3401b85 test: add test for Rule.ReportDescriptor type (#19449) (Francesco Trotta)
    • e497aa7 chore: update rewrite dependencies (#19448) (Francesco Trotta)
    • dab5478 chore: better error message for missing plugin in config (#19402) (Tanuj Kanti)
    • ebfe2eb chore: set js language for bug report issue config block (#19439) (Josh Goldberg ✨)
    • 5fd211d test: processors can return subpaths (#19425) (Milos Djermanovic)
  • 9.20.1 - 2025-02-11

    Bug Fixes

    Documentation

    • fe3ccb2 docs: allow typing in search box while dropdown is open (#19424) (Amaresh S M)
    • 93c78a5 docs: Add instructions for pnpm compat (#19422) (Nicholas C. Zakas)
    • b476a93 docs: Fix Keyboard Navigation for Search Results (#19416) (Amaresh S M)
    • ccb60c0 docs: Update README (GitHub Actions Bot)
  • 9.20.0 - 2025-02-07

    Features

    • e89a54a feat: change behavior of inactive flags (#19386) (Milos Djermanovic)

    Bug Fixes

    • 91d4d9f fix: Bring types in sync with @ eslint/core (#19157) (Nicholas C. Zakas)
    • fa25c7a fix: Emit warning when empty config file is used (#19399) (Nicholas C. Zakas)
    • 31a9fd0 fix: Clearer error message for wrong plugin format (#19380) (Nicholas C. Zakas)
    • 61d99e3 fix: Better error message for unserializable parser (#19384) (Nicholas C. Zakas)
    • db1b9a6 fix: Ensure module scope is checked for references in consistent-this (#19383) (Nicholas C. Zakas)
    • 8bcd820 fix: arrow-body-style crash with single-token body (#19379) (Milos Djermanovic)

    Documentation

    • b7012c8 docs: rewrite examples with var using let and const (#19407) (Mueez Javaid Hashmi)
    • 6406376 docs: Update README (GitHub Actions Bot)
    • 350f2b9 docs: rewrite some examples with var using let and const (#19404) (Mueez Javaid Hashmi)
    • 93c325a docs: rewrite examples with var using let and const (#19398) (Mueez Javaid Hashmi)
    • 56ff404 docs: replace var with let or const in rules docs (#19396) (Daniel Harbrueger)
    • 4053226 docs: change sourceType in no-eval examples (#19393) (Milos Djermanovic)
    • 1324af0 docs: replace var with let and const in rules docs (#19392) (Daniel Harbrueger)
    • 8b87e00 docs: replace var with const and let in rules (#19389) (Tanuj Kanti)
    • 758c66b docs: Explain what frozen rules mean (#19382) (Nicholas C. Zakas)
    • 0ef8bb8 docs: additional checks for rule examples (#19358) (Milos Djermanovic)
    • 58ab2f6 docs: fix order of installation steps in getting started (#19326) (Tanuj Kanti)

    Chores

    • 979097a chore: upgrade @ eslint/js@9.20.0 (#19412) (Francesco Trotta)
    • 031734e chore: package.json update for @ eslint/js release (Jenkins)
    • d4c47c3 test: avoid empty config warning in test output (#19408) (Milos Djermanovic)
    • 67dd82a chore: update dependency @ eslint/json to ^0.10.0 (#19387) (renovate[bot])
    • 15ac0e1 chore: add permissions: read-all to stale.yml workflow (#19374) (Josh Goldberg ✨)
  • 9.19.0 - 2025-01-24

    Features

    • 1637b8e feat: add --report-unused-inline-configs (#19201) (Josh Goldberg ✨)

    Bug Fixes

    • aae6717 fix: sync rule type header comments automatically (#19276) (Francesco Trotta)

    Documentation

    • cfea9ab docs: Clarify overrideConfig option (#19370) (Nicholas C. Zakas)
    • 2b84f66 docs: Update README (#19362) (Nicholas C. Zakas)
    • 044f93c docs: clarify frozen rule description (#19351) (Pavel)
    • 797ee7c docs: fix Bluesky links (#19368) (Milos Djermanovic)
    • 81a9c0e docs: Update README (GitHub Actions Bot)
    • 093fb3d docs: replace var with let and const in rule examples (#19365) (Tanuj Kanti)
    • 417de32 docs: replace var with const in rule examples (#19352) (jj)
    • 17f2aae docs: update getting-started config to match default generated config (#19308) (0xDev)
    • 8a0a5a8 docs: better global ignores instruction (#19297) (Jacopo Marrone)
    • 6671a2c docs: Update README (GitHub Actions Bot)
    • e39d3f2 docs: fix divider for rule category (#19264) (Tanuj Kanti)
    • e0cf53f docs: fix search result box position for small screens (#19328) (Tanuj Kanti)
    • f92a680 docs: replace var with let or const in rule examples (#19331) (Ravi Teja Kolla)
    • b04b84b docs: revert accidental changes in TS config files docs (#19336) (Francesco Trotta)

    Chores

    • 9b9cb05 chore: upgrade @ eslint/js@9.19.0 (#19371) (Milos Djermanovic)
    • 58560e7 chore: package.json update for @ eslint/js release (Jenkins)
    • 2089707 test: fix failing test in Node.js v22.13.0 (#19345) (Francesco Trotta)
  • 9.18.0 - 2025-01-10

    Features

    • e84e6e2 feat: Report allowed methods for no-console rule (#19306) (Anna Bocharova)
    • 8efc2d0 feat: unflag TypeScript config files (#19266) (Francesco Trotta)
    • 87a9352 feat: check imports and class names in no-shadow-restricted-names (#19272) (Milos Djermanovic)

    Bug Fixes

    • da768d4 fix: correct overrideConfigFile type (#19289) (Francesco Trotta)

    Documentation

Snyk has created this PR to upgrade eslint from 6.8.0 to 9.23.0.

See this package in npm:
eslint

See this project in Snyk:
https://app.snyk.io/org/nerds-github/project/5c08c7f3-e081-4b45-bb54-aed4a1afcddf?utm_source=github&utm_medium=referral&page=upgrade-pr
Copy link

sourcery-ai bot commented Apr 20, 2025

Reviewer's Guide by Sourcery

This pull request upgrades the eslint dependency from version 6.8.0 to version 9.23.0. This update is performed by modifying the version number in the package.json file.

No diagrams generated as the changes look simple and do not need a visual representation.

File-Level Changes

Change Details Files
The pull request upgrades the eslint dependency from version 6.8.0 to version 9.23.0.
  • Updated the eslint dependency version in package.json.
deps/v8/tools/clusterfuzz/js_fuzzer/package.json

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!
  • Generate a plan of action for an issue: Comment @sourcery-ai plan on
    an issue to generate a plan of action for it.

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

Copy link

@sourcery-ai sourcery-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have skipped reviewing this pull request. Here's why:

  • It seems to have been created by a bot ('[Snyk]' found in title). We assume it knows what it's doing!
  • We don't review packaging changes - Let us know if you'd like us to change this.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants