Repository navigation
chore(deps-dev): bump @typescript-eslint/parser from 8.69.0 to 8.70.0 - #349
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) from 8.69.0 to 8.70.0. - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.0/packages/parser) --- updated-dependencies: - dependency-name: "@typescript-eslint/parser" dependency-version: 8.70.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
clestons
left a comment
There was a problem hiding this comment.
APPROVE — chore(deps-dev): @typescript-eslint/parser 8.69.0 → 8.70.0
[2-round](R1a DeepSeek + 执行器机械核验;纯 bump 跳 Codex PK)· dependabot · package.json + package-lock.json only。
- 纯 dev-dependency patch bump,无 runtime、无逻辑改动。
- lockfile 机械核验:resolved 全部
registry.npmjs.org(无 npmmirror/taobao 翻转)、8 处 integrity sha512 齐全、只动版本号。 - eslint 工具链内部子包(scope-manager/types/typescript-estree 等)随之对齐到 8.70.0,一致。
APPROVE = 这份代码可以合并。(dvt B6 冻结期,APPROVE 仅表示代码可合;我自己不合。)
clestons
left a comment
There was a problem hiding this comment.
PR Review — #349
变更:@typescript-eslint/parser 8.69.0 → 8.70.0 (devDependency),仅 package.json/package-lock.json 版本号改动,无源码/逻辑/API 变更。
R1 (DeepSeek, 2-round):无 finding。api_compat unchanged,无并发/状态/安全面改动。
CI:Build / Code Quality / CodeQL / Smart Contracts / Tests / Type Check / cla-check 全绿。Security Audit / CI Success 失败 — 这是仓库级预存问题(multer 2.2.0 npm audit 欠账,见 B6 阻塞记录),与本次版本号改动无关,不构成本 PR 的阻塞项。
结论:APPROVE。代码可以合,但本仓库当前处于 B6 零合并冻结期,实际合并需等待冻结解除。
clestons
left a comment
There was a problem hiding this comment.
PR Review — #349
意图(T1):把 devDependency @typescript-eslint/parser 从 ^8.69.0 升到 ^8.70.0(dependabot 自动升级),并让 lockfile 与之一致。
结论:APPROVE。 代码可以合。本仓库当前处于 B6 零合并冻结期,实际合并需等冻结解除(合不合由维护者决定,我不合并)。
本轮性质:head 未变,第三次审同一棵树
- 当前 head
c27976e33aaff854a37d425cf103a2115cd5b71e,与之前两次 clestons APPROVE 的 commit 完全一致(2026-09-16、2026-10-02)。 merge-base(origin/master, head) == origin/master == 1991e921(2026-09-05),base 未前移,因此没有兄弟 PR 合并后的新树(Step 0b-2 不触发)。- 本次重新入队是记账产物:
pr_watch_targets.last_reviewed_head_oid为空,daemon 会一直把它当待审。本轮已回写完整 40 位 sha 修正。 - 我没有因为「审过两次」而跳过 R1:按 ABSOLUTE CONSTRAINT #5 两条豁免都不成立(这不是纯文档 PR,也没有「修我自己上一轮 findings」的增量),R1a/R1b 都真跑了。
变更范围(机械计数,非目测)
| 文件 | 改动 |
|---|---|
package.json |
1 行:"@typescript-eslint/parser": "^8.69.0" → "^8.70.0" |
package-lock.json |
8 处:1 bump + 7 处 nested 新增 |
lockfile 逐条比对(packages 全表,676 → 683):
BUMPED node_modules/@typescript-eslint/parser 8.69.0 -> 8.70.0
ADDED .../parser/node_modules/@typescript-eslint/project-service -> 8.70.0
ADDED .../parser/node_modules/@typescript-eslint/scope-manager -> 8.70.0
ADDED .../parser/node_modules/@typescript-eslint/tsconfig-utils -> 8.70.0
ADDED .../parser/node_modules/@typescript-eslint/types -> 8.70.0
ADDED .../parser/node_modules/@typescript-eslint/typescript-estree -> 8.70.0
ADDED .../parser/node_modules/@typescript-eslint/visitor-keys -> 8.70.0
ADDED .../parser/node_modules/eslint-visitor-keys -> 5.0.1
changed entries missing integrity: []
registry / integrity:8 处改动全部 registry.npmjs.org,sha512 integrity 齐全,没有任何一条 registry 从 npmjs 翻到镜像站。
更正上一轮 review 的一处措辞:上一轮写的是「resolved 全部 registry.npmjs.org」。整份 lockfile 里有 16 条 npmmirror 条目,但它们 base 就在、本 PR 一条没碰(
NEWLY non-npmjs: []、no longer non-npmjs: [])。准确说法是「本 PR 改动的 8 条全部 npmjs + integrity」。结论不变,但那句话对整文件是过宽的。
engines 交叉核对:新增的 nested eslint-visitor-keys@5.0.1 要求 ^20.19.0 || ^22.13.0 || >=24。仓库无 .npmrc、无 engine-strict;workflows 全部 node-version: "20",setup-node 解析到 20.x 最新版(≥20.19),满足。不构成 finding。
CI 检查(post 前现读 gh pr checks 349)
| 检查 | 结果 |
|---|---|
| Build / Tests / Type Check / Code Quality / Smart Contracts | pass |
| CodeQL / CodeQL Analysis (javascript-typescript) | pass |
| cla-check | pass |
| Security Audit | fail |
| CI Success | fail(聚合项,因 Security Audit 失败而失败,自身 4s) |
归因(这是本轮唯一需要动手的部分):Security Audit 的失败原因是 multer <=2.2.0 的 high advisory(日志原文 2 high severity vulnerabilities / high multer <=2.2.0 / npm audit found high-severity advisories)。而:
multer: "2.2.0"是package.jsonbase 上就有的固定依赖(第 79 行);- multer 不在本 PR 改动的 8 条 lockfile 条目里(
changed: 8; any multer among them: False)。
⇒ 该失败与本 PR 的 diff 无关,是仓库级预存欠账(B6 记录里的 npm audit 债)。同一 run 里还有 Path does not exist: trivy-results.sarif(SARIF 产物路径问题),同样是仓库级配置问题,与版本号改动无关。
R1(DeepSeek)与轮次
- R1a(full):
FINDINGS: none;GATE 信号security_surface_touched=NO, concurrency_or_state_touched=NO, api_compat=UNCHANGED→ 无强制升轮信号。 - R1b(security):
(none — no security-relevant surface in diff),SECURITY_TRIAGE: clean。 - 分级:2 轮。纯 devDependency 版本号 bump,devDependencies 不进生产产物,不碰
src//contracts//lib/逻辑,无 API/并发/状态/安全面。与 head 相同的两次前审一致。 - R1 的 context 已按 Step 2 的要求把被
compress_diff.py丢掉的 lockfile hunk 拼回去(194 行),不是只看版本号。
pre-pr-check
N/A —— 作者是 dependabot,无人工 PR body 可作答,本 PR 也没有需要机械自检的源码改动。
说明 / Assumptions
- 本 PR 三次进入队列、head 三次相同,我把「重新入队」判定为记账缺陷而非新工作,本轮据此只重跑验证 + 回写 sha,不刷新处置。
- 上一轮 review 中「整份 lockfile 全 npmjs」这一措辞过宽,本 PR 已按实测更正(见上);该更正不改变结论。
Bumps @typescript-eslint/parser from 8.69.0 to 8.70.0.
Release notes
Sourced from @typescript-eslint/parser's releases.
Changelog
Sourced from @typescript-eslint/parser's changelog.
Commits
7ee7608chore(release): publish 8.70.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)