Skip to content

chore(deps-dev): bump @typescript-eslint/parser from 8.69.0 to 8.70.0 - #349

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/typescript-eslint/parser-8.70.0
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/typescript-eslint/parser-8.70.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 16, 2026

Copy link
Copy Markdown
Contributor

Bumps @typescript-eslint/parser from 8.69.0 to 8.70.0.

Release notes

Sourced from @​typescript-eslint/parser's releases.

v8.70.0

8.70.0 (2026-09-07)

🚀 Features

  • eslint-plugin: [no-generated-empty-object-type] add rule (#12730)
  • website: generate per-page social preview cards (#12734)

🩹 Fixes

  • use stable release of pnpm 12 (#12808)
  • update pnpm to 12.3.4 and dedupe Docusaurus packages (#12829)
  • eslint-plugin: [member-ordering] don't report fields that read fields declared before them (#12729)
  • eslint-plugin: [no-unnecessary-condition] no false positive on RHS of a nested logical expression (#12728)
  • eslint-plugin: [no-deprecated] report deprecated imported values used in object shorthand properties (#12780)
  • project-service: avoid discarded tsserver logs (#12748)
  • typescript-estree: clarify the parserOptions.project error message (#12817)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Changelog

Sourced from @​typescript-eslint/parser's changelog.

8.70.0 (2026-09-07)

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) from 8.69.0 to 8.70.0.
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.0/packages/parser)

---
updated-dependencies:
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.70.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 16, 2026

@clestons clestons left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE — chore(deps-dev): @typescript-eslint/parser 8.69.0 → 8.70.0

[2-round](R1a DeepSeek + 执行器机械核验;纯 bump 跳 Codex PK)· dependabot · package.json + package-lock.json only。

  • 纯 dev-dependency patch bump,无 runtime、无逻辑改动。
  • lockfile 机械核验:resolved 全部 registry.npmjs.org(无 npmmirror/taobao 翻转)、8 处 integrity sha512 齐全、只动版本号。
  • eslint 工具链内部子包(scope-manager/types/typescript-estree 等)随之对齐到 8.70.0,一致。

APPROVE = 这份代码可以合并。(dvt B6 冻结期,APPROVE 仅表示代码可合;我自己不合。)

@clestons clestons left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PR Review — #349

变更:@typescript-eslint/parser 8.69.0 → 8.70.0 (devDependency),仅 package.json/package-lock.json 版本号改动,无源码/逻辑/API 变更。

R1 (DeepSeek, 2-round):无 finding。api_compat unchanged,无并发/状态/安全面改动。

CI:Build / Code Quality / CodeQL / Smart Contracts / Tests / Type Check / cla-check 全绿。Security Audit / CI Success 失败 — 这是仓库级预存问题(multer 2.2.0 npm audit 欠账,见 B6 阻塞记录),与本次版本号改动无关,不构成本 PR 的阻塞项。

结论:APPROVE。代码可以合,但本仓库当前处于 B6 零合并冻结期,实际合并需等待冻结解除。

@clestons clestons left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PR Review — #349

意图(T1):把 devDependency @typescript-eslint/parser 从 ^8.69.0 升到 ^8.70.0(dependabot 自动升级),并让 lockfile 与之一致。

结论:APPROVE。 代码可以合。本仓库当前处于 B6 零合并冻结期,实际合并需等冻结解除(合不合由维护者决定,我不合并)。

本轮性质:head 未变,第三次审同一棵树

  • 当前 head c27976e33aaff854a37d425cf103a2115cd5b71e,与之前两次 clestons APPROVE 的 commit 完全一致(2026-09-16、2026-10-02)。
  • merge-base(origin/master, head) == origin/master == 1991e921(2026-09-05),base 未前移,因此没有兄弟 PR 合并后的新树(Step 0b-2 不触发)。
  • 本次重新入队是记账产物:pr_watch_targets.last_reviewed_head_oid 为空,daemon 会一直把它当待审。本轮已回写完整 40 位 sha 修正。
  • 我没有因为「审过两次」而跳过 R1:按 ABSOLUTE CONSTRAINT #5 两条豁免都不成立(这不是纯文档 PR,也没有「修我自己上一轮 findings」的增量),R1a/R1b 都真跑了。

变更范围(机械计数,非目测)

文件 改动
package.json 1 行:"@typescript-eslint/parser": "^8.69.0" → "^8.70.0"
package-lock.json 8 处:1 bump + 7 处 nested 新增

lockfile 逐条比对(packages 全表,676 → 683):

BUMPED   node_modules/@typescript-eslint/parser            8.69.0 -> 8.70.0
ADDED    .../parser/node_modules/@typescript-eslint/project-service     -> 8.70.0
ADDED    .../parser/node_modules/@typescript-eslint/scope-manager       -> 8.70.0
ADDED    .../parser/node_modules/@typescript-eslint/tsconfig-utils      -> 8.70.0
ADDED    .../parser/node_modules/@typescript-eslint/types               -> 8.70.0
ADDED    .../parser/node_modules/@typescript-eslint/typescript-estree   -> 8.70.0
ADDED    .../parser/node_modules/@typescript-eslint/visitor-keys        -> 8.70.0
ADDED    .../parser/node_modules/eslint-visitor-keys                    -> 5.0.1
changed entries missing integrity: []

registry / integrity:8 处改动全部 registry.npmjs.org,sha512 integrity 齐全,没有任何一条 registry 从 npmjs 翻到镜像站。

更正上一轮 review 的一处措辞:上一轮写的是「resolved 全部 registry.npmjs.org」。整份 lockfile 里有 16 条 npmmirror 条目,但它们 base 就在、本 PR 一条没碰(NEWLY non-npmjs: []、no longer non-npmjs: [])。准确说法是「本 PR 改动的 8 条全部 npmjs + integrity」。结论不变,但那句话对整文件是过宽的。

engines 交叉核对:新增的 nested eslint-visitor-keys@5.0.1 要求 ^20.19.0 || ^22.13.0 || >=24。仓库无 .npmrc、无 engine-strict;workflows 全部 node-version: "20",setup-node 解析到 20.x 最新版(≥20.19),满足。不构成 finding。

CI 检查(post 前现读 gh pr checks 349)

检查 结果
Build / Tests / Type Check / Code Quality / Smart Contracts pass
CodeQL / CodeQL Analysis (javascript-typescript) pass
cla-check pass
Security Audit fail
CI Success fail(聚合项,因 Security Audit 失败而失败,自身 4s)

归因(这是本轮唯一需要动手的部分):Security Audit 的失败原因是 multer <=2.2.0 的 high advisory(日志原文 2 high severity vulnerabilities / high multer <=2.2.0 / npm audit found high-severity advisories)。而:

  • multer: "2.2.0" 是 package.json base 上就有的固定依赖(第 79 行);
  • multer 不在本 PR 改动的 8 条 lockfile 条目里(changed: 8; any multer among them: False)。

⇒ 该失败与本 PR 的 diff 无关,是仓库级预存欠账(B6 记录里的 npm audit 债)。同一 run 里还有 Path does not exist: trivy-results.sarif(SARIF 产物路径问题),同样是仓库级配置问题,与版本号改动无关。

R1(DeepSeek)与轮次

  • R1a(full):FINDINGS: none;GATE 信号 security_surface_touched=NO, concurrency_or_state_touched=NO, api_compat=UNCHANGED → 无强制升轮信号。
  • R1b(security):(none — no security-relevant surface in diff),SECURITY_TRIAGE: clean。
  • 分级:2 轮。纯 devDependency 版本号 bump,devDependencies 不进生产产物,不碰 src//contracts//lib/ 逻辑,无 API/并发/状态/安全面。与 head 相同的两次前审一致。
  • R1 的 context 已按 Step 2 的要求把被 compress_diff.py 丢掉的 lockfile hunk 拼回去(194 行),不是只看版本号。

pre-pr-check

N/A —— 作者是 dependabot,无人工 PR body 可作答,本 PR 也没有需要机械自检的源码改动。

说明 / Assumptions

  • 本 PR 三次进入队列、head 三次相同,我把「重新入队」判定为记账缺陷而非新工作,本轮据此只重跑验证 + 回写 sha,不刷新处置。
  • 上一轮 review 中「整份 lockfile 全 npmjs」这一措辞过宽,本 PR 已按实测更正(见上);该更正不改变结论。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant