Skip to content

[CSR-0] chore: Bump eslint-plugin-turbo from 2.8.20 to 2.10.12 - #415

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/eslint-plugin-turbo-2.10.12
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/eslint-plugin-turbo-2.10.12

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Bumps eslint-plugin-turbo from 2.8.20 to 2.10.12.

Release notes

Sourced from eslint-plugin-turbo's releases.

Turborepo v2.10.12

What's Changed

Changelog

... (truncated)

Commits


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot @github

dependabot Bot commented on behalf of github Aug 31, 2026

Copy link
Copy Markdown
Contributor Author

Assignees

The following users could not be added as assignees: ynahmany. Either the username does not exist or it does not have the correct permissions to be added as an assignee.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 31, 2026
Bumps [eslint-plugin-turbo](https://github.com/vercel/turborepo/tree/HEAD/packages/eslint-plugin-turbo) from 2.8.20 to 2.10.12.
- [Release notes](https://github.com/vercel/turborepo/releases)
- [Changelog](https://github.com/vercel/turborepo/blob/main/RELEASE.md)
- [Commits](https://github.com/vercel/turborepo/commits/v2.10.12/packages/eslint-plugin-turbo)

---
updated-dependencies:
- dependency-name: eslint-plugin-turbo
  dependency-version: 2.10.12
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/eslint-plugin-turbo-2.10.12 branch from f830d9f to 4a205f2 Compare August 31, 2026 15:34

Copy link
Copy Markdown
Contributor

Security triage: Tier B — the named bump is fine; the lockfile it ships with is not.

What and why — eslint-plugin-turbo 2.8.20 → 2.10.12 (minor, same major, direct:development). This closes no security finding. npm audit on this repo reports @humanfs/node (moderate, <0.16.8), vitest / @vitest/mocker (moderate, ≤4.1.10) and esbuild (low, 0.27.3–0.28.0); none of them is this package. There is no Vanta finding for this repo due inside the next 30 days.

Exposure — development. Declared in the root devDependencies; it is a lint rule set and reaches no published package.

The fix — manifest bump plus lockfile refresh, one manifest, edit confined to devDependencies. It also widens the declared range from ^2.0.0 to ^2.10.12, which is a deliberate narrowing of what will resolve in future installs — worth knowing, not objectionable.

Why Tier B — the regenerated lockfile does more than the title says. Alongside the eslint-plugin-turbo stanza it strips "peer": true from roughly 25 @esbuild/* platform stanzas (@esbuild/aix-ppc64, android-*, darwin-*, linux-*, win32-*, …). That is npm re-deriving peer marking across the whole tree, unrelated to the named bump, and it puts the diff well past the small-lockfile bar this routine will merge unattended. The same churn appears in #411, #412, #413, #414, #416, #417 and #418 — it is a property of regenerating this lockfile right now, not of any one bump.

Breaking-change check — turborepo releases 2.9–2.10 are covered by the repo's own RELEASE.md; I found no breaking-change or rule-removal section in that range for eslint-plugin-turbo.

CI coverage — this repo's lint, types-matrix and unit-test workflows all run on every PR to main with no paths filter, so a dependency-only diff triggers all three. Types Matrix concluded success on head 4a205f2 (run 33409266789).

Verification — I read the diff and resolved the dependency scope from the root manifest. I did not run this repo's scripts against this branch.

What a human should still check — whether the "peer": true removals across the @esbuild/* stanzas are wanted here, since they will land on main with this merge and are not what the title advertises. If they are, this is otherwise a routine dev-tooling bump.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants