Skip to content

chore(deps-dev): bump oxlint from 1.76.0 to 1.80.0 - #2769

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/oxlint-1.80.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/oxlint-1.80.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor

Bumps oxlint from 1.76.0 to 1.80.0.

Release notes

Sourced from oxlint's releases.

oxlint v1.80.0 & oxfmt v0.65.0

Table of Contents

Oxlint v1.80.0

🚀 Features

  • 70c3e35 linter/typescript/no-confusing-non-null-assertion: Implement suggestion (#26012) (Mikhail Baev)

🐛 Bug Fixes

  • 17ae11c linter/oxc/double-comparisons: Handle grouped logical expressions (#26044) (camc314)
  • 8a353a7 linter/eslint/no-control-regex: Refine help message text (#25996) (Rahul Mishra)
  • 8a9bdbd estree: Include decorators in FormalParameterRest spans (#26021) (camc314)
  • 8d94cd1 linter/eslint/no-useless-rename: Preserve type modifiers (#26020) (Cameron)
  • 2cde1f6 rust: Address nightly deprecations (#25998) (Boshen)
  • 51d36d7 linter/vue: Resolve vue imports via shared import helpers (#25903) (Connor Shea)
  • 83a68d2 linter/react/no-react-children: Resolve react imports by symbol (#25901) (Connor Shea)
  • 124e196 linter: Resolve globals by reference, not by name (#25905) (Connor Shea)
  • a701bcc linter: Remove invalid React compiler doc links (#25900) (Boshen)

📚 Documentation

  • 9b7e153 linter: Set version to 1.79.0 for rules shipped in 1.79.0 (#25902) (connorshea)

Oxfmt v0.65.0

🐛 Bug Fixes

  • bf37dd5 formatter: Preserve class decorators before export when the statement is suppressed (#26034) (leaysgur)

oxlint v1.79.0 & oxfmt v0.64.0

Table of Contents

Oxlint v1.79.0

💥 BREAKING CHANGES

  • 8c4552d linter: [BREAKING] Split react/react-compiler into per-category rules (#25500) (Boshen)

See React Compiler Support for details.

🚀 Features

  • 9b7394e linter/typescript/no-empty-object-type: Implement suggestion (#25833) (Mikhail Baev)

🐛 Bug Fixes

... (truncated)

Changelog

Sourced from oxlint's changelog.

Changelog

All notable changes to this package will be documented in this file.

The format is based on Keep a Changelog.

[1.82.0] - 2026-09-07

🚀 Features

  • 6a0e19c linter/eslint/no-unmodified-loop-condition: Support checkConditionalExpressions option (#26249) (camc314)

[1.81.0] - 2026-08-31

📚 Documentation

  • d5be037 linter/typescript/switch-exhaustiveness-check: Clarify default case comment pattern (#26100) (camc314)

[1.79.0] - 2026-08-18

💥 BREAKING CHANGES

  • 8c4552d linter: [BREAKING] Split react/react-compiler into per-category rules (#25500) (Boshen)

🐛 Bug Fixes

  • 228e8e0 linter: Resolve inactive React compiler rules (#25830) (Boshen)
  • aa49d86 linter: Allow spread rule options in config types (#25675) (ch3rry)
  • 36f8451 linter/eslint/no-eval: Align indirect default with ESLint (#25656) (camc314)
  • beb724d linter/eslint/no-unused-vars: Report bare underscore parameters (#25663) (camc314)
  • 4004c10 linter/eslint/no-irregular-whitespace: Check comments by default (#25660) (camc314)
  • 285820e linter/no-large-snapshots: Precompile and document allowed snapshot matchers (#25611) (Mikhail Baev)
  • 4df5835 linter: Allow capitalized built-in calls (#25516) (Boshen)

[1.78.0] - 2026-08-10

🚀 Features

  • ccb8fe8 linter/jsdoc: Implement no-blank-blocks rule (#25207) (Mikhail Baev)
  • d4a897c linter/eslint: Implement one-var rule (#24470) (Cole Ellison)
  • 5ab9340 linter/jsx-a11y/anchor-has-content: Add options to match eslint (#24571) (Cole Ellison)

🐛 Bug Fixes

  • 9573937 linter/typescript: Validate ban-ts-comment description_format (#25320) (Mikhail Baev)

[1.77.0] - 2026-08-03

🐛 Bug Fixes

... (truncated)

Commits
  • 97e99b8 release(apps): oxlint v1.80.0 && oxfmt v0.65.0 (#26045)
  • 0db127c release(apps): oxlint v1.79.0 && oxfmt v0.64.0 (#25866)
  • 228e8e0 fix(linter): resolve inactive React compiler rules (#25830)
  • aa49d86 fix(linter): allow spread rule options in config types (#25675)
  • 8922381 refactor(linter): remove inactive react config rule (#25740)
  • 8c4552d feat(linter)!: split react/react-compiler into per-category rules (#25500)
  • 36f8451 fix(linter/eslint/no-eval): align indirect default with ESLint (#25656)
  • beb724d fix(linter/eslint/no-unused-vars): report bare underscore parameters (#25663)
  • 4004c10 fix(linter/eslint/no-irregular-whitespace): check comments by default (#25660)
  • 285820e fix(linter/no-large-snapshots): precompile and document allowed snapshot matc...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) from 1.76.0 to 1.80.0.
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.80.0/npm/oxlint)

---
updated-dependencies:
- dependency-name: oxlint
  dependency-version: 1.80.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 7, 2026
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Dependency Triage: oxlint 1.76.0 → 1.80.0

Package: oxlint (dev dependency, oxc-project)
Semver level: minor (1.76 → 1.80, four minor releases bundled)
Manifests touched: root package.json + pnpm-lock.yaml (2 files)
Batch classification: Weekly batch (opened 2026-09-07 alongside the other 7 PRs, no GHSA quoted in body).
CI status observed: get_status on head SHA 5fba3b68be... returned state: pending, total_count: 0 — no checks have reported yet at the time of this triage. PR's mergeable_state is blocked, consistent with required checks not yet run rather than a merge conflict.

Upstream evidence

  • Source: oxc-project/oxc releases, maintained by the oxc-project org (Boshen et al.) — no maintainer or publishing-account change visible in the quoted release notes.
  • Release notes for 1.77.0–1.80.0 show routine bug fixes and one breaking change in 1.79.0: "Split react/react-compiler into per-category rules" (feat(linter)!: split react/react-compiler into per-category rules oxc-project/oxc#25500). This is a breaking change to lint rule configuration shipped inside a package pinned by exact version ("oxlint": "1.76.0" → "1.80.0", no caret), so it will not recur automatically, but the bump itself crosses that break.
  • Publish dates: 1.80.0 dated implicitly via the release changelog; the changelog also lists 1.81.0 (2026-08-31) and 1.82.0 (2026-09-07) as already available upstream but not included in this PR — i.e., Dependabot is not proposing the latest available version, consistent with the cooldown window still filtering out the newest releases.
  • I could not fetch a diff for install/postinstall script changes or new transitive dependencies beyond what the lockfile diff shows (only @oxlint/binding-* platform binaries version-bumped, one added @jridgewell/sourcemap-codec transitive version bump, svgo@4.0.2 and picomatch@4.0.5 duplicate entries removed as no-longer-needed pins). Nothing structurally new stood out in the visible lockfile diff.

Structural failure modes checked

  • Root-only manifest change with lockfile update together — no split-PR ERR_PNPM_OUTDATED_LOCKFILE pattern.
  • oxlint is not in pnpm-workspace.yaml overrides: — no ERR_PNPM_LOCKFILE_CONFIG_MISMATCH risk.
  • Not part of the react or lsp group.

Open questions for the reviewer

  • Confirm the lint config does not rely on the pre-1.79.0 combined react/react-compiler rule name, since that rule was split in this range — CI running oxlint should surface this immediately if broken, but worth checking config files under .oxlintrc* before merge.
  • CI has not yet reported; recommend waiting for actual check results before merging given mergeable_state: blocked.

Generated by Dependabot weekly triage · auto · 46 AIC · ⊞ 8.4K · ◷

@kompiro

kompiro commented Sep 7, 2026

Copy link
Copy Markdown
Owner

Holding this one — the bump itself is fine, the code it now lints is not.

Between 1.76 and 1.80 oxlint added React rules, several in correctness. With .oxlintrc.json setting categories.correctness: "error" and the root script running oxlint --deny-warnings, they became fatal without any config change here: 24 diagnostics (16 errors + 8 warnings) over 21 sites in 17 files, all in packages/app — react(refs), react(set-state-in-effect), react(globals), react(immutability), react(exhaustive-effect-dependencies), react(memo-dependencies).

Nothing in the upstream diff is suspect: 1.80.0 is published from GitHub Actions with SLSA provenance, boshen is still the sole maintainer, there is no install script, and the lock moves only the 19 platform binaries. The block is entirely on our side.

The findings are runtime-behavior ones (a ref read during render, a synchronous setState inside an effect), so they get their own PR rather than being bundled into a dependency bump or silenced by switching the new rules off: #2775.

Leaving this open rather than closing it — the judgment is hold, not reject, so no @dependabot ignore. Once #2775 lands, @dependabot rebase here and this PR's CI is what proves the sweep was complete.

Full analysis of this batch: #2773.

kompiro added a commit that referenced this pull request Sep 7, 2026
…sweep

The hold in the triage doc assumed a fix PR, then the bump. But the fix
PR runs oxlint 1.76, which does not carry the new rules, so its green is
not evidence the sweep was complete. Records where the verification
actually happens (#2769's CI after the rebase), and makes the local
1.80.0 run the acceptance criterion for the fix PR.

Also corrects the finding count: 24 diagnostics over 21 unique sites in
17 files, not 24 sites in 12 files.
kompiro added a commit that referenced this pull request Sep 7, 2026
Seven of the eight PRs were adopted, one held. Nothing on the supply
side: no new publisher, no transferred repo, no new lifecycle script, and
not one package name new to the lock.

Both CI failures came from the same shape — a declaration Dependabot
cannot reach living in the same repo. #2768 moved `@types/vscode` but not
`engines.vscode`; ADR-2562 had already settled that the three sites move
together, so it lands through replacement PR #2779, which raises the
required VS Code to 1.134. #2769 pulls in oxlint's new React rules, which
land in correctness and turn 24 diagnostics fatal under `--deny-warnings`
with no config change here; it is held while #2775 fixes the sites, and
the ADR records why the fix PR's own CI cannot verify that sweep.

Deletes the design doc it was promoted from.
@kompiro

kompiro commented Sep 8, 2026

Copy link
Copy Markdown
Owner

Closing in favour of #2784, which carries this bump plus the code and config changes it needs.

Working through the findings turned up a coupling that the earlier plan (hold this, fix separately, then rebase) did not survive: oxlint 1.76 rejects the config the fix needs.

x Rule 'globals' not found in plugin 'react'
x Rule 'immutability' not found in plugin 'react'

Three of the 21 sites are the same RegistryProbe test harness, and the right resolution for them is a test-file override — but 1.76 does not know those rule names and fails to start. So the config half could not land ahead of the bump, and the bump could not land ahead of the fixes. One commit it is.

That is the same conclusion ADR-2333 reached for the 1.61 → 1.76 bump, which I should have cited during the triage instead of rejecting the replacement-PR route on general grounds. ADR-2773 is being corrected accordingly.

Nothing was wrong with the bump itself: 1.80.0 is published from GitHub Actions with SLSA provenance, boshen is still the sole maintainer, there is no install script, and the lock moves only the 19 platform binaries.

The judgment stays adopt, so no @dependabot ignore — #2784 lands 1.80.0 and this PR will not be reopened for it.

@kompiro kompiro closed this Sep 8, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/oxlint-1.80.0 branch September 8, 2026 14:08
kompiro added a commit that referenced this pull request Sep 8, 2026
The ADR rejected both the replacement-PR route and the config route for
#2769 on general grounds, without citing ADR-2333 — which had reached the
opposite conclusion three weeks earlier on the 1.61 to 1.76 bump, for the
same reason that surfaced here: the fix has to ride in the same commit as
the bump.

Implementing #2775 made that concrete. oxlint 1.76 rejects the config the
fix needs outright ("Rule 'globals' not found in plugin 'react'"), so the
test-file override cannot land ahead of the bump and the bump cannot land
ahead of the fix. Bundling was not a preference, it was forced. #2769
moves from hold to adopt via replacement PR #2784.

Records the process gap too: dependency triage edits no files, so the
`paths:` triggers never fire and the past-decision check only ran when
start-dev reached the work — after the triage had been written.
kompiro added a commit that referenced this pull request Sep 8, 2026
* chore(app): take oxlint 1.80 and fix the React findings it adds

Replacement PR for the Dependabot bump in #2769. The bump and the fixes
have to share a commit: oxlint 1.76 rejects the config outright with
"Rule 'globals' not found in plugin 'react'", so the test-file override
below cannot land ahead of it.

Between 1.76 and 1.80 oxlint added React rules in `correctness`, which
`--deny-warnings` turns fatal here without any config change — 24
diagnostics over 21 sites. Resolved per rule class, the way ADR-2333 did
for the 1.61 to 1.76 bump:

- react(refs): `useLatestRef` and `use-command` now mirror into the ref
  from an effect instead of during render; AppShell assigns the parent's
  recompile ref in an effect and clears it on unmount; ProjectModeApp
  holds its ProjectManager in lazy state, which also stops it building a
  throwaway one on every render.
- react(set-state-in-effect): ProjectPicker adjusts during render, the
  theme provider reads the OS setting through useSyncExternalStore,
  useStyleSource derives its imports, DiffModeBanner derives the active
  record, and ChatPane resets by remounting on a key rather than through
  a watched prop. FileTree loads inside an async continuation with a
  cancellation guard, which also stops a slow load for a directory the
  user already left from overwriting a newer one.
- react(globals) / react(immutability): the three sites are the same
  RegistryProbe test harness, so the rules are off for test files,
  extending the override block that already exists for that reason.
- dependency arrays: `containingBlock` moves to module scope so the drag
  callbacks' empty deps are honest, and ChatPane's scroll effect reads
  `messages.length`. Three remaining deps are triggers the body cannot
  read, and say so inline.

Verified the test-file override does not disable the rules generally:
a probe that reassigns an outer binding still errors in a non-test file
and is silent in a test file.

Closes #2775

* fix(app): key the loaded style to the imports it came from

Deriving the imports fixed the effect's synchronous setState but lost
what the synchronous clear had been doing: with only a length check
guarding the return, a value loaded for one import set was served while a
different set was still resolving. An entry that drops its import and
then gains another showed the first import's styling in between, and
AppShell feeds this straight into useViewSvg, so the preview rendered it.

Tags the loaded value with the path and import list it came from and
serves it only on a match. Also covers the transition the old code
happened to get right, which no test had.

Found by CodeRabbit on #2784.
kompiro added a commit that referenced this pull request Sep 9, 2026
The #2768 section stated "判定は採用" in the present tense while the
decision table and the section below it record the final 保留 and the
closure of #2779. A reader hitting that line first came away thinking
@types/vscode had landed.

Says it was the initial judgment and points forward to where it changed,
and keeps what did not change: the floor is still going to 1.134, via
#2782, only later. The #2769 heading had the same shape — it still
announced the separate-PR plan that the bump's config requirement made
impossible — so it now names the arc instead of the abandoned plan.

Found by CodeRabbit on #2773.
kompiro added a commit that referenced this pull request Sep 9, 2026
* docs(design): triage the 2026-09-08 Dependabot batch

Analyze all eight open Dependabot PRs upstream: registry publisher and
provenance, install scripts, lock dependency edges, and GitHub advisories.
Nothing on the supply side: no new publisher, no transferred repo, no new
lifecycle script, and not one package name new to the lock.

Two PRs fail CI, both because a declaration Dependabot cannot reach lives
in the same repo. #2768 moves `@types/vscode` but not `engines.vscode`,
which the policy guard from ADR-2562 was written to catch; the fix is the
replacement PR that ADR already settled on. #2769 pulls in oxlint's new
React rules, which land in correctness and turn 24 existing sites fatal
under `--deny-warnings`; the recommendation is to hold the bump and fix
those sites in their own PR rather than bundle or silence them.

The other six are clean and recommended for merge as-is, including the
jsdom 29 to 30 major whose only breaking change is a Node floor the repo
already clears.

* docs(design): note that the oxlint fix PR's own CI cannot verify the sweep

The hold in the triage doc assumed a fix PR, then the bump. But the fix
PR runs oxlint 1.76, which does not carry the new rules, so its green is
not evidence the sweep was complete. Records where the verification
actually happens (#2769's CI after the rebase), and makes the local
1.80.0 run the acceptance criterion for the fix PR.

Also corrects the finding count: 24 diagnostics over 21 unique sites in
17 files, not 24 sites in 12 files.

* docs(adr): promote the 2026-09-08 Dependabot triage to ADR-2773

Seven of the eight PRs were adopted, one held. Nothing on the supply
side: no new publisher, no transferred repo, no new lifecycle script, and
not one package name new to the lock.

Both CI failures came from the same shape — a declaration Dependabot
cannot reach living in the same repo. #2768 moved `@types/vscode` but not
`engines.vscode`; ADR-2562 had already settled that the three sites move
together, so it lands through replacement PR #2779, which raises the
required VS Code to 1.134. #2769 pulls in oxlint's new React rules, which
land in correctness and turn 24 diagnostics fatal under `--deny-warnings`
with no config change here; it is held while #2775 fixes the sites, and
the ADR records why the fix PR's own CI cannot verify that sweep.

Deletes the design doc it was promoted from.

* docs(adr): change #2768 from adopt to hold in ADR-2773

Applying the triage turned up a constraint the analysis had missed.
`extester-bootstrap.mjs` calls `downloadCode("max")`, and `max` resolves
to the highest VS Code the pinned `vscode-extension-tester` declares
support for — 1.131.0 on 8.24.0 — so `engines.vscode` cannot exceed it.
Replacement PR #2779 failed on exactly that and is closed.

Raising the floor therefore needs an ExTester bump, and both candidates
break a policy: 8.25.0 clears cooldown but adds `extract-zip@2.0.1`,
which carries an unpatched high advisory (CVE-2026-56876) that upstream
itself backed away from in 8.26.0; 8.26.0 is clean but one day old.
Deferring to 2026-09-14 breaks neither and costs six days of a type
bump, so #2768 becomes a hold folded into #2782.

Also records that this second constraint on the floor has no machine
check, unlike the equality one.

* docs(adr): correct the overrides claim in ADR-2773

Both this ADR and ADR-2753 said `pnpm-workspace.yaml`'s `overrides:` is
empty, so `ERR_PNPM_LOCKFILE_CONFIG_MISMATCH` could not occur. That check
read `package.json`'s `pnpm.overrides`, which pnpm 11 ignores — the
source of truth is `pnpm-workspace.yaml`, exactly as
`.claude/rules/dependabot.md` warns. It holds 23 floors, five of them
touching this batch.

Redone properly, every resolved version clears its floor, which matches
CI staying green on `--frozen-lockfile`. So the outcome stands and the
stated reason does not: it is "the floors were satisfied", not "there are
no floors".

ADR-2753 carries the same false sentence, and the svgo it merged is on
the override list — the "direct dependency with an override" shape the
rules call out. Its body stays as written (ADR-2687), so the correction
lives here.

Found by CodeRabbit on #2773.

* docs(adr): correct ADR-2773 for the ADR-2333 precedent it missed

The ADR rejected both the replacement-PR route and the config route for
#2769 on general grounds, without citing ADR-2333 — which had reached the
opposite conclusion three weeks earlier on the 1.61 to 1.76 bump, for the
same reason that surfaced here: the fix has to ride in the same commit as
the bump.

Implementing #2775 made that concrete. oxlint 1.76 rejects the config the
fix needs outright ("Rule 'globals' not found in plugin 'react'"), so the
test-file override cannot land ahead of the bump and the bump cannot land
ahead of the fix. Bundling was not a preference, it was forced. #2769
moves from hold to adopt via replacement PR #2784.

Records the process gap too: dependency triage edits no files, so the
`paths:` triggers never fire and the past-decision check only ran when
start-dev reached the work — after the triage had been written.

* docs(adr): mark #2768's adopt as the judgment it started at

The #2768 section stated "判定は採用" in the present tense while the
decision table and the section below it record the final 保留 and the
closure of #2779. A reader hitting that line first came away thinking
@types/vscode had landed.

Says it was the initial judgment and points forward to where it changed,
and keeps what did not change: the floor is still going to 1.134, via
#2782, only later. The #2769 heading had the same shape — it still
announced the separate-PR plan that the bump's config requirement made
impossible — so it now names the arc instead of the abandoned plan.

Found by CodeRabbit on #2773.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant