Skip to content

build(deps-dev): bump eslint-plugin-import from 2.31.0 to 2.32.0 - #39

Merged
UlisesGascon merged 1 commit into
masterfrom
dependabot/npm_and_yarn/eslint-plugin-import-2.32.0
Sep 14, 2026
Merged

UlisesGascon merged 1 commit into
masterfrom
dependabot/npm_and_yarn/eslint-plugin-import-2.32.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 1, 2025

Copy link
Copy Markdown
Contributor

Bumps eslint-plugin-import from 2.31.0 to 2.32.0.

Release notes

Sourced from eslint-plugin-import's releases.

v2.32.0

Added

Fixed

Changed

... (truncated)

Changelog

Sourced from eslint-plugin-import's changelog.

[2.32.0] - 2025-06-20

Added

  • add [enforce-node-protocol-usage] rule and import/node-version setting (#3024, thanks [@​GoldStrikeArch] and [@​sevenc-nanashi])
  • add TypeScript types (#3097, thanks [@​G-Rath])
  • [extensions]: add `pathGroupOverrides to allow enforcement decision overrides based on specifier (#3105, thanks [@​Xunnamius])
  • [order]: add sortTypesGroup option to allow intragroup sorting of type-only imports (#3104, thanks [@​Xunnamius])
  • [order]: add newlines-between-types option to control intragroup sorting of type-only imports (#3127, thanks [@​Xunnamius])
  • [order]: add consolidateIslands option to collapse excess spacing for aesthetically pleasing imports (#3129, thanks [@​Xunnamius])

Fixed

  • [no-unused-modules]: provide more meaningful error message when no .eslintrc is present (#3116, thanks [@​michaelfaith])
  • configs: added missing name attribute for eslint config inspector (#3151, thanks [@​NishargShah])
  • [order]: ensure arcane imports do not cause undefined behavior (#3128, thanks [@​Xunnamius])
  • [order]: resolve undefined property access issue when using named ordering (#3166, thanks [@​Xunnamius])
  • [enforce-node-protocol-usage]: avoid a crash with some TS code (#3173, thanks [@​ljharb])
  • [order]: codify invariants from docs into config schema (#3152, thanks [@​Xunnamius])

Changed

Commits
  • 01c9eb0 v2.32.0
  • ae57cc1 [Deps] update array-includes, array.prototype.findlastindex, `eslint-modu...
  • 9e1ad6b [Fix] order: codify invariants from docs into config schema
  • f017790 [Docs] no-restricted-paths: clarify wording and fix errors
  • 7d83a57 [Docs] no-unused-modules: add missing double quote
  • 519eb94 [utils] v2.12.1
  • 71ad145 [actions] split out tests into new vs old eslint
  • 9b096c4 [utils] [dev deps] update @arethetypeswrong/cli, @ljharb/tsconfig, `@type...
  • da5f6ec [Fix] enforce-node-protocol-usage: avoid a crash with some TS code
  • 6e49a58 [Refactor] order: remove unnecessary negative check
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [eslint-plugin-import](https://github.com/import-js/eslint-plugin-import) from 2.31.0 to 2.32.0.
- [Release notes](https://github.com/import-js/eslint-plugin-import/releases)
- [Changelog](https://github.com/import-js/eslint-plugin-import/blob/main/CHANGELOG.md)
- [Commits](import-js/eslint-plugin-import@v2.31.0...v2.32.0)

---
updated-dependencies:
- dependency-name: eslint-plugin-import
  dependency-version: 2.32.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 1, 2025
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedeslint-plugin-import@​2.31.0 ⏵ 2.32.09810010087100

View full report

@UlisesGascon UlisesGascon self-assigned this Sep 14, 2026
@UlisesGascon
UlisesGascon merged commit 655e895 into master Sep 14, 2026
@UlisesGascon
UlisesGascon deleted the dependabot/npm_and_yarn/eslint-plugin-import-2.32.0 branch September 14, 2026 14:57
@UlisesGascon UlisesGascon mentioned this pull request Sep 14, 2026
meta-codesync Bot pushed a commit to facebook/memlab that referenced this pull request Oct 9, 2026
Summary:
Bumps [[https://github.com/jshttp/proxy-addr | proxy-addr]] from 2.0.7 to 2.0.8.

== Release notes ==

//Sourced from [[https://github.com/jshttp/proxy-addr/releases | proxy-addr's releases]].//

> **2.0.8**
>
> **Important**
>
> - Fix [[https://www.cve.org/CVERecord?id=CVE-2026-90711 | CVE-2026-90711]] ([[GHSA-jqcg-44mw-7w3h | GHSA-jqcg-44mw-7w3h]])
>
> **What's Changed**
>
> - Add OSSF scorecard action by [[https://github.com/carpasse | @​carpasse]] in [[jshttp/proxy-addr#27 | jshttp/proxy-addr#27]]
> - Fix ci pipeline and add missing Node.JS versions by [[https://github.com/carpasse | @​carpasse]] in [[jshttp/proxy-addr#26 | jshttp/proxy-addr#26]]
> - [StepSecurity] Apply security best practices by [[https://github.com/step-security-bot | @​step-security-bot]] in [[jshttp/proxy-addr#29 | jshttp/proxy-addr#29]]
> - build(deps): bump coverallsapp/github-action from 1.2.5 to 2.3.6 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#30 | jshttp/proxy-addr#30]]
> - build(deps): bump github/codeql-action from 2.23.2 to 3.28.18 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#31 | jshttp/proxy-addr#31]]
> - build(deps-dev): bump eslint-plugin-import from 2.23.4 to 2.31.0 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#32 | jshttp/proxy-addr#32]]
> - build(deps): bump ossf/scorecard-action from 2.0.6 to 2.4.2 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#33 | jshttp/proxy-addr#33]]
> - build(deps): bump actions/upload-artifact from 3.1.3 to 4.6.2 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#35 | jshttp/proxy-addr#35]]
> - build(deps-dev): bump deep-equal from 1.0.1 to 1.1.2 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#34 | jshttp/proxy-addr#34]]
> - build(deps-dev): bump eslint-plugin-markdown from 2.2.0 to 2.2.1 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#36 | jshttp/proxy-addr#36]]
> - chore: add funding to package.json by [[https://github.com/Phillip9587 | @​Phillip9587]] in [[jshttp/proxy-addr#40 | jshttp/proxy-addr#40]]
> - build(deps): bump github/codeql-action from 3.28.18 to 3.29.5 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#41 | jshttp/proxy-addr#41]]
> - build(deps): bump github/codeql-action from 3.29.7 to 3.29.11 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#43 | jshttp/proxy-addr#43]]
> - build(deps): bump actions/checkout from 3.6.0 to 5.0.0 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#42 | jshttp/proxy-addr#42]]
> - build(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#47 | jshttp/proxy-addr#47]]
> - build(deps): bump github/codeql-action from 3.29.11 to 4.31.2 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#46 | jshttp/proxy-addr#46]]
> - build(deps): bump coverallsapp/github-action from 2.3.6 to 2.3.7 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#50 | jshttp/proxy-addr#50]]
> - build(deps): bump github/codeql-action from 4.31.2 to 4.31.5 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#49 | jshttp/proxy-addr#49]]
> - build(deps): bump actions/checkout from 5.0.0 to 6.0.0 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#48 | jshttp/proxy-addr#48]]
> - build(deps): bump actions/checkout from 6.0.0 to 6.0.2 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#56 | jshttp/proxy-addr#56]]
> - build(deps): bump github/codeql-action from 4.31.5 to 4.32.0 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#55 | jshttp/proxy-addr#55]]
> - build(deps): bump github/codeql-action from 4.32.0 to 4.32.4 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#57 | jshttp/proxy-addr#57]]
> - build(deps): bump actions/upload-artifact from 5.0.0 to 7.0.0 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#58 | jshttp/proxy-addr#58]]
> - Fix "arugment" typo in README by [[https://github.com/schiwekM | @​schiwekM]] in [[jshttp/proxy-addr#61 | jshttp/proxy-addr#61]]
> - build(deps): bump github/codeql-action from 4.32.4 to 4.36.0 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#64 | jshttp/proxy-addr#64]]
> - build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#63 | jshttp/proxy-addr#63]]
> - build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#45 | jshttp/proxy-addr#45]]
> - build(deps-dev): bump eslint-plugin-import from 2.31.0 to 2.32.0 by [[https://github.com/dependabot | @​dependabot]][bot] in [[jshttp/proxy-addr#39 | jshttp/proxy-addr#39]]
> - chore(ci): npm-publish via reusable workflows by [[https://github.com/sheplu | @​sheplu]] in [[jshttp/proxy-addr#54 | jshttp/proxy-addr#54]]
> - refresh CI by [[https://github.com/UlisesGascon | @​UlisesGascon]] in [[jshttp/proxy-addr#69 | jshttp/proxy-addr#69]]
> - fix: typo by [[https://github.com/UlisesGascon | @​UlisesGascon]] in [[jshttp/proxy-addr#71 | jshttp/proxy-addr#71]]
> - Release: 2.0.8 by [[https://github.com/UlisesGascon | @​UlisesGascon]] in [[jshttp/proxy-addr#70 | jshttp/proxy-addr#70]]
>
> **New Contributors**
>
> - [[https://github.com/carpasse | @​carpasse]] made their first contribution in [[jshttp/proxy-addr#27 | jshttp/proxy-addr#27]]
> - [[https://github.com/step-security-bot | @​step-security-bot]] made their first contribution in [[jshttp/proxy-addr#29 | jshttp/proxy-addr#29]]
> - [[https://github.com/dependabot | @​dependabot]][bot] made their first contribution in [[jshttp/proxy-addr#30 | jshttp/proxy-addr#30]]
> - [[https://github.com/Phillip9587 | @​Phillip9587]] made their first contribution in [[jshttp/proxy-addr#40 | jshttp/proxy-addr#40]]
> - [[https://github.com/schiwekM | @​schiwekM]] made their first contribution in [[jshttp/proxy-addr#61 | jshttp/proxy-addr#61]]
> - [[https://github.com/sheplu | @​sheplu]] made their first contribution in [[jshttp/proxy-addr#54 | jshttp/proxy-addr#54]]
>
> **Full Changelog**: jshttp/proxy-addr@v2.0.7...v2.0.8

== Changelog ==

//Sourced from [[https://github.com/jshttp/proxy-addr/blob/master/HISTORY.md | proxy-addr's changelog]].//

> **2.0.8**
>
> - Fix [[https://www.cve.org/CVERecord?id=CVE-2026-90711 | CVE-2026-90711]] ([[GHSA-jqcg-44mw-7w3h | GHSA-jqcg-44mw-7w3h]])

== Commits ==

- [[jshttp/proxy-addr@a11ad82 | a11ad82]] 2.0.8 ([[jshttp/proxy-addr#70 | #70]])
- [[jshttp/proxy-addr@780911d | 780911d]] fix: reject IPv4 trust via mapped IPv6 subnets with a short prefix
- [[jshttp/proxy-addr@92e103e | 92e103e]] fix(ci): use publised as release trigger event ([[jshttp/proxy-addr#71 | #71]])
- [[jshttp/proxy-addr@3e5ac75 | 3e5ac75]] ci: merge coverage via artifacts, disable fail-fast, add Node.js 23-26 ([[jshttp/proxy-addr#69 | #69]])
- [[jshttp/proxy-addr@4b9db81 | 4b9db81]] chore(ci): npm-publish via workflows ([[jshttp/proxy-addr#54 | #54]])
- [[jshttp/proxy-addr@655e895 | 655e895]] build(deps-dev): bump eslint-plugin-import from 2.31.0 to 2.32.0 ([[jshttp/proxy-addr#39 | #39]])
- [[jshttp/proxy-addr@50ce4d0 | 50ce4d0]] build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 ([[jshttp/proxy-addr#45 | #45]])
- [[jshttp/proxy-addr@0fd347f | 0fd347f]] build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 ([[jshttp/proxy-addr#63 | #63]])
- [[jshttp/proxy-addr@6a517fa | 6a517fa]] build(deps): bump github/codeql-action from 4.32.4 to 4.36.0 ([[jshttp/proxy-addr#64 | #64]])
- [[jshttp/proxy-addr@0d45e2a | 0d45e2a]] Fix "arugment" typo in README ([[jshttp/proxy-addr#61 | #61]])
- Additional commits viewable in [[jshttp/proxy-addr@v2.0.7...v2.0.8 | compare view]]

== Maintainer changes ==

This version was pushed to npm by [[https://www.npmjs.com/~GitHub%20Actions | GitHub Actions]], a new releaser for proxy-addr since your current version.

Pull Request resolved: #159

Reviewed By: boujeepossum

Differential Revision: D124273538

Pulled By: JacksonGL

fbshipit-source-id: 6a06bb9ac8395ba2225ee76fab79fb9099bb16f1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant