Skip to content

build: Bump the backend-minor group across 1 directory with 17 updates - #205

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/backend-minor-a2495560b4
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/backend-minor-a2495560b4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the backend-minor group with 17 updates in the / directory:

Package From To
@nestjs/throttler 6.5.0 6.7.0
@opentelemetry/auto-instrumentations-node 0.79.0 0.80.0
@opentelemetry/exporter-trace-otlp-http 0.221.0 0.222.0
@opentelemetry/resources 2.10.0 2.11.0
@opentelemetry/sdk-node 0.221.0 0.222.0
jose 6.2.10 6.2.12
@types/node 26.4.0 26.6.2
@typescript-eslint/eslint-plugin 8.68.0 8.70.1
@typescript-eslint/parser 8.68.0 8.70.1
eslint 10.9.1 10.11.0
eslint-plugin-sonarjs 4.2.0 4.2.1
globals 17.11.0 17.12.0
jest 30.5.0 30.5.2
prettier 3.9.6 3.9.9
supertest 7.2.2 7.3.0
ts-jest 29.4.12 29.4.13
typescript-eslint 8.68.0 8.70.1

Updates @nestjs/throttler from 6.5.0 to 6.7.0

Release notes

Sourced from @​nestjs/throttler's releases.

v6.7.0

Minor Changes

  • 7004a97: Normalize IPv6 source addresses in the default tracker, and evict expired records from the in-memory storage.

    The built-in getTracker returned req.ip verbatim, so a client holding an IPv6 allocation could send every request from a different address within its own subnet and never share a counter, defeating the rate limit. Addresses are now masked to a /64 before being used as the tracker; the prefix length is configurable via the new ipv6SubnetPrefix module option. IPv4 addresses, IPv4-mapped addresses, the loopback, and custom getTracker implementations are unaffected.

    ThrottlerStorageService also never removed records, so a stream of requests from distinct trackers grew the internal map for the lifetime of the process. Idle records are now swept out once their window has fully elapsed. Limiting behaviour is unchanged: a record is only dropped after every pending hit has expired and any block has lapsed.

    Note that the tracker string for IPv6 clients changes shape (2001:db8:0:1::/64), so storage keys rotate once on upgrade.

v6.6.0

Minor Changes

  • c342bad: Declare the supported Node versions in engines, matching the range the CI matrix tests
  • c625e98: Update to allow for support for Nest version 12
Changelog

Sourced from @​nestjs/throttler's changelog.

6.7.0

Minor Changes

  • 7004a97: Normalize IPv6 source addresses in the default tracker, and evict expired records from the in-memory storage.

    The built-in getTracker returned req.ip verbatim, so a client holding an IPv6 allocation could send every request from a different address within its own subnet and never share a counter, defeating the rate limit. Addresses are now masked to a /64 before being used as the tracker; the prefix length is configurable via the new ipv6SubnetPrefix module option. IPv4 addresses, IPv4-mapped addresses, the loopback, and custom getTracker implementations are unaffected.

    ThrottlerStorageService also never removed records, so a stream of requests from distinct trackers grew the internal map for the lifetime of the process. Idle records are now swept out once their window has fully elapsed. Limiting behaviour is unchanged: a record is only dropped after every pending hit has expired and any block has lapsed.

    Note that the tracker string for IPv6 clients changes shape (2001:db8:0:1::/64), so storage keys rotate once on upgrade.

6.6.0

Minor Changes

  • c342bad: Declare the supported Node versions in engines, matching the range the CI matrix tests
  • c625e98: Update to allow for support for Nest version 12

6.4.0

6.5.1

Patch Changes

  • 603cb82: handles edge case where multiple clients making frequent requests interfere with each other
Commits
  • cc1834c Merge pull request #2696 from nestjs/changeset-release/master
  • 22c1797 chore: version packages
  • e0d634e Merge pull request #2695 from nestjs/fix/ipv6-tracker-normalization
  • e0b3928 docs: add a security policy
  • 7004a97 fix: normalize ipv6 trackers and evict stale throttler records
  • 4c98809 chore: version packages
  • 1977e00 ci: update release flow for trusted publishing
  • b69e1c9 chore: update lockfile and workspace for newer pnpm
  • c342bad ci: restore the release pipeline and align the toolchain
  • 194da4a chore(deps): update nest monorepo to v11.2.4
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​nestjs/throttler since your current version.


Updates @opentelemetry/auto-instrumentations-node from 0.79.0 to 0.80.0

Release notes

Sourced from @​opentelemetry/auto-instrumentations-node's releases.

auto-instrumentations-node: v0.80.0

0.80.0 (2026-08-31)

Features

  • deps: update deps matching '@opentelemetry/*' (#3716) (015582a)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-amqplib bumped from ^0.68.0 to ^0.69.0
      • @​opentelemetry/instrumentation-aws-lambda bumped from ^0.73.0 to ^0.74.0
      • @​opentelemetry/instrumentation-aws-sdk bumped from ^0.76.0 to ^0.77.0
      • @​opentelemetry/instrumentation-bunyan bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-cassandra-driver bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-connect bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-cucumber bumped from ^0.37.0 to ^0.38.0
      • @​opentelemetry/instrumentation-dataloader bumped from ^0.38.0 to ^0.39.0
      • @​opentelemetry/instrumentation-dns bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-express bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.40.0 to ^0.41.0
      • @​opentelemetry/instrumentation-generic-pool bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-graphql bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-hapi bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-host-metrics bumped from ^0.4.0 to ^0.5.0
      • @​opentelemetry/instrumentation-ioredis bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-kafkajs bumped from ^0.30.0 to ^0.31.0
      • @​opentelemetry/instrumentation-knex bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-koa bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-lru-memoizer bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-memcached bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-mongodb bumped from ^0.74.0 to ^0.75.0
      • @​opentelemetry/instrumentation-mongoose bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-mysql bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-mysql2 bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-nestjs-core bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-net bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-openai bumped from ^0.19.0 to ^0.20.0
      • @​opentelemetry/instrumentation-oracledb bumped from ^0.46.0 to ^0.47.0
      • @​opentelemetry/instrumentation-pg bumped from ^0.73.0 to ^0.74.0
      • @​opentelemetry/instrumentation-pino bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-redis bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-restify bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-router bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-runtime-node bumped from ^0.34.0 to ^0.35.0
      • @​opentelemetry/instrumentation-socket.io bumped from ^0.68.0 to ^0.69.0
      • @​opentelemetry/instrumentation-tedious bumped from ^0.40.0 to ^0.41.0

... (truncated)

Changelog

Sourced from @​opentelemetry/auto-instrumentations-node's changelog.

0.80.0 (2026-08-31)

Features

  • deps: update deps matching '@opentelemetry/*' (#3716) (015582a)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-amqplib bumped from ^0.68.0 to ^0.69.0
      • @​opentelemetry/instrumentation-aws-lambda bumped from ^0.73.0 to ^0.74.0
      • @​opentelemetry/instrumentation-aws-sdk bumped from ^0.76.0 to ^0.77.0
      • @​opentelemetry/instrumentation-bunyan bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-cassandra-driver bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-connect bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-cucumber bumped from ^0.37.0 to ^0.38.0
      • @​opentelemetry/instrumentation-dataloader bumped from ^0.38.0 to ^0.39.0
      • @​opentelemetry/instrumentation-dns bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-express bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.40.0 to ^0.41.0
      • @​opentelemetry/instrumentation-generic-pool bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-graphql bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-hapi bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-host-metrics bumped from ^0.4.0 to ^0.5.0
      • @​opentelemetry/instrumentation-ioredis bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-kafkajs bumped from ^0.30.0 to ^0.31.0
      • @​opentelemetry/instrumentation-knex bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-koa bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-lru-memoizer bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-memcached bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-mongodb bumped from ^0.74.0 to ^0.75.0
      • @​opentelemetry/instrumentation-mongoose bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-mysql bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-mysql2 bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-nestjs-core bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-net bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-openai bumped from ^0.19.0 to ^0.20.0
      • @​opentelemetry/instrumentation-oracledb bumped from ^0.46.0 to ^0.47.0
      • @​opentelemetry/instrumentation-pg bumped from ^0.73.0 to ^0.74.0
      • @​opentelemetry/instrumentation-pino bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-redis bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-restify bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-router bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-runtime-node bumped from ^0.34.0 to ^0.35.0
      • @​opentelemetry/instrumentation-socket.io bumped from ^0.68.0 to ^0.69.0
      • @​opentelemetry/instrumentation-tedious bumped from ^0.40.0 to ^0.41.0
      • @​opentelemetry/instrumentation-undici bumped from ^0.31.0 to ^0.32.0

... (truncated)

Commits

Updates @opentelemetry/exporter-trace-otlp-http from 0.221.0 to 0.222.0

Release notes

Sourced from @​opentelemetry/exporter-trace-otlp-http's releases.

experimental/v0.222.0

0.222.0

💥 Breaking Changes

  • fix(sdk-node)!: fail-fast on Propagator creation from config file #6930 @​trentm
  • fix(sdk-node)!: fail-fast on MeterProvider creation from config file #6954 @​trentm
  • fix(sdk-node)!: fail-fast on TracerProvider creation from config file #6962 @​trentm
  • fix(sdk-node)!: fail-fast on Resource creation from config file #6989 @​trentm
    • This also breaks some usage of startNodeSDK() for environment-based config, i.e. when not using a config file. For example with OTEL_NODE_RESOURCE_DETECTORS=all, it results in an error message and a no-op SDK. (This does not impact users of new NodeSDK() -- the currently recommended mechanism to start an SDK using this package.)

      Could not create OpenTelemetry SDK from configuration, SDK will not be setup: unknown ExperimentalResourceDetector name in configuration: "container"

🚀 Features

🐛 Bug Fixes

  • fix(instrumentation-http): redact sensitive query parameters on incoming (server) spans; add redactedQueryParamsServer config option @​dyladan
  • fix(sdk-node): support headers_list when creating OTLP exporters from declarative configuration #6953 @​JacksonWeber

📚 Documentation

🏠 Internal

  • refactor(sampler-jaeger-remote): remove axios dependency and use fetch to get the sampler configuration from Jaeger API #6963 @​david-luna
Commits
  • 0b72a81 chore: prepare next release (#7044)
  • a9c5338 ci: roll prerelease changelog into one final release changelog (#7045)
  • f41805e chore: prepare next release (#7042)
  • b85eb28 chore(instrumentation-http): fix lint errors (#7039)
  • 3f92530 ci: support pre-releases and major version bumps in release workflow (#7035)
  • 82a5831 docs(otlp-exporter-base): document HTTP exporter options (#6735)
  • e086dec Merge commit from fork
  • 59dac70 chore(deps): update jamesives/github-pages-deploy-action action to v4.9.0 (#7...
  • d0ce753 chore: add @​maryliag to maintainers (#7024)
  • 03469a1 chore(deps): update open-telemetry/shared-workflows action to v0.10.0 (#7032)
  • Additional commits viewable in compare view

Updates @opentelemetry/resources from 2.10.0 to 2.11.0

Release notes

Sourced from @​opentelemetry/resources's releases.

v2.11.0

2.11.0

🚀 Features

  • feat(context-async-hooks): implement attach() on AsyncLocalStorageContextManager #6845 @​pichlermarc
    • On Node.js 25.9+, delegates to AsyncLocalStorage.withScope() returning a native RunScope. On older Node.js, falls back to enterWith() with a manual disposable wrapper.
  • feat(sdk-trace): allow configuring the force flush timeout per call #6929 @​LarryHu0217

🐛 Bug Fixes

  • fix(sdk-metrics): ignore Infinity in exponential histograms #7015 @​mwear

🏠 Internal

  • perf(sdk-metrics): reuse a single DataView for exponential histogram bit reads #6998 @​mwear
  • chore(ci): run documentation tests on a weekly schedule #6920 @​LarryHu0217
  • feat(ci): support pre-releases and major version bumps in the release workflow #6768 @​pichlermarc
  • chore(resources): Ensure that multiple uses of serviceInstanceIdDetector.detect() return the same value for service.instance.id
Changelog

Sourced from @​opentelemetry/resources's changelog.

2.11.0

🚀 Features

  • feat(context-async-hooks): implement attach() on AsyncLocalStorageContextManager #6845 @​pichlermarc
    • On Node.js 25.9+, delegates to AsyncLocalStorage.withScope() returning a native RunScope. On older Node.js, falls back to enterWith() with a manual disposable wrapper.
  • feat(sdk-trace): allow configuring the force flush timeout per call #6929 @​LarryHu0217

🐛 Bug Fixes

  • fix(sdk-trace-base): avoid a Webpack self-reference error in CommonJS output #6981 @​sansynx
  • fix(sdk-metrics): ignore Infinity in exponential histograms #7015 @​mwear

🏠 Internal

  • perf(sdk-metrics): reuse a single DataView for exponential histogram bit reads #6998 @​mwear
  • chore(ci): run documentation tests on a weekly schedule #6920 @​LarryHu0217
  • feat(ci): support pre-releases and major version bumps in the release workflow #6768 @​pichlermarc
  • chore(resources): Ensure that multiple uses of serviceInstanceIdDetector.detect() return the same value for service.instance.id
Commits
  • 0b72a81 chore: prepare next release (#7044)
  • a9c5338 ci: roll prerelease changelog into one final release changelog (#7045)
  • f41805e chore: prepare next release (#7042)
  • b85eb28 chore(instrumentation-http): fix lint errors (#7039)
  • 3f92530 ci: support pre-releases and major version bumps in release workflow (#7035)
  • 82a5831 docs(otlp-exporter-base): document HTTP exporter options (#6735)
  • e086dec Merge commit from fork
  • 59dac70 chore(deps): update jamesives/github-pages-deploy-action action to v4.9.0 (#7...
  • d0ce753 chore: add @​maryliag to maintainers (#7024)
  • 03469a1 chore(deps): update open-telemetry/shared-workflows action to v0.10.0 (#7032)
  • Additional commits viewable in compare view

Updates @opentelemetry/sdk-node from 0.221.0 to 0.222.0

Release notes

Sourced from @​opentelemetry/sdk-node's releases.

experimental/v0.222.0

0.222.0

💥 Breaking Changes

  • fix(sdk-node)!: fail-fast on Propagator creation from config file #6930 @​trentm
  • fix(sdk-node)!: fail-fast on MeterProvider creation from config file #6954 @​trentm
  • fix(sdk-node)!: fail-fast on TracerProvider creation from config file #6962 @​trentm
  • fix(sdk-node)!: fail-fast on Resource creation from config file #6989 @​trentm
    • This also breaks some usage of startNodeSDK() for environment-based config, i.e. when not using a config file. For example with OTEL_NODE_RESOURCE_DETECTORS=all, it results in an error message and a no-op SDK. (This does not impact users of new NodeSDK() -- the currently recommended mechanism to start an SDK using this package.)

      Could not create OpenTelemetry SDK from configuration, SDK will not be setup: unknown ExperimentalResourceDetector name in configuration: "container"

🚀 Features

🐛 Bug Fixes

  • fix(instrumentation-http): redact sensitive query parameters on incoming (server) spans; add redactedQueryParamsServer config option @​dyladan
  • fix(sdk-node): support headers_list when creating OTLP exporters from declarative configuration #6953 @​JacksonWeber

📚 Documentation

🏠 Internal

  • refactor(sampler-jaeger-remote): remove axios dependency and use fetch to get the sampler configuration from Jaeger API #6963 @​david-luna
Commits
  • 0b72a81 chore: prepare next release (#7044)
  • a9c5338 ci: roll prerelease changelog into one final release changelog (#7045)
  • f41805e chore: prepare next release (#7042)
  • b85eb28 chore(instrumentation-http): fix lint errors (#7039)
  • 3f92530 ci: support pre-releases and major version bumps in release workflow (#7035)
  • 82a5831 docs(otlp-exporter-base): document HTTP exporter options (#6735)
  • e086dec Merge commit from fork
  • 59dac70 chore(deps): update jamesives/github-pages-deploy-action action to v4.9.0 (#7...
  • d0ce753 chore: add @​maryliag to maintainers (#7024)
  • 03469a1 chore(deps): update open-telemetry/shared-workflows action to v0.10.0 (#7032)
  • Additional commits viewable in compare view

Updates jose from 6.2.10 to 6.2.12

Release notes

Sourced from jose's releases.

v6.2.12

Documentation

  • clarify and shorten public API guidance (be62530)

Refactor

  • simplify JWS and JWE operation cores (92e9640)

Performance

  • avoid copying AES-GCM output (6925d43)
  • deduplicate pending jwks key imports (bf5138b)
  • encode single-signature JWS input once (7bc9a33)
  • normalize General JWE shared headers once (78637bd)
  • normalize jwks selection metadata once (fd3ae3f)
  • use native encoding for larger ASCII strings (b23a6f3)

v6.2.11

Documentation

  • render subpath indexes as tables (94589ee)
  • shorten API index descriptions (681482f)

Refactor

  • model JWE key management modes (e01dda6)
  • types: reduce declaration repetition (55b970f)
Changelog

Sourced from jose's changelog.

6.2.12 (2026-09-05)

Documentation

  • clarify and shorten public API guidance (be62530)

Refactor

  • simplify JWS and JWE operation cores (92e9640)

Performance

  • avoid copying AES-GCM output (6925d43)
  • deduplicate pending jwks key imports (bf5138b)
  • encode single-signature JWS input once (7bc9a33)
  • normalize General JWE shared headers once (78637bd)
  • normalize jwks selection metadata once (fd3ae3f)
  • use native encoding for larger ASCII strings (b23a6f3)

6.2.11 (2026-09-04)

Documentation

  • render subpath indexes as tables (94589ee)
  • shorten API index descriptions (681482f)

Refactor

  • model JWE key management modes (e01dda6)
  • types: reduce declaration repetition (55b970f)
Commits
  • 505a55b chore(release): 6.2.12
  • 7bc9a33 perf: encode single-signature JWS input once
  • 78637bd perf: normalize General JWE shared headers once
  • bf5138b perf: deduplicate pending jwks key imports
  • b23a6f3 perf: use native encoding for larger ASCII strings
  • fd3ae3f perf: normalize jwks selection metadata once
  • 6925d43 perf: avoid copying AES-GCM output
  • be62530 docs: clarify and shorten public API guidance
  • 1b41312 build: preserve README when generation fails
  • 0b51829 build: check tree-shaking for every public binding
  • Additional commits viewable in compare view

Updates @types/node from 26.4.0 to 26.6.2

Commits

Updates @typescript-eslint/eslint-plugin from 8.68.0 to 8.70.1

Release notes

Sourced from @​typescript-eslint/eslint-plugin's releases.

v8.70.1

8.70.1 (2026-09-21)

🩹 Fixes

  • ast-spec: narrow import attribute keys to identifiers and strings (#12879)
  • eslint-plugin: [no-useless-default-assignment] avoid false positives on tuples with a rest element (#12768)
  • eslint-plugin: [no-unnecessary-type-parameters] handle type precedence in the suggestion fixer (#12637)
  • eslint-plugin: [no-explicit-any] use unknown[] for bare any rest parameters (#12818)
  • eslint-plugin: [no-generated-empty-object-type] don't report a mapped type whose keys are not resolved yet (#12854)
  • eslint-plugin: [no-misused-spread] omit WeakMap spread suggestions (#12850)
  • eslint-plugin: [no-unnecessary-type-assertion] false positive for empty object asserted to a type alias of Record (#12869)
  • eslint-plugin: [no-meaningless-void-operator] allow void on assignment expressions (#12873)
  • eslint-plugin: [await-thenable] prevent autofix from breaking code when removing await (#12716)
  • eslint-plugin: [no-unnecessary-parameter-property-assignment] account for parameter reassignment (#12880)
  • eslint-plugin: [unbound-method] treat Intl.Collator.prototype.compare as spec-bound (#12845)
  • eslint-plugin: [no-unnecessary-condition] handle union-keyed index access on the left-hand side of nullish assignment (#12747)
  • eslint-plugin: [no-useless-default-assignment] convert the fixer to a suggestion fixer (#12826)
  • eslint-plugin: [no-misused-promises] handle multiple Promise constituents (#12904)
  • rule-tester: test the final autofix output instead of the first pass (#12867)
  • scope-manager: merge implicit global definitions (#12809)
  • type-utils: match package specifiers on whole path components (#12838)
  • typescript-estree: resolve symlinked paths when matching files to projects (#12725)
  • typescript-estree: add missing < token opening type arguments (#12821)
  • typescript-estree: require string literal import attribute values (#12894)
  • website: prevent playground from breaking down after opening link with the .js file type (#12777)

❤️ Thank You

See GitHub Releases for more information.

... (truncated)

Changelog

Sourced from @​typescript-eslint/eslint-plugin's changelog.

8.70.1 (2026-09-21)

🩹 Fixes

  • eslint-plugin: [no-misused-promises] handle multiple Promise constituents (#12904)
  • eslint-plugin: [no-useless-default-assignment] convert the fixer to a suggestion fixer (#12826)
  • eslint-plugin: [no-unnecessary-condition] handle union-keyed index access on the left-hand side of nullish assignment (#12747)
  • eslint-plugin: [unbound-method] treat Intl.Collator.prototype.compare as spec-bound (#12845)
  • eslint-plugin: [no-unnecessary-parameter-property-assignment] account for parameter reassignment (#12880)
  • eslint-plugin: [await-thenable] prevent autofix from breaking code when removing await (#12716)
  • eslint-plugin: [no-meaningless-void-operator] allow void on assignment expressions (#12873)
  • eslint-plugin: [no-unnecessary-type-assertion] false positive for empty object asserted to a type alias of Record (#12869)
  • eslint-plugin: [no-misused-spread] omit WeakMap spread suggestions (#12850)
  • eslint-plugin: [no-generated-empty-object-type] don't report a mapped type whose keys are not resolved yet (#12854)
  • eslint-plugin: [no-explicit-any] use unknown[] for bare any rest parameters (#12818)
  • eslint-plugin: [no-unnecessary-type-parameters] handle type precedence in the suggestion fixer (#12637)
  • eslint-plugin: [no-useless-default-assignment] avoid false positives on tuples with a rest element (#12768)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

8.70.0 (2026-09-07)

🚀 Features

  • eslint-plugin: [no-generated-empty-object-type] add rule (#12730)

🩹 Fixes

  • eslint-plugin: [no-deprecated] report deprecated imported values used in object shorthand properties (#12780)
  • eslint-plugin: [no-unnecessary-condition] no false positive on RHS of a nested logical expression (#12728)
  • eslint-plugin: [member-ordering] don't report fields that read fields declared before them (#12729)

❤️ Thank You

... (truncated)

Commits
  • 23d38ce chore(release): publish 8.70.1
  • 9d82e4b chore: expand eslint-plugin rules test files glob (#12878)
  • f7482f6 fix(eslint-plugin): [no-misused-promises] handle multiple Promise constituent...
  • 2673044 docs(eslint-plugin): [prefer-promise-reject-errors] add option sections and e...
  • 8f141a2 fix(eslint-plugin): [no-useless-default-assignment] convert the fixer to a su...
  • 479cd85 chore: enable assertion option requireData for all rule tests (#12816)
  • f3c190c fix(eslint-plugin): [no-unnecessary-condition] handle union-keyed index acces...
  • b1993df fix(eslint-plugin): [unbound-method] treat Intl.Collator.prototype.compare as...
  • da394bc fix(eslint-plugin): [no-unnecessary-parameter-property-assignment] account fo...
  • 4a742ff fix(eslint-plugin): [await-thenable] prevent autofix from breaking code when ...
  • Additional commits viewable in compare view

Updates @typescript-eslint/parser from 8.68.0 to 8.70.1

Release notes

Sourced from @​typescript-eslint/parser's releases.

v8.70.1

8.70.1 (2026-09-21)

🩹 Fixes

  • ast-spec: narrow import attribute keys to identifiers and strings (#12879)
  • eslint-plugin: [no-useless-default-assignment] avoid false positives on tuples with a rest element (#12768)
  • eslint-plugin: [no-unnecessary-type-parameters] handle type precedence in the suggestion fixer (#12637)
  • eslint-plugin: [no-explicit-any] use unknown[] for bare any rest parameters (#12818)
  • eslint-plugin: [no-generated-empty-object-type] don't report a mapped type whose keys are not resolved yet (#12854)
  • eslint-plugin: [no-misused-spread] omit WeakMap spread suggestions (#12850)
  • eslint-plugin: [no-unnecessary-type-assertion] false positive for empty object asserted to a type alias of Record (#12869)
  • eslint-plugin: [no-meaningless-void-operator] allow void on assignment expressions (#12873)
  • eslint-plugin: [await-thenable] prevent autofix from breaking code when removing await (#12716)
  • eslint-plugin: [no-unnecessary-parameter-property-assignment] account for parameter reassignment (#12880)
  • eslint-plugin: [unbound-method] treat Intl.Collator.prototype.compare as spec-bound (#12845)
  • eslint-plugin: [no-unnecessary-condition] handle union-keyed index access on the left-hand side of nullish assignment (#12747)
  • eslint-plugin: [no-useless-default-assignment] convert the fixer to a suggestion fixer (#12826)
  • eslint-plugin: [no-misused-promises] handle multiple Promise constituents (#12904)
  • rule-tester: test the final autofix output instead of the first pass (#12867)
  • scope-manager: merge implicit global definitions (#12809)
  • type-utils: match package specifiers on whole path components (#12838)
  • typescript-estree: resolve symlinked paths when matching files to projects (#12725)
  • typescript-estree: add missing < token opening type arguments (#12821)
  • typescript-estree: require string literal import attribute values (#12894)
  • website: prevent playground from breaking down after opening link with the .js file type (#12777)

❤️ Thank You

See

Bumps the backend-minor group with 17 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@nestjs/throttler](https://github.com/nestjs/throttler) | `6.5.0` | `6.7.0` |
| [@opentelemetry/auto-instrumentations-node](https://github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/auto-instrumentations-node) | `0.79.0` | `0.80.0` |
| [@opentelemetry/exporter-trace-otlp-http](https://github.com/open-telemetry/opentelemetry-js) | `0.221.0` | `0.222.0` |
| [@opentelemetry/resources](https://github.com/open-telemetry/opentelemetry-js) | `2.10.0` | `2.11.0` |
| [@opentelemetry/sdk-node](https://github.com/open-telemetry/opentelemetry-js) | `0.221.0` | `0.222.0` |
| [jose](https://github.com/panva/jose) | `6.2.10` | `6.2.12` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.4.0` | `26.6.2` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.68.0` | `8.70.1` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.68.0` | `8.70.1` |
| [eslint](https://github.com/eslint/eslint) | `10.9.1` | `10.11.0` |
| [eslint-plugin-sonarjs](https://github.com/SonarSource/SonarJS) | `4.2.0` | `4.2.1` |
| [globals](https://github.com/sindresorhus/globals) | `17.11.0` | `17.12.0` |
| [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest) | `30.5.0` | `30.5.2` |
| [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.9` |
| [supertest](https://github.com/ladjs/supertest) | `7.2.2` | `7.3.0` |
| [ts-jest](https://github.com/kulshekhar/ts-jest) | `29.4.12` | `29.4.13` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.68.0` | `8.70.1` |



Updates `@nestjs/throttler` from 6.5.0 to 6.7.0
- [Release notes](https://github.com/nestjs/throttler/releases)
- [Changelog](https://github.com/nestjs/throttler/blob/master/CHANGELOG.md)
- [Commits](nestjs/throttler@v6.5.0...v6.7.0)

Updates `@opentelemetry/auto-instrumentations-node` from 0.79.0 to 0.80.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js-contrib/blob/main/packages/auto-instrumentations-node/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-js-contrib/commits/auto-instrumentations-node-v0.80.0/packages/auto-instrumentations-node)

Updates `@opentelemetry/exporter-trace-otlp-http` from 0.221.0 to 0.222.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.221.0...experimental/v0.222.0)

Updates `@opentelemetry/resources` from 2.10.0 to 2.11.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@v2.10.0...v2.11.0)

Updates `@opentelemetry/sdk-node` from 0.221.0 to 0.222.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.221.0...experimental/v0.222.0)

Updates `jose` from 6.2.10 to 6.2.12
- [Release notes](https://github.com/panva/jose/releases)
- [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md)
- [Commits](panva/jose@v6.2.10...v6.2.12)

Updates `@types/node` from 26.4.0 to 26.6.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@typescript-eslint/eslint-plugin` from 8.68.0 to 8.70.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.68.0 to 8.70.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/parser)

Updates `eslint` from 10.9.1 to 10.11.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.9.1...v10.11.0)

Updates `eslint-plugin-sonarjs` from 4.2.0 to 4.2.1
- [Release notes](https://github.com/SonarSource/SonarJS/releases)
- [Changelog](https://github.com/SonarSource/SonarJS/blob/master/docs/RELEASE.md)
- [Commits](https://github.com/SonarSource/SonarJS/commits)

Updates `globals` from 17.11.0 to 17.12.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.11.0...v17.12.0)

Updates `jest` from 30.5.0 to 30.5.2
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v30.5.2/packages/jest)

Updates `prettier` from 3.9.6 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.6...3.9.9)

Updates `supertest` from 7.2.2 to 7.3.0
- [Release notes](https://github.com/ladjs/supertest/releases)
- [Commits](forwardemail/supertest@v7.2.2...v7.3.0)

Updates `ts-jest` from 29.4.12 to 29.4.13
- [Release notes](https://github.com/kulshekhar/ts-jest/releases)
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md)
- [Commits](kulshekhar/ts-jest@v29.4.12...v29.4.13)

Updates `typescript-eslint` from 8.68.0 to 8.70.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/typescript-eslint)

---
updated-dependencies:
- dependency-name: "@nestjs/throttler"
  dependency-version: 6.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: "@opentelemetry/auto-instrumentations-node"
  dependency-version: 0.80.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: "@opentelemetry/exporter-trace-otlp-http"
  dependency-version: 0.222.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: "@opentelemetry/resources"
  dependency-version: 2.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: "@opentelemetry/sdk-node"
  dependency-version: 0.222.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: jose
  dependency-version: 6.2.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor
- dependency-name: "@types/node"
  dependency-version: 26.6.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.70.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.70.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: eslint
  dependency-version: 10.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: eslint-plugin-sonarjs
  dependency-version: 4.2.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: backend-minor
- dependency-name: globals
  dependency-version: 17.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: jest
  dependency-version: 30.5.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: backend-minor
- dependency-name: prettier
  dependency-version: 3.9.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: backend-minor
- dependency-name: supertest
  dependency-version: 7.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: backend-minor
- dependency-name: ts-jest
  dependency-version: 29.4.13
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: backend-minor
- dependency-name: typescript-eslint
  dependency-version: 8.70.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: backend-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from Mikefluff as a code owner September 27, 2026 08:07
@dependabot @github

dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 4, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/backend-minor-a2495560b4 branch October 4, 2026 08:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants