Skip to content

build(deps-dev): bump @duckduckgo/eslint-config from v0.1.0 to v0.2.1 - #2718

Merged
daxtheduck merged 1 commit into
mainfrom
dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1
Jun 10, 2026
Merged

daxtheduck merged 1 commit into
mainfrom
dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 27, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @duckduckgo/eslint-config from v0.1.0 to v0.2.1.

Release notes

Sourced from @​duckduckgo/eslint-config's releases.

v0.2.1

⚠️ Pushed to main

  • don't apply major label to dependabot prs (@​muodov)

Authors: 1

v0.2.0

🚀 Enhancement

🐛 Bug Fix

⚠️ Pushed to main

  • set release CI identity to Dax (@​muodov)
  • Add recommended Prettier config to the readme (@​muodov)

Authors: 1

Changelog

Sourced from @​duckduckgo/eslint-config's changelog.

v0.2.1 (Wed May 27 2026)

⚠️ Pushed to main

  • don't apply major label to dependabot prs (@​muodov)

Authors: 1


v0.2.0 (Wed May 27 2026)

🚀 Enhancement

🐛 Bug Fix

⚠️ Pushed to main

  • set release CI identity to Dax (@​muodov)
  • Add recommended Prettier config to the readme (@​muodov)

Authors: 1

Commits
  • 1a2a3f0 Bump version to: 0.2.1 [skip ci]
  • e2b7298 Update CHANGELOG.md [skip ci]
  • d773502 don't apply major label to dependabot prs
  • 9bc1a41 Bump version to: 0.2.0 [skip ci]
  • 5d03d08 Update CHANGELOG.md [skip ci]
  • 7ddf7cf set release CI identity to Dax
  • 07b1e4c Merge pull request #4 from duckduckgo/max/automation
  • 3d05557 don't hardcode the version in readme
  • 930248c use colldown from dependabot
  • 673dccf Merge pull request #3 from duckduckgo/max/dependabot
  • Additional commits viewable in compare view


Note

Low Risk
Dev-only dependency and lockfile updates; risk is limited to possible new or changed ESLint findings in CI, not production behavior.

Overview
Bumps the shared @duckduckgo/eslint-config dev dependency from v0.1.0 to v0.2.1 in the root package.json, with the lockfile refreshed accordingly.

That pull in newer transitive lint tooling—notably eslint-config-prettier v10 and eslint-plugin-n v18 (stricter Node engine expectations and optional TypeScript-related peers). The special-pages workspace also switches @duckduckgo/design-tokens from a commit SHA to the v0.28.0 tag reference in the lockfile.

No runtime or application source changes; impact is limited to local/CI eslint behavior when rules or plugin defaults differ in the new config release.

Reviewed by Cursor Bugbot for commit 88f5f26. Bugbot is set up for automated code reviews on this repo. Configure here.

@dependabot dependabot Bot added dependencies Update one or more dependencies version minor Increment the minor version when merged labels May 27, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner May 27, 2026 11:46
@dependabot dependabot Bot added dependencies Update one or more dependencies version minor Increment the minor version when merged labels May 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Suggested comment for Cursor review (copy and paste as a new comment):

@cursoragent can you review against the current code and outline potential impacts based on the changelogs of the update?

Can you check the test coverage and ensure that the new code is covered?
Can you think through if this dependency is still needed or if there's better practices used elsewhere.

Can you draft a separate PR with any fixes that might be needed?

Note: GitHub Actions bot cannot trigger Cursor agent directly. Please copy the above comment to invoke the review.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Dependency risk review for @duckduckgo/eslint-config v0.1.0 -> v0.2.1:

Confirmed findings: none blocking.

Evidence checked:

  • PR diff only updates package.json and package-lock.json for this direct dev dependency.
  • Upstream index.js is unchanged between the old resolved commit 09f3780... and v0.2.1 1a2a3f...; upstream release notes are release/dependabot automation, README/changelog, and dependency metadata changes.
  • The lockfile impact is limited to dev-only lint packages: eslint-config-prettier 9.1.2 -> 10.1.8, eslint-plugin-n 17.23.2 -> 18.0.1, plus related resolver/semver/get-tsconfig/tapable changes. ts-declaration-location is removed because eslint-plugin-n moved it to an optional peer.
  • Current repo usage still needs the dependency: eslint.config.js imports @duckduckgo/eslint-config directly.
  • Local validation passed with the PR state after generated assets were built: npm run build && npm run lint.
  • PR unit/integration/snapshot checks observed passing for the dependency-relevant paths. The failed build job is a release-branch push rejection, and the failed Asana sync is missing ASANA_ACCESS_TOKEN; neither appears caused by this dependency bump.

Uncertain/residual concerns:

  • eslint-plugin-n 18 is a breaking major and the installed package declares Node ^20.19.0 || ^22.13.0 || >=24. CI uses .nvmrc value 22 and resolved locally to Node 22.22.3, so validation passed. If any supported developer/automation environment pins an older Node 22 point release, lint/install could fail and should be validated there.
  • npm audit reports existing repo dev-dependency advisories, but the vulnerable package versions are unchanged between base and this PR; I did not find a new advisory introduced by this bump.

No separate fix PR drafted because I did not find a concrete dependency-update issue to fix.

Open in Web View Automation 

Sent by Cursor Automation: Review dependabot

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Web Compatibility Assessment

No findings. This PR only updates the root dev dependency @duckduckgo/eslint-config and the corresponding lockfile entries; it does not change injected runtime code, wrapper utilities, message bridge, platform entry points, DOM manipulation, or API shims.

Security Assessment

No findings. There are no changes to captured globals, messaging transports, origin validation, config handling, iframe access, or page-world execution paths.

Risk Level

Low Risk: devDependency/lockfile-only change affecting lint tooling rather than shipped injected JavaScript behavior.

Recommendations

No code changes requested. Verification performed: npm ci, npm run build, and npm run lint all pass. The release comparison for @duckduckgo/eslint-config v0.1.0...v0.2.1 shows automation/metadata changes and dependency metadata updates, with no index.js rule/config changes.

Open in Web View Automation 

Sent by Cursor Automation: Web compat and sec

@jonathanKingston

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1 branch from bfd5ad8 to 81d355f Compare June 9, 2026 14:36
@github-actions

github-actions Bot commented Jun 9, 2026 •

Copy link
Copy Markdown
Contributor

Build Branch

Branch pr-releases/dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1
Commit 3ca35032d3
Updated June 10, 2026 at 10:36:28 AM UTC

Static preview entry points

QR codes (mobile preview)
Entry point QR code
Docs QR for docs preview
Static pages QR for static pages preview
Integration pages QR for integration pages preview

Integration commands

npm (Android / Extension):

npm i github:duckduckgo/content-scope-scripts#pr-releases/dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1

Swift Package Manager (Apple):

.package(url: "https://github.com/duckduckgo/content-scope-scripts.git", branch: "pr-releases/dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1")

git submodule (Windows):

git -C submodules/content-scope-scripts fetch origin pr-releases/dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1
git -C submodules/content-scope-scripts checkout origin/pr-releases/dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1
Pin to exact commit

npm (Android / Extension):

npm i github:duckduckgo/content-scope-scripts#3ca35032d307b27017ff36dbf3eadffd61243ca7

Swift Package Manager (Apple):

.package(url: "https://github.com/duckduckgo/content-scope-scripts.git", revision: "3ca35032d307b27017ff36dbf3eadffd61243ca7")

git submodule (Windows):

git -C submodules/content-scope-scripts fetch origin pr-releases/dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1
git -C submodules/content-scope-scripts checkout 3ca35032d307b27017ff36dbf3eadffd61243ca7

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Injected PR Evaluation: Web Compatibility & Security

Reviewed diff b76f876…81d355f — 2 files changed (package.json, package-lock.json only).

Web Compatibility Assessment

No findings. This PR bumps @duckduckgo/eslint-config from v0.1.0 → v0.2.1 (devDependency). No files under injected/, messaging/, platform entry points, or runtime bundles are modified. ESLint configuration is a build-time/lint-time tool and is not shipped to browsers.

Security Assessment

No findings. The changed packages are devDependencies only and do not affect injected script execution, messaging transports, captured globals, or remote config handling.

Info: Transitive updates include eslint-config-prettier (9→10) and eslint-plugin-n (17→18). eslint-plugin-n@18 raises its Node engine requirement to ^20.19.0 || ^22.13.0 || >=24 and moves ts-declaration-location to an optional peer dependency. This affects local/CI lint environments only, not production browser payloads.

Risk Level

Low Risk — dev-only dependency version bump with no runtime code changes.

Recommendations

  1. Merge when CI green — no injected-code review blockers.
  2. Verify CI Node version meets eslint-plugin-n@18 engine requirement (^20.19.0 || ^22.13.0 || >=24). This repo uses Node 22, so should be fine.
  3. No additional web-compat or security tests required for this change class.
Open in Web View Automation 

Sent by Cursor Automation: Web compat and sec

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Dependency review: @duckduckgo/eslint-config v0.1.0 → v0.2.1

Verdict: Low risk — safe to merge once CI is green.

This PR only bumps the git tag in package.json / package-lock.json. No application source changes.


Changelog & rule impact

Compared v0.1.0...v0.2.1 in duckduckgo/eslint-config:

Area Change
index.js (exported rules) Unchanged — same flat-config array and rule set
v0.2.0 Dependabot/CI/release automation; transitive dep bumps
v0.2.1 Release tooling tweak only

Confirmed: No new/changed ESLint rules reach this repo. Local overrides in eslint.config.js (@typescript-eslint/*, no-void, require-await, react-hooks, etc.) are unaffected.

Transitive bumps (via lockfile):

Package Was Now Notes
eslint-config-prettier 9.x 10.x Adds @stylistic conflict disables; we don't use @stylistic
eslint-plugin-n 17.x 18.x ESM migration, Node ≥20.19 / ≥22.13, ESLint ≥8.57.1; drops no-unpublished-bin from recommended (not enabled in DDG config)
ts-declaration-location direct dep optional peer of eslint-plugin-n Only relevant for n/no-sync, which DDG config does not enable

Validation

  • npx eslint . — pass
  • npm run build && npm run lint (CI-equivalent) — pass
  • CI unit job runs npm run lint after build (.github/workflows/tests.yml)

Test coverage gap (pre-existing): No repo-local unit tests for ESLint config composition. Coverage is the CI lint gate. Upstream [email protected] now ships a scripts/smoke-test.mjs, but this repo does not invoke it.


Is the dependency still needed?

Yes. eslint.config.js spreads ...ddgConfig as the shared DDG baseline (standard-style rules + import/n/promise plugins). Inlining would duplicate config maintained across DDG repos.


Supply chain

Factor Assessment
Provenance First-party duckduckgo/eslint-config (private), pinned to git tag #v0.2.1
Integrity Lockfile now includes integrity hash for the git dep — improvement over v0.1.0
Version field Corrected from 1.0.0 → 0.2.1 in lockfile (aligns tag with package version)
Nested deps eslint-plugin-import / eslint-plugin-promise nested under @duckduckgo/eslint-config — pre-existing pattern, not introduced here
Runtime exposure Dev-only; not shipped in browser bundles

Uncertain (low severity): eslint-plugin-n@18 requires Node ^20.19.0 \|\| ^22.13.0 \|\| >=24. .nvmrc is 22 without a patch floor; developers on Node 22.0–22.12 may see engine warnings. CI setup-node with .nvmrc currently resolves to a compatible 22.x. Consider pinning .nvmrc to 22.13+ if engine warnings appear locally — not a blocker for this PR.


Fix PR

No companion fix PR needed. ESLint passes with the updated config; no repo changes required beyond this bump.

Open in Web View Automation 

Sent by Cursor Automation: Review dependabot

@jonathanKingston

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1 branch from 81d355f to f640143 Compare June 9, 2026 15:10

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Injected PR Evaluation: Web Compatibility & Security

Reviewed diff 6a9b19ff…f6401435 — 2 files changed (package.json, package-lock.json).

This PR bumps @duckduckgo/eslint-config from v0.1.0 → v0.2.1 (devDependency only). Transitive lockfile updates include eslint-config-prettier 9→10, eslint-plugin-n 17→18, and minor semver/tapable/enhanced-resolve bumps. No runtime/injected source files are modified.

Verified locally: npx eslint . passes with the new config.


Web Compatibility Assessment

No findings.

This change does not touch injected/, messaging/, platform entry points, wrapper utilities, or any code bundled into contentScope.js. Dev-only lint tooling has zero effect on API surface fidelity, prototype chains, DOM interaction, timing, platform behavior, or third-party script compatibility in the browser.


Security Assessment

No findings.

@duckduckgo/eslint-config is a devDependency and is not shipped to end users. The lockfile updates (eslint-config-prettier, eslint-plugin-n, etc.) affect CI/local lint only — no impact on global capture hygiene, messaging trust boundaries, prototype attacks, data exfiltration vectors, config trust, or iframe security in the injected runtime.


Risk Level

Low Risk — dependency-only bump confined to ESLint tooling; no injected runtime, messaging, or security-sensitive code paths changed.


Recommendations

  1. Merge when CI is green — no web-compat or security blockers from this diff.
  2. Optional sanity check — confirm npm run lint passes in CI (rule changes in eslint-plugin-n v18 are dev-time only; local eslint . already passes).
  3. No injected-runtime tests required for this PR scope.
Open in Web View Automation 

Sent by Cursor Automation: Web compat and sec

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Dependency update review: @duckduckgo/eslint-config v0.1.0 → v0.2.1

Verdict: Low risk — safe to merge. No companion fix PR is needed.


What actually changed

The PR only bumps the git tag in package.json / package-lock.json. Comparing index.js at v0.1.0 and v0.2.1 shows no rule or config changes — the files are identical.

The upstream changelog (v0.2.0 / v0.2.1) covers release automation and Dependabot housekeeping, not lint rule changes. The functional delta is transitive dependency bumps inside @duckduckgo/eslint-config:

Transitive dep Before After
eslint-config-prettier ^9.1.0 → 9.1.2 ^10.0.0 → 10.1.8
eslint-plugin-n ^17.11.1 → 17.23.2 ^18.0.0 → 18.1.0

Lockfile also drops ts-declaration-location as a direct transitive install (eslint-plugin-n v18 moved it to an optional peer).


Impact on this repo (confirmed)

Integration: eslint.config.js spreads ...ddgConfig and layers TypeScript, React hooks, and repo-specific overrides on top. The shared config remains the right abstraction for DDG-wide lint consistency — no alternative in-repo.

Lint behavior: npx eslint . passes cleanly on both main (v0.1.0) and this branch (v0.2.1) with zero errors/warnings. CI's npm run lint job (which includes eslint + tsc + prettier) is the effective regression test; no dedicated eslint-config unit tests exist here, which is normal for a lint preset consumer.

eslint-plugin-n v18 breaking changes: The v18.0.0 release includes ESM migration, stricter Node/ESLint engine requirements, and changes to recommended rules (no-unpublished-bin removed, no-sync peer dep change). None of these affect this repo because @duckduckgo/eslint-config only enables seven explicit n/* rules (handle-callback-err, no-callback-literal, no-deprecated-api, no-exports-assign, no-new-require, no-path-concat, process-exit-as-throw) — not the plugin's recommended preset and not n/no-sync.

eslint-config-prettier v10: No new lint violations observed; it continues to disable formatting conflicts with Prettier as before.


Supply chain

  • Source: First-party DDG git dependency (github:duckduckgo/eslint-config#v0.2.1), tag-pinned to commit 1a2a3f07.
  • Integrity: Lockfile now records an integrity hash for the git tarball — improvement over v0.1.0.
  • Risk: Low. No new external publishers; transitive bumps are well-known eslint-community / prettier packages.

Uncertain / minor (no action required)

  1. Node engine floor: eslint-plugin-n@18 requires Node ^20.19.0 || ^22.13.0 || >=24. .nvmrc is 22 (resolves to latest 22.x in CI; currently 22.14.0 here). Developers on Node 22.0–22.12 may see EBADENGINE warnings at install time but lint still works. Pinning .nvmrc to 22.13 would make this explicit — optional hygiene, not a blocker.

  2. Version label in lockfile: Package version string changed from 1.0.0 to 0.2.1 upstream (semver reset). Cosmetic only; git tag pin is what matters.


Fix PR

No fixes required. Evaluated opening a companion PR (e.g. .nvmrc pin) and determined the engine concern is informational only given current CI/dev tooling.

Open in Web View Automation 

Sent by Cursor Automation: Review dependabot

@jonathanKingston

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1 branch from f640143 to d4dc96e Compare June 9, 2026 15:38

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Injected PR Evaluation: Web Compatibility & Security

PR: build(deps-dev): bump @duckduckgo/eslint-config from v0.1.0 to v0.2.1 (#2718)

Reviewed diff 23c7c8c...d4dc96e — only package.json and package-lock.json change the @duckduckgo/eslint-config pin from v0.1.0 → v0.2.1. No files under injected/, messaging/, or other runtime bundles are modified.

Verified locally: npx eslint . passes with the updated config.


Web Compatibility Assessment

No findings.

This is a devDependency used only by root eslint.config.js at lint time. It is not bundled into content-scope scripts injected into web pages, so it cannot affect API shims, prototype patches, DOM behavior, or third-party script compatibility at runtime.


Security Assessment

No findings.

  • No changes to captured-globals.js, message bridge, messaging transports, or origin validation.
  • No new network surface, postMessage, or dynamic code execution paths.
  • Transitive bumps (eslint-config-prettier 9→10, eslint-plugin-n 17→18) are dev-only and do not ship to browsers.

Risk Level

Low Risk — dependency-only change confined to the lint toolchain; zero runtime/injection surface area.


Recommendations

  1. Merge after CI green — confirm the repo’s npm run lint job passes on this branch (eslint portion verified; full pipeline may include tsc/build steps unrelated to this bump).
  2. No injected-code follow-up required — no web-compat or security mitigations needed for this PR.
  3. Optional housekeeping — upstream eslint-config v0.2.x also corrects its package version metadata (1.0.0 → 0.2.1); no action needed here beyond the pin update already in this PR.
Open in Web View Automation 

Sent by Cursor Automation: Web compat and sec

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Dependency update risk assessment: @duckduckgo/eslint-config v0.1.0 → v0.2.1

Verdict: Low risk — safe to merge (no follow-up PR required)


Summary

This PR only bumps the git-pinned devDependency in package.json / package-lock.json. Upstream index.js (the actual ESLint rules) is unchanged between v0.1.0 and v0.2.1; the release is primarily dependency maintenance, release automation, and version normalization.


Changelog impact (confirmed)

Area Change Impact on this repo
@duckduckgo/eslint-config rules (index.js) No diff None — same n/*, import/*, promise/*, and Standard-derived rules
eslint-config-prettier 9 → 10 Adds @stylistic rule disabling None observed — project uses Prettier for formatting; lint passes
eslint-plugin-n 17 → 18 ESM migration; no-unpublished-bin removed from recommended; Node ≥20.19 / ESLint ≥8.57.1 Low — this config sets explicit n/* rules (not recommended), so the recommended-set change does not apply
Package version 1.0.0 → 0.2.1 Tag-based pinning unchanged (#v0.2.1) Cosmetic — fixes prior version/tag mismatch

Upstream v0.2.0 changelog: dependabot bumps, CI, release automation, README. No rule changes.


Validation performed

  • npm ci && npm run build && npm run lint on the PR branch: passes (eslint, tsc, strict-core, surrogates check, prettier).
  • Node in CI (.nvmrc = 22) satisfies eslint-plugin-n@18 engine requirement (^22.13.0).
  • Root eslint is ^10.4.0, above peer minimums.

Test coverage

  • Upstream: v0.2.x adds a smoke test (scripts/smoke-test.mjs) that loads the flat config and lints index.js.
  • This repo: npm run lint in .github/workflows/tests.yml (after npm run build) is the real integration gate. No additional tests needed for this bump.

Dependency necessity

@duckduckgo/eslint-config remains the right abstraction — it centralizes DDG-wide JS lint standards and is extended locally in eslint.config.js with typescript-eslint, React hooks, and project-specific overrides. No better alternative in-repo.


Supply chain

Factor Assessment
Source Internal DDG repo (duckduckgo/eslint-config), git tag pinned
Integrity Lockfile now includes integrity hash for the git tarball (improvement over v0.1.0 lock entry)
Transitive deps eslint-config-prettier@10, eslint-plugin-n@18 — both reputable, pulled via the shared config
Version renumbering 1.0.0 → 0.2.1 is confusing for semver tooling but not a functional downgrade because resolution is by git ref, not npm version

Uncertain (low priority): Future eslint-plugin-n@18 minor releases could add stricter Node builtin checks (node-builtins support data updated in v18). Monitor if new n/no-unsupported-features findings appear on Node API usage in scripts/ — none surfaced in this validation.


Follow-up PR

No code changes required. Lint is clean with the new config; no separate fix PR drafted.

Open in Web View Automation 

Sent by Cursor Automation: Review dependabot

@jonathanKingston

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1 branch from d4dc96e to f8d02ee Compare June 9, 2026 16:17

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Web Compatibility Assessment

No findings. This PR only bumps @duckduckgo/eslint-config (v0.1.0 → v0.2.1) in package.json / package-lock.json. No files under injected/, messaging/, special-pages/, or platform entry points are modified. The eslint config is a devDependency consumed at lint time via eslint.config.js; it is not bundled into injected scripts shipped to web pages.

info — package.json (line 43): Dev-tooling-only change; zero API surface, prototype, DOM, timing, or platform-runtime impact.

info — package-lock.json (transitive deps): Lockfile updates for eslint-config-prettier (^10), eslint-plugin-n (^18), and other dev-only packages. These do not affect production bundles or page-world behavior.


Security Assessment

No findings. No changes to captured-globals.js, messaging transports, message bridge, wrapper-utils.js, shouldExemptMethod(), origin validation, or any runtime trust boundary.

info — package.json / package-lock.json: Dependency resolution change only. @duckduckgo/eslint-config and its transitive plugins run in the Node.js lint toolchain, not in the hostile page environment.


Risk Level

Low Risk — This is a devDependency version bump with no injected runtime code changes and no modifications to security-sensitive subsystems.


Recommendations

  1. CI verification (info): Merge after npm run lint passes in CI. Local npx eslint . succeeds with v0.2.1; upstream changes between v0.1.0 and v0.2.1 are primarily CI/automation and transitive dev-dep bumps — the exported rule set in index.js is unchanged.
  2. Node engine note (info): eslint-plugin-n@18 (transitive) requires Node ^20.19.0 || ^22.13.0 || >=24. This repo targets Node 22, so no action needed unless CI matrix includes older Node versions.
  3. No runtime follow-up required: No config gating, messaging hardening, or compat testing needed for this PR.
Open in Web View Automation 

Sent by Cursor Automation: Web compat and sec

@jonathanKingston

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Jun 9, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR is already up-to-date with main! If you'd still like to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@jonathanKingston

Copy link
Copy Markdown
Contributor

@dependabot recreate

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1 branch from f8d02ee to 9215b63 Compare June 9, 2026 16:40

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Injected PR Evaluation: Web Compatibility & Security

Web Compatibility Assessment

No findings.

This PR only updates devDependencies (package.json, package-lock.json). It does not modify injected/src/, wrapper-utils.js, captured-globals.js, messaging transports, the message bridge, platform entry points, or any code bundled into page-world injections. There is no change to browser API shimming, DOM interaction, prototype patching, or feature lifecycle behavior.

Security Assessment

No findings.

@duckduckgo/eslint-config is a devDependency used at lint time only; it is not shipped to end users in injected bundles or special-pages runtime artifacts. The lockfile updates are limited to ESLint tooling and transitive dev tooling (eslint-config-prettier 9→10, eslint-plugin-n 17→18, plus minor semver/tapable/enhanced-resolve churn). None of these affect the hostile-page trust boundary, messaging validation, or global-capture hygiene in production code.

Info (dev tooling only): eslint-plugin-n@18 tightens its Node engine requirement to ^20.19.0 || ^22.13.0 || >=24. This repo targets Node 22 and remains compatible; it is a CI/dev-environment constraint, not a runtime security surface.

Risk Level

Low Risk — dependency-only bump with no injected runtime, messaging, or security-sensitive source changes.

Recommendations

  1. Info: Merge is safe from a web-compat/security perspective. No injected-runtime testing is required for this diff alone.
  2. Info: Confirm CI lint passes on the PR branch (local npx eslint . succeeds with v0.2.1). Full npm run lint also depends on generated injected artifacts (build/locales, surrogates) unrelated to this change.
  3. Info: The lockfile includes minor transitive churn (enhanced-resolve, semver, tapable, get-tsconfig) beyond the direct eslint-config bump; scope is still dev-only and expected for a Dependabot lockfile refresh.
Open in Web View Automation 

Sent by Cursor Automation: Web compat and sec

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Dependency update review: @duckduckgo/eslint-config v0.1.0 → v0.2.1

Verdict: Low risk — safe to merge once CI is green. No companion fix PR needed.


What changed

PR diff is limited to package.json / package-lock.json. No application source or eslint.config.js edits.

Upstream v0.1.0...v0.2.1 is release automation + transitive dep maintenance. index.js is byte-for-byte identical between tags — no new/changed ESLint rules reach this repo.

Transitive bumps (via lockfile):

Package Before After Notes
eslint-config-prettier 9.1.2 10.1.8 Adds @stylistic conflict disables; we don't use @stylistic
eslint-plugin-n 17.23.2 18.1.0 ESM migration; Node ^20.19.0 || ^22.13.0 || >=24; ESLint >=8.57.1
ts-declaration-location direct transitive optional peer of eslint-plugin-n Only relevant for n/no-sync, which DDG config does not enable

eslint-plugin-n v18 breaking changes (no-unpublished-bin removed from recommended, no-sync peer dep change) do not affect this repo because @duckduckgo/eslint-config enables seven explicit n/* rules, not the plugin's recommended preset.


Impact on this repo (confirmed)

  • Integration: eslint.config.js spreads ...ddgConfig and layers typescript-eslint, React hooks, and repo overrides on top. Still the right DDG-wide baseline.
  • Prettier alignment: .prettierrc already matches upstream's newly documented recommendation (singleQuote, printWidth: 140, tabWidth: 4).
  • Lint behavior: npx eslint . passes on both v0.1.0 and v0.2.1 with 0 errors and the same 6 pre-existing unused-disable warnings (in generated contentScope.js output lint). No new violations from this bump.
  • CI-equivalent validation: npm run build && npm run lint passes on this branch (eslint, tsc, strict-core, surrogates, prettier).

Test coverage

  • Upstream: v0.2.x adds scripts/smoke-test.mjs (loads flat config, lints index.js).
  • This repo: No dedicated eslint-config unit tests (normal for a preset consumer). The unit job's npm run lint after npm run build in .github/workflows/tests.yml is the effective integration gate. Adequate for this change class.

Supply chain

Factor Assessment
Provenance First-party duckduckgo/eslint-config, git tag #v0.2.1 → commit 1a2a3f07
Integrity Lockfile now records integrity hash for the git tarball — improvement over v0.1.0
Version metadata Upstream corrected 1.0.0 → 0.2.1 in lockfile; cosmetic only (resolution is by git ref)
Runtime exposure Dev-only; not shipped in browser bundles
npm audit 13 existing dev-dep advisories; none attributable to this bump's changed packages

Uncertain / minor (no action required)

  1. Node engine floor: eslint-plugin-n@18 requires Node ^20.19.0 \|\| ^22.13.0 \|\| >=24. .nvmrc is 22 (no patch floor); CI setup-node resolves to a compatible 22.x. Developers on Node 22.0–22.12 may see EBADENGINE warnings at install — lint still works on 22.14.0. Pinning .nvmrc to 22.13+ would be optional hygiene, not a blocker.

  2. Future eslint-plugin-n minors: v18 updated node-builtins support data. If stricter builtin checks land, scripts/ Node API usage could surface new n/* findings — none observed in this validation.


Fix PR

None drafted. Evaluated a companion PR (e.g. .nvmrc pin) and determined the engine concern is informational only given current CI/dev tooling. No concrete dependency-update defect to fix.

Open in Web View Automation 

Sent by Cursor Automation: Review dependabot

@github-actions
github-actions Bot enabled auto-merge June 9, 2026 16:46
@github-actions
github-actions Bot added this pull request to the merge queue Jun 10, 2026
@cursor
cursor Bot removed this pull request from the merge queue due to a manual request Jun 10, 2026
@jonathanKingston

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1 branch from 9215b63 to 2baf811 Compare June 10, 2026 10:11

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Web Compatibility Assessment

No findings. This PR only updates devDependencies (package.json, package-lock.json). No files under injected/, messaging/, or platform entry points are modified. The bumped packages (@duckduckgo/eslint-config, eslint-config-prettier, eslint-plugin-n, and other transitive dev-only deps) are not bundled into content-scope scripts and do not execute in the page context.

Security Assessment

No findings. No changes to captured-globals.js, messaging transports, message bridge, wrapper utilities, feature initialization, or any runtime security boundary. Dev tooling cannot be exploited by hostile web pages because it is not shipped to end users.

info — package.json / package-lock.json: @duckduckgo/eslint-config v0.1.0 → v0.2.1 with transitive bumps (eslint-config-prettier 9→10, eslint-plugin-n 17→18). These affect CI/local lint only.

Risk Level

Low Risk — Pure dev-dependency version bump with zero runtime code changes; no web compatibility or security surface area in injected scripts.

Recommendations

  1. info — Merge is safe from a web-compat/security perspective. Confirm CI lint job passes on this branch (expected; eslint . succeeds locally with the new config).
  2. info — eslint-plugin-n@18 raises the Node engine floor to ^20.19.0 || ^22.13.0 || >=24. This repo already targets Node 22, so no action needed unless CI matrix includes older Node versions.
  3. info — Future lint rule changes from the bumped eslint plugins may surface new violations in separate PRs; that is a developer-experience concern, not a runtime regression risk.

Automated review — Injected PR Evaluation: Web Compatibility & Security

Open in Web View Automation 

Sent by Cursor Automation: Web compat and sec

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Dependency review: @duckduckgo/eslint-config v0.1.0 → v0.2.1

Verdict: Low risk — safe to merge. No companion fix PR drafted.


What changed

This PR only updates the git tag in package.json / package-lock.json. Comparing index.js at v0.1.0 vs v0.2.1 shows no rule or flat-config changes — the exported config is byte-for-byte identical.

Upstream changelog (v0.2.0 / v0.2.1) is release automation, Dependabot housekeeping, README, and transitive dependency bumps — not lint rule changes.

Transitive lockfile impact:

Package Before After Relevance here
eslint-config-prettier 9.1.2 10.1.8 Adds @stylistic conflict disables; repo does not use @stylistic
eslint-plugin-n 17.23.2 18.1.0 Major with ESM migration + stricter engines; DDG config enables only 7 explicit n/* rules, not the plugin recommended preset
ts-declaration-location direct transitive optional peer of eslint-plugin-n Only needed for n/no-sync, which DDG config does not enable

Impact on this repo (confirmed)

  • Integration: eslint.config.js spreads ...ddgConfig and layers TypeScript, React hooks, and repo-specific overrides. The shared config remains the right abstraction — inlining would duplicate DDG-wide lint policy.
  • Prettier alignment: .prettierrc already matches the settings now documented in upstream v0.2.1 README (singleQuote, printWidth: 140, tabWidth: 4).
  • eslint-plugin-n v18 breaking changes (release notes): ESM migration, Node ^20.19.0 || ^22.13.0 || >=24, no-unpublished-bin removed from recommended, ts-declaration-location moved to optional peer. None affect this repo because @duckduckgo/eslint-config only enables: n/handle-callback-err, n/no-callback-literal, n/no-deprecated-api, n/no-exports-assign, n/no-new-require, n/no-path-concat, n/process-exit-as-throw.
  • eslint-config-prettier v10 (release notes): adds @stylistic support only; no new violations observed.

Validation

Check Result
npx eslint . pass
npm run build && npm run lint (CI-equivalent) pass (Node 22.14.0)
Runtime / injected code diff none — devDependency only

Test coverage: No repo-local unit tests for ESLint config composition (pre-existing). Coverage is the CI unit job lint gate (.github/workflows/tests.yml). Upstream v0.2.1 now ships scripts/smoke-test.mjs, but this repo does not invoke it — acceptable for a config consumer.


Supply chain

Factor Assessment
Provenance First-party duckduckgo/eslint-config (private), tag-pinned #v0.2.1 → commit 1a2a3f07
Integrity Lockfile now records integrity hash for the git dep — improvement over v0.1.0
Version metadata Corrected from 1.0.0 → 0.2.1 in lockfile (cosmetic; tag pin is authoritative)
Runtime exposure Dev-only; not shipped in browser bundles
New publishers None — transitive bumps are eslint-community / prettier packages

Uncertain / minor (no action required)

  1. Node engine floor: eslint-plugin-n@18 requires Node ^20.19.0 || ^22.13.0 || >=24. .nvmrc is 22 without a patch floor; developers on Node 22.0–22.12 may see EBADENGINE warnings at install. CI setup-node with .nvmrc resolves to a compatible 22.x (22.14.0 here). Pinning .nvmrc to 22.13+ would make this explicit — optional hygiene, not a blocker.

  2. npm audit: Existing dev-dependency advisories remain; no new vulnerable package versions introduced by this bump.


Fix PR

No fixes required. Evaluated a companion PR (e.g. .nvmrc pin) and determined the engine concern is informational only given current CI/dev tooling.

Open in Web View Automation 

Sent by Cursor Automation: Review dependabot

Comment thread package.json
@daxtheduck
daxtheduck enabled auto-merge June 10, 2026 10:19
@jonathanKingston

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps [@duckduckgo/eslint-config](https://github.com/duckduckgo/eslint-config) from v0.1.0 to v0.2.1.
- [Release notes](https://github.com/duckduckgo/eslint-config/releases)
- [Changelog](https://github.com/duckduckgo/eslint-config/blob/main/CHANGELOG.md)
- [Commits](duckduckgo/eslint-config@09f3780...1a2a3f0)

---
updated-dependencies:
- dependency-name: "@duckduckgo/eslint-config"
  dependency-version: 1a2a3f071f76b51a9917df6476211a8f20eb81bd
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1 branch from 2baf811 to 88f5f26 Compare June 10, 2026 10:35

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Injected PR Evaluation: Web Compatibility & Security

PR: build(deps-dev): bump @duckduckgo/eslint-config from v0.1.0 to v0.2.1

Reviewed diff e2c8664…88f5f26 — 2 files changed (package.json, package-lock.json). No changes under injected/, messaging/, platform entry points, or any runtime bundle source.


Web Compatibility Assessment

No findings.

This PR modifies only devDependencies. @duckduckgo/eslint-config and its transitive packages (eslint-config-prettier, eslint-plugin-n, etc.) are used exclusively at lint/CI time. They are not bundled into contentScope.js or shipped to end-user browsers. No API overrides, DOM manipulation, messaging, or feature initialization code is touched.


Security Assessment

No findings.

  • Global capture / messaging / prototype attacks: Not applicable — no injected runtime code changed.
  • Supply chain (info): The dependency resolves from github:duckduckgo/eslint-config#v0.2.1 (commit 1a2a3f0). This is an internal DDG package pinned by git tag; acceptable for a dev tool, but verify CI lint passes on merge.
  • Lockfile noise (info): package-lock.json also updates special-pages → @duckduckgo/design-tokens from a commit hash to #v0.28.0. This is unrelated to the eslint-config bump and should be confirmed intentional (likely lockfile regeneration side-effect).

Risk Level

Low Risk — dev-only tooling version bump with zero changes to injected page-world code, wrapper utilities, messaging transports, or security-sensitive runtime paths.


Recommendations

  1. Verify CI lint passes — eslint-plugin-n major bump (v17 → v18) may surface new lint violations; confirm npm run lint is green before merge.
  2. Confirm Node engine compatibility — eslint-plugin-n@18 requires ^20.19.0 || ^22.13.0 || >=24; repo .nvmrc specifies Node 22, which satisfies this.
  3. Optional housekeeping — If the @duckduckgo/design-tokens lockfile entry change is unintentional, regenerate the lockfile from a clean main checkout to keep the PR scoped to eslint-config only.
Open in Web View Automation 

Sent by Cursor Automation: Web compat and sec

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependency update review: @duckduckgo/eslint-config v0.1.0 → v0.2.1

Verdict: Low risk — safe to merge. No follow-up PR required.


What actually changed

Compared v0.1.0...v0.2.1 in the upstream repo:

  • index.js is byte-for-byte identical — no new/disabled ESLint rules in this repo.
  • Package metadata/CI/release automation added upstream (Dependabot, smoke test, semver normalization 1.0.0 → 0.2.1).
  • Transitive bumps only:
    • eslint-config-prettier 9.x → 10.x — adds @stylistic rule disabling; unused here.
    • eslint-plugin-n 17.x → 18.x — ESM migration, Node >=20.19, ESLint >=8.57.1; aligns with this repo (Node 22 via .nvmrc, eslint ^10.4.0).

Impact on content-scope-scripts

Integration point is eslint.config.js, which spreads ...ddgConfig then layers project-specific typescript-eslint, React hooks, and overrides (e.g. no-void for injected/messaging).

Confirmed (validated locally):

  • npx eslint . passes on this branch.
  • Full npm run lint passes after npm run build (matches CI unit job, which is green).

Confirmed (upstream changelog): v0.2.0/v0.2.1 changes are tooling/docs only; no rule-set edits.

Uncertain (low concern): eslint-plugin-n@18 moved ts-declaration-location to an optional peer dep and dropped no-unpublished-bin from its recommended preset. Neither affects this repo — the shared config enables only explicit n/* rules (n/no-deprecated-api, n/no-path-concat, etc.), not the plugin recommended preset or n/no-sync.


Test coverage

Layer Coverage
Upstream New smoke test (scripts/smoke-test.mjs) loads config + lints index.js
This repo npm run lint in CI (unit job) exercises the full flat config across all workspaces, plus lint-no-output-globals for bundled output

No dedicated unit tests for the config package itself in C-S-S, but lint is the meaningful integration test and it passes.


Is the dependency still warranted?

Yes. This is the shared DDG ESLint baseline; duplicating ~200 lines of rules locally would be worse. .prettierrc already matches the upstream-recommended settings (singleQuote, printWidth: 140, tabWidth: 4).


Supply chain

Factor Assessment
Provenance First-party duckduckgo/eslint-config, tag-pinned (#v0.2.1)
Integrity Lockfile now includes integrity hash for the git dependency (improvement over v0.1.0)
Transitives npm registry packages with pinned versions/integrity
Runtime exposure Dev-only; not shipped in browser bundles

No new third-party maintainer risk beyond routine transitive npm updates.


Lockfile noise (informational)

package-lock.json also normalizes @duckduckgo/design-tokens to #v0.28.0 and bumps some unrelated transitives (enhanced-resolve, tapable, semver). These are lockfile resolution artifacts, not functional changes from this PR's intent.


No separate fix PR drafted — nothing actionable found beyond merging once remaining CI jobs finish.

Open in Web View Automation 

Sent by Cursor Automation: Review dependabot

Comment thread package.json
@daxtheduck
daxtheduck added this pull request to the merge queue Jun 10, 2026
@jonathanKingston

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Jun 10, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot attempted to update this pull request, but because the branch dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1 is protected it was unable to do so.

@dependabot @github

dependabot Bot commented on behalf of github Jun 10, 2026

Copy link
Copy Markdown
Contributor Author

Oh no! Something went wrong on our end. Please try again later.

If the problem persists, please contact GitHub support for assistance 🙇

Merged via the queue into main with commit d7a851f Jun 10, 2026
48 checks passed
@daxtheduck
daxtheduck deleted the dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1 branch June 10, 2026 12:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Update one or more dependencies version minor Increment the minor version when merged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants