Repository navigation
build(deps-dev): bump @duckduckgo/eslint-config from v0.1.0 to v0.2.1 - #2718
daxtheduck merged 1 commit into
Conversation
|
Suggested comment for Cursor review (copy and paste as a new comment): Note: GitHub Actions bot cannot trigger Cursor agent directly. Please copy the above comment to invoke the review. |
There was a problem hiding this comment.
Stale comment
Dependency risk review for
@duckduckgo/eslint-configv0.1.0 -> v0.2.1:Confirmed findings: none blocking.
Evidence checked:
- PR diff only updates
package.jsonandpackage-lock.jsonfor this direct dev dependency.- Upstream
index.jsis unchanged between the old resolved commit09f3780...and v0.2.11a2a3f...; upstream release notes are release/dependabot automation, README/changelog, and dependency metadata changes.- The lockfile impact is limited to dev-only lint packages:
eslint-config-prettier9.1.2 -> 10.1.8,eslint-plugin-n17.23.2 -> 18.0.1, plus related resolver/semver/get-tsconfig/tapable changes.ts-declaration-locationis removed becauseeslint-plugin-nmoved it to an optional peer.- Current repo usage still needs the dependency:
eslint.config.jsimports@duckduckgo/eslint-configdirectly.- Local validation passed with the PR state after generated assets were built:
npm run build && npm run lint.- PR unit/integration/snapshot checks observed passing for the dependency-relevant paths. The failed
buildjob is a release-branch push rejection, and the failed Asana sync is missingASANA_ACCESS_TOKEN; neither appears caused by this dependency bump.Uncertain/residual concerns:
eslint-plugin-n18 is a breaking major and the installed package declares Node^20.19.0 || ^22.13.0 || >=24. CI uses.nvmrcvalue22and resolved locally to Node 22.22.3, so validation passed. If any supported developer/automation environment pins an older Node 22 point release, lint/install could fail and should be validated there.npm auditreports existing repo dev-dependency advisories, but the vulnerable package versions are unchanged between base and this PR; I did not find a new advisory introduced by this bump.No separate fix PR drafted because I did not find a concrete dependency-update issue to fix.
Sent by Cursor Automation: Review dependabot
There was a problem hiding this comment.
Stale comment
Web Compatibility Assessment
No findings. This PR only updates the root dev dependency
@duckduckgo/eslint-configand the corresponding lockfile entries; it does not change injected runtime code, wrapper utilities, message bridge, platform entry points, DOM manipulation, or API shims.Security Assessment
No findings. There are no changes to captured globals, messaging transports, origin validation, config handling, iframe access, or page-world execution paths.
Risk Level
Low Risk: devDependency/lockfile-only change affecting lint tooling rather than shipped injected JavaScript behavior.
Recommendations
No code changes requested. Verification performed:
npm ci,npm run build, andnpm run lintall pass. The release comparison for@duckduckgo/eslint-configv0.1.0...v0.2.1shows automation/metadata changes and dependency metadata updates, with noindex.jsrule/config changes.Sent by Cursor Automation: Web compat and sec
|
@dependabot rebase |
bfd5ad8 to
81d355f
Compare
Build Branch
Static preview entry points
QR codes (mobile preview)
Integration commandsnpm (Android / Extension): Swift Package Manager (Apple): .package(url: "https://github.com/duckduckgo/content-scope-scripts.git", branch: "pr-releases/dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1")git submodule (Windows): git -C submodules/content-scope-scripts fetch origin pr-releases/dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1
git -C submodules/content-scope-scripts checkout origin/pr-releases/dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1Pin to exact commitnpm (Android / Extension): Swift Package Manager (Apple): .package(url: "https://github.com/duckduckgo/content-scope-scripts.git", revision: "3ca35032d307b27017ff36dbf3eadffd61243ca7")git submodule (Windows): git -C submodules/content-scope-scripts fetch origin pr-releases/dependabot/npm_and_yarn/main/duckduckgo/eslint-config-v0.2.1
git -C submodules/content-scope-scripts checkout 3ca35032d307b27017ff36dbf3eadffd61243ca7 |
There was a problem hiding this comment.
Stale comment
Injected PR Evaluation: Web Compatibility & Security
Reviewed diff
b76f876…81d355f— 2 files changed (package.json,package-lock.jsononly).Web Compatibility Assessment
No findings. This PR bumps
@duckduckgo/eslint-configfromv0.1.0→v0.2.1(devDependency). No files underinjected/,messaging/, platform entry points, or runtime bundles are modified. ESLint configuration is a build-time/lint-time tool and is not shipped to browsers.Security Assessment
No findings. The changed packages are
devDependenciesonly and do not affect injected script execution, messaging transports, captured globals, or remote config handling.Info: Transitive updates include
eslint-config-prettier(9→10) andeslint-plugin-n(17→18).eslint-plugin-n@18raises its Node engine requirement to^20.19.0 || ^22.13.0 || >=24and movests-declaration-locationto an optional peer dependency. This affects local/CI lint environments only, not production browser payloads.Risk Level
Low Risk — dev-only dependency version bump with no runtime code changes.
Recommendations
- Merge when CI green — no injected-code review blockers.
- Verify CI Node version meets
eslint-plugin-n@18engine requirement (^20.19.0 || ^22.13.0 || >=24). This repo uses Node 22, so should be fine.- No additional web-compat or security tests required for this change class.
Sent by Cursor Automation: Web compat and sec
There was a problem hiding this comment.
Stale comment
Dependency review:
@duckduckgo/eslint-configv0.1.0 → v0.2.1Verdict: Low risk — safe to merge once CI is green.
This PR only bumps the git tag in
package.json/package-lock.json. No application source changes.
Changelog & rule impact
Compared
v0.1.0...v0.2.1induckduckgo/eslint-config:
Area Change index.js(exported rules)Unchanged — same flat-config array and rule set v0.2.0 Dependabot/CI/release automation; transitive dep bumps v0.2.1 Release tooling tweak only Confirmed: No new/changed ESLint rules reach this repo. Local overrides in
eslint.config.js(@typescript-eslint/*,no-void,require-await, react-hooks, etc.) are unaffected.Transitive bumps (via lockfile):
Package Was Now Notes eslint-config-prettier9.x 10.x Adds @stylisticconflict disables; we don't use@stylisticeslint-plugin-n17.x 18.x ESM migration, Node ≥20.19 / ≥22.13, ESLint ≥8.57.1; drops no-unpublished-binfrom recommended (not enabled in DDG config)ts-declaration-locationdirect dep optional peer of eslint-plugin-nOnly relevant for n/no-sync, which DDG config does not enable
Validation
npx eslint .— passnpm run build && npm run lint(CI-equivalent) — pass- CI
unitjob runsnpm run lintafter build (.github/workflows/tests.yml)Test coverage gap (pre-existing): No repo-local unit tests for ESLint config composition. Coverage is the CI lint gate. Upstream
[email protected]now ships ascripts/smoke-test.mjs, but this repo does not invoke it.
Is the dependency still needed?
Yes.
eslint.config.jsspreads...ddgConfigas the shared DDG baseline (standard-style rules + import/n/promise plugins). Inlining would duplicate config maintained across DDG repos.
Supply chain
Factor Assessment Provenance First-party duckduckgo/eslint-config(private), pinned to git tag#v0.2.1Integrity Lockfile now includes integrityhash for the git dep — improvement over v0.1.0Version field Corrected from 1.0.0→0.2.1in lockfile (aligns tag with package version)Nested deps eslint-plugin-import/eslint-plugin-promisenested under@duckduckgo/eslint-config— pre-existing pattern, not introduced hereRuntime exposure Dev-only; not shipped in browser bundles Uncertain (low severity):
eslint-plugin-n@18requires Node^20.19.0 \|\| ^22.13.0 \|\| >=24..nvmrcis22without a patch floor; developers on Node 22.0–22.12 may see engine warnings. CIsetup-nodewith.nvmrccurrently resolves to a compatible 22.x. Consider pinning.nvmrcto22.13+ if engine warnings appear locally — not a blocker for this PR.
Fix PR
No companion fix PR needed. ESLint passes with the updated config; no repo changes required beyond this bump.
Sent by Cursor Automation: Review dependabot
|
@dependabot rebase |
81d355f to
f640143
Compare
There was a problem hiding this comment.
Stale comment
Injected PR Evaluation: Web Compatibility & Security
Reviewed diff
6a9b19ff…f6401435— 2 files changed (package.json,package-lock.json).This PR bumps
@duckduckgo/eslint-configfromv0.1.0→v0.2.1(devDependency only). Transitive lockfile updates includeeslint-config-prettier9→10,eslint-plugin-n17→18, and minor semver/tapable/enhanced-resolve bumps. No runtime/injected source files are modified.Verified locally:
npx eslint .passes with the new config.
Web Compatibility Assessment
No findings.
This change does not touch
injected/,messaging/, platform entry points, wrapper utilities, or any code bundled intocontentScope.js. Dev-only lint tooling has zero effect on API surface fidelity, prototype chains, DOM interaction, timing, platform behavior, or third-party script compatibility in the browser.
Security Assessment
No findings.
@duckduckgo/eslint-configis adevDependencyand is not shipped to end users. The lockfile updates (eslint-config-prettier,eslint-plugin-n, etc.) affect CI/local lint only — no impact on global capture hygiene, messaging trust boundaries, prototype attacks, data exfiltration vectors, config trust, or iframe security in the injected runtime.
Risk Level
Low Risk — dependency-only bump confined to ESLint tooling; no injected runtime, messaging, or security-sensitive code paths changed.
Recommendations
- Merge when CI is green — no web-compat or security blockers from this diff.
- Optional sanity check — confirm
npm run lintpasses in CI (rule changes ineslint-plugin-nv18 are dev-time only; localeslint .already passes).- No injected-runtime tests required for this PR scope.
Sent by Cursor Automation: Web compat and sec
There was a problem hiding this comment.
Stale comment
Dependency update review:
@duckduckgo/eslint-configv0.1.0 → v0.2.1Verdict: Low risk — safe to merge. No companion fix PR is needed.
What actually changed
The PR only bumps the git tag in
package.json/package-lock.json. Comparingindex.jsatv0.1.0andv0.2.1shows no rule or config changes — the files are identical.The upstream changelog (v0.2.0 / v0.2.1) covers release automation and Dependabot housekeeping, not lint rule changes. The functional delta is transitive dependency bumps inside
@duckduckgo/eslint-config:
Transitive dep Before After eslint-config-prettier^9.1.0 → 9.1.2 ^10.0.0 → 10.1.8 eslint-plugin-n^17.11.1 → 17.23.2 ^18.0.0 → 18.1.0 Lockfile also drops
ts-declaration-locationas a direct transitive install (eslint-plugin-nv18 moved it to an optional peer).
Impact on this repo (confirmed)
Integration:
eslint.config.jsspreads...ddgConfigand layers TypeScript, React hooks, and repo-specific overrides on top. The shared config remains the right abstraction for DDG-wide lint consistency — no alternative in-repo.Lint behavior:
npx eslint .passes cleanly on bothmain(v0.1.0) and this branch (v0.2.1) with zero errors/warnings. CI'snpm run lintjob (which includes eslint + tsc + prettier) is the effective regression test; no dedicated eslint-config unit tests exist here, which is normal for a lint preset consumer.
eslint-plugin-nv18 breaking changes: The v18.0.0 release includes ESM migration, stricter Node/ESLint engine requirements, and changes to recommended rules (no-unpublished-binremoved,no-syncpeer dep change). None of these affect this repo because@duckduckgo/eslint-configonly enables seven explicitn/*rules (handle-callback-err,no-callback-literal,no-deprecated-api,no-exports-assign,no-new-require,no-path-concat,process-exit-as-throw) — not the plugin's recommended preset and notn/no-sync.
eslint-config-prettierv10: No new lint violations observed; it continues to disable formatting conflicts with Prettier as before.
Supply chain
- Source: First-party DDG git dependency (
github:duckduckgo/eslint-config#v0.2.1), tag-pinned to commit1a2a3f07.- Integrity: Lockfile now records an
integrityhash for the git tarball — improvement over v0.1.0.- Risk: Low. No new external publishers; transitive bumps are well-known eslint-community / prettier packages.
Uncertain / minor (no action required)
Node engine floor:
eslint-plugin-n@18requires Node^20.19.0 || ^22.13.0 || >=24..nvmrcis22(resolves to latest 22.x in CI; currently 22.14.0 here). Developers on Node 22.0–22.12 may seeEBADENGINEwarnings at install time but lint still works. Pinning.nvmrcto22.13would make this explicit — optional hygiene, not a blocker.Version label in lockfile: Package version string changed from
1.0.0to0.2.1upstream (semver reset). Cosmetic only; git tag pin is what matters.
Fix PR
No fixes required. Evaluated opening a companion PR (e.g.
.nvmrcpin) and determined the engine concern is informational only given current CI/dev tooling.Sent by Cursor Automation: Review dependabot
|
@dependabot rebase |
f640143 to
d4dc96e
Compare
There was a problem hiding this comment.
Stale comment
Injected PR Evaluation: Web Compatibility & Security
PR:
build(deps-dev): bump @duckduckgo/eslint-config from v0.1.0 to v0.2.1(#2718)Reviewed diff
23c7c8c...d4dc96e— onlypackage.jsonandpackage-lock.jsonchange the@duckduckgo/eslint-configpin fromv0.1.0→v0.2.1. No files underinjected/,messaging/, or other runtime bundles are modified.Verified locally:
npx eslint .passes with the updated config.
Web Compatibility Assessment
No findings.
This is a devDependency used only by root
eslint.config.jsat lint time. It is not bundled into content-scope scripts injected into web pages, so it cannot affect API shims, prototype patches, DOM behavior, or third-party script compatibility at runtime.
Security Assessment
No findings.
- No changes to
captured-globals.js, message bridge, messaging transports, or origin validation.- No new network surface,
postMessage, or dynamic code execution paths.- Transitive bumps (
eslint-config-prettier9→10,eslint-plugin-n17→18) are dev-only and do not ship to browsers.
Risk Level
Low Risk — dependency-only change confined to the lint toolchain; zero runtime/injection surface area.
Recommendations
- Merge after CI green — confirm the repo’s
npm run lintjob passes on this branch (eslint portion verified; full pipeline may include tsc/build steps unrelated to this bump).- No injected-code follow-up required — no web-compat or security mitigations needed for this PR.
- Optional housekeeping — upstream
eslint-configv0.2.x also corrects its package version metadata (1.0.0→0.2.1); no action needed here beyond the pin update already in this PR.Sent by Cursor Automation: Web compat and sec
There was a problem hiding this comment.
Stale comment
Dependency update risk assessment:
@duckduckgo/eslint-configv0.1.0 → v0.2.1Verdict: Low risk — safe to merge (no follow-up PR required)
Summary
This PR only bumps the git-pinned devDependency in
package.json/package-lock.json. Upstreamindex.js(the actual ESLint rules) is unchanged betweenv0.1.0andv0.2.1; the release is primarily dependency maintenance, release automation, and version normalization.
Changelog impact (confirmed)
Area Change Impact on this repo @duckduckgo/eslint-configrules (index.js)No diff None — same n/*,import/*,promise/*, and Standard-derived ruleseslint-config-prettier9 → 10Adds @stylisticrule disablingNone observed — project uses Prettier for formatting; lint passes eslint-plugin-n17 → 18ESM migration; no-unpublished-binremoved from recommended; Node ≥20.19 / ESLint ≥8.57.1Low — this config sets explicit n/*rules (notrecommended), so the recommended-set change does not applyPackage version 1.0.0→0.2.1Tag-based pinning unchanged ( #v0.2.1)Cosmetic — fixes prior version/tag mismatch Upstream v0.2.0 changelog: dependabot bumps, CI, release automation, README. No rule changes.
Validation performed
npm ci && npm run build && npm run linton the PR branch: passes (eslint, tsc, strict-core, surrogates check, prettier).- Node in CI (
.nvmrc= 22) satisfieseslint-plugin-n@18engine requirement (^22.13.0).- Root
eslintis^10.4.0, above peer minimums.
Test coverage
- Upstream: v0.2.x adds a smoke test (
scripts/smoke-test.mjs) that loads the flat config and lintsindex.js.- This repo:
npm run lintin.github/workflows/tests.yml(afternpm run build) is the real integration gate. No additional tests needed for this bump.
Dependency necessity
@duckduckgo/eslint-configremains the right abstraction — it centralizes DDG-wide JS lint standards and is extended locally ineslint.config.jswithtypescript-eslint, React hooks, and project-specific overrides. No better alternative in-repo.
Supply chain
Factor Assessment Source Internal DDG repo ( duckduckgo/eslint-config), git tag pinnedIntegrity Lockfile now includes integrityhash for the git tarball (improvement over v0.1.0 lock entry)Transitive deps eslint-config-prettier@10,eslint-plugin-n@18— both reputable, pulled via the shared configVersion renumbering 1.0.0→0.2.1is confusing for semver tooling but not a functional downgrade because resolution is by git ref, not npm versionUncertain (low priority): Future
eslint-plugin-n@18minor releases could add stricter Node builtin checks (node-builtinssupport data updated in v18). Monitor if newn/no-unsupported-featuresfindings appear on Node API usage inscripts/— none surfaced in this validation.
Follow-up PR
No code changes required. Lint is clean with the new config; no separate fix PR drafted.
Sent by Cursor Automation: Review dependabot
|
@dependabot rebase |
d4dc96e to
f8d02ee
Compare
There was a problem hiding this comment.
Stale comment
Web Compatibility Assessment
No findings. This PR only bumps
@duckduckgo/eslint-config(v0.1.0 → v0.2.1) inpackage.json/package-lock.json. No files underinjected/,messaging/,special-pages/, or platform entry points are modified. The eslint config is a devDependency consumed at lint time viaeslint.config.js; it is not bundled into injected scripts shipped to web pages.info —
package.json(line 43): Dev-tooling-only change; zero API surface, prototype, DOM, timing, or platform-runtime impact.info —
package-lock.json(transitive deps): Lockfile updates foreslint-config-prettier(^10),eslint-plugin-n(^18), and other dev-only packages. These do not affect production bundles or page-world behavior.
Security Assessment
No findings. No changes to
captured-globals.js, messaging transports, message bridge,wrapper-utils.js,shouldExemptMethod(), origin validation, or any runtime trust boundary.info —
package.json/package-lock.json: Dependency resolution change only.@duckduckgo/eslint-configand its transitive plugins run in the Node.js lint toolchain, not in the hostile page environment.
Risk Level
Low Risk — This is a devDependency version bump with no injected runtime code changes and no modifications to security-sensitive subsystems.
Recommendations
- CI verification (info): Merge after
npm run lintpasses in CI. Localnpx eslint .succeeds with v0.2.1; upstream changes between v0.1.0 and v0.2.1 are primarily CI/automation and transitive dev-dep bumps — the exported rule set inindex.jsis unchanged.- Node engine note (info):
eslint-plugin-n@18(transitive) requires Node^20.19.0 || ^22.13.0 || >=24. This repo targets Node 22, so no action needed unless CI matrix includes older Node versions.- No runtime follow-up required: No config gating, messaging hardening, or compat testing needed for this PR.
Sent by Cursor Automation: Web compat and sec
|
@dependabot rebase |
|
Looks like this PR is already up-to-date with main! If you'd still like to recreate it from scratch, overwriting any edits, you can request |
|
@dependabot recreate |
f8d02ee to
9215b63
Compare
There was a problem hiding this comment.
Stale comment
Injected PR Evaluation: Web Compatibility & Security
Web Compatibility Assessment
No findings.
This PR only updates devDependencies (
package.json,package-lock.json). It does not modifyinjected/src/,wrapper-utils.js,captured-globals.js, messaging transports, the message bridge, platform entry points, or any code bundled into page-world injections. There is no change to browser API shimming, DOM interaction, prototype patching, or feature lifecycle behavior.Security Assessment
No findings.
@duckduckgo/eslint-configis a devDependency used at lint time only; it is not shipped to end users in injected bundles or special-pages runtime artifacts. The lockfile updates are limited to ESLint tooling and transitive dev tooling (eslint-config-prettier9→10,eslint-plugin-n17→18, plus minor semver/tapable/enhanced-resolve churn). None of these affect the hostile-page trust boundary, messaging validation, or global-capture hygiene in production code.Info (dev tooling only):
eslint-plugin-n@18tightens its Node engine requirement to^20.19.0 || ^22.13.0 || >=24. This repo targets Node 22 and remains compatible; it is a CI/dev-environment constraint, not a runtime security surface.Risk Level
Low Risk — dependency-only bump with no injected runtime, messaging, or security-sensitive source changes.
Recommendations
- Info: Merge is safe from a web-compat/security perspective. No injected-runtime testing is required for this diff alone.
- Info: Confirm CI lint passes on the PR branch (local
npx eslint .succeeds with v0.2.1). Fullnpm run lintalso depends on generated injected artifacts (build/locales, surrogates) unrelated to this change.- Info: The lockfile includes minor transitive churn (
enhanced-resolve,semver,tapable,get-tsconfig) beyond the direct eslint-config bump; scope is still dev-only and expected for a Dependabot lockfile refresh.Sent by Cursor Automation: Web compat and sec
There was a problem hiding this comment.
Stale comment
Dependency update review:
@duckduckgo/eslint-configv0.1.0 → v0.2.1Verdict: Low risk — safe to merge once CI is green. No companion fix PR needed.
What changed
PR diff is limited to
package.json/package-lock.json. No application source oreslint.config.jsedits.Upstream
v0.1.0...v0.2.1is release automation + transitive dep maintenance.index.jsis byte-for-byte identical between tags — no new/changed ESLint rules reach this repo.Transitive bumps (via lockfile):
Package Before After Notes eslint-config-prettier9.1.2 10.1.8 Adds @stylisticconflict disables; we don't use@stylisticeslint-plugin-n17.23.2 18.1.0 ESM migration; Node ^20.19.0 || ^22.13.0 || >=24; ESLint>=8.57.1ts-declaration-locationdirect transitive optional peer of eslint-plugin-nOnly relevant for n/no-sync, which DDG config does not enable
eslint-plugin-nv18 breaking changes (no-unpublished-binremoved from recommended,no-syncpeer dep change) do not affect this repo because@duckduckgo/eslint-configenables seven explicitn/*rules, not the plugin's recommended preset.
Impact on this repo (confirmed)
- Integration:
eslint.config.jsspreads...ddgConfigand layerstypescript-eslint, React hooks, and repo overrides on top. Still the right DDG-wide baseline.- Prettier alignment:
.prettierrcalready matches upstream's newly documented recommendation (singleQuote,printWidth: 140,tabWidth: 4).- Lint behavior:
npx eslint .passes on both v0.1.0 and v0.2.1 with 0 errors and the same 6 pre-existingunused-disablewarnings (in generatedcontentScope.jsoutput lint). No new violations from this bump.- CI-equivalent validation:
npm run build && npm run lintpasses on this branch (eslint, tsc, strict-core, surrogates, prettier).
Test coverage
- Upstream: v0.2.x adds
scripts/smoke-test.mjs(loads flat config, lintsindex.js).- This repo: No dedicated eslint-config unit tests (normal for a preset consumer). The
unitjob'snpm run lintafternpm run buildin.github/workflows/tests.ymlis the effective integration gate. Adequate for this change class.
Supply chain
Factor Assessment Provenance First-party duckduckgo/eslint-config, git tag#v0.2.1→ commit1a2a3f07Integrity Lockfile now records integrityhash for the git tarball — improvement over v0.1.0Version metadata Upstream corrected 1.0.0→0.2.1in lockfile; cosmetic only (resolution is by git ref)Runtime exposure Dev-only; not shipped in browser bundles npm audit13 existing dev-dep advisories; none attributable to this bump's changed packages
Uncertain / minor (no action required)
Node engine floor:
eslint-plugin-n@18requires Node^20.19.0 \|\| ^22.13.0 \|\| >=24..nvmrcis22(no patch floor); CIsetup-noderesolves to a compatible 22.x. Developers on Node 22.0–22.12 may seeEBADENGINEwarnings at install — lint still works on 22.14.0. Pinning.nvmrcto22.13+ would be optional hygiene, not a blocker.Future
eslint-plugin-nminors: v18 updatednode-builtinssupport data. If stricter builtin checks land,scripts/Node API usage could surface newn/*findings — none observed in this validation.
Fix PR
None drafted. Evaluated a companion PR (e.g.
.nvmrcpin) and determined the engine concern is informational only given current CI/dev tooling. No concrete dependency-update defect to fix.Sent by Cursor Automation: Review dependabot
|
@dependabot rebase |
9215b63 to
2baf811
Compare
There was a problem hiding this comment.
Stale comment
Web Compatibility Assessment
No findings. This PR only updates
devDependencies(package.json,package-lock.json). No files underinjected/,messaging/, or platform entry points are modified. The bumped packages (@duckduckgo/eslint-config,eslint-config-prettier,eslint-plugin-n, and other transitive dev-only deps) are not bundled into content-scope scripts and do not execute in the page context.Security Assessment
No findings. No changes to
captured-globals.js, messaging transports, message bridge, wrapper utilities, feature initialization, or any runtime security boundary. Dev tooling cannot be exploited by hostile web pages because it is not shipped to end users.info —
package.json/package-lock.json:@duckduckgo/eslint-configv0.1.0 → v0.2.1 with transitive bumps (eslint-config-prettier9→10,eslint-plugin-n17→18). These affect CI/local lint only.Risk Level
Low Risk — Pure dev-dependency version bump with zero runtime code changes; no web compatibility or security surface area in injected scripts.
Recommendations
- info — Merge is safe from a web-compat/security perspective. Confirm CI lint job passes on this branch (expected;
eslint .succeeds locally with the new config).- info —
eslint-plugin-n@18raises the Node engine floor to^20.19.0 || ^22.13.0 || >=24. This repo already targets Node 22, so no action needed unless CI matrix includes older Node versions.- info — Future lint rule changes from the bumped eslint plugins may surface new violations in separate PRs; that is a developer-experience concern, not a runtime regression risk.
Automated review — Injected PR Evaluation: Web Compatibility & Security
Sent by Cursor Automation: Web compat and sec
There was a problem hiding this comment.
Stale comment
Dependency review:
@duckduckgo/eslint-configv0.1.0 → v0.2.1Verdict: Low risk — safe to merge. No companion fix PR drafted.
What changed
This PR only updates the git tag in
package.json/package-lock.json. Comparingindex.jsat v0.1.0 vs v0.2.1 shows no rule or flat-config changes — the exported config is byte-for-byte identical.Upstream changelog (v0.2.0 / v0.2.1) is release automation, Dependabot housekeeping, README, and transitive dependency bumps — not lint rule changes.
Transitive lockfile impact:
Package Before After Relevance here eslint-config-prettier9.1.2 10.1.8 Adds @stylisticconflict disables; repo does not use@stylisticeslint-plugin-n17.23.2 18.1.0 Major with ESM migration + stricter engines; DDG config enables only 7 explicit n/*rules, not the plugin recommended presetts-declaration-locationdirect transitive optional peer of eslint-plugin-nOnly needed for n/no-sync, which DDG config does not enable
Impact on this repo (confirmed)
- Integration:
eslint.config.jsspreads...ddgConfigand layers TypeScript, React hooks, and repo-specific overrides. The shared config remains the right abstraction — inlining would duplicate DDG-wide lint policy.- Prettier alignment:
.prettierrcalready matches the settings now documented in upstream v0.2.1 README (singleQuote,printWidth: 140,tabWidth: 4).eslint-plugin-nv18 breaking changes (release notes): ESM migration, Node^20.19.0 || ^22.13.0 || >=24,no-unpublished-binremoved from recommended,ts-declaration-locationmoved to optional peer. None affect this repo because@duckduckgo/eslint-configonly enables:n/handle-callback-err,n/no-callback-literal,n/no-deprecated-api,n/no-exports-assign,n/no-new-require,n/no-path-concat,n/process-exit-as-throw.eslint-config-prettierv10 (release notes): adds@stylisticsupport only; no new violations observed.
Validation
Check Result npx eslint .pass npm run build && npm run lint(CI-equivalent)pass (Node 22.14.0) Runtime / injected code diff none — devDependency only Test coverage: No repo-local unit tests for ESLint config composition (pre-existing). Coverage is the CI
unitjob lint gate (.github/workflows/tests.yml). Upstream v0.2.1 now shipsscripts/smoke-test.mjs, but this repo does not invoke it — acceptable for a config consumer.
Supply chain
Factor Assessment Provenance First-party duckduckgo/eslint-config(private), tag-pinned#v0.2.1→ commit1a2a3f07Integrity Lockfile now records integrityhash for the git dep — improvement over v0.1.0Version metadata Corrected from 1.0.0→0.2.1in lockfile (cosmetic; tag pin is authoritative)Runtime exposure Dev-only; not shipped in browser bundles New publishers None — transitive bumps are eslint-community / prettier packages
Uncertain / minor (no action required)
Node engine floor:
eslint-plugin-n@18requires Node^20.19.0 || ^22.13.0 || >=24..nvmrcis22without a patch floor; developers on Node 22.0–22.12 may seeEBADENGINEwarnings at install. CIsetup-nodewith.nvmrcresolves to a compatible 22.x (22.14.0 here). Pinning.nvmrcto22.13+ would make this explicit — optional hygiene, not a blocker.
npm audit: Existing dev-dependency advisories remain; no new vulnerable package versions introduced by this bump.
Fix PR
No fixes required. Evaluated a companion PR (e.g.
.nvmrcpin) and determined the engine concern is informational only given current CI/dev tooling.Sent by Cursor Automation: Review dependabot
|
@dependabot rebase |
Bumps [@duckduckgo/eslint-config](https://github.com/duckduckgo/eslint-config) from v0.1.0 to v0.2.1. - [Release notes](https://github.com/duckduckgo/eslint-config/releases) - [Changelog](https://github.com/duckduckgo/eslint-config/blob/main/CHANGELOG.md) - [Commits](duckduckgo/eslint-config@09f3780...1a2a3f0) --- updated-dependencies: - dependency-name: "@duckduckgo/eslint-config" dependency-version: 1a2a3f071f76b51a9917df6476211a8f20eb81bd dependency-type: direct:development ... Signed-off-by: dependabot[bot] <[email protected]>
2baf811 to
88f5f26
Compare
There was a problem hiding this comment.
Injected PR Evaluation: Web Compatibility & Security
PR: build(deps-dev): bump @duckduckgo/eslint-config from v0.1.0 to v0.2.1
Reviewed diff e2c8664…88f5f26 — 2 files changed (package.json, package-lock.json). No changes under injected/, messaging/, platform entry points, or any runtime bundle source.
Web Compatibility Assessment
No findings.
This PR modifies only devDependencies. @duckduckgo/eslint-config and its transitive packages (eslint-config-prettier, eslint-plugin-n, etc.) are used exclusively at lint/CI time. They are not bundled into contentScope.js or shipped to end-user browsers. No API overrides, DOM manipulation, messaging, or feature initialization code is touched.
Security Assessment
No findings.
- Global capture / messaging / prototype attacks: Not applicable — no injected runtime code changed.
- Supply chain (info): The dependency resolves from
github:duckduckgo/eslint-config#v0.2.1(commit1a2a3f0). This is an internal DDG package pinned by git tag; acceptable for a dev tool, but verify CI lint passes on merge. - Lockfile noise (info):
package-lock.jsonalso updatesspecial-pages→@duckduckgo/design-tokensfrom a commit hash to#v0.28.0. This is unrelated to the eslint-config bump and should be confirmed intentional (likely lockfile regeneration side-effect).
Risk Level
Low Risk — dev-only tooling version bump with zero changes to injected page-world code, wrapper utilities, messaging transports, or security-sensitive runtime paths.
Recommendations
- Verify CI lint passes —
eslint-plugin-nmajor bump (v17 → v18) may surface new lint violations; confirmnpm run lintis green before merge. - Confirm Node engine compatibility —
eslint-plugin-n@18requires^20.19.0 || ^22.13.0 || >=24; repo.nvmrcspecifies Node 22, which satisfies this. - Optional housekeeping — If the
@duckduckgo/design-tokenslockfile entry change is unintentional, regenerate the lockfile from a cleanmaincheckout to keep the PR scoped to eslint-config only.
Sent by Cursor Automation: Web compat and sec
There was a problem hiding this comment.
Dependency update review: @duckduckgo/eslint-config v0.1.0 → v0.2.1
Verdict: Low risk — safe to merge. No follow-up PR required.
What actually changed
Compared v0.1.0...v0.2.1 in the upstream repo:
index.jsis byte-for-byte identical — no new/disabled ESLint rules in this repo.- Package metadata/CI/release automation added upstream (Dependabot, smoke test, semver normalization
1.0.0→0.2.1). - Transitive bumps only:
eslint-config-prettier9.x → 10.x — adds@stylisticrule disabling; unused here.eslint-plugin-n17.x → 18.x — ESM migration, Node>=20.19, ESLint>=8.57.1; aligns with this repo (Node 22via.nvmrc,eslint ^10.4.0).
Impact on content-scope-scripts
Integration point is eslint.config.js, which spreads ...ddgConfig then layers project-specific typescript-eslint, React hooks, and overrides (e.g. no-void for injected/messaging).
Confirmed (validated locally):
npx eslint .passes on this branch.- Full
npm run lintpasses afternpm run build(matches CIunitjob, which is green).
Confirmed (upstream changelog): v0.2.0/v0.2.1 changes are tooling/docs only; no rule-set edits.
Uncertain (low concern): eslint-plugin-n@18 moved ts-declaration-location to an optional peer dep and dropped no-unpublished-bin from its recommended preset. Neither affects this repo — the shared config enables only explicit n/* rules (n/no-deprecated-api, n/no-path-concat, etc.), not the plugin recommended preset or n/no-sync.
Test coverage
| Layer | Coverage |
|---|---|
| Upstream | New smoke test (scripts/smoke-test.mjs) loads config + lints index.js |
| This repo | npm run lint in CI (unit job) exercises the full flat config across all workspaces, plus lint-no-output-globals for bundled output |
No dedicated unit tests for the config package itself in C-S-S, but lint is the meaningful integration test and it passes.
Is the dependency still warranted?
Yes. This is the shared DDG ESLint baseline; duplicating ~200 lines of rules locally would be worse. .prettierrc already matches the upstream-recommended settings (singleQuote, printWidth: 140, tabWidth: 4).
Supply chain
| Factor | Assessment |
|---|---|
| Provenance | First-party duckduckgo/eslint-config, tag-pinned (#v0.2.1) |
| Integrity | Lockfile now includes integrity hash for the git dependency (improvement over v0.1.0) |
| Transitives | npm registry packages with pinned versions/integrity |
| Runtime exposure | Dev-only; not shipped in browser bundles |
No new third-party maintainer risk beyond routine transitive npm updates.
Lockfile noise (informational)
package-lock.json also normalizes @duckduckgo/design-tokens to #v0.28.0 and bumps some unrelated transitives (enhanced-resolve, tapable, semver). These are lockfile resolution artifacts, not functional changes from this PR's intent.
No separate fix PR drafted — nothing actionable found beyond merging once remaining CI jobs finish.
Sent by Cursor Automation: Review dependabot
|
@dependabot rebase |
|
Dependabot attempted to update this pull request, but because the branch |
|
Oh no! Something went wrong on our end. Please try again later. If the problem persists, please contact GitHub support for assistance 🙇 |


Bumps @duckduckgo/eslint-config from v0.1.0 to v0.2.1.
Release notes
Sourced from @duckduckgo/eslint-config's releases.
Changelog
Sourced from @duckduckgo/eslint-config's changelog.
Commits
1a2a3f0Bump version to: 0.2.1 [skip ci]e2b7298Update CHANGELOG.md [skip ci]d773502don't apply major label to dependabot prs9bc1a41Bump version to: 0.2.0 [skip ci]5d03d08Update CHANGELOG.md [skip ci]7ddf7cfset release CI identity to Dax07b1e4cMerge pull request #4 from duckduckgo/max/automation3d05557don't hardcode the version in readme930248cuse colldown from dependabot673dccfMerge pull request #3 from duckduckgo/max/dependabotNote
Low Risk
Dev-only dependency and lockfile updates; risk is limited to possible new or changed ESLint findings in CI, not production behavior.
Overview
Bumps the shared
@duckduckgo/eslint-configdev dependency from v0.1.0 to v0.2.1 in the rootpackage.json, with the lockfile refreshed accordingly.That pull in newer transitive lint tooling—notably
eslint-config-prettierv10 andeslint-plugin-nv18 (stricter Node engine expectations and optional TypeScript-related peers). The special-pages workspace also switches@duckduckgo/design-tokensfrom a commit SHA to thev0.28.0tag reference in the lockfile.No runtime or application source changes; impact is limited to local/CI
eslintbehavior when rules or plugin defaults differ in the new config release.Reviewed by Cursor Bugbot for commit 88f5f26. Bugbot is set up for automated code reviews on this repo. Configure here.