Skip to content

Bump the wonder-stuff group with 2 updates#3343

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/wonder-stuff-85f70cbe43
Open

Bump the wonder-stuff group with 2 updates#3343
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/wonder-stuff-85f70cbe43

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 13, 2026

Bumps the wonder-stuff group with 2 updates: @khanacademy/eslint-config and @khanacademy/eslint-plugin.

Updates @khanacademy/eslint-config from 5.2.1 to 6.0.2

Release notes

Sourced from @​khanacademy/eslint-config's releases.

@​khanacademy/eslint-config@​6.0.2

Patch Changes

  • 427718c: Re-publishing using Trusted Publishing (no functional change)
  • Updated dependencies [427718c]
    • @​khanacademy/eslint-plugin@​3.2.2
Changelog

Sourced from @​khanacademy/eslint-config's changelog.

6.0.2

Patch Changes

  • 427718c: Re-publishing using Trusted Publishing (no functional change)
  • Updated dependencies [427718c]
    • @​khanacademy/eslint-plugin@​3.2.2

6.0.1

Patch Changes

  • 71b60fb: Re-publish with Trusted Publishing (no functional changes from previous release)
  • Updated dependencies [71b60fb]
    • @​khanacademy/eslint-plugin@​3.2.1

6.0.0

Patch Changes

  • 8972b362: Re-publishing to enable Trusted Publishing
  • eee37380: Re-publish with Trusted Publishing (no functional changes in this release)
  • Updated dependencies [8972b362]
  • Updated dependencies [31bd9f47]
  • Updated dependencies [eee37380]
    • @​khanacademy/eslint-plugin@​3.2.0
Commits
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for @​khanacademy/eslint-config since your current version.


Updates @khanacademy/eslint-plugin from 3.1.2 to 3.2.2

Release notes

Sourced from @​khanacademy/eslint-plugin's releases.

@​khanacademy/eslint-plugin@​3.2.2

Patch Changes

  • 427718c: Re-publishing using Trusted Publishing (no functional change)
Changelog

Sourced from @​khanacademy/eslint-plugin's changelog.

3.2.2

Patch Changes

  • 427718c: Re-publishing using Trusted Publishing (no functional change)

3.2.1

Patch Changes

  • 71b60fb: Re-publish with Trusted Publishing (no functional changes from previous release)

3.2.0

Minor Changes

  • 31bd9f47: Updated to latest ancesdir and checksync

Patch Changes

  • 8972b362: Re-publishing to enable Trusted Publishing
  • eee37380: Re-publish with Trusted Publishing (no functional changes in this release)
Commits
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for @​khanacademy/eslint-plugin since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 13, 2026
@github-actions
Copy link
Contributor

github-actions bot commented Mar 13, 2026

🗄️ Schema Change: No Changes ✅

@github-actions
Copy link
Contributor

github-actions bot commented Mar 13, 2026

🛠️ Item Splitting: No Changes ✅

@github-actions
Copy link
Contributor

github-actions bot commented Mar 13, 2026

Size Change: 0 B

Total Size: 486 kB

ℹ️ View Unchanged
Filename Size
packages/kas/dist/es/index.js 20.8 kB
packages/keypad-context/dist/es/index.js 1 kB
packages/kmath/dist/es/index.js 5.96 kB
packages/math-input/dist/es/index.js 98.5 kB
packages/math-input/dist/es/strings.js 1.61 kB
packages/perseus-core/dist/es/index.item-splitting.js 11.8 kB
packages/perseus-core/dist/es/index.js 24.9 kB
packages/perseus-editor/dist/es/index.js 100 kB
packages/perseus-linter/dist/es/index.js 8.82 kB
packages/perseus-score/dist/es/index.js 9.26 kB
packages/perseus-utils/dist/es/index.js 403 B
packages/perseus/dist/es/index.js 187 kB
packages/perseus/dist/es/strings.js 7.47 kB
packages/pure-markdown/dist/es/index.js 1.39 kB
packages/simple-markdown/dist/es/index.js 6.71 kB

compressed-size-action

@github-actions
Copy link
Contributor

github-actions bot commented Mar 13, 2026

npm Snapshot: Published

Good news!! We've packaged up the latest commit from this PR (bc5fb4c) and published it to npm. You
can install it using the tag PR3343.

Example:

pnpm add @khanacademy/perseus@PR3343

If you are working in Khan Academy's frontend, you can run the below command.

./dev/tools/bump_perseus_version.ts -t PR3343

If you are working in Khan Academy's webapp, you can run the below command.

./dev/tools/bump_perseus_version.js -t PR3343

Comment on lines +19 to +20
"@khanacademy/eslint-config": "^6.0.2",
"@khanacademy/eslint-plugin": "^3.2.2",
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 Bumping @khanacademy/eslint-config from v5 to v6 introduces several unmet peer dependency requirements that could cause linting failures. Most critically, the new config requires eslint-import-resolver-typescript@^4.4.4 but the project has ^3.5.5 (major version mismatch); it also requires eslint-plugin-import@^2.32.0 (project has 2.29.1) and @typescript-eslint/*@8.46.3 (project has 8.27.0). These peer deps should be bumped alongside the eslint-config upgrade.

Extended reasoning...

What the bug is

@khanacademy/eslint-config@6.0.2 declares several peer dependencies that are not satisfied by the versions currently in this project's package.json. The lockfile at lines 2280-2287 shows the peer dependency requirements explicitly:

  • eslint-import-resolver-typescript: ^4.4.4 — project has ^3.5.5 (resolves to 3.6.1)
  • eslint-plugin-import: ^2.32.0 — project has ^2.29.1 (resolves to 2.29.1)
  • @typescript-eslint/eslint-plugin: 8.46.3 (exact) — project has ^8.18.0 (resolves to 8.27.0)
  • @typescript-eslint/parser: 8.46.3 (exact) — project has ^8.18.0 (resolves to 8.27.0)

The most severe mismatch

The eslint-import-resolver-typescript mismatch is the most concerning because it crosses a major version boundary (v3 vs v4 required). Major version bumps typically indicate breaking API changes. If the eslint-config v6 relies on v4-specific resolver APIs, import resolution during linting could fail or behave incorrectly.

Step-by-step proof

  1. The PR changes package.json line 19 from "@khanacademy/eslint-config": "^5.2.1" to "^6.0.2".
  2. In pnpm-lock.yaml at line 2286, the resolved @khanacademy/eslint-config@6.0.2 declares eslint-import-resolver-typescript: ^4.4.4 as a peer dependency.
  3. package.json line 65 still has "eslint-import-resolver-typescript": "^3.5.5".
  4. The lockfile at line 11090 confirms pnpm resolved the config with eslint-import-resolver-typescript: 3.6.1 — violating the ^4.4.4 peer dep requirement.
  5. Similarly, line 2287 requires eslint-plugin-import: ^2.32.0, but line 11091 shows 2.29.1 was resolved.
  6. Lines 2282-2283 require exact versions @typescript-eslint/eslint-plugin: 8.46.3 and @typescript-eslint/parser: 8.46.3, but lines 11086-11087 show 8.27.0 was resolved.

Why this wasn't caught

pnpm defaults to strict-peer-dependencies=false, so it installs successfully with warnings rather than erroring. Dependabot only bumped the direct dependencies (eslint-config and eslint-plugin) without analyzing or updating their peer dependency requirements.

Impact and fix

The peer dependency violations could cause linting failures, especially from the major version mismatch in eslint-import-resolver-typescript. The eslint-plugin-import and @typescript-eslint/* mismatches are within the same major version so are less likely to cause breakage, but still represent unmet contracts. The fix is to bump all four peer dependencies in package.json to versions that satisfy the requirements: eslint-import-resolver-typescript to ^4.4.4, eslint-plugin-import to ^2.32.0, and both @typescript-eslint packages to ^8.46.3.

Note: One verifier suggested the @typescript-eslint mismatch is a duplicate of the resolver mismatch since they share the same root cause. While the root cause is indeed the same (Dependabot not updating peer deps), these are distinct packages with different version gaps and risk profiles, and the fix requires updating each one separately. Consolidating them here ensures nothing is missed.

@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/wonder-stuff-85f70cbe43 branch from 689c58d to 49661fd Compare March 13, 2026 05:05
Bumps the wonder-stuff group with 2 updates: [@khanacademy/eslint-config](https://github.com/Khan/wonder-stuff/tree/HEAD/packages/eslint-config-khan) and [@khanacademy/eslint-plugin](https://github.com/Khan/wonder-stuff/tree/HEAD/packages/eslint-plugin-khan).


Updates `@khanacademy/eslint-config` from 5.2.1 to 6.0.2
- [Release notes](https://github.com/Khan/wonder-stuff/releases)
- [Changelog](https://github.com/Khan/wonder-stuff/blob/main/packages/eslint-config-khan/CHANGELOG.md)
- [Commits](https://github.com/Khan/wonder-stuff/commits/@khanacademy/eslint-config@6.0.2/packages/eslint-config-khan)

Updates `@khanacademy/eslint-plugin` from 3.1.2 to 3.2.2
- [Release notes](https://github.com/Khan/wonder-stuff/releases)
- [Changelog](https://github.com/Khan/wonder-stuff/blob/main/packages/eslint-plugin-khan/CHANGELOG.md)
- [Commits](https://github.com/Khan/wonder-stuff/commits/@khanacademy/eslint-plugin@3.2.2/packages/eslint-plugin-khan)

---
updated-dependencies:
- dependency-name: "@khanacademy/eslint-config"
  dependency-version: 6.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: wonder-stuff
- dependency-name: "@khanacademy/eslint-plugin"
  dependency-version: 3.2.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: wonder-stuff
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/wonder-stuff-85f70cbe43 branch from 49661fd to bc5fb4c Compare March 16, 2026 05:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants