Skip to content

fix(deps-dev): bump eslint-plugin-react-refresh from 0.5.3 to 0.5.7 - #918

Merged
d-oit merged 2 commits into
mainfrom
dependabot/npm_and_yarn/eslint-plugin-react-refresh-0.5.7
Oct 6, 2026
Merged

d-oit merged 2 commits into
mainfrom
dependabot/npm_and_yarn/eslint-plugin-react-refresh-0.5.7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps eslint-plugin-react-refresh from 0.5.3 to 0.5.7.

Release notes

Sourced from eslint-plugin-react-refresh's releases.

v0.5.7

Add allowCompoundComponents option (#117)

Default: false (true in vite config)

Don't warn when components are exported as an object gathering them. Every member of the object must be a component, and a member holding an anonymous function requires a component name as key.

This should be enabled if the fast refresh implementation correctly handles this case. Vite supports it since @vitejs/plugin-react 4.7.0, @vitejs/plugin-react-swc 3.11.0.

{
  "react-refresh/only-export-components": [
    "error",
    { "allowCompoundComponents": true }
  ]
}

Enabling this option allows code such as the following:

const Root = () => <></>;
const Label = () => <></>;
export const Tag = { Root, Label };

v0.5.6

  • Support re-exporting namespace components (fixes #116)

v0.5.5

  • Fix SCREAMING_SNAKE_CASE constant exported via export { Name } incorrectly treated as React component #114 (fixes #113)
  • Add contentType and size to allowExportNames in Next config #115

v0.5.4

  • Add instant to allowExportNames in Next config #112
Changelog

Sourced from eslint-plugin-react-refresh's changelog.

0.5.7

Add allowCompoundComponents option (#117)

Default: false (true in vite config)

Don't warn when components are exported as an object gathering them. Every member of the object must be a component, and a member holding an anonymous function requires a component name as key.

This should be enabled if the fast refresh implementation correctly handles this case. Vite supports it since @vitejs/plugin-react 4.7.0, @vitejs/plugin-react-swc 3.11.0.

{
  "react-refresh/only-export-components": [
    "error",
    { "allowCompoundComponents": true }
  ]
}

Enabling this option allows code such as the following:

const Root = () => <></>;
const Label = () => <></>;
export const Tag = { Root, Label };

0.5.6

  • Support re-exporting namespace components (fixes #116)

0.5.5

  • Fix SCREAMING_SNAKE_CASE constant exported via export { Name } incorrectly treated as React component #114 (fixes #113)
  • Add contentType and size to allowExportNames in Next config #115

0.5.4

  • Add instant to allowExportNames in Next config #112
Commits
  • fd40d83 Add allowCompoundComponents option [publish] (#117)
  • 620568a Support re-exporting namespace components (fixes #116) [publish]
  • 65c3172 [publish] v0.5.5
  • 8411020 Bump deps
  • c28fa15 Fix SCREAMING_SNAKE_CASE constant exported via export { Name } incorrectly ...
  • 554c764 [publish] add contentType and size to allowExportNames in Next config (#115)
  • e316617 [publish] Add instant to allowExportNames in Next config (#112)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

📝 Summary by GitNexus

Summary

A narrowly scoped development dependency update with no traced downstream reach. Review attention is centered on dependency metadata and the lockfile.

🟡 MEDIUM blast radius. This updates the development dependency eslint-plugin-react-refresh in package.json and pnpm-lock.yaml, with no graph dependents.

Review package.json alongside pnpm-lock.yaml to check that the dependency version is represented consistently. No affected execution flows or cross-repo consumers were found.

Added by GitNexus for PR #918. Edit freely — this block is replaced on the next review, everything above it is left untouched.

Bumps [eslint-plugin-react-refresh](https://github.com/ArnaudBarre/eslint-plugin-react-refresh) from 0.5.3 to 0.5.7.
- [Release notes](https://github.com/ArnaudBarre/eslint-plugin-react-refresh/releases)
- [Changelog](https://github.com/ArnaudBarre/eslint-plugin-react-refresh/blob/main/CHANGELOG.md)
- [Commits](ArnaudBarre/eslint-plugin-react-refresh@v0.5.3...v0.5.7)

---
updated-dependencies:
- dependency-name: eslint-plugin-react-refresh
  dependency-version: 0.5.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@vercel

vercel Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
do-knowledge-studio Ready Ready Preview, v0 Oct 6, 2026 6:05am UTC

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026
@github-actions github-actions Bot added the config label Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Blocked merge diagnosis — blocked
⏳ Check run(s) still in progress: ["Codacy Static Code Analysis","labeler","commitlint","GitHub Actions Workflow Validation","Diagnose Blocked Merge State","Detect Changes","YAML Syntax Validation","Trivy Filesystem Security Scan","Dependency Advisory Audit","Infrastructure as Code Security","Secret Detection","Shell Script Security Analysis","Analyze (javascript-typescript)","Analyze (actions)","GitNexus"]

@codacy-production

Copy link
Copy Markdown
Contributor

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@nexus-check

nexus-check Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor
Akon Labs

GitNexus Review · PR #918

No issues found in 2 changed files. (target branch indexed; the incoming branch is not, so cross-branch structure came from the diff alone)

Summary

A narrowly scoped development dependency update with no traced downstream reach. Review attention is centered on dependency metadata and the lockfile.

🟡 MEDIUM blast radius. This updates the development dependency eslint-plugin-react-refresh in package.json and pnpm-lock.yaml, with no graph dependents.

Review package.json alongside pnpm-lock.yaml to check that the dependency version is represented consistently. No affected execution flows or cross-repo consumers were found.

Full detail lives in the GitNexus check run for this commit.

@nexus-check

nexus-check Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🤖 Agent context for GitNexus Review · PR #918

This comment carries deterministic graph detail for coding agents and reviewers who want the receipts — the main review comment carries the human summary.

🟡 MEDIUM blast radius — no downstream dependents were found in the code graph; a spot-check of the dependents should cover it. (likely driven by file-risk heuristics — no direct dependents or affected modules were found)

Blast Level Dependents Modules Files
🟡 MEDIUM 0 0 2

What changed

Changed Files (2)
File Status
package.json 🟡 modified
pnpm-lock.yaml 🟡 modified

What to check

File Risk (2)
File Risk Category
package.json 🟡 MEDIUM Dependencies
pnpm-lock.yaml 🟢 LOW Lock File

@d-oit
d-oit enabled auto-merge (squash) October 6, 2026 06:04
@d-oit
d-oit merged commit 879109d into main Oct 6, 2026
24 of 25 checks passed
@d-oit
d-oit deleted the dependabot/npm_and_yarn/eslint-plugin-react-refresh-0.5.7 branch October 6, 2026 06:05

This branch was successfully deployed

1 active deployment
Preview — 3321fc28 Deployed Oct 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

config dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant