AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

@Next/Codemod Upgrade Force-Pins ESLint 10, Breaking Installs For Projects With Eslint-Plugin-Import

The upgrade codemod modifies eslint from a caret range to an exact latest major (10.10.0) even when target Next.js peer dependencies allow ESLint 9, causing peer dependency conflict with eslint-plugin-import and aborting the upgrade.

highConfidence 92%Next.jsAffected Vcanary

Origin Analysis

The codemod's package update logic treats eslint as a direct upgrade target with latest version and pins exact version, without checking whether the current eslint version satisfies the peer dependency requirements of the target eslint-config-next. Peer conflicts with existing plugins such as eslint-plugin-import (which only supports eslint ^9) are not considered before installation.
1. Create a Next.js 15.5.0 app with TypeScript and ESLint. 2. Add dev dependency eslint-plugin-import@2.32.0 and install. 3. Run `npx @next/codemod@canary upgrade latest`. 4. Observe package.json change: "eslint": "^9" -> "eslint": "10.10.0". 5. npm install fails with peer dependency error: eslint-plugin-import requires eslint ^2...^9 but found 10.10.0. 6. Codemod exits with `Error: Failed to install dependencies` without applying Next upgrade.

Fixing Code Block

Edge Case Audit

This change does not force eslint upgrade, which may leave projects on older eslint majors if target eslint-config-next later requires a newer version than current; however such a requirement would be a peer conflict and should be handled explicitly. The patch may need to handle workspace/project package managers (npm, pnpm, yarn) when reading peer dependencies. Backward compatibility: if the existing eslint is a non-standard range (e.g., github URL), the helper should skip modification. Rollback: if this change causes unexpected behavior, revert to previous codemod version; users can manually adjust eslint after upgrade. Also ensure codemod checks multiple locations for eslint (dependencies vs devDependencies) and does not remove explicit user preference.

Ecosystem Topology