Plate 93
typescript-eslint 8.71.0: no-unsafe-enum-assignment + rule fixes (28 Sep 2026)
typescript-eslint published v8.71.0 on 28 September 2026: new typed rule @typescript-eslint/no-unsafe-enum-assignment (flags plain numbers/unsafe values assigned into enum-typed locations) plus fixes for no-misused-promises, no-unnecessary-type-assertion, unbound-method, and switch-exhaustiveness-check. npm latest confirmed 8.71.0; ShopperCove docs checklist only; pairs with live ESLint 10.12 coverage; no affiliate.
Aditya Challa4 min read
typescript-eslint 8.71.0: no-unsafe-enum-assignment + rule fixes (28 Sep 2026)
On 28 September 2026, typescript-eslint published v8.71.0, a minor release that adds a new type-aware rule and several plugin fixes. ShopperCove did not upgrade a production lint pipeline for this note and did not run benchmarks. Package identity was confirmed on the npm registry on 5 October 2026 (@typescript-eslint/eslint-plugin@8.71.0, dist-tag latest). Primary sources: the GitHub release v8.71.0 and the rule docs for no-unsafe-enum-assignment. This is a docs-based upgrade checklist—not performance advice and not a security advisory (no CVEs are claimed here).
There is no affiliate link in this article. This post has no affiliate links.
New rule: @typescript-eslint/no-unsafe-enum-assignment
Extending plugin:@typescript-eslint/strict-type-checked enables this rule. It requires type information (with the usual type-checked lint performance tradeoffs).
What it targets: TypeScript is deliberately lenient about assigning plain number values into numeric enums (useful for bit-flag combinations). The cost is that any number—including one that matches no enum member—can land in an enum-typed location. Numeric literals that merely coincide with a member’s value, and arithmetic that yields a plain number, have the same problem.
The rule reports those unsafe assignments so you depend on named members, not accidental numeric coincidence.
From the official examples:
| Pattern | Notes |
|---|---|
const fruit: Fruit = someNumber | Plain number into enum type — flagged |
const fruit: Fruit = 0 when Fruit.Apple === 0 | Literal that only “works” because of the member value — flagged |
mutated++ / mutated += 1 on an enum-typed variable | Yields plain number — flagged |
const fruit: Fruit = Fruit.Apple | Named member — OK |
| Reassign with another named member | OK |
Options: none (not configurable).
When not to use it (per docs): codebases that intentionally derive enum values with non-bitwise operators; validating untrusted API/user input before treating it as an enum (temporary disables or a validator like Zod may be better); third-party enums imported only as types; or teams that treat enums as a namespaced bag of values (consider const object + union instead).
Enable explicitly if you are not on strict-type-checked:
Fixes in 8.71.0
From the release notes:
| Rule | Fix |
|---|---|
no-misused-promises | Handle a return outside of any function (#12912) |
no-unnecessary-type-assertion | Specialize generic assertion report message (#12832) |
unbound-method | Respect this: void on class properties |
switch-exhaustiveness-check | Always sort literal cases in stable order (#12885) |
Hands-on upgrade checklist
- Inventory:
npm ls @typescript-eslint/eslint-plugin(and matching@typescript-eslint/parser/ utils). Note whether you are below 8.71.0. - Pin / bump in staging: install
@typescript-eslint/eslint-plugin@8.71.0(and keep sister packages on the same 8.71.0 line). Confirm withnpm view @typescript-eslint/eslint-plugin version→ expect 8.71.0 as latest as of sources read 5 Oct 2026. - Type-aware config: if you use
strict-type-checked, expectno-unsafe-enum-assignmentto light up on numeric-enum assignment patterns. If you only use recommended (non-strict) configs, decide whether to enable the rule deliberately. - Re-run lint CI: watch for new enum-assignment findings and for quieter/more accurate results on the four fixed rules above.
- Do not invent security urgency: this minor is features + bugfixes in the official release notes; ShopperCove is not attaching CVE IDs.
ShopperCove did not change production typescript-eslint versions for this article. Prefer the GitHub release and rule docs over third-party roundups. For core ESLint (not this plugin), see the live ShopperCove note on ESLint v10.12.0.
Bottom line
typescript-eslint v8.71.0 (28 Sep 2026) adds no-unsafe-enum-assignment for type-aware configs and ships four useful rule fixes. Pin @typescript-eslint/*@8.71.0 when ready. No affiliate.
Sources
- https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.71.0
- https://typescript-eslint.io/rules/no-unsafe-enum-assignment/
- https://www.npmjs.com/package/@typescript-eslint/eslint-plugin
- https://registry.npmjs.org/@typescript-eslint/eslint-plugin/8.71.0
- https://typescript-eslint.io/users/releases/
Related
- https://www.shoppercove.com/blog/eslint-10-12-release-october-2026
- https://www.shoppercove.com/blog/vite-plus-1-0-unified-toolchain-october-2026
- https://www.shoppercove.com/blog/playwright-1-63-test-locks-october-2026
- https://www.shoppercove.com/blog/astro-7-3-preview-ignore-lock-october-2026
- https://www.shoppercove.com/blog/angular-router-ssr-queryparams-dos-october-2026
- https://www.shoppercove.com/blog/webpack-5-111-esm-output-stable-september-2026
- https://www.shoppercove.com/blog/nodejs-26-lts-october-2026-schedule-change
- https://www.shoppercove.com/blog/nextjs-15-lts-end-of-support-october-2026
Lab evidence
What I found running this
Sources read 5 Oct 2026 (Asia/Calcutta) via WebFetch/npm: GitHub release v8.71.0 (published 2026-09-28T17:07:50Z); npm @typescript-eslint/eslint-plugin@8.71.0 (time 2026-09-28T17:13:54.998Z; dist-tag latest=8.71.0). Rule docs https://typescript-eslint.io/rules/no-unsafe-enum-assignment/ — requires type information; enabled via plugin:@typescript-eslint/strict-type-checked. Checklist: bump @typescript-eslint/* to 8.71.0; enable or review no-unsafe-enum-assignment if on strict-type-checked; re-run CI for fixed rules. No production lint suite upgraded on ShopperCove; no invented CVEs; no affiliate.
Related links
Plate 16
ESLint v10.12.0: SourceCode tokens/comments types + rule fixes (2 Oct 2026)
ESLint published v10.12.0 on 2 October 2026 as a minor release: documentation and TypeScript types for SourceCode#getText(), getLoc(), and getRange() now accept tokens and comments (matching runtime behavior), plus multiple rule fixes including astral/Unicode letter handling and autofix edge cases. npm latest confirmed 10.12.0; ShopperCove docs checklist only; no affiliate.
5 Oct 2026
Plate 51
Biome 2.5.15: type-inference speedups, nursery rules, HTML formatter (30 Sep 2026)
Biome published @biomejs/biome@2.5.15 on 30 September 2026: type-inference and HTML formatter performance, plus nursery rules for React defaults, Svelte runes, logical CSS, and more. ShopperCove upgrade checklist only; no affiliate.
5 Oct 2026
Plate 78
oxlint 1.87.0: React suggestion fixes + jsx-a11y hardening (5 Oct 2026)
oxlint published v1.87.0 on 5 October 2026: suggestion support for three React/unicorn rules and jsx-a11y/label/mouse/lang hardening plus other fixes. npm latest 1.87.0 confirmed; ShopperCove docs checklist only; no affiliate.
5 Oct 2026