
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
eslint-config-un
Advanced tools
A universal-ish ESLint config aiming to be reasonably strict and easily configurable.
Grown out of the personal collection of rules, an ESLint config aspiring to cover as many rules as possible, be reasonably strict and easily configurable. Only supports ESLint 9 and the flat config format.
npm i -D eslint-config-un
pnpm i -D eslint-config-un
yarn add -D eslint-config-un
Includes the rules from the following configs & plugins:
eslint-plugin-n
with node
prefix)eslint-plugin-import-x
with import
prefix)typescript
, vue
, nuxt
, pinia
, jest
, jest-extended
, vitest
, @builder.io/qwik
and @qwik.dev/core
packages and enables corresponding configurations (which can also be enabled or disabled explicitly).overrides
for rules.In your eslint.config.[cm]?js
:
// @ts-check
import {eslintConfig} from 'eslint-config-un';
export default eslintConfig({
// your configuration (optional)
});
eslint>=9
. Please ensure you have installed the correct version. Some package managers are installing non-optional peer dependencies automatically.typescript
or vue
) is performed using local-pkg
..vue
files if enforceTypescriptInScriptSection
is set to true in vue's config options which in turn is automatically set to true if typescript
package found installed. If you have .vue
files authored in both TypeScript and JavaScript, use enforceTypescriptInScriptSection.{files,ignores}
to manually specify TS & JS Vue components respectively. It is not currently possible to apply different ESLint rules depending on the value of lang
attribute of <script>
SFC section.preferArrowFunctions
security
json
yaml
toml
packageJson
perfectionist
deMorgan
errorsInsteadOfWarnings
option. You can find all such rules by inspecting the source code of this package.*.md
filesIf markdown
config is enabled (which is the default), the same rules provided by other configs will be applied to code blocks (```lang ... ```) inside Markdown files. This works because under the hood the plugin @eslint/markdown
that provides that functionality will create virtual files for each code block with the same extension as specified after ```.
But applying certain rules for code blocks might not be desirable because some of them are too strict for the code that won't be executed anyway or even unfixable (like missing imports). You can find the full list of disabled rules in src/configs/markdown.ts
file.
languageOptions
: Key globals
: Global AudioWorkletGlobalScope
has leading or trailing whitespace.Install globals
package as a dev dependency.
0.6.0
qwik
via eslint-plugin-qwik
, enabled automatically if @builder.io/qwik
or @qwik.dev/core
package is installed.jsonSchemaValidator
via eslint-plugin-json-schema-validator
, <u>disabled</u> by default.vitest/prefer-to-be-{falsy,truthy}
rules since their fixes don't result in the equivalent code and therefore cannot be suitable for most projects.enforceForIfStatements: false
for logical-assignment-operators
since code enforced by this option might be harder to read and understand.node
config option to specify eslint-plugin-n
plugin settings.jest
and vitest
configs, an option testDefinitionKeyword
now accepts a string that is used to set all the properties of the object.<style>
blocks are now created via eslint-processor-vue-blocks
. Added an option to disable or customize this behavior.<config>.overrides
type now includes disable-autofix/*
rules.typescript-eslint
: 8.24.1 -> 8.25.0@stylistic/eslint-plugin
: 4.0.1 -> 4.1.0@vitest/eslint-plugin
: 1.1.31 -> 1.1.36eslint-config-prettier
: 10.0.1 -> 10.0.2eslint-plugin-de-morgan
: 1.1.0 -> 1.2.0yaml-eslint-parser
: 1.2.3 -> 1.3.0FAQs
A universal-ish ESLint config aiming to be reasonably strict and easily configurable.
The npm package eslint-config-un receives a total of 295 weekly downloads. As such, eslint-config-un popularity was classified as not popular.
We found that eslint-config-un demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.