
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
lint-format
Advanced tools
Automatically setup the best and future-proofed linting and formatting config for your project with or without VS Code.
Uses ESLint, Prettier, eslint-config-airbnb, babel-eslint, eslint-config-prettier, eslint-plugin-html, eslint-plugin-import, eslint-plugin-jsx-a11y, eslint-config-wesbos, eslint-plugin-prettier, eslint-plugin-react, eslint-plugin-react-hooks under the hood.
These are opinionated settings for ESLint and Prettier. You might like them - or you might not. Don't worry, you can always change them.
You can use ESLint globally and/or locally per project.
It's usually best to install this locally once per project, that way you can have project-specific settings as well as sync those settings with others working on your project via git.
You can also install globally so that any project or rogue JS file you write will have linting and formatting applied without having to go through the setup. You might disagree and that is okay, just don't do it then 😃.
If you don't already have a package.json file, create one with npm init.
Then we need to install everything needed by the config:
npx install-peerdeps --dev lint-format
(note: npx is not a spelling mistake of npm. npx comes with when node and npm are installed and makes script running easier 😃)
You can see in your package.json there are now a big list of devDependencies.
Create a .eslintrc file in the root of your project's directory (it should live where package.json does). Your .eslintrc file should look like this:
{
"extends": ["lint-format"]
}
Tip: You can alternatively put this object in your package.json under the property "eslintConfig":. This makes one less file in your project.
"scripts": {
"lint": "eslint .",
"lint:fix": "eslint . --fix"
},
npm run lint and fix all fixable issues with npm run lint:fix. You probably want your editor to do this though.npx install-peerdeps --global lint-format
.eslintrc file:ESLint will look for one in your home directory
~/.eslintrc for macC:\Users\username\.eslintrc for windowsIn your .eslintrc file, it should look like this:
{
"extends": ["lint-format"]
}
eslint . or configure your editor as we show next.If you'd like to overwrite eslint or prettier settings, you can add the rules in your .eslintrc file. The ESLint rules go directly under "rules" while prettier options go under "prettier/prettier". Note that prettier rules overwrite anything in my config (trailing comma, and single quote), so you'll need to include those as well.
{
"extends": [
"lint-format"
],
"rules": {
"no-console": 2,
"prettier/prettier": [
"error",
{
"trailingComma": "es5",
"singleQuote": true,
"printWidth": 120,
"tabWidth": 8,
}
]
}
}
You should read this entire thing. Serious!
Once you have done one, or both, of the above installs. You probably want your editor to automatically lint and fix for you. Here are the instructions for the VS Code:
Code/File → Preferences → Settings. It's easier to enter these settings while editing the settings.json file, so click the
icon in the top right corner or open Command Pallet by pressing Ctrl/CMD+Shift+P and then type Preferences: Open Settings (JSON): // These are all my auto-save configs
"editor.formatOnSave": true,
// turn it off for JS and JSX, we will do this via eslint
"[javascript]": {
"editor.formatOnSave": false
},
"[javascriptreact]": {
"editor.formatOnSave": false
},
// tell the ESLint plugin to run on save
"editor.codeActionsOnSave": {
"source.fixAll": true
},
// Optional BUT IMPORTANT: If you have the prettier extension enabled for other languages like CSS and HTML, turn it off for JS since we are doing it through Eslint already
"prettier.disableLanguages": ["javascript", "javascriptreact"],
npm run eject or yarn ejectnpx install-peerdeps --dev lint-formatpackage.json and replace "extends": "react-app" with "extends": "lint-format"Start fresh. Sometimes global modules can goof you up. This will remove them all:
npm remove --global lint-format babel-eslint eslint eslint-config-prettier eslint-config-airbnb eslint-plugin-html eslint-plugin-prettier eslint-plugin-import eslint-plugin-jsx-a11y eslint-plugin-react prettier eslint-plugin-react-hooks
To do the above for local, omit the --global flag.
Then if you are using a local install, remove your package-lock.json file and delete the node_modules/ directory.
Then follow the above instructions again.
FAQs
Automatically setup the best and future-proofed linting and formatting config for your project with or without VS Code.
We found that lint-format demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.