chore(deps): update dependency eslint-config-prettier to v9.1.2 [security]

This MR contains the following updates:

Package Change Age Confidence
eslint-config-prettier 9.1.1 -> 9.1.2 age confidence

eslint-config-prettier, eslint-plugin-prettier, synckit, @​pkgr/core, napi-postinstall have embedded malicious code

CVE-2025-54313 / GHSA-f29h-pxvx-f335

More information

Details

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:H/MR:N/UI:N/S:C/C:L/I:H/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

prettier/eslint-config-prettier (eslint-config-prettier)

v9.1.2

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

♻️ Rebasing: Whenever MR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this MR and you won't be reminded about this update again.


  • If you want to rebase/retry this MR, check this box

This MR has been generated by Renovate Bot.

Merge request reports

Loading