Skip to content

chore(deps-dev): bump prettier from 3.8.3 to 3.9.6 in /paaster - #1208

Merged
WardPearce merged 1 commit into
mainfrom
dependabot/npm_and_yarn/paaster/prettier-3.9.6
Sep 10, 2026
Merged

chore(deps-dev): bump prettier from 3.8.3 to 3.9.6 in /paaster#1208
WardPearce merged 1 commit into
mainfrom
dependabot/npm_and_yarn/paaster/prettier-3.9.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps prettier from 3.8.3 to 3.9.6.

Release notes

Sourced from prettier's releases.

3.9.6

What's Changed

🔗 Changelog

3.9.5

🔗 Changelog

3.9.4

  • Angular: Format @content(name) -> @content (name) to align with other block syntax (#19499 by @​fisker)

🔗 Changelog

3.9.3

🔗 Changelog

3.9.1

🔗 Changelog

3.9.0

diff

🔗 Prettier 3.9: Major parser upgrades and Formatting improvements

3.8.5

🔗 Changelog

3.8.4

🔗 Changelog

Changelog

Sourced from prettier's changelog.

3.9.6

diff

TypeScript: Preserve quotes for methods named new (#19621 by @​kovsu)

// Input
interface Container {
  "new"(id: string): number;
}
// Prettier 3.9.5
interface Container {
new(id: string): number;
}
// Prettier 3.9.6
interface Container {
"new"(id: string): number;
}

TypeScript: Support import defer (#19624, #19675 by @​fisker)

// Input
import defer * as foo from "foo";
// Prettier 3.9.5
import * as foo from "foo";
// Prettier 3.9.6
import defer * as foo from "foo";

JavaScript: Added a new official plugin @prettier/plugin-yuku (#19628, #19629 by @​fisker)

@prettier/plugin-yuku is powered by Yuku (A high-performance JavaScript/TypeScript compiler toolchain written in Zig).

This plugin includes two new parsers: yuku (JavaScript syntax) and yuku-ts (TypeScript syntax).

To use this plugin:

  1. Install the plugin:

    yarn add --dev prettier @prettier/plugin-yuku

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 3, 2026
@socket-security

socket-security Bot commented Aug 3, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedprettier@​3.8.3 ⏵ 3.9.69810097 +198100

View full report

@socket-security

socket-security Bot commented Aug 3, 2026

Copy link
Copy Markdown

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Block Low
Potential code anomaly (AI signal): npm prettier is 60.0% likely to have a medium risk anomaly

Notes: No direct evidence of embedded malware (no eval/new Function, no credential theft, no obvious backdoor/persistence, no explicit network exfiltration) is visible in this fragment. The dominant security concern is supply-chain/execution risk: the code dynamically imports and executes formatter plugins based on user/config-supplied plugin identifiers and resolution rooted at process.cwd(). Additionally, it can read/write local files (including writing formatted output back to caller-specified paths) and uses predictable temp JSON files that may be susceptible to interference in shared environments. Security posture depends heavily on whether plugin inputs and file paths are trusted/validated and whether dependency/plugin resolution is constrained.

Confidence: 0.60

Severity: 0.55

From: paaster/package-lock.jsonnpm/prettier@3.9.6

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/prettier@3.9.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/paaster/prettier-3.9.6 branch 2 times, most recently from 99e7d76 to 360bd06 Compare August 5, 2026 03:13
Bumps [prettier](https://github.com/prettier/prettier) from 3.8.3 to 3.9.6.
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.8.3...3.9.6)

---
updated-dependencies:
- dependency-name: prettier
  dependency-version: 3.9.6
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/paaster/prettier-3.9.6 branch from 360bd06 to d4e3d06 Compare August 9, 2026 08:27
@WardPearce
WardPearce merged commit f3e9224 into main Sep 10, 2026
3 of 4 checks passed
@WardPearce
WardPearce deleted the dependabot/npm_and_yarn/paaster/prettier-3.9.6 branch September 10, 2026 05:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant