Update eslint and its plugins, enable more rules and fix their findings:
1. `unicorn/no-unsafe-string-replacement` found that uploading a file
whose name contains `$&` inserted a broken markdown link, because
`String#replace` expands such patterns in the replacement string
2. `@typescript-eslint/require-await` removes `async` from functions
that never await
3. Plugin rules not covered by a preset are now listed explicitly
---------
Co-authored-by: bircni <bircni@icloud.com>