Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
github.com/trunkcode/hugo-seo
Hugo module adds the following attributes on the markup.
target
and rel
attribute on external linktitle
attribute on link and image elementshugo mod get github.com/trunkcode/hugo-seo@v0.2.2
Add the settings in the following snippet at the end of your site configuration file (default: config.toml) and save the file.
[module]
[[module.imports]]
path = "github.com/trunkcode/hugo-seo"
disable = false
module:
imports:
- path: github.com/trunkcode/hugo-seo
disable: false
{
"module": {
"imports": [
{
"path": "github.com/trunkcode/hugo-seo",
"disable": false
}
]
}
}
[Params]
[hugoSeo]
faExternalIcon = true
relValue = "noreferrer nofollow"
Params:
hugoSeo:
faExternalIcon: true
relValue: "noreferrer nofollow"
{
"Params": {
"hugoSeo": {
"faExternalIcon": true,
"relValue": "noreferrer nofollow"
}
}
}
The following is the full list of Hugo Seo variables with their default value. Users may choose to override those values in their site config file(s).
Default value: false
Add Font Awesome external icon on the external links.
Default value: "noopener"
Specifies the relationship between the current document and the linked document.
This project is licensed under the Apache License 2.0 - see the LICENSE.md file for details.
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.